Combofix Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
ComboFix 15-01-28.01 - Hiho 28.01.2015 11:47:43.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.2013.1222 [GMT 1:00]
ausgeführt von:: c:\users\Hiho\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {179979E8-273D-D14E-0543-2861940E4886}
FW: Kaspersky Internet Security *Disabled* {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
SP: Kaspersky Internet Security *Disabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Treiber/Dienste )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_DCService.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-12-28 bis 2015-01-28 ))))))))))))))))))))))))))))))
.
.
2015-01-28 10:58 . 2015-01-28 10:58 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-01-28 10:58 . 2015-01-28 10:58 -------- d-----w- c:\users\Christiane\AppData\Local\temp
2015-01-28 10:52 . 2015-01-28 10:52 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{59CB6930-6134-49C1-B499-D7F7A82A76ED}\offreg.dll
2015-01-28 10:06 . 2015-01-28 10:06 -------- d-----w- c:\program files\VS Revo Group
2015-01-27 18:14 . 2015-01-28 10:39 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2015-01-27 18:14 . 2015-01-28 10:41 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2015-01-26 20:54 . 2015-01-26 20:57 -------- d-----w- C:\FRST
2015-01-25 11:16 . 2014-12-02 11:01 9054624 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{59CB6930-6134-49C1-B499-D7F7A82A76ED}\mpengine.dll
2015-01-14 13:56 . 2014-12-12 05:11 3971512 ----a-w- c:\windows\system32\ntkrnlpa.exe
2015-01-14 13:56 . 2014-12-12 05:11 3916728 ----a-w- c:\windows\system32\ntoskrnl.exe
2015-01-14 13:56 . 2014-12-19 02:43 164864 ----a-w- c:\windows\system32\profsvc.dll
2015-01-14 13:56 . 2014-12-11 17:47 46592 ----a-w- c:\windows\system32\TSWbPrxy.exe
2015-01-14 13:55 . 2014-12-19 01:34 116224 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2015-01-14 13:55 . 2014-12-06 03:50 242688 ----a-w- c:\windows\system32\nlasvc.dll
2015-01-13 12:44 . 2015-01-13 12:44 -------- d-----w- c:\users\Hiho\AppData\Roaming\Schletter
2015-01-13 12:34 . 2015-01-13 12:34 -------- d-----w- c:\users\Hiho\AppData\Local\Apps
2015-01-13 12:34 . 2015-01-17 17:19 -------- d-----w- c:\users\Hiho\AppData\Local\Deployment
2015-01-13 11:51 . 2014-08-12 17:32 36536 ----a-w- c:\windows\system32\drivers\klhk.sys
2015-01-13 06:27 . 2015-01-13 12:13 -------- d-----w- c:\users\Hiho\AppData\Local\Package Cache
2015-01-10 09:04 . 2015-01-28 10:56 -------- d-----w- c:\users\Default\AppData\Roaming\Compatibility Verifier
2015-01-10 09:04 . 2015-01-10 09:04 -------- d-----w- c:\users\Default\AppData\Local\Programs
2015-01-10 07:16 . 2015-01-17 16:01 -------- d-----w- c:\users\Hiho\AppData\Roaming\Compatibility Verifier
2015-01-08 06:52 . 2015-01-08 06:53 -------- d-----w- c:\users\Public\Faktura mobil
2015-01-03 18:14 . 2014-12-13 03:33 115712 ----a-w- c:\windows\system32\ieUnatt.exe
2014-12-29 14:05 . 2014-12-29 14:05 -------- d-----w- c:\windows\system32\appraiser
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-01-14 06:24 . 2014-08-13 18:34 64200 ----a-w- c:\windows\system32\drivers\klwtp.sys
2015-01-14 06:24 . 2014-08-18 13:43 119816 ----a-w- c:\windows\system32\drivers\klflt.sys
2015-01-08 08:55 . 2010-01-26 09:15 249488 ------w- c:\windows\system32\MpSigStub.exe
2014-12-15 16:23 . 2014-12-15 16:23 4779560 ----a-w- c:\windows\system32\LxXtreme110.dll
2014-12-15 16:23 . 2014-12-15 16:23 28200 ----a-w- c:\windows\system32\LxTPSW100.dll
2014-12-15 16:23 . 2014-12-15 16:23 106536 ----a-w- c:\windows\system32\LxUISettingsN100.dll
2014-12-15 16:23 . 2014-12-15 16:23 65576 ----a-w- c:\windows\system32\LxPXTree100.dll
2014-12-15 16:23 . 2014-12-15 16:23 1341992 ----a-w- c:\windows\system32\LxTool115.dll
2014-12-15 16:23 . 2014-12-15 16:23 129576 ----a-w- c:\windows\system32\LxMail100.dll
2014-12-15 16:23 . 2014-12-15 16:23 51752 ----a-w- c:\windows\system32\LXCurr100.dll
2014-12-15 16:22 . 2014-12-15 16:22 70184 ----a-w- c:\windows\system32\LxCI12.dll
2014-12-15 16:22 . 2014-12-15 16:22 213032 ----a-w- c:\windows\system32\LxBasics100.dll
2014-12-10 12:51 . 2014-12-10 12:51 51752 ----a-w- c:\windows\system32\FKStampPainter20.dll
2014-12-04 04:38 . 2014-12-28 17:02 337920 ----a-w- c:\windows\system32\generaltel.dll
2014-12-04 04:38 . 2014-12-28 17:02 610304 ----a-w- c:\windows\system32\invagent.dll
2014-12-04 04:38 . 2014-12-28 17:02 315392 ----a-w- c:\windows\system32\devinv.dll
2014-12-04 04:38 . 2014-12-28 17:02 728576 ----a-w- c:\windows\system32\appraiser.dll
2014-12-04 04:38 . 2014-12-28 17:02 159744 ----a-w- c:\windows\system32\aepic.dll
2014-12-04 04:38 . 2014-12-28 17:02 202752 ----a-w- c:\windows\system32\aepdu.dll
2014-12-04 04:34 . 2014-12-28 17:02 873984 ----a-w- c:\windows\system32\aeinv.dll
2014-12-01 23:28 . 2014-12-28 17:02 1160872 ----a-w- c:\windows\system32\aitstatic.exe
2014-11-22 02:20 . 2014-12-28 17:03 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-11-22 02:20 . 2014-12-28 17:03 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2014-11-22 02:07 . 2014-12-28 17:03 501248 ----a-w- c:\windows\system32\vbscript.dll
2014-11-22 02:07 . 2014-12-28 17:03 62464 ----a-w- c:\windows\system32\iesetup.dll
2014-11-22 02:06 . 2014-12-28 17:03 47616 ----a-w- c:\windows\system32\ieetwproxystub.dll
2014-11-22 02:05 . 2014-12-28 17:03 64000 ----a-w- c:\windows\system32\MshtmlDac.dll
2014-11-22 01:55 . 2014-12-28 17:03 102912 ----a-w- c:\windows\system32\ieetwcollector.exe
2014-11-22 01:54 . 2014-12-28 17:03 620032 ----a-w- c:\windows\system32\jscript9diag.dll
2014-11-22 01:48 . 2014-12-28 17:03 667648 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-11-22 01:40 . 2014-12-28 17:03 60416 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2014-11-22 01:29 . 2014-12-28 17:03 4299264 ----a-w- c:\windows\system32\jscript9.dll
2014-11-22 01:22 . 2014-12-28 17:03 2052096 ----a-w- c:\windows\system32\inetcpl.cpl
2014-11-22 01:21 . 2014-12-28 17:03 1155072 ----a-w- c:\windows\system32\mshtmlmedia.dll
2014-11-22 01:00 . 2014-12-28 17:03 1888256 ----a-w- c:\windows\system32\wininet.dll
2014-11-18 13:56 . 2014-11-18 13:56 1202848 ----a-w- c:\windows\system32\FM20.DLL
2014-11-11 02:44 . 2014-12-28 17:02 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-11-11 02:44 . 2014-11-24 13:03 186880 ----a-w- c:\windows\system32\pku2u.dll
2014-11-11 02:44 . 2014-11-24 13:03 550912 ----a-w- c:\windows\system32\kerberos.dll
2014-11-11 01:32 . 2014-12-28 17:02 74752 ----a-w- c:\windows\system32\drivers\tdx.sys
2014-11-08 02:45 . 2014-12-28 17:02 2048 ----a-w- c:\windows\system32\tzres.dll
2014-11-06 09:51 . 2014-11-06 09:51 76840 ----a-w- c:\windows\system32\LxDNTvm115.dll
2014-11-06 09:51 . 2014-11-06 09:51 209960 ----a-w- c:\windows\system32\LXPrnUtil10.dll
2014-11-06 09:51 . 2014-11-06 09:51 141352 ----a-w- c:\windows\system32\LXReportManage.ocx
2014-11-06 09:51 . 2014-11-06 09:51 140840 ----a-w- c:\windows\system32\LxDNTvmc115.dll
2014-11-06 09:51 . 2014-11-06 09:51 322088 ----a-w- c:\windows\system32\LxDNT115.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-07-16 307768]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Winsol_Autostart.lnk]
backup=c:\windows\pss\Winsol_Autostart.lnk.CommonStartup
backupExtension=.CommonStartup
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Winsol_Autostart.lnk
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2014-12-19 16:50 1022152 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
2009-07-17 04:57 4562944 ----a-w- c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataCardMonitor]
2013-07-01 09:02 253952 ----a-w- c:\program files\T-Mobile\T-Mobile Internet Manager\DataCardMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2010-08-25 18:45 171032 ----a-w- c:\windows\System32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2013-05-30 12:50 96056 ----a-w- c:\program files\HP\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2010-08-25 18:45 136216 ----a-w- c:\windows\System32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LexwareInfoService]
2014-09-26 16:19 196648 ----a-w- c:\program files\Lexware\Update Manager\LxUpdateManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
2009-06-25 02:19 140520 ------w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2010-08-25 18:45 170520 ----a-w- c:\windows\System32\igfxpers.exe
.
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [2010-03-20 101504]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2010-04-07 204800]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-11-22 102912]
R3 ser2at;ATEN USB to Serial port driver;c:\windows\system32\DRIVERS\ser2at.sys [2009-10-15 80896]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S0 cm_km_w;Kaspersky Lab Crypto Module (FDE PDK);c:\windows\system32\DRIVERS\cm_km_w.sys [2013-01-14 189136]
S1 klhk;klhk;c:\windows\system32\DRIVERS\klhk.sys [2014-08-12 36536]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2014-02-25 25696]
S1 klpd;klpd;c:\windows\system32\DRIVERS\klpd.sys [2013-04-12 14432]
S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys [2014-06-05 44992]
S1 Klwtp;Klwtp;c:\windows\system32\DRIVERS\klwtp.sys [2015-01-14 64200]
S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys [2014-07-09 146240]
S2 AVP15.0.1;Kaspersky Anti-Virus Service 15.0.1;c:\program files\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avp.exe [2014-08-30 234520]
S2 buuoujqmrk32;buuoujqmrk32;c:\program files\003\buuoujqmrk32.exe run options=01110010030000000000000000000000 sourceguid=65CF66DC-5268-40F3-A63A-3DA446B5FAAA [x]
S2 kldisk;kldisk;c:\windows\system32\DRIVERS\kldisk.sys [2014-07-02 36928]
S2 Lexware_Update_Service;Lexware Update Service;c:\program files\Lexware\Update Service\Hmg.InstallationService.Service.exe [2014-08-14 64552]
S2 Verifies and fixes application compatibility issues;Compatibility Verify;c:\users\Default\AppData\Roaming\Compatibility Verifier\compatibilitychecksvc.exe [2015-01-12 91304]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [2010-04-09 63616]
S3 klflt;Kaspersky Lab Kernel DLL;c:\windows\system32\DRIVERS\klflt.sys [2015-01-14 119816]
S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys [2014-03-28 24672]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2013-08-08 25696]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-05-22 167936]
S3 VIACRX86;VIACRX86;c:\windows\system32\DRIVERS\viacr.sys [2009-07-14 59392]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - BMLoad
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-01-27 18:13 1086280 ----a-w- c:\program files\Google\Chrome\Application\40.0.2214.93\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2015-01-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-22 05:59]
.
2015-01-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-22 05:59]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = about :blank
mStart Page = about :blank
uSearchAssistant = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=DE&userid=416cee76-a3f3-407c-8fd5-2bb424bb044e&searchtype=ds&q={searchTerms}&installDate={installDate}
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{09A10376-994C-4BBF-9121-F50CF7BA237E} - {F2A56BFE-7911-451A-BC74-A9C3C2E95126} - c:\program files\Kaspersky Lab\Kaspersky Internet Security 15.0.1\IEExt\ie_plugin.dll
TCP: Interfaces\{F9337CFF-39AB-487D-8B58-E79B1771C117}: NameServer = 193.189.244.225 193.189.244.206
DPF: {B07F54E6-0806-47DB-B5D8-398F240776F2} - file:///D:/viewer/ORDcmViewCD.ocx
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
HKU-Default-Run-Skype - c:\program files\Skype\Phone\Skype.exe
SafeBoot-mcmscsvc
SafeBoot-MCODS
AddRemove-Winsol_is1 - c:\program files\Technische Alternative\Winsol\unins000.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
c:\windows\system32\WLANExt.exe
c:\windows\system32\conhost.exe
c:\program files\Dell\Dell Wireless WLAN Card\bcmwltry.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\003\buuoujqmrk32.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\program files\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avpui.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\users\Default\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2015-01-28 12:05:33 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2015-01-28 11:05
.
Vor Suchlauf: 22 Verzeichnis(se), 235.654.983.680 Bytes frei
Nach Suchlauf: 26 Verzeichnis(se), 235.017.879.552 Bytes frei
.
- - End Of File - - 416C11838D4839B726E9E5023B3CF60B
--- --- ---
5C616939100B85E558DA92B899A0FC36
Hallo Aneri, ich habs nach Anweisun ggemacht. Leider hab ich noch immer den compatibilitiycheck.exe im Task Manager sobald ich online bin. Schade hat nicht funktioniert. Hab ich was falsch gemacht?