Terrenay | 23.05.2016 18:52 | Ich dachte nicht, dass ich das jemals wieder sagen könnte, aber das Internet geht wieder :D
Danke schonmal, du bist der beste :)
ComboFix kommt gleich^^ Code:
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:16-05-2016
durchgeführt von Sven (2011-01-03 14:33:20) Run:1
Gestartet von C:\Users\Sven\Desktop
Geladene Profile: Sven (Verfügbare Profile: Mirjam Zanetti & Sven & Tim & Gast)
Start-Modus: Safe Mode (minimal)
==============================================
fixlist Inhalt:
*****************
start
CloseProcesses:
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [ QQPCTray] => "C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QQPCTray.exe" /regrun
Unlock: C:\Program Files (x86)\Tencent
C:\Program Files (x86)\Tencent
HKU\S-1-5-21-1536315646-4119356758-1407283469-1001\...\Run: [taskhost] => rundll32.exe C:\ProgramData\WindowsMsg\675D131108D4FD145B0BFBC68A3E018A.dll Start /AUTORUN
Unlock: C:\ProgramData\WindowsMsg
C:\ProgramData\WindowsMsg
HKU\S-1-5-21-1536315646-4119356758-1407283469-1001\...\Policies\system: [DisableClock] 0
HKU\S-1-5-21-1536315646-4119356758-1407283469-1001\...\Policies\Explorer: [NoNetworkConnections] 0
HKU\S-1-5-21-1536315646-4119356758-1407283469-1001\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-1536315646-4119356758-1407283469-1001\...\Policies\Explorer: [NoCommonGroups] 0
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => Keine Datei
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => Keine Datei
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => Keine Datei
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => Keine Datei
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => Keine Datei
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => Keine Datei
ShellIconOverlayIdentifiers: [.QMDeskTopGCIcon] -> {B7667919-3765-4815-A66D-98A09BE662D6} => C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QMGCShellExt64.dll Keine Datei
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => Keine Datei
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => Keine Datei
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => Keine Datei
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => Keine Datei
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => Keine Datei
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => Keine Datei
Winsock: Catalog9 01 C:\Windows\system32\zdengine.dll Keine Datei
Winsock: Catalog9 02 C:\Windows\system32\zdengine.dll Keine Datei
Winsock: Catalog9 03 C:\Windows\system32\zdengine.dll Keine Datei
Winsock: Catalog9 04 C:\Windows\system32\zdengine.dll Keine Datei
Winsock: Catalog9 15 C:\Windows\system32\zdengine.dll Keine Datei
Winsock: Catalog9-x64 01 C:\Windows\system32\zdengine64.dll Keine Datei
Winsock: Catalog9-x64 02 C:\Windows\system32\zdengine64.dll Keine Datei
Winsock: Catalog9-x64 03 C:\Windows\system32\zdengine64.dll Keine Datei
Winsock: Catalog9-x64 04 C:\Windows\system32\zdengine64.dll Keine Datei
Winsock: Catalog9-x64 15 C:\Windows\system32\zdengine64.dll Keine Datei
HKU\S-1-5-21-1536315646-4119356758-1407283469-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschränkung <======= ACHTUNG
BHO: 电脑管家网页防火墙 -> {7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} -> C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\TSWebMon64.dat => Keine Datei
Toolbar: HKU\S-1-5-21-1536315646-4119356758-1407283469-1001 -> Kein Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Keine Datei
FF Extension: Rikaisama - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\dk8rovbg.default-1456592647169\extensions\{697F6AFE-5321-4DE1-BFE6-4471C3721BD4} [2016-05-12]
CHR Extension: (rikaikun) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jipdnfibhldikgcjhfnomkfpcebammhp [2015-06-22]
CHR HKLM-x32\...\Chrome\Extension: [fgdfbnnnceningmmfememmedbfgmcpcp] - <kein Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [jmnjdacpgoffbagiiehfohoiadgabenc] - <kein Path/update_url>
S2 GoogleChromeUpSvc; C:\ProgramData\Windows Update\svrupg.exe [2783744 2016-05-17] (TODO: ) [Datei ist nicht signiert]
Unlock: C:\ProgramData\Windows Update
C:\ProgramData\Windows Update
S4 muftionSysSrv; "C:\Program Files (x86)\Muftion\muftionSysSrv.exe" {79740E79-A383-47A7-B513-3DF6563D007F} {A16B1AF7-982D-40C3-B5C1-633E1A6A6678} [X]
Unlock: C:\Program Files (x86)\Muftion
C:\Program Files (x86)\Muftion
C:\ProgramData\msiql.exe.lnk
C:\ProgramData\cookies
Unlock: C:\Users\Sven\AppData\Roaming\svrupg.exe
C:\Users\Sven\AppData\Roaming\svrupg.exe
C:\Users\Tim.MirjamZanetti\AppData\Local\UCBrowser
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UC浏览器
S1 UCGuard; C:\Windows\System32\DRIVERS\ucguard.sys [80768 2016-04-25] (Huorong Borui (Beijing) Technology Co., Ltd.)
Unlock: C:\Windows\System32\DRIVERS\ucguard.sys
C:\Windows\System32\DRIVERS\ucguard.sys
C:\Users\Tim.MirjamZanetti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件
C:\Users\Tim.MirjamZanetti\AppData\Roaming\Tencent
C:\ProgramData\hp.exe
C:\ProgramData\webad.xml
C:\Program Files (x86)\badu
C:\Users\Tim.MirjamZanetti\AppData\Roaming\UPUpdata
C:\Users\Tim.MirjamZanetti\AppData\Local\Could not connect. Error code = 0x-1463489703---
C:\ProgramData\download
C:\Program Files (x86)\Preghpluaph
C:\Program Files (x86)\Atapacult
C:\Program Files\6252fcdab494a399247c79cfd21d523e
C:\ProgramData\oqztiqep.adk
ACHTUNG: ==> Auf den BCD konnte nicht zugegriffen werden.
Task: {0E4EE11D-8CC4-49C1-AFF6-69AEEBF6D71E} - \ttwifi -> Keine Datei <==== ACHTUNG
Task: {1B396549-A773-464C-B9B3-B4C49CF28A10} - System32\Tasks\GPU Grid Computing => C:\Windows\SysWOW64\dfrg\runner.exe <==== ACHTUNG
Task: {2BE9495A-0536-4095-919C-3BAFBE453A32} - \UCBrowserUpdater -> Keine Datei <==== ACHTUNG
C:\Windows\SysWOW64\dfrg\runner.exe
Task: {518F9709-9D6E-4D35-A47D-D168B434E37B} - \rde3028 -> Keine Datei <==== ACHTUNG
Task: {E6A77144-B34A-441D-91C8-6EB1F41677AB} - \Muftion System -> Keine Datei <==== ACHTUNG
Task: {E87E1163-69D4-48D1-9F28-74D7FD0D0C23} - \osTip -> Keine Datei <==== ACHTUNG
AlternateDataStreams: C:\ProgramData\Temp:373E1720 [118]
AlternateDataStreams: C:\ProgramData\Temp:AD022376 [296]
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="1"
Unlock: C:\Windows\system32\Drivers\etc\hosts
C:\Windows\system32\Drivers\etc\hosts
Hosts:
RemoveProxy:
CMD: ipconfig /flushdns
CMD: netsh winsock reset
EmptyTemp:
end
*****************
Prozess erfolgreich geschlossen.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Wert erfolgreich entfernt
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ QQPCTray => Wert erfolgreich entfernt
"C:\Program Files (x86)\Tencent" => nicht gefunden.
"C:\Program Files (x86)\Tencent" => nicht gefunden.
HKU\S-1-5-21-1536315646-4119356758-1407283469-1001\Software\Microsoft\Windows\CurrentVersion\Run\\taskhost => Wert erfolgreich entfernt
"C:\ProgramData\WindowsMsg" => nicht gefunden.
"C:\ProgramData\WindowsMsg" => nicht gefunden.
HKU\S-1-5-21-1536315646-4119356758-1407283469-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableClock => Wert erfolgreich entfernt
HKU\S-1-5-21-1536315646-4119356758-1407283469-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoNetworkConnections => Wert erfolgreich entfernt
HKU\S-1-5-21-1536315646-4119356758-1407283469-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => Wert erfolgreich entfernt
HKU\S-1-5-21-1536315646-4119356758-1407283469-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoCommonGroups => Wert erfolgreich entfernt
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive1" => Schlüssel erfolgreich entfernt
HKCR\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A} => Schlüssel nicht gefunden.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive2" => Schlüssel erfolgreich entfernt
HKCR\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => Schlüssel nicht gefunden.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive3" => Schlüssel erfolgreich entfernt
HKCR\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524} => Schlüssel nicht gefunden.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtPending" => Schlüssel erfolgreich entfernt
HKCR\CLSID\{056D528D-CE28-4194-9BA3-BA2E9197FF8C} => Schlüssel nicht gefunden.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSynced" => Schlüssel erfolgreich entfernt
HKCR\CLSID\{05B38830-F4E9-4329-978B-1DD28605D202} => Schlüssel nicht gefunden.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSyncing" => Schlüssel erfolgreich entfernt
HKCR\CLSID\{0596C850-7BDD-4C9D-AFDF-873BE6890637} => Schlüssel nicht gefunden.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\.QMDeskTopGCIcon" => Schlüssel erfolgreich entfernt
"HKCR\CLSID\{B7667919-3765-4815-A66D-98A09BE662D6}" => Schlüssel erfolgreich entfernt
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive1" => Schlüssel erfolgreich entfernt
HKCR\Wow6432Node\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A} => Schlüssel nicht gefunden.
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive2" => Schlüssel erfolgreich entfernt
HKCR\Wow6432Node\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => Schlüssel nicht gefunden.
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive3" => Schlüssel erfolgreich entfernt
HKCR\Wow6432Node\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524} => Schlüssel nicht gefunden.
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtPending" => Schlüssel erfolgreich entfernt
HKCR\Wow6432Node\CLSID\{056D528D-CE28-4194-9BA3-BA2E9197FF8C} => Schlüssel nicht gefunden.
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSynced" => Schlüssel erfolgreich entfernt
HKCR\Wow6432Node\CLSID\{05B38830-F4E9-4329-978B-1DD28605D202} => Schlüssel nicht gefunden.
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSyncing" => Schlüssel erfolgreich entfernt
HKCR\Wow6432Node\CLSID\{0596C850-7BDD-4C9D-AFDF-873BE6890637} => Schlüssel nicht gefunden.
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001" => Schlüssel erfolgreich entfernt
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002" => Schlüssel erfolgreich entfernt
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003" => Schlüssel erfolgreich entfernt
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004" => Schlüssel erfolgreich entfernt
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015" => Schlüssel erfolgreich entfernt
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000001" => Schlüssel erfolgreich entfernt
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000002" => Schlüssel erfolgreich entfernt
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000003" => Schlüssel erfolgreich entfernt
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000004" => Schlüssel erfolgreich entfernt
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000015" => Schlüssel erfolgreich entfernt
"HKU\S-1-5-21-1536315646-4119356758-1407283469-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B}" => Schlüssel erfolgreich entfernt
"HKCR\CLSID\{7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B}" => Schlüssel erfolgreich entfernt
HKU\S-1-5-21-1536315646-4119356758-1407283469-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Wert erfolgreich entfernt
HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Schlüssel nicht gefunden.
C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\dk8rovbg.default-1456592647169\extensions\{697F6AFE-5321-4DE1-BFE6-4471C3721BD4} => erfolgreich verschoben
C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jipdnfibhldikgcjhfnomkfpcebammhp => erfolgreich verschoben
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fgdfbnnnceningmmfememmedbfgmcpcp" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jmnjdacpgoffbagiiehfohoiadgabenc" => Schlüssel erfolgreich entfernt
GoogleChromeUpSvc => Dienst erfolgreich entfernt
"C:\ProgramData\Windows Update" => wurde entsperrt
C:\ProgramData\Windows Update => erfolgreich verschoben
muftionSysSrv => Dienst erfolgreich entfernt
"C:\Program Files (x86)\Muftion" => nicht gefunden.
"C:\Program Files (x86)\Muftion" => nicht gefunden.
C:\ProgramData\msiql.exe.lnk => erfolgreich verschoben
C:\ProgramData\cookies => erfolgreich verschoben
"C:\Users\Sven\AppData\Roaming\svrupg.exe" => wurde entsperrt
C:\Users\Sven\AppData\Roaming\svrupg.exe => erfolgreich verschoben
C:\Users\Tim.MirjamZanetti\AppData\Local\UCBrowser => erfolgreich verschoben
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UC浏览器 => erfolgreich verschoben
UCGuard => Dienst erfolgreich entfernt
"C:\Windows\System32\DRIVERS\ucguard.sys" => wurde entsperrt
C:\Windows\System32\DRIVERS\ucguard.sys => erfolgreich verschoben
C:\Users\Tim.MirjamZanetti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件 => erfolgreich verschoben
C:\Users\Tim.MirjamZanetti\AppData\Roaming\Tencent => erfolgreich verschoben
C:\ProgramData\hp.exe => erfolgreich verschoben
C:\ProgramData\webad.xml => erfolgreich verschoben
C:\Program Files (x86)\badu => erfolgreich verschoben
C:\Users\Tim.MirjamZanetti\AppData\Roaming\UPUpdata => erfolgreich verschoben
C:\Users\Tim.MirjamZanetti\AppData\Local\Could not connect. Error code = 0x-1463489703--- => erfolgreich verschoben
C:\ProgramData\download => erfolgreich verschoben
C:\Program Files (x86)\Preghpluaph => erfolgreich verschoben
C:\Program Files (x86)\Atapacult => erfolgreich verschoben
C:\Program Files\6252fcdab494a399247c79cfd21d523e => erfolgreich verschoben
C:\ProgramData\oqztiqep.adk => erfolgreich verschoben
ACHTUNG: ==> Auf den BCD konnte nicht zugegriffen werden. => Fehler: Kein automatisierter Fix für diesen Eintrag gefunden.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0E4EE11D-8CC4-49C1-AFF6-69AEEBF6D71E}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0E4EE11D-8CC4-49C1-AFF6-69AEEBF6D71E}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ttwifi" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1B396549-A773-464C-B9B3-B4C49CF28A10}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B396549-A773-464C-B9B3-B4C49CF28A10}" => Schlüssel erfolgreich entfernt
C:\Windows\System32\Tasks\GPU Grid Computing => erfolgreich verschoben
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GPU Grid Computing" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2BE9495A-0536-4095-919C-3BAFBE453A32}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2BE9495A-0536-4095-919C-3BAFBE453A32}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UCBrowserUpdater" => Schlüssel erfolgreich entfernt
"C:\Windows\SysWOW64\dfrg\runner.exe" => nicht gefunden.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{518F9709-9D6E-4D35-A47D-D168B434E37B}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{518F9709-9D6E-4D35-A47D-D168B434E37B}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\rde3028" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E6A77144-B34A-441D-91C8-6EB1F41677AB}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E6A77144-B34A-441D-91C8-6EB1F41677AB}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Muftion System" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E87E1163-69D4-48D1-9F28-74D7FD0D0C23}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E87E1163-69D4-48D1-9F28-74D7FD0D0C23}" => Schlüssel erfolgreich entfernt
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\osTip" => Schlüssel erfolgreich entfernt
C:\ProgramData\Temp => ":373E1720" ADS erfolgreich entfernt.
C:\ProgramData\Temp => ":AD022376" ADS erfolgreich entfernt.
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc" => Schlüssel erfolgreich entfernt
"C:\Windows\system32\Drivers\etc\hosts" => wurde entsperrt
C:\Windows\system32\Drivers\etc\hosts => erfolgreich verschoben
Hosts erfolgreich wiederhergestellt.
========= RemoveProxy: =========
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt
HKU\S-1-5-21-1536315646-4119356758-1407283469-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wert erfolgreich entfernt
HKU\S-1-5-21-1536315646-4119356758-1407283469-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wert erfolgreich entfernt
========= Ende von RemoveProxy: =========
========= ipconfig /flushdns =========
Der Befehl "ipconfig" ist entweder falsch geschrieben oder
konnte nicht gefunden werden.
========= Ende von CMD: =========
========= netsh winsock reset =========
Der Befehl "netsh" ist entweder falsch geschrieben oder
konnte nicht gefunden werden.
========= Ende von CMD: =========
EmptyTemp: => 20.7 GB temporäre Dateien entfernt.
Das System musste neu gestartet werden.
==== Ende von Fixlog 14:38:11 ==== So, hier noch die Combofix: Code:
ComboFix 16-05-18.01 - Sven 23.05.2016 19:19:06.1.2 - x64 NETWORK
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.41.1031.18.3541.2127 [GMT 2:00]
ausgeführt von:: c:\users\Sven\Desktop\ComboFix.exe
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Sven\Documents\~WRL2131.tmp
c:\users\Tim.MirjamZanetti\AppData\Roaming\993219139f5a6214ac82f006aa238ea12
c:\users\Tim.MirjamZanetti\AppData\Roaming\svrupg.exe
c:\windows\8178baefb0fa9dc188cf02763d3585cd.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2016-04-23 bis 2016-05-23 ))))))))))))))))))))))))))))))
.
.
2016-05-23 17:37 . 2016-05-23 17:37 -------- d-----w- c:\users\Tim\AppData\Local\temp
2016-05-23 17:37 . 2016-05-23 17:37 -------- d-----w- c:\users\Tim.MirjamZanetti\AppData\Local\temp
2016-05-23 17:37 . 2016-05-23 17:37 -------- d-----w- c:\users\Public\AppData\Local\temp
2016-05-23 17:11 . 2016-05-23 17:11 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{88FB62E2-26DE-47D6-B979-CB52A23D6CC0}\offreg.840.dll
2016-05-17 20:30 . 2016-05-17 20:30 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{88FB62E2-26DE-47D6-B979-CB52A23D6CC0}\offreg.948.dll
2016-05-17 20:17 . 2016-05-17 20:17 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{88FB62E2-26DE-47D6-B979-CB52A23D6CC0}\offreg.1172.dll
2016-05-17 20:04 . 2016-05-17 20:04 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{88FB62E2-26DE-47D6-B979-CB52A23D6CC0}\offreg.1192.dll
2016-05-17 19:57 . 2016-05-17 19:57 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{88FB62E2-26DE-47D6-B979-CB52A23D6CC0}\offreg.1256.dll
2016-05-17 19:03 . 2016-05-17 19:03 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{88FB62E2-26DE-47D6-B979-CB52A23D6CC0}\offreg.1212.dll
2016-05-17 18:49 . 2016-05-17 18:49 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{88FB62E2-26DE-47D6-B979-CB52A23D6CC0}\offreg.1228.dll
2016-05-17 13:47 . 2016-05-17 13:47 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{88FB62E2-26DE-47D6-B979-CB52A23D6CC0}\offreg.1204.dll
2016-05-17 13:20 . 2016-05-17 13:20 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{88FB62E2-26DE-47D6-B979-CB52A23D6CC0}\offreg.1260.dll
2016-05-17 13:08 . 2016-05-17 13:08 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{88FB62E2-26DE-47D6-B979-CB52A23D6CC0}\offreg.1224.dll
2016-05-17 13:00 . 2016-05-17 13:00 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{88FB62E2-26DE-47D6-B979-CB52A23D6CC0}\offreg.1080.dll
2016-05-17 12:22 . 2016-05-17 12:22 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{88FB62E2-26DE-47D6-B979-CB52A23D6CC0}\offreg.1236.dll
2016-05-17 12:10 . 2016-05-17 12:10 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{88FB62E2-26DE-47D6-B979-CB52A23D6CC0}\offreg.1164.dll
2016-05-17 11:50 . 2016-05-17 11:50 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{88FB62E2-26DE-47D6-B979-CB52A23D6CC0}\offreg.1104.dll
2016-05-17 11:36 . 2016-05-17 19:28 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{88FB62E2-26DE-47D6-B979-CB52A23D6CC0}\offreg.1180.dll
2016-05-17 11:02 . 2016-05-17 13:21 -------- d-----w- c:\program files (x86)\osTip
2016-05-17 10:38 . 2016-05-17 10:38 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{88FB62E2-26DE-47D6-B979-CB52A23D6CC0}\offreg.1012.dll
2016-05-17 10:35 . 2016-04-20 01:13 11695896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{88FB62E2-26DE-47D6-B979-CB52A23D6CC0}\mpengine.dll
2016-05-16 17:25 . 2011-01-03 13:39 -------- d-----w- C:\FRST
2016-05-16 17:19 . 2016-05-17 20:22 -------- d-----w- c:\users\Sven\AppData\Local\app
2016-05-16 17:05 . 2016-05-16 17:05 -------- d-----w- C:\found.002
2016-05-16 16:52 . 2016-05-17 10:38 -------- d-----w- c:\users\Tim.MirjamZanetti\AppData\Local\app
2016-05-16 16:48 . 2016-05-16 16:48 -------- d-----w- c:\users\Public\Thunder Network
2016-05-16 16:48 . 2016-05-16 16:48 -------- d-----w- c:\programdata\Thunder Network
2016-05-16 16:46 . 2016-05-16 16:46 -------- d-----w- c:\users\Tim.MirjamZanetti\AppData\Local\Profiles
2016-05-16 16:41 . 2016-05-16 16:42 -------- d-----w- c:\users\Tim.MirjamZanetti\AppData\Roaming\Profiles
2016-05-16 10:25 . 2016-04-20 01:13 11695896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2016-05-13 13:47 . 2016-05-13 13:47 -------- d-----w- c:\program files (x86)\Sizer
2016-05-13 13:46 . 2016-05-13 13:45 715038 ----a-w- c:\windows\unins003.exe
2016-05-13 13:46 . 2011-12-07 17:37 148992 ----a-w- c:\windows\system32\lagarith.dll
2016-05-13 13:46 . 2011-12-07 17:32 216064 ----a-w- c:\windows\SysWow64\lagarith.dll
2016-05-13 10:46 . 2016-05-13 10:46 -------- d-----w- c:\users\Tim.MirjamZanetti\AppData\Local\Dxtory Software
2016-05-13 10:46 . 2014-06-08 20:14 2610736 ----a-w- c:\windows\system32\DxtoryCodec.dll
2016-05-13 10:46 . 2014-06-08 20:14 2508336 ----a-w- c:\windows\SysWow64\DxtoryCodec.dll
2016-05-13 10:46 . 2016-05-13 10:46 -------- d-----w- c:\program files (x86)\ExKode
2016-05-12 17:34 . 2016-05-12 17:34 5995712 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2016-05-11 13:37 . 2016-05-11 13:36 1167568 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9ECA1DC1-BAE7-49FC-8E7C-0673F4600C11}\gapaengine.dll
2016-05-11 10:20 . 2016-04-09 05:49 3217408 ----a-w- c:\windows\system32\win32k.sys
2016-05-11 10:20 . 2016-04-09 06:58 2048 ----a-w- c:\windows\system32\tzres.dll
2016-05-11 10:20 . 2016-04-09 06:54 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2016-05-11 10:12 . 2016-04-09 07:01 5546216 ----a-w- c:\windows\system32\ntoskrnl.exe
2016-05-10 14:14 . 2016-05-10 14:14 -------- d-----w- c:\users\Mirjam Zanetti\AppData\Roaming\Highresolution Enterprises
2016-05-09 10:24 . 2016-05-09 10:24 -------- d-----w- c:\programdata\regid.1995-08.com.techsmith
2016-05-09 10:24 . 2016-05-09 10:24 -------- d-----w- c:\program files (x86)\QuickTime
2016-05-09 10:24 . 2016-05-09 10:24 -------- d-----w- c:\program files (x86)\Common Files\TechSmith Shared
2016-05-09 10:24 . 2016-05-09 10:24 -------- d-----w- c:\program files (x86)\TechSmith
2016-05-07 16:36 . 2016-05-07 16:36 -------- d-----w- c:\programdata\Riot Games
2016-05-07 16:14 . 2016-05-07 16:18 -------- d-----w- c:\users\Tim.MirjamZanetti\AppData\Roaming\Riot Games
2016-05-06 18:56 . 2016-05-06 18:56 -------- d-----w- c:\users\Tim.MirjamZanetti\AppData\Roaming\Highresolution Enterprises
2016-05-06 12:55 . 2016-05-06 12:55 -------- d-----w- c:\users\Sven\AppData\Roaming\Highresolution Enterprises
2016-05-06 12:55 . 2016-05-06 12:55 -------- d-----w- c:\program files\Highresolution Enterprises
2016-04-27 11:58 . 2016-05-07 16:14 -------- d-----w- c:\users\Tim.MirjamZanetti\AppData\Roaming\Audacity
2016-04-26 20:02 . 2016-04-26 20:02 -------- d-----w- c:\program files (x86)\Common Files\Java
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-05-23 17:10 . 2016-03-23 11:19 196608 ----a-w- c:\windows\ServiceProfiles\NetworkService\msmqlog.bin
2016-05-12 17:34 . 2012-03-23 00:24 797376 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2016-05-12 17:34 . 2012-03-23 00:24 142528 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2016-05-11 12:02 . 2012-11-07 12:34 139319312 ----a-w- c:\windows\system32\MRT.exe
2016-05-06 14:29 . 2013-02-28 21:36 34720 ---ha-w- c:\windows\system32\hamachi.sys
2016-04-26 20:01 . 2016-04-03 09:13 110144 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2016-04-22 07:57 . 2010-11-21 03:27 453288 ------w- c:\windows\system32\MpSigStub.exe
2016-04-09 06:54 . 2016-05-11 10:12 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2016-04-04 18:14 . 2016-04-15 17:42 38120 ----a-w- c:\windows\system32\CompatTelRunner.exe
2016-04-04 18:02 . 2016-04-15 17:42 1169408 ----a-w- c:\windows\system32\aeinv.dll
2016-04-02 13:08 . 2016-04-15 17:42 1386496 ----a-w- c:\windows\system32\appraiser.dll
2016-03-23 14:02 . 2016-04-15 17:42 215040 ----a-w- c:\windows\system32\aepic.dll
2016-03-17 22:56 . 2016-04-15 17:47 2084864 ----a-w- c:\windows\system32\ole32.dll
2016-03-17 22:28 . 2016-04-15 17:47 1414144 ----a-w- c:\windows\SysWow64\ole32.dll
2016-03-17 18:04 . 2016-04-15 17:42 698368 ----a-w- c:\windows\system32\generaltel.dll
2016-03-17 18:04 . 2016-04-15 17:42 499200 ----a-w- c:\windows\system32\devinv.dll
2016-03-17 18:04 . 2016-04-15 17:42 279040 ----a-w- c:\windows\system32\invagent.dll
2016-03-17 18:04 . 2016-04-15 17:42 76800 ----a-w- c:\windows\system32\acmigration.dll
2016-03-16 18:50 . 2016-04-15 17:49 156672 ----a-w- c:\windows\system32\mtxoci.dll
2016-03-16 18:28 . 2016-04-15 17:49 111616 ----a-w- c:\windows\SysWow64\mtxoci.dll
2016-03-16 18:28 . 2016-04-15 17:49 176128 ----a-w- c:\windows\SysWow64\msorcl32.dll
2016-03-16 00:16 . 2016-04-15 17:41 760320 ----a-w- c:\windows\system32\samsrv.dll
2016-03-16 00:16 . 2016-04-15 17:41 106496 ----a-w- c:\windows\system32\samlib.dll
2016-03-15 23:53 . 2016-04-15 17:41 60416 ----a-w- c:\windows\SysWow64\samlib.dll
2016-03-06 18:53 . 2016-04-15 17:49 2048 ----a-w- c:\windows\system32\msxml3r.dll
2016-03-06 18:53 . 2016-04-15 17:49 1885696 ----a-w- c:\windows\system32\msxml3.dll
2016-03-06 18:38 . 2016-04-15 17:49 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
2016-03-06 18:38 . 2016-04-15 17:49 1240576 ----a-w- c:\windows\SysWow64\msxml3.dll
2016-03-01 08:50 . 2016-03-01 08:50 1058 ----a-w- c:\windows\run.vbs
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2016-05-06 5565960]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2016-04-01 596504]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"IsMyWinLockerReboot"="msiexec.exe" [2015-06-15 73216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableSecureUIAPath"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
R1 MpKslb3491254;MpKslb3491254;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{58D6DEB4-DD46-4141-AC8F-5EF5CD5D6FA6}\MpKslb3491254.sys;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{58D6DEB4-DD46-4141-AC8F-5EF5CD5D6FA6}\MpKslb3491254.sys [x]
R1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x]
R1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x]
R1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
R2 Apple Mobile Device Service;Apple Mobile Device Service;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [x]
R2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.exe;c:\program files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.exe [x]
R2 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
R2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [x]
R2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [x]
R2 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\EscSvc64.exe;c:\windows\SYSNATIVE\EscSvc64.exe [x]
R2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe;c:\program files (x86)\Acer\Registration\GREGsvc.exe [x]
R2 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
R2 Razer Game Scanner Service;Razer Game Scanner;c:\program files (x86)\Razer\Razer Services\GSS\GameScannerService.exe;c:\program files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [x]
R2 RzKLService;RzKLService;c:\program files (x86)\Razer\Razer Cortex\RzKLService.exe;c:\program files (x86)\Razer\Razer Cortex\RzKLService.exe [x]
R2 rzpmgrk;rzpmgrk;c:\windows\system32\drivers\rzpmgrk.sys;c:\windows\SYSNATIVE\drivers\rzpmgrk.sys [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
R3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.exe;c:\program files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.exe [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 GamesAppIntegrationService;GamesAppIntegrationService;c:\program files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [x]
R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x]
R3 OverwolfUpdater;Overwolf Updater Windows SCM;c:\program files (x86)\Overwolf\OverwolfUpdater.exe;c:\program files (x86)\Overwolf\OverwolfUpdater.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 ScreamBAudioSvc;ScreamBee Audio;c:\windows\system32\drivers\ScreamingBAudio64.sys;c:\windows\SYSNATIVE\drivers\ScreamingBAudio64.sys [x]
R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x]
R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WSDScan;WSD-Scanunterstützung durch UMB;c:\windows\system32\DRIVERS\WSDScan.sys;c:\windows\SYSNATIVE\DRIVERS\WSDScan.sys [x]
R4 ArcService;Arc Service;c:\program files (x86)\Perfect World Entertainment\Arc\ArcService.exe;c:\program files (x86)\Perfect World Entertainment\Arc\ArcService.exe [x]
R4 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;c:\program files\BitComet\tools\BitCometService.exe;c:\program files\BitComet\tools\BitCometService.exe [x]
R4 EgisTec Ticket Service;EgisTec Ticket Service;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [x]
R4 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
R4 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
R4 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
R4 NoIPDUCService4;NO-IP DUC v4.1.1;c:\program files (x86)\No-IP\ducservice.exe;c:\program files (x86)\No-IP\ducservice.exe [x]
R4 PdiService;Portrait Displays SDK Service;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys;c:\windows\SYSNATIVE\DRIVERS\amdhub30.sys [x]
S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys;c:\windows\SYSNATIVE\DRIVERS\amdxhc.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2016-05-13 11:14 1186968 ----a-w- c:\program files (x86)\Google\Chrome\Application\50.0.2661.102\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2016-05-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-23 17:34]
.
2011-01-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2016-02-16 21:00]
.
2016-05-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2016-02-16 21:00]
.
2016-05-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1536315646-4119356758-1407283469-1002Core.job
- c:\users\Tim\AppData\Local\Google\Update\GoogleUpdate.exe [2014-01-26 16:18]
.
2016-05-23 c:\windows\Tasks\HP Photo Creations Communicator.job
- c:\programdata\HP Photo Creations\Communicator.exe [2014-01-23 11:39]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"XMouseButtonControl"="c:\program files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe" [2015-10-18 1127408]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.google.com
IE: &Alles mit BitComet herunterladen - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Mit BitComet herunter&laden - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{CAFC688E-6314-427C-8B2E-F1D3D855A2BF}: NameServer = 8.8.8.8,8.8.4.4
FF - ProfilePath - c:\users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\dk8rovbg.default-1456592647169\
FF - prefs.js: browser.startup.homepage - google.ch
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM_Wow6432Node-ActiveSetup-{65122CB0-EA0F-47DF-A953-017170ED12F9} - c:\program files (x86)\UCBrowser\Application\5.6.12150.8\Installer\chrmstp.exe
AddRemove-Uninstall cos - c:\program files (x86)\SearchesToYesbnd\unIns.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_LOCAL_MACHINE\software\BlueStacks]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_21_0_0_242_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_21_0_0_242_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_21_0_0_242_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_21_0_0_242_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_21_0_0_242.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.21"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_21_0_0_242.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_21_0_0_242.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_21_0_0_242.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Nico Mak Computing\WinZip]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2016-05-23 19:42:22
ComboFix-quarantined-files.txt 2016-05-23 17:42
.
Vor Suchlauf: 30 Verzeichnis(se), 161'355'415'552 Bytes frei
Nach Suchlauf: 33 Verzeichnis(se), 160'334'995'456 Bytes frei
.
- - End Of File - - 3BD7C27F5C4388BE7C0FC48F4F1D9638
A36C5E4F47E84449FF07ED3517B43A31 |