Virussammlen | 17.06.2014 15:23 | Code:
ComboFix 14-06-16.01 - Jonas 17.06.2014 16:03:47.1.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3325.2014 [GMT 2:00]
ausgeführt von:: c:\users\Jonas\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.dll
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.exe
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\cb.drv
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\cid.dll
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\CLSV.dll
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\delfile.sys
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\eb.drv
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\energy.drv
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\energy.exe
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\exec.sys
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\fan.dll
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\fan.sys
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\fix.exe
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\FW.exe
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\hymt.dll
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\hymt.tmp
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\kernel32.exe
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\pal.tmp
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\PE.dll
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\PE.exe
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\ppal.exe
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\runddl.dll
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.dll
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.exe
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.tmp
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\sld.dll
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\sld.tmp
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\SM.dll
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\snl2w.tmp
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\std.exe
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\tjd.dll
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\tjd.drv
c:\users\Jonas\AppData\Roaming\Microsoft\Windows\Recent\tjd.exe
c:\windows\Fonts\upcli.ttf
c:\windows\system32\tmp3B89.tmp
c:\windows\system32\tmp3BF7.tmp
c:\windows\system32\tmp5D83.tmp
c:\windows\system32\tmp99F6.tmp
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-05-17 bis 2014-06-17 ))))))))))))))))))))))))))))))
.
.
2014-06-17 14:16 . 2014-06-17 14:16 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-06-17 14:16 . 2014-06-17 14:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-06-16 17:26 . 2014-04-30 23:37 8073384 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{B9F0C5D6-43DB-403E-B069-9F7D22A4A489}\mpengine.dll ERROR(0x00000005)
2014-06-16 16:57 . 2014-06-16 16:57 -------- d-----w- c:\windows\system32\drivers\NST
2014-06-16 16:57 . 2014-06-16 16:57 -------- d-----w- c:\program files\Norton Identity Safe
2014-06-13 13:32 . 2014-06-13 13:32 -------- d-----w- C:\170fb40c1244885abd07451e32c60b6f
2014-06-12 18:01 . 2014-06-16 17:05 -------- d-----w- C:\FRST
2014-05-28 21:46 . 2010-04-05 20:00 221568 ----a-w- c:\windows\system32\drivers\netio.sys
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-06-02 15:21 . 2014-04-04 19:27 42784 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2014-05-14 15:36 . 2012-04-02 12:16 692400 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-05-14 15:36 . 2011-05-26 10:40 70832 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-04-17 03:32 . 2008-10-08 09:57 8050496 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll ERROR(0x00000005)
2014-04-15 00:34 . 2014-04-15 00:34 1070232 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2014-03-31 07:35 . 2010-04-13 10:56 231584 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2014-06-02 15:21 3594264 ----a-w- c:\program files\AVG SafeGuard toolbar\18.1.7.598\AVG SafeGuard toolbar_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG SafeGuard toolbar\18.1.7.598\AVG SafeGuard toolbar_toolbar.dll" [2014-06-02 3594264]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-04-25 08:03 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-04-25 08:03 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-04-25 08:03 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-04-25 08:03 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-04-25 08:03 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-04-25 08:03 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2011-04-27 2937528]
"ICQ"="c:\program files\ICQ7.7\ICQ.exe" [2012-01-23 127040]
"Spotify Web Helper"="c:\users\Jonas\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2014-05-15 1176632]
"GoogleChromeAutoLaunch_7F41DE71C33EFD8EC5D292FBB70B0F95"="c:\program files\Google\Chrome\Application\chrome.exe" [2014-06-05 860488]
"Steam"="c:\program files\Steam\Steam.exe" [2014-05-29 1754816]
"Spotify"="c:\users\Jonas\AppData\Roaming\Spotify\Spotify.exe" [2014-05-15 6170168]
"AmazonMP3DownloaderHelper"="c:\users\Jonas\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe" [2013-05-22 400704]
"AudialsNotifier"="c:\program files\Audials\Audials 10\AudialsNotifier.exe" [2013-10-07 529160]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-04-07 39408]
"SanDiskSecureAccess_Manager.exe"="c:\users\Jonas\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe" [2012-02-14 30705792]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-08 178712]
"TVEService"="c:\program files\HomeCinema\TV Enhance\TVEService.exe" [2008-10-14 180224]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-04-07 30192]
"Google EULA Launcher"="c:\program files\Google\Google EULA\GoogleEULALauncher.exe" [2008-10-14 20480]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2013-10-24 12017368]
"Hercules DJ Series TrayAgent"="c:\program files\Guillemot\HDJTray\HDJSeries2TrayBar.exe" [2013-05-10 2914640]
"vProt"="c:\program files\AVG SafeGuard toolbar\vprot.exe" [2014-06-02 2567192]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2008-01-21 215552]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-06-13 23:57 1091912 ----a-w- c:\program files\Google\Chrome\Application\35.0.1916.153\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-06-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 15:36]
.
2014-06-17 c:\windows\Tasks\AVG-Secure-Search-Update_0414c_rel.job
- c:\program files\AVG SafeGuard toolbar\AVG-Secure-Search-Update_0414c.exe [2014-04-20 22:34]
.
2014-06-17 c:\windows\Tasks\AVG-Secure-Search-Update_0414c_rmv.job
- c:\program files\AVG SafeGuard toolbar\AVG-Secure-Search-Update_0414c.exe [2014-04-20 22:34]
.
2014-06-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-13 11:57]
.
2014-06-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-13 11:57]
.
2008-10-20 c:\windows\Tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}.job
- c:\windows\system32\msfeedssync.exe [2014-06-12 23:17]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = www.google.com
uDefault_Search_URL = www.google.com
mStart Page = www.google.com
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: An OneNote s&enden - c:\progra~1\MICROS~4\Office14\ONBttnIE.dll/105
IE: Crawler Search - tbr:iemenu
IE: Free YouTube to MP3 Converter - c:\users\Jonas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~4\Office14\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-25/4
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files\ICQ7.7\ICQ.exe
TCP: DhcpNameServer = 192.168.2.1
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} -
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.7\ViProtocol.dll
FF - ProfilePath - c:\users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\ngs0vmb4.Standard-Benutzer\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-10 - (no file)
WebBrowser-{872B5B88-9DB5-4310-BDD0-AC189557E5F5} - (no file)
HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
HKU-Default-Run-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-Fraps - c:\users\Jonas\Documents\My Games\FarmingSimulator2009\mods\snapshot\uninstall.exe
AddRemove-Free YouTube to MP3 Converter_is1 - c:\program files\Common Files\DVDVideoSoft\Uninstall.exe
AddRemove-_{ADDBE07D-95B8-4789-9C76-187FFF9624B4} - c:\program files\Corel\CorelDRAW Essential Edition 3\Programs\MSILauncher {ADDBE07D-95B8-4789-9C76-187FFF9624B4}
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2014-06-17 16:16
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
.
c:\users\Jonas\AppData\Local\Temp\catchme.dll 53248 bytes executable
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 1
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NCO]
"ImagePath"="\"c:\program files\Norton Identity Safe\Engine\2014.7.0.47\NST.exe\" /s \"NCO\" /m \"c:\program files\Norton Identity Safe\Engine\2014.7.0.47\diMaster.dll\" /prefetch:1"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-131767531-2465167464-222506596-1000\Software\SecuROM\License information*]
"datasecu"=hex:13,ec,a7,38,98,69,f9,00,c5,18,e5,60,86,15,9a,99,82,bb,c2,a7,09,
2a,b8,85,f4,6b,e1,15,e6,ed,38,6a,e3,61,f8,ed,29,e7,10,0e,10,ac,c0,2f,00,8c,\
"rkeysecu"=hex:bf,3c,58,bb,21,34,5b,35,67,7f,61,b0,92,6d,88,a0
.
Zeit der Fertigstellung: 2014-06-17 16:19:10
ComboFix-quarantined-files.txt 2014-06-17 14:18
.
Vor Suchlauf: 8 Verzeichnis(se), 664.120.160.256 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 721.121.419.264 Bytes frei
.
- - End Of File - - 173F3824A5471571F8B0D0C2798B7548
671B81004FDD1588FA9ED1331C9CECA9 |