soll ich den combofix nochmal durchlaufen lassen, wenn ich nebenbei doch am pc was gemacht hab.
das ist wo ich was gemacht habe nebenbei
Combofix :
Code:
Alles auswählen Aufklappen ATTFilter
ComboFix 13-08-13.02 - Mandy 19.08.2013 19:25:37.1.2 - x86
Microsoft Windows 7 Starter 6.1.7601.1.1252.49.1031.18.1013.304 [GMT 2:00]
ausgeführt von:: c:\users\Mandy\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\DealPly
c:\program files\DealPly\uninst.exe
c:\program files\Windows Live\Messenger\msacm32.dll
c:\programdata\1376322694.bdinstall.bin
c:\programdata\1376322871.bdinstall.bin
c:\programdata\1376325072.1136.bin
c:\programdata\1376325072.1376.bin
c:\programdata\1376325072.1632.bin
c:\programdata\1376325072.2580.bin
c:\programdata\1376325072.2668.bin
c:\programdata\1376325072.2868.bin
c:\programdata\1376325072.3532.bin
c:\programdata\1376325072.3768.bin
c:\programdata\1376325072.4340.bin
c:\programdata\1376325072.4364.bin
c:\programdata\1376325072.5044.bin
c:\programdata\1376325072.5368.bin
c:\programdata\1376325072.784.bin
c:\users\blaablaa\AppData\Roaming\Microsoft\Windows\.data
c:\users\blaablaa\AppData\Roaming\Microsoft\Windows\unicode2.nls
c:\windows\system32\roboot.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-07-19 bis 2013-08-19 ))))))))))))))))))))))))))))))
.
.
2013-08-19 17:49 . 2013-08-19 17:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-19 17:49 . 2013-08-19 17:49 -------- d-----w- c:\users\blaablaa\AppData\Local\temp
2013-08-19 17:33 . 2013-08-19 17:33 60872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A2268201-9EC7-4AAC-B6FF-F9F7ADA78FD7}\offreg.dll
2013-08-16 07:54 . 2013-07-15 01:34 7143960 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A2268201-9EC7-4AAC-B6FF-F9F7ADA78FD7}\mpengine.dll
2013-08-14 21:15 . 2013-08-14 21:15 -------- d-----w- c:\users\Mandy\AppData\Roaming\SoftMaker
2013-08-14 21:14 . 2013-08-14 21:14 -------- d-----w- c:\program files\SoftMaker Viewer
2013-08-14 21:13 . 2010-09-23 11:15 98344 ----a-w- c:\windows\unTMV.exe
2013-08-14 08:04 . 2013-07-09 04:50 652800 ----a-w- c:\windows\system32\rpcrt4.dll
2013-08-14 08:04 . 2013-07-09 04:52 175104 ----a-w- c:\windows\system32\wintrust.dll
2013-08-14 08:04 . 2013-07-09 04:46 1166848 ----a-w- c:\windows\system32\crypt32.dll
2013-08-14 08:04 . 2013-07-09 04:46 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2013-08-14 08:04 . 2013-07-09 04:46 103936 ----a-w- c:\windows\system32\cryptnet.dll
2013-08-14 08:04 . 2013-07-09 05:03 3913664 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-08-14 08:04 . 2013-07-09 05:03 3968960 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-08-14 08:04 . 2013-07-09 04:53 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-08-14 08:04 . 2013-07-06 05:05 1293760 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-08-14 08:04 . 2013-07-25 08:57 1620992 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-08-14 08:04 . 2013-07-19 01:41 2048 ----a-w- c:\windows\system32\tzres.dll
2013-08-14 08:03 . 2013-06-15 03:38 31232 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2013-08-13 19:49 . 2013-08-13 19:49 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-08-13 19:48 . 2013-08-13 19:48 -------- d-----w- c:\program files\Java
2013-08-13 18:11 . 2013-08-13 18:11 -------- d-----w- c:\program files\VS Revo Group
2013-08-13 18:06 . 2013-08-13 18:06 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-13 18:06 . 2013-08-13 18:06 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-08-12 19:49 . 2013-08-12 19:49 -------- d-----w- C:\FRST
2013-08-12 16:35 . 2013-08-12 16:35 -------- d-----w- c:\users\Mandy\AppData\Roaming\QuickScan
2013-08-12 16:33 . 2013-08-12 16:56 -------- d-----w- c:\programdata\Bitdefender
2013-08-12 15:40 . 2013-08-12 16:56 -------- d-----w- c:\program files\Common Files\Bitdefender
2013-08-12 14:51 . 2013-08-12 14:51 0 ---h--w- c:\windows\nslB87E.tmp
2013-08-12 13:42 . 2013-08-12 13:44 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2013-08-10 21:33 . 2013-08-10 21:33 -------- d-----w- c:\program files\Tracker Software
2013-08-10 16:58 . 2013-08-10 18:28 -------- d-----w- c:\programdata\eSafe
2013-08-10 16:58 . 2013-08-10 18:24 -------- d-----w- c:\program files\DealPlyLive
2013-08-10 16:58 . 2013-08-10 16:58 -------- d-----w- c:\users\Mandy\AppData\Local\DealPlyLive
2013-08-10 16:58 . 2013-08-10 16:58 -------- d-----w- c:\programdata\DealPlyLive
2013-08-10 16:58 . 2013-08-10 16:58 -------- d-----w- c:\users\Mandy\AppData\Roaming\Dealply
2013-08-10 16:58 . 2013-08-10 16:58 -------- d-----w- c:\users\Mandy\AppData\Roaming\DSite
2013-08-10 16:57 . 2013-08-10 16:57 -------- d-----w- c:\users\Mandy\AppData\Roaming\eIntaller
2013-08-10 16:57 . 2013-08-10 16:57 -------- d-----w- c:\program files\Image Converter
2013-08-10 09:17 . 2013-08-12 15:46 -------- d-----w- c:\programdata\Avira
2013-08-08 21:11 . 2013-08-15 21:12 -------- d-----w- c:\windows\system32\MRT
2013-08-08 14:25 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-08-08 13:36 . 2013-08-08 13:36 -------- d-----w- c:\users\Mandy\AppData\Local\ElevatedDiagnostics
2013-08-08 13:02 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\system32\DWrite.dll
2013-08-08 12:17 . 2012-12-16 14:13 295424 ----a-w- c:\windows\system32\atmfd.dll
2013-08-08 12:17 . 2012-12-16 14:13 34304 ----a-w- c:\windows\system32\atmlib.dll
2013-08-08 12:13 . 2013-08-11 11:22 1890 ----a-w- c:\windows\system32\ASOROSet.bin
2013-08-08 10:58 . 2013-08-10 18:26 -------- d-----w- c:\users\Mandy\AppData\Roaming\Systweak
2013-08-08 10:55 . 2013-08-08 10:55 -------- d-----w- c:\users\Mandy\AppData\Local\Programs
2013-08-08 10:29 . 2013-08-08 10:29 -------- d-----w- C:\f77ac4d2369eda7f3983c157b73a6e4b
2013-08-07 23:16 . 2013-08-07 23:16 49152 ----a-w- c:\windows\system32\taskhost.exe
2013-08-07 22:56 . 2013-08-07 22:56 -------- d-----w- c:\windows\system32\searchplugins
2013-08-07 22:56 . 2013-08-07 22:56 -------- d-----w- c:\windows\system32\Extensions
2013-08-07 21:55 . 2013-08-07 21:55 -------- d-----w- c:\users\Mandy\AppData\Roaming\Iminent
2013-08-07 21:54 . 2013-08-07 21:54 -------- d-----w- c:\programdata\Iminent
2013-08-07 21:53 . 2013-08-08 10:35 -------- d-----w- c:\program files\Common Files\Umbrella
2013-08-07 21:53 . 2013-08-07 21:55 -------- d-----w- c:\program files\Iminent
2013-08-07 21:47 . 2013-08-07 21:47 -------- d-----w- c:\program files\Julien MANICI
2013-08-07 21:44 . 2013-08-07 22:02 -------- d-----w- c:\users\Mandy\AppData\Local\http___www.julien-manici
2013-08-07 21:33 . 2013-04-12 13:45 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-08-07 21:33 . 2012-11-22 04:45 626688 ----a-w- c:\windows\system32\usp10.dll
2013-08-07 21:33 . 2013-02-12 03:32 15872 ----a-w- c:\windows\system32\drivers\usb8023x.sys
2013-08-07 21:33 . 2013-02-12 03:32 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-08-07 21:32 . 2012-11-02 05:11 376832 ----a-w- c:\windows\system32\dpnet.dll
2013-08-07 21:32 . 2013-04-25 23:30 1505280 ----a-w- c:\windows\system32\d3d11.dll
2013-08-07 21:31 . 2013-01-24 04:47 196328 ----a-w- c:\windows\system32\drivers\fvevol.sys
2013-08-07 21:31 . 2013-03-19 04:53 186368 ----a-w- c:\windows\system32\wwansvc.dll
2013-08-07 21:31 . 2013-03-19 03:33 40960 ----a-w- c:\windows\system32\wwanprotdim.dll
2013-08-07 21:31 . 2013-03-19 02:49 69632 ----a-w- c:\windows\system32\smss.exe
2013-08-07 21:31 . 2013-03-19 04:48 38912 ----a-w- c:\windows\system32\csrsrv.dll
2013-08-07 21:31 . 2013-04-10 05:03 936448 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2013-08-07 21:30 . 2013-05-10 03:20 24576 ----a-w- c:\windows\system32\cryptdlg.dll
2013-08-07 21:29 . 2013-02-15 04:37 3217408 ----a-w- c:\windows\system32\mstscax.dll
2013-08-07 21:29 . 2013-02-15 04:34 131584 ----a-w- c:\windows\system32\aaclient.dll
2013-08-07 21:29 . 2013-02-15 03:25 36864 ----a-w- c:\windows\system32\tsgqec.dll
2013-08-07 21:29 . 2013-04-26 04:55 492544 ----a-w- c:\windows\system32\win32spl.dll
2013-08-07 21:29 . 2012-11-01 04:47 1389568 ----a-w- c:\windows\system32\msxml6.dll
2013-08-07 21:29 . 2013-05-13 03:08 903168 ----a-w- c:\windows\system32\certutil.exe
2013-08-07 21:29 . 2013-05-13 03:08 43008 ----a-w- c:\windows\system32\certenc.dll
2013-08-07 21:27 . 2013-06-04 04:53 509440 ----a-w- c:\windows\system32\qedit.dll
2013-08-07 21:27 . 2013-06-05 03:05 2347520 ----a-w- c:\windows\system32\win32k.sys
2013-08-07 21:11 . 2012-11-20 04:51 220160 ----a-w- c:\windows\system32\ncrypt.dll
2013-08-07 21:11 . 2013-04-10 05:18 728424 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-08-07 21:11 . 2013-04-10 05:18 218984 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-08-07 21:11 . 2013-01-03 05:04 187752 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2013-08-07 21:10 . 2013-05-27 04:57 680960 ----a-w- c:\program files\Windows Defender\MpSvc.dll
2013-08-07 21:10 . 2013-05-27 04:57 392704 ----a-w- c:\program files\Windows Defender\MpClient.dll
2013-08-07 21:10 . 2013-05-27 04:57 224768 ----a-w- c:\program files\Windows Defender\MpCommu.dll
2013-08-07 20:58 . 2013-08-07 20:58 -------- d-----w- c:\program files\Mozilla Maintenance Service
2013-08-07 20:56 . 2013-01-04 04:50 169984 ----a-w- c:\windows\system32\winsrv.dll
2013-08-07 20:56 . 2013-02-27 05:05 101720 ----a-w- c:\windows\system32\consent.exe
2013-08-07 20:56 . 2013-02-27 04:49 1796096 ----a-w- c:\windows\system32\authui.dll
2013-08-07 20:56 . 2013-02-27 04:49 47104 ----a-w- c:\windows\system32\appinfo.dll
2013-08-07 20:19 . 2013-08-07 20:19 -------- d-----w- C:\found.000
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-13 19:49 . 2012-07-30 15:47 867240 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-08-13 19:49 . 2012-07-30 15:47 789416 ----a-w- c:\windows\system32\deployJava1.dll
2013-08-07 20:36 . 2010-06-24 02:33 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-04-07 8555040]
"Iminent"="c:\program files\Iminent\Iminent.exe" [2013-07-02 1074736]
"IminentMessenger"="c:\program files\Iminent\Iminent.Messengers.exe" [2013-07-02 884784]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-05-11 958576]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0??\0?[BdFirewallPath]*\0x\0??\0?[InstallPath]..\\0ex\0??\0?[BdFirewallPath]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\users\Mandy\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"Facebook Update"="c:\users\Mandy\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"YouCam Service"="c:\program files\CyberLink\YouCam\YouCamService.exe" /s
.
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [2010-07-13 297000]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-03-02 33320]
R3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [x]
R3 massfilter;Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys [2010-10-07 10752]
S2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S2 SProtection;SProtection;c:\program files\Common Files\Umbrella\umbrella.exe [2013-08-07 2864448]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-04-01 109056]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 579944]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 194408]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 21864]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 19304]
S3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
S3 yukonw7;NDIS6.2-Miniporttreiber für Marvell Yukon-Ethernet-Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-07-13 311296]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc
.
Inhalt des "geplante Tasks" Ordners
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD2500BEVT-35A23T0_WD-WXD1A110950309503&ts=1376153892
mStart Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD2500BEVT-35A23T0_WD-WXD1A110950309503&ts=1376153892
IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Free YouTube to MP3 Converter - c:\program files\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm
IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Mandy\AppData\Roaming\Mozilla\Firefox\Profiles\l80t3m2l.default\
FF - prefs.js: browser.startup.homepage - about :home
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1428909&SearchSource=2&CUI=UN29133404102847052&UM=1&q=
FF - user.js: extensions.delta.tlbrSrchUrl -
FF - user.js: extensions.delta.id - fc16653100000000000090a4de22af7f
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15924
FF - user.js: extensions.delta.vrsn - 1.8.22.0
FF - user.js: extensions.delta.vrsni - 1.8.22.0
FF - user.js: extensions.delta.vrsnTs - 1.8.22.023:57
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - de
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.ffxUnstlRst - true
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta_i.babTrack - affID=124247&tsp=4967
FF - user.js: extensions.delta_i.babExt -
FF - user.js: extensions.delta_i.srcExt - ss
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
FF - user.js: extensions.autoDisableScopes - 0
FF - user.js: extensions.shownSelectionUI - true
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
Toolbar-Locked - (no file)
WebBrowser-{872B5B88-9DB5-4310-BDD0-AC189557E5F5} - (no file)
HKLM-Run-YouCam Service - c:\program files\CyberLink\YouCam\YouCamService.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-08-19 19:56:38
ComboFix-quarantined-files.txt 2013-08-19 17:56
.
Vor Suchlauf: 10 Verzeichnis(se), 53.026.693.120 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 53.726.908.416 Bytes frei
.
- - End Of File - - 828D4AD3723C1D03C3E6FB04D099631C
2E5DEBB2116B3417023E0D6562D7ED07