suc4life | 20.03.2015 15:07 | Okay mach ich.
habe noch nen Log von malewarebyts von heute. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 20.03.2015
Suchlauf-Zeit: 14:07:50
Logdatei: 2.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.03.20.04
Rootkit Datenbank: v2015.02.25.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Esther
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 371022
Verstrichene Zeit: 14 Min, 49 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 12
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\27058, , [08bc5fe8058504321a61a055d42ff709],
PUP.Optional.QuickRef.A, HKLM\SOFTWARE\WOW6432NODE\QuickRef_1.10.0.9, , [a3213611b0daea4c53ad8e2cc73c16ea],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\27058, , [d2f270d74e3cf046572408edea19a759],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, , [b1132d1ab0dad561d4196dcc877e43bd],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, , [f3d1a99e4842270fc32b3603f90c6799],
PUP.Optional.ASPackage.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SERVERAS, , [bd07f05716742c0a7134644adf24cf31],
PUP.Optional.TermTutor.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TTNFD, , [6c587dca51393bfba8db706058ab2dd3],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3568682189-3202487810-3345936486-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\27058, , [ac188dba7d0de74fe33b3e91b84bb050],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3568682189-3202487810-3345936486-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\System NotifierV12.03, , [e2e2a4a3f9916bcb8c237053f60dd32d],
PUP.Optional.IStart.A, HKU\S-1-5-21-3568682189-3202487810-3345936486-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\MOZILLA\EXTENDS, , [a3214dfae8a21a1ce39e753d4ab9f40c],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, , [e3e18abd4c3e49ed5914296234cf44bc],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, , [e3e18abd4c3e49ed5914296234cf44bc],
Registrierungswerte: 5
PUP.Optional.TermTutor.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|termtutor@termtutor.com, C:\Program Files (x86)\Mozilla Firefox\extensions\termtutor@termtutor.com, , [6e564007602a4beb8cf5636daa59926e]
PUP.Optional.ASPackage.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SERVERAS|ImagePath, C:\Users\Esther\AppData\Roaming\ASPackage\ASSrv.exe, , [bd07f05716742c0a7134644adf24cf31]
PUP.Optional.TermTutor.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TTNFD|ImagePath, system32\drivers\ttnfd.sys, , [6c587dca51393bfba8db706058ab2dd3]
Hijack.ShellA.Gen, HKU\S-1-5-21-3568682189-3202487810-3345936486-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON|shell, explorer.exe, "C:\Users\Esther\AppData\Roaming\Microsoft\Windows\consolehost.exe", , [8d37f453e8a203335f27b9fff112c739]
PUP.Optional.IStart.A, HKU\S-1-5-21-3568682189-3202487810-3345936486-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\MOZILLA\EXTENDS|appid, istart_ffnt@gmail.com, , [a3214dfae8a21a1ce39e753d4ab9f40c]
Registrierungsdaten: 14
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC&q={searchTerms}),,[735187c0eb9fc3736074af34e124bd43]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hp&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC),,[ae16f2556624d95d8252d60df4117d83]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.mystartsearch.com/?type=hp&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC),,[477d4601a9e12a0ce7ed9251d82d09f7]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC&q={searchTerms}),,[5c68390e3c4e41f563711cc77c895fa1]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[6460331499f152e467f629c7a0658878]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC&q={searchTerms}),,[d6eeb7901e6c7db9c31128bbbf46cb35]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hp&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC),,[be0662e58109999da92b6b787d88c040]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.mystartsearch.com/?type=hp&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC),,[9430380f8efceb4b20b4964d46bf12ee]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC&q={searchTerms}),,[2a9a64e30882c96dd7fd6e75da2b946c]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[952fc87f1278053155080be5e2231be5]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-3568682189-3202487810-3345936486-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC&q={searchTerms}),,[14b01b2ce8a242f4795c489ba85df40c]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-3568682189-3202487810-3345936486-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.mystartsearch.com/?type=hp&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC),,[a22204431476dc5aa82d4a99f510d729]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-3568682189-3202487810-3345936486-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hp&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC),,[60645fe80a806acc8154f8ebbd4834cc]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-3568682189-3202487810-3345936486-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC&q={searchTerms}),,[0bb9a4a3d5b564d2b3228f54050021df]
Ordner: 1
PUP.Optional.GlobalUpdate.A, C:\Users\Esther\AppData\Local\Temp\comh.160363, , [e3e18abd4c3e49ed5914296234cf44bc],
Dateien: 35
PUP.Optional.MyStartSearch.A, C:\$Recycle.Bin\S-1-5-21-3568682189-3202487810-3345936486-1002\$RG96AEP.tmp, , [40848abd791196a086a538f1986e41bf],
PUP.Optional.Winsock.Hijack, C:\Windows\SysWOW64\BDL.dll, , [4084380f66246accfc6865d18280629e],
PUP.Optional.QuickRef.A, C:\Windows\System32\drivers\qrnfd_1_10_0_9.sys, , [a91ba1a66228d462de93f32a3cc66898],
PUP.Optional.SnapDo.A, C:\Windows\Installer\291e8e.msi, , [972d3d0a8703fe38c18c288806fb36ca],
PUP.Optional.VeriStaff, C:\Windows\Installer\291e95.msi, , [83410542a3e746f0dfbf65f8629e9b65],
PUP.Optional.SmartBar, C:\Windows\Installer\MSIF338.tmp-\Smartbar.Installer.CustomActions.dll, , [eadaaa9d3d4d2f07efb68ba3cd337090],
PUP.Optional.SmartBar, C:\Windows\Installer\MSI7E44.tmp-\Smartbar.Installer.CustomActions.dll, , [952ffe49a1e9d561168f99953cc4e020],
PUP.Optional.BasementDuster.A, C:\Users\Esther\AppData\Local\Temp\BasementDusterr.log, , [33917acdadddaa8c6f446945bb48956b],
PUP.Optional.BasementDuster.A, C:\Windows\Temp\BasementDuster.log, , [9b29f354820864d2862d75394db6b54b],
PUP.Optional.BasementDuster.A, C:\Windows\Temp\BasementDusterr.log, , [a0244ff83e4c4beb3d76feb049ba18e8],
PUP.Optional.BasementDuster.A, C:\Users\Esther\AppData\Local\Temp\BDL.ini.log, , [20a426215238fd39c6eef0be986be41c],
PUP.Optional.BasementDuster.A, C:\Windows\System32\BasementDusterOff.ini, , [556fde69b2d80036f9bc0da180836d93],
PUP.Optional.BasementDuster.A, C:\Windows\SysWOW64\BasementDusterOff.ini, , [388c0245a6e48ea8a90c109ee32018e8],
PUP.Optional.Astromenda, C:\Users\Esther\AppData\Roaming\Mozilla\Firefox\Profiles\5k46ozs4.default\searchplugins\Astromenda.xml, , [6e5606412b5f7db9009bbd16be4508f8],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\bf32074a-df96-4108-a46b-04ec16af1242-10_user, , [7450410658329d993f95fcde0ff45ba5],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\bf32074a-df96-4108-a46b-04ec16af1242-5, , [2e960d3adeacfe3833a1d30752b1c23e],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\bf32074a-df96-4108-a46b-04ec16af1242-5_user, , [edd71e29f595a49264708258a1621fe1],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\bf32074a-df96-4108-a46b-04ec16af1242-10_user.job, , [e9dbda6dee9c9e98cbfbe84fe81dc838],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\bf32074a-df96-4108-a46b-04ec16af1242-5.job, , [a4201e297e0ca88e2d9974c365a07b85],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\bf32074a-df96-4108-a46b-04ec16af1242-5_user.job, , [60642d1a533777bf6c5ae057bb4a58a8],
PUP.Optional.Vitruvian.A, C:\Users\Esther\AppData\Local\Temp\vitruvian-installer-hardwareprofile-v0001, , [a1231a2dafdb5ed83c0e6cd4709551af],
PUP.Optional.Vitruvian.A, C:\Users\Esther\AppData\Local\Temp\vitruvian-installer-install-v0003, , [6c589aada5e563d3074387b922e3e21e],
PUP.Optional.Vitruvian.A, C:\Users\Esther\AppData\Local\Temp\vitruvian-installer-processes-v0002, , [ab19311606842214ee5c0c34aa5ba55b],
PUP.Optional.Vitruvian.A, C:\Users\Esther\AppData\Local\Temp\vitruvian-installer-scheduledtasks-v0001, , [6c58c78063275adc301a46faf2131ce4],
PUP.Optional.GlobalUpdate.A, C:\Users\Esther\AppData\Local\Temp\comh.160363\GoogleCrashHandler.exe, , [e3e18abd4c3e49ed5914296234cf44bc],
PUP.Optional.GlobalUpdate.A, C:\Users\Esther\AppData\Local\Temp\comh.160363\GoogleUpdate.exe, , [e3e18abd4c3e49ed5914296234cf44bc],
PUP.Optional.GlobalUpdate.A, C:\Users\Esther\AppData\Local\Temp\comh.160363\GoogleUpdateBroker.exe, , [e3e18abd4c3e49ed5914296234cf44bc],
PUP.Optional.GlobalUpdate.A, C:\Users\Esther\AppData\Local\Temp\comh.160363\GoogleUpdateHelper.msi, , [e3e18abd4c3e49ed5914296234cf44bc],
PUP.Optional.GlobalUpdate.A, C:\Users\Esther\AppData\Local\Temp\comh.160363\GoogleUpdateOnDemand.exe, , [e3e18abd4c3e49ed5914296234cf44bc],
PUP.Optional.GlobalUpdate.A, C:\Users\Esther\AppData\Local\Temp\comh.160363\goopdate.dll, , [e3e18abd4c3e49ed5914296234cf44bc],
PUP.Optional.GlobalUpdate.A, C:\Users\Esther\AppData\Local\Temp\comh.160363\goopdateres_en.dll, , [e3e18abd4c3e49ed5914296234cf44bc],
PUP.Optional.GlobalUpdate.A, C:\Users\Esther\AppData\Local\Temp\comh.160363\npGoogleUpdate4.dll, , [e3e18abd4c3e49ed5914296234cf44bc],
PUP.Optional.GlobalUpdate.A, C:\Users\Esther\AppData\Local\Temp\comh.160363\psmachine.dll, , [e3e18abd4c3e49ed5914296234cf44bc],
PUP.Optional.GlobalUpdate.A, C:\Users\Esther\AppData\Local\Temp\comh.160363\psuser.dll, , [e3e18abd4c3e49ed5914296234cf44bc],
PUP.Optional.MyStartSearch.A, C:\Users\Esther\AppData\Roaming\Mozilla\Firefox\Profiles\5k46ozs4.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://www.mystartsearch.com/newtab/?type=nt&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC");), ,[1da7a0a7672339fd0720f932d0362ad6]
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) Hier der Log von Combofix Code:
ComboFix 15-03-14.03 - Esther 20.03.2015 14:32:18.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3828.1886 [GMT 1:00]
ausgeführt von:: C:\Users\Esther\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
C:\ProgramData\PCDr\6584\AddOnDownloaded\01729c78-925e-4e01-a2dd-3c0f0989e6d1.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\095557b2-2408-4eaf-b39b-d55c8606482c.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\10494c60-ec8b-4856-b24a-b6d076c4499f.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\526d8043-c04a-458e-b41c-9f0b037eb5ab.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\649574c7-1acb-458c-a846-1bc04bfcdb93.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\6b56d7e1-5ac6-46da-8615-10fbe2919ac8.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\6f9e83ca-5216-40db-863d-61ffff2a1563.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\7419b29f-5d5c-499d-8452-7a5038bd3fda.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\7bcbc662-5181-400d-af1d-2d1e64d3d11a.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\812fed95-c1fb-4695-be1a-fd6265302cf9.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\95863b84-2a1c-4539-bd21-ffbef3ea7fd9.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\9afbb1e4-1951-4d6e-bd32-2e0e5254786f.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\a7a4f473-8998-4029-be3e-f4280478bd6b.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\ac83e4d3-2f37-4679-a3b4-b7f5aa568264.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\b282128e-9a7f-43e3-90a2-c1f1133ea714.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\b4e7e391-8ff3-4363-bb72-f41a243749b1.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\b9f9154e-1581-4a2a-a195-eeb46e9e239b.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\c6528f35-d623-4e84-a9b2-58ecb22dabd4.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\c746a3b1-ed0c-4bff-941c-d5e6f0583ce7.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\edb10714-8498-4679-a667-4c4c359de017.dll
C:\ProgramData\PCDr\6584\AddOnDownloaded\ef32b2f9-e518-400c-8172-d1a06ae9d208.dll
C:\Windows\assembly\tmp\U
C:\Windows\SysWow64\hookdll.dll
((((((((((((((((((((((( Dateien erstellt von 2015-02-20 bis 2015-03-20 ))))))))))))))))))))))))))))))
2015-03-20 12:18:06 . 2015-03-20 12:20:13 -------- d-----w- C:\FRST
2015-03-19 15:11:43 . 2015-03-19 15:11:43 -------- d-----w- C:\Program Files (x86)\VS Revo Group
2015-03-19 14:47:33 . 2015-03-19 14:47:35 -------- d-----w- C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-19 13:54:11 . 2015-03-20 13:50:30 129752 ----a-w- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2015-03-19 13:52:03 . 2015-03-19 13:52:05 -------- d-----w- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-03-19 13:52:03 . 2015-03-19 13:52:03 -------- d-----w- C:\ProgramData\Malwarebytes
2015-03-19 13:52:03 . 2014-11-21 05:14:22 63704 ----a-w- C:\Windows\system32\drivers\mwac.sys
2015-03-19 13:52:03 . 2014-11-21 05:14:12 93400 ----a-w- C:\Windows\system32\drivers\mbamchameleon.sys
2015-03-19 13:52:03 . 2014-11-21 05:14:08 25816 ----a-w- C:\Windows\system32\drivers\mbam.sys
2015-03-18 14:20:48 . 2015-03-16 15:21:54 295808 ------w- C:\Windows\SysWow64\BDL.dll
2015-03-18 14:08:46 . 2015-03-18 14:08:46 -------- d-----w- C:\Users\Esther\AppData\Local\globalUpdate
2015-03-18 14:07:32 . 2015-03-18 14:07:32 -------- d-----w- C:\Users\Esther\AppData\Roaming\Lavasoft
2015-03-18 14:07:32 . 2015-03-18 14:07:32 -------- d-----w- C:\ProgramData\Lavasoft
2015-03-17 20:17:09 . 2015-02-20 04:41:01 41984 ----a-w- C:\Windows\system32\lpk.dll
2015-03-17 20:17:09 . 2015-02-20 04:40:56 14336 ----a-w- C:\Windows\system32\dciman32.dll
2015-03-17 20:17:09 . 2015-02-20 04:40:55 46080 ----a-w- C:\Windows\system32\atmlib.dll
2015-03-17 20:17:09 . 2015-02-20 04:13:43 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2015-03-17 20:17:09 . 2015-02-20 03:29:16 372224 ----a-w- C:\Windows\system32\atmfd.dll
2015-03-17 20:17:09 . 2015-02-20 03:09:16 299008 ----a-w- C:\Windows\SysWow64\atmfd.dll
2015-03-17 20:17:08 . 2015-02-20 04:40:59 100864 ----a-w- C:\Windows\system32\fontsub.dll
2015-03-17 20:17:08 . 2015-02-20 04:13:49 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2015-03-17 20:17:08 . 2015-02-20 04:13:46 10240 ----a-w- C:\Windows\SysWow64\dciman32.dll
2015-03-17 20:17:08 . 2015-02-20 04:12:51 25600 ----a-w- C:\Windows\SysWow64\lpk.dll
2015-03-17 20:15:41 . 2015-02-03 03:31:08 215552 ----a-w- C:\Windows\system32\ubpm.dll
2015-03-17 20:06:40 . 2015-02-04 03:16:35 465920 ----a-w- C:\Windows\system32\WMPhoto.dll
2015-03-17 20:06:39 . 2015-02-04 02:54:09 417792 ----a-w- C:\Windows\SysWow64\WMPhoto.dll
2015-03-17 19:58:14 . 2015-01-09 03:14:27 91136 ----a-w- C:\Windows\system32\wdi.dll
2015-03-17 19:58:14 . 2015-01-09 03:14:19 950272 ----a-w- C:\Windows\system32\perftrack.dll
2015-03-17 19:58:14 . 2015-01-09 03:14:19 29696 ----a-w- C:\Windows\system32\powertracker.dll
2015-03-17 19:58:14 . 2015-01-09 02:48:18 76800 ----a-w- C:\Windows\SysWow64\wdi.dll
2015-02-21 09:14:45 . 2015-02-21 09:14:46 -------- d-----w- C:\Program Files\Dell Support Center
2015-02-21 06:54:47 . 2015-02-05 17:57:47 621384 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2015-02-21 06:54:44 . 2015-02-21 06:54:45 -------- d-----w- C:\Windows\SysWow64\NV
2015-02-21 06:54:44 . 2015-02-21 06:54:45 -------- d-----w- C:\Windows\system32\NV
2015-02-18 15:29:14 . 2015-02-18 15:29:14 255672 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\1031\OSFINTL.DLL
2015-02-18 13:58:30 . 2015-02-18 13:58:30 853712 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\1031\ACEWSTR.DLL
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
2015-03-18 13:59:15 . 2011-10-13 17:11:14 122905848 ----a-w- C:\Windows\system32\MRT.exe
2015-02-17 14:29:58 . 2015-02-17 14:29:58 1247912 ----a-w- C:\Windows\SysWow64\FM20.DLL
2015-02-06 19:58:34 . 2015-02-06 19:58:34 58224 ----a-w- C:\Windows\system32\drivers\qrnfd_1_10_0_9.sys
2015-02-06 17:02:10 . 2012-06-24 09:38:31 701616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2015-02-06 17:02:10 . 2011-06-28 06:01:26 71344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2015-02-05 21:01:44 . 2015-02-06 17:18:50 2902784 ----a-w- C:\Windows\SysWow64\nvapi.dll
2015-02-05 21:01:44 . 2014-12-22 19:33:48 877816 ----a-w- C:\Windows\SysWow64\nvumdshim.dll
2015-02-05 21:01:44 . 2014-12-22 19:33:46 164752 ----a-w- C:\Windows\SysWow64\nvinit.dll
2015-02-05 21:01:44 . 2014-12-22 19:33:44 14119744 ----a-w- C:\Windows\SysWow64\nvd3dum.dll
2015-02-05 21:01:44 . 2011-05-03 05:17:06 995248 ----a-w- C:\Windows\system32\nvumdshimx.dll
2015-02-05 21:01:44 . 2011-05-03 05:17:05 177624 ----a-w- C:\Windows\system32\nvinitx.dll
2015-02-05 21:01:44 . 2011-05-03 05:17:02 3299512 ----a-w- C:\Windows\system32\nvapi64.dll
2015-02-05 19:07:04 . 2010-12-24 01:10:26 6861128 ----a-w- C:\Windows\system32\nvcpl.dll
2015-02-05 19:07:03 . 2010-12-24 01:10:12 3517584 ----a-w- C:\Windows\system32\nvsvc64.dll
2015-02-05 19:07:00 . 2010-12-24 01:10:40 935056 ----a-w- C:\Windows\system32\nvvsvc.exe
2015-02-05 19:07:00 . 2010-12-24 01:10:40 2558792 ----a-w- C:\Windows\system32\nvsvcr.dll
2015-02-05 19:07:00 . 2010-12-23 18:10:40 62792 ----a-w- C:\Windows\system32\nvshext.dll
2015-02-05 19:06:59 . 2010-12-24 01:10:40 385168 ----a-w- C:\Windows\system32\nvmctray.dll
2015-02-05 19:06:59 . 2010-12-24 01:10:38 74896 ----a-w- C:\Windows\system32\nv3dappshextr.dll
2015-02-05 19:06:59 . 2010-12-24 01:10:38 1098384 ----a-w- C:\Windows\system32\nv3dappshext.dll
2015-02-05 12:50:11 . 2010-12-23 18:10:40 4236870 ----a-w- C:\Windows\system32\nvcoproc.bin
2015-02-04 03:16:29 . 2015-02-12 16:45:51 609280 ----a-w- C:\Windows\system32\generaltel.dll
2015-02-04 03:16:20 . 2015-02-12 16:45:50 762368 ----a-w- C:\Windows\system32\invagent.dll
2015-02-04 03:16:16 . 2015-02-12 16:45:49 414720 ----a-w- C:\Windows\system32\devinv.dll
2015-02-04 03:16:14 . 2015-02-12 16:45:50 894976 ----a-w- C:\Windows\system32\appraiser.dll
2015-02-04 03:16:13 . 2015-02-12 16:45:49 227328 ----a-w- C:\Windows\system32\aepdu.dll
2015-02-04 03:16:13 . 2015-02-12 16:45:49 192000 ----a-w- C:\Windows\system32\aepic.dll
2015-02-04 03:13:28 . 2015-02-12 16:45:50 1098752 ----a-w- C:\Windows\system32\aeinv.dll
2015-01-27 23:36:21 . 2015-02-12 16:45:49 1239720 ----a-w- C:\Windows\system32\aitstatic.exe
2015-01-10 08:07:47 . 2015-02-06 17:18:54 1895240 ----a-w- C:\Windows\system32\nvdispco6434725.dll
2015-01-10 08:07:47 . 2015-02-06 17:18:54 1556808 ----a-w- C:\Windows\system32\nvdispgenco6434725.dll
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-10-19 06:12:03 222712 ----a-w- C:\Users\Esther\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\SkyDriveShell.dll
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-10-19 06:12:03 222712 ----a-w- C:\Users\Esther\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\SkyDriveShell.dll
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-10-19 06:12:03 222712 ----a-w- C:\Users\Esther\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\SkyDriveShell.dll
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2015-01-21 13:59:12 1729744 ----a-w- C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2015-01-21 13:59:12 1729744 ----a-w- C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2015-01-21 13:59:12 1729744 ----a-w- C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"RoxWatchTray"="C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 10:33:58 240112]
"Acrobat Assistant 8.0"="C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe" [2012-09-23 19:43:48 3477640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"="C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [2011-10-10 16:40:49 559616]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=C:\Windows\SysWOW64\nvinit.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
R1 ttnfd;ttnfd;C:\Windows\system32\drivers\ttnfd.sys;C:\Windows\SYSNATIVE\drivers\ttnfd.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [x]
R2 serveras;AS Service component;C:\Users\Esther\AppData\Roaming\ASPackage\ASSrv.exe;C:\Users\Esther\AppData\Roaming\ASPackage\ASSrv.exe [x]
R2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe;C:\Program Files (x86)\Skype\Updater\Updater.exe [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\system32\DRIVERS\ssudbus.sys;C:\Windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 dgderdrv;dgderdrv;C:\Windows\system32\drivers\dgderdrv.sys;C:\Windows\SYSNATIVE\drivers\dgderdrv.sys [x]
R3 ggflt;SEMC USB Flash Driver Filter;C:\Windows\system32\DRIVERS\ggflt.sys;C:\Windows\SYSNATIVE\DRIVERS\ggflt.sys [x]
R3 globalUpdatem;globalUpdate Update Service (globalUpdatem);C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe;C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\system32\IEEtwCollector.exe;C:\Windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 JMCR;JMCR;C:\Windows\system32\DRIVERS\jmcr.sys;C:\Windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
R3 MBAMProtector;MBAMProtector;C:\Windows\system32\drivers\mbam.sys;C:\Windows\SYSNATIVE\drivers\mbam.sys [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;C:\Windows\system32\drivers\mwac.sys;C:\Windows\SYSNATIVE\drivers\mwac.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 NETw5s64;Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows 7 64-Bit;C:\Windows\system32\DRIVERS\NETw5s64.sys;C:\Windows\SYSNATIVE\DRIVERS\NETw5s64.sys [x]
R3 PCDSRVC{3B54B31B-D06B6431-06020200}_0;PCDSRVC{3B54B31B-D06B6431-06020200}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell\supportassist\pcdsrvc_x64.pkms;c:\program files\dell\supportassist\pcdsrvc_x64.pkms [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys;C:\Windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\Windows\system32\DRIVERS\ssudmdm.sys;C:\Windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys;C:\Windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TurboBoost;TurboBoost;C:\Program Files\Intel\TurboBoost\TurboBoost.exe;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [x]
R3 zghsmdm;ZTE General Handset USB Modem Proprietary;C:\Windows\system32\DRIVERS\zghsmdm.sys;C:\Windows\SYSNATIVE\DRIVERS\zghsmdm.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 nvpciflt;nvpciflt;C:\Windows\system32\DRIVERS\nvpciflt.sys;C:\Windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S0 PxHlpa64;PxHlpa64;C:\Windows\System32\Drivers\PxHlpa64.sys;C:\Windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\system32\DRIVERS\stdcfltn.sys;C:\Windows\SYSNATIVE\DRIVERS\stdcfltn.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys;C:\Windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AAV UpdateService;AAV UpdateService;C:\Program Files (x86)\AAVUpdateManager\aavus.exe;C:\Program Files (x86)\AAVUpdateManager\aavus.exe [x]
S2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [x]
S2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE;C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [x]
S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE;C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [x]
S2 GfExperienceService;NVIDIA GeForce Experience Service;C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe;C:\Program Files (x86)\Nero\Update\NASvc.exe [x]
S2 NOBU;Dell DataSafe Online;C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE;C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x]
S2 NvNetworkService;NVIDIA Network Service;C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE;C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE [x]
S2 ss_conn_service;SAMSUNG Mobile Connectivity Service;C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe;C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer9;TeamViewer 9;C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe;C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe [x]
S2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\system32\DRIVERS\TurboB.sys;C:\Windows\SYSNATIVE\DRIVERS\TurboB.sys [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 Acceler;Accelerometer Service;C:\Windows\system32\DRIVERS\Accelern.sys;C:\Windows\SYSNATIVE\DRIVERS\Accelern.sys [x]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys;C:\Windows\SYSNATIVE\DRIVERS\CtClsFlt.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys;C:\Windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys;C:\Windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display-Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys;C:\Windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys;C:\Windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys;C:\Windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
S3 NvStreamKms;NvStreamKms;C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);C:\Windows\system32\drivers\nvvad64v.sys;C:\Windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 qicflt;upper Device Filter Driver;C:\Windows\system32\DRIVERS\qicflt.sys;C:\Windows\SYSNATIVE\DRIVERS\qicflt.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys;C:\Windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys;C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys [x]
S3 wdkmd;Intel WiDi KMD;C:\Windows\system32\DRIVERS\WDKMD.sys;C:\Windows\SYSNATIVE\DRIVERS\WDKMD.sys [x]
Inhalt des "geplante Tasks" Ordners
2015-03-20 C:\Windows\Tasks\Adobe Flash Player Updater.job
- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-24 09:38:31 . 2015-02-06 17:02:12]
--------- X64 Entries -----------
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-10-19 06:12:04 261624 ----a-w- C:\Users\Esther\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\amd64\SkyDriveShell64.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-10-19 06:12:04 261624 ----a-w- C:\Users\Esther\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\amd64\SkyDriveShell64.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-10-19 06:12:04 261624 ----a-w- C:\Users\Esther\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\amd64\SkyDriveShell64.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2015-01-21 14:03:40 2334928 ----a-w- C:\PROGRA~1\MICROS~2\Office15\GROOVEEX.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2015-01-21 14:03:40 2334928 ----a-w- C:\PROGRA~1\MICROS~2\Office15\GROOVEEX.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2015-01-21 14:03:40 2334928 ----a-w- C:\PROGRA~1\MICROS~2\Office15\GROOVEEX.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" [2010-11-09 06:55:22 6539880]
"RtHDVBg"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" [2010-11-03 11:30:06 2181224]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2010-09-02 11:53:42 161304]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2010-09-02 11:53:28 386584]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2010-09-02 11:53:34 415256]
"IntelWireless"="C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-03-05 15:09:02 1928976]
"NvBackend"="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-12-13 00:13:07 2531472]
"ShadowPlay"="C:\Windows\system32\nvspcap64.dll" [2014-12-13 00:12:12 2824504]
"AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2014-02-27 19:38:18 558496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=C:\Windows\System32\nvinitx.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
------- Zusätzlicher Suchlauf -------
uLocal Page = C:\Windows\system32\blank.htm
uStart Page = hxxp://www.mystartsearch.com/?type=hp&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC
uDefault_Search_URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC&q={searchTerms}
mDefault_Search_URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC&q={searchTerms}
mDefault_Page_URL = hxxp://www.mystartsearch.com/?type=hp&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC
mStart Page = hxxp://www.mystartsearch.com/?type=hp&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC
mLocal Page = C:\Windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.mystartsearch.com/web/?type=ds&ts=1426688414&from=cmi&uid=ST9500420AS_5VJCG2ACXXXX5VJCG2AC&q={searchTerms}
uSearchAssistant = hxxp://www.google.com
IE: An OneNote s&enden - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: An vorhandene PDF-Datei anfügen - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
IE: In Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Linkziel an vorhandene PDF-Datei anhängen - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Linkziel in Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Nach Microsoft E&xcel exportieren - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.192.1
TCP: Interfaces\{4FE29C76-38E3-44A5-A08F-A4B3E1AB3A6F}: NameServer = 0.0.0.0
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
FF - ProfilePath - C:\Users\Esther\AppData\Roaming\Mozilla\Firefox\Profiles\5k46ozs4.default\
FF - prefs.js: browser.startup.homepage - google.de
- - - - Entfernte verwaiste Registrierungseinträge - - - -
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
HKLM-Run-SynTPEnh - C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe |