DonJuanito | 16.04.2014 12:58 | Ok sorry, dann poste ich die Texte gleich in mehreren post's.
Bin eben neu hier ;)
Was kann es denn für Auswirkungen haben das ich jetzt ComboFix ausgeführt hatte ? Hier die Log Files Adw Cleaner (29.03.14) Code:
# AdwCleaner v3.022 - Report created 29/03/2014 at 12:29:50
# Updated 13/03/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : JuraJula - PCJURAJULA
# Running from : C:\Users\JuraJula\Downloads\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\smarttweak
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Mozilla Firefox v28.0 (de)
[ File : C:\Users\JuraJula\AppData\Roaming\Mozilla\Firefox\Profiles\w6098u8m.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [859 octets] - [29/03/2014 12:29:07]
AdwCleaner[S0].txt - [739 octets] - [29/03/2014 12:29:50]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [798 octets] ##########
Junkware Removal Tool (29.03.14) Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Ultimate x64
Ran by JuraJula on 29.03.2014 at 12:37:43,09
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\JuraJula\AppData\Roaming\microsoft\windows\start menu\programs\smarttweak software"
~~~ FireFox
Emptied folder: C:\Users\JuraJula\AppData\Roaming\mozilla\firefox\profiles\w6098u8m.default\minidumps [1 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 29.03.2014 at 12:41:07,67
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Malwarebytes Anti-Malware (29.03.14 Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 29.03.2014
Scan Time: 11:16:41
Logfile: VIRUS LOG 1.txt
Administrator: Yes
Version: 2.00.0.1000
Malware Database: v2014.03.29.01
Rootkit Database: v2014.03.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Chameleon: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: JuraJula
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 241962
Time Elapsed: 5 min, 17 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 28
Trojan.Dropped, C:\Users\Default\AppData\Local\Temp\RarSFX0\System speed\DrWatsonDisable\Instal.exe, Quarantined, [20e5ed1cb9c2d85e74709fca07facc34],
Trojan.Dropped, C:\Users\Default\AppData\Local\Temp\RarSFX0\System speed\DrWatsonDisable\Uninstal.exe, Quarantined, [0cf9fc0db7c459ddab395514bf4213ed],
Trojan.Dropped, C:\Users\Default\AppData\Local\Temp\RarSFX0\System speed\Hiber_off\Instal.exe, Quarantined, [0005a8615f1c86b0756f34352dd4cc34],
Trojan.Dropped, C:\Users\Default\AppData\Local\Temp\RarSFX0\System speed\Hiber_off\Uninstal.exe, Quarantined, [a85dde2b5b2038fe14d0f970bd44e020],
Trojan.Dropped, C:\Users\Default\AppData\Local\Temp\RarSFX0\System speed\IRQ8Priority\Instal.exe, Quarantined, [fb0a0efb4a3105317e669ccdd031fc04],
Trojan.Dropped, C:\Users\Default\AppData\Local\Temp\RarSFX0\System speed\IRQ8Priority\Uninstal.exe, Quarantined, [ba4b11f81f5c91a5885c91d8e31ed32d],
Trojan.Dropped, C:\Users\Default\AppData\Local\Temp\RarSFX0\System speed\LargeSystemCache\Instal.exe, Quarantined, [c045fa0f205b1224c61efe6b9e6321df],
Trojan.Dropped, C:\Users\Default\AppData\Local\Temp\RarSFX0\System speed\LargeSystemCache\Uninstal.exe, Quarantined, [d2336d9cb4c7102616ced2973cc5817f],
Trojan.Dropped, C:\Users\Default\AppData\Local\Temp\RarSFX0\System speed\NoReport\Instal.exe, Quarantined, [a85d20e9dd9e280e4e963831d03123dd],
Trojan.Dropped, C:\Users\Default\AppData\Local\Temp\RarSFX0\System speed\NoReport\Uninstal.exe, Quarantined, [966f1eebadcead89f3f1254450b1b749],
Trojan.Dropped, C:\Users\Default\AppData\Local\Temp\RarSFX0\System speed\PagingExecutive\Instal.exe, Quarantined, [61a4c544007b11250ada6ffaae5354ac],
Trojan.Dropped, C:\Users\Default\AppData\Local\Temp\RarSFX0\System speed\PagingExecutive\Uninstal.exe, Quarantined, [9a6bdb2e6219ec4ae9fbb7b2d22f9b65],
Trojan.Dropped, C:\Users\Default\AppData\Local\Temp\RarSFX0\System speed\UAC_off\Instal.exe, Quarantined, [ea1bc148abd09d99d01444252cd55ca4],
Trojan.Dropped, C:\Users\Default\AppData\Local\Temp\RarSFX0\System speed\UAC_off\Uninstal.exe, Quarantined, [788d6c9d4b3075c1568e76f3867bbc44],
Trojan.Dropped, C:\Users\JuraJula\AppData\Local\Temp\RarSFX0\System speed\DrWatsonDisable\Instal.exe, Quarantined, [ff068683a2d93df922c282e7f40d1de3],
Trojan.Dropped, C:\Users\JuraJula\AppData\Local\Temp\RarSFX0\System speed\DrWatsonDisable\Uninstal.exe, Quarantined, [61a4dc2d43380333598b2b3e2cd52fd1],
Trojan.Dropped, C:\Users\JuraJula\AppData\Local\Temp\RarSFX0\System speed\Hiber_off\Instal.exe, Quarantined, [44c1c8416417e155df0574f554ad4ab6],
Trojan.Dropped, C:\Users\JuraJula\AppData\Local\Temp\RarSFX0\System speed\Hiber_off\Uninstal.exe, Quarantined, [eb1ab158d3a8d26424c084e5ce334cb4],
Trojan.Dropped, C:\Users\JuraJula\AppData\Local\Temp\RarSFX0\System speed\IRQ8Priority\Instal.exe, Quarantined, [49bcea1f97e4c2748d57aebb8081c838],
Trojan.Dropped, C:\Users\JuraJula\AppData\Local\Temp\RarSFX0\System speed\IRQ8Priority\Uninstal.exe, Quarantined, [9570a366aecdb2845b89a3c62cd5a759],
Trojan.Dropped, C:\Users\JuraJula\AppData\Local\Temp\RarSFX0\System speed\LargeSystemCache\Instal.exe, Quarantined, [0ef748c1e7948aac3ba982e77f825aa6],
Trojan.Dropped, C:\Users\JuraJula\AppData\Local\Temp\RarSFX0\System speed\LargeSystemCache\Uninstal.exe, Quarantined, [db2a0ffae09bd264a2425316c53c9a66],
Trojan.Dropped, C:\Users\JuraJula\AppData\Local\Temp\RarSFX0\System speed\NoReport\Instal.exe, Quarantined, [7b8a13f6fb8042f4dc08f277e41de31d],
Trojan.Dropped, C:\Users\JuraJula\AppData\Local\Temp\RarSFX0\System speed\NoReport\Uninstal.exe, Quarantined, [46bfc346e9929e98c32127428e73837d],
Trojan.Dropped, C:\Users\JuraJula\AppData\Local\Temp\RarSFX0\System speed\PagingExecutive\Instal.exe, Quarantined, [20e5e425cdaefe38954f4b1e857c4fb1],
Trojan.Dropped, C:\Users\JuraJula\AppData\Local\Temp\RarSFX0\System speed\PagingExecutive\Uninstal.exe, Quarantined, [b055e227f18aaf8700e4e287728fba46],
Trojan.Dropped, C:\Users\JuraJula\AppData\Local\Temp\RarSFX0\System speed\UAC_off\Instal.exe, Quarantined, [33d267a2b1caac8a667e096047bafa06],
Trojan.Dropped, C:\Users\JuraJula\AppData\Local\Temp\RarSFX0\System speed\UAC_off\Uninstal.exe, Quarantined, [02038683ef8c9e98a53fbeab20e121df],
Physical Sectors: 0
(No malicious items detected)
(end) Combo Fix (29.03.14 Code:
ComboFix 14-03-24.01 - JuraJula 29.03.2014 12:05:56.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1251.7.1049.18.3959.2396 [GMT 0:00]
Running from: c:\users\JuraJula\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2014-02-28 to 2014-03-29 )))))))))))))))))))))))))))))))
.
.
2014-03-29 11:41 . 2014-03-29 11:41 -------- d-----w- c:\programdata\HP
2014-03-29 11:08 . 2007-10-22 03:37 17928 ----a-w- c:\windows\SysWow64\X3DAudio1_2.dll
2014-03-29 01:38 . 2014-03-29 01:38 -------- d-----w- c:\program files (x86)\SmartDVB
2014-03-29 00:53 . 2014-03-29 00:53 -------- d-----w- c:\program files\CCleaner
2014-03-29 00:24 . 2014-03-29 00:24 -------- d-----w- c:\programdata\DBC2F6FD-3140-41E0-A2A1-D6BAB77D5E21_97A6E9190B374845A2EEEC5B058B8C9F_F893F7CA-8278-41DF-A76F-CAF0437A90CD__
2014-03-29 00:23 . 2014-03-29 00:23 -------- d-----w- c:\program files (x86)\DVBViewer Demo
2014-03-29 00:23 . 2014-03-29 00:23 -------- d-----w- c:\programdata\CMUV
2014-03-28 22:56 . 2014-03-28 22:56 164864 -c--a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
2014-03-28 22:56 . 2014-03-28 22:56 167424 -c--a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-03-28 22:56 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2014-03-28 22:56 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL
2014-03-28 22:56 . 2014-03-28 22:56 14631424 -c--a-w- c:\windows\system32\wmp.dll
2014-03-28 22:53 . 2014-03-28 22:53 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2014-03-28 22:50 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2014-03-28 22:49 . 2014-03-28 22:49 548864 -c--a-w- c:\windows\system32\vbscript.dll
2014-03-28 22:49 . 2014-03-28 22:49 454656 -c--a-w- c:\windows\SysWow64\vbscript.dll
2014-03-28 22:48 . 2014-03-28 22:48 -------- d-----w- c:\windows\de-DE
2014-03-28 22:47 . 2014-03-28 22:47 -------- d-----w- c:\windows\SysWow64\drivers\UMDF\de-DE
2014-03-28 22:47 . 2014-03-28 22:47 -------- d-----w- c:\windows\SysWow64\drivers\de-DE
2014-03-28 22:47 . 2014-03-28 22:47 -------- d-----w- c:\windows\SysWow64\0407
2014-03-28 22:47 . 2014-03-28 22:47 -------- d-----w- c:\windows\SysWow64\de
2014-03-28 22:47 . 2014-03-28 22:57 -------- d-----w- c:\windows\SysWow64\wbem\de-DE
2014-03-28 22:47 . 2014-03-28 22:47 -------- d-----w- c:\windows\system32\0407
2014-03-28 22:47 . 2014-03-28 22:57 -------- d-----w- c:\windows\system32\drivers\de-DE
2014-03-28 22:47 . 2014-03-28 22:47 -------- d-----w- c:\windows\system32\drivers\UMDF\de-DE
2014-03-28 22:46 . 2014-03-28 22:46 -------- d-----w- c:\windows\system32\de
2014-03-28 22:46 . 2014-03-28 22:57 -------- d-----w- c:\windows\system32\wbem\de-DE
2014-03-28 22:42 . 2014-03-28 22:50 3928064 -c--a-w- c:\windows\system32\d2d1.dll
2014-03-28 22:41 . 2014-03-28 22:49 202752 -c--a-w- c:\windows\system32\scrrun.dll
2014-03-28 22:41 . 2014-03-28 22:49 168960 -c--a-w- c:\windows\system32\wscript.exe
2014-03-28 22:41 . 2014-03-28 22:49 163840 -c--a-w- c:\windows\SysWow64\scrrun.dll
2014-03-28 22:41 . 2014-03-28 22:49 156160 -c--a-w- c:\windows\system32\cscript.exe
2014-03-28 22:41 . 2014-03-28 22:49 150016 -c--a-w- c:\windows\system32\wshom.ocx
2014-03-28 22:41 . 2014-03-28 22:49 141824 -c--a-w- c:\windows\SysWow64\wscript.exe
2014-03-28 22:41 . 2014-03-28 22:49 126976 -c--a-w- c:\windows\SysWow64\cscript.exe
2014-03-28 22:41 . 2014-03-28 22:49 121856 -c--a-w- c:\windows\SysWow64\wshom.ocx
2014-03-28 22:41 . 2014-03-28 22:49 1643520 -c--a-w- c:\windows\system32\DWrite.dll
2014-03-28 22:41 . 2014-03-28 22:49 1247744 -c--a-w- c:\windows\SysWow64\DWrite.dll
2014-03-28 22:40 . 2014-03-28 22:49 1424384 -c--a-w- c:\windows\system32\WindowsCodecs.dll
2014-03-28 22:40 . 2014-03-28 22:49 1230336 -c--a-w- c:\windows\SysWow64\WindowsCodecs.dll
2014-03-28 22:20 . 2014-03-28 22:20 -------- d-----w- C:\AWLCD_WORK
2014-03-28 19:15 . 2014-03-29 12:13 42496 ----a-w- c:\windows\system32\drivers\oem-drv64.sys
2014-03-28 19:15 . 2014-03-28 19:15 -------- d-----w- c:\windows\system32\OEM
2014-03-28 18:51 . 2014-03-28 18:51 -------- d-----w- c:\programdata\Intel
2014-03-28 18:49 . 2014-03-28 18:49 -------- d-----w- C:\Intel
2014-03-28 18:48 . 2012-09-19 03:57 881808 ----a-w- c:\windows\system32\RtkApi64.dll
2014-03-28 18:46 . 2012-09-19 03:57 62784 ----a-w- c:\windows\system32\drivers\HECIx64.sys
2014-03-28 18:45 . 2012-09-19 03:57 690832 ----a-w- c:\windows\system32\drivers\Rt630x64.sys
2014-03-28 18:45 . 2012-09-19 03:57 74344 ----a-w- c:\windows\system32\RtNicProp64.dll
2014-03-28 18:39 . 2014-03-28 18:48 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
2014-03-28 18:39 . 2014-03-28 18:39 -------- d-----w- c:\programdata\Ralink Driver
2014-03-28 18:31 . 2014-03-28 18:31 -------- d-----w- c:\users\JuraJula
2014-03-28 18:31 . 2013-12-12 06:31 5549504 ----a-w- c:\windows\system32\xNtKrnl.exe
2014-03-28 18:31 . 2013-12-06 14:59 488584 ----a-w- c:\windows\system32\comparevers.exe
2014-03-28 18:31 . 2011-02-05 17:06 605552 ----a-w- c:\windows\system32\xOsLoad.exe
2014-03-28 18:30 . 2014-03-28 18:30 -------- d-sh--we c:\users\Default\Шаблоны
2014-03-28 18:30 . 2014-03-28 18:30 -------- d-sh--we c:\users\Default\Мои документы
2014-03-28 18:30 . 2014-03-28 18:30 -------- d-sh--we c:\users\Default\Главное меню
2014-03-28 18:30 . 2014-03-28 18:30 -------- d-sh--we c:\users\Все пользователи
2014-03-28 18:30 . 2014-03-28 18:30 -------- d-sh--we c:\programdata\Шаблоны
2014-03-28 18:30 . 2014-03-28 18:30 -------- d-sh--we c:\programdata\Избранное
2014-03-28 18:30 . 2014-03-28 18:30 -------- d-sh--we c:\programdata\Рабочий стол
2014-03-28 18:30 . 2014-03-28 18:30 -------- d-sh--we c:\programdata\Документы
2014-03-28 18:30 . 2014-03-28 18:30 -------- d-sh--we c:\programdata\Главное меню
2014-03-28 18:30 . 2014-03-28 18:30 -------- d-----w- C:\Recovery
2014-03-28 18:29 . 2014-03-29 02:07 -------- d-----w- c:\windows\rescache
2014-03-28 18:19 . 2014-01-16 05:46 -------- d-----w- c:\users\Default\AppData\Roaming\Auslogics
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-16 13:54 . 2014-01-16 13:54 8338432 ----a-w- c:\windows\system32\spwizimg.dll
2014-01-16 13:53 . 2014-01-16 13:53 8338432 ----a-w- c:\windows\SysWow64\spwizimg.dll
2014-01-16 13:44 . 2014-01-16 13:44 27214336 ----a-w- c:\windows\SysWow64\imageres.dll
2014-01-16 13:43 . 2014-01-16 13:43 93944832 ----a-w- c:\windows\system32\imageres.dll
2014-01-16 04:25 . 2009-07-13 23:54 44544 ----a-w- c:\windows\system32\themeservice.dll
2014-01-16 04:25 . 2010-11-21 03:23 2851840 ----a-w- c:\windows\system32\themeui.dll
2014-01-16 04:25 . 2009-07-13 23:55 332288 ----a-w- c:\windows\system32\uxtheme.dll
2014-01-16 04:20 . 2014-01-16 04:20 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-01-16 04:20 . 2014-01-16 04:20 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2013-11-24 . 54F3947A7F8F34BEBB95C356F29C3CFA . 3094528 . . [6.1.7600.16385] .. c:\windows\explorer.exe
[7] 2013-11-24 . 332FEAB1435662FC6C672E25BEB37BE3 . 2871808 . . [6.1.7601.17567] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[7] 2013-11-24 . 3B69712041F3D63605529BD66DC00C48 . 2871808 . . [6.1.7601.21669] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[7] 2010-11-21 . AC4C51EB24AA95B77F705AB159189E24 . 2872320 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled\
RocketDock.lnk - c:\program files (x86)\Racy Skin Pack\RocketDock\RocketDock.exe [2007-9-2 495616]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.362.0\SeaPort.exe;c:\program files (x86)\Microsoft\BingBar\7.1.362.0\SeaPort.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
R3 Synth3dVsc;Microsoft Virtual 3D Video Transport Driver;c:\windows\system32\drivers\Synth3dVsc.sys;c:\windows\SYSNATIVE\drivers\Synth3dVsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;Remote Deskotop USB Hub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
S0 oem-drv64;OEM-SLP2.1 Driver (HPD64);c:\windows\system32\DRIVERS\oem-drv64.sys;c:\windows\SYSNATIVE\DRIVERS\oem-drv64.sys [x]
S2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.362.0\BBSvc.exe;c:\program files (x86)\Microsoft\BingBar\7.1.362.0\BBSvc.exe [x]
S3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x]
S3 IntcDAud;Аудио Intel(R) для дисплеев;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 IT9135BDA;IT9135 BDA Devices;c:\windows\system32\Drivers\IT9135BDA.sys;c:\windows\SYSNATIVE\Drivers\IT9135BDA.sys [x]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPSDRV
*NewlyCreated* - WS2IFSL
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-09-19 13192848]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-09-19 170304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-09-19 398656]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-09-19 441152]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.44.1
FF - ProfilePath - c:\users\JuraJula\AppData\Roaming\Mozilla\Firefox\Profiles\w6098u8m.default\
FF - prefs.js: browser.startup.homepage - google.de
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-IT9130 DriverInstaller_12.2.3.1 - c:\temp\\DriverInstall64.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_38_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_38_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_38_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_38_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{6EF568F4-D437-4466-AA63-A3645136D93E}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}]
@Denied: (A 2) (Everyone)
@="IFlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib]
@="{6EF568F4-D437-4466-AA63-A3645136D93E}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]
@Denied: (A 2) (Everyone)
@="IFlashBroker2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]
@="{6EF568F4-D437-4466-AA63-A3645136D93E}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2014-03-29 12:15:43 - machine was rebooted
ComboFix-quarantined-files.txt 2014-03-29 12:15
.
Pre-Run: 9 Verzeichnis(se), 124.618.416.128 Bytes frei
Post-Run: 15 Verzeichnis(se), 124.476.764.160 Bytes frei
.
- - End Of File - - A3403DBC5A692B216C5808F86034831F
A36C5E4F47E84449FF07ED3517B43A31 |