Ok, zuerst
Fixlog.txt: Code:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 29-12-2013 01
Ran by Karel at 2013-12-31 09:23:31 Run:1
Running from C:\Users\Karel\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
*****************
"C:\Program Files\Windows Defender" => Deleting reparse point and unlocking started.
"C:\Program Files\Windows Defender\de-DE" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpAsDesc.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpClient.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpCmdRun.exe" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpCommu.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpEvMsg.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpOAV.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpRTP.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpSvc.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MSASCui.exe" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MsMpCom.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MsMpLics.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MsMpRes.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender" => Deleting reparse point and unlocking completed.
==== End of Fixlog ====
Combofix.txt: Code:
Combofix Logfile:
Code:
ComboFix 13-12-29.01 - Karel 31.12.2013 9:31.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3000.1739 [GMT 1:00]
ausgeführt von:: c:\users\Karel\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Google\Desktop\Install
c:\program files\Google\Desktop\Install\{c42bd6ab-a235-dbfa-7d01-4bc83f06ff5b}\9519~1\A535~1\E628~1\{c42bd6ab-a235-dbfa-7d01-4bc83f06ff5b}\@
c:\program files\Google\Desktop\Install\{c42bd6ab-a235-dbfa-7d01-4bc83f06ff5b}\9519~1\A535~1\E628~1\{c42bd6ab-a235-dbfa-7d01-4bc83f06ff5b}\U\00000001.@
c:\program files\Google\Desktop\Install\{c42bd6ab-a235-dbfa-7d01-4bc83f06ff5b}\9519~1\A535~1\E628~1\{c42bd6ab-a235-dbfa-7d01-4bc83f06ff5b}\U\00000002.@
c:\program files\Google\Desktop\Install\{c42bd6ab-a235-dbfa-7d01-4bc83f06ff5b}\9519~1\A535~1\E628~1\{c42bd6ab-a235-dbfa-7d01-4bc83f06ff5b}\U\80000000.@
c:\program files\Google\Desktop\Install\{c42bd6ab-a235-dbfa-7d01-4bc83f06ff5b}\9519~1\A535~1\E628~1\{c42bd6ab-a235-dbfa-7d01-4bc83f06ff5b}\U\800000cb.@
c:\programdata\5C539ED5A6.sys
C:\Thumbs.db
c:\users\Karel\4.0
c:\users\Karel\AppData\Local\Google\Desktop\Install
c:\users\Karel\AppData\Local\Google\Desktop\Install\{c42bd6ab-a235-dbfa-7d01-4bc83f06ff5b}\2E2F~1\28F0~1\E628~1\{c42bd6ab-a235-dbfa-7d01-4bc83f06ff5b}\@
c:\users\Karel\AppData\Roaming\01003.128
c:\users\Karel\AppData\Roaming\01003.128\chrome.manifest
c:\users\Karel\AppData\Roaming\01003.128\components\AcroFF.txt
c:\users\Karel\AppData\Roaming\01003.128\install.rdf
c:\users\Karel\AppData\Roaming\AcroIEHelpe.txt
c:\users\Karel\AppData\Roaming\Microsoft\Windows\Recent\Artmann, Peter.URL
c:\users\Karel\AppData\Roaming\Microsoft\Windows\Recent\Haus CO.zip.URL
c:\users\Karel\AppData\Roaming\Microsoft\Windows\Recent\P1010420.JPG.URL
c:\users\Karel\AppData\Roaming\srvblck5.tmp
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-11-28 bis 2013-12-31 ))))))))))))))))))))))))))))))
.
.
2013-12-31 08:43 . 2013-12-31 08:47 -------- d-----w- c:\users\Karel\AppData\Local\temp
2013-12-31 08:43 . 2013-12-31 08:43 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-30 12:51 . 2013-12-30 12:51 -------- d-----w- C:\FRST
2013-12-29 14:18 . 2013-12-30 12:47 -------- d-----w- c:\programdata\Kaspersky Lab
2013-12-29 13:59 . 2010-08-19 18:22 409600 ----a-w- c:\users\Karel\rescue2usb.exe
2013-12-29 13:59 . 2010-04-01 10:01 28160 ----a-w- c:\users\Karel\syslinux.exe
2013-12-29 13:59 . 2009-10-16 15:43 237849 ----a-w- c:\users\Karel\grub.exe
2013-12-29 13:23 . 2013-12-29 13:24 -------- d-----w- c:\program files\Microsoft Mouse and Keyboard Center
2013-12-29 13:18 . 2013-12-29 13:18 -------- d-----w- c:\windows\Migration
2013-12-29 13:15 . 2012-05-04 09:59 514560 ----a-w- c:\windows\system32\qdvd.dll
2013-12-29 13:10 . 2013-12-29 13:10 165160 ----a-w- c:\windows\system32\SynTPAPI.dll
2013-12-29 13:10 . 2013-12-29 13:10 1303728 ----a-w- c:\windows\system32\drivers\SynTP.sys
2013-12-29 13:10 . 2013-12-29 13:10 214312 ----a-w- c:\windows\system32\SynCtrl.dll
2013-12-29 13:10 . 2013-12-29 13:10 173352 ----a-w- c:\windows\system32\SynCOM.dll
2013-12-29 13:07 . 2013-12-29 13:06 531968 ------w- c:\windows\system32\stapi32.dll
2013-12-29 13:07 . 2013-12-29 13:06 380928 ----a-w- c:\windows\system32\aestecap.dll
2013-12-29 13:07 . 2013-12-29 13:06 61440 ----a-w- c:\windows\system32\aestaren.dll
2013-12-29 13:07 . 2013-12-29 13:06 140288 ----a-w- c:\windows\system32\aestacap.dll
2013-12-29 13:07 . 2013-12-29 13:06 86016 ----a-w- c:\windows\system32\AESTCom.dll
2013-12-29 13:07 . 2013-12-29 13:06 495708 ----a-w- c:\windows\sttray.exe
2013-12-29 13:07 . 2013-12-29 13:06 1953792 ----a-w- c:\windows\system32\stlang.dll
2013-12-29 13:07 . 2013-12-29 13:06 12705884 ----a-w- c:\windows\system32\idtcpl.cpl
2013-12-29 13:07 . 2013-12-29 13:06 179712 ----a-w- c:\windows\system32\staco.dll
2013-12-29 13:06 . 2013-12-29 13:06 934912 ----a-w- c:\windows\system32\stapo.dll
2013-12-29 13:06 . 2013-12-29 13:06 431616 ----a-w- c:\windows\system32\drivers\stwrt.sys
2013-12-29 13:06 . 2013-12-29 13:06 405504 ----a-w- c:\windows\system32\stcplx.dll
2013-12-29 12:24 . 2013-12-29 12:26 -------- d-----w- C:\AdwCleaner
2013-12-28 19:47 . 2013-12-28 19:50 -------- d-----w- c:\windows\system32\MRT
2013-12-28 19:43 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2013-12-28 19:43 . 2013-05-10 03:48 164864 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2013-12-28 19:39 . 2013-12-28 19:39 640512 ----a-w- c:\windows\system32\advapi32.dll
2013-12-28 19:39 . 2013-12-28 19:39 619520 ----a-w- c:\windows\system32\tdh.dll
2013-12-28 19:39 . 2013-12-28 19:39 3969472 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-12-28 19:39 . 2013-12-28 19:39 3914176 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-12-28 19:39 . 2013-12-28 19:39 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-12-28 19:39 . 2013-12-28 19:39 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-12-28 19:39 . 2013-12-28 19:39 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2013-12-28 19:39 . 2013-12-28 19:39 231424 ----a-w- c:\windows\system32\mswsock.dll
2013-12-28 18:44 . 2013-12-28 18:44 -------- d-----w- c:\users\Karel\AppData\Roaming\AVG2014
2013-12-28 18:43 . 2013-12-28 18:43 -------- d-----w- c:\programdata\AVG2014
2013-12-28 18:43 . 2013-12-28 18:43 -------- d-----w- C:\$AVG
2013-12-28 18:43 . 2013-12-28 18:43 -------- d-----w- c:\program files\AVG
2013-12-28 18:38 . 2013-12-31 08:08 -------- d-----w- c:\programdata\MFAData
2013-12-28 18:38 . 2013-12-28 18:50 -------- d-----w- c:\users\Karel\AppData\Local\Avg2014
2013-12-28 18:38 . 2013-12-28 18:38 -------- d-----w- c:\users\Karel\AppData\Local\MFAData
2013-12-28 17:27 . 2013-12-28 17:27 -------- d-----w- C:\Intel
2013-12-28 14:33 . 2013-12-28 14:33 -------- d-----w- c:\programdata\Oracle
2013-12-28 14:33 . 2013-12-28 14:33 -------- d-----w- c:\program files\Common Files\Java
2013-12-28 14:32 . 2013-12-28 14:32 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-12-28 14:30 . 2013-12-28 18:43 -------- d-----w- c:\users\Karel\AppData\Roaming\TuneUp Software
2013-12-28 14:29 . 2013-12-28 17:55 -------- d-----w- c:\program files\TuneUp Utilities 2014
2013-12-28 14:29 . 2013-12-28 14:39 -------- d-----w- c:\programdata\TuneUp Software
2013-12-28 14:29 . 2013-12-28 15:08 -------- d-sh--w- c:\programdata\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2013-12-28 14:29 . 2013-12-28 14:29 -------- d--h--w- c:\programdata\Common Files
2013-12-28 10:46 . 2013-12-28 10:46 -------- d-----w- c:\users\Karel\AppData\Roaming\Malwarebytes
2013-12-28 10:46 . 2013-12-28 10:46 -------- d-----w- c:\programdata\Malwarebytes
2013-12-28 10:46 . 2013-12-28 10:46 -------- d-----w- c:\users\Karel\AppData\Local\Programs
2013-12-18 06:44 . 2013-12-18 06:44 -------- d-----w- c:\users\Karel\AppData\Local\Macromedia
2013-12-17 20:03 . 2013-12-17 20:03 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-12-10 14:37 . 2013-12-28 19:42 -------- d-----w- c:\windows\Logs
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-29 13:10 . 2010-01-22 18:25 120104 ----a-w- c:\windows\system32\SynTPCo4.dll
2013-12-17 20:03 . 2012-03-20 18:54 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-11-05 20:50 . 2013-11-05 20:50 120600 ----a-w- c:\windows\system32\drivers\avgdiskx.sys
2013-11-04 20:57 . 2013-11-04 20:57 209176 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2013-10-31 22:00 . 2013-10-31 22:00 176952 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2013-10-31 21:30 . 2013-10-31 21:30 222520 ----a-w- c:\windows\system32\drivers\avglogx.sys
2013-10-24 21:28 . 2013-10-24 21:28 147768 ----a-w- c:\windows\system32\drivers\avgidshx.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QLBController"="c:\program files\Hewlett-Packard\HP HotKey Support\QLBController.exe" [2010-01-28 256056]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2010-01-08 186904]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2010-01-12 563736]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2013-12-29 1791272]
"WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-09-01 499768]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-03-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-03-12 175640]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-03-12 166936]
"PDFHook"="c:\program files\Nuance\PDF Professional 6\pdfpro6hook.exe" [2009-11-13 1277952]
"PDF6 Registry Controller"="c:\program files\Nuance\PDF Professional 6\RegistryController.exe" [2009-11-03 110880]
"NortonOnlineBackupReminder"="c:\program files\Symantec\Norton Online Backup\Activation\NOBuActivation.exe" [2009-12-03 3331944]
"NSU_agent"="c:\program files\Nokia\Nokia Software Updater\nsu3ui_agent.exe" [2012-02-28 190768]
"AVG_UI"="c:\program files\AVG\AVG2014\avgui.exe" [2013-11-07 4956176]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2013-12-29 495708]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"NCPluginUpdater"="c:\program files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" [2013-12-12 21720]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableVirtualization"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\users\Karel\AppData\Local\Google\Desktop\Install\{c42bd6ab-a235-dbfa-7d01-4bc83f06ff5b}\???\???\???\{c42bd6ab-a235-dbfa-7d01-4bc83f06ff5b}\GoogleUpdate.exe" >
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Nuance PDF Reader-reminder"="c:\program files\Nuance\PDF Reader\Ereg\Ereg.exe" -r "c:\programdata\Nuance\PDF Reader\Ereg\Ereg.ini"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-18 639224]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2013-11-26 108032]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl.sys [2010-04-19 18432]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-11-23 1120752]
R3 rtl819xp;Realtek RTL8190/RTL8192E 802.11n Wireless LAN (Mini-) PCI NIC-NT-Treiber;c:\windows\system32\DRIVERS\rtl819xp.sys [2010-02-01 557088]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S0 AVGIDSHX;AVGIDSHX;c:\windows\system32\DRIVERS\avgidshx.sys [2013-10-24 147768]
S0 Avglogx;AVG Logging Driver;c:\windows\system32\DRIVERS\avglogx.sys [2013-10-31 222520]
S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2013-09-09 27448]
S1 Avgdiskx;AVG Disk Driver;c:\windows\system32\DRIVERS\avgdiskx.sys [2013-11-05 120600]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdriverx.sys [2013-11-04 209176]
S1 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\avgidsshimx.sys [2013-09-16 22840]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2013-10-31 176952]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2013-08-01 193848]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\aestsrv.exe [2013-12-29 81920]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2014\avgidsagent.exe [2013-11-11 3478544]
S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2014\avgwdsvc.exe [2013-09-24 348008]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2012-09-27 86528]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2012-08-10 197536]
S2 hpHotkeyMonitor;HP Hotkey Monitor;c:\program files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [2010-01-28 265272]
S2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [2010-01-12 635416]
S2 PDFProFiltSrv;PDFProFiltSrv;c:\program files\Nuance\PDF Professional 6\PDFProFiltSrv.exe [2009-11-03 134944]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-01-07 29472]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2009-07-09 122880]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2011-06-10 394856]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [2011-09-08 1117800]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-01-22 18:06 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-12-31 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3067011553-2313972656-3019485188-1002Core.job
- c:\users\Karel\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-07 06:46]
.
2013-12-31 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3067011553-2313972656-3019485188-1002UA.job
- c:\users\Karel\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-07 06:46]
.
2013-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-03-13 19:02]
.
2013-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-03-13 19:02]
.
2013-12-29 c:\windows\Tasks\HPCeeScheduleForKarel.job
- c:\program files\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05 10:53]
.
.
------- Zusätzlicher Suchlauf -------
.
IE: Mit Nuance PDF Converter 6.0 öffnen - c:\program files\Nuance\PDF Professional 6\cnvres_ger.dll /100
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //FWEvent.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{43120BA0-0FFC-4941-87CA-2D0D88590447}: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Karel\AppData\Roaming\Mozilla\Firefox\Profiles\nhycx0g9.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: keyword.URL - hxxp://go.web.de/tb/mff_keyurl_search/?su=
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-{EE202411-2C26-49E8-9784-1BC1DBF7DE96} - c:\program files\InstallShield Installation Information\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{E3286BF1-E654-42FF-B4A6-5E111731DF6B}"=hex:51,66,7a,6c,4c,1d,38,12,9f,68,3b,
e7,66,a8,91,07,cb,b0,1d,51,12,6f,9b,7f
"{21FA44EF-376D-4D53-9B0F-8A89D3229068}"=hex:51,66,7a,6c,4c,1d,38,12,81,47,e9,
25,5f,79,3d,08,e4,19,c9,c9,d6,7c,d4,7c
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{551A852F-39A6-44A7-9C13-AFBEC9185A9D}"=hex:51,66,7a,6c,4c,1d,38,12,41,86,09,
51,94,77,c9,01,e3,05,ec,fe,cc,46,1e,89
"{6EBF7485-159F-4BFF-A14F-B9E3AAC4465B}"=hex:51,66,7a,6c,4c,1d,38,12,eb,77,ac,
6a,ad,5b,91,0e,de,59,fa,a3,af,9a,02,4f
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9}"=hex:51,66,7a,6c,4c,1d,38,12,13,6e,8b,
de,9d,82,dc,02,fb,e8,fc,e1,51,c5,af,ed
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}"=hex:51,66,7a,6c,4c,1d,38,12,ae,8e,49,
e5,24,cb,cf,07,fe,fc,9f,d4,e9,44,8b,04
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:df,5e,f7,fb,ee,cf,ce,01
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(4008)
c:\program files\Hewlett-Packard\HP Support Framework\Resources\HPSFMessenger\HPSFTaskbar.dll
c:\program files\WIDCOMM\Bluetooth Software\btncopy.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\progra~1\AVG\AVG2014\avgrsx.exe
c:\program files\AVG\AVG2014\avgcsrvx.exe
c:\program files\IDT\WDM\STacSV.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\btwdins.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\windows\system32\taskhost.exe
c:\program files\Microsoft Mouse and Keyboard Center\itype.exe
c:\program files\Microsoft Mouse and Keyboard Center\ipoint.exe
c:\program files\AVG\AVG2014\avgnsx.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\windows\system32\conhost.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Hewlett-Packard\Shared\hpqToaster.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-12-31 10:00:56 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2013-12-31 09:00
.
Vor Suchlauf: 16 Verzeichnis(se), 398.026.366.976 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 398.185.349.120 Bytes frei
.
- - End Of File - - D6535197175664CEC04846524DB8D794 --- --- ---
5C616939100B85E558DA92B899A0FC36 |