![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: Malwarebytes Blockt IP Ausgänge aber findet nichtsWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
| | #6 |
![]() ![]() | Malwarebytes Blockt IP Ausgänge aber findet nichtsCode:
ATTFilter ComboFix 13-10-29.02 - Psino 29.10.2013 19:13:59.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8156.6512 [GMT 1:00]
ausgeführt von:: c:\users\Psino\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\ntuser.dat
c:\windows\ico.ico
c:\windows\SysWow64\tmp9A3C.tmp
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-09-28 bis 2013-10-29 ))))))))))))))))))))))))))))))
.
.
2013-10-29 18:16 . 2013-10-29 18:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-10-29 16:53 . 2013-10-29 16:53 -------- d-----w- C:\FRST
2013-10-29 16:18 . 2013-10-29 16:18 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4D318610-1579-4E32-8CAC-908C7F683207}\offreg.dll
2013-10-29 10:47 . 2013-10-15 23:20 10280728 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4D318610-1579-4E32-8CAC-908C7F683207}\mpengine.dll
2013-10-28 18:23 . 2013-10-28 21:35 -------- d-----w- c:\programdata\NVIDIA
2013-10-28 18:23 . 2013-10-23 08:20 6669600 ----a-w- c:\windows\system32\nvcpl.dll
2013-10-28 18:23 . 2013-10-23 08:20 3489568 ----a-w- c:\windows\system32\nvsvc64.dll
2013-10-28 18:23 . 2013-10-23 08:20 922912 ----a-w- c:\windows\system32\nvvsvc.exe
2013-10-28 18:23 . 2013-10-23 08:20 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-10-28 18:23 . 2013-10-23 08:20 2559776 ----a-w- c:\windows\system32\nvsvcr.dll
2013-10-28 18:23 . 2013-10-23 08:20 219424 ----a-w- c:\windows\system32\nvmctray.dll
2013-10-28 18:23 . 2013-10-23 08:20 3426956 ----a-w- c:\windows\system32\nvcoproc.bin
2013-10-28 16:22 . 2013-10-28 16:22 2179072 ----a-w- c:\programdata\Microsoft\BingDesktop\BingCore\BingDesktopCore.dll
2013-10-25 15:22 . 2007-07-20 13:31 92214 ----a-w- c:\windows\matrix.scr
2013-10-25 12:00 . 2013-10-25 12:00 -------- d-----w- c:\windows\ERUNT
2013-10-25 11:57 . 2013-10-29 13:33 -------- d-----w- C:\AdwCleaner
2013-10-24 22:21 . 2013-10-24 22:21 -------- d-----w- c:\program files\CPUID
2013-10-24 18:23 . 2010-07-13 13:26 804352 ------w- c:\windows\system32\Cmeau106.exe
2013-10-24 18:23 . 2010-07-01 10:19 8151040 ------w- c:\windows\SysWow64\CM106.dll
2013-10-24 18:23 . 2009-04-02 14:59 143360 ------w- c:\windows\Vmix106.dll
2013-10-24 18:23 . 2009-01-16 16:12 221184 ------w- c:\windows\system\cm106eye.exe
2013-10-24 18:23 . 2008-07-23 17:00 389120 ------w- c:\windows\system32\CM106.cpl
2013-10-24 18:23 . 2006-09-13 11:08 491520 ------w- c:\windows\system\cmau106.dll
2013-10-24 18:23 . 2006-09-13 08:21 200704 ------w- c:\windows\SysWow64\cmpa106.dll
2013-10-24 18:23 . 2009-08-19 14:00 359424 ------w- c:\windows\system32\CmiInstallResAll64.dll
2013-10-24 18:23 . 2006-10-06 03:45 524768 ----a-w- c:\windows\difxapi.dll
2013-10-24 18:23 . 2009-10-01 16:04 1307648 ----a-w- c:\windows\system32\drivers\CM10664.sys
2013-10-24 18:23 . 2004-04-14 09:28 315392 ----a-w- c:\windows\system\fltr106.dll
2013-10-24 18:13 . 2010-06-02 02:55 74072 ----a-w- c:\windows\SysWow64\XAPOFX1_5.dll
2013-10-24 18:13 . 2010-06-02 02:55 527192 ----a-w- c:\windows\SysWow64\XAudio2_7.dll
2013-10-24 18:13 . 2010-05-26 09:41 248672 ----a-w- c:\windows\SysWow64\d3dx11_43.dll
2013-10-24 18:13 . 2010-05-26 09:41 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll
2013-10-24 18:13 . 2010-05-26 09:41 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll
2013-10-24 18:13 . 2010-02-04 08:01 22360 ----a-w- c:\windows\SysWow64\X3DAudio1_7.dll
2013-10-24 17:30 . 2013-10-24 18:31 -------- d-----w- c:\program files (x86)\Common Files\Steam
2013-10-24 10:56 . 2007-04-04 16:53 81768 ----a-w- c:\windows\SysWow64\xinput1_3.dll
2013-10-24 07:01 . 2013-10-22 14:37 36664 ----a-w- c:\windows\system32\uxtuneup.dll
2013-10-24 07:01 . 2013-10-22 14:37 30008 ----a-w- c:\windows\SysWow64\uxtuneup.dll
2013-10-24 01:11 . 2013-10-23 18:12 -------- d-----w- c:\windows\Panther
2013-10-24 01:11 . 2013-10-24 01:11 -------- d-----w- C:\Boot
2013-10-23 22:51 . 2013-10-23 22:51 -------- d-----w- c:\programdata\Creative Labs
2013-10-23 22:43 . 2013-10-23 22:43 -------- d-----w- c:\program files\Canon
2013-10-23 22:42 . 2013-10-23 22:42 -------- d--h--w- c:\programdata\CanonBJ
2013-10-23 22:42 . 2007-04-15 20:00 82944 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPP93.DLL
2013-10-23 22:42 . 2007-04-15 20:00 27648 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPD93.DLL
2013-10-23 22:42 . 2013-10-23 22:42 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
2013-10-23 22:42 . 2007-04-15 20:00 258560 ----a-w- c:\windows\system32\CNMLM93.DLL
2013-10-23 22:42 . 2007-04-13 05:46 246272 ----a-w- c:\windows\system32\CNC610L.DLL
2013-10-23 22:42 . 2007-03-23 07:32 92672 ----a-w- c:\windows\system32\CNC610I.DLL
2013-10-23 22:42 . 2007-03-15 05:13 229888 ----a-w- c:\windows\system32\CNC610O.DLL
2013-10-23 22:42 . 2007-03-23 07:33 1439744 ----a-w- c:\windows\system32\CNC610C.DLL
2013-10-23 22:41 . 2013-10-23 22:45 -------- d-----w- c:\program files (x86)\Canon
2013-10-23 22:23 . 2013-10-22 14:37 35640 ----a-w- c:\windows\system32\TURegOpt.exe
2013-10-23 22:23 . 2013-10-22 14:37 26936 ----a-w- c:\windows\system32\authuitu.dll
2013-10-23 22:23 . 2013-10-22 14:37 22328 ----a-w- c:\windows\SysWow64\authuitu.dll
2013-10-23 22:23 . 2013-10-28 09:30 -------- d-----w- c:\program files (x86)\TuneUp Utilities 2012
2013-10-23 22:22 . 2013-10-23 22:23 -------- d-----w- c:\programdata\TuneUp Software
2013-10-23 22:22 . 2013-10-23 22:22 -------- d-sh--w- c:\programdata\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2013-10-23 22:22 . 2013-10-23 22:22 -------- d--h--w- c:\programdata\Common Files
2013-10-23 21:42 . 2013-10-23 21:42 -------- d-----w- c:\program files (x86)\Microsoft Synchronization Services
2013-10-23 21:42 . 2013-10-23 21:42 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2013-10-23 21:40 . 2013-10-23 21:40 -------- d-----w- c:\program files\Microsoft Office
2013-10-23 21:39 . 2013-10-23 22:01 -------- d-----w- c:\programdata\Microsoft Help
2013-10-23 21:39 . 2013-10-23 21:39 -------- d-----r- C:\MSOCache
2013-10-23 21:26 . 2006-10-06 12:17 53248 ------w- c:\windows\Ctregrun.exe
2013-10-23 21:26 . 2000-05-22 14:58 647872 ------w- c:\windows\SysWow64\Mscomct2.ocx
2013-10-23 21:17 . 2003-06-12 21:25 7062 ----a-w- c:\windows\SysWow64\audiopid.vxd
2013-10-23 21:16 . 2013-10-23 21:16 -------- d-----w- c:\program files (x86)\OpenAL
2013-10-23 21:16 . 2013-10-23 21:16 -------- d-----w- c:\windows\SysWow64\Data
2013-10-23 21:16 . 2013-10-23 21:16 -------- d-----w- c:\windows\system32\Data
2013-10-23 21:16 . 2006-06-09 13:20 3072 ----a-w- c:\windows\SysWow64\CTXFIGER.DLL
2013-10-23 21:16 . 2006-06-09 13:20 3072 ----a-w- c:\windows\system32\CTXFIGER.DLL
2013-10-23 21:16 . 2004-07-30 12:46 20480 ----a-w- c:\windows\SysWow64\INRESGER.DLL
2013-10-23 21:16 . 2004-07-30 12:46 20480 ----a-w- c:\windows\system32\INRESGER.DLL
2013-10-23 21:16 . 2009-05-18 12:34 22691984 ----a-w- c:\windows\SysWow64\AppSetup.exe
2013-10-23 21:01 . 2013-10-23 21:01 -------- d-----w- c:\program files\WinRAR
2013-10-23 20:40 . 2013-10-23 20:40 -------- d-----w- c:\programdata\Malwarebytes
2013-10-23 20:40 . 2013-10-23 20:40 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-10-23 20:40 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-10-23 20:38 . 2013-10-23 20:38 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2013-10-23 20:36 . 2013-10-23 20:36 -------- d-----w- C:\NVIDIA
2013-10-23 20:30 . 2013-10-23 20:30 172032 ----a-w- c:\windows\SysWow64\AniGIF.ocx
2013-10-23 20:26 . 2013-10-23 20:26 -------- d-----w- c:\program files\Microsoft IntelliType Pro
2013-10-23 20:25 . 2013-10-23 20:25 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-10-23 20:25 . 2013-10-23 20:25 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-10-23 20:25 . 2013-10-23 20:25 -------- d-----w- c:\program files (x86)\Java
2013-10-23 20:24 . 2013-10-23 20:25 -------- d-----w- c:\programdata\Oracle
2013-10-23 20:23 . 2013-10-23 20:23 312744 ----a-w- c:\windows\system32\javaws.exe
2013-10-23 20:23 . 2013-10-23 20:23 189352 ----a-w- c:\windows\system32\javaw.exe
2013-10-23 20:23 . 2013-10-23 20:23 189352 ----a-w- c:\windows\system32\java.exe
2013-10-23 20:23 . 2013-10-23 20:23 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-10-23 20:23 . 2013-10-23 20:23 -------- d-----w- c:\program files\Java
2013-10-23 20:23 . 2013-10-23 20:23 -------- d-----w- c:\program files\VideoLAN
2013-10-23 20:20 . 2013-09-04 12:12 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-10-23 20:20 . 2013-09-04 12:11 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-10-23 20:20 . 2013-09-04 12:11 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-10-23 20:20 . 2013-09-04 12:11 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-10-23 20:20 . 2013-09-04 12:11 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-10-23 20:20 . 2013-09-04 12:11 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-10-23 20:20 . 2013-09-04 12:11 7808 ----a-w- c:\windows\system32\drivers\usbd.sys
2013-10-23 19:59 . 2013-10-23 19:59 -------- d-----w- c:\windows\PCHEALTH
2013-10-23 19:55 . 2013-10-24 18:13 -------- d-----w- c:\program files (x86)\Microsoft.NET
2013-10-23 19:51 . 2013-10-23 19:51 -------- d-----w- c:\windows\SysWow64\Wat
2013-10-23 19:51 . 2013-10-23 19:51 -------- d-----w- c:\windows\system32\Wat
2013-10-23 19:44 . 2013-10-23 19:44 -------- d-----w- c:\windows\SysWow64\wbem\en-US
2013-10-23 19:44 . 2013-10-23 19:44 -------- d-----w- c:\windows\system32\wbem\en-US
2013-10-23 19:21 . 2012-07-26 07:46 2560 ----a-w- c:\windows\system32\drivers\de-DE\wdf01000.sys.mui
2013-10-23 19:08 . 2012-08-23 15:09 3584 ----a-w- c:\windows\system32\drivers\de-DE\tsusbflt.sys.mui
2013-10-23 19:03 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2013-10-23 19:00 . 2013-10-28 18:23 -------- d-----w- c:\program files\NVIDIA Corporation
2013-10-23 19:00 . 2013-10-28 18:22 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2013-10-23 18:54 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2013-10-23 18:54 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2013-10-23 18:54 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2013-10-23 18:54 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2013-10-23 18:54 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2013-10-23 18:54 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2013-10-23 18:54 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2013-10-23 18:49 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2013-10-23 18:49 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2013-10-23 18:49 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2013-10-23 18:49 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2013-10-23 18:49 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2013-10-23 18:47 . 2011-05-04 05:25 2315776 ----a-w- c:\windows\system32\tquery.dll
2013-10-23 18:46 . 2013-08-05 02:25 155584 ----a-w- c:\windows\system32\drivers\ataport.sys
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-17 20:22 . 2013-09-17 20:22 31520 ----a-w- c:\windows\system32\nvhdap64.dll
2013-09-17 20:22 . 2013-09-17 20:22 196384 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
2013-09-17 20:22 . 2013-09-17 20:22 1510176 ----a-w- c:\windows\system32\nvhdagenco6420103.dll
2013-09-03 12:35 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-08-29 01:48 . 2013-10-23 18:48 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"tsiVideo"="start" [X]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-11-05 283160]
"XFastUSB"="c:\program files (x86)\XFastUSB\XFastUsb.exe" [2013-10-23 5019360]
"CTSyncService"="c:\program files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" [2009-07-08 1233195]
"VolPanel"="c:\program files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe" [2009-05-04 241789]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-10-10 681032]
"CTxfiHlp"="CTXFIHLP.EXE" [2010-05-05 25600]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-01-21 91520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"UpdReg"=c:\windows\UpdReg.EXE
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [x]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x]
R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS;c:\windows\SYSNATIVE\drivers\CT20XUT.SYS [x]
R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS;c:\windows\SYSNATIVE\drivers\CTEXFIFX.SYS [x]
R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS;c:\windows\SYSNATIVE\drivers\CTHWIUT.SYS [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Sound Blaster X-Fi MB Licensing Service;Sound Blaster X-Fi MB Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x]
R4 WCUService;SmartView Software Updater Service;c:\program files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe;c:\program files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe [x]
S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AsrAppCharger.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS;c:\windows\SYSNATIVE\drivers\FNETURPX.SYS [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [x]
S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS;c:\windows\SYSNATIVE\drivers\CT20XUT.SYS [x]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS;c:\windows\SYSNATIVE\drivers\CTEXFIFX.SYS [x]
S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS;c:\windows\SYSNATIVE\drivers\CTHWIUT.SYS [x]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
S3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS;c:\windows\SYSNATIVE\drivers\FNETTBOH_305.SYS [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [x]
S3 USBMULCD;USB Multi-Channel Audio Device Interface;c:\windows\system32\drivers\CM10664.sys;c:\windows\SYSNATIVE\drivers\CM10664.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - UGLOAPOG
*Deregistered* - ugloapog
.
Inhalt des "geplante Tasks" Ordners
.
2013-10-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3593069957-3938038606-1495275051-1000Core.job
- c:\users\Psino\AppData\Local\Google\Update\GoogleUpdate.exe [2013-10-23 18:28]
.
2013-10-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3593069957-3938038606-1495275051-1000UA.job
- c:\users\Psino\AppData\Local\Google\Update\GoogleUpdate.exe [2013-10-23 18:28]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1BingDesktopOverlays]
@="{B82655E9-B81D-4A97-8154-0D84A4C048E4}"
[HKEY_CLASSES_ROOT\CLSID\{B82655E9-B81D-4A97-8154-0D84A4C048E4}]
2013-10-28 16:22 2492416 ----a-w- c:\programdata\Microsoft\BingDesktop\BingCore\BingDesktopOverlays.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"XFast LAN"="c:\program files\ASRock\XFast LAN\cFosSpeed.exe" [2011-10-19 1441152]
"RunDLLEntry"="c:\windows\system32\AmbRunE.dll" [2009-02-26 17920]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2011-08-10 1873256]
"CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1840720]
"Cm106Sound"="c:\windows\Syswow64\cm106.dll" [2010-07-01 8151040]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.0.2
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-10-29 19:17:23
ComboFix-quarantined-files.txt 2013-10-29 18:17
.
Vor Suchlauf: 10 Verzeichnis(se), 61.820.194.816 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 61.603.246.080 Bytes frei
.
- - End Of File - - 39A75656876823E3FDBE904CEA7CF13A
Das FRST Log ist aufgeteilt da es mehr Zeichen als 120k sind. Habs dir als .rar Hochgeladen da auch die .txt zu gross ist. MfG Psino Geändert von psino (29.10.2013 um 19:33 Uhr) |
| Themen zu Malwarebytes Blockt IP Ausgänge aber findet nichts |
| appdata, block, blockt, code, default, explorer.exe, geblockt, gekauft, gen, google, hoffe, log, löschen, malwarebytes, meldungen, neue, neuen, nichts, port, process, programme, programmen, scan, standard, update |