Hallo Schrauber,
Schritt 1 habe ich durchgeführt. Allerdings kann ich combofix nicht herunterladen. Woran könnte dies liegen. (Nutze einen anderen Computer zum Download)
mfG
So, jetzt alles erledigt. Keine besonderen Vorkommnisse. Anbei poste ich das Log- File. Code:
ComboFix 14-08-19.01 - Norman 21.08.2014 10:30:20.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3885.1989 [GMT 2:00]
ausgeführt von:: c:\users\Norman\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\END
c:\esupport\eDriver\Software\ASUS\MultiFrame\XP32_Vista32_Vista64_Win7_32_Win7_64_1.0.0021\Desktop_.ini
C:\prefs.js
c:\program files (x86)\Common Files\ASPG_icon.ico
c:\program files (x86)\MediaBuzzV1
c:\program files (x86)\MediaWatchV1
c:\programdata\374311380
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_ekdgbodaoampohmhmecigaomnjppbplb_0
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_ekdgbodaoampohmhmecigaomnjppbplb_0\70
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\background.html
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\chromeCoreFilesIndex.txt
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\crossriderManifest.json
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\manifest.xml
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins.json
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\1.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\102.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\104.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\13.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\14.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\155.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\17.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\177.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\182.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\183.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\184.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\19.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\191.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\193.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\195.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\207.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\21.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\211.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\22.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\220.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\221.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\242.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\244.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\246.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\262.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\263.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\267.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\28.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\4.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\47.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\64.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\7.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\72.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\78.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\80.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\9.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\91.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\93.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\plugins\97.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\userCode\background.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\extensionData\userCode\extension.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\icons\actions\1.png
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\icons\icon128.png
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\icons\icon16.png
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\icons\icon48.png
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\api\chrome.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\api\cookie.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\api\message.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\api\monitor.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\api\pageAction.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\api\pageActionBG.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\background.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\lib\app_api.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\lib\bg_app_api.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\lib\consts.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\lib\cookie_store.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\lib\crossriderAPI.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\lib\delegate.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\lib\events.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\lib\extensionDataStore.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\lib\installer.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\lib\logFile.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\lib\logging.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\lib\onBGDocumentLoad.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\lib\popupResource\newPopup.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\lib\popupResource\popup.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\lib\reports.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\lib\storageWrapper.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\lib\updateManager.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\lib\util.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\lib\xhr.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\main.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\js\platformVersion.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\manifest.json
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdgbodaoampohmhmecigaomnjppbplb\13785.340.6094_0\popup.html
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkakfimgbmogkpmjokgnbbanmmemcdij
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkakfimgbmogkpmjokgnbbanmmemcdij\183\background.html
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkakfimgbmogkpmjokgnbbanmmemcdij\183\ckIF.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkakfimgbmogkpmjokgnbbanmmemcdij\183\content.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkakfimgbmogkpmjokgnbbanmmemcdij\183\lsdb.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkakfimgbmogkpmjokgnbbanmmemcdij\183\manifest.json
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\omioomoieildjihcajfoobhhiecjkmfn
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\omioomoieildjihcajfoobhhiecjkmfn\189\ApbPXl.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\omioomoieildjihcajfoobhhiecjkmfn\189\background.html
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\omioomoieildjihcajfoobhhiecjkmfn\189\content.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\omioomoieildjihcajfoobhhiecjkmfn\189\lsdb.js
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Extensions\omioomoieildjihcajfoobhhiecjkmfn\189\manifest.json
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ekdgbodaoampohmhmecigaomnjppbplb
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ekdgbodaoampohmhmecigaomnjppbplb\000260.ldb
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ekdgbodaoampohmhmecigaomnjppbplb\000274.ldb
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ekdgbodaoampohmhmecigaomnjppbplb\000289.ldb
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ekdgbodaoampohmhmecigaomnjppbplb\000290.log
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ekdgbodaoampohmhmecigaomnjppbplb\CURRENT
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ekdgbodaoampohmhmecigaomnjppbplb\LOCK
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ekdgbodaoampohmhmecigaomnjppbplb\LOG
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ekdgbodaoampohmhmecigaomnjppbplb\LOG.old
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ekdgbodaoampohmhmecigaomnjppbplb\MANIFEST-000288
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ekdgbodaoampohmhmecigaomnjppbplb_0.localstorage-journal
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ekdgbodaoampohmhmecigaomnjppbplb_0.localstorage
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_omioomoieildjihcajfoobhhiecjkmfn_0.localstorage-journal
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_omioomoieildjihcajfoobhhiecjkmfn_0.localstorage
c:\users\Norman\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\users\Norman\AppData\Local\Temp\__tmp_0604b699
c:\users\Norman\AppData\Roaming\Mozilla\Firefox\Profiles\riiyz2xl.default\extensions\vamchw@ovy.co.uk
c:\users\Norman\AppData\Roaming\Mozilla\Firefox\Profiles\riiyz2xl.default\extensions\vamchw@ovy.co.uk\bootstrap.js
c:\users\Norman\AppData\Roaming\Mozilla\Firefox\Profiles\riiyz2xl.default\extensions\vamchw@ovy.co.uk\chrome.manifest
c:\users\Norman\AppData\Roaming\Mozilla\Firefox\Profiles\riiyz2xl.default\extensions\vamchw@ovy.co.uk\content\bg.js
c:\users\Norman\AppData\Roaming\Mozilla\Firefox\Profiles\riiyz2xl.default\extensions\vamchw@ovy.co.uk\install.rdf
c:\windows\IsUn0407.exe
c:\windows\msvcr71.dll
c:\windows\PFRO.log
.
Infizierte Kopie von c:\windows\SysWow64\kernel32.dll wurde gefunden und desinfiziert
Kopie von - c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22653_none_fc95db0bba8ae4c2\kernel32.dll wurde wiederhergestellt
.
.
((((((((((((((((((((((((((((((((((((((( Treiber/Dienste )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NETHFDRV
-------\Service_globalUpdate
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-07-21 bis 2014-08-21 ))))))))))))))))))))))))))))))
.
.
2014-08-21 08:12 . 2014-08-18 04:14 11319200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0B15F75D-E5C3-457A-A11C-DCEA76F85816}\mpengine.dll
2014-08-21 07:23 . 2014-08-21 07:23 -------- d-----w- c:\program files (x86)\CooiLSalEECoUpon
2014-08-21 07:10 . 2014-08-21 07:10 -------- d-----w- c:\program files (x86)\VS Revo Group
2014-08-20 08:27 . 2014-08-20 08:31 -------- d-----w- C:\FRST
2014-08-18 10:20 . 2014-08-21 07:23 -------- d-----w- c:\programdata\8e27c8f07b9e9861
2014-08-13 12:02 . 2014-03-09 21:48 171160 ----a-w- c:\windows\system32\infocardapi.dll
2014-08-13 12:02 . 2014-03-09 21:48 1389208 ----a-w- c:\windows\system32\icardagt.exe
2014-08-13 12:02 . 2014-03-09 21:47 99480 ----a-w- c:\windows\SysWow64\infocardapi.dll
2014-08-13 12:02 . 2014-03-09 21:47 619672 ----a-w- c:\windows\SysWow64\icardagt.exe
2014-08-13 12:02 . 2014-06-30 22:24 8856 ----a-w- c:\windows\system32\icardres.dll
2014-08-13 12:02 . 2014-06-30 22:14 8856 ----a-w- c:\windows\SysWow64\icardres.dll
2014-08-13 12:01 . 2014-06-06 06:16 35480 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe
2014-08-13 12:01 . 2014-06-06 06:12 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-08-13 11:14 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDTAT.DLL
2014-08-13 11:14 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDRU1.DLL
2014-08-13 11:14 . 2014-07-09 02:03 6656 ----a-w- c:\windows\system32\KBDRU.DLL
2014-08-13 11:14 . 2014-07-09 01:31 7168 ----a-w- c:\windows\SysWow64\KBDYAK.DLL
2014-08-13 11:14 . 2014-07-09 01:31 6656 ----a-w- c:\windows\SysWow64\KBDBASH.DLL
2014-08-13 11:14 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDYAK.DLL
2014-08-13 11:14 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDBASH.DLL
2014-08-13 11:14 . 2014-07-16 03:23 2048 ----a-w- c:\windows\system32\tzres.dll
2014-08-13 11:14 . 2014-07-16 02:46 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2014-08-13 11:13 . 2014-06-03 10:02 3241984 ----a-w- c:\windows\system32\msi.dll
2014-08-13 11:13 . 2014-06-03 09:29 2363392 ----a-w- c:\windows\SysWow64\msi.dll
2014-08-13 11:13 . 2014-06-03 10:02 112064 ----a-w- c:\windows\system32\consent.exe
2014-08-13 11:13 . 2014-06-03 10:02 1941504 ----a-w- c:\windows\system32\authui.dll
2014-08-13 11:13 . 2014-06-03 09:29 1805824 ----a-w- c:\windows\SysWow64\authui.dll
2014-08-13 11:13 . 2014-06-03 10:02 504320 ----a-w- c:\windows\system32\msihnd.dll
2014-08-13 11:13 . 2014-06-03 09:29 337408 ----a-w- c:\windows\SysWow64\msihnd.dll
2014-08-13 11:12 . 2014-06-16 02:10 985536 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2014-08-13 11:12 . 2014-07-16 02:12 3163648 ----a-w- c:\windows\system32\win32k.sys
2014-08-13 11:12 . 2014-07-16 03:25 404480 ----a-w- c:\windows\system32\gdi32.dll
2014-08-13 11:12 . 2014-07-16 02:46 311808 ----a-w- c:\windows\SysWow64\gdi32.dll
2014-08-13 11:12 . 2014-06-25 02:05 14175744 ----a-w- c:\windows\system32\shell32.dll
2014-08-13 11:05 . 2014-05-08 09:32 3178496 ----a-w- c:\windows\system32\rdpcorets.dll
2014-08-13 11:05 . 2014-05-08 09:32 16384 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2014-08-13 11:05 . 2014-07-14 02:02 1216000 ----a-w- c:\windows\system32\rpcrt4.dll
2014-08-13 11:05 . 2014-07-14 01:40 664064 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2014-08-13 11:05 . 2014-01-09 02:22 5694464 ----a-w- c:\windows\SysWow64\mstscax.dll
2014-08-13 11:05 . 2014-01-03 22:44 6574592 ----a-w- c:\windows\system32\mstscax.dll
2014-08-13 11:04 . 2014-08-07 02:06 529920 ----a-w- c:\windows\system32\aepdu.dll
2014-08-13 11:04 . 2014-08-07 02:01 424448 ----a-w- c:\windows\system32\aeinv.dll
2014-08-06 06:02 . 2014-08-20 07:08 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-08-06 06:02 . 2014-08-13 10:46 -------- d-----w- c:\programdata\Malwarebytes
2014-08-06 06:02 . 2014-05-12 05:26 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-08-06 05:54 . 2014-08-06 05:54 687 ----a-w- C:\awh81A.tmp
2014-08-06 05:42 . 2012-08-23 14:10 19456 ----a-w- c:\windows\system32\drivers\rdpvideominiport.sys
2014-08-06 05:42 . 2012-08-23 11:12 192000 ----a-w- c:\windows\SysWow64\rdpendp_winip.dll
2014-08-06 05:42 . 2012-08-23 14:13 243200 ----a-w- c:\windows\system32\rdpudd.dll
2014-08-06 05:42 . 2012-08-23 10:51 228864 ----a-w- c:\windows\system32\rdpendp_winip.dll
2014-08-06 05:41 . 2013-09-25 02:23 1030144 ----a-w- c:\windows\system32\TSWorkspace.dll
2014-08-06 05:41 . 2013-09-25 01:57 792576 ----a-w- c:\windows\SysWow64\TSWorkspace.dll
2014-08-06 05:40 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll
2014-08-06 05:40 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2014-08-06 05:26 . 2014-08-06 05:26 687 ----a-w- C:\awh4AE4.tmp
2014-08-04 09:22 . 2014-08-04 09:22 687 ----a-w- C:\awh2D46.tmp
2014-08-04 05:32 . 2014-08-04 05:32 687 ----a-w- C:\awhCDC9.tmp
2014-08-04 05:09 . 2014-08-04 05:09 687 ----a-w- C:\awh6C78.tmp
2014-08-02 11:26 . 2014-08-02 11:26 687 ----a-w- C:\awh4FB5.tmp
2014-07-31 06:44 . 2014-07-31 06:44 687 ----a-w- C:\awh5292.tmp
2014-07-30 18:23 . 2014-07-30 18:23 687 ----a-w- C:\awhAD4E.tmp
2014-07-30 06:25 . 2014-07-30 06:25 687 ----a-w- C:\awh3957.tmp
2014-07-29 07:11 . 2014-07-29 07:11 687 ----a-w- C:\awh4587.tmp
2014-07-29 06:15 . 2014-07-29 06:15 -------- d-----w- c:\users\Norman\AppData\Local\com
2014-07-29 06:12 . 2014-08-20 07:08 -------- d-----w- c:\program files (x86)\Optimizer Pro
2014-07-29 06:11 . 2014-07-29 06:11 -------- d-----w- c:\program files (x86)\PepperZip
2014-07-29 06:11 . 2014-07-28 18:24 4795904 ----a-w- c:\windows\score.exe
2014-07-29 06:11 . 2014-08-06 10:25 -------- d-----w- c:\users\Norman\AppData\Roaming\VOPackage
2014-07-29 06:10 . 2014-07-29 06:10 687 ----a-w- C:\awh1812.tmp
2014-07-28 05:13 . 2014-07-28 05:13 687 ----a-w- C:\awh17F2.tmp
2014-07-27 18:10 . 2014-07-27 18:10 687 ----a-w- C:\awh63A2.tmp
2014-07-27 16:56 . 2014-07-27 16:56 687 ----a-w- C:\awh5C71.tmp
2014-07-27 09:26 . 2014-07-27 09:26 687 ----a-w- C:\awh26C1.tmp
2014-07-26 10:38 . 2014-07-26 10:38 687 ----a-w- C:\awh6315.tmp
2014-07-25 15:47 . 2014-07-25 15:47 687 ----a-w- C:\awh1525.tmp
2014-07-25 05:50 . 2014-07-25 05:50 687 ----a-w- C:\awh20F7.tmp
2014-07-24 16:49 . 2014-07-24 16:49 687 ----a-w- C:\awh7FC9.tmp
2014-07-24 06:47 . 2014-07-24 06:47 687 ----a-w- C:\awh3C06.tmp
2014-07-23 06:18 . 2014-07-23 06:18 687 ----a-w- C:\awh15E0.tmp
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-08-21 09:21 . 2011-07-03 17:09 45056 ----a-w- c:\windows\system32\acovcnt.exe
2014-08-13 12:09 . 2010-10-13 15:55 99218768 ----a-w- c:\windows\system32\MRT.exe
2014-08-05 07:20 . 2010-12-20 11:35 270496 ------w- c:\windows\system32\MpSigStub.exe
2014-07-21 17:35 . 2014-07-21 17:35 687 ----a-w- C:\awh4A3D.tmp
2014-07-19 15:44 . 2014-07-19 15:44 687 ----a-w- C:\awh3716.tmp
2014-07-18 15:11 . 2014-07-18 15:11 687 ----a-w- C:\awh750.tmp
2014-07-18 14:37 . 2014-07-18 14:37 687 ----a-w- C:\awh580E.tmp
2014-07-18 14:28 . 2014-07-18 14:28 687 ----a-w- C:\awh40C7.tmp
2014-07-18 06:06 . 2014-07-18 06:06 687 ----a-w- C:\awh1AEF.tmp
2014-07-17 06:59 . 2014-07-17 06:59 687 ----a-w- C:\awh422D.tmp
2014-07-17 04:17 . 2014-07-17 04:17 687 ----a-w- C:\awh4327.tmp
2014-07-16 14:43 . 2012-05-30 06:30 20280 ----a-w- c:\windows\system32\roboot64.exe
2014-07-15 10:26 . 2014-07-15 10:26 687 ----a-w- C:\awh8729.tmp
2014-07-15 05:27 . 2014-07-15 05:27 687 ----a-w- C:\awhE7BB.tmp
2014-07-11 15:31 . 2014-07-11 15:31 687 ----a-w- C:\awhBA2A.tmp
2014-07-11 06:50 . 2014-07-11 06:50 687 ----a-w- C:\awh79EF.tmp
2014-07-11 05:29 . 2014-07-11 05:29 687 ----a-w- C:\awhE2B0.tmp
2014-07-10 20:06 . 2014-07-10 20:06 687 ----a-w- C:\awh6585.tmp
2014-07-10 09:46 . 2014-07-10 09:46 687 ----a-w- C:\awh1C36.tmp
2014-07-09 12:03 . 2014-07-09 12:03 687 ----a-w- C:\awhBA49.tmp
2014-07-09 09:46 . 2012-11-17 11:41 699056 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-07-09 09:46 . 2012-11-17 11:41 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-07-09 09:46 . 2014-05-14 07:47 11204096 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2014-07-08 05:34 . 2014-07-08 05:34 687 ----a-w- C:\awh53D9.tmp
2014-07-07 05:03 . 2014-07-07 05:03 687 ----a-w- C:\awh474C.tmp
2014-07-06 09:34 . 2014-07-06 09:34 687 ----a-w- C:\awh9DC4.tmp
2014-07-03 18:57 . 2014-07-03 18:57 687 ----a-w- C:\awh4F67.tmp
2014-07-03 07:21 . 2014-07-03 07:21 687 ----a-w- C:\awhCAAE.tmp
2014-06-30 18:35 . 2014-06-30 18:35 687 ----a-w- C:\awhA0FF.tmp
2014-06-29 12:21 . 2014-06-29 12:21 687 ----a-w- C:\awhDF56.tmp
2014-06-28 07:16 . 2014-06-28 07:16 687 ----a-w- C:\awhC681.tmp
2014-06-25 20:34 . 2014-06-25 20:34 0 ----a-w- c:\windows\SysWow64\shoF32B.tmp
2014-06-25 14:36 . 2014-06-25 14:36 687 ----a-w- C:\awh843C.tmp
2014-06-25 05:27 . 2014-06-25 05:27 687 ----a-w- C:\awh53F9.tmp
2014-06-24 20:32 . 2014-06-24 20:32 687 ----a-w- C:\awh6891.tmp
2014-06-22 09:11 . 2014-06-22 09:11 687 ----a-w- C:\awh58E8.tmp
2014-06-21 08:12 . 2014-06-21 08:12 687 ----a-w- C:\awhF48B.tmp
2014-06-20 12:29 . 2014-06-20 12:29 687 ----a-w- C:\awh8D6F.tmp
2014-06-18 09:44 . 2014-06-19 12:55 608179 ----a-w- c:\users\Norman\AppData\Local\AnyProtectScannerSetup.exe
2014-06-18 02:18 . 2014-07-09 13:17 692736 ----a-w- c:\windows\system32\osk.exe
2014-06-18 01:51 . 2014-07-09 13:17 646144 ----a-w- c:\windows\SysWow64\osk.exe
2014-06-16 14:59 . 2014-06-16 14:59 108544 ----a-w- c:\windows\SysWow64\hfnapi.dll
2014-06-16 14:59 . 2014-06-16 14:59 246784 ----a-w- c:\windows\SysWow64\hfpapi.dll
2014-06-06 10:10 . 2014-07-09 13:17 624128 ----a-w- c:\windows\system32\qedit.dll
2014-06-06 09:44 . 2014-07-09 13:17 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2014-06-05 14:45 . 2014-07-09 13:16 1460736 ----a-w- c:\windows\system32\lsasrv.dll
2014-06-05 14:26 . 2014-07-09 13:16 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2014-06-05 14:25 . 2014-07-09 13:16 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2014-05-30 08:08 . 2014-07-09 13:17 210944 ----a-w- c:\windows\system32\wdigest.dll
2014-05-30 08:08 . 2014-07-09 13:17 86528 ----a-w- c:\windows\system32\TSpkg.dll
2014-05-30 08:08 . 2014-07-09 13:17 340992 ----a-w- c:\windows\system32\schannel.dll
2014-05-30 08:08 . 2014-07-09 13:17 314880 ----a-w- c:\windows\system32\msv1_0.dll
2014-05-30 08:08 . 2014-07-09 13:17 307200 ----a-w- c:\windows\system32\ncrypt.dll
2014-05-30 08:08 . 2014-07-09 13:17 728064 ----a-w- c:\windows\system32\kerberos.dll
2014-05-30 08:08 . 2014-07-09 13:17 22016 ----a-w- c:\windows\system32\credssp.dll
2014-05-30 07:52 . 2014-07-09 13:17 172032 ----a-w- c:\windows\SysWow64\wdigest.dll
2014-05-30 07:52 . 2014-07-09 13:17 65536 ----a-w- c:\windows\SysWow64\TSpkg.dll
2014-05-30 07:52 . 2014-07-09 13:17 247808 ----a-w- c:\windows\SysWow64\schannel.dll
2014-05-30 07:52 . 2014-07-09 13:17 220160 ----a-w- c:\windows\SysWow64\ncrypt.dll
2014-05-30 07:52 . 2014-07-09 13:17 259584 ----a-w- c:\windows\SysWow64\msv1_0.dll
2014-05-30 07:52 . 2014-07-09 13:17 550912 ----a-w- c:\windows\SysWow64\kerberos.dll
2014-05-30 07:52 . 2014-07-09 13:17 17408 ----a-w- c:\windows\SysWow64\credssp.dll
2014-05-30 06:45 . 2014-07-09 13:17 497152 ----a-w- c:\windows\system32\drivers\afd.sys
2014-05-28 07:03 . 2014-05-28 07:03 0 ----a-w- c:\windows\SysWow64\shoB2FA.tmp
2009-04-08 17:31 . 2009-04-08 17:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-12 04:45 . 2008-08-12 04:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
2011-01-17 14:54 175912 ----a-w- c:\program files (x86)\DVDVideoSoftTB\prxtbDVDV.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files (x86)\DVDVideoSoftTB\prxtbDVDV.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GoogleChromeAutoLaunch_29B69EEE740A47DF7549CA7579BEBBEF"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2014-08-07 860488]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe -d [2010-6-8 12862]
Microsoft Office.lnk - c:\program files (x86)\Microsoft Office\Office10\OSA.EXE -b -l [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys;c:\windows\SYSNATIVE\DRIVERS\ewusbnet.sys [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys;c:\windows\SYSNATIVE\DRIVERS\ggflt.sys [x]
R3 globalUpdatem;globalUpdate Update Service (globalUpdatem);c:\program files (x86)\globalUpdate\Update\GoogleUpdate.exe;c:\program files (x86)\globalUpdate\Update\GoogleUpdate.exe [x]
R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys;c:\windows\SYSNATIVE\DRIVERS\ewusbfake.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 massfilter;Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys;c:\windows\SYSNATIVE\drivers\massfilter.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x]
R3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [x]
R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 PuranDefrag;PuranDefrag;c:\windows\system32\PuranDefragS.exe;c:\windows\SYSNATIVE\PuranDefragS.exe [x]
R4 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys;c:\windows\SYSNATIVE\DRIVERS\lullaby.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 scores;scores;c:\windows\score.exe;c:\windows\score.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x]
S2 UI Assistant Service;UI Assistant Service;c:\program files (x86)\1&1 Surf-Stick\AssistantServices.exe;c:\program files (x86)\1&1 Surf-Stick\AssistantServices.exe [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);c:\windows\system32\DRIVERS\JME.sys;c:\windows\SYSNATIVE\DRIVERS\JME.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-08-13 11:36 1104200 ----a-w- c:\program files (x86)\Google\Chrome\Application\36.0.1985.143\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-08-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-17 09:46]
.
2014-06-18 c:\windows\Tasks\ASUS SmartLogon Console Sensor.job
- c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe [2009-07-31 17:38]
.
2014-08-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-06-08 21:07]
.
2014-08-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-06-08 21:07]
.
2014-08-21 c:\windows\Tasks\MT66 Software Update.job
- c:\program files (x86)\Common Files\MT66 Software Update\UpdateClient.exe [2012-12-08 17:44]
.
2014-04-02 c:\windows\Tasks\User_Feed_Synchronization-{F29BB976-EE78-451D-926D-D0607B097FA2}.job
- c:\windows\system32\msfeedssync.exe [2013-12-04 08:55]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-01-10 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-01-10 392984]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-01-10 417560]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = about:newtab
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
mDefault_Page_URL = www.google.com
mStart Page = about:newtab
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.google.com
mSearch Bar = hxxp://www.google.com
uSearchAssistant = www.google.com
uSearchURL,(Default) = www.google.com/
IE: &Citavi Picker... - file://c:\programdata\Swiss Academic Software\Citavi Picker\Internet Explorer\ShowContextMenu.html
IE: An OneNote s&enden - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: Free YouTube to Mp3 Converter - c:\users\Norman\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~1\Office10\EXCEL.EXE/3000
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
WebBrowser-{872B5B88-9DB5-4310-BDD0-AC189557E5F5} - (no file)
AddRemove-K_Series_ScreenSaver_EN - c:\windows\system32\K_Series_ScreenSaver_EN.scr
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-420645628-1813877703-113317616-1001\Software\SecuROM\License information*]
"datasecu"=hex:ad,83,d5,3f,8a,72,7d,7b,60,89,b5,c0,a8,df,05,70,ae,3a,e5,16,c9,
b0,0b,82,14,95,d0,a0,ee,cb,78,4d,19,34,84,71,65,30,21,1d,56,ee,6d,a6,69,04,\
"rkeysecu"=hex:51,83,8d,fb,bf,3d,92,99,22,9a,2a,04,84,cc,cf,a3
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.14"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\SysWOW64\IoctlSvc.exe
c:\program files (x86)\ASUS\ControlDeck\ControlDeck.exe
c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
c:\windows\AsScrPro.exe
c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2014-08-21 11:24:05 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2014-08-21 09:24
.
Vor Suchlauf: 3.615.866.880 Bytes frei
Nach Suchlauf: 9.619.111.936 Bytes frei
.
- - End Of File - - FB1D0E53C0FEB0A3B65EFAD1D429ED15 |