Code:
Alles auswählen Aufklappen ATTFilter
ComboFix 13-02-13.02 - Alex 14.02.2013 23:24:09.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8127.6335 [GMT 1:00]
ausgeführt von:: c:\users\Alex\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\ChilkatMail_v7_9.dll
E:\Autorun.inf
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-01-14 bis 2013-02-14 ))))))))))))))))))))))))))))))
.
.
2013-02-14 17:33 . 2013-02-14 17:33 -------- d-----w- C:\_OTL
2013-02-14 11:01 . 2013-02-14 11:01 -------- d-----w- c:\users\Alex\AppData\Local\ElevatedDiagnostics
2013-02-14 10:57 . 2013-02-14 10:57 -------- d-----w- c:\users\Alex\AppData\Local\Mozilla
2013-02-14 10:57 . 2013-02-14 10:57 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2013-02-14 10:17 . 2013-02-14 10:17 -------- d-----w- c:\program files\CCleaner
2013-02-13 21:46 . 2013-01-09 01:10 996352 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-13 21:46 . 2013-01-08 22:01 768000 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-13 20:31 . 2013-02-13 20:31 -------- d-----w- c:\users\Alex\AppData\Local\DoNotTrackPlus
2013-02-13 20:31 . 2013-02-13 20:31 -------- d-----w- c:\users\Alex\AppData\Local\AskToolbar
2013-02-13 20:02 . 2013-02-13 20:05 -------- d-----w- c:\program files (x86)\GameforgeLive
2013-02-13 15:54 . 2013-02-13 15:54 -------- d-----w- c:\users\Alex\AppData\Roaming\Avira
2013-02-13 15:47 . 2013-02-13 15:47 -------- d-----w- c:\program files (x86)\Ask.com
2013-02-13 15:47 . 2013-02-13 15:47 -------- d-----w- C:\Firefox
2013-02-13 15:47 . 2013-02-13 15:47 -------- d-----w- c:\users\Alex\AppData\Local\APN
2013-02-13 15:47 . 2013-02-13 15:47 -------- d-----w- c:\programdata\Avira
2013-02-13 15:47 . 2013-02-13 15:47 -------- d-----w- c:\program files (x86)\Avira
2013-02-13 15:47 . 2012-12-03 14:36 129216 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-02-13 15:47 . 2012-12-03 14:36 99912 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-02-13 15:47 . 2012-11-16 19:17 27800 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-02-13 11:32 . 2013-02-13 11:32 181064 ----a-w- c:\windows\PSEXESVC.EXE
2013-02-13 11:30 . 2013-02-13 11:32 -------- d-----w- C:\Tweaking.com_Windows_Repair_Logs
2013-02-13 11:29 . 2013-01-05 05:53 5553512 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-02-13 11:29 . 2013-01-05 05:00 3967848 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-02-13 11:29 . 2013-01-05 05:00 3913064 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-02-13 11:29 . 2013-01-04 05:46 215040 ----a-w- c:\windows\system32\winsrv.dll
2013-02-13 11:29 . 2013-01-04 04:51 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2013-02-13 11:29 . 2013-01-04 03:26 3153408 ----a-w- c:\windows\system32\win32k.sys
2013-02-13 11:29 . 2013-01-04 02:47 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2013-02-13 11:29 . 2013-01-04 02:47 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2013-02-13 11:29 . 2013-01-04 02:47 2048 ----a-w- c:\windows\SysWow64\user.exe
2013-02-13 11:29 . 2013-01-04 02:47 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2013-02-13 11:29 . 2013-01-03 06:00 1913192 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-02-13 11:29 . 2013-01-03 06:00 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2013-02-12 18:37 . 2013-02-12 18:38 -------- d-----w- c:\users\Alex\AppData\Local\Rockstar Games
2013-02-12 18:37 . 2013-02-12 18:37 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2013-02-12 18:37 . 2013-02-12 18:37 -------- d-----w- c:\windows\SysWow64\xlive
2013-02-12 08:21 . 2013-01-18 11:15 9161176 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{38666730-A543-42A7-80B7-3069825FE261}\mpengine.dll
2013-02-11 13:50 . 2013-02-11 13:50 -------- d-----w- c:\users\Alex\AppData\Roaming\MP3SkypeRecorder
2013-02-11 13:50 . 2013-02-11 13:50 -------- d-----w- c:\users\Alex\AppData\Local\Alexander_Nikiforov
2013-02-11 13:50 . 2013-02-11 13:53 -------- d-----w- c:\program files (x86)\MP3 Skype Recorder
2013-02-11 09:13 . 2013-02-11 09:13 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-02-11 09:13 . 2013-02-11 09:13 -------- d-----w- c:\program files (x86)\Java
2013-02-09 13:50 . 2013-02-14 18:45 -------- d-----w- c:\users\Alex\AppData\Local\Diagnostics
2013-02-08 15:37 . 2013-02-08 15:37 -------- d-----w- c:\users\Alex\AppData\Roaming\Malwarebytes
2013-02-08 15:36 . 2013-02-08 15:36 -------- d-----w- c:\programdata\Malwarebytes
2013-02-08 15:36 . 2013-02-08 15:36 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-02-08 15:36 . 2012-12-14 15:49 24176 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-02-07 23:20 . 2013-02-07 23:20 -------- d-----w- c:\users\Alex\AppData\Roaming\Windows SideBar
2013-02-07 20:11 . 2013-02-07 20:11 -------- d-----w- c:\program files (x86)\Yontoo
2013-02-07 20:11 . 2013-02-14 10:54 -------- d-----w- c:\programdata\Tarma Installer
2013-02-07 20:10 . 2013-02-07 20:11 -------- d-----w- c:\users\Alex\AppData\Roaming\BitTorrent
2013-02-04 09:39 . 2013-02-04 09:39 -------- d-----w- c:\program files (x86)\Common Files\Skype
2013-02-04 09:39 . 2013-02-04 09:39 -------- d-----r- c:\program files (x86)\Skype
2013-02-03 17:06 . 2003-08-15 15:02 69632 ------w- c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe
2013-02-03 17:06 . 2003-08-15 15:01 380928 ------w- c:\program files (x86)\Common Files\InstallShield\UpdateService\agent.exe
2013-02-03 17:06 . 2003-08-15 14:57 212992 ------w- c:\program files (x86)\Common Files\InstallShield\UpdateService\ISDM.exe
2013-02-03 17:05 . 2003-09-03 01:28 724992 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iKernel.dll
2013-02-03 17:05 . 2003-09-03 01:27 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\ctor.dll
2013-02-03 17:05 . 2003-09-03 01:26 266240 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iscript.dll
2013-02-03 17:05 . 2003-09-03 01:26 192512 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iuser.dll
2013-02-03 17:05 . 2003-09-03 01:25 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe
2013-02-03 17:05 . 2013-02-03 17:05 311428 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\Setup.dll
2013-02-03 17:05 . 2013-02-03 17:05 184452 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iGdi.dll
2013-02-02 19:28 . 2010-02-23 06:46 23680 ----a-w- c:\windows\system32\drivers\IOMap64.sys
2013-02-02 19:26 . 2013-02-02 19:26 -------- d-----w- c:\windows\Downloaded Installations
2013-02-02 17:20 . 2013-02-02 17:20 -------- d-----w- c:\users\Alex\AppData\Local\Sony Online Entertainment
2013-02-02 16:42 . 2013-02-02 16:42 -------- d-----w- c:\users\Alex\AppData\Local\SCE
2013-02-02 16:38 . 2013-02-02 16:38 -------- d-----w- c:\users\Alex\AppData\Local\4A Games
2013-02-01 16:19 . 2013-02-01 16:19 -------- d-----w- c:\users\Alex\AppData\Local\Gameforge4d
2013-02-01 16:18 . 2013-02-01 16:18 -------- d-----w- c:\users\Alex\AppData\Local\Programs
2013-02-01 09:57 . 2013-02-01 09:57 -------- d--h--r- c:\users\Alex\AppData\Roaming\SecuROM
2013-02-01 08:51 . 2013-02-01 22:40 -------- d-----w- c:\program files (x86)\Common Files\Steam
2013-01-31 21:00 . 2013-01-31 22:41 -------- d-----w- c:\users\Alex\AppData\Roaming\.minecraft
2013-01-31 15:47 . 2013-02-08 09:53 -------- d-----w- c:\users\Alex\AppData\Local\Spotify
2013-01-31 15:46 . 2013-02-09 18:51 -------- d-----w- c:\users\Alex\AppData\Roaming\Spotify
2013-01-31 14:45 . 2013-01-31 14:45 -------- d-----w- c:\users\Alex\AppData\Roaming\Need for Speed World
2013-01-31 14:03 . 2013-01-31 14:03 -------- d-----w- c:\users\Alex\AppData\Local\Electronic_Arts_Inc
2013-01-31 13:59 . 2013-01-31 13:59 -------- d-----w- c:\programdata\Electronic Arts
2013-01-31 13:59 . 2013-01-31 13:59 -------- d-----w- c:\program files (x86)\Electronic Arts
2013-01-31 13:35 . 2013-01-31 13:35 -------- d-----w- c:\users\Alex\.thumbnails
2013-01-31 13:33 . 2013-01-31 13:33 -------- d-----w- c:\users\Alex\AppData\Local\fontconfig
2013-01-31 13:33 . 2013-02-03 23:25 -------- d-----w- c:\users\Alex\.gimp-2.8
2013-01-31 13:33 . 2013-01-31 13:33 -------- d-----w- c:\users\Alex\AppData\Local\gegl-0.2
2013-01-31 13:14 . 2013-01-31 13:14 -------- d-----w- c:\program files (x86)\PlanetSide 2
2013-01-31 11:23 . 2012-11-30 05:41 424448 ----a-w- c:\windows\system32\KernelBase.dll
2013-01-29 14:17 . 2013-01-29 14:17 -------- d-----w- c:\program files (x86)\AMD APP
2013-01-29 14:16 . 2013-01-29 14:16 -------- d-----w- c:\program files\ATI Technologies
2013-01-29 14:16 . 2013-01-29 14:16 -------- d-----w- c:\program files\ATI
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-13 21:48 . 2012-05-08 07:26 70004024 ----a-w- c:\windows\system32\MRT.exe
2013-02-11 09:13 . 2013-01-04 23:37 861088 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-02-11 09:13 . 2013-01-04 23:37 782240 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-01-17 00:28 . 2010-11-21 03:27 273840 ------w- c:\windows\system32\MpSigStub.exe
2013-01-04 23:42 . 2013-01-04 23:43 959976 ----a-w- c:\windows\system32\deployJava1.dll
2013-01-04 23:42 . 2013-01-04 23:43 308200 ----a-w- c:\windows\system32\javaws.exe
2013-01-04 23:42 . 2013-01-04 23:43 1081320 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-01-04 23:42 . 2013-01-04 23:43 188392 ----a-w- c:\windows\system32\javaw.exe
2013-01-04 23:42 . 2013-01-04 23:43 188392 ----a-w- c:\windows\system32\java.exe
2013-01-04 23:42 . 2013-01-04 23:43 108008 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-01-04 04:43 . 2013-02-13 11:29 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2012-12-29 10:34 . 2012-10-10 20:23 1504696 ----a-w- c:\windows\system32\nvdispgenco64.dll
2012-12-29 10:34 . 2012-10-10 20:22 2504248 ----a-w- c:\windows\SysWow64\nvapi.dll
2012-12-29 10:34 . 2012-05-08 05:56 2824656 ----a-w- c:\windows\system32\nvapi64.dll
2012-12-29 10:34 . 2012-05-08 05:56 1813432 ----a-w- c:\windows\system32\nvdispco64.dll
2012-12-29 10:34 . 2012-05-08 05:56 15129064 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2012-12-29 10:34 . 2012-05-08 05:56 15052368 ----a-w- c:\windows\system32\nvwgf2umx.dll
2012-12-29 10:34 . 2012-05-08 05:56 1107592 ----a-w- c:\windows\system32\nvumdshimx.dll
2012-12-29 08:40 . 2012-05-23 07:09 6382008 ----a-w- c:\windows\system32\nvcpl.dll
2012-12-29 08:40 . 2012-05-23 07:09 3455416 ----a-w- c:\windows\system32\nvsvc64.dll
2012-12-29 08:40 . 2012-05-23 07:09 2923201 ----a-w- c:\windows\system32\nvcoproc.bin
2012-12-29 08:40 . 2012-05-23 07:09 884152 ----a-w- c:\windows\system32\nvvsvc.exe
2012-12-29 08:40 . 2012-05-23 07:09 63928 ----a-w- c:\windows\system32\nvshext.dll
2012-12-29 08:40 . 2012-05-23 07:09 2558392 ----a-w- c:\windows\system32\nvsvcr.dll
2012-12-29 08:40 . 2012-05-23 07:09 118712 ----a-w- c:\windows\system32\nvmctray.dll
2012-12-29 01:54 . 2012-12-29 01:54 550328 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2012-12-16 17:11 . 2013-01-05 10:04 46080 ----a-w- c:\windows\system32\atmlib.dll
2012-12-16 14:45 . 2013-01-05 10:04 367616 ----a-w- c:\windows\system32\atmfd.dll
2012-12-16 14:13 . 2013-01-05 10:04 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2012-12-16 14:13 . 2013-01-05 10:04 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2013-02-08 1521800]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2013-02-08 14:10 1521800 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2013-01-10 22:05 197920 ----a-w- c:\program files (x86)\Yontoo\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2013-02-08 1521800]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-01-08 18705664]
"Spotify Web Helper"="c:\users\Alex\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2013-01-31 1199576]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-03-27 291608]
"ApnUpdater"="c:\program files (x86)\Ask.com\Updater\Updater.exe" [2013-02-08 1644680]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-02-13 385248]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\E:\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"IAStorIcon"=c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
"IMSS"="c:\program files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
"IntelSBA"=c:\program files (x86)\Intel\Intel(R) Small Business Advantage\Service\SBALaunchDelay.exe "c:\program files (x86)\Intel\Intel(R) Small Business Advantage\UI\IntelSmallBusinessAdvantage.exe -minimized" 60
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-01-08 161536]
R3 FairplayKD;FairplayKD;c:\programdata\MTA San Andreas All\1.3\temp\FairplayKD.sys [x]
R3 iaStorA;iaStorA;c:\windows\system32\drivers\iaStorA.sys [2011-12-19 566192]
R3 iaStorS;iaStorS;c:\windows\system32\drivers\iaStorS.sys [2011-12-19 637360]
R3 MSICDSetup;MSICDSetup;D:\CDriver64.sys [x]
R3 NTIOLib_1_0_3;NTIOLib_1_0_3;c:\program files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [x]
R3 NTIOLib_1_0_C;NTIOLib_1_0_C;D:\NTIOLib_X64.sys [x]
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\drivers\nvstusb.sys [2012-05-15 398656]
R3 PciIsaSerial;PCI-ISA Communication Port;c:\windows\system32\drivers\PciIsaSerial.sys [2008-12-19 68608]
R3 PciPPorts;PCI ECP Parallel Port;c:\windows\system32\drivers\PciPPorts.sys [2009-07-23 96768]
R3 PciSPorts;High-Speed PCI Serial Port;c:\windows\system32\drivers\PciSPorts.sys [2008-12-19 122880]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [2010-11-01 14544]
R3 X6va011;X6va011;c:\windows\SysWOW64\Drivers\X6va011 [x]
S0 iaStorF;iaStorF;c:\windows\system32\drivers\iaStorF.sys [2011-12-19 24496]
S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\drivers\iusb3hcs.sys [2012-03-27 19224]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2012-11-16 27800]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2013-02-13 86752]
S2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [2013-02-13 565472]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-02-01 13592]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-06-19 634632]
S2 Intel(R) Small Business Advantage;Intel(R) Small Business Advantage;c:\program files (x86)\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe [2012-02-27 49376]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-07-19 166720]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-12-29 383416]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2012-12-14 3467768]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-19 365376]
S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys [2012-03-27 356632]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys [2012-03-27 789272]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-02-16 676968]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 16355130
*NewlyCreated* - 34131717
*NewlyCreated* - 80125705
*Deregistered* - 16355130
*Deregistered* - 34131717
*Deregistered* - 80125705
.
Inhalt des "geplante Tasks" Ordners
.
2013-02-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-992614989-2845173188-1475335217-1003Core.job
- c:\users\Alex\AppData\Local\Google\Update\GoogleUpdate.exe [2013-01-04 23:21]
.
2013-02-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-992614989-2845173188-1475335217-1003UA.job
- c:\users\Alex\AppData\Local\Google\Update\GoogleUpdate.exe [2013-01-04 23:21]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-08-15 7288424]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=54728d0c-c1c1-40a3-bbe8-b69833c9529f&searchtype=ds&q={searchTerms}
LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\6up0nnlq.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
WebBrowser-{707DB484-2428-402D-AFB5-D85B387544C7} - (no file)
AddRemove-IMLock - c:\windows\System32\tnblf.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va011]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va011"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-992614989-2845173188-1475335217-1003\Software\SecuROM\License information*]
"datasecu"=hex:26,6c,65,25,ed,1c,bf,3d,77,7e,23,21,2e,30,66,a1,32,6a,ef,8c,b1,
65,83,46,43,7d,d3,36,f3,dc,2c,a9,ab,2c,ab,6b,a4,99,43,1e,97,66,75,f9,64,0c,\
"rkeysecu"=hex:48,cf,30,1e,52,2b,f8,78,70,90,c7,4d,67,85,9c,f2
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-02-14 23:30:59
ComboFix-quarantined-files.txt 2013-02-14 22:30
.
Vor Suchlauf: 20 Verzeichnis(se), 676.872.355.840 Bytes frei
Nach Suchlauf: 24 Verzeichnis(se), 676.728.524.800 Bytes frei
.
- - End Of File - - 22761785C1E97850131A601E3583A248