Danke für die schnelle Antwort, hier das Combofix-Log Code:
ComboFix 14-02-19.01 - Jonas **** 20.02.2014 9:31.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4091.2160 [GMT 1:00]
ausgeführt von:: c:\users\Jonas ****\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Common Files\Acer GameZone online.ico
c:\program files (x86)\ESO Survey Live\ESOSurveyLive.exe
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\epfflkmclhdfgibcmofagfgpmegidbce
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\epfflkmclhdfgibcmofagfgpmegidbce\2.7\a_a2.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\epfflkmclhdfgibcmofagfgpmegidbce\2.7\background.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\epfflkmclhdfgibcmofagfgpmegidbce\2.7\content.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\epfflkmclhdfgibcmofagfgpmegidbce\2.7\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\epfflkmclhdfgibcmofagfgpmegidbce\2.7\manifest.json
c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\epfflkmclhdfgibcmofagfgpmegidbce
c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\epfflkmclhdfgibcmofagfgpmegidbce\2.7\a_a2.js
c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\epfflkmclhdfgibcmofagfgpmegidbce\2.7\background.html
c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\epfflkmclhdfgibcmofagfgpmegidbce\2.7\content.js
c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\epfflkmclhdfgibcmofagfgpmegidbce\2.7\lsdb.js
c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\epfflkmclhdfgibcmofagfgpmegidbce\2.7\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\epfflkmclhdfgibcmofagfgpmegidbce
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\epfflkmclhdfgibcmofagfgpmegidbce\2.7\a_a2.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\epfflkmclhdfgibcmofagfgpmegidbce\2.7\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\epfflkmclhdfgibcmofagfgpmegidbce\2.7\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\epfflkmclhdfgibcmofagfgpmegidbce\2.7\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\epfflkmclhdfgibcmofagfgpmegidbce\2.7\manifest.json
c:\users\Jonas ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\fadgadbklejlmilpbompfkilmahdkjje
c:\users\Jonas ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\fadgadbklejlmilpbompfkilmahdkjje\2.3_0\background.html
c:\users\Jonas ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\fadgadbklejlmilpbompfkilmahdkjje\2.3_0\content.js
c:\users\Jonas ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\fadgadbklejlmilpbompfkilmahdkjje\2.3_0\lsdb.js
c:\users\Jonas ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\fadgadbklejlmilpbompfkilmahdkjje\2.3_0\manifest.json
c:\users\Jonas ****\AppData\Local\Google\Chrome\User Data\Default\Extensions\fadgadbklejlmilpbompfkilmahdkjje\2.3_0\Nrxbo9Cn.js
c:\users\Jonas ****\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fadgadbklejlmilpbompfkilmahdkjje_0.localstorage-journal
c:\users\Jonas ****\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fadgadbklejlmilpbompfkilmahdkjje_0.localstorage
c:\users\Jonas ****\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\users\Jonas ****\AppData\Roaming\Mozilla\Firefox\Profiles\gpdkaj8x.default-1378759098533\extensions\staged\evhlry@wvjuua-.net
c:\users\Jonas ****\AppData\Roaming\Mozilla\Firefox\Profiles\gpdkaj8x.default-1378759098533\extensions\staged\evhlry@wvjuua-.net\bootstrap.js
c:\users\Jonas ****\AppData\Roaming\Mozilla\Firefox\Profiles\gpdkaj8x.default-1378759098533\extensions\staged\evhlry@wvjuua-.net\chrome.manifest
c:\users\Jonas ****\AppData\Roaming\Mozilla\Firefox\Profiles\gpdkaj8x.default-1378759098533\extensions\staged\evhlry@wvjuua-.net\content\bg.js
c:\users\Jonas ****\AppData\Roaming\Mozilla\Firefox\Profiles\gpdkaj8x.default-1378759098533\extensions\staged\evhlry@wvjuua-.net\install.rdf
c:\users\Jonas ****\AppData\Roaming\Mozilla\Firefox\Profiles\gpdkaj8x.default-1378759098533\extensions\staged\gqqzqmroio@rtfya.edu
c:\users\Jonas ****\AppData\Roaming\Mozilla\Firefox\Profiles\gpdkaj8x.default-1378759098533\extensions\staged\gqqzqmroio@rtfya.edu\bootstrap.js
c:\users\Jonas ****\AppData\Roaming\Mozilla\Firefox\Profiles\gpdkaj8x.default-1378759098533\extensions\staged\gqqzqmroio@rtfya.edu\chrome.manifest
c:\users\Jonas ****\AppData\Roaming\Mozilla\Firefox\Profiles\gpdkaj8x.default-1378759098533\extensions\staged\gqqzqmroio@rtfya.edu\content\bg.js
c:\users\Jonas ****\AppData\Roaming\Mozilla\Firefox\Profiles\gpdkaj8x.default-1378759098533\extensions\staged\gqqzqmroio@rtfya.edu\install.rdf
c:\windows\SysWow64\frapsvid.dll
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-01-20 bis 2014-02-20 ))))))))))))))))))))))))))))))
.
.
2014-02-20 08:42 . 2014-02-20 08:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-02-19 23:10 . 2014-02-19 23:13 -------- d-----w- C:\FRST
2014-02-18 19:58 . 2014-02-18 20:55 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2014-02-18 19:58 . 2014-02-18 19:58 119000 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-02-18 19:57 . 2014-02-18 19:57 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-02-15 14:15 . 2014-02-15 14:15 -------- d-----w- c:\program files (x86)\Brurli Corp
2014-02-15 14:11 . 2014-02-15 14:11 -------- d-----w- c:\users\Jonas ****\AppData\Roaming\Caphyon
2014-02-15 14:10 . 2014-02-15 14:11 -------- d-----w- c:\programdata\regid.2003-04.com.caphyon
2014-02-15 14:10 . 2014-02-15 14:10 -------- d-----w- c:\program files (x86)\Caphyon
2014-02-15 14:10 . 2014-02-15 14:11 -------- d-----w- c:\programdata\Caphyon
2014-02-15 14:02 . 2014-02-15 14:02 -------- d-----w- c:\program files (x86)\Myncos
2014-02-13 13:06 . 2014-02-13 13:06 -------- d-----w- c:\program files (x86)\Common Files\BattlEye
2014-02-13 13:04 . 2014-02-19 14:52 -------- d-----w- c:\users\Jonas ****\AppData\Local\DayZ
2014-01-31 12:19 . 2014-01-31 12:19 -------- d-----w- c:\programdata\fadgadbklejlmilpbompfkilmahdkjje
2014-01-23 00:24 . 2014-01-23 00:34 -------- d-----w- c:\users\Jonas ****\FTBRETROSSP
2014-01-23 00:19 . 2014-01-23 00:35 -------- d-----w- c:\users\Jonas ****\AppData\Roaming\ftblauncher
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-02-12 13:30 . 2014-01-15 02:38 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A8E75326-60E8-40E8-B093-956635445471}\offreg.dll
2014-02-05 10:01 . 2013-01-29 13:57 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-02-05 10:01 . 2013-01-29 13:57 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-01-05 06:27 . 2014-01-05 06:27 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-01-05 06:27 . 2014-01-05 06:27 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2014-01-05 06:27 . 2014-01-05 06:27 942592 ----a-w- c:\windows\system32\jsIntl.dll
2014-01-05 06:27 . 2014-01-05 06:27 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-01-05 06:27 . 2014-01-05 06:27 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2014-01-05 06:27 . 2014-01-05 06:27 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2014-01-05 06:27 . 2014-01-05 06:27 84992 ----a-w- c:\windows\system32\mshtmled.dll
2014-01-05 06:27 . 2014-01-05 06:27 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2014-01-05 06:27 . 2014-01-05 06:27 81408 ----a-w- c:\windows\system32\icardie.dll
2014-01-05 06:27 . 2014-01-05 06:27 774144 ----a-w- c:\windows\system32\jscript.dll
2014-01-05 06:27 . 2014-01-05 06:27 77312 ----a-w- c:\windows\system32\tdc.ocx
2014-01-05 06:27 . 2014-01-05 06:27 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2014-01-05 06:27 . 2014-01-05 06:27 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2014-01-05 06:27 . 2014-01-05 06:27 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2014-01-05 06:27 . 2014-01-05 06:27 626176 ----a-w- c:\windows\system32\msfeeds.dll
2014-01-05 06:27 . 2014-01-05 06:27 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2014-01-05 06:27 . 2014-01-05 06:27 62464 ----a-w- c:\windows\system32\pngfilt.dll
2014-01-05 06:27 . 2014-01-05 06:27 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2014-01-05 06:27 . 2014-01-05 06:27 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2014-01-05 06:27 . 2014-01-05 06:27 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2014-01-05 06:27 . 2014-01-05 06:27 548352 ----a-w- c:\windows\system32\vbscript.dll
2014-01-05 06:27 . 2014-01-05 06:27 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2014-01-05 06:27 . 2014-01-05 06:27 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2014-01-05 06:27 . 2014-01-05 06:27 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2014-01-05 06:27 . 2014-01-05 06:27 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-01-05 06:27 . 2014-01-05 06:27 48128 ----a-w- c:\windows\system32\imgutil.dll
2014-01-05 06:27 . 2014-01-05 06:27 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2014-01-05 06:27 . 2014-01-05 06:27 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2014-01-05 06:27 . 2014-01-05 06:27 413696 ----a-w- c:\windows\system32\html.iec
2014-01-05 06:27 . 2014-01-05 06:27 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2014-01-05 06:27 . 2014-01-05 06:27 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2014-01-05 06:27 . 2014-01-05 06:27 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2014-01-05 06:27 . 2014-01-05 06:27 337408 ----a-w- c:\windows\SysWow64\html.iec
2014-01-05 06:27 . 2014-01-05 06:27 30208 ----a-w- c:\windows\system32\licmgr10.dll
2014-01-05 06:27 . 2014-01-05 06:27 296960 ----a-w- c:\windows\system32\dxtrans.dll
2014-01-05 06:27 . 2014-01-05 06:27 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2014-01-05 06:27 . 2014-01-05 06:27 247808 ----a-w- c:\windows\system32\msls31.dll
2014-01-05 06:27 . 2014-01-05 06:27 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2014-01-05 06:27 . 2014-01-05 06:27 243200 ----a-w- c:\windows\system32\webcheck.dll
2014-01-05 06:27 . 2014-01-05 06:27 235520 ----a-w- c:\windows\system32\url.dll
2014-01-05 06:27 . 2014-01-05 06:27 235008 ----a-w- c:\windows\system32\elshyph.dll
2014-01-05 06:27 . 2014-01-05 06:27 195584 ----a-w- c:\windows\system32\msrating.dll
2014-01-05 06:27 . 2014-01-05 06:27 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2014-01-05 06:27 . 2014-01-05 06:27 167424 ----a-w- c:\windows\system32\iexpress.exe
2014-01-05 06:27 . 2014-01-05 06:27 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2014-01-05 06:27 . 2014-01-05 06:27 147968 ----a-w- c:\windows\system32\occache.dll
2014-01-05 06:27 . 2014-01-05 06:27 143872 ----a-w- c:\windows\system32\wextract.exe
2014-01-05 06:27 . 2014-01-05 06:27 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2014-01-05 06:27 . 2014-01-05 06:27 13824 ----a-w- c:\windows\system32\mshta.exe
2014-01-05 06:27 . 2014-01-05 06:27 135680 ----a-w- c:\windows\system32\iepeers.dll
2014-01-05 06:27 . 2014-01-05 06:27 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2014-01-05 06:27 . 2014-01-05 06:27 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2014-01-05 06:27 . 2014-01-05 06:27 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-01-05 06:27 . 2014-01-05 06:27 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2014-01-05 06:27 . 2014-01-05 06:27 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2014-01-05 06:27 . 2014-01-05 06:27 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2014-01-05 06:27 . 2014-01-05 06:27 105984 ----a-w- c:\windows\system32\iesysprep.dll
2014-01-05 06:27 . 2014-01-05 06:27 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2014-01-05 06:27 . 2014-01-05 06:27 101376 ----a-w- c:\windows\system32\inseng.dll
2014-01-05 06:26 . 2014-01-05 06:26 878080 ----a-w- c:\windows\system32\advapi32.dll
2014-01-05 06:26 . 2014-01-05 06:26 859648 ----a-w- c:\windows\system32\tdh.dll
2014-01-05 06:26 . 2014-01-05 06:26 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2014-01-05 06:26 . 2014-01-05 06:26 640512 ----a-w- c:\windows\SysWow64\advapi32.dll
2014-01-05 06:26 . 2014-01-05 06:26 5549504 ----a-w- c:\windows\system32\ntoskrnl.exe
2014-01-05 06:26 . 2014-01-05 06:26 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2014-01-05 06:26 . 2014-01-05 06:26 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2014-01-05 06:26 . 2014-01-05 06:26 3969472 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2014-01-05 06:26 . 2014-01-05 06:26 3914176 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2014-01-05 06:26 . 2014-01-05 06:26 362496 ----a-w- c:\windows\system32\wow64win.dll
2014-01-05 06:26 . 2014-01-05 06:26 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2014-01-05 06:26 . 2014-01-05 06:26 243712 ----a-w- c:\windows\system32\wow64.dll
2014-01-05 06:26 . 2014-01-05 06:26 2048 ----a-w- c:\windows\SysWow64\user.exe
2014-01-05 06:26 . 2014-01-05 06:26 1732032 ----a-w- c:\windows\system32\ntdll.dll
2014-01-05 06:26 . 2014-01-05 06:26 16384 ----a-w- c:\windows\system32\ntvdm64.dll
2014-01-05 06:26 . 2014-01-05 06:26 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2014-01-05 06:26 . 2014-01-05 06:26 13312 ----a-w- c:\windows\system32\wow64cpu.dll
2014-01-05 06:26 . 2014-01-05 06:26 619520 ----a-w- c:\windows\SysWow64\tdh.dll
2014-01-05 06:26 . 2014-01-05 06:26 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll
2014-01-05 06:25 . 2014-01-05 06:25 327168 ----a-w- c:\windows\system32\mswsock.dll
2014-01-05 06:25 . 2014-01-05 06:25 231424 ----a-w- c:\windows\SysWow64\mswsock.dll
2014-01-05 06:25 . 2014-01-05 06:25 1903552 ----a-w- c:\windows\system32\drivers\tcpip.sys
2014-01-04 06:12 . 2014-01-04 06:12 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-01-04 06:12 . 2014-01-04 06:12 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-01-04 06:12 . 2014-01-04 06:12 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-01-04 06:12 . 2014-01-04 06:12 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-01-04 06:12 . 2014-01-04 06:12 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-01-04 06:12 . 2014-01-04 06:12 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2014-01-04 06:12 . 2014-01-04 06:12 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2014-01-04 06:12 . 2014-01-04 06:12 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-01-04 06:12 . 2014-01-04 06:12 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-01-04 06:12 . 2014-01-04 06:12 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-01-04 06:12 . 2014-01-04 06:12 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-01-04 06:12 . 2014-01-04 06:12 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2014-01-04 06:12 . 2014-01-04 06:12 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2014-01-04 06:12 . 2014-01-04 06:12 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2014-01-04 06:12 . 2014-01-04 06:12 3928064 ----a-w- c:\windows\system32\d2d1.dll
2014-01-04 06:12 . 2014-01-04 06:12 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\Steam.exe" [2014-02-11 1824000]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-11-14 20584608]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"NortonOnlineBackupReminder"="c:\program files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-07-24 588648]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"HOSTS Anti-Adware_PUPs"="c:\program files (x86)\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe" [2014-01-20 302961]
.
c:\users\Jonas ****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
CurseClientStartup.ccip [2013-2-26 0]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 e9f32388;GS Supporter;c:\windows\system32\rundll32.exe;c:\windows\SYSNATIVE\rundll32.exe [x]
R2 HOSTS Anti-PUPs;HOSTS Anti-PUPs;c:\program files (x86)\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe;c:\program files (x86)\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 avmeject;AVM Eject;c:\windows\system32\drivers\avmeject.sys;c:\windows\SYSNATIVE\drivers\avmeject.sys [x]
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys;c:\windows\SYSNATIVE\drivers\btusbflt.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 FWLANUSB;AVM FRITZ!WLAN;c:\windows\system32\DRIVERS\fwlanusb.sys;c:\windows\SYSNATIVE\DRIVERS\fwlanusb.sys [x]
R3 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
R3 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys;c:\windows\SYSNATIVE\DRIVERS\MijXfilt.sys [x]
R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe;c:\program files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series - Adaptertreiber für Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys;c:\windows\SYSNATIVE\DRIVERS\Rts516xIR.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x]
R3 X6va011;X6va011;c:\windows\SysWOW64\Drivers\X6va011;c:\windows\SysWOW64\Drivers\X6va011 [x]
R3 X6va012;X6va012;c:\windows\SysWOW64\Drivers\X6va012;c:\windows\SysWOW64\Drivers\X6va012 [x]
R3 X6va015;X6va015;c:\windows\SysWOW64\Drivers\X6va015;c:\windows\SysWOW64\Drivers\X6va015 [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [x]
S2 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe;c:\program files (x86)\Acer\Registration\GregHSRW.exe [x]
S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 RzKLService;RzKLService;c:\program files (x86)\Razer\Razer Game Booster\RzKLService.exe;c:\program files (x86)\Razer\Razer Game Booster\RzKLService.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXHWAZL.sys;c:\windows\SYSNATIVE\DRIVERS\CAXHWAZL.sys [x]
S3 hidshim;Service for HID-KMDF Shim layer;c:\windows\system32\DRIVERS\hidshim.sys;c:\windows\SYSNATIVE\DRIVERS\hidshim.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x]
S3 NETw5s64;Intel(R) Wireless WiFi Link Adaptertreiber für Windows 7 64-Bit;c:\windows\system32\DRIVERS\NETw5s64.sys;c:\windows\SYSNATIVE\DRIVERS\NETw5s64.sys [x]
S3 nuvotonhidgeneric;Nuvoton EC Generic HID;c:\windows\system32\DRIVERS\nuvotonhidgeneric.sys;c:\windows\SYSNATIVE\DRIVERS\nuvotonhidgeneric.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - AWRCIKOB
*Deregistered* - awrcikob
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-01-29 17:52 1211672 ----a-w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.102\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-02-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-29 10:01]
.
2014-02-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-27 21:30]
.
2014-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-27 21:30]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]
"mwlDaemon"="c:\program files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2009-09-11 349480]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-11-03 8312352]
"PLFSetI"="c:\windows\PLFSetI.exe" [2013-01-27 200704]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2009-09-30 823840]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2013-12-10 2279712]
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.com
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com
IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm
IE: Mit Mipony herunterladen - file://c:\program files (x86)\MiPony\Browser\IEContext.htm
IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Jonas ****\AppData\Roaming\Mozilla\Firefox\Profiles\gpdkaj8x.default-1378759098533\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} - c:\program files (x86)\EgisTec\MyWinLocker 3\x86\psdprotect.dll
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ESO Survey Live.lnk - c:\program files (x86)\ESO Survey Live\ESOSurveyLive.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} - c:\program files (x86)\EgisTec\MyWinLocker 3\x64\psdprotect.dll
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-Uplay Install 273 - c:\program files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe ****\UninstalString2.txt
AddRemove-{B931FB80-537A-4600-00AD-AC5DEDB6C25B} - c:\program files (x86)\Electronic Arts\The Lord of the Rings
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va011]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va011"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va012]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va012"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va015]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va015"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2407130220-617045063-1494062072-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:44,42,99,a0,c4,c7,2e,16,68,6c,53,22,5a,38,0e,19,02,1e,5f,e4,38,ce,da,
81,03,3b,78,83,89,95,33,89,17,93,cf,3f,c5,46,b5,2f,00,f2,2c,aa,6b,21,41,58,\
"??"=hex:86,fd,76,61,cd,76,64,d0,18,0b,81,20,6c,7d,1b,bc
.
[HKEY_USERS\S-1-5-21-2407130220-617045063-1494062072-1000\Software\SecuROM\License information*]
"datasecu"=hex:b7,1f,44,8e,54,3b,00,ab,7e,a3,47,79,e1,5d,5b,df,7c,84,66,d4,2b,
46,ce,de,df,c2,e1,86,11,36,96,0c,bf,58,11,3e,0d,48,1f,be,27,f8,5d,5f,63,9f,\
"rkeysecu"=hex:c8,88,4a,2e,78,6b,0b,ed,72,16,87,49,31,a4,b7,66
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing\WinZip]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-02-20 09:45:56
ComboFix-quarantined-files.txt 2014-02-20 08:45
.
Vor Suchlauf: 29 Verzeichnis(se), 136.365.989.888 Bytes frei
Nach Suchlauf: 34 Verzeichnis(se), 135.839.436.800 Bytes frei
.
- - End Of File - - B426FD1F9E628A3EA02D8AE1E1088301
5C616939100B85E558DA92B899A0FC36 |