Grazie r16, sei sempre gentilissimo!
Questo è il log di combofix:
ComboFix 08-11-23.01 - st.ar 2008-11-24 10:48:54.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1040.18.1965 [GMT 1:00]
ausgeführt von:: c:\users\st.ar\Downloads\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\x64
c:\windows\system32\x64\csnp2uvc.dll
c:\windows\system32\x64\rsnpvc64.dll
c:\windows\system32\x64\sncduvc.sys
c:\windows\system32\x64\snp2uvc.sys
c:\windows\system32\x64\vsnpvc64.dll
.
((((((((((((((((((((((( Dateien erstellt von 2008-10-24 bis 2008-11-24 ))))))))))))))))))))))))))))))
.
2008-11-22 22:36 . 2008-11-22 22:36 <DIR> d-------- c:\users\st.ar\AppData\Roaming\Malwarebytes
2008-11-22 22:36 . 2008-11-22 22:36 <DIR> d-------- c:\users\All Users\Malwarebytes
2008-11-22 22:36 . 2008-11-22 22:36 <DIR> d-------- c:\programdata\Malwarebytes
2008-11-22 22:36 . 2008-11-22 22:36 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-22 22:36 . 2008-10-22 16:10 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2008-11-22 22:36 . 2008-10-22 16:10 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2008-11-22 21:06 . 2008-11-22 21:07 <DIR> d-------- c:\users\st.ar\AppData\Roaming\SopCast
2008-11-22 21:06 . 2008-11-22 21:06 <DIR> d-------- c:\program files\SopCast
2008-11-21 10:38 . 2008-11-21 10:38 <DIR> d-------- c:\program files\CCleaner
2008-11-21 10:11 . 2008-11-21 10:11 <DIR> d-------- c:\program files\Trend Micro
2008-11-19 11:56 . 2008-10-16 22:13 1,809,944 --a------ c:\windows\System32\wuaueng.dll
2008-11-19 11:56 . 2008-10-16 21:56 1,524,736 --a------ c:\windows\System32\wucltux.dll
2008-11-19 11:56 . 2008-10-16 22:09 51,224 --a------ c:\windows\System32\wuauclt.exe
2008-11-19 11:56 . 2008-10-16 22:09 43,544 --a------ c:\windows\System32\wups2.dll
2008-11-19 11:55 . 2008-10-16 22:12 561,688 --a------ c:\windows\System32\wuapi.dll
2008-11-19 11:55 . 2008-10-16 14:08 162,064 --a------ c:\windows\System32\wuwebv.dll
2008-11-19 11:55 . 2008-10-16 21:55 83,456 --a------ c:\windows\System32\wudriver.dll
2008-11-19 11:55 . 2008-10-16 22:08 34,328 --a------ c:\windows\System32\wups.dll
2008-11-19 11:55 . 2008-10-16 13:56 31,232 --a------ c:\windows\System32\wuapp.exe
2008-11-15 19:48 . 2008-11-15 19:48 <DIR> d-------- c:\users\All Users\FLEXnet
2008-11-15 19:48 . 2008-11-15 19:48 <DIR> d-------- c:\programdata\FLEXnet
2008-11-15 19:23 . 2008-11-15 19:23 <DIR> d-------- c:\program files\Adobe Media Player
2008-11-15 19:06 . 2008-11-15 19:06 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2008-11-15 18:51 . 2008-11-15 18:51 <DIR> d-------- c:\program files\Common Files\Macrovision Shared
2008-11-15 16:27 . 2008-11-15 18:12 <DIR> d-------- c:\users\st.ar\AppData\Roaming\Download Manager
2008-11-12 11:36 . 2008-09-10 04:40 1,334,272 --a------ c:\windows\System32\msxml6.dll
2008-11-12 11:36 . 2008-09-05 06:14 1,191,936 --a------ c:\windows\System32\msxml3.dll
2008-11-12 11:36 . 2008-08-27 02:05 212,480 --a------ c:\windows\System32\drivers\mrxsmb10.sys
2008-11-05 11:55 . 2008-08-05 10:49 428,544 --a------ c:\windows\System32\EncDec.dll
2008-11-05 11:55 . 2008-08-05 10:49 293,376 --a------ c:\windows\System32\psisdecd.dll
2008-11-05 11:55 . 2008-08-05 10:48 217,088 --a------ c:\windows\System32\psisrndr.ax
2008-11-05 11:55 . 2008-08-05 10:48 177,664 --a------ c:\windows\System32\mpg2splt.ax
2008-11-05 11:55 . 2008-08-05 10:48 80,896 --a------ c:\windows\System32\MSNP.ax
2008-11-04 12:40 . 2008-11-04 13:10 <DIR> d-------- c:\users\st.ar\AppData\Roaming\U3
2008-10-29 06:39 . 2008-08-12 04:39 443,392 --a------ c:\windows\System32\win32spl.dll
2008-10-29 06:39 . 2008-09-18 05:56 147,456 --a------ c:\windows\System32\Faultrep.dll
2008-10-29 06:39 . 2008-09-18 05:56 125,952 --a------ c:\windows\System32\wersvc.dll
2008-10-27 13:50 . 2008-10-27 18:17 <DIR> d-a------ c:\users\All Users\TEMP
2008-10-27 13:50 . 2008-10-27 18:17 <DIR> d-a------ c:\programdata\TEMP
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-24 09:36 --------- d-----w c:\users\st.ar\AppData\Roaming\OpenOffice.org2
2008-11-24 09:32 75,993,376 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-24 09:32 --------- d-----w c:\programdata\Kaspersky Lab
2008-11-24 00:17 1,021,880 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-23 18:45 --------- d-----w c:\users\st.ar\AppData\Roaming\skypePM
2008-11-23 18:44 --------- d-----w c:\users\st.ar\AppData\Roaming\Skype
2008-11-21 05:51 27,335 ----a-w c:\users\st.ar\AppData\Roaming\nvModes.dat
2008-11-15 18:27 --------- d-----w c:\program files\Common Files\Adobe
2008-10-25 07:48 583,915 ----a-w c:\windows\system32\drivers\ar5211.sys
2008-10-23 11:10 --------- d-----w c:\program files\Microsoft Silverlight
2008-10-17 15:35 --------- d-----w c:\users\st.ar\AppData\Roaming\PeerNetworking
2008-10-16 12:06 --------- d-----w c:\program files\Windows Mail
2008-10-13 09:41 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2008-10-05 14:53 --------- d-----w c:\program files\uusee
2008-10-05 09:16 --------- d-----w c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-05 09:16 --------- d-----w c:\program files\iTunes
2008-10-05 09:16 --------- d-----w c:\program files\iPod
2008-10-02 03:49 827,392 ----a-w c:\windows\System32\wininet.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\System32\msxml4.dll
2008-09-27 20:48 --------- d-----w c:\program files\Google
2008-09-27 19:47 --------- d-----w c:\programdata\GRETECH
2008-09-27 19:46 --------- d-----w c:\users\st.ar\AppData\Roaming\GRETECH
2008-09-27 19:45 --------- d-----w c:\program files\GRETECH
2008-09-18 12:59 110 ----a-w c:\users\st.ar\AppData\Roaming\wklnhst.dat
2008-09-18 05:09 3,601,464 ----a-w c:\windows\System32\ntkrnlpa.exe
2008-09-18 05:09 3,549,240 ----a-w c:\windows\System32\ntoskrnl.exe
2008-09-18 02:16 2,032,640 ----a-w c:\windows\System32\win32k.sys
2008-09-03 03:59 468,992 ----a-w c:\windows\System32\newdev.dll
2008-09-03 03:58 74,752 ----a-w c:\windows\System32\newdev.exe
2008-08-31 20:08 48,396 ----a-w c:\windows\UninstVeetleTVPlayer.exe
2008-08-29 08:18 87,336 ----a-w c:\windows\System32\dns-sd.exe
2008-08-29 07:53 61,440 ----a-w c:\windows\System32\dnssd.dll
2008-07-07 21:16 56 ---ha-w c:\users\All Users\ezsidmv.dat
2008-07-07 21:16 56 ---ha-w c:\programdata\ezsidmv.dat
2008-06-18 19:02 174 --sha-w c:\program files\desktop.ini
2008-04-28 13:18 32 ----a-w c:\users\All Users\ezsid.dat
2008-04-28 13:18 32 ----a-w c:\programdata\ezsid.dat
2008-07-16 14:11 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-07-16 14:11 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-07-16 14:11 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-25 457216]
"eAudio"="c:\acer\Empowering Technology\eAudio\eAudio.exe" [2007-06-11 1286144]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2007-08-15 772616]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\Play Movie\PMVService.exe" [2007-05-24 206952]
"PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-06-06 159744]
"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-29 185896]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-07-25 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-25 8433664]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-25 81920]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 c:\windows\RtHDVCpl.exe]
"Skytel"="Skytel.exe" [2007-06-15 c:\windows\SkyTel.exe]
c:\users\st.ar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-07-28 535336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1.0\r3hook.dll,c:\progra~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{2E2F1A78-1C3D-492D-9957-8E9581487425}"= c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe
"{F3646932-7A75-40D6-BEEE-C5366675653E}"= c:\program files\Acer Arcade Deluxe\VideoMagician\VideoMagician.exe:VideoMagician
"{0E5DEFB0-FF0C-48DE-9412-720274AD2AC4}"= c:\program files\Acer Arcade Deluxe\HomeMedia\HomeMedia.exe:HomeMedia
"{1C185533-4B0F-4322-917F-ED8F386D4653}"= c:\program files\Acer Arcade Deluxe\DV Wizard\DV Wizard.exe:DV Wizard
"{925C0C20-8AD8-478F-9D5C-7E59D9694C28}"= c:\program files\Acer Arcade Deluxe\DVDivine\DVDivine.exe:DVDivine
"{5A5F257D-766F-442D-AE06-9819C7FCD323}"= c:\program files\Acer Arcade Deluxe\Play Movie\PlayMovie.exe:Play Movie
"{A9DEBBCA-DFD4-45D6-8414-C87D2A35EE5D}"= c:\program files\Acer Arcade Deluxe\Play Movie\PMVService.exe:Play Movie Resident Program
"{7FDE0FEB-48D3-4AC0-8665-97A984C4D156}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{10F77775-4486-48DA-BABD-969D41E3F77E}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{3281AF66-A869-476A-A610-03ADBA7386C2}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{7A9195DC-B25D-4F39-8648-C4E330CCC931}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{934242C2-F840-4F30-85C2-5F37D81E3092}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{AB7B8E55-A93B-4DC2-BEA1-C42B35076DBB}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{6D2CEC77-49D9-427A-81E0-2C312DE20F8F}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{421DF317-BC54-4D46-824B-671AE441E7EB}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{499102CE-D8E7-4B3E-97D4-8AEA67D64AB0}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{FEC4C5C3-AC0C-4784-ACAB-A2F7FBE3F695}c:\\users\\st.ar\\appdata\\locallow\\powerchallenge\\powersoccer\\powersoccer.exe"= UDP:c:\users\st.ar\appdata\locallow\powerchallenge\powersoccer\powersoccer.exe:powersoccer.exe
"UDP Query User{C47E746E-90EF-4FDF-AA0D-71D0C4F269A5}c:\\users\\st.ar\\appdata\\locallow\\powerchallenge\\powersoccer\\powersoccer.exe"= TCP:c:\users\st.ar\appdata\locallow\powerchallenge\powersoccer\powersoccer.exe:powersoccer.exe
"{0C7297EB-8317-4711-9B61-0A712C7E76CC}"= UDP:5353:Adobe CSI CS4
"{5CAF9B8B-E9B6-497A-A8DE-24A7AEF93F6F}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{709CDE41-6ED3-4AEE-ABD7-1C73D71E3BF9}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"TCP Query User{562C72BA-D6C1-4B4A-903A-7D9E144E31BD}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{66AB1167-D7B2-447E-972D-AE32C7363B94}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"TCP Query User{72768452-78D1-470A-B310-6B6B382433EF}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{305EB721-C2C1-4072-8996-0DDB789AC608}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"TCP Query User{8FEE54CB-36D4-4381-9757-4946A6A297B8}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{35104476-7FF8-4A85-9E08-482A6AF1E4EE}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"TCP Query User{D7155B80-CCF1-4316-818A-0F8800181E30}c:\\program files\\gretech\\gomplayer\\gom.exe"= UDP:c:\program files\gretech\gomplayer\gom.exe:GOM Player
"UDP Query User{B3D1A28A-CD45-4F25-9D66-97AF84910926}c:\\program files\\gretech\\gomplayer\\gom.exe"= TCP:c:\program files\gretech\gomplayer\gom.exe:GOM Player
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2007-04-04 20760]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};\??\c:\program files\Acer Arcade Deluxe\Play Movie\
000.fcl [2008-02-21 02:25:58 13560]
R2 adfs;adfs;c:\windows\system32\drivers\adfs.sys [2008-08-14 74720]
R2 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [2007-07-28 50688]
R3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2007-07-28 32256]
S3 ms6823;IEEE802.11b Wireless USB Adapter;c:\windows\system32\DRIVERS\ms6823.sys [2004-06-10 55168]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{adbc9158-aa61-11dd-844b-001b38d00b9b}]
\shell\AutoRun\command - H:\LaunchU3.exe -a
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
HKLM-Run-Acer Tour - (no file)
HKLM-Run-eRecoveryService - (no file)
.
------- Zusätzlicher Suchlauf -------
.
FireFox -: Profile - c:\users\st.ar\AppData\Roaming\Mozilla\Firefox\Profiles\vsof6zna.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - about:blank
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-24 10:51:31
Windows 6.0.6001 Service Pack 1 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
- - - - - - - > 'winlogon.exe'(864)
c:\progra~1\KASPER~1\KASPER~1.0\r3hook.dll
- - - - - - - > 'lsass.exe'(648)
c:\progra~1\KASPER~1\KASPER~1.0\r3hook.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
.
Zeit der Fertigstellung: 2008-11-24 10:53:00
ComboFix-quarantined-files.txt 2008-11-24 09:52:55
Vor Suchlauf: 45.872.713.728 byte disponibili
Nach Suchlauf: 45,818,765,312 byte disponibili
217 --- E O F --- 2008-11-21 06:21:54