Solitron | 31.03.2014 11:53 | Hier die gewünschte C:\ComboFix.txt Code:
ComboFix 14-03-24.01 - tobi 31.03.2014 12:38:18.2.4 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.3327.2213 [GMT 2:00]
ausgeführt von:: c:\users\tobi\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\addplushd\adDPlushd-bho.dll
c:\programdata\dlprotect.exe
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0\51
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\background.html
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\chromeCoreFilesIndex.txt
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\crossriderManifest.json
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\manifest.xml
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins.json
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\1_base.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\102_dealply_m.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\103_intext_5_m.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\104_jollywallet_m.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\123_intext_adv_m.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\13_CrossriderAppUtils.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\14_CrossriderUtils.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\155_ibario_pops_m.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\17_jQuery.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\177_crossriderDashboard.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\179_revizer_p_dynamic_m.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\180_bpo_serp_m.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\182_openUrl.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\183_tabsWrapper.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\184_noproblemppc_m.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\19_CHAppAPIWrapper.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\190_pops_5_m.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\191_ciuvo_m.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\207_dbWrapper.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\21_debug.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\22_resources.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\220_icm_base_m.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\221_icm_downloads_m.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\223_imonomy_m.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\231_revizer_ws_dynamic_2_m.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\246_setup.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\28_initializer.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\4_jquery_1_7_1.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\47_resources_background.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\64_appApiMessage.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\7_hooks.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\72_appApiValidation.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\78_CrossriderInfo.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\80_CHPopupAppAPI.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\9_search_engine_hook.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\91_monetizationLoader.js.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\93_superfish_no_coupons_m.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins\97_resourceApiWrapper.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\userCode\background.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\userCode\extension.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\icons\actions\1.png
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\icons\icon128.png
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\icons\icon16.png
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\icons\icon48.png
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\api\chrome.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\api\cookie.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\api\message.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\api\monitor.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\api\pageAction.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\api\pageActionBG.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\background.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\app_api.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\bg_app_api.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\consts.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\cookie_store.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\crossriderAPI.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\delegate.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\events.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\extensionDataStore.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\installer.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\logFile.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\logging.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\onBGDocumentLoad.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\popupResource\newPopup.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\popupResource\popup.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\reports.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\storageWrapper.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\updateManager.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\util.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\xhr.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\main.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\platformVersion.js
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\manifest.json
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\popup.html
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000162.ldb
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000167.ldb
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000173.ldb
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000176.ldb
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000177.log
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\CURRENT
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\LOCK
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\LOG
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\LOG.old
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\MANIFEST-000175
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0.localstorage-journal
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0.localstorage
c:\users\tobi\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\users\tobi\AppData\Roaming\load_winupd.exe
c:\users\tobi\AppData\Roaming\youtube downloader.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-02-28 bis 2014-03-31 ))))))))))))))))))))))))))))))
.
.
2014-03-31 10:47 . 2014-03-31 10:47 -------- d-----w- c:\users\tobi\AppData\Local\temp
2014-03-31 10:47 . 2014-03-31 10:47 -------- d-----w- c:\users\Public\AppData\Local\temp
2014-03-31 10:47 . 2014-03-31 10:47 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-03-31 10:36 . 2014-03-31 10:36 39464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{71C05A62-9400-44B8-98E1-58EECA801114}\MpKsl24076ebc.sys
2014-03-30 21:35 . 2014-03-07 04:35 7969936 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{71C05A62-9400-44B8-98E1-58EECA801114}\mpengine.dll
2014-03-30 00:59 . 2014-03-30 01:16 107736 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-03-30 00:58 . 2014-03-05 08:26 51416 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-03-30 00:58 . 2014-03-05 08:26 73432 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-03-30 00:58 . 2014-03-05 08:26 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-03-29 19:53 . 2014-02-17 12:30 765968 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3DC107DD-C63E-488D-B619-97DA21A5239C}\gapaengine.dll
2014-03-29 19:53 . 2014-03-07 04:35 7969936 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-03-24 17:01 . 2014-03-24 17:01 -------- d-----w- c:\users\tobi\AppData\Local\Blizzard Entertainment
2014-03-24 17:01 . 2014-03-30 17:09 -------- d-----w- c:\users\tobi\AppData\Local\Battle.net
2014-03-24 17:01 . 2014-03-24 17:15 -------- d-----w- c:\users\tobi\AppData\Roaming\Battle.net
2014-03-24 17:00 . 2014-03-24 17:01 -------- d-----w- c:\programdata\Blizzard Entertainment
2014-03-24 16:58 . 2014-03-24 16:59 -------- d-----w- c:\programdata\Battle.net
2014-03-24 15:26 . 2014-03-24 15:26 -------- d-----w- c:\users\tobi\AppData\Local\webkit
2014-03-23 21:54 . 2014-03-23 21:58 2208 ----a-w- c:\windows\system32\ASOROSet.bin
2014-03-23 21:45 . 2014-03-23 22:04 -------- d-----w- c:\users\tobi\AppData\Roaming\Systweak
2014-03-23 21:45 . 2013-02-28 15:27 18776 ----a-w- c:\windows\system32\roboot.exe
2014-03-23 15:05 . 2014-03-23 15:05 -------- d-----w- c:\programdata\CDB
2014-03-22 22:14 . 2014-03-24 15:27 -------- d-----w- c:\users\tobi\AppData\Local\gtk-2.0
2014-03-22 22:11 . 2014-03-22 22:11 -------- d-----w- c:\users\tobi\.thumbnails
2014-03-22 22:09 . 2014-03-22 22:09 -------- d-----w- c:\users\tobi\AppData\Local\fontconfig
2014-03-22 22:09 . 2014-03-24 15:31 -------- d-----w- c:\users\tobi\.gimp-2.8
2014-03-22 22:09 . 2014-03-22 22:09 -------- d-----w- c:\users\tobi\AppData\Local\gegl-0.2
2014-03-22 22:01 . 2014-03-22 22:03 -------- d-----w- c:\program files\GIMP 2
2014-03-22 22:01 . 2014-03-22 22:01 -------- d-----w- c:\users\tobi\AppData\Roaming\BupSystem
2014-03-22 22:01 . 2014-03-23 17:05 -------- d-----w- c:\users\tobi\AppData\Roaming\Security System 2
2014-03-22 22:00 . 2014-03-31 10:46 -------- d-----w- c:\program files\addplushd
2014-03-22 22:00 . 2014-03-23 21:30 -------- d-----w- c:\program files\ResultsAlpha
2014-03-22 21:57 . 2014-03-22 22:00 -------- d-----w- c:\users\tobi\AppData\Local\DownloadGuide
2014-03-19 13:33 . 2013-12-21 08:56 454656 ----a-w- c:\windows\system32\vbscript.dll
2014-03-18 21:14 . 2014-03-18 21:14 71680 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2014-03-18 21:12 . 2014-03-30 22:39 -------- d-----w- c:\users\UpdatusUser
2014-03-18 21:08 . 2013-10-01 23:45 32256 ----a-w- c:\windows\system32\TsUsbGDCoInstaller.dll
2014-03-18 21:08 . 2013-10-02 00:32 12800 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-03-18 21:08 . 2013-10-02 00:42 49152 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys
2014-03-18 21:08 . 2013-10-02 00:30 14336 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-03-18 21:08 . 2013-10-02 00:14 50176 ----a-w- c:\windows\system32\MsRdpWebAccess.dll
2014-03-18 21:08 . 2013-10-02 00:14 17920 ----a-w- c:\windows\system32\wksprtPS.dll
2014-03-18 21:08 . 2013-10-01 23:58 53248 ----a-w- c:\windows\system32\tsgqec.dll
2014-03-18 21:08 . 2013-10-01 23:08 855552 ----a-w- c:\windows\system32\rdvidcrl.dll
2014-03-18 21:08 . 2013-10-01 23:00 76288 ----a-w- c:\windows\system32\TSWbPrxy.exe
2014-03-18 21:08 . 2013-10-01 22:53 350208 ----a-w- c:\windows\system32\wksprt.exe
2014-03-18 21:08 . 2013-10-01 22:34 1068544 ----a-w- c:\windows\system32\mstsc.exe
2014-03-16 21:55 . 2014-03-16 21:55 -------- d-----w- c:\users\tobi\AppData\Local\Arktos Entertainment
2014-03-16 21:52 . 2014-03-16 21:52 291128 ----a-w- c:\windows\system32\PnkBstrB.xtr
2014-03-16 21:52 . 2014-03-16 21:52 -------- d-----w- c:\users\tobi\AppData\Local\PunkBuster
2014-03-16 21:52 . 2014-03-16 21:52 -------- d-----w- c:\users\tobi\AppData\Local\Arktos
2014-03-16 21:52 . 2014-03-16 21:52 -------- d-----w- c:\users\tobi\AppData\Local\CrashRpt
2014-03-16 21:42 . 2014-03-16 21:52 139528 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2014-03-16 21:42 . 2014-03-16 21:42 138904 ----a-w- c:\users\tobi\AppData\Roaming\PnkBstrK.sys
2014-03-16 21:42 . 2014-03-16 21:52 291128 ----a-w- c:\windows\system32\PnkBstrB.exe
2014-03-16 21:42 . 2014-03-16 21:42 281872 ----a-w- c:\windows\system32\PnkBstrB.ex0
2014-03-16 21:42 . 2014-03-16 21:42 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2014-03-11 22:25 . 2014-03-11 22:25 5777288 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2014-03-11 20:30 . 2014-02-04 02:04 509440 ----a-w- c:\windows\system32\qedit.dll
2014-03-11 20:30 . 2014-01-28 02:07 185344 ----a-w- c:\windows\system32\wwansvc.dll
2014-03-11 20:30 . 2014-02-07 01:07 2349056 ----a-w- c:\windows\system32\win32k.sys
2014-03-11 20:30 . 2014-02-04 02:04 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-03-11 20:30 . 2014-01-29 02:06 381440 ----a-w- c:\windows\system32\wer.dll
2014-03-03 00:09 . 2014-03-03 00:09 -------- d-----w- c:\users\tobi\AppData\Roaming\steamvr
2014-03-02 17:52 . 2014-03-02 17:52 -------- d-----w- c:\users\tobi\AppData\Local\Skype
2014-03-02 17:52 . 2014-03-02 17:52 -------- d-----w- c:\program files\Common Files\Skype
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-11 22:25 . 2012-08-02 01:33 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-03-11 22:25 . 2011-07-07 19:03 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-02-18 14:52 . 2014-02-18 14:52 851176 ----a-w- c:\windows\system32\WinUSBCoInstaller2.dll
2014-02-18 14:52 . 2014-02-18 14:52 1461992 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2014-02-17 12:30 . 2014-02-28 19:35 765968 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-02-06 07:08 . 2014-02-21 14:43 7947048 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C0B26EA4-B0DB-4251-8F7A-B6B8C2E2383D}\mpengine.dll
2014-01-19 07:32 . 2011-07-07 12:54 231584 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WSHelperSetup.exe"="c:\program files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe" [2013-07-25 1985824]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2014-02-18 689744]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"WSHelperSetup.exe"="c:\program files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe" [2013-07-25 1985824]
"Wondershare Helper Compact.exe"="c:\program files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe" [2013-07-25 1985824]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 948440]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2014-02-21 152392]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^LOLRecorder.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\LOLRecorder.lnk
backup=c:\windows\pss\LOLRecorder.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Tobi^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
path=c:\users\Tobi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApplePhotoStreams]
2013-11-20 14:43 59720 ----a-w- d:\apple\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2014-02-05 23:52 43848 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVSSkypeRecorder]
2013-08-27 11:40 821416 ----a-w- c:\program files\DVDVideoSoft\Free Video Call Recorder for Skype\skyui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2013-04-02 00:50 138096 ----atw- c:\users\tobi\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlyForHeroInstaller]
2012-10-12 15:22 5856256 ----a-w- c:\users\tobi\AppData\Roaming\FlyForHeroInstaller\FlyForHeroInstaller.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iCloudServices]
2013-11-20 14:43 59720 ----a-w- d:\apple\Common Files\Apple\Internet Services\iCloudServices.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2014-02-21 02:54 152392 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWS]
2011-11-11 12:08 205336 ----a-w- c:\program files\Logitech\LWS\Webcam Software\LWS.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2014-02-10 16:46 20922016 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Speech Recognition]
2009-07-14 01:14 51712 ----a-w- c:\windows\Speech\Common\sapisvr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2013-07-02 08:16 254336 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
R3 apf003;apf003;c:\windows\system32\apf003.sys [2013-05-29 13232]
R3 cpuz134;cpuz134;c:\users\tobi\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [x]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-03-01 108032]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-11-19 37352]
S1 HssDRV6;Hotspot Shield Routing Driver 6;c:\windows\system32\DRIVERS\hssdrv6.sys [2012-08-01 35560]
S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2014-02-18 440400]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - MPKSL24076EBC
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-03-15 19:46 1150280 ----a-w- c:\program files\Google\Chrome\Application\33.0.1750.154\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-03-31 c:\windows\Tasks\addplushd-chromeinstaller.job
- c:\program files\addplushd\addplushd-chromeinstaller.exe [2014-03-22 22:00]
.
2014-03-31 c:\windows\Tasks\addplushd-codedownloader.job
- c:\program files\addplushd\addplushd-codedownloader.exe [2014-03-22 22:01]
.
2014-03-31 c:\windows\Tasks\addplushd-enabler.job
- c:\program files\addplushd\addplushd-enabler.exe [2014-03-22 22:01]
.
2014-03-31 c:\windows\Tasks\addplushd-firefoxinstaller.job
- c:\program files\addplushd\addplushd-firefoxinstaller.exe [2014-03-22 22:01]
.
2014-03-31 c:\windows\Tasks\addplushd-updater.job
- c:\program files\addplushd\addplushd-updater.exe [2014-03-22 22:01]
.
2014-03-30 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-02 22:25]
.
2014-03-30 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1740813220-741005101-994693073-1006Core.job
- c:\users\tobi\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-04-02 00:50]
.
2014-03-30 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1740813220-741005101-994693073-1006UA.job
- c:\users\tobi\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-04-02 00:50]
.
2014-03-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-11-03 13:02]
.
2014-03-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-11-03 13:02]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = <local>;*.local
uSearchAssistant = hxxp://www.bing.com/search?q={searchTerms}
Trusted Zone: aeriagames.com
TCP: DhcpNameServer = 192.168.2.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM-Run-Download Protect - c:\programdata\dlprotect.exe
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
MSConfigStartUp-HDAudDeck - c:\program files\VIA\VIAudioi\VDeck\VDeck.exe
MSConfigStartUp-KPeerNexonEU - c:\nexon\NEXON_EU_Downloader\nxEULauncher.exe
MSConfigStartUp-LogMeIn Hamachi Ui - c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe
MSConfigStartUp-Overwolf - c:\program files\Overwolf\Overwolf.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:00,cb,2c,17,77,54,ce,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ee,eb,06,df,6d,58,42,41,95,c6,ff,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ee,eb,06,df,6d,58,42,41,95,c6,ff,\
.
[HKEY_USERS\S-1-5-21-1740813220-741005101-994693073-1006\Software\SecuROM\License information*]
"datasecu"=hex:ca,27,64,1b,9d,aa,9b,0c,bb,16,3d,0f,c4,6f,15,8b,89,61,58,a9,42,
f8,0e,e3,e9,6f,d8,f6,07,b6,a3,dc,4a,c2,16,cc,e9,c8,b0,cd,6c,97,86,8f,8a,9b,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{722b3793-5367-4446-b6bb-db89b05c1f24}\LocalServer32]
@DACL=(02 0000)
@=expand:"%SystemRoot%\\System32\\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {722b3793-5367-4446-b6bb-db89b05c1f24}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-03-31 12:49:33
ComboFix-quarantined-files.txt 2014-03-31 10:49
ComboFix2.txt 2012-10-11 23:45
.
Vor Suchlauf: 12 Verzeichnis(se), 29.377.298.432 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 30.953.422.848 Bytes frei
.
- - End Of File - - A8F5332750A704052AED3335127B74E1
A36C5E4F47E84449FF07ED3517B43A31 |