Buggerns | 09.04.2016 18:00 | Hi Jürgen,
der Link wird irgendwie nicht angezeigt, sorry. Habe aber wie gesagt nur gepostet und mich dann fürs Crossposting entschuldigt, mehr nicht.
Die Schritte habe ich alle durchgeführt, der USB-Stick konnte von Panda leider wegen Avira nicht geimpft werden, durch den Remover ist die Verknüpfungssache aber schonmal behoben. Combofix hat beim ersten Mal jedoch den PC neu gestartet und - womöglich weil Avira direkt wieder ansprang und Fenster sich öffneten - nur einen leeren errorlog.txt angezeigt, beim zweiten Mal dann bekam ich diese Logdatei: Code:
ComboFix 16-04-06.01 - Ben 09.04.2016 18:41:53.2.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.16342.13630 [GMT 2:00]
ausgeführt von:: c:\users\Ben\Desktop\ComboFix.exe
AV: Avira Antivirus *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Antivirus *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Vorheriger Suchlauf -------
.
c:\users\Ben\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\users\Ben\AppData\Roaming\SpeedRunnersLog.txt
c:\users\Ben\AppData\Roaming\TargetInvocationLog.txt
I:\Autorun.inf
I:\install.exe
I:\setup.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2016-03-09 bis 2016-04-09 ))))))))))))))))))))))))))))))
.
.
2016-04-09 16:49 . 2016-04-09 16:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-04-09 16:18 . 2016-04-09 16:18 -------- d-----w- C:\Rem-VBSqt
2016-04-09 16:17 . 2016-04-09 16:17 -------- d-----w- c:\programdata\Panda Security
2016-04-09 16:16 . 2016-04-09 16:16 -------- d-----w- c:\program files (x86)\Panda USB Vaccine
2016-04-09 15:36 . 2016-04-09 15:40 -------- d-----w- C:\FRST
2016-04-09 13:57 . 2016-04-09 13:57 -------- d-----w- c:\program files (x86)\VS Revo Group
2016-04-06 22:13 . 2015-09-10 18:07 55116 --sha-w- c:\users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\VID-20151943-WA0114.MP4.js
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-04-09 14:07 . 2015-07-27 14:21 192216 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2016-03-11 19:52 . 2013-05-19 22:28 69888 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2016-03-11 19:52 . 2013-05-19 22:28 154816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2016-03-11 19:52 . 2013-05-19 22:28 133168 ----a-w- c:\windows\system32\drivers\avipbb.sys
2016-03-10 12:09 . 2015-07-27 14:20 64896 ----a-w- c:\windows\system32\drivers\mwac.sys
2016-03-10 12:08 . 2015-07-27 14:20 140672 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2016-03-10 12:08 . 2015-07-27 14:20 27008 ----a-w- c:\windows\system32\drivers\mbam.sys
2016-03-06 20:31 . 2012-02-19 15:10 146614896 ----a-w- c:\windows\system32\MRT.exe
2016-02-19 19:02 . 2016-03-06 20:05 38336 ----a-w- c:\windows\system32\CompatTelRunner.exe
2016-02-19 18:54 . 2016-03-06 20:05 1168896 ----a-w- c:\windows\system32\aeinv.dll
2016-02-19 14:07 . 2016-03-06 20:05 1373184 ----a-w- c:\windows\system32\appraiser.dll
2016-02-12 18:52 . 2016-03-06 20:07 98816 ----a-w- c:\windows\system32\wudriver.dll
2016-02-12 18:52 . 2016-03-06 20:07 3169792 ----a-w- c:\windows\system32\wucltux.dll
2016-02-12 18:52 . 2016-03-06 20:07 192512 ----a-w- c:\windows\system32\wuwebv.dll
2016-02-12 18:44 . 2016-03-06 20:07 91136 ----a-w- c:\windows\system32\WinSetupUI.dll
2016-02-12 18:39 . 2016-03-06 20:07 174080 ----a-w- c:\windows\SysWow64\wuwebv.dll
2016-02-12 18:22 . 2016-03-06 20:07 2610688 ----a-w- c:\windows\system32\wuaueng.dll
2016-02-12 18:19 . 2016-03-06 20:07 709120 ----a-w- c:\windows\system32\wuapi.dll
2016-02-12 18:18 . 2016-03-06 20:07 37888 ----a-w- c:\windows\system32\wuapp.exe
2016-02-12 18:18 . 2016-03-06 20:07 140288 ----a-w- c:\windows\system32\wuauclt.exe
2016-02-12 18:18 . 2016-03-06 20:07 36864 ----a-w- c:\windows\system32\wups.dll
2016-02-12 18:18 . 2016-03-06 20:07 37888 ----a-w- c:\windows\system32\wups2.dll
2016-02-12 18:18 . 2016-03-06 20:07 12288 ----a-w- c:\windows\system32\wu.upgrade.ps.dll
2016-02-12 18:06 . 2016-03-06 20:07 573440 ----a-w- c:\windows\SysWow64\wuapi.dll
2016-02-12 18:05 . 2016-03-06 20:07 93696 ----a-w- c:\windows\SysWow64\wudriver.dll
2016-02-12 18:05 . 2016-03-06 20:07 30208 ----a-w- c:\windows\SysWow64\wups.dll
2016-02-12 18:05 . 2016-03-06 20:07 35328 ----a-w- c:\windows\SysWow64\wuapp.exe
2016-02-11 14:07 . 2016-03-06 20:05 689152 ----a-w- c:\windows\system32\generaltel.dll
2016-02-06 10:48 . 2016-02-09 20:40 25839104 ----a-w- c:\windows\system32\mshtml.dll
2016-02-06 10:32 . 2016-02-09 20:41 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2016-02-06 10:24 . 2016-02-09 20:41 2887680 ----a-w- c:\windows\system32\iertutil.dll
2016-02-06 10:11 . 2016-02-09 20:40 615936 ----a-w- c:\windows\system32\ieui.dll
2016-02-06 10:10 . 2016-02-09 20:40 144384 ----a-w- c:\windows\system32\ieUnatt.exe
2016-02-06 09:54 . 2016-02-09 20:40 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2016-02-06 09:37 . 2016-02-09 20:40 115712 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2016-02-06 09:32 . 2016-02-09 20:40 14458368 ----a-w- c:\windows\system32\ieframe.dll
2016-02-06 09:09 . 2016-02-09 20:40 1547264 ----a-w- c:\windows\system32\urlmon.dll
2016-02-05 14:07 . 2016-03-06 20:05 696832 ----a-w- c:\windows\system32\invagent.dll
2016-02-05 14:07 . 2016-03-06 20:05 499200 ----a-w- c:\windows\system32\devinv.dll
2016-02-05 14:07 . 2016-03-06 20:05 76800 ----a-w- c:\windows\system32\acmigration.dll
2016-01-22 20:31 . 2016-02-09 21:08 387784 ----a-w- c:\windows\system32\iedkcs32.dll
2016-01-22 06:56 . 2016-02-09 21:08 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2016-01-22 06:41 . 2016-02-09 21:08 66560 ----a-w- c:\windows\system32\iesetup.dll
2016-01-22 06:40 . 2016-02-09 21:09 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll
2016-01-22 06:40 . 2016-02-09 21:08 417792 ----a-w- c:\windows\system32\html.iec
2016-01-22 06:40 . 2016-02-09 21:08 88064 ----a-w- c:\windows\system32\MshtmlDac.dll
2016-01-22 06:40 . 2016-02-09 21:08 571904 ----a-w- c:\windows\system32\vbscript.dll
2016-01-22 06:33 . 2016-02-09 21:08 54784 ----a-w- c:\windows\system32\jsproxy.dll
2016-01-22 06:32 . 2016-02-09 21:09 34304 ----a-w- c:\windows\system32\iernonce.dll
2016-01-22 06:29 . 2016-02-09 21:08 6052352 ----a-w- c:\windows\system32\jscript9.dll
2016-01-22 06:27 . 2016-02-09 21:09 114688 ----a-w- c:\windows\system32\ieetwcollector.exe
2016-01-22 06:27 . 2016-02-09 21:08 817664 ----a-w- c:\windows\system32\jscript.dll
2016-01-22 06:27 . 2016-02-09 21:08 814080 ----a-w- c:\windows\system32\jscript9diag.dll
2016-01-22 06:27 . 2016-02-09 19:49 5573056 ----a-w- c:\windows\system32\ntoskrnl.exe
2016-01-22 06:27 . 2016-02-09 19:49 154560 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2016-01-22 06:27 . 2016-02-09 19:49 95680 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2016-01-22 06:24 . 2016-02-09 19:49 1733592 ----a-w- c:\windows\system32\ntdll.dll
2016-01-22 06:20 . 2016-02-09 19:49 362496 ----a-w- c:\windows\system32\wow64win.dll
2016-01-22 06:20 . 2016-02-09 19:49 243712 ----a-w- c:\windows\system32\wow64.dll
2016-01-22 06:20 . 2016-02-09 19:49 13312 ----a-w- c:\windows\system32\wow64cpu.dll
2016-01-22 06:20 . 2016-02-09 19:49 215040 ----a-w- c:\windows\system32\winsrv.dll
2016-01-22 06:20 . 2016-02-09 21:08 968704 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2016-01-22 06:20 . 2016-02-09 19:49 210432 ----a-w- c:\windows\system32\wdigest.dll
2016-01-22 06:20 . 2016-02-09 19:49 86528 ----a-w- c:\windows\system32\TSpkg.dll
2016-01-22 06:20 . 2016-02-09 19:49 135680 ----a-w- c:\windows\system32\sspicli.dll
2016-01-22 06:20 . 2016-02-09 19:49 28672 ----a-w- c:\windows\system32\sspisrv.dll
2016-01-22 06:20 . 2016-02-09 19:49 503808 ----a-w- c:\windows\system32\srcore.dll
2016-01-22 06:20 . 2016-02-09 19:49 50176 ----a-w- c:\windows\system32\srclient.dll
2016-01-22 06:19 . 2016-02-09 19:43 14179840 ----a-w- c:\windows\system32\shell32.dll
2016-01-22 06:19 . 2016-02-09 19:49 28160 ----a-w- c:\windows\system32\secur32.dll
2016-01-22 06:19 . 2016-02-09 19:49 344064 ----a-w- c:\windows\system32\schannel.dll
2016-01-22 06:19 . 2016-02-09 19:49 1214464 ----a-w- c:\windows\system32\rpcrt4.dll
2016-01-22 06:18 . 2016-02-09 19:49 961024 ----a-w- c:\windows\system32\CPFilters.dll
2016-01-22 06:18 . 2016-02-09 19:49 723968 ----a-w- c:\windows\system32\EncDec.dll
2016-01-22 06:18 . 2016-02-09 19:49 16384 ----a-w- c:\windows\system32\ntvdm64.dll
2016-01-22 06:17 . 2016-02-09 21:08 489984 ----a-w- c:\windows\system32\dxtmsft.dll
2016-01-22 06:17 . 2016-02-09 19:49 312320 ----a-w- c:\windows\system32\ncrypt.dll
2016-01-22 06:17 . 2016-02-09 19:49 159744 ----a-w- c:\windows\system32\mtxoci.dll
2016-01-22 06:17 . 2016-02-09 19:49 315392 ----a-w- c:\windows\system32\msv1_0.dll
2016-01-22 06:16 . 2016-02-09 19:49 60416 ----a-w- c:\windows\system32\msobjs.dll
2016-01-22 06:16 . 2016-02-09 19:49 146432 ----a-w- c:\windows\system32\msaudite.dll
2016-01-22 06:16 . 2016-02-09 19:49 1461248 ----a-w- c:\windows\system32\lsasrv.dll
2016-01-22 06:15 . 2016-02-09 19:49 730112 ----a-w- c:\windows\system32\kerberos.dll
2016-01-22 06:15 . 2016-02-09 19:49 422400 ----a-w- c:\windows\system32\KernelBase.dll
2016-01-22 06:15 . 2016-02-09 19:49 1163264 ----a-w- c:\windows\system32\kernel32.dll
2016-01-22 06:15 . 2016-02-09 19:43 1866752 ----a-w- c:\windows\system32\ExplorerFrame.dll
2016-01-22 06:13 . 2016-02-09 19:49 3993536 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2016-01-22 06:13 . 2016-02-09 19:49 3938752 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2016-01-22 06:13 . 2016-02-09 19:49 43520 ----a-w- c:\windows\system32\csrsrv.dll
2016-01-22 06:13 . 2016-02-09 19:49 43520 ----a-w- c:\windows\system32\cryptbase.dll
2016-01-22 06:13 . 2016-02-09 19:49 22016 ----a-w- c:\windows\system32\credssp.dll
2016-01-22 06:12 . 2016-02-09 19:43 1940992 ----a-w- c:\windows\system32\authui.dll
2016-01-22 06:12 . 2016-02-09 19:49 6656 ----a-w- c:\windows\system32\apisetschema.dll
2016-01-22 06:12 . 2016-02-09 19:49 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-01-22 06:12 . 2016-02-09 19:49 3072 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-01-22 06:12 . 2016-02-09 19:49 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-01-22 06:12 . 2016-02-09 19:49 880128 ----a-w- c:\windows\system32\advapi32.dll
2016-01-22 06:12 . 2016-02-09 19:49 686080 ----a-w- c:\windows\system32\adtschema.dll
2016-01-22 06:12 . 2016-02-09 19:49 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-01-22 06:12 . 2016-02-09 19:49 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files (x86)\Windows Sidebar\sidebar.exe" [2010-11-21 1174016]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2016-03-31 3077712]
"GoogleChromeAutoLaunch_8B4B86C2A5661DC92D9A84E265233F91"="c:\users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe" [2016-03-27 874136]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"THX TruStudio NB Settings"="c:\program files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" [2011-05-19 909824]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"Cisco AnyConnect Secure Mobility Agent for Windows"="c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" [2012-12-10 527864]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2016-03-11 807392]
"StartCCC"="c:\program files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2015-07-28 767176]
"Avira SystrayStartTrigger"="c:\program files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe" [2016-01-27 66328]
"Wondershare Helper Compact.exe"="c:\program files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe" [2014-02-20 1994752]
"VID-20151943-WA0114"="wscript.exe" [2013-10-12 141824]
.
c:\users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
errorlog.txt [2016-4-9 0]
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
VID-20151943-WA0114.MP4.js [2015-9-10 55116]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R2 AntiVirMailService;Avira Email-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avmailc7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avmailc7.exe [x]
R2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x]
R2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 acsock;acsock;c:\windows\system32\DRIVERS\acsock64.sys;c:\windows\SYSNATIVE\DRIVERS\acsock64.sys [x]
R3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AsrAppCharger.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\AMD\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 AODDriver4.3;AODDriver4.3;c:\program files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
S2 Avira.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\Launcher\Avira.ServiceHost.exe;c:\program files (x86)\Avira\Launcher\Avira.ServiceHost.exe [x]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 vpnagent;Cisco AnyConnect Secure Mobility Agent;c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe;c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
Inhalt des "geplante Tasks" Ordners
.
2016-04-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-20 13:52]
.
2016-04-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-20 13:52]
.
2016-04-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1744302370-2936264581-3152195107-1000Core.job
- c:\users\Ben\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-31 15:00]
.
2016-04-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1744302370-2936264581-3152195107-1000UA.job
- c:\users\Ben\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-31 15:00]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-05-18 11855976]
"THXCfg64"="c:\windows\system32\THXCfg64.dll" [2011-05-13 26624]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.google.com
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\00l7ys0v.default\
FF - prefs.js: browser.startup.homepage - hxxps://mail.google.com/
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-ASRockXTU - (no file)
Wow6432Node-HKCU-Run-zASRockInstantBoot - (no file)
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1744302370-2936264581-3152195107-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*m*p*3*7Û`\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-1744302370-2936264581-3152195107-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*1&1xxµ*€h*]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-1744302370-2936264581-3152195107-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*1&1xxµ*€h*\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-1744302370-2936264581-3152195107-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ÇQ„$]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-1744302370-2936264581-3152195107-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ÇQ„$\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-1744302370-2936264581-3152195107-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*àuìnàý*ˆ]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-1744302370-2936264581-3152195107-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*àuìnàý*ˆ\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-1744302370-2936264581-3152195107-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6900898A-DFB6-6292-DEED-E1E91AA53164}*]
"mafaaaipknjicgchlogcmpbpal"=hex:6f,61,67,63,6d,67,6d,6f,63,6c,61,6d,65,6c,6c,
61,69,69,65,64,68,64,6b,70,69,6c,6e,70,6b,62,00,6c
"abgadacjnehmelehimndopaponokpnbmbh"=hex:70,61,6d,61,6e,6e,63,6e,6d,63,6a,68,
6d,6e,65,62,64,63,69,6a,6f,6f,69,69,6f,67,61,6f,6f,6d,66,6c,00,ff
.
[HKEY_USERS\S-1-5-21-1744302370-2936264581-3152195107-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-1744302370-2936264581-3152195107-1000\Software\SecuROM\License information*]
"datasecu"=hex:8c,76,e3,f7,36,3a,9b,da,90,ec,69,1d,06,a7,14,bd,db,ae,60,58,db,
4c,2c,77,ce,5d,3c,8b,8a,61,82,a0,e1,b2,98,55,e8,d2,2c,89,99,00,35,df,52,45,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2016-04-09 18:51:43
ComboFix-quarantined-files.txt 2016-04-09 16:51
.
Vor Suchlauf: 24 Verzeichnis(se), 110.149.431.296 Bytes frei
Nach Suchlauf: 25 Verzeichnis(se), 110.005.514.240 Bytes frei
.
- - End Of File - - EFE45B8827C48FA56A79C99664C6F213
A36C5E4F47E84449FF07ED3517B43A31 Vielen vielen Dank weiterhin! |