ok, hier das log: Code:
Combofix Logfile:
Code:
ComboFix 13-07-13.01 - Thomas 14.07.2013 0:19.1.2 - x86 MINIMAL
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3034.2542 [GMT 2:00]
ausgeführt von:: D:\ComboFix.exe
AV: AntiVir Desktop *Enabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Enabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Recycle.Bin
c:\users\Thomas\4.0
c:\users\Thomas\AppData\Roaming\Adobe\plugs
c:\users\Thomas\AppData\Roaming\Adobe\plugs\EooDDxxNNyyTTdU
c:\users\Thomas\AppData\Roaming\Adobe\shed
c:\users\Thomas\AppData\Roaming\Adobe\shed\sssddOOLLpXttQQAADDff
c:\users\Thomas\AppData\Roaming\Ocaqef\piku.exe
c:\users\Thomas\AppData\Roaming\skype.dat
c:\users\Thomas\AppData\Roaming\skype.ini
c:\windows\IsUn0407.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-06-13 bis 2013-07-13 ))))))))))))))))))))))))))))))
.
.
2013-07-13 22:25 . 2013-07-13 22:25 -------- d-----w- c:\users\Thomas\AppData\Local\temp
2013-07-13 22:25 . 2013-07-13 22:25 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-07-13 22:03 . 2013-07-13 22:03 -------- d-----w- C:\found.000
2013-07-13 20:55 . 2013-07-13 20:55 -------- d-----w- C:\FRST
2013-06-28 09:10 . 2013-06-12 04:18 7068072 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6D370428-1D2F-475A-AFBB-934DA47B0DD4}\mpengine.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-16 22:39 . 2013-06-12 20:02 1800704 ----a-w- c:\windows\system32\jscript9.dll
2013-05-16 22:28 . 2013-06-12 20:02 1129472 ----a-w- c:\windows\system32\wininet.dll
2013-05-16 22:27 . 2013-06-12 20:02 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2013-05-16 22:21 . 2013-06-12 20:02 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2013-05-16 22:20 . 2013-06-12 20:02 420864 ----a-w- c:\windows\system32\vbscript.dll
2013-05-16 22:16 . 2013-06-12 20:02 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2013-05-08 04:37 . 2013-06-12 19:17 905576 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-05-02 22:03 . 2013-06-12 19:17 3603832 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-05-02 22:03 . 2013-06-12 19:17 3551096 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-05-02 04:04 . 2013-06-12 19:17 443904 ----a-w- c:\windows\system32\win32spl.dll
2013-05-02 04:03 . 2013-06-12 19:17 37376 ----a-w- c:\windows\system32\printcom.dll
2013-05-02 00:06 . 2009-10-02 22:14 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-04-24 04:00 . 2013-06-12 19:17 985600 ----a-w- c:\windows\system32\crypt32.dll
2013-04-24 04:00 . 2013-06-12 19:17 98304 ----a-w- c:\windows\system32\cryptnet.dll
2013-04-24 04:00 . 2013-06-12 19:17 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2013-04-24 04:00 . 2013-06-12 19:17 41984 ----a-w- c:\windows\system32\certenc.dll
2013-04-24 01:46 . 2013-06-12 19:17 812544 ----a-w- c:\windows\system32\certutil.exe
2013-04-17 12:30 . 2013-06-12 19:17 24576 ----a-w- c:\windows\system32\cryptdlg.dll
2013-04-15 14:20 . 2013-05-15 19:33 638328 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-09-04 200704]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-12-09 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-12-09 178712]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-12-09 154136]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-12-22 3810304]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-05-07 178712]
"Logitech Hardware Abstraction Layer"="c:\program files\Common Files\Logitech\khalshared\KHALMNPR.EXE" [2007-01-12 101136]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-06-03 446635]
"Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2009-11-13 1807600]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-05-23 128296]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-12 101136]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-01-10 281768]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-12-15 483420]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-09-09 421776]
.
c:\users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-24 1295656]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-11-18 780840]
SetPoint.lnk - c:\program files\SetPoint\SetPoint.exe [2009-3-31 679936]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe /firstrun [2008-9-24 1295656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-03-23 22:54 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
R2 ACEDRV09;ACEDRV09;c:\windows\system32\drivers\ACEDRV09.sys [2010-01-20 110304]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\aestsrv.exe [2008-12-15 81920]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - ECACHE
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.de/
uInternet Settings,ProxyOverride = *.local
IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKCU-Run-{73CABE9D-48A2-2F71-EB61-5F64EAFFAA2C} - c:\users\Thomas\AppData\Roaming\Biif\goalloy.exe
HKCU-Run-463E6CEB - c:\users\Thomas\AppData\Roaming\Oldjpxnefv\E95E03AE463E6CEBD258.exe
HKCU-Run-{2C83784C-42A0-AD7E-1BB2-2B630FF4087E} - c:\users\Thomas\AppData\Roaming\Ocaqef\piku.exe
SafeBoot-Wdf01000.sys
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-Zeitungsdruckerei - c:\windows\IsUn0407.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2013-07-14 00:25
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,f2,b1,57,65,c8,79,f4,42,a4,3a,09,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,f2,b1,57,65,c8,79,f4,42,a4,3a,09,\
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(972)
c:\windows\system32\btncopy.dll
.
Zeit der Fertigstellung: 2013-07-14 00:27:44
ComboFix-quarantined-files.txt 2013-07-13 22:27
.
Vor Suchlauf: 10 Verzeichnis(se), 167.385.952.256 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 167.582.941.184 Bytes frei
.
- - End Of File - - 512D036A6D33C63A343DF674DE5C90DE --- --- ---
CDB4DE4BBD714F152979DA2DCBEF57EB |