Noshio88 | 12.12.2013 09:47 | Code:
ComboFix 13-12-10.01 - Affka 12.12.2013 9:42.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8134.6245 [GMT 1:00]
ausgeführt von:: c:\users\Affka\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\END
c:\windows\SysWow64\ChilkatMail_v7_9.dll
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-11-12 bis 2013-12-12 ))))))))))))))))))))))))))))))
.
.
2013-12-12 08:45 . 2013-12-12 08:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-12 02:01 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2013-12-12 02:01 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
2013-12-12 02:01 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2013-12-12 02:01 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL
2013-12-12 02:01 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll
2013-12-11 22:14 . 2013-10-30 02:32 335360 ----a-w- c:\windows\system32\msieftp.dll
2013-12-11 16:15 . 2013-12-11 19:15 -------- d-----w- C:\chat.Noshio
2013-12-11 15:37 . 2013-12-11 15:37 -------- d-----w- c:\program files\TeamSpeak 3 Client
2013-12-11 09:18 . 2013-12-12 02:17 -------- d-----w- c:\programdata\firebird
2013-12-11 09:17 . 2010-09-17 10:52 855552 ----a-w- c:\windows\system32\GDS32.DLL
2013-12-11 09:17 . 2010-09-17 10:13 548864 ----a-w- c:\windows\SysWow64\GDS32.DLL
2013-12-11 09:16 . 2013-12-11 09:16 -------- d-----w- c:\program files\Firebird
2013-12-11 09:16 . 2013-12-11 09:16 -------- d-----w- c:\program files (x86)\SpacialAudio
2013-12-09 18:00 . 2013-12-09 18:00 -------- d-----w- C:\FRST
2013-12-09 16:09 . 2013-12-09 16:09 -------- d-----w- c:\program files (x86)\Mp3tag
2013-12-09 14:52 . 2013-12-09 15:44 -------- d-----w- c:\program files (x86)\Common Files\Nero
2013-12-09 14:52 . 2013-12-09 15:44 -------- d-----w- c:\program files (x86)\Nero
2013-12-09 14:52 . 2013-12-09 18:49 -------- d-----w- c:\programdata\Nero
2013-12-09 14:50 . 2013-12-09 14:50 -------- d-----w- c:\program files (x86)\MSXML 4.0
2013-12-09 14:50 . 2010-05-26 10:41 248672 ----a-w- c:\windows\SysWow64\d3dx11_43.dll
2013-12-09 14:50 . 2010-05-26 10:41 470880 ----a-w- c:\windows\SysWow64\d3dx10_43.dll
2013-12-09 14:49 . 2010-05-26 10:41 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll
2013-12-09 14:49 . 2010-05-26 10:41 1868128 ----a-w- c:\windows\SysWow64\d3dcsx_43.dll
2013-12-09 14:49 . 2010-05-26 10:41 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll
2013-12-09 13:34 . 2013-09-04 12:12 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-12-09 13:34 . 2013-09-04 12:11 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-12-09 13:34 . 2013-09-04 12:11 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-12-09 13:34 . 2013-09-04 12:11 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-12-09 13:34 . 2013-09-04 12:11 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-12-09 13:34 . 2013-09-04 12:11 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-12-09 13:34 . 2013-09-04 12:11 7808 ----a-w- c:\windows\system32\drivers\usbd.sys
2013-12-09 10:03 . 2013-12-09 10:03 -------- d-----w- c:\program files (x86)\Movie Maker 2.6
2013-12-08 18:52 . 2013-12-08 18:52 -------- d-----w- c:\program files (x86)\Common Files\Skype
2013-12-08 18:52 . 2013-12-08 18:52 -------- d-----r- c:\program files (x86)\Skype
2013-12-08 18:52 . 2013-12-08 18:52 -------- d-----w- c:\programdata\Skype
2013-12-08 12:16 . 2013-12-08 12:17 -------- d-----w- c:\program files (x86)\VirtualDJ
2013-12-08 10:05 . 2013-12-08 10:05 -------- d-----w- c:\program files (x86)\PoP-Tools
2013-12-08 09:39 . 2013-12-08 09:39 -------- d-----w- c:\program files (x86)\UseNeXT
2013-12-08 09:06 . 2013-12-08 09:06 -------- d-----w- c:\programdata\AskPartnerNetwork
2013-12-08 09:06 . 2013-12-08 09:06 -------- d-----w- c:\program files (x86)\AskPartnerNetwork
2013-12-08 09:06 . 2013-12-08 09:06 -------- d-----w- c:\programdata\APN
2013-12-08 09:05 . 2013-12-08 09:05 -------- d-----w- c:\programdata\Avira
2013-12-08 09:05 . 2013-12-08 09:05 -------- d-----w- c:\program files (x86)\Avira
2013-12-08 09:05 . 2013-12-08 09:01 83160 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-12-08 09:05 . 2013-12-08 09:01 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-12-08 09:05 . 2013-12-08 09:01 132600 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-12-08 09:05 . 2013-12-08 09:01 107416 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-12-08 08:29 . 2013-12-08 08:29 -------- d-----w- c:\programdata\Websteroids
2013-12-07 15:13 . 2013-12-07 15:13 -------- d-----w- c:\program files (x86)\On2 Technologies
2013-12-07 15:13 . 2004-08-30 12:26 53248 ----a-w- c:\windows\SysWow64\vp6dec_settings.cpl
2013-12-07 15:13 . 2004-08-30 12:25 438272 ----a-w- c:\windows\SysWow64\vp6vfw.dll
2013-12-07 15:13 . 2004-08-30 12:23 327680 ----a-w- c:\windows\SysWow64\vp6dec.ax
2013-12-07 15:13 . 2002-07-25 16:07 614532 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe
2013-12-07 15:13 . 2001-09-05 03:18 77824 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
2013-12-07 15:13 . 2001-09-05 03:18 225280 ----a-w- c:\program files (x86)\Common Files\InstallShield\IScript\iscript.dll
2013-12-07 15:13 . 2001-09-05 03:14 176128 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
2013-12-07 15:13 . 2001-09-05 03:13 32768 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2013-12-07 11:04 . 2013-04-24 08:45 810496 ----a-w- c:\windows\SysWow64\xvidcore.dll
2013-12-07 11:04 . 2013-04-24 08:45 80896 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2013-12-07 11:04 . 2013-04-24 08:45 183808 ----a-w- c:\windows\SysWow64\xvidvfw.dll
2013-12-07 11:04 . 2013-12-07 11:07 -------- d-----w- c:\program files (x86)\SplitCam
2013-12-07 11:01 . 2013-12-07 11:01 -------- d-----w- c:\programdata\Updater
2013-12-07 11:01 . 2013-12-07 11:01 -------- d-----w- c:\programdata\RHelpers
2013-12-07 10:07 . 2013-10-17 15:32 35112 ----a-w- c:\windows\system32\drivers\teamviewervpn.sys
2013-12-07 10:07 . 2013-12-07 10:07 -------- d-----w- c:\program files (x86)\TeamViewer
2013-12-07 09:48 . 2006-03-31 11:41 3927248 ----a-w- c:\windows\system32\d3dx9_30.dll
2013-12-07 07:17 . 2013-12-07 07:17 -------- d-----w- c:\program files\WinRAR
2013-12-07 07:10 . 2013-12-07 07:10 -------- d-----w- c:\program files (x86)\Google
2013-12-07 07:03 . 2013-12-07 07:03 -------- d-----w- c:\program files\CCleaner
2013-12-07 00:55 . 2013-10-14 17:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
2013-12-07 00:51 . 2013-12-07 00:51 -------- d-----w- c:\program files (x86)\Microsoft CAPICOM 2.1.0.2
2013-12-07 00:50 . 2013-12-07 00:51 -------- d-----w- c:\program files\Microsoft Silverlight
2013-12-07 00:50 . 2013-12-07 00:51 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2013-12-06 17:39 . 2013-12-11 16:05 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird
2013-12-06 17:39 . 2013-12-06 17:39 12800 ----a-w- c:\programdata\dlprotect.exe
2013-12-06 17:39 . 2013-12-06 17:39 118784 ----a-w- c:\windows\system32\msasn164.exe
2013-12-06 17:39 . 2013-12-06 17:39 125440 ----a-w- c:\windows\system32\DlProtectSvc.exe
2013-12-06 17:37 . 2013-12-06 17:38 -------- d-----w- c:\program files (x86)\Re-markit
2013-12-06 17:29 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\SysWow64\D3DX9_42.dll
2013-12-06 17:29 . 2006-09-28 15:05 2414360 ----a-w- c:\windows\SysWow64\d3dx9_31.dll
2013-12-06 17:29 . 2013-12-06 17:29 -------- d-----w- c:\program files (x86)\Common Files\PX Storage Engine
2013-12-06 17:29 . 2013-12-06 17:30 -------- d-----w- c:\program files (x86)\Winamp
2013-12-06 17:27 . 2013-12-06 17:27 -------- d-----w- c:\program files\VideoLAN
2013-12-06 17:13 . 2013-12-06 17:13 -------- d-----w- C:\gamigo
2013-12-06 16:17 . 2013-12-07 07:11 -------- d-----w- c:\program files (x86)\Common Files\Steam
2013-12-06 16:17 . 2013-12-12 02:17 -------- d-----w- c:\program files (x86)\Steam
2013-12-06 16:11 . 2013-12-11 16:05 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2013-12-06 16:06 . 2013-11-29 16:56 1096480 ----a-w- c:\windows\system32\nvspcap64.dll
2013-12-06 16:06 . 2013-11-29 16:56 979744 ----a-w- c:\windows\SysWow64\nvspcap.dll
2013-12-06 16:05 . 2013-10-30 17:03 39200 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2013-12-06 16:05 . 2013-10-30 17:02 32544 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2013-12-06 15:59 . 2013-12-06 15:59 -------- d-----w- C:\Intel
2013-12-06 15:53 . 2013-12-06 15:53 -------- d-----w- c:\programdata\LogiShrd
2013-12-06 15:51 . 2013-12-06 15:51 -------- d-----w- c:\programdata\Logitech
2013-12-06 15:51 . 2013-12-06 15:51 -------- d-----w- c:\program files (x86)\Common Files\LWS
2013-12-06 15:51 . 2013-12-06 15:51 -------- d-----w- c:\program files (x86)\Logitech
2013-12-06 15:37 . 2013-11-18 00:28 10285968 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B6258553-B259-4903-A2F3-BA8575A9DDE4}\mpengine.dll
2013-12-06 15:33 . 2013-08-28 01:12 461312 ----a-w- c:\windows\system32\scavengeui.dll
2013-12-06 15:31 . 2013-12-06 15:52 -------- d-----w- c:\program files (x86)\Common Files\logishrd
2013-12-06 15:31 . 2013-12-06 15:51 -------- d-----w- c:\program files\Common Files\logishrd
2013-12-06 15:28 . 2013-12-06 17:09 -------- d-----w- c:\users\Affka
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-11 09:20 . 2013-08-09 10:15 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-12-11 09:20 . 2013-08-09 10:15 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-11-19 02:33 . 2010-11-21 03:27 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-11-14 11:56 . 2013-08-09 10:25 61216 ----a-w- c:\windows\system32\OpenCL.dll
2013-11-14 11:56 . 2013-08-09 10:25 53024 ----a-w- c:\windows\SysWow64\OpenCL.dll
2013-11-14 11:56 . 2013-08-09 10:25 1436528 ----a-w- c:\windows\system32\nvumdshimx.dll
2013-11-14 11:56 . 2013-10-02 04:33 15218504 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-11-14 11:56 . 2013-10-02 04:33 2697248 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-11-14 11:56 . 2013-08-09 10:25 3069608 ----a-w- c:\windows\system32\nvapi64.dll
2013-11-11 15:02 . 2013-08-09 10:25 6674208 ----a-w- c:\windows\system32\nvcpl.dll
2013-11-11 15:02 . 2013-08-09 10:25 3490080 ----a-w- c:\windows\system32\nvsvc64.dll
2013-11-11 15:01 . 2013-08-09 10:25 922912 ----a-w- c:\windows\system32\nvvsvc.exe
2013-11-11 15:01 . 2013-08-09 10:25 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-11-11 15:01 . 2013-08-09 10:25 2559776 ----a-w- c:\windows\system32\nvsvcr.dll
2013-11-11 15:01 . 2013-08-09 10:25 219424 ----a-w- c:\windows\system32\nvmctray.dll
2013-11-11 15:01 . 2013-08-09 10:25 3467927 ----a-w- c:\windows\system32\nvcoproc.bin
2013-11-11 07:59 . 2013-11-11 07:59 590112 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2013-11-07 15:00 . 2013-08-09 11:03 82896128 ----a-w- c:\windows\system32\MRT.exe
2013-10-30 17:02 . 2013-10-02 04:33 35104 ----a-w- c:\windows\system32\nvaudcap64v.dll
2013-10-02 04:27 . 2013-08-09 09:03 653 ----a-w- c:\windows\iinfo.bat
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{065d63b4-653d-4e86-8543-e90921d3da2f}]
2013-12-06 17:37 137216 ----a-w- c:\program files (x86)\Re-markit\136.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}]
2013-10-23 18:43 12240 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{F63AAEDC-3602-49EF-AA45-262380A98980}]
2013-10-23 16:41 168224 ----a-w- c:\users\Affka\AppData\Roaming\ValueApps\IE\MonPrx.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" [2013-10-23 12240]
.
[HKEY_CLASSES_ROOT\clsid\{41564952-412d-5637-00a7-7a786e7484d7}]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\Affka\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\Affka\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\Affka\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SplitCam"="c:\program files (x86)\SplitCam\SplitCam.exe" [2013-10-23 13723808]
"icq"="c:\users\Affka\AppData\Roaming\ICQM\icq.exe" [2013-12-06 29919576]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2013-06-10 292088]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-12-08 683576]
.
c:\users\Affka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Affka\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-11-9 29770248]
IML.lnk - c:\windows\System32\iml.vbs [2010-5-21 4472]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer5"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 iaStorA;iaStorA;c:\windows\system32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
R3 iaStorS;iaStorS;c:\windows\system32\drivers\iaStorS.sys;c:\windows\SYSNATIVE\drivers\iaStorS.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\drivers\iusb3xhc.sys;c:\windows\SYSNATIVE\drivers\iusb3xhc.sys [x]
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\drivers\nvstusb.sys;c:\windows\SYSNATIVE\drivers\nvstusb.sys [x]
R3 PciIsaSerial;PCI-ISA Communication Port;c:\windows\system32\drivers\PciIsaSerial.sys;c:\windows\SYSNATIVE\drivers\PciIsaSerial.sys [x]
R3 PciPPorts;PCI ECP Parallel Port;c:\windows\system32\drivers\PciPPorts.sys;c:\windows\SYSNATIVE\drivers\PciPPorts.sys [x]
R3 PciSPorts;High-Speed PCI Serial Port;c:\windows\system32\drivers\PciSPorts.sys;c:\windows\SYSNATIVE\drivers\PciSPorts.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 iaStorF;iaStorF;c:\windows\system32\drivers\iaStorF.sys;c:\windows\SYSNATIVE\drivers\iaStorF.sys [x]
S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\drivers\iusb3hcs.sys;c:\windows\SYSNATIVE\drivers\iusb3hcs.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x]
S2 APNMCP;Ask Aktualisierungsdienst;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [x]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x]
S2 cipher64;Verbessertes Heimnetzgruppen-Listener Desktop;c:\windows\system32\msasn164.exe;c:\windows\SYSNATIVE\msasn164.exe [x]
S2 DlProtectSvc;Download Protect Service;c:\windows\System32\DlProtectSvc.exe;c:\windows\SYSNATIVE\DlProtectSvc.exe [x]
S2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_2_5\bin\fbguard.exe;c:\program files\Firebird\Firebird_2_5\bin\fbguard.exe [x]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 SpliCamService;SplitCamService;c:\program files (x86)\SplitCam\SplitCamService.exe;c:\program files (x86)\SplitCam\SplitCamService.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x]
S3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_2_5\bin\fbserver.exe;c:\program files\Firebird\Firebird_2_5\bin\fbserver.exe [x]
S3 LVUVC64;Logitech HD Pro Webcam C920(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 scvad_simple;SplitCam Virtual Microphone (WDM);c:\windows\system32\drivers\SplitCamAudio.sys;c:\windows\SYSNATIVE\drivers\SplitCamAudio.sys [x]
S3 splitcam_hd_driver;SplitCam Virtual Video Driver;c:\windows\system32\DRIVERS\splitcam_hd_driver.sys;c:\windows\SYSNATIVE\DRIVERS\splitcam_hd_driver.sys [x]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys;c:\windows\SYSNATIVE\DRIVERS\teamviewervpn.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-07 07:10 1210320 ----a-w- c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-12-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-09 09:20]
.
2013-12-12 c:\windows\Tasks\AmiUpdXp.job
- c:\users\Affka\AppData\Local\SwvUpdater\Updater.exe [2013-12-06 17:37]
.
2013-12-11 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-231953219-3282353072-3266765423-1002Core.job
- c:\users\Affka\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-07 18:28]
.
2013-12-12 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-231953219-3282353072-3266765423-1002UA.job
- c:\users\Affka\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-07 18:28]
.
2013-12-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-07 07:10]
.
2013-12-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-07 07:10]
.
2013-12-12 c:\windows\Tasks\Re-markit Update.job
- c:\program files (x86)\Re-markit\ReMarkit_up.exe [2013-12-06 17:37]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}]
2013-10-23 18:43 13776 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll" [2013-10-23 13776]
.
[HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 164016 ----a-w- c:\users\Affka\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 164016 ----a-w- c:\users\Affka\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 164016 ----a-w- c:\users\Affka\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 164016 ----a-w- c:\users\Affka\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.myhoome.com/
mDefault_Page_URL = hxxp://www.myhoome.com/
mStart Page = hxxp://www.myhoome.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Affka\AppData\Roaming\Mozilla\Firefox\Profiles\t8pxekai.default\
FF - prefs.js: browser.startup.homepage - google.de
FF - ExtSQL: 2013-12-06 18:37; {09c97f6d-1110-4a9d-b1d4-c01fe8769b68}; c:\program files (x86)\Re-markit\136.xpi
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-231953219-3282353072-3266765423-1002\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A44FDF76-7D5D-B9CE-3157-650326D3AC83}*]
@Allowed: (Read) (RestrictedCode)
"iaooeklheclhkmmloj"=hex:6b,61,66,6b,70,6d,64,6c,65,67,68,69,66,63,66,64,66,69,
67,69,6d,62,00,00
"haipkjhgmlebgggl"=hex:6b,61,66,6b,70,6d,64,6c,65,67,68,69,66,63,66,64,66,69,
67,69,6d,62,00,00
"iacemkdhpaafgfdjal"=hex:63,61,62,6b,69,6d,00,00
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-12-12 09:46:42
ComboFix-quarantined-files.txt 2013-12-12 08:46
.
Vor Suchlauf: 12 Verzeichnis(se), 793.779.015.680 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 793.388.568.576 Bytes frei
.
- - End Of File - - 333EC905A40B973AE657B4AAD1E87985
A36C5E4F47E84449FF07ED3517B43A31 |