Vielen lieben Dank für die schnelle Antwort!
Ich habe combofix ausgeführt. Hab jedoch von Antivir, obwohl ich es beendet hatte, trotzdem ne Nachricht bekommen, dass was an der Registry gesperrt wurde.. Code:
ComboFix 14-01-29.01 - Jane 31.01.2014 9:42.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8175.6805 [GMT 1:00]
ausgeführt von:: d:\user\Jane\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-12-28 bis 2014-01-31 ))))))))))))))))))))))))))))))
.
.
2014-01-31 08:44 . 2014-01-31 08:44 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-01-31 08:44 . 2014-01-31 08:44 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-01-30 23:07 . 2014-01-30 23:08 -------- d-----w- C:\AdwCleaner
2014-01-30 22:43 . 2014-01-30 22:43 -------- d-----w- c:\users\Jane\AppData\Roaming\Malwarebytes
2014-01-30 22:43 . 2014-01-30 22:43 -------- d-----w- c:\programdata\Malwarebytes
2014-01-30 22:43 . 2014-01-30 22:43 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2014-01-30 22:43 . 2013-04-04 13:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-01-30 21:44 . 2014-01-30 21:44 -------- d-----w- c:\program files (x86)\ESET
2014-01-30 21:19 . 2014-01-30 23:49 -------- d-----w- C:\FRST
2014-01-27 13:29 . 2014-01-27 13:29 -------- d-----w- c:\program files\CCleaner
2014-01-22 12:59 . 2014-01-22 13:00 -------- d-----w- c:\users\Jane\AppData\Local\Amazon
2014-01-21 17:14 . 2014-01-21 17:14 -------- d-----w- c:\program files\McAfee Security Scan
2014-01-20 19:39 . 2014-01-20 19:39 -------- d--h--r- c:\users\Jane\AppData\Roaming\SecuROM
2014-01-20 19:14 . 2014-01-20 19:14 -------- d-----w- c:\programdata\EA Core
2014-01-20 18:57 . 2014-01-20 18:55 447752 ----a-w- c:\windows\SysWow64\vp6vfw.dll
2014-01-20 18:57 . 2014-01-20 18:57 -------- d-----w- c:\program files (x86)\Microsoft WSE
2014-01-19 18:41 . 2014-01-27 13:30 -------- d-----w- c:\program files (x86)\Steam
2014-01-19 18:41 . 2014-01-20 17:12 -------- d-----w- c:\program files (x86)\Common Files\Steam
2014-01-16 19:17 . 2014-01-16 19:17 -------- d-----w- c:\programdata\Oracle
2014-01-16 19:16 . 2014-01-16 19:16 -------- d-----w- c:\program files (x86)\Common Files\Java
2014-01-16 19:16 . 2014-01-16 19:16 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-01-16 19:16 . 2014-01-16 19:16 -------- d-----w- c:\program files (x86)\Java
2014-01-16 19:14 . 2014-01-16 19:14 -------- d-----w- c:\program files\PDF Split And Merge Basic
2014-01-16 17:14 . 2014-01-16 17:14 -------- d-----w- c:\programdata\McAfee
2014-01-16 17:14 . 2014-01-16 17:14 -------- d-----w- c:\programdata\McAfee Security Scan
2014-01-15 14:16 . 2013-11-27 01:41 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-01-15 14:16 . 2013-11-27 01:41 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-01-15 14:16 . 2013-11-27 01:41 53248 ----a-w- c:\windows\system32\drivers\usbehci.sys
2014-01-15 14:16 . 2013-11-27 01:41 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2014-01-15 14:16 . 2013-11-27 01:41 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2014-01-15 14:16 . 2013-11-27 01:41 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2014-01-15 14:16 . 2013-11-27 01:41 7808 ----a-w- c:\windows\system32\drivers\usbd.sys
2014-01-15 14:16 . 2013-11-26 11:40 376768 ----a-w- c:\windows\system32\drivers\netio.sys
2014-01-15 14:16 . 2013-11-26 10:32 3156480 ----a-w- c:\windows\system32\win32k.sys
2014-01-08 08:13 . 2014-01-08 08:17 -------- d-----w- c:\users\Arbeit
2014-01-06 19:36 . 2014-01-16 23:34 -------- d-----w- c:\users\Jane\AppData\Local\gtk-2.0
2014-01-06 18:32 . 2014-01-06 18:32 -------- d-----w- c:\users\Jane\.thumbnails
2014-01-06 18:25 . 2014-01-06 18:25 -------- d-----w- c:\users\Jane\AppData\Local\fontconfig
2014-01-06 18:25 . 2014-01-16 23:37 -------- d-----w- c:\users\Jane\.gimp-2.8
2014-01-06 18:25 . 2014-01-06 18:25 -------- d-----w- c:\users\Jane\AppData\Local\gegl-0.2
2014-01-06 18:23 . 2014-01-06 18:24 -------- d-----w- c:\program files\GIMP 2
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-16 17:14 . 2013-11-18 14:16 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-01-16 17:14 . 2013-11-18 14:16 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-01-16 00:54 . 2013-11-18 18:40 86054176 ----a-w- c:\windows\system32\MRT.exe
2013-12-18 10:07 . 2013-11-18 13:15 84720 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-12-18 10:07 . 2013-11-18 13:15 131576 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-12-18 10:07 . 2013-11-18 13:15 108440 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-11-26 11:54 . 2013-12-13 13:06 23183360 ----a-w- c:\windows\system32\mshtml.dll
2013-11-26 10:19 . 2013-12-13 13:06 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2013-11-26 10:18 . 2013-12-13 13:06 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2013-11-26 09:48 . 2013-12-13 13:06 66048 ----a-w- c:\windows\system32\iesetup.dll
2013-11-26 09:46 . 2013-12-13 13:06 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll
2013-11-26 09:41 . 2013-12-13 13:06 2764288 ----a-w- c:\windows\system32\iertutil.dll
2013-11-26 09:29 . 2013-12-13 13:06 53760 ----a-w- c:\windows\system32\jsproxy.dll
2013-11-26 09:27 . 2013-12-13 13:06 33792 ----a-w- c:\windows\system32\iernonce.dll
2013-11-26 09:23 . 2013-12-13 13:06 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-11-26 09:21 . 2013-12-13 13:06 574976 ----a-w- c:\windows\system32\ieui.dll
2013-11-26 09:18 . 2013-12-13 13:06 139264 ----a-w- c:\windows\system32\ieUnatt.exe
2013-11-26 09:18 . 2013-12-13 13:06 111616 ----a-w- c:\windows\system32\ieetwcollector.exe
2013-11-26 09:16 . 2013-12-13 13:06 708608 ----a-w- c:\windows\system32\jscript9diag.dll
2013-11-26 08:57 . 2013-12-13 13:06 218624 ----a-w- c:\windows\system32\ie4uinit.exe
2013-11-26 08:35 . 2013-12-13 13:06 5769216 ----a-w- c:\windows\system32\jscript9.dll
2013-11-26 08:28 . 2013-12-13 13:06 553472 ----a-w- c:\windows\SysWow64\jscript9diag.dll
2013-11-26 08:16 . 2013-12-13 13:06 4243968 ----a-w- c:\windows\SysWow64\jscript9.dll
2013-11-26 08:02 . 2013-12-13 13:06 1995264 ----a-w- c:\windows\system32\inetcpl.cpl
2013-11-26 07:48 . 2013-12-13 13:06 12996608 ----a-w- c:\windows\system32\ieframe.dll
2013-11-26 07:32 . 2013-12-13 13:06 1928192 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-11-26 07:07 . 2013-12-13 13:06 2334208 ----a-w- c:\windows\system32\wininet.dll
2013-11-26 06:40 . 2013-12-13 13:06 1395200 ----a-w- c:\windows\system32\urlmon.dll
2013-11-26 06:34 . 2013-12-13 13:06 817664 ----a-w- c:\windows\system32\ieapfltr.dll
2013-11-26 06:33 . 2013-12-13 13:06 1820160 ----a-w- c:\windows\SysWow64\wininet.dll
2013-11-25 23:56 . 2013-11-25 23:56 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-11-25 23:56 . 2013-11-25 23:56 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-11-25 23:56 . 2013-11-25 23:56 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-11-25 23:56 . 2013-11-25 23:56 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2013-11-25 23:56 . 2013-11-25 23:56 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-11-25 23:56 . 2013-11-25 23:56 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-11-25 23:56 . 2013-11-25 23:56 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-11-25 23:56 . 2013-11-25 23:56 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-11-25 23:56 . 2013-11-25 23:56 337408 ----a-w- c:\windows\SysWow64\html.iec
2013-11-25 23:56 . 2013-11-25 23:56 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-11-25 23:56 . 2013-11-25 23:56 235008 ----a-w- c:\windows\system32\elshyph.dll
2013-11-25 23:56 . 2013-11-25 23:56 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2013-11-25 23:56 . 2013-11-25 23:56 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-11-25 23:56 . 2013-11-25 23:56 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2013-11-25 23:56 . 2013-11-25 23:56 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-11-25 23:56 . 2013-11-25 23:56 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-11-25 23:56 . 2013-11-25 23:56 942592 ----a-w- c:\windows\system32\jsIntl.dll
2013-11-25 23:56 . 2013-11-25 23:56 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-11-25 23:56 . 2013-11-25 23:56 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-11-25 23:56 . 2013-11-25 23:56 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-11-25 23:56 . 2013-11-25 23:56 84992 ----a-w- c:\windows\system32\mshtmled.dll
2013-11-25 23:56 . 2013-11-25 23:56 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-11-25 23:56 . 2013-11-25 23:56 81408 ----a-w- c:\windows\system32\icardie.dll
2013-11-25 23:56 . 2013-11-25 23:56 774144 ----a-w- c:\windows\system32\jscript.dll
2013-11-25 23:56 . 2013-11-25 23:56 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-11-25 23:56 . 2013-11-25 23:56 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-11-25 23:56 . 2013-11-25 23:56 626176 ----a-w- c:\windows\system32\msfeeds.dll
2013-11-25 23:56 . 2013-11-25 23:56 62464 ----a-w- c:\windows\system32\pngfilt.dll
2013-11-25 23:56 . 2013-11-25 23:56 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2013-11-25 23:56 . 2013-11-25 23:56 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2013-11-25 23:56 . 2013-11-25 23:56 548352 ----a-w- c:\windows\system32\vbscript.dll
2013-11-25 23:56 . 2013-11-25 23:56 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-11-25 23:56 . 2013-11-25 23:56 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2013-11-25 23:56 . 2013-11-25 23:56 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-11-25 23:56 . 2013-11-25 23:56 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-11-25 23:56 . 2013-11-25 23:56 48128 ----a-w- c:\windows\system32\imgutil.dll
2013-11-25 23:56 . 2013-11-25 23:56 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2013-11-25 23:56 . 2013-11-25 23:56 413696 ----a-w- c:\windows\system32\html.iec
2013-11-25 23:56 . 2013-11-25 23:56 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-11-25 23:56 . 2013-11-25 23:56 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-11-25 23:56 . 2013-11-25 23:56 30208 ----a-w- c:\windows\system32\licmgr10.dll
2013-11-25 23:56 . 2013-11-25 23:56 296960 ----a-w- c:\windows\system32\dxtrans.dll
2013-11-25 23:56 . 2013-11-25 23:56 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2013-11-25 23:56 . 2013-11-25 23:56 247808 ----a-w- c:\windows\system32\msls31.dll
2013-11-25 23:56 . 2013-11-25 23:56 243200 ----a-w- c:\windows\system32\webcheck.dll
2013-11-25 23:56 . 2013-11-25 23:56 235520 ----a-w- c:\windows\system32\url.dll
2013-11-25 23:56 . 2013-11-25 23:56 195584 ----a-w- c:\windows\system32\msrating.dll
2013-11-25 23:56 . 2013-11-25 23:56 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-11-25 23:56 . 2013-11-25 23:56 147968 ----a-w- c:\windows\system32\occache.dll
2013-11-25 23:56 . 2013-11-25 23:56 143872 ----a-w- c:\windows\system32\wextract.exe
2013-11-25 23:56 . 2013-11-25 23:56 13824 ----a-w- c:\windows\system32\mshta.exe
2013-11-25 23:56 . 2013-11-25 23:56 135680 ----a-w- c:\windows\system32\iepeers.dll
2013-11-25 23:56 . 2013-11-25 23:56 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2013-11-25 23:56 . 2013-11-25 23:56 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2013-11-25 23:56 . 2013-11-25 23:56 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-11-25 23:56 . 2013-11-25 23:56 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-11-25 23:56 . 2013-11-25 23:56 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-11-25 23:56 . 2013-11-25 23:56 105984 ----a-w- c:\windows\system32\iesysprep.dll
2013-11-25 23:56 . 2013-11-25 23:56 101376 ----a-w- c:\windows\system32\inseng.dll
2013-11-23 18:26 . 2013-12-13 10:40 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-11-23 17:47 . 2013-12-13 10:40 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2013-11-21 10:29 . 2013-11-21 10:29 31136 ----a-w- c:\windows\SysWow64\drivers\HWiNFO64A.SYS
2013-11-18 23:05 . 2013-11-18 23:05 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-11-18 23:05 . 2013-11-18 23:05 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-11-18 23:05 . 2013-11-18 23:05 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2013-11-18 23:05 . 2013-11-18 23:05 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2013-11-18 23:05 . 2013-11-18 23:05 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-11-18 23:05 . 2013-11-18 23:05 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-11-18 23:05 . 2013-11-18 23:05 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-11-18 23:05 . 2013-11-18 23:05 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GAINWARD"="c:\program files (x86)\EXPERTool\TBPanel.exe" [2010-12-23 2259568]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2012-09-12 56128]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-12-18 684600]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
c:\users\Jane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Samsung Magician.lnk - c:\program files (x86)\Samsung\Samsung Magician\Samsung Magician.exe /AUTOHIDE [2013-11-21 4351392]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.8.130\SSScheduler.exe [2013-9-6 324320]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer8"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 LVUVC64;Logitech HD Webcam C270(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.8.130\McCHSvc.exe;c:\program files\McAfee Security Scan\3.8.130\McCHSvc.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x]
R4 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorA.sys [x]
S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorF.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage-Technologie;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2014-01-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-18 17:14]
.
2014-01-30 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1956929518-3918672675-1206063416-1000Core.job
- c:\users\Jane\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-11-24 22:39]
.
2014-01-30 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1956929518-3918672675-1206063416-1000UA.job
- c:\users\Jane\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-11-24 22:39]
.
.
--------- X64 Entries -----------
.
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = www.bing.com
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 131.114.21.25 131.114.21.15
FF - ProfilePath - c:\users\Jane\AppData\Roaming\Mozilla\Firefox\Profiles\1ycs7ioo.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1956929518-3918672675-1206063416-1000\Software\SecuROM\License information*]
"datasecu"=hex:8b,44,ca,7f,b0,04,5b,7c,50,42,a3,0a,68,f0,13,e7,b3,61,11,0d,16,
27,37,20,61,86,8c,07,4f,1b,d9,58,c5,56,ec,f6,c4,c6,b9,02,f9,0b,4c,50,5d,23,\
"rkeysecu"=hex:23,4d,f3,03,7d,fc,e8,57,20,72,a6,fc,d9,9b,7c,d3
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-01-31 09:45:30
ComboFix-quarantined-files.txt 2014-01-31 08:45
.
Vor Suchlauf: 9 Verzeichnis(se), 74.146.967.552 Bytes frei
Nach Suchlauf: 12 Verzeichnis(se), 73.936.175.104 Bytes frei
.
- - End Of File - - 5DEC82BEF5B51DACFDFFDA613C7D683D Wie konnte ich mich eigentlich an nur ner Textdatei infizieren? Was hab ich falsch gemacht? :-/
Edit: Mein Desktopordner liegt auf der D, das gehört so.. hab wegen der SSD Teile meiner eigenen dokumente auf die D verschoben.
Ich habe nun auch den Laptop der besagten Freundin, soll ich dafür einen neuen Thread aufmachen oder das hier machen?
Liebe Grüße und ich hoff bei meinem Pc ist die Infektion noch ned so schlimm :-/ |