BonnaFide | 30.03.2014 12:18 | Code:
ComboFix 14-03-24.01 - Tobias 30.03.2014 12:42:44.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.7645.5186 [GMT 2:00]
ausgeführt von:: c:\users\Tobias\Downloads\Programs\ComboFix.exe
AV: Bitdefender-Virenschutz *Disabled/Updated* {98CD50CE-5097-4098-9669-6C401FB3969C}
AV: Bitdefender Virenschutz *Disabled/Updated* {9B5F5313-CAF9-DD97-C460-E778420237B4}
FW: Bitdefender Firewall *Disabled* {A0F6D1EB-1AF8-41C0-BD36-C575E160D1E7}
FW: Bitdefender Firewall *Enabled* {A364D236-8096-DCCF-EF3F-4E4DBCD170CF}
SP: Bitdefender-Spyware-Schutz *Disabled/Updated* {23ACB12A-76AD-4F16-ACD9-57326434DC21}
SP: Bitdefender Spyware-Schutz *Disabled/Updated* {203EB2F7-ECC3-D219-FED0-DC0A39857D09}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\programdata\1387282959.bdinstall.bin
c:\programdata\1387283801.bdinstall.bin
c:\programdata\1391957200.bdinstall.bin
c:\programdata\1392489982.8540.bin
c:\programdata\1392489982.9312.bin
c:\programdata\1392489982.9356.bin
c:\programdata\1392489982.9524.bin
c:\programdata\1392568455.bdinstall.bin
c:\windows\IsUn0407.exe
c:\windows\iun6002.exe
c:\windows\SysWow64\DEBUG.log
c:\windows\SysWow64\Packet.dll
c:\windows\SysWow64\wpcap.dll
c:\windows\SysWOW64mfc45.dll
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-02-28 bis 2014-03-30 ))))))))))))))))))))))))))))))
.
.
2014-03-29 15:28 . 2014-03-29 15:37 -------- d-----w- C:\FRST
2014-03-29 14:17 . 2014-03-29 14:17 32512 ------w- c:\windows\system32\drivers\hitmanpro37.sys
2014-03-29 13:20 . 2014-03-29 14:14 -------- d-----w- c:\programdata\HitmanPro
2014-03-28 18:29 . 2014-03-28 18:29 -------- d-----w- c:\program files (x86)\EVGA Precision X
2014-03-28 18:22 . 2014-03-28 18:23 -------- d-----w- c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition
2014-03-28 18:16 . 2014-03-28 18:16 -------- d-----w- c:\program files (x86)\Lavalys
2014-03-27 12:49 . 2014-03-27 12:49 -------- d-----w- c:\windows\system32\25DB~1
2014-03-24 19:53 . 2014-03-24 19:53 -------- d-----w- c:\users\Tobias\AppData\Local\EdgeOfReality
2014-03-23 15:46 . 2014-03-23 15:46 -------- d-----w- c:\users\Tobias\AppData\Roaming\com.valve.FTP
2014-03-21 19:18 . 2014-01-09 02:22 5694464 ----a-w- c:\windows\SysWow64\mstscax.dll
2014-03-21 19:18 . 2014-01-03 22:44 6574592 ----a-w- c:\windows\system32\mstscax.dll
2014-03-20 19:39 . 2014-03-20 19:39 -------- d-----w- c:\users\Tobias\AppData\Roaming\Unified Remote
2014-03-20 19:38 . 2014-03-20 19:38 -------- d-----w- c:\program files (x86)\Unified Remote
2014-03-20 18:26 . 2013-09-25 02:23 1030144 ----a-w- c:\windows\system32\TSWorkspace.dll
2014-03-20 18:26 . 2013-09-25 01:57 792576 ----a-w- c:\windows\SysWow64\TSWorkspace.dll
2014-03-12 15:26 . 2014-02-04 02:32 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-03-12 15:26 . 2014-02-04 02:32 624128 ----a-w- c:\windows\system32\qedit.dll
2014-03-12 15:26 . 2014-02-04 02:04 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2014-03-12 15:26 . 2014-02-04 02:04 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2014-03-11 16:15 . 2014-03-26 16:37 -------- d-----w- c:\program files (x86)\RivaTuner Statistics Server
2014-03-11 13:57 . 2014-03-11 13:57 -------- d-----w- c:\windows\system32\F9D6~1
2014-03-08 12:05 . 2014-03-08 12:05 -------- d-----w- c:\users\Tobias\AppData\Local\Skype
2014-03-08 12:04 . 2014-03-08 12:04 -------- d-----w- c:\program files (x86)\Common Files\Skype
2014-03-08 12:04 . 2014-03-08 12:04 -------- d-----r- c:\program files (x86)\Skype
2014-03-04 14:20 . 2014-03-04 14:20 -------- d-----w- c:\users\Tobias\AppData\Local\Epic_Games,_Inc
2014-03-03 23:20 . 2014-03-03 23:20 -------- d-----w- c:\users\Tobias\AppData\Local\{E2CDB563-0785-4A7A-89DA-3BED4B6A4183}
2014-03-03 23:19 . 2014-03-03 23:19 -------- d-----w- c:\users\Tobias\AppData\Local\{415C729F-7314-46CA-AB34-C6188AFAFA86}
2014-03-03 23:11 . 2014-03-03 23:11 -------- d-----w- C:\UDK
2014-03-03 17:35 . 2014-03-03 17:41 -------- d-----w- c:\users\Tobias\AppData\Roaming\3Dea
2014-03-03 17:35 . 2014-03-03 17:35 -------- d-----w- c:\program files\3Dea
2014-03-03 17:35 . 2014-03-03 17:35 -------- d-----w- c:\program files\Microsoft Kinect Drivers
2014-03-03 12:11 . 2014-03-03 12:11 -------- d-----w- c:\users\Tobias\AppData\Roaming\Apple Computer
2014-03-02 10:23 . 2014-03-02 10:23 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2014-03-02 10:23 . 2014-03-02 10:23 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2014-03-02 10:23 . 2014-03-02 10:23 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2014-03-02 10:23 . 2014-03-02 10:23 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2014-03-02 10:23 . 2014-03-02 10:23 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2014-03-02 10:23 . 2014-03-02 10:23 -------- d-----w- c:\program files (x86)\QuickTime
2014-03-02 10:23 . 2014-03-02 10:23 -------- d-----w- c:\programdata\Apple Computer
2014-03-01 21:36 . 2014-03-01 21:54 -------- d-----w- c:\users\Tobias\AppData\Local\immersive-explorer.com
2014-02-28 19:25 . 2014-03-01 15:29 -------- d-----w- c:\users\Tobias\AppData\Roaming\Awesomium
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-29 17:45 . 2012-12-27 18:19 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-03-29 17:41 . 2012-12-27 18:03 280904 ------w- c:\windows\SysWow64\PnkBstrB.exe
2014-03-20 18:56 . 2012-12-27 18:03 214392 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-03-16 18:19 . 2012-12-24 20:02 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-03-16 18:19 . 2012-12-24 20:02 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-03-16 12:48 . 2012-12-30 01:17 90015360 ----a-w- c:\windows\system32\MRT.exe
2014-02-16 17:10 . 2014-02-16 17:10 601360 ----a-w- c:\windows\system32\drivers\avckf.sys
2014-02-16 17:10 . 2014-02-16 16:34 150256 ------w- c:\windows\system32\drivers\gzflt.sys
2014-02-16 17:10 . 2014-02-16 17:10 76944 ----a-w- c:\windows\system32\drivers\bdvedisk.sys
2014-02-16 17:10 . 2014-02-16 16:34 389240 ------w- c:\windows\system32\drivers\trufos.sys
2014-02-16 17:10 . 2014-02-16 17:10 727592 ----a-w- c:\windows\system32\drivers\avc3.sys
2014-02-08 18:34 . 2014-02-20 07:50 61216 ----a-w- c:\windows\system32\OpenCL.dll
2014-02-08 18:34 . 2014-02-20 07:50 53024 ----a-w- c:\windows\SysWow64\OpenCL.dll
2014-02-08 18:34 . 2014-02-20 07:46 9690424 ----a-w- c:\windows\SysWow64\nvopencl.dll
2014-02-08 18:34 . 2014-02-20 07:46 892192 ----a-w- c:\windows\system32\NvIFR64.dll
2014-02-08 18:34 . 2014-02-20 07:46 875296 ----a-w- c:\windows\system32\NvFBC64.dll
2014-02-08 18:34 . 2014-02-20 07:46 863520 ----a-w- c:\windows\SysWow64\NvIFR.dll
2014-02-08 18:34 . 2014-02-20 07:46 844576 ----a-w- c:\windows\SysWow64\NvFBC.dll
2014-02-08 18:34 . 2014-02-20 07:46 31432480 ----a-w- c:\windows\system32\nvoglv64.dll
2014-02-08 18:34 . 2014-02-20 07:46 23683360 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2014-02-08 18:34 . 2014-02-20 07:46 18257576 ----a-w- c:\windows\system32\nvwgf2umx.dll
2014-02-08 18:34 . 2014-02-20 07:46 15740232 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2014-02-08 18:34 . 2014-02-20 07:46 12324640 ------w- c:\windows\system32\drivers\nvlddmkm.sys
2014-02-08 18:34 . 2014-02-20 07:46 11589272 ----a-w- c:\windows\system32\nvopencl.dll
2014-02-08 18:34 . 2014-02-20 07:46 9728064 ----a-w- c:\windows\SysWow64\nvcuda.dll
2014-02-08 18:34 . 2014-02-20 07:46 3142432 ----a-w- c:\windows\system32\nvcuvid.dll
2014-02-08 18:34 . 2014-02-20 07:46 3090184 ------w- c:\windows\system32\nvapi64.dll
2014-02-08 18:34 . 2014-02-20 07:46 2956576 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2014-02-08 18:34 . 2014-02-20 07:46 2782496 ----a-w- c:\windows\system32\nvcuvenc.dll
2014-02-08 18:34 . 2014-02-20 07:46 2713728 ----a-w- c:\windows\SysWow64\nvapi.dll
2014-02-08 18:34 . 2014-02-20 07:46 25256224 ----a-w- c:\windows\system32\nvcompiler.dll
2014-02-08 18:34 . 2014-02-20 07:46 2410784 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2014-02-08 18:34 . 2014-02-20 07:46 1885472 ----a-w- c:\windows\system32\nvdispco6433489.dll
2014-02-08 18:34 . 2014-02-20 07:46 17715784 ----a-w- c:\windows\system32\nvd3dumx.dll
2014-02-08 18:34 . 2014-02-20 07:46 17560352 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2014-02-08 18:34 . 2014-02-20 07:46 1515296 ----a-w- c:\windows\system32\nvdispgenco6433489.dll
2014-02-08 18:34 . 2014-02-20 07:46 14669032 ------w- c:\windows\SysWow64\nvd3dum.dll
2014-02-08 18:34 . 2014-02-20 07:46 11636176 ----a-w- c:\windows\system32\nvcuda.dll
2014-02-08 17:42 . 2014-02-20 07:51 3498272 ------w- c:\windows\system32\nvsvc64.dll
2014-02-08 17:42 . 2014-02-20 07:50 6712608 ----a-w- c:\windows\system32\nvcpl.dll
2014-02-08 17:42 . 2014-02-20 07:50 923936 ------w- c:\windows\system32\nvvsvc.exe
2014-02-08 17:42 . 2014-02-20 07:51 63776 ----a-w- c:\windows\system32\nvshext.dll
2014-02-08 17:42 . 2014-02-20 07:50 386336 ----a-w- c:\windows\system32\nvmctray.dll
2014-02-08 17:42 . 2014-02-20 07:50 2559776 ------w- c:\windows\system32\nvsvcr.dll
2014-02-08 16:18 . 2014-02-20 07:51 599840 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2014-02-05 09:31 . 2014-02-20 07:53 1048152 ------w- c:\windows\SysWow64\nvspcap.dll
2014-02-05 09:30 . 2014-02-20 07:53 1179576 ------w- c:\windows\system32\nvspcap64.dll
2014-01-26 13:24 . 2013-08-15 21:18 447752 ----a-w- c:\windows\SysWow64\vp6vfw.dll
2014-01-24 23:35 . 2014-01-25 10:04 4784312 ------w- c:\windows\SysWow64\GameMon.des
2014-01-19 07:33 . 2012-12-24 20:10 270496 ------w- c:\windows\system32\MpSigStub.exe
2014-01-17 15:24 . 2014-01-17 15:24 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2014-01-17 15:24 . 2014-01-17 15:24 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
2014-01-04 12:31 . 2014-01-04 12:31 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll
2014-01-03 16:16 . 2009-08-18 11:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2014-01-03 16:16 . 2009-08-18 10:24 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files (x86)\Internet Download Manager\IDMan.exe" [2014-02-21 3829328]
"WinPatrol"="c:\program files (x86)\BillP Studios\WinPatrol\winpatrol.exe" [2014-02-25 496192]
"Spotify Web Helper"="c:\users\Tobias\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2014-01-17 1171968]
"Unified Remote v2"="c:\program files (x86)\Unified Remote\RemoteServer.exe" [2014-03-19 333008]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"bdruninstaller"="c:\program files\Common Files\Bitdefender\SetupInformation\downloader\setuplauncher.exe" [2013-06-19 676568]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2014-01-17 421888]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SafeBox;SafeBox;c:\program files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe;c:\program files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 BDSandBox;BDSandBox;c:\windows\system32\drivers\bdsandbox.sys;c:\windows\SYSNATIVE\drivers\bdsandbox.sys [x]
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
R3 hitmanpro37;HitmanPro 3.7 Support Driver;c:\windows\system32\drivers\hitmanpro37.sys;c:\windows\SYSNATIVE\drivers\hitmanpro37.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys;c:\windows\SYSNATIVE\drivers\libusb0.sys [x]
R3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\DRIVERS\mcvidrv_x64.sys;c:\windows\SYSNATIVE\DRIVERS\mcvidrv_x64.sys [x]
R3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv_x64.sys;c:\windows\SYSNATIVE\drivers\mcaudrv_x64.sys [x]
R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys;c:\windows\SYSNATIVE\DRIVERS\MijXfilt.sys [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x]
R3 NVFLASH;NVFLASH;c:\windows\system32\drivers\nvflash.sys;c:\windows\SYSNATIVE\drivers\nvflash.sys [x]
R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [x]
R3 RTCore64;RTCore64;c:\program files (x86)\EVGA Precision X\RTCore64.sys;c:\program files (x86)\EVGA Precision X\RTCore64.sys [x]
R3 RZMAELSTROMVADService;Razer Surround Audio Enhancer Service;c:\windows\system32\drivers\RzMaelstromVAD.sys;c:\windows\SYSNATIVE\drivers\RzMaelstromVAD.sys [x]
R3 SWDUMon;SWDUMon;c:\windows\system32\DRIVERS\SWDUMon.sys;c:\windows\SYSNATIVE\DRIVERS\SWDUMon.sys [x]
R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x]
R3 tapoas;TAP-Win32 Adapter OAS;c:\windows\system32\DRIVERS\tapoas.sys;c:\windows\SYSNATIVE\DRIVERS\tapoas.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 XENfiltv;XENfiltv;c:\windows\system32\drivers\XENfiltv.sys;c:\windows\SYSNATIVE\drivers\XENfiltv.sys [x]
R4 BdDesktopParental;Bitdefender Desktop Parental Control;c:\program files\Bitdefender\Bitdefender 2013\bdparentalservice.exe;c:\program files\Bitdefender\Bitdefender 2013\bdparentalservice.exe [x]
S0 gzflt;gzflt;c:\windows\system32\DRIVERS\gzflt.sys;c:\windows\SYSNATIVE\DRIVERS\gzflt.sys [x]
S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S0 RzFilter;RzFilter;c:\windows\system32\drivers\RzFilter.sys;c:\windows\SYSNATIVE\drivers\RzFilter.sys [x]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys;SysWow64\drivers\AsUpIO.sys [x]
S1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 AgomoService;Agomo;c:\program files (x86)\Agomo\AgomoClient.exe;c:\program files (x86)\Agomo\AgomoClient.exe [x]
S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.18\atkexComSvc.exe;c:\program files (x86)\ASUS\AXSP\1.00.18\atkexComSvc.exe [x]
S2 ASGT;ASGT;c:\windows\SysWOW64\ASGT.exe;c:\windows\SysWOW64\ASGT.exe [x]
S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.16\aaHMSvc.exe;c:\program files (x86)\ASUS\AAHM\1.00.16\aaHMSvc.exe [x]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [x]
S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys;c:\windows\SYSNATIVE\DRIVERS\idmwfp.sys [x]
S2 KinectManagement;Kinect Management;c:\program files\Microsoft Kinect Drivers\Service\KinectManagementService.exe;c:\program files\Microsoft Kinect Drivers\Service\KinectManagementService.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 UPDATESRV;Bitdefender Desktop Update Service;c:\program files\Bitdefender\Bitdefender 2013\updatesrv.exe;c:\program files\Bitdefender\Bitdefender 2013\updatesrv.exe [x]
S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe;c:\windows\SYSNATIVE\viakaraokesrv.exe [x]
S3 cpuz136;cpuz136;c:\windows\TEMP\cpuz136\cpuz136_x64.sys;c:\windows\TEMP\cpuz136\cpuz136_x64.sys [x]
S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 RzDxgk;RzDxgk;c:\windows\system32\drivers\RzDxgk.sys;c:\windows\SYSNATIVE\drivers\RzDxgk.sys [x]
S3 USBMULCD;Aureon 7.1 USB Interface;c:\windows\system32\drivers\CM10664.sys;c:\windows\SYSNATIVE\drivers\CM10664.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-02-02 14:11 1211672 ------w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.102\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-03-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-24 18:19]
.
2013-12-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-12-24 19:55]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2012-11-15 23:07 23496 ------w- c:\program files (x86)\Internet Download Manager\IDMShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox1]
@="{152C96EB-288E-4EDC-B7C6-D21F8250ADF3}"
[HKEY_CLASSES_ROOT\CLSID\{152C96EB-288E-4EDC-B7C6-D21F8250ADF3}]
2013-02-27 14:43 269200 ------w- c:\program files\Bitdefender\Bitdefender SafeBox\safeboxshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox2]
@="{342DAA0B-D796-460D-8566-901E08A1CCAD}"
[HKEY_CLASSES_ROOT\CLSID\{342DAA0B-D796-460D-8566-901E08A1CCAD}]
2013-02-27 14:43 269200 ------w- c:\program files\Bitdefender\Bitdefender SafeBox\safeboxshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox3]
@="{57595DAE-1AE1-4D97-A49E-67CBB53B52DF}"
[HKEY_CLASSES_ROOT\CLSID\{57595DAE-1AE1-4D97-A49E-67CBB53B52DF}]
2013-02-27 14:43 269200 ------w- c:\program files\Bitdefender\Bitdefender SafeBox\safeboxshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox4]
@="{33816773-98AE-4723-ADE0-EBE54C8B5A67}"
[HKEY_CLASSES_ROOT\CLSID\{33816773-98AE-4723-ADE0-EBE54C8B5A67}]
2013-02-27 14:43 269200 ------w- c:\program files\Bitdefender\Bitdefender SafeBox\safeboxshell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cm106Sound"="c:\windows\Syswow64\cm106.dll" [2009-12-08 8151040]
"Bdagent"="c:\program files\Bitdefender\Bitdefender 2013\bdagent.exe" [2013-09-27 1575192]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-02-05 2234144]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-02-05 1179576]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-06-13 472984]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Bar = hxxp://www.google.com
IE: Download aller Links mit IDM - c:\program files (x86)\Internet Download Manager\IEGetAll.htm
IE: Download mit IDM - c:\program files (x86)\Internet Download Manager\IEExt.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.1.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-DriverMax_RESTART - (no file)
HKLM_Wow6432Node-ActiveSetup-{8A69D345-D564-463c-AFF1-A69D9E530F96} - c:\program files (x86)\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3249350345-894808183-506122138-1000\Software\Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):06,59,2a,8c,f2,21,1c,f1,e8,c2,71,b3,c7,6d,0f,b5,25,7f,b4,dc,5b,
68,87,58,c4,0f,6f,fe,e8,86,ae,6f,62,bc,d6,ca,1c,2d,99,cd,00,00,00,00,00,00,\
.
[HKEY_USERS\S-1-5-21-3249350345-894808183-506122138-1000\Software\Classes\Wow6432Node\CLSID\{f2b6e509-7db6-4d57-ae75-9db54603287d}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000058
"Therad"=dword:00000012
.
[HKEY_USERS\S-1-5-21-3249350345-894808183-506122138-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_USERS\S-1-5-21-3249350345-894808183-506122138-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:65,4b,ae,31,4a,20,bb,a0,28,13,6b,28,bf,10,20,7c,12,cf,30,8d,98,95,5f,
a3,f9,5c,7d,93,d7,ff,1c,76,a6,19,2f,f4,0c,33,73,2f,22,ab,e5,9b,4d,66,fa,26,\
"??"=hex:e2,06,90,c3,a9,ab,f7,ca,1c,f7,63,d7,3e,f2,89,5d
.
[HKEY_USERS\S-1-5-21-3249350345-894808183-506122138-1000\Software\SecuROM\License information*]
"datasecu"=hex:6b,53,4a,b3,df,57,c9,34,6d,07,79,70,40,23,a5,c0,89,c7,80,37,f1,
19,08,2c,2a,b6,f0,d8,76,c8,c9,5c,14,24,cb,97,c8,0d,16,f7,c9,49,d9,52,5b,8a,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_152_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_152_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{722b3793-5367-4446-b6bb-db89b05c1f24}\LocalServer32]
@DACL=(02 0000)
@=expand:"%SystemRoot%\\System32\\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {722b3793-5367-4446-b6bb-db89b05c1f24}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\ASUS\AI Suite II\AsRoutineController.exe
c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files (x86)\ASUS\AI Suite II\AI Suite II.exe
c:\program files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
c:\windows\SysWOW64\rundll32.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2014-03-30 13:13:11 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2014-03-30 11:13
.
Vor Suchlauf: 19 Verzeichnis(se), 48.197.296.128 Bytes frei
Nach Suchlauf: 24 Verzeichnis(se), 50.876.977.152 Bytes frei
.
- - End Of File - - 0EFF55A1D619AC72331FDDA2AF65BE88
A36C5E4F47E84449FF07ED3517B43A31 |