TheMissMico | 25.08.2013 21:49 | Hallo,
vielen Dank für die Nachricht.
Habe alles gemacht. Leider habe ich beim ersten Mal vergessen ComboFix auf dem Desktop zu speichern, deshalb hab ich nun alles zweimal gemacht. Beim zweiten Mal war Combofix auf dem Desktop gespeichert, beim ersten Mal nicht. Ich poste nun mal alles.
Hier der Combofix-Log 1 ohne Desktop-Speicherung: Code:
ComboFix 13-08-25.01 - Mira 25.08.2013 22:31:21.1.2 - x86
Microsoft Windows 7 Professional N 6.1.7601.1.1252.49.1031.18.1015.173 [GMT 2:00]
ausgeführt von:: c:\users\Mira\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\security\Database\tmp.edb
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-07-25 bis 2013-08-25 ))))))))))))))))))))))))))))))
.
.
2013-08-25 20:38 . 2013-08-25 20:39 -------- d-----w- c:\users\Mira\AppData\Local\temp
2013-08-25 20:38 . 2013-08-25 20:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-25 20:22 . 2013-08-06 07:28 7166848 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1999145B-6BE5-4357-9C19-89419BC35233}\mpengine.dll
2013-08-25 14:05 . 2013-08-25 14:05 -------- d-----w- C:\FRST
2013-08-25 10:04 . 2013-08-25 10:04 -------- d-----w- c:\users\Mira\AppData\Roaming\Avira
2013-08-24 23:19 . 2013-08-24 23:15 67168 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-08-24 22:56 . 2013-07-18 06:02 135136 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-08-24 22:56 . 2013-03-06 14:13 37352 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-08-24 22:56 . 2013-07-18 06:02 84744 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-08-24 22:51 . 2013-08-24 22:59 -------- d-----w- c:\programdata\Avira
2013-08-24 22:51 . 2013-08-24 22:51 -------- d-----w- c:\program files\Avira
2013-08-24 21:51 . 2013-08-25 20:24 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2013-08-24 21:50 . 2009-01-25 11:14 15224 ----a-w- c:\windows\system32\sdnclean.exe
2013-08-24 21:50 . 2013-08-24 21:51 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2013-08-24 19:47 . 2013-08-24 19:45 697992 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5346A05D-3D98-4BC7-8D24-C440DB68108F}\gapaengine.dll
2013-08-24 19:46 . 2013-08-06 07:28 7166848 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-08-20 21:21 . 2013-08-20 21:21 -------- d-----w- c:\users\Mira\AppData\Roaming\CANON INC
2013-08-20 21:09 . 2013-08-20 21:09 -------- d-----w- c:\users\Mira\AppData\Roaming\Canon_Inc_IC
2013-08-20 21:05 . 2013-08-20 21:05 -------- d-----w- c:\program files\Common Files\Canon_Inc_IC
2013-08-20 21:02 . 2013-08-20 21:02 -------- d-----w- c:\users\Mira\AppData\Roaming\canon
2013-08-20 21:01 . 2013-08-20 21:02 -------- d-----w- c:\programdata\Canon_Inc_IC
2013-08-15 06:41 . 2013-07-26 02:49 2706432 ----a-w- c:\windows\system32\mshtml.tlb
2013-08-15 06:37 . 2013-07-06 05:05 1293760 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-08-15 06:37 . 2013-07-09 04:50 652800 ----a-w- c:\windows\system32\rpcrt4.dll
2013-08-15 06:37 . 2013-07-09 04:52 175104 ----a-w- c:\windows\system32\wintrust.dll
2013-08-15 06:37 . 2013-07-09 04:46 1166848 ----a-w- c:\windows\system32\crypt32.dll
2013-08-15 06:37 . 2013-07-09 04:46 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2013-08-15 06:37 . 2013-07-09 04:46 103936 ----a-w- c:\windows\system32\cryptnet.dll
2013-08-15 06:37 . 2013-07-09 05:03 3913664 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-08-15 06:37 . 2013-07-09 05:03 3968960 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-08-15 06:37 . 2013-07-09 04:53 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-08-15 06:36 . 2013-06-15 03:38 31232 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2013-08-15 06:36 . 2013-07-19 01:41 2048 ----a-w- c:\windows\system32\tzres.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-24 21:04 . 2013-01-21 19:33 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-08-24 21:04 . 2013-01-21 19:33 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-07-18 06:32 . 2013-06-14 11:03 698504 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-07-17 00:14 . 2013-07-17 00:14 745472 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-07-17 00:14 . 2013-07-17 00:14 185344 ----a-w- c:\windows\system32\elshyph.dll
2013-07-17 00:14 . 2013-07-17 00:14 158720 ----a-w- c:\windows\system32\msls31.dll
2013-07-17 00:14 . 2013-07-17 00:14 523264 ----a-w- c:\windows\system32\vbscript.dll
2013-07-17 00:14 . 2013-07-17 00:14 150528 ----a-w- c:\windows\system32\iexpress.exe
2013-07-17 00:14 . 2013-07-17 00:14 138752 ----a-w- c:\windows\system32\wextract.exe
2013-07-17 00:14 . 2013-07-17 00:14 137216 ----a-w- c:\windows\system32\ieUnatt.exe
2013-07-17 00:14 . 2013-07-17 00:14 12800 ----a-w- c:\windows\system32\mshta.exe
2013-07-17 00:14 . 2013-07-17 00:14 38400 ----a-w- c:\windows\system32\imgutil.dll
2013-07-17 00:14 . 2013-07-17 00:14 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-07-17 00:14 . 2013-07-17 00:14 73728 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-07-17 00:14 . 2013-07-17 00:14 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-07-17 00:14 . 2013-07-17 00:14 61952 ----a-w- c:\windows\system32\tdc.ocx
2013-07-17 00:14 . 2013-07-17 00:14 361984 ----a-w- c:\windows\system32\html.iec
2013-07-17 00:14 . 2013-07-17 00:14 719360 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-07-17 00:14 . 2013-07-17 00:14 23040 ----a-w- c:\windows\system32\licmgr10.dll
2013-07-17 00:14 . 2013-07-17 00:14 1441280 ----a-w- c:\windows\system32\inetcpl.cpl
2013-06-18 19:50 . 2013-06-18 19:50 211560 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2013-06-18 19:50 . 2012-08-30 20:03 107392 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2013-06-05 03:05 . 2013-07-11 06:20 2347520 ----a-w- c:\windows\system32\win32k.sys
2013-06-04 04:53 . 2013-07-11 06:20 509440 ----a-w- c:\windows\system32\qedit.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-06-09 06:03 222832 ----a-w- c:\users\Mira\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-06-09 06:03 222832 ----a-w- c:\users\Mira\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-06-09 06:03 222832 ----a-w- c:\users\Mira\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\SkyDriveShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-01-08 18706176]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTAgent.exe" [2012-10-23 3108480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-11-11 287800]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-02-20 152392]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-06-20 995176]
"SDTray"="c:\program files\Spybot - Search & Destroy 2\SDTray.exe" [2013-07-25 5624784]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-07-18 345144]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\users\Mira\AppData\Local\Google\Update\GoogleUpdate.exe" /c
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
.
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-05-16 1817560]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-05-16 1033688]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-05-15 171928]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-06-18 107392]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [2013-06-20 295376]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R4 AntiVirWebService;Avira Browser-Schutz;c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2013-07-18 589368]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-03-06 37352]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-02-01 242240]
S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2013-07-18 84024]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2011-05-13 26168]
S3 ATSwpWDF;AuthenTec TruePrint WBF Driver;c:\windows\system32\DRIVERS\ATSwpWDF.sys [2012-10-18 971752]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-01-12 227896]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000-Serie - Adaptertreiber für Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - SSMDRV
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc SensrSvc
.
Inhalt des "geplante Tasks" Ordners
.
2013-08-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-21 21:04]
.
2013-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-870972194-2688002223-977081185-1000Core.job
- c:\users\Mira\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-17 20:38]
.
2013-08-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-870972194-2688002223-977081185-1000UA.job
- c:\users\Mira\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-17 20:38]
.
.
------- Zusätzlicher Suchlauf -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Mira\AppData\Roaming\Mozilla\Firefox\Profiles\z00lni02.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Notify-SDWinLogon - SDWinLogon.dll
SafeBoot-Wdf01000.sys
AddRemove-Free Audio Converter_is1 - c:\program files\Common Files\DVDVideoSoft\lib\Uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-08-25 22:42:05
ComboFix-quarantined-files.txt 2013-08-25 20:42
.
Vor Suchlauf: 8.352.518.144 Bytes frei
Nach Suchlauf: 8.477.544.448 Bytes frei
.
- - End Of File - - 967C16BAEC0421E5E57622D261AD4555
A36C5E4F47E84449FF07ED3517B43A31
Und hier der 2. Log mit Speicherung auf dem Desktop: Code:
ComboFix 13-08-25.01 - Mira 25.08.2013 23:16:44.2.2 - x86
Microsoft Windows 7 Professional N 6.1.7601.1.1252.49.1031.18.1015.220 [GMT 2:00]
ausgeführt von:: c:\users\Mira\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-07-25 bis 2013-08-25 ))))))))))))))))))))))))))))))
.
.
2013-08-25 21:24 . 2013-08-25 21:24 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-25 20:51 . 2013-08-06 07:28 7166848 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9AD9D156-7551-4EE6-9970-93F16286FB3C}\mpengine.dll
2013-08-25 20:42 . 2013-08-25 21:24 -------- d-----w- c:\users\Mira\AppData\Local\temp
2013-08-25 14:05 . 2013-08-25 14:05 -------- d-----w- C:\FRST
2013-08-25 10:04 . 2013-08-25 10:04 -------- d-----w- c:\users\Mira\AppData\Roaming\Avira
2013-08-24 23:19 . 2013-08-24 23:15 67168 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-08-24 22:56 . 2013-07-18 06:02 135136 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-08-24 22:56 . 2013-03-06 14:13 37352 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-08-24 22:56 . 2013-07-18 06:02 84744 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-08-24 22:51 . 2013-08-24 22:59 -------- d-----w- c:\programdata\Avira
2013-08-24 22:51 . 2013-08-24 22:51 -------- d-----w- c:\program files\Avira
2013-08-24 21:51 . 2013-08-25 20:24 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2013-08-24 21:50 . 2009-01-25 11:14 15224 ----a-w- c:\windows\system32\sdnclean.exe
2013-08-24 21:50 . 2013-08-24 21:51 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2013-08-24 19:47 . 2013-08-24 19:45 697992 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5346A05D-3D98-4BC7-8D24-C440DB68108F}\gapaengine.dll
2013-08-24 19:46 . 2013-08-06 07:28 7166848 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-08-20 21:21 . 2013-08-20 21:21 -------- d-----w- c:\users\Mira\AppData\Roaming\CANON INC
2013-08-20 21:09 . 2013-08-20 21:09 -------- d-----w- c:\users\Mira\AppData\Roaming\Canon_Inc_IC
2013-08-20 21:05 . 2013-08-20 21:05 -------- d-----w- c:\program files\Common Files\Canon_Inc_IC
2013-08-20 21:02 . 2013-08-20 21:02 -------- d-----w- c:\users\Mira\AppData\Roaming\canon
2013-08-20 21:01 . 2013-08-20 21:02 -------- d-----w- c:\programdata\Canon_Inc_IC
2013-08-15 06:41 . 2013-07-26 02:49 2706432 ----a-w- c:\windows\system32\mshtml.tlb
2013-08-15 06:37 . 2013-07-06 05:05 1293760 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-08-15 06:37 . 2013-07-09 04:50 652800 ----a-w- c:\windows\system32\rpcrt4.dll
2013-08-15 06:37 . 2013-07-09 04:52 175104 ----a-w- c:\windows\system32\wintrust.dll
2013-08-15 06:37 . 2013-07-09 04:46 1166848 ----a-w- c:\windows\system32\crypt32.dll
2013-08-15 06:37 . 2013-07-09 04:46 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2013-08-15 06:37 . 2013-07-09 04:46 103936 ----a-w- c:\windows\system32\cryptnet.dll
2013-08-15 06:37 . 2013-07-09 05:03 3913664 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-08-15 06:37 . 2013-07-09 05:03 3968960 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-08-15 06:37 . 2013-07-09 04:53 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-08-15 06:36 . 2013-06-15 03:38 31232 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2013-08-15 06:36 . 2013-07-19 01:41 2048 ----a-w- c:\windows\system32\tzres.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-24 21:04 . 2013-01-21 19:33 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-08-24 21:04 . 2013-01-21 19:33 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-07-18 06:32 . 2013-06-14 11:03 698504 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-07-17 00:14 . 2013-07-17 00:14 745472 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-07-17 00:14 . 2013-07-17 00:14 185344 ----a-w- c:\windows\system32\elshyph.dll
2013-07-17 00:14 . 2013-07-17 00:14 158720 ----a-w- c:\windows\system32\msls31.dll
2013-07-17 00:14 . 2013-07-17 00:14 523264 ----a-w- c:\windows\system32\vbscript.dll
2013-07-17 00:14 . 2013-07-17 00:14 150528 ----a-w- c:\windows\system32\iexpress.exe
2013-07-17 00:14 . 2013-07-17 00:14 138752 ----a-w- c:\windows\system32\wextract.exe
2013-07-17 00:14 . 2013-07-17 00:14 137216 ----a-w- c:\windows\system32\ieUnatt.exe
2013-07-17 00:14 . 2013-07-17 00:14 12800 ----a-w- c:\windows\system32\mshta.exe
2013-07-17 00:14 . 2013-07-17 00:14 38400 ----a-w- c:\windows\system32\imgutil.dll
2013-07-17 00:14 . 2013-07-17 00:14 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-07-17 00:14 . 2013-07-17 00:14 73728 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-07-17 00:14 . 2013-07-17 00:14 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-07-17 00:14 . 2013-07-17 00:14 61952 ----a-w- c:\windows\system32\tdc.ocx
2013-07-17 00:14 . 2013-07-17 00:14 361984 ----a-w- c:\windows\system32\html.iec
2013-07-17 00:14 . 2013-07-17 00:14 719360 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-07-17 00:14 . 2013-07-17 00:14 23040 ----a-w- c:\windows\system32\licmgr10.dll
2013-07-17 00:14 . 2013-07-17 00:14 1441280 ----a-w- c:\windows\system32\inetcpl.cpl
2013-06-18 19:50 . 2013-06-18 19:50 211560 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2013-06-18 19:50 . 2012-08-30 20:03 107392 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2013-06-05 03:05 . 2013-07-11 06:20 2347520 ----a-w- c:\windows\system32\win32k.sys
2013-06-04 04:53 . 2013-07-11 06:20 509440 ----a-w- c:\windows\system32\qedit.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-06-09 06:03 222832 ----a-w- c:\users\Mira\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-06-09 06:03 222832 ----a-w- c:\users\Mira\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-06-09 06:03 222832 ----a-w- c:\users\Mira\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\SkyDriveShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-01-08 18706176]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTAgent.exe" [2012-10-23 3108480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-11-11 287800]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-02-20 152392]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-06-20 995176]
"SDTray"="c:\program files\Spybot - Search & Destroy 2\SDTray.exe" [2013-07-25 5624784]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-07-18 345144]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\users\Mira\AppData\Local\Google\Update\GoogleUpdate.exe" /c
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
.
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-05-16 1817560]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-05-16 1033688]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-05-15 171928]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-06-18 107392]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [2013-06-20 295376]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R4 AntiVirWebService;Avira Browser-Schutz;c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2013-07-18 589368]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-03-06 37352]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-02-01 242240]
S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2013-07-18 84024]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2011-05-13 26168]
S3 ATSwpWDF;AuthenTec TruePrint WBF Driver;c:\windows\system32\DRIVERS\ATSwpWDF.sys [2012-10-18 971752]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-01-12 227896]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000-Serie - Adaptertreiber für Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc SensrSvc
.
Inhalt des "geplante Tasks" Ordners
.
2013-08-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-21 21:04]
.
2013-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-870972194-2688002223-977081185-1000Core.job
- c:\users\Mira\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-17 20:38]
.
2013-08-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-870972194-2688002223-977081185-1000UA.job
- c:\users\Mira\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-17 20:38]
.
.
------- Zusätzlicher Suchlauf -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Mira\AppData\Roaming\Mozilla\Firefox\Profiles\z00lni02.default\
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,38,12,5b,ab,e0,
b0,13,40,37,0c,c5,34,01,f3,05,d0,46,eb
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:00,32,9b,af,92,08,ce,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b1,06,18,dc,58,54,00,4b,bb,28,d1,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b1,06,18,dc,58,54,00,4b,bb,28,d1,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-08-25 23:27:49
ComboFix-quarantined-files.txt 2013-08-25 21:27
ComboFix2.txt 2013-08-25 20:42
.
Vor Suchlauf: 8.638.435.328 Bytes frei
Nach Suchlauf: 9.067.077.632 Bytes frei
.
- - End Of File - - 59E179108273EC769A566F0508FFCE64
A36C5E4F47E84449FF07ED3517B43A31 Und im Anhang nochmal die Dateien.
Nochmals meine Frage:
Sollte ich meine Passwörter ändern (von anderem PC vielleicht?), meine Daten sichern oder ist dann auch der jeweilige Stick infiziert? Online Banking sperren oder so etwas zur Sicherheit oder besteht dafür kein Anlass?
Liebe Grüße
Mira |