virus0190 | 12.03.2014 18:28 | Code:
ComboFix 14-03-10.01 - VIRUS 12.03.2014 17:35:08.1.8 - x64
Microsoft Windows 7 eXtreme 6.1.7601.1.1252.49.1031.18.6135.4962 [GMT 1:00]
ausgeführt von:: c:\users\VIRUS\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *Disabled/Updated* {179979E8-273D-D14E-0543-2861940E4886}
SP: Kaspersky Anti-Virus *Disabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\VIRUS\AppData\Roaming\chrtmp
c:\users\VIRUS\AppData\Roaming\inst.exe
c:\users\VIRUS\AppData\Roaming\keygen.exe
c:\users\VIRUS\AppData\Roaming\poclbm
c:\users\VIRUS\AppData\Roaming\poclbm\poclbm.ini
c:\users\VIRUS\AppData\Roaming\vso_ts_preview.xml
c:\users\VIRUS\DCPlusPlus-0.699.exe
c:\users\VIRUS\TeamViewerQS.exe
c:\windows\SysWow64\DEBUG.log
c:\windows\SysWow64\UNWISE.EXE
c:\windows\wininit.ini
c:\windows\TEMP\logishrd\LVPrcInj01.dll . . . . Nicht in der Lage zu löschen
c:\windows\TEMP\logishrd\LVPrcInj02.dll . . . . Nicht in der Lage zu löschen
.
.
((((((((((((((((((((((((((((((((((((((( Treiber/Dienste )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_uvnc_service
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-02-12 bis 2014-03-12 ))))))))))))))))))))))))))))))
.
.
2050-01-01 15:15 . 2050-01-01 15:15 -------- d-----w- c:\programdata\CAREL
2014-03-12 17:06 . 2014-03-12 17:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-03-10 19:34 . 2014-03-10 19:34 -------- d-----w- c:\users\VIRUS\AppData\Roaming\MotioninJoy
2014-03-10 19:34 . 2012-05-12 11:31 121416 ----a-w- c:\windows\system32\drivers\MijXfilt.sys
2014-03-10 19:34 . 2011-12-07 18:42 328712 ----a-w- c:\windows\system32\MijFrc.dll
2014-03-10 17:00 . 2014-03-10 17:00 -------- d-----w- c:\program files (x86)\pidgin-otr
2014-03-10 16:41 . 2014-03-10 16:42 -------- d-----w- c:\users\VIRUS\AppData\Local\gtk-2.0
2014-03-09 11:09 . 2014-03-09 11:10 -------- d-----w- C:\FRST
2014-03-09 10:18 . 2014-03-09 10:45 -------- d-----w- c:\windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-03-09 09:53 . 2014-03-09 10:03 -------- d-----w- c:\program files (x86)\ICQ Password Changer
2014-03-09 09:53 . 2010-06-01 00:44 676864 ----a-w- c:\windows\SysWow64\mxMonecSocket.dll
2014-03-09 09:51 . 2014-03-09 10:04 -------- d-----w- c:\program files (x86)\ICQ Password Hasher
2014-03-08 07:33 . 2014-03-08 07:33 -------- d-----w- c:\program files (x86)\WinPcap
2014-03-08 07:33 . 2014-03-08 08:14 -------- d-----w- c:\program files (x86)\Cain
2014-03-08 07:25 . 2014-03-10 21:58 -------- d-----w- c:\users\VIRUS\AppData\Roaming\.purple
2014-03-08 07:25 . 2014-03-08 07:25 -------- d-----w- c:\program files (x86)\Pidgin
2014-02-13 17:47 . 2013-12-21 09:53 548864 ----a-w- c:\windows\system32\vbscript.dll
2014-02-13 17:47 . 2013-12-21 08:56 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2014-02-13 17:07 . 2013-12-06 02:30 2048 ----a-w- c:\windows\system32\msxml3r.dll
2014-02-13 17:07 . 2013-12-06 02:30 1882112 ----a-w- c:\windows\system32\msxml3.dll
2014-02-13 17:07 . 2013-12-06 02:02 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
2014-02-13 17:07 . 2013-12-06 02:02 1237504 ----a-w- c:\windows\SysWow64\msxml3.dll
2014-02-13 17:07 . 2013-12-24 23:09 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2014-02-13 17:07 . 2013-12-24 22:48 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2014-02-13 17:07 . 2013-11-26 08:16 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2014-02-13 17:07 . 2013-11-22 22:48 3928064 ----a-w- c:\windows\system32\d2d1.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-12 16:28 . 2012-04-06 12:09 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-03-12 16:28 . 2011-07-11 20:11 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-02-19 20:28 . 2013-08-14 10:40 624224 ----a-w- c:\windows\system32\drivers\klif.sys
2014-02-19 20:28 . 2013-06-08 18:18 115296 ----a-w- c:\windows\system32\drivers\klflt.sys
2014-02-19 20:28 . 2013-05-05 20:42 29280 ----a-w- c:\windows\system32\drivers\klkbdflt.sys
2014-02-16 08:09 . 2011-07-11 18:48 88567024 ----a-w- c:\windows\system32\MRT.exe
2014-02-10 17:04 . 2014-01-03 06:59 430080 ----a-w- c:\windows\mod_frst.exe
2013-12-20 17:23 . 2013-06-06 15:38 178272 ----a-w- c:\windows\system32\drivers\kneps.sys
2013-12-18 20:09 . 2013-10-15 20:33 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-12-14 19:36 . 2013-12-14 19:36 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-12-14 19:36 . 2013-12-14 19:36 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-12-14 19:36 . 2013-12-14 19:36 942592 ----a-w- c:\windows\system32\jsIntl.dll
2013-12-14 19:36 . 2013-12-14 19:36 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-12-14 19:36 . 2013-12-14 19:36 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-12-14 19:36 . 2013-12-14 19:36 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-12-14 19:36 . 2013-12-14 19:36 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-12-14 19:36 . 2013-12-14 19:36 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-12-14 19:36 . 2013-12-14 19:36 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2013-12-14 19:36 . 2013-12-14 19:36 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-12-14 19:36 . 2013-12-14 19:36 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2013-12-14 19:36 . 2013-12-14 19:36 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-12-14 19:36 . 2013-12-14 19:36 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-12-14 19:36 . 2013-12-14 19:36 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-12-14 19:36 . 2013-12-14 19:36 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-12-14 19:36 . 2013-12-14 19:36 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-12-14 19:36 . 2013-12-14 19:36 337408 ----a-w- c:\windows\SysWow64\html.iec
2013-12-14 19:36 . 2013-12-14 19:36 247808 ----a-w- c:\windows\system32\msls31.dll
2013-12-14 19:36 . 2013-12-14 19:36 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-12-14 19:36 . 2013-12-14 19:36 235008 ----a-w- c:\windows\system32\elshyph.dll
2013-12-14 19:36 . 2013-12-14 19:36 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2013-12-14 19:36 . 2013-12-14 19:36 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-12-14 19:36 . 2013-12-14 19:36 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2013-12-14 19:36 . 2013-12-14 19:36 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2013-12-14 19:36 . 2013-12-14 19:36 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2013-12-14 19:36 . 2013-12-14 19:36 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-12-14 19:36 . 2013-12-14 19:36 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-12-14 19:36 . 2013-12-14 19:36 105984 ----a-w- c:\windows\system32\iesysprep.dll
2013-12-14 19:36 . 2013-12-14 19:36 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-12-14 19:36 . 2013-12-14 19:36 84992 ----a-w- c:\windows\system32\mshtmled.dll
2013-12-14 19:36 . 2013-12-14 19:36 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-12-14 19:36 . 2013-12-14 19:36 81408 ----a-w- c:\windows\system32\icardie.dll
2013-12-14 19:36 . 2013-12-14 19:36 774144 ----a-w- c:\windows\system32\jscript.dll
2013-12-14 19:36 . 2013-12-14 19:36 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-12-14 19:36 . 2013-12-14 19:36 62464 ----a-w- c:\windows\system32\pngfilt.dll
2013-12-14 19:36 . 2013-12-14 19:36 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2013-12-14 19:36 . 2013-12-14 19:36 48128 ----a-w- c:\windows\system32\imgutil.dll
2013-12-14 19:36 . 2013-12-14 19:36 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2013-12-14 19:36 . 2013-12-14 19:36 413696 ----a-w- c:\windows\system32\html.iec
2013-12-14 19:36 . 2013-12-14 19:36 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-12-14 19:36 . 2013-12-14 19:36 30208 ----a-w- c:\windows\system32\licmgr10.dll
2013-12-14 19:36 . 2013-12-14 19:36 296960 ----a-w- c:\windows\system32\dxtrans.dll
2013-12-14 19:36 . 2013-12-14 19:36 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2013-12-14 19:36 . 2013-12-14 19:36 243200 ----a-w- c:\windows\system32\webcheck.dll
2013-12-14 19:36 . 2013-12-14 19:36 235520 ----a-w- c:\windows\system32\url.dll
2013-12-14 19:36 . 2013-12-14 19:36 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-12-14 19:36 . 2013-12-14 19:36 147968 ----a-w- c:\windows\system32\occache.dll
2013-12-14 19:36 . 2013-12-14 19:36 143872 ----a-w- c:\windows\system32\wextract.exe
2013-12-14 19:36 . 2013-12-14 19:36 13824 ----a-w- c:\windows\system32\mshta.exe
2013-12-14 19:36 . 2013-12-14 19:36 135680 ----a-w- c:\windows\system32\iepeers.dll
2013-12-14 19:36 . 2013-12-14 19:36 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-12-14 19:36 . 2013-12-14 19:36 101376 ----a-w- c:\windows\system32\inseng.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2011-06-17 . 5740B1555D51D56547043181789027A5 . 2871808 . . [6.1.7600.16385] .. c:\windows\explorer.exe
[-] 2011-06-17 . 5740B1555D51D56547043181789027A5 . 2871808 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[7] 2011-06-16 . 3B69712041F3D63605529BD66DC00C48 . 2871808 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[7] 2010-11-21 . AC4C51EB24AA95B77F705AB159189E24 . 2872320 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2014-01-20 43848]
"vmware-tray.exe"="c:\program files (x86)\VMware\VMware Workstation\vmware-tray.exe" [2012-08-15 104088]
"VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"FreePDF Assistant"="c:\program files (x86)\FreePDF_XP\fpassist.exe" [2011-02-23 371200]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2013-05-01 421888]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2013-10-08 766208]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2014-01-20 152392]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
UltraMon.lnk - c:\windows\Installer\{ED7FE81C-378C-411D-B5B4-509B978BA204}\IcoUltraMon.ico /auto [2012-9-30 29310]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableInstallerDetection"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoThumbnailCache"= 1 (0x1)
. SafeBoot Registrierungsschlüssel muss repariert werden. Dieser PC kann nicht im abgesicherten Modus starten.
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
"VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 NSHE;Guardant Emulator Driver;c:\windows\system32\Drivers\NSHE.SYS;c:\windows\SYSNATIVE\Drivers\NSHE.SYS [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 VMwareHostd;VMware Workstation Server;c:\program files (x86)\VMware\VMware Workstation\vmware-hostd.exe;c:\program files (x86)\VMware\VMware Workstation\vmware-hostd.exe [x]
R3 cpuz136;cpuz136;c:\users\VIRUS\AppData\Local\Temp\cpuz136\cpuz136_x64.sys;c:\users\VIRUS\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [x]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys;c:\windows\SYSNATIVE\drivers\dgderdrv.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 GDPkIcpt;GDPkIcpt;c:\windows\system32\drivers\PktIcpt.sys;c:\windows\SYSNATIVE\drivers\PktIcpt.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 lblbtoag;{97438807-7B06-4AE5-88CC-9BA3518FE069};c:\program files (x86)\ophcrack\pwdump\servpw.exe;c:\program files (x86)\ophcrack\pwdump\servpw.exe [x]
R3 LcAgent;LC Remote Agent;c:\windows\Temp\lcagent.exe;c:\windows\Temp\lcagent.exe [x]
R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys;c:\windows\SYSNATIVE\DRIVERS\MijXfilt.sys [x]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys;c:\windows\SYSNATIVE\DRIVERS\netaapl64.sys [x]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys;c:\windows\SYSNATIVE\Drivers\pcouffin.sys [x]
R3 PSKMAD;PSKMAD;c:\windows\system32\DRIVERS\PSKMAD.sys;c:\windows\SYSNATIVE\DRIVERS\PSKMAD.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 tapoas;TAP-Win32 Adapter OAS;c:\windows\system32\DRIVERS\tapoas.sys;c:\windows\SYSNATIVE\DRIVERS\tapoas.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R4 klflt;klflt;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x]
S0 vidsflt61;Acronis Disk Storage Filter (61);c:\windows\system32\DRIVERS\vsflt61.sys;c:\windows\SYSNATIVE\DRIVERS\vsflt61.sys [x]
S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys;c:\windows\SYSNATIVE\DRIVERS\vmci.sys [x]
S0 vsock;vSockets Driver;c:\windows\system32\drivers\vsock.sys;c:\windows\SYSNATIVE\drivers\vsock.sys [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
S1 klpd;klpd;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x]
S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x]
S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 hmpalert;HitmanPro.Alert Support Driver;c:\windows\system32\drivers\hmpalert.sys;c:\windows\SYSNATIVE\drivers\hmpalert.sys [x]
S2 hmpalertsvc;HitmanPro.Alert Service;c:\program files (x86)\HitmanPro.Alert\hmpalert.exe;c:\program files (x86)\HitmanPro.Alert\hmpalert.exe [x]
S2 lnss_sscans;GFI LANguard N.S.S. Scheduled Scans Service;c:\program files (x86)\GFI\LANguard Network Security Scanner 3\sscansvc.exe;c:\program files (x86)\GFI\LANguard Network Security Scanner 3\sscansvc.exe [x]
S2 LVPrcS64;Process Monitor;c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe;c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [x]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys;c:\windows\SYSNATIVE\drivers\npf.sys [x]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 UltraMonUtility;UltraMon Utility Driver;c:\program files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys;c:\program files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys [x]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [x]
S2 vstor2-mntapi10-shared;Vstor2 MntApi 1.0 Driver (shared);SysWOW64\drivers\vstor2-mntapi10-shared.sys;SysWOW64\drivers\vstor2-mntapi10-shared.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
S3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys;c:\windows\SYSNATIVE\DRIVERS\LVPr2M64.sys [x]
S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
S3 LVUVC64;QuickCam Communicate Deluxe(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
S3 TTUSB2BDA_NTAMD64;TTUSB2BDA USB 2.0 Driver AMD64;c:\windows\system32\DRIVERS\ttusb2bda_amd64.sys;c:\windows\SYSNATIVE\DRIVERS\ttusb2bda_amd64.sys [x]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 660360]
"cFosSpeed"="c:\program files\cFosSpeed\cFosSpeed.exe" [2013-04-19 1587040]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files (x86)\ICQ7.6\ICQ.exe
LSP: %windir%\system32\vsocklib.dll
TCP: Interfaces\{4EFB06E1-8BFC-4820-A94E-4762C24D7E08}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
TCP: Interfaces\{603E97FA-19B0-4611-9624-F0A6CD467E8E}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
TCP: Interfaces\{E5EC2D48-0B67-4CCB-A162-39543A5F3DA1}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
FF - ProfilePath - c:\users\VIRUS\AppData\Roaming\Mozilla\Firefox\Profiles\vw6e6odi.default-1346587543496\
FF - prefs.js: network.proxy.socks - 127.0.0.1
FF - prefs.js: network.proxy.socks_port - 1234
FF - prefs.js: network.proxy.type - 0
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKLM-Run-Wondershare Helper Compact.exe - c:\program files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-Handy Recovery 3.0 - c:\progra~2\Handy Recovery\UNWISE.EXE
AddRemove-WinSetupFromUSB - c:\tools\Win Setup USB\Uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-94310977-2867148783-715122529-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:54,ff,31,f9,85,6a,4a,cd,74,cd,74,42,c1,67,60,43,8d,2a,a4,f8,8b,ca,31,
c7,ea,5d,2c,fb,9a,f5,98,50,77,ec,01,89,dd,09,bf,3f,f7,47,d8,3e,6e,06,c1,61,\
"??"=hex:95,54,71,c0,cc,ec,33,1d,14,3e,00,aa,c8,48,af,7a
.
[HKEY_USERS\S-1-5-21-94310977-2867148783-715122529-1000\Software\SecuROM\License information*]
"datasecu"=hex:45,0b,e0,ed,af,ba,6e,b6,88,5c,ec,7b,45,cd,17,06,3a,3e,bb,2d,f1,
ee,a8,37,94,6f,cc,2c,89,6a,03,40,05,8f,62,b0,20,37,82,bb,d0,2e,f3,ea,26,5f,\
"rkeysecu"=hex:d4,0f,97,05,97,7f,62,9a,3e,9f,02,f2,c8,81,18,bf
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
c:\windows\SysWOW64\vmnat.exe
c:\windows\SysWOW64\vmnetdhcp.exe
c:\program files (x86)\VMware\VMware Workstation\vmware-authd.exe
c:\program files (x86)\TeamViewer\Version9\TeamViewer.exe
c:\program files (x86)\TeamViewer\Version9\tv_w32.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2014-03-12 18:22:25 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2014-03-12 17:22
.
Vor Suchlauf: 10 Verzeichnis(se), 53.190.684.672 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 52.809.797.632 Bytes frei
.
- - End Of File - - F97A21FDB679ED61332FBA8C4F370E02
A36C5E4F47E84449FF07ED3517B43A31 sooooo und jetzt? :wtf: |