Code:
Alles auswählen Aufklappen ATTFilter
ComboFix 14-06-16.01 - Grisu 17.06.2014 22:00:11.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.6135.2522 [GMT 2:00]
ausgeführt von:: c:\users\Grisu\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *Enabled/Updated* {179979E8-273D-D14E-0543-2861940E4886}
FW: Kaspersky Internet Security *Enabled* {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
SP: Kaspersky Internet Security *Enabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Grisu\AppData\Roaming\Microsoft\Windows\Recent\PDFCreator.url
c:\windows\IsUn0407.exe
J:\Autorun.inf
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-05-17 bis 2014-06-17 ))))))))))))))))))))))))))))))
.
.
2014-06-17 20:09 . 2014-06-17 20:09 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-06-17 18:57 . 2014-05-19 23:18 10702536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3130D8BB-6A1F-4E9D-881C-7E95235FCFB7}\mpengine.dll
2014-06-16 14:05 . 2014-06-16 14:05 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll
2014-06-16 14:05 . 2014-06-16 14:05 -------- d-----w- c:\programdata\Logs
2014-06-16 14:04 . 2014-02-13 15:56 19392 ----a-w- c:\windows\system32\roboot64.exe
2014-06-16 13:28 . 2005-03-18 15:19 3823312 ----a-w- c:\windows\system32\d3dx9_25.dll
2014-06-16 13:28 . 2005-02-05 17:45 3544272 ----a-w- c:\windows\system32\d3dx9_24.dll
2014-06-16 00:51 . 2014-06-16 00:51 -------- d-----w- c:\program files (x86)\Java
2014-06-13 01:43 . 2014-06-13 01:43 -------- d-----w- c:\programdata\McAfee
2014-06-12 05:17 . 2014-06-12 05:17 -------- d-----w- c:\program files (x86)\ESET
2014-06-11 17:32 . 2014-06-11 18:07 -------- d-----w- C:\AdwCleaner
2014-06-11 13:21 . 2014-06-09 10:24 61016 ----a-w- c:\windows\system32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64.sys
2014-06-11 12:16 . 2014-06-13 01:34 -------- d-----w- c:\program files (x86)\Greener Web
2014-06-11 10:17 . 2014-04-25 02:34 801280 ----a-w- c:\windows\system32\usp10.dll
2014-06-11 10:17 . 2014-04-25 02:06 626688 ----a-w- c:\windows\SysWow64\usp10.dll
2014-06-11 10:17 . 2014-04-05 02:47 1903552 ----a-w- c:\windows\system32\drivers\tcpip.sys
2014-06-11 10:17 . 2014-04-05 02:47 288192 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2014-06-11 10:17 . 2014-03-26 14:44 2002432 ----a-w- c:\windows\system32\msxml6.dll
2014-06-11 10:17 . 2014-03-26 14:44 1882112 ----a-w- c:\windows\system32\msxml3.dll
2014-06-11 10:17 . 2014-03-26 14:41 2048 ----a-w- c:\windows\system32\msxml6r.dll
2014-06-11 10:17 . 2014-03-26 14:41 2048 ----a-w- c:\windows\system32\msxml3r.dll
2014-06-11 10:17 . 2014-03-26 14:27 1389056 ----a-w- c:\windows\SysWow64\msxml6.dll
2014-06-11 10:17 . 2014-03-26 14:27 1237504 ----a-w- c:\windows\SysWow64\msxml3.dll
2014-06-11 10:17 . 2014-03-26 14:25 2048 ----a-w- c:\windows\SysWow64\msxml6r.dll
2014-06-11 10:17 . 2014-03-26 14:25 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
2014-06-11 10:13 . 2014-05-30 09:28 51200 ----a-w- c:\windows\system32\jsproxy.dll
2014-06-10 22:12 . 2001-05-04 10:05 505104 ----a-r- c:\windows\SysWow64\msxml.dll
2014-06-10 22:12 . 1998-06-23 23:00 115016 ----a-r- c:\windows\SysWow64\MSINET.OCX
2014-06-10 22:12 . 2014-06-10 22:12 -------- d-----w- c:\program files (x86)\Ubi Soft
2014-06-10 22:12 . 2002-06-17 06:25 26088 ----a-r- c:\windows\SysWow64\xmlinst.exe
2014-06-10 22:12 . 2002-04-24 11:43 35840 ----a-r- c:\windows\SysWow64\comdlg32.oca
2014-06-10 22:12 . 2002-04-09 16:23 29184 ----a-r- c:\windows\SysWow64\MSINET.oca
2014-06-10 22:12 . 2002-01-07 15:30 24576 ----a-r- c:\windows\SysWow64\msxml3a.dll
2014-06-10 22:12 . 2001-05-04 10:05 28432 ----a-r- c:\windows\SysWow64\msxmlr.dll
2014-06-10 22:12 . 2000-05-21 23:00 140488 ----a-r- c:\windows\SysWow64\comdlg32.ocx
2014-06-10 22:12 . 2000-03-17 07:21 36864 ----a-r- c:\windows\SysWow64\xmlparse.dll
2014-06-10 22:12 . 2000-03-17 07:21 69632 ----a-r- c:\windows\SysWow64\xmltok.dll
2014-06-10 22:12 . 1998-06-17 23:00 89360 ----a-r- c:\windows\SysWow64\VB5DB.DLL
2014-06-10 00:34 . 2014-06-16 00:52 -------- d-----w- c:\programdata\Oracle
2014-06-10 00:34 . 2014-06-16 00:51 98216 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-06-10 00:00 . 2014-06-10 08:31 122584 ----a-w- c:\windows\system32\drivers\3A056054.sys
2014-06-09 01:19 . 2014-06-09 01:19 122584 ----a-w- c:\windows\system32\drivers\29593062.sys
2014-06-08 12:55 . 2013-10-14 16:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
2014-06-08 12:46 . 2014-06-08 12:46 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2014-06-08 08:33 . 2013-11-23 18:26 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2014-06-08 08:33 . 2013-11-23 17:47 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2014-06-08 08:33 . 2011-02-25 06:19 2871808 ----a-w- c:\windows\explorer.exe
2014-06-08 08:33 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\SysWow64\explorer.exe
2014-06-08 08:33 . 2013-12-24 23:09 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2014-06-08 08:33 . 2013-12-24 22:48 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2014-06-08 08:33 . 2013-11-26 08:16 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2014-06-08 08:33 . 2013-11-22 22:48 3928064 ----a-w- c:\windows\system32\d2d1.dll
2014-06-08 08:33 . 2014-02-04 02:32 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-06-08 08:33 . 2014-02-04 02:04 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2014-06-08 08:33 . 2012-02-11 06:36 559104 ----a-w- c:\windows\system32\spoolsv.exe
2014-06-08 08:33 . 2012-02-11 06:36 67072 ----a-w- c:\windows\splwow64.exe
2014-06-08 08:14 . 2014-06-08 08:14 -------- d-s---w- c:\windows\system32\CompatTel
2014-06-07 11:11 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-06-07 11:11 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
2014-06-07 11:11 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2014-06-07 11:11 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL
2014-06-07 11:11 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll
2014-06-07 10:59 . 2014-06-07 10:59 -------- d-----w- c:\windows\Migration
2014-06-06 18:53 . 2014-06-12 03:57 -------- d-----w- c:\windows\system32\MRT
2014-06-06 18:41 . 2014-06-06 18:41 -------- d-----w- c:\programdata\PDF Architect 2
2014-06-06 18:41 . 2014-04-25 15:44 110264 ----a-w- c:\windows\system32\pdfcmon.dll
2014-06-06 18:41 . 2014-04-25 15:44 662288 ----a-w- c:\windows\SysWow64\MSCOMCT2.OCX
2014-06-06 18:41 . 2014-04-25 15:44 137000 ----a-w- c:\windows\SysWow64\MSMAPI32.OCX
2014-06-06 18:41 . 2014-04-25 15:44 1070152 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2014-06-06 18:41 . 2014-04-25 15:44 23552 ----a-w- c:\windows\SysWow64\MSMPIDE.DLL
2014-06-06 18:41 . 1998-07-06 16:56 125712 ----a-w- c:\windows\SysWow64\VB6DE.DLL
2014-06-06 18:41 . 1998-07-06 16:55 158208 ----a-w- c:\windows\SysWow64\MSCMCDE.DLL
2014-06-06 18:41 . 1998-07-06 16:55 64512 ----a-w- c:\windows\SysWow64\MSCC2DE.DLL
2014-06-06 18:28 . 2012-10-08 08:06 261632 ----a-w- c:\windows\system32\Spool\prtprocs\x64\EKIJ5000PPR.dll
2014-06-06 18:28 . 2014-06-06 18:28 -------- d-----w- c:\windows\system32\kodak
2014-06-06 18:26 . 2014-06-06 18:26 -------- d-----w- c:\programdata\Visan
2014-06-06 18:26 . 2014-06-06 18:26 -------- d-----w- c:\programdata\PrintProjects
2014-06-06 18:26 . 2014-06-06 18:26 -------- d-----w- c:\program files (x86)\PrintProjects
2014-06-06 18:20 . 2014-06-06 18:21 -------- d-----w- c:\windows\SysWow64\kodak
2014-06-06 18:18 . 2014-06-06 18:18 -------- d-----w- c:\windows\SysWow64\spool
2014-06-06 18:17 . 2014-06-06 18:18 -------- d-----w- c:\program files (x86)\Kodak
2014-06-06 18:15 . 2014-06-08 08:28 -------- d-----w- c:\programdata\Kodak
2014-06-06 17:29 . 2014-06-15 14:54 -------- d-----w- C:\FRST
2014-06-06 14:57 . 2013-07-04 12:50 633856 ----a-w- c:\windows\system32\comctl32.dll
2014-06-06 14:57 . 2013-07-04 11:50 530432 ----a-w- c:\windows\SysWow64\comctl32.dll
2014-06-06 14:57 . 2013-07-09 05:52 224256 ----a-w- c:\windows\system32\wintrust.dll
2014-06-06 14:57 . 2013-07-09 04:52 175104 ----a-w- c:\windows\SysWow64\wintrust.dll
2014-06-06 14:57 . 2013-10-19 02:18 81408 ----a-w- c:\windows\system32\imagehlp.dll
2014-06-06 14:57 . 2013-10-19 01:36 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2014-06-06 14:55 . 2013-06-06 05:50 41472 ----a-w- c:\windows\system32\lpk.dll
2014-06-06 14:54 . 2014-04-12 02:19 1460736 ----a-w- c:\windows\system32\lsasrv.dll
2014-06-06 14:53 . 2014-02-04 02:35 190912 ----a-w- c:\windows\system32\drivers\storport.sys
2014-06-06 14:43 . 2013-08-28 01:12 461312 ----a-w- c:\windows\system32\scavengeui.dll
2014-06-06 01:02 . 2014-06-06 01:02 -------- d-----w- c:\windows\system32\SPReview
2014-06-06 01:01 . 2014-06-06 01:01 -------- d-----w- c:\windows\system32\EventProviders
2014-06-06 00:31 . 2014-06-06 00:31 -------- d-----w- C:\Plugins
2014-06-06 00:30 . 2014-06-06 00:31 -------- d-----w- c:\program files (x86)\Ganymede
2014-06-05 23:52 . 2014-06-05 23:52 -------- d-----w- c:\programdata\Package Cache
2014-06-05 16:38 . 2010-11-05 01:57 48976 ----a-w- c:\windows\system32\netfxperf.dll
2014-06-05 16:38 . 2010-11-05 01:57 1942856 ----a-w- c:\windows\system32\dfshim.dll
2014-06-05 16:36 . 2010-11-20 13:33 184704 ----a-w- c:\windows\system32\drivers\pci.sys
2014-06-05 16:35 . 2010-11-20 13:02 8192 ----a-w- c:\windows\system32\KBDTUQ.DLL
2014-06-05 16:34 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll
2014-06-05 16:34 . 2010-11-20 13:27 244736 ----a-w- c:\program files\Windows Portable Devices\sqmapi.dll
2014-06-05 16:33 . 2010-11-20 13:27 244736 ----a-w- c:\windows\system32\sqmapi.dll
2014-06-05 16:11 . 2011-03-11 06:33 2565632 ----a-w- c:\windows\system32\esent.dll
2014-06-05 16:11 . 2011-03-11 05:33 1699328 ----a-w- c:\windows\SysWow64\esent.dll
2014-06-05 16:11 . 2011-03-11 06:41 166272 ----a-w- c:\windows\system32\drivers\nvstor.sys
2014-06-05 16:11 . 2011-03-11 06:41 148352 ----a-w- c:\windows\system32\drivers\nvraid.sys
2014-06-05 16:11 . 2011-03-11 06:41 410496 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2014-06-05 16:11 . 2011-03-11 06:41 27008 ----a-w- c:\windows\system32\drivers\amdxata.sys
2014-06-05 16:11 . 2011-03-11 06:41 107904 ----a-w- c:\windows\system32\drivers\amdsata.sys
2014-06-05 16:11 . 2011-03-11 06:30 96768 ----a-w- c:\windows\system32\fsutil.exe
2014-06-05 16:11 . 2011-03-11 05:31 74240 ----a-w- c:\windows\SysWow64\fsutil.exe
2014-06-05 16:11 . 2011-03-11 04:37 91648 ----a-w- c:\windows\system32\drivers\USBSTOR.SYS
2014-06-05 13:03 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-06-05 13:00 . 2014-06-17 19:04 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-06-05 12:59 . 2014-06-05 12:59 -------- d-----w- c:\program files (x86)\ Malwarebytes Anti-Malware
2014-06-05 12:59 . 2014-06-05 12:59 -------- d-----w- c:\programdata\Malwarebytes
2014-06-05 12:59 . 2014-05-12 05:26 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-06-05 12:59 . 2014-05-12 05:26 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-06-05 12:59 . 2014-05-12 05:25 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-06-05 03:58 . 2014-06-05 03:58 -------- d-----w- c:\windows\SysWow64\%Report%
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-06-06 14:15 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2014-06-06 14:15 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2014-06-03 09:20 . 2013-10-17 13:47 458336 ----a-w- c:\windows\system32\drivers\kl1.sys
2014-06-03 09:20 . 2013-06-06 15:38 178272 ----a-w- c:\windows\system32\drivers\kneps.sys
2014-06-03 09:11 . 2013-10-17 13:47 29280 ----a-w- c:\windows\system32\drivers\klkbdflt.sys
2014-06-03 09:11 . 2013-10-17 13:47 625248 ----a-w- c:\windows\system32\drivers\klif.sys
2014-06-03 09:11 . 2013-06-08 18:18 115296 ----a-w- c:\windows\system32\drivers\klflt.sys
2014-04-09 13:13 . 2014-04-09 13:13 489064 ----a-w- C:\SecurityScanner.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2014-05-14 06:18 1730264 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2014-05-14 06:18 1730264 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2014-05-14 06:18 1730264 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files (x86)\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-09-18 205976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"EKStatusMonitor"="c:\program files (x86)\Kodak\AiO\StatusMonitor\EKStatusMonitor.exe" [2013-01-15 2750840]
"EKIJ5000StatusMonitor"="c:\windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.EXE" [2012-10-08 3182080]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
DSL-Manager.lnk - c:\program files (x86)\DSL-Manager\DslMgr.exe [2014-6-3 1085440]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R4 klflt;klflt;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x]
R4 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files (x86)\Kodak\AiO\Center\EKAiOHostService.exe;c:\program files (x86)\Kodak\AiO\Center\EKAiOHostService.exe [x]
R4 Kodak AiO Status Monitor Service;Kodak AiO Status Monitor Service;c:\program files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe;c:\program files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
S1 {a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64;{a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64;c:\windows\system32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64.sys;c:\windows\SYSNATIVE\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64.sys [x]
S1 DslMNLwf;DSL-Manager NDIS LightWeight Filter;c:\windows\system32\DRIVERS\dslmnlwf.sys;c:\windows\SYSNATIVE\DRIVERS\dslmnlwf.sys [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
S1 klpd;klpd;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x]
S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x]
S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S3 e1yexpress;Intel(R) Gigabit-Netzwerkverbindungstreiber;c:\windows\system32\DRIVERS\e1y60x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1y60x64.sys [x]
S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 TDslMgrService;DSL-Manager;c:\program files (x86)\DSL-Manager\DslMgrSvc.exe;c:\program files (x86)\DSL-Manager\DslMgrSvc.exe [x]
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - MBAMSWISSARMY
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-06-03 14:19 1091912 ----a-w- c:\program files (x86)\Google\Chrome\Application\35.0.1916.114\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-06-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-03 01:59]
.
2014-06-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-06-03 14:14]
.
2014-06-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-06-03 14:14]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2014-05-14 06:15 2335960 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2014-05-14 06:15 2335960 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2014-05-14 06:15 2335960 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EKIJ5000StatusMonitor"="c:\windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe" [2012-10-08 3182080]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office15\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office15\EXCEL.EXE/3000
IE: Zu Anti-Banner hinzufügen - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ie_banner_deny.htm
TCP: DhcpNameServer = 192.168.2.1
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
FF - ProfilePath - c:\users\Grisu\AppData\Roaming\Mozilla\Firefox\Profiles\ik2h1i7j.default\
FF - prefs.js: network.proxy.ftp - 91.202.164.113
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.http - 91.202.164.113
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - 91.202.164.113
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - 91.202.164.113
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 0
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKLM-Run-Conime - c:\windows\system32\conime.exe
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
c:\users\Grisu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-Cheat Engine 6.3_is1 - d:\programme\Cheat Engine 6.3\unins000.exe
AddRemove-S4Uninst - c:\windows\IsUn0407.exe
AddRemove-{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D} - d:\programme\PDFCreator\unins000.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-06-17 22:20:05
ComboFix-quarantined-files.txt 2014-06-17 20:20
.
Vor Suchlauf: 9 Verzeichnis(se), 20.125.138.944 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 20.366.884.864 Bytes frei
.
- - End Of File - - 51C3D027E9311A84ECB86C300248FC2F
A36C5E4F47E84449FF07ED3517B43A31