Hallo,
zunächst erstmal vielen, vielen Dank für die schnelle Bearbeitung. Ich hatte wirklich nicht damit gerechnet, heute noch eine Antwort zu bekommen. Das ist wirklich großartig.
Ich habe die Schritte wie beschrieben ausgeführt. Tatsächlich erschien beim Start von CombiFix eine Fehlermeldung, dass Avira noch aktiviert sei, obwohl ich es abgeschaltet hatte.
Sie sah folgendermaßen aus:
"CombiFix hat festgestellt das folgende Real-Time-Scanner aktiv sind:
antivirus: Avira Desktop
antispyware: Avira Desktop
Antivirus und Eindringling Schutzprogramme sind dafuer bekannt,
dass sie die Arbeit von ComboFix behindern. Dies kann zu
unvorhersehbaren Ergebnissen oder eventuellen. PC Schaden fuehren.
Bitte deaktiviere diese Scanner, bevor Du auf 'OK' klickst."
Wie in der Anleitung beschrieben habe ich diese Meldung missachtet und auf OK geklickt. Das Programm hat daraufhin seine Arbeit ohne Zwischenfälle verrichtet. Die zweite in der Beschreibung angegebene Fehlermeldung erschien nicht.
Wie gewünscht ist hier die entstandene Log-File:
Combofix Logfile: Code:
ComboFix 14-06-09.01 - Elias 09.06.2014 21:57:38.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4061.2687 [GMT 2:00]
ausgeführt von:: c:\users\Elias\Desktop\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\program files (x86)\Common Files\ASPG_icon.ico
c:\program files (x86)\Warner Bros. Digital Copy Manager\Warner Bros. Digital Copy Manager.exe
c:\users\Elias\AppData\Local\7fe5b999\U
c:\users\Elias\AppData\Local\7fe5b999\U\80000000.@
c:\users\Elias\AppData\Local\7fe5b999\U\800000cb.@
c:\users\Elias\AppData\Local\7fe5b999\U\800000cf.@
c:\users\Elias\AppData\Local\lame_enc.dll
c:\users\Elias\AppData\Local\no23xwrapper.dll
c:\users\Elias\AppData\Local\ogg.dll
c:\users\Elias\AppData\Local\vorbis.dll
c:\users\Elias\AppData\Local\vorbisenc.dll
c:\users\Elias\AppData\Local\vorbisfile.dll
c:\users\Elias\AppData\Roaming\MafiaSetup.exe
c:\users\Public\invokesi.exe
c:\windows\assembly\tmp\U
c:\windows\IsUn0407.exe
c:\windows\msvcr71.dll
c:\windows\SysWOW64\C2MP\TrayMenu.exe
c:\windows\SysWow64\Packet.dll
c:\windows\SysWow64\pthreadVC.dll
c:\windows\SysWow64\wpcap.dll
c:\windows\wininit.ini
D:\install.exe
.
Infizierte Kopie von c:\windows\SysWow64\userinit.exe wurde gefunden und desinfiziert
Kopie von - c:\combofix\HarddiskVolumeShadowCopy5_!Windows!SysWOW64!userinit.exe wurde wiederhergestellt
.
.
((((((((((((((((((((((((((((((((((((((( Treiber/Dienste )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Service_npf
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-05-09 bis 2014-06-09 ))))))))))))))))))))))))))))))
.
.
2014-06-09 20:12 . 2014-06-09 20:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-06-09 20:12 . 2014-06-09 20:12 -------- d-----w- c:\users\Benjamin\AppData\Local\temp
2014-06-09 13:02 . 2014-06-09 13:08 -------- d-----w- C:\FRST
2014-06-08 13:24 . 2014-06-08 13:24 -------- d-----w- c:\users\Elias\AppData\Roaming\ParetoLogic
2014-06-08 13:24 . 2014-06-08 13:24 -------- d-----w- c:\users\Elias\AppData\Roaming\DriverCure
2014-05-28 21:31 . 2014-05-28 21:31 -------- d-----w- c:\programdata\The Learning Company
2014-05-28 21:31 . 2002-05-07 05:09 274432 ----a-w- c:\windows\TLCUNINSTALL.EXE
2014-05-20 13:02 . 2014-05-20 13:02 45384 ----a-w- c:\windows\SysWow64\DiscHandler.exe
2014-05-18 12:35 . 2014-05-18 12:35 -------- d-----w- c:\users\Elias\.thumbnails
2014-05-17 21:57 . 2014-05-06 04:40 23544320 ----a-w- c:\windows\system32\mshtml.dll
2014-05-17 21:57 . 2014-05-06 03:00 84992 ----a-w- c:\windows\system32\mshtmled.dll
2014-05-17 21:57 . 2014-05-06 04:17 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-05-13 15:05 . 2014-05-13 15:05 4009984 ----a-w- c:\windows\system32\ffmpeg.dll
2014-05-13 15:05 . 2014-05-13 15:05 474624 ----a-w- c:\windows\system32\ff_kernelDeint.dll
2014-05-13 15:05 . 2014-05-13 15:05 127488 ----a-w- c:\windows\system32\ff_vfw.dll
2014-05-13 15:05 . 2014-05-13 15:05 4374528 ----a-w- c:\windows\system32\ffdshow.ax
2014-05-13 15:04 . 2014-05-13 15:04 631296 ----a-w- c:\windows\system32\TomsMoComp_ff.dll
2014-05-13 15:04 . 2014-05-13 15:04 222720 ----a-w- c:\windows\system32\ff_libdts.dll
2014-05-13 15:04 . 2014-05-13 15:04 156672 ----a-w- c:\windows\system32\ff_libmad.dll
2014-05-13 15:04 . 2014-05-13 15:04 116224 ----a-w- c:\windows\system32\ff_liba52.dll
2014-05-13 15:04 . 2014-05-13 15:04 114688 ----a-w- c:\windows\system32\ff_wmv9.dll
2014-05-13 15:04 . 2014-05-13 15:04 190464 ----a-w- c:\windows\system32\libmpeg2_ff.dll
2014-05-13 15:04 . 2014-05-13 15:04 183296 ----a-w- c:\windows\system32\ff_unrar.dll
2014-05-13 15:04 . 2014-05-13 15:04 1532928 ----a-w- c:\windows\system32\ff_samplerate.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-27 13:26 . 2013-08-09 13:51 130584 ----a-w- c:\windows\system32\drivers\avipbb.sys
2014-05-27 13:26 . 2013-08-09 13:51 112080 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2014-05-17 12:09 . 2012-04-03 12:59 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-05-17 12:09 . 2011-11-05 09:48 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-05-13 15:02 . 2014-05-13 15:02 3916288 ----a-w- c:\windows\SysWow64\ffmpeg.dll
2014-05-13 15:01 . 2014-05-13 15:01 112640 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2014-05-13 15:01 . 2014-05-13 15:01 3502592 ----a-w- c:\windows\SysWow64\ffdshow.ax
2014-05-13 15:01 . 2014-05-13 15:01 271360 ----a-w- c:\windows\SysWow64\TomsMoComp_ff.dll
2014-05-13 15:00 . 2014-05-13 15:00 99840 ----a-w- c:\windows\SysWow64\ff_wmv9.dll
2014-05-13 15:00 . 2014-05-13 15:00 157184 ----a-w- c:\windows\SysWow64\ff_unrar.dll
2014-05-13 15:00 . 2014-05-13 15:00 211968 ----a-w- c:\windows\SysWow64\ff_libdts.dll
2014-05-13 15:00 . 2014-05-13 15:00 1525760 ----a-w- c:\windows\SysWow64\ff_samplerate.dll
2014-05-13 15:00 . 2014-05-13 15:00 147456 ----a-w- c:\windows\SysWow64\ff_libmad.dll
2014-05-13 15:00 . 2014-05-13 15:00 114688 ----a-w- c:\windows\SysWow64\ff_liba52.dll
2014-05-13 15:00 . 2014-05-13 15:00 136704 ----a-w- c:\windows\SysWow64\libmpeg2_ff.dll
2014-05-06 03:07 . 2014-05-17 21:57 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2014-05-01 16:02 . 2014-05-01 16:02 428792 ----a-w- c:\windows\system32\cdxareader.ax
2014-05-01 15:56 . 2014-05-01 15:56 368888 ----a-w- c:\windows\SysWow64\cdxareader.ax
2014-04-12 02:12 . 2014-05-17 11:48 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2014-04-12 02:10 . 2014-05-17 11:48 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2014-04-08 20:50 . 2014-04-08 20:50 235520 ----a-w- c:\windows\SysWow64\xvidvfw.dll
2014-04-08 20:50 . 2014-04-08 20:50 632320 ----a-w- c:\windows\SysWow64\xvidcore.dll
2014-04-08 15:30 . 2014-04-08 15:30 7682192 ----a-w- c:\windows\system32\avcodec-lav-55.dll
2014-04-08 15:30 . 2014-04-08 15:30 570512 ----a-w- c:\windows\system32\LAVSplitter.ax
2014-04-08 15:30 . 2014-04-08 15:30 441488 ----a-w- c:\windows\system32\IntelQuickSyncDecoder.dll
2014-04-08 15:30 . 2014-04-08 15:30 430736 ----a-w- c:\windows\system32\swscale-lav-2.dll
2014-04-08 15:30 . 2014-04-08 15:30 401040 ----a-w- c:\windows\system32\avutil-lav-52.dll
2014-04-08 15:30 . 2014-04-08 15:30 302224 ----a-w- c:\windows\system32\LAVAudio.ax
2014-04-08 15:30 . 2014-04-08 15:30 286352 ----a-w- c:\windows\system32\libbluray.dll
2014-04-08 15:30 . 2014-04-08 15:30 250512 ----a-w- c:\windows\system32\avfilter-lav-4.dll
2014-04-08 15:30 . 2014-04-08 15:30 161424 ----a-w- c:\windows\system32\avresample-lav-1.dll
2014-04-08 15:30 . 2014-04-08 15:30 1251984 ----a-w- c:\windows\system32\avformat-lav-55.dll
2014-04-08 15:30 . 2014-04-08 15:30 1109136 ----a-w- c:\windows\system32\LAVVideo.ax
2014-04-08 15:29 . 2014-04-08 15:29 411280 ----a-w- c:\windows\SysWow64\swscale-lav-2.dll
2014-04-08 15:29 . 2014-04-08 15:29 238736 ----a-w- c:\windows\SysWow64\libbluray.dll
2014-04-08 15:29 . 2014-04-08 15:29 934544 ----a-w- c:\windows\SysWow64\LAVVideo.ax
2014-04-08 15:29 . 2014-04-08 15:29 7186064 ----a-w- c:\windows\SysWow64\avcodec-lav-55.dll
2014-04-08 15:29 . 2014-04-08 15:29 478864 ----a-w- c:\windows\SysWow64\LAVSplitter.ax
2014-04-08 15:29 . 2014-04-08 15:29 412304 ----a-w- c:\windows\SysWow64\avutil-lav-52.dll
2014-04-08 15:29 . 2014-04-08 15:29 344720 ----a-w- c:\windows\SysWow64\IntelQuickSyncDecoder.dll
2014-04-08 15:29 . 2014-04-08 15:29 263824 ----a-w- c:\windows\SysWow64\LAVAudio.ax
2014-04-08 15:29 . 2014-04-08 15:29 241296 ----a-w- c:\windows\SysWow64\avfilter-lav-4.dll
2014-04-08 15:29 . 2014-04-08 15:29 152208 ----a-w- c:\windows\SysWow64\avresample-lav-1.dll
2014-04-08 15:29 . 2014-04-08 15:29 1293456 ----a-w- c:\windows\SysWow64\avformat-lav-55.dll
2014-03-31 20:46 . 2014-03-31 20:46 130712 ----a-w- c:\windows\SysWow64\MSSTDFMT.DLL
2014-03-31 20:46 . 2014-03-31 20:46 1070232 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2009-04-08 17:31 . 2009-04-08 17:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-12 04:45 . 2008-08-12 04:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-08-29 18:45 220632 ----a-w- c:\users\Elias\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-08-29 18:45 220632 ----a-w- c:\users\Elias\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-08-29 18:45 220632 ----a-w- c:\users\Elias\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2011-11-10 3077528]
"Akamai NetSession Interface"="c:\users\Elias\AppData\Local\Akamai\netsession_win.exe" [2014-04-17 4672920]
"GoogleChromeAutoLaunch_ADF2EF7A9169565BE50E52E39FE78F03"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2014-05-13 860488]
"Steam"="c:\program files (x86)\Steam\Steam.exe" [2013-12-11 1823656]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-07-13 2244096]
"HControlUser"="c:\program files (x86)\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"ATKOSD2"="c:\program files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" [2009-07-07 8493624]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Media\DMedia.exe" [2009-04-20 159744]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe" [2009-07-24 240112]
"CPMonitor"="c:\program files (x86)\Roxio 2010\5.0\CPMonitor.exe" [2009-07-21 84464]
"Desktop Disc Tool"="c:\program files (x86)\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe" [2009-06-23 494064]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-09-23 926896]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-05-27 737872]
"dcmsvc"="c:\program files (x86)\dcmsvc\dcmsvc.exe" [2009-04-07 30440]
.
c:\users\Elias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
CodecPackUpdateChecker.lnk - c:\windows\SysWOW64\C2MP\UpdateChecker.exe [2014-5-20 48688]
FancyStart daemon.lnk - c:\windows\Installer\{60D6618B-153F-4353-8185-908E676E5888}\_DCE9A4DB2A5F2786140FA3.exe -d [2011-11-3 12862]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver]
2011-11-03 00:52 72248 ----a-w- c:\windows\AsScrProlog.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
2011-11-03 00:52 3054136 ----a-w- c:\windows\AsScrPro.exe
.
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\System32\drivers\sfdrv01a.sys;c:\windows\SYSNATIVE\drivers\sfdrv01a.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 FastBootAgent;FastBootAgent;c:\windows\SysWOW64\Fast Boot\FastBootAgent.exe;c:\windows\SysWOW64\Fast Boot\FastBootAgent.exe [x]
R2 FreemakeVideoCapture;FreemakeVideoCapture;c:\program files (x86)\Freemake\CaptureLib\CaptureLibService.exe;c:\program files (x86)\Freemake\CaptureLib\CaptureLibService.exe [x]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe;c:\program files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 RoxMediaDB12;RoxMediaDB12;c:\program files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe;c:\program files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 X6va005;X6va005;c:\users\Elias\AppData\Local\Temp\0053A90.tmp;c:\users\Elias\AppData\Local\Temp\0053A90.tmp [x]
R4 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys;c:\windows\SYSNATIVE\DRIVERS\lullaby.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys;c:\program files\ATKGFNEX\ASMMAP64.sys [x]
S2 WinisoCDBus;WinISO Virtual CD Drive;c:\windows\system32\drivers\WinisoCDBus.sys;c:\windows\SYSNATIVE\drivers\WinisoCDBus.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-05-23 17:54 1091912 ----a-w- c:\program files (x86)\Google\Chrome\Application\35.0.1916.114\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-06-09 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1230764542-2489123228-2413629413-1000Core.job
- c:\users\Elias\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-11-11 14:35]
.
2014-06-09 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1230764542-2489123228-2413629413-1000UA.job
- c:\users\Elias\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-11-11 14:35]
.
2014-06-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-07 20:52]
.
2014-06-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-07 20:52]
.
2014-06-09 c:\windows\Tasks\ParetoLogic Registration3.job
- c:\windows\system32\rundll32.exe [2009-07-13 01:14]
.
2014-05-29 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files (x86)\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2008-02-22 10:25]
.
2014-06-09 c:\windows\Tasks\ParetoLogic Update Version3.job
- c:\program files (x86)\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2011-03-29 23:51]
.
2014-06-09 c:\windows\Tasks\PC Health Advisor Defrag.job
- c:\program files (x86)\ParetoLogic\PCHA\PCHA.exe [2011-03-29 23:17]
.
2014-06-09 c:\windows\Tasks\PC Health Advisor.job
- c:\program files (x86)\ParetoLogic\PCHA\PCHA.exe [2011-03-29 23:17]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-08-29 18:45 244696 ----a-w- c:\users\Elias\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-08-29 18:45 244696 ----a-w- c:\users\Elias\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-08-29 18:45 244696 ----a-w- c:\users\Elias\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-07-12 165912]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-07-12 387608]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-07-12 365592]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-04-09 320000]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-06-12 619392]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://google.de/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com
IE: Free YouTube Download - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Elias\AppData\Roaming\Mozilla\Firefox\Profiles\2frlzdjb.default\
FF - prefs.js: browser.startup.homepage - google.de
FF - ExtSQL: !HIDDEN! 2012-12-16 20:42; {ACAA314B-EEBA-48e4-AD47-84E31C44796C}; c:\program files (x86)\Common Files\DVDVideoSoft\plugins\ff
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-ActosKezej - (no file)
Wow6432Node-HKLM-Run-Setwallpaper - c:\programdata\SetWallpaper.cmd
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
c:\users\Elias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Warner Bros.lnk - c:\program files (x86)\Warner Bros. Digital Copy Manager\Warner Bros. Digital Copy Manager.exe
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackTrayMenu.lnk - c:\windows\SysWOW64\C2MP\TrayMenu.exe
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\System32\Macromed\SHOCKW~2\UNWISE.EXE
AddRemove-Akamai - c:\program files (x86)\Common Files\Akamai\uninstall.exe
AddRemove-DVDVideoSoftTB Toolbar - c:\program files (x86)\DVDVideoSoftTB\uninstall.exe
AddRemove-RESIDENT EVIL - d:\resident evil\Uninstall.exe
AddRemove-Rune_is1 - d:\r.g. catalyst\Rune\uninstall\unins000.exe
AddRemove-Shockwave - c:\windows\System32\Macromed\SHOCKW~1\UNWISE.EXE
AddRemove-«Aliens versus Predator»_is1 - d:\games\R.G. Catalyst\Aliens versus Predator\unins000.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va005]
"ImagePath"="\??\c:\users\Elias\AppData\Local\Temp\0053A90.tmp"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,63,cf,bf,6a,cb,5a,76,49,a6,33,e2,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,63,cf,bf,6a,cb,5a,76,49,a6,33,e2,\
.
[HKEY_USERS\S-1-5-21-1230764542-2489123228-2413629413-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:cf,06,5f,64,45,cb,d7,83,1f,39,9e,77,3b,bc,7f,91,ce,7d,81,11,6d,7e,37,
07,7b,3b,e0,e3,61,58,d3,45,f7,19,8a,b3,62,5c,da,7b,fc,fa,b8,22,12,ea,6e,d7,\
"??"=hex:3d,de,ff,80,7e,74,6c,e6,85,f2,79,6e,25,b0,a9,db
.
[HKEY_USERS\S-1-5-21-1230764542-2489123228-2413629413-1000\Software\SecuROM\License information*]
"datasecu"=hex:bd,52,19,d1,ff,9c,ff,68,c8,9f,cd,d6,e3,5f,32,71,fb,ff,b7,f5,d0,
d9,06,af,93,99,d2,7c,42,a1,64,95,cd,36,d5,0b,a2,0f,e5,76,4b,0f,53,04,ce,14,\
"rkeysecu"=hex:78,95,80,70,3c,f2,af,47,c4,73,23,4b,d9,0d,08,c5
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\PnkBstrB.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
c:\program files (x86)\ASUS\ATK Hotkey\HControl.exe
c:\program files (x86)\ASUS\ATK Hotkey\Atouch64.exe
c:\program files (x86)\ASUS\ATK Hotkey\ATKOSD.exe
c:\program files (x86)\ASUS\ATK Hotkey\KBFiltr.exe
c:\program files (x86)\ASUS\ATK Hotkey\WDC.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2014-06-09 22:36:04 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2014-06-09 20:36
.
Vor Suchlauf: 14 Verzeichnis(se), 93.274.238.976 Bytes frei
Nach Suchlauf: 20 Verzeichnis(se), 103.724.564.480 Bytes frei
.
- - End Of File - - 2F8DE4BAC608391F2462AD8C07380F37 --- --- ---
5C616939100B85E558DA92B899A0FC36
[/CODE]
Wie soll ich nun mit der angezeigten Log-File verfahren? Kann ich sie einfach schließen oder soll ich sie abspeichern?
Mit freundlichen Grüßen,
pcguy10 |