Ich Grüsse euch erst mal, hab ein problem mit Avira der ständig warnung zeigt wenn ich usb rein stecke oder SD karte, ich hoffe ihr könnt mir weiter hilfen.
Code:
Alles auswählen Aufklappen ATTFilter
ComboFix 10-10-09.04 - Toshiba 10.10.2010 14:42:48.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.49.1031.18.2038.1193 [GMT 2:00]
ausgeführt von:: c:\users\Toshiba\Desktop\ComboFix.exe
* Neuer Wiederherstellungspunkt wurde erstellt
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Toshiba\AppData\Local\Temp\978B.tmp
c:\users\Toshiba\AppData\Roaming\logs.dat
c:\users\Toshiba\AppData\Roaming\Microsoft\Run.exe
c:\users\Toshiba\AppData\Roaming\Microsoft\taskmgr.exe
c:\users\Toshiba\AppData\Roaming\qghumeaylnlfdxfircvs85.exe
c:\users\Toshiba\AppData\Roaming\taskeng.exe
c:\users\Toshiba\AppData\Roaming\taskmgr.exe
.
((((((((((((((((((((((( Dateien erstellt von 2010-09-10 bis 2010-10-10 ))))))))))))))))))))))))))))))
.
2010-10-09 20:26 . 2010-10-09 20:26 -------- d-----w- c:\program files\Boilsoft Video Splitter
2010-10-09 19:59 . 2010-10-09 19:59 -------- d-----w- c:\users\Toshiba\AppData\Roaming\Boilsoft
2010-10-09 19:42 . 2010-10-09 19:42 -------- d-----w- c:\program files\Haali
2010-10-08 21:17 . 2010-10-08 21:17 -------- d-----w- c:\users\Toshiba\AppData\Roaming\Avira
2010-10-08 16:21 . 2010-09-09 22:52 6084944 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D2177659-06D0-468B-95F5-8D1E409B9A8B}\mpengine.dll
2010-10-08 15:52 . 2010-10-08 15:52 -------- d-----w- c:\programdata\Avira
2010-10-08 15:52 . 2010-10-08 15:52 -------- d-----w- c:\program files\Avira
2010-10-08 15:52 . 2010-03-01 08:05 124784 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-10-08 15:52 . 2010-02-16 12:24 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-10-08 15:52 . 2009-05-11 10:49 51992 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-10-08 15:52 . 2009-05-11 10:49 17016 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-10-08 07:49 . 2010-10-08 07:49 -------- d-----w- c:\program files\Emicsoft Studio
2010-10-08 06:03 . 2010-10-09 20:10 -------- d-----w- C:\Downloads
2010-10-08 06:03 . 2010-10-08 06:03 -------- d-----w- c:\users\Toshiba\AppData\Roaming\FlashGet
2010-10-08 06:03 . 2010-10-08 06:03 -------- d-----w- c:\program files\FlashGet
2010-10-07 01:18 . 2010-10-07 01:18 -------- d-----w- C:\Neuer Ordner
2010-10-07 00:52 . 2010-09-08 07:09 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-10-07 00:52 . 2010-09-08 07:07 50688 ----a-w- c:\windows\system32\ff_acm.acm
2010-10-06 21:49 . 2010-10-07 01:19 -------- d-----w- c:\programdata\QuickMediaConverter
2010-10-06 21:48 . 2010-10-06 21:48 -------- d-----w- c:\users\Toshiba\AppData\Roaming\CocoonSoftware
2010-10-06 21:48 . 2010-10-07 01:19 -------- d-----w- c:\program files\QuickMediaConverter
2010-10-06 21:48 . 2010-10-06 21:48 -------- d-----w- c:\users\Toshiba\AppData\Local\WDSetup
2010-10-06 16:37 . 2010-10-07 00:54 -------- d-----w- c:\users\Toshiba\AppData\Roaming\Leawo
2010-10-06 16:37 . 2009-08-16 15:08 178176 ----a-w- c:\windows\system32\unrar.dll
2010-10-06 16:37 . 2010-10-06 16:37 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-10-06 16:36 . 2010-10-07 00:54 -------- d-----w- c:\program files\Leawo
2010-10-06 16:28 . 2010-10-06 16:28 -------- d-----w- c:\program files\Common Files\SWF Studio
2010-10-06 16:27 . 2010-10-06 16:27 -------- d-----w- c:\program files\Riva
2010-10-06 14:49 . 2010-10-06 14:49 -------- d-----w- c:\users\Toshiba\AppData\Roaming\Sony Ericsson
2010-10-06 14:43 . 2010-10-06 14:43 -------- d-----w- c:\program files\Common Files\Adobe
2010-10-04 19:40 . 2010-10-04 19:40 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2010-10-04 19:38 . 2010-10-04 19:38 -------- d-----w- C:\Intel
2010-10-04 19:23 . 2010-10-04 19:23 -------- d-----w- c:\users\Toshiba\AppData\Roaming\Sony Corporation
2010-10-04 15:58 . 2007-07-19 16:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
2010-10-03 22:37 . 2010-10-03 22:37 -------- d-----w- c:\program files\Microsoft
2010-10-03 22:36 . 2010-10-03 22:36 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-10-03 22:36 . 2010-10-03 22:36 -------- d-----w- c:\windows\PCHEALTH
2010-10-02 19:43 . 2010-10-03 20:00 -------- dc----w- c:\windows\system32\DRVSTORE
2010-10-02 19:40 . 2009-09-04 15:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2010-10-02 19:40 . 2009-09-04 15:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2010-10-02 19:40 . 2009-09-04 15:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2010-10-02 19:40 . 2006-11-29 11:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2010-10-02 19:39 . 2010-10-02 19:39 -------- d-----w- c:\program files\Microsoft Silverlight
2010-10-02 19:39 . 2010-08-11 04:44 2983424 ----a-w- c:\windows\system32\UIRibbon.dll
2010-10-02 19:39 . 2010-08-11 04:35 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2010-10-02 19:38 . 2010-05-23 10:11 196608 ----a-w- c:\windows\system32\mfreadwrite.dll
2010-10-02 19:38 . 2010-05-23 10:15 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL
2010-10-02 19:38 . 2010-05-23 10:11 3181568 ----a-w- c:\windows\system32\mf.dll
2010-10-02 19:37 . 2010-10-02 19:37 15712 ----a-w- c:\program files\Common Files\Windows Live\.cache\4167a9321cb626914\MeshBetaRemover.exe
2010-10-02 19:37 . 2010-10-02 19:37 94040 ----a-w- c:\program files\Common Files\Windows Live\.cache\3d10c1f31cb626913\DSETUP.dll
2010-10-02 19:37 . 2010-10-02 19:37 525656 ----a-w- c:\program files\Common Files\Windows Live\.cache\3d10c1f31cb626913\DXSETUP.exe
2010-10-02 19:37 . 2010-10-02 19:37 1691480 ----a-w- c:\program files\Common Files\Windows Live\.cache\3d10c1f31cb626913\dsetup32.dll
2010-10-02 19:37 . 2010-10-02 19:37 94040 ----a-w- c:\program files\Common Files\Windows Live\.cache\397286ee1cb626912\DSETUP.dll
2010-10-02 19:37 . 2010-10-02 19:37 525656 ----a-w- c:\program files\Common Files\Windows Live\.cache\397286ee1cb626912\DXSETUP.exe
2010-10-02 19:37 . 2010-10-02 19:37 1691480 ----a-w- c:\program files\Common Files\Windows Live\.cache\397286ee1cb626912\dsetup32.dll
2010-10-02 19:36 . 2010-10-02 19:36 6260088 ----a-w- c:\program files\Common Files\Windows Live\.cache\170fa9891cb62690e\Silverlight.4.0.exe
2010-10-02 19:34 . 2010-10-02 22:44 -------- d-----w- c:\users\Toshiba\AppData\Local\Windows Live
2010-09-28 08:33 . 2010-09-28 08:33 -------- d-----w- c:\users\Toshiba\AppData\Local\Shareaza
2010-09-28 08:33 . 2010-09-28 09:00 -------- d-----w- c:\users\Toshiba\AppData\Roaming\Shareaza
2010-09-28 08:33 . 2010-09-28 15:27 -------- d-----w- c:\program files\Shareaza
2010-09-26 20:28 . 2010-10-06 17:31 -------- d-----w- C:\TEMP
2010-09-26 20:20 . 2010-09-26 20:34 -------- d-----w- c:\program files\IrfanView
2010-09-26 09:26 . 2010-10-08 16:25 -------- d-----w- c:\program files\Windows Live Safety Center
2010-09-22 16:10 . 2010-09-22 16:10 103864 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
2010-09-22 11:11 . 2010-09-22 11:11 825640 ----a-w- c:\program files\Common Files\Windows Live\.cache\474201d31cb626915\OEM\Packages\default\SearchEnhancementPackSetup.EXE
2010-09-22 01:09 . 2010-10-07 19:07 -------- d-----w- c:\users\Toshiba\AppData\Roaming\vlc
2010-09-22 01:08 . 2010-09-22 01:08 -------- d-----w- c:\program files\VideoLAN
2010-09-21 10:18 . 2010-09-21 10:34 -------- d-----w- c:\users\Toshiba\AppData\Roaming\PSpad
2010-09-21 10:18 . 2010-09-21 10:18 -------- d-----w- c:\program files\PSPad editor
2010-09-21 10:09 . 2010-09-21 10:10 -------- d-----w- c:\users\Toshiba\AppData\Roaming\Paltalk
2010-09-21 10:09 . 2010-09-21 10:09 -------- d-----w- c:\program files\Paltalk Messenger
2010-09-21 10:09 . 2010-09-21 10:09 -------- d-----w- c:\windows\PaltalkScene
2010-09-20 21:53 . 2010-10-09 23:51 -------- d-----w- c:\users\Toshiba\AppData\Roaming\gtk-2.0
2010-09-20 21:48 . 2010-09-20 21:48 -------- d-----w- c:\users\Toshiba\.thumbnails
2010-09-20 21:47 . 2010-10-10 06:35 -------- d-----w- c:\users\Toshiba\.gimp-2.6
2010-09-20 21:41 . 2010-09-20 21:41 -------- d-----w- c:\program files\GIMP-2.0
2010-09-20 20:30 . 2010-10-06 14:43 -------- d-----w- c:\users\Toshiba\AppData\Local\Adobe
2010-09-20 19:58 . 2010-10-09 21:42 -------- d-----w- c:\users\Toshiba\AppData\Roaming\FileZilla
2010-09-20 19:57 . 2010-10-05 13:13 -------- d-----w- c:\program files\FileZilla FTP Client
2010-09-20 10:39 . 2010-09-20 10:39 -------- d-----w- c:\program files\Common Files\xing shared
2010-09-20 10:39 . 2010-09-20 10:39 569397 ----a-w- c:\program files\Internet Explorer\PLUGINS\RichFX\Player\nprfxins.dll
2010-09-20 10:39 . 2010-09-20 10:39 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-09-20 10:39 . 2010-09-20 10:39 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-09-20 10:39 . 2010-09-20 10:39 -------- d-----w- c:\program files\Real
2010-09-20 10:39 . 2010-09-20 10:39 -------- d-----w- c:\program files\Common Files\Real
2010-09-19 20:07 . 2010-10-10 12:07 -------- d-----w- c:\users\Toshiba\AppData\Roaming\skypePM
2010-09-19 20:05 . 2010-10-10 12:42 -------- d-----w- c:\users\Toshiba\AppData\Roaming\Skype
2010-09-19 20:05 . 2010-09-19 20:05 -------- d-----r- c:\program files\Skype
2010-09-19 20:05 . 2010-09-19 20:05 -------- d-----w- c:\program files\Common Files\Skype
2010-09-19 20:05 . 2010-09-19 20:05 -------- d-----w- c:\programdata\Skype
2010-09-19 18:45 . 2010-09-22 19:05 -------- d-----w- c:\users\Toshiba\AppData\Roaming\DivX
2010-09-19 18:45 . 2010-09-19 18:45 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-09-19 18:44 . 2010-09-19 18:44 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-09-19 18:44 . 2010-09-19 18:45 -------- d-----w- c:\program files\DivX
2010-09-19 18:43 . 2010-09-19 18:45 -------- d-----w- c:\programdata\DivX
2010-09-19 17:10 . 2010-09-19 17:11 -------- d-----w- c:\users\Toshiba\AppData\Local\Microsoft Games
2010-09-19 09:32 . 2010-09-19 09:32 -------- d-----w- c:\users\Toshiba\AppData\Roaming\OpenOffice.org
2010-09-19 09:30 . 2010-09-19 09:30 -------- d-----w- c:\program files\JRE
2010-09-19 09:30 . 2010-09-19 09:30 -------- d-----w- c:\program files\OpenOffice.org 3
2010-09-19 09:30 . 2010-09-19 09:30 -------- d-----w- c:\program files\Common Files\Java
2010-09-19 09:30 . 2010-09-19 09:30 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-19 09:29 . 2010-09-19 09:29 -------- d-----w- c:\program files\Java
2010-09-14 16:11 . 2010-09-14 16:11 -------- d-----w- c:\users\Toshiba\AppData\Local\Diagnostics
2010-09-13 21:32 . 2010-10-08 23:04 -------- d-----w- c:\users\Toshiba\AppData\Local\Google
2010-09-13 21:32 . 2010-09-29 17:16 -------- d-----w- c:\program files\Google
2010-09-13 21:32 . 2010-09-13 21:32 -------- d-----w- c:\windows\system32\Macromed
2010-09-10 13:42 . 2010-10-08 15:10 -------- d-----w- c:\users\Toshiba\AppData\Roaming\install
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-09-02 13351304]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-09-29 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-01 1164584]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-09-20 202256]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
c:\users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-09-13 136176]
R3 sembbus;SEMC WMC Composite Device driver (WDM);c:\windows\system32\DRIVERS\sembbus.sys [2008-02-06 260992]
R3 sembcard;Sony Ericsson PC300 Mobile Broadband Command Interface Drivers (WDM);c:\windows\system32\DRIVERS\sembcard.sys [2008-02-06 337408]
R3 sembmdfl2;Sony Ericsson PC300 Wireless Modem Filter;c:\windows\system32\DRIVERS\sembmdfl2.sys [2008-02-06 14976]
R3 sembmdm2;Sony Ericsson PC300 Wireless Modem Driver;c:\windows\system32\DRIVERS\sembmdm2.sys [2008-02-06 380672]
R3 sembmgmt;Sony Ericsson PC300 Mobile Broadband Device Management Drivers (WDM);c:\windows\system32\DRIVERS\sembmgmt.sys [2008-02-06 343680]
R3 sembnd5;Sony Ericsson PC300 Mobile Broadband Network Adapter SENECA (NDIS);c:\windows\system32\DRIVERS\sembnd5.sys [2008-02-06 24960]
R3 sembunic;Sony Ericsson PC300 Mobile Broadband Network Adapter SENECA (WDM);c:\windows\system32\DRIVERS\sembunic.sys [2008-02-06 344064]
R3 sembwwan;Sony Ericsson PC300 Mobile Broadband Ethernet Control Drivers (WDM);c:\windows\system32\DRIVERS\sembwwan.sys [2008-02-06 337408]
R3 SEMCReserved;SEMC Reserved Interface;c:\windows\system32\DRIVERS\semcreserved.sys [2008-02-15 17408]
R3 Sony_EricssonWWSC;Sony Ericsson SIM Card Reader;c:\windows\system32\DRIVERS\sesc.sys [2007-08-14 12672]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000-Serie - Adaptertreiber für Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
S3 RTL8167;Realtek 8167 NT-Treiber;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
.
Inhalt des "geplante Tasks" Ordners
2010-10-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-13 21:32]
2010-10-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-13 21:32]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.de/
IE: &Alles mit FlashGet laden - c:\program files\FlashGet\jc_all.htm
IE: &Mit FlashGet laden - c:\program files\FlashGet\jc_link.htm
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Lookup on Merriam Webster
IE: Lookup on Wikipedia
Trusted Zone: campusspeicher.de\server14
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
HKCU-Run-Windows Update System - c:\users\Toshiba\AppData\Roaming\taskmgr.exe
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
[HKEY_USERS\S-1-5-21-2731685071-1132721656-2652739292-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
[HKEY_USERS\S-1-5-21-2731685071-1132721656-2652739292-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
- - - - - - - > 'Explorer.exe'(3612)
c:\program files\DivX\DivX Plus Media Foundation Components\DivXThumbnailProvider.dll
c:\program files\DivX\DivX Plus Media Foundation Components\DivXMFSource.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\system32\taskhost.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\conhost.exe
c:\windows\system32\sppsvc.exe
c:\windows\system32\conhost.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\Windows Media Player\wmpnetwk.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Zeit der Fertigstellung: 2010-10-10 14:58:01 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2010-10-10 12:58
Vor Suchlauf: 10 Verzeichnis(se), 33.253.355.520 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 33.963.888.640 Bytes frei
- - End Of File - - 6D984AAF6DC835DD80EF13DEC396404C