matze.ilbi | 27.02.2014 11:32 | Danke für die schnelle Antwort.
Hier meine Log-Datei: Code:
ComboFix 14-02-24.02 - Vostro 27.02.2014 9:09.1.2 - x86
ausgeführt von:: c:\users\Vostro\Desktop\ComboFix.exe
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\kikin
c:\program files\kikin\config.ini
c:\program files\kikin\configuration.xml
c:\program files\kikin\ie_kikin.dll
c:\program files\kikin\kikin.ico
c:\program files\kikin\KikinBroker.exe
c:\program files\kikin\uninst.exe
c:\programdata\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
c:\programdata\dsgsdgdsgdsgw.pad
c:\programdata\erolpxei.pad
c:\programdata\fl4z8jznbf.cpp
c:\programdata\HotbarSA
c:\programdata\HotbarSA\HotbarSA.dat
c:\programdata\HotbarSA\HotbarSA_hpk.dat
c:\programdata\HotbarSA\HotbarSA_kyf.dat
c:\programdata\HotbarSA\HotbarSAAbout.mht
c:\programdata\HotbarSA\HotbarSAau.dat
c:\programdata\HotbarSA\HotbarSAEULA.mht
c:\programdata\lsass.exe
c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar
c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar\About Hotbar.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar\Hotbar Customer Support Center.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar\Hotbar Games!.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar\Hotbar Videos!.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar\Reset Cursor.lnk
c:\users\Vostro\AppData\Local\lame_enc.dll
c:\users\Vostro\AppData\Local\no23xwrapper.dll
c:\users\Vostro\AppData\Local\ogg.dll
c:\users\Vostro\AppData\Local\vnajdrq.dll
c:\users\Vostro\AppData\Local\vorbis.dll
c:\users\Vostro\AppData\Local\vorbisenc.dll
c:\users\Vostro\AppData\Local\vorbisfile.dll
c:\users\Vostro\AppData\Roaming\kikin
c:\users\Vostro\AppData\Roaming\kikin\ff_kkes.xml
c:\users\Vostro\AppData\Roaming\kikin\ie_kkes.xml
c:\users\Vostro\AppData\Roaming\kikin\ie_settings.xml
c:\users\Vostro\AppData\Roaming\WeatherDPA
c:\users\Vostro\Documents\~WRL1298.tmp
c:\windows\system32\drivers\etc\hosts.ics
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-01-27 bis 2014-02-27 ))))))))))))))))))))))))))))))
.
.
2014-02-27 08:24 . 2014-02-27 10:21 -------- d-----w- c:\users\Vostro\AppData\Local\temp
2014-02-27 08:24 . 2014-02-27 08:24 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-02-27 08:24 . 2014-02-27 08:24 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-02-26 18:44 . 2014-02-06 07:08 7947048 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F53A342B-A194-4211-9F2D-6CBE82A2AB3E}\mpengine.dll
2014-02-26 18:30 . 2014-02-26 18:30 -------- d-----w- c:\program files\IObit Toolbar
2014-02-26 18:29 . 2014-02-26 18:41 -------- d-----w- C:\FRST
2014-02-21 20:37 . 2014-02-25 08:35 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0
2014-02-21 19:14 . 2014-02-21 19:14 -------- d-----w- c:\users\Default\AppData\Roaming\IObit
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-04 19:17 . 2014-01-04 19:17 1129472 ----a-w- c:\windows\system32\wininet.dll
2014-01-04 19:17 . 2014-01-04 19:17 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2014-01-04 19:17 . 2014-01-04 19:17 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2014-01-04 19:17 . 2014-01-04 19:17 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2014-01-04 19:17 . 2014-01-04 19:17 1806848 ----a-w- c:\windows\system32\jscript9.dll
2014-01-04 19:17 . 2014-01-04 19:17 420864 ----a-w- c:\windows\system32\vbscript.dll
2014-01-04 19:15 . 2014-01-04 19:15 2050560 ----a-w- c:\windows\system32\win32k.sys
2014-01-04 19:14 . 2014-01-04 19:14 36864 ----a-w- c:\windows\system32\wshcon.dll
2014-01-04 19:14 . 2014-01-04 19:14 172032 ----a-w- c:\windows\system32\scrrun.dll
2014-01-04 19:14 . 2014-01-04 19:14 155648 ----a-w- c:\windows\system32\wscript.exe
2014-01-04 19:14 . 2014-01-04 19:14 135168 ----a-w- c:\windows\system32\cscript.exe
2014-01-04 19:14 . 2014-01-04 19:14 131072 ----a-w- c:\windows\system32\wshom.ocx
2014-01-04 19:14 . 2014-01-04 19:14 335360 ----a-w- c:\windows\system32\SysFxUI.dll
2014-01-04 19:14 . 2014-01-04 19:14 167936 ----a-w- c:\windows\system32\drivers\portcls.sys
2014-01-04 19:14 . 2014-01-04 19:14 130048 ----a-w- c:\windows\system32\drivers\drmk.sys
2014-01-04 19:14 . 2008-03-29 23:57 1304064 ----a-w- c:\windows\system32\WMALFXGFXDSP.dll
2014-01-04 19:14 . 2014-01-04 19:14 158208 ----a-w- c:\windows\system32\imagehlp.dll
2013-12-18 05:13 . 2009-10-08 09:45 231584 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{03EB0E9C-7A91-4381-A220-9B52B641CDB1}"= "c:\program files\IObit Apps Toolbar\IE\8.6\iobitappsToolbarIE.dll" [2013-12-27 1398080]
.
[HKEY_CLASSES_ROOT\clsid\{03eb0e9c-7a91-4381-a220-9b52b641cdb1}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}]
2013-12-27 16:04 1398080 ----a-w- c:\program files\IObit Apps Toolbar\IE\8.6\iobitappsToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F}]
2014-02-25 09:32 464720 ----a-w- c:\program files\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}]
2013-01-28 14:49 281760 ----a-w- c:\program files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{03EB0E9C-7A91-4381-A220-9B52B641CDB1}"= "c:\program files\IObit Apps Toolbar\IE\8.6\iobitappsToolbarIE.dll" [2013-12-27 1398080]
.
[HKEY_CLASSES_ROOT\clsid\{03eb0e9c-7a91-4381-a220-9b52b641cdb1}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sony PC Companion"="c:\program files\Sony\Sony PC Companion\PCCompanion.exe" [2013-10-31 449760]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-03-29 125952]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-10-02 20472992]
"Advanced SystemCare 6"="c:\program files\IObit\Advanced SystemCare 6\ASCTray.exe" [2013-04-18 491840]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2013-05-08 41056]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"SearchSettings"="c:\program files\Common Files\Spigot\Search Settings\SearchSettings.exe" [2014-02-19 1387328]
"SunJavaUpdateSched"="c:\program files\common files\java\java update\jusched.exe" [2012-01-18 254696]
"IObit Malware Fighter"="c:\program files\IObit\IObit Malware Fighter\IMF.exe" [2013-12-13 1573184]
.
c:\users\Vostro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
fbnzj8z4lf.lnk - c:\windows\System32\rundll32.exe c:\progra~2\fl4z8jznbf.cpp,XXS1 [2006-11-2 44544]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableInstallerDetection"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WDDMStatus.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WDDMStatus.lnk
backup=c:\windows\pss\WDDMStatus.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WDSmartWare.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WDSmartWare.lnk
backup=c:\windows\pss\WDSmartWare.lnk.CommonStartup
backupExtension=.CommonStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cm106Sound
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVHotkey
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2013-05-08 21:20 41056 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEM02Mon.exe]
2007-05-09 23:01 36864 ----a-w- c:\windows\OEM02Mon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2009-09-24 13:41 434176 ----a-w- c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-05-10 18:01 202256 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
S2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files\IObit\Advanced SystemCare 6\ASCService.exe [2013-04-18 574272]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
.
Inhalt des "geplante Tasks" Ordners
.
2014-02-27 c:\windows\Tasks\Driver Booster Update.job
- c:\program files\IObit\Driver Booster\AutoUpdate.exe [2013-10-15 13:16]
.
2014-02-27 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-10-25 20:06]
.
2014-02-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-25 10:57]
.
2014-02-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-25 10:57]
.
2014-02-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2719662579-187885903-3024253376-1000Core.job
- c:\users\Vostro\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-12 12:29]
.
2014-02-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2719662579-187885903-3024253376-1000UA.job
- c:\users\Vostro\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-12 12:29]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = https://www.google.de/
mStart Page = hxxp://search.chatzum.com/?orig=HP&affid=62&cztbid=1759291256
uInternet Settings,ProxyOverride = fritz.box;192.168.178.1
uSearchAssistant = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=d463741b-0c72-4b31-9395-18c434c815e6&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}&installDate=01/01/1970
IE: Free YouTube Download - c:\program files\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\program files\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
IE: {{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - c:\program files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
TCP: DhcpNameServer = 192.168.2.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - (no file)
BHO-{E601996F-E400-41CA-804B-CD6373A7EEE2} - c:\program files\kikin\ie_kikin.dll
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-kikin Plugin (NO23 Edition) - c:\program files\kikin\uninst.exe
AddRemove-Google Chrome - c:\users\Vostro\AppData\Local\Google\Chrome\Application\33.0.1750.117\Installer\setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2014-02-27 11:22
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
.
c:\users\Vostro\AppData\Roaming\Skype\matze6142\bistats.db-journal 37448 bytes
c:\users\Vostro\AppData\Roaming\Skype\matze6142\bistats.lock 0 bytes
c:\users\Vostro\AppData\Roaming\Skype\matze6142\keyval.lock 0 bytes
c:\users\Vostro\AppData\Roaming\Skype\matze6142\main.db-journal 74384 bytes
c:\users\Vostro\AppData\Roaming\Skype\matze6142\main.lock 0 bytes
c:\users\Vostro\AppData\Roaming\Skype\matze6142\mmanager\mediacache.ldb 40 bytes
c:\users\Vostro\AppData\Roaming\Skype\matze6142\msn.lock 0 bytes
c:\users\Vostro\AppData\Roaming\Skype\matze6142\thmanager\thumbcache.ldb 40 bytes
c:\users\Vostro\AppData\Roaming\Skype\shared_dynco\dc.db-journal 1289168 bytes
c:\users\Vostro\AppData\Roaming\Skype\shared_dynco\dc.lock 0 bytes
c:\users\Vostro\AppData\Roaming\Skype\shared_httpfe\queue.lock 0 bytes
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 11
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2719662579-187885903-3024253376-1000\Software\SecuROM\License information*]
"datasecu"=hex:0e,69,f2,9b,ff,dc,85,87,1a,1a,4e,ef,a1,99,2f,90,f5,0c,6f,d6,5e,
91,5c,24,d6,86,b8,aa,6e,2e,14,c6,16,03,5b,2d,c5,5a,4a,2b,ab,73,50,00,b4,11,\
"rkeysecu"=hex:6c,7a,01,05,1d,9a,45,94,a5,a3,84,03,0d,8a,b3,09
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe
c:\program files\Application Updater\ApplicationUpdater.exe
c:\program files\ICQ6Toolbar\ICQ Service.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\windows\System32\WUDFHost.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\IObit\Advanced SystemCare 6\Monitor.exe
c:\windows\system32\conime.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\ehome\ehmsas.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2014-02-27 11:27:39 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2014-02-27 10:27
.
Vor Suchlauf: 13 Verzeichnis(se), 47.733.780.480 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 51.521.982.464 Bytes frei
.
- - End Of File - - 10E85EB3CD0E236244577DB35EE653FA
5C616939100B85E558DA92B899A0FC36 |