BluueEyes | 22.12.2013 17:06 | Hatte Combofix aus dem Desktop gespeichert, es wurde unter ComboFix(1) gespeichert, da ich es anscheinend doch noch auf dem Desktop hatte. Hatte dann ComboFix(1) gestartet. Das Programm ging auf und irgendetwas wurde geladen, auf einmal erschien die Meldung, dass ComboFix nicht in ComboFix (1) umbenannt werden kann. Dann wurde das Fenster geschlossen. Dann war allerdings nur noch ein Combofix-Programma auf meinem Desktop, das ComboFix(1) war verschwunden, nur das normale war noch da. Dann kam von Avira, obwohl ich den Guard deaktiviert hatte, eine Meldung, dass ein Zugriff auf die Registry geblockt wurde. Was hat das alles zu bedeuten ? Code:
ComboFix 13-12-21.01 - ****** 22.12.2013 16:41:19.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8159.6211 [GMT 1:00]
ausgeführt von:: c:\users\******\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\wininit.ini
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-11-22 bis 2013-12-22 ))))))))))))))))))))))))))))))
.
.
2013-12-22 15:53 . 2013-12-22 15:53 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-12-22 15:53 . 2013-12-22 15:53 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-12-22 15:53 . 2013-12-22 15:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-18 19:40 . 2013-12-18 19:40 -------- d-----w- C:\FRST
2013-12-11 15:51 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2013-12-11 15:51 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2013-12-11 15:51 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
2013-12-11 15:49 . 2013-11-26 08:02 1995264 ----a-w- c:\windows\system32\inetcpl.cpl
2013-12-11 15:49 . 2013-11-26 07:48 12996608 ----a-w- c:\windows\system32\ieframe.dll
2013-12-11 15:49 . 2013-11-26 08:35 5769216 ----a-w- c:\windows\system32\jscript9.dll
2013-12-11 15:49 . 2013-11-26 08:16 4243968 ----a-w- c:\windows\SysWow64\jscript9.dll
2013-12-10 20:09 . 2013-12-10 20:09 -------- d-----w- c:\program files (x86)\capcom
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-18 17:18 . 2013-11-11 19:11 84720 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-12-18 17:18 . 2013-11-11 19:11 131576 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-12-18 17:18 . 2013-11-11 19:11 108440 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-12-15 22:58 . 2011-07-18 20:31 90708896 ----a-w- c:\windows\system32\MRT.exe
2013-12-10 20:46 . 2012-07-13 08:11 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-12-10 20:46 . 2012-07-13 08:11 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-22 13:32 . 2013-11-22 13:32 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-11-22 13:32 . 2013-11-22 13:32 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-11-22 13:32 . 2013-11-22 13:32 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-11-22 13:32 . 2013-11-22 13:32 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2013-11-22 13:32 . 2013-11-22 13:32 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-11-22 13:32 . 2013-11-22 13:32 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2013-11-22 13:32 . 2013-11-22 13:32 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-11-22 13:32 . 2013-11-22 13:32 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2013-11-22 13:32 . 2013-11-22 13:32 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-11-22 13:32 . 2013-11-22 13:32 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-11-22 13:32 . 2013-11-22 13:32 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-11-22 13:32 . 2013-11-22 13:32 337408 ----a-w- c:\windows\SysWow64\html.iec
2013-11-22 13:32 . 2013-11-22 13:32 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-11-22 13:32 . 2013-11-22 13:32 235008 ----a-w- c:\windows\system32\elshyph.dll
2013-11-22 13:32 . 2013-11-22 13:32 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2013-11-22 13:32 . 2013-11-22 13:32 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-11-22 13:32 . 2013-11-22 13:32 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2013-11-22 13:32 . 2013-11-22 13:32 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2013-11-22 13:32 . 2013-11-22 13:32 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-11-22 13:32 . 2013-11-22 13:32 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-11-22 13:32 . 2013-11-22 13:32 942592 ----a-w- c:\windows\system32\jsIntl.dll
2013-11-22 13:32 . 2013-11-22 13:32 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-11-22 13:32 . 2013-11-22 13:32 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-11-22 13:32 . 2013-11-22 13:32 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-11-22 13:32 . 2013-11-22 13:32 84992 ----a-w- c:\windows\system32\mshtmled.dll
2013-11-22 13:32 . 2013-11-22 13:32 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-11-22 13:32 . 2013-11-22 13:32 81408 ----a-w- c:\windows\system32\icardie.dll
2013-11-22 13:32 . 2013-11-22 13:32 774144 ----a-w- c:\windows\system32\jscript.dll
2013-11-22 13:32 . 2013-11-22 13:32 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-11-22 13:32 . 2013-11-22 13:32 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-11-22 13:32 . 2013-11-22 13:32 626176 ----a-w- c:\windows\system32\msfeeds.dll
2013-11-22 13:32 . 2013-11-22 13:32 62464 ----a-w- c:\windows\system32\pngfilt.dll
2013-11-22 13:32 . 2013-11-22 13:32 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2013-11-22 13:32 . 2013-11-22 13:32 548352 ----a-w- c:\windows\system32\vbscript.dll
2013-11-22 13:32 . 2013-11-22 13:32 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-11-22 13:32 . 2013-11-22 13:32 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-11-22 13:32 . 2013-11-22 13:32 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-11-22 13:32 . 2013-11-22 13:32 48128 ----a-w- c:\windows\system32\imgutil.dll
2013-11-22 13:32 . 2013-11-22 13:32 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2013-11-22 13:32 . 2013-11-22 13:32 413696 ----a-w- c:\windows\system32\html.iec
2013-11-22 13:32 . 2013-11-22 13:32 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-11-22 13:32 . 2013-11-22 13:32 30208 ----a-w- c:\windows\system32\licmgr10.dll
2013-11-22 13:32 . 2013-11-22 13:32 296960 ----a-w- c:\windows\system32\dxtrans.dll
2013-11-22 13:32 . 2013-11-22 13:32 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2013-11-22 13:32 . 2013-11-22 13:32 247808 ----a-w- c:\windows\system32\msls31.dll
2013-11-22 13:32 . 2013-11-22 13:32 243200 ----a-w- c:\windows\system32\webcheck.dll
2013-11-22 13:32 . 2013-11-22 13:32 235520 ----a-w- c:\windows\system32\url.dll
2013-11-22 13:32 . 2013-11-22 13:32 195584 ----a-w- c:\windows\system32\msrating.dll
2013-11-22 13:32 . 2013-11-22 13:32 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-11-22 13:32 . 2013-11-22 13:32 147968 ----a-w- c:\windows\system32\occache.dll
2013-11-22 13:32 . 2013-11-22 13:32 143872 ----a-w- c:\windows\system32\wextract.exe
2013-11-22 13:32 . 2013-11-22 13:32 13824 ----a-w- c:\windows\system32\mshta.exe
2013-11-22 13:32 . 2013-11-22 13:32 135680 ----a-w- c:\windows\system32\iepeers.dll
2013-11-22 13:32 . 2013-11-22 13:32 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2013-11-22 13:32 . 2013-11-22 13:32 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-11-22 13:32 . 2013-11-22 13:32 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-11-22 13:32 . 2013-11-22 13:32 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-11-22 13:32 . 2013-11-22 13:32 105984 ----a-w- c:\windows\system32\iesysprep.dll
2013-11-22 13:32 . 2013-11-22 13:32 101376 ----a-w- c:\windows\system32\inseng.dll
2013-11-11 18:26 . 2013-11-03 19:48 59 ----a-w- c:\windows\system32\SupportTool.exe.bat
2013-10-14 17:00 . 2013-11-22 13:35 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
2013-10-12 02:30 . 2013-11-14 16:04 830464 ----a-w- c:\windows\system32\nshwfp.dll
2013-10-12 02:29 . 2013-11-14 16:04 859648 ----a-w- c:\windows\system32\IKEEXT.DLL
2013-10-12 02:29 . 2013-11-14 16:04 324096 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2013-10-12 02:03 . 2013-11-14 16:04 656896 ----a-w- c:\windows\SysWow64\nshwfp.dll
2013-10-12 02:01 . 2013-11-14 16:04 216576 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL
2013-10-10 18:14 . 2013-11-11 19:11 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-10-08 05:50 . 2013-10-20 20:08 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-10-05 20:25 . 2013-11-14 16:06 1474048 ----a-w- c:\windows\system32\crypt32.dll
2013-10-05 19:57 . 2013-11-14 16:06 1168384 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-10-04 02:28 . 2013-11-14 16:05 190464 ----a-w- c:\windows\system32\SmartcardCredentialProvider.dll
2013-10-04 02:25 . 2013-11-14 16:05 197120 ----a-w- c:\windows\system32\credui.dll
2013-10-04 02:24 . 2013-11-14 16:05 1930752 ----a-w- c:\windows\system32\authui.dll
2013-10-04 01:58 . 2013-11-14 16:05 152576 ----a-w- c:\windows\SysWow64\SmartcardCredentialProvider.dll
2013-10-04 01:56 . 2013-11-14 16:05 168960 ----a-w- c:\windows\SysWow64\credui.dll
2013-10-04 01:56 . 2013-11-14 16:05 1796096 ----a-w- c:\windows\SysWow64\authui.dll
2013-10-03 02:23 . 2013-11-14 16:04 404480 ----a-w- c:\windows\system32\gdi32.dll
2013-10-03 02:00 . 2013-11-14 16:04 311808 ----a-w- c:\windows\SysWow64\gdi32.dll
2013-09-28 01:09 . 2013-11-14 16:05 497152 ----a-w- c:\windows\system32\drivers\afd.sys
2013-09-25 02:26 . 2013-11-14 16:05 95680 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2013-09-25 02:26 . 2013-11-14 16:05 154560 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2013-09-25 02:23 . 2013-11-14 16:05 28672 ----a-w- c:\windows\system32\sspisrv.dll
2013-09-25 02:23 . 2013-11-14 16:05 135680 ----a-w- c:\windows\system32\sspicli.dll
2013-09-25 02:23 . 2013-11-14 16:05 28160 ----a-w- c:\windows\system32\secur32.dll
2013-09-25 02:22 . 2013-11-14 16:05 340992 ----a-w- c:\windows\system32\schannel.dll
2013-09-25 02:21 . 2013-11-14 16:05 307200 ----a-w- c:\windows\system32\ncrypt.dll
2013-09-25 02:21 . 2013-11-14 16:05 1447936 ----a-w- c:\windows\system32\lsasrv.dll
2013-09-25 01:58 . 2013-11-14 16:05 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2013-09-25 01:57 . 2013-11-14 16:05 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2013-09-25 01:57 . 2013-11-14 16:05 247808 ----a-w- c:\windows\SysWow64\schannel.dll
2013-09-25 01:56 . 2013-11-14 16:05 220160 ----a-w- c:\windows\SysWow64\ncrypt.dll
2013-09-25 01:03 . 2013-11-14 16:05 30720 ----a-w- c:\windows\system32\lsass.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}]
2013-12-20 19:28 12240 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" [2013-12-20 12240]
.
[HKEY_CLASSES_ROOT\clsid\{41564952-412d-5637-00a7-7a786e7484d7}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-01-08 18706176]
"HP Deskjet 3520 series (NET)"="c:\program files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe" [2012-01-31 2551656]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2012-02-29 56088]
"CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2010-08-03 107816]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-10-28 49208]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"ApnTBMon"="c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2013-12-20 1778640]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-12-18 684600]
.
c:\users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.4.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2012-8-13 1199104]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableSecureUIAPath"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
R2 Amsp;Trend Micro Solution Platform;c:\program files\Trend Micro\AMSP\coreServiceShell.exe coreFrameworkHost.exe;c:\program files\Trend Micro\AMSP\coreServiceShell.exe coreFrameworkHost.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8192su.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys;c:\windows\SYSNATIVE\DRIVERS\wsvd.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 TMEBC;TMEBC;c:\windows\system32\DRIVERS\TMEBC64.sys;c:\windows\SYSNATIVE\DRIVERS\TMEBC64.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 tmevtmgr;tmevtmgr;c:\windows\system32\DRIVERS\tmevtmgr.sys;c:\windows\SYSNATIVE\DRIVERS\tmevtmgr.sys [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x]
S2 APNMCP;Ask Aktualisierungsdienst;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [x]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x]
S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [x]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 MemeoBackgroundService;MemeoBackgroundService;c:\program files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe;c:\program files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe [x]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
S2 tmeevw;tmeevw;c:\windows\system32\DRIVERS\tmeevw.sys;c:\windows\SYSNATIVE\DRIVERS\tmeevw.sys [x]
S2 tmnciesc;tmnciesc;c:\windows\system32\DRIVERS\tmnciesc.sys;c:\windows\SYSNATIVE\DRIVERS\tmnciesc.sys [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\drivers\asmthub3.sys;c:\windows\SYSNATIVE\drivers\asmthub3.sys [x]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\drivers\asmtxhci.sys;c:\windows\SYSNATIVE\drivers\asmtxhci.sys [x]
S3 netr7364;RT73 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr7364.sys;c:\windows\SYSNATIVE\DRIVERS\netr7364.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{2D46B6DC-2207-486B-B523-A557E6D54B47}]
start [BU]
.
Inhalt des "geplante Tasks" Ordners
.
2013-12-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-13 20:46]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}]
2013-12-20 19:28 13776 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll" [2013-12-20 13776]
.
[HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-03-13 12452968]
"MedionReminder"="c:\program files (x86)\CyberLink\PowerRecover\Reminder.exe" [2012-05-10 430080]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392]
"Trend Micro Client Framework"="c:\program files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe" [2013-07-23 221584]
"Eraser"="c:\progra~1\Eraser\Eraser.exe" [2012-05-22 980920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"MedionReminder"="c:\program files (x86)\CyberLink\PowerRecover\Reminder.exe" [2012-05-10 430080]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4
TCP: DhcpNameServer = 192.168.2.1 192.168.2.1
FF - ProfilePath - c:\users\******\AppData\Roaming\Mozilla\Firefox\Profiles\d4khtsq6.default\
FF - ExtSQL: 2013-10-23 20:44; toolbar_AVIRA-V7@apn.ask.com; c:\users\******\AppData\Roaming\Mozilla\Firefox\Profiles\d4khtsq6.default\extensions\toolbar_AVIRA-V7@apn.ask.com.xpi
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-RocketDock - c:\program files (x86)\RocketDock\RocketDock.exe
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
c:\users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\simplicheck.lnk - c:\program files (x86)\simplitec\simplicheck\simplicheck.exe -timer
AddRemove-Mafia Game - c:\windows\system32\MafiaSetup.exe
AddRemove-Tomb Raider Chronicles - c:\windows\IsUn0407.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=hex:51,66,7a,6c,4c,1d,38,12,11,7f,11,
d0,78,5b,08,05,de,bb,01,03,dd,4c,30,54
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:7a,6b,8f,6c,71,17,ce,01
.
[HKEY_USERS\S-1-5-21-1427051060-1297858171-1060903477-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:84,c4,47,7d,45,6a,69,b3,ef,5e,a9,bf,88,96,a5,5b,f4,0f,1f,3f,6a,a2,0c,
06,b7,56,5c,9e,e7,79,de,c6,72,14,22,4c,4a,d4,ef,de,9a,06,f7,f6,82,c9,f4,11,\
"??"=hex:03,19,76,33,70,8c,2e,19,d1,71,a8,71,bc,15,cf,05
.
[HKEY_USERS\S-1-5-21-1427051060-1297858171-1060903477-1001\Software\SecuROM\License information*]
"datasecu"=hex:d9,e7,75,33,5a,91,14,dc,ca,bd,bd,4a,55,e0,c7,f4,ce,fc,8a,01,e1,
58,f1,d9,68,03,e6,f5,f8,da,d9,37,ae,dd,4f,a2,c2,2d,e7,b8,b1,7e,05,f3,71,b3,\
"rkeysecu"=hex:a3,a3,14,22,c9,8f,7d,a8,33,9c,b8,0d,03,72,a3,47
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-12-22 16:55:16
ComboFix-quarantined-files.txt 2013-12-22 15:55
ComboFix2.txt 2013-08-18 17:56
.
Vor Suchlauf: 12 Verzeichnis(se), 1.092.231.163.904 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 1.091.786.317.824 Bytes frei
.
- - End Of File - - C96B1AFAA3C096383E991A4E406BBE83 |