Code:
ComboFix 13-07-23.01 - User 23.07.2013 22:02:26.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.1791.937 [GMT 2:00]
ausgeführt von:: c:\users\User\Desktop\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\User\4.0
c:\windows\System32\Desktop_.ini
c:\windows\system32\frapsvid.dll
c:\windows\unin0407.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-06-23 bis 2013-07-23 ))))))))))))))))))))))))))))))
.
.
2013-07-23 19:38 . 2013-07-23 19:38 -------- d-----w- C:\FRST
2013-07-23 18:24 . 2013-07-23 18:23 1187697 ----a-w- c:\windows\unins000.exe
2013-07-23 18:12 . 2012-10-23 10:18 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-07-23 18:12 . 2012-10-23 10:18 360392 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-07-23 18:11 . 2012-10-23 10:18 106560 ----a-w- c:\windows\system32\drivers\aswFW.sys
2013-07-23 18:10 . 2012-10-23 10:18 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2013-07-23 18:10 . 2012-10-23 10:18 199320 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2013-07-23 18:10 . 2012-10-23 10:18 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-07-23 18:10 . 2012-10-23 10:18 20624 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2013-07-23 18:10 . 2012-10-23 10:18 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-07-23 18:10 . 2012-10-23 10:18 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-07-23 18:09 . 2012-09-21 09:26 12112 ----a-w- c:\windows\system32\drivers\aswNdis.sys
2013-07-23 18:09 . 2012-10-23 10:17 41224 ----a-w- c:\windows\avastSS.scr
2013-07-23 18:09 . 2012-10-23 10:17 227648 ----a-w- c:\windows\system32\aswBoot.exe
2013-07-23 18:08 . 2013-07-23 18:08 -------- d-----w- c:\programdata\AVAST Software
2013-07-23 18:08 . 2013-07-23 18:08 -------- d-----w- c:\program files\AVAST Software
2013-07-23 13:13 . 2013-07-23 13:27 -------- d-----w- c:\users\User\AppData\Roaming\DVDFab9
2013-07-23 13:03 . 2013-07-23 13:04 -------- d-----w- c:\program files\DVDFab 9
2013-07-10 03:50 . 2013-06-04 01:50 2049024 ----a-w- c:\windows\system32\win32k.sys
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-23 10:53 . 2012-04-04 12:53 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-07-23 10:53 . 2011-05-18 08:14 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-16 09:27 . 2010-06-24 10:33 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-08 04:37 . 2013-06-12 06:42 905576 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-05-02 22:03 . 2013-06-12 06:28 3603832 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-05-02 22:03 . 2013-06-12 06:28 3551096 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-05-02 04:04 . 2013-06-12 06:18 443904 ----a-w- c:\windows\system32\win32spl.dll
2013-05-02 04:03 . 2013-06-12 06:18 37376 ----a-w- c:\windows\system32\printcom.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-23 10:17 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-23 4297136]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-08-04 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
.
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2012-10-27 116608]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2010-02-24 185472]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Inhalt des "geplante Tasks" Ordners
.
2013-07-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2527675546-1131128584-3539002440-1000Core.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2012-12-01 20:02]
.
2013-07-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2527675546-1131128584-3539002440-1000UA.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2012-12-01 20:02]
.
2013-07-23 c:\windows\Tasks\User_Feed_Synchronization-{68A693EE-AF0D-4514-B5EC-D25B557818A6}.job
- c:\windows\system32\msfeedssync.exe [2013-07-10 08:05]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.gmx.net/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = localhost; 127.0.0.1; <local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - c:\users\User\AppData\Local\Temp\laehswkiurpawadjh.dll
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2013-07-23 22:11
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2527675546-1131128584-3539002440-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:ac,4c,09,4c,5b,e1,46,a0,1c,b1,78,dc,b0,24,8a,fc,e1,8e,da,81,8d,10,c8,
b4,fd,6c,d9,03,a5,c8,34,78,02,99,10,c8,07,28,74,a9,89,a0,46,7c,b7,b7,f2,d1,\
"??"=hex:61,00,bc,6f,92,a0,86,58,42,90,f7,81,95,72,fa,b7
.
[HKEY_USERS\S-1-5-21-2527675546-1131128584-3539002440-1000\Software\SecuROM\License information*]
"datasecu"=hex:70,7e,7f,58,b2,04,85,1b,04,57,35,4e,86,23,c8,6c,6a,66,4a,de,c1,
7b,f4,fd,0c,bc,5c,68,0a,02,55,0c,71,2e,b4,72,1e,6a,80,69,eb,cf,ff,17,b1,5a,\
"rkeysecu"=hex:ed,ae,22,ce,23,c5,f0,6e,65,de,48,bd,b0,90,b5,2c
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Zeit der Fertigstellung: 2013-07-23 22:13:42
ComboFix-quarantined-files.txt 2013-07-23 20:13
.
Vor Suchlauf: 14 Verzeichnis(se), 30.807.216.128 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 30.812.000.256 Bytes frei
.
- - End Of File - - 2E43CD73E29697FCA0F3FFFC0BA7CBF4
5C616939100B85E558DA92B899A0FC36 |