Hallo Schrauber,
Jetzt kommt die Logdatei teil 1 Code:
ComboFix 13-11-15.01 - Uwe Augustin 15.11.2013 11:47:26.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.15561.13512 [GMT 1:00]
ausgeführt von:: c:\users\Uwe Augustin\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\DealPly
c:\program files (x86)\DealPly\DealPly.crx
c:\program files (x86)\DealPly\DealPly.xpi
c:\program files (x86)\DealPly\DealPlyIE.dll
c:\program files (x86)\DealPly\DealPlyIE64.dll
c:\program files (x86)\DealPly\DealPlyUpdate.exe
c:\program files (x86)\DealPly\DealPlyUpdateRun.exe
c:\program files (x86)\DealPly\DealPlyUpdateVer.exe
c:\program files (x86)\DealPly\icon.ico
c:\program files (x86)\DealPly\uninst.exe
c:\program files (x86)\Uniblue\SpeedUpMyPC
c:\program files (x86)\Uniblue\SpeedUpMyPC\cwebpage.dll
c:\program files (x86)\Uniblue\SpeedUpMyPC\InstallerExtensions.dll
c:\program files (x86)\Uniblue\SpeedUpMyPC\intermediate_views.dat
c:\program files (x86)\Uniblue\SpeedUpMyPC\latest_scan_results.xsl
c:\program files (x86)\Uniblue\SpeedUpMyPC\launcher.exe
c:\program files (x86)\Uniblue\SpeedUpMyPC\library.dat
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\br\br.dll
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\br\LC_MESSAGES\messages.mo
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\de\de.dll
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\de\LC_MESSAGES\messages.mo
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\dk\dk.dll
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\dk\LC_MESSAGES\messages.mo
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\en\en.dll
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\en\LC_MESSAGES\messages.mo
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\es\es.dll
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\es\LC_MESSAGES\messages.mo
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\fi\fi.dll
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\fi\LC_MESSAGES\messages.mo
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\fr\fr.dll
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\fr\LC_MESSAGES\messages.mo
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\it\it.dll
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\it\LC_MESSAGES\messages.mo
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\jp\jp.dll
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\jp\LC_MESSAGES\messages.mo
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\nl\LC_MESSAGES\messages.mo
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\nl\nl.dll
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\no\LC_MESSAGES\messages.mo
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\no\no.dll
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\ru\LC_MESSAGES\messages.mo
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\ru\ru.dll
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\se\LC_MESSAGES\messages.mo
c:\program files (x86)\Uniblue\SpeedUpMyPC\locale\se\se.dll
c:\program files (x86)\Uniblue\SpeedUpMyPC\Microsoft.VC90.CRT.manifest
c:\program files (x86)\Uniblue\SpeedUpMyPC\msvcp90.dll
c:\program files (x86)\Uniblue\SpeedUpMyPC\msvcr90.dll
c:\program files (x86)\Uniblue\SpeedUpMyPC\repair_transform.xsl
c:\program files (x86)\Uniblue\SpeedUpMyPC\sp_move_serial.exe
c:\program files (x86)\Uniblue\SpeedUpMyPC\spmonitor.exe
c:\program files (x86)\Uniblue\SpeedUpMyPC\spnotifier.exe
c:\program files (x86)\Uniblue\SpeedUpMyPC\sump.exe
c:\program files (x86)\Uniblue\SpeedUpMyPC\Third party Terms\comtypes.txt
c:\program files (x86)\Uniblue\SpeedUpMyPC\Third party Terms\cwebpage.dll.html
c:\program files (x86)\Uniblue\SpeedUpMyPC\Third party Terms\decorator.py.txt
c:\program files (x86)\Uniblue\SpeedUpMyPC\Third party Terms\ordereddict.py.txt
c:\program files (x86)\Uniblue\SpeedUpMyPC\Third party Terms\py2exe.txt
c:\program files (x86)\Uniblue\SpeedUpMyPC\Third party Terms\python-changes.txt
c:\program files (x86)\Uniblue\SpeedUpMyPC\Third party Terms\python.txt
c:\program files (x86)\Uniblue\SpeedUpMyPC\Third party Terms\simplejson.txt
c:\program files (x86)\Uniblue\SpeedUpMyPC\Third party Terms\wmi.txt
c:\program files (x86)\Uniblue\SpeedUpMyPC\unins000.dat
c:\program files (x86)\Uniblue\SpeedUpMyPC\unins000.exe
c:\program files (x86)\Uniblue\SpeedUpMyPC\unins000.msg
c:\program files (x86)\Uniblue\SpeedUpMyPC\views.dat
c:\program files (x86)\Uniblue\SpeedUpMyPC\x86\Trackerbird.py.clr2.dll
c:\program files (x86)\Uniblue\SpeedUpMyPC\x86\Trackerbird.py.clr4.dll
c:\windows\SysWow64\FlashPlayerApp.exe
c:\windows\Tasks\SpeedUpMyPC.job
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-10-15 bis 2013-11-15 ))))))))))))))))))))))))))))))
.
.
2013-11-14 18:42 . 2013-11-14 18:42 -------- d-----w- c:\program files (x86)\SINOVO
2013-11-14 18:41 . 2013-11-14 18:41 -------- d-----w- c:\windows\Downloaded Installations
2013-11-14 17:04 . 2013-11-14 17:04 -------- d-----w- c:\program files (x86)\Abbott Diabetes Care
2013-11-13 15:05 . 2013-10-05 20:25 1474048 ----a-w- c:\windows\system32\crypt32.dll
2013-11-13 15:05 . 2013-10-05 19:57 1168384 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-11-12 18:11 . 2013-11-12 18:11 -------- d-----w- C:\FRST
2013-11-12 09:18 . 2013-11-12 09:18 -------- d-----w- c:\program files (x86)\iMesh Applications
2013-11-12 09:14 . 2013-11-12 18:03 -------- d-----w- c:\program files (x86)\MyPC Backup
2013-11-12 09:14 . 2013-11-12 18:00 -------- d-----w- c:\program files (x86)\BuzzSearch
2013-11-12 09:14 . 2013-09-17 10:25 20312 ----a-w- c:\windows\system32\roboot64.exe
2013-11-12 09:10 . 2013-11-12 09:10 -------- d-----w- c:\programdata\BonanzaDealsLive
2013-11-12 09:09 . 2013-11-12 09:09 -------- d-----w- c:\program files (x86)\metaCrawler
2013-11-12 09:09 . 2013-11-12 09:09 -------- d-----w- c:\program files (x86)\BonanzaDeals
2013-11-11 15:59 . 2013-11-11 15:59 -------- d-----w- c:\program files\CCleaner
2013-11-11 15:54 . 2013-11-11 15:54 -------- d-----w- c:\program files (x86)\Allin1Convert_8h
2013-11-08 17:06 . 2013-11-08 17:06 -------- d-----w- c:\program files (x86)\MSXML 4.0
2013-11-08 17:05 . 2013-11-13 18:44 -------- d-----w- c:\windows\system32\MRT
2013-11-08 12:20 . 2013-11-15 10:51 -------- d-----w- c:\program files (x86)\Uniblue
2013-11-08 08:54 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2013-11-08 08:47 . 2013-11-08 08:47 -------- d-----w- c:\windows\SysWow64\NVSYS
2013-11-08 08:46 . 2013-11-08 08:46 -------- d-----w- C:\NVIDIA
2013-11-07 21:08 . 2013-11-07 21:12 -------- d-----w- c:\program files (x86)\Common Files\Steam
2013-11-07 20:47 . 2013-11-07 20:47 -------- d-----w- c:\program files (x86)\Electronic Arts
2013-11-07 20:47 . 2006-09-28 15:05 2414360 ----a-w- c:\windows\SysWow64\d3dx9_31.dll
2013-11-07 20:46 . 2013-11-07 20:46 -------- d-----w- c:\windows\SysWow64\AGEIA
2013-11-07 20:46 . 2013-11-07 20:46 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2013-11-07 20:46 . 2013-11-07 20:46 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2013-11-07 20:35 . 2013-11-07 20:35 -------- d-----w- c:\program files (x86)\EA GAMES
2013-11-07 20:30 . 2013-11-07 20:30 -------- d-----w- c:\program files (x86)\Common Files\Microsoft Games
2013-11-07 20:25 . 2013-11-14 17:04 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
2013-11-07 20:25 . 2005-05-26 14:34 3767504 ----a-w- c:\windows\system32\d3dx9_26.dll
2013-11-07 20:25 . 2005-05-26 14:34 2297552 ----a-w- c:\windows\SysWow64\d3dx9_26.dll
2013-11-07 20:25 . 2005-03-18 16:19 3823312 ----a-w- c:\windows\system32\d3dx9_25.dll
2013-11-07 20:10 . 2013-11-08 08:46 -------- d-----w- c:\program files (x86)\Common Files\InstallShield
2013-11-07 20:05 . 2013-11-07 20:12 -------- d-----w- c:\program files (x86)\Microsoft Games
2013-11-07 19:45 . 2013-11-07 19:45 -------- d-----w- c:\programdata\McAfee
2013-11-07 19:41 . 2013-11-07 19:41 -------- d-----w- c:\program files (x86)\PDF Architect
2013-11-07 19:41 . 2013-04-09 14:13 110264 ----a-w- c:\windows\system32\pdfcmon.dll
2013-11-07 19:41 . 2012-05-05 10:54 662288 ----a-w- c:\windows\SysWow64\MSCOMCT2.OCX
2013-11-07 19:41 . 2012-05-05 10:54 137000 ----a-w- c:\windows\SysWow64\MSMAPI32.OCX
2013-11-07 19:41 . 1998-07-06 17:56 125712 ----a-w- c:\windows\SysWow64\VB6DE.DLL
2013-11-07 19:41 . 1998-07-06 17:55 158208 ----a-w- c:\windows\SysWow64\MSCMCDE.DLL
2013-11-07 19:41 . 1998-07-06 17:55 64512 ----a-w- c:\windows\SysWow64\MSCC2DE.DLL
2013-11-07 19:41 . 2013-11-11 16:01 -------- d-----w- c:\program files (x86)\PDFCreator
2013-11-07 19:41 . 2012-05-05 10:54 23552 ----a-w- c:\windows\SysWow64\MSMPIDE.DLL
2013-11-07 19:41 . 2013-11-07 19:41 -------- d-----w- c:\program files (x86)\Amazon Browser Bar
2013-11-07 19:41 . 2013-11-07 19:41 129536 ----a-w- c:\users\Public\AlexaNSISPlugin.2316.dll
2013-11-07 19:11 . 2013-11-07 19:23 -------- d-----w- c:\program files (x86)\Common Files\Nero
2013-11-07 19:11 . 2013-11-07 19:24 -------- d-----w- c:\program files (x86)\Nero
2013-11-07 19:11 . 2013-11-07 19:23 -------- d-----w- c:\programdata\Nero
2013-11-07 19:05 . 2010-05-26 10:41 470880 ----a-w- c:\windows\SysWow64\d3dx10_43.dll
2013-11-07 19:05 . 2010-05-26 10:41 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll
2013-11-07 19:04 . 2010-05-26 10:41 1868128 ----a-w- c:\windows\SysWow64\d3dcsx_43.dll
2013-11-07 18:52 . 2013-11-07 18:52 -------- d--h--w- c:\programdata\CanonBJ
2013-11-07 18:52 . 2009-07-14 01:40 84992 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNBPP4.DLL
2013-11-07 17:56 . 2013-11-07 17:55 81112 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-11-07 16:32 . 2013-11-07 16:32 -------- d-----w- c:\program files (x86)\Secunia
2013-11-07 14:46 . 2013-11-07 14:46 -------- d-----w- c:\programdata\RapidSolution
2013-11-07 14:46 . 2013-11-07 14:46 -------- d-----w- c:\program files (x86)\Audials
2013-11-07 14:41 . 2013-11-07 14:41 -------- d-----w- c:\windows\Msagent
2013-11-07 14:37 . 2013-11-07 14:37 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2013-11-07 14:32 . 2013-11-07 14:32 -------- d-----w- c:\programdata\DealPlyLive
2013-11-07 14:32 . 2013-11-07 14:32 -------- d-----w- c:\program files (x86)\DealPlyLive
2013-11-07 14:32 . 2013-11-07 14:32 -------- d-----w- c:\program files (x86)\AnvSoft
2013-11-07 14:30 . 2012-08-21 12:01 33240 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2013-11-07 14:30 . 2013-11-07 14:30 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-11-07 14:30 . 2013-11-07 14:30 -------- d-----w- c:\program files\iTunes
2013-11-07 14:30 . 2013-11-07 14:30 -------- d-----w- c:\program files (x86)\iTunes
2013-11-07 14:30 . 2013-11-07 14:30 -------- d-----w- c:\programdata\Apple Computer
2013-11-07 14:30 . 2013-11-07 14:30 -------- d-----w- c:\program files\iPod
2013-11-07 14:30 . 2013-11-07 14:30 -------- d-----w- c:\program files (x86)\Apple Software Update
2013-11-07 14:30 . 2013-11-07 14:30 -------- d-----w- c:\program files\Common Files\Apple
2013-11-07 14:29 . 2013-11-07 14:29 -------- d-----w- c:\program files\Bonjour
2013-11-07 14:29 . 2013-11-07 14:29 -------- d-----w- c:\program files (x86)\Bonjour
2013-11-07 14:29 . 2013-11-07 14:30 -------- d-----w- c:\program files (x86)\Common Files\Apple
2013-11-07 14:29 . 2013-11-07 14:30 -------- d-----w- c:\programdata\Apple
2013-11-07 13:52 . 2013-11-14 15:50 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-07 13:52 . 2013-11-07 13:52 -------- d-----w- c:\windows\SysWow64\Macromed
2013-11-07 13:52 . 2013-11-07 13:52 -------- d-----w- c:\windows\system32\Macromed
2013-11-07 13:47 . 2013-11-07 13:47 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2013-11-07 13:42 . 2013-11-07 13:42 -------- d-----w- c:\programdata\AskPartnerNetwork
2013-11-07 13:42 . 2013-11-07 13:42 -------- d-----w- c:\program files (x86)\AskPartnerNetwork
2013-11-07 13:41 . 2013-11-07 13:41 -------- d-----w- c:\programdata\APN
2013-11-07 13:40 . 2013-11-07 13:37 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-11-07 13:40 . 2013-11-07 13:37 132088 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-11-07 13:40 . 2013-11-07 13:37 105344 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-11-07 13:40 . 2013-11-07 13:41 -------- d-----w- c:\programdata\Avira
2013-11-07 13:40 . 2013-11-07 13:40 -------- d-----w- c:\program files (x86)\Avira
2013-11-07 13:28 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe
2013-11-07 13:28 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll
2013-11-07 13:28 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2013-11-07 13:28 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll
2013-11-07 13:27 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll
2013-11-07 13:27 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll
2013-11-07 13:27 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll
2013-11-07 13:27 . 2012-06-02 14:19 186752 ----a-w- c:\windows\system32\wuwebv.dll
2013-11-07 13:27 . 2012-06-02 14:15 36864 ----a-w- c:\windows\system32\wuapp.exe
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-07 13:33 . 2012-07-17 12:37 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-10-07 08:02 . 2013-10-07 08:02 47240 ----a-w- c:\windows\system32\drivers\tbhsd.sys
2013-10-07 08:01 . 2013-10-07 08:01 24744 ----a-w- c:\windows\system32\drivers\RrNetCapFilterDriver.sys
2013-09-05 21:01 . 2013-09-05 21:01 96768 ----a-w- c:\windows\system32\fsutil.exe
2013-09-05 21:01 . 2013-09-05 21:01 91648 ----a-w- c:\windows\system32\drivers\USBSTOR.SYS
2013-09-05 21:01 . 2013-09-05 21:01 74240 ----a-w- c:\windows\SysWow64\fsutil.exe
2013-09-05 21:01 . 2013-09-05 21:01 410496 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2013-09-05 21:01 . 2013-09-05 21:01 27008 ----a-w- c:\windows\system32\drivers\amdxata.sys
2013-09-05 21:01 . 2013-09-05 21:01 2565632 ----a-w- c:\windows\system32\esent.dll
2013-09-05 21:01 . 2013-09-05 21:01 189824 ----a-w- c:\windows\system32\drivers\storport.sys
2013-09-05 21:01 . 2013-09-05 21:01 1699328 ----a-w- c:\windows\SysWow64\esent.dll
2013-09-05 21:01 . 2013-09-05 21:01 166272 ----a-w- c:\windows\system32\drivers\nvstor.sys
2013-09-05 21:01 . 2013-09-05 21:01 148352 ----a-w- c:\windows\system32\drivers\nvraid.sys
2013-09-05 21:01 . 2013-09-05 21:01 107904 ----a-w- c:\windows\system32\drivers\amdsata.sys
2013-09-05 21:01 . 2013-09-05 21:01 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2013-09-05 21:01 . 2013-09-05 21:01 1910208 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-09-05 21:00 . 2013-09-05 21:00 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2013-09-05 21:00 . 2013-09-05 21:00 2048 ----a-w- c:\windows\system32\tzres.dll
2013-09-05 21:00 . 2013-09-05 21:00 224256 ----a-w- c:\windows\system32\wintrust.dll
2013-09-05 21:00 . 2013-09-05 21:00 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2013-09-05 21:00 . 2013-09-05 21:00 175104 ----a-w- c:\windows\SysWow64\wintrust.dll
2013-09-05 21:00 . 2013-09-05 21:00 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2013-09-05 21:00 . 2013-09-05 21:00 139776 ----a-w- c:\windows\system32\cryptnet.dll
2013-09-05 21:00 . 2013-09-05 21:00 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2013-09-05 20:59 . 2013-09-05 20:59 39936 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2013-09-05 20:58 . 2013-09-05 20:58 663552 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2013-09-05 20:58 . 2013-09-05 20:58 1217024 ----a-w- c:\windows\system32\rpcrt4.dll
2013-09-05 20:57 . 2013-09-05 20:57 624128 ----a-w- c:\windows\system32\qedit.dll
2013-09-05 20:57 . 2013-09-05 20:57 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2013-09-05 20:56 . 2013-09-05 20:56 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-09-05 20:56 . 2013-09-05 20:56 751104 ----a-w- c:\windows\system32\win32spl.dll
2013-09-05 20:56 . 2013-09-05 20:56 492544 ----a-w- c:\windows\SysWow64\win32spl.dll
2013-09-05 20:54 . 2013-09-05 20:54 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-09-05 20:54 . 2013-09-05 20:54 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2013-09-05 20:53 . 2013-09-05 20:53 1643520 ----a-w- c:\windows\system32\DWrite.dll
2013-09-05 20:53 . 2013-09-05 20:53 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
2013-09-05 20:53 . 2013-09-05 20:53 1887232 ----a-w- c:\windows\system32\d3d11.dll
2013-09-05 20:53 . 2013-09-05 20:53 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2013-09-05 20:51 . 2013-09-05 20:51 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-09-05 20:51 . 2013-09-05 20:51 144384 ----a-w- c:\windows\system32\cdd.dll
2013-09-05 20:51 . 2013-09-05 20:51 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-09-05 20:51 . 2013-09-05 20:51 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-09-05 20:51 . 2013-09-05 20:51 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-09-05 20:51 . 2013-09-05 20:51 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-09-05 20:51 . 2013-09-05 20:51 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-09-05 20:51 . 2013-09-05 20:51 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-09-05 20:50 . 2013-09-05 20:50 78680 ----a-w- c:\windows\system32\mcupdate_AuthenticAMD.dll
2013-09-05 20:50 . 2013-09-05 20:50 48640 ----a-w- c:\windows\system32\wwanprotdim.dll
2013-09-05 20:50 . 2013-09-05 20:50 230400 ----a-w- c:\windows\system32\wwansvc.dll
2013-09-05 20:50 . 2013-09-05 20:50 903168 ----a-w- c:\windows\SysWow64\certutil.exe
2013-09-05 20:50 . 2013-09-05 20:50 52224 ----a-w- c:\windows\system32\certenc.dll
2013-09-05 20:50 . 2013-09-05 20:50 43008 ----a-w- c:\windows\SysWow64\certenc.dll
2013-09-05 20:50 . 2013-09-05 20:50 1192448 ----a-w- c:\windows\system32\certutil.exe
2013-09-05 20:49 . 2013-09-05 20:49 44032 ----a-w- c:\windows\system32\tsgqec.dll
2013-09-05 20:49 . 2013-09-05 20:49 3717632 ----a-w- c:\windows\system32\mstscax.dll
2013-09-05 20:49 . 2013-09-05 20:49 36864 ----a-w- c:\windows\SysWow64\tsgqec.dll
2013-09-05 20:49 . 2013-09-05 20:49 3217408 ----a-w- c:\windows\SysWow64\mstscax.dll
2013-09-05 20:49 . 2013-09-05 20:49 158720 ----a-w- c:\windows\system32\aaclient.dll
2013-09-05 20:49 . 2013-09-05 20:49 131584 ----a-w- c:\windows\SysWow64\aaclient.dll
2013-09-05 20:49 . 2013-09-05 20:49 30720 ----a-w- c:\windows\system32\cryptdlg.dll
2013-09-05 20:49 . 2013-09-05 20:49 24576 ----a-w- c:\windows\SysWow64\cryptdlg.dll
2013-09-05 20:48 . 2013-09-05 20:48 19968 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-09-05 20:47 . 2013-09-05 20:47 1888768 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-09-05 20:47 . 2013-09-05 20:47 1620992 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2013-09-05 20:47 . 2013-09-05 20:47 223752 ----a-w- c:\windows\system32\drivers\fvevol.sys
2013-09-05 20:47 . 2013-09-05 20:47 70144 ----a-w- c:\windows\system32\appinfo.dll
2013-09-05 20:47 . 2013-09-05 20:47 1930752 ----a-w- c:\windows\system32\authui.dll
2013-09-05 20:47 . 2013-09-05 20:47 1796096 ----a-w- c:\windows\SysWow64\authui.dll
2013-09-05 20:47 . 2013-09-05 20:47 111448 ----a-w- c:\windows\system32\consent.exe
2013-09-05 20:46 . 2013-09-05 20:46 561664 ----a-w- c:\windows\apppatch\AcLayers.dll
2013-09-05 20:45 . 2013-09-05 20:45 800768 ----a-w- c:\windows\system32\usp10.dll
2013-09-05 20:45 . 2013-09-05 20:45 626688 ----a-w- c:\windows\SysWow64\usp10.dll
2013-09-05 20:45 . 2013-09-05 20:45 68608 ----a-w- c:\windows\system32\taskhost.exe
2013-09-05 20:44 . 2013-09-05 20:44 55296 ----a-w- c:\windows\SysWow64\cero.rs
2013-09-05 20:44 . 2013-09-05 20:44 55296 ----a-w- c:\windows\system32\cero.rs
2013-09-05 20:44 . 2013-09-05 20:44 51712 ----a-w- c:\windows\SysWow64\esrb.rs
2013-09-05 20:44 . 2013-09-05 20:44 51712 ----a-w- c:\windows\system32\esrb.rs
2013-09-05 20:44 . 2013-09-05 20:44 46592 ----a-w- c:\windows\SysWow64\fpb.rs
2013-09-05 20:44 . 2013-09-05 20:44 46592 ----a-w- c:\windows\system32\fpb.rs
2013-09-05 20:44 . 2013-09-05 20:44 45568 ----a-w- c:\windows\SysWow64\oflc-nz.rs
2013-09-05 20:44 . 2013-09-05 20:44 45568 ----a-w- c:\windows\system32\oflc-nz.rs
2013-09-05 20:44 . 2013-09-05 20:44 44544 ----a-w- c:\windows\SysWow64\pegibbfc.rs
2013-09-05 20:44 . 2013-09-05 20:44 44544 ----a-w- c:\windows\system32\pegibbfc.rs
2013-09-05 20:44 . 2013-09-05 20:44 441856 ----a-w- c:\windows\system32\Wpc.dll
2013-09-05 20:44 . 2013-09-05 20:44 43520 ----a-w- c:\windows\SysWow64\csrr.rs
2013-09-05 20:44 . 2013-09-05 20:44 43520 ----a-w- c:\windows\system32\csrr.rs
2013-09-05 20:44 . 2013-09-05 20:44 40960 ----a-w- c:\windows\SysWow64\cob-au.rs
2013-09-05 20:44 . 2013-09-05 20:44 40960 ----a-w- c:\windows\system32\cob-au.rs
2013-09-05 20:44 . 2013-09-05 20:44 308736 ----a-w- c:\windows\SysWow64\Wpc.dll
2013-09-05 20:44 . 2013-09-05 20:44 30720 ----a-w- c:\windows\SysWow64\usk.rs
2013-09-05 20:44 . 2013-09-05 20:44 30720 ----a-w- c:\windows\system32\usk.rs
2013-09-05 20:44 . 2013-09-05 20:44 2746368 ----a-w- c:\windows\system32\gameux.dll
2013-09-05 20:44 . 2013-09-05 20:44 2576384 ----a-w- c:\windows\SysWow64\gameux.dll
2013-09-05 20:44 . 2013-09-05 20:44 23552 ----a-w- c:\windows\SysWow64\oflc.rs
2013-09-05 20:44 . 2013-09-05 20:44 23552 ----a-w- c:\windows\system32\oflc.rs
2013-09-05 20:44 . 2013-09-05 20:44 21504 ----a-w- c:\windows\SysWow64\grb.rs
2013-09-05 20:44 . 2013-09-05 20:44 21504 ----a-w- c:\windows\system32\grb.rs
2013-09-05 20:44 . 2013-09-05 20:44 20480 ----a-w- c:\windows\SysWow64\pegi.rs
2013-09-05 20:44 . 2013-09-05 20:44 20480 ----a-w- c:\windows\SysWow64\pegi-pt.rs
2013-09-05 20:44 . 2013-09-05 20:44 20480 ----a-w- c:\windows\SysWow64\pegi-fi.rs Der zweite Teil Code:
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}]
2013-10-23 18:43 12240 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{5cf5a690-c8f4-488e-9d20-f21aef602d41}]
2013-11-07 23:28 249632 ----a-w- c:\program files (x86)\BuzzSearch\BuzzSearchBHO.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{a4c2fb10-84c3-44eb-9f9e-860fa1d9a797}]
2013-11-11 15:54 62864 ----a-w- c:\program files (x86)\Allin1Convert_8h\bar\1.bin\8hSrcAs.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{F443A627-5009-4323-9C1D-7FD598D0D712}]
2012-08-15 19:35 2162272 ----a-w- c:\program files (x86)\Amazon Browser Bar\AmazonBrowserBar.3.0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{fbcbc43a-dca9-4192-a4c8-b57fd0f77d4d}]
2013-11-11 15:54 716360 ----a-w- c:\progra~2\ALLIN1~2\bar\1.bin\8hbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{fe063412-bea4-4d76-8ed3-183be6220d17}]
2013-08-21 17:36 100336 ----a-w- c:\program files (x86)\BonanzaDeals\BonanzaDealsIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" [2013-10-23 12240]
"{EA582743-9076-4178-9AA6-7393FDF4D5CE}"= "c:\program files (x86)\Amazon Browser Bar\AmazonBrowserBar.3.0.dll" [2012-08-15 2162272]
"{cd1a63ba-a08c-431b-9a34-f240aadc728d}"= "c:\program files (x86)\Allin1Convert_8h\bar\1.bin\8hbar.dll" [2013-11-11 716360]
.
[HKEY_CLASSES_ROOT\clsid\{41564952-412d-5637-00a7-7a786e7484d7}]
.
[HKEY_CLASSES_ROOT\clsid\{ea582743-9076-4178-9aa6-7393fdf4d5ce}]
[HKEY_CLASSES_ROOT\TypeLib\{33D0AD98-3347-4A54-8929-5163EBEB9F72}]
.
[HKEY_CLASSES_ROOT\clsid\{cd1a63ba-a08c-431b-9a34-f240aadc728d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudialsNotifier"="c:\program files (x86)\Audials\Audials 10\AudialsNotifier.exe" [2013-10-07 529160]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-11-07 347192]
"ApnTBMon"="c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2013-10-23 1673680]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"Allin1Convert Search Scope Monitor"="c:\progra~2\ALLIN1~2\bar\1.bin\8hsrchmn.exe" [2013-11-11 44784]
"Allin1Convert_8h Browser Plugin Loader"="c:\progra~2\ALLIN1~2\bar\1.bin\8hbrmon.exe" [2013-11-11 30096]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FreeStyle Auto-Assist.lnk - c:\program files (x86)\Abbott Diabetes Care\FreeStyle Auto-Assist\BGTrayApp.exe [2013-11-14 64336]
Microsoft Office.lnk - c:\program files (x86)\Microsoft Office\Office10\OSA.EXE -b -l [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
R2 bonanzadealslive;BonanzaDealsLive-Dienst (bonanzadealslive);c:\program files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe;c:\program files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 dealplylive;DealPly Live-Dienst (dealplylive);c:\program files (x86)\DealPlyLive\Update\DealPlyLive.exe;c:\program files (x86)\DealPlyLive\Update\DealPlyLive.exe [x]
R2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
R3 bonanzadealslivem;BonanzaDealsLive-Dienst (bonanzadealslivem);c:\program files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe;c:\program files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [x]
R3 dealplylivem;DealPly Live-Dienst (dealplylivem);c:\program files (x86)\DealPlyLive\Update\DealPlyLive.exe;c:\program files (x86)\DealPlyLive\Update\DealPlyLive.exe [x]
R3 DIRECTIO;DIRECTIO;UNC\srv1c027-b.wds8-b.intern\reminst\Test\BitPro64\DirectIo.sys;UNC\srv1c027-b.wds8-b.intern\reminst\Test\BitPro64\DirectIo.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
S0 amd_sata;amd_sata;c:\windows\system32\drivers\amd_sata.sys;c:\windows\SYSNATIVE\drivers\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\drivers\amd_xata.sys;c:\windows\SYSNATIVE\drivers\amd_xata.sys [x]
S0 amdkmpfd;AMD PCI Root Bus Lower Filter;c:\windows\system32\drivers\amdkmpfd.sys;c:\windows\SYSNATIVE\drivers\amdkmpfd.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 RrNetCapFilterDriver;RadioRip Filter Driver;c:\windows\system32\DRIVERS\RrNetCapFilterDriver.sys;c:\windows\SYSNATIVE\DRIVERS\RrNetCapFilterDriver.sys [x]
S2 Allin1Convert_8hService;Allin1ConvertService;c:\progra~2\ALLIN1~2\bar\1.bin\8hbarsvc.exe;c:\progra~2\ALLIN1~2\bar\1.bin\8hbarsvc.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AntiVirMailService;Avira Email-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avmailc.exe;c:\program files (x86)\Avira\AntiVir Desktop\avmailc.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x]
S2 APNMCP;Ask Aktualisierungsdienst;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [x]
S2 PDF Architect Helper Service;PDF Architect Helper Service;c:\program files (x86)\PDF Architect\HelperService.exe;c:\program files (x86)\PDF Architect\HelperService.exe [x]
S2 PDF Architect Service;PDF Architect Service;c:\program files (x86)\PDF Architect\ConversionService.exe;c:\program files (x86)\PDF Architect\ConversionService.exe [x]
S2 Update BuzzSearch;Update BuzzSearch;c:\program files (x86)\BuzzSearch\updateBuzzSearch.exe;c:\program files (x86)\BuzzSearch\updateBuzzSearch.exe [x]
S2 Updater Service for AMZN;Updater Service for AMZN;c:\program files (x86)\Amazon Browser Bar\ToolbarUpdaterService.exe;c:\program files (x86)\Amazon Browser Bar\ToolbarUpdaterService.exe [x]
S2 Util BuzzSearch;Util BuzzSearch;c:\program files (x86)\BuzzSearch\bin\utilBuzzSearch.exe;c:\program files (x86)\BuzzSearch\bin\utilBuzzSearch.exe [x]
S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys;c:\windows\SYSNATIVE\DRIVERS\amdhub30.sys [x]
S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys;c:\windows\SYSNATIVE\DRIVERS\amdxhc.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
Inhalt des "geplante Tasks" Ordners
.
2013-11-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-07 15:50]
.
2013-11-15 c:\windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job
- c:\program files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-11-12 09:10]
.
2013-11-15 c:\windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job
- c:\program files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-11-12 09:10]
.
2013-11-15 c:\windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job
- c:\program files (x86)\DealPlyLive\Update\DealPlyLive.exe [2013-11-07 14:32]
.
2013-11-15 c:\windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job
- c:\program files (x86)\DealPlyLive\Update\DealPlyLive.exe [2013-11-07 14:32]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}]
2013-10-23 18:43 13776 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll" [2013-10-23 13776]
.
[HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-08-09 12666984]
"Allin1Convert Home Page Guard 64 bit"="c:\progra~2\ALLIN1~2\bar\1.bin\AppIntegrator64.exe" [2013-11-11 548936]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.amazon.de/gp/bit/amazonserp/ref=bit_bds-p24_serp_ie_de_display?ie=UTF8&tagbase=bds-p24&tbrId=v1_abb-channel-24_2517c64f9e774823a1dc50e698352820_39_1007_20131107_DE_ie_sp_
mDefault_Search_URL = hxxp://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=TOSHIBAXDT01ACA100_93KUV87KSXX93KUV87KSX&ts=1384247651&type=default&q={searchTerms}
mDefault_Page_URL = hxxp://www.dosearches.com/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=hp&from=cor&uid=TOSHIBAXDT01ACA100_93KUV87KSXX93KUV87KSX&ts=1384247651
mStart Page = hxxp://www.dosearches.com/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=hp&from=cor&uid=TOSHIBAXDT01ACA100_93KUV87KSXX93KUV87KSX&ts=1384247651
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=TOSHIBAXDT01ACA100_93KUV87KSXX93KUV87KSX&ts=1384247651&type=default&q={searchTerms}
uInternet Settings,ProxyOverride = *.local
IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~1\Office10\EXCEL.EXE/3000
LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Uwe Augustin\AppData\Roaming\Mozilla\Firefox\Profiles\uzimm5ot.default\
FF - prefs.js: browser.search.selectedEngine - Amazon
FF - prefs.js: browser.startup.homepage - hxxp://www.amazon.de/gp/bit/amazonserp/ref=bit_bds-p24_serp_ff_de_display?ie=UTF8&tagbase=bds-p24&tbrId=v1_abb-channel-24_2517c64f9e774823a1dc50e698352820_39_1007_20131107_DE_ff_sp_
FF - prefs.js: keyword.URL -
FF - ExtSQL: 2013-11-07 15:32; {e53a26f5-7199-4a5b-86f5-d2e86854b979}; c:\users\Uwe Augustin\AppData\Roaming\Mozilla\Firefox\Profiles\uzimm5ot.default\extensions\{e53a26f5-7199-4a5b-86f5-d2e86854b979}
FF - ExtSQL: 2013-11-07 20:41; abb@amazon.com; c:\users\Uwe Augustin\AppData\Roaming\Mozilla\Firefox\Profiles\uzimm5ot.default\extensions\abb@amazon.com.xpi
FF - ExtSQL: 2013-11-07 20:41; FFPDFArchitectConverter@pdfarchitect.com; c:\program files (x86)\PDF Architect\FFPDFArchitectExt
FF - ExtSQL: 2013-11-08 00:28; firefox@mybuzzsearch.com; c:\users\Uwe Augustin\AppData\Roaming\Mozilla\Firefox\Profiles\uzimm5ot.default\extensions\firefox@mybuzzsearch.com.xpi
FF - ExtSQL: 2013-11-12 10:09; {f9d03c26-0575-497e-821d-f7956d23e0ca}; c:\users\Uwe Augustin\AppData\Roaming\Mozilla\Firefox\Profiles\uzimm5ot.default\extensions\{f9d03c26-0575-497e-821d-f7956d23e0ca}
FF - ExtSQL: 2013-11-12 10:11; {60364604-8b4c-42f4-a2ca-a76ca7b61b37}; c:\users\Uwe Augustin\AppData\Roaming\Mozilla\Firefox\Profiles\uzimm5ot.default\extensions\{60364604-8b4c-42f4-a2ca-a76ca7b61b37}
FF - ExtSQL: 2013-11-12 10:11; ffxtlbr@metacrawler.com; c:\users\Uwe Augustin\AppData\Roaming\Mozilla\Firefox\Profiles\uzimm5ot.default\extensions\ffxtlbr@metacrawler.com
FF - user.js: extensions.metacrawler.hmpg - true
FF - user.js: extensions.metacrawler.hmpgUrl - hxxp://i.search.metacrawler.com/?f=1&a=ironmc2&cd=2XzuyEtN2Y1L1Qzu0DzzyDtD0EyCtA0CyDtAyE0A0CyCtDtCtN0D0Tzu0CyCzztCtN1L2XzutBtFtBtFzztFtCtByEyBtN1L1Czu&cr=1155026517&ir=
FF - user.js: extensions.metacrawler.dfltSrch - true
FF - user.js: extensions.metacrawler.srchPrvdr - metaCrawler
FF - user.js: extensions.metacrawler.dnsErr - true
FF - user.js: extensions.metacrawler_i.newTab - false
FF - user.js: extensions.metacrawler.newTabUrl - hxxp://i.search.metacrawler.com/?f=2&a=ironmc2&cd=2XzuyEtN2Y1L1Qzu0DzzyDtD0EyCtA0CyDtAyE0A0CyCtDtCtN0D0Tzu0CyCzztCtN1L2XzutBtFtBtFzztFtCtByEyBtN1L1Czu&cr=1155026517&ir=
FF - user.js: extensions.metacrawler.tlbrSrchUrl - hxxp://i.search.metacrawler.com/?f=3&a=ironmc2&cd=2XzuyEtN2Y1L1Qzu0DzzyDtD0EyCtA0CyDtAyE0A0CyCtDtCtN0D0Tzu0CyCzztCtN1L2XzutBtFtBtFzztFtCtByEyBtN1L1Czu&cr=1155026517&ir=&q=
FF - user.js: extensions.metacrawler.id - D850E63C534AC601
FF - user.js: extensions.metacrawler.instlDay - 16021
FF - user.js: extensions.metacrawler.vrsn - 1.8.19.0
FF - user.js: extensions.metacrawler.vrsni - 1.8.19.0
FF - user.js: extensions.metacrawler_i.vrsnTs - 1.8.19.010:9:58
FF - user.js: extensions.metacrawler.prtnrId - metaCrawler
FF - user.js: extensions.metacrawler.prdct - metacrawler
FF - user.js: extensions.metacrawler.aflt - ironmc2
FF - user.js: extensions.metacrawler_i.smplGrp - none
FF - user.js: extensions.metacrawler.tlbrId - base
FF - user.js: extensions.metacrawler.instlRef -
FF - user.js: extensions.metacrawler.dfltLng -
FF - user.js: extensions.metacrawler.appId - {0FA5C13C-4EDA-488A-A8EB-B84CD7395A79}
FF - user.js: extensions.metacrawler.excTlbr - false
FF - user.js: extensions.metacrawler_i.hmpg - true
FF - user.js: extensions.metacrawler.cr - 1155026517
FF - user.js: extensions.metacrawler.cd - 2XzuyEtN2Y1L1Qzu0DzzyDtD0EyCtA0CyDtAyE0A0CyCtDtCtN0D0Tzu0CyCzztCtN1L2XzutBtFtBtFzztFtCtByEyBtN1L1Czu
FF - user.js: extensions.irmcrawler.aflt - ironmc2
FF - user.js: extensions.irmcrawler.instlRef -
FF - user.js: extensions.irmcrawler.cr - 1155026517
FF - user.js: extensions.irmcrawler.cd - 2XzuyEtN2Y1L1Qzu0DzzyDtD0EyCtA0CyDtAyE0A0CyCtDtCtN0D0Tzu0CyCzztCtN1L2XzutBtFtBtFzztFtCtByEyBtN1L1Czu
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{9cf699ca-2174-4ed8-bec1-ba82095edce0} - c:\program files (x86)\DealPly\DealPlyIE.dll
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{F241C880-6982-4CE5-8CF7-7085BA96DA5A} - (no file)
ShellIconOverlayIdentifiers-{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} - (no file)
ShellIconOverlayIdentifiers-{BBACC218-34EA-4666-9D7A-C78F2274A524} - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{F241C880-6982-4CE5-8CF7-7085BA96DA5A} - (no file)
ShellIconOverlayIdentifiers-{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} - (no file)
ShellIconOverlayIdentifiers-{BBACC218-34EA-4666-9D7A-C78F2274A524} - (no file)
AddRemove-DealPly - c:\program files (x86)\DealPly\uninst.exe
AddRemove-{E55B3271-7CA8-4D0C-AE06-69A24856E996}_is1 - c:\program files (x86)\Uniblue\SpeedUpMyPC\unins000.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1080362047-3627582943-708705303-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:9f,a5,7b,ca,6b,75,48,54,1d,e8,bf,c0,d3,72,83,cb,55,e9,20,11,2e,a2,59,
fc,f8,2e,b6,e5,9f,d0,3d,20,91,f5,d8,c8,cd,c8,03,22,d2,ee,9e,d8,10,49,8b,77,\
"??"=hex:bc,ef,70,53,64,33,2d,bd,82,05,7a,ce,af,a3,6c,d3
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-11-15 11:54:57 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2013-11-15 10:54
.
Vor Suchlauf: 8 Verzeichnis(se), 689.886.236.672 Bytes frei
Nach Suchlauf: 11 Verzeichnis(se), 689.707.843.584 Bytes frei
.
- - End Of File - - DFAD00E8A17416C96CF8CB44022572F0
A36C5E4F47E84449FF07ED3517B43A31 alles drin denke ich,
Xenax |