hallo, hier die logfile Code:
ComboFix 13-12-04.02 - Waldi 04.12.2013 18:05:38.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.16303.14361 [GMT 8:00]
ausgeführt von:: c:\users\Waldi\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Waldi\AppData\Local\assembly\tmp
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-11-04 bis 2013-12-04 ))))))))))))))))))))))))))))))
.
.
2013-12-04 10:07 . 2013-12-04 10:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-04 01:08 . 2013-11-17 17:28 10285968 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{737FFFDE-B4BD-4448-86F2-7DCE377B9498}\mpengine.dll
2013-12-03 10:32 . 2013-12-03 10:32 -------- d-----w- C:\FRST
2013-12-03 08:56 . 2013-12-03 08:59 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2013-12-03 08:46 . 2013-12-03 08:46 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2013-12-03 07:20 . 2013-12-03 07:20 -------- d-----w- c:\program files\Enigma Software Group
2013-12-03 07:20 . 2013-12-03 09:29 -------- d-----w- c:\windows\72AAF4551E54475BB0AB5413C78D0E63.TMP
2013-12-03 07:20 . 2013-12-03 07:20 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2013-12-03 03:36 . 2013-12-03 04:30 -------- d-----w- c:\programdata\mryu
2013-12-03 03:36 . 2013-12-03 03:36 -------- d-----w- c:\programdata\tkipd
2013-12-03 03:36 . 2013-12-03 03:36 -------- d-----w- c:\programdata\tbrjps
2013-12-01 04:05 . 2013-12-01 04:05 -------- d-----w- c:\programdata\Malwarebytes
2013-12-01 04:05 . 2013-12-01 04:05 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-12-01 04:05 . 2013-04-04 06:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-12-01 02:54 . 2013-12-04 00:11 -------- d-----w- c:\programdata\mdh
2013-12-01 02:37 . 2013-12-03 23:40 -------- d-----w- c:\programdata\kjqvm
2013-12-01 02:37 . 2013-12-03 23:04 -------- d-----w- c:\programdata\upcr
2013-12-01 02:37 . 2013-12-01 02:37 -------- d-----w- c:\programdata\fkmfb
2013-11-29 04:53 . 2013-12-01 04:16 -------- d-----w- c:\programdata\tvidqe
2013-11-29 04:26 . 2013-12-01 04:16 -------- d-----w- c:\programdata\udoec
2013-11-29 04:26 . 2013-12-01 03:24 -------- d-----w- c:\programdata\rwxuvcn
2013-11-29 04:26 . 2013-11-29 04:26 -------- d-----w- c:\programdata\jsxck
2013-11-27 02:42 . 2013-11-30 05:28 -------- d-----w- c:\programdata\qswcb
2013-11-27 02:05 . 2013-11-30 05:28 -------- d-----w- c:\programdata\pgt
2013-11-27 02:05 . 2013-11-30 05:25 -------- d-----w- c:\programdata\xcf
2013-11-27 02:05 . 2013-11-27 02:05 -------- d-----w- c:\programdata\gpe
2013-11-26 06:22 . 2013-11-27 03:17 -------- d-----w- c:\programdata\oimr
2013-11-26 05:05 . 2013-11-27 02:42 -------- d-----w- c:\programdata\unmf
2013-11-26 05:05 . 2013-11-27 02:05 -------- d-----w- c:\programdata\wiltobo
2013-11-26 05:05 . 2013-11-26 05:05 -------- d-----w- c:\programdata\vlyvk
2013-11-25 02:46 . 2013-12-03 22:56 -------- d-----w- c:\programdata\qmbhac
2013-11-25 02:46 . 2013-11-27 03:17 -------- d-----w- c:\programdata\ifkeojg
2013-11-25 02:46 . 2013-11-27 03:17 -------- d-----w- c:\programdata\fmqb
2013-11-25 02:46 . 2013-11-27 02:03 -------- d-----w- c:\programdata\dkarde
2013-11-25 02:46 . 2013-11-25 02:46 -------- d-----w- c:\programdata\tyak
2013-11-25 02:40 . 2013-12-03 23:04 -------- d-----w- c:\programdata\dcdp
2013-11-22 05:43 . 2013-11-22 05:43 -------- d-----w- c:\windows\SysWow64\Wat
2013-11-22 05:43 . 2013-11-22 05:43 -------- d-----w- c:\windows\system32\Wat
2013-11-20 12:01 . 2013-11-20 12:01 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2013-11-20 10:48 . 2013-11-20 10:48 53248 ----a-w- c:\windows\ipuninst.exe
2013-11-20 10:44 . 2013-11-20 10:44 -------- d-----w- c:\program files\BlackIsle
2013-11-20 09:49 . 2013-11-20 09:49 -------- d-sh--w- c:\programdata\SecuROM
2013-11-20 09:48 . 2013-11-20 09:48 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2013-11-20 09:48 . 2013-11-20 09:48 -------- d-----w- c:\windows\SysWow64\xlive
2013-11-19 20:35 . 2013-11-19 20:35 -------- d-----w- c:\program files\WinRAR
2013-11-19 17:48 . 2013-09-04 12:12 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-11-19 17:48 . 2013-09-04 12:11 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-11-19 17:48 . 2013-09-04 12:11 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-11-19 17:48 . 2013-09-04 12:11 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-11-19 17:48 . 2013-09-04 12:11 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-11-19 17:48 . 2013-09-04 12:11 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-11-19 17:48 . 2013-09-04 12:11 7808 ----a-w- c:\windows\system32\drivers\usbd.sys
2013-11-16 21:45 . 2013-11-28 01:36 -------- d-----w- c:\program files (x86)\Common Files\Steam
2013-11-16 20:51 . 2013-04-26 09:24 41984 ----a-w- c:\windows\system32\drivers\USB3Ver.dll
2013-11-16 13:17 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2013-11-16 13:00 . 2013-12-03 09:27 -------- d-----w- c:\program files (x86)\JDownloader
2013-11-16 13:00 . 2013-11-16 13:00 -------- d-----w- c:\programdata\VisualBee
2013-11-15 17:58 . 2011-04-28 03:54 80384 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2013-11-14 21:42 . 2013-11-14 21:42 -------- d-----w- c:\windows\SysWow64\wbem\en-US
2013-11-14 21:42 . 2013-11-14 21:42 -------- d-----w- c:\windows\system32\wbem\en-US
2013-11-14 20:44 . 2012-07-26 07:46 2560 ----a-w- c:\windows\system32\drivers\de-DE\wdf01000.sys.mui
2013-11-14 20:32 . 2012-08-23 14:13 243200 ----a-w- c:\windows\system32\rdpudd.dll
2013-11-14 20:32 . 2012-08-23 14:10 19456 ----a-w- c:\windows\system32\drivers\rdpvideominiport.sys
2013-11-14 20:32 . 2012-08-23 14:08 30208 ----a-w- c:\windows\system32\drivers\TsUsbGD.sys
2013-11-14 20:32 . 2012-08-23 13:24 15360 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2013-11-14 20:32 . 2012-08-23 11:12 192000 ----a-w- c:\windows\SysWow64\rdpendp_winip.dll
2013-11-14 20:32 . 2012-08-23 10:51 228864 ----a-w- c:\windows\system32\rdpendp_winip.dll
2013-11-14 20:32 . 2012-08-23 09:51 3174912 ----a-w- c:\windows\system32\rdpcorets.dll
2013-11-14 20:21 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2013-11-14 19:33 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2013-11-14 19:33 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2013-11-14 19:33 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2013-11-14 19:33 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2013-11-14 19:33 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2013-11-14 19:33 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2013-11-14 19:33 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2013-11-14 19:27 . 2013-11-14 19:27 -------- d-----w- c:\windows\system32\MRT
2013-11-14 19:10 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2013-11-14 19:10 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2013-11-14 19:10 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2013-11-14 19:10 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2013-11-14 19:10 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2013-11-14 16:38 . 2013-02-27 06:02 111448 ----a-w- c:\windows\system32\consent.exe
2013-11-14 16:38 . 2013-02-27 05:47 70144 ----a-w- c:\windows\system32\appinfo.dll
2013-11-14 16:32 . 2013-10-04 02:24 1930752 ----a-w- c:\windows\system32\authui.dll
2013-11-14 16:32 . 2013-10-04 02:28 190464 ----a-w- c:\windows\system32\SmartcardCredentialProvider.dll
2013-11-14 16:32 . 2013-10-04 02:25 197120 ----a-w- c:\windows\system32\credui.dll
2013-11-14 16:32 . 2013-10-04 01:58 152576 ----a-w- c:\windows\SysWow64\SmartcardCredentialProvider.dll
2013-11-14 16:32 . 2013-10-04 01:56 168960 ----a-w- c:\windows\SysWow64\credui.dll
2013-11-14 16:32 . 2013-10-04 01:56 1796096 ----a-w- c:\windows\SysWow64\authui.dll
2013-11-14 16:30 . 2013-09-25 02:23 1030144 ----a-w- c:\windows\system32\TSWorkspace.dll
2013-11-14 16:30 . 2013-09-25 01:57 792576 ----a-w- c:\windows\SysWow64\TSWorkspace.dll
2013-11-14 16:30 . 2012-11-30 05:45 362496 ----a-w- c:\windows\system32\wow64win.dll
2013-11-14 16:30 . 2012-11-30 05:45 13312 ----a-w- c:\windows\system32\wow64cpu.dll
2013-11-14 16:30 . 2012-11-30 05:43 16384 ----a-w- c:\windows\system32\ntvdm64.dll
2013-11-14 16:25 . 2013-04-25 23:30 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2013-11-14 16:23 . 2012-08-21 21:01 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
2013-11-14 16:20 . 2013-05-13 03:43 1192448 ----a-w- c:\windows\system32\certutil.exe
2013-11-14 16:20 . 2013-05-13 05:50 52224 ----a-w- c:\windows\system32\certenc.dll
2013-11-14 16:20 . 2013-05-13 03:08 903168 ----a-w- c:\windows\SysWow64\certutil.exe
2013-11-14 16:20 . 2013-05-13 03:08 43008 ----a-w- c:\windows\SysWow64\certenc.dll
2013-11-14 16:20 . 2013-07-09 05:52 224256 ----a-w- c:\windows\system32\wintrust.dll
2013-11-14 16:20 . 2013-07-09 04:52 175104 ----a-w- c:\windows\SysWow64\wintrust.dll
2013-11-14 16:18 . 2013-04-10 05:48 1732608 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2013-11-14 16:18 . 2013-04-10 05:46 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2013-11-14 16:18 . 2013-04-10 05:46 1393152 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2013-11-14 16:18 . 2013-04-10 05:46 1367040 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2013-11-14 16:18 . 2013-04-10 05:03 936448 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2013-11-14 16:17 . 2012-07-04 22:16 73216 ----a-w- c:\windows\system32\netapi32.dll
2013-11-14 16:17 . 2012-07-04 22:13 59392 ----a-w- c:\windows\system32\browcli.dll
2013-11-14 16:17 . 2012-07-04 22:13 136704 ----a-w- c:\windows\system32\browser.dll
2013-11-14 16:17 . 2012-07-04 21:14 41984 ----a-w- c:\windows\SysWow64\browcli.dll
2013-11-14 16:17 . 2013-01-03 06:00 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2013-11-14 16:17 . 2012-08-22 18:12 376688 ----a-w- c:\windows\system32\drivers\netio.sys
2013-11-14 16:15 . 2012-08-22 18:12 950128 ----a-w- c:\windows\system32\drivers\ndis.sys
2013-11-14 16:15 . 2012-07-04 20:26 41472 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2013-11-14 16:14 . 2013-09-08 02:30 1903552 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-11-14 16:14 . 2013-09-08 02:27 327168 ----a-w- c:\windows\system32\mswsock.dll
2013-11-14 16:14 . 2013-09-08 02:03 231424 ----a-w- c:\windows\SysWow64\mswsock.dll
2013-11-14 16:13 . 2013-08-28 01:12 461312 ----a-w- c:\windows\system32\scavengeui.dll
2013-11-14 16:13 . 2013-06-25 22:55 785624 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2013-11-14 16:13 . 2012-11-28 22:56 9728 ----a-w- c:\windows\system32\Wdfres.dll
2013-11-14 16:13 . 2012-11-28 22:56 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2013-11-14 16:13 . 2011-04-29 03:06 467456 ----a-w- c:\windows\system32\drivers\srv.sys
2013-11-14 16:13 . 2011-04-29 03:05 410112 ----a-w- c:\windows\system32\drivers\srv2.sys
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-18 19:33 . 2010-11-21 03:27 267936 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}]
2013-10-23 18:43 12240 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" [2013-10-23 12240]
.
[HKEY_CLASSES_ROOT\clsid\{41564952-412d-5637-00a7-7a786e7484d7}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-10-28 3675352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-03-15 642656]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-10-31 683576]
"ApnTBMon"="c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2013-10-23 1673680]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-09-05 958576]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2013-04-26 292848]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Hotkey.lnk - c:\program files (x86)\Hotkey\Hotkey.exe [2013-7-24 4985856]
Qualcomm Atheros Killer Network Manager.lnk - c:\program files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe -minimized [2013-4-30 553984]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 amdkmpfd;AMD PCI Root Bus Lower Filter;c:\windows\system32\DRIVERS\amdkmpfd.sys;c:\windows\SYSNATIVE\DRIVERS\amdkmpfd.sys [x]
S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 BfLwf;Qualcomm Atheros Bandwidth Control;c:\windows\system32\DRIVERS\bflwfx64.sys;c:\windows\SYSNATIVE\DRIVERS\bflwfx64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO64A.SYS;c:\windows\SYSNATIVE\drivers\HWiNFO64A.SYS [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x]
S2 APNMCP;Ask Aktualisierungsdienst;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [x]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x]
S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 PowerBiosServer;PowerBiosServer;c:\program files (x86)\Hotkey\PowerBiosServer.exe;c:\program files (x86)\Hotkey\PowerBiosServer.exe [x]
S2 Qualcomm Atheros Killer Service;Qualcomm Atheros Killer Service;c:\program files\Qualcomm Atheros\Killer Network Manager\BFNService.exe;c:\program files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [x]
S2 ZAtheros Bt and Wlan Coex Agent;ZAtheros Bt and Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x]
S3 Ak27x64;Killer Wireless-N 1102 device driver;c:\windows\system32\DRIVERS\Ak27x64.sys;c:\windows\SYSNATIVE\DRIVERS\Ak27x64.sys [x]
S3 AthBTPort;Qualcomm Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
S3 btath_avdt;Qualcomm Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys;c:\windows\SYSNATIVE\drivers\btath_avdt.sys [x]
S3 BTATH_BUS;Qualcomm Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
S3 fspad_win764;Finger Sensing Pad Driver;c:\windows\system32\DRIVERS\fspad_win764.sys;c:\windows\SYSNATIVE\DRIVERS\fspad_win764.sys [x]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x]
S3 RSBASTOR;Realtek PCIE CardReader Driver - BA;c:\windows\system32\DRIVERS\RtsBaStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsBaStor.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2013-12-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-13 23:26]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}]
2013-10-23 18:43 13776 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll" [2013-10-23 13776]
.
[HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2013-05-10 165872]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2013-05-10 407536]
"Persistence"="c:\windows\system32\igfxpers.exe" [2013-05-10 444400]
"Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2012-09-20 1832760]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2013-03-26 13449288]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.akersolutions.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
LSP: %SYSTEMROOT%\system32\BfLLR.dll
TCP: DhcpNameServer = 208.67.222.222 208.67.220.220
FF - ProfilePath - c:\users\Waldi\AppData\Roaming\Mozilla\Firefox\Profiles\mqcraxjw.default\
FF - ExtSQL: 2013-10-24 02:44; toolbar_AVIRA-V7@apn.ask.com; c:\users\Waldi\AppData\Roaming\Mozilla\Firefox\Profiles\mqcraxjw.default\extensions\toolbar_AVIRA-V7@apn.ask.com.xpi
FF - ExtSQL: 2013-11-26 14:27; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Waldi\AppData\Roaming\Mozilla\Firefox\Profiles\mqcraxjw.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-fspuip - c:\program files (x86)\FSP\fspuip.exe
AddRemove-Battlelog Web Plugins - c:\program files (x86)\Battlelog Web Plugins\uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2950695333-3433012553-3668464571-1000\Software\SecuROM\License information*]
"datasecu"=hex:de,10,07,18,bf,e2,19,59,2e,2c,9e,d9,47,a3,e4,3e,1e,7f,81,e9,48,
69,14,2e,33,d4,40,c5,82,45,fd,ef,d3,07,42,e7,db,db,02,1b,6d,43,d5,ba,d1,aa,\
"rkeysecu"=hex:cf,fd,36,ed,8f,83,8f,67,d5,d5,68,a4,04,da,e7,c7
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-12-04 18:08:45
ComboFix-quarantined-files.txt 2013-12-04 10:08
.
Vor Suchlauf: 8 Verzeichnis(se), 11.320.582.144 Bytes frei
Nach Suchlauf: 12 Verzeichnis(se), 12.563.337.216 Bytes frei
.
- - End Of File - - 6F75F24F1A015B8651A516A0DFAFB13D
A36C5E4F47E84449FF07ED3517B43A31 |