kampfknödel | 31.07.2013 11:09 | bei dem downloadlink den du mir angegeben hast kam bei der installation folgende fehlermeldung:
"Fehler beim Überschreiben der Datei:
"C:\32788R22FWJFW\swxcacls.3XE"
Klichen Sie auf Abbrechen, um abzubrechen,
auf Wiederholen, um den Schreibvorgang erneut zu versuchen
oder auf Ignoriren um diese Datei zu überspringen"
deswegen hab ich die datei dann von der vom Programm anschließend angegeben original Seite gedownloaded und es hat geklappt! Code:
ComboFix 13-07-30.05 - Sebastian 31.07.2013 11:47:28.1.4 - x64
Microsoft Windows 8 6.2.9200.0.1252.49.1031.18.6086.4359 [GMT 2:00]
ausgeführt von:: c:\users\Sebastian\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\cryptsvc.dll . . . ist infiziert!!
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-06-28 bis 2013-07-31 ))))))))))))))))))))))))))))))
.
.
2013-07-31 09:42 . 2013-07-17 11:29 10458 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2013-07-30 15:02 . 2013-07-30 15:02 -------- d-----w- C:\FRST
2013-07-30 12:51 . 2013-07-30 12:51 137 ----a-w- c:\windows\DeleteOnReboot.bat
2013-07-30 11:17 . 2013-07-30 13:49 -------- d-----w- c:\programdata\eSafe
2013-07-30 10:02 . 2013-07-30 10:22 -------- d-----w- c:\program files (x86)\Firefly Studios
2013-07-30 10:00 . 2001-09-05 02:18 77824 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
2013-07-30 10:00 . 2001-09-05 02:18 225280 ------w- c:\program files (x86)\Common Files\InstallShield\IScript\iscript.dll
2013-07-30 10:00 . 2001-09-05 02:14 176128 ------w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
2013-07-30 10:00 . 2001-09-05 02:13 32768 ------w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2013-07-30 10:00 . 2001-09-05 03:24 610436 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe
2013-07-25 20:06 . 2013-07-25 20:06 289968 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10211.bin
2013-07-19 09:24 . 2013-07-19 09:24 -------- d-----w- c:\program files\WinRAR
2013-07-17 14:26 . 2013-07-17 14:26 -------- d-----w- c:\program files (x86)\TeamSpeak 3 Client
2013-07-15 22:10 . 2013-05-15 22:35 144384 ----a-w- c:\windows\system32\tssdisai.dll
2013-07-06 16:41 . 2013-07-07 03:09 -------- d-----r- c:\windows\BrowserChoice
2013-07-06 08:42 . 2013-07-14 13:03 78185248 ----a-w- c:\windows\system32\MRT.exe
2013-07-04 17:44 . 2013-07-04 17:44 -------- d-----w- c:\programdata\HP
2013-07-04 17:44 . 2010-05-14 13:04 253440 ----a-w- c:\windows\system32\Spool\prtprocs\x64\hpfpp02t.dll
2013-07-04 17:43 . 2010-05-14 13:04 138752 ----a-w- c:\windows\system32\hpf3l02t.dll
2013-07-03 18:06 . 2013-07-06 09:12 -------- d-----w- C:\Windows.old
2013-07-03 17:55 . 2013-07-06 09:02 -------- d-----w- C:\$SysReset
2013-07-03 10:02 . 2013-07-03 10:02 -------- d-----w- c:\program files (x86)\GUILD WARS
2013-07-03 10:00 . 2013-07-03 10:00 66872 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-07-03 09:59 . 2013-07-08 15:21 183112 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-07-03 09:23 . 2013-07-03 09:10 83672 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-07-03 09:23 . 2013-07-03 09:10 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-07-03 09:23 . 2013-07-03 09:10 130016 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-07-03 09:23 . 2013-07-03 09:10 100712 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-07-03 09:23 . 2013-07-03 09:23 -------- d-----w- c:\programdata\Avira
2013-07-03 09:23 . 2013-07-03 09:23 -------- d-----w- c:\program files (x86)\Avira
2013-07-03 09:04 . 2013-07-03 09:04 -------- d-----w- c:\programdata\Malwarebytes
2013-07-03 09:04 . 2013-07-03 09:04 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-07-03 09:04 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-07-03 09:03 . 2013-07-03 09:03 -------- d-----w- c:\program files (x86)\Auslogics
2013-07-03 08:49 . 2013-07-03 09:03 2829 ----a-w- c:\windows\War3Unin.pif
2013-07-03 08:49 . 2013-07-03 09:03 139264 ----a-w- c:\windows\War3Unin.exe
2013-07-03 08:48 . 2013-05-30 23:24 1257472 ----a-w- c:\windows\system32\kernel32.dll
2013-07-03 08:48 . 2013-05-23 23:01 1300992 ----a-w- c:\windows\system32\gdi32.dll
2013-07-03 08:48 . 2013-05-23 22:27 1022464 ----a-w- c:\windows\SysWow64\gdi32.dll
2013-07-03 08:48 . 2013-05-15 02:25 888320 ----a-w- c:\windows\system32\autochk.exe
2013-07-03 08:48 . 2013-05-15 02:24 793088 ----a-w- c:\windows\SysWow64\autochk.exe
2013-07-03 08:48 . 2013-05-15 02:24 482816 ----a-w- c:\windows\SysWow64\untfs.dll
2013-07-03 08:48 . 2013-05-15 02:25 542208 ----a-w- c:\windows\system32\untfs.dll
2013-07-03 08:46 . 2013-04-27 05:20 733184 ----a-w- c:\windows\system32\win32spl.dll
2013-07-03 08:45 . 2013-04-16 02:34 1455368 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-07-03 08:44 . 2013-03-15 00:17 861184 ----a-w- c:\windows\system32\drivers\http.sys
2013-07-03 08:42 . 2013-04-23 23:13 1013248 ----a-w- c:\windows\SysWow64\certutil.exe
2013-07-03 08:42 . 2013-04-23 23:12 1569792 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-07-03 08:42 . 2013-04-23 23:12 109056 ----a-w- c:\windows\SysWow64\cryptnet.dll
2013-07-03 08:42 . 2013-04-23 22:56 1255936 ----a-w- c:\windows\system32\certutil.exe
2013-07-03 08:42 . 2013-04-23 22:55 68096 ----a-w- c:\windows\system32\cryptsvc.dll
2013-07-03 08:42 . 2013-04-23 22:55 1889280 ----a-w- c:\windows\system32\crypt32.dll
2013-07-03 08:42 . 2013-04-23 22:55 141312 ----a-w- c:\windows\system32\cryptnet.dll
2013-07-03 08:42 . 2008-07-31 08:41 68616 ----a-w- c:\windows\SysWow64\XAPOFX1_1.dll
2013-07-03 08:42 . 2008-07-31 08:40 509448 ----a-w- c:\windows\SysWow64\XAudio2_2.dll
2013-07-03 08:42 . 2008-07-12 06:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll
2013-07-03 08:42 . 2008-07-12 06:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2013-07-03 08:42 . 2008-07-12 06:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll
2013-07-03 08:41 . 2013-02-02 05:41 1437184 ----a-w- c:\windows\SysWow64\GdiPlus.dll
2013-07-03 08:41 . 2013-02-02 05:31 1690624 ----a-w- c:\windows\system32\GdiPlus.dll
2013-07-03 08:38 . 2013-04-02 23:37 25088 ----a-w- c:\windows\SysWow64\cryptdlg.dll
2013-07-03 08:38 . 2013-04-02 23:12 30720 ----a-w- c:\windows\system32\cryptdlg.dll
2013-07-03 08:38 . 2013-02-12 00:17 20992 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-07-03 08:38 . 2013-03-22 03:49 2382336 ----a-w- c:\windows\SysWow64\esent.dll
2013-07-03 08:38 . 2013-03-21 22:47 2851840 ----a-w- c:\windows\system32\esent.dll
2013-07-03 08:35 . 2013-02-05 22:29 370688 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2013-07-03 08:35 . 2013-02-05 22:28 215552 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2013-07-03 08:35 . 2013-03-02 08:23 375808 ----a-w- c:\windows\SysWow64\ReAgent.dll
2013-07-03 08:35 . 2013-03-02 02:44 1011200 ----a-w- c:\windows\system32\reseteng.dll
2013-07-03 08:35 . 2013-03-06 06:31 222208 ----a-w- c:\windows\system32\shdocvw.dll
2013-07-03 08:35 . 2013-03-06 06:31 19758592 ----a-w- c:\windows\system32\shell32.dll
2013-07-03 08:35 . 2013-03-06 07:10 112872 ----a-w- c:\windows\system32\consent.exe
2013-07-03 08:35 . 2013-03-06 06:29 70144 ----a-w- c:\windows\system32\appinfo.dll
2013-07-03 08:33 . 2012-12-15 04:55 443392 ----a-w- c:\windows\system32\ReAgent.dll
2013-07-03 08:33 . 2012-12-04 04:21 368640 ----a-w- c:\windows\system32\sppwinob.dll
2013-07-03 08:31 . 2012-11-26 04:21 71168 ----a-w- c:\windows\SysWow64\ncryptsslp.dll
2013-07-03 08:31 . 2012-11-26 04:20 86016 ----a-w- c:\windows\system32\ncryptsslp.dll
2013-07-03 08:28 . 2013-07-30 14:14 -------- d-----w- c:\programdata\PMB Files
2013-07-03 08:27 . 2012-11-02 05:20 48640 ----a-w- c:\windows\system32\wups2.dll
2013-07-03 08:25 . 2012-10-24 03:25 13312 ----a-w- c:\windows\system32\pcalua.exe
2013-07-03 08:25 . 2012-10-24 03:24 405504 ----a-w- c:\windows\system32\pcasvc.dll
2013-07-03 08:25 . 2012-10-24 03:24 31232 ----a-w- c:\windows\system32\pcadm.dll
2013-07-03 08:25 . 2012-10-24 03:05 11776 ----a-w- c:\windows\system32\pcaevts.dll
2013-07-03 08:25 . 2012-10-24 04:54 396008 ----a-w- c:\windows\system32\hal.dll
2013-07-03 08:24 . 2012-10-17 04:32 673280 ----a-w- c:\windows\system32\mfmpeg2srcsnk.dll
2013-07-03 08:24 . 2012-10-17 03:57 568832 ----a-w- c:\windows\SysWow64\mfnetcore.dll
2013-07-03 08:24 . 2012-10-17 03:57 513024 ----a-w- c:\windows\SysWow64\mfmpeg2srcsnk.dll
2013-07-03 08:24 . 2012-10-17 04:32 1172992 ----a-w- c:\windows\system32\mfnetsrc.dll
2013-07-03 08:24 . 2012-10-17 04:32 677888 ----a-w- c:\windows\system32\mfnetcore.dll
2013-07-03 08:24 . 2012-10-17 03:57 929792 ----a-w- c:\windows\SysWow64\mfnetsrc.dll
2013-07-03 08:22 . 2012-11-10 04:23 148480 ----a-w- c:\windows\system32\poqexec.exe
2013-07-03 08:22 . 2012-11-10 04:23 132608 ----a-w- c:\windows\SysWow64\poqexec.exe
2013-07-03 08:22 . 2012-11-10 04:22 122880 ----a-w- c:\windows\system32\VmHostAI.dll
2013-07-03 08:22 . 2012-11-10 04:22 126976 ----a-w- c:\windows\system32\RDWebAI.dll
2013-07-03 08:22 . 2012-11-10 04:20 135680 ----a-w- c:\windows\system32\appserverai.dll
2013-07-03 08:20 . 2012-10-11 07:13 33512 ----a-w- c:\windows\system32\drivers\battc.sys
2013-07-03 08:18 . 2012-08-31 00:53 17888 ----a-w- c:\windows\SysWow64\msvcr100_clr0400.dll
2013-07-03 08:18 . 2012-08-31 00:52 17888 ----a-w- c:\windows\system32\msvcr100_clr0400.dll
2013-07-03 08:15 . 2012-10-12 06:14 36352 ----a-w- c:\windows\system32\rfxvmt.dll
2013-07-03 08:15 . 2012-10-12 06:13 109568 ----a-w- c:\windows\system32\dskquota.dll
2013-07-03 08:15 . 2012-10-12 05:39 82944 ----a-w- c:\windows\SysWow64\dskquota.dll
2013-07-03 08:15 . 2012-10-12 08:08 27880 ----a-w- c:\windows\system32\drivers\rdpvideominiport.sys
2013-07-03 08:15 . 2012-10-12 05:50 235520 ----a-w- c:\windows\system32\rdpudd.dll
2013-07-03 08:15 . 2012-11-01 04:41 1802240 ----a-w- c:\windows\SysWow64\msxml6.dll
2013-07-03 08:15 . 2012-11-01 04:41 1438720 ----a-w- c:\windows\SysWow64\msxml3.dll
2013-07-03 08:15 . 2012-11-01 04:40 2361344 ----a-w- c:\windows\system32\msxml6.dll
2013-07-03 08:15 . 2012-11-01 04:40 1836032 ----a-w- c:\windows\system32\msxml3.dll
2013-07-03 08:15 . 2012-11-01 04:21 2048 ----a-w- c:\windows\system32\msxml6r.dll
2013-07-03 08:15 . 2012-11-01 04:21 2048 ----a-w- c:\windows\system32\msxml3r.dll
2013-07-03 08:15 . 2012-11-01 04:20 2048 ----a-w- c:\windows\SysWow64\msxml6r.dll
2013-07-03 08:15 . 2012-11-01 04:20 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
2013-07-03 08:13 . 2012-09-20 06:33 420352 ----a-w- c:\windows\system32\WWAHost.exe
2013-07-03 08:11 . 2012-12-16 08:20 35328 ----a-w- c:\windows\SysWow64\atmlib.dll
2013-07-03 08:11 . 2012-12-16 07:57 300032 ----a-w- c:\windows\SysWow64\atmfd.dll
2013-07-03 08:11 . 2012-11-08 04:01 3072 ----a-w- c:\windows\SysWow64\lpk.dll
2013-07-03 08:11 . 2012-12-16 08:28 46080 ----a-w- c:\windows\system32\atmlib.dll
2013-07-03 08:11 . 2012-12-16 08:08 362496 ----a-w- c:\windows\system32\atmfd.dll
2013-07-03 08:11 . 2012-11-08 04:24 75776 ----a-w- c:\windows\SysWow64\fontsub.dll
2013-07-03 08:11 . 2012-11-08 04:24 10752 ----a-w- c:\windows\SysWow64\dciman32.dll
2013-07-03 08:11 . 2012-11-08 04:20 96256 ----a-w- c:\windows\system32\fontsub.dll
2013-07-03 08:11 . 2012-11-08 04:20 14336 ----a-w- c:\windows\system32\dciman32.dll
2013-07-03 08:11 . 2012-11-08 04:02 3072 ----a-w- c:\windows\system32\lpk.dll
2013-07-03 08:11 . 2013-07-03 08:11 -------- d-----w- c:\program files\Preload
2013-07-03 08:11 . 2013-07-03 08:11 -------- d-----w- c:\program files\Accessory Store
2013-07-03 08:08 . 2012-10-10 07:04 94208 ----a-w- c:\windows\system32\synceng.dll
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-18 08:37 . 2012-07-26 08:13 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-06-27 22:04 . 2012-07-26 08:14 78200 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-27 22:04 . 2012-07-26 08:14 693112 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-03 19603048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2012-08-15 2994880]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-07-03 345144]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"IsMyWinLockerReboot"="msiexec.exe" [2012-07-26 62976]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~2\NVIDIA~1\3DVISI~1\nvStInit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 EgisTec Ticket Service;EgisTec Ticket Service;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [x]
R4 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 ccSet_NARA;NARA Settings Manager;c:\windows\system32\drivers\NARAx64\0401000.00E\ccSetx64.sys;c:\windows\SYSNATIVE\drivers\NARAx64\0401000.00E\ccSetx64.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x]
S2 CCDMonitorService;CCDMonitorService;c:\program files (x86)\Acer\Acer Cloud\CCDMonitorService.exe;c:\program files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [x]
S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 ePowerSvc;ePower Service;c:\program files\Acer\Acer Power Management\ePowerSvc.exe;c:\program files\Acer\Acer Power Management\ePowerSvc.exe [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2013-07-30 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-03 07:19]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-07-02 12921488]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\progra~2\NVIDIA~1\3DVISI~1\nvStInit64.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\as7wtusk.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - ExtSQL: 2013-07-03 10:49; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\as7wtusk.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-07-03 10:58; antigameorigin@antigame.de; c:\users\Sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\as7wtusk.default\extensions\antigameorigin@antigame.de.xpi
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{41564952-412D-5637-00A7-7A786E7484D7} - c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll
Toolbar-Locked - (no file)
Toolbar-{41564952-412D-5637-00A7-7A786E7484D7} - c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll
Toolbar-Locked - (no file)
WebBrowser-{41564952-412D-5637-00A7-7A786E7484D7} - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3541986494-3416644221-1888541715-1002CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:62,e2,b7,a0,19,c4,4e,93,18,3c,f6,e2,de,36,c1,42,6e,f1,b3,1f,01,
9b,d2,b7,dc,1e,3e,ce,12,f5,39,0d,c4,46,e8,42,9c,2d,a7,f9,ad,d7,37,2f,8f,0a,\
"rkeysecu"=hex:46,87,87,f2,60,38,b8,d2,a6,f3,24,f4,47,38,1a,ff
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B9A09F18-45AB-4F09-A117-A4ADDA8FA8C8}]
@Denied: (A) (Everyone)
"Solution"="{36eb6792-3a29-43b3-8cd0-f67d266fb426}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane\0]
"Key"="ActionsPane"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\8.0\\ActionsPane.xsd"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
Zeit der Fertigstellung: 2013-07-31 11:54:45
ComboFix-quarantined-files.txt 2013-07-31 09:54
.
Vor Suchlauf: 11 Verzeichnis(se), 397.434.929.152 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 397.596.078.080 Bytes frei
.
- - End Of File - - 4045E5DFE20CBC757B273FCF1078F5FD
D41D8CD98F00B204E9800998ECF8427E 2 Sachen noch:
1. hatte ich während der Installation von Combfix zugriffe auf die Registry die mir avira gemeldet hat obwohl ich es eigentlich deaktiviert hatte
2. Ich habe win8 und jetzt funktioniert der "Ausschaltknopf" nichtmehr. Wenn ich unten in der Taskleiste auf das Symbol drücke kommt folgende Fehlermeldung:
"C:\Programm Files\Acer\Acer Power Managment\ePowerButton.exe
Ein an das System angeschlossenes Gerät funktioniert nicht."
Ausschalten durch längeres gedrückthalten des An-/Ausknopfes war erfolgreich und der Computer lies sich hinterher ohne Probleme wieder hochfahren! |