Rotary41 | 11.09.2012 14:24 | Und das nächste Log:
Combofix Logfile: Code:
ComboFix 12-09-11.01 - Matthias 11.09.2012 15:03:31.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.1977.909 [GMT 2:00]
ausgeführt von:: c:\users\Matthias\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Infizierte Kopie von c:\windows\system32\userinit.exe wurde gefunden und desinfiziert
Kopie von - c:\windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe wurde wiederhergestellt
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-08-11 bis 2012-09-11 ))))))))))))))))))))))))))))))
.
.
2012-09-11 13:11 . 2012-09-11 13:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-09-11 13:11 . 2012-09-11 13:11 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2012-09-10 21:00 . 2012-09-10 21:00 -------- d-----w- C:\_OTL
2012-09-10 20:46 . 2012-09-10 20:46 -------- d-----w- c:\windows\system32\drivers\UMDF\de-DE
2012-09-10 20:46 . 2012-09-10 20:46 3584 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\de-DE\LMPRTPRC.DLL.mui
2012-09-10 20:44 . 2012-09-10 20:44 40960 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\de\Microsoft.Ink.Resources.dll
2012-09-10 20:43 . 2012-09-10 20:44 -------- d-----w- c:\windows\system32\0407
2012-09-10 20:43 . 2012-09-10 20:46 -------- d-----w- c:\windows\de-DE
2012-09-10 20:43 . 2012-09-10 20:46 -------- d-----w- c:\windows\system32\drivers\de-DE
2012-09-10 20:43 . 2012-09-10 20:46 -------- d-----w- c:\windows\system32\de
2012-09-10 20:43 . 2012-09-10 20:46 -------- d-----w- c:\windows\system32\wbem\de-DE
2012-09-10 20:43 . 2012-09-10 20:43 -------- d-----w- c:\windows\system32\Windows System Resource Manager
2012-09-10 20:40 . 2012-09-10 20:40 -------- d-----w- c:\windows\system32\Vistalizator
2012-09-05 15:29 . 2012-09-05 15:29 -------- d-----w- c:\program files\ESET
2012-09-04 10:37 . 2012-09-04 10:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-09-04 10:37 . 2012-07-03 11:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-16 06:01 . 2012-07-04 14:02 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-08-15 14:48 . 2012-05-11 15:57 623616 ----a-w- c:\windows\system32\localspl.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-10 20:46 . 2012-09-10 20:46 6144 ----a-w- c:\windows\system32\drivers\UMDF\de-DE\WpdMtpDr.dll.mui
2012-09-10 20:46 . 2012-09-10 20:46 3584 ----a-w- c:\windows\system32\drivers\de-DE\umbus.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 2560 ----a-w- c:\windows\system32\drivers\de-DE\wd.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 4608 ----a-w- c:\windows\system32\drivers\de-DE\SCR111.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 4608 ----a-w- c:\windows\system32\drivers\de-DE\pscr.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 4608 ----a-w- c:\windows\system32\drivers\de-DE\grserial.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 4096 ----a-w- c:\windows\system32\drivers\de-DE\scmstcs.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 4096 ----a-w- c:\windows\system32\drivers\de-DE\gpr400.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 3584 ----a-w- c:\windows\system32\drivers\de-DE\stcusb.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 3584 ----a-w- c:\windows\system32\drivers\de-DE\serscan.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 3584 ----a-w- c:\windows\system32\drivers\de-DE\cxbp0wdm.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 3072 ----a-w- c:\windows\system32\drivers\de-DE\cmbp0wdm.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 5120 ----a-w- c:\windows\system32\drivers\de-DE\pcmcia.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 5632 ----a-w- c:\windows\system32\drivers\de-DE\nv4_mini.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 5120 ----a-w- c:\windows\system32\drivers\de-DE\ntrigdigi.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 6656 ----a-w- c:\windows\system32\drivers\de-DE\yk60x86.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 6144 ----a-w- c:\windows\system32\drivers\de-DE\bcm4sbxp.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 4608 ----a-w- c:\windows\system32\drivers\de-DE\msdsm.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 4096 ----a-w- c:\windows\system32\drivers\de-DE\parport.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 3584 ----a-w- c:\windows\system32\drivers\de-DE\rndismpx.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 3584 ----a-w- c:\windows\system32\drivers\de-DE\parvdm.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 2560 ----a-w- c:\windows\system32\drivers\de-DE\amdide.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 3584 ----a-w- c:\windows\system32\drivers\de-DE\scsiport.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 10240 ----a-w- c:\windows\system32\drivers\de-DE\afd.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 4096 ----a-w- c:\windows\system32\drivers\de-DE\modem.sys.mui
2012-09-10 20:46 . 2012-09-10 20:46 3072 ----a-w- c:\windows\system32\drivers\de-DE\srv.sys.mui
2012-09-10 20:45 . 2012-09-10 20:45 3584 ----a-w- c:\windows\system32\drivers\de-DE\RNDISMP.sys.mui
2012-09-10 20:45 . 2012-09-10 20:45 3072 ----a-w- c:\windows\system32\drivers\de-DE\qwavedrv.sys.mui
2012-09-10 20:45 . 2012-09-10 20:45 3584 ----a-w- c:\windows\system32\drivers\de-DE\pacer.sys.mui
2012-09-10 20:45 . 2012-09-10 20:45 77824 ----a-w- c:\windows\system32\drivers\de-DE\ntfs.sys.mui
2012-09-10 20:45 . 2012-09-10 20:45 3584 ----a-w- c:\windows\system32\drivers\de-DE\nfsrdr.sys.mui
2012-09-10 20:45 . 2012-09-10 20:45 4096 ----a-w- c:\windows\system32\drivers\de-DE\ipnat.sys.mui
2012-09-10 20:45 . 2012-09-10 20:45 4096 ----a-w- c:\windows\system32\drivers\de-DE\dxgkrnl.sys.mui
2012-09-10 20:45 . 2012-09-10 20:45 5632 ----a-w- c:\windows\system32\drivers\de-DE\fltmgr.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 3072 ----a-w- c:\windows\system32\drivers\de-DE\pnpmem.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 10752 ----a-w- c:\windows\system32\drivers\de-DE\ltmdmnt.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 7168 ----a-w- c:\windows\system32\drivers\de-DE\IPMIDrv.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 4608 ----a-w- c:\windows\system32\drivers\de-DE\wacompen.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 3584 ----a-w- c:\windows\system32\drivers\de-DE\hidbth.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 12288 ----a-w- c:\windows\system32\drivers\de-DE\serial.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 3072 ----a-w- c:\windows\system32\drivers\de-DE\Dot4usb.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 5120 ----a-w- c:\windows\system32\drivers\de-DE\bthpan.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 2560 ----a-w- c:\windows\system32\drivers\de-DE\BrParwdm.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 11776 ----a-w- c:\windows\system32\drivers\de-DE\BrSerId.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 3584 ----a-w- c:\windows\system32\drivers\de-DE\atikmdag.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 3584 ----a-w- c:\windows\system32\drivers\de-DE\ati2mtag.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 3584 ----a-w- c:\windows\system32\drivers\de-DE\ati2mpad.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 3072 ----a-w- c:\windows\system32\drivers\de-DE\UAGP35.SYS.mui
2012-09-10 20:44 . 2012-09-10 20:44 3072 ----a-w- c:\windows\system32\drivers\de-DE\GAGP30KX.SYS.mui
2012-09-10 20:44 . 2012-09-10 20:44 12288 ----a-w- c:\windows\system32\drivers\de-DE\ohci1394.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 45056 ----a-w- c:\windows\system32\drivers\de-DE\http.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 7680 ----a-w- c:\windows\system32\drivers\de-DE\luafv.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 6144 ----a-w- c:\windows\system32\drivers\de-DE\b57nd60x.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 25088 ----a-w- c:\windows\system32\drivers\de-DE\e1e6032.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 6144 ----a-w- c:\windows\system32\drivers\de-DE\sermouse.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 5120 ----a-w- c:\windows\system32\drivers\de-DE\mouclass.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 5120 ----a-w- c:\windows\system32\drivers\de-DE\e100b325.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 40960 ----a-w- c:\windows\system32\drivers\de-DE\volsnap.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 3584 ----a-w- c:\windows\system32\drivers\de-DE\mouhid.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 22016 ----a-w- c:\windows\system32\drivers\de-DE\E1G60I32.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 5632 ----a-w- c:\windows\system32\drivers\de-DE\tpm.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 3072 ----a-w- c:\windows\system32\drivers\de-DE\wdf01000.sys.mui
2012-09-10 20:44 . 2012-09-10 20:44 28160 ----a-w- c:\windows\system32\drivers\de-DE\mpio.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 15872 ----a-w- c:\windows\system32\drivers\de-DE\fvevol.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 5632 ----a-w- c:\windows\system32\drivers\de-DE\kbdclass.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 3072 ----a-w- c:\windows\system32\drivers\de-DE\VIAAGP.SYS.mui
2012-09-10 20:43 . 2012-09-10 20:43 3072 ----a-w- c:\windows\system32\drivers\de-DE\ULIAGPKX.SYS.mui
2012-09-10 20:43 . 2012-09-10 20:43 3072 ----a-w- c:\windows\system32\drivers\de-DE\SISAGP.SYS.mui
2012-09-10 20:43 . 2012-09-10 20:43 3072 ----a-w- c:\windows\system32\drivers\de-DE\kbdhid.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 11264 ----a-w- c:\windows\system32\drivers\de-DE\i8042prt.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 3072 ----a-w- c:\windows\system32\drivers\de-DE\NV_AGP.SYS.mui
2012-09-10 20:43 . 2012-09-10 20:43 8704 ----a-w- c:\windows\system32\drivers\de-DE\pci.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 4608 ----a-w- c:\windows\system32\drivers\de-DE\isapnp.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 3584 ----a-w- c:\windows\system32\drivers\de-DE\mssmbios.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 3072 ----a-w- c:\windows\system32\drivers\de-DE\AMDAGP.SYS.mui
2012-09-10 20:43 . 2012-09-10 20:43 3072 ----a-w- c:\windows\system32\drivers\de-DE\AGP440.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 21504 ----a-w- c:\windows\system32\drivers\de-DE\viac7.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 21504 ----a-w- c:\windows\system32\drivers\de-DE\processr.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 21504 ----a-w- c:\windows\system32\drivers\de-DE\intelppm.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 21504 ----a-w- c:\windows\system32\drivers\de-DE\crusoe.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 21504 ----a-w- c:\windows\system32\drivers\de-DE\amdk8.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 21504 ----a-w- c:\windows\system32\drivers\de-DE\amdk7.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 11264 ----a-w- c:\windows\system32\drivers\de-DE\acpi.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 8704 ----a-w- c:\windows\system32\drivers\de-DE\bthport.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 4096 ----a-w- c:\windows\system32\drivers\de-DE\hdaudbus.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 10240 ----a-w- c:\windows\system32\drivers\de-DE\battc.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 4096 ----a-w- c:\windows\system32\drivers\de-DE\vmbus.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 3584 ----a-w- c:\windows\system32\drivers\de-DE\vmstorfl.sys.mui
2012-09-10 20:43 . 2012-09-10 20:43 15872 ----a-w- c:\windows\web\ts\bin\de\TSPortalWebPart.resources.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-07-30 01:52 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-11-28 417792]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-08-10 348664]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GOEC62~1.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^VPN Client.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\VPN Client.lnk
backup=c:\windows\pss\VPN Client.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Assist Launcher]
2007-11-19 22:17 1261568 ----a-w- c:\program files\Acer\Acer Assist\launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Product Registration]
2007-11-26 18:21 3387392 ----a-w- c:\program files\Acer\Acer Registration\ACE1.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2008-06-11 21:43 640376 ----a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
2008-06-12 01:25 37232 ----a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 14:57 948672 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 00:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcadeDeluxeAgent]
2008-10-09 05:49 147456 ------w- c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CarboniteSetupLite]
2008-10-03 03:18 294544 ----a-w- c:\program files\Carbonite\CarbonitePreinstaller.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
2008-10-09 05:49 167936 ------w- c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eDataSecurity Loader]
2008-07-30 01:52 526896 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2010-08-15 17:16 30192 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-03-05 23:59 133104 ----atw- c:\users\Matthias\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2011-02-11 18:26 171032 ----a-w- c:\windows\System32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2011-02-11 18:26 137752 ----a-w- c:\windows\System32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
2007-05-17 21:45 279912 ----a-w- c:\program files\Microsoft LifeCam\LifeExp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
2008-07-02 18:35 850440 ----a-w- c:\progra~1\LAUNCH~1\LManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2012-07-03 11:46 462920 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2011-02-11 18:26 172568 ----a-w- c:\windows\System32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayMovie]
2008-10-17 22:54 167936 ------w- c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-01-05 20:18 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2008-06-20 00:52 6244896 ----a-w- c:\windows\RtHDVCpl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
2007-11-21 01:15 1826816 ----a-w- c:\windows\SkyTel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-17 09:07 252296 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2008-02-22 18:50 1037608 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-03-26 06:08 198160 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX3000]
2007-04-10 21:46 709992 ----a-w- c:\windows\vVX3000.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
2009-04-11 06:28 2153472 ----a-w- c:\windows\System32\oobefldr.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-21 02:25 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Inhalt des "geplante Tasks" Ordners
.
2012-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 16:36]
.
2012-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 16:36]
.
2012-09-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-649290938-3021887346-2181847563-1000Core.job
- c:\users\Matthias\AppData\Local\Google\Update\GoogleUpdate.exe [2009-03-05 23:59]
.
2012-09-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-649290938-3021887346-2181847563-1000UA.job
- c:\users\Matthias\AppData\Local\Google\Update\GoogleUpdate.exe [2009-03-05 23:59]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page =
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=2&o=vp32&d=0209&m=aspire_4730z
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: An vorhandene PDF-Datei anfügen - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: In Adobe PDF konvertieren - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Linkziel in Adobe PDF konvertieren - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.178.1
DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} - hxxps://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM-Run-eRecoveryService - (no file)
MSConfigStartUp-DW6 - c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-TomTomHOME - c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-09-11 15:16
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
.
c:\windows\system32\wbem\Performance\WmiApRpl_new.h 357 bytes
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 1
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-649290938-3021887346-2181847563-1000\Software\SecuROM\License information*]
"datasecu"=hex:35,92,e1,91,33,4e,29,6e,e0,01,d0,0c,4b,6b,a0,21,21,9a,a6,1f,88,
ff,5e,17,54,96,45,7c,0a,85,72,8d,18,f0,cb,6c,7c,10,d5,86,e1,95,0e,30,62,79,\
"rkeysecu"=hex:c4,66,44,8c,7c,08,40,32,f9,80,49,ff,1c,bb,ee,55
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(2656)
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
c:\program files\Audible\Bin\AAXSDKWin.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
c:\program files\Acer\Empowering Technology\Service\ETService.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
c:\program files\Cyberlink\Shared files\RichVideo.exe
c:\windows\system32\WebUpdateSvc4.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\conime.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\System32\wsqmcons.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-09-11 15:22:46 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2012-09-11 13:22
.
Vor Suchlauf: 16 Verzeichnis(se), 34.727.518.208 Bytes frei
Nach Suchlauf: 21 Verzeichnis(se), 34.549.776.384 Bytes frei
.
- - End Of File - - 9A15021AC1B4DFDA1D6E99D40B91CBC0 --- --- --- |