Hallo Arne,
hier ist die LOG-Datei von Combo-Fix. Ich weiß nicht genau, wie ich schnell ich ab nächste Woche antworten kann, da die Arbeit wieder ruft
Aber vielleicht haben wir (bzw. Du) das Problem aus der Welt geschafft.
[code]
Combofix Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
ComboFix 12-07-31.03 - Daniel 02.08.2012 10:40:47.1.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.1791.1123 [GMT 2:00]
ausgeführt von:: c:\users\Daniel\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-07-02 bis 2012-08-02 ))))))))))))))))))))))))))))))
.
.
2012-08-02 08:44 . 2012-08-02 08:44 -------- d-----w- c:\users\SSGClient\AppData\Local\temp
2012-08-01 07:11 . 2012-08-01 07:11 -------- d-----w- c:\users\Daniel\AppData\Local\ElevatedDiagnostics
2012-07-25 09:07 . 2012-07-25 09:07 -------- d-----w- C:\_OTL
2012-07-12 14:08 . 2012-06-12 03:08 3148800 ----a-w- c:\windows\system32\win32k.sys
2012-07-12 06:01 . 2012-06-06 06:06 2004480 ----a-w- c:\windows\system32\msxml6.dll
2012-07-11 07:25 . 2012-07-11 07:25 -------- d-----w- c:\program files (x86)\ESET
2012-07-06 11:46 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2012-07-04 07:20 . 2012-07-04 07:19 268720 ----a-w- c:\windows\system32\javaws.exe
2012-07-04 07:20 . 2012-07-04 07:19 955840 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-07-04 07:20 . 2012-07-04 07:19 839096 ----a-w- c:\windows\system32\deployJava1.dll
2012-07-04 07:20 . 2012-07-04 07:19 189360 ----a-w- c:\windows\system32\javaw.exe
2012-07-04 07:20 . 2012-07-04 07:19 188840 ----a-w- c:\windows\system32\java.exe
2012-07-04 07:19 . 2012-07-04 07:19 -------- d-----w- c:\program files\Java
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-01 06:23 . 2012-06-14 13:55 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-01 06:23 . 2012-06-14 13:55 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-12 14:04 . 2012-06-14 10:32 59701280 ----a-w- c:\windows\system32\MRT.exe
2012-06-18 09:51 . 2012-06-18 09:51 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-06-18 09:51 . 2012-06-18 09:51 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-06-18 09:51 . 2012-06-18 09:51 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-06-18 09:51 . 2012-06-18 09:51 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-06-18 09:51 . 2012-06-18 09:51 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-06-18 09:51 . 2012-06-18 09:51 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-06-18 09:51 . 2012-06-18 09:51 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-06-18 09:51 . 2012-06-18 09:51 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-06-18 09:51 . 2012-06-18 09:51 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-06-18 09:51 . 2012-06-18 09:51 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-06-18 09:51 . 2012-06-18 09:51 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-06-18 09:51 . 2012-06-18 09:51 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-06-18 09:51 . 2012-06-18 09:51 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-06-18 09:51 . 2012-06-18 09:51 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-06-18 09:51 . 2012-06-18 09:51 89088 ----a-w- c:\windows\system32\ie4uinit.exe
2012-06-18 09:51 . 2012-06-18 09:51 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-06-18 09:51 . 2012-06-18 09:51 82432 ----a-w- c:\windows\system32\icardie.dll
2012-06-18 09:51 . 2012-06-18 09:51 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-06-18 09:51 . 2012-06-18 09:51 697344 ----a-w- c:\windows\system32\msfeeds.dll
2012-06-18 09:51 . 2012-06-18 09:51 65024 ----a-w- c:\windows\system32\pngfilt.dll
2012-06-18 09:51 . 2012-06-18 09:51 603648 ----a-w- c:\windows\system32\vbscript.dll
2012-06-18 09:51 . 2012-06-18 09:51 55296 ----a-w- c:\windows\system32\msfeedsbs.dll
2012-06-18 09:51 . 2012-06-18 09:51 534528 ----a-w- c:\windows\system32\ieapfltr.dll
2012-06-18 09:51 . 2012-06-18 09:51 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-06-18 09:51 . 2012-06-18 09:51 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-06-18 09:51 . 2012-06-18 09:51 452608 ----a-w- c:\windows\system32\dxtmsft.dll
2012-06-18 09:51 . 2012-06-18 09:51 448512 ----a-w- c:\windows\system32\html.iec
2012-06-18 09:51 . 2012-06-18 09:51 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2012-06-18 09:51 . 2012-06-18 09:51 403248 ----a-w- c:\windows\system32\iedkcs32.dll
2012-06-18 09:51 . 2012-06-18 09:51 39936 ----a-w- c:\windows\system32\iernonce.dll
2012-06-18 09:51 . 2012-06-18 09:51 3695416 ----a-w- c:\windows\system32\ieapfltr.dat
2012-06-18 09:51 . 2012-06-18 09:51 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-06-18 09:51 . 2012-06-18 09:51 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-06-18 09:51 . 2012-06-18 09:51 282112 ----a-w- c:\windows\system32\dxtrans.dll
2012-06-18 09:51 . 2012-06-18 09:51 267776 ----a-w- c:\windows\system32\ieaksie.dll
2012-06-18 09:51 . 2012-06-18 09:51 249344 ----a-w- c:\windows\system32\webcheck.dll
2012-06-18 09:51 . 2012-06-18 09:51 222208 ----a-w- c:\windows\system32\msls31.dll
2012-06-18 09:51 . 2012-06-18 09:51 197120 ----a-w- c:\windows\system32\msrating.dll
2012-06-18 09:51 . 2012-06-18 09:51 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-06-18 09:51 . 2012-06-18 09:51 163840 ----a-w- c:\windows\system32\ieakui.dll
2012-06-18 09:51 . 2012-06-18 09:51 160256 ----a-w- c:\windows\system32\wextract.exe
2012-06-18 09:51 . 2012-06-18 09:51 160256 ----a-w- c:\windows\system32\ieakeng.dll
2012-06-18 09:51 . 2012-06-18 09:51 149504 ----a-w- c:\windows\system32\occache.dll
2012-06-18 09:51 . 2012-06-18 09:51 145920 ----a-w- c:\windows\system32\iepeers.dll
2012-06-18 09:51 . 2012-06-18 09:51 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-06-18 09:51 . 2012-06-18 09:51 12288 ----a-w- c:\windows\system32\mshta.exe
2012-06-18 09:51 . 2012-06-18 09:51 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-06-18 09:51 . 2012-06-18 09:51 114176 ----a-w- c:\windows\system32\admparse.dll
2012-06-18 09:51 . 2012-06-18 09:51 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-06-18 09:51 . 2012-06-18 09:51 10752 ----a-w- c:\windows\system32\msfeedssync.exe
2012-06-18 09:51 . 2012-06-18 09:51 103936 ----a-w- c:\windows\system32\inseng.dll
2012-06-18 09:51 . 2012-06-18 09:51 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-06-14 12:47 . 2012-06-14 12:47 708608 ----a-w- c:\windows\SysWow64\wab32.dll
2012-06-14 11:05 . 2012-06-14 11:05 155648 ----a-r- c:\users\Daniel\AppData\Roaming\Microsoft\Installer\{D123A234-875B-484E-A226-7BCDA51F1252}\ARPPRODUCTICON.exe
2012-06-05 07:06 . 2012-06-05 07:06 82432 ----a-w- c:\windows\SysWow64\msxml4r.dll
2012-06-05 07:06 . 2012-06-05 07:06 28160 ----a-w- c:\windows\SysWow64\msxml3a.dll
2012-06-02 22:19 . 2012-06-19 06:00 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-19 06:00 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-19 06:00 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-19 06:00 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-19 06:00 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-19 06:00 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-19 06:00 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-19 06:00 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:15 . 2012-06-19 06:00 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-05-04 17:29 . 2012-06-18 11:52 772504 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-05-04 17:29 . 2012-06-18 11:52 687504 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-05-04 11:06 . 2012-06-14 10:24 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 11:00 . 2012-06-18 11:55 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-05-04 10:03 . 2012-06-14 10:24 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03 . 2012-06-14 10:24 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-05-04 09:59 . 2012-06-18 11:55 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MultiScreen"="c:\program files (x86)\MultiScreen\MultiScreen.exe" [2009-08-11 303104]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-05-01 348624]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-01 250056]
R3 Asushwio;Asushwio;d:\bin\64bit\Asushwio.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-18 113120]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys [2010-09-30 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys [2010-09-30 180736]
R3 SagedeAdministrationService30;Sage Administration Service 3.0;c:\program files (x86)\Sage\Application Server\3.0\Sagede.ApplicationServer.Administration.Service.exe [2012-04-03 9216]
R3 SagedeApplicationServerService30;Sage Application Server 2012;c:\program files (x86)\Sage\Application Server\3.0\Sagede.ApplicationServer.WindowsService.exe [2012-04-03 7744]
R3 SSGClient;Sage Secure Gateway Client;c:\program files (x86)\Sage\SecureGatewayClient\Gateway.Client.Hosts.Service.exe [2011-11-21 62216]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2012-05-02 27760]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-01 86224]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 Sage Mobile SystemControlService;Sage Mobile Konfigurationsdienst (Systemkontext);c:\program files (x86)\Common Files\Sage Software Shared\Mobile\Control Services\Sagede.Mobile.ControlServices.SystemContextService.exe [2012-04-23 8192]
S2 Sage Mobile UserControlService;Sage Mobile Konfigurationsdienst (Benutzerkontext);c:\program files (x86)\Common Files\Sage Software Shared\Mobile\Control Services\Sagede.Mobile.ControlServices.UserContextService.exe [2012-04-23 9728]
S2 SageDB 5.0;SageDB 5.0;c:\program files (x86)\Sage\SageDB 5.0\bin\mysqld-nt.exe [2011-07-18 5685248]
S2 SageMultiUserService40;Sage Mehrbenutzerdienst 4.0;c:\program files (x86)\Common Files\Sage Software Shared\MultiUserServiceServer.exe [2011-10-06 198144]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-04-04 24904]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
Inhalt des "geplante Tasks" Ordners
.
2012-08-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-14 06:23]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\or4bq4do.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxps://www.google.de/
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-08-02 10:49:21 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2012-08-02 08:49
.
Vor Suchlauf: 10 Verzeichnis(se), 284.033.613.824 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 283.856.691.200 Bytes frei
.
- - End Of File - - 40DA1FE15DA55667B53B6D3EF2DDA9A0
--- --- ---