Mutzemaus | 12.09.2013 15:46 | So, hier gehts nun weiter: Code:
ComboFix 13-09-10.03 - Nicole 12.09.2013 14:33:14.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3957.2359 [GMT 2:00]
ausgeführt von:: c:\users\Nicole\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
FW: COMODO Firewall *Disabled* {8F7746F7-FE68-E084-3B6C-7404A51E8FB3}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: COMODO Antivirus *Disabled/Outdated* {0C2D2636-923D-EE52-2A83-E643204A8275}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Vorheriger Suchlauf -------
.
C:\firefox.exe
C:\nspr4.dll
C:\nss3.dll
C:\plc4.dll
C:\plds4.dll
c:\program files (x86)\Windows Live\Messenger\msacm32.dll
C:\readme.txt
C:\softokn3.dll
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-08-12 bis 2013-09-12 ))))))))))))))))))))))))))))))
.
.
2013-09-12 12:43 . 2013-09-12 12:43 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-09-11 19:05 . 2013-08-10 05:22 1365504 ----a-w- c:\windows\system32\urlmon.dll
2013-09-11 08:36 . 2013-08-05 02:25 155584 ----a-w- c:\windows\system32\drivers\ataport.sys
2013-09-10 18:30 . 2013-09-10 18:30 -------- d-----w- c:\programdata\EA Core
2013-09-10 18:29 . 2013-09-10 18:29 -------- d-----w- c:\users\Nicole\AppData\Roaming\Origin
2013-09-10 18:29 . 2013-09-10 18:29 -------- d-----w- c:\users\Nicole\AppData\Local\Origin
2013-09-10 18:28 . 2013-09-10 18:29 -------- d-----w- c:\programdata\Origin
2013-09-10 07:35 . 2013-08-06 08:58 9515512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{54D140BF-FB5F-4368-9ACB-E445B91616C6}\mpengine.dll
2013-09-08 12:22 . 2013-09-08 12:22 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-09-08 12:22 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-09-07 22:59 . 2013-09-07 22:59 -------- d-----w- c:\users\Nicole\AppData\Roaming\LavasoftStatistics
2013-09-07 22:59 . 2013-09-07 22:59 -------- d-----w- c:\programdata\Ad-Aware Antivirus
2013-09-07 22:54 . 2013-09-08 12:20 -------- d-----w- c:\program files (x86)\Ad-Aware Antivirus
2013-09-07 22:54 . 2013-09-07 22:54 -------- d-----w- c:\programdata\Lavasoft
2013-09-07 22:54 . 2013-09-07 22:54 -------- d-----w- c:\programdata\Downloaded Installations
2013-09-07 22:54 . 2013-09-08 12:17 -------- d-----w- c:\program files (x86)\Lavasoft
2013-09-07 22:52 . 2013-09-07 22:52 14456 ----a-w- c:\windows\system32\drivers\gfibto.sys
2013-09-07 22:52 . 2013-09-07 23:29 -------- d-----w- c:\users\Nicole\AppData\Roaming\Ad-Aware Antivirus
2013-09-07 21:49 . 2013-09-08 12:10 -------- d-----w- c:\program files (x86)\Hosts_Anti_Adwares_PUPs
2013-09-06 16:32 . 2013-09-07 21:48 -------- d-----w- C:\AdwCleaner
2013-09-05 20:35 . 2013-09-05 20:35 -------- d-----w- c:\program files (x86)\Origin
2013-08-20 18:17 . 2013-08-20 18:17 -------- d-----w- c:\program files (x86)\Common Files\COMODO
2013-08-18 14:37 . 2013-08-18 14:39 -------- d-s---w- c:\programdata\Shared Space
2013-08-18 14:33 . 2013-08-18 14:33 -------- d-----w- c:\windows\SysWow64\Extensions
2013-08-18 14:33 . 2013-08-18 14:33 -------- d-----w- c:\windows\SysWow64\searchplugins
2013-08-18 14:33 . 2013-08-18 14:33 -------- d-----w- c:\users\Nicole\AppData\Roaming\SeeSimilar
2013-08-18 14:33 . 2013-08-18 17:40 -------- d-----w- c:\program files (x86)\SeeSimilar
2013-08-18 14:32 . 2013-08-18 14:35 57096 ----a-w- c:\windows\system32\certsentry.dll
2013-08-18 14:32 . 2013-08-18 14:35 48392 ----a-w- c:\windows\SysWow64\certsentry.dll
2013-08-18 07:40 . 2013-08-18 07:40 -------- d-----w- c:\users\Nicole\AppData\Roaming\Malwarebytes
2013-08-18 07:40 . 2013-08-18 07:40 -------- d-----w- c:\programdata\Malwarebytes
2013-08-18 07:36 . 2013-08-18 07:36 -------- d-----w- c:\users\Nicole\AppData\Local\Programs
2013-08-17 17:42 . 2013-08-17 17:42 -------- d-----w- C:\FRST
2013-08-17 12:49 . 2013-08-17 12:49 -------- d-----w- c:\program files\COMODO
2013-08-17 12:32 . 2013-08-17 12:32 -------- d-----w- C:\TDSSKiller_Quarantine
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-11 19:03 . 2013-06-18 16:30 79143768 ----a-w- c:\windows\system32\MRT.exe
2013-09-10 17:50 . 2013-06-17 20:51 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-10 17:50 . 2013-06-17 20:51 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-09-03 09:18 . 2013-06-18 17:03 81112 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-09-03 09:18 . 2013-06-18 17:01 132088 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-09-03 09:18 . 2013-06-18 17:01 105344 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-08-02 01:48 . 2013-09-11 08:36 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-07-08 19:59 . 2013-07-08 19:59 708632 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2013-06-21 21:53 . 2013-06-21 21:53 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-06-21 21:53 . 2013-06-21 21:53 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-06-21 21:53 . 2013-06-21 21:53 523264 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-06-21 21:53 . 2013-06-21 21:53 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-06-21 21:53 . 2013-06-21 21:53 38400 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-06-21 21:53 . 2013-06-21 21:53 226304 ----a-w- c:\windows\system32\elshyph.dll
2013-06-21 21:53 . 2013-06-21 21:53 185344 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-06-21 21:53 . 2013-06-21 21:53 158720 ----a-w- c:\windows\SysWow64\msls31.dll
2013-06-21 21:53 . 2013-06-21 21:53 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-06-21 21:53 . 2013-06-21 21:53 138752 ----a-w- c:\windows\SysWow64\wextract.exe
2013-06-21 21:53 . 2013-06-21 21:53 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-06-21 21:53 . 2013-06-21 21:53 12800 ----a-w- c:\windows\SysWow64\mshta.exe
2013-06-21 21:53 . 2013-06-21 21:53 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-06-21 21:53 . 2013-06-21 21:53 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-06-21 21:53 . 2013-06-21 21:53 97280 ----a-w- c:\windows\system32\mshtmled.dll
2013-06-21 21:53 . 2013-06-21 21:53 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-06-21 21:53 . 2013-06-21 21:53 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-06-21 21:53 . 2013-06-21 21:53 81408 ----a-w- c:\windows\system32\icardie.dll
2013-06-21 21:53 . 2013-06-21 21:53 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-06-21 21:53 . 2013-06-21 21:53 762368 ----a-w- c:\windows\system32\ieapfltr.dll
2013-06-21 21:53 . 2013-06-21 21:53 62976 ----a-w- c:\windows\system32\pngfilt.dll
2013-06-21 21:53 . 2013-06-21 21:53 61952 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-06-21 21:53 . 2013-06-21 21:53 599552 ----a-w- c:\windows\system32\vbscript.dll
2013-06-21 21:53 . 2013-06-21 21:53 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-06-21 21:53 . 2013-06-21 21:53 51200 ----a-w- c:\windows\system32\imgutil.dll
2013-06-21 21:53 . 2013-06-21 21:53 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-06-21 21:53 . 2013-06-21 21:53 452096 ----a-w- c:\windows\system32\dxtmsft.dll
2013-06-21 21:53 . 2013-06-21 21:53 441856 ----a-w- c:\windows\system32\html.iec
2013-06-21 21:53 . 2013-06-21 21:53 361984 ----a-w- c:\windows\SysWow64\html.iec
2013-06-21 21:53 . 2013-06-21 21:53 281600 ----a-w- c:\windows\system32\dxtrans.dll
2013-06-21 21:53 . 2013-06-21 21:53 27648 ----a-w- c:\windows\system32\licmgr10.dll
2013-06-21 21:53 . 2013-06-21 21:53 270848 ----a-w- c:\windows\system32\iedkcs32.dll
2013-06-21 21:53 . 2013-06-21 21:53 247296 ----a-w- c:\windows\system32\webcheck.dll
2013-06-21 21:53 . 2013-06-21 21:53 235008 ----a-w- c:\windows\system32\url.dll
2013-06-21 21:53 . 2013-06-21 21:53 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-06-21 21:53 . 2013-06-21 21:53 216064 ----a-w- c:\windows\system32\msls31.dll
2013-06-21 21:53 . 2013-06-21 21:53 197120 ----a-w- c:\windows\system32\msrating.dll
2013-06-21 21:53 . 2013-06-21 21:53 173568 ----a-w- c:\windows\system32\ieUnatt.exe
2013-06-21 21:53 . 2013-06-21 21:53 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-06-21 21:53 . 2013-06-21 21:53 1509376 ----a-w- c:\windows\system32\inetcpl.cpl
2013-06-21 21:53 . 2013-06-21 21:53 149504 ----a-w- c:\windows\system32\occache.dll
2013-06-21 21:53 . 2013-06-21 21:53 144896 ----a-w- c:\windows\system32\wextract.exe
2013-06-21 21:53 . 2013-06-21 21:53 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-06-21 21:53 . 2013-06-21 21:53 1400416 ----a-w- c:\windows\system32\ieapfltr.dat
2013-06-21 21:53 . 2013-06-21 21:53 13824 ----a-w- c:\windows\system32\mshta.exe
2013-06-21 21:53 . 2013-06-21 21:53 136192 ----a-w- c:\windows\system32\iepeers.dll
2013-06-21 21:53 . 2013-06-21 21:53 135680 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-06-21 21:53 . 2013-06-21 21:53 12800 ----a-w- c:\windows\system32\msfeedssync.exe
2013-06-21 21:53 . 2013-06-21 21:53 102912 ----a-w- c:\windows\system32\inseng.dll
2013-06-21 21:52 . 2013-06-21 21:52 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-06-21 21:52 . 2013-06-21 21:52 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-06-21 21:52 . 2013-06-21 21:52 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2013-06-21 21:52 . 2013-06-21 21:52 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2013-06-21 21:52 . 2013-06-21 21:52 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-06-21 21:52 . 2013-06-21 21:52 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-06-21 21:52 . 2013-06-21 21:52 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-06-21 21:52 . 2013-06-21 21:52 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-06-21 21:52 . 2013-06-21 21:52 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2013-06-21 21:52 . 2013-06-21 21:52 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2013-06-21 21:52 . 2013-06-21 21:52 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-06-21 21:52 . 2013-06-21 21:52 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-06-21 21:52 . 2013-06-21 21:52 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-06-21 21:52 . 2013-06-21 21:52 3928064 ----a-w- c:\windows\system32\d2d1.dll
2013-06-21 21:52 . 2013-06-21 21:52 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2013-06-21 21:52 . 2013-06-21 21:52 363008 ----a-w- c:\windows\system32\dxgi.dll
2013-06-21 21:52 . 2013-06-21 21:52 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-06-21 21:52 . 2013-06-21 21:52 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-06-21 21:52 . 2013-06-21 21:52 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2013-06-21 21:52 . 2013-06-21 21:52 333312 ----a-w- c:\windows\system32\d3d10_1core.dll
2013-06-21 21:52 . 2013-06-21 21:52 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-06-21 21:52 . 2013-06-21 21:52 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-06-21 21:52 . 2013-06-21 21:52 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-06-21 21:52 . 2013-06-21 21:52 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-06-21 21:52 . 2013-06-21 21:52 296960 ----a-w- c:\windows\system32\d3d10core.dll
2013-06-21 21:52 . 2013-06-21 21:52 293376 ----a-w- c:\windows\SysWow64\dxgi.dll
2013-06-21 21:52 . 2013-06-21 21:52 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll
2013-06-21 21:52 . 2013-06-21 21:52 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2013-06-21 21:52 . 2013-06-21 21:52 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-06-21 21:52 . 2013-06-21 21:52 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-06-21 21:52 . 2013-06-21 21:52 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2013-06-21 21:52 . 2013-06-21 21:52 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2013-06-21 21:52 . 2013-06-21 21:52 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll
2013-06-21 21:52 . 2013-06-21 21:52 221184 ----a-w- c:\windows\system32\UIAnimation.dll
2013-06-21 21:52 . 2013-06-21 21:52 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll
2013-06-21 21:52 . 2013-06-21 21:52 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll
2013-06-21 21:52 . 2013-06-21 21:52 1988096 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2013-06-21 21:52 . 2013-06-21 21:52 194560 ----a-w- c:\windows\system32\d3d10_1.dll
2013-06-21 21:52 . 2013-06-21 21:52 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll
2013-06-21 21:52 . 2013-06-21 21:52 1682432 ----a-w- c:\windows\system32\XpsPrint.dll
2013-06-21 21:52 . 2013-06-21 21:52 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2013-06-21 21:52 . 2013-06-21 21:52 1238528 ----a-w- c:\windows\system32\d3d10.dll
2013-06-21 21:52 . 2013-06-21 21:52 1175552 ----a-w- c:\windows\system32\FntCache.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
"CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2009-06-03 103720]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
"UpdatePDRShortCut"="c:\program files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-01-04 222504]
"RemoteControl8"="c:\program files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe" [2009-04-15 91432]
"PDVD8LanguageShortcut"="c:\program files (x86)\CyberLink\PowerDVD8\Language\Language.exe" [2009-04-15 50472]
"UpdatePPShortCut"="c:\program files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]
"UpdatePSTShortCut"="c:\program files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2009-07-21 210216]
"UCam_Menu"="c:\program files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-05-11 958576]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-09-03 347192]
"gbrspcontrol"="c:\program files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" [2013-05-30 1851088]
.
c:\users\Nicole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.4.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2012-8-13 1199104]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Start GeekBuddy.lnk - c:\program files (x86)\Comodo\GeekBuddy\launcher.exe "unit_manager.exe" [2013-7-24 49360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 DragonUpdater;COMODO Dragon Update Service;c:\program files (x86)\Comodo\Dragon\dragon_updater.exe;c:\program files (x86)\Comodo\Dragon\dragon_updater.exe [x]
R2 HOSTS Anti-PUPs;HOSTS Anti-PUPs;c:\program files (x86)\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe;c:\program files (x86)\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe [x]
R3 cmdvirth;COMODO Virtual Service Manager;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe [x]
R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
S0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys;c:\windows\SYSNATIVE\drivers\gfibto.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys;c:\windows\SYSNATIVE\DRIVERS\cmderd.sys [x]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys;c:\windows\SYSNATIVE\DRIVERS\cmdguard.sys [x]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys;c:\windows\SYSNATIVE\DRIVERS\cmdhlp.sys [x]
S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys;c:\windows\SYSNATIVE\Drivers\SABI.sys [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 CLPSLauncher;COMODO LPS Launcher;c:\program files (x86)\Common Files\COMODO\launcher_service.exe;c:\program files (x86)\Common Files\COMODO\launcher_service.exe [x]
S2 GeekBuddyRSP;GeekBuddyRSP Service;c:\program files (x86)\Common Files\COMODO\GeekBuddyRSP.exe;c:\program files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
Inhalt des "geplante Tasks" Ordners
.
2013-09-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-17 17:50]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-15 9644576]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-02-09 16413288]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cistray.exe" [2013-07-08 1502424]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://securedsearch2.lavasoft.com/index.php?pr=vmn&id=adawaretb&v=3_4&ent=hp&u=DEEF6E208983E93783FBC6522BAE9F6A
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.2.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-EA Core - c:\program files (x86)\Electronic Arts\EADM\Core.exe
Wow6432Node-HKLM-Run-HOSTS Anti-Adware_PUPs - c:\program files (x86)\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe
Wow6432Node-HKLM-Run-Search Protection - c:\programdata\Search Protection\SearchProtection.exe
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
SafeBoot-82779302.sys
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-09-12 14:53:47
ComboFix-quarantined-files.txt 2013-09-12 12:53
.
Vor Suchlauf: 18 Verzeichnis(se), 138.997.256.192 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 138.680.758.272 Bytes frei
.
- - End Of File - - BCE09598F080FCC1C06623F1395F70B4 Danke für die Hilfe :-)
Was war das denn eigentlich?
Tja, leider ist es wohl doch noch nicht behoben. Ich hatte gerade eben wieder das gleiche Problem :headbang: |