Hier von Combofix
Combofix Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
ComboFix 13-06-13.01 - User 15.06.2013 16:00:10.3.8 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.16330.13845 [GMT 2:00]
ausgeführt von:: c:\users\User\Desktop\ComboFix.exe
AV: Kaspersky PURE 2.0 *Disabled/Updated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
FW: Kaspersky PURE 2.0 *Disabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}
SP: Kaspersky PURE 2.0 *Disabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\ntuser.dat
c:\users\User\AppData\Roaming\technic-launcher.jar
c:\windows\SysWow64\frapsvid.dll
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-05-15 bis 2013-06-15 ))))))))))))))))))))))))))))))
.
.
2013-06-15 14:09 . 2013-06-15 14:09 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-06-15 14:09 . 2013-06-15 14:09 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-06-15 14:09 . 2013-06-15 14:09 -------- d-----w- c:\users\Gast\AppData\Local\temp
2013-06-15 14:09 . 2013-06-15 14:09 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-06-15 13:31 . 2013-06-15 13:31 -------- d-----w- C:\FRST
2013-06-15 11:20 . 2013-06-15 11:20 -------- d-----w- c:\programdata\VS Revo Group
2013-06-15 11:09 . 2013-06-15 11:09 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-06-15 11:09 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-06-15 10:46 . 2013-05-13 06:37 9460464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3E64C082-C017-4ED5-BB82-8A0299946804}\mpengine.dll
2013-06-12 15:16 . 2013-05-17 01:25 257536 ----a-w- c:\program files (x86)\Internet Explorer\ieproxy.dll
2013-06-12 14:16 . 2013-05-10 05:49 30720 ----a-w- c:\windows\system32\cryptdlg.dll
2013-06-08 18:44 . 2013-06-08 18:47 -------- d-----w- c:\users\User\AppData\Roaming\.technic - Kopie
2013-06-08 18:44 . 2013-06-08 18:44 -------- d-----w- c:\users\User\AppData\Roaming\.techniclauncher - Kopie
2013-06-08 14:15 . 2013-06-08 14:14 311200 ----a-w- c:\windows\system32\javaws.exe
2013-06-08 14:15 . 2013-06-08 14:15 108448 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-06-08 14:15 . 2013-06-08 14:14 188832 ----a-w- c:\windows\system32\javaw.exe
2013-06-08 14:15 . 2013-06-08 14:14 188320 ----a-w- c:\windows\system32\java.exe
2013-06-08 14:14 . 2013-06-08 14:14 -------- d-----w- c:\program files\Java
2013-06-08 14:13 . 2013-06-08 14:13 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-06-08 14:13 . 2013-06-08 14:13 -------- d-----w- c:\program files (x86)\Java
2013-06-08 14:11 . 2013-06-08 14:11 810 ----a-w- c:\windows\system32\cc_20130608_161137.reg
2013-06-08 13:44 . 2013-06-08 13:44 -------- d-----w- c:\users\User\AppData\Local\VS Revo Group
2013-06-08 13:44 . 2009-12-30 09:21 31800 ----a-w- c:\windows\system32\drivers\revoflt.sys
2013-06-08 13:44 . 2013-06-08 13:44 -------- d-----w- c:\program files\VS Revo Group
2013-06-08 10:30 . 2013-06-08 10:30 1836 ----a-w- c:\windows\system32\cc_20130608_123004.reg
2013-06-08 10:27 . 2013-06-08 10:27 2758 ----a-w- c:\windows\system32\cc_20130608_122715.reg
2013-06-08 10:26 . 2013-06-08 10:26 32032 ----a-w- c:\windows\system32\cc_20130608_122655.reg
2013-06-08 09:47 . 2013-06-08 09:47 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2013-06-03 14:36 . 2013-06-08 09:43 -------- d-----w- c:\program files (x86)\Aurora
2013-06-01 17:10 . 2013-06-01 17:10 -------- d-----w- c:\programdata\Caphyon
2013-06-01 17:09 . 2013-06-01 17:09 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR
2013-06-01 17:06 . 2013-06-01 17:06 -------- d-----w- c:\users\User\AppData\Roaming\TJMM Assemblys
2013-05-31 21:25 . 2013-05-31 21:25 -------- d-----w- c:\users\User\AppData\Roaming\.mc3totalconversion
2013-05-31 21:24 . 2013-06-15 10:44 -------- d-----w- c:\users\User\AppData\Roaming\.techniclauncher
2013-05-29 20:14 . 2012-06-09 17:21 206336 ----a-w- c:\windows\system32\unrar.dll
2013-05-29 20:14 . 2012-06-25 18:00 92160 ----a-w- c:\windows\system32\ff_vfw.dll
2013-05-29 20:14 . 2013-05-29 20:14 -------- d-----w- c:\program files\K-Lite Codec Pack x64
2013-05-29 15:45 . 2013-05-29 15:45 -------- d-----w- c:\windows\de
2013-05-29 15:44 . 2013-05-29 15:44 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2013-05-29 15:43 . 2013-05-29 15:44 -------- d-----w- c:\program files (x86)\Windows Live
2013-05-29 15:39 . 2013-05-29 20:04 -------- d-----w- c:\users\User\AppData\Local\Windows Live
2013-05-29 15:39 . 2013-05-29 15:39 -------- d-----w- c:\program files (x86)\Common Files\Windows Live
2013-05-29 14:32 . 2013-05-29 14:32 -------- d-----w- c:\program files (x86)\Bandicam
2013-05-29 14:25 . 2013-05-29 14:32 -------- d-----w- c:\program files (x86)\BandiMPEG1
2013-05-29 14:15 . 2013-05-29 14:17 -------- d-----w- C:\Fraps
2013-05-29 12:26 . 2013-05-29 15:55 -------- d-----w- c:\program files (x86)\rFactor
2013-05-29 11:43 . 2013-05-29 11:43 -------- d-----w- c:\users\User\AppData\Local\Craften_Dev_Team
2013-05-29 11:43 . 2013-05-29 15:45 -------- d-----w- c:\program files (x86)\Craften Terminal
2013-05-21 14:10 . 2013-05-21 14:10 -------- d-----w- c:\program files (x86)\Convar
2013-05-21 14:10 . 2003-07-18 11:58 516784 ----a-r- c:\windows\SysWow64\XceedCry.dll
2013-05-21 14:10 . 2002-04-12 11:19 28672 ----a-w- c:\windows\SysWow64\DartWeb.oca
2013-05-21 14:10 . 2002-02-28 07:46 217088 ----a-w- c:\windows\SysWow64\DartSock.dll
2013-05-21 14:10 . 2002-02-21 08:12 118784 ----a-w- c:\windows\SysWow64\DartWeb.dll
2013-05-21 14:10 . 2002-02-04 00:43 44544 ----a-w- c:\windows\SysWow64\msxml4a.dll
2013-05-21 14:10 . 1998-06-17 22:00 89360 ----a-w- c:\windows\SysWow64\VB5DB.DLL
2013-05-21 14:10 . 1998-06-13 20:53 44544 ----a-w- c:\windows\SysWow64\Gif89.dll
2013-05-17 19:55 . 2013-05-17 20:01 -------- d-----w- c:\program files (x86)\The Guild 2 - Renaissance
2013-05-17 16:07 . 2013-05-17 16:07 -------- d-----w- c:\users\User\AppData\Local\CrashRpt
2013-05-17 15:38 . 2013-05-17 15:38 -------- d-----w- c:\program files (x86)\Atari
2013-05-17 14:21 . 2013-04-10 06:01 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-05-17 14:21 . 2013-04-10 06:01 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-05-17 14:21 . 2011-02-03 11:25 144384 ----a-w- c:\windows\system32\cdd.dll
2013-05-17 14:21 . 2013-02-27 06:02 111448 ----a-w- c:\windows\system32\consent.exe
2013-05-17 14:21 . 2013-02-27 05:52 14172672 ----a-w- c:\windows\system32\shell32.dll
2013-05-17 14:21 . 2013-02-27 05:52 197120 ----a-w- c:\windows\system32\shdocvw.dll
2013-05-17 14:21 . 2013-02-27 05:48 1930752 ----a-w- c:\windows\system32\authui.dll
2013-05-17 14:21 . 2013-02-27 05:47 70144 ----a-w- c:\windows\system32\appinfo.dll
2013-05-17 14:21 . 2013-02-27 04:49 1796096 ----a-w- c:\windows\SysWow64\authui.dll
2013-05-17 14:20 . 2013-04-10 03:30 3153920 ----a-w- c:\windows\system32\win32k.sys
2013-05-17 14:20 . 2013-03-19 05:53 48640 ----a-w- c:\windows\system32\wwanprotdim.dll
2013-05-17 14:20 . 2013-03-19 05:53 230400 ----a-w- c:\windows\system32\wwansvc.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-12 15:16 . 2012-03-30 20:40 75825640 ----a-w- c:\windows\system32\MRT.exe
2013-06-12 14:28 . 2013-02-27 19:10 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-12 14:28 . 2013-02-27 19:10 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-06-10 13:22 . 2013-04-14 16:38 282104 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-06-10 13:22 . 2013-04-14 16:28 282104 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-06-10 13:22 . 2013-04-14 16:28 234768 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-06-08 14:14 . 2012-03-28 13:36 1092512 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-06-08 14:14 . 2012-03-28 13:36 971680 ----a-w- c:\windows\system32\deployJava1.dll
2013-06-08 14:13 . 2012-04-30 12:04 866720 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-06-08 14:13 . 2012-03-28 13:37 788896 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-05-29 15:44 . 2012-07-17 12:37 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-03 19:24 . 2013-05-03 19:24 634 ----a-w- c:\windows\system32\cc_20130503_212404.reg
2013-05-02 00:06 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-05-01 16:23 . 2013-05-01 16:23 286 ----a-w- c:\windows\system32\cc_20130501_182327.reg
2013-05-01 16:23 . 2013-05-01 16:23 147638 ----a-w- c:\windows\system32\cc_20130501_182309.reg
2013-04-27 15:31 . 2013-04-27 15:31 45056 ----a-r- c:\users\User\AppData\Roaming\Microsoft\Installer\{B2390904-74BD-48AA-B2CC-6612F8D46379}\GameShadow.exe1_0A3DE514292C4EBA987823B82B0B2BA2.exe
2013-04-27 15:31 . 2013-04-27 15:31 45056 ----a-r- c:\users\User\AppData\Roaming\Microsoft\Installer\{B2390904-74BD-48AA-B2CC-6612F8D46379}\GameShadow.exe_0A3DE514292C4EBA987823B82B0B2BA2.exe
2013-04-27 15:31 . 2013-04-27 15:31 45056 ----a-r- c:\users\User\AppData\Roaming\Microsoft\Installer\{B2390904-74BD-48AA-B2CC-6612F8D46379}\ARPPRODUCTICON.exe
2013-04-24 14:41 . 2013-04-14 16:28 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-04-13 05:49 . 2013-05-17 14:21 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49 . 2013-05-17 14:21 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49 . 2013-05-17 14:21 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49 . 2013-05-17 14:21 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45 . 2013-05-17 14:21 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45 . 2013-05-17 14:21 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-04-12 14:45 . 2013-04-24 12:12 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-07 14:39 . 2013-01-12 11:06 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2013-04-07 14:39 . 2013-01-12 11:06 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2013-04-02 10:04 . 2013-04-02 10:04 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2013-03-30 10:28 . 2013-02-05 14:06 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2013-03-30 10:28 . 2013-02-05 14:06 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2013-03-29 12:02 . 2013-01-12 11:06 1236816 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2013-03-19 06:04 . 2013-04-10 12:25 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-03-19 05:46 . 2013-04-10 12:25 43520 ----a-w- c:\windows\system32\csrsrv.dll
2013-03-19 05:04 . 2013-04-10 12:25 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-03-19 05:04 . 2013-04-10 12:25 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-03-19 04:47 . 2013-04-10 12:25 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll
2013-03-19 03:06 . 2013-04-10 12:25 112640 ----a-w- c:\windows\system32\smss.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{9B6B03F1-16CF-4491-BBBB-E872802DD717}]
2013-02-03 15:26 111616 ----a-w- c:\programdata\DNSErrorHelper\bho.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 130736 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 130736 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 130736 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\KAVOverlayIcon]
@="{dd230880-495a-11d1-b064-008048ec2fc5}"
[HKEY_CLASSES_ROOT\CLSID\{dd230880-495a-11d1-b064-008048ec2fc5}]
2012-08-30 21:24 496056 ----a-w- c:\program files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\shellex.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-03 19603048]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-01-05 291608]
"RoccatKonePure"="c:\program files (x86)\ROCCAT\Kone Pure Mouse\KonePureMonitor.EXE" [2012-11-30 569040]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe" [2012-08-30 202328]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R1 XSpaceWg;XSpaceWg;c:\windows\system32\drivers\XSpaceWg.sys;c:\windows\SYSNATIVE\drivers\XSpaceWg.sys [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 lvpepf64;Volume Adapter;c:\windows\system32\DRIVERS\lv302a64.sys;c:\windows\SYSNATIVE\DRIVERS\lv302a64.sys [x]
R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
R3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\drivers\LVUSBS64.sys;c:\windows\SYSNATIVE\drivers\LVUSBS64.sys [x]
R3 miniusb;FrameManager Display Adapter;c:\windows\system32\DRIVERS\sam_miniusb.sys;c:\windows\SYSNATIVE\DRIVERS\sam_miniusb.sys [x]
R3 papycpu;papycpu; [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys;c:\windows\SYSNATIVE\DRIVERS\revoflt.sys [x]
R3 Samsung UPD Service2;Samsung UPD Service2;c:\windows\System32\SUPDSvc2.exe;c:\windows\SYSNATIVE\SUPDSvc2.exe [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe;c:\program files (x86)\Tunngle\TnglCtrl.exe [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 vvftav;vvftav;c:\windows\system32\drivers\vvftav.sys;c:\windows\SYSNATIVE\drivers\vvftav.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\users\User\AppData\Local\Temp\tmp624B.tmp;c:\users\User\AppData\Local\Temp\tmp624B.tmp [x]
R3 ZSMC0305;USB PC Camera VC305;c:\windows\system32\Drivers\usbVM305.sys;c:\windows\SYSNATIVE\Drivers\usbVM305.sys [x]
S0 CSCrySec;InfoWatch Encrypt Sector Library driver;c:\windows\system32\DRIVERS\CSCrySec.sys;c:\windows\SYSNATIVE\DRIVERS\CSCrySec.sys [x]
S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 CSVirtualDiskDrv;InfoWatch Virtual Disk driver;c:\windows\system32\DRIVERS\CSVirtualDiskDrv.sys;c:\windows\SYSNATIVE\DRIVERS\CSVirtualDiskDrv.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys;c:\windows\SYSNATIVE\DRIVERS\kl2.sys [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys;c:\windows\SYSNATIVE\drivers\acedrv11.sys [x]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
S2 CSObjectsSrv;Verwaltungsservice vom CryproStorage-System;c:\program files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe;c:\program files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [x]
S2 LVPrcS64;Process Monitor;c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe;c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
S3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys;c:\windows\SYSNATIVE\DRIVERS\LVPr2M64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 SODI;SODI;c:\windows\system32\DRIVERS\sam_miniport.sys;c:\windows\SYSNATIVE\DRIVERS\sam_miniport.sys [x]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys;c:\windows\SYSNATIVE\DRIVERS\tap0901t.sys [x]
S4 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [x]
S4 FrameManager Service;FrameManager Service;c:\program files\Samsung\FrameManager\sam_service.exe;c:\program files\Samsung\FrameManager\sam_service.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-06-06 18:29 1165776 ----a-w- c:\program files (x86)\Google\Chrome\Application\27.0.1453.110\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-06-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-27 14:28]
.
2013-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-10 20:37]
.
2013-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-10 20:37]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 164016 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 164016 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 164016 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 164016 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\KAVOverlayIcon]
@="{dd230880-495a-11d1-b064-008048ec2fc5}"
[HKEY_CLASSES_ROOT\CLSID\{dd230880-495a-11d1-b064-008048ec2fc5}]
2012-08-30 21:26 566712 ----a-w- c:\program files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\x64\shellex.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-01-16 12445288]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://google.de/
mStart Page = about :blank
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: An OneNote s&enden - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 217.0.43.97 217.0.43.113
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\h2syn23t.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - ExtSQL: 2013-04-16 19:43; {fe272bd1-5f76-4ea4-8501-a05d35d823fc}; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\h2syn23t.default\extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi
FF - ExtSQL: 2013-04-16 19:43; elemhidehelper@adblockplus.org; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\h2syn23t.default\extensions\elemhidehelper@adblockplus.org.xpi
FF - ExtSQL: 2013-05-12 21:19; helper@savefrom.net; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\h2syn23t.default\extensions\helper@savefrom.net.xpi
FF - ExtSQL: 2013-05-28 20:52; client@anonymox.net; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\h2syn23t.default\extensions\client@anonymox.net.xpi
FF - user.js: network.http.max-connections-per-server - 6
FF - user.js: network.http.max-persistent-connections-per-server - 3
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRing0_1_2_0]
"ImagePath"="\??\c:\users\User\AppData\Local\Temp\tmp624B.tmp"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-06-15 16:16:10
ComboFix-quarantined-files.txt 2013-06-15 14:16
.
Vor Suchlauf: 38 Verzeichnis(se), 1.517.633.789.952 Bytes frei
Nach Suchlauf: 39 Verzeichnis(se), 1.517.495.947.264 Bytes frei
.
- - End Of File - - A360E2997A384DAF9CED024139DA4D67
--- --- ---
A36C5E4F47E84449FF07ED3517B43A31