webmaster128 | 21.01.2014 12:49 | Hi,
hier ist die ComboFix.txt Code:
ComboFix 14-01-16.03 - user 21.01.2014 10:18:48.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.49.1031.18.2047.1275 [GMT 1:00]
ausgeführt von:: c:\dokumente und einstellungen\user\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Outdated* {11638345-E4FC-4BEE-BB73-EC754659C5F6}
FW: FireWall *Enabled* {11638345-E4FC-4BEE-BB73-EC754659C5F6}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\dokumente und einstellungen\user\WINDOWS
c:\windows\IsUn0407.exe
c:\windows\iun6002.exe
c:\windows\system32\OLD115.tmp
c:\windows\system32\OLD118.tmp
c:\windows\system32\SET187.tmp
c:\windows\system32\SET18B.tmp
c:\windows\system32\SET193.tmp
c:\windows\system32\Settings
c:\windows\system32\Settings\Settings.ini
c:\windows\system32\winlogon.bak
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-12-21 bis 2014-01-21 ))))))))))))))))))))))))))))))
.
.
2014-01-20 12:23 . 2014-01-20 12:23 -------- dc----w- C:\FRST
2014-01-20 10:28 . 2014-01-20 11:47 104664 -c--a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-01-20 10:26 . 2014-01-20 11:46 51416 -c--a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-01-19 00:49 . 2014-01-19 00:49 -------- dc----w- c:\dokumente und einstellungen\user\Lokale Einstellungen\Anwendungsdaten\Freetec
2014-01-12 10:57 . 2014-01-12 10:57 -------- dc----w- c:\dokumente und einstellungen\user\Lokale Einstellungen\Anwendungsdaten\PDF24
2014-01-12 10:56 . 2014-01-12 10:57 -------- dc----w- c:\programme\PDF24
2014-01-05 19:08 . 2014-01-05 19:08 -------- dc----w- c:\dokumente und einstellungen\user\.cache
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-10 20:58 . 2012-05-08 11:24 692616 -c--a-w- c:\windows\system32\FlashPlayerApp.exe
2013-12-10 20:58 . 2011-12-15 07:45 71048 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2012-02-08 00:49 22376 ----a-w- c:\programme\Internet Download Manager\IDMShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\programme\Gemeinsame Dateien\LightScribe\LightScribeControlPanel.exe" [2009-06-17 2363392]
"icq"="c:\dokumente und einstellungen\user\Anwendungsdaten\ICQM\icq.exe" [2013-10-26 29919576]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AccelerometerSysTrayApplet"="c:\windows\system32\AccelerometerSt.exe" [2007-01-24 124928]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-03-13 141336]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-03-13 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-03-13 142360]
"IAAnotif"="c:\programme\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"QlbCtrl.exe"="c:\programme\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2010-02-25 287800]
"SynTPEnh"="c:\programme\Synaptics\SynTP\SynTPEnh.exe" [2010-06-03 1791272]
"SoundMAXPnP"="c:\programme\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448]
"acevents"="c:\programme\ActivIdentity\ActivClient\acevents.exe" [2009-06-03 153640]
"accrdsub"="c:\programme\ActivIdentity\ActivClient\accrdsub.exe" [2009-06-03 400936]
"WatcherHelper"="c:\program files\HPQ\HP Connection Manager\WaHelper.exe" [2007-07-24 120352]
"hpWirelessAssistant"="c:\programme\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"StartCCC"="c:\programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-12-07 61440]
"IntelZeroConfig"="c:\programme\Intel\WiFi\bin\ZCfgSvc.exe" [2010-07-19 1400832]
"IntelWireless"="c:\programme\Gemeinsame Dateien\Intel\WirelessCommon\iFrmewrk.exe" [2010-07-19 1206544]
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"DivXUpdate"="c:\programme\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"SSBkgdUpdate"="c:\programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\programme\ScanSoft\PaperPort\pptd40nt.exe" [2008-07-09 29984]
"IndexSearch"="c:\programme\ScanSoft\PaperPort\IndexSearch.exe" [2008-07-09 46368]
"PPort11reminder"="c:\programme\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"BrMfcWnd"="c:\programme\Brother\Brmfcmon\BrMfcWnd.exe" [2009-01-19 1150976]
"ControlCenter3"="c:\programme\Brother\ControlCenter3\brctrcen.exe" [2009-01-09 114688]
"avgnt"="c:\programme\Avira\AntiVir Desktop\avgnt.exe" [2013-06-02 345312]
"LWS"="c:\programme\Logitech\LWS\Webcam Software\LWS.exe" [2012-09-12 204136]
"PDFPrint"="c:\programme\PDF24\pdf24.exe" [2013-12-12 186408]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\GEMEIN~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
.
c:\dokumente und einstellungen\user\Startmenü\Programme\Autostart\
Adobe Gamma.lnk - c:\programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
.
c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\
BTTray.lnk - c:\programme\WIDCOMM\Bluetooth Software\BTTray.exe [2007-12-6 576104]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ackpbsc]
2009-06-03 15:14 113152 ----a-w- c:\programme\ActivIdentity\ActivClient\ackpbsc.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\acunlock]
2009-06-03 15:13 299520 ----a-w- c:\programme\ActivIdentity\ActivClient\acunlock.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HPQ\\HP Connection Manager\\SwiApiMux.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\xampp\\apache\\bin\\httpd.exe"=
"c:\\WINDOWS\\system32\\muzapp.exe"=
"c:\\Dokumente und Einstellungen\\user\\Anwendungsdaten\\ICQM\\icq.exe"=
"c:\\Programme\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:War Thunder
"20010:UDP"= 20010:UDP:War Thunder
"3478:UDP"= 3478:UDP:War Thunder
"7850:TCP"= 7850:TCP:War Thunder
"27022:TCP"= 27022:TCP:War Thunder
"6881:TCP"= 6881:TCP:War Thunder
"33333:TCP"= 33333:TCP:War Thunder
"20443:TCP"= 20443:TCP:War Thunder
"8090:TCP"= 8090:TCP:War Thunder
.
R1 avfwot;avfwot;c:\windows\system32\drivers\avfwot.sys [02.06.2013 14:44 113024]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [02.06.2013 14:44 37352]
R1 IDMTDI;IDMTDI;c:\windows\system32\drivers\idmtdi.sys [23.04.2012 13:22 108448]
R2 ac.sharedstore;ActivIdentity Shared Store Service;c:\programme\Gemeinsame Dateien\ActivIdentity\ac.sharedstore.exe [03.06.2009 16:16 207400]
R2 AntiVirFirewallService;Avira FireWall;c:\programme\Avira\AntiVir Desktop\avfwsvc.exe [02.06.2013 14:44 657120]
R2 AntiVirMailService;Avira Email Schutz;c:\programme\Avira\AntiVir Desktop\avmailc.exe [02.06.2013 14:44 371768]
R2 AntiVirSchedulerService;Avira Planer;c:\programme\Avira\AntiVir Desktop\sched.exe [02.06.2013 14:44 86752]
R2 AntiVirWebService;Avira Browser-Schutz;c:\programme\Avira\AntiVir Desktop\avwebgrd.exe [02.06.2013 14:44 562744]
R2 Netzmanager Service;Netzmanager Infrastruktur Informationssystem Dienst;c:\programme\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [24.10.2011 08:53 2565632]
R2 SWIHPWMI;SWIHPWMI;c:\programme\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe [04.12.2006 16:13 292384]
R3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\drivers\avfwim.sys [02.06.2013 14:44 92448]
R3 Com4QLBEx;Com4QLBEx;c:\programme\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [16.03.2011 09:10 227896]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [23.07.2008 11:31 44800]
R3 NETwLx32; Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows XP 32-Bit;c:\windows\system32\drivers\NETwLx32.sys [09.12.2011 16:14 6607744]
R3 rismc32;RICOH Smart Card Reader;c:\windows\system32\drivers\rismc32.sys [09.12.2011 15:59 49152]
S2 SkypeUpdate;Skype Updater;c:\programme\Skype\Updater\Updater.exe [05.09.2013 09:34 171680]
S2 WinDefend;Windows Defender;c:\programme\Windows Defender\MsMpEng.exe [03.11.2006 18:19 13592]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [19.07.2012 19:05 64320]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\EagleXNt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [24.09.2012 18:53 112640]
S3 HP24X;HP PC Card Smart Card Reader;c:\windows\system32\drivers\HP24X.sys [17.07.2007 01:24 35072]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [16.10.2012 11:47 102656]
S3 scrswi;Sierra Wireless Smart Card Reader;c:\windows\system32\drivers\scrswi.sys [10.01.2008 16:59 44160]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [19.07.2012 19:05 179520]
S3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.);c:\windows\system32\drivers\ssudserd.sys [19.07.2012 19:05 179520]
S3 SWNC8U02;HP hs2300 MUX NDIS Driver (#02);c:\windows\system32\drivers\SWNC8U02.sys [31.01.2008 13:04 165248]
S3 SWUMX02;HP hs2300 USB MUX Driver (#02);c:\windows\system32\drivers\swumx02.sys [31.01.2008 13:05 142976]
S3 TelekomNM3;Telekom Netzmanager Packet Filter Driver;c:\programme\Netzmanager\NMInfraIS2\Driver\TelekomNM3.sys [16.09.2010 16:02 35040]
S3 XDva405;XDva405;\??\c:\windows\system32\XDva405.sys --> c:\windows\system32\XDva405.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 11:11 451872 -c--a-w- c:\programme\Gemeinsame Dateien\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-01-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-08 20:58]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.t-online.de/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = microsoft.com;windowsupdate.microsoft.com;v4.windowsupdate.microsoft.com;v5.windowsupdate.microsoft.com
uInternet Settings,ProxyServer = 0.0.0.0:80
IE: Download aller Links mit IDM - c:\programme\Internet Download Manager\IEGetAll.htm
IE: Download mit IDM - c:\programme\Internet Download Manager\IEExt.htm
IE: Senden an &Bluetooth-Gerät... - c:\programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Senden an Bluetooth - c:\programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -
LSP: c:\programme\Avira\AntiVir Desktop\avsda.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\dokumente und einstellungen\user\Anwendungsdaten\Mozilla\Firefox\Profiles\nkg8u3bh.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: network.proxy.ftp - 87.110.181.144
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - 87.110.181.144
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.http - localhost
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - 87.110.181.144
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - localhost
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 4
FF - ExtSQL: 2013-12-12 03:05; EFGLQA@78ETGYN-0W7FN789T87.COM; c:\dokumente und einstellungen\user\Anwendungsdaten\Mozilla\Firefox\Profiles\nkg8u3bh.default\extensions\EFGLQA@78ETGYN-0W7FN789T87.COM
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - (no file)
HKCU-Run-Badoo Desktop - c:\dokumente und einstellungen\All Users\Anwendungsdaten\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe
HKLM-Run-AirCardEnabler - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2014-01-21 10:26
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-796845957-527237240-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"??"=hex:8f,f1,3e,37,ba,cb,36,d5,bd,d0,75,76,b5,42,56,5e,f6,88,17,80,8b,5f,64,
19,fa,b5,40,6c,10,a1,02,fd,64,42,a8,a1,87,66,fc,1d,c2,3d,f3,d9,1a,d5,f4,51,\
"??"=hex:95,60,0c,0d,6a,e3,bf,88,82,41,f0,55,3d,eb,9c,8d
.
[HKEY_USERS\S-1-5-21-796845957-527237240-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:e8,18,a8,89,32,99,32,49,03,fb,2f,fc,01,ce,4c,e2,79,ed,2d,62,45,
2f,45,c2,3e,1b,1e,e1,d6,98,b1,39,98,af,6d,ad,09,16,b7,d3,26,ff,29,68,d5,3f,\
"rkeysecu"=hex:5f,6a,c6,2c,b8,4a,a4,57,26,73,0a,bc,72,5e,24,28
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{27ea5492-eb74-4144-a6d9-5801a319b5a3}]
@Denied: (Full) (Everyone)
"Model"=dword:000000b1
"Therad"=dword:00000014
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):ea,4c,ed,17,fb,6a,bc,0f,d9,c0,71,af,11,6a,a2,68,b8,05,cf,a6,10,
a5,a2,e8,f2,fd,25,6e,35,9f,9a,03,af,29,fa,d9,4f,d7,44,28,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6e18ff95-9dae-4dbc-b836-f3274dad4066}]
@Denied: (Full) (Everyone)
"Model"=dword:0000012d
"Therad"=dword:00000019
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):5f,1e,ac,b6,26,5f,4c,bb,bc,e5,3d,a0,0d,73,29,ad,c6,80,25,20,02,
47,1b,d1,2a,94,98,b8,b1,59,c6,b3,eb,0c,52,9d,33,4d,d6,b1,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(1312)
c:\programme\ActivIdentity\ActivClient\ackpbsc.dll
c:\programme\ActivIdentity\ActivClient\aclog.dll
c:\programme\ActivIdentity\ActivClient\accrypto.dll
c:\programme\ActivIdentity\ActivClient\ACLIBEAY.dll
c:\windows\system32\Ati2evxx.dll
c:\programme\ActivIdentity\ActivClient\acunlock.dll
c:\programme\ActivIdentity\ActivClient\aipingui.dll
c:\programme\ActivIdentity\ActivClient\acevtsub.dll
c:\programme\ActivIdentity\ActivClient\asphat32.dll
c:\programme\ActivIdentity\ActivClient\acerrmes.dll
c:\programme\ActivIdentity\ActivClient\aiwinext.dll
c:\programme\ActivIdentity\ActivClient\aspcom.dll
c:\programme\ActivIdentity\ActivClient\aicext.dll
c:\programme\ActivIdentity\ActivClient\Resources\acerrmrc.dll
c:\programme\ActivIdentity\ActivClient\Resources\asphatrc.dll
c:\programme\ActivIdentity\ActivClient\Resources\aipinguirc.dll
c:\programme\ActivIdentity\ActivClient\resources\acCobAPIrc.dll
c:\programme\ActivIdentity\ActivClient\resources\acCobAPIlrc.dll
c:\programme\ActivIdentity\ActivClient\Resources\acunlockrc.dll
.
- - - - - - - > 'lsass.exe'(1372)
c:\programme\Avira\AntiVir Desktop\avsda.dll
.
Zeit der Fertigstellung: 2014-01-21 10:36:22
ComboFix-quarantined-files.txt 2014-01-21 09:36
.
Vor Suchlauf: 14 Verzeichnis(se), 13.782.732.800 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 17.262.776.320 Bytes frei
.
WindowsXP-KB310994-SP2-Pro-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 65A203CB41C287A3C02DE9E0BD88F8C7
72B8CE41AF0DE751C946802B3ED844B4 Sry ich hatte die Firewall noch an. Hier ist nochmal die Combofix.txt Code:
ComboFix 14-01-16.03 - user 21.01.2014 12:27:32.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.49.1031.18.2047.1299 [GMT 1:00]
ausgeführt von:: c:\dokumente und einstellungen\user\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Outdated* {11638345-E4FC-4BEE-BB73-EC754659C5F6}
FW: FireWall *Disabled* {11638345-E4FC-4BEE-BB73-EC754659C5F6}
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-12-21 bis 2014-01-21 ))))))))))))))))))))))))))))))
.
.
2014-01-20 12:23 . 2014-01-20 12:23 -------- dc----w- C:\FRST
2014-01-20 10:28 . 2014-01-20 11:47 104664 -c--a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-01-20 10:26 . 2014-01-20 11:46 51416 -c--a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-01-19 00:49 . 2014-01-19 00:49 -------- dc----w- c:\dokumente und einstellungen\user\Lokale Einstellungen\Anwendungsdaten\Freetec
2014-01-12 10:57 . 2014-01-12 10:57 -------- dc----w- c:\dokumente und einstellungen\user\Lokale Einstellungen\Anwendungsdaten\PDF24
2014-01-12 10:56 . 2014-01-12 10:57 -------- dc----w- c:\programme\PDF24
2014-01-05 19:08 . 2014-01-05 19:08 -------- dc----w- c:\dokumente und einstellungen\user\.cache
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-10 20:58 . 2012-05-08 11:24 692616 -c--a-w- c:\windows\system32\FlashPlayerApp.exe
2013-12-10 20:58 . 2011-12-15 07:45 71048 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2012-02-08 00:49 22376 ----a-w- c:\programme\Internet Download Manager\IDMShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\programme\Gemeinsame Dateien\LightScribe\LightScribeControlPanel.exe" [2009-06-17 2363392]
"icq"="c:\dokumente und einstellungen\user\Anwendungsdaten\ICQM\icq.exe" [2013-10-26 29919576]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AccelerometerSysTrayApplet"="c:\windows\system32\AccelerometerSt.exe" [2007-01-24 124928]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-03-13 141336]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-03-13 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-03-13 142360]
"IAAnotif"="c:\programme\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"QlbCtrl.exe"="c:\programme\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2010-02-25 287800]
"SynTPEnh"="c:\programme\Synaptics\SynTP\SynTPEnh.exe" [2010-06-03 1791272]
"SoundMAXPnP"="c:\programme\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448]
"acevents"="c:\programme\ActivIdentity\ActivClient\acevents.exe" [2009-06-03 153640]
"accrdsub"="c:\programme\ActivIdentity\ActivClient\accrdsub.exe" [2009-06-03 400936]
"WatcherHelper"="c:\program files\HPQ\HP Connection Manager\WaHelper.exe" [2007-07-24 120352]
"hpWirelessAssistant"="c:\programme\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"StartCCC"="c:\programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-12-07 61440]
"IntelZeroConfig"="c:\programme\Intel\WiFi\bin\ZCfgSvc.exe" [2010-07-19 1400832]
"IntelWireless"="c:\programme\Gemeinsame Dateien\Intel\WirelessCommon\iFrmewrk.exe" [2010-07-19 1206544]
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"DivXUpdate"="c:\programme\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"SSBkgdUpdate"="c:\programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\programme\ScanSoft\PaperPort\pptd40nt.exe" [2008-07-09 29984]
"IndexSearch"="c:\programme\ScanSoft\PaperPort\IndexSearch.exe" [2008-07-09 46368]
"PPort11reminder"="c:\programme\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"BrMfcWnd"="c:\programme\Brother\Brmfcmon\BrMfcWnd.exe" [2009-01-19 1150976]
"ControlCenter3"="c:\programme\Brother\ControlCenter3\brctrcen.exe" [2009-01-09 114688]
"avgnt"="c:\programme\Avira\AntiVir Desktop\avgnt.exe" [2013-06-02 345312]
"LWS"="c:\programme\Logitech\LWS\Webcam Software\LWS.exe" [2012-09-12 204136]
"PDFPrint"="c:\programme\PDF24\pdf24.exe" [2013-12-12 186408]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\GEMEIN~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
.
c:\dokumente und einstellungen\user\Startmenü\Programme\Autostart\
Adobe Gamma.lnk - c:\programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
.
c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\
BTTray.lnk - c:\programme\WIDCOMM\Bluetooth Software\BTTray.exe [2007-12-6 576104]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ackpbsc]
2009-06-03 15:14 113152 ----a-w- c:\programme\ActivIdentity\ActivClient\ackpbsc.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\acunlock]
2009-06-03 15:13 299520 ----a-w- c:\programme\ActivIdentity\ActivClient\acunlock.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HPQ\\HP Connection Manager\\SwiApiMux.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\xampp\\apache\\bin\\httpd.exe"=
"c:\\WINDOWS\\system32\\muzapp.exe"=
"c:\\Dokumente und Einstellungen\\user\\Anwendungsdaten\\ICQM\\icq.exe"=
"c:\\Programme\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:War Thunder
"20010:UDP"= 20010:UDP:War Thunder
"3478:UDP"= 3478:UDP:War Thunder
"7850:TCP"= 7850:TCP:War Thunder
"27022:TCP"= 27022:TCP:War Thunder
"6881:TCP"= 6881:TCP:War Thunder
"33333:TCP"= 33333:TCP:War Thunder
"20443:TCP"= 20443:TCP:War Thunder
"8090:TCP"= 8090:TCP:War Thunder
.
R1 avfwot;avfwot;c:\windows\system32\drivers\avfwot.sys [02.06.2013 14:44 113024]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [02.06.2013 14:44 37352]
R1 IDMTDI;IDMTDI;c:\windows\system32\drivers\idmtdi.sys [23.04.2012 13:22 108448]
R2 ac.sharedstore;ActivIdentity Shared Store Service;c:\programme\Gemeinsame Dateien\ActivIdentity\ac.sharedstore.exe [03.06.2009 16:16 207400]
R2 AntiVirFirewallService;Avira FireWall;c:\programme\Avira\AntiVir Desktop\avfwsvc.exe [02.06.2013 14:44 657120]
R2 AntiVirMailService;Avira Email Schutz;c:\programme\Avira\AntiVir Desktop\avmailc.exe [02.06.2013 14:44 371768]
R2 AntiVirSchedulerService;Avira Planer;c:\programme\Avira\AntiVir Desktop\sched.exe [02.06.2013 14:44 86752]
R2 AntiVirWebService;Avira Browser-Schutz;c:\programme\Avira\AntiVir Desktop\avwebgrd.exe [02.06.2013 14:44 562744]
R2 Netzmanager Service;Netzmanager Infrastruktur Informationssystem Dienst;c:\programme\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [24.10.2011 08:53 2565632]
R2 SWIHPWMI;SWIHPWMI;c:\programme\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe [04.12.2006 16:13 292384]
R3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\drivers\avfwim.sys [02.06.2013 14:44 92448]
R3 Com4QLBEx;Com4QLBEx;c:\programme\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [16.03.2011 09:10 227896]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [23.07.2008 11:31 44800]
R3 NETwLx32; Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows XP 32-Bit;c:\windows\system32\drivers\NETwLx32.sys [09.12.2011 16:14 6607744]
R3 rismc32;RICOH Smart Card Reader;c:\windows\system32\drivers\rismc32.sys [09.12.2011 15:59 49152]
S2 SkypeUpdate;Skype Updater;c:\programme\Skype\Updater\Updater.exe [05.09.2013 09:34 171680]
S2 WinDefend;Windows Defender;c:\programme\Windows Defender\MsMpEng.exe [03.11.2006 18:19 13592]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [19.07.2012 19:05 64320]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\EagleXNt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [24.09.2012 18:53 112640]
S3 HP24X;HP PC Card Smart Card Reader;c:\windows\system32\drivers\HP24X.sys [17.07.2007 01:24 35072]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [16.10.2012 11:47 102656]
S3 scrswi;Sierra Wireless Smart Card Reader;c:\windows\system32\drivers\scrswi.sys [10.01.2008 16:59 44160]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [19.07.2012 19:05 179520]
S3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.);c:\windows\system32\drivers\ssudserd.sys [19.07.2012 19:05 179520]
S3 SWNC8U02;HP hs2300 MUX NDIS Driver (#02);c:\windows\system32\drivers\SWNC8U02.sys [31.01.2008 13:04 165248]
S3 SWUMX02;HP hs2300 USB MUX Driver (#02);c:\windows\system32\drivers\swumx02.sys [31.01.2008 13:05 142976]
S3 TelekomNM3;Telekom Netzmanager Packet Filter Driver;c:\programme\Netzmanager\NMInfraIS2\Driver\TelekomNM3.sys [16.09.2010 16:02 35040]
S3 XDva405;XDva405;\??\c:\windows\system32\XDva405.sys --> c:\windows\system32\XDva405.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 11:11 451872 -c--a-w- c:\programme\Gemeinsame Dateien\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-01-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-08 20:58]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.t-online.de/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = microsoft.com;windowsupdate.microsoft.com;v4.windowsupdate.microsoft.com;v5.windowsupdate.microsoft.com
uInternet Settings,ProxyServer = 0.0.0.0:80
IE: Download aller Links mit IDM - c:\programme\Internet Download Manager\IEGetAll.htm
IE: Download mit IDM - c:\programme\Internet Download Manager\IEExt.htm
IE: Senden an &Bluetooth-Gerät... - c:\programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Senden an Bluetooth - c:\programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: c:\programme\Avira\AntiVir Desktop\avsda.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\dokumente und einstellungen\user\Anwendungsdaten\Mozilla\Firefox\Profiles\nkg8u3bh.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: network.proxy.ftp - 87.110.181.144
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - 87.110.181.144
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.http - localhost
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - 87.110.181.144
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - localhost
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 4
FF - ExtSQL: 2013-12-12 03:05; EFGLQA@78ETGYN-0W7FN789T87.COM; c:\dokumente und einstellungen\user\Anwendungsdaten\Mozilla\Firefox\Profiles\nkg8u3bh.default\extensions\EFGLQA@78ETGYN-0W7FN789T87.COM
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2014-01-21 12:33
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-796845957-527237240-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"??"=hex:8f,f1,3e,37,ba,cb,36,d5,bd,d0,75,76,b5,42,56,5e,f6,88,17,80,8b,5f,64,
19,fa,b5,40,6c,10,a1,02,fd,64,42,a8,a1,87,66,fc,1d,c2,3d,f3,d9,1a,d5,f4,51,\
"??"=hex:95,60,0c,0d,6a,e3,bf,88,82,41,f0,55,3d,eb,9c,8d
.
[HKEY_USERS\S-1-5-21-796845957-527237240-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:e8,18,a8,89,32,99,32,49,03,fb,2f,fc,01,ce,4c,e2,79,ed,2d,62,45,
2f,45,c2,3e,1b,1e,e1,d6,98,b1,39,98,af,6d,ad,09,16,b7,d3,26,ff,29,68,d5,3f,\
"rkeysecu"=hex:5f,6a,c6,2c,b8,4a,a4,57,26,73,0a,bc,72,5e,24,28
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{27ea5492-eb74-4144-a6d9-5801a319b5a3}]
@Denied: (Full) (Everyone)
"Model"=dword:000000b1
"Therad"=dword:00000014
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):ea,4c,ed,17,fb,6a,bc,0f,d9,c0,71,af,11,6a,a2,68,b8,05,cf,a6,10,
a5,a2,e8,f2,fd,25,6e,35,9f,9a,03,af,29,fa,d9,4f,d7,44,28,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6e18ff95-9dae-4dbc-b836-f3274dad4066}]
@Denied: (Full) (Everyone)
"Model"=dword:0000012d
"Therad"=dword:00000019
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):5f,1e,ac,b6,26,5f,4c,bb,bc,e5,3d,a0,0d,73,29,ad,c6,80,25,20,02,
47,1b,d1,2a,94,98,b8,b1,59,c6,b3,eb,0c,52,9d,33,4d,d6,b1,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(1316)
c:\programme\ActivIdentity\ActivClient\ackpbsc.dll
c:\programme\ActivIdentity\ActivClient\aclog.dll
c:\programme\ActivIdentity\ActivClient\accrypto.dll
c:\programme\ActivIdentity\ActivClient\ACLIBEAY.dll
c:\windows\system32\Ati2evxx.dll
c:\programme\ActivIdentity\ActivClient\acunlock.dll
c:\programme\ActivIdentity\ActivClient\aipingui.dll
c:\programme\ActivIdentity\ActivClient\acevtsub.dll
c:\programme\ActivIdentity\ActivClient\asphat32.dll
c:\programme\ActivIdentity\ActivClient\acerrmes.dll
c:\programme\ActivIdentity\ActivClient\aiwinext.dll
c:\programme\ActivIdentity\ActivClient\aspcom.dll
c:\programme\ActivIdentity\ActivClient\aicext.dll
c:\programme\ActivIdentity\ActivClient\Resources\acerrmrc.dll
c:\programme\ActivIdentity\ActivClient\Resources\asphatrc.dll
c:\programme\ActivIdentity\ActivClient\Resources\aipinguirc.dll
c:\programme\ActivIdentity\ActivClient\resources\acCobAPIrc.dll
c:\programme\ActivIdentity\ActivClient\resources\acCobAPIlrc.dll
c:\programme\ActivIdentity\ActivClient\Resources\acunlockrc.dll
.
- - - - - - - > 'lsass.exe'(1372)
c:\programme\Avira\AntiVir Desktop\avsda.dll
.
- - - - - - - > 'explorer.exe'(3100)
c:\programme\Internet Download Manager\IDMShellExt.dll
c:\programme\Internet Download Manager\IDMNetMon.DLL
c:\windows\system32\btmmhook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Zeit der Fertigstellung: 2014-01-21 12:40:05
ComboFix-quarantined-files.txt 2014-01-21 11:40
.
Vor Suchlauf: 14 Verzeichnis(se), 17.211.527.168 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 17.240.428.544 Bytes frei
.
- - End Of File - - DDEE7BB1BFBF160AA58D6507BFED49BA
72B8CE41AF0DE751C946802B3ED844B4 |