Microwave | 29.08.2013 11:56 | Danke für die postwendende Antwort!
Leider hängt Combofix gerade bei Stufe_50 herum. Was tun?
Kann ich es bedenkenlos noch einmal neustarten?
Übrigens nur kein "Stress", gewisse Hooks sind auch von mir selber, z.B. alle die, die im Gmer-Log im sauberen 5er-Pack auftreten, und die 5 oberen Hooks in den Hookshark64-Bildern - bitte sagen, wenn ich den Kram deaktivieren soll.
Es scheinen ja doch einige von meinen (früheren) Experiment"chen" bemängelt zu werden.
Aber es gibt halt auch noch unklare Hooks, und eine Routine-Überprüfung ist sicher nie falsch.
Die ADS sind auch meine, hab da mal vor Monaten etwas rumprobiert und bekomm sie jetzt nicht mehr gelöscht.
Grüße - Microwave
EDIT: Combofix hat sich doch gefangen. Code:
ComboFix 13-08-29.01 - Microwave 29.08.2013 12:03:54.2.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.41.1031.18.4085.2035 [GMT 2:00]
ausgeführt von:: c:\users\Microwave\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\cryptsvc.dll . . . fehlt!!
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-07-28 bis 2013-08-29 ))))))))))))))))))))))))))))))
.
.
2013-08-29 10:53 . 2013-08-29 10:53 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2013-08-29 10:53 . 2013-08-29 10:53 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-08-29 10:53 . 2013-08-29 10:53 -------- d-----w- c:\users\Gast\AppData\Local\temp
2013-08-28 21:19 . 2013-08-06 08:58 9515512 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E015AC9C-DA27-4804-AB26-9D18B9201D85}\mpengine.dll
2013-08-28 18:32 . 2013-02-20 21:47 149400 ----a-w- c:\windows\system32\symsrv.dll
2013-08-28 18:15 . 2013-08-28 18:17 -------- d-----w- c:\windows\system32\badfiles
2013-08-28 17:03 . 2013-08-28 17:03 12872 ----a-w- c:\windows\system32\bootdelete.exe
2013-08-28 11:53 . 2013-08-28 11:53 6776 ----a-w- c:\windows\system32\R00tk!tLKM1.sys
2013-08-28 11:53 . 2013-08-28 11:53 264704 ----a-w- c:\windows\system32\R00tk!t64.dll
2013-08-28 11:53 . 2013-08-28 11:53 244736 ----a-w- c:\windows\SysWow64\R00tk!t86.dll
2013-08-28 09:53 . 2013-08-06 08:58 9515512 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-08-28 09:41 . 2013-08-29 10:53 -------- d-----w- c:\users\Microwave\AppData\Local\temp
2013-08-28 08:13 . 2013-08-28 08:13 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-08-28 08:13 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-08-27 11:52 . 2013-08-27 11:52 -------- d-----w- c:\windows\allWindows
2013-08-26 21:15 . 2013-08-26 21:15 -------- d-----w- C:\SymCache
2013-08-23 11:00 . 2013-08-23 10:59 941720 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3CC3FF74-22F5-4C94-AF8B-71C00534A32D}\gapaengine.dll
2013-08-20 05:02 . 2013-08-20 05:02 204568 ----a-w- c:\windows\system32\drivers\ssudmdm.sys
2013-08-20 05:02 . 2013-08-20 05:02 103576 ----a-w- c:\windows\system32\drivers\ssudbus.sys
2013-08-19 12:22 . 2013-08-19 19:53 -------- d-----w- c:\program files (x86)\KVIrc
2013-08-16 09:12 . 2013-08-16 19:15 -------- d-----w- c:\program files (x86)\scilor
2013-08-15 04:18 . 2013-07-09 05:46 1472512 ----a-w- c:\windows\system32\crypt32.dll
2013-08-15 04:17 . 2013-07-09 04:52 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2013-08-15 04:17 . 2013-07-09 02:49 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2013-08-15 04:17 . 2013-07-09 02:49 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2013-08-15 04:17 . 2013-07-09 02:49 2048 ----a-w- c:\windows\SysWow64\user.exe
2013-08-15 04:17 . 2013-07-06 06:03 1910208 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-07-31 06:43 . 2013-07-31 06:43 -------- d-----w- C:\NvidiaLogging
2013-07-31 06:42 . 2013-05-14 19:28 39712 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2013-07-31 06:42 . 2013-05-14 19:27 29984 ----a-w- c:\windows\system32\nvaudcap64v.dll
2013-07-31 06:42 . 2013-05-14 19:27 28448 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-22 23:28 . 2012-04-08 20:07 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-08-22 23:28 . 2012-02-18 23:55 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-08-21 19:44 . 2012-12-02 15:53 17288 ----a-w- c:\windows\system32\drivers\Dbgv.sys
2013-08-16 01:01 . 2012-02-18 20:12 78161360 ----a-w- c:\windows\system32\MRT.exe
2013-07-17 10:05 . 2012-07-03 16:50 941720 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-07-09 04:45 . 2013-08-15 04:18 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-07-04 20:34 . 2013-07-04 20:34 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-07-04 20:34 . 2013-07-04 20:34 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-07-04 20:34 . 2013-07-04 20:34 226304 ----a-w- c:\windows\system32\elshyph.dll
2013-07-04 20:34 . 2013-07-04 20:34 185344 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-07-04 20:34 . 2013-07-04 20:34 158720 ----a-w- c:\windows\SysWow64\msls31.dll
2013-07-04 20:34 . 2013-07-04 20:34 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-07-04 20:34 . 2013-07-04 20:34 138752 ----a-w- c:\windows\SysWow64\wextract.exe
2013-07-04 20:34 . 2013-07-04 20:34 523264 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-07-04 20:34 . 2013-07-04 20:34 38400 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-07-04 20:34 . 2013-07-04 20:34 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-07-04 20:34 . 2013-07-04 20:34 12800 ----a-w- c:\windows\SysWow64\mshta.exe
2013-07-04 20:34 . 2013-07-04 20:34 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-07-04 20:34 . 2013-07-04 20:34 61952 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-07-04 20:34 . 2013-07-04 20:34 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-07-04 20:34 . 2013-07-04 20:34 361984 ----a-w- c:\windows\SysWow64\html.iec
2013-07-04 20:34 . 2013-07-04 20:34 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-07-04 20:34 . 2013-07-04 20:34 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-07-04 20:34 . 2013-07-04 20:34 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-07-04 20:34 . 2013-07-04 20:34 216064 ----a-w- c:\windows\system32\msls31.dll
2013-07-04 20:34 . 2013-07-04 20:34 197120 ----a-w- c:\windows\system32\msrating.dll
2013-07-04 20:34 . 2013-07-04 20:34 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-07-04 20:34 . 2013-07-04 20:34 81408 ----a-w- c:\windows\system32\icardie.dll
2013-07-04 20:34 . 2013-07-04 20:34 762368 ----a-w- c:\windows\system32\ieapfltr.dll
2013-07-04 20:34 . 2013-07-04 20:34 452096 ----a-w- c:\windows\system32\dxtmsft.dll
2013-07-04 20:34 . 2013-07-04 20:34 441856 ----a-w- c:\windows\system32\html.iec
2013-07-04 20:34 . 2013-07-04 20:34 281600 ----a-w- c:\windows\system32\dxtrans.dll
2013-07-04 20:34 . 2013-07-04 20:34 270848 ----a-w- c:\windows\system32\iedkcs32.dll
2013-07-04 20:34 . 2013-07-04 20:34 235008 ----a-w- c:\windows\system32\url.dll
2013-07-04 20:34 . 2013-07-04 20:34 1400416 ----a-w- c:\windows\system32\ieapfltr.dat
2013-07-04 20:34 . 2013-07-04 20:34 97280 ----a-w- c:\windows\system32\mshtmled.dll
2013-07-04 20:34 . 2013-07-04 20:34 599552 ----a-w- c:\windows\system32\vbscript.dll
2013-07-04 20:34 . 2013-07-04 20:34 27648 ----a-w- c:\windows\system32\licmgr10.dll
2013-07-04 20:34 . 2013-07-04 20:34 247296 ----a-w- c:\windows\system32\webcheck.dll
2013-07-04 20:34 . 2013-07-04 20:34 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-07-04 20:34 . 2013-07-04 20:34 1509376 ----a-w- c:\windows\system32\inetcpl.cpl
2013-07-04 20:34 . 2013-07-04 20:34 144896 ----a-w- c:\windows\system32\wextract.exe
2013-07-04 20:34 . 2013-07-04 20:34 102912 ----a-w- c:\windows\system32\inseng.dll
2013-07-04 20:34 . 2013-07-04 20:34 173568 ----a-w- c:\windows\system32\ieUnatt.exe
2013-07-04 20:34 . 2013-07-04 20:34 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-07-04 20:34 . 2013-07-04 20:34 62976 ----a-w- c:\windows\system32\pngfilt.dll
2013-07-04 20:34 . 2013-07-04 20:34 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-07-04 20:34 . 2013-07-04 20:34 51200 ----a-w- c:\windows\system32\imgutil.dll
2013-07-04 20:34 . 2013-07-04 20:34 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-07-04 20:34 . 2013-07-04 20:34 149504 ----a-w- c:\windows\system32\occache.dll
2013-07-04 20:34 . 2013-07-04 20:34 13824 ----a-w- c:\windows\system32\mshta.exe
2013-07-04 20:34 . 2013-07-04 20:34 136192 ----a-w- c:\windows\system32\iepeers.dll
2013-07-04 20:34 . 2013-07-04 20:34 135680 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-07-04 20:34 . 2013-07-04 20:34 12800 ----a-w- c:\windows\system32\msfeedssync.exe
2013-07-04 20:34 . 2013-07-04 20:34 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-06-21 12:06 . 2013-07-01 18:56 61216 ----a-w- c:\windows\system32\OpenCL.dll
2013-06-21 12:06 . 2013-07-01 18:56 53024 ----a-w- c:\windows\SysWow64\OpenCL.dll
2013-06-21 12:06 . 2013-07-01 18:55 9239344 ----a-w- c:\windows\system32\nvcuda.dll
2013-06-21 12:06 . 2013-07-01 18:55 7687592 ----a-w- c:\windows\SysWow64\nvcuda.dll
2013-06-21 12:06 . 2013-07-01 18:55 7641832 ----a-w- c:\windows\system32\nvopencl.dll
2013-06-21 12:06 . 2013-07-01 18:55 6324360 ----a-w- c:\windows\SysWow64\nvopencl.dll
2013-06-21 12:06 . 2013-07-01 18:55 572704 ----a-w- c:\windows\system32\NvFBC64.dll
2013-06-21 12:06 . 2013-07-01 18:55 570656 ----a-w- c:\windows\system32\NvIFR64.dll
2013-06-21 12:06 . 2013-07-01 18:55 467232 ----a-w- c:\windows\SysWow64\NvIFR.dll
2013-06-21 12:06 . 2013-07-01 18:55 465184 ----a-w- c:\windows\SysWow64\NvFBC.dll
2013-06-21 12:06 . 2013-07-01 18:55 2953504 ----a-w- c:\windows\system32\nvcuvid.dll
2013-06-21 12:06 . 2013-07-01 18:55 27781920 ----a-w- c:\windows\system32\nvoglv64.dll
2013-06-21 12:06 . 2013-07-01 18:55 2777888 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2013-06-21 12:06 . 2013-07-01 18:55 2363680 ----a-w- c:\windows\system32\nvcuvenc.dll
2013-06-21 12:06 . 2013-07-01 18:55 21102368 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2013-06-21 12:06 . 2013-07-01 18:55 2002720 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2013-06-21 12:06 . 2013-07-01 18:55 1832224 ----a-w- c:\windows\system32\nvdispco6432049.dll
2013-06-21 12:06 . 2013-07-01 18:55 15920536 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-06-21 12:06 . 2013-07-01 18:55 15144928 ----a-w- c:\windows\system32\nvd3dumx.dll
2013-06-21 12:06 . 2013-07-01 18:55 1511712 ----a-w- c:\windows\system32\nvdispgenco6432049.dll
2013-06-21 12:06 . 2013-07-01 18:55 13411896 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2013-06-21 12:06 . 2013-07-01 18:55 12427240 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-06-21 12:06 . 2013-07-01 18:55 11235104 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2013-06-21 12:06 . 2013-07-01 18:55 2936208 ----a-w- c:\windows\system32\nvapi64.dll
2013-06-21 12:06 . 2013-07-01 18:55 2597856 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-06-21 12:06 . 2013-07-01 18:55 25256224 ----a-w- c:\windows\system32\nvcompiler.dll
2013-06-21 12:06 . 2013-07-01 18:55 17560352 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2013-06-21 10:23 . 2013-07-01 18:57 6496544 ----a-w- c:\windows\system32\nvcpl.dll
2013-06-21 10:23 . 2013-07-01 18:57 3514656 ----a-w- c:\windows\system32\nvsvc64.dll
2013-06-21 10:23 . 2013-07-01 18:57 884512 ----a-w- c:\windows\system32\nvvsvc.exe
2013-06-21 10:23 . 2013-07-01 18:57 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-06-21 10:23 . 2013-07-01 18:57 2555680 ----a-w- c:\windows\system32\nvsvcr.dll
2013-06-21 10:23 . 2013-07-01 18:57 237856 ----a-w- c:\windows\system32\nvmctray.dll
2013-06-21 03:16 . 2013-06-21 03:16 566048 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2013-06-18 19:50 . 2013-06-18 19:50 247216 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2013-06-18 19:50 . 2011-04-27 14:25 139616 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2013-06-05 03:34 . 2013-07-10 09:58 3153920 ----a-w- c:\windows\system32\win32k.sys
2013-06-04 06:00 . 2013-07-10 09:59 624128 ----a-w- c:\windows\system32\qedit.dll
2013-06-04 04:53 . 2013-07-10 09:59 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2006-05-03 10:06 163328 --sha-r- c:\windows\SysWOW64\flvDX.dll
2007-02-21 11:47 31232 --sha-r- c:\windows\SysWOW64\msfDX.dll
2010-01-06 22:00 107520 --sha-r- c:\windows\SysWOW64\TAKDSDecoder.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
Kryptografiedienst Fehler !!
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-21 19875432]
"FreeAC"="c:\program files (x86)\FreeAlarmClock\FreeAlarmClock.exe" [2012-04-25 1328976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HControlUser"="c:\program files (x86)\ASUS\ATK Hotkey\HControlUser.exe" [2009-04-02 98304]
"ATKOSD2"="c:\program files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" [2009-07-07 8493624]
"VolPanel"="c:\program files (x86)\Creative\SB Audigy\Volume Panel\VolPanlu.exe" [2008-12-29 237693]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"IJNetworkScannerSelectorEX"="c:\program files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe" [2011-01-15 452016]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{60D6618B-153F-4353-8185-908E676E5888}\_DCE9A4DB2A5F2786140FA3.exe -d [2012-2-18 12862]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"RequireSignedAppInit_DLLs"=0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\prwntdrv]
@=""
.
R3 AstFsFlt;AstFsFlt;c:\windows\system32\DRIVERS\eu3OmF9A.sys;c:\windows\SYSNATIVE\DRIVERS\eu3OmF9A.sys [x]
R4 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed - Virtueller Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x]
R4 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protokoll;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x]
R4 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x]
R4 ASUSProcObsrv;ASUS Process Creation/Termination Observer;g:\i386\AsPrOb64.sys;g:\i386\AsPrOb64.sys [x]
R4 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x]
R4 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys;c:\program files\ATKGFNEX\ASMMAP64.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - uwdiapog
.
Inhalt des "geplante Tasks" Ordners
.
2013-08-29 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-08 23:28]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-06-20 1356240]
"IntelPROSet"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2013-02-08 4791024]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-07-27 1028896]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = https://accounts.google.com/ServiceLogin?service=mail&passive=true&rm=false&continue=hxxp://mail.google.com/mail/&scc=1<mpl=default<mplcache=2
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = 216.49.160.27:80
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.178.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} -
FF - ProfilePath - c:\users\Microwave\AppData\Roaming\Mozilla\Firefox\Profiles\kmfhmlgi.default\
.
.
------- Dateityp-Verknüpfung -------
.
vbefile\shell\open2\command="%SystemRoot%\System32\CScript.exe" "%1" %*
vbsfile\shell\open2\command="%SystemRoot%\System32\CScript.exe" "%1" %*
jsefile\shell\open2\command=c:\windows\System32\CScript.exe "%1" %*
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files (x86)\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll
Toolbar-Locked - (no file)
Toolbar-{95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files (x86)\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll
SafeBoot-51160022.sys
ShellIconOverlayIdentifiers- - (no file)
ShellIconOverlayIdentifiers- - (no file)
ShellIconOverlayIdentifiers- - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\fsflt]
"ImagePath"="\??\c:\windows\System32\drivers:fsflt.sys"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93,
aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:d2,21,5b,54,c2,fb,cc,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,52,af,b6,5e,b0,d1,2a,4d,8e,1d,f3,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,52,af,b6,5e,b0,d1,2a,4d,8e,1d,f3,\
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-2703395309-1160498691-1679700947-1000\Software\SecuROM\License information*]
"datasecu"=hex:4a,50,65,1d,50,dd,96,ad,3d,88,02,8d,be,bf,bc,c6,08,2f,fc,22,f4,
76,da,f6,74,b5,57,f1,e0,49,d0,fc,5c,03,4d,23,95,55,c5,ed,60,a3,bd,81,1d,24,\
"rkeysecu"=hex:66,a6,dc,4b,f6,7d,02,12,38,37,98,4a,e1,82,1c,c8
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}]
@Denied: (A 2) (Everyone)
@="FlashProp Class"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-08-29 12:56:47
ComboFix-quarantined-files.txt 2013-08-29 10:56
.
Vor Suchlauf: 31 Verzeichnis(se), 26'479'824'896 Bytes frei
Nach Suchlauf: 32 Verzeichnis(se), 26'354'675'712 Bytes frei
.
- - End Of File - - 63432C3DE31860BF812C2F79F1166972
A36C5E4F47E84449FF07ED3517B43A31 |