Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Lukicsel cryptnet32.dll gefunden

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 16.01.2012, 20:13   #3
LindseyStomp
 
Lukicsel cryptnet32.dll gefunden - Standard

Lukicsel cryptnet32.dll gefunden



Hi und danke für die schnelle Reaktion

Combofix ist sauber durchgelaufen. Hier das Log:
Code:
ATTFilter
Combofix Logfile:
Code:
ATTFilter
ComboFix 12-01-16.02 - *** 16.01.2012  19:45:55.2.2 - x86
Microsoft Windows XP Professional  5.1.2600.3.1252.49.1031.18.2046.1221 [GMT 1:00]
ausgeführt von:: c:\dokumente und einstellungen\***\Desktop\ComboFix.exe
AV: G DATA AVK Client *Disabled/Updated* {71310606-6F3B-49F2-9A81-8315AA75FBB3}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\dokumente und einstellungen\All Users\Anwendungsdaten\Tarma Installer
c:\dokumente und einstellungen\All Users\Anwendungsdaten\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\_Setup.dll
c:\dokumente und einstellungen\All Users\Anwendungsdaten\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\20101106184800.log
c:\dokumente und einstellungen\All Users\Anwendungsdaten\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Cache\_Default.tiz
c:\dokumente und einstellungen\All Users\Anwendungsdaten\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Cache\AxInterop.ImageEnXLibrary_1.9000.0.0_L_75236aeec3d51fd0_MSIL.tiz
c:\dokumente und einstellungen\All Users\Anwendungsdaten\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Cache\CFToolkit_4.1.0.0_a87e673e9ecb6e8e_MSIL.tiz
c:\dokumente und einstellungen\All Users\Anwendungsdaten\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Cache\DROPPED_20100101190241.tiz
c:\dokumente und einstellungen\All Users\Anwendungsdaten\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Cache\DROPPED_20100101190244.tiz
c:\dokumente und einstellungen\All Users\Anwendungsdaten\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Cache\DROPPED_20100101190312.tiz
c:\dokumente und einstellungen\All Users\Anwendungsdaten\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Cache\FreeOCR_2.1.0.8_L_075a6c69191ec1db_x86.tiz
c:\dokumente und einstellungen\All Users\Anwendungsdaten\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Cache\Interop.ImageLibrary_1.9000.0.0_L_8cdfa8b955dbb1c7_MSIL.tiz
c:\dokumente und einstellungen\All Users\Anwendungsdaten\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Cache\Interop.PDFAX0717_7.17.0.0_L_3d5fa783dbb69c0f_MSIL.tiz
c:\dokumente und einstellungen\All Users\Anwendungsdaten\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Setup.dat
c:\dokumente und einstellungen\All Users\Anwendungsdaten\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Setup.exe
c:\dokumente und einstellungen\All Users\Anwendungsdaten\Tarma Installer\{108A39BF-4ED1-4293-B11A-06BD521FB8F7}\Setup.ico
c:\dokumente und einstellungen\All Users\Anwendungsdaten\TEMP
c:\windows\IsUn0407.exe
c:\windows\iun6002.exe
c:\windows\system32\crt.dat
c:\windows\system32\shimg.dll
c:\windows\unin0407.exe
.
.
(((((((((((((((((((((((   Dateien erstellt von 2011-12-16 bis 2012-01-16  ))))))))))))))))))))))))))))))
.
.
2012-01-15 17:59 . 2012-01-15 18:03	--------	d-----w-	c:\dokumente und einstellungen\***\Anwendungsdaten\QuickScan
2012-01-07 14:21 . 2012-01-07 14:21	479232	----a-w-	c:\programme\Mozilla Firefox\msvcm80.dll
2012-01-07 14:21 . 2012-01-07 14:21	43992	----a-w-	c:\programme\Mozilla Firefox\mozutils.dll
2012-01-07 14:21 . 2012-01-07 14:21	548864	----a-w-	c:\programme\Mozilla Firefox\msvcp80.dll
2012-01-07 14:21 . 2012-01-07 14:21	626688	----a-w-	c:\programme\Mozilla Firefox\msvcr80.dll
2011-12-27 16:39 . 2011-12-27 16:39	--------	d-----w-	c:\dokumente und einstellungen\***\Lokale Einstellungen\Anwendungsdaten\LucasArts
2011-12-27 16:37 . 2008-03-05 15:03	479752	----a-w-	c:\windows\system32\XAudio2_0.dll
2011-12-27 16:37 . 2008-03-05 15:00	25608	----a-w-	c:\windows\system32\X3DAudio1_3.dll
2011-12-27 16:37 . 2008-03-05 14:56	1420824	----a-w-	c:\windows\system32\D3DCompiler_37.dll
2011-12-27 16:37 . 2008-02-05 22:07	462864	----a-w-	c:\windows\system32\d3dx10_37.dll
2011-12-27 16:37 . 2008-03-05 14:56	3786760	----a-w-	c:\windows\system32\D3DX9_37.dll
2011-12-27 16:23 . 2011-12-27 16:23	--------	d-----w-	c:\programme\LucasArts
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-15 09:04 . 2011-06-29 06:54	414368	----a-w-	c:\windows\system32\FlashPlayerCPLApp.cpl
2008-08-11 01:18 . 2008-08-11 01:18	46408	-c--a-w-	c:\programme\mozilla firefox\plugins\atmccli.dll
2012-01-07 14:21 . 2011-03-25 01:04	121816	----a-w-	c:\programme\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\programme\Winload\tbWin0.dll" [2010-10-18 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 10:26	3908192	----a-w-	c:\programme\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
2010-10-18 10:26	3908192	----a-w-	c:\programme\Winload\tbWin0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\programme\Winload\tbWin0.dll" [2010-10-18 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{40C3CC16-7269-4B32-9531-17F2950FB06F}"= "c:\programme\Winload\tbWin0.dll" [2010-10-18 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\programme\Apoint\Apoint.exe" [2007-04-15 159744]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-31 8429568]
"nwiz"="nwiz.exe" [2007-05-31 1626112]
"NvMediaCenter"="NvMCTray.dll" [2007-05-31 81920]
"IntelZeroConfig"="c:\programme\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\programme\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-24 17920]
"AVK Client"="c:\programme\G DATA\AVKClient\AVKCl.exe" [2007-11-06 775752]
"CmCardRun"="c:\windows\system32\CmWatch.exe" [2003-09-16 229376]
"SigmatelSysTrayApp"="c:\programme\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wxvault.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages	REG_MULTI_SZ   	msv1_0 wvauth
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Programme\\G DATA\\AVKClient\\AVKCl.exe"=
"c:\\Programme\\NetObjects\\NetObjects Fusion Essentials\\Fusion.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Programme\\FRITZ!\\FriFax32.exe"=
"c:\\Programme\\Microsoft ActiveSync\\rapimgr.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Dokumente und Einstellungen\\***\\Eigene Dateien\\Downloads\\System Aufraeumen\\Boot beschleunigen Soluto\\solutoinstaller.exe"=
"c:\\Programme\\Soluto\\Soluto.exe"=
"c:\\Programme\\Soluto\\SolutoService.exe"=
"c:\\Programme\\Soluto\\SolutoConsole.exe"=
"c:\\Programme\\Soluto\\SolutoUpdateService.exe"=
"c:\\Programme\\LearnLift\\MemoryLifter2\\MLifter.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:Remote Desktop
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
.
R2 ACEDRV09;ACEDRV09;c:\windows\system32\drivers\ACEDRV09.sys [20.10.2009 07:15 110304]
R2 acedrv11;acedrv11;c:\windows\system32\drivers\ACEDRV11.sys [23.01.2008 09:19 501560]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\programme\IObit\Advanced SystemCare 4\ASCService.exe [08.05.2011 23:23 352656]
R2 AntiVirusKit Client;G DATA AntiVirus Client;c:\programme\G DATA\AVKClient\AVKCl.exe [20.11.2007 12:48 775752]
R2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\programme\Broadcom\ASFIPMon\AsfIpMon.exe -service --> c:\programme\Broadcom\ASFIPMon\AsfIpMon.exe -service [?]
R2 AVKProxy;G DATA AntiVirus Proxy;c:\programme\Gemeinsame Dateien\G DATA\AVKProxy\AVKProxy.exe [20.11.2007 12:48 714312]
R2 AVKWCtl;AntiVirus Wächter;c:\programme\G DATA\AVKClient\AVKWCtl.exe [20.11.2007 12:48 1062472]
R2 GDTdiInterceptor;GDTdiInterceptor;c:\windows\system32\drivers\GDTdiIcpt.sys [20.11.2007 12:49 40400]
R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [13.08.2004 13:40 5120]
R3 dfmirage;dfmirage;c:\windows\system32\drivers\dfmirage.sys [30.10.2008 00:05 31896]
R3 GDMnIcpt;GDMnIcpt;c:\windows\system32\drivers\MiniIcpt.sys [20.11.2007 12:48 45768]
R3 xcpip;TCP/IP-Protokolltreiber;c:\windows\system32\drivers\xcpip.sys --> c:\windows\system32\drivers\xcpip.sys [?]
R3 xpsec;IPSEC-Treiber;c:\windows\system32\drivers\xpsec.sys --> c:\windows\system32\drivers\xpsec.sys [?]
S0 Soluto;Soluto;c:\windows\system32\drivers\Soluto.sys [22.08.2011 20:22 51144]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.03.2010 12:16 130384]
S2 gupdate;Google Update Service (gupdate); [x]
S2 SolutoService;Soluto PCGenome Core Service;c:\programme\Soluto\SolutoService.exe [21.07.2011 10:52 392224]
S3 ACTIVhidmini;Promethean USB Board Driver;c:\windows\system32\DRIVERS\ACTIVhidmini.sys --> c:\windows\system32\DRIVERS\ACTIVhidmini.sys [?]
S3 ActivHidSerMini;Promethean Serial Board Driver;c:\windows\system32\DRIVERS\activhidsermini.sys --> c:\windows\system32\DRIVERS\activhidsermini.sys [?]
S3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [02.11.2006 13:32 97536]
S3 gupdatem;Google Update-Dienst (gupdatem); [x]
S3 ICDUSB3;ICDUSB3;c:\windows\system32\drivers\ICDUSB3.sys [08.10.2009 07:05 11264]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [15.04.2010 09:27 9728]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [24.07.2011 23:45 137600]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [24.07.2011 23:45 8576]
S3 prmvmouse;Promethean HID Mouse Service;c:\windows\system32\DRIVERS\activmouse.sys --> c:\windows\system32\DRIVERS\activmouse.sys [?]
S3 TipCtrl;TipCtrl; [x]
S3 UI Assistant Service;UI Assistant Service;c:\programme\Join Air\AssistantServices.exe [15.04.2010 09:27 241664]
S3 UMSSSTOR;C-Media Storage;c:\windows\system32\drivers\Umss.SYS [27.06.2009 15:16 48512]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.03.2010 12:16 753504]
S3 xfq2s.sys;xfq2s.sys;\??\c:\windows\system32\drivers\xfq2s.sys --> c:\windows\system32\drivers\xfq2s.sys [?]
.
Inhalt des "geplante Tasks" Ordners
.
2012-01-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2319825
uInternet Settings,ProxyServer = http=128.252.19.19:3124
uInternet Settings,ProxyOverride = <local>
IE: add to &BOM - c:\\PROGRA~1\\BIET-O~1\\\\AddToBOM.hta
IE: Free YouTube to MP3 Converter - c:\dokumente und einstellungen\***\Anwendungsdaten\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
FF - ProfilePath - c:\dokumente und einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\901af4d5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: keyword.URL - hxxp://de.search.yahoo.com/search?fr=mcafee&p=
FF - prefs.js: network.proxy.http - 201.244.14.36
FF - prefs.js: network.proxy.http_port - 3128
FF - prefs.js: network.proxy.type - 4
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Notify-ckpNotify - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-Allway Sync 'n' Go_is1 - e:\allway sync 'n' go\unins000.exe
AddRemove-FRITZ! 2.0 - c:\windows\IsUn0407.exe
AddRemove-Mathe-Blitz - c:\windows\unin0407.exe
AddRemove-Microsoft Interactive Training - c:\windows\IsUn0407.exe
AddRemove-NetObjects Fusion Essentials - c:\windows\IsUn0407.exe
AddRemove-{108A39BF-4ED1-4293-B11A-06BD521FB8F7} - c:\dokume~1\ALLUSE~1\ANWEND~1\TARMAI~1\{108A3~1\Setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-01-16 19:52
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse... 
.
Scanne versteckte Autostarteinträge... 
.
Scanne versteckte Dateien... 
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•6~*]
"7040311900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(812)
c:\windows\system32\wxvault.dll
c:\windows\system32\detoured.dll
.
- - - - - - - > 'lsass.exe'(868)
c:\windows\system32\wxvault.dll
c:\windows\system32\detoured.dll
c:\windows\system32\wvauth.dll
c:\windows\system32\biolsp.dll
.
Zeit der Fertigstellung: 2012-01-16  19:55:00
ComboFix-quarantined-files.txt  2012-01-16 18:54
.
Vor Suchlauf: 22 Verzeichnis(se), 22.933.635.072 Bytes frei
Nach Suchlauf: 23 Verzeichnis(se), 23.087.640.576 Bytes frei
.
- - End Of File - - B13274E671387AC7897D6848B32E7C33
         
--- --- ---
__________________

 

Themen zu Lukicsel cryptnet32.dll gefunden
.dll, 0x00000001, alternate, antivirus, audacity, bho, converter, cryptnet32.dll, einstellungen, error, explorer, fehlalarm, firefox, fontcache, format, ftp, google, google earth, helper, iobit, log, logfile, lukicsel, microsoft, mozilla thunderbird, mp3, msvcrt, netzwerk, nodrives, nvidia, plug-in, programme, registry, required, scan, secure search, software, systemcare, tarma, trojaner, warum, win32k.sys, winload toolbar, winlogon.exe





Zum Thema Lukicsel cryptnet32.dll gefunden - Hi und danke für die schnelle Reaktion Combofix ist sauber durchgelaufen. Hier das Log: Code: Alles auswählen Aufklappen ATTFilter Combofix Logfile: Code: Alles auswählen Aufklappen ATTFilter ComboFix 12-01-16.02 - *** - Lukicsel cryptnet32.dll gefunden...
Archiv
Du betrachtest: Lukicsel cryptnet32.dll gefunden auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.