ChristinaXXX | 27.09.2012 19:19 | [code]
Combofix Logfile: Code:
ComboFix 12-09-27.03 - Chrissi 27.09.2012 19:35:17.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3070.1369 [GMT 2:00]
ausgeführt von:: c:\users\Chrissi\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Chrissi\Documents\~WRL1243.tmp
c:\users\Chrissi\epson373062eu.exe
c:\users\Chrissi\epson373282eu.exe
c:\users\Chrissi\setup_dm_Fotowelt.exe
.
.
((((((((((((((((((((((((((((((((((((((( Treiber/Dienste )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_usnjsvc
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-08-27 bis 2012-09-27 ))))))))))))))))))))))))))))))
.
.
2012-09-26 13:00 . 2011-03-12 21:55 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2012-09-26 13:00 . 2012-03-01 14:46 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-09-26 13:00 . 2012-03-01 14:46 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2012-09-26 13:00 . 2012-02-29 14:08 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2012-09-26 13:00 . 2012-02-29 13:44 683008 ----a-w- c:\windows\system32\d2d1.dll
2012-09-26 13:00 . 2012-02-29 13:41 1069056 ----a-w- c:\windows\system32\DWrite.dll
2012-09-25 15:42 . 2012-09-25 15:42 -------- d-----w- c:\program files\Windows Portable Devices
2012-09-25 15:11 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2012-09-25 15:11 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2012-09-25 15:11 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2012-09-25 15:09 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2012-09-25 15:09 . 2009-10-01 01:02 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2012-09-25 15:09 . 2009-10-01 01:01 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2012-09-25 15:00 . 2012-02-29 15:11 5120 ----a-w- c:\windows\system32\wmi.dll
2012-09-25 15:00 . 2012-02-29 15:11 172032 ----a-w- c:\windows\system32\wintrust.dll
2012-09-25 15:00 . 2012-02-29 15:09 157696 ----a-w- c:\windows\system32\imagehlp.dll
2012-09-25 15:00 . 2012-02-29 13:32 12800 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-09-25 14:51 . 2012-07-04 14:02 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-09-25 14:48 . 2012-09-25 14:48 98816 ----a-w- c:\windows\system32\mfps.dll
2012-09-25 14:47 . 2012-09-25 14:47 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2012-09-25 14:47 . 2012-09-25 14:47 519680 ----a-w- c:\windows\system32\d3d11.dll
2012-09-25 14:47 . 2012-09-25 14:47 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2012-09-25 14:47 . 2012-09-25 14:47 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2012-09-25 14:47 . 2012-09-25 14:47 252928 ----a-w- c:\windows\system32\dxdiag.exe
2012-09-25 14:47 . 2012-09-25 14:47 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2012-09-25 14:47 . 2012-09-25 14:47 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2012-09-25 13:22 . 2012-09-25 13:22 -------- d-----w- C:\_OTL
2012-09-25 13:07 . 2012-04-23 16:00 984064 ----a-w- c:\windows\system32\crypt32.dll
2012-09-25 13:07 . 2012-04-23 16:00 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-09-25 13:07 . 2012-04-23 16:00 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2012-09-25 13:07 . 2011-07-29 16:01 293376 ----a-w- c:\windows\system32\psisdecd.dll
2012-09-25 13:07 . 2011-07-29 16:01 217088 ----a-w- c:\windows\system32\psisrndr.ax
2012-09-25 13:07 . 2011-07-29 16:00 57856 ----a-w- c:\windows\system32\MSDvbNP.ax
2012-09-25 13:07 . 2011-07-29 16:00 69632 ----a-w- c:\windows\system32\Mpeg2Data.ax
2012-09-25 13:07 . 2011-10-14 16:03 189952 ----a-w- c:\windows\system32\winmm.dll
2012-09-25 13:07 . 2011-10-14 16:00 23552 ----a-w- c:\windows\system32\mciseq.dll
2012-09-25 13:07 . 2012-05-11 15:57 623616 ----a-w- c:\windows\system32\localspl.dll
2012-09-25 13:07 . 2011-11-18 20:23 1205064 ----a-w- c:\windows\system32\ntdll.dll
2012-09-25 13:05 . 2011-11-16 16:23 377344 ----a-w- c:\windows\system32\winhttp.dll
2012-09-25 13:00 . 2012-06-04 15:26 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-09-25 13:00 . 2012-06-02 00:04 278528 ----a-w- c:\windows\system32\schannel.dll
2012-09-25 13:00 . 2011-11-16 16:21 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2012-09-25 12:59 . 2012-06-02 00:03 204288 ----a-w- c:\windows\system32\ncrypt.dll
2012-09-25 12:59 . 2011-11-16 16:23 72704 ----a-w- c:\windows\system32\secur32.dll
2012-09-25 12:59 . 2011-11-16 14:12 9728 ----a-w- c:\windows\system32\lsass.exe
2012-09-25 12:55 . 2012-08-30 08:17 6980552 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{023BE9D9-C0CE-4F59-98F8-8A8EC8007338}\mpengine.dll
2012-09-25 12:51 . 2012-01-09 15:54 613376 ----a-w- c:\windows\system32\rdpencom.dll
2012-09-25 12:37 . 2012-06-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-09-25 12:37 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll
2012-09-25 12:37 . 2012-06-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-09-25 12:37 . 2012-06-02 22:12 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-09-25 12:36 . 2012-06-02 22:19 35864 ----a-w- c:\windows\system32\wups.dll
2012-09-25 12:36 . 2012-06-02 22:19 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-09-25 12:36 . 2012-06-02 22:12 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-09-25 12:36 . 2012-06-02 13:19 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-09-25 12:36 . 2012-06-02 13:12 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-09-24 05:22 . 2012-09-24 05:23 -------- d-----w- c:\windows\system32\ca-ES
2012-09-24 05:22 . 2012-09-24 05:23 -------- d-----w- c:\windows\system32\eu-ES
2012-09-24 05:22 . 2012-09-24 05:23 -------- d-----w- c:\windows\system32\vi-VN
2012-09-23 12:14 . 2012-09-23 12:14 -------- d-----w- c:\windows\system32\EventProviders
2012-09-22 16:51 . 2012-09-22 16:51 -------- d-----w- c:\program files\ESET
2012-09-22 11:09 . 2012-09-22 11:09 -------- d-----w- c:\users\Chrissi\AppData\Roaming\Malwarebytes
2012-09-22 11:09 . 2012-09-22 11:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-09-22 11:09 . 2012-09-22 11:09 -------- d-----w- c:\programdata\Malwarebytes
2012-09-22 11:09 . 2012-09-07 15:04 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-22 07:14 . 2012-09-22 16:39 -------- d-----w- c:\windows\Microsoft Antimalware
2012-09-14 04:26 . 2012-09-14 04:26 -------- d-----w- c:\program files\Common Files\Skype
2012-09-14 04:26 . 2012-09-14 04:26 -------- d-----r- c:\program files\Skype
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-25 14:47 . 2012-09-25 14:47 4096 ----a-w- c:\windows\system32\drivers\en-US\dxgkrnl.sys.mui
2012-09-25 14:47 . 2012-09-25 14:47 4096 ----a-w- c:\windows\system32\drivers\de-DE\dxgkrnl.sys.mui
2012-09-20 19:01 . 2012-08-12 16:08 696240 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-20 19:01 . 2011-08-20 14:02 73136 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-12-12 1840424]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-16 39408]
"Sony PC Companion"="c:\program files\Sony\Sony PC Companion\PCCompanion.exe" [2012-05-31 445624]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
"Skytel"="Skytel.exe" [2008-06-25 1826816]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-08-31 102400]
"LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2007-09-01 32768]
"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2007-09-06 188416]
"LMgrOSD"="c:\program files\Launch Manager\OSD.exe" [2006-12-26 180224]
"Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2007-09-07 86016]
"OmniPass"="c:\program files\Softex\OmniPass\scureapp.exe" [2007-11-02 2564096]
"LanguageShortcut"="c:\program files\HomeCinema\PowerDVD\Language\Language.exe" [2007-01-08 52256]
"UCam_Menu"="c:\program files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe" [2007-09-13 222504]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-11 13543968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-11 92704]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-07-25 220160]
"toolbar_eula_launcher"="c:\program files\GoogleEULA\EULALauncher.exe" [2007-02-09 16896]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-21 185872]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-12-02 2221352]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-26 421160]
"SMART Board Service"="c:\program files\SMART Technologies\Education Software\SMARTBoardService.exe" [2011-07-13 1761136]
"EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2010-10-12 979328]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-08-12 348664]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-11 919008]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
WiseUpdt.lnk - c:\program files\Schroedel\KlassenManager 3.0\WiseUpdt.exe [2011-8-17 194853]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Inhalt des "geplante Tasks" Ordners
.
2012-09-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-12 19:01]
.
2012-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-28 07:38]
.
2012-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-28 07:38]
.
2012-09-05 c:\windows\Tasks\Norton Security Scan for Chrissi.job
- c:\progra~1\NORTON~2\Engine\351~1.8\Nss.exe [2011-11-06 00:45]
.
2012-09-26 c:\windows\Tasks\ReclaimerResumeInstall_Chrissi.job
- c:\users\Chrissi\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe [2012-09-26 16:08]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.spiegel.de/
mStart Page = hxxp://www.netcologne.de
mWindow Title = Internet Explorer bereitgestellt von NetCologne
uInternet Settings,ProxyOverride = *.local
IE: An OneNote s&enden - c:\progra~1\MICROS~4\Office14\ONBttnIE.dll/105
IE: Free YouTube Download - c:\users\Chrissi\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~4\Office14\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-25/4
TCP: DhcpNameServer = 192.168.0.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKCU-Run-SjaPfXBKSlE.exe - c:\programdata\SjaPfXBKSlE.exe
HKLM-Run-CtrlVol - c:\program files\Launch Manager\CtrlVol.exe
HKLM-Run-snp2uvc - c:\windows\vsnp2uvc.exe
HKLM-Run-PLFSetL - c:\windows\PLFSetL.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-09-27 20:12
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1541561756-3189364277-4046548892-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:36,2a,1f,a8,98,b3,13,53,b6,0b,c2,7b,ed,34,72,08,87,1c,66,18,18,49,e1,
a8,11,ce,f7,99,3e,cb,3e,5a,24,7b,88,e1,2d,43,bc,df,b3,d9,6f,de,6b,54,99,81,\
"??"=hex:db,04,0e,52,89,49,8c,2b,47,79,02,ff,71,4f,c8,12
.
[HKEY_USERS\S-1-5-21-1541561756-3189364277-4046548892-1001\Software\SecuROM\License information*]
"datasecu"=hex:32,d2,8f,c1,4f,43,f4,46,bb,d1,08,35,e7,42,c7,ff,03,58,a9,a8,95,
db,09,19,8b,bc,cd,f7,89,77,ee,e9,dc,4b,7f,09,c1,97,e5,e3,ae,56,5d,88,dc,85,\
"rkeysecu"=hex:be,88,e9,bb,d3,91,37,d0,d7,02,b1,3f,34,29,b9,f2
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(908)
c:\program files\Softex\OmniPass\SCUREDLL.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\Softex\OmniPass\OmniServ.exe
c:\windows\system32\rundll32.exe
c:\windows\SYSTEM32\WISPTIS.EXE
c:\program files\Common Files\microsoft shared\ink\TabTip.exe
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Common Files\EPSON\EBAPI\eEBSVC.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\IoctlSvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\WUDFHost.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\SYSTEM32\WISPTIS.EXE
c:\program files\Common Files\microsoft shared\ink\TabTip.exe
c:\program files\Softex\OmniPass\opvapp.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\windows\System32\rundll32.exe
c:\program files\Launch Manager\WisLMSvc.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Sony\Sony PC Companion\PCCompanionInfo.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\program files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-09-27 20:17:31 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2012-09-27 18:17
.
Vor Suchlauf: 13 Verzeichnis(se), 174.625.062.912 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 174.487.957.504 Bytes frei
.
- - End Of File - - 0143C7A6157BB2018BF8BDA3F851626D --- --- --- |