Rafau2012 | 22.05.2014 15:34 | so habs geschafft:)
COMBI LOG
Combofix Logfile: Code:
ComboFix 14-05-19.01 - SYSTEM 22.05.2014 16:15:54.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.16297.14125 [GMT 2:00]
ausgeführt von:: c:\windows\SysWOW64\config\systemprofile\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}
FW: Kaspersky Internet Security *Disabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}
SP: Kaspersky Internet Security *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{0904D6ED-EE39-48D7-8F28-39CA9D8A7906}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{2B8CC93A-9D39-4E45-92B2-75BEAFEB8BD8}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{653AC8B9-BEC7-4C71-8E6A-34F8F263A7F8}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{7F49A7AF-D89C-4AF1-9B70-C6CCC5EB0F23}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{8C0182F0-D8BB-4DA8-928E-9001C8CDEB88}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{92D7D1A2-0ED9-4954-8D88-2E39F25BC15C}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{AF2EEF1C-6930-45AB-AFC0-66F72930AF05}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{B2E065D9-7C08-406F-A94F-7EDA50A703F1}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{D7FBBA52-2D68-4825-B19F-C528848ED495}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{E811012E-0053-47A4-BC8D-7DA0336F123E}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{10BD5412-1AC2-419B-BB91-6F16F6946689}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{3D657213-4FBF-4625-9C10-029A603BA0CC}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{3EFE3162-713D-4C6F-BD2B-256AA63BED8D}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{5E91861D-C3F2-4693-9BD2-C74F403E872A}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{7AC79284-BC91-46E4-9FFD-D01F6D410F04}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{A3A96759-4F81-419B-BA94-EF459EBE3A54}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{A56DBE6C-09C2-4C12-868E-3E3318DD2495}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{B4C78930-42C3-49A5-B878-A19283A51565}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{C1894907-0B21-456A-8BF3-615187C2B1D3}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{E6FB537A-0BDC-4827-9735-E9C9338F8A65}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\OCS\ICSharpCode.SharpZipLib.dll
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\OCS\ocs_v71b.exe
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{0904D6ED-EE39-48D7-8F28-39CA9D8A7906}.tmp
c:\windows\system32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{2B8CC93A-9D39-4E45-92B2-75BEAFEB8BD8}.tmp
c:\windows\system32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{653AC8B9-BEC7-4C71-8E6A-34F8F263A7F8}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{7F49A7AF-D89C-4AF1-9B70-C6CCC5EB0F23}.tmp
c:\windows\system32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{8C0182F0-D8BB-4DA8-928E-9001C8CDEB88}.tmp
c:\windows\system32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{92D7D1A2-0ED9-4954-8D88-2E39F25BC15C}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{AF2EEF1C-6930-45AB-AFC0-66F72930AF05}.tmp
c:\windows\system32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{B2E065D9-7C08-406F-A94F-7EDA50A703F1}.tmp
c:\windows\system32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{D7FBBA52-2D68-4825-B19F-C528848ED495}.tmp
c:\windows\system32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{E811012E-0053-47A4-BC8D-7DA0336F123E}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{10BD5412-1AC2-419B-BB91-6F16F6946689}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{3D657213-4FBF-4625-9C10-029A603BA0CC}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{3EFE3162-713D-4C6F-BD2B-256AA63BED8D}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{5E91861D-C3F2-4693-9BD2-C74F403E872A}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{7AC79284-BC91-46E4-9FFD-D01F6D410F04}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{A3A96759-4F81-419B-BA94-EF459EBE3A54}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{A56DBE6C-09C2-4C12-868E-3E3318DD2495}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{B4C78930-42C3-49A5-B878-A19283A51565}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{C1894907-0B21-456A-8BF3-615187C2B1D3}.tmp
c:\windows\system32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{E6FB537A-0BDC-4827-9735-E9C9338F8A65}.tmp
c:\windows\system32\config\systemprofile\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\windows\System32\config\systemprofile\AppData\Local\Temp\OCS\ICSharpCode.SharpZipLib.dll
c:\windows\System32\config\systemprofile\AppData\Local\Temp\OCS\ocs_v71b.exe
.
---- Vorheriger Suchlauf -------
.
C:\Install.exe
c:\program files (x86)\DealPly
c:\program files (x86)\DealPly\DealPly.crx
c:\program files (x86)\DealPly\icon.ico
c:\program files (x86)\DealPly\uninst.exe
C:\uninstall.exe
c:\users\Rafa\AppData\Local\Google\Chrome\User Data\Default\bProtectorPreferences
c:\users\Rafa\AppData\Roaming\convert\convert.exe
c:\users\Rafa\Taskmgr.exe
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\_iu14D2N.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{0904D6ED-EE39-48D7-8F28-39CA9D8A7906}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{2B8CC93A-9D39-4E45-92B2-75BEAFEB8BD8}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{653AC8B9-BEC7-4C71-8E6A-34F8F263A7F8}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{7F49A7AF-D89C-4AF1-9B70-C6CCC5EB0F23}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{8C0182F0-D8BB-4DA8-928E-9001C8CDEB88}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{92D7D1A2-0ED9-4954-8D88-2E39F25BC15C}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{AF2EEF1C-6930-45AB-AFC0-66F72930AF05}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{B2E065D9-7C08-406F-A94F-7EDA50A703F1}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{D7FBBA52-2D68-4825-B19F-C528848ED495}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{E811012E-0053-47A4-BC8D-7DA0336F123E}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{10BD5412-1AC2-419B-BB91-6F16F6946689}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{3D657213-4FBF-4625-9C10-029A603BA0CC}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{3EFE3162-713D-4C6F-BD2B-256AA63BED8D}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{5E91861D-C3F2-4693-9BD2-C74F403E872A}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{7AC79284-BC91-46E4-9FFD-D01F6D410F04}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{A3A96759-4F81-419B-BA94-EF459EBE3A54}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{A56DBE6C-09C2-4C12-868E-3E3318DD2495}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{B4C78930-42C3-49A5-B878-A19283A51565}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{C1894907-0B21-456A-8BF3-615187C2B1D3}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{E6FB537A-0BDC-4827-9735-E9C9338F8A65}.tmp
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\OCS\ICSharpCode.SharpZipLib.dll
c:\windows\system32\config\SYSTEM~1\AppData\Local\Temp\OCS\ocs_v71b.exe
c:\windows\system32\config\systemprofile\AppData\Local\Temp\_iu14D2N.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{0904D6ED-EE39-48D7-8F28-39CA9D8A7906}.tmp
c:\windows\system32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{2B8CC93A-9D39-4E45-92B2-75BEAFEB8BD8}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{653AC8B9-BEC7-4C71-8E6A-34F8F263A7F8}.tmp
c:\windows\system32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{7F49A7AF-D89C-4AF1-9B70-C6CCC5EB0F23}.tmp
c:\windows\system32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{8C0182F0-D8BB-4DA8-928E-9001C8CDEB88}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{92D7D1A2-0ED9-4954-8D88-2E39F25BC15C}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{AF2EEF1C-6930-45AB-AFC0-66F72930AF05}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{B2E065D9-7C08-406F-A94F-7EDA50A703F1}.tmp
c:\windows\system32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{D7FBBA52-2D68-4825-B19F-C528848ED495}.tmp
c:\windows\system32\config\systemprofile\AppData\Local\Temp\{BF85EE71-154A-44D7-93FB-93AD37EBB8E7}\{E811012E-0053-47A4-BC8D-7DA0336F123E}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{10BD5412-1AC2-419B-BB91-6F16F6946689}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{3D657213-4FBF-4625-9C10-029A603BA0CC}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{3EFE3162-713D-4C6F-BD2B-256AA63BED8D}.tmp
c:\windows\system32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{5E91861D-C3F2-4693-9BD2-C74F403E872A}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{7AC79284-BC91-46E4-9FFD-D01F6D410F04}.tmp
c:\windows\system32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{A3A96759-4F81-419B-BA94-EF459EBE3A54}.tmp
c:\windows\system32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{A56DBE6C-09C2-4C12-868E-3E3318DD2495}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{B4C78930-42C3-49A5-B878-A19283A51565}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{C1894907-0B21-456A-8BF3-615187C2B1D3}.tmp
c:\windows\system32\config\systemprofile\AppData\Local\Temp\{C700C51D-1C88-4073-A7E7-9F3B1862E7B8}\{E6FB537A-0BDC-4827-9735-E9C9338F8A65}.tmp
c:\windows\System32\config\systemprofile\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\windows\system32\config\systemprofile\AppData\Local\Temp\OCS\ICSharpCode.SharpZipLib.dll
c:\windows\System32\config\systemprofile\AppData\Local\Temp\OCS\ocs_v71b.exe
c:\windows\SysWow64\Cache
c:\windows\SysWow64\Cache\12c07d8834c79ba4.fb
c:\windows\SysWow64\Cache\12c07d8834c79ba4__exp__1400846112
c:\windows\SysWow64\Cache\26c630d098e22dd5.fb
c:\windows\SysWow64\Cache\26c630d098e22dd5__exp__1400709644
c:\windows\SysWow64\Cache\272512937d9e61a4.fb
c:\windows\SysWow64\Cache\272512937d9e61a4__exp__1400846143
c:\windows\SysWow64\Cache\287204568329e189.fb
c:\windows\SysWow64\Cache\287204568329e189__exp__1400709657
c:\windows\SysWow64\Cache\28bc8f716fd76a47.fb
c:\windows\SysWow64\Cache\28bc8f716fd76a47__exp__1400846126
c:\windows\SysWow64\Cache\31a0997e9a5b5eb3.fb
c:\windows\SysWow64\Cache\31a0997e9a5b5eb3__exp__1400709653
c:\windows\SysWow64\Cache\32c84fe32bb74d60.fb
c:\windows\SysWow64\Cache\32c84fe32bb74d60__exp__1400846146
c:\windows\SysWow64\Cache\3917078cb68ec657.fb
c:\windows\SysWow64\Cache\3917078cb68ec657__exp__1400709615
c:\windows\SysWow64\Cache\590ba23ce359fd0c.fb
c:\windows\SysWow64\Cache\590ba23ce359fd0c__exp__1400846145
c:\windows\SysWow64\Cache\610289e025a3ee9a.fb
c:\windows\SysWow64\Cache\610289e025a3ee9a__exp__1400709640
c:\windows\SysWow64\Cache\651c5d3cdbfb8bd1.fb
c:\windows\SysWow64\Cache\651c5d3cdbfb8bd1__exp__1400846141
c:\windows\SysWow64\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\SysWow64\Cache\6c59ac5e7e7a3ad0__exp__1400846142
c:\windows\SysWow64\Cache\6d03dad1035885d3.fb
c:\windows\SysWow64\Cache\6d03dad1035885d3__exp__1400846150
c:\windows\SysWow64\Cache\935ee77178548e84.fb
c:\windows\SysWow64\Cache\935ee77178548e84__exp__1400846137
c:\windows\SysWow64\Cache\95f567698be8a182.fb
c:\windows\SysWow64\Cache\95f567698be8a182__exp__1400709648
c:\windows\SysWow64\Cache\ad10a52aff5e038d.fb
c:\windows\SysWow64\Cache\ad10a52aff5e038d__exp__1400846132
c:\windows\SysWow64\Cache\c1fa887b03019701.fb
c:\windows\SysWow64\Cache\c1fa887b03019701__exp__1400846149
c:\windows\SysWow64\Cache\c4d28dca2e7648be.fb
c:\windows\SysWow64\Cache\c4d28dca2e7648be__exp__1400846138
c:\windows\SysWow64\Cache\d201ef9910cd39de.fb
c:\windows\SysWow64\Cache\d201ef9910cd39de__exp__1400846139
c:\windows\SysWow64\Cache\d2e94710a5708128.fb
c:\windows\SysWow64\Cache\d2e94710a5708128__exp__1400709624
c:\windows\SysWow64\Cache\d79b9dfe81484ec4.fb
c:\windows\SysWow64\Cache\d79b9dfe81484ec4__exp__1400709632
c:\windows\SysWow64\Cache\f998975c9cc711ee.fb
c:\windows\SysWow64\Cache\f998975c9cc711ee__exp__1400846148
c:\windows\SysWow64\msvcsv60.dll
c:\windows\SysWow64\winsh320
c:\windows\SysWow64\winsh321
c:\windows\SysWow64\winsh322
c:\windows\SysWow64\winsh323
c:\windows\SysWow64\winsh324
c:\windows\SysWow64\winsh325
c:\windows\wininit.ini
E:\install.exe
.
-- Vorheriger Suchlauf --
.
Infizierte Kopie von c:\windows\SysWow64\user32.dll wurde gefunden und desinfiziert
Kopie von - c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll wurde wiederhergestellt
.
--------
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-04-22 bis 2014-05-22 ))))))))))))))))))))))))))))))
.
.
2014-05-22 14:28 . 2014-05-22 14:28 -------- d-----w- c:\users\Rafa\AppData\Local\temp
2014-05-22 14:28 . 2014-05-22 14:28 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-05-21 13:12 . 2014-05-21 22:18 -------- d-----w- C:\FRST
2014-05-21 08:57 . 2014-05-21 08:58 -------- d-----w- c:\program files (x86)\TrojanHunter 5.5
2014-05-21 08:57 . 2014-05-21 08:57 -------- d-----w- c:\programdata\TrojanHunter
2014-05-20 23:26 . 2014-05-21 10:02 119512 ----a-w- c:\windows\system32\drivers\48230029.sys
2014-05-20 21:28 . 2014-05-20 21:28 -------- d-----w- c:\windows\system32\%LOCALAPPDATA%
2014-05-20 20:56 . 2014-05-20 20:56 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2014-05-20 20:56 . 2014-05-22 13:26 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-05-20 20:22 . 2014-05-20 20:22 -------- d-----w- c:\windows\SysWow64\%LOCALAPPDATA%
2014-05-20 20:22 . 2014-05-20 20:23 -------- d-----w- c:\windows\system32\config\systemprofile\lucidlogix
2014-05-20 20:21 . 2014-05-22 14:28 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\Temp
2014-05-20 20:16 . 2014-05-20 20:16 -------- d-----w- c:\users\Default\AppData\Local\Amazon Cloud Player
2014-05-20 20:16 . 2014-05-20 20:16 -------- d-----w- c:\users\Default\AppData\Local\NVIDIA
2014-05-20 20:16 . 2014-05-20 20:17 -------- d-----w- c:\users\TEMP
2014-05-20 19:10 . 2014-05-20 19:10 -------- d-----w- c:\users\Rafa\AppData\Roaming\SWAM
2014-05-19 14:03 . 2014-05-19 14:03 -------- d-----w- c:\programdata\DirectX
2014-05-14 15:03 . 2014-05-14 15:03 -------- d-----w- c:\program files (x86)\Vintage Amp Room
2014-05-14 15:00 . 2009-11-05 07:50 9535488 ----a-w- c:\program files (x86)\Tube Delay.dll
2014-05-14 14:53 . 2014-05-14 15:03 -------- d-----w- c:\program files (x86)\Softube
2014-05-11 17:47 . 2014-05-11 17:49 -------- d-----w- c:\programdata\VideoCopilot
2014-05-11 17:05 . 2014-05-21 00:53 -------- d-----w- c:\program files (x86)\GenArts
2014-05-11 17:05 . 2014-05-11 17:05 -------- d-----w- c:\programdata\GenArts
2014-05-11 13:04 . 2014-05-11 13:04 -------- d-----w- c:\programdata\Juicer3
2014-05-11 11:56 . 2014-05-11 11:56 159744 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
2014-05-11 11:56 . 2014-05-11 11:56 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2014-05-11 11:56 . 2014-05-11 11:56 159744 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
2014-05-11 11:56 . 2014-05-11 11:56 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2014-05-11 11:56 . 2014-05-11 11:56 159744 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
2014-05-11 11:56 . 2014-05-11 11:56 159744 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
2014-05-11 11:56 . 2014-05-11 11:56 159744 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
2014-05-11 11:56 . 2014-05-11 11:56 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2014-05-11 11:56 . 2014-05-11 11:56 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2014-05-11 11:56 . 2014-05-11 11:56 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2014-05-11 11:56 . 2014-05-11 11:56 159744 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
2014-05-11 11:56 . 2014-05-11 11:56 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2014-05-09 18:37 . 2014-05-09 18:37 -------- d-----w- c:\programdata\Note
2014-05-08 17:08 . 2014-05-08 17:08 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\McAfee
2014-05-08 13:48 . 2014-05-08 13:48 227704 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2014-05-08 13:48 . 2014-05-08 13:48 227704 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
2014-05-07 16:49 . 2014-05-07 16:49 -------- d-----w- c:\program files (x86)\Yamaha
2014-05-07 16:49 . 2014-05-07 16:49 -------- d-----w- c:\program files (x86)\Common Files\Yamaha
2014-05-07 16:46 . 2014-05-07 16:46 -------- d-----w- c:\users\Rafa\AppData\Local\Downloaded Installations
2014-05-03 09:25 . 2014-05-03 09:25 -------- d-----w- c:\users\Rafa\AppData\Roaming\DropboxMaster
2014-04-27 11:15 . 2014-04-27 11:16 -------- d-----w- c:\programdata\AVG Secure Search
2014-04-25 09:22 . 2014-04-25 09:22 -------- d-----w- c:\users\Rafa\AppData\Roaming\Blue Cat Audio
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-04-27 11:15 . 2014-03-26 00:34 50464 ----a-w- c:\windows\system32\drivers\avgtpx64.sys
2014-04-17 17:22 . 2014-04-17 17:22 98304 ----a-w- c:\windows\SysWow64\firefaceusb.exe
2014-04-17 17:22 . 2014-04-17 17:22 98304 ----a-w- c:\windows\system32\firefaceusb.exe
2014-04-17 17:22 . 2014-04-17 17:22 84096 ----a-w- c:\windows\system32\drivers\fireface_usb.sys
2014-04-17 17:22 . 2014-04-17 17:22 35840 ----a-w- c:\windows\system32\fireface_usb_asio_64.dll
2014-04-17 17:22 . 2014-04-17 17:22 33792 ----a-w- c:\windows\SysWow64\fireface_usb_asio.dll
2014-04-17 17:22 . 2014-04-17 17:22 33792 ----a-w- c:\windows\system32\fireface_usb_asio.dll
2014-04-17 17:22 . 2014-04-17 17:22 22900440 ----a-w- c:\windows\system32\TotalMixFX.exe
2014-04-17 17:22 . 2014-04-17 17:22 101504 ----a-w- c:\windows\system32\drivers\fireface_usb_64.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}]
2011-09-12 06:06 413400 ----a-w- c:\progra~2\SITERA~1\SiteRank.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2014-04-27 11:15 3559448 ----a-w- c:\program files (x86)\AVG Secure Search\18.1.0.443\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files (x86)\AVG Secure Search\18.1.0.443\AVG Secure Search_toolbar.dll" [2014-04-27 3559448]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"XFastUsb"="c:\program files (x86)\XFastUsb\XFastUsb.exe" [2011-08-30 4942336]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
"SiteRanker"="c:\program files (x86)\SiteRanker\SiteRankTray.exe" [2011-09-12 320000]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2012-05-23 296056]
"WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2012-06-28 74752]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [2012-10-30 206448]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2014-01-20 43848]
"SearchSettings"="c:\program files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe" [2012-10-16 1111432]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"UATrayIcon"="c:\program files (x86)\Universal Audio\Powered Plugins\UATrayIcon.exe" [2013-10-03 1404928]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2014-01-20 152392]
"vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2014-04-27 2557976]
"yfwtray"="c:\program files (x86)\Yamaha\FWDriver\yfwtray.exe" [2008-03-06 110592]
"yfwcm"="c:\program files (x86)\Yamaha\FWDriver\yfwcm.exe" [2009-05-27 557056]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2014-01-17 421888]
"THGuard"="c:\program files (x86)\TrojanHunter 5.5\THGuard.exe" [2012-10-22 1086880]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~1\LUCIDL~1\VIRTU\x86\appinit_dll.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
"UnlockerAssistant"="c:\program files (x86)\Unlocker\UnlockerAssistant.exe"
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
2;2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 CltMngSvc;Search Protect by Conduit Service;c:\progra~2\SearchProtect\Main\bin\CltMngSvc.exe;c:\progra~2\SearchProtect\Main\bin\CltMngSvc.exe [x]
R2 WajamUpdaterV2;WajamUpdaterV2;c:\program files (x86)\Wajam\Updater\WajamUpdaterV2.exe;c:\program files (x86)\Wajam\Updater\WajamUpdaterV2.exe [x]
R3 DELTAII;Service for M-Audio Delta Driver (WDM);c:\windows\system32\DRIVERS\MAudioDelta.sys;c:\windows\SYSNATIVE\DRIVERS\MAudioDelta.sys [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [x]
R3 firefaceu64;RME Fireface USB Audio Device;c:\windows\system32\drivers\fireface_usb_64.sys;c:\windows\SYSNATIVE\drivers\fireface_usb_64.sys [x]
R3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS;c:\windows\SYSNATIVE\drivers\FNETTBOH_305.SYS [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 PAC207;SoC PC-Camera;c:\windows\system32\DRIVERS\PFC027.SYS;c:\windows\SYSNATIVE\DRIVERS\PFC027.SYS [x]
R3 t2usb64;Trigger II External Graphics;c:\windows\system32\drivers\t2usb64.sys;c:\windows\SYSNATIVE\drivers\t2usb64.sys [x]
R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
S0 mctkmdldr;mctkmdldr;c:\windows\system32\drivers\mctkmdldr64.sys;c:\windows\SYSNATIVE\drivers\mctkmdldr64.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AsrAppCharger.sys [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys;c:\windows\SYSNATIVE\drivers\avgtpx64.sys [x]
S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS;c:\windows\SYSNATIVE\drivers\FNETURPX.SYS [x]
S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys;c:\windows\SYSNATIVE\DRIVERS\kl2.sys [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [x]
S2 DigiNet;Digidesign Ethernet Support;c:\windows\system32\DRIVERS\diginet.sys;c:\windows\SYSNATIVE\DRIVERS\diginet.sys [x]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [x]
S2 GManager;GManager;c:\windows\system32\GManager.exe;c:\windows\SYSNATIVE\GManager.exe [x]
S2 MCTDesktopSvr;MCTDesktopSvr;c:\program files (x86)\Common Files\DesktopUtil\MCTDesktopSvr.exe;c:\program files (x86)\Common Files\DesktopUtil\MCTDesktopSvr.exe [x]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 PaceLicenseDServices;PACE License Services;c:\program files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe;c:\program files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 vToolbarUpdater18.1.0;vToolbarUpdater18.1.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.0\ToolbarUpdater.exe;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.0\ToolbarUpdater.exe [x]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
S3 iLokDrvr;Usb Driver;c:\windows\system32\DRIVERS\iLokDrvr.sys;c:\windows\SYSNATIVE\DRIVERS\iLokDrvr.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
S3 mctkmd;mctkmd;c:\windows\system32\drivers\mctkmd64.sys;c:\windows\SYSNATIVE\drivers\mctkmd64.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 SynUSB64;eLicenser;c:\windows\system32\DRIVERS\SynUSB64.sys;c:\windows\SYSNATIVE\DRIVERS\SynUSB64.sys [x]
S3 UAD2Pcie;Universal Audio UAD-2 DSP Accelerator;c:\windows\system32\DRIVERS\UAD2Pcie.sys;c:\windows\SYSNATIVE\DRIVERS\UAD2Pcie.sys [x]
S3 UAD2System;UAD-2 Global System Service;c:\windows\system32\DRIVERS\UAD2System.sys;c:\windows\SYSNATIVE\DRIVERS\UAD2System.sys [x]
S3 VirtuWDDM;VirtuWDDM;c:\windows\system32\DRIVERS\VirtuWDDM.sys;c:\windows\SYSNATIVE\DRIVERS\VirtuWDDM.sys [x]
S3 YFWBUS;Yamaha Steinberg FW Bus;c:\windows\system32\Drivers\yfwbus.sys;c:\windows\SYSNATIVE\Drivers\yfwbus.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-05-16 16:11 1077576 ----a-w- c:\program files (x86)\Google\Chrome\Application\34.0.1847.137\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-05-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-26 12:44]
.
2014-05-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-26 12:44]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VIRTU"="c:\program files\Lucidlogix Technologies\VIRTU\VirtuControlPanel.Exe" [2011-04-21 2619488]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-14 172144]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-12-14 399984]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-14 441968]
"MCTDUtil"="c:\program files (x86)\Common Files\DesktopUtil\Util-Desktop.exe" [2011-05-03 195200]
"FDispPos"="c:\program files (x86)\Common Files\DesktopUtil\Util-Desktop.exe" [2011-05-03 195200]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-02-05 2234144]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-02-05 1179576]
"FirefaceUsbTray1"="firefaceusb.exe" [2014-04-17 98304]
"FirefaceMixTray2"="TotalMixFX.exe" [2014-04-17 22900440]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\progra~1\LUCIDL~1\VIRTU\appinit_dll.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 83.169.186.161 83.169.186.225
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.0\ViProtocol.dll
FF - ProfilePath -
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - c:\program files (x86)\DealPly\DealPlyIE.dll
BHO-{B922D405-6D13-4A2B-AE89-08A030DA4402} - (no file)
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
BHO-{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - c:\program files (x86)\Hotspot Shield\HssIE\HssIE_64.dll
Toolbar-{EFEED92A-A33D-4873-BA8F-32BAA631E54D} - (no file)
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file)
HKLM-Run-Nvtmru - c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe
AddRemove-Camel Audio Camel Phat VST v3.15 - c:\progra~2\COMMON~1\DIGIDE~1\WAVESH~1\CAMELP~1\UNWISE.EXE
AddRemove-Camel Audio Camel Space VST v1.15 - c:\progra~2\COMMON~1\DIGIDE~1\WAVESH~1\CAMELS~1\UNWISE.EXE
AddRemove-claro - c:\program files (x86)\Claro LTD\claro\1.8.3.10\uninstall.exe
AddRemove-db audioware Sidechain Gate VST v1.1.0 - c:\progra~2\STEINB~1\VSTPLU~1\SIDECH~2\UNWISE.EXE
AddRemove-DealPly - c:\program files (x86)\DealPly\uninst.exe
AddRemove-GmdeiaMusic Oddity bank5 Addon - c:\progra~2\STEINB~1\VSTPLU~1\GMEDIA~1\UNWISE.EXE
AddRemove-Native Instruments Battery 3 - c:\progra~2\STEINB~1\CUBASE~1\VSTPLU~1\STEINB~1\UNWISE.EXE
AddRemove-Pinguin Audio Meter v2.2 - c:\audio\PINGUI~1\UNWISE.EXE
AddRemove-Predator_is1 - c:\program files (x86)\Steinberg\Cubase 5\VSTPlugins\unins000.exe
AddRemove-Rob Papen Blue VSTi v1.01 - c:\progra~2\STEINB~1\CUBASE~1\VSTPLU~1\WAVESH~1\Blue\UNWISE.EXE
AddRemove-SearchProtect - c:\progra~2\SearchProtect\Main\bin\uninstall.exe
AddRemove-Sndbad Shaders 1.04 - c:\users\Rafa\Documents\Uninstall.exe
AddRemove-{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693} - c:\programdata\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\uninstall.exe
AddRemove-{B2D9F699-B4A4-4D37-941E-1B55DF33A96D}_is1 - c:\program files (x86)\Steinberg\Cubase 5\VSTPlugins\BREVERB 2\unins000.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PaceLicenseDServices]
"ImagePath"="\"c:\program files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe\" -u https://activation.paceap.com/InitiateActivation"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:43,5c,05,7c,dc,a6,b6,31,2d,cf,25,00,89,1c,88,2e,db,dc,07,d7,49,
ec,1f,bd,03,6d,3b,e5,a9,cf,a0,41,f3,05,cf,d7,c9,f1,ae,61,e8,3d,d4,9a,15,ee,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:43,5c,05,7c,dc,a6,b6,31,2d,cf,25,00,89,1c,88,2e,db,dc,07,d7,49,
ec,1f,bd,03,6d,3b,e5,a9,cf,a0,41,f3,05,cf,d7,c9,f1,ae,61,e8,3d,d4,9a,15,ee,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-05-22 16:35:12
ComboFix-quarantined-files.txt 2014-05-22 14:35
.
Vor Suchlauf: 23 Verzeichnis(se), 216.157.560.832 Bytes frei
Nach Suchlauf: 27 Verzeichnis(se), 215.517.421.568 Bytes frei
.
- - End Of File - - DE643549854A0AAA3965A2C599D375E3 --- --- ---
A36C5E4F47E84449FF07ED3517B43A31
[/CODE] |