Combofix Logfile: Code:
ComboFix 12-03-20.01 - Mathias 20.03.2012 21:50:19.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.43.1031.18.2047.1198 [GMT 1:00]
ausgeführt von:: c:\users\Mathias\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Mathias\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\System32\AscConTest.dll"
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\System32\AscConTest.dll
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-02-20 bis 2012-03-20 ))))))))))))))))))))))))))))))
.
.
2012-03-20 21:00 . 2012-03-20 21:03 -------- d-----w- c:\users\Mathias\AppData\Local\temp
2012-03-20 21:00 . 2012-03-20 21:00 -------- d-----w- c:\users\Günther\AppData\Local\temp
2012-03-20 10:30 . 2012-02-08 06:03 6552120 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{575A7275-2E6F-491B-B418-2528458FD775}\mpengine.dll
2012-03-19 17:09 . 2012-03-19 17:09 -------- d-----w- c:\program files\ESET
2012-03-17 17:30 . 2012-03-17 17:30 592824 ----a-w- c:\program files\Mozilla Firefox\gkmedias.dll
2012-03-17 17:30 . 2012-03-17 17:30 44472 ----a-w- c:\program files\Mozilla Firefox\mozglue.dll
2012-03-14 15:30 . 2012-03-14 15:30 -------- d-----w- c:\programdata\Sony Corporation
2012-03-14 11:28 . 2012-02-02 15:16 2044416 ----a-w- c:\windows\system32\win32k.sys
2012-03-14 11:28 . 2012-02-14 15:45 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-03-14 11:28 . 2012-02-14 15:45 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2012-03-14 11:28 . 2012-02-13 14:12 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2012-03-14 11:28 . 2012-02-13 13:47 683008 ----a-w- c:\windows\system32\d2d1.dll
2012-03-14 11:28 . 2012-02-13 13:44 1068544 ----a-w- c:\windows\system32\DWrite.dll
2012-03-14 11:28 . 2012-01-31 10:59 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-03-14 11:26 . 2012-01-09 15:54 613376 ----a-w- c:\windows\system32\rdpencom.dll
2012-03-14 11:26 . 2012-01-09 13:58 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-11 10:53 . 2012-03-11 10:53 -------- d-----w- c:\program files\iPod
2012-03-11 10:53 . 2012-03-11 10:54 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2012-03-11 10:53 . 2012-03-11 10:54 -------- d-----w- c:\program files\iTunes
2012-03-11 10:47 . 2012-03-11 10:47 -------- d-----w- c:\program files\Bonjour
2012-03-11 10:32 . 2012-03-11 10:32 -------- d-----w- c:\program files\Apple Software Update
2012-02-22 08:20 . 2007-03-05 11:42 15128 ----a-w- c:\windows\system32\x3daudio1_1.dll
2012-02-22 05:10 . 2012-02-22 13:38 -------- d-----w- c:\program files\DAEMON Tools Lite
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-12 12:19 . 2010-05-09 19:17 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-02-23 08:18 . 2010-05-28 20:48 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-02-20 21:11 . 2011-05-24 11:22 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-08 11:55 . 2012-02-08 11:55 161792 ----a-w- c:\windows\system32\msls31.dll
2012-02-08 11:55 . 2012-02-08 11:55 86528 ----a-w- c:\windows\system32\iesysprep.dll
2012-02-08 11:55 . 2012-02-08 11:55 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-02-08 11:55 . 2012-02-08 11:55 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-02-08 11:55 . 2012-02-08 11:55 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-02-08 11:55 . 2012-02-08 11:55 63488 ----a-w- c:\windows\system32\tdc.ocx
2012-02-08 11:55 . 2012-02-08 11:55 367104 ----a-w- c:\windows\system32\html.iec
2012-02-08 11:55 . 2012-02-08 11:55 74752 ----a-w- c:\windows\system32\iesetup.dll
2012-02-08 11:55 . 2012-02-08 11:55 23552 ----a-w- c:\windows\system32\licmgr10.dll
2012-02-08 11:55 . 2012-02-08 11:55 152064 ----a-w- c:\windows\system32\wextract.exe
2012-02-08 11:55 . 2012-02-08 11:55 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-02-08 11:55 . 2012-02-08 11:55 150528 ----a-w- c:\windows\system32\iexpress.exe
2012-02-08 11:55 . 2012-02-08 11:55 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-02-08 11:55 . 2012-02-08 11:55 35840 ----a-w- c:\windows\system32\imgutil.dll
2012-02-08 11:55 . 2012-02-08 11:55 11776 ----a-w- c:\windows\system32\mshta.exe
2012-02-08 11:55 . 2012-02-08 11:55 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-02-08 11:55 . 2012-02-08 11:55 101888 ----a-w- c:\windows\system32\admparse.dll
2012-03-17 17:30 . 2011-05-12 02:13 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-04-20 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-20 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-20 81920]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-17 281768]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2011-10-29 273528]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-06 421736]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1723684492-1119337897-2682288371-1000]
"EnableNotificationsRef"=dword:00000002
.
R3 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-09-06 169312]
S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2007-04-04 266343]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - BMLoad
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Inhalt des "geplante Tasks" Ordners
.
2012-03-20 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-03-01 10:59]
.
2012-03-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-16 18:08]
.
2012-03-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-16 18:08]
.
2012-03-20 c:\windows\Tasks\User_Feed_Synchronization-{3878B4AC-7B06-48BA-ABB8-506B25B244BF}.job
- c:\windows\system32\msfeedssync.exe [2012-02-08 11:55]
.
2012-03-20 c:\windows\Tasks\User_Feed_Synchronization-{ACCB2B73-7376-4D85-961A-F9F10035963C}.job
- c:\windows\system32\msfeedssync.exe [2012-02-08 11:55]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.at/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://de.rd.yahoo.com/customize/ycomp/defaults/su/*hxxp://de.yahoo.com
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{1CE4DE72-7FCC-4eb8-8F66-AE6A56A0A54D} - {0854DA01-5BF8-4E9D-A0E9-3CD5500AFB8C} - c:\progra~1\COMMON~1\WEBSPE~1.0\LgxIEBar.dll
TCP: Interfaces\{E6BD94DC-1049-4C17-88CA-1A95E28EE6A7}: NameServer = 213.94.78.16 213.94.78.17
FF - ProfilePath - c:\users\Mathias\AppData\Roaming\Mozilla\Firefox\Profiles\mw7gam1n.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.at/
.
.
**************************************************************************
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien:
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Live\Acer PlayMovie\000.fcl"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1723684492-1119337897-2682288371-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:f2,6b,60,8c,84,a3,fe,59,6d,eb,c4,f2,03,2e,18,f7,6c,6c,c7,b3,a9,08,66,
4a,d1,c8,d5,38,94,20,09,ce,cd,b4,fc,a5,71,06,0f,a0,f1,37,1d,33,36,00,39,6d,\
"??"=hex:45,70,ca,16,58,94,8c,90,ec,0b,c6,41,f9,c2,45,14
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000001
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(2580)
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_ger.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
c:\program files\Acer Arcade Live\Acer DV Magician\Component\PNRM1Splter.ax
c:\program files\Acer Arcade Live\Acer DV Magician\Component\R2DM1Splter.ax
c:\program files\Acer Arcade Live\SlideShow DVD\Component\PSDM2Splter.ax
c:\program files\Acer Arcade Live\SlideShow DVD\Component\PSDM1Splter.ax
c:\program files\Acer Arcade Live\Acer DV Magician\Component\PNRM2Splter.ax
c:\program files\Acer Arcade Live\Acer DV Magician\Component\R2DM2Splter.ax
c:\program files\Acer Arcade Live\Acer VideoMagician\Kernel\EditMovie\MDTLM2Splter.ax
c:\program files\Acer Arcade Live\Acer VideoMagician\Kernel\EditMovie\MDTLM1Splter.ax
c:\program files\Adobe\Elements Organizer 8.0\CAHeadless\ad2mpgdmx.ax
c:\program files\Common Files\Nikon\MPEG\nikonspmpeg.ax
c:\program files\Common Files\Nikon\MPEG\nikonmpegin.dll
c:\program files\Common Files\Sony Shared\OpenMG\OmgMP4Decoder2.ax
c:\program files\Common Files\Sony Shared\OpenMG\OmgDShowAsyncIO.dll
c:\program files\Common Files\Sony Shared\OpenMG\OmgMp4LibWrapper.dll
c:\progra~1\COMMON~1\ArcSoft\MPEGEN~1\RealMediaSplitter.ax
c:\progra~1\COMMON~1\ArcSoft\MPEGEN~1\mpgaudio.ax
c:\progra~1\COMMON~1\ArcSoft\MPEGEN~1\AdavAudioDec.dll
c:\program files\Common Files\Nikon\MPEG\nikondsmpeg.ax
c:\program files\Common Files\Nikon\MPEG\nikonmpgdec.dll
c:\program files\Acer Arcade Live\Acer HomeMedia\Kernel\DMP\CLWMFDemux.ax
c:\progra~1\COMMON~1\ArcSoft\MPEGEN~1\ASViD.ax
c:\program files\Acer Arcade Live\Acer VideoMagician\Kernel\Movie\CLDemuxer.ax
c:\progra~1\COMMON~1\ArcSoft\MPEGEN~1\H264Splitter.ax
c:\progra~1\COMMON~1\ArcSoft\MPEGEN~1\ArcSpl.ax
c:\progra~1\COMMON~1\ArcSoft\MPEGEN~1\uArcDemux.ax
c:\progra~1\COMMON~1\ArcSoft\MPEGEN~1\ArcTSSpl.ax
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Microsoft\BingBar\SeaPort.EXE
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\3DataManager\WTGService.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\program files\Google\Update\1.3.21.99\GoogleCrashHandler.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\NOTEPAD.EXE
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-03-20 22:20:41 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2012-03-20 21:20
.
Vor Suchlauf: 18 Verzeichnis(se), 27.485.851.648 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 27.016.851.456 Bytes frei
.
- - End Of File - - 01F7EAC0E747B01BEA8F6F468F55AE23 --- --- ---
nein, macht er nicht nicht mehr |