Combofix Logfile: Code:
ComboFix 13-06-15.01 - Qadir 16.06.2013 18:08:56.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.2046.1361 [GMT 2:00]
ausgeführt von:: c:\users\Qadir\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Qadir\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Antivirus *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\1334772755.bdinstall.bin
c:\programdata\1334942059.bdinstall.bin
c:\programdata\contiinUEEtosaVe
c:\programdata\contiinUEEtosaVe\51af0bfc4771c.dll
c:\programdata\contiinUEEtosaVe\51af0bfc4771c.tlb
c:\programdata\contiinUEEtosaVe\settings.ini
c:\users\All Users\contiinUEEtosaVe\51af0bfc4771c.dll
c:\users\All Users\contiinUEEtosaVe\51af0bfc4771c.tlb
c:\users\All Users\contiinUEEtosaVe\settings.ini
c:\users\Qadir\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmhlaanifolhekpaminkellhiklfkcdd
c:\users\Qadir\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmhlaanifolhekpaminkellhiklfkcdd\1\51af0bfc474d40.74263894.js
c:\users\Qadir\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmhlaanifolhekpaminkellhiklfkcdd\1\background.html
c:\users\Qadir\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmhlaanifolhekpaminkellhiklfkcdd\1\content.js
c:\users\Qadir\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmhlaanifolhekpaminkellhiklfkcdd\1\lsdb.js
c:\users\Qadir\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmhlaanifolhekpaminkellhiklfkcdd\1\manifest.json
c:\users\Qadir\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmhlaanifolhekpaminkellhiklfkcdd\1\sqlite.js
c:\windows\desktop
c:\windows\IsUn0407.exe
c:\windows\system32\frapsvid.dll
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-05-16 bis 2013-06-16 ))))))))))))))))))))))))))))))
.
.
2013-06-16 16:23 . 2013-06-16 16:23 9310 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXTBOX.JS
2013-06-16 16:23 . 2013-06-16 16:23 8646 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TILEBOX.JS
2013-06-16 16:23 . 2013-06-16 16:23 8613 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\SAVEDUSER.JS
2013-06-16 16:23 . 2013-06-16 16:23 6910 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\NEWUSERCOMM.JS
2013-06-16 16:23 . 2013-06-16 16:23 6429 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS
2013-06-16 16:23 . 2013-06-16 16:23 63115 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS
2013-06-16 16:20 . 2013-06-16 16:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-06-15 18:20 . 2013-06-15 18:35 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2013-06-14 17:55 . 2013-06-14 18:19 -------- d-----w- C:\ubuntu
2013-06-14 12:43 . 2013-06-14 13:11 -------- d-----w- c:\program files\Origin Games
2013-06-14 12:43 . 2013-06-14 17:39 -------- d-----w- c:\users\Qadir\AppData\Local\Origin
2013-06-14 12:42 . 2013-06-15 16:38 -------- d-----w- c:\program files\Origin
2013-06-13 20:16 . 2013-06-13 20:16 -------- d-----w- c:\users\Qadir\VirtualBox VMs
2013-06-13 20:14 . 2013-04-12 10:33 188176 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2013-06-13 20:14 . 2013-04-12 10:33 94480 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2013-06-13 20:10 . 2012-10-24 12:17 63128 ----a-w- c:\windows\system32\vsocklib.dll
2013-06-13 20:10 . 2012-10-24 12:16 61464 ----a-w- c:\windows\system32\drivers\vsock.sys
2013-06-13 20:10 . 2013-02-26 00:27 26064 ----a-w- c:\windows\system32\drivers\VMkbd.sys
2013-06-13 20:09 . 2013-02-26 00:28 357456 ----a-w- c:\windows\system32\vmnetdhcp.exe
2013-06-13 20:09 . 2013-02-26 00:28 436304 ----a-w- c:\windows\system32\vmnat.exe
2013-06-13 20:09 . 2013-02-26 00:28 26192 ----a-w- c:\windows\system32\drivers\vmnetuserif.sys
2013-06-13 20:09 . 2013-02-26 00:28 780368 ----a-w- c:\windows\system32\vnetlib.dll
2013-06-13 20:09 . 2012-10-11 14:15 41496 ----a-w- c:\windows\system32\drivers\hcmon.sys
2013-06-13 20:09 . 2013-06-13 20:09 -------- d-----w- c:\program files\Common Files\VMware
2013-06-12 15:51 . 2013-06-08 11:13 2706432 ----a-w- c:\windows\system32\mshtml.tlb
2013-06-12 15:51 . 2013-06-08 11:41 218112 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2013-06-12 07:26 . 2013-04-25 23:30 1505280 ----a-w- c:\windows\system32\d3d11.dll
2013-06-12 07:26 . 2013-05-10 03:20 24576 ----a-w- c:\windows\system32\cryptdlg.dll
2013-06-12 07:26 . 2013-04-26 04:55 492544 ----a-w- c:\windows\system32\win32spl.dll
2013-06-12 07:26 . 2013-05-13 03:08 903168 ----a-w- c:\windows\system32\certutil.exe
2013-06-12 07:26 . 2013-05-13 04:45 1160192 ----a-w- c:\windows\system32\crypt32.dll
2013-06-12 07:26 . 2013-05-13 04:45 103936 ----a-w- c:\windows\system32\cryptnet.dll
2013-06-12 07:26 . 2013-05-13 04:45 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2013-06-12 07:26 . 2013-05-13 03:08 43008 ----a-w- c:\windows\system32\certenc.dll
2013-06-12 07:26 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-06-12 07:26 . 2013-05-06 05:06 3913576 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-06-12 07:26 . 2013-05-06 05:06 3968872 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-06-12 07:26 . 2013-05-08 05:38 1293672 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-06-10 19:53 . 2013-06-10 19:53 -------- d-----w- c:\program files\Axantum
2013-06-10 12:18 . 2013-06-10 12:18 -------- d-----w- c:\users\Qadir\AppData\Local\B1E
2013-06-10 12:18 . 2013-06-10 12:18 -------- d-----w- c:\users\Qadir\AppData\Roaming\B1Toolbar
2013-06-05 20:59 . 2013-06-05 20:59 -------- d-----w- c:\programdata\ATI
2013-06-05 20:55 . 2013-06-05 20:55 -------- d-----w- c:\program files\AMD AVT
2013-06-05 20:55 . 2013-06-05 20:55 -------- d-----w- c:\program files\Common Files\ATI Technologies
2013-06-05 20:53 . 2013-06-05 20:53 -------- d-----w- c:\program files\ATI
2013-06-05 20:52 . 2013-06-05 20:55 -------- d-----w- c:\program files\ATI Technologies
2013-06-05 10:01 . 2013-06-05 16:36 -------- d-----w- c:\users\Qadir\AppData\Roaming\Flashmedia
2013-06-05 09:58 . 2013-06-05 09:58 -------- d-----w- c:\programdata\StarApp
2013-06-05 09:57 . 2013-06-05 20:48 -------- d-----w- c:\program files\ContinueToSave
2013-06-05 09:57 . 2013-06-05 09:58 -------- d-----w- c:\programdata\InstallMate
2013-05-31 16:32 . 2013-05-31 16:32 -------- d-----w- c:\users\Qadir\AppData\Local\WDSetup
2013-05-31 16:26 . 2013-05-31 17:07 -------- d-----w- c:\program files\bootanim_changer
2013-05-26 20:45 . 2013-05-26 20:45 -------- d-----w- c:\program files\MediaInfo
2013-05-26 15:59 . 2013-05-26 19:48 -------- d-----w- c:\program files\QuickTime
2013-05-26 15:56 . 2013-05-26 15:56 -------- d-----w- c:\program files\Mirillis
2013-05-26 15:53 . 2013-05-26 15:53 -------- d-----w- c:\program files\MPC-HC
2013-05-22 22:19 . 2013-05-22 22:19 -------- d-----w- c:\programdata\KONAMI
2013-05-22 18:02 . 2013-05-31 17:11 138032 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2013-05-22 18:02 . 2013-05-31 17:11 281688 ----a-w- c:\windows\system32\PnkBstrB.exe
2013-05-22 18:02 . 2013-05-30 16:12 281688 ----a-w- c:\windows\system32\PnkBstrB.ex0
2013-05-22 18:02 . 2013-05-22 18:02 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2013-05-22 16:43 . 2013-05-22 16:43 87608 ----a-w- c:\users\Qadir\AppData\Roaming\inst.exe
2013-05-22 16:43 . 2013-05-22 16:43 47360 ----a-w- c:\users\Qadir\AppData\Roaming\pcouffin.sys
2013-05-19 20:12 . 2013-06-05 16:48 -------- d-----w- c:\programdata\Tarma Installer
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-12 13:27 . 2012-04-21 11:05 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-12 13:27 . 2011-06-20 20:42 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-31 17:11 . 2012-12-01 16:07 281688 ----a-w- c:\windows\system32\PnkBstrB.xtr
2013-05-09 08:59 . 2013-03-02 21:48 368944 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-05-09 08:59 . 2013-03-02 21:47 61680 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-05-09 08:59 . 2013-03-02 21:47 56080 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-05-09 08:59 . 2013-03-02 21:47 765736 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-05-09 08:59 . 2013-03-02 21:47 49376 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-05-09 08:59 . 2013-03-02 21:47 174664 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-05-09 08:59 . 2013-03-02 21:47 204784 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2013-05-09 08:59 . 2013-03-02 21:47 21576 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2013-05-09 08:59 . 2013-03-02 21:47 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-05-09 08:59 . 2013-03-02 21:48 29816 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-05-09 08:59 . 2013-03-02 21:47 104752 ----a-w- c:\windows\system32\drivers\aswFW.sys
2013-05-09 08:58 . 2013-03-02 21:47 41664 ----a-w- c:\windows\avastSS.scr
2013-05-09 08:58 . 2013-03-02 20:57 229648 ----a-w- c:\windows\system32\aswBoot.exe
2013-04-26 14:26 . 2011-06-28 19:13 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2013-04-26 14:09 . 2013-04-26 14:09 22328 ----a-w- c:\users\Qadir\AppData\Roaming\PnkBstrK.sys
2013-04-25 18:52 . 2013-04-25 18:52 641024 ----a-w- c:\windows\system32\ficvdec_x86.dll
2013-04-17 14:41 . 2013-04-17 14:41 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-04-17 14:41 . 2012-08-13 16:16 866720 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-04-17 14:41 . 2011-06-20 20:26 788896 ----a-w- c:\windows\system32\deployJava1.dll
2013-04-13 04:45 . 2013-05-16 09:42 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45 . 2013-05-16 09:42 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-04-12 13:45 . 2013-04-24 11:07 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-12 10:33 . 2013-04-12 10:33 104720 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2013-04-12 10:32 . 2013-04-12 10:32 115984 ----a-w- c:\windows\system32\drivers\VBoxNetFlt.sys
2013-04-12 10:32 . 2013-04-12 10:32 174864 ----a-w- c:\windows\system32\VBoxNetFltNobj.dll
2013-04-10 05:18 . 2013-05-16 09:42 728424 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-04-10 05:18 . 2013-05-16 09:42 218984 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-04-10 03:14 . 2013-05-16 09:42 2347520 ----a-w- c:\windows\system32\win32k.sys
2013-04-04 12:50 . 2013-01-22 18:47 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-03-29 02:37 . 2013-03-29 02:37 71704 ----a-w- c:\windows\system32\atimpc32.dll
2013-03-29 02:37 . 2013-03-29 02:37 71704 ----a-w- c:\windows\system32\amdpcom32.dll
2013-03-29 02:37 . 2013-03-29 02:37 118584 ----a-w- c:\windows\system32\atiuxpag.dll
2013-03-29 02:37 . 2013-03-29 02:37 92304 ----a-w- c:\windows\system32\atiu9pag.dll
2013-03-29 02:37 . 2013-03-29 02:37 970912 ----a-w- c:\windows\system32\aticfx32.dll
2013-03-29 02:36 . 2013-03-29 02:36 7233336 ----a-w- c:\windows\system32\atidxx32.dll
2013-03-29 02:36 . 2013-03-29 02:36 4450264 ----a-w- c:\windows\system32\atiumdva.dll
2013-03-29 02:36 . 2013-03-29 02:36 5944264 ----a-w- c:\windows\system32\atiumdag.dll
2013-03-29 02:33 . 2013-03-29 02:33 9986048 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2013-03-29 02:13 . 2013-03-29 02:13 180224 ----a-w- c:\windows\system32\clinfo.exe
2013-03-29 02:13 . 2013-03-29 02:13 798734 ----a-w- c:\windows\system32\amdocl_ld32.exe
2013-03-29 02:13 . 2013-03-29 02:13 995342 ----a-w- c:\windows\system32\amdocl_as32.exe
2013-03-29 02:13 . 2013-03-29 02:13 65536 ----a-w- c:\windows\system32\OpenVideo.dll
2013-03-29 02:12 . 2013-03-29 02:12 56320 ----a-w- c:\windows\system32\OVDecode.dll
2013-03-29 02:10 . 2013-03-29 02:10 23810560 ----a-w- c:\windows\system32\amdocl.dll
2013-03-29 02:09 . 2013-03-29 02:09 50176 ----a-w- c:\windows\system32\OpenCL.dll
2013-03-29 02:00 . 2013-03-29 02:00 62976 ----a-w- c:\windows\system32\coinst_12.104.dll
2013-03-29 01:57 . 2013-03-29 01:57 163840 ----a-w- c:\windows\system32\atiapfxx.exe
2013-03-29 01:55 . 2013-03-29 01:55 46080 ----a-w- c:\windows\system32\aticalrt.dll
2013-03-29 01:55 . 2013-03-29 01:55 44032 ----a-w- c:\windows\system32\aticalcl.dll
2013-03-29 01:51 . 2013-03-29 01:51 13703168 ----a-w- c:\windows\system32\aticaldd.dll
2013-03-29 01:48 . 2013-03-29 01:48 19870720 ----a-w- c:\windows\system32\atioglxx.dll
2013-03-29 01:35 . 2013-03-29 01:35 442368 ----a-w- c:\windows\system32\atidemgy.dll
2013-03-29 01:34 . 2013-03-29 01:34 492544 ----a-w- c:\windows\system32\atieclxx.exe
2013-03-29 01:34 . 2013-03-29 01:34 219136 ----a-w- c:\windows\system32\atiesrxx.exe
2013-03-29 01:32 . 2013-03-29 01:32 163840 ----a-w- c:\windows\system32\atitmmxx.dll
2013-03-29 01:32 . 2013-03-29 01:32 25600 ----a-w- c:\windows\system32\atimuixx.dll
2013-03-29 01:32 . 2013-03-29 01:32 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2013-03-29 01:10 . 2013-03-29 01:10 430080 ----a-w- c:\windows\system32\atiadlxx.dll
2013-03-29 01:10 . 2013-03-29 01:10 14848 ----a-w- c:\windows\system32\atiglpxx.dll
2013-03-29 01:09 . 2013-03-29 01:09 34816 ----a-w- c:\windows\system32\atigktxx.dll
2013-03-29 01:08 . 2013-03-29 01:08 463872 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2013-03-29 01:07 . 2013-03-29 01:07 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2013-03-20 19:14 . 2013-03-20 19:14 242240 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2013-03-19 04:53 . 2013-05-16 09:42 186368 ----a-w- c:\windows\system32\wwansvc.dll
2013-03-19 04:48 . 2013-04-10 06:30 38912 ----a-w- c:\windows\system32\csrsrv.dll
2013-03-19 03:33 . 2013-05-16 09:42 40960 ----a-w- c:\windows\system32\wwanprotdim.dll
2013-03-19 02:49 . 2013-04-10 06:30 69632 ----a-w- c:\windows\system32\smss.exe
2010-08-03 10:11 819200 --sha-w- c:\windows\System32\xvidcore.dll
2010-08-03 10:11 180224 --sha-w- c:\windows\System32\xvidvfw.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-05-09 08:58 121968 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-15 23:49 130736 ----a-w- c:\users\Qadir\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-15 23:49 130736 ----a-w- c:\users\Qadir\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-15 23:49 130736 ----a-w- c:\users\Qadir\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-15 23:49 130736 ----a-w- c:\users\Qadir\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKLM\~\startupfolder\C:^Users^Qadir^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
path=c:\users\Qadir\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
2010-03-13 12:54 91520 ----a-w- c:\program files\Microsoft Office\Office14\BCSSync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2013-03-14 08:23 3672640 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2013-02-13 02:37 1263952 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixCamera]
2008-08-21 12:19 188928 ----a-w- c:\windows\FixCamera.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2012-08-13 16:45 116648 ----atw- c:\users\Qadir\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HTC Sync Loader]
2012-04-01 15:04 634880 ----a-w- c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MouseDriver]
2012-12-19 07:42 241152 ----a-w- c:\windows\System32\TiltWheelMouse.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-04-16 20:12 3872080 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
2007-05-15 02:03 86016 ----a-w- c:\windows\System32\nvsvc.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDVCPL]
2012-03-27 15:07 10967656 ------w- c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2013-03-28 20:35 642656 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2013-03-15 16:29 1632680 ----a-w- c:\program files\Steam\steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2013-03-12 05:32 253816 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-01-08 161536]
R3 apf001;apf001;c:\program files\Aeria games\apf001.sys [x]
R3 bdsandbox;bdsandbox;c:\windows\system32\drivers\bdsandbox.sys [2012-04-21 63056]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files\Garena Classic\safedrv.sys [x]
R3 HPMo4DE3;Mouse Suite Driver_4DE3 (WDF Version);c:\windows\system32\DRIVERS\HPMo4DE3.sys [2011-03-09 20992]
R3 HPub4DE3;USB Mouse Low Filter Driver_4DE3 (WDF Version);c:\windows\system32\Drivers\HPub4DE3.sys [2011-04-12 13824]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-10-26 25088]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2010-06-23 23040]
R3 KMWDFilterV1;KMWDFilterV1;c:\windows\System32\Drivers\RPGMOUSEV1.sys [2009-05-11 24576]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2011-05-08 4100400]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
S0 aswKbd;aswKbd; [x]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2013-02-18 12112]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S0 aswRvrt;aswRvrt; [x]
S0 aswVmm;aswVmm; [x]
S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [2012-10-24 71152]
S0 vsock;vSockets Driver;c:\windows\system32\drivers\vsock.sys [2012-10-24 61464]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-03-20 242240]
S1 HssDRV6;Hotspot Shield Routing Driver 6;c:\windows\system32\DRIVERS\hssdrv6.sys [2012-07-24 35560]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2013-04-12 188176]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2013-04-12 94480]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2013-03-29 219136]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-05-09 66336]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2013-05-09 137960]
S2 hshld;Hotspot Shield Service;c:\program files\Hotspot Shield\bin\openvpnas.exe [2012-07-24 474992]
S2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe [2012-07-24 387440]
S2 TeamViewer8;TeamViewer 8;c:\program files\TeamViewer\Version8\TeamViewer_Service.exe [2012-12-14 3467768]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files\Common Files\VMware\USB\vmware-usbarbitrator.exe [2012-10-11 721048]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2013-02-14 79872]
S3 avchv;avchv Function Driver;c:\windows\system32\DRIVERS\avchv.sys [2012-04-21 240184]
S3 Ph3xIB32;Philips 713x Inbox PCI TV Card;c:\windows\system32\DRIVERS\Ph3xIB32.sys [2009-07-13 1311232]
S3 t_mouse.sys;HID-compliand device;c:\windows\system32\DRIVERS\t_mouse.sys [2012-12-19 5120]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2013-04-12 104720]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2013-04-12 115984]
.
.
Inhalt des "geplante Tasks" Ordners
.
2013-06-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-21 13:27]
.
2013-06-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3081888169-1950234315-1978571111-1000Core.job
- c:\users\Qadir\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-13 16:45]
.
2013-06-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3081888169-1950234315-1978571111-1000UA.job
- c:\users\Qadir\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-13 16:45]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://search.b1.org/?bsrc=hmior&chid=c167991
uInternet Settings,ProxyServer = socks=127.0.0.1:9050
uSearchAssistant = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=DE&userid=6e30a1f2-775c-4265-8dca-077440fcaee6&searchtype=ds&q={searchTerms}&installDate={installDate}
IE: An OneNote s&enden - c:\progra~1\MIF5BA~1\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MIF5BA~1\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Qadir\AppData\Roaming\Mozilla\Firefox\Profiles\7ytje0qm.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.arcor.de/
FF - prefs.js: network.proxy.http - 80.65.254.213
FF - prefs.js: network.proxy.http_port - 3128
FF - prefs.js: network.proxy.socks - 127.0.0.1
FF - prefs.js: network.proxy.socks_port - 9050
FF - prefs.js: network.proxy.type - 0
FF - user.js: extensions.shownSelectionUI - true
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
ShellIconOverlayIdentifiers-{152C96EB-288E-4EDC-B7C6-D21F8250ADF3} - (no file)
ShellIconOverlayIdentifiers-{342DAA0B-D796-460D-8566-901E08A1CCAD} - (no file)
ShellIconOverlayIdentifiers-{57595DAE-1AE1-4D97-A49E-67CBB53B52DF} - (no file)
ShellIconOverlayIdentifiers-{33816773-98AE-4723-ADE0-EBE54C8B5A67} - (no file)
MSConfigStartUp-Akamai NetSession Interface - c:\users\Qadir\AppData\Local\Akamai\netsession_win.exe
MSConfigStartUp-COMODO - c:\program files\COMODO\COMODO GeekBuddy\CLPSLA.exe
MSConfigStartUp-CPA - c:\program files\COMODO\COMODO GeekBuddy\VALA.exe
MSConfigStartUp-Facebook Update - c:\users\Qadir\AppData\Local\Facebook\Update\FacebookUpdate.exe
MSConfigStartUp-NokiaSuite - c:\program files\Nokia\Nokia Suite\NokiaSuite.exe
MSConfigStartUp-PlusService - c:\program files\Yuna Software\Messenger Plus!\PlusService.exe
MSConfigStartUp-snp2uvc - c:\windows\vsnp2uvc.exe
MSConfigStartUp-trustGTX14 - c:\program files\Trust\GXT14 Mouse\POINTERGHOST.exe
MSConfigStartUp-tsnp2uvc - c:\windows\tsnp2uvc.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\SetId\Internal]
@Denied: (A 2) (LocalSystem)
"DATA2"="<settings accountStatus=\"4\" oldDevice=\"\" timeDiff=\"1106312873\" expireTime=\"1309830893\" productStatus=\"1\" obSize=\"2\" InstallTS=\"1289332796\" isSubsc=\"0\" authStat_ts=\"0\" version=\"14.1\" keyType=\"194\" prodId=\"1\" moduleId1=\"7\" moduleId2=\"10\" relType=\"1\" />"
.
[HKEY_USERS\S-1-5-21-3081888169-1950234315-1978571111-1000\Software\SecuROM\License information*]
"datasecu"=hex:03,13,45,2a,0a,07,eb,48,13,22,ee,62,b3,7e,b9,57,49,1d,d1,b5,44,
8e,bb,3d,95,ae,a3,74,8d,2c,6f,98,b3,0d,29,62,6e,3f,33,09,29,e6,34,e2,fe,e1,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(564)
c:\users\Qadir\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\atieclxx.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\taskhost.exe
c:\program files\Hotspot Shield\HssWPR\hsssrv.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\conhost.exe
c:\windows\system32\vmnat.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\VMware\VMware Player\vmware-authd.exe
c:\windows\system32\vmnetdhcp.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\DllHost.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-06-16 18:51:23 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2013-06-16 16:51
.
Vor Suchlauf: 11 Verzeichnis(se), 111.566.303.232 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 111.684.112.384 Bytes frei
.
- - End Of File - - 6CC1E5166915BD6700E4936BD6302978 --- --- ---
A36C5E4F47E84449FF07ED3517B43A31
[/CODE]
Ich wollte heute mal meinen Firefox Suchanbieter ändern:
"about :config", "keyword.URL", dann waren zwei sachen zu sehen einmal "keyword.URL" und einmal "sweetim.toolbar.previous.keyword.URL"
Wie kann ich "sweetim.toolbar.previous.keyword.URL" entferen? |