Hi Leo!
Erstmal das Combofix-Monster, dann geht´s weiter... Code:
ComboFix 13-08-28.02 - Administrator 28.08.2013 22:17:43.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.49.1031.18.1983.1450 [GMT 2:00]
ausgeführt von:: c:\dokumente und einstellungen\Administrator\Desktop\ComboFix.exe
AV: Avira Desktop *Enabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\dokumente und einstellungen\Administrator\Anwendungsdaten\ImgBurn.exe
c:\dokumente und einstellungen\Administrator\Anwendungsdaten\Piwa
c:\dokumente und einstellungen\Administrator\Anwendungsdaten\Piwa\afvu.kyy
c:\dokumente und einstellungen\Administrator\Anwendungsdaten\Piwa\afvu.tmp
c:\dokumente und einstellungen\Administrator\Anwendungsdaten\yuvcodecs-1.3.exe
c:\dokumente und einstellungen\Administrator\WINDOWS
c:\dokumente und einstellungen\All Users\Anwendungsdaten\TEMP
C:\Install.exe
c:\programme\Gemeinsame Dateien\Will.ico
c:\windows\dasetup.log
c:\windows\Installer\$PatchCache$\Managed\979F5176EB21C1C4AABE61588102F4B1\15.1.0\appconfig.ini2
c:\windows\IsUn0407.exe
c:\windows\system32\sstray.exe
c:\windows\unin0407.exe
.
.
((((((((((((((((((((((((((((((((((((((( Treiber/Dienste )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_SSHNAS
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-07-28 bis 2013-08-28 ))))))))))))))))))))))))))))))
.
.
2013-08-28 10:52 . 2013-08-28 10:53 -------- d-----w- C:\AdwCleaner
2013-08-26 19:44 . 2013-08-26 19:44 -------- d-----w- C:\FRST
2013-08-25 13:55 . 2013-08-25 13:55 -------- d-----w- c:\programme\HitmanPro
2013-08-23 17:47 . 2013-08-23 17:47 861088 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-08-23 17:47 . 2013-08-23 17:47 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-08-23 17:47 . 2013-08-23 17:47 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-08-23 17:18 . 2013-08-23 17:28 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\HitmanPro
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-23 17:47 . 2007-10-03 11:40 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-08-02 23:48 . 2006-10-18 20:47 1543680 ------w- c:\windows\system32\wmvdecod.dll
2013-07-26 02:47 . 2006-06-23 11:27 920064 ----a-w- c:\windows\system32\wininet.dll
2013-07-26 02:47 . 2007-08-11 17:43 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-07-26 02:47 . 2007-08-11 17:43 43520 ------w- c:\windows\system32\licmgr10.dll
2013-07-25 15:52 . 2004-08-04 07:42 385024 ------w- c:\windows\system32\html.iec
2013-07-10 10:37 . 2007-08-11 17:42 406016 ----a-w- c:\windows\system32\usp10.dll
2013-07-04 07:33 . 2001-08-23 12:00 2152448 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-07-04 07:33 . 2001-08-18 04:28 2031104 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-06-24 19:36 . 2013-06-24 19:36 466008 ----a-w- c:\windows\system32\drivers\sptd.sys
2013-06-23 21:38 . 2013-06-23 21:38 34936 ----a-w- c:\windows\system32\uninstHelixYUV.exe
2013-06-23 21:37 . 2013-06-23 21:37 7760687 ----a-w- c:\dokumente und einstellungen\Administrator\Anwendungsdaten\SetupGFD.exe
2013-06-23 21:37 . 2013-06-23 21:36 5243208 ----a-w- c:\dokumente und einstellungen\Administrator\Anwendungsdaten\AvsP.exe
2013-06-23 21:36 . 2013-06-23 21:36 1357348 ----a-w- c:\dokumente und einstellungen\Administrator\Anwendungsdaten\MatroskaSplitter.exe
2013-06-23 21:36 . 2013-06-23 21:35 5082084 ----a-w- c:\dokumente und einstellungen\Administrator\Anwendungsdaten\Avisynth.exe
2013-06-05 09:08 . 2001-08-23 12:00 1876864 ----a-w- c:\windows\system32\win32k.sys
2013-06-04 07:22 . 2007-08-12 09:55 563712 ----a-w- c:\windows\system32\qedit.dll
2012-02-16 14:55 . 2012-02-29 20:40 134104 ----a-w- c:\programme\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"type32"="c:\programme\Microsoft IntelliType Pro\type32.exe" [2005-06-10 196608]
"IntelliPoint"="c:\programme\Microsoft IntelliPoint\point32.exe" [2005-06-10 217088]
"SSBkgdUpdate"="c:\programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\programme\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 57393]
"IndexSearch"="c:\programme\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 40960]
"SetDefPrt"="c:\programme\Brother\Brmfl05a\BrStDvPt.exe" [2005-01-26 49152]
"ControlCenter2.0"="c:\programme\Brother\ControlCenter2\brctrcen.exe" [2005-05-17 933888]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RTHDCPL"="RTHDCPL.EXE" [2008-04-10 16861184]
"avgnt"="c:\programme\Avira\AntiVir Desktop\avgnt.exe" [2013-07-03 345144]
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2013-05-11 958576]
"SunJavaUpdateSched"="c:\programme\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-24 132496]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AntiVirService"=2 (0x2)
"AntiVirSchedulerService"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [05.04.2013 11:24 37352]
R2 AAV UpdateService;AAV UpdateService;c:\programme\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [24.10.2008 17:35 128296]
R2 MotoHelper;MotoHelper Service;c:\programme\Motorola\MotoHelper\MotoHelperService.exe [07.09.2010 18:47 202048]
R2 RppClientService;Recover PDF Password Client Service;c:\programme\Eltima Software\Recover PDF Password\agent\RPPc.exe [20.01.2013 15:52 687104]
S2 HitmanProScheduler;HitmanPro Scheduler;c:\programme\HitmanPro\hmpsched.exe [25.08.2013 15:55 106280]
S3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\drivers\motfilt.sys [25.06.2011 22:05 6016]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [25.06.2011 22:05 19968]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [25.06.2011 22:05 8320]
S3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\drivers\Motousbnet.sys [25.06.2011 22:05 23424]
S3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\drivers\motusbdevice.sys [25.06.2011 22:05 9472]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
S4 AntiVirSchedulerService;Avira Planer;c:\programme\Avira\AntiVir Desktop\sched.exe [05.04.2013 11:24 84024]
.
Inhalt des "geplante Tasks" Ordners
.
2013-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programme\Google\Update\GoogleUpdate.exe [2012-07-17 09:03]
.
2013-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programme\Google\Update\GoogleUpdate.exe [2012-07-17 09:03]
.
2013-08-28 c:\windows\Tasks\User_Feed_Synchronization-{9983DE20-63FA-4786-BC4C-D0B6DD06C7CE}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.com
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\dokumente und einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\alkm4gsh.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM-Run-nForce Tray Options - sstray.exe
AddRemove-Adobe Acrobat 5.0 - c:\windows\ISUN0407.EXE
AddRemove-H A W I K III - c:\windows\unin0407.exe
AddRemove-Schulschriften - c:\windows\unin0407.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2013-08-28 22:25
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1960408961-220523388-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,8e,53,b7,0e,77,89,aa,4b,b4,88,08,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,23,d6,2e,df,3e,e6,06,4d,8c,74,6d,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'explorer.exe'(2232)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\System32\brss01a.exe
c:\programme\Java\jre7\bin\jqs.exe
c:\windows\System32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\programme\Motorola\MotoHelper\MotoHelperAgent.exe
c:\windows\RTHDCPL.EXE
c:\programme\avira\antivir desktop\ipmGui.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-08-28 22:28:49 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2013-08-28 20:28
.
Vor Suchlauf: 11 Verzeichnis(se), 88.723.951.616 Bytes frei
Nach Suchlauf: 12 Verzeichnis(se), 90.812.612.608 Bytes frei
.
WindowsXP-KB310994-SP2-Pro-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn /usepmtimer
.
- - End Of File - - 4A7AD36C19381304A7D7BE9362483A49
72B8CE41AF0DE751C946802B3ED844B4 Schnauf!!!
Hier die Logdatei von AdwCleaner: Code:
# AdwCleaner v3.001 - Report created 28/08/2013 at 12:52:46
# Updated 24/08/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Administrator - OLLI
# Running from : C:\Dokumente und Einstellungen\Administrator\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Programme\Ask.com
Folder Deleted : C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\AskToolbar
Folder Deleted : C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\AskSearch
Folder Deleted : C:\Dokumente und Einstellungen\Administrator\IECompatCache
Folder Deleted : C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\AskToolbar
Folder Deleted : C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\PackageAware
Folder Deleted : C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\alkm4gsh.default\Extensions\toolbar@ask.com
File Deleted : C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\Uninstall.exe
File Deleted : C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\alkm4gsh.default\searchplugins\Askcom.xml
File Deleted : C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHost.Tool
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C17DC5CF-54FF-4E63-8AC7-94335D6DA231}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D14D0EE2-2DD1-4230-BE70-3F3AD6172C40}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{05366194-3126-4601-AC1A-DDE573E093DC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{061F450C-37B9-4330-9235-0F25D9F75B33}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22FEB0F5-0BA0-4D4B-8A66-55A21667BC31}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{26249267-15F4-4DA3-8247-C5A78E4FA918}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{39B217B4-8C69-4E45-A8DC-8CC4DAD3CF0A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3CB4CE45-8849-4638-9226-D6B615A15827}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{43AB7B5D-4C40-4103-A549-7002A116A7D5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{996ED20F-A740-47A2-A7EF-9620D422BB4E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D2B79F7D-2D7D-4420-B2A9-ECE52C7C83A0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{061F450C-37B9-4330-9235-0F25D9F75B33}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{22FEB0F5-0BA0-4D4B-8A66-55A21667BC31}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2B79F7D-2D7D-4420-B2A9-ECE52C7C83A0}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1D55DAA5-04AC-4036-B0BE-DA81EE9676CD}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{58CBF821-A0C7-4AE8-9430-77DD1AF38E99}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{72BCBFF7-2837-4CA0-B3B5-3DAED7F54601}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{824125FD-7732-4DA2-9277-3A7D0A0A0813}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{043C5167-00BB-4324-AF7E-62013FAEDACF}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3B7599DF-3D5D-4EF5-BF51-9C2EDA788E83}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3B7599DF-3D5D-4EF5-BF51-9C2EDA788E83}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C17DC5CF-54FF-4E63-8AC7-94335D6DA231}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D14D0EE2-2DD1-4230-BE70-3F3AD6172C40}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F994E0D9-8335-48F1-99C2-A712C21F8D5F}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{043C5167-00BB-4324-AF7E-62013FAEDACF}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}]
Key Deleted : HKCU\Software\APN
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\AskToolbar
Key Deleted : HKLM\Software\APN
Key Deleted : HKLM\Software\AskToolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Smart-Ads-Solutions
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\vShare
Product Deleted : Ask Toolbar
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v10.0.2 (de)
[ File : C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\alkm4gsh.default\prefs.js ]
Line Deleted : user_pref("browser.search.order.1", "Ask.com");
Line Deleted : user_pref("browser.search.selectedEngine", "Ask.com");
Line Deleted : user_pref("browser.startup.homepage", "hxxp://search.avira.com/?l=dis&o=APN10261&gct=hp&dc=EU&locale=de_DE");
Line Deleted : user_pref("extensions.installCache", "[{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Programme\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7[...]
*************************
AdwCleaner[R0].txt - [8812 octets] - [28/08/2013 12:52:14]
AdwCleaner[S0].txt - [8387 octets] - [28/08/2013 12:52:46]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8447 octets] ########## Gehe ich recht in der Annahme, dass du die andere Logdatei (AdwCleaner[R0]) nicht brauchst? Habe das, wie gefordert natürlich vor der Combofix-Hölle erledigt...
Schritt 3 (FRST)
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-08-2013
Ran by Administrator (administrator) on 28-08-2013 23:03:42
Running from C:\Dokumente und Einstellungen\Administrator\Desktop
Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(brother Industries Ltd) C:\WINDOWS\System32\brsvc01a.exe
(brother Industries Ltd) C:\WINDOWS\System32\brss01a.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\sched.exe
() C:\Programme\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avguard.exe
(Oracle Corporation) C:\Programme\Java\jre7\bin\jqs.exe
() C:\Programme\Motorola\MotoHelper\MotoHelperService.exe
(Eltima Software) C:\Programme\Eltima Software\Recover PDF Password\agent\RPPc.exe
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avshadow.exe
(SurfRight B.V.) C:\Programme\HitmanPro\hmpsched.exe
() C:\Programme\Motorola\MotoHelper\MotoHelperAgent.exe
(Microsoft Corporation) C:\Programme\Microsoft IntelliType Pro\type32.exe
(Microsoft Corporation) C:\Programme\Microsoft IntelliPoint\point32.exe
(ScanSoft, Inc.) C:\Programme\ScanSoft\PaperPort\pptd40nt.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Avira Operations GmbH & Co. KG) C:\Programme\Avira\AntiVir Desktop\avgnt.exe
(Sun Microsystems, Inc.) C:\Programme\Java\jre1.6.0_03\bin\jusched.exe
(Microsoft Corporation) C:\Programme\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Programme\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Programme\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [type32] - C:\Programme\Microsoft IntelliType Pro\type32.exe [196608 2005-06-10] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] - C:\Programme\Microsoft IntelliPoint\point32.exe [217088 2005-06-10] (Microsoft Corporation)
HKLM\...\Run: [SSBkgdUpdate] - C:\Programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [155648 2003-10-14] (Scansoft, Inc.)
HKLM\...\Run: [PaperPort PTD] - C:\Programme\ScanSoft\PaperPort\pptd40nt.exe [57393 2005-03-17] (ScanSoft, Inc.)
HKLM\...\Run: [IndexSearch] - C:\Programme\ScanSoft\PaperPort\IndexSearch.exe [40960 2005-03-17] (ScanSoft, Inc.)
HKLM\...\Run: [SetDefPrt] - C:\Programme\Brother\Brmfl05a\BrStDvPt.exe [49152 2005-01-26] (Brother Industories, Ltd.)
HKLM\...\Run: [ControlCenter2.0] - C:\Programme\Brother\ControlCenter2\brctrcen.exe [933888 2005-05-17] (Brother Industries, Ltd.)
HKLM\...\Run: [NeroFilterCheck] - C:\WINDOWS\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\...\Run: [RTHDCPL] - C:\Windows\RTHDCPL.EXE [16861184 2008-04-10] (Realtek Semiconductor Corp.)
HKLM\...\Run: [avgnt] - C:\Programme\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-03] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [Adobe ARM] - C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Programme\Java\jre1.6.0_03\bin\jusched.exe [132496 2007-09-25] (Sun Microsystems, Inc.)
Winlogon\Notify\WgaLogon: WgaLogon.dll (Microsoft Corporation)
HKCU\...\Winlogon: [Shell] explorer.exe <==== ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {336E8C83-A81D-413C-B0E2-3BDABBF43A22} URL = hxxp://www.google.de/search?q={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
SearchScopes: HKCU - {336E8C83-A81D-413C-B0E2-3BDABBF43A22} URL = hxxp://www.google.de/search?q={searchTerms}
SearchScopes: HKCU - {5D064C52-C18F-421B-925F-305C059B4A87} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=2a713c7e-1794-4266-a829-babd29538c2e&apn_sauid=DF68BF3F-55F4-4D70-A54A-33D4160D16D3
BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU -&Adresse - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\System32\browseui.dll (Microsoft Corporation)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ipp - No CLSID Value -
Handler: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\System32\msvidctl.dll (Microsoft Corporation)
Handler: msdaipp - No CLSID Value -
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\alkm4gsh.default
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.17.2 - C:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Programme\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Programme\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Programme\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: Default - C:\Programme\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
========================== Services (Whitelisted) =================
R2 AAV UpdateService; C:\Programme\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
R2 AntiVirSchedulerService; C:\Programme\Avira\AntiVir Desktop\sched.exe [84024 2013-07-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Programme\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-03] (Avira Operations GmbH & Co. KG)
R2 Brother XP spl Service; C:\WINDOWS\System32\brsvc01a.exe [57344 2002-04-12] (brother Industries Ltd)
S2 gupdate; C:\Programme\Google\Update\GoogleUpdate.exe [116648 2012-07-17] (Google Inc.)
S3 gupdatem; C:\Programme\Google\Update\GoogleUpdate.exe [116648 2012-07-17] (Google Inc.)
S2 HitmanProScheduler; C:\Programme\HitmanPro\hmpsched.exe [106280 2013-08-28] (SurfRight B.V.)
R2 MotoHelper; C:\Programme\Motorola\MotoHelper\MotoHelperService.exe [202048 2010-09-07] ()
R2 RppClientService; C:\Programme\Eltima Software\Recover PDF Password\agent\RPPc.exe [687104 2012-04-20] (Eltima Software)
S3 WMPNetworkSvc; C:\Programme\Windows Media Player\WMPNetwk.exe [920576 2006-10-24] (Microsoft Corporation)
R2 JavaQuickStarterService; "C:\Programme\Java\jre7\bin\jqs.exe" -service -config "C:\Programme\Java\jre7\lib\deploy\jqs\jqs.conf" [x]
==================== Drivers (Whitelisted) ====================
R1 AmdK8; C:\Windows\System32\DRIVERS\AmdK8.sys [43520 2006-07-01] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-04-05] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-04-05] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-04-05] (Avira Operations GmbH & Co. KG)
S3 basic2; C:\Windows\System32\DRIVERS\HSF_BSC2.sys [67167 2001-08-17] (Conexant)
R3 BrScnUsb; C:\Windows\System32\Drivers\BrScnUsb.sys [15295 2004-10-15] (Brother Industries Ltd.)
R2 Fallback; C:\Windows\System32\DRIVERS\HSF_FALL.sys [289887 2001-08-17] (Conexant)
R2 Fsks; C:\Windows\System32\DRIVERS\HSF_FSKS.sys [115807 2001-08-17] (Conexant)
S3 HSFHWBS2; C:\Windows\System32\DRIVERS\HSFBS2S2.sys [220032 2004-08-04] (Conexant Systems, Inc.)
S3 HSF_DP; C:\Windows\System32\DRIVERS\HSFDPSP2.sys [1041536 2004-08-04] (Conexant Systems, Inc.)
S3 hsf_msft; C:\Windows\System32\DRIVERS\HSF_MSFT.sys [542879 2001-08-17] (Conexant)
R2 K56; C:\Windows\System32\DRIVERS\HSF_K56K.sys [391199 2001-08-17] (Conexant)
S3 ms_mpu401; C:\Windows\System32\drivers\msmpu401.sys [2944 2001-08-17] (Microsoft Corporation)
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [14736 2009-05-09] (Microsoft Corporation)
S3 nv4; C:\Windows\System32\DRIVERS\nv4.sys [731648 2001-08-17] (NVIDIA Corporation)
S3 nvax; C:\Windows\System32\drivers\nvax.sys [13056 2003-06-02] (NVIDIA Corporation)
S3 NVENET; C:\Windows\System32\DRIVERS\NVENET.sys [80896 2003-06-02] (NVIDIA Corporation)
R3 NVENETFD; C:\Windows\System32\DRIVERS\NVENETFD.sys [54016 2008-01-29] (NVIDIA Corporation)
R0 nvgts; C:\Windows\System32\DRIVERS\nvgts.sys [132096 2008-01-25] (NVIDIA Corporation)
R3 nvnetbus; C:\Windows\System32\DRIVERS\nvnetbus.sys [22016 2008-01-29] (NVIDIA Corporation)
S3 nvnforce; C:\Windows\System32\drivers\nvapu.sys [241664 2003-06-02] (NVIDIA Corporation)
R0 nv_agp; C:\Windows\System32\DRIVERS\nv_agp.sys [18688 2003-06-02] (NVIDIA Corporation)
S3 Rksample; C:\Windows\System32\DRIVERS\HSF_SAMP.sys [57471 2001-08-17] (Conexant)
R3 RT73; C:\Windows\System32\DRIVERS\rt73.sys [245504 2005-11-04] (Ralink Technology, Corp.)
S3 rtl8139; C:\Windows\System32\DRIVERS\RTL8139.SYS [20992 2004-08-04] (Realtek Semiconductor Corporation)
R2 SoftFax; C:\Windows\System32\DRIVERS\HSF_FAXX.sys [199711 2001-08-17] (Conexant)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [466008 2013-06-24] (Duplex Secure Ltd.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-04-05] (Avira GmbH)
R2 Tones; C:\Windows\System32\DRIVERS\HSF_TONE.sys [50751 2001-08-17] (Conexant)
R2 V124; C:\Windows\System32\DRIVERS\HSF_V124.sys [488383 2001-08-17] (Conexant)
S3 winachsf; C:\Windows\System32\DRIVERS\HSFCXTS2.sys [685056 2004-08-04] (Conexant Systems, Inc.)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS [x]
S4 hpt3xx; No ImagePath
S4 IntelIde; No ImagePath
S3 MSICPL; \??\E:\install4\MSICPL.sys [x]
S3 NTACCESS; \??\E:\NTACCESS.sys [x]
S3 SetupNTGLM7X; \??\E:\NTGLM7X.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-28 22:28 - 2013-08-28 22:28 - 00012181 _____ C:\ComboFix.txt
2013-08-28 22:23 - 2013-08-28 22:23 - 00008192 ____H C:\WINDOWS\system32\config\SECURITY.tmp.LOG
2013-08-28 22:23 - 2013-08-28 22:23 - 00000000 ____H C:\WINDOWS\system32\config\system.tmp.LOG
2013-08-28 22:23 - 2013-08-28 22:23 - 00000000 ____H C:\WINDOWS\system32\config\software.tmp.LOG
2013-08-28 22:23 - 2013-08-28 22:23 - 00000000 ____H C:\WINDOWS\system32\config\SAM.tmp.LOG
2013-08-28 22:23 - 2013-08-28 22:23 - 00000000 ____H C:\WINDOWS\system32\config\default.tmp.LOG
2013-08-28 22:15 - 2013-08-28 22:15 - 00000000 _RSHD C:\cmdcons
2013-08-28 22:15 - 2013-08-28 21:59 - 00000223 _____ C:\Boot.bak
2013-08-28 22:15 - 2004-08-03 23:00 - 00262448 __RSH C:\cmldr
2013-08-28 22:13 - 2013-08-28 22:28 - 00000000 ____D C:\ComboFix
2013-08-28 22:13 - 2011-06-26 08:45 - 00256000 _____ C:\WINDOWS\PEV.exe
2013-08-28 22:13 - 2010-11-07 19:20 - 00208896 _____ C:\WINDOWS\MBR.exe
2013-08-28 22:13 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe
2013-08-28 22:13 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe
2013-08-28 22:13 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe
2013-08-28 22:13 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe
2013-08-28 22:13 - 2000-08-31 02:00 - 00098816 _____ C:\WINDOWS\sed.exe
2013-08-28 22:13 - 2000-08-31 02:00 - 00080412 _____ C:\WINDOWS\grep.exe
2013-08-28 22:13 - 2000-08-31 02:00 - 00068096 _____ C:\WINDOWS\zip.exe
2013-08-28 21:58 - 2013-08-28 21:59 - 00000000 ____D C:\WINDOWS\pss
2013-08-28 20:54 - 2013-08-28 22:28 - 00000000 ____D C:\WINDOWS\erdnt
2013-08-28 20:54 - 2013-08-28 22:28 - 00000000 ____D C:\Qoobox
2013-08-28 20:54 - 2013-08-28 20:54 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme\Verwaltung
2013-08-28 20:35 - 2013-08-28 20:54 - 05114728 ____R (Swearware) C:\Dokumente und Einstellungen\Administrator\Desktop\ComboFix.exe
2013-08-28 12:59 - 2013-08-28 12:59 - 00004340 _____ C:\WINDOWS\KB2834904-v2.log
2013-08-28 12:59 - 2013-08-28 12:59 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
2013-08-28 12:52 - 2013-08-28 12:53 - 00000000 ____D C:\AdwCleaner
2013-08-28 12:51 - 2013-08-28 12:52 - 00994642 _____ C:\Dokumente und Einstellungen\Administrator\Desktop\adwcleaner.exe
2013-08-26 21:45 - 2013-08-26 21:45 - 00033446 _____ C:\Dokumente und Einstellungen\Administrator\Desktop\Addition.txt
2013-08-26 21:44 - 2013-08-26 21:44 - 00000000 ____D C:\FRST
2013-08-25 15:55 - 2013-08-25 15:55 - 00001594 _____ C:\Dokumente und Einstellungen\All Users\Desktop\HitmanPro.lnk
2013-08-25 15:55 - 2013-08-25 15:55 - 00000000 ____D C:\Programme\HitmanPro
2013-08-23 19:47 - 2013-08-23 19:47 - 00861088 _____ (Oracle Corporation) C:\WINDOWS\system32\npDeployJava1.dll
2013-08-23 19:47 - 2013-08-23 19:47 - 00782240 _____ (Oracle Corporation) C:\WINDOWS\system32\deployJava1.dll
2013-08-23 19:47 - 2013-08-23 19:47 - 00262560 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2013-08-23 19:47 - 2013-08-23 19:47 - 00174496 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2013-08-23 19:47 - 2013-08-23 19:47 - 00174496 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2013-08-23 19:47 - 2013-08-23 19:47 - 00094112 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2013-08-23 19:44 - 2013-08-23 19:44 - 00001714 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader XI.lnk
2013-08-23 19:28 - 2013-08-23 19:28 - 00002872 _____ C:\WINDOWS\system32\.crusader
2013-08-14 09:27 - 2013-08-14 09:27 - 00012018 _____ C:\WINDOWS\KB2862772-IE8.log
2013-08-14 09:25 - 2013-08-14 09:25 - 00005335 _____ C:\WINDOWS\KB2863058.log
2013-08-14 09:25 - 2013-08-14 09:25 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$
2013-08-14 09:25 - 2013-08-14 09:25 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$
2013-08-14 09:25 - 2013-08-14 09:25 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$
2013-08-14 09:24 - 2013-08-14 09:24 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$
2013-08-14 08:49 - 2013-08-14 09:25 - 00009524 _____ C:\WINDOWS\KB2850869.log
2013-08-14 08:48 - 2013-08-14 09:25 - 00011041 _____ C:\WINDOWS\KB2859537.log
==================== One Month Modified Files and Folders =======
2013-08-28 22:44 - 2012-07-17 11:03 - 00001100 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-28 22:44 - 2007-08-27 19:31 - 01832459 _____ C:\WINDOWS\WindowsUpdate.log
2013-08-28 22:44 - 2007-08-11 18:48 - 00000259 _____ C:\WINDOWS\wiadebug.log
2013-08-28 22:44 - 2007-08-11 18:48 - 00000050 _____ C:\WINDOWS\wiaservc.log
2013-08-28 22:44 - 2007-08-11 18:10 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-08-28 22:44 - 2001-08-23 14:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2013-08-28 22:42 - 2007-08-11 18:18 - 00032536 _____ C:\WINDOWS\SchedLgU.Txt
2013-08-28 22:42 - 2007-08-11 18:18 - 00000300 ___SH C:\Dokumente und Einstellungen\Administrator\ntuser.ini
2013-08-28 22:42 - 2007-08-11 18:18 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator
2013-08-28 22:38 - 2007-08-11 19:17 - 00000339 __RSH C:\boot.ini
2013-08-28 22:38 - 2001-08-23 14:00 - 00000629 _____ C:\WINDOWS\win.ini
2013-08-28 22:38 - 2001-08-23 14:00 - 00000227 _____ C:\WINDOWS\system.ini
2013-08-28 22:33 - 2012-07-17 11:03 - 00001104 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-28 22:28 - 2013-08-28 22:28 - 00012181 _____ C:\ComboFix.txt
2013-08-28 22:28 - 2013-08-28 22:13 - 00000000 ____D C:\ComboFix
2013-08-28 22:28 - 2013-08-28 20:54 - 00000000 ____D C:\WINDOWS\erdnt
2013-08-28 22:28 - 2013-08-28 20:54 - 00000000 ____D C:\Qoobox
2013-08-28 22:23 - 2013-08-28 22:23 - 00008192 ____H C:\WINDOWS\system32\config\SECURITY.tmp.LOG
2013-08-28 22:23 - 2013-08-28 22:23 - 00000000 ____H C:\WINDOWS\system32\config\system.tmp.LOG
2013-08-28 22:23 - 2013-08-28 22:23 - 00000000 ____H C:\WINDOWS\system32\config\software.tmp.LOG
2013-08-28 22:23 - 2013-08-28 22:23 - 00000000 ____H C:\WINDOWS\system32\config\SAM.tmp.LOG
2013-08-28 22:23 - 2013-08-28 22:23 - 00000000 ____H C:\WINDOWS\system32\config\default.tmp.LOG
2013-08-28 22:23 - 2007-08-11 19:16 - 22282240 _____ C:\WINDOWS\system32\config\software.bak
2013-08-28 22:23 - 2007-08-11 19:16 - 07340032 _____ C:\WINDOWS\system32\config\system.bak
2013-08-28 22:23 - 2007-08-11 19:16 - 00524288 _____ C:\WINDOWS\system32\config\default.bak
2013-08-28 22:23 - 2007-08-11 18:45 - 00045056 _____ C:\WINDOWS\system32\config\SECURITY.bak
2013-08-28 22:23 - 2007-08-11 18:45 - 00024576 _____ C:\WINDOWS\system32\config\SAM.bak
2013-08-28 22:15 - 2013-08-28 22:15 - 00000000 _RSHD C:\cmdcons
2013-08-28 21:59 - 2013-08-28 22:15 - 00000223 _____ C:\Boot.bak
2013-08-28 21:59 - 2013-08-28 21:58 - 00000000 ____D C:\WINDOWS\pss
2013-08-28 20:54 - 2013-08-28 20:54 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme\Verwaltung
2013-08-28 20:54 - 2013-08-28 20:35 - 05114728 ____R (Swearware) C:\Dokumente und Einstellungen\Administrator\Desktop\ComboFix.exe
2013-08-28 20:54 - 2007-08-11 18:18 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator\Startmenü\Programme
2013-08-28 12:59 - 2013-08-28 12:59 - 00004340 _____ C:\WINDOWS\KB2834904-v2.log
2013-08-28 12:59 - 2013-08-28 12:59 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
2013-08-28 12:59 - 2007-08-27 22:46 - 00197449 _____ C:\WINDOWS\medctroc.Log
2013-08-28 12:59 - 2007-08-11 19:45 - 00560911 _____ C:\WINDOWS\netfxocm.log
2013-08-28 12:59 - 2007-08-11 19:45 - 00161085 _____ C:\WINDOWS\tabletoc.log
2013-08-28 12:59 - 2007-08-11 18:46 - 03211869 _____ C:\WINDOWS\FaxSetup.log
2013-08-28 12:59 - 2007-08-11 18:46 - 01561825 _____ C:\WINDOWS\ocgen.log
2013-08-28 12:59 - 2007-08-11 18:46 - 01516611 _____ C:\WINDOWS\iis6.log
2013-08-28 12:59 - 2007-08-11 18:46 - 01474897 _____ C:\WINDOWS\tsoc.log
2013-08-28 12:59 - 2007-08-11 18:46 - 00991384 _____ C:\WINDOWS\msmqinst.log
2013-08-28 12:59 - 2007-08-11 18:46 - 00959828 _____ C:\WINDOWS\comsetup.log
2013-08-28 12:59 - 2007-08-11 18:46 - 00581158 _____ C:\WINDOWS\ntdtcsetup.log
2013-08-28 12:59 - 2007-08-11 18:46 - 00160831 _____ C:\WINDOWS\msgsocm.log
2013-08-28 12:59 - 2007-08-11 18:46 - 00150555 _____ C:\WINDOWS\ocmsn.log
2013-08-28 12:59 - 2007-08-11 18:46 - 00001374 _____ C:\WINDOWS\imsins.log
2013-08-28 12:53 - 2013-08-28 12:52 - 00000000 ____D C:\AdwCleaner
2013-08-28 12:52 - 2013-08-28 12:51 - 00994642 _____ C:\Dokumente und Einstellungen\Administrator\Desktop\adwcleaner.exe
2013-08-28 12:52 - 2007-08-11 18:46 - 00000000 ___RD C:\Programme
2013-08-28 06:54 - 2012-03-01 00:20 - 00000434 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{9983DE20-63FA-4786-BC4C-D0B6DD06C7CE}.job
2013-08-26 21:45 - 2013-08-26 21:45 - 00033446 _____ C:\Dokumente und Einstellungen\Administrator\Desktop\Addition.txt
2013-08-26 21:44 - 2013-08-26 21:44 - 00000000 ____D C:\FRST
2013-08-26 19:05 - 2007-08-27 19:35 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Adobe
2013-08-25 15:55 - 2013-08-25 15:55 - 00001594 _____ C:\Dokumente und Einstellungen\All Users\Desktop\HitmanPro.lnk
2013-08-25 15:55 - 2013-08-25 15:55 - 00000000 ____D C:\Programme\HitmanPro
2013-08-23 19:47 - 2013-08-23 19:47 - 00861088 _____ (Oracle Corporation) C:\WINDOWS\system32\npDeployJava1.dll
2013-08-23 19:47 - 2013-08-23 19:47 - 00782240 _____ (Oracle Corporation) C:\WINDOWS\system32\deployJava1.dll
2013-08-23 19:47 - 2013-08-23 19:47 - 00262560 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2013-08-23 19:47 - 2013-08-23 19:47 - 00174496 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2013-08-23 19:47 - 2013-08-23 19:47 - 00174496 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2013-08-23 19:47 - 2013-08-23 19:47 - 00094112 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2013-08-23 19:47 - 2007-10-03 13:40 - 00143872 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2013-08-23 19:47 - 2007-10-03 13:40 - 00000000 ____D C:\Programme\Java
2013-08-23 19:45 - 2007-08-27 19:35 - 00000000 ____D C:\Programme\Gemeinsame Dateien\Adobe
2013-08-23 19:44 - 2013-08-23 19:44 - 00001714 _____ C:\Dokumente und Einstellungen\All Users\Desktop\Adobe Reader XI.lnk
2013-08-23 19:44 - 2007-08-27 19:35 - 00000000 ____D C:\Programme\Adobe
2013-08-23 19:28 - 2013-08-23 19:28 - 00002872 _____ C:\WINDOWS\system32\.crusader
2013-08-16 17:09 - 2007-08-11 18:08 - 00000000 ____D C:\Programme\Outlook Express
2013-08-14 09:27 - 2013-08-14 09:27 - 00012018 _____ C:\WINDOWS\KB2862772-IE8.log
2013-08-14 09:27 - 2013-07-23 09:34 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-08-14 09:27 - 2009-06-21 10:53 - 00000000 ____D C:\WINDOWS\ie8updates
2013-08-14 09:27 - 2007-08-27 21:34 - 00467138 _____ C:\WINDOWS\updspapi.log
2013-08-14 09:27 - 2007-08-11 18:46 - 00001374 _____ C:\WINDOWS\imsins.BAK
2013-08-14 09:25 - 2013-08-14 09:25 - 00005335 _____ C:\WINDOWS\KB2863058.log
2013-08-14 09:25 - 2013-08-14 09:25 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$
2013-08-14 09:25 - 2013-08-14 09:25 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$
2013-08-14 09:25 - 2013-08-14 09:25 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$
2013-08-14 09:25 - 2013-08-14 08:49 - 00009524 _____ C:\WINDOWS\KB2850869.log
2013-08-14 09:25 - 2013-08-14 08:48 - 00011041 _____ C:\WINDOWS\KB2859537.log
2013-08-14 09:25 - 2007-08-29 19:56 - 00766156 _____ C:\WINDOWS\system32\TZLog.log
2013-08-14 09:25 - 2007-08-27 21:39 - 75778376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-08-14 09:24 - 2013-08-14 09:24 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$
2013-08-06 14:35 - 2012-07-17 11:03 - 00000000 ____D C:\Programme\Google
2013-08-03 01:48 - 2006-10-18 22:47 - 01543680 ____N (Microsoft Corporation) C:\WINDOWS\system32\wmvdecod.dll
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2007-08-11 19:43] - [2008-04-14 04:22] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e
C:\Windows\System32\winlogon.exe
[2001-08-23 14:00] - [2008-04-14 04:23] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a
C:\Windows\System32\svchost.exe
[2001-08-23 14:00] - [2008-04-14 04:23] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366
C:\Windows\System32\services.exe
[2001-08-23 14:00] - [2009-02-09 13:21] - 0111104 ____A (Microsoft Corporation) a3edbe9053889fb24ab22492472b39dc
C:\Windows\System32\User32.dll
[2001-08-23 14:00] - [2008-04-14 04:22] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd
C:\Windows\System32\userinit.exe
[2001-08-23 14:00] - [2008-04-14 04:23] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106
C:\Windows\System32\Drivers\volsnap.sys
[2001-08-23 14:00] - [2008-04-14 03:52] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
So, Leo, ich weiß, man soll keine Romane schreiben und du hast ja auch massig zu tun hier, aber ich muss nochmal was zum Combofixdings los werden, das hat mich nämlich fix und alle gemacht:
Combofix hat mich gefühlte zehnmal aufgefordert, Antivir doch nun endlich zu deaktivieren, obwohl ich nach stundenlangem Surfen schon alles erdenkliche ausprobiert hatte. Du bist nicht online gewesen (kein Vorwurf!!!! - du bist ja sooft online, dass ich mich schon frage, ob das mit beruf und Privatleben überhaupt vereinbat ist!!!) und da hab ich aus einer Korrespondenz von cosinus mit einem anderen Hilfesuchenden beschlossen, das Gemecker von CF zu ignorieren...
Hatte bis zu diesem Zeitpunkt folgendes getan:
Echtzeitscanner aus - Schirmchen zu, aber das bedeutet ja noch lange nicht, dass Antivir wirklich aus ist, gell?
"Ich hatte den Echtzeit-Scanner aus und das Antivir-Schirmchen war geschlossen, das bedeutet doch deaktiviert, oder?"
Das hatte ich dich schon am Sonntag im Beitrag #22 gefragt. Du hattest zu seiner Zeit darauf nicht geantwortet, wofür ich bei meiner ständigen Fragerei von unqualifiziertem Zeugs absolutes Vertsändnis aufbringe
(kann es übrigens sein, dass der ESET Onlinescan gar nicht richtig funktioniert hat, wenn Antivir gar nicht richtig deaktiviert war?),
nur jetzt weiß ich, dass "Schirmchen zu" erst der Auftakt ist...
Also hab dann unter Konfiguration (bei Antivir selbst) noch alles zum Produktschutz und zum Sytemschutz "wegehakt" und dann noch nach Suche von "msconfig" beide Avira-Prozesse deaktiviert. Nur, damit du weißt, unter welchen Umständen die Combofix-Logdatei entstanden ist. Sorry für diesen Redeschwall!!!!!
Habe Backup vorher veranlasst und hinter die Ohren des Besitzers geschrieben... ;)
Schmeißt du mich jetzt aus dem Forum?
Gute Nacht,
Lexi |