Hallo Schrauber :)
Danke für die Antwort :)
Bei deinem Link, ging die .exe nicht...es war laut meinem fehleranfälligen PC keine Win32 Anwendung...habe sie dann von bleepingcomputer.com heruntergeladen...hoffe das ist auch ok.
Installiert und ausgeführt.
Hier der Log: Code:
ComboFix 13-12-26.01 - yannick 26.12.2013 14:18:52.1.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.49.1031.18.2046.859 [GMT 1:00]
ausgeführt von:: c:\users\yannick\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\WinPCap
c:\program files\WinPCap\LICENSE
c:\programdata\vwj0rjr9.jss
c:\users\yannick\Desktop\Setup.exe
c:\windows\ST6UNST.000
c:\windows\system32\frapsvid.dll
c:\windows\system32\zip32.dll
D:\install.exe
D:\setup.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-11-26 bis 2013-12-26 ))))))))))))))))))))))))))))))
.
.
2013-12-26 13:28 . 2013-12-26 13:28 -------- d-----w- c:\users\yannick\AppData\Local\temp
2013-12-26 13:28 . 2013-12-26 13:28 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-12-26 13:28 . 2013-12-26 13:28 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-26 11:08 . 2013-12-26 11:11 -------- d-----w- c:\program files\Steam
2013-12-26 10:23 . 2013-12-26 10:23 8782 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS
2013-12-26 10:23 . 2013-12-26 10:23 7271 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS
2013-12-26 10:23 . 2013-12-26 10:23 23327 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS
2013-12-24 15:35 . 2013-12-24 15:35 -------- d-----w- C:\FRST
2013-12-24 15:29 . 2013-12-24 15:29 -------- d-----w- c:\users\yannick\AppData\Roaming\AVAST Software
2013-12-24 15:28 . 2013-12-24 15:28 57672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-12-24 15:28 . 2013-12-24 15:28 180248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-12-24 15:28 . 2013-12-24 15:28 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-12-24 15:28 . 2013-12-24 15:28 410528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-12-24 15:28 . 2013-12-24 15:28 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-12-24 15:28 . 2013-12-24 15:28 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-12-24 15:28 . 2013-12-24 15:28 54832 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2013-12-24 15:28 . 2013-12-24 15:28 270240 ----a-w- c:\windows\system32\aswBoot.exe
2013-12-24 15:28 . 2013-12-24 15:28 43152 ----a-w- c:\windows\avastSS.scr
2013-12-24 15:27 . 2013-12-24 15:27 -------- d-----w- c:\program files\AVAST Software
2013-12-24 15:25 . 2013-12-24 15:25 -------- d-----w- c:\programdata\AVAST Software
2013-12-22 20:24 . 2013-12-22 20:25 -------- d-----w- c:\programdata\Freemake
2013-12-22 20:24 . 2013-12-22 20:24 -------- d-----w- c:\program files\Freemake
2013-12-22 14:10 . 2013-12-22 14:12 -------- d--h--w- c:\program files\Temp
2013-12-22 13:16 . 2013-12-22 13:16 -------- d-----w- c:\program files\Audio Recorder Pro
2013-12-21 12:36 . 2013-12-21 12:36 -------- d-----w- c:\users\yannick\AppData\Roaming\IrfanView
2013-12-21 12:36 . 2013-12-21 12:36 -------- d-----w- c:\program files\IrfanView
2013-12-18 18:20 . 2013-12-18 19:33 -------- d-----w- c:\users\yannick\AppData\Roaming\IvAi
2013-12-12 12:08 . 2013-12-12 12:08 -------- d-----w- c:\program files\Common Files\Overwolf
2013-12-09 11:16 . 2013-12-09 11:16 -------- d-----w- c:\users\yannick\mitschnitt SL_data
2013-12-06 15:29 . 2013-12-06 15:30 -------- d-----w- c:\program files\Dropbox
2013-12-06 15:26 . 2013-12-26 10:25 -------- d-----w- c:\users\yannick\AppData\Roaming\Dropbox
2013-12-03 15:09 . 2013-12-03 15:09 -------- d-----w- c:\program files\LogMeIn Hamachi
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-11 17:24 . 2013-03-01 12:32 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-12-11 17:24 . 2013-03-01 12:32 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-11-20 19:27 . 2013-10-26 15:08 37664 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2013-11-14 11:57 . 2013-11-24 11:02 892704 ----a-w- c:\windows\system32\nvhdagenco32.dll
2013-11-14 11:57 . 2013-11-24 11:02 28448 ----a-w- c:\windows\system32\nvhdap32.dll
2013-11-14 11:57 . 2013-11-24 11:02 161056 ----a-w- c:\windows\system32\drivers\nvhda32v.sys
2013-11-14 11:57 . 2013-11-24 11:02 15862272 ----a-w- c:\windows\system32\nvwgf2um.dll
2013-11-14 11:57 . 2013-02-22 10:40 53024 ----a-w- c:\windows\system32\OpenCL.dll
2013-11-14 11:57 . 2013-11-24 11:02 9619872 ----a-w- c:\windows\system32\nvopencl.dll
2013-11-14 11:57 . 2013-11-24 11:02 22951200 ----a-w- c:\windows\system32\nvoglv32.dll
2013-11-14 11:57 . 2013-11-24 11:02 10446112 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2013-11-14 11:57 . 2013-11-24 11:02 893728 ----a-w- c:\windows\system32\nvdispgenco3233182.dll
2013-11-14 11:57 . 2013-11-24 11:02 2947872 ----a-w- c:\windows\system32\nvcuvid.dll
2013-11-14 11:57 . 2013-11-24 11:02 1049888 ----a-w- c:\windows\system32\nvdispco3233182.dll
2013-11-14 11:57 . 2013-02-22 10:39 15218504 ----a-w- c:\windows\system32\nvd3dum.dll
2013-11-14 11:57 . 2013-11-24 11:02 9663656 ----a-w- c:\windows\system32\nvcuda.dll
2013-11-14 11:57 . 2013-11-24 11:02 2747680 ----a-w- c:\windows\system32\nvcuvenc.dll
2013-11-14 11:57 . 2013-11-24 11:02 2697248 ----a-w- c:\windows\system32\nvapi.dll
2013-11-14 11:57 . 2013-11-24 11:02 17560352 ----a-w- c:\windows\system32\nvcompiler.dll
2013-11-11 14:26 . 2013-02-22 10:41 4321056 ----a-w- c:\windows\system32\nvcpl.dll
2013-11-11 14:26 . 2013-02-22 10:41 3036960 ----a-w- c:\windows\system32\nvsvc.dll
2013-11-11 14:26 . 2013-02-22 10:41 664352 ----a-w- c:\windows\system32\nvvsvc.exe
2013-11-11 14:26 . 2013-02-22 10:41 62752 ----a-w- c:\windows\system32\nvshext.dll
2013-11-11 14:26 . 2013-02-22 10:41 2555168 ----a-w- c:\windows\system32\nvsvcr.dll
2013-11-11 14:26 . 2013-02-22 10:41 209184 ----a-w- c:\windows\system32\nvmctray.dll
.
Code:
<pre>
c:\program files\KY-Programming\Hannover RP\bin\Hannover RP .exe
</pre> .
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2013-11-20 19:27 3135664 ----a-w- c:\program files\AVG SafeGuard toolbar\17.1.3.1\AVG SafeGuard toolbar_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG SafeGuard toolbar\17.1.3.1\AVG SafeGuard toolbar_toolbar.dll" [2013-11-20 3135664]
"{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}"= "c:\program files\AVAST Software\Avast\aswWebRepIE.dll" [2013-12-24 1138536]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj]
.
[HKEY_CLASSES_ROOT\clsid\{cc1a175a-e45b-41ed-a30c-c9b1d7a0c02f}]
[HKEY_CLASSES_ROOT\TypeLib\{6B795924-95E7-4D31-8521-407360C3AA0B}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-12-24 15:27 259464 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\yannick\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\yannick\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\yannick\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-18 1233920]
"RGSC"="c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe" [N/A]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-07-25 20684656]
"ECFSTServ"="c:\users\yannick\Desktop\lotsen\Easy Clearance 3\ECFSTServ.exe" [2010-04-18 1067520]
"MP3 Skype Recorder"="c:\program files\MP3 Skype Recorder\MP3 Skype Recorder.exe" [2011-11-17 1975296]
"DT Emphelungstool"="c:\users\yannick\AppData\Local\Deutsche Telekom\Empfehlungstool\DTEmpfehlungstool.exe" [N/A]
"Overwolf"="c:\program files\Overwolf\Overwolf.exe" [2013-12-09 35768]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-05-31 152392]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2013-05-01 421888]
"vProt"="c:\program files\AVG SafeGuard toolbar\vprot.exe" [2013-11-20 2334384]
"Nvtmru"="c:\program files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-11-14 1028384]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2013-11-29 3806544]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2013-12-24 3764024]
.
c:\users\yannick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\yannick\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-12-18 30714312]
Wecker für Windows 6.lnk - c:\program files\Wecker6\Wecker.exe [2013-10-20 1622066]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.8.130\SSScheduler.exe [2013-9-6 273296]
TP-LINK Wireless Configuration Utility.lnk - c:\program files\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe -nogui [2013-2-28 841216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2010-02-24 185472]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-05 20:34 1210320 ----a-w- c:\program files\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-12-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-01 17:24]
.
2013-12-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-10-31 17:20]
.
2013-12-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-10-31 17:20]
.
.
------- Zusätzlicher Suchlauf -------
.
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.2.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\17.1.3\ViProtocol.dll
FF - ProfilePath - c:\users\yannick\AppData\Roaming\Mozilla\Firefox\Profiles\b4cu94sg.default\
FF - prefs.js: browser.startup.homepage - www.google.de
FF - prefs.js: keyword.URL - hxxp://www.google.de/search?q=
FF - ExtSQL: 2013-10-26 17:08; avg@toolbar; c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.1.3.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-3D-Fahrschule Demo - c:\program files\3D-Fahrschule Demo\uninstall.exe
AddRemove-ArtMoney SE_is1 - c:\games\ArtMoney\Uninstall\unins000.exe
AddRemove-MP4 To MP3 Converter_is1 - c:\mp4tomp3converter\unins000.exe
AddRemove-Passenger Simulation - d:\flight simulator x\Passenger Simulation\uninst.exe
AddRemove-Real Atc Mission AZ269 - d:\flight simulator x\Missions\Airline Pilot\Uninstal.exe
AddRemove-Real Atc Mission AZ296 - d:\flight simulator x\Missions\APP LFPG\Uninstal.exe
AddRemove-vBus - c:\users\yannick\Desktop\afas\Uninstal.exe
AddRemove-VirtualBus_is1 - c:\users\yannick\Desktop\afas\VirtualBus\unins000.exe
AddRemove-{67F30877-CBBB-425C-9511-93181EFB8F08}_is1 - c:\program files\Airport Simulator 2013 Demo\unins000.exe
AddRemove-{75B3DAA3-0CB4-439B-A672-0A3FDD167AC3}_is1 - c:\program files\Flughafen-Feuerwehr-Simulator 2013 Demoversion\unins000.exe
AddRemove-American Samoa Rescue - d:\flight simulator x\Missions\Emergency\American Samoa Rescue\Uninstal.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2013-12-26 14:28
Windows 6.0.6001 Service Pack 1 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
.
c:\users\yannick\AppData\Local\Temp\catchme.dll 53248 bytes executable
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 1
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AIDA64Driver]
"ImagePath"="\??\c:\program files\FinalWire\AIDA64 Extreme Edition\kerneld.x32"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2342529146-4219116895-3439109131-1000\Software\SecuROM\License information*]
"datasecu"=hex:a7,23,ae,37,8c,ca,74,bb,1c,54,27,23,0b,91,18,5f,1c,e9,04,d5,41,
69,fa,60,3c,eb,e2,72,64,d5,21,37,54,ac,ae,a1,9e,b7,f1,ee,43,01,ee,5e,67,4b,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
Zeit der Fertigstellung: 2013-12-26 14:31:57
ComboFix-quarantined-files.txt 2013-12-26 13:31
.
Vor Suchlauf: 9.983.459.328 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 34.238.722.048 Bytes frei
.
- - End Of File - - 582E731FC7BAC52A8FD91EE32143773A
5C616939100B85E558DA92B899A0FC36
Ganz liebe Grüße und ein schönes Rest-Weihnachtsfest
Yannick |