Galilahi | 10.12.2013 17:55 | Hallo Marius,
wenn du mir empfiehlst zu AVAST zu wechseln, werde ich das gerne tun. Aber das ist eine andere Baustelle. Ich habe kein DSL und das wird ewig dauern, das Programm zu laden. Antivir hat schon über 100 MB, ich weiß nicht wieviel AVAST hat!? Aber die Toolbar kann ich wohl löschen, da ich sie sowieso nicht verwende?
Hier Combofix: Code:
ComboFix 13-12-08.01 - Mercier 10.12.2013 16:37:40.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.49.1031.18.767.354 [GMT 1:00]
ausgeführt von:: c:\dokumente und einstellungen\Mercier\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\dokumente und einstellungen\Mercier\WINDOWS
c:\programme\DJ1050_J410_Basicx86_1313.exe
c:\programme\Nero_BurningROM2014-15.0.01300_trial.exe
c:\programme\Opera_1214_int_Setup.exe
c:\windows\IsUn0407.exe
c:\windows\system\A258_R35.BPL
c:\windows\system32\dllcache\wmpvis.dll
c:\windows\wininit.ini
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-11-10 bis 2013-12-10 ))))))))))))))))))))))))))))))
.
.
2013-12-10 00:03 . 2013-12-10 00:03 -------- d-----w- c:\windows\system32\wbem\Repository
2013-12-09 17:37 . 2013-12-09 17:38 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Malwarebytes' Anti-Malware (portable)
2013-12-08 19:54 . 2013-12-08 19:54 104664 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2013-12-08 19:34 . 2013-12-08 19:34 51416 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2013-12-08 13:46 . 2013-12-10 10:51 -------- d-----w- C:\FRST
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-05 15:55 . 2013-02-23 11:04 90400 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-11-26 15:20 . 2013-02-23 11:04 37352 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-11-26 15:20 . 2013-02-23 11:04 137208 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-11-24 11:55 . 2012-04-03 07:04 692616 -c--a-w- c:\windows\system32\FlashPlayerApp.exe
2013-11-24 11:55 . 2011-06-15 10:52 71048 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-10-13 07:22 . 2005-02-18 15:35 920064 ----a-w- c:\windows\system32\wininet.dll
2013-10-13 07:22 . 2002-08-29 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2013-10-13 07:22 . 2002-08-29 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2013-10-13 07:21 . 2002-08-29 12:00 18944 ----a-w- c:\windows\system32\corpol.dll
2013-10-13 06:57 . 2005-05-04 11:04 385024 ----a-w- c:\windows\system32\html.iec
2013-10-12 15:56 . 2002-08-29 12:00 279552 ----a-w- c:\windows\system32\oakley.dll
2013-10-09 13:12 . 2002-08-29 12:00 287744 ----a-w- c:\windows\system32\gdi32.dll
2013-10-07 10:59 . 2002-08-29 12:00 608256 ----a-w- c:\windows\system32\crypt32.dll
2013-10-05 01:42 . 2008-05-05 05:25 8192 -c--a-w- c:\windows\system32\xpsp4res.dll
2013-01-31 09:30 . 2012-03-18 07:58 12927928 -c--a-w- c:\programme\AiRoboForm-cnetc.exe
2013-01-27 11:34 . 2013-01-27 11:34 379128 -c--a-w- c:\programme\SoftonicDownloader_fuer_langenscheidt-vokabeltrainer-franzosisch.exe
2012-12-17 08:46 . 2011-12-22 18:08 6968242 -c--a-w- c:\programme\avira_free_antivirus_de.exe
2012-12-16 14:48 . 2012-12-16 14:48 2602234 -c--a-w- c:\programme\doc2img2_setup.exe
2012-12-16 14:11 . 2012-12-16 14:11 658771 -c--a-w- c:\programme\MWSnap300.exe
2012-12-16 09:31 . 2012-12-16 09:31 982272 -c--a-w- c:\programme\Ghostscript-Setup.exe
2012-11-23 15:56 . 2012-11-23 15:31 1458576 -c--a-w- c:\programme\powersuite.exe
2012-11-10 10:06 . 2012-11-10 10:06 18090960 -c--a-w- c:\programme\Firefox Setup 16.0.2.exe
2012-08-20 10:44 . 2012-08-20 10:44 352952 -c--a-w- c:\programme\SoftonicDownloader_fuer_sweepi.exe
2012-03-03 18:28 . 2012-03-03 18:28 4935195 -c--a-w- c:\programme\downloadhelper.exe
2012-01-30 13:40 . 2012-01-30 13:40 7258593 -c--a-w- c:\programme\wavsetup.exe
2012-01-20 15:00 . 2012-01-20 15:00 360328 -c--a-w- c:\programme\SansaUpdaterInstall.exe
2012-01-20 14:24 . 2012-01-20 14:24 25766024 -c--a-w- c:\programme\wmp11-windowsxp-x86-DE-DE.exe
2012-01-19 10:30 . 2012-01-19 10:30 12391568 -c--a-w- c:\programme\AiRoboForm.exe
2012-01-16 16:45 . 2012-01-16 16:45 20290952 -c--a-w- c:\programme\jre-7u2-windows-i586.exe
2011-12-13 14:03 . 2011-12-13 14:03 4701696 -c--a-w- c:\programme\SumatraPDF-1.9-install.exe
2011-09-11 08:37 . 2011-09-11 08:37 642632 -c--a-w- c:\programme\hdtune_255.exe
2011-09-10 17:08 . 2011-09-10 17:08 1402880 -c--a-w- c:\programme\HiJackThis.msi
2011-03-19 13:10 . 2011-03-19 13:10 2871968 -c--a-w- c:\programme\install_flash_player_ax.exe
2011-03-14 12:16 . 2011-03-14 12:16 1062574 -c--a-w- c:\programme\7z911.exe
2011-03-13 14:57 . 2011-03-13 14:57 1631768 -c--a-w- c:\programme\32fsg32.exe
2011-01-17 16:30 . 2011-01-17 16:30 2676560 -c--a-w- c:\programme\Productivity_2.2.exe
2011-01-15 18:52 . 2011-01-15 18:52 59398824 -c--a-w- c:\programme\avira_antivir_personal_de.exe
2010-12-27 18:23 . 2011-03-19 13:19 400384 -c--a-w- c:\programme\JavaRa.exe
2009-05-17 07:59 . 2009-04-25 09:57 519257 -c--a-w- c:\programme\QuickGammaV2DE.exe
2009-04-14 09:26 . 2009-04-14 09:26 18295296 -c--a-w- c:\programme\gimp-2.6.6-i686.EXE
2009-03-19 19:09 . 2009-03-19 19:09 1628800 -c--a-w- c:\programme\Paint.NET.3.36.exe
2009-03-19 19:00 . 2009-03-19 19:00 2959376 -c--a-w- c:\programme\dotnetfx35setup.exe
2008-12-14 10:59 . 2008-12-14 10:59 16194992 -c--a-w- c:\programme\PDFCreator-0_9_6_setup.exe
2008-10-04 08:10 . 2008-08-31 14:26 1156272 -c--a-w- c:\programme\WDC3Setup.exe
2008-08-13 13:52 . 2008-10-12 13:25 1445792 -c--a-w- c:\programme\disk-defrag-setup.exe
2008-05-14 11:31 . 2008-10-12 13:25 2306304 -c--a-w- c:\programme\zicon.exe
2008-04-30 16:32 . 2008-10-12 13:25 6505472 -c--a-w- c:\programme\irfanview_plugins_410_setup.exe
2008-04-30 12:34 . 2008-10-12 13:25 1397248 -c--a-w- c:\programme\iview410g_setup.exe
2008-04-29 06:54 . 2008-10-12 13:25 1440047 -c--a-w- c:\programme\wrar371d.exe
2008-03-24 10:07 . 2008-10-12 13:25 866246 -c--a-w- c:\programme\p2s_setup.exe
2008-03-21 17:29 . 2008-10-12 13:25 77322 -c--a-w- c:\programme\dic_allemand_medical.exe
2008-03-21 17:28 . 2008-10-12 13:25 259306 -c--a-w- c:\programme\dictionnaire_medizin.exe
2008-03-05 17:30 . 2008-10-12 13:25 3516928 -c--a-w- c:\programme\TweakPower.exe
2008-02-14 12:08 . 2008-10-12 13:10 38885976 -c--a-w- c:\programme\GoogleSketchUpWDE64.exe
2008-01-06 15:53 . 2008-10-12 13:25 3722850 -c--a-w- c:\programme\absetup.exe
2007-11-21 12:32 . 2008-10-12 13:25 691880 -c--a-w- c:\programme\mrs_EXCELTOOLS_free.exe
2007-11-21 12:29 . 2008-10-12 13:25 352840 -c--a-w- c:\programme\mrs_FEIERTAGE.exe
2007-11-21 10:42 . 2008-10-12 13:25 871952 -c--a-w- c:\programme\undelete_plus_setup Datenrettung.exe
2007-10-18 16:38 . 2008-10-12 13:25 243055 -c--a-w- c:\programme\mrs_OUTLOOK.exe
2007-10-09 17:24 . 2008-10-12 13:25 1020116 -c--a-w- c:\programme\Passfoto-Setup.exe
2007-09-05 09:53 . 2008-10-12 13:25 823839 -c--a-w- c:\programme\dic_allemand.exe
2007-09-05 09:51 . 2008-10-12 13:25 309309 -c--a-w- c:\programme\dictionnaire_setup.exe
2007-01-22 17:11 . 2008-10-12 13:25 18016148 -c--a-w- c:\programme\Inkscape-0.44.1-1.win32.exe
2006-08-28 08:45 . 2008-10-12 13:25 2333850 -c--a-w- c:\programme\Activicons setup.exe
2000-04-01 16:27 . 2000-04-01 16:27 122880 -c--a-w- c:\programme\uidll.dll
1999-10-13 11:49 . 1999-10-13 11:49 131072 -c--a-w- c:\programme\booleen.dll
2013-06-11 13:33 . 2013-06-11 13:31 262112 -c--a-w- c:\programme\mozilla firefox\components\browsercomps.dll
1995-07-11 07:50 24576 -csha-w- c:\windows\system32\AWCODC32.DLL
1995-07-11 07:50 6144 -csha-w- c:\windows\system32\AWDCXC32.DLL
1995-11-16 16:39 11776 -csha-w- c:\windows\system32\AWDENC32.DLL
1995-07-11 07:50 26624 -csha-w- c:\windows\system32\AWRESX32.DLL
1995-10-09 14:58 10240 -csha-w- c:\windows\system32\AWVIEW32.DLL
1998-04-04 18:23 24576 -csha-w- c:\windows\system32\LFAVI90N.DLL
1998-05-20 15:14 28672 -csha-w- c:\windows\system32\lfawd90n.dll
1998-05-15 15:00 33792 -csha-w- c:\windows\system32\lfbmp90n.dll
1998-05-18 15:50 27136 -csha-w- c:\windows\system32\lfcal90n.dll
1998-05-15 15:01 235008 -csha-w- c:\windows\system32\LFCMP90n.DLL
1998-06-24 16:59 237568 -csha-w- c:\windows\system32\LFDIC90N.DLL
1998-04-04 18:24 31232 -csha-w- c:\windows\system32\LFEPS90N.DLL
1998-05-15 14:59 64512 -csha-w- c:\windows\system32\lffax90n.dll
1997-11-21 16:03 338944 -csha-w- c:\windows\system32\lffpx7.dll
1998-05-20 15:14 88576 -csha-w- c:\windows\system32\lffpx90n.dll
1998-05-15 15:02 39936 -csha-w- c:\windows\system32\lfgif90n.dll
1998-05-15 15:02 46592 -csha-w- c:\windows\system32\LFICA90N.DLL
1998-04-04 18:24 27136 -csha-w- c:\windows\system32\LFIMG90N.DLL
1997-09-30 12:30 122880 -csha-w- c:\windows\system32\LFKODAK.DLL
1998-04-04 18:24 35840 -csha-w- c:\windows\system32\LFLMA90N.DLL
1998-04-04 18:24 31232 -csha-w- c:\windows\system32\LFLMB90N.DLL
1998-04-04 18:24 25600 -csha-w- c:\windows\system32\LFMAC90N.DLL
1998-04-04 18:25 26112 -csha-w- c:\windows\system32\LFMSP90N.DLL
1998-04-04 18:25 26624 -csha-w- c:\windows\system32\LFPCD90N.DLL
1998-05-15 15:03 31232 -csha-w- c:\windows\system32\lfpct90n.dll
1998-04-04 18:25 30720 -csha-w- c:\windows\system32\lfpcx90n.dll
1998-06-23 08:10 133632 -csha-w- c:\windows\system32\lfpng90n.dll
1998-05-18 16:27 29184 -csha-w- c:\windows\system32\lfpsd90n.dll
1998-04-04 18:25 26112 -csha-w- c:\windows\system32\LFRAS90N.DLL
1998-04-04 18:25 28160 -csha-w- c:\windows\system32\LFTGA90N.DLL
1998-05-15 15:05 118272 -csha-w- c:\windows\system32\lftif90n.dll
1998-04-04 18:26 25600 -csha-w- c:\windows\system32\lfwfx90n.dll
1998-05-15 15:05 28672 -csha-w- c:\windows\system32\lfwmf90n.dll
1998-04-04 18:26 27648 -csha-w- c:\windows\system32\lfwpg90n.dll
1998-05-15 14:27 238592 -csha-w- c:\windows\system32\ltann90n.dll
1998-05-15 14:26 220160 -csha-w- c:\windows\system32\LTDIS90n.dll
1998-05-18 16:03 145920 -csha-w- c:\windows\system32\LTDLG90N.DLL
1998-04-04 18:22 146432 -csha-w- c:\windows\system32\ltefx90n.dll
1998-06-23 10:41 99328 -csha-w- c:\windows\system32\ltfil90n.DLL
1998-05-20 15:13 104448 -csha-w- c:\windows\system32\ltimg90n.dll
1998-05-20 15:14 38400 -csha-w- c:\windows\system32\ltisi90n.dll
1998-06-19 13:44 290304 -csha-w- c:\windows\system32\ltkrn90n.dll
1998-06-29 15:28 43520 -csha-w- c:\windows\system32\LTNET90N.DLL
1998-04-03 17:01 3824 -csha-w- c:\windows\system32\ltthk90w.dll
1998-05-19 16:53 35328 -csha-w- c:\windows\system32\lttwn90n.dll
1998-04-03 17:01 45936 -csha-w- c:\windows\system32\ltvdd90w.drv
1998-05-20 15:15 148480 -csha-w- c:\windows\system32\LTVID90N.DLL
1999-02-22 10:00 159744 -csha-w- c:\windows\system32\MFCANS32.DLL
1998-04-29 18:00 58880 -csha-w- c:\windows\system32\npplg90N.dll
1995-05-21 22:00 640512 -csha-w- c:\windows\system32\OC30.DLL
1999-05-26 07:46 212480 -csha-w- c:\windows\system32\pcdlib32.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\programme\Ask.com\GenericAskToolbar.dll" [2012-06-20 1519824]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\programme\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2013-01-31 109784]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2002-09-11 46592]
"StorageGuard"="c:\programme\Gemeinsame Dateien\Sonic\Update Manager\sgtray.exe" [2003-02-13 155648]
"LogMeIn GUI"="c:\programme\LogMeIn\x86\LogMeInSystray.exe" [2008-08-11 63048]
"WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-09-14 24576]
"WOOTASKBARICON"="c:\progra~1\Wanadoo\TaskbarIcon.exe" [2004-09-14 49152]
"QuickTime Task"="c:\programme\QuickTime\qttask.exe" [2009-01-05 413696]
"GrooveMonitor"="c:\programme\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"ApnUpdater"="c:\programme\Ask.com\Updater\Updater.exe" [2012-06-20 1568976]
"avgnt"="c:\programme\Avira\AntiVir Desktop\avgnt.exe" [2013-11-26 683576]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programme\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2012-11-08 15:28 92072 ----a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programme\\Messenger\\msmsgs.exe"=
"c:\\Programme\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programme\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programme\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\twain_32\\L12U16U2\\SrvMod.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\Programme\\FinalMediaPlayer\\FMPCheckForUpdates.exe"=
"c:\\Programme\\File Type Assistant\\TSAssist.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [09.10.2008 17:27 39472]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [23.02.2013 12:04 37352]
R1 SSHDRV86;SSHDRV86;c:\windows\system32\drivers\SSHDRV86.sys [26.05.2008 18:24 81408]
R2 AntiVirSchedulerService;Avira Planer;c:\programme\Avira\AntiVir Desktop\sched.exe [23.02.2013 12:04 440376]
R2 AntiVirWebService;Avira Browser-Schutz;c:\programme\Avira\AntiVir Desktop\avwebgrd.exe [23.02.2013 12:04 1164360]
R2 AVMPORT;AVMPORT;c:\windows\system32\drivers\avmport.sys [12.06.2003 11:12 59520]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\programme\LogMeIn\x86\LMIGuardianSvc.exe [04.10.2010 16:18 374704]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\programme\LogMeIn\x86\rainfo.sys [11.08.2008 12:41 12856]
R3 AVMWAN;AVM NDIS WAN CAPI-Treiber;c:\windows\system32\drivers\avmwan.sys [12.06.2003 10:40 37568]
R3 fpcibase;AVM ISDN-Controller FRITZ!Card PCI v2.0;c:\windows\system32\drivers\fpcibase.sys [12.06.2003 10:40 444416]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [30.01.2012 14:44 16512]
.
Inhalt des "geplante Tasks" Ordners
.
2013-12-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 11:55]
.
2013-12-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2013-12-10 c:\windows\Tasks\Final Media Player Update Checker.job
- c:\programme\FinalMediaPlayer\FMPCheckForUpdates.exe [2012-09-04 15:24]
.
2013-12-10 c:\windows\Tasks\ProgramRefresh-ATFST.job
- c:\programme\File Type Assistant\TSASetup.exe [2013-04-12 10:11]
.
2013-12-10 c:\windows\Tasks\ProgramUpdateCheck.job
- c:\programme\File Type Assistant\tsassist.exe [2012-09-04 11:09]
.
2013-12-10 c:\windows\Tasks\rbmonitor.job
- c:\programme\Uniblue\RegistryBooster\rbmonitor.exe [2012-04-11 07:32]
.
2013-12-10 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\programme\Ask.com\UpdateTask.exe [2012-06-20 11:18]
.
2013-12-10 c:\windows\Tasks\User_Feed_Synchronization-{F4548AA5-7DBB-483E-9A42-FDDF15752DD7}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.ixquick.de/
uSearchMigratedDefaultURL =
mStart Page = hxxp://home.sweetim.com/?st=17&barid={2D7781C5-689B-11E2-8034-404E57434431}
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/su/*hxxp://www.yahoo.com
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: RF - Formular ausfüllen - file://c:\programme\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RF - Formular speichern - file://c:\programme\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: RF - Menü anpassen - file://c:\programme\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: RF - RoboForm-Leiste ein/aus - file://c:\programme\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: { - c:\programme\Messenger\msmsgs.exe
LSP: c:\programme\Avira\AntiVir Desktop\avsda.dll
TCP: Interfaces\{E465ED50-0270-44F9-B2C5-2562BAB1150D}: NameServer = 62.27.27.62
FF - ProfilePath - c:\dokumente und einstellungen\Mercier\Anwendungsdaten\Mozilla\Firefox\Profiles\arpi31hg.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - SweetIM Search
FF - prefs.js: browser.startup.homepage - hxxp://home.sweetim.com/?crg=3.1010000.10002&barid={2D7781C5-689B-11E2-8034-404E57434431}
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&barid={2D7781C5-689B-11E2-8034-404E57434431}&q=
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
c:\dokumente und einstellungen\Mercier\Startmenü\Programme\Autostart\Tintenwarnungen überwachen - HP Deskjet 1050 J410 series.lnk - (no file)
AddRemove-FranzA - c:\windows\IsUn0407.exe
AddRemove-FranzB - c:\windows\IsUn0407.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2013-12-10 17:02
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,96,6b,d3,af,36,58,2c,46,a8,91,6d,\
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,96,6b,d3,af,36,58,2c,46,a8,91,6d,\
.
[HKEY_USERS\S-1-5-21-436374069-1767777339-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(408)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'lsass.exe'(464)
c:\programme\Avira\AntiVir Desktop\avsda.dll
.
Zeit der Fertigstellung: 2013-12-10 17:10:11
ComboFix-quarantined-files.txt 2013-12-10 16:10
ComboFix2.txt 2012-01-11 21:20
.
Vor Suchlauf: 1.471.660.032 Bytes frei
Nach Suchlauf: 1.525.854.208 Bytes frei
.
- - End Of File - - FE3F628D7E701B444AC95B2D130270B6
72B8CE41AF0DE751C946802B3ED844B4 Vielen Dank schon mal für Deine Mühe.
Liebe Grüße
Uschi |