Code:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.11.20.10
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16736
Pascal :: PASCAL-PC [Administrator]
20.11.2013 18:47:54
MBAM-log-2013-11-20 (18-51-51).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 341200
Laufzeit: 3 Minute(n), 22 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 2
D:\Users\Pascal\Downloads\SoftonicDownloader_fuer_gamespy-arcade.exe (PUP.Optional.Softonic.A) -> Keine Aktion durchgeführt.
D:\Users\Pascal\Downloads\SoftonicDownloader_fuer_trojan-remover.exe (PUP.Optional.Softonic.A) -> Keine Aktion durchgeführt.
(Ende) Code:
# AdwCleaner v3.012 - Bericht erstellt am 20/11/2013 um 18:54:06
# Updated 11/11/2013 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits)
# Benutzername : Pascal - PASCAL-PC
# Gestartet von : D:\Users\Pascal\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
***** [ Browser ] *****
-\\ Internet Explorer v0.0.0.0
-\\ Mozilla Firefox v25.0.1 (de)
[ Datei : D:\Users\Pascal\AppData\Roaming\Mozilla\Firefox\Profiles\vzcsjy6m.default\prefs.js ]
[ Datei : D:\Users\Martini\AppData\Roaming\Mozilla\Firefox\Profiles\kutln7f6.default-1364595953560\prefs.js ]
[ Datei : D:\Users\Martini\AppData\Roaming\Mozilla\Firefox\Profiles\vztfwutp.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [83416 octets] - [26/09/2013 15:04:31]
AdwCleaner[R1].txt - [4796 octets] - [10/10/2013 14:27:25]
AdwCleaner[R2].txt - [1578 octets] - [20/11/2013 18:53:13]
AdwCleaner[S0].txt - [83332 octets] - [26/09/2013 15:04:51]
AdwCleaner[S1].txt - [4652 octets] - [10/10/2013 14:28:37]
AdwCleaner[S2].txt - [1402 octets] - [20/11/2013 18:54:06]
########## EOF - D:\AdwCleaner\AdwCleaner[S2].txt - [1462 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Ultimate x64
Ran by Pascal on 20.11.2013 at 18:58:46.48
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: D:\Users\Pascal\AppData\Roaming\mozilla\firefox\profiles\vzcsjy6m.default\minidumps [18 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 20.11.2013 at 19:07:15.98
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ComboFix 13-11-19.01 - Pascal 20.11.2013 19:09:47.2.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.41.1031.18.16301.13583 [GMT 1:00]
ausgeführt von:: d:\users\Pascal\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Outpost Security Suite *Disabled/Updated* {ECEA6BCD-A007-0BC7-D5A5-0254DCBD816E}
FW: Outpost Security Suite *Disabled* {D4D1EAE8-EA68-0A9F-FEFA-AB61226EC615}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Outpost Security Suite *Disabled/Updated* {578B8A29-863D-0449-EF15-3926A73ACBD3}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-10-20 bis 2013-11-20 ))))))))))))))))))))))))))))))
.
.
2013-11-20 18:16 . 2013-11-20 18:16 -------- d-----w- d:\users\UpdatusUser\AppData\Local\temp
2013-11-20 18:16 . 2013-11-20 18:16 -------- d-----w- d:\users\UpdatusUser.Pascal-PC\AppData\Local\temp
2013-11-20 18:16 . 2013-11-20 18:16 -------- d-----w- d:\users\TEMP\AppData\Local\temp
2013-11-20 18:16 . 2013-11-20 18:16 -------- d-----w- d:\users\Martini\AppData\Local\temp
2013-11-20 18:16 . 2013-11-20 18:16 -------- d-----w- d:\users\Default\AppData\Local\temp
2013-11-20 18:16 . 2013-11-20 18:16 -------- d-----w- d:\users\Administrator\AppData\Local\temp
2013-11-20 18:08 . 2013-11-20 18:08 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{74FE1043-3FA9-4A54-9FFE-F791D8C140CB}\offreg.dll
2013-11-20 16:05 . 2013-11-20 16:05 -------- d-----w- d:\users\Pascal\AppData\Local\Criterion Games
2013-11-19 14:53 . 2013-11-08 03:12 10285968 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{74FE1043-3FA9-4A54-9FFE-F791D8C140CB}\mpengine.dll
2013-11-17 17:51 . 2013-11-17 17:51 -------- d-----w- C:\NVIDIA
2013-11-17 17:51 . 2013-11-17 17:51 -------- d-----w- d:\users\Pascal\AppData\Local\NVIDIA Corporation
2013-11-14 17:56 . 2013-11-14 17:56 -------- d-----w- c:\program files (x86)\Cheat Engine 6.3
2013-11-14 17:30 . 2013-11-14 17:30 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2013-11-14 14:14 . 2013-10-05 20:25 1474048 ----a-w- c:\windows\system32\crypt32.dll
2013-11-13 16:45 . 2013-11-13 16:45 -------- d-----w- c:\program files (x86)\Workshell
2013-11-09 11:55 . 2013-11-09 11:55 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-11-09 11:55 . 2013-11-09 11:55 -------- d-----w- c:\program files\iTunes
2013-11-09 11:55 . 2013-11-09 11:55 -------- d-----w- c:\program files (x86)\iTunes
2013-11-09 11:55 . 2013-11-09 11:55 -------- d-----w- c:\program files\iPod
2013-11-04 14:32 . 2007-10-12 14:14 5081608 ----a-w- c:\windows\system32\d3dx9_36.dll
2013-11-02 23:14 . 2013-11-02 23:15 -------- d-----w- d:\users\Pascal\AppData\Roaming\Mumble
2013-11-02 17:43 . 2013-11-02 17:43 -------- d-----w- c:\program files (x86)\MSXML 4.0
2013-11-02 17:42 . 2013-11-02 17:42 -------- d-----w- C:\Python27
2013-11-02 17:41 . 2011-03-21 15:29 1097672 ----a-w- c:\windows\system32\drivers\SandBox64.sys
2013-11-02 17:41 . 2011-02-02 16:04 293048 ----a-w- c:\windows\system32\drivers\VBEngNT.sys
2013-11-02 17:41 . 2010-09-27 14:38 424040 ----a-w- c:\windows\system32\drivers\afwcore.sys
2013-11-02 17:41 . 2010-04-20 15:02 39528 ----a-w- c:\windows\system32\drivers\afw.sys
2013-11-02 17:40 . 2013-11-20 14:09 -------- d-----w- c:\windows\system32\Filt
2013-11-02 17:40 . 2013-11-02 17:40 -------- d-----w- d:\users\Pascal\AppData\Roaming\Agnitum
2013-11-02 17:40 . 2013-11-02 17:40 -------- d-----w- c:\program files\Agnitum
2013-11-02 17:40 . 2013-11-02 17:40 -------- d-----w- c:\programdata\Agnitum
2013-11-02 17:39 . 2013-11-02 17:39 -------- d-----w- c:\program files (x86)\Hewlett-Packard
2013-11-02 17:37 . 2013-11-07 16:19 -------- d-----w- d:\users\Pascal\AppData\Roaming\HpUpdate
2013-11-02 17:37 . 2013-11-02 17:37 -------- d-----w- c:\windows\Hewlett-Packard
2013-11-02 17:33 . 2013-11-02 17:33 -------- d-----w- d:\users\Pascal\AppData\Local\Secunia PSI
2013-11-02 17:28 . 2013-11-02 17:28 -------- d-----w- c:\program files (x86)\Secunia
2013-11-02 17:25 . 2013-11-02 17:25 -------- d-----w- c:\program files (x86)\Mumble
2013-11-02 13:52 . 2013-11-02 13:52 -------- d-----w- d:\users\Pascal\AppData\Local\SmartTechnology
2013-11-02 13:50 . 2013-11-02 13:50 -------- d-----w- c:\programdata\SmartTechnology
2013-11-02 13:50 . 2013-11-02 13:50 -------- d-----w- c:\program files\SmartTechnology
2013-11-02 12:55 . 2013-10-08 06:50 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-11-02 12:53 . 2013-11-02 12:52 312744 ----a-w- c:\windows\system32\javaws.exe
2013-11-02 12:52 . 2013-11-02 12:52 189352 ----a-w- c:\windows\system32\javaw.exe
2013-11-02 12:52 . 2013-11-02 12:52 189352 ----a-w- c:\windows\system32\java.exe
2013-11-02 12:52 . 2013-11-02 12:52 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-11-02 12:52 . 2013-11-02 12:52 -------- d-----w- c:\program files\Java
2013-11-02 11:15 . 2013-11-02 11:15 -------- d-----w- d:\users\Pascal\AppData\Local\Vitalwerks
2013-11-02 11:15 . 2013-11-02 11:15 -------- d-----w- c:\program files (x86)\No-IP
2013-11-01 00:01 . 2013-11-01 00:01 -------- d-----w- c:\program files (x86)\Microsoft Games
2013-10-28 17:55 . 2013-11-08 20:47 1064224 ----a-w- c:\windows\system32\nvspcap64.dll
2013-10-28 17:55 . 2013-11-08 20:47 955168 ----a-w- c:\windows\SysWow64\nvspcap.dll
2013-10-28 17:55 . 2013-09-27 23:01 39200 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2013-10-28 17:55 . 2013-09-27 23:01 28960 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2013-10-24 18:41 . 2006-06-19 11:01 69632 ----a-w- c:\windows\SysWow64\ztvcabinet.dll
2013-10-24 18:41 . 2006-05-25 13:52 162304 ----a-w- c:\windows\SysWow64\ztvunrar36.dll
2013-10-24 18:41 . 2005-08-25 23:50 77312 ----a-w- c:\windows\SysWow64\ztvunace26.dll
2013-10-24 18:41 . 2003-02-02 18:06 153088 ----a-w- c:\windows\SysWow64\UNRAR3.dll
2013-10-24 18:41 . 2002-03-05 23:00 75264 ----a-w- c:\windows\SysWow64\unacev2.dll
2013-10-23 14:13 . 2013-10-23 14:13 -------- d-----w- d:\users\Pascal\AppData\Roaming\NVIDIA
2013-10-23 13:27 . 2013-10-23 10:30 15855568 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2013-10-23 13:27 . 2013-10-16 00:48 1884448 ----a-w- c:\windows\system32\nvdispco6433158.dll
2013-10-23 13:27 . 2013-10-16 00:48 1511712 ----a-w- c:\windows\system32\nvdispgenco6433158.dll
2013-10-23 02:02 . 2013-10-23 02:02 589600 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2013-10-22 20:53 . 2013-10-22 20:53 -------- d-----w- d:\users\Pascal\AppData\Roaming\TeamViewer
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-20 16:02 . 2013-10-18 16:53 43520 ----a-w- c:\windows\SysWow64\CmdLineExt03.dll
2013-11-17 19:14 . 2013-08-11 14:18 214392 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-11-17 19:05 . 2013-08-11 14:18 214392 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-11-14 16:04 . 2013-08-10 19:03 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-14 15:51 . 2013-08-10 13:15 82896128 ----a-w- c:\windows\system32\MRT.exe
2013-11-04 14:33 . 2013-08-11 14:18 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-10-23 10:30 . 2013-10-21 16:37 18286416 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-10-23 10:30 . 2013-10-21 16:37 15212336 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-10-23 10:30 . 2013-10-17 17:42 61216 ----a-w- c:\windows\system32\OpenCL.dll
2013-10-23 10:30 . 2013-10-17 17:42 53024 ----a-w- c:\windows\SysWow64\OpenCL.dll
2013-10-23 10:30 . 2013-10-17 17:41 3067560 ----a-w- c:\windows\system32\nvapi64.dll
2013-10-23 10:30 . 2013-10-17 17:41 2695200 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-10-23 10:30 . 2013-10-17 17:41 1435504 ----a-w- c:\windows\system32\nvumdshimx.dll
2013-10-23 10:30 . 2013-10-17 17:41 141336 ----a-w- c:\windows\SysWow64\nvinit.dll
2013-10-23 08:20 . 2013-10-17 17:42 6669600 ----a-w- c:\windows\system32\nvcpl.dll
2013-10-23 08:20 . 2013-10-17 17:42 3489568 ----a-w- c:\windows\system32\nvsvc64.dll
2013-10-23 08:20 . 2013-10-17 17:42 922912 ----a-w- c:\windows\system32\nvvsvc.exe
2013-10-23 08:20 . 2013-10-17 17:42 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-10-23 08:20 . 2013-10-17 17:42 2559776 ----a-w- c:\windows\system32\nvsvcr.dll
2013-10-23 08:20 . 2013-10-17 17:42 219424 ----a-w- c:\windows\system32\nvmctray.dll
2013-10-23 08:20 . 2013-10-17 17:42 3426956 ----a-w- c:\windows\system32\nvcoproc.bin
2013-10-15 14:53 . 2013-10-15 14:53 53248 ----a-w- c:\windows\SysWow64\unrar.dll
2013-10-14 10:04 . 2013-10-14 10:04 18456 ----a-w- c:\windows\system32\drivers\psi_mf_amd64.sys
2013-10-13 23:50 . 2013-08-11 14:18 298280 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-10-10 23:31 . 2013-08-17 14:29 3360624 ----a-w- c:\windows\SysWow64\pbsvc.exe
2013-10-05 19:50 . 2013-10-05 19:50 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2013-09-27 23:01 . 2013-08-10 15:45 29984 ----a-w- c:\windows\system32\nvaudcap64v.dll
2013-09-12 08:58 . 2013-10-20 10:29 1884448 ----a-w- c:\windows\system32\nvdispco6432723.dll
2013-09-12 08:58 . 2013-10-20 10:29 1511712 ----a-w- c:\windows\system32\nvdispgenco6432723.dll
2013-09-08 02:30 . 2013-10-09 22:41 1903552 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-09-08 02:27 . 2013-10-09 22:41 327168 ----a-w- c:\windows\system32\mswsock.dll
2013-09-08 02:03 . 2013-10-09 22:41 231424 ----a-w- c:\windows\SysWow64\mswsock.dll
2013-09-04 12:12 . 2013-10-16 19:23 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-09-04 12:11 . 2013-10-16 19:23 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-09-04 12:11 . 2013-10-16 19:23 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-09-04 12:11 . 2013-10-16 19:23 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-09-04 12:11 . 2013-10-16 19:23 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-09-04 12:11 . 2013-10-16 19:23 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-09-04 12:11 . 2013-10-16 19:23 7808 ----a-w- c:\windows\system32\drivers\usbd.sys
2013-09-03 12:35 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-08-30 07:48 . 2013-09-26 14:39 378944 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-08-30 07:48 . 2013-09-26 14:39 72016 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-08-30 07:48 . 2013-09-26 14:39 64288 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-08-30 07:48 . 2013-09-26 14:39 1030952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-08-30 07:48 . 2013-09-26 14:39 204880 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-08-30 07:48 . 2013-09-26 14:39 65336 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-08-30 07:48 . 2013-09-26 14:39 33400 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-08-30 07:48 . 2013-09-26 14:39 80816 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-08-30 07:47 . 2013-09-26 14:39 41664 ----a-w- c:\windows\avastSS.scr
2013-08-30 07:47 . 2013-08-10 14:48 287840 ----a-w- c:\windows\system32\aswBoot.exe
2013-08-29 02:17 . 2013-10-09 22:41 5549504 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-08-29 02:16 . 2013-10-09 22:41 1732032 ----a-w- c:\windows\system32\ntdll.dll
2013-08-29 02:16 . 2013-10-09 22:41 243712 ----a-w- c:\windows\system32\wow64.dll
2013-08-29 02:16 . 2013-10-09 22:41 859648 ----a-w- c:\windows\system32\tdh.dll
2013-08-29 02:13 . 2013-10-09 22:41 878080 ----a-w- c:\windows\system32\advapi32.dll
2013-08-29 01:51 . 2013-10-09 22:41 3969472 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-08-29 01:51 . 2013-10-09 22:41 3914176 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-08-29 01:50 . 2013-10-09 22:41 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2013-08-29 01:50 . 2013-10-09 22:41 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll
2013-08-29 01:50 . 2013-10-09 22:41 619520 ----a-w- c:\windows\SysWow64\tdh.dll
2013-08-29 01:48 . 2013-10-09 22:41 640512 ----a-w- c:\windows\SysWow64\advapi32.dll
2013-08-29 01:48 . 2013-10-09 22:41 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-08-29 00:49 . 2013-10-09 22:41 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2013-08-29 00:49 . 2013-10-09 22:41 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2013-08-29 00:49 . 2013-10-09 22:41 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2013-08-29 00:49 . 2013-10-09 22:41 2048 ----a-w- c:\windows\SysWow64\user.exe
2013-08-28 01:21 . 2013-10-09 22:41 3155968 ----a-w- c:\windows\system32\win32k.sys
2013-08-28 01:12 . 2013-10-09 22:41 461312 ----a-w- c:\windows\system32\scavengeui.dll
2013-08-27 20:40 . 2013-08-27 20:40 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-07-03 3673184]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-08-30 4858968]
"TrojanScanner"="c:\program files (x86)\Trojan Remover\Trjscan.exe" [2013-10-24 1655568]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-10-28 49208]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-11-01 152392]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2013-11-11 2349392]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2013-10-14 565464]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~1\Agnitum\OUTPOS~1\wl_hook.dll c:\windows\SysWOW64\nvinit.dll
.
R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe;c:\program files (x86)\Secunia\PSI\sua.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 ASWFilt;ASWFilt;c:\windows\system32\Filt\ASWFilt64.dll;c:\windows\SYSNATIVE\Filt\ASWFilt64.dll [x]
R3 cpuz135;cpuz135;c:\program files (x86)\CPUID\PC Wizard 2012\pcwiz_x64.sys;c:\program files (x86)\CPUID\PC Wizard 2012\pcwiz_x64.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf_amd64.sys;c:\windows\SYSNATIVE\DRIVERS\psi_mf_amd64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SaiK0CD5;SaiK0CD5;c:\windows\system32\DRIVERS\SaiK0CD5.sys;c:\windows\SYSNATIVE\DRIVERS\SaiK0CD5.sys [x]
R3 SaiU0CD5;SaiU0CD5;c:\windows\system32\DRIVERS\SaiU0CD5.sys;c:\windows\SYSNATIVE\DRIVERS\SaiU0CD5.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 VBEngNT;VBEngNT;c:\windows\system32\drivers\VBEngNT.sys;c:\windows\SYSNATIVE\drivers\VBEngNT.sys [x]
R3 VBFilt;VBFilt;c:\windows\system32\Filt\VBFilt64.dll;c:\windows\SYSNATIVE\Filt\VBFilt64.dll [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 aswRvrt;aswRvrt; [x]
S0 aswVmm;aswVmm; [x]
S1 afw;Agnitum Firewall Driver;c:\windows\system32\DRIVERS\afw.sys;c:\windows\SYSNATIVE\DRIVERS\afw.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 SandBox;SandBox;c:\windows\system32\drivers\SandBox64.sys;c:\windows\SYSNATIVE\drivers\SandBox64.sys [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe;c:\program files (x86)\Secunia\PSI\PSIA.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys;c:\windows\SYSNATIVE\drivers\afwcore.sys [x]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - MBAMPROTECTOR
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Inhalt des "geplante Tasks" Ordners
.
2013-11-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-10 16:04]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-08-30 07:47 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Outpost]
@="{33C9E362-3EDA-4930-8AFE-5DA39A8BB77A}"
[HKEY_CLASSES_ROOT\CLSID\{33C9E362-3EDA-4930-8AFE-5DA39A8BB77A}]
2011-03-30 18:02 601528 ----a-w- c:\program files\Agnitum\Outpost Security Suite Free\op_shell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-14 441968]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-12-14 399984]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-14 172144]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-11-08 1028384]
"VX3000"="c:\windows\vVX3000.exe" [2009-06-30 762224]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2013-11-08 1064224]
"ProfilerU"="c:\program files\SmartTechnology\Software\ProfilerU.exe" [2013-04-16 454144]
"SaiMfd"="c:\program files\SmartTechnology\Software\SaiMfd.exe" [2013-04-16 158208]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2011-04-04 4510072]
"OutpostFeedBack"="c:\program files\Agnitum\Outpost Security Suite Free\feedback.exe" [2011-03-30 808064]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\progra~1\Agnitum\OUTPOS~1\wl_hook64.dll c:\windows\System32\nvinitx.dll
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
TCP: Interfaces\{271FB102-E8E4-4880-9621-574BE15360B6}: DhcpNameServer = 192.168.1.1
FF - ProfilePath - d:\users\Pascal\AppData\Roaming\Mozilla\Firefox\Profiles\vzcsjy6m.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - ExtSQL: 2013-09-25 16:17; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF - ExtSQL: 2013-09-26 16:39; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: 2013-10-10 20:42; {99B98C2C-7274-45a3-A640-D9DF1A1C8460}; d:\users\Pascal\AppData\Roaming\Mozilla\Firefox\Profiles\vzcsjy6m.default\extensions\{99B98C2C-7274-45a3-A640-D9DF1A1C8460}.xpi
FF - ExtSQL: !HIDDEN! 2013-09-25 16:17; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
AddRemove-Age of Chivalry: Hegemony - c:\program files (x86)\Microsoft Games\Age of Empires II\Uninstall Age of Chivalry.exe
AddRemove-Battlelog Web Plugins - c:\program files (x86)\Battlelog Web Plugins\uninstall.exe
AddRemove-ESN Sonar-0.70.4 - c:\program files (x86)\Battlelog Web Plugins\Sonar\esnsonar_uninstall.exe
AddRemove-GOGPACKSPACECOLONYHD_is1 - c:\gog games\Space Colony HD\unins000.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3527207512-1547861424-694024003-1010\Software\SecuROM\License information*]
"datasecu"=hex:09,63,f1,03,79,b4,74,96,03,fb,6a,c9,be,f4,b3,ca,4d,25,ef,82,dc,
ca,23,26,6a,43,ce,6f,0e,22,7c,82,9e,68,01,ce,ec,b5,ec,3b,67,28,cb,9c,a5,91,\
"rkeysecu"=hex:3b,33,f6,1b,13,e3,7f,f5,63,9c,9a,14,f7,48,97,55
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_152_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_152_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-11-20 19:19:21
ComboFix-quarantined-files.txt 2013-11-20 18:19
ComboFix2.txt 2013-11-16 19:05
.
Vor Suchlauf: 15 Verzeichnis(se), 314'327'846'912 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 314'000'027'648 Bytes frei
.
- - End Of File - - 53B3D7E471FEE6D238C0638251A25D01
A36C5E4F47E84449FF07ED3517B43A31 Danke Nochmal :) |