Sotala,
Habs gemacht und ausnahmsweise hats auch sofort funktioniert
Combofix Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
ComboFix 12-03-02.01 - Mike_Kathi 03.03.2012 20:00:18.1.4 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3253.2066 [GMT 1:00]
ausgeführt von:: c:\users\Mike_Kathi\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\CFLog
c:\users\Mike_Kathi\AppData\Roaming\AcroIEHelpe.txt
c:\users\Mike_Kathi\AppData\Roaming\srvblck2.tmp
c:\windows\Downloaded Program Files\IDropPTB.dll
c:\windows\logboot_03.03.2012.tureg.log
c:\windows\system32\oobe\audit.exe
c:\windows\system32\oobe\msoobe.exe
c:\windows\system32\oobe\oobeldr.exe
c:\windows\system32\oobe\Setup.exe
c:\windows\system32\oobe\setupsqm.exe
c:\windows\system32\oobe\windeploy.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-02-03 bis 2012-03-03 ))))))))))))))))))))))))))))))
.
.
2012-03-03 19:07 . 2012-03-03 19:07 -------- d-----w- c:\users\Mike_Kathi\AppData\Local\temp
2012-03-03 19:07 . 2012-03-03 19:07 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-03-03 19:07 . 2012-03-03 19:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-03-03 02:29 . 2011-07-13 02:55 2237440 ----a-r- C:\OTLPE.exe
2012-03-03 02:29 . 2012-03-03 11:51 -------- d-----w- C:\_OTL
2012-03-02 21:23 . 2012-02-08 06:03 6552120 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{58BA1F09-4F7C-48CF-8F81-A373D76C2526}\mpengine.dll
2012-03-01 13:25 . 2011-12-08 18:28 21312 ----a-w- c:\windows\system32\authuitu.dll
2012-03-01 13:25 . 2011-12-08 18:28 29504 ----a-w- c:\windows\system32\uxtuneup.dll
2012-03-01 13:23 . 2011-12-08 18:34 31552 ----a-w- c:\windows\system32\TURegOpt.exe
2012-03-01 13:23 . 2012-03-01 15:04 -------- d-----w- c:\users\Mike_Kathi\AppData\Roaming\TuneUp Software
2012-03-01 13:20 . 2012-03-01 13:25 -------- d-----w- c:\program files\TuneUp Utilities 2011
2012-03-01 13:19 . 2012-03-01 13:25 -------- d-----w- c:\programdata\TuneUp Software
2012-02-20 17:20 . 2012-02-20 17:20 -------- d-----w- c:\users\Mike_Kathi\AppData\Roaming\Xfire
2012-02-20 17:20 . 2012-02-20 17:20 -------- d-----w- c:\programdata\Xfire
2012-02-20 17:19 . 2012-02-20 17:20 -------- d-----w- c:\program files\Xfire
2012-02-16 13:21 . 2011-12-30 05:27 478720 ----a-w- c:\windows\system32\timedate.cpl
2012-02-16 13:21 . 2011-12-16 07:52 690688 ----a-w- c:\windows\system32\msvcrt.dll
2012-02-16 13:21 . 2012-01-04 08:58 442880 ----a-w- c:\windows\system32\ntshrui.dll
2012-02-16 13:21 . 2012-01-14 03:35 2343424 ----a-w- c:\windows\system32\win32k.sys
2012-02-15 18:32 . 2012-02-15 18:32 -------- d-----w- c:\users\Mike_Kathi\AppData\Local\PDF24
2012-02-08 18:40 . 2012-02-08 18:40 -------- d-----w- c:\program files\Teachmaster 4.3
2012-02-08 18:39 . 2012-02-08 18:39 -------- d-----w- c:\users\Mike_Kathi\Teachmaster 4.3
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-22 07:30 . 2011-11-26 19:00 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-15 15:26 . 2011-11-19 17:38 137416 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-01-29 04:10 . 2010-07-06 21:02 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-01-11 19:02 . 2012-01-10 15:58 952 --sha-w- c:\programdata\KGyGaAvL.sys
2012-01-10 21:44 . 2012-01-10 21:44 8198936 ----a-w- c:\windows\system32\TVWSetup.exe
2012-01-10 21:44 . 2012-01-10 21:44 267544 ----a-w- c:\windows\system32\igfxsrvc.exe
2012-01-10 21:44 . 2012-01-10 21:44 142616 ----a-w- c:\windows\system32\igfxtray.exe
2012-01-10 21:44 . 2012-01-10 21:44 177944 ----a-w- c:\windows\system32\igfxpers.exe
2012-01-10 21:44 . 2012-01-10 21:44 188184 ----a-w- c:\windows\system32\igfxext.exe
2012-01-10 21:44 . 2012-01-10 21:44 4699928 ----a-w- c:\windows\system32\GfxUI.exe
2012-01-10 21:44 . 2012-01-10 21:44 177432 ----a-w- c:\windows\system32\hkcmd.exe
2012-01-10 21:36 . 2012-01-10 21:36 81920 ----a-w- c:\windows\system32\igfxCoIn_v2622.dll
2012-01-10 21:18 . 2012-01-10 21:18 10859520 ----a-w- c:\windows\system32\drivers\igdkmd32.sys
2012-01-10 21:18 . 2012-01-10 21:18 6323712 ----a-w- c:\windows\system32\igdumd32.dll
2012-01-10 21:12 . 2012-01-10 21:12 581120 ----a-w- c:\windows\system32\igdumdx32.dll
2012-01-10 20:55 . 2010-08-09 04:37 7988224 ----a-w- c:\windows\system32\igd10umd32.dll
2012-01-10 20:29 . 2012-01-10 20:29 13904384 ----a-w- c:\windows\system32\ig4icd32.dll
2012-01-10 20:17 . 2012-01-10 20:17 284672 ----a-w- c:\windows\system32\igfxrrom.lrc
2012-01-10 20:17 . 2012-01-10 20:17 284672 ----a-w- c:\windows\system32\igfxrhrv.lrc
2012-01-10 20:17 . 2012-01-10 20:17 284672 ----a-w- c:\windows\system32\igfxrsky.lrc
2012-01-10 20:17 . 2012-01-10 20:17 284160 ----a-w- c:\windows\system32\igfxrtrk.lrc
2012-01-10 20:17 . 2012-01-10 20:17 284160 ----a-w- c:\windows\system32\igfxrslv.lrc
2012-01-10 20:17 . 2012-01-10 20:17 283648 ----a-w- c:\windows\system32\igfxrtha.lrc
2012-01-10 20:17 . 2012-01-10 20:17 285184 ----a-w- c:\windows\system32\igfxresn.lrc
2012-01-10 20:17 . 2012-01-10 20:17 284672 ----a-w- c:\windows\system32\igfxrrus.lrc
2012-01-10 20:17 . 2012-01-10 20:17 284160 ----a-w- c:\windows\system32\igfxrsve.lrc
2012-01-10 20:17 . 2012-01-10 20:17 284672 ----a-w- c:\windows\system32\igfxrptg.lrc
2012-01-10 20:17 . 2012-01-10 20:17 284672 ----a-w- c:\windows\system32\igfxrplk.lrc
2012-01-10 20:17 . 2012-01-10 20:17 284160 ----a-w- c:\windows\system32\igfxrptb.lrc
2012-01-10 20:17 . 2012-01-10 20:17 284672 ----a-w- c:\windows\system32\igfxrita.lrc
2012-01-10 20:17 . 2012-01-10 20:17 284160 ----a-w- c:\windows\system32\igfxrnor.lrc
2012-01-10 20:17 . 2012-01-10 20:17 281600 ----a-w- c:\windows\system32\igfxrjpn.lrc
2012-01-10 20:17 . 2012-01-10 20:17 281088 ----a-w- c:\windows\system32\igfxrkor.lrc
2012-01-10 20:17 . 2012-01-10 20:17 285184 ----a-w- c:\windows\system32\igfxrell.lrc
2012-01-10 20:17 . 2012-01-10 20:17 284160 ----a-w- c:\windows\system32\igfxrhun.lrc
2012-01-10 20:17 . 2012-01-10 20:17 283136 ----a-w- c:\windows\system32\igfxrheb.lrc
2012-01-10 20:17 . 2012-01-10 20:17 285184 ----a-w- c:\windows\system32\igfxrfra.lrc
2012-01-10 20:17 . 2012-01-10 20:17 284672 ----a-w- c:\windows\system32\igfxrnld.lrc
2012-01-10 20:17 . 2012-01-10 20:17 284672 ----a-w- c:\windows\system32\igfxrdeu.lrc
2012-01-10 20:17 . 2012-01-10 20:17 284160 ----a-w- c:\windows\system32\igfxrfin.lrc
2012-01-10 20:17 . 2012-01-10 20:17 284672 ----a-w- c:\windows\system32\igfxrcsy.lrc
2012-01-10 20:17 . 2012-01-10 20:17 283648 ----a-w- c:\windows\system32\igfxrdan.lrc
2012-01-10 20:17 . 2012-01-10 20:17 280576 ----a-w- c:\windows\system32\igfxrcht.lrc
2012-01-10 20:17 . 2012-01-10 20:17 280576 ----a-w- c:\windows\system32\igfxrchs.lrc
2012-01-10 20:17 . 2012-01-10 20:17 283136 ----a-w- c:\windows\system32\igfxrara.lrc
2012-01-10 20:15 . 2012-01-10 20:15 260608 ----a-w- c:\windows\system32\igfxTMM.dll
2012-01-10 20:15 . 2012-01-10 20:15 306176 ----a-w- c:\windows\system32\igfxpph.dll
2012-01-10 20:15 . 2012-01-10 20:15 24576 ----a-w- c:\windows\system32\igfxexps.dll
2012-01-10 20:15 . 2012-01-10 20:15 120320 ----a-w- c:\windows\system32\igfxcpl.cpl
2012-01-10 20:15 . 2010-08-09 04:37 57856 ----a-w- c:\windows\system32\igfxsrvc.dll
2012-01-10 20:14 . 2012-01-10 20:14 130048 ----a-w- c:\windows\system32\igfxdo.dll
2012-01-10 20:14 . 2010-08-09 04:37 96256 ----a-w- c:\windows\system32\hccutils.dll
2012-01-10 20:14 . 2012-01-10 20:14 146944 ----a-w- c:\windows\system32\gfxSrvc.dll
2012-01-10 20:14 . 2012-01-10 20:14 4096 ----a-w- c:\windows\system32\IGFXDEVLib.dll
2012-01-10 20:14 . 2012-01-10 20:14 294400 ----a-w- c:\windows\system32\igfxdev.dll
2012-01-10 20:14 . 2012-01-10 20:14 283648 ----a-w- c:\windows\system32\igfxrenu.lrc
2012-01-10 20:14 . 2010-08-09 04:37 9030656 ----a-w- c:\windows\system32\igfxress.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2009-11-02 103720]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-06-02 9222760]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RtHDVBg.exe" [2010-06-02 1481320]
"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2009-12-14 200704]
"LMgrVolOSD"="c:\program files\Launch Manager\OSD.exe" [2009-12-11 348960]
"Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2010-06-21 436264]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-12-10 1594664]
"NUSB3MON"="c:\program files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288]
"avgnt"="c:\programme user\Antivier\Avira\AntiVir Desktop\avgnt.exe" [2011-10-19 258512]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-01-10 142616]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-01-10 177432]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-01-10 177944]
"PDFPrint"="c:\programme user\Pdf converter\PDF24\pdf24.exe" [2012-02-09 160840]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"iTunesHelper"="c:\programme user\Itunes\iTunesHelper.exe"
.
R2 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 mitsijm2011;Autodesk Moldflow Inventor Tool Suite Integration 2011 - Job-Manager;c:\program files\Autodesk\Inventor 2011\Moldflow\bin\mitsijm.exe [2010-01-23 462336]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-05-24 193056]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 XDva392;XDva392;c:\windows\system32\XDva392.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2010-07-26 19656]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-10-19 36000]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AntiVirSchedulerService;Avira Planer;c:\programme user\Antivier\Avira\AntiVir Desktop\sched.exe [2011-10-19 86224]
S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648]
S2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-04 13336]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2010-07-27 1620584]
S2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [2011-12-08 1527104]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-05-10 2320920]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2010-02-26 132480]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-06-21 246272]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [2010-03-04 67624]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-04-27 64904]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-04-27 146568]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [2010-04-01 1009184]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 579944]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 194408]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 21864]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 19304]
S3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [2010-10-07 10064]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
S3 WisLMSvc;WisLMSvc;c:\program files\Launch Manager\WisLMSvc.exe [2009-10-23 118560]
S3 X10Hid;X10 Hid Device;c:\windows\System32\Drivers\x10hid.sys [2009-05-13 13720]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://medion.msn.com
uInternet Settings,ProxyOverride = *.local
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Mike_Kathi\AppData\Roaming\Mozilla\Firefox\Profiles\rby8achi.default\
FF - prefs.js: browser.startup.homepage - hxxp://go.web.de/tb/mff_startpage_home
FF - prefs.js: keyword.URL - hxxp://go.web.de/tb2/mff_keyurl_search/?su=
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
.
------- Dateityp-Verknüpfung -------
.
.scr=AutoCADScriptFile
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
SafeBoot-BsScanner
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-03-03 20:09:51
ComboFix-quarantined-files.txt 2012-03-03 19:09
.
Vor Suchlauf: 13 Verzeichnis(se), 493.368.426.496 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 493.231.788.032 Bytes frei
.
- - End Of File - - 46F6904EF8BC7F8B75EB14C417C3A79B
--- --- ---