Die letzten drei male hatte Avira mir den zugriff verweigert, doch diesmal war ohne mein zutun der Schrim einfach geschlossen. :balla:
Seitdem ich angefangen hab diese Sachen da zu machen scheint er irgendwie zu spinnen.
Also weil der Schirm zu war hab ich es einfach mal geöffnet,ich hoffe es ist die richtige File. Code:
ComboFix 13-09-19.01 - Julian 19.09.2013 14:25:44.2.4 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3326.1965 [GMT 2:00]
ausgeführt von:: c:\users\Julian\Downloads\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Julian\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\users\Julian\AppData\Local\temp\a19482f6-74a8-457b-b041-bf6df9233adc\CliSecureRT.dll
c:\users\Julian\AppData\Roaming\Microsoft\Windows\Recent\nolife-radio.com-radio-NoLife-radio.m3u.url
D:\install.exe
.
Infizierte Kopie von c:\windows\system32\userinit.exe wurde gefunden und desinfiziert
Kopie von - c:\windows\erdnt\cache\userinit.exe wurde wiederhergestellt
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-08-19 bis 2013-09-19 ))))))))))))))))))))))))))))))
.
.
2013-09-19 12:35 . 2013-09-19 12:35 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-09-19 12:35 . 2013-09-19 12:35 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-09-17 19:52 . 2013-09-17 19:52 -------- d-----w- C:\FRST
2013-09-11 14:23 . 2013-09-11 14:23 -------- d-----w- c:\users\Julian\AppData\Local\Overwolf
2013-09-06 12:57 . 2013-09-06 12:57 -------- d-----w- c:\users\Julian\AppData\Local\CrashRpt
2013-09-06 12:55 . 2013-09-06 12:55 -------- d-----w- c:\program files\Microsoft Chart Controls
2013-08-28 13:57 . 2013-08-28 13:58 -------- d-----w- c:\users\Julian\AppData\Local\PAYDAY 2
2013-08-28 13:57 . 2013-08-28 13:57 -------- d-----w- c:\program files\AGEIA Technologies
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-14 13:37 . 2011-08-31 12:09 139112 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2013-09-14 13:37 . 2011-08-31 12:20 280792 ----a-w- c:\windows\system32\PnkBstrB.xtr
2013-09-14 13:37 . 2011-08-31 12:09 280792 ----a-w- c:\windows\system32\PnkBstrB.exe
2013-09-14 13:36 . 2011-08-31 12:09 280856 ----a-w- c:\windows\system32\PnkBstrB.ex0
2013-09-13 18:19 . 2012-04-03 08:26 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-13 18:19 . 2011-06-26 14:01 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-06 14:19 . 2011-08-31 12:09 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2013-09-06 12:55 . 2011-08-31 12:09 138056 ----a-w- c:\users\Julian\AppData\Roaming\PnkBstrK.sys
2013-09-05 13:37 . 2013-05-07 12:35 66144 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-09-05 13:37 . 2012-10-18 15:21 88840 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-09-05 13:37 . 2012-10-18 15:21 136672 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-07-07 10:29 . 2013-07-07 10:29 22560 ----a-w- c:\windows\system32\drivers\HWiNFO32.SYS
2013-06-25 14:00 . 2013-06-25 14:00 34304 ----a-w- c:\windows\system32\drivers\SAlpham.sys
2013-06-25 14:00 . 2013-06-25 14:00 113920 ----a-w- c:\windows\system32\drivers\SteelBus.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 6"="c:\program files\IObit\Advanced SystemCare 6\ASCTray.exe" [2013-04-18 491840]
"SteelSeries Engine"="c:\program files\SteelSeries\SteelSeries Engine\SteelSeriesEngine.exe" [2013-07-12 242688]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVMWlanClient"="c:\program files\avmwlanstick\wlangui.exe" [2009-05-07 1904640]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2010-08-03 358472]
"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2010-08-03 1809992]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2010-08-03 3649096]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-09-05 347192]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808]
"CDAServer"="c:\program files\Common Files\Common Desktop Agent\CDASrv.exe" [2010-12-17 332288]
"IObit Malware Fighter"="c:\program files\IObit\IObit Malware Fighter\IMF.exe" [2013-06-07 1514816]
"Razer Synapse"="c:\program files\Razer\Synapse\RzSynapse.exe" [2013-06-21 610152]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2013-06-28 2255184]
.
c:\users\Julian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.4.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2012-8-13 1199104]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"EADM"="c:\program files\Origin\Origin.exe" -AutoStart
"KPeerNexonEU"=c:\nexon\NEXON_EU_Downloader\nxEULauncher.exe
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
"Sidebar"=c:\program files\Windows Sidebar\sidebar.exe /autoRun
"Google Update"="c:\users\Julian\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"Comrade.exe"=c:\program files\GameSpy\Comrade\Comrade.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
.
R2 AODDriver4.2;AODDriver4.2;c:\program files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2012-04-09 48256]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-06-21 162408]
R3 avmeject;AVM Eject;c:\windows\system32\drivers\avmeject.sys [2009-05-07 4352]
R3 EagleXNt;EagleXNt; [x]
R3 esgiguard;esgiguard; [x]
R3 FileMonitor;FileMonitor;c:\program files\IObit\IObit Malware Fighter\Drivers\win7_x86\FileMonitor.sys [2013-03-23 21480]
R3 FWLANUSB;AVM FRITZ!WLAN;c:\windows\system32\DRIVERS\fwlanusb.sys [2007-01-25 265088]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2012-03-05 3953632]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-12-25 14848]
R3 RegFilter;RegFilter;c:\program files\IObit\IObit Malware Fighter\drivers\win7_x86\regfilter.sys [2013-03-26 31752]
R3 RZMAELSTROMVADService;Razer Surround Audio Enhancer Service;c:\windows\system32\drivers\RzMaelstromVAD.sys [2013-05-17 33016]
R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2010-07-01 34896]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-12-25 49664]
R3 UrlFilter;UrlFilter;c:\program files\IObit\IObit Malware Fighter\drivers\win7_x86\UrlFilter.sys [2013-03-26 20944]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files\Razer\Razer Game Booster\Driver\WinRing0.sys [2012-11-13 14416]
R3 XDva397;XDva397; [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [2010-11-26 15672]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-03-30 37352]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO32.SYS [2013-07-07 22560]
S2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files\IObit\Advanced SystemCare 6\ASCService.exe [2013-04-18 574272]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-12-19 219136]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-12-19 291840]
S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2013-09-05 84024]
S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2012-04-09 48256]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2013-06-28 1440080]
S2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [2013-04-25 335168]
S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2011-09-23 641832]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2011-03-14 5120]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [2011-12-14 1514304]
S3 amdiox86;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox86.sys [2010-02-18 37944]
S3 Apowersoft_AudioDevice;Apowersoft_AudioDevice;c:\windows\system32\drivers\Apowersoft_AudioDevice.sys [2010-12-30 16640]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2012-11-06 84992]
S3 busenum;SteelBusSvc;c:\windows\system32\DRIVERS\SteelBus.sys [2013-06-25 113920]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-23 19720]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-23 14856]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2011-02-16 340072]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [2009-10-30 579072]
S3 SAlphamHid;SteelHIDSvc;c:\windows\system32\DRIVERS\SAlpham.sys [2013-06-25 34304]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys [2011-12-12 10064]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2010-12-16 37504]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Inhalt des "geplante Tasks" Ordners
.
2013-09-19 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 18:19]
.
2013-09-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-618426037-2681808743-1371803286-1000Core.job
- c:\users\Julian\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-29 15:13]
.
2013-09-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-618426037-2681808743-1371803286-1000UA.job
- c:\users\Julian\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-29 15:13]
.
2013-09-19 c:\windows\Tasks\WpsUpdateTask_Julian.job
- c:\program files\Kingsoft\Kingsoft Office\office6\wpsupdate.exe [2012-09-17 18:27]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://de.search.yahoo.com?type=800236&fr=spigot-yhp-ie
IE: Free YouTube Download - c:\users\Julian\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: samsungsetup.com\www
Trusted Zone: soe.com
Trusted Zone: sony.com
Trusted Zone: vizzed.com\www
TCP: DhcpNameServer = 192.168.178.1
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-618426037-2681808743-1371803286-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:9b,6a,6b,96,79,7f,b4,1a,df,e1,7b,d3,b4,18,b5,ff,7a,21,43,13,d3,56,52,
ff,7a,45,9a,c1,e6,ca,a0,47,19,00,40,0b,3b,c7,2a,da,97,1c,3f,57,60,62,4c,ab,\
"??"=hex:a1,5e,47,db,25,65,bb,27,8b,92,55,34,10,3f,d9,49
.
[HKEY_USERS\S-1-5-21-618426037-2681808743-1371803286-1000\Software\SecuROM\License information*]
"datasecu"=hex:db,13,d6,56,cf,0e,95,cc,32,2d,e9,c5,27,1e,0d,d6,c8,a2,61,d0,f6,
ba,4c,92,d1,b3,88,8f,e4,7a,52,6c,0a,36,e1,83,67,c5,87,0f,06,60,ae,d9,46,e1,\
"rkeysecu"=hex:f6,bb,ce,61,71,57,15,7c,93,d6,28,d3,1f,c0,ff,cd
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\atieclxx.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\avmwlanstick\WlanNetService.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\taskhost.exe
c:\program files\IObit\Smart Defrag 2\SmartDefrag.exe
c:\program files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\System32\WUDFHost.exe
c:\windows\System32\WUDFHost.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\WMPSideShowGadget.exe
c:\program files\Windows Media Player\wmplayer.exe
c:\windows\system32\taskhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Logitech\GamePanel Software\Applets\LCDCountdown.exe
c:\program files\Logitech\GamePanel Software\Applets\LCDClock.exe
c:\program files\Logitech\GamePanel Software\Applets\LCDPop3.exe
c:\program files\Logitech\GamePanel Software\Applets\LCDMedia.exe
c:\program files\Logitech\GamePanel Software\Applets\LCDRSS.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\system32\DllHost.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-09-19 14:43:12 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2013-09-19 12:43
ComboFix2.txt 2013-05-07 12:56
.
Vor Suchlauf: 318015737856 Bytes frei
Nach Suchlauf: 318076157952 Bytes frei
.
- - End Of File - - B9A118EC43AF90BD84D5C9DE6552E9A6
A36C5E4F47E84449FF07ED3517B43A31 |