Code:
ComboFix 13-12-01.01 - Stinkerseitz 02.12.2013 17:09:50.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4095.2751 [GMT 1:00]
ausgeführt von:: c:\users\Stinkerseitz\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\tmp93B8.tmp
c:\windows\SysWow64\tmp93B9.tmp
c:\windows\SysWow64\tmpC600.tmp
c:\windows\SysWow64\tmpC601.tmp
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-11-02 bis 2013-12-02 ))))))))))))))))))))))))))))))
.
.
2013-12-02 16:20 . 2013-12-02 16:20 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-12-02 16:20 . 2013-12-02 16:20 -------- d-----w- c:\users\UpdatusUser.Stinkerseitz-PC\AppData\Local\temp
2013-12-02 16:20 . 2013-12-02 16:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-02 16:05 . 2012-07-05 20:06 687544 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-12-02 16:05 . 2012-07-05 20:06 772544 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-12-01 18:30 . 2013-12-01 18:29 312744 ----a-w- c:\windows\system32\javaws.exe
2013-12-01 18:30 . 2013-12-01 18:29 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-12-01 18:30 . 2013-12-01 18:29 189352 ----a-w- c:\windows\system32\javaw.exe
2013-12-01 18:30 . 2013-12-01 18:29 189352 ----a-w- c:\windows\system32\java.exe
2013-12-01 18:29 . 2013-12-01 18:29 -------- d-----w- c:\program files\Java
2013-12-01 18:24 . 2013-12-01 18:24 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-12-01 18:23 . 2013-12-01 18:23 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-12-01 18:15 . 2013-12-01 18:30 -------- d-----w- c:\programdata\Oracle
2013-12-01 09:13 . 2013-11-08 03:12 10285968 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E4B0B98B-68C4-43C0-A4D2-C5AB102186E5}\mpengine.dll
2013-12-01 08:52 . 2013-12-01 08:52 -------- d-----w- C:\FRST
2013-12-01 08:43 . 2013-12-01 08:43 -------- d-----w- c:\windows\ERUNT
2013-12-01 08:26 . 2013-11-18 00:28 10285968 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{44A8015D-53AC-4D62-B6B3-220C90368F4F}\mpengine.dll
2013-12-01 02:05 . 2013-10-14 17:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
2013-11-30 20:08 . 2013-11-30 20:08 -------- d-----w- c:\program files (x86)\ESET
2013-11-30 19:53 . 2013-11-30 19:53 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-11-30 19:06 . 2013-11-30 19:06 56616 ----a-w- c:\windows\system32\drivers\mjkxnsgt.sys
2013-11-30 19:05 . 2013-11-30 19:05 56616 ----a-w- c:\windows\system32\drivers\aoybskii.sys
2013-11-30 18:29 . 2013-11-08 03:12 10285968 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-11-30 09:05 . 2013-11-30 09:05 -------- d-----w- c:\users\Stinkerseitz\AppData\Local\DriverTuner
2013-11-30 08:46 . 2013-10-30 11:06 821824 ----a-w- c:\windows\SysWow64\dgderapi.dll
2013-11-29 18:40 . 2013-11-29 18:41 -------- d-----w- c:\program files (x86)\Mozilla Firefox 4.0 Beta 7
2013-11-27 13:47 . 2013-11-27 13:47 -------- d-----w- c:\program files\Lexmark
2013-11-24 18:40 . 2013-11-24 18:40 -------- d-----w- c:\programdata\Licenses
2013-11-24 16:47 . 2013-11-24 16:47 -------- d-----w- c:\users\Stinkerseitz\AppData\Roaming\Simply Super Software
2013-11-24 16:46 . 2013-11-24 16:46 -------- d-----w- c:\programdata\Simply Super Software
2013-11-22 19:12 . 2005-11-13 22:22 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2013-11-22 19:12 . 2005-11-13 22:21 274432 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2013-11-22 19:12 . 2005-11-13 22:20 204800 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2013-11-22 19:12 . 2005-11-13 22:19 65024 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe
2013-11-22 19:12 . 2005-11-13 22:19 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2013-11-22 19:12 . 2013-11-22 19:12 331908 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2013-11-22 19:12 . 2013-11-22 19:12 200836 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2013-11-22 19:12 . 2005-11-13 22:22 757760 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2013-11-21 20:42 . 2013-11-21 20:44 -------- d-----w- c:\users\Stinkerseitz\AppData\Roaming\Red Alert 3
2013-11-21 07:49 . 2013-11-21 08:13 -------- d-----w- c:\users\Stinkerseitz\AppData\Local\Darksiders2
2013-11-19 18:57 . 2013-11-19 18:57 -------- d-----w- c:\users\Stinkerseitz\AppData\Local\NVIDIA Corporation
2013-11-18 14:14 . 2013-11-18 14:14 -------- d-----w- c:\program files (x86)\Team Fortress 2
2013-11-18 09:31 . 2013-11-18 09:31 -------- d-----w- c:\users\Stinkerseitz\AppData\Local\id Software
2013-11-14 12:59 . 2013-11-14 12:59 -------- d-----w- c:\programdata\WinterSoft
2013-11-14 12:59 . 2013-11-14 12:59 -------- d-----w- c:\users\Stinkerseitz\AppData\Local\Packages
2013-11-14 12:59 . 2013-11-14 19:42 -------- d-----w- c:\programdata\fd10bf0bf388fa62
2013-11-14 12:58 . 2013-11-14 12:59 -------- d-----w- c:\programdata\InstallMate
2013-11-09 21:38 . 2013-11-09 21:38 138152 ----a-w- c:\windows\SysWow64\drivers\AnyDVD.sys
2013-11-09 21:38 . 2013-11-09 21:38 138152 ----a-w- c:\windows\system32\drivers\AnyDVD.sys
2013-11-08 20:14 . 2013-11-08 20:14 -------- d-sh--w- c:\programdata\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2013-11-08 20:14 . 2013-11-08 20:14 -------- d--h--w- c:\programdata\Common Files
2013-11-08 20:13 . 2013-11-08 20:13 -------- d-----w- c:\program files (x86)\Common Files\DVDVideoSoft
2013-11-07 17:01 . 2013-11-07 17:01 -------- d-----w- c:\program files (x86)\Mplayer
2013-11-06 09:34 . 2013-10-18 09:40 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D457C527-DAC5-4327-9CF1-4B29B1D33C70}\gapaengine.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-27 10:42 . 2011-05-22 09:19 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-19 02:33 . 2010-02-15 14:29 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-11-13 02:07 . 2010-02-15 14:49 82896128 ----a-w- c:\windows\system32\MRT.exe
2013-11-10 16:03 . 2010-06-03 22:36 281768 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-11-10 16:03 . 2010-04-11 09:24 281768 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-11-10 16:01 . 2010-04-11 09:24 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-11-08 20:47 . 2013-10-31 15:53 1064224 ----a-w- c:\windows\system32\nvspcap64.dll
2013-11-08 20:47 . 2013-10-31 15:53 955168 ----a-w- c:\windows\SysWow64\nvspcap.dll
2013-11-04 18:50 . 2010-04-11 09:24 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-10-30 11:13 . 2011-01-06 13:02 4659712 ----a-w- c:\windows\SysWow64\Redemption.dll
2013-10-30 11:07 . 2013-10-30 11:07 90112 ----a-w- c:\windows\MAMCityDownload.ocx
2013-10-30 11:07 . 2013-10-30 11:07 330240 ----a-w- c:\windows\MASetupCaller.dll
2013-10-30 11:07 . 2013-10-30 11:07 30568 ----a-w- c:\windows\MusiccityDownload.exe
2013-10-23 18:13 . 2013-10-23 18:13 21504 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Offline Scanner\FilesList32.dll
2013-10-23 10:30 . 2013-10-31 15:50 9524088 ----a-w- c:\windows\SysWow64\nvcuda.dll
2013-10-23 10:30 . 2013-10-31 15:50 9480328 ----a-w- c:\windows\SysWow64\nvopencl.dll
2013-10-23 10:30 . 2013-10-31 15:50 696096 ----a-w- c:\windows\system32\NvFBC64.dll
2013-10-23 10:30 . 2013-10-31 15:50 655136 ----a-w- c:\windows\system32\NvIFR64.dll
2013-10-23 10:30 . 2013-10-31 15:50 599840 ----a-w- c:\windows\SysWow64\NvFBC.dll
2013-10-23 10:30 . 2013-10-31 15:50 560416 ----a-w- c:\windows\SysWow64\NvIFR.dll
2013-10-23 10:30 . 2013-10-31 15:50 3131680 ----a-w- c:\windows\system32\nvcuvid.dll
2013-10-23 10:30 . 2013-10-31 15:50 3124512 ----a-w- c:\windows\system32\nvcuvenc.dll
2013-10-23 10:30 . 2013-10-31 15:50 2946848 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2013-10-23 10:30 . 2013-10-31 15:50 2747168 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2013-10-23 10:30 . 2013-10-31 15:50 22933792 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2013-10-23 10:30 . 2013-10-31 15:50 1884448 ----a-w- c:\windows\system32\nvdispco6433165.dll
2013-10-23 10:30 . 2013-10-31 15:50 18199872 ----a-w- c:\windows\system32\nvd3dumx.dll
2013-10-23 10:30 . 2013-10-31 15:50 1511712 ----a-w- c:\windows\system32\nvdispgenco6433165.dll
2013-10-23 10:30 . 2013-10-31 15:50 12572960 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2013-10-23 10:30 . 2013-10-31 15:50 11426568 ----a-w- c:\windows\system32\nvcuda.dll
2013-10-23 10:30 . 2013-10-31 15:50 11374520 ----a-w- c:\windows\system32\nvopencl.dll
2013-10-23 10:30 . 2013-10-31 15:50 25257248 ----a-w- c:\windows\system32\nvcompiler.dll
2013-10-23 10:30 . 2013-10-31 15:50 17560352 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2013-10-23 10:30 . 2013-09-29 12:29 15212336 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-10-23 10:30 . 2012-10-10 20:23 15855568 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2013-10-23 10:30 . 2012-10-10 20:22 2695200 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-10-23 10:30 . 2011-10-30 18:04 30344480 ----a-w- c:\windows\system32\nvoglv64.dll
2013-10-23 10:30 . 2010-01-12 11:03 3067560 ----a-w- c:\windows\system32\nvapi64.dll
2013-10-23 10:30 . 2009-07-13 21:59 18286416 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-10-23 08:20 . 2011-04-07 21:19 6669600 ----a-w- c:\windows\system32\nvcpl.dll
2013-10-23 08:20 . 2011-04-07 21:18 3489568 ----a-w- c:\windows\system32\nvsvc64.dll
2013-10-23 08:20 . 2011-04-07 21:19 922912 ----a-w- c:\windows\system32\nvvsvc.exe
2013-10-23 08:20 . 2011-04-07 21:19 2559776 ----a-w- c:\windows\system32\nvsvcr.dll
2013-10-23 08:20 . 2011-04-07 21:19 219424 ----a-w- c:\windows\system32\nvmctray.dll
2013-10-23 08:20 . 2010-01-11 22:19 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-10-23 02:02 . 2013-10-23 02:02 589600 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2013-10-18 09:40 . 2011-03-25 18:09 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-10-16 00:48 . 2013-10-23 08:48 1884448 ----a-w- c:\windows\system32\nvdispco6433158.dll
2013-10-16 00:48 . 2013-10-23 08:48 1511712 ----a-w- c:\windows\system32\nvdispgenco6433158.dll
2013-09-30 23:38 . 2013-09-30 23:38 97176 ----a-w- c:\windows\SysWow64\ElbyCDIO.dll
2013-09-27 23:01 . 2013-10-31 15:50 39200 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2013-09-27 23:01 . 2013-10-31 15:50 28960 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2013-09-27 23:01 . 2013-09-29 12:30 29984 ----a-w- c:\windows\system32\nvaudcap64v.dll
2013-09-27 08:53 . 2013-09-27 08:53 248240 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2013-09-27 08:53 . 2010-10-24 20:25 134944 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2013-09-19 13:09 . 2009-08-18 11:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2013-09-19 13:09 . 2009-08-18 10:24 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-09-19 13:07 . 2010-10-01 17:52 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2013-09-19 13:07 . 2010-10-01 17:52 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2013-09-12 08:58 . 2013-09-29 12:29 1884448 ----a-w- c:\windows\system32\nvdispco6432723.dll
2013-09-12 08:58 . 2013-09-29 12:29 1511712 ----a-w- c:\windows\system32\nvdispgenco6432723.dll
2013-09-08 02:30 . 2013-10-08 20:57 1903552 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-09-08 02:27 . 2013-10-08 20:57 327168 ----a-w- c:\windows\system32\mswsock.dll
2013-09-08 02:03 . 2013-10-08 20:57 231424 ----a-w- c:\windows\SysWow64\mswsock.dll
2013-09-04 12:12 . 2013-10-08 20:57 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-09-04 12:11 . 2013-10-08 20:57 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-09-04 12:11 . 2013-10-08 20:57 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-09-04 12:11 . 2013-10-08 20:57 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-09-04 12:11 . 2013-10-08 20:57 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-09-04 12:11 . 2013-10-08 20:57 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-09-04 12:11 . 2013-10-08 20:57 7808 ----a-w- c:\windows\system32\drivers\usbd.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"KiesPreload"="c:\progs\Kies\Kies.exe" [2013-11-06 1564528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"TrojanScanner"="c:\program files (x86)\Progs\Trojan Remover\Trjscan.exe" [2013-11-11 1658640]
"KiesTrayAgent"="c:\progs\Kies\KiesTrayAgent.exe" [2013-11-06 311152]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-09-05 958576]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-2-15 1207312]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableSecureUIAPath"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R1 nyvlvnpy;nyvlvnpy;c:\windows\system32\drivers\nyvlvnpy.sys;c:\windows\SYSNATIVE\drivers\nyvlvnpy.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R2 SetupARService;SetupARService;c:\program files (x86)\Realtek\Audio\SetupAfterRebootService.exe;c:\program files (x86)\Realtek\Audio\SetupAfterRebootService.exe [x]
R3 cpuz130;cpuz130;c:\users\STINKE~1\AppData\Local\Temp\cpuz130\cpuz_x64.sys;c:\users\STINKE~1\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys;c:\windows\SYSNATIVE\drivers\dgderdrv.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 phaudlwr;Philips Audio Filter;c:\windows\system32\DRIVERS\phaudlwr.sys;c:\windows\SYSNATIVE\DRIVERS\phaudlwr.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SPC530;Philips SPC530NC PC Camera;c:\windows\system32\drivers\SPC530.sys;c:\windows\SYSNATIVE\drivers\SPC530.sys [x]
R3 SPC530m;Philips SPC530NC PC Cameram;c:\windows\system32\drivers\SPC530m.sys;c:\windows\SYSNATIVE\drivers\SPC530m.sys [x]
R3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\DRIVERS\sscebus.sys;c:\windows\SYSNATIVE\DRIVERS\sscebus.sys [x]
R3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\DRIVERS\sscemdfl.sys;c:\windows\SYSNATIVE\DRIVERS\sscemdfl.sys [x]
R3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\DRIVERS\sscemdm.sys;c:\windows\SYSNATIVE\DRIVERS\sscemdm.sys [x]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys;c:\windows\SYSNATIVE\Drivers\TFsExDisk.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R4 sptd;sptd; [x]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys;c:\windows\SYSNATIVE\DRIVERS\Lbd.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 OODefragAgent;O&O Defrag;c:\program files\Progs\OO Software\Defrag\oodag.exe;c:\program files\Progs\OO Software\Defrag\oodag.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2013-12-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-22 10:42]
.
2013-12-01 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-536369218-3522263162-1686712380-1001Core.job
- c:\users\Stinkerseitz\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-14 17:44]
.
2013-12-02 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-536369218-3522263162-1686712380-1001UA.job
- c:\users\Stinkerseitz\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-14 17:44]
.
2013-12-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 18:47]
.
2013-12-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 18:47]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 130576]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-09-29 110360]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-11-08 1028384]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2013-11-08 1064224]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
mSearchAssistant = hxxp://www.google.com
IE: An OneNote s&enden - c:\progra~2\MIF5BA~1\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MIF5BA~1\Office14\EXCEL.EXE/3000
IE: ????3?? - c:\users\Stinkerseitz\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: ????3?????? - c:\users\Stinkerseitz\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Stinkerseitz\AppData\Roaming\Mozilla\Firefox\Profiles\v3ohwoyh.default-1373988548901\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{5B2D16F2-C56C-3DDB-0AD0-279E6CCF922E} - c:\program files (x86)\YoutubeAdblocker\nCH.dll
Toolbar-10 - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-MSC - c:\program files\Microsoft Security Client\mssecex.exe
AddRemove-Battlelog Web Plugins - c:\program files (x86)\Battlelog Web Plugins\uninstall.exe
AddRemove-CodInstl - c:\windows\system32\CDUninst.isu
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-VIS - c:\users\Stinkerseitz\AppData\Roaming\Windows Net Data\uninstaller.exe
AddRemove-{4820778D-AB0D-6D18-C316-52A6A0E1D507} - c:\programdata\YoutubeAdblocker\k0_z.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-536369218-3522263162-1686712380-1001\Software\Microsoft\Internet Explorer\MenuExt\O(uë_f3*N}]
@="c:\\Users\\Stinkerseitz\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm"
"contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-536369218-3522263162-1686712380-1001\Software\Microsoft\Internet Explorer\MenuExt\O(uë_f3*N}hQèþ”¥c]
@="c:\\Users\\Stinkerseitz\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm"
"contexts"=dword:000000f3
.
[HKEY_USERS\S-1-5-21-536369218-3522263162-1686712380-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ee,0e,d3,bd,da,05,3d,cd,0c,70,3c,f9,d0,77,fa,54,e7,4a,04,76,cc,ab,4b,
c6,01,bc,9a,34,27,41,78,de,0b,24,de,72,d3,c4,a0,69,d5,a5,de,5f,68,8c,54,66,\
"??"=hex:67,1e,55,4c,83,b7,05,0d,0e,f0,0d,1c,af,e4,ed,85
.
[HKEY_USERS\S-1-5-21-536369218-3522263162-1686712380-1001\Software\SecuROM\License information*]
"datasecu"=hex:02,88,d1,b2,97,93,a9,3f,a1,2d,a2,96,36,75,ba,5c,7e,91,6a,66,85,
ed,09,22,08,bd,52,29,7f,00,42,9e,01,27,b7,60,ac,0a,41,59,c8,e8,ee,b2,ca,ed,\
"rkeysecu"=hex:11,00,db,c8,39,2a,ba,51,66,84,48,18,03,22,54,7d
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG14.00.00.01PROFESSIONAL"="AB9ED146F7D44953282487292A6EAE51D29B07AB1B3BAF287DBE886927281846756D9EFEF3C98A9CC9C8FA42CC5712FC338BBC490AF834D37BC8D5478064A21C01EC7BB0104970B73F8FABB4B30BDF10F41DBA08AED0BC024D477C793A61C3A19D4CF1DF57CEA1CBB8888A4D99F17902C95C7B18953A8221C364A0B7D3442FDBDEF46CE95ACD6B102AF6ECA93EECE4E2268B5C7DD01EE4B675FAC7894E23BCE31C7FBCFA2CA840D2CB538C40684BFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B98088EDD5E5BE2F6E6679DB7CE019D40AA5CC038D530D6EB345240E89F84AC9E7DA7FDC280B073496D4228915942B44FFB43691B9B92CD5D4DBC97A78433C6B39FF8B293657D15592877722D06FEEC28F4B558E691A824A4E4D0635994542427AF6DC2120F99EFD0FAF625B00D723057002B135F5B2FDD1FC176D50EBFBB6D1FD8A1F581CDB4131B42CAC33740C71A2FCA3972946B6F40A204F041E9396FAE964AA4B9BC36317579DEF1F36D3560275287EB762979E671D8CB781F2577AA58DB38FD9EAF9FA7F07EB5DD7D18C3513B3BEC4241D47EC67D3F43B98A8B355B3F93DA2559DD27634113AEF3510B89E11B35B2AD1A61387553A7125442FDF2239B326C8843D9ACE38972B58F0032E88EF2631818EBB02A0CC7B8E65BAC70F35989042D07D8CE545CCE2BBE7CBF0B05894F385DD9C5B319D88F6B76D7CFEBBD090A26E0F83B7906B479A23A00E927C7B5A47E49C35A71105CC78E7646588B1DEF028D4FA3AFAB6D88D690244D7CAE5E2C48D0A51881085D4C6FC1A09595012001B7FEC3C61EC9FBA69900F710195A3B3A74A03F8D34A41291EA7D342B7B8F9AE259188E12954DE413D6513565867991DDC7B3E6CF128A84CB008975DDA38FA36F774483AA4443A08587B7E1DF2E6D5B4FC42374FDDF11D04ADB8428F9476D16B6844878AA81CDEA6909BB86851EADD5F3D159C02A81A452138B5F993FC72991F8DBB94A1EC3A1C4DE1DB8AFCF09C202E93919A8DC84C3ADE005E19662A858782EB705D8852A88F1B7E9DDEC2E43CC258129F60F8F9680479F9E23720B13217180B86708D7745E7AFDF62F5500C7FC493E355AD83289054972931304D4D0C1E94FE3F3BE7C0795AA6AB2857F1EB39939DA5282EFA75689A22D02722651D3898F2CA1926950EBB392EEED8B08D1C97D08C1DAFDC047175F055BEFD736032EDCD4DD3EFC76A450D106ADDFC11157EE168A140FB2BEDA8AE86838432C98E119B372DD69C15ABF831D9DFD9F7BBDE22EE6D9270FD85F22931D04B7C72DB25B709A63DC38458C59FBD6356CAC60B8193505D282E2FD1B51390957FDACECEF4E3332653C233C891FD1D36E38676DAB95551B97E2F482F00EA6C925E386513E8E05AE"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-12-02 17:30:50
ComboFix-quarantined-files.txt 2013-12-02 16:30
.
Vor Suchlauf: 22 Verzeichnis(se), 396.502.413.312 Bytes frei
Nach Suchlauf: 23 Verzeichnis(se), 396.135.628.800 Bytes frei
.
- - End Of File - - 3EE560CC533DB46A9FF5F95B10B6597A
5C616939100B85E558DA92B899A0FC36 |