Eledwhen | 21.02.2015 14:02 | Erstmal vielen herzlichen Dank für die äußerst schnelle Hilfe.
Desweiteren habe ich nun Punkt für Punkt abgearbeitet und habe hier nun den Log.
*editiert: Vom Desktop ausgeführt, erst überlesen, sry. Code:
ComboFix 15-02-16.01 - Eledwhen 21.02.2015 14:33:57.2.4 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.3564.2174 [GMT 1:00]
ausgeführt von:: c:\users\Eledwhen\Desktop\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Desktop *Enabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\ntuser.pol
C:\readme.txt
c:\users\Eledwhen\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\users\Eledwhen\AppData\Roaming\InetStat\inetstat.exe
c:\users\Eledwhen\AppData\Roaming\systweak\ssd\SSDPTstub.exe
c:\windows\system32\roboot.exe
c:\windows\system32\Tasks\Optimizer Pro Schedule
.
.
((((((((((((((((((((((( Dateien erstellt von 2015-01-21 bis 2015-02-21 ))))))))))))))))))))))))))))))
.
.
2015-02-21 13:40 . 2015-02-21 13:40 -------- d-----w- c:\users\HomeGroupUser$\AppData\Local\temp
2015-02-21 13:40 . 2015-02-21 13:40 -------- d-----w- c:\users\Gast\AppData\Local\temp
2015-02-21 13:40 . 2015-02-21 13:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-02-21 13:40 . 2015-02-21 13:40 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2015-02-21 12:36 . 2015-02-21 12:36 -------- d-----w- c:\program files\VS Revo Group
2015-02-21 12:27 . 2015-02-21 12:28 114904 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-02-21 12:27 . 2015-02-21 12:27 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2015-02-21 12:27 . 2015-02-21 12:27 -------- d-----w- c:\programdata\Malwarebytes
2015-02-21 12:27 . 2014-11-21 05:14 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2015-02-21 12:27 . 2014-11-21 05:14 75480 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-02-21 12:27 . 2014-11-21 05:14 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2015-02-21 11:49 . 2015-02-21 12:14 -------- d-----w- C:\FRST
2015-02-19 07:05 . 2015-02-19 07:05 -------- d-----w- c:\program files\LogMeIn Hamachi
2015-02-18 13:57 . 2015-02-18 13:57 -------- d-----w- c:\users\Eledwhen\AppData\Roaming\HandBrake
2015-02-18 13:51 . 2015-02-18 13:51 -------- d-----w- c:\users\Eledwhen\AppData\Roaming\RHEng
2015-02-17 13:48 . 2015-02-17 14:10 -------- d-----w- c:\users\Eledwhen\AppData\Local\JDownloader 2.0
2015-02-17 13:44 . 2015-02-17 13:44 -------- d-----w- c:\program files\Common Files\Java
2015-02-17 13:44 . 2015-02-17 13:44 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2015-02-17 13:43 . 2015-02-17 13:43 -------- d-----w- c:\program files\Java
2015-02-12 09:03 . 2015-01-23 03:43 620032 ----a-w- c:\windows\system32\jscript9diag.dll
2015-02-12 09:03 . 2015-01-23 03:17 4300800 ----a-w- c:\windows\system32\jscript9.dll
2015-02-11 07:15 . 2015-01-14 05:44 3972544 ----a-w- c:\windows\system32\ntkrnlpa.exe
2015-02-08 05:21 . 2015-02-08 05:21 -------- d-----w- c:\program files\Origin Games
2015-02-08 05:21 . 2015-02-08 05:23 -------- d-----w- c:\users\Eledwhen\AppData\Roaming\Origin
2015-02-08 05:21 . 2015-02-08 05:23 -------- d-----w- c:\users\Eledwhen\AppData\Local\Origin
2015-02-08 05:20 . 2015-02-09 08:34 -------- d-----w- c:\programdata\Origin
2015-02-08 05:20 . 2015-02-09 08:34 -------- d-----w- c:\program files\Origin
2015-02-04 19:23 . 2015-02-08 05:20 -------- d-----w- c:\programdata\Electronic Arts
2015-02-04 19:06 . 2015-02-04 19:06 -------- d-----w- c:\program files\Microsoft WSE
2015-01-31 09:35 . 2015-01-09 22:25 621200 ----a-w- c:\windows\system32\nvStreaming.exe
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-02-16 15:20 . 2014-06-25 08:36 26176 ---ha-w- c:\windows\system32\hamachi.sys
2015-02-12 10:00 . 2014-09-26 10:18 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2015-02-12 10:00 . 2014-09-26 10:18 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2015-02-05 18:55 . 2014-06-01 18:26 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-02-05 18:55 . 2014-06-01 18:26 701616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-01-26 10:47 . 2014-09-26 10:18 1236816 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2015-01-25 10:27 . 2014-09-30 08:24 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2015-01-25 10:27 . 2014-09-30 08:24 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2015-01-24 09:38 . 2014-11-13 10:46 1236816 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2015-01-10 02:43 . 2015-01-03 18:26 2902272 ----a-w- c:\windows\system32\nvapi.dll
2015-01-10 02:43 . 2014-06-02 16:28 60560 ----a-w- c:\windows\system32\OpenCL.dll
2015-01-10 02:43 . 2014-06-02 16:27 16009120 ----a-w- c:\windows\system32\nvwgf2um.dll
2015-01-10 02:43 . 2014-06-02 16:27 14116136 ----a-w- c:\windows\system32\nvd3dum.dll
2015-01-09 22:58 . 2014-06-02 16:29 4404040 ----a-w- c:\windows\system32\nvcpl.dll
2015-01-09 22:58 . 2014-06-02 16:29 3057808 ----a-w- c:\windows\system32\nvsvc.dll
2015-01-09 22:58 . 2014-06-02 16:29 670352 ----a-w- c:\windows\system32\nvvsvc.exe
2015-01-09 22:58 . 2014-06-02 16:29 61584 ----a-w- c:\windows\system32\nvshext.dll
2015-01-09 22:58 . 2014-06-02 16:29 374928 ----a-w- c:\windows\system32\nvmctray.dll
2015-01-09 22:58 . 2014-06-02 16:29 2554184 ----a-w- c:\windows\system32\nvsvcr.dll
2014-12-19 02:43 . 2015-01-14 11:23 164864 ----a-w- c:\windows\system32\profsvc.dll
2014-12-19 01:34 . 2015-01-14 11:23 116224 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2014-12-18 02:01 . 2015-01-03 18:26 27280 ----a-w- c:\windows\system32\nvhdap32.dll
2014-12-18 02:01 . 2015-01-03 18:26 161424 ----a-w- c:\windows\system32\drivers\nvhda32v.sys
2014-12-18 02:01 . 2014-06-02 16:27 908608 ----a-w- c:\windows\system32\nvhdagenco3220103.dll
2014-12-13 10:02 . 2015-01-03 18:26 1047696 ----a-w- c:\windows\system32\nvdispco3234709.dll
2014-12-13 10:02 . 2015-01-03 18:26 911504 ----a-w- c:\windows\system32\nvdispgenco3234709.dll
2014-12-13 00:11 . 2015-01-03 18:44 2210040 ----a-w- c:\windows\system32\nvspcap.dll
2014-12-13 00:11 . 2015-01-03 18:44 1291464 ----a-w- c:\windows\system32\nvspbridge.dll
2014-12-11 17:47 . 2015-01-14 11:23 56320 ----a-w- c:\windows\system32\TSWbPrxy.exe
2014-12-06 03:50 . 2015-01-14 11:23 242688 ----a-w- c:\windows\system32\nlasvc.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{D5CC379B-625E-74AF-A0EA-DE98A516B2F7}]
2014-08-12 08:03 332800 ----a-w- c:\programdata\deaal4me\1hLZqI.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-10-21 16:52 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-10-21 16:52 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-10-21 16:52 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-10-21 16:52 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-10-21 16:52 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2014-03-04 3696912]
"Akamai NetSession Interface"="c:\users\Eledwhen\AppData\Local\Akamai\netsession_win.exe" [2014-10-29 4673432]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2014-04-10 12021464]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2014-12-09 702768]
"NvBackend"="c:\program files\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-12-13 2531472]
"ShadowPlay"="c:\windows\system32\nvspcap.dll" [2014-12-13 2210040]
"Avira Systray"="c:\program files\Avira\My Avira\Avira.OE.Systray.exe" [2015-01-19 126712]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2014-12-17 508800]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2015-02-17 3978600]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.8.150\SSScheduler.exe [2014-4-9 279456]
PIPModeResolutionUtility.lnk - c:\program files\LG Electronics\Auto Resolution\bin\AppResUtilityService.exe -startup [2014-6-1 338472]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"HP Software Update"=c:\program files\Hp\HP Software Update\HPWuSchd2.exe
.
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2014-12-11 315496]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-01-12 102912]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.8.150\McCHSvc.exe [2014-04-09 235696]
R3 Origin Client Service;Origin Client Service;c:\program files\Origin\OriginClientService.exe [2015-02-08 1910128]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 Synth3dVsc;Microsoft Virtual 3D Video Transport Driver;c:\windows\system32\drivers\Synth3dVsc.sys [2010-11-20 77184]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2012-08-23 24064]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 27136]
R3 tsusbhub;Remote Deskotop USB Hub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-20 112640]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2014-08-15 37352]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2014-06-13 243128]
S1 netfilter;netfilter;c:\windows\system32\drivers\netfilter.sys [2014-06-12 31744]
S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2014-12-09 431920]
S2 Avira.OE.ServiceHost;Avira Service Host;c:\program files\Avira\My Avira\Avira.OE.ServiceHost.exe [2015-01-19 182520]
S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-07-14 1390176]
S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-07-14 1767520]
S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-12-13 915600]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2015-02-17 1848680]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn Hamachi\LMIGuardianSvc.exe [2015-02-16 411920]
S2 NvNetworkService;NVIDIA Network Service;c:\program files\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-12-13 1701520]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-12-13 18186896]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-01-09 410768]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-12-13 18576]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad32v.sys [2014-11-22 32912]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2013-11-26 683736]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-02-01 12:22 1086280 ----a-w- c:\program files\Google\Chrome\Application\40.0.2214.94\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2015-02-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-01 18:55]
.
2015-02-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-07-12 18:47]
.
2015-02-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-07-12 18:47]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://myhome.vi-view.com/?type=hp&ts=1421413001&from=cor&uid=SAMSUNGXHD103SI_S1VSJ9CS507234
mStart Page = hxxp://myhome.vi-view.com/?type=hp&ts=1421413001&from=cor&uid=SAMSUNGXHD103SI_S1VSJ9CS507234
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK217RbjR1YFa37oBy_U-nTnTbDTt8PVUCrSqw52C61hLp8hv9QZmpJ5Ag6gYp5YX9h9CiuEDb4WkOwFM7qcutI0GooqJR1aC_N5KIFGttSsLOWJvh3Vz9hsjYy_WK68qFkuydAXKBX6KtJtkjrYWyGbM97zPymQ1cbPguPcLUprsCa1llzxkoroDGLZRd4XLe-sFB3IvfA,,&q={searchTerms}
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKCU-Run-InetStat - c:\users\Eledwhen\AppData\Roaming\InetStat\inetstat.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,55,e9,da,82,56,57,4b,49,81,65,6d,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,55,e9,da,82,56,57,4b,49,81,65,6d,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\system32\conhost.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\conhost.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2015-02-21 14:46:41 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2015-02-21 13:46
ComboFix2.txt 2015-02-21 12:59
.
Vor Suchlauf: 25 Verzeichnis(se), 425.244.262.400 Bytes frei
Nach Suchlauf: 27 Verzeichnis(se), 425.211.305.984 Bytes frei
.
- - End Of File - - 5580CA217DB4342AB8AF4032122DBB01
A36C5E4F47E84449FF07ED3517B43A31 |