DiyrtDrager | 16.06.2012 14:30 | Hier die Combofix Log Datei
Combofix Logfile: Code:
ComboFix 12-06-15.06 - Philipp 16.06.2012 14:46:01.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3325.2103 [GMT 2:00]
ausgeführt von:: c:\users\Philipp\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\windows\Installer\{df28e464-d8e7-079e-2418-b0ea3ccd31c5}\@
c:\windows\Installer\{df28e464-d8e7-079e-2418-b0ea3ccd31c5}\U\00000001.@
c:\windows\Installer\{df28e464-d8e7-079e-2418-b0ea3ccd31c5}\U\80000000.@
c:\windows\Installer\{df28e464-d8e7-079e-2418-b0ea3ccd31c5}\U\800000cb.@
c:\windows\IsUn0407.exe
.
Infizierte Kopie von c:\windows\system32\services.exe wurde gefunden und desinfiziert
Kopie von - c:\32788r22fwjfw\HarddiskVolumeShadowCopy5_!Windows!System32!services.exe wurde wiederhergestellt
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-05-16 bis 2012-06-16 ))))))))))))))))))))))))))))))
.
.
2012-06-16 13:06 . 2012-06-16 13:10 -------- d-----w- c:\users\Philipp\AppData\Local\temp
2012-06-16 13:06 . 2012-06-16 13:06 -------- d-----w- c:\users\Gast\AppData\Local\temp
2012-06-16 13:06 . 2012-06-16 13:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-16 12:08 . 2012-06-16 12:08 -------- d-----w- c:\users\Philipp\AppData\Local\Macromedia
2012-06-15 17:52 . 2012-06-15 17:52 -------- d-sh--w- c:\windows\system32\%APPDATA%
2012-06-14 12:22 . 2010-10-24 04:06 178176 ----a-w- c:\windows\system32\ztvunrar39.dll
2012-06-14 12:22 . 2006-05-25 12:52 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
2012-06-14 12:22 . 2006-06-19 10:01 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
2012-06-14 12:22 . 2003-02-02 17:06 153088 ----a-w- c:\windows\system32\UNRAR3.dll
2012-06-14 12:22 . 2002-03-05 22:00 75264 ----a-w- c:\windows\system32\unacev2.dll
2012-06-14 12:22 . 2012-06-14 13:33 -------- d-----w- c:\program files\Trojan Remover
2012-06-13 15:47 . 2012-06-13 15:47 -------- d-----w- c:\program files\iPod
2012-06-13 15:47 . 2012-06-13 15:48 -------- d-----w- c:\program files\iTunes
2012-06-13 15:30 . 2012-04-23 16:00 984064 ----a-w- c:\windows\system32\crypt32.dll
2012-06-13 15:30 . 2012-04-23 16:00 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-06-13 15:30 . 2012-04-23 16:00 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2012-06-12 18:46 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-12 18:46 . 2012-06-12 18:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-06-12 18:30 . 2012-06-12 18:30 -------- d-----w- c:\program files\Unlocker
2012-06-10 19:20 . 2012-06-10 19:20 -------- d-----w- c:\users\Philipp\AppData\Roaming\mp3DirectCut
2012-06-10 19:18 . 2012-06-10 19:18 -------- d-----w- c:\program files\mp3DirectCut
2012-06-10 11:58 . 2012-06-10 12:13 -------- d-----w- C:\PFS6_TMP
2012-06-08 11:09 . 2012-06-08 11:09 -------- d-----w- c:\users\Philipp\AppData\Local\Panasonic
2012-06-08 11:09 . 2007-06-21 22:10 501912 ----a-w- c:\windows\system32\PICSDK2.dll
2012-06-08 11:09 . 2006-10-30 22:10 71840 ----a-w- c:\windows\system32\EPPicMgr.dll
2012-06-08 11:09 . 2006-10-30 22:10 120992 ----a-w- c:\windows\system32\EpPicPrt.dll
2012-06-08 11:09 . 2006-10-19 22:10 80024 ----a-w- c:\windows\system32\PICSDK.dll
2012-06-08 11:09 . 2006-10-19 22:10 108704 ----a-w- c:\windows\system32\PICEntry.dll
2012-06-08 11:06 . 2012-06-08 11:06 -------- d-----w- c:\program files\Common Files\Panasonic
2012-06-08 11:05 . 2012-06-08 11:05 -------- d-----w- c:\program files\Microsoft Synchronization Services
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-16 12:06 . 2012-04-13 11:07 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-16 12:06 . 2011-05-14 18:39 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-27 08:20 . 2012-05-10 19:07 137928 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-04-24 22:32 . 2012-05-10 19:07 83392 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-04-18 18:56 . 2012-04-18 18:56 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2012-04-18 18:56 . 2012-04-18 18:56 69632 ----a-w- c:\windows\system32\QuickTime.qts
2012-04-16 19:17 . 2012-05-10 19:07 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-04-13 07:36 . 2012-05-09 18:50 6734704 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{EDFA81CD-1420-4133-9ACE-537119C53CE1}\mpengine.dll ERROR(0x00000005)
2012-04-13 07:36 . 2008-11-24 09:42 6734704 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll ERROR(0x00000005)
2012-04-03 08:16 . 2012-05-10 13:58 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-03 08:16 . 2012-05-10 13:58 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-30 12:39 . 2012-05-10 13:59 905600 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-03-20 23:28 . 2012-05-10 13:59 53120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2012-04-24 15:54 . 2011-11-11 20:13 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Wisdom-soft AutoScreenRecorder 3.1 Free"="0" [X]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-02-20 360448]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"Steam"="c:\program files\Steam\Steam.exe" [2011-10-02 1242448]
"HP Deskjet 3050A J611 series (NET)"="c:\program files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe" [2011-06-08 1804648]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2008-12-02 6695456]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2008-12-02 1833504]
"Google EULA Launcher"="c:\program files\Google\Google EULA\GoogleEULALauncher.exe" [2008-10-14 20480]
"PAC7311_Monitor"="c:\windows\PixArt\PAC7311\Monitor.exe" [2006-11-03 319488]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-30 59280]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-05-01 348624]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-06-07 421776]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-08-21 443968]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
NETGEAR WG111v3 Setup-Assistent.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2008-6-13 2109440]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux3"=wdmaud.drv
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-16 257224]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Inhalt des "geplante Tasks" Ordners
.
2012-06-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-13 12:06]
.
2012-06-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-13 17:43]
.
2012-06-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-13 17:43]
.
2012-06-16 c:\windows\Tasks\HP Photo Creations Messager.job
- c:\programdata\HP Photo Creations\MessageCheck.exe [2011-02-15 10:11]
.
2012-06-16 c:\windows\Tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}.job
- c:\windows\system32\msfeedssync.exe [2011-04-25 19:42]
.
.
------- Zusätzlicher Suchlauf -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.startfenster.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: Free YouTube Download - c:\users\Philipp\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to MP3 Converter - c:\users\Philipp\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-25/4
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\9s22iugf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.youtube.com/
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-ELAN 2012 NW - c:\users\Philipp\Desktop\2012\uninstall\uninstall.exe
AddRemove-_{ADDBE07D-95B8-4789-9C76-187FFF9624B4} - c:\program files\Corel\CorelDRAW Essential Edition 3\Programs\MSILauncher {ADDBE07D-95B8-4789-9C76-187FFF9624B4}
.
.
.
**************************************************************************
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien:
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MpsSvc]
"ImagePath"="."
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1417529056-3181727439-1968797575-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:8a,86,76,f6,98,a5,33,b4,1e,4b,47,29,a2,62,f8,bd,54,2d,67,9f,4a,61,d9,
5d,54,9e,e2,9a,1c,f7,27,39,e9,a3,df,71,44,19,13,9c,f3,ff,7a,b7,2e,cc,0e,6d,\
"??"=hex:69,3e,43,58,9f,64,ba,75,fe,6b,77,07,2a,78,dd,74
.
[HKEY_USERS\S-1-5-21-1417529056-3181727439-1968797575-1000\Software\SecuROM\License information*]
"datasecu"=hex:92,50,6b,5f,75,e5,92,10,ba,9f,7f,0d,48,02,46,d1,e9,c9,58,d6,9d,
8d,aa,38,4d,1c,15,ad,dc,5f,c3,8c,07,5c,ec,db,c6,46,3a,79,88,ad,69,33,f6,51,\
"rkeysecu"=hex:ba,7c,85,ed,da,92,1f,cd,74,5d,35,62,71,70,23,67
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(640)
c:\program files\RocketDock\RocketDock.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Spybot - Search & Destroy\SDWinSec.exe
c:\windows\system32\WUDFHost.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\conime.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\windows\ehome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Common Files\Steam\SteamService.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-06-16 15:21:41 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2012-06-16 13:19
.
Vor Suchlauf: 20 Verzeichnis(se), 440.247.226.368 Bytes frei
Nach Suchlauf: 24 Verzeichnis(se), 440.945.516.544 Bytes frei
.
- - End Of File - - 10A355D948DBEC29CD003F117D99CE57 --- --- --- |