Guten morgen Code:
ComboFix 15-07-05.01 - Ingo 06.07.2015 7:41.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.7912.5752 [GMT 2:00]
ausgeführt von:: c:\users\Ingo\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Ingo\AppData\Roaming\Roaming
c:\users\Ingo\AppData\Roaming\Roaming\HoldemManager\config\FTPRushTables.xml
c:\users\Ingo\AppData\Roaming\Roaming\HoldemManager\config\PokerstarsZoomTables.xml
c:\windows\msdownld.tmp
c:\windows\SysWow64\SET245E.tmp
c:\windows\SysWow64\SET2569.tmp
c:\windows\SysWow64\SET27AE.tmp
c:\windows\SysWow64\SET3BFD.tmp
c:\windows\SysWow64\SET4F08.tmp
c:\windows\SysWow64\SET511F.tmp
c:\windows\SysWow64\SET524B.tmp
.
.
((((((((((((((((((((((( Dateien erstellt von 2015-06-06 bis 2015-07-06 ))))))))))))))))))))))))))))))
.
.
2015-07-06 05:51 . 2015-07-06 05:51 -------- d-----w- c:\users\postgres\AppData\Local\temp
2015-07-06 05:51 . 2015-07-06 05:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-07-05 14:14 . 2015-07-05 14:16 -------- d-----w- C:\FRST
2015-07-05 12:22 . 2015-07-05 12:22 -------- d-----w- c:\program files (x86)\Common Files\Skype
2015-07-05 12:09 . 2015-07-05 12:09 0 ----a-w- c:\windows\ativpsrm.bin
2015-07-05 12:04 . 2015-07-05 12:04 -------- d-----w- c:\users\Ingo\AppData\Roaming\ATI
2015-07-05 12:04 . 2015-07-05 12:04 -------- d-----w- c:\users\Ingo\AppData\Local\ATI
2015-07-05 12:04 . 2015-07-05 12:04 -------- d-----w- c:\programdata\ATI
2015-07-05 11:57 . 2015-07-05 11:57 -------- d-----w- c:\program files (x86)\AMD AVT
2015-07-05 11:57 . 2015-07-05 11:57 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
2015-07-05 11:54 . 2015-07-05 11:54 -------- d-----w- c:\program files\Common Files\ATI Technologies
2015-07-05 11:54 . 2015-07-05 11:57 -------- d-----w- c:\program files (x86)\AMD
2015-07-05 10:19 . 2015-07-05 11:12 207872 ----a-w- c:\windows\PAExec.exe
2015-07-05 08:53 . 2015-07-05 12:05 -------- d-----w- c:\windows\system32\catroot2
2015-07-05 08:22 . 2015-07-05 08:22 -------- d-----w- c:\windows\SysWow64\wbem\Performance
2015-07-05 08:21 . 2015-07-05 08:21 -------- d-----w- c:\program files\Uninstall Information
2015-07-05 08:11 . 2015-07-05 08:11 -------- d-----w- C:\RegBackup
2015-07-04 19:17 . 2015-07-05 15:54 113880 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-07-04 19:17 . 2015-07-04 19:18 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2015-07-04 19:17 . 2015-06-18 06:41 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2015-07-04 19:17 . 2015-06-18 06:41 109272 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-07-04 19:17 . 2015-06-18 06:41 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2015-07-04 18:58 . 2015-07-03 19:40 364472 ----a-w- c:\windows\system32\aswBoot.exe
2015-07-04 18:03 . 2015-07-05 12:22 -------- d-----r- c:\program files (x86)\Skype
2015-07-04 10:33 . 2015-07-04 10:33 -------- d-----w- c:\users\Ingo\AppData\Roaming\PacificPoker
2015-07-04 10:33 . 2015-07-04 10:33 -------- d-----w- c:\program files (x86)\PacificPoker
2015-07-04 10:14 . 2015-07-03 22:14 135800 ----a-w- c:\windows\system32\drivers\epp64.sys
2015-07-04 08:52 . 2015-07-04 10:48 37624 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2015-07-04 08:52 . 2015-07-05 04:53 -------- d-----w- c:\programdata\RogueKiller
2015-07-04 08:16 . 2015-07-04 08:16 -------- d-----w- c:\programdata\Malwarebytes
2015-07-03 19:53 . 2015-07-03 19:53 -------- d-----w- c:\program files (x86)\Common Files\Java
2015-07-03 19:44 . 2015-07-01 04:55 897088 ----a-w- c:\program files (x86)\Mozilla Firefox\uninstall\helper.exe
2015-07-03 19:44 . 2015-07-01 02:31 188584 ----a-w- c:\program files (x86)\Mozilla Firefox\gmp-clearkey\0.1\clearkey.dll
2015-07-03 19:44 . 2015-07-01 02:31 51880 ----a-w- c:\program files (x86)\Mozilla Firefox\browser\components\browsercomps.dll
2015-07-03 19:41 . 2015-07-03 19:41 -------- d-----w- c:\users\Ingo\AppData\Roaming\AVAST Software
2015-07-03 19:41 . 2015-07-03 19:41 -------- d-----w- c:\windows\SysWow64\vbox
2015-07-03 19:41 . 2015-07-03 19:41 -------- d-----w- c:\windows\system32\vbox
2015-07-03 19:40 . 2015-07-03 19:47 -------- d-----w- c:\program files (x86)\Google
2015-07-03 19:40 . 2015-07-03 19:40 272248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2015-07-03 19:40 . 2015-07-03 19:40 137288 ----a-w- c:\windows\system32\drivers\aswStm.sys
2015-07-03 19:40 . 2015-07-03 19:41 442264 ----a-w- c:\windows\system32\drivers\aswSP.sys
2015-07-03 19:40 . 2015-07-03 19:40 89944 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2015-07-03 19:40 . 2015-07-03 19:40 65736 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2015-07-03 19:40 . 2015-07-03 19:40 29168 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2015-07-03 19:40 . 2015-07-03 19:40 93528 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2015-07-03 19:40 . 2015-07-03 19:40 1047320 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2015-07-03 19:40 . 2015-07-03 19:40 43112 ----a-w- c:\windows\avastSS.scr
2015-07-03 19:39 . 2015-07-03 19:39 -------- d-----w- c:\program files\AVAST Software
2015-07-03 19:37 . 2015-07-03 19:37 -------- d-----w- c:\programdata\AVAST Software
2015-07-03 19:01 . 2015-07-03 19:01 -------- d-----w- c:\program files (x86)\iTunes
2015-06-06 15:36 . 2015-07-05 22:06 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10145.bin
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-07-03 19:53 . 2014-03-19 20:05 111016 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2015-07-03 19:52 . 2014-03-19 16:16 778416 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2015-07-03 19:52 . 2014-03-19 16:16 142512 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-06-10 05:11 . 2014-03-19 14:37 140135120 ----a-w- c:\windows\system32\MRT.exe
2015-05-27 14:26 . 2014-07-31 12:58 155136 ----a-w- c:\windows\SysWow64\unrar.dll
2015-05-25 18:24 . 2015-06-05 21:01 5569984 ----a-w- c:\windows\system32\ntoskrnl.exe
2015-05-25 18:23 . 2015-06-05 21:01 155584 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2015-05-25 18:23 . 2015-06-05 21:01 95680 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2015-05-25 18:21 . 2015-06-05 21:01 1728960 ----a-w- c:\windows\system32\ntdll.dll
2015-05-25 18:19 . 2015-06-05 21:01 243712 ----a-w- c:\windows\system32\wow64.dll
2015-05-25 18:19 . 2015-06-05 21:00 362496 ----a-w- c:\windows\system32\wow64win.dll
2015-05-25 18:19 . 2015-06-05 21:00 13312 ----a-w- c:\windows\system32\wow64cpu.dll
2015-05-25 18:19 . 2015-06-05 21:01 215040 ----a-w- c:\windows\system32\winsrv.dll
2015-05-25 18:19 . 2015-06-05 21:01 1255424 ----a-w- c:\windows\system32\diagtrack.dll
2015-05-25 18:19 . 2015-06-05 21:01 210944 ----a-w- c:\windows\system32\wdigest.dll
2015-05-25 18:19 . 2015-06-05 21:01 879104 ----a-w- c:\windows\system32\tdh.dll
2015-05-25 18:19 . 2015-06-05 21:01 86528 ----a-w- c:\windows\system32\TSpkg.dll
2015-05-25 18:19 . 2015-06-05 21:01 136192 ----a-w- c:\windows\system32\sspicli.dll
2015-05-25 18:19 . 2015-06-05 21:00 29184 ----a-w- c:\windows\system32\sspisrv.dll
2015-05-25 18:19 . 2015-06-05 21:01 503808 ----a-w- c:\windows\system32\srcore.dll
2015-05-25 18:19 . 2015-06-05 21:01 113664 ----a-w- c:\windows\system32\sechost.dll
2015-05-25 18:19 . 2015-06-05 21:00 50176 ----a-w- c:\windows\system32\srclient.dll
2015-05-25 18:19 . 2015-06-05 21:00 28160 ----a-w- c:\windows\system32\secur32.dll
2015-05-25 18:19 . 2015-06-05 21:01 342016 ----a-w- c:\windows\system32\schannel.dll
2015-05-25 18:19 . 2015-06-05 21:01 314880 ----a-w- c:\windows\system32\msv1_0.dll
2015-05-25 18:19 . 2015-06-05 21:01 309760 ----a-w- c:\windows\system32\ncrypt.dll
2015-05-25 18:19 . 2015-06-05 21:00 16384 ----a-w- c:\windows\system32\ntvdm64.dll
2015-05-25 18:19 . 2015-06-05 21:01 728576 ----a-w- c:\windows\system32\kerberos.dll
2015-05-25 18:19 . 2015-06-05 21:01 424960 ----a-w- c:\windows\system32\KernelBase.dll
2015-05-25 18:19 . 2015-06-05 21:01 1461760 ----a-w- c:\windows\system32\lsasrv.dll
2015-05-25 18:19 . 2015-06-05 21:01 1162752 ----a-w- c:\windows\system32\kernel32.dll
2015-05-25 18:18 . 2015-06-05 21:00 43520 ----a-w- c:\windows\system32\csrsrv.dll
2015-05-25 18:18 . 2015-06-05 21:00 22016 ----a-w- c:\windows\system32\credssp.dll
2015-05-25 18:18 . 2015-06-05 21:01 879104 ----a-w- c:\windows\system32\advapi32.dll
2015-05-25 18:18 . 2015-06-05 21:01 404992 ----a-w- c:\windows\system32\tracerpt.exe
2015-05-25 18:18 . 2015-06-05 21:01 47104 ----a-w- c:\windows\system32\typeperf.exe
2015-05-25 18:18 . 2015-06-05 21:01 112640 ----a-w- c:\windows\system32\smss.exe
2015-05-25 18:18 . 2015-06-05 21:01 296960 ----a-w- c:\windows\system32\rstrui.exe
2015-05-25 18:18 . 2015-06-05 21:01 43008 ----a-w- c:\windows\system32\relog.exe
2015-05-25 18:18 . 2015-06-05 21:01 104448 ----a-w- c:\windows\system32\logman.exe
2015-05-25 18:18 . 2015-06-05 21:01 31232 ----a-w- c:\windows\system32\lsass.exe
2015-05-25 18:18 . 2015-06-05 21:00 19456 ----a-w- c:\windows\system32\diskperf.exe
2015-05-25 18:18 . 2015-06-05 21:01 338432 ----a-w- c:\windows\system32\conhost.exe
2015-05-25 18:18 . 2015-06-05 21:01 64000 ----a-w- c:\windows\system32\auditpol.exe
2015-05-25 18:14 . 2015-06-05 21:00 60416 ----a-w- c:\windows\system32\msobjs.dll
2015-05-25 18:14 . 2015-06-05 21:00 146432 ----a-w- c:\windows\system32\msaudite.dll
2015-05-25 18:11 . 2015-06-05 21:00 4608 ----a-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 4608 ----a-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 4096 ----a-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 4096 ----a-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3584 ----a-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3584 ----a-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3584 ----a-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3584 ----a-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3072 ----a-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3072 ----a-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3072 ----a-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 6656 ----a-w- c:\windows\system32\apisetschema.dll
2015-05-25 18:11 . 2015-06-05 21:00 6144 ----a-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 4096 ----a-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 4096 ----a-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3584 ----a-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3584 ----a-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3072 ----a-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3072 ----a-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 5120 ----a-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3584 ----a-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3072 ----a-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3072 ----a-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3072 ----a-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3072 ----a-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3072 ----a-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3072 ----a-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3072 ----a-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 3072 ----a-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-05-25 18:11 . 2015-06-05 21:00 686080 ----a-w- c:\windows\system32\adtschema.dll
2015-05-25 18:07 . 2015-06-05 21:01 3989440 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2015-05-25 18:07 . 2015-06-05 21:01 3934144 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2015-05-25 18:04 . 2015-06-05 21:01 1310744 ----a-w- c:\windows\SysWow64\ntdll.dll
2015-05-25 18:01 . 2015-06-05 21:01 172032 ----a-w- c:\windows\SysWow64\wdigest.dll
2015-05-25 18:01 . 2015-06-05 21:01 635392 ----a-w- c:\windows\SysWow64\tdh.dll
2015-05-25 18:01 . 2015-06-05 21:01 65536 ----a-w- c:\windows\SysWow64\TSpkg.dll
2015-05-25 18:01 . 2015-06-05 21:00 43008 ----a-w- c:\windows\SysWow64\srclient.dll
2015-05-25 18:01 . 2015-06-05 21:01 248832 ----a-w- c:\windows\SysWow64\schannel.dll
2015-05-25 18:01 . 2015-06-05 21:01 92160 ----a-w- c:\windows\SysWow64\sechost.dll
2015-05-25 18:01 . 2015-06-05 21:00 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2015-05-25 18:01 . 2015-06-05 21:01 221184 ----a-w- c:\windows\SysWow64\ncrypt.dll
2015-05-25 18:01 . 2015-06-05 21:00 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2015-05-25 18:01 . 2015-06-05 21:01 259584 ----a-w- c:\windows\SysWow64\msv1_0.dll
2015-05-25 18:01 . 2015-06-05 21:01 551424 ----a-w- c:\windows\SysWow64\kerberos.dll
2015-05-25 18:01 . 2015-06-05 21:00 17408 ----a-w- c:\windows\SysWow64\credssp.dll
2015-05-25 18:01 . 2015-06-05 21:01 641536 ----a-w- c:\windows\SysWow64\advapi32.dll
2015-05-25 18:01 . 2015-06-05 21:01 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2015-05-25 18:00 . 2015-06-05 21:01 40448 ----a-w- c:\windows\SysWow64\typeperf.exe
2015-05-25 18:00 . 2015-06-05 21:01 364544 ----a-w- c:\windows\SysWow64\tracerpt.exe
2015-05-25 18:00 . 2015-06-05 21:01 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2015-05-25 18:00 . 2015-06-05 21:01 37888 ----a-w- c:\windows\SysWow64\relog.exe
2015-05-25 18:00 . 2015-06-05 21:01 82944 ----a-w- c:\windows\SysWow64\logman.exe
2015-05-25 18:00 . 2015-06-05 21:00 17408 ----a-w- c:\windows\SysWow64\diskperf.exe
2015-05-25 18:00 . 2015-06-05 21:01 50176 ----a-w- c:\windows\SysWow64\auditpol.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2015-06-01 8358680]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2015-06-29 53282944]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-07-03 5515496]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2015-04-10 335232]
"StartCCC"="c:\program files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-11-20 767176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss]
@="Service"
.
R2 AODDriver4.2.0;AODDriver4.2.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
R2 APXACC;AppEx Networks Accelerator LWF;c:\windows\system32\DRIVERS\appexDrv.sys;c:\windows\SYSNATIVE\DRIVERS\appexDrv.sys [x]
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 DokanMounter;DokanMounter;c:\program files (x86)\Dokan\DokanLibrary\mounter.exe;c:\program files (x86)\Dokan\DokanLibrary\mounter.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]
R3 busenum;SteelBusSvc;c:\windows\system32\DRIVERS\SteelBus64.sys;c:\windows\SYSNATIVE\DRIVERS\SteelBus64.sys [x]
R3 cpuz134;cpuz134;c:\users\Ingo\AppData\Local\Temp\cpuz134\cpuz134_x64.sys;c:\users\Ingo\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 LADF_CaptureOnly;LADF Capture Filter Driver;c:\windows\system32\DRIVERS\ladfGSCamd64.sys;c:\windows\SYSNATIVE\DRIVERS\ladfGSCamd64.sys [x]
R3 LADF_RenderOnly;LADF Render Filter Driver;c:\windows\system32\DRIVERS\ladfGSRamd64.sys;c:\windows\SYSNATIVE\DRIVERS\ladfGSRamd64.sys [x]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys;c:\windows\SYSNATIVE\DRIVERS\netaapl64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SAlphamHid;SteelHIDSvc;c:\windows\system32\DRIVERS\SAlpham64.sys;c:\windows\SYSNATIVE\DRIVERS\SAlpham64.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 amdide64;amdide64;c:\windows\system32\DRIVERS\amdide64.sys;c:\windows\SYSNATIVE\DRIVERS\amdide64.sys [x]
S0 asahci64;asahci64;c:\windows\system32\DRIVERS\asahci64.sys;c:\windows\SYSNATIVE\DRIVERS\asahci64.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 epp64;epp64;c:\windows\system32\DRIVERS\epp64.sys;c:\windows\SYSNATIVE\DRIVERS\epp64.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\AMD\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AODDriver4.3;AODDriver4.3;c:\program files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
S2 Apple Mobile Device Service;Apple Mobile Device Service;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 Dokan;Dokan;c:\windows\system32\drivers\dokan.sys;c:\windows\SYSNATIVE\drivers\dokan.sys [x]
S2 postgresql-8.4;postgresql-8.4 - PostgreSQL Server 8.4;c:\postgresql\bin\pg_ctl.exe runservice -N postgresql-8.4 -D c:/postgreSQL/data -w;c:\postgresql\bin\pg_ctl.exe runservice -N postgresql-8.4 -D c:/postgreSQL/data -w [x]
S2 VBoxAswDrv;VBoxAsw Support Driver;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [x]
S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys;c:\windows\SYSNATIVE\DRIVERS\amdhub30.sys [x]
S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys;c:\windows\SYSNATIVE\DRIVERS\amdxhc.sys [x]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys;c:\windows\SYSNATIVE\DRIVERS\asmthub3.sys [x]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys;c:\windows\SYSNATIVE\DRIVERS\asmtxhci.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 AvastVBoxSvc;AvastVBox COM Service;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2015-07-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-19 19:52]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2015-07-03 19:40 722400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2013-10-24 13662936]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2014-10-14 12697368]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2015-06-29 170280]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = https://www.google.de/webhp?ie=utf-8&oe=utf-8&gws_rd=cr&ei=dNzcVILaOYmHPKHagLAM
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 83.169.185.161 83.169.185.225
FF - ProfilePath - c:\users\Ingo\AppData\Roaming\Mozilla\Firefox\Profiles\d8fmdcq0.default-1424889923445\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.de/?gws_rd=ssl
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\postgresql-8.4]
"ImagePath"="\"c:\postgresql\bin\pg_ctl.exe\" runservice -N \"postgresql-8.4\" -D \"c:/postgreSQL/data\" -w"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Cryptography\RNG*]
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
.
Zeit der Fertigstellung: 2015-07-06 07:53:57
ComboFix-quarantined-files.txt 2015-07-06 05:53
.
Vor Suchlauf: 22 Verzeichnis(se), 353.471.021.056 Bytes frei
Nach Suchlauf: 25 Verzeichnis(se), 353.627.230.208 Bytes frei
.
- - End Of File - - 9E8467667BF122D603D10C88B4B84EAF
A36C5E4F47E84449FF07ED3517B43A31 |