Hallo Schrauber :)
Vielen Dank für deine Hilfe!
Ich habe die Programme deinstalliert und ComboFix durchlaufen lassen.
Der Log ist nur zu groß zum senden. Soll ich ihn zippen und als Archiv anhängen?
Ich hoffe ich hab nun nichts falsch gemacht. Ich konnte den log Text des ersten ComboFix Durchlaufes nicht mehr finden und hab ComboFix nochmals gestartet. Das ist der neue Text:
Combofix Logfile: Code:
ComboFix 14-12-25.01 - Anna 28.12.2014 13:44:23.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.2046.1154 [GMT 1:00]
ausgeführt von:: c:\users\Anna\AppData\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
SP: Microsoft Security Essentials *Disabled/Updated* {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-11-28 bis 2014-12-28 ))))))))))))))))))))))))))))))
.
.
2014-12-28 12:54 . 2014-12-28 12:54 -------- d-----w- c:\users\Gast\AppData\Local\temp
2014-12-28 12:54 . 2014-12-28 12:54 -------- d-----w- c:\users\Gast.Anna-PC\AppData\Local\temp
2014-12-28 12:54 . 2014-12-28 12:54 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-12-28 08:49 . 2014-12-28 08:49 -------- d-----w- c:\program files\VS Revo Group
2014-12-27 19:24 . 2014-12-27 19:24 104960 ----a-w- C:\kwtdrpow.sys
2014-12-27 18:39 . 2014-12-27 18:45 -------- d-----w- C:\FRST
2014-12-26 12:47 . 2014-12-02 11:01 9054624 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-12-20 18:05 . 2014-12-21 10:27 -------- d-----w- c:\program files\Mozilla Thunderbird
2014-12-19 09:42 . 2014-09-16 19:49 908840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1068B2E3-C663-46F4-995C-CAB2476A7130}\gapaengine.dll
2014-12-10 22:44 . 2014-11-04 00:19 2048 ----a-w- c:\windows\system32\tzres.dll
2014-12-10 22:43 . 2014-11-07 01:33 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-12-10 22:34 . 2014-12-03 02:06 278528 ----a-w- c:\windows\system32\schannel.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-12-10 20:23 . 2012-07-31 09:50 701104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-12-10 20:23 . 2011-07-26 13:31 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-10-30 11:24 . 2009-10-09 09:39 229000 ------w- c:\windows\system32\MpSigStub.exe
2014-10-24 01:04 . 2014-11-12 09:59 67072 ----a-w- c:\windows\system32\packager.dll
2014-10-24 01:03 . 2014-11-19 22:13 499200 ----a-w- c:\windows\system32\kerberos.dll
2014-10-18 01:08 . 2014-11-12 09:57 564224 ----a-w- c:\windows\system32\oleaut32.dll
2014-10-12 23:34 . 2014-11-12 09:50 2054656 ----a-w- c:\windows\system32\win32k.sys
2014-10-10 01:01 . 2014-11-12 10:01 449536 ----a-w- c:\windows\system32\termsrv.dll
2014-10-10 01:00 . 2014-11-12 10:01 146432 ----a-w- c:\windows\system32\msaudite.dll
2014-10-10 01:00 . 2014-11-12 10:01 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2014-10-09 23:22 . 2014-11-12 10:01 619520 ----a-w- c:\windows\system32\adtschema.dll
2014-10-03 01:18 . 2014-11-12 09:57 274432 ----a-w- c:\windows\system32\AUDIOKSE.dll
2014-10-03 01:17 . 2014-11-12 09:57 170496 ----a-w- c:\windows\system32\EncDump.dll
2014-10-03 01:17 . 2014-11-12 09:57 396800 ----a-w- c:\windows\system32\AudioEng.dll
2014-10-03 01:17 . 2014-11-12 09:57 316928 ----a-w- c:\windows\system32\audiosrv.dll
2014-10-01 15:37 . 2014-07-10 14:30 18872 ----a-w- c:\windows\system32\drivers\SPPD.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
2011-01-17 14:54 175912 ----a-w- c:\program files\DVDVideoSoftTB\prxtbDVDV.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\prxtbDVDV.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{872B5B88-9DB5-4310-BDD0-AC189557E5F5}"= "c:\program files\DVDVideoSoftTB\prxtbDVDV.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 21:08 131480 ----a-w- c:\users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 21:08 131480 ----a-w- c:\users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"]
@="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 21:08 131480 ----a-w- c:\users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"]
@="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 21:08 131480 ----a-w- c:\users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 21:08 131480 ----a-w- c:\users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"]
@="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 21:08 131480 ----a-w- c:\users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 21:08 131480 ----a-w- c:\users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"]
@="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 21:08 131480 ----a-w- c:\users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2014-12-11 30877280]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-22 438272]
"RtHDVCpl"="RtHDVCpl.exe" [2007-06-13 4489216]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-06-20 1316136]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 174872]
"VX1000"="c:\windows\vVX1000.exe" [2007-04-10 709992]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-08-22 974432]
.
c:\users\Gast.Anna-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Users^Anna^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
path=c:\users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 ----a-w- e:\program files\DAEMON Tools Lite\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2014-12-11 10:20 30877280 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
2007-05-28 12:39 1826816 ----a-w- c:\windows\SkyTel.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"TOSCDSPD"=TOSCDSPD.EXE
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Toshiba Registration"=c:\program files\Toshiba\Registration\ToshibaRegistration.exe
"StartCCC"=c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
"HSON"=%ProgramFiles%\TOSHIBA\TBS\HSON.exe
"KeNotify"=c:\program files\TOSHIBA\Utilities\KeNotify.exe
"VX1000"=c:\windows\vVX1000.exe
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe"
"OODefragTray"=c:\windows\system32\oodtray.exe
"SmoothView"=%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
"NDSTray.exe"=NDSTray.exe
"00TCrdMain"=%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
"topi"=c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
"TPwrMain"=%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2011832117-4060477738-2340815351-1000]
"EnableNotificationsRef"=dword:00000001
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - MPKSLD5EF59E6
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Inhalt des "geplante Tasks" Ordners
.
2014-12-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-31 20:23]
.
2014-12-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-19 17:12]
.
2014-11-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-19 17:12]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAatbtHfwE_XaJc2CtZufSuDtW1sATSVNOa2XqXhTvzdxVQ7UHjOtuUdMoyUSrFvt1k_1FKKXK9KhsrNxnvKgDAA_Pw3s3ra037N78AYgqdNeUhphRcSY7iYutPEeoqG8sHvcdHZpgBXoy5_0hJRDSUdrxRIZR9jw3MfiA,,
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAatbtHfwE_XaJc2CtZufSuDtW1sATSVNOa2XqXhTvzdxVQ7UHjOtuUdMoyUSrFvt1kzfegdWUUW2FWGasqolBgPSA48YaEkpHp-wtvZ3IU900xgS6PAEvOASGuAn_b0-vQgmA_1S3Ufo8zEVcwhw5AuRfcGcPSEs6SChg,,&q={searchTerms}
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\9fmqf23o.default\
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://de.dawanda.com/shop/DimDimDesign
FF - ExtSQL: !HIDDEN! 2009-09-03 10:16; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2014-12-28 13:54
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2011832117-4060477738-2340815351-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*5)]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-2011832117-4060477738-2340815351-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*5)\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2011832117-4060477738-2340815351-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.*5)]
"0"=hex:46,3a,5c,54,72,61,63,6b,30,34,2e,63,64,61,00,02,70,7f,c0,02,30,80,c0,
02,72,2c,7f,1f,6f,00,00,80,bc,00,20,6e,6f,74,20,63,6f,6d,70,6c,61,69,6e,20,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_15_0_0_246_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_15_0_0_246_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="B2757C5B7CD217703459A9024B463B2AABD43DC26D9DABEBC86682E4A077F7BA796B791B2505523A9293FAA3EE5EFC719327E92CF0B6C55BF096F58A73FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79338EDD5E5BE2F6E667A2D97226D213B555BA7FD869164D67940CF03D7DC51FC9FD821FED568E80514D282E05FC42347892B72E0B9721E286A79E68F55C4AE9B94AA9D6B5E14E1C827800B0937818128DCD7481E821201014821D581904ECF48FEB4000E3816D3FA91694C689D218A00A6B495EB537E51BE9E565C1C4B1113982DB7333CF562ACEC0D2FDC390AD7E494EE55CEF929CCE966D3FCC482EE9CC921E1AE42EE0C4788D17DDCC9DE6ECBADB11C1C80530D6657AD8029AB31DF26BC1C0ACA9D195757F2552ED81ECDE3AF28958031F8FD630EC2239258B6F6FD8EAEB1D17CA237E531CA468B993F05E837E69823361A8E2B75ACDEF22CF8B9369FD97B9E743C9C0105C7C267F6B8A61F96BF4C0600709433ED61F34780B3C8F398B3271AE0813171E85812A7F67407311788B161DF910F9D9419E8E2A55D8F99E2D8D737E7A71CCB60EEDE97D593BB8049A6F5DFD1A421F662A37DBBEB95EFEB632DA42EE75F74456A0DEAB42094B66CE7A46C19CBB445E00D6B8D0BF396CE0DC1D36351BC5E0F2BB9D550C9CAEDFC8B2751BC417A262F60BC1D5F13DC8C5F137249975A3AB8761EB19B7FA597810BBB51B5C3B0F8C8BBAAA18279748CED31C2CB1E5842C5CEEADAED94F3C518996B29F31DBCD29A751934C3AA7F0F9A7215A66E45E32DB02BA88915CC7E559F64F34FDAED1F89017EB7A1CBE367F6924DEBDD5102E27DEB9B337E24E34E651CA3ED9A240568DF2F1367F0CEF169938875FE8ADB8DFDC6392C69338948AFB180408D2A24768B180C2AE4653CAEF68080A9C17E31AE3A31F13048A69C7A1BA129376DF56D7EB5CEF8978056C7FCDE8FE58319134A38F1D48B3A29C90303A8AA8DF78D85BBA265A7AB7D98814F49FEDC891DBBA1EF61AC09BE2FADF1150722649431F2714EB40CD5EB6BE2FCD44B81D14C90306656BA0D858FE88FE0D5B529FE20AA049A31CCAAA5CDEB4EB5FBA50709209ADFB8F8A2405C1DF6CB4EDB6C1586BF9D65273B0B7B9BA81EFC6D0DA82357ACC0739699287379F4C6CD25E000F89DAC4BF66B142DB18C2DFC65AF359CE0D08035F6C817693B5BD03F040CF06EA3E2E97FCC24F1B733642B13557D8A0976E79912B5B29DD769CEBB38774F4CCEA57660F5433013E1CD90CA2D7FED54C25A2904F01DD7AA13ED97D83DF7DC78B8886073E301B40DED899F351F32A05AF22C715081F604F51E0B04A0DD0FD822D215519A81EEFC9660FE4D4CF6E43C44F9E50D0FB6263C62F35B72EDBD0282751F51FA94B513D"
"OODEFRAG11.00.00.01WORKSTATION"="07036AA46B2A12161FBD068A55D13E215768E799D8C4DDAD068DD9D6475B6641680C6B011C0962B60C678FBD6B82CF96C167479B5ED016BFA8FD5860C39809E23E869EAE2EC977C48A57DEF09E0AD05E5414B71CC9035740E762984263EFE24A6D66CC6EF982B1B7CF0915D9E81BCBF7339856E856CB7551FA37CE7D402B33DF5F12E3971D7AD9DC1871F8C5089A31B28B17626101CB29E99DE5FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A9C6AECB7A5D1407C038D530D6EB3452C038D530D6EB34521CB04F31134FCBF6B1C23382D4F4F4A5D2C59A1106277A7C5A542727E360CE0C4D2501F04AD57FAA42BD23CB62E0FA15DC119ECFE739E672DA57003C767B899E2B3F3BA6F3033DC39B72AA06FB92F6CC8E639CFC64CB5E1D4B6C730951F8F39CD543D3F05921C69AD5B8600B3079BB7299C78D507415648B17F67AC1757162A68D08649F23CE637A2DFC2069F5D7A29DD0602E34F41B81454A6C53CFCA5230CFBB79CB39637C5D2581BF88E42344865D2FE2FCC828B9C3449758FC4D195C391EE817ABF60CEF83CBD5147C7276294632CF17BEE233A13B75D5D7BC8C9024E00D46F26AC6F3C4A99852A3243D8F45C58F755C7C889FD5FBBCFC1E9D13C2130B8C25B4B149D7E624A7442AE823F1AD6D6004A102755BAD9FEEAC716B97276423FD7D977055D698CE8799F77B380746298084EDDE9936D641D5252BB78618AA9639686B59F2F3EF893DE7F14FC1994A6842245AE79866CE83B04E3BD68152C9D5892793E0E096D53441668F1A3B5CC91D69B114354A86EA8AB03021E3DC7AF9562E9B07428F0A0A38FDEFDCD6D263A6412F25DAA23892D2FDFAF9753AA0154994594C50FAA57E1CFD5506FA46E9A5974F4017064F246B800BAB7DE17B098D178A32E40F4EFB06F2F51A4C9DEA180028C63FC2FEA18058C6624E30258C07B21ABC5333774121994812150A8D8B283337AC400941C07581C6B8682C11184036592FCD2C509E54142948022B2634186376064CEF5E975EF37946EBAE0B898C2D32EBA2E3F4F48D34F895104059321B1AECE15F207D584A222BC8C59A8F91F69455014917D315751DEB75E37CA91B16C1754C6CE6D5F57D617A7FD275AA27C1C947002D25F115E8580C6C96B730C4A5ACBFDCD7B335A86D6A5B30E4E87F03E08E62FDAD0F64D0F9CE3801B2EE194A978DCDA7799DFDEC49DA16A343C3C3A27D0A51159CFDD7666FD1213EB9C1240AEC7E76C99FDAA4826DB447A5A676C3C572C695E2423A0BB540144CB19D7227A95EF9E3638BCA32EEEE5DDC07BE975BF1D1338409D83552679BAB95ED486A888DD4629618706DC378159C9A9CAA62FDF0E0A0C6AC8F8093E46396288A15364663F0FADF8E79668C2CDA219A"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000004
.
Zeit der Fertigstellung: 2014-12-28 13:58:43
ComboFix-quarantined-files.txt 2014-12-28 12:58
ComboFix2.txt 2014-12-28 09:56
.
Vor Suchlauf: 8 Verzeichnis(se), 37.484.425.216 Bytes frei
Nach Suchlauf: 9 Verzeichnis(se), 39.185.608.704 Bytes frei
.
- - End Of File - - F2D70CD9D71A29D88BE2BAAC07CBBFE6 --- --- ---
5C616939100B85E558DA92B899A0FC36
[/CODE]
Hab den ersten Text wiedergefunden:
Combofix Logfile: Code:
ComboFix 14-12-25.01 - Anna 28.12.2014 13:44:23.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.2046.1154 [GMT 1:00]
ausgeführt von:: c:\users\Anna\AppData\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
SP: Microsoft Security Essentials *Disabled/Updated* {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-11-28 bis 2014-12-28 ))))))))))))))))))))))))))))))
.
.
2014-12-28 12:54 . 2014-12-28 12:54 -------- d-----w- c:\users\Gast\AppData\Local\temp
2014-12-28 12:54 . 2014-12-28 12:54 -------- d-----w- c:\users\Gast.Anna-PC\AppData\Local\temp
2014-12-28 12:54 . 2014-12-28 12:54 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-12-28 08:49 . 2014-12-28 08:49 -------- d-----w- c:\program files\VS Revo Group
2014-12-27 19:24 . 2014-12-27 19:24 104960 ----a-w- C:\kwtdrpow.sys
2014-12-27 18:39 . 2014-12-27 18:45 -------- d-----w- C:\FRST
2014-12-26 12:47 . 2014-12-02 11:01 9054624 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-12-20 18:05 . 2014-12-21 10:27 -------- d-----w- c:\program files\Mozilla Thunderbird
2014-12-19 09:42 . 2014-09-16 19:49 908840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1068B2E3-C663-46F4-995C-CAB2476A7130}\gapaengine.dll
2014-12-10 22:44 . 2014-11-04 00:19 2048 ----a-w- c:\windows\system32\tzres.dll
2014-12-10 22:43 . 2014-11-07 01:33 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-12-10 22:34 . 2014-12-03 02:06 278528 ----a-w- c:\windows\system32\schannel.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-12-10 20:23 . 2012-07-31 09:50 701104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-12-10 20:23 . 2011-07-26 13:31 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-10-30 11:24 . 2009-10-09 09:39 229000 ------w- c:\windows\system32\MpSigStub.exe
2014-10-24 01:04 . 2014-11-12 09:59 67072 ----a-w- c:\windows\system32\packager.dll
2014-10-24 01:03 . 2014-11-19 22:13 499200 ----a-w- c:\windows\system32\kerberos.dll
2014-10-18 01:08 . 2014-11-12 09:57 564224 ----a-w- c:\windows\system32\oleaut32.dll
2014-10-12 23:34 . 2014-11-12 09:50 2054656 ----a-w- c:\windows\system32\win32k.sys
2014-10-10 01:01 . 2014-11-12 10:01 449536 ----a-w- c:\windows\system32\termsrv.dll
2014-10-10 01:00 . 2014-11-12 10:01 146432 ----a-w- c:\windows\system32\msaudite.dll
2014-10-10 01:00 . 2014-11-12 10:01 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2014-10-09 23:22 . 2014-11-12 10:01 619520 ----a-w- c:\windows\system32\adtschema.dll
2014-10-03 01:18 . 2014-11-12 09:57 274432 ----a-w- c:\windows\system32\AUDIOKSE.dll
2014-10-03 01:17 . 2014-11-12 09:57 170496 ----a-w- c:\windows\system32\EncDump.dll
2014-10-03 01:17 . 2014-11-12 09:57 396800 ----a-w- c:\windows\system32\AudioEng.dll
2014-10-03 01:17 . 2014-11-12 09:57 316928 ----a-w- c:\windows\system32\audiosrv.dll
2014-10-01 15:37 . 2014-07-10 14:30 18872 ----a-w- c:\windows\system32\drivers\SPPD.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
2011-01-17 14:54 175912 ----a-w- c:\program files\DVDVideoSoftTB\prxtbDVDV.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\prxtbDVDV.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{872B5B88-9DB5-4310-BDD0-AC189557E5F5}"= "c:\program files\DVDVideoSoftTB\prxtbDVDV.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 21:08 131480 ----a-w- c:\users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 21:08 131480 ----a-w- c:\users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"]
@="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 21:08 131480 ----a-w- c:\users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"]
@="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 21:08 131480 ----a-w- c:\users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 21:08 131480 ----a-w- c:\users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"]
@="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 21:08 131480 ----a-w- c:\users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 21:08 131480 ----a-w- c:\users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"]
@="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 21:08 131480 ----a-w- c:\users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2014-12-11 30877280]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-22 438272]
"RtHDVCpl"="RtHDVCpl.exe" [2007-06-13 4489216]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-06-20 1316136]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 174872]
"VX1000"="c:\windows\vVX1000.exe" [2007-04-10 709992]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-08-22 974432]
.
c:\users\Gast.Anna-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Users^Anna^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
path=c:\users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 ----a-w- e:\program files\DAEMON Tools Lite\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2014-12-11 10:20 30877280 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
2007-05-28 12:39 1826816 ----a-w- c:\windows\SkyTel.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"TOSCDSPD"=TOSCDSPD.EXE
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Toshiba Registration"=c:\program files\Toshiba\Registration\ToshibaRegistration.exe
"StartCCC"=c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
"HSON"=%ProgramFiles%\TOSHIBA\TBS\HSON.exe
"KeNotify"=c:\program files\TOSHIBA\Utilities\KeNotify.exe
"VX1000"=c:\windows\vVX1000.exe
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe"
"OODefragTray"=c:\windows\system32\oodtray.exe
"SmoothView"=%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
"NDSTray.exe"=NDSTray.exe
"00TCrdMain"=%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
"topi"=c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
"TPwrMain"=%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2011832117-4060477738-2340815351-1000]
"EnableNotificationsRef"=dword:00000001
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - MPKSLD5EF59E6
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Inhalt des "geplante Tasks" Ordners
.
2014-12-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-31 20:23]
.
2014-12-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-19 17:12]
.
2014-11-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-19 17:12]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAatbtHfwE_XaJc2CtZufSuDtW1sATSVNOa2XqXhTvzdxVQ7UHjOtuUdMoyUSrFvt1k_1FKKXK9KhsrNxnvKgDAA_Pw3s3ra037N78AYgqdNeUhphRcSY7iYutPEeoqG8sHvcdHZpgBXoy5_0hJRDSUdrxRIZR9jw3MfiA,,
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAatbtHfwE_XaJc2CtZufSuDtW1sATSVNOa2XqXhTvzdxVQ7UHjOtuUdMoyUSrFvt1kzfegdWUUW2FWGasqolBgPSA48YaEkpHp-wtvZ3IU900xgS6PAEvOASGuAn_b0-vQgmA_1S3Ufo8zEVcwhw5AuRfcGcPSEs6SChg,,&q={searchTerms}
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Anna\AppData\Roaming\Mozilla\Firefox\Profiles\9fmqf23o.default\
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://de.dawanda.com/shop/DimDimDesign
FF - ExtSQL: !HIDDEN! 2009-09-03 10:16; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2014-12-28 13:54
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2011832117-4060477738-2340815351-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*5)]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-2011832117-4060477738-2340815351-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*5)\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2011832117-4060477738-2340815351-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.*5)]
"0"=hex:46,3a,5c,54,72,61,63,6b,30,34,2e,63,64,61,00,02,70,7f,c0,02,30,80,c0,
02,72,2c,7f,1f,6f,00,00,80,bc,00,20,6e,6f,74,20,63,6f,6d,70,6c,61,69,6e,20,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_15_0_0_246_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_15_0_0_246_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="B2757C5B7CD217703459A9024B463B2AABD43DC26D9DABEBC86682E4A077F7BA796B791B2505523A9293FAA3EE5EFC719327E92CF0B6C55BF096F58A73FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79338EDD5E5BE2F6E667A2D97226D213B555BA7FD869164D67940CF03D7DC51FC9FD821FED568E80514D282E05FC42347892B72E0B9721E286A79E68F55C4AE9B94AA9D6B5E14E1C827800B0937818128DCD7481E821201014821D581904ECF48FEB4000E3816D3FA91694C689D218A00A6B495EB537E51BE9E565C1C4B1113982DB7333CF562ACEC0D2FDC390AD7E494EE55CEF929CCE966D3FCC482EE9CC921E1AE42EE0C4788D17DDCC9DE6ECBADB11C1C80530D6657AD8029AB31DF26BC1C0ACA9D195757F2552ED81ECDE3AF28958031F8FD630EC2239258B6F6FD8EAEB1D17CA237E531CA468B993F05E837E69823361A8E2B75ACDEF22CF8B9369FD97B9E743C9C0105C7C267F6B8A61F96BF4C0600709433ED61F34780B3C8F398B3271AE0813171E85812A7F67407311788B161DF910F9D9419E8E2A55D8F99E2D8D737E7A71CCB60EEDE97D593BB8049A6F5DFD1A421F662A37DBBEB95EFEB632DA42EE75F74456A0DEAB42094B66CE7A46C19CBB445E00D6B8D0BF396CE0DC1D36351BC5E0F2BB9D550C9CAEDFC8B2751BC417A262F60BC1D5F13DC8C5F137249975A3AB8761EB19B7FA597810BBB51B5C3B0F8C8BBAAA18279748CED31C2CB1E5842C5CEEADAED94F3C518996B29F31DBCD29A751934C3AA7F0F9A7215A66E45E32DB02BA88915CC7E559F64F34FDAED1F89017EB7A1CBE367F6924DEBDD5102E27DEB9B337E24E34E651CA3ED9A240568DF2F1367F0CEF169938875FE8ADB8DFDC6392C69338948AFB180408D2A24768B180C2AE4653CAEF68080A9C17E31AE3A31F13048A69C7A1BA129376DF56D7EB5CEF8978056C7FCDE8FE58319134A38F1D48B3A29C90303A8AA8DF78D85BBA265A7AB7D98814F49FEDC891DBBA1EF61AC09BE2FADF1150722649431F2714EB40CD5EB6BE2FCD44B81D14C90306656BA0D858FE88FE0D5B529FE20AA049A31CCAAA5CDEB4EB5FBA50709209ADFB8F8A2405C1DF6CB4EDB6C1586BF9D65273B0B7B9BA81EFC6D0DA82357ACC0739699287379F4C6CD25E000F89DAC4BF66B142DB18C2DFC65AF359CE0D08035F6C817693B5BD03F040CF06EA3E2E97FCC24F1B733642B13557D8A0976E79912B5B29DD769CEBB38774F4CCEA57660F5433013E1CD90CA2D7FED54C25A2904F01DD7AA13ED97D83DF7DC78B8886073E301B40DED899F351F32A05AF22C715081F604F51E0B04A0DD0FD822D215519A81EEFC9660FE4D4CF6E43C44F9E50D0FB6263C62F35B72EDBD0282751F51FA94B513D"
"OODEFRAG11.00.00.01WORKSTATION"="07036AA46B2A12161FBD068A55D13E215768E799D8C4DDAD068DD9D6475B6641680C6B011C0962B60C678FBD6B82CF96C167479B5ED016BFA8FD5860C39809E23E869EAE2EC977C48A57DEF09E0AD05E5414B71CC9035740E762984263EFE24A6D66CC6EF982B1B7CF0915D9E81BCBF7339856E856CB7551FA37CE7D402B33DF5F12E3971D7AD9DC1871F8C5089A31B28B17626101CB29E99DE5FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A9C6AECB7A5D1407C038D530D6EB3452C038D530D6EB34521CB04F31134FCBF6B1C23382D4F4F4A5D2C59A1106277A7C5A542727E360CE0C4D2501F04AD57FAA42BD23CB62E0FA15DC119ECFE739E672DA57003C767B899E2B3F3BA6F3033DC39B72AA06FB92F6CC8E639CFC64CB5E1D4B6C730951F8F39CD543D3F05921C69AD5B8600B3079BB7299C78D507415648B17F67AC1757162A68D08649F23CE637A2DFC2069F5D7A29DD0602E34F41B81454A6C53CFCA5230CFBB79CB39637C5D2581BF88E42344865D2FE2FCC828B9C3449758FC4D195C391EE817ABF60CEF83CBD5147C7276294632CF17BEE233A13B75D5D7BC8C9024E00D46F26AC6F3C4A99852A3243D8F45C58F755C7C889FD5FBBCFC1E9D13C2130B8C25B4B149D7E624A7442AE823F1AD6D6004A102755BAD9FEEAC716B97276423FD7D977055D698CE8799F77B380746298084EDDE9936D641D5252BB78618AA9639686B59F2F3EF893DE7F14FC1994A6842245AE79866CE83B04E3BD68152C9D5892793E0E096D53441668F1A3B5CC91D69B114354A86EA8AB03021E3DC7AF9562E9B07428F0A0A38FDEFDCD6D263A6412F25DAA23892D2FDFAF9753AA0154994594C50FAA57E1CFD5506FA46E9A5974F4017064F246B800BAB7DE17B098D178A32E40F4EFB06F2F51A4C9DEA180028C63FC2FEA18058C6624E30258C07B21ABC5333774121994812150A8D8B283337AC400941C07581C6B8682C11184036592FCD2C509E54142948022B2634186376064CEF5E975EF37946EBAE0B898C2D32EBA2E3F4F48D34F895104059321B1AECE15F207D584A222BC8C59A8F91F69455014917D315751DEB75E37CA91B16C1754C6CE6D5F57D617A7FD275AA27C1C947002D25F115E8580C6C96B730C4A5ACBFDCD7B335A86D6A5B30E4E87F03E08E62FDAD0F64D0F9CE3801B2EE194A978DCDA7799DFDEC49DA16A343C3C3A27D0A51159CFDD7666FD1213EB9C1240AEC7E76C99FDAA4826DB447A5A676C3C572C695E2423A0BB540144CB19D7227A95EF9E3638BCA32EEEE5DDC07BE975BF1D1338409D83552679BAB95ED486A888DD4629618706DC378159C9A9CAA62FDF0E0A0C6AC8F8093E46396288A15364663F0FADF8E79668C2CDA219A"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000004
.
Zeit der Fertigstellung: 2014-12-28 13:58:43
ComboFix-quarantined-files.txt 2014-12-28 12:58
ComboFix2.txt 2014-12-28 09:56
.
Vor Suchlauf: 8 Verzeichnis(se), 37.484.425.216 Bytes frei
Nach Suchlauf: 9 Verzeichnis(se), 39.185.608.704 Bytes frei
.
- - End Of File - - F2D70CD9D71A29D88BE2BAAC07CBBFE6 --- --- ---
5C616939100B85E558DA92B899A0FC36
[/CODE] |