So hier die Berichte vom ADWCleaner: Code:
# AdwCleaner v3.000 - Report created 20/08/2013 at 17:09:32
# Updated 20/08/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Admin - JOSH
# Running from : C:\Documents and Settings\Admin\Desktop\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found C:\Documents and Settings\Admin\Application Data\registry mechanic
Folder Found C:\Documents and Settings\All Users\Start Menu\Programs\registry mechanic
Folder Found C:\Program Files\AskTBar
Folder Found C:\Program Files\registry mechanic
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9CB65201-89C4-402C-BA80-02D8C59F9B1D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063DB1-4EC0-403E-8DD8-394C54984B2C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CB65201-89C4-402C-BA80-02D8C59F9B1D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CB65206-89C4-402C-BA80-02D8C59F9B1D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063DB1-4EC0-403E-8DD8-394C54984B2C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{9CB65201-89C4-402C-BA80-02D8C59F9B1D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{9CB65206-89C4-402C-BA80-02D8C59F9B1D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FE063DB1-4EC0-403E-8DD8-394C54984B2C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
Key Found : HKLM\SOFTWARE\Classes\IMsiDe1egate.Application.1
Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CB65201-89C4-402C-BA80-02D8C59F9B1D}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE063DB1-4EC0-403E-8DD8-394C54984B2C}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{FE063DB9-4EC0-403E-8DD8-394C54984B2C}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{9CB65206-89C4-402C-BA80-02D8C59F9B1D}]
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [DrvUpdater]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{FE063DB9-4EC0-403E-8DD8-394C54984B2C}]
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
-\\ Mozilla Firefox v5.0.1 (ru)
[ File : C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\5pvzvqwj.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [2991 octets] - [20/08/2013 17:09:32]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [3051 octets] ########## und Code:
# AdwCleaner v3.000 - Report created 20/08/2013 at 17:10:11
# Updated 20/08/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Admin - JOSH
# Running from : C:\Documents and Settings\Admin\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Documents and Settings\All Users\Start Menu\Programs\registry mechanic
Folder Deleted : C:\Program Files\AskTBar
Folder Deleted : C:\Program Files\registry mechanic
Folder Deleted : C:\Documents and Settings\Admin\Application Data\registry mechanic
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\IMsiDe1egate.Application.1
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [DrvUpdater]
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9CB65201-89C4-402C-BA80-02D8C59F9B1D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9CB65206-89C4-402C-BA80-02D8C59F9B1D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE063DB1-4EC0-403E-8DD8-394C54984B2C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CB65201-89C4-402C-BA80-02D8C59F9B1D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE063DB1-4EC0-403E-8DD8-394C54984B2C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CB65201-89C4-402C-BA80-02D8C59F9B1D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CB65206-89C4-402C-BA80-02D8C59F9B1D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063DB1-4EC0-403E-8DD8-394C54984B2C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9CB65201-89C4-402C-BA80-02D8C59F9B1D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063DB1-4EC0-403E-8DD8-394C54984B2C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{FE063DB9-4EC0-403E-8DD8-394C54984B2C}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{FE063DB9-4EC0-403E-8DD8-394C54984B2C}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{9CB65206-89C4-402C-BA80-02D8C59F9B1D}]
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
-\\ Mozilla Firefox v5.0.1 (ru)
[ File : C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\5pvzvqwj.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [3131 octets] - [20/08/2013 17:09:32]
AdwCleaner[S0].txt - [3110 octets] - [20/08/2013 17:10:11]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3170 octets] ########## So, hier die Daten von ComboFix Code:
ComboFix 13-08-19.02 - Admin 20.08.2013 17:34:08.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2446 [GMT 3:00]
Running from: c:\documents and settings\Admin\Desktop\ComboFix.exe
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((( Files Created from 2013-07-20 to 2013-08-20 )))))))))))))))))))))))))))))))
.
.
2013-08-20 17:36 . 2013-08-20 17:36 -------- d-sh--w- c:\documents and settings\Admin\IECompatCache
2013-08-20 17:30 . 2013-08-20 17:37 -------- d-----w- c:\documents and settings\All Users\Application Data\HitmanPro
2013-08-20 14:08 . 2013-08-20 14:10 -------- d-----w- C:\AdwCleaner
2013-08-20 13:14 . 2013-08-20 13:14 -------- d-----w- C:\FRST
2013-08-20 12:45 . 2013-08-20 12:45 -------- d-----w- c:\program files\HitmanPro
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-07 21:56 . 2010-09-10 05:57 920064 ----a-w- c:\windows\system32\wininet.dll
2013-06-07 21:56 . 2010-09-09 18:03 43520 ----a-w- c:\windows\system32\licmgr10.dll
2013-06-07 21:56 . 2011-12-28 15:05 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2013-06-07 20:55 . 2009-03-07 20:35 385024 ----a-w- c:\windows\system32\html.iec
2013-06-04 07:23 . 2008-04-14 12:00 562688 ----a-w- c:\windows\system32\qedit.dll
2013-06-04 01:40 . 2010-08-31 13:38 1876736 ----a-w- c:\windows\system32\win32k.sys
2011-07-08 07:52 . 2011-12-28 15:44 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2010-10-13 . 474D3DCCB57DEFCD917311EEC47204B9 . 361600 . . [5.1.2600.6009] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2010-09-29 21:53 72336 ----a-w- c:\program files\Internet Download Manager\IDMShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2010-09-29 3249504]
"AvaFind"="c:\program files\AvaFind\AvaFind.exe" [2007-12-22 295936]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-01-15 147456]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2011-04-14 20053608]
"HControlUser"="c:\program files\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"ATKHOTKEY"="c:\program files\ASUS\ATK Hotkey\HControl.exe" [2009-10-26 174720]
"USB Antivirus"="c:\program files\USB Disk Security\USBGuard.exe" [2008-08-16 798720]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"TimeServer"="c:\documents and settings\Admin\Application Data\Opera\WIN7.exe" [2013-07-15 135168]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="ctfmon.exe" [2008-04-14 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2010-09-29 3249504]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2009-03-07 128512]
.
c:\documents and settings\Admin\Start Menu\Programs\Startup\
Webshots.lnk - c:\program files\Webshots\Launcher.exe /t [2011-12-30 45056]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Launcher.lnk - c:\program files\InternetEverywhere\InternetEverywhere_Launcher.exe [2012-1-25 472528]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
"EditLevel"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders schannel.dll, credssp.dll, digest.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
.
R0 ahcix86;ahcix86;c:\windows\system32\drivers\ahcix86.sys [13.10.2010 07:47 189448]
R1 IDMTDI;IDMTDI;c:\windows\system32\drivers\idmtdi.sys [28.12.2011 18:03 78328]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [30.12.2011 20:15 108289]
R2 InternetEverywhere_Service;InternetEverywhere_Service;c:\program files\InternetEverywhere\InternetEverywhere_Service.exe [25.01.2012 19:29 316880]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [13.10.2010 07:47 101904]
R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [28.12.2011 18:41 140376]
R3 JME;JMicron Ethernet Adapter NDIS5.1 Driver;c:\windows\system32\drivers\JME.sys [28.12.2011 18:40 83088]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [28.12.2011 18:42 1691480]
S3 ewsercd;Huawei DataCard USB Serial Port;c:\windows\system32\drivers\ewsercd.sys [25.01.2012 19:29 100224]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [25.01.2012 19:29 112128]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [25.01.2012 19:29 103040]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [28.12.2011 18:07 436792]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - SR
*NewlyCreated* - SRSERVICE
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.webshots.com/r/internal/start/client/RAND
uDefault_Search_URL = hxxp://www.google.com/
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: Interfaces\{763D3CAE-6300-49A7-9962-56732E0B7F18}: NameServer = 41.190.192.172,8.8.8.8
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\5pvzvqwj.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2013-08-20 17:36
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):8f,e0,14,a6,6c,b2,79,78,c6,08,dc,ee,1b,2c,de,34,19,81,00,14,d0,
97,42,8f,20,97,e2,bf,f0,e6,39,c7,6c,f5,69,93,58,6b,c4,13,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{f5fe3fea-a8d3-43b1-b068-546217191eb9}]
@Denied: (Full) (Everyone)
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(836)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'explorer.exe'(448)
c:\windows\system32\WININET.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~2\Office14\1033\GrooveIntlResource.dll
c:\program files\Internet Download Manager\IDMShellExt.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2013-08-20 17:37:18
ComboFix-quarantined-files.txt 2013-08-20 14:37
ComboFix2.txt 2013-08-20 14:26
.
Pre-Run: 43.023.130.624 bytes free
Post-Run: 43.006.173.184 bytes free
.
- - End Of File - - B2A5B3CC3358405F867374FC5480796D
8F558EB6672622401DA993E1E865C861 So, und der letzte Bericht:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-08-2013 03
Ran by Admin (administrator) on 20-08-2013 17:44:58
Running from C:\Documents and Settings\Admin\Desktop
Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\Ati2evxx.exe
(Avira GmbH) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira GmbH) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
() C:\Program Files\InternetEverywhere\InternetEverywhere_Service.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(ASUS) C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\HControl.exe
(zbshareware, Inc) C:\Program Files\USB Disk Security\USBGuard.exe
(Avira GmbH) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
() C:\Documents and Settings\Admin\Application Data\Opera\WIN7.exe
(Tonec Inc.) C:\Program Files\Internet Download Manager\IDMan.exe
(Think Less Do More Services) C:\Program Files\AvaFind\AvaFind.exe
(Nero AG) C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
() C:\Program Files\InternetEverywhere\InternetEverywhere_Launcher.exe
(Webshots.com) C:\PROGRA~1\Webshots\webshots.scr
(ASUS) C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe
(Nero AG) C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\WDC.exe
(Tonec Inc.) C:\Program Files\Internet Download Manager\IEMonitor.exe
(Nero AG) C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDCPL] - C:\Windows\RTHDCPL.EXE [20053608 2011-04-14] (Realtek Semiconductor Corp.)
HKLM\...\Run: [HControlUser] - C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM\...\Run: [ATKHOTKEY] - C:\Program Files\ASUS\ATK Hotkey\HControl.exe [174720 2009-10-26] (ASUS)
HKLM\...\Run: [USB Antivirus] - C:\Program Files\USB Disk Security\USBGuard.exe [798720 2008-08-16] (zbshareware, Inc)
HKLM\...\Run: [NeroFilterCheck] - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [155648 2006-01-12] (Nero AG)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [209153 2009-03-02] (Avira GmbH)
HKLM\...\Run: [TimeServer] - C:\Documents and Settings\Admin\Application Data\Opera\WIN7.exe [135168 2013-07-15] ()
Winlogon\Notify\AtiExtEvent: Ati2evxx.dll (ATI Technologies Inc.)
HKCU\...\Run: [IDMan] - C:\Program Files\Internet Download Manager\IDMan.exe [3249504 2010-09-30] (Tonec Inc.)
HKCU\...\Run: [AvaFind] - C:\Program Files\AvaFind\AvaFind.exe [295936 2007-12-22] (Think Less Do More Services)
HKCU\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [147456 2007-01-15] (Nero AG)
HKU\Administrator\...\Run: [IDMan] - C:\Program Files\Internet Download Manager\IDMan.exe [ 2010-09-30] (Tonec Inc.)
HKU\Default User\...\Run: [IDMan] - C:\Program Files\Internet Download Manager\IDMan.exe [ 2010-09-30] (Tonec Inc.)
HKU\Default User\...\RunOnce: [_nltide_3] - C:\Windows\System32\advpack.dll [ 2009-03-07] (Microsoft Corporation)
Lsa: [Authentication Packages] msv1_0 nwprovau
Startup: C:\Documents and Settings\Admin\Start Menu\Programs\Startup\Webshots.lnk
ShortcutTarget: Webshots.lnk -> C:\Program Files\Webshots\Launcher.exe ()
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
ShortcutTarget: Adobe Reader Speed Launch.lnk -> C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
ShortcutTarget: Adobe Reader Synchronizer.lnk -> C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Launcher.lnk
ShortcutTarget: Launcher.lnk -> C:\Program Files\InternetEverywhere\InternetEverywhere_Launcher.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.webshots.com/r/internal/start/client/RAND
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKLM - {6BA4BBC5-3A34-465E-A7AD-CA216AD72022} URL = hxxp://en.wikipedia.org/w/index.php?title=Special:Search&search={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
SearchScopes: HKCU - {6B528F7B-1290-4F85-BA27-8515B393FF4B} URL =
SearchScopes: HKCU - {6BA4BBC5-3A34-465E-A7AD-CA216AD72022} URL =
BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Tonec Inc.)
BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
Handler: ipp - No CLSID Value -
Handler: msdaipp - No CLSID Value -
ShellExecuteHooks: - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No File [ ]
Tcpip\..\Interfaces\{763D3CAE-6300-49A7-9962-56732E0B7F18}: [NameServer]41.190.192.172,8.8.8.8
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\5pvzvqwj.default
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\mailru.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\ozonru.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\priceru.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\wikipedia-ru.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yandex-slovari.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\yandex.xml
FF Extension: Default - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKCU\...\Firefox\Extensions: [mozilla_cc@internetdownloadmanager.com] C:\Documents and Settings\Admin\Application Data\IDM\idmmzcc3
FF Extension: IDM CC - C:\Documents and Settings\Admin\Application Data\IDM\idmmzcc3
FF HKCU\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] C:\Documents and Settings\Admin\Application Data\IDM\idmmzcc3
FF Extension: IDM CC - C:\Documents and Settings\Admin\Application Data\IDM\idmmzcc3
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [108289 2009-05-13] (Avira GmbH)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [185089 2012-01-07] (Avira GmbH)
R2 InternetEverywhere_Service; C:\Program Files\InternetEverywhere\InternetEverywhere_Service.exe [316880 2010-03-26] ()
R2 NWCWorkstation; C:\Windows\System32\nwwks.dll [65536 2008-04-14] (Microsoft Corporation)
S2 ERSvc; %SystemRoot%\System32\ersvc.dll [x]
S4 HidServ; %SystemRoot%\System32\hidserv.dll [x]
S2 wscsvc; %SYSTEMROOT%\system32\wscsvc.dll [x]
==================== Drivers (Whitelisted) ====================
R0 ahcix86; C:\Windows\System32\DRIVERS\ahcix86.sys [189448 2010-10-13] (Advanced Micro Devices, Inc)
S3 Ambfilt; C:\Windows\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
R1 AmdPPM; C:\Windows\System32\DRIVERS\AmdPPM.sys [33792 2010-10-13] (Advanced Micro Devices)
R3 AR5416; C:\Windows\System32\DRIVERS\athw.sys [1938272 2010-11-05] (Atheros Communications, Inc.)
R3 ASNDIS5; C:\PROGRA~1\ASUS\ATKHOT~1\ASNDIS5.SYS [16269 2004-05-27] (Printing Communications Assoc., Inc. (PCAUSA))
R2 Aspi32; C:\Windows\System32\Drivers\Aspi32.sys [16877 2002-07-17] (Adaptec)
R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdXP3.sys [101904 2010-10-13] (ATI Technologies, Inc.)
R1 avgio; C:\Program Files\Avira\AntiVir Desktop\avgio.sys [11608 2009-02-13] (Avira GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [56816 2012-01-07] (Avira GmbH)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [96104 2009-03-30] (Avira GmbH)
S3 ewsercd; C:\Windows\System32\DRIVERS\ewsercd.sys [100224 2012-01-25] (Huawei Technologies Co., Ltd.)
S3 hwusbfake; C:\Windows\System32\DRIVERS\ewusbfake.sys [103040 2012-01-25] (Huawei Technologies Co., Ltd.)
R1 IDMTDI; C:\Windows\System32\DRIVERS\idmtdi.sys [78328 2010-09-30] (Tonec Inc.)
S3 Monfilt; C:\Windows\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2010-10-13] (ATK0100)
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R2 NwlnkIpx; C:\Windows\System32\DRIVERS\nwlnkipx.sys [88320 2008-04-14] (Microsoft Corporation)
R2 NwlnkNb; C:\Windows\System32\DRIVERS\nwlnknb.sys [63232 2008-04-14] (Microsoft Corporation)
R2 NwlnkSpx; C:\Windows\System32\DRIVERS\nwlnkspx.sys [55936 2008-04-14] (Microsoft Corporation)
R3 NWRDR; C:\Windows\System32\DRIVERS\nwrdr.sys [163584 2008-04-14] (Microsoft Corporation)
R0 Si3112; C:\Windows\System32\Drivers\Si3112.sys [74280 2010-10-13] (Silicon Image, Inc)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [436792 2011-12-28] (Duplex Secure Ltd.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2009-05-11] (Avira GmbH)
S3 catchme; \??\C:\DOCUME~1\Admin\LOCALS~1\Temp\catchme.sys [x]
S4 IntelIde; No ImagePath
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-20 20:30 - 2013-08-20 20:37 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\HitmanPro
2013-08-20 17:43 - 2013-08-20 17:43 - 00000000 ____D C:\WINDOWS\system32\xircom
2013-08-20 17:43 - 2013-08-20 17:43 - 00000000 ____D C:\WINDOWS\srchasst
2013-08-20 17:43 - 2013-08-20 17:43 - 00000000 ____D C:\Program Files\xerox
2013-08-20 17:43 - 2013-08-20 17:43 - 00000000 ____D C:\Program Files\microsoft frontpage
2013-08-20 17:37 - 2013-08-20 17:37 - 00009983 _____ C:\ComboFix.txt
2013-08-20 17:32 - 2013-08-20 17:39 - 00000000 ____D C:\ComboFix
2013-08-20 17:20 - 2013-08-20 17:37 - 00000000 ____D C:\Qoobox
2013-08-20 17:20 - 2013-08-20 17:25 - 00000000 ____D C:\WINDOWS\erdnt
2013-08-20 17:20 - 2011-06-26 09:45 - 00256000 _____ C:\WINDOWS\PEV.exe
2013-08-20 17:20 - 2010-11-07 20:20 - 00208896 _____ C:\WINDOWS\MBR.exe
2013-08-20 17:20 - 2009-04-20 07:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe
2013-08-20 17:20 - 2000-08-31 03:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe
2013-08-20 17:20 - 2000-08-31 03:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe
2013-08-20 17:20 - 2000-08-31 03:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe
2013-08-20 17:20 - 2000-08-31 03:00 - 00098816 _____ C:\WINDOWS\sed.exe
2013-08-20 17:20 - 2000-08-31 03:00 - 00080412 _____ C:\WINDOWS\grep.exe
2013-08-20 17:20 - 2000-08-31 03:00 - 00068096 _____ C:\WINDOWS\zip.exe
2013-08-20 17:18 - 2013-08-20 17:19 - 05106564 ____R (Swearware) C:\Documents and Settings\Admin\Desktop\ComboFix.exe
2013-08-20 17:08 - 2013-08-20 17:10 - 00000000 ____D C:\AdwCleaner
2013-08-20 17:01 - 2013-08-20 17:02 - 00975858 _____ C:\Documents and Settings\Admin\Desktop\adwcleaner.exe
2013-08-20 16:14 - 2013-08-20 16:14 - 00000000 ____D C:\FRST
2013-08-20 16:00 - 2013-08-20 16:01 - 01070241 _____ (Farbar) C:\Documents and Settings\Admin\Desktop\FRST.exe
2013-08-20 15:56 - 2013-08-20 15:58 - 00000020 _____ C:\Documents and Settings\Admin\defogger_reenable
2013-08-20 15:45 - 2013-08-20 15:45 - 00000000 ____D C:\Program Files\HitmanPro
==================== One Month Modified Files and Folders =======
2013-08-20 20:36 - 2013-08-20 20:36 - 00000000 __SHD C:\Documents and Settings\Admin\IECompatCache
2013-08-20 17:45 - 2011-12-28 20:00 - 00000000 ____D C:\Documents and Settings\Admin\Application Data\AvaFind Data
2013-08-20 17:45 - 2011-12-28 18:06 - 01727707 _____ C:\WINDOWS\WindowsUpdate.log
2013-08-20 17:44 - 2012-01-05 19:30 - 00003000 _____ C:\Documents and Settings\Admin\Desktop\AVAFIND_ERROR.LOG
2013-08-20 17:43 - 2013-08-20 17:43 - 00000000 ____D C:\WINDOWS\system32\xircom
2013-08-20 17:43 - 2013-08-20 17:43 - 00000000 ____D C:\WINDOWS\srchasst
2013-08-20 17:43 - 2013-08-20 17:43 - 00000000 ____D C:\Program Files\xerox
2013-08-20 17:43 - 2013-08-20 17:43 - 00000000 ____D C:\Program Files\microsoft frontpage
2013-08-20 17:43 - 2011-12-28 19:36 - 00000049 _____ C:\WINDOWS\wiaservc.log
2013-08-20 17:43 - 2011-12-28 19:35 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-08-20 17:43 - 2011-12-28 19:27 - 00000000 ____D C:\WINDOWS\ime
2013-08-20 17:43 - 2011-12-28 19:27 - 00000000 ____D C:\WINDOWS\Help
2013-08-20 17:43 - 2011-12-28 18:13 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-08-20 17:42 - 2011-12-28 18:25 - 00000178 ___SH C:\Documents and Settings\Admin\ntuser.ini
2013-08-20 17:42 - 2011-12-28 18:25 - 00000000 ____D C:\Documents and Settings\Admin
2013-08-20 17:42 - 2011-12-28 18:13 - 00032564 _____ C:\WINDOWS\SchedLgU.Txt
2013-08-20 17:39 - 2013-08-20 17:32 - 00000000 ____D C:\ComboFix
2013-08-20 17:37 - 2013-08-20 17:37 - 00009983 _____ C:\ComboFix.txt
2013-08-20 17:37 - 2013-08-20 17:20 - 00000000 ____D C:\Qoobox
2013-08-20 17:36 - 2008-04-14 15:00 - 00000246 _____ C:\WINDOWS\system.ini
2013-08-20 17:32 - 2011-12-28 18:04 - 00000000 ____D C:\WINDOWS\system32\Restore
2013-08-20 17:25 - 2013-08-20 17:20 - 00000000 ____D C:\WINDOWS\erdnt
2013-08-20 17:19 - 2013-08-20 17:18 - 05106564 ____R (Swearware) C:\Documents and Settings\Admin\Desktop\ComboFix.exe
2013-08-20 17:10 - 2013-08-20 17:08 - 00000000 ____D C:\AdwCleaner
2013-08-20 17:02 - 2013-08-20 17:01 - 00975858 _____ C:\Documents and Settings\Admin\Desktop\adwcleaner.exe
2013-08-20 16:45 - 2011-12-28 19:33 - 00004016 _____ C:\WINDOWS\regopt.log
2013-08-20 16:45 - 2011-12-28 19:32 - 01039924 _____ C:\WINDOWS\setupapi.log
2013-08-20 16:45 - 2011-12-28 19:31 - 00001024 ____H C:\WINDOWS\system32\config\userdiff.LOG
2013-08-20 16:22 - 2008-04-14 15:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2013-08-20 16:14 - 2013-08-20 16:14 - 00000000 ____D C:\FRST
2013-08-20 16:07 - 2011-12-28 19:32 - 00267008 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-08-20 16:01 - 2013-08-20 16:00 - 01070241 _____ (Farbar) C:\Documents and Settings\Admin\Desktop\FRST.exe
2013-08-20 15:58 - 2013-08-20 15:56 - 00000020 _____ C:\Documents and Settings\Admin\defogger_reenable
2013-08-20 15:45 - 2013-08-20 15:45 - 00000000 ____D C:\Program Files\HitmanPro
2013-08-20 15:41 - 2013-07-15 18:28 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.dat
2013-08-20 15:12 - 2012-04-02 14:38 - 00000000 __SHD C:\WINDOWS\CSC
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2008-07-03 14:38] - [2008-07-03 14:38] - 1033728 ____A (Microsoft Corporation) 2bb75b7f548d82a099125d0c5971de7d
C:\Windows\System32\winlogon.exe
[2009-04-02 17:56] - [2009-04-02 17:56] - 0509440 ____A (Microsoft Corporation) 53a8857723277b1d6d5ee60a9f85b117
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-12-23 18:05] - [2009-12-23 18:05] - 0110592 ____A (Microsoft Corporation) c519e15665cd89a91ad383fce3cb556a
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================ --- --- ---
--- --- ---
Ich hoffe war alles richtig? |