combofix.txt Code:
ComboFix 14-07-31.02 - Finanzdienstleistung 01.08.2014 18:09:52.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.49.1031.18.2039.865 [GMT 2:00]
ausgeführt von:: c:\users\Finanzdienstleistung\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
FW: avast! Antivirus *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Finanzdienstleistung\4.0
c:\users\Finanzdienstleistung\AppData\Local\assembly\tmp
c:\users\Finanzdienstleistung\AppData\Roaming\.#
c:\users\Finanzdienstleistung\AppData\Roaming\337
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\ebase.dll
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\image\default\app_close.png
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\image\default\app_max.png
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\image\default\app_min.png
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\image\default\app_restore.png
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\image\default\wallpaper_resource.xml
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\image\default\window.png
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\language\en_us\wallpaper_lang.ini
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\language\es_es\wallpaper_lang.ini
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\language\pt_br\wallpaper_lang.ini
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\language\tr_tr\wallpaper_lang.ini
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\language\zh_tw\wallpaper_lang.ini
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\layout\default\dp_appwnd.xml
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\layout\default\msgbox.xml
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\libpng.dll
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\main
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\msvcp100.dll
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\msvcr100.dll
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\ouilibnl.dll
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\plusapp.exe
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\style\wallpaper_style.xml
c:\users\Finanzdienstleistung\AppData\Roaming\337\337 Wallpaper\TrayDownloader.exe
c:\users\Finanzdienstleistung\AppData\Roaming\Adobe\plugs
c:\users\Finanzdienstleistung\AppData\Roaming\Adobe\shed
c:\users\Finanzdienstleistung\AppData\Roaming\Microsoft\Windows\Recent\AXA, EL-Bonus.pdf.url
c:\users\Finanzdienstleistung\AppData\Roaming\Microsoft\Windows\Recent\Gute Gruende uns zu waehlen.pdf.url
c:\users\Finanzdienstleistung\AppData\Roaming\Regres
c:\users\Finanzdienstleistung\AppData\Roaming\Regres\wintab.exe
c:\users\Finanzdienstleistung\Documents\~WRL0003.tmp
c:\users\Finanzdienstleistung\infinst.exe
c:\users\Public\AlexaNSISPlugin.4228.dll
c:\windows\Installer\{366D38BF-E12D-48FB-9F01-EEF3E7DCADEF}\BT.Setup.Updater.T_CD8CBA3468C240F981B372C3EA3FF361.exe
c:\windows\IsUn0407.exe
c:\windows\system32\AF15BDAEX.dll
c:\windows\TEMP\jna5677241050741795506.dll
c:\windows\XSxS
D:\install.exe
H:\resycled
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-07-01 bis 2014-08-01 ))))))))))))))))))))))))))))))
.
.
2014-08-01 10:53 . 2014-08-01 10:53 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{29706143-15B6-4DF7-9027-E6D7E536849B}\offreg.dll
2014-08-01 10:14 . 2014-07-02 03:11 8217224 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{29706143-15B6-4DF7-9027-E6D7E536849B}\mpengine.dll
2014-07-27 23:20 . 2014-07-27 23:19 26136 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2014-07-27 23:19 . 2014-07-27 23:19 270752 ----a-w- c:\windows\system32\drivers\aswNdisFlt.sys
2014-07-27 06:18 . 2014-07-27 06:18 -------- d-----w- c:\users\Gast\AppData\Roaming\AVAST Software
2014-07-26 17:08 . 2014-07-29 15:13 -------- dc----w- C:\FRST
2014-07-26 16:31 . 2014-07-26 16:31 -------- d-----w- c:\programdata\MAGIX
2014-07-26 16:25 . 2014-07-26 16:25 -------- d-----w- c:\users\Finanzdienstleistung\AppData\Roaming\AVAST Software
2014-07-26 16:24 . 2014-07-26 16:24 71944 ----a-w- c:\windows\system32\drivers\aswStm.sys
2014-07-26 16:24 . 2014-07-26 16:24 192352 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-07-26 16:24 . 2014-07-26 16:25 414520 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-07-26 16:24 . 2014-07-26 16:24 779536 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-07-26 16:24 . 2014-07-26 16:24 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-07-26 16:24 . 2014-07-26 16:24 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-07-26 16:24 . 2014-07-26 16:24 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-07-26 16:24 . 2014-07-26 16:24 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-07-26 16:24 . 2014-07-26 16:24 276432 ----a-w- c:\windows\system32\aswBoot.exe
2014-07-26 16:24 . 2014-07-26 16:24 43152 ----a-w- c:\windows\avastSS.scr
2014-07-26 16:24 . 2014-07-26 16:24 -------- dc----w- c:\program files\AVAST Software
2014-07-26 16:22 . 2014-07-26 16:24 -------- d-----w- c:\programdata\AVAST Software
2014-07-24 00:11 . 2014-07-24 16:44 -------- d-----w- c:\programdata\ItogiVhovu
2014-07-24 00:10 . 2014-07-24 21:18 -------- d-----w- c:\programdata\OvmaTmed
2014-07-23 23:18 . 2014-07-30 20:03 822384 ----a-w- c:\program files\Mozilla Firefox\icuuc52.dll
2014-07-23 23:18 . 2014-07-30 20:03 10594416 ----a-w- c:\program files\Mozilla Firefox\icudt52.dll
2014-07-23 23:18 . 2014-07-30 20:03 1022576 ----a-w- c:\program files\Mozilla Firefox\icuin52.dll
2014-07-23 10:40 . 2014-07-23 10:40 -------- d-----w- c:\users\Finanzdienstleistung\AppData\Roaming\DesktopIconGoodgame
2014-07-21 15:07 . 2014-07-21 15:07 -------- d-----w- c:\programdata\firebird
2014-07-21 15:06 . 2014-07-21 15:06 -------- d-----w- c:\users\Finanzdienstleistung\AppData\Roaming\NUERNBERGER
2014-07-21 15:05 . 2014-07-21 15:05 -------- d-----w- c:\users\Finanzdienstleistung\AppData\Local\Nuernberger_Versicherungs
2014-07-21 13:28 . 2014-07-24 14:12 -------- dc----w- c:\program files\NÜRNBERGER AutoUpdater
2014-07-21 13:16 . 2014-07-21 13:16 -------- d-----w- c:\users\Finanzdienstleistung\AppData\Roaming\Keseling
2014-07-21 09:27 . 2014-07-21 09:30 -------- d-----w- c:\windows\Downloaded Installations
2014-07-21 00:22 . 2014-07-23 19:33 -------- d-----w- c:\programdata\OkhoHamu
2014-07-19 21:00 . 2014-07-21 07:39 -------- d-----w- c:\programdata\OyhiRalow
2014-07-19 21:00 . 2014-07-21 08:27 -------- d-----w- c:\programdata\IvqeKjaqu
2014-07-11 01:06 . 2014-07-11 01:06 -------- d-s---w- c:\windows\system32\CompatTel
2014-07-10 07:40 . 2014-07-01 01:38 402944 ----a-w- c:\windows\system32\aepdu.dll
2014-07-10 07:40 . 2014-07-01 01:35 303104 ----a-w- c:\windows\system32\aeinv.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-07-09 10:36 . 2012-04-12 21:28 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-07-09 10:36 . 2011-09-24 20:43 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2008-06-19 09:16 . 2014-02-17 16:21 118784 ----a-w- c:\program files\mozilla firefox\plugins\MyCamera.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-07-26 16:24 578240 -c--a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04 131480 ----a-w- c:\users\Finanzdienstleistung\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04 131480 ----a-w- c:\users\Finanzdienstleistung\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04 131480 ----a-w- c:\users\Finanzdienstleistung\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-04-03 19:32 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-04-03 19:32 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-04-03 19:32 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-04-03 19:32 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-04-03 19:32 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2014-04-03 22414424]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2009-05-26 1159168]
"BTnetPortComm"="c:\program files\NuernbergerBT\BT.Net_Listener.exe" [2014-03-24 977536]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-07-31 4085896]
.
c:\users\Finanzdienstleistung\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
auto.bat [2014-4-13 23]
Dropbox.lnk - c:\users\Finanzdienstleistung\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-7-21 35464216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdAuxService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdCoreService]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
backupExtension=.CommonStartup
backup=c:\windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-11-21 16:57 959904 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Synchronizer]
2014-05-08 13:48 746376 -c--a-w- c:\program files\Adobe\Reader 11.0\Reader\AdobeCollabSync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AvastUI.exe]
2014-07-31 11:20 4085896 -c--a-w- c:\program files\AVAST Software\Avast\avastui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileDocuments]
2012-02-23 10:30 59240 ----a-w- c:\program files\Common Files\Apple\Internet Services\ubd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "c:\programdata\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini"
"ISA Service Extensions"="javaw" -Xmx30m -jar "c:\program files\HanseMerkur\ServiceExtensions\ServiceExtensions.jar"
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe"
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe"
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
.
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [x]
R0 TFSysMon;TFSysMon;c:\windows\system32\drivers\TfSysMon.sys [x]
R2 sdAuxService;PC Tools Auxiliary Service; [x]
R3 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg.sys [2012-01-11 70536]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [x]
R4 WinRiskXASmClServiceHandler;InterRisk WinRisk Smart-Client Dienststeuerung;c:\program files\InterRisk\WinRiskXA\smart\client\bin\BWServiceHandler.exe [2009-12-10 90112]
S0 aswNdisFlt;Avast! Firewall Driver;c:\windows\system32\DRIVERS\aswNdisFlt.sys [2014-07-27 270752]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2011-11-14 331880]
S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2011-12-01 342168]
S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [2014-07-27 26136]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-07-26 779536]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-07-26 414520]
S1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi.sys [2012-01-11 253352]
S1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD.sys [2012-01-11 185560]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2014-07-26 24184]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-07-26 67824]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-07-26 71944]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2014-07-27 106488]
S2 BTAVB_KomDienst_Vers_Btnet_1402;BTAVB_KomDienst_Vers_Btnet_1402;i:\btnet_0214\AVB_Steuerung\BTAVB_KomDienst.exe [2013-04-03 17920]
S2 NbgAutoUpdater;NÜRNBERGER AutoUpdater;c:\program files\NÜRNBERGER AutoUpdater\BT.Setup.InstallationsDienst.exe [2013-12-05 23120]
S2 TeamViewer9;TeamViewer 9;c:\program files\TeamViewer\Version9\TeamViewer_Service.exe [2014-04-25 5024576]
S2 WinRiskXASmClSoftwareUpdate;InterRisk WinRisk Smart-Client Softwareaktualisierung;c:\program files\InterRisk\WinRiskXA\smart\client\bin\BWUpdater.exe [2012-04-18 24576]
S3 AVMCOWAN;AVM ISDN CoNDIS WAN CAPI Driver;c:\windows\system32\DRIVERS\AVMCOWAN.sys [2009-07-13 64000]
S3 BrSerIb;Brother Serial Interface Driver(WDM);c:\windows\system32\DRIVERS\BrSerIb.sys [2012-12-04 78960]
S3 BrUsbSIb;Brother Serial USB Driver(WDM);c:\windows\system32\DRIVERS\BrUsbSIb.sys [2012-12-04 18800]
S3 FPCIBASE;AVM FRITZ!Card PCI;c:\windows\system32\DRIVERS\fpcibase.sys [2009-07-13 559104]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-03-22 278560]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-10-26 13:33 1185744 ----a-w- c:\program files\Google\Chrome\Application\30.0.1599.101\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-08-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-12 10:36]
.
2014-06-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-22 21:12]
.
2014-06-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-22 21:12]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.search.ask.com/?o=APN10645A&gct=hp&d=406-0&v=n11099-240&t=4
uDefault_Search_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mSearch Bar = hxxp://www.google.com
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com
uSearchURL,(Default) = hxxp://go.web.de/suchbox/webdesuche?su=%s
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
Trusted Zone: web.de
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Finanzdienstleistung\AppData\Roaming\Mozilla\Firefox\Profiles\fd4ejuoy.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - user.js: security.csp.enable - false
FF - user.js: extensions.delta.tlbrSrchUrl -
FF - user.js: extensions.delta.id - 1063ab6a00000000000000196640d147
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15948
FF - user.js: extensions.delta.vrsn - 1.8.24.6
FF - user.js: extensions.delta.vrsni - 1.8.24.6
FF - user.js: extensions.delta.vrsnTs - 1.8.24.622:28
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - de
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.ffxUnstlRst - true
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta_i.babTrack - affID=123884&tt=280813_ctrl2&tsp=4991
FF - user.js: extensions.delta_i.babExt -
FF - user.js: extensions.delta_i.srcExt - ss
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
FF - user.js: extentions.webcake.installId - 69b03aca-20c0-40ca-a44b-814fc830bd7d
FF - user.js: extentions.webcake.defaultEnableAppsList - layers/inline,layers/shopping,layers/banner,layers/search,newOffers/wc
FF - user.js: extensions.iminent.id - 1063ab6a00000000000000196640d147
FF - user.js: extensions.iminent.appId - {0E4B2CAB-B859-4C57-B96E-63DDEC692BC4}
FF - user.js: extensions.iminent.instlDay - 16051
FF - user.js: extensions.iminent.vrsn - 1.8.28.3
FF - user.js: extensions.iminent.vrsni - 1.8.28.3
FF - user.js: extensions.iminent.vrsnTs - 1.8.28.30:43
FF - user.js: extensions.iminent.prtnrId - iminent
FF - user.js: extensions.iminent.prdct - iminent
FF - user.js: extensions.iminent.aflt - orgnl
FF - user.js: extensions.iminent.smplGrp - none
FF - user.js: extensions.iminent.tlbrId - YBCPCSTIPO
FF - user.js: extensions.iminent.instlRef -
FF - user.js: extensions.iminent.dfltLng -
FF - user.js: extensions.iminent.excTlbr - false
FF - user.js: extensions.iminent.ffxUnstlRst - false
FF - user.js: extensions.iminent.admin - false
FF - user.js: extensions.iminent.autoRvrt - false
FF - user.js: extensions.iminent.rvrt - false
FF - user.js: extensions.iminent.newTab - false
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{b81767e1-672d-4da1-b5cc-d277185815a6} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
Toolbar-{b81767e1-672d-4da1-b5cc-d277185815a6} - (no file)
Toolbar-10 - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{B81767E1-672D-4DA1-B5CC-D277185815A6} - (no file)
WebBrowser-{64EAD72B-FFD4-4E01-AA3A-4C71665D73E4} - (no file)
HKCU-Run-IvqeKjaqu - (no file)
HKCU-Run-OyhiRalow - (no file)
HKCU-Run-OvmaTmed - (no file)
HKCU-Run-ItogiVhovu - (no file)
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\NÜRNBERGER AutoUpdater.lnk - c:\windows\Installer\{366D38BF-E12D-48FB-9F01-EEF3E7DCADEF}\BT.Setup.Updater.T_CD8CBA3468C240F981B372C3EA3FF361.exe
SafeBoot-46574612.sys
.
.
"ImagePath"="system32\drivers\
[verify-U]-driver.sys"
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\services\[verify-U]_System]
"ImagePath"="system32\drivers\
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}"=hex:51,66,7a,6c,4c,1d,38,12,57,36,90,
43,f7,9e,4b,04,e0,be,4b,59,e7,b4,e8,87
"{8E5E2654-AD2D-48BF-AC2D-D17F00898D06}"=hex:51,66,7a,6c,4c,1d,38,12,3a,25,4d,
8a,1f,e3,d1,0d,d3,3b,92,3f,05,d7,c9,12
"{472734EA-242A-422B-ADF8-83D1E48CC825}"=hex:51,66,7a,6c,4c,1d,38,12,84,37,34,
43,18,6a,45,07,d2,ee,c0,91,e1,d2,8c,31
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=hex:51,66,7a,6c,4c,1d,38,12,11,7f,11,
d0,78,5b,08,05,de,bb,01,03,dd,4c,30,54
"{95B7759C-8C7F-4BF1-B163-73684A933233}"=hex:51,66,7a,6c,4c,1d,38,12,f2,76,a4,
91,4d,c2,9f,0e,ce,75,30,28,4f,cd,76,27
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,
27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b
"{D7E97865-918F-41E4-9CD0-25AB1C574CE8}"=hex:51,66,7a,6c,4c,1d,38,12,0b,7b,fa,
d3,bd,df,8a,04,e3,c6,66,eb,19,09,08,fc
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}"=hex:51,66,7a,6c,4c,1d,38,12,75,3e,1c,
2e,3b,47,9a,0a,cd,64,23,dc,cb,3e,10,f3
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,
ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3
"{AE7CD045-E861-484F-8273-0445EE161910}"=hex:51,66,7a,6c,4c,1d,38,12,2b,d3,6f,
aa,53,a6,21,0d,fd,65,47,05,eb,48,5d,04
"{CCB69577-088B-4004-9ED8-FF5BCC83A039}"=hex:51,66,7a,6c,4c,1d,38,12,19,96,a5,
c8,b9,46,6a,05,e1,ce,bc,1b,c9,dd,e4,2d
"{D3D233D5-9F6D-436C-B6C7-E63F77503B30}"=hex:51,66,7a,6c,4c,1d,38,12,bb,30,c1,
d7,5f,d1,02,06,c9,d1,a5,7f,72,0e,7f,24
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{F4971EE7-DAA0-4053-9964-665D8EE6A077}"=hex:51,66,7a,6c,4c,1d,38,12,89,1d,84,
f0,92,94,3d,05,e6,72,25,1d,8b,b8,e4,63
"{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}"=hex:51,66,7a,6c,4c,1d,38,12,70,05,61,
f9,ec,d1,23,0d,da,9c,48,eb,44,0f,8e,cc
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:1e,6c,1c,53,5d,26,cd,01
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Micro Focus]
@Denied: (C D) (Everyone)
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\system32\msiexec.exe
i:\btnet_0214\Dope\Dope-Mobile\utils\java_jdk_windows-x86-32\bin\javaw.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\program files\Google\Update\1.3.24.15\GoogleCrashHandler.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2014-08-01 18:30:04 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2014-08-01 16:30
.
Vor Suchlauf: 2.625.179.648 Bytes frei
Nach Suchlauf: 3.122.507.776 Bytes frei
.
- - End Of File - - B5B1432E90C95854944B0803F0D04D05
A36C5E4F47E84449FF07ED3517B43A31 |