ingolfomas | 07.11.2013 18:07 | Hallo schrauber,
habe ich gemacht.
Antivirensoftware ist der Bitdefender. Habe ihn ausgeschaltet, aber trotzdem wurde gemerckert, "der Scanner sei noch aktiv".
Angezeigt wurde er mir jedoch nicht mehr.
Anbei die Log-Datei: Code:
ComboFix 13-11-04.01 - myNotebook 07.11.2013 17:49:02.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3957.2581 [GMT 1:00]
ausgeführt von:: c:\users\myNotebook\Desktop\ComboFix.exe
AV: Bitdefender Antivirus Free Edition *Enabled/Updated* {9B5F5313-CAF9-DD97-C460-E778420237B4}
SP: Bitdefender Antivirus Free Edition *Enabled/Updated* {203EB2F7-ECC3-D219-FED0-DC0A39857D09}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\1371637406.bdinstall.bin
c:\programdata\1371637718.bdinstall.bin
c:\programdata\PCDr\6308\AddOnDownloaded\2c784c13-702f-431e-a492-e9dddd757b25.dll
c:\programdata\PCDr\6308\AddOnDownloaded\3cc3b539-b998-4728-8055-1201221a38d4.dll
c:\programdata\PCDr\6308\AddOnDownloaded\66858fdf-b35c-4b24-a074-915d56b3871b.dll
c:\programdata\PCDr\6308\AddOnDownloaded\704dfeb5-9129-4d88-8096-7f3bc80eb1ec.dll
c:\programdata\PCDr\6308\AddOnDownloaded\8fab1a01-d6b6-4640-ac86-c3ddd583c840.dll
c:\programdata\PCDr\6308\AddOnDownloaded\9d97f346-8efc-4e33-9c3b-3eef6c324e61.dll
c:\programdata\PCDr\6308\AddOnDownloaded\b96b7bbd-964e-47f1-9323-f48f460042bf.dll
c:\programdata\PCDr\6308\AddOnDownloaded\b99be28c-ffd7-4136-9706-38ff86c43537.dll
c:\programdata\PCDr\6308\AddOnDownloaded\f12de547-df4d-4236-9129-baac054f90ab.dll
c:\programdata\PCDr\6308\AddOnDownloaded\fc470dbb-846d-42d3-bb0a-6363a559f3fb.dll
c:\users\Admin\AppData\Roaming\AcroIEHelpe.txt
c:\users\myNotebook\AppData\Roaming\AcroIEHelpe.txt
c:\users\myNotebook\GoToAssistDownloadHelper.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-10-07 bis 2013-11-07 ))))))))))))))))))))))))))))))
.
.
2013-11-07 10:00 . 2013-11-07 10:15 -------- d-----w- c:\users\Admin
2013-11-07 09:40 . 2013-11-07 09:40 -------- d-----w- C:\FRST
2013-11-06 11:40 . 2013-11-06 11:40 -------- d-----w- c:\users\myNotebook\AppData\Roaming\Malwarebytes
2013-11-06 11:39 . 2013-11-06 11:39 -------- d-----w- c:\programdata\Malwarebytes
2013-11-06 11:39 . 2013-04-04 13:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-11-06 10:19 . 2013-11-06 11:42 -------- d-----w- C:\AdwCleaner
2013-11-05 10:52 . 2013-11-05 10:52 -------- d-----w- c:\windows\SysWow64\wbem\en-US
2013-11-05 10:52 . 2013-11-05 10:52 -------- d-----w- c:\windows\system32\wbem\en-US
2013-11-05 10:49 . 2013-02-17 00:40 28672 ----a-w- c:\windows\system32\IEUDINIT.EXE
2013-11-05 10:41 . 2013-11-05 10:41 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-11-05 10:35 . 2013-11-05 10:35 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-11-05 10:35 . 2013-11-05 10:35 7808 ----a-w- c:\windows\system32\drivers\usbd.sys
2013-11-05 10:35 . 2013-11-05 10:35 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-11-05 10:35 . 2013-11-05 10:35 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-11-05 10:35 . 2013-11-05 10:35 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-11-05 10:35 . 2013-11-05 10:35 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-11-05 10:35 . 2013-11-05 10:35 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-11-05 10:33 . 2013-11-05 10:33 461312 ----a-w- c:\windows\system32\scavengeui.dll
2013-11-05 10:29 . 2013-11-05 10:29 185344 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2013-11-05 10:29 . 2013-11-05 10:29 100864 ----a-w- c:\windows\system32\drivers\usbcir.sys
2013-11-05 10:28 . 2013-11-05 10:28 785624 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2013-11-05 10:28 . 2013-11-05 10:28 633856 ----a-w- c:\windows\system32\comctl32.dll
2013-11-05 10:28 . 2013-11-05 10:28 530432 ----a-w- c:\windows\SysWow64\comctl32.dll
2013-11-05 10:28 . 2013-11-05 10:28 76800 ----a-w- c:\windows\system32\drivers\hidclass.sys
2013-11-05 10:28 . 2013-11-05 10:28 42496 ----a-w- c:\windows\system32\drivers\usbscan.sys
2013-11-05 10:28 . 2013-11-05 10:28 32896 ----a-w- c:\windows\system32\drivers\hidparse.sys
2013-11-05 10:27 . 2013-11-05 10:27 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
2013-11-05 10:27 . 2013-11-05 10:27 46080 ----a-w- c:\windows\system32\atmlib.dll
2013-11-05 10:27 . 2013-11-05 10:27 41472 ----a-w- c:\windows\system32\lpk.dll
2013-11-05 10:27 . 2013-11-05 10:27 368128 ----a-w- c:\windows\system32\atmfd.dll
2013-11-05 10:27 . 2013-11-05 10:27 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2013-11-05 10:27 . 2013-11-05 10:27 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2013-11-05 10:27 . 2013-11-05 10:27 25600 ----a-w- c:\windows\SysWow64\lpk.dll
2013-11-05 10:27 . 2013-11-05 10:27 14336 ----a-w- c:\windows\system32\dciman32.dll
2013-11-05 10:27 . 2013-11-05 10:27 10240 ----a-w- c:\windows\SysWow64\dciman32.dll
2013-11-05 10:27 . 2013-11-05 10:27 100864 ----a-w- c:\windows\system32\fontsub.dll
2013-11-05 10:26 . 2013-11-05 10:26 983488 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-11-05 10:19 . 2013-11-05 10:19 124112 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-11-05 10:19 . 2013-11-05 10:19 102608 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2013-11-05 10:19 . 2013-11-05 10:19 3155968 ----a-w- c:\windows\system32\win32k.sys
2013-11-05 10:17 . 2013-11-05 10:17 497152 ----a-w- c:\windows\system32\drivers\afd.sys
2013-11-05 10:17 . 2013-11-05 10:17 327168 ----a-w- c:\windows\system32\mswsock.dll
2013-11-05 10:17 . 2013-11-05 10:17 231424 ----a-w- c:\windows\SysWow64\mswsock.dll
2013-11-05 10:17 . 2013-11-05 10:17 1903552 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-11-05 10:09 . 2013-11-05 16:56 -------- d-----w- c:\programdata\ProductData
2013-11-05 10:09 . 2013-11-05 10:09 -------- d-----w- c:\programdata\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2013-10-30 22:31 . 2012-02-14 11:49 114176 ----a-w- c:\windows\SysWow64\PCWizard.cpl
2013-10-17 09:01 . 2013-10-17 09:01 -------- d-----w- c:\programdata\Oracle
2013-10-17 09:01 . 2013-10-17 09:01 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-10-17 09:01 . 2013-10-17 09:01 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-10-17 09:01 . 2013-10-17 09:01 -------- d-----w- c:\program files (x86)\Java
2013-10-13 10:18 . 2013-10-13 10:18 -------- d-----w- C:\SymCache
2013-10-12 17:28 . 2013-10-12 17:28 -------- d-----w- c:\program files (x86)\Windows Kits
2013-10-12 17:25 . 2013-10-12 17:28 -------- d-----w- c:\programdata\Package Cache
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-05 10:34 . 2013-11-05 10:34 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-10-11 08:19 . 2012-04-19 07:30 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-10-11 08:19 . 2011-11-06 20:52 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-16 22:35 . 2012-07-17 12:37 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-09-14 09:21 . 2013-09-14 09:21 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll
2013-09-14 09:21 . 2013-09-14 09:21 6656 ----a-w- c:\windows\system32\apisetschema.dll
2013-09-14 09:21 . 2013-09-14 09:21 6144 ---ha-w- c:\windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 5120 ---ha-w- c:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 43520 ----a-w- c:\windows\system32\csrsrv.dll
2013-09-14 09:21 . 2013-09-14 09:21 424448 ----a-w- c:\windows\system32\KernelBase.dll
2013-09-14 09:21 . 2013-09-14 09:21 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3584 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3584 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 338432 ----a-w- c:\windows\system32\conhost.exe
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-14 09:21 . 2013-09-14 09:21 274944 ----a-w- c:\windows\SysWow64\KernelBase.dll
2013-09-14 09:21 . 2013-09-14 09:21 215040 ----a-w- c:\windows\system32\winsrv.dll
2013-09-14 09:21 . 2013-09-14 09:21 1161216 ----a-w- c:\windows\system32\kernel32.dll
2013-09-14 09:21 . 2013-09-14 09:21 112640 ----a-w- c:\windows\system32\smss.exe
2013-09-14 09:19 . 2013-09-14 09:19 197120 ----a-w- c:\windows\system32\shdocvw.dll
2013-09-14 09:19 . 2013-09-14 09:19 14172672 ----a-w- c:\windows\system32\shell32.dll
2013-09-14 09:18 . 2013-09-14 09:18 155584 ----a-w- c:\windows\system32\drivers\ataport.sys
2013-09-08 16:52 . 2013-09-08 16:52 30720 ----a-w- c:\windows\system32\cryptdlg.dll
2013-09-08 16:52 . 2013-09-08 16:52 24576 ----a-w- c:\windows\SysWow64\cryptdlg.dll
2013-09-08 16:52 . 2013-09-08 16:52 1887232 ----a-w- c:\windows\system32\d3d11.dll
2013-09-08 16:52 . 2013-09-08 16:52 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2013-09-08 16:51 . 2013-09-08 16:51 48640 ----a-w- c:\windows\system32\wwanprotdim.dll
2013-09-08 16:51 . 2013-09-08 16:51 230400 ----a-w- c:\windows\system32\wwansvc.dll
2013-09-08 16:51 . 2013-09-08 16:51 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-09-08 16:51 . 2013-09-08 16:51 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-09-08 16:51 . 2013-09-08 16:51 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-09-08 16:51 . 2013-09-08 16:51 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-09-08 16:51 . 2013-09-08 16:51 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-09-08 16:51 . 2013-09-08 16:51 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-09-08 16:51 . 2013-09-08 16:51 223752 ----a-w- c:\windows\system32\drivers\fvevol.sys
2013-09-08 16:50 . 2013-09-08 16:50 561664 ----a-w- c:\windows\apppatch\AcLayers.dll
2013-09-08 16:50 . 2013-09-08 16:50 362496 ----a-w- c:\windows\system32\wow64win.dll
2013-09-08 16:50 . 2013-09-08 16:50 16384 ----a-w- c:\windows\system32\ntvdm64.dll
2013-09-08 16:50 . 2013-09-08 16:50 13312 ----a-w- c:\windows\system32\wow64cpu.dll
2013-09-08 16:48 . 2013-09-08 16:48 800768 ----a-w- c:\windows\system32\usp10.dll
2013-09-08 16:48 . 2013-09-08 16:48 626688 ----a-w- c:\windows\SysWow64\usp10.dll
2013-09-08 16:48 . 2013-09-08 16:48 55296 ----a-w- c:\windows\system32\cero.rs
2013-09-08 16:48 . 2013-09-08 16:48 51712 ----a-w- c:\windows\system32\esrb.rs
2013-09-08 16:48 . 2013-09-08 16:48 46592 ----a-w- c:\windows\system32\fpb.rs
2013-09-08 16:48 . 2013-09-08 16:48 45568 ----a-w- c:\windows\SysWow64\oflc-nz.rs
2013-09-08 16:48 . 2013-09-08 16:48 45568 ----a-w- c:\windows\system32\oflc-nz.rs
2013-09-08 16:48 . 2013-09-08 16:48 44544 ----a-w- c:\windows\SysWow64\pegibbfc.rs
2013-09-08 16:48 . 2013-09-08 16:48 44544 ----a-w- c:\windows\system32\pegibbfc.rs
2013-09-08 16:48 . 2013-09-08 16:48 43520 ----a-w- c:\windows\SysWow64\csrr.rs
2013-09-08 16:48 . 2013-09-08 16:48 43520 ----a-w- c:\windows\system32\csrr.rs
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-8-17 1080096]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe /firstrun [2009-6-30 1316192]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 SkypeUpdate;Skype Updater;d:\programme\Updater\Updater.exe;d:\programme\Updater\Updater.exe [x]
R3 BDA_Capture_225;USB Digital-TV receiver. Driver 3.0.1.18;c:\windows\system32\Drivers\BDA_Capture_225_x64.sys;c:\windows\SYSNATIVE\Drivers\BDA_Capture_225_x64.sys [x]
R3 BDA_Loader_225;USB Digital-TV Receiver. Firmware Loader 7.1.9.0;c:\windows\system32\Drivers\BDA_Loader_225_x64.sys;c:\windows\SYSNATIVE\Drivers\BDA_Loader_225_x64.sys [x]
R3 cpuz136;cpuz136;d:\program files (x86)\CPUID\PC Wizard 2013\pcwiz_x64.sys;d:\program files (x86)\CPUID\PC Wizard 2013\pcwiz_x64.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 PCDSRVC{D3412D80-CF3B4A27-06020200}_0;PCDSRVC{D3412D80-CF3B4A27-06020200}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\my dell\pcdsrvc_x64.pkms;c:\program files\my dell\pcdsrvc_x64.pkms [x]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys;c:\windows\SYSNATIVE\pwdrvio.sys [x]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys;c:\windows\SYSNATIVE\pwdspio.sys [x]
R3 qcusbser;Mobile Connector USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\qcusbser.sys;c:\windows\SYSNATIVE\DRIVERS\qcusbser.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys;c:\windows\SYSNATIVE\DRIVERS\Rts516xIR.sys [x]
R3 SAllBDA;TeVii DVB-S/S2 Receiver;c:\windows\system32\Drivers\TeViiS2.sys;c:\windows\SYSNATIVE\Drivers\TeViiS2.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 gzflt;gzflt;c:\windows\system32\DRIVERS\gzflt.sys;c:\windows\SYSNATIVE\DRIVERS\gzflt.sys [x]
S2 AdvancedSystemCareService7;Advanced SystemCare Service 7;c:\program files (x86)\IObit\Advanced SystemCare 7\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
S2 DeviceManager;DeviceManager;c:\program files (x86)\Common Files\DeviceHelper\DeviceManager.exe;c:\program files (x86)\Common Files\DeviceHelper\DeviceManager.exe [x]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe;c:\program files\Dell\DellDock\DockLogin.exe [x]
S2 gzserv;Bitdefender Antivirus Free Edition;c:\program files\Bitdefender\Antivirus Free Edition\gzserv.exe;c:\program files\Bitdefender\Antivirus Free Edition\gzserv.exe [x]
S2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys;c:\windows\SYSNATIVE\Drivers\SSPORT.sys [x]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 azvusb;Virtual USB Hub;c:\windows\system32\DRIVERS\azvusb.sys;c:\windows\SYSNATIVE\DRIVERS\azvusb.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys;c:\windows\SYSNATIVE\DRIVERS\CtClsFlt.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
2013-11-05 10:09 2486592 ----a-w- c:\program files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2009-09-16 357376]
"Broadcom Wireless Manager UI"="c:\program files\dell\dell wireless wlan card\wltray.exe" [2009-07-17 4968960]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.freenet.de/
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com
IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Nach Microsoft &Excel exportieren - d:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\myNotebook\AppData\Roaming\Mozilla\Firefox\Profiles\igko3hht.Standard-Benutzer\
FF - prefs.js: browser.search.selectedEngine - Startpage HTTPS - Deutsch
FF - prefs.js: browser.startup.homepage - hxxp://es.search.yahoo.com/?type=198484&fr=spigot-yhp-ff
FF - prefs.js: keyword.url - hxxp://es.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=198484&p=
FF - ExtSQL: 2013-11-06 16:51; firefox@ghostery.com; c:\users\myNotebook\AppData\Roaming\Mozilla\Firefox\Profiles\igko3hht.Standard-Benutzer\extensions\firefox@ghostery.com.xpi
FF - ExtSQL: 2013-11-06 16:52; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\myNotebook\AppData\Roaming\Mozilla\Firefox\Profiles\igko3hht.Standard-Benutzer\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-11-06 16:56; {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}; c:\users\myNotebook\AppData\Roaming\Mozilla\Firefox\Profiles\igko3hht.Standard-Benutzer\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
FF - ExtSQL: 2013-11-06 16:56; {0b457cAA-602d-484a-8fe7-c1d894a011ba}; c:\users\myNotebook\AppData\Roaming\Mozilla\Firefox\Profiles\igko3hht.Standard-Benutzer\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
SafeBoot-SolutoService
HKLM_Wow6432Node-ActiveSetup-{71504FB8-F84D-4B63-A97F-D6D5F0F0F410} - msiexec
Toolbar-Locked - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\PCDSRVC{D3412D80-CF3B4A27-06020200}_0]
"ImagePath"="\??\c:\program files\my dell\pcdsrvc_x64.pkms"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d4,66,b2,a3,84,d3,1b,46,8b,bc,1e,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d4,66,b2,a3,84,d3,1b,46,8b,bc,1e,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000001
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
d:\program files (x86)\Cisco Systems\VPN Client\cvpnd.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-11-07 18:01:15 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2013-11-07 17:01
.
Vor Suchlauf: 13 Verzeichnis(se), 29.020.200.960 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 28.650.520.576 Bytes frei
.
- - End Of File - - 932660CC0F65221C176EDA844EF48E45
A36C5E4F47E84449FF07ED3517B43A31 Daaaannke!
ingolfomas |