hab ich gemacht: Code:
ComboFix 11-06-05.06 - Maggi 06.06.2011 17:06:48.1.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1252.49.1031.18.3067.2082 [GMT 2:00]
ausgeführt von:: c:\users\Maggi\Desktop\cofi.exe
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Treiber/Dienste )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_Windows Defender
.
.
((((((((((((((((((((((( Dateien erstellt von 2011-05-06 bis 2011-06-06 ))))))))))))))))))))))))))))))
.
.
2011-06-06 15:15 . 2011-06-06 15:15 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-06 13:13 . 2011-05-29 07:11 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-06 13:13 . 2011-06-06 13:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-06-06 13:13 . 2011-05-29 07:11 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-05 21:09 . 2011-06-05 21:09 -------- d-----w- C:\_OTL
2011-06-03 11:34 . 2011-05-09 20:46 6962000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{80695B86-DBFD-47A2-BECC-5863F1DDC8E3}\mpengine.dll
2011-06-02 08:29 . 2011-06-02 08:29 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-25 15:33 . 2011-04-22 19:36 26496 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-05-24 15:23 . 2011-05-24 15:26 -------- d-----w- c:\program files\ICQ7.5
2011-05-24 09:36 . 2011-04-09 05:56 123904 ----a-w- c:\windows\system32\poqexec.exe
2011-05-19 19:34 . 2011-05-19 19:35 -------- d-----w- c:\program files\Tunngle
2011-05-13 09:40 . 2011-05-13 09:40 -------- d---a-w- C:\PADS_ES_Evaluation
2011-05-13 09:38 . 2011-05-13 09:38 -------- d-----w- c:\windows\Downloaded Installations
2011-05-11 16:49 . 2007-01-04 10:15 9336 ----a-w- c:\windows\system32\WinIo.sys
2011-05-11 07:28 . 2011-03-25 03:06 284160 ----a-w- c:\windows\system32\drivers\usbport.sys
2011-05-11 07:28 . 2011-03-25 03:06 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2011-05-11 07:28 . 2011-03-25 03:06 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2011-05-11 07:28 . 2011-03-25 03:06 75776 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2011-05-11 07:28 . 2011-03-25 03:06 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2011-05-11 07:28 . 2011-03-25 03:06 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2011-05-11 07:28 . 2011-03-25 03:06 5888 ----a-w- c:\windows\system32\drivers\usbd.sys
2011-05-11 07:28 . 2011-04-09 06:13 3957632 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-05-11 07:28 . 2011-04-09 06:13 3901824 ----a-w- c:\windows\system32\ntoskrnl.exe
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-06 11:59 . 2009-07-13 23:11 245328 ----a-w- c:\windows\system32\drivers\volsnap.sys
2011-04-26 20:56 . 2011-04-26 20:56 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2011-04-26 20:56 . 2011-04-26 20:56 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2011-03-20 08:59 . 2009-11-04 09:06 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-03-12 11:31 . 2011-04-28 09:05 442880 ----a-w- c:\windows\system32\XpsPrint.dll
2011-03-11 05:44 . 2011-04-28 09:05 146304 ----a-w- c:\windows\system32\drivers\storport.sys
2011-03-11 05:44 . 2011-04-28 09:05 143744 ----a-w- c:\windows\system32\drivers\nvstor.sys
2011-03-11 05:44 . 2011-04-28 09:05 1210240 ----a-w- c:\windows\system32\drivers\ntfs.sys
2011-03-11 05:44 . 2011-04-28 09:05 117120 ----a-w- c:\windows\system32\drivers\nvraid.sys
2011-03-11 05:43 . 2011-04-28 09:05 332160 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2011-03-11 05:43 . 2011-04-28 09:05 80256 ----a-w- c:\windows\system32\drivers\amdsata.sys
2011-03-11 05:43 . 2011-04-28 09:05 22400 ----a-w- c:\windows\system32\drivers\amdxata.sys
2011-03-11 05:40 . 2011-04-14 21:17 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2011-03-11 05:40 . 2011-04-14 21:17 1137664 ----a-w- c:\windows\system32\mfc42.dll
2011-03-11 05:39 . 2011-04-28 09:05 1686016 ----a-w- c:\windows\system32\esent.dll
2011-03-11 05:37 . 2011-04-28 09:05 74240 ----a-w- c:\windows\system32\fsutil.exe
2004-03-15 16:51 . 2004-03-15 16:51 114688 ----a-w- c:\program files\internet explorer\plugins\LV71ActiveXControl.dll
2006-01-23 09:32 . 2006-01-23 09:32 131072 ----a-w- c:\program files\internet explorer\plugins\LV80ActiveXControl.dll
2007-02-08 09:48 . 2007-02-08 09:48 133920 ----a-w- c:\program files\internet explorer\plugins\LV82ActiveXControl.dll
2007-07-24 17:03 . 2007-07-24 17:03 118784 ----a-w- c:\program files\internet explorer\plugins\LV85ActiveXControl.dll
2008-12-10 13:50 . 2008-12-10 13:50 118784 ----a-w- c:\program files\internet explorer\plugins\LV86ActiveXControl.dll
2009-06-23 18:41 . 2009-06-23 18:41 158720 ----a-w- c:\program files\internet explorer\plugins\LV90ActiveXControl.dll
2011-05-02 09:02 . 2011-03-24 17:28 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"ICQ"="c:\program files\ICQ7.2\ICQ.exe" [2011-01-05 133432]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-02 281768]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2008-10-31 6609440]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2008-10-31 1833504]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 AVSUSB1;AvaSpec-USB1 driver;c:\windows\system32\Drivers\AVSUSB1.SYS [2006-11-08 45877]
R3 lvalarmk;lvalarmk;c:\windows\system32\drivers\lvalarmk.sys [2008-12-05 20104]
R3 ni1006k;NI PXI-1006 Chassis Pilot;c:\windows\system32\drivers\ni1006k.sys [2009-04-01 26192]
R3 ni1045k;NI PXI-1045 Chassis Pilot;c:\windows\system32\drivers\ni1045kl.sys [2009-06-17 11344]
R3 ni1065k;NI PXIe-1065 Chassis Pilot;c:\windows\system32\drivers\ni1065k.sys [2009-04-01 22608]
R3 nicdrk;nicdrk;c:\windows\system32\drivers\nicdrkl.sys [2009-01-02 11352]
R3 nicsrk;nicsrk;c:\windows\system32\drivers\nicsrkl.sys [2009-05-28 11336]
R3 nidevldu;NI Device Loader;c:\windows\system32\nipalsm.exe [2008-08-21 12696]
R3 nidimk;nidimk;c:\windows\system32\drivers\nidimkl.sys [2008-06-13 11360]
R3 nidmxfk;nidmxfk;c:\windows\system32\drivers\nidmxfkl.sys [2009-06-17 11336]
R3 nidsark;nidsark;c:\windows\system32\drivers\nidsarkl.sys [2009-06-17 11344]
R3 niemrk;niemrk;c:\windows\system32\drivers\niemrkl.sys [2009-05-28 11336]
R3 niesrk;niesrk;c:\windows\system32\drivers\niesrkl.sys [2009-05-28 11336]
R3 nifslk;nifslk;c:\windows\system32\drivers\nifslkl.sys [2009-01-06 11352]
R3 niLXIDiscovery;National Instruments LXI Discovery Service;c:\program files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe [2009-03-05 131704]
R3 nimDNSResponder;National Instruments mDNS Responder Service;c:\program files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe [2009-06-04 193648]
R3 nimru2k;nimru2k;c:\windows\system32\drivers\nimru2kl.sys [2008-11-24 11360]
R3 nimsdrk;nimsdrk;c:\windows\system32\drivers\nimsdrkl.sys [2008-12-29 11392]
R3 nimslk;nimslk;c:\windows\system32\drivers\nimslk.dll [x]
R3 nimsrlk;nimsrlk;c:\windows\system32\drivers\nimsrlk.dll [x]
R3 nimstsk;nimstsk;c:\windows\system32\drivers\nimstskl.sys [2008-12-29 11360]
R3 nimxpk;nimxpk;c:\windows\system32\drivers\nimxpkl.sys [2009-06-16 11368]
R3 ninshsdk;ninshsdk;c:\windows\system32\drivers\ninshsdkl.sys [2009-03-30 11360]
R3 nipalfwedl;nipalfwedl;c:\windows\system32\drivers\nipalfwedl.sys [2009-05-26 11904]
R3 nipalusbedl;nipalusbedl;c:\windows\system32\drivers\nipalusbedl.sys [2009-05-26 11896]
R3 nipxigpk;NI PXI Generic Chassis Pilot;c:\windows\system32\drivers\nipxigpk.sys [2008-06-25 20568]
R3 niscdk;niscdk;c:\windows\system32\drivers\niscdkl.sys [2009-01-05 11376]
R3 nisdigk;nisdigk;c:\windows\system32\drivers\nisdigkl.sys [2009-02-05 11352]
R3 nisftk;nisftk;c:\windows\system32\drivers\nisftkl.sys [2009-03-30 11344]
R3 nispdk;nispdk;c:\windows\system32\drivers\nispdkl.sys [2009-01-05 11376]
R3 nissrk;nissrk;c:\windows\system32\drivers\nissrkl.sys [2009-05-28 11336]
R3 nistc2k;nistc2k;c:\windows\system32\drivers\nistc2kl.sys [2009-01-02 11312]
R3 nistcrk;nistcrk;c:\windows\system32\drivers\nistcrkl.sys [2009-01-02 11360]
R3 niswdk;niswdk;c:\windows\system32\drivers\niswdkl.sys [2008-07-28 11336]
R3 nitiork;nitiork;c:\windows\system32\drivers\nitiorkl.sys [2009-01-02 11360]
R3 niufurk;niufurk;c:\windows\system32\drivers\niufurkl.sys [2009-05-28 11368]
R3 NiViFWK;NI-VISA FireWire Driver;c:\windows\system32\drivers\NiViFWKl.sys [2009-03-05 11384]
R3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciKl.sys [2009-06-21 11360]
R3 niwfrk;niwfrk;c:\windows\system32\drivers\niwfrkl.sys [2009-05-28 11336]
R3 nixsrk;nixsrk;c:\windows\system32\drivers\nixsrkl.sys [2009-05-28 11336]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2009-10-23 16456]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2009-10-23 11088]
R3 usb6xxxk;usb6xxxk;c:\windows\system32\drivers\usb6xxxkl.sys [x]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-11-19 691696]
S0 nipbcfk;National Instruments Class Upper Filter Driver;c:\windows\System32\drivers\nipbcfk.sys [2008-08-21 15448]
S1 ntiomin;ntiomin; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 acedrv10;acedrv10;c:\windows\system32\drivers\acedrv10.sys [2007-07-27 330144]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2010-02-24 185472]
S2 acehlp10;acehlp10;c:\windows\system32\drivers\acehlp10.sys [2007-07-27 251680]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-04-29 136360]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-07-15 233472]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640]
S2 nipxirmk;nipxirmk;c:\windows\system32\drivers\nipxirmkl.sys [2009-06-04 11344]
S2 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiKl.sys [2009-06-21 11360]
S2 resetWinService;Reset Reader;c:\program files\Realtek Semiconductor Corp\Realtek USB 2.0 Card Reader\reset.exe [2008-10-29 70656]
S2 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [2010-11-22 718072]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-07-15 36608]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-05-29 22712]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2010-06-21 105576]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [2010-01-29 997408]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - FSUSBEXDISK
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://start.icq.com/
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 81.173.194.76 81.173.194.69
TCP: Interfaces\{34B33514-5C05-43A7-8A2F-A23262FD8FDF}: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Maggi\AppData\Roaming\Mozilla\Firefox\Profiles\docb55n9.default\
FF - prefs.js: browser.startup.homepage - www.gmx.net
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.6&q=
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM-Run-NPSStartup - (no file)
HKLM-Run-Malwarebytes' Anti-Malware (reboot) - c:\program files\aaMalwarebytes' Anti-Malware\mbam.exe
SafeBoot-15569176.sys
AddRemove-Nero - Burning Rom!UninstallKey - d:\programme\Nero 7\\nero\uninstall\UNNERO.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1241376093-3597709944-3704505792-1000\Software\SecuROM\License information*]
"datasecu"=hex:c4,86,32,37,7c,88,5f,17,f7,54,13,04,0e,95,a3,6b,bc,81,9e,6b,c7,
9f,d5,3d,80,3b,e5,ee,8f,a6,a8,c8,73,97,a8,ae,51,a2,81,ee,c5,4f,df,4f,26,53,\
"rkeysecu"=hex:a5,a6,49,e1,45,84,b0,e0,e6,02,57,c8,d3,8a,0e,fb
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\programdata\EPSON\EPW!3 SSRP\E_S30RP1.EXE
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\conhost.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2011-06-06 17:22:45 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2011-06-06 15:22
.
Vor Suchlauf: 18 Verzeichnis(se), 17.429.696.512 Bytes frei
Nach Suchlauf: 20 Verzeichnis(se), 17.127.968.768 Bytes frei
.
- - End Of File - - 657E1B468657E5806380AF8F88C73AF5 |