Student1 | 23.06.2014 20:36 | Hallo Matthias!
vielen Dank für deine schnelle Antwort und das du mir helfen möchtest. Ich habe Combofix runtergeladen und ausgeführt. Dabei hat sich das Programm noch vor dem Scann zweimal beschwert das Avira an ist. Ich konnte Avira jedoch nich schließen da ich keinen Zugriff darauf habe.
hier die log file Code:
ComboFix 14-06-23.01 - Yamato 23.06.2014 20:31:08.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3068.1905 [GMT 2:00]
ausgeführt von:: c:\users\Yamato\Desktop\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\END
c:\program files\Acer\Acer Bio Protection\PwdFilter.dll
c:\programdata\l_u0_0.pad
c:\programdata\Roaming
c:\programdata\Roaming\Intel\Wireless\Settings\Settings.ini
c:\users\Yamato\4.0
c:\users\Yamato\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data
c:\users\Yamato\AppData\Local\Google\Chrome\User Data\Default\bProtectorPreferences
c:\users\Yamato\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage
c:\users\Yamato\AppData\Roaming\.#
c:\users\Yamato\AppData\Roaming\.#\MBX@1190@1DB2990.###
c:\users\Yamato\AppData\Roaming\.#\MBX@1190@1DB29C0.###
c:\users\Yamato\AppData\Roaming\.#\MBX@1190@1DB29F0.###
c:\windows\IsUn0407.exe
c:\windows\wininit.ini
D:\install.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-05-23 bis 2014-06-23 ))))))))))))))))))))))))))))))
.
.
2014-06-23 18:55 . 2014-06-23 18:55 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-06-22 10:15 . 2014-06-22 10:15 104960 ----a-w- C:\kfriapow.sys
2014-06-20 08:50 . 2014-06-05 10:54 8140904 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0F53892B-A395-4F19-97D2-B093ED2163AC}\mpengine.dll
2014-06-18 18:25 . 2014-06-20 17:34 -------- d-----w- C:\FRST
2014-06-18 08:42 . 2014-06-18 08:42 -------- d-----w- c:\programdata\30308
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-20 08:56 . 2013-02-24 12:42 93528 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2014-05-20 08:56 . 2013-02-24 12:42 136216 ----a-w- c:\windows\system32\drivers\avipbb.sys
2014-03-31 20:46 . 2014-03-31 20:46 130712 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2014-03-31 20:46 . 2014-03-31 20:46 1070232 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2014-03-31 07:35 . 2010-05-12 19:35 231584 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-07-29 16:52 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-26 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808]
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-07 6139904]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-04 1037608]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-21 30192]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-08-01 405504]
"eAudio"="c:\program files\Acer\Empowering Technology\eAudio\eAudio.exe" [2008-05-30 544768]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-07-29 526896]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-25 28672]
"ZPdtWzdVitaKey MC3000"="c:\program files\Acer\Acer Bio Protection\PdtWzd.exe" [2009-06-13 3719680]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-06-16 809480]
"Skytel"="Skytel.exe" [2007-11-20 1826816]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2516296]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2013-05-08 41056]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2012-03-08 884584]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2014-05-20 737872]
"DivXMediaServer"="c:\program files\DivX\DivX Media Server\DivXMediaServer.exe" [2013-05-20 450560]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2013-02-13 1263952]
"MapsGalaxy Search Scope Monitor"="c:\progra~1\MAPSGA~2\bar\1.bin\39srchmn.exe" [2013-08-10 44784]
"MapsGalaxy_39 Browser Plugin Loader"="c:\progra~1\MAPSGA~2\bar\1.bin\39brmon.exe" [2013-08-10 30096]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2009-6-13 1216512]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2009-06-13 07:02 3162624 ----a-w- c:\program files\Acer\Acer Bio Protection\WinNotify.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\google\google~1\goec62~1.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\Acer\Acer Bio Protection\PwdFilter
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - FSUSBEXDISK
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Inhalt des "geplante Tasks" Ordners
.
2013-06-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-02 21:30]
.
2013-06-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3122945756-3708475220-1533568220-1000Core.job
- c:\users\Yamato\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-30 19:40]
.
2013-06-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3122945756-3708475220-1533568220-1000UA.job
- c:\users\Yamato\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-30 19:40]
.
2014-05-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cf6bccb4935a90.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 01:58]
.
2013-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 01:58]
.
2014-06-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3122945756-3708475220-1533568220-1000Core1cf8eb53c017248.job
- c:\users\Yamato\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-23 10:22]
.
2013-06-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3122945756-3708475220-1533568220-1000UA.job
- c:\users\Yamato\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-23 10:22]
.
2013-06-23 c:\windows\Tasks\MATLAB R2011b Startup Accelerator.job
- c:\program files\MATLAB\R2011b\bin\win32\MATLABStartupAccelerator.exe [2011-12-10 14:36]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://google.de/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=0609&m=aspire_8930
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
Trusted Zone: uni-stuttgart.de\asa1.rus
Trusted Zone: vorhilfe.de
TCP: DhcpNameServer = 192.168.0.1
DPF: {CC679CB8-DC4B-458B-B817-D447B3B6AC31} - hxxps://asa1.rus.uni-stuttgart.de/CACHE/stc/10/binaries/vpnweb.cab
DPF: {E55FD215-A32E-43FE-A777-A7E8F165F560} - hxxp://92.51.137.94/objects/NpFv522.dll
DPF: {E55FD215-A32E-43FE-A777-A7E8F165F561} - hxxp://92.51.137.94/objects/NpFv530.dll
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - c:\program files\Ask.com\GenericAskToolbar.dll
Toolbar-10 - (no file)
HKCU-Run-Afifcoq - c:\users\Yamato\AppData\Roaming\Ikucy\ytgye.exe
HKCU-Run-OctoLzax - (no file)
HKCU-Run-UnfejOwirm - (no file)
HKLM-Run-eRecoveryService - (no file)
HKLM-Run-NPSStartup - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-WOLAPI - c:\westwood\Internet\UnstllAP.EXE
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2014-06-23 21:09
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3122945756-3708475220-1533568220-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:b2,c9,f9,29,ae,6b,68,87,4e,3e,78,56,8a,8d,89,23,33,da,c8,3a,7e,a6,81,
db,b7,30,04,16,0a,c9,ab,e6,9d,ae,1a,e8,75,2b,7b,09,1b,28,8d,ae,cf,d7,9d,eb,\
"??"=hex:d2,8a,3d,7f,d6,ee,ff,ab,38,51,7b,8c,dc,d7,d2,0c
.
[HKEY_USERS\S-1-5-21-3122945756-3708475220-1533568220-1000\Software\SecuROM\License information*]
"datasecu"=hex:4c,5c,1d,5a,58,f2,b4,be,77,3a,ec,76,8c,4c,e2,04,c3,02,cf,15,e5,
f2,a8,e1,b1,88,90,b8,f8,11,2b,07,7b,85,1a,6a,cd,a2,23,e4,0d,e2,00,af,f5,42,\
"rkeysecu"=hex:4a,a8,af,a9,40,d9,1e,8c,40,1e,c3,89,c6,52,15,08
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(3748)
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\vfsFPService.exe
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\WLANExt.exe
c:\program files\Acer\Acer Bio Protection\CompPtcVUI.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
c:\program files\Acer\Empowering Technology\Service\ETService.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\Windows Live\Family Safety\fsssvc.exe
c:\windows\system32\FsUsbExService.Exe
c:\program files\Acer\Acer Bio Protection\BASVC.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\progra~1\MAPSGA~2\bar\1.bin\39barsvc.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\Canon\Easy-WebPrint EX\NitroPDFReaderDriverService2.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\Acer\Acer VCM\RS_Service.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2014-06-23 21:13:00 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2014-06-23 19:12
.
Vor Suchlauf: 14 Verzeichnis(se), 51.143.147.520 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 54.987.845.632 Bytes frei
.
- - End Of File - - E2CCB489F972B4D15732669B0ECCC71D
BB9D3A6A13C5010348DA7C900BB6AF50 |