![]() |
|
Plagegeister aller Art und deren Bekämpfung: FritBox wlan lansgsam trotz gutem Empfang !Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() FritBox wlan lansgsam trotz gutem Empfang ! hi, ![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #2 |
![]() ![]() ![]() | ![]() FritBox wlan lansgsam trotz gutem Empfang !Code:
ATTFilter ComboFix 15-08-20.01 - Veli 23.08.2015 10:37:48.2.4 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.7150.3183 [GMT 2:00] ausgeführt von:: c:\users\Veli\Downloads\ComboFix.exe AV: Microsoft Security Essentials *Enabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A} SP: Microsoft Security Essentials *Enabled/Updated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Veli\AppData\Roaming\InstallDir c:\users\Veli\AppData\Roaming\Microsoft\Windows\hEmyXQ5qjGHsl1.dat c:\windows\SysWow64\InstallDir c:\windows\SysWow64\Packet.dll c:\windows\SysWow64\wpcap.dll c:\windows\SysWow64\X86 . . ((((((((((((((((((((((( Dateien erstellt von 2015-07-23 bis 2015-08-23 )))))))))))))))))))))))))))))) . . 2015-08-23 08:50 . 2015-08-23 08:50 -------- d-----w- c:\users\Public\AppData\Local\temp 2015-08-23 08:50 . 2015-08-23 08:50 -------- d-----w- c:\users\Default\AppData\Local\temp 2015-08-23 01:39 . 2015-08-23 01:39 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D8E27869-359B-4D5E-A2D4-CCDA83D45FB2}\offreg.312.dll 2015-08-23 01:36 . 2015-07-31 09:21 11745192 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D8E27869-359B-4D5E-A2D4-CCDA83D45FB2}\mpengine.dll 2015-08-22 11:25 . 2015-08-22 11:25 -------- d-----w- c:\program files\Mozilla Firefox 2015-08-22 10:35 . 2015-08-22 10:40 -------- d-----w- C:\$Windows.~BT 2015-08-22 05:20 . 2015-08-22 05:20 -------- d-----w- c:\program files (x86)\Common Files\Skype 2015-08-22 05:20 . 2015-08-22 05:20 -------- d-----r- c:\program files (x86)\Skype 2015-08-22 01:36 . 2015-07-31 09:21 11745192 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2015-08-22 01:00 . 2015-08-11 01:20 25191936 ----a-w- c:\windows\system32\mshtml.dll 2015-08-22 01:00 . 2015-08-11 01:14 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2015-08-22 01:00 . 2015-08-11 00:33 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb 2015-08-21 13:36 . 2015-08-21 13:35 1190000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6A93E5E4-68B3-4243-B8BC-9C66B8749EBB}\gapaengine.dll 2015-08-13 01:25 . 2015-07-30 13:13 103120 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll 2015-08-13 01:25 . 2015-07-30 13:13 124624 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll 2015-08-12 12:31 . 2015-08-21 14:12 113880 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2015-08-12 12:31 . 2015-06-18 06:41 63704 ----a-w- c:\windows\system32\drivers\mwac.sys 2015-08-12 12:31 . 2015-06-18 06:41 109272 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2015-08-12 12:31 . 2015-06-18 06:41 25816 ----a-w- c:\windows\system32\drivers\mbam.sys 2015-08-12 10:24 . 2015-07-15 18:15 5568960 ----a-w- c:\windows\system32\ntoskrnl.exe 2015-08-12 10:23 . 2015-07-16 20:35 2885632 ----a-w- c:\windows\system32\iertutil.dll 2015-08-12 10:22 . 2015-07-20 18:12 98304 ----a-w- c:\windows\system32\wudriver.dll 2015-08-02 00:07 . 2015-08-12 13:52 -------- d-----w- c:\program files (x86)\SectionDouble 2015-07-31 01:05 . 2015-07-31 01:07 -------- d-----w- c:\users\Veli\AppData\Roaming\xVideoServiceThief . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2015-08-13 01:01 . 2014-09-26 15:45 132483416 ----a-w- c:\windows\system32\MRT.exe 2015-08-12 02:31 . 2014-09-26 15:04 778440 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2015-08-12 02:31 . 2014-09-26 15:04 142536 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2015-07-15 17:54 . 2015-08-12 10:24 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2015-07-05 10:08 . 2014-09-26 15:30 300704 ------w- c:\windows\system32\MpSigStub.exe 2015-07-04 18:07 . 2015-07-15 10:54 2087424 ----a-w- c:\windows\system32\ole32.dll 2015-07-04 17:48 . 2015-07-15 10:54 1414656 ----a-w- c:\windows\SysWow64\ole32.dll 2015-07-04 06:27 . 2014-09-26 13:36 65536 ----a-w- c:\windows\system32\spu_storage.bin 2015-07-01 19:38 . 2014-09-27 16:13 1190000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2015-06-17 17:47 . 2015-07-15 10:59 404992 ----a-w- c:\windows\system32\gdi32.dll 2015-06-17 17:37 . 2015-07-15 10:59 312320 ----a-w- c:\windows\SysWow64\gdi32.dll 2015-06-15 21:50 . 2015-07-15 10:54 112064 ----a-w- c:\windows\system32\consent.exe 2015-06-15 21:45 . 2015-07-15 10:54 3242496 ----a-w- c:\windows\system32\msi.dll 2015-06-15 21:45 . 2015-07-15 10:54 504320 ----a-w- c:\windows\system32\msihnd.dll 2015-06-15 21:45 . 2015-07-15 10:54 1941504 ----a-w- c:\windows\system32\authui.dll 2015-06-15 21:45 . 2015-07-15 10:54 70656 ----a-w- c:\windows\system32\appinfo.dll 2015-06-15 21:44 . 2015-07-15 10:54 128000 ----a-w- c:\windows\system32\msiexec.exe 2015-06-15 21:43 . 2015-07-15 10:54 2364416 ----a-w- c:\windows\SysWow64\msi.dll 2015-06-15 21:43 . 2015-07-15 10:54 337408 ----a-w- c:\windows\SysWow64\msihnd.dll 2015-06-15 21:43 . 2015-07-15 10:54 1805824 ----a-w- c:\windows\SysWow64\authui.dll 2015-06-15 21:42 . 2015-07-15 10:54 73216 ----a-w- c:\windows\SysWow64\msiexec.exe 2015-06-15 21:42 . 2015-07-15 10:54 25088 ----a-w- c:\windows\system32\msimsg.dll 2015-06-15 21:37 . 2015-07-15 10:54 25088 ----a-w- c:\windows\SysWow64\msimsg.dll 2015-06-09 18:03 . 2015-07-15 10:59 3180544 ----a-w- c:\windows\system32\rdpcorets.dll 2015-06-09 18:03 . 2015-07-15 10:59 16384 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll 2015-06-09 13:16 . 2015-01-31 18:11 34512 ----a-w- c:\windows\system32\drivers\debutfilterx64.sys 2015-06-02 00:07 . 2015-07-15 10:59 254976 ----a-w- c:\windows\system32\cewmdm.dll 2015-06-01 23:47 . 2015-07-15 10:59 210432 ----a-w- c:\windows\SysWow64\cewmdm.dll 2015-05-25 18:19 . 2015-06-10 08:29 1255424 ----a-w- c:\windows\system32\diagtrack.dll 2015-05-25 18:19 . 2015-06-10 08:29 879104 ----a-w- c:\windows\system32\tdh.dll 2015-05-25 18:19 . 2015-06-10 08:29 113664 ----a-w- c:\windows\system32\sechost.dll 2015-05-25 18:18 . 2015-06-10 08:29 879104 ----a-w- c:\windows\system32\advapi32.dll 2015-05-25 18:18 . 2015-06-10 08:29 404992 ----a-w- c:\windows\system32\tracerpt.exe 2015-05-25 18:18 . 2015-06-10 08:29 47104 ----a-w- c:\windows\system32\typeperf.exe 2015-05-25 18:18 . 2015-06-10 08:29 43008 ----a-w- c:\windows\system32\relog.exe 2015-05-25 18:18 . 2015-06-10 08:29 104448 ----a-w- c:\windows\system32\logman.exe 2015-05-25 18:18 . 2015-06-10 08:29 19456 ----a-w- c:\windows\system32\diskperf.exe 2015-05-25 18:01 . 2015-06-10 08:29 635392 ----a-w- c:\windows\SysWow64\tdh.dll 2015-05-25 18:01 . 2015-06-10 08:29 92160 ----a-w- c:\windows\SysWow64\sechost.dll 2015-05-25 18:01 . 2015-06-10 08:29 641536 ----a-w- c:\windows\SysWow64\advapi32.dll 2015-05-25 18:00 . 2015-06-10 08:29 40448 ----a-w- c:\windows\SysWow64\typeperf.exe 2015-05-25 18:00 . 2015-06-10 08:29 364544 ----a-w- c:\windows\SysWow64\tracerpt.exe 2015-05-25 18:00 . 2015-06-10 08:29 37888 ----a-w- c:\windows\SysWow64\relog.exe 2015-05-25 18:00 . 2015-06-10 08:29 82944 ----a-w- c:\windows\SysWow64\logman.exe 2015-05-25 18:00 . 2015-06-10 08:29 17408 ----a-w- c:\windows\SysWow64\diskperf.exe 2015-05-25 17:00 . 2015-06-10 08:29 36864 ----a-w- c:\windows\system32\UtcResources.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2014-10-02 04:37 223432 ----a-w- c:\users\Veli\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2014-10-02 04:37 223432 ----a-w- c:\users\Veli\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2014-10-02 04:37 223432 ----a-w- c:\users\Veli\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Viber"="c:\users\Veli\AppData\Local\Viber\Viber.exe" [2015-08-12 72389840] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2015-08-07 53737488] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2013-11-19 766208] "VolPanel"="c:\program files (x86)\Creative\Sound Blaster X-Fi Surround 5.1 Pro\Volume Panel\VolPanlu.exe" [2010-12-08 241757] "Module Loader"="c:\program files (x86)\Creative\Shared Files\Module Loader\DLLML.exe" [2007-07-23 57344] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) "DisableCAD"= 1 (0x1) "EnableSecureUIAPath"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 MBAMService;MBAMService;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 BthL2caScoIfSrv;Bluetooth Profile Interface Driver Service;c:\windows\system32\Drivers\BtL2caScoIf.sys;c:\windows\SYSNATIVE\Drivers\BtL2caScoIf.sys [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 scvad_simple;SplitCam Virtual Microphone (WDM);c:\windows\system32\drivers\SplitCamAudio.sys;c:\windows\SYSNATIVE\drivers\SplitCamAudio.sys [x] R3 splitcam_hd_driver;SplitCam Virtual Video Driver;c:\windows\system32\DRIVERS\splitcam_hd_driver.sys;c:\windows\SYSNATIVE\DRIVERS\splitcam_hd_driver.sys [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x] R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x] S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x] S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x] S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.EXE;c:\program files\Realtek\Audio\HDA\AERTSr64.EXE [x] S2 AIPS;Arp Intelligent Protection Service;c:\program files (x86)\netcut\services\AIPS.exe;c:\program files (x86)\netcut\services\AIPS.exe [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x] S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x] S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service;c:\program files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe;c:\program files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [x] S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x] S2 RtkAudioService;Realtek Audio Service;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe [x] S2 ZAtheros Bt and Wlan Coex Agent;ZAtheros Bt and Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x] S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys;c:\windows\SYSNATIVE\DRIVERS\amdhub30.sys [x] S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys;c:\windows\SYSNATIVE\DRIVERS\amdxhc.sys [x] S3 AthBTPort;Qualcomm Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x] S3 btath_avdt;Qualcomm Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys;c:\windows\SYSNATIVE\drivers\btath_avdt.sys [x] S3 BTATH_BUS;Qualcomm Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x] S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x] S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x] S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x] S3 BtAudioBusSrv;Ralink Bluetooth Audio Bus Service;c:\windows\system32\Drivers\BtAudioBus.sys;c:\windows\SYSNATIVE\Drivers\BtAudioBus.sys [x] S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x] S3 debutfilter;Debut Filter Driver v6.40.02;c:\windows\system32\DRIVERS\debutfilterx64.sys;c:\windows\SYSNATIVE\DRIVERS\debutfilterx64.sys [x] S3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys;c:\windows\SYSNATIVE\drivers\ksaud.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] S3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x] S3 PsxDrv;PsxDrv;c:\windows\system32\drivers\psxdrv.sys;c:\windows\SYSNATIVE\drivers\psxdrv.sys [x] S3 RSP2STOR;Realtek PCIE CardReader Driver - P2;c:\windows\system32\DRIVERS\RtsP2Stor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsP2Stor.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2015-08-23 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-26 02:31] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2014-10-02 04:37 262344 ----a-w- c:\users\Veli\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2014-10-02 04:37 262344 ----a-w- c:\users\Veli\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2014-10-02 04:37 262344 ----a-w- c:\users\Veli\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2013-11-04 7204568] "NUSB3MON"="c:\program files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe" [2012-04-11 97280] "Creative SB Monitoring Utility"="sbavmon.dll" [2010-07-29 115712] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2015-04-29 1337000] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uDefault_Search_URL = hxxp://www.google.com uStart Page = hxxp://www.google.com mDefault_Search_URL = hxxp://www.google.com mDefault_Page_URL = hxxp://www.google.com mStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://www.google.com uSearchAssistant = hxxp://www.google.com IE: Free YouTube Download - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm IE: Free YouTube to MP3 Converter - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm Trusted Zone: com\*.Wondershare TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\users\Veli\AppData\Roaming\Mozilla\Firefox\Profiles\rvpbyvxo.default-1431283104865\ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . AddRemove-{8F46BFB2-11A5-4878-806A-87E5CA3C267A}_is1 - c:\users\Veli\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\SpeakyChatLB\unins000.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing\WinZip] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2015-08-23 10:56:57 ComboFix-quarantined-files.txt 2015-08-23 08:56 ComboFix2.txt 2015-02-22 22:57 . Vor Suchlauf: 19 Verzeichnis(se), 271.313.592.320 Bytes frei Nach Suchlauf: 21 Verzeichnis(se), 272.216.403.968 Bytes frei . - - End Of File - - 30B41BFDA0A92A36B826E3CBDFDBF9C9 A36C5E4F47E84449FF07ED3517B43A31
__________________ |
![]() |
Themen zu FritBox wlan lansgsam trotz gutem Empfang ! |
combofix, converter, defender, desktop, device driver, dnsapi.dll, explorer, failed, flash player, google, installmanager.exe, langsam, mozilla, mp3, onedrive, prozesse, realtek, registry, rundll, scan, security, services.exe, software, svchost.exe, system, udp, windows, wlan, yandex, zugriff verweigert |