Combofix Logfile: Code:
ComboFix 12-09-07.03 - Jeff 07.09.2012 22:06:17.1.4 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3583.2452 [GMT 2:00]
ausgeführt von:: c:\users\Jeff\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\blekkotb_031\blEKkotb_019x.dll
c:\program files\Mozilla Firefox\searchplugins\search.xml
G:\Autorun.inf
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-08-07 bis 2012-09-07 ))))))))))))))))))))))))))))))
.
.
2012-09-07 20:11 . 2012-09-07 20:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-09-07 19:40 . 2012-09-07 19:46 -------- d-----w- C:\_OTL
2012-09-07 17:57 . 2012-09-07 17:57 29904 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{403B3E48-6563-48B8-99DB-0FE22F60D56B}\MpKsl9862028b.sys
2012-09-07 17:41 . 2012-08-23 07:15 7022536 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{403B3E48-6563-48B8-99DB-0FE22F60D56B}\mpengine.dll
2012-09-06 13:33 . 2012-08-23 07:15 7022536 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-09-05 18:45 . 2012-09-05 20:06 -------- d-----w- C:\Fraps
2012-09-05 18:13 . 2012-09-05 18:13 -------- d-----w- c:\program files\HyperCam 2
2012-09-05 18:12 . 2012-09-05 18:13 -------- d-----w- c:\programdata\SweetIM
2012-09-05 18:12 . 2012-09-05 18:13 -------- d-----w- c:\program files\SweetIM
2012-09-05 18:10 . 2012-09-05 18:10 -------- d-----w- c:\programdata\blekko toolbars
2012-09-05 18:10 . 2012-09-07 20:10 -------- d-----w- c:\program files\blekkotb_031
2012-09-05 18:10 . 2012-09-05 18:10 -------- d-----w- c:\programdata\Anti-phishing Domain Advisor
2012-09-05 14:45 . 2012-09-05 14:45 -------- d-----w- c:\program files\Microsoft
2012-09-05 14:44 . 2012-09-05 14:44 -------- d-----w- c:\program files\Common Files\Java
2012-09-05 14:44 . 2012-09-05 14:44 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-05 14:44 . 2012-09-05 14:44 -------- d-----w- c:\program files\Java
2012-09-05 13:18 . 2012-09-05 13:18 -------- d-----w- c:\program files\TeamViewer
2012-09-04 19:02 . 2004-11-23 22:22 32768 ----a-r- c:\windows\system32\XSIChooser.exe
2012-08-30 13:46 . 2012-08-30 13:46 65536 ----a-w- c:\windows\system32\frapsvid.dll
2012-08-29 18:04 . 2012-09-06 17:57 -------- d-----w- C:\HammerAutosave
2012-08-28 11:23 . 2012-08-28 11:23 -------- d-----w- c:\programdata\ATI
2012-08-28 11:23 . 2012-08-28 11:23 -------- d-----w- c:\program files\AMD APP
2012-08-23 14:43 . 2010-06-02 02:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2012-08-23 14:43 . 2010-06-02 02:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2012-08-23 14:43 . 2010-06-02 02:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2012-08-23 14:43 . 2010-05-26 09:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2012-08-23 14:43 . 2010-05-26 09:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2012-08-23 14:43 . 2010-05-26 09:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2012-08-23 14:43 . 2010-05-26 09:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2012-08-23 14:43 . 2010-05-26 09:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2012-08-23 11:59 . 2012-09-05 19:40 -------- d-----w- c:\program files\Common Files\Steam
2012-08-23 11:08 . 2012-08-23 11:08 -------- d-----w- c:\program files\1-abc
2012-08-22 21:35 . 2010-02-04 08:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2012-08-22 21:35 . 2010-02-04 08:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2012-08-22 21:35 . 2010-02-04 08:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2012-08-22 21:35 . 2010-02-04 08:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2012-08-22 21:19 . 2012-08-22 21:19 -------- d-----w- c:\program files\Disney Interactive Studios
2012-08-22 20:55 . 2012-08-22 20:55 -------- d-----w- c:\program files\Microsoft Garage
2012-08-22 16:42 . 2012-08-22 16:43 -------- d-----w- c:\program files\Google
2012-08-22 16:41 . 2012-08-22 16:41 -------- d-----w- c:\program files\Common Files\Adobe
2012-08-22 13:43 . 2012-09-07 17:38 -------- d-----w- c:\program files\Opera
2012-08-18 23:50 . 2012-08-18 23:50 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2012-08-16 15:17 . 2012-08-16 15:17 -------- d-----w- c:\programdata\WEBREG
2012-08-16 15:14 . 2012-08-16 15:14 -------- d-----w- c:\programdata\HP Product Assistant
2012-08-16 15:12 . 2012-08-16 15:12 -------- d-----w- c:\program files\Common Files\HP
2012-08-16 15:11 . 2012-08-16 15:11 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2012-08-16 15:10 . 2008-10-06 13:37 315392 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpfpp083.dll
2012-08-16 15:10 . 2008-10-29 18:56 271704 ----a-w- c:\windows\system32\hpzids01.dll
2012-08-16 15:10 . 2008-10-06 13:38 121344 ----a-w- c:\windows\system32\hpf3l083.dll
2012-08-16 15:10 . 2008-10-29 18:57 974848 ----a-w- c:\windows\system32\hpost_p02b.dll
2012-08-16 15:10 . 2008-10-29 18:57 737280 ----a-w- c:\windows\system32\hposwia_p02b.dll
2012-08-16 15:10 . 2008-10-29 18:57 307200 ----a-w- c:\windows\system32\hposc_p02a.dll
2012-08-16 15:09 . 2012-08-16 15:15 -------- d-----w- c:\program files\HP
2012-08-16 15:07 . 2012-08-16 15:16 -------- d-----w- c:\programdata\HP
2012-08-16 15:07 . 2009-07-14 01:15 319488 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpfppw73.dll
2012-08-16 14:24 . 2009-02-27 01:42 31640 ----a-w- c:\windows\system32\msonpmon.dll
2012-08-16 14:24 . 2006-10-26 17:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2012-08-16 14:23 . 2012-08-18 23:51 -------- d-----w- c:\program files\Microsoft Works
2012-08-16 14:22 . 2012-08-16 14:22 -------- d-----w- c:\windows\PCHEALTH
2012-08-16 14:20 . 2012-08-16 14:20 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2012-08-16 14:19 . 2012-08-19 22:10 -------- d-----w- c:\programdata\Microsoft Help
2012-08-16 14:19 . 2012-08-16 14:19 -------- d-----r- C:\MSOCache
2012-08-16 01:44 . 2012-08-16 01:44 -------- d-----w- c:\windows\system32\wbem\en-US
2012-08-16 01:07 . 2012-03-01 05:46 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-08-16 01:07 . 2012-03-01 05:29 5120 ----a-w- c:\windows\system32\wmi.dll
2012-08-16 01:07 . 2012-03-01 05:37 172544 ----a-w- c:\windows\system32\wintrust.dll
2012-08-16 01:07 . 2012-03-01 05:33 159232 ----a-w- c:\windows\system32\imagehlp.dll
2012-08-16 01:04 . 2010-02-11 07:10 293376 ----a-w- c:\windows\system32\browserchoice.exe
2012-08-16 01:00 . 2012-08-16 01:00 -------- d-----w- c:\program files\MSXML 4.0
2012-08-16 00:46 . 2011-03-12 11:23 870912 ----a-w- c:\windows\system32\XpsPrint.dll
2012-08-14 18:01 . 2012-08-14 18:01 -------- d-----w- c:\program files\Firefox Backup Tool
2012-08-14 17:51 . 2012-08-14 18:18 215128 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-08-14 17:49 . 2012-08-14 18:18 139128 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-08-14 17:49 . 2012-08-14 18:18 215128 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-08-14 17:49 . 2012-08-14 18:16 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-08-14 17:49 . 2012-08-14 18:16 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe
2012-08-14 17:29 . 2012-08-14 18:10 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-14 17:29 . 2012-08-14 18:10 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-14 17:29 . 2012-08-14 17:29 -------- d-----w- c:\windows\system32\Macromed
2012-08-14 17:27 . 2012-04-05 16:03 3969336 ----a-w- c:\windows\system32\GameMon.des
2012-08-14 17:27 . 2004-12-31 06:43 4682 ----a-w- c:\windows\system32\npptNT2.sys
2012-08-14 17:27 . 2003-07-16 15:17 5174 ----a-w- c:\windows\system32\nppt9x.vxd
2012-08-14 17:26 . 2012-08-14 17:26 -------- d-----w- c:\program files\Common Files\INCA Shared
2012-08-14 17:23 . 2012-08-14 17:23 -------- d-----w- c:\program files\Oracle
2012-08-14 17:23 . 2012-09-05 14:44 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-08-14 17:23 . 2012-09-05 14:44 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-14 17:17 . 2012-08-14 17:17 -------- d-----w- c:\program files\CCleaner
2012-08-14 17:10 . 2012-08-14 17:10 -------- dc----w- c:\windows\system32\DRVSTORE
2012-08-14 17:10 . 2009-05-18 11:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-08-14 17:10 . 2008-04-17 10:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2012-08-14 17:10 . 2012-08-14 17:10 -------- d-----w- c:\program files\iPod
2012-08-14 17:10 . 2012-08-14 17:10 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2012-08-14 17:10 . 2012-08-14 17:10 -------- d-----w- c:\program files\iTunes
2012-08-14 17:10 . 2012-08-14 17:10 -------- d-----w- c:\programdata\Apple Computer
2012-08-14 17:09 . 2012-08-14 17:09 -------- d-----w- c:\program files\Apple Software Update
2012-08-14 17:09 . 2012-08-14 17:09 -------- d-----w- c:\program files\Bonjour
2012-08-14 17:09 . 2012-08-14 17:10 -------- d-----w- c:\program files\Common Files\Apple
2012-08-14 17:09 . 2012-08-14 17:09 -------- d-----w- c:\programdata\Apple
2012-08-14 16:59 . 2012-09-05 19:51 -------- d-----w- c:\windows\Panther
2012-08-14 16:54 . 2012-08-14 16:54 -------- d-----w- c:\program files\Common Files\Steganos
2012-08-14 16:36 . 2012-08-14 16:36 713784 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BAD8719A-30A1-4FA7-8718-C82075023871}\gapaengine.dll
2012-08-14 16:35 . 2012-01-31 12:44 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-08-14 16:33 . 2012-08-16 01:03 -------- d-----w- c:\program files\Microsoft Security Client
2012-08-14 16:27 . 2012-08-14 16:27 -------- d-----w- c:\program files\AMD AVT
2012-08-14 16:25 . 2012-08-14 16:25 -------- d-----w- c:\programdata\LogiShrd
2012-08-14 16:23 . 2012-08-14 16:23 19720 ----a-w- c:\windows\system32\drivers\LGBusEnum.sys
2012-08-14 16:23 . 2012-08-14 16:23 14856 ----a-w- c:\windows\system32\drivers\LGVirHid.sys
2012-08-14 16:23 . 2012-08-14 16:23 341000 ----a-w- c:\windows\system32\drivers\UMDF\lgSSQVGA.dll
2012-08-14 16:23 . 2012-08-14 16:23 140808 ----a-w- c:\windows\system32\drivers\UMDF\lgSSBW.dll
2012-08-14 16:23 . 2012-08-14 16:29 -------- d-----w- c:\program files\Logitech Gaming Software
2012-08-14 16:19 . 2012-08-14 16:19 0 ----a-w- c:\windows\ativpsrm.bin
2012-08-14 16:17 . 2012-08-14 16:17 -------- d-----w- c:\program files\Common Files\ATI Technologies
2012-08-14 16:17 . 2012-08-28 11:22 -------- d-----w- c:\programdata\AMD
2012-08-14 16:17 . 2010-02-18 07:18 37944 ----a-w- c:\windows\system32\drivers\amdiox86.sys
2012-08-14 16:16 . 2012-08-28 11:22 -------- d-----w- c:\program files\ATI Technologies
2012-08-14 16:16 . 2012-08-14 16:25 -------- d-----w- C:\AMD
2012-08-14 16:15 . 2012-08-14 16:15 -------- d-----w- c:\program files\ATI
2012-08-14 16:15 . 2012-08-14 16:15 -------- d-----w- C:\ATI
2012-08-14 16:14 . 2012-08-14 16:14 -------- d-----w- c:\program files\NVIDIA Corporation
2012-08-14 16:12 . 2012-02-17 05:34 826880 ----a-w- c:\windows\system32\rdpcore.dll
2012-08-14 16:11 . 2012-09-04 19:01 -------- d-----w- c:\program files\Common Files\InstallShield
2012-08-14 16:11 . 2012-09-06 19:36 -------- d-sh--w- c:\windows\Installer
2012-08-14 16:10 . 2009-04-30 04:46 704512 ----a-r- c:\windows\system32\cohelper.dll
2012-08-14 16:10 . 2009-04-28 21:27 5940 ----a-r- c:\windows\system32\drivers\nvphy.bin
2012-08-14 16:10 . 2009-04-30 05:06 287008 ----a-w- c:\windows\system32\drivers\nvmf6232.sys
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-28 04:09 . 2012-07-28 04:09 5538984 ----a-w- c:\windows\system32\atiumdag.dll
2012-07-28 04:06 . 2012-07-28 04:06 8758784 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2012-07-28 03:43 . 2012-07-28 03:43 58880 ----a-w- c:\windows\system32\coinst_8.982.dll
2012-07-28 02:50 . 2011-04-20 02:07 20546560 ----a-w- c:\windows\system32\atioglxx.dll
2012-07-28 02:15 . 2012-07-28 02:15 163840 ----a-w- c:\windows\system32\atiapfxx.exe
2012-07-28 02:15 . 2011-04-20 02:09 931328 ----a-w- c:\windows\system32\aticfx32.dll
2012-07-28 02:10 . 2012-07-28 02:10 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2012-07-28 02:10 . 2012-07-28 02:10 469504 ----a-w- c:\windows\system32\atieclxx.exe
2012-07-28 02:09 . 2012-07-28 02:09 217600 ----a-w- c:\windows\system32\atiesrxx.exe
2012-07-28 02:08 . 2012-07-28 02:08 163840 ----a-w- c:\windows\system32\atitmmxx.dll
2012-07-28 02:08 . 2012-07-28 02:08 20992 ----a-w- c:\windows\system32\atimuixx.dll
2012-07-28 02:07 . 2012-07-28 02:07 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2012-07-28 02:07 . 2012-06-11 17:16 6430208 ----a-w- c:\windows\system32\atidxx32.dll
2012-07-28 01:35 . 2012-07-28 01:35 46080 ----a-w- c:\windows\system32\aticalrt.dll
2012-07-28 01:35 . 2012-07-28 01:35 44032 ----a-w- c:\windows\system32\aticalcl.dll
2012-07-28 01:32 . 2012-07-28 01:32 4751872 ----a-w- c:\windows\system32\atiumdva.dll
2012-07-28 01:30 . 2012-07-28 01:30 13605888 ----a-w- c:\windows\system32\aticaldd.dll
2012-07-28 01:15 . 2011-04-20 01:23 368640 ----a-w- c:\windows\system32\atiadlxx.dll
2012-07-28 01:15 . 2011-04-20 01:22 14848 ----a-w- c:\windows\system32\atiglpxx.dll
2012-07-28 01:14 . 2011-04-20 01:22 33280 ----a-w- c:\windows\system32\atigktxx.dll
2012-07-28 01:14 . 2012-07-28 01:14 296448 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2012-07-28 01:13 . 2011-04-20 01:21 109568 ----a-w- c:\windows\system32\atiuxpag.dll
2012-07-28 01:13 . 2011-04-20 01:21 83456 ----a-w- c:\windows\system32\atiu9pag.dll
2012-07-28 01:12 . 2012-07-28 01:12 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2012-07-28 01:08 . 2012-07-28 01:08 56832 ----a-w- c:\windows\system32\atimpc32.dll
2012-07-28 01:08 . 2012-07-28 01:08 56832 ----a-w- c:\windows\system32\amdpcom32.dll
2012-07-27 20:47 . 2012-07-27 20:47 159232 ----a-w- c:\windows\system32\clinfo.exe
2012-07-27 20:47 . 2012-07-27 20:47 65024 ----a-w- c:\windows\system32\OpenVideo.dll
2012-07-27 20:47 . 2012-07-27 20:47 56320 ----a-w- c:\windows\system32\OVDecode.dll
2012-07-27 20:46 . 2012-07-27 20:46 13013504 ----a-w- c:\windows\system32\amdocl.dll
2012-06-11 11:48 . 2012-06-11 11:48 50176 ----a-w- c:\windows\system32\OpenCL.dll
2012-07-14 00:15 . 2012-08-14 16:36 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2012-07-04 13:03 1310040 ----a-r- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2012-07-04 1310040]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="d:\rocketdock\RocketDock.exe" [2007-09-02 495616]
"SSS12 Browser Monitor"="d:\steganos privacy suite 12\SteganosBrowserMonitor.exe" [2011-08-18 57344]
"Steam"="d:\steam\Steam.exe" [2012-08-23 1353080]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2009-09-21 1681408]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2012-05-21 5092152]
"SSS12 HotKeys"="d:\steganos privacy suite 12\SteganosHotKeyService.exe" [2011-08-18 84480]
"SSS12 File Redirection Starter"="d:\steganos privacy suite 12\fredirstarter.exe" [2011-08-18 17408]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-30 59280]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-06-07 421776]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-08-06 642216]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"Anti-phishing Domain Advisor"="c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe" [2012-05-03 217256]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2012-05-29 115032]
"Sweetpacks Communicator"="c:\program files\SweetIM\Communicator\SweetPacksUpdateManager.exe" [2012-08-15 231768]
.
c:\users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 gupdate;Google Update-Dienst (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R2 MouseWithoutBordersSvc;Mouse without Borders Service;c:\program files\Microsoft Garage\Mouse without Borders\MouseWithoutBordersSvc.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
S1 MpKsl9862028b;MpKsl9862028b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{403B3E48-6563-48B8-99DB-0FE22F60D56B}\MpKsl9862028b.sys [x]
S1 SLEE_17_DRIVER;Steganos Live Encryption Engine 17 [Driver];c:\windows\system32\drivers\Sleen17.sys [x]
S1 STGMFEngine32;Steganos RAM Disk Engine [Driver];c:\windows\system32\drivers\STGMFEngine32.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [x]
S2 Steganos Volatile Disk;Steganos Volatile Disk;c:\windows\system32\STGRAMDiskHandler32.exe [x]
S2 TeamViewer7;TeamViewer 7;c:\program files\TeamViewer\Version7\TeamViewer_Service.exe [x]
S3 amdiox86;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox86.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Inhalt des "geplante Tasks" Ordners
.
2012-09-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-14 18:10]
.
2012-09-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-08-22 16:42]
.
2012-09-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-08-22 16:42]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://blekko.com/ws/?source=c3348dd4&toolbarid=blekkotb_031&u=4C0BF23A9232A0B36F84845047959A7C&tbp=homepage
uInternet Settings,ProxyOverride = *.local
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\frknonnv.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://de-de.facebook.com/|hxxp://shotonline.gamescampus.eu/|hxxp://www.stayfriends.de/|hxxp://www.kicker.de/
FF - prefs.js: browser.search.selectedEngine - Blekko
FF - prefs.js: keyword.URL - hxxp://blekko.com/ws/?source=c3348dd4&tbp=rbox&toolbarid=blekkotb_031&u=4C0BF23A9232A0B36F84845047959A7C&q=
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM-Run-ipoint - c:\users\Jeff\C_1wh.exe
.
.
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, hxxp://www.gmer.net
Windows 6.1.7601 Disk: WDC_WD50 rev.01.0 -> Harddisk0\DR0 -> \Device\0000005d
.
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user != kernel MBR !!!
sectors 976773166 (+255): user != kernel
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2743029956-1779779573-3456650838-1000\Software\SecuROM\License information*]
"datasecu"=hex:9f,fe,00,ad,80,b3,2d,86,aa,a2,cc,d6,8e,59,dc,b8,7c,58,df,97,e5,
8c,df,22,c4,84,7c,f8,92,fe,eb,e2,a7,c7,30,bd,02,c9,b9,3f,e8,e0,3f,77,a9,47,\
"rkeysecu"=hex:22,74,fe,96,1a,d5,3d,ec,15,2a,a9,a4,3c,0b,4d,28
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-09-07 22:12:58
ComboFix-quarantined-files.txt 2012-09-07 20:12
.
Vor Suchlauf: 10 Verzeichnis(se), 446.732.832.768 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 446.628.110.336 Bytes frei
.
- - End Of File - - 4C3D70B3962AB9A76D8526743089A543 --- --- ---
Muss ich jetzt noch etwas machen ? |