Roberto1 | 02.02.2014 10:49 | Hier der Combofix log Code:
ComboFix 14-02-01.01 - Juve1 02.02.2014 9:15.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.4014.1594 [GMT 1:00]
ausgeführt von:: c:\users\Juve1\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
FW: Kaspersky Internet Security *Disabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}
SP: Kaspersky Internet Security *Disabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Juve1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Firefox.lnk
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-01-02 bis 2014-02-02 ))))))))))))))))))))))))))))))
.
.
2014-02-02 09:17 . 2014-02-02 09:17 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-02-02 09:17 . 2014-02-02 09:17 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-02-01 15:12 . 2014-02-01 15:15 -------- d-----w- C:\FRST
2014-01-26 10:03 . 2014-01-28 22:12 -------- d-----w- C:\WhatsApp
2014-01-24 14:16 . 2014-01-24 14:16 -------- d-----w- c:\windows\LastGood
2014-01-23 21:23 . 2014-01-23 21:23 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{67571C3D-3011-42D7-AB1F-299AF28D2401}\offreg.dll
2014-01-22 07:52 . 2014-01-22 07:52 206080 ----a-w- c:\windows\system32\drivers\ssudmdm.sys
2014-01-22 07:52 . 2014-01-22 07:52 108800 ----a-w- c:\windows\system32\drivers\ssudbus.sys
2014-01-21 22:23 . 2014-01-21 22:23 -------- d-----w- C:\Neuer Ordner
2014-01-21 19:25 . 2014-01-21 19:26 -------- d-----w- C:\samu neu
2014-01-16 23:08 . 2013-12-18 20:09 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-01-15 11:58 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{67571C3D-3011-42D7-AB1F-299AF28D2401}\mpengine.dll
2014-01-15 11:52 . 2013-11-27 01:41 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-01-15 11:52 . 2013-11-27 01:41 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-01-15 11:52 . 2013-11-27 01:41 53248 ----a-w- c:\windows\system32\drivers\usbehci.sys
2014-01-15 11:52 . 2013-11-27 01:41 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2014-01-15 11:52 . 2013-11-27 01:41 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2014-01-15 11:52 . 2013-11-27 01:41 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2014-01-15 11:52 . 2013-11-27 01:41 7808 ----a-w- c:\windows\system32\drivers\usbd.sys
2014-01-15 11:52 . 2013-11-26 10:32 3156480 ----a-w- c:\windows\system32\win32k.sys
2014-01-15 11:52 . 2013-11-26 11:40 376768 ----a-w- c:\windows\system32\drivers\netio.sys
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-15 11:53 . 2013-01-19 00:50 86054176 ----a-w- c:\windows\system32\MRT.exe
2013-12-11 08:55 . 2012-08-02 13:09 29792 ----a-w- c:\windows\system32\drivers\klim6.sys
2013-12-11 08:55 . 2012-06-19 15:28 458336 ----a-w- c:\windows\system32\drivers\kl1.sys
2013-12-11 08:50 . 2013-01-19 22:30 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-12-11 08:50 . 2013-01-19 22:30 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-11-26 11:54 . 2013-12-17 06:40 23183360 ----a-w- c:\windows\system32\mshtml.dll
2013-11-26 11:25 . 2013-01-18 23:05 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-11-26 10:19 . 2013-12-17 06:40 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2013-11-26 10:18 . 2013-12-17 06:40 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2013-11-26 09:48 . 2013-12-17 06:40 66048 ----a-w- c:\windows\system32\iesetup.dll
2013-11-26 09:46 . 2013-12-17 06:40 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll
2013-11-26 09:41 . 2013-12-17 06:40 2764288 ----a-w- c:\windows\system32\iertutil.dll
2013-11-26 09:29 . 2013-12-17 06:40 53760 ----a-w- c:\windows\system32\jsproxy.dll
2013-11-26 09:27 . 2013-12-17 06:40 33792 ----a-w- c:\windows\system32\iernonce.dll
2013-11-26 09:23 . 2013-12-17 06:40 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-11-26 09:21 . 2013-12-17 06:40 574976 ----a-w- c:\windows\system32\ieui.dll
2013-11-26 09:18 . 2013-12-17 06:40 139264 ----a-w- c:\windows\system32\ieUnatt.exe
2013-11-26 09:18 . 2013-12-17 06:40 111616 ----a-w- c:\windows\system32\ieetwcollector.exe
2013-11-26 09:16 . 2013-12-17 06:40 708608 ----a-w- c:\windows\system32\jscript9diag.dll
2013-11-26 08:57 . 2013-12-17 06:40 218624 ----a-w- c:\windows\system32\ie4uinit.exe
2013-11-26 08:35 . 2013-12-17 06:40 5769216 ----a-w- c:\windows\system32\jscript9.dll
2013-11-26 08:28 . 2013-12-17 06:40 553472 ----a-w- c:\windows\SysWow64\jscript9diag.dll
2013-11-26 08:16 . 2013-12-17 06:40 4243968 ----a-w- c:\windows\SysWow64\jscript9.dll
2013-11-26 08:02 . 2013-12-17 06:40 1995264 ----a-w- c:\windows\system32\inetcpl.cpl
2013-11-26 07:48 . 2013-12-17 06:40 12996608 ----a-w- c:\windows\system32\ieframe.dll
2013-11-26 07:32 . 2013-12-17 06:40 1928192 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-11-26 07:07 . 2013-12-17 06:40 2334208 ----a-w- c:\windows\system32\wininet.dll
2013-11-26 06:40 . 2013-12-17 06:40 1395200 ----a-w- c:\windows\system32\urlmon.dll
2013-11-26 06:34 . 2013-12-17 06:40 817664 ----a-w- c:\windows\system32\ieapfltr.dll
2013-11-26 06:33 . 2013-12-17 06:40 1820160 ----a-w- c:\windows\SysWow64\wininet.dll
2013-11-23 18:26 . 2013-12-17 06:33 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-11-23 17:47 . 2013-12-17 06:33 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2013-11-12 02:23 . 2013-12-17 06:33 2048 ----a-w- c:\windows\system32\tzres.dll
2013-11-12 02:07 . 2013-12-17 06:33 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2013-11-08 15:02 . 2013-11-08 15:02 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-11-08 15:02 . 2013-11-08 15:02 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-11-08 15:02 . 2013-11-08 15:02 942592 ----a-w- c:\windows\system32\jsIntl.dll
2013-11-08 15:02 . 2013-11-08 15:02 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-11-08 15:02 . 2013-11-08 15:02 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-11-08 15:02 . 2013-11-08 15:02 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-11-08 15:02 . 2013-11-08 15:02 84992 ----a-w- c:\windows\system32\mshtmled.dll
2013-11-08 15:02 . 2013-11-08 15:02 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-11-08 15:02 . 2013-11-08 15:02 81408 ----a-w- c:\windows\system32\icardie.dll
2013-11-08 15:02 . 2013-11-08 15:02 774144 ----a-w- c:\windows\system32\jscript.dll
2013-11-08 15:02 . 2013-11-08 15:02 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-11-08 15:02 . 2013-11-08 15:02 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-11-08 15:02 . 2013-11-08 15:02 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-11-08 15:02 . 2013-11-08 15:02 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2013-11-08 15:02 . 2013-11-08 15:02 626176 ----a-w- c:\windows\system32\msfeeds.dll
2013-11-08 15:02 . 2013-11-08 15:02 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-11-08 15:02 . 2013-11-08 15:02 62464 ----a-w- c:\windows\system32\pngfilt.dll
2013-11-08 15:02 . 2013-11-08 15:02 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2013-11-08 15:02 . 2013-11-08 15:02 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-11-08 15:02 . 2013-11-08 15:02 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2013-11-08 15:02 . 2013-11-08 15:02 548352 ----a-w- c:\windows\system32\vbscript.dll
2013-11-08 15:02 . 2013-11-08 15:02 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-11-08 15:02 . 2013-11-08 15:02 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2013-11-08 15:02 . 2013-11-08 15:02 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-11-08 15:02 . 2013-11-08 15:02 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-11-08 15:02 . 2013-11-08 15:02 48128 ----a-w- c:\windows\system32\imgutil.dll
2013-11-08 15:02 . 2013-11-08 15:02 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-11-08 15:02 . 2013-11-08 15:02 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2013-11-08 15:02 . 2013-11-08 15:02 413696 ----a-w- c:\windows\system32\html.iec
2013-11-08 15:02 . 2013-11-08 15:02 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-11-08 15:02 . 2013-11-08 15:02 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-11-08 15:02 . 2013-11-08 15:02 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-11-08 15:02 . 2013-11-08 15:02 337408 ----a-w- c:\windows\SysWow64\html.iec
2013-11-08 15:02 . 2013-11-08 15:02 30208 ----a-w- c:\windows\system32\licmgr10.dll
2013-11-08 15:02 . 2013-11-08 15:02 296960 ----a-w- c:\windows\system32\dxtrans.dll
2013-11-08 15:02 . 2013-11-08 15:02 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2013-11-08 15:02 . 2013-11-08 15:02 247808 ----a-w- c:\windows\system32\msls31.dll
2013-11-08 15:02 . 2013-11-08 15:02 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-11-08 15:02 . 2013-11-08 15:02 243200 ----a-w- c:\windows\system32\webcheck.dll
2013-11-08 15:02 . 2013-11-08 15:02 235520 ----a-w- c:\windows\system32\url.dll
2013-11-08 15:02 . 2013-11-08 15:02 235008 ----a-w- c:\windows\system32\elshyph.dll
2013-11-08 15:02 . 2013-11-08 15:02 195584 ----a-w- c:\windows\system32\msrating.dll
2013-11-08 15:02 . 2013-11-08 15:02 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2013-11-08 15:02 . 2013-11-08 15:02 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-11-08 15:02 . 2013-11-08 15:02 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-11-08 15:02 . 2013-11-08 15:02 147968 ----a-w- c:\windows\system32\occache.dll
2013-11-08 15:02 . 2013-11-08 15:02 143872 ----a-w- c:\windows\system32\wextract.exe
2013-11-08 15:02 . 2013-11-08 15:02 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2013-11-08 15:02 . 2013-11-08 15:02 13824 ----a-w- c:\windows\system32\mshta.exe
2013-11-08 15:02 . 2013-11-08 15:02 135680 ----a-w- c:\windows\system32\iepeers.dll
2013-11-08 15:02 . 2013-11-08 15:02 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2013-11-08 15:02 . 2013-11-08 15:02 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2013-11-08 15:02 . 2013-11-08 15:02 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-11-08 15:02 . 2013-11-08 15:02 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-11-08 15:02 . 2013-11-08 15:02 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-11-08 15:02 . 2013-11-08 15:02 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-11-08 15:02 . 2013-11-08 15:02 105984 ----a-w- c:\windows\system32\iesysprep.dll
2013-11-08 15:02 . 2013-11-08 15:02 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-11-08 15:02 . 2013-11-08 15:02 101376 ----a-w- c:\windows\system32\inseng.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2013-12-11 1564528]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2014-01-17 759496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2013-12-11 311152]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe" [2013-10-10 356128]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2009-11-30 18:20 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe"
"MarketingTools"=c:\program files (x86)\Sony\Marketing Tools\MarketingTools.exe
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe;c:\program files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys;c:\windows\SYSNATIVE\drivers\btusbflt.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\SysWOW64\FsUsbExDisk.SYS;c:\windows\SysWOW64\FsUsbExDisk.SYS [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 libusb0;libusb-win32 - Kernel Driver 03/24/2013 0.0.0.0;c:\windows\system32\DRIVERS\libusb0.sys;c:\windows\SYSNATIVE\DRIVERS\libusb0.sys [x]
R3 McComponentHostServiceSony;McAfee Security Scan Component Host Service for Sony;c:\program files (x86)\Sony\MSS\3.0.271\McCHSvc.exe;c:\program files (x86)\Sony\MSS\3.0.271\McCHSvc.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe;c:\program files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x]
S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys;c:\windows\SYSNATIVE\drivers\npf.sys [x]
S2 regi;regi;c:\windows\system32\drivers\regi.sys;c:\windows\SYSNATIVE\drivers\regi.sys [x]
S2 rimspci;rimspci;c:\windows\system32\drivers\rimssne64.sys;c:\windows\SYSNATIVE\drivers\rimssne64.sys [x]
S2 risdsnpe;risdsnpe;c:\windows\system32\drivers\risdsne64.sys;c:\windows\SYSNATIVE\drivers\risdsne64.sys [x]
S2 SampleCollector;VAIO Care Performance Service;c:\program files\Sony\VAIO Care\VCPerfService.exe;c:\program files\Sony\VAIO Care\VCPerfService.exe [x]
S2 VSNService;VSNService;c:\program files\Sony\VAIO Smart Network\VSNService.exe;c:\program files\Sony\VAIO Smart Network\VSNService.exe [x]
S3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys;c:\windows\SYSNATIVE\drivers\Impcd.sys [x]
S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
S3 NETw5s64;Intel(R) Wireless WiFi Link Adaptertreiber für Windows 7 64-Bit;c:\windows\system32\DRIVERS\NETw5s64.sys;c:\windows\SYSNATIVE\DRIVERS\NETw5s64.sys [x]
S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\drivers\SFEP.sys;c:\windows\SYSNATIVE\drivers\SFEP.sys [x]
S3 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe;c:\program files\Sony\VAIO Power Management\SPMService.exe [x]
S3 VCService;VCService;c:\program files\Sony\VAIO Care\VCService.exe;c:\program files\Sony\VAIO Care\VCService.exe [x]
S3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update\VUAgent.exe;c:\program files\Sony\VAIO Update\VUAgent.exe [x]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-01-28 22:08 1211672 ----a-w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.102\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-02-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-19 08:50]
.
2014-02-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-06-18 13:21]
.
2014-02-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-06-18 13:21]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-10-13 186904]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-02-09 10060320]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-11 16397416]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = https://www.google.de/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Hinzufügen zu Anti-Banner - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000
IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Juve1\AppData\Roaming\Mozilla\Firefox\Profiles\p1d0emrt.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.tuttosport.com/
FF - prefs.js: network.proxy.ftp - 88.202.124.121
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.http - 88.202.124.121
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - 88.202.124.121
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - 88.202.124.121
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 0
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
SafeBoot-mcmscsvc
SafeBoot-MCODS
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-Apoint - c:\program files (x86)\Apoint\Apoint.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SampleCollector]
"ImagePath"="\"c:\program files\Sony\VAIO Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=10000\" \"/procinterval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor Time:1\" \"/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor Information(*)\Processor Frequency:1\" \"&\" \"/expandcounter=\Processor(*)\% Idle Time:1\" \"/expandcounter=\Processor(*)\% C1 Time:1\" \"/expandcounter=\Processor(*)\% C2 Time:1\" \"/expandcounter=\Processor(*)\%C3 & Time:1\" \"/expandcounter=\Processor(*)\% Processor Time:1\" \"/directory=c:\programdata\Sony Corporation\VAIO Care\inteldata\""
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{2B9F5787-88A5-4945-90E7-C4B18563BC5E}"=hex:51,66,7a,6c,4c,1d,38,12,e9,54,8c,
2f,97,c6,2b,0c,ef,f1,87,f1,80,3d,f8,4a
"{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}"=hex:51,66,7a,6c,4c,1d,38,12,1d,cf,77,
51,95,a1,d1,09,ee,9c,1f,b7,fe,e1,bb,5b
"{73455575-E40C-433C-9784-C78DC7761455}"=hex:51,66,7a,6c,4c,1d,38,12,1b,56,56,
77,3e,aa,52,06,e8,92,84,cd,c2,28,50,41
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{9E6D0D23-3D72-4A94-AE1F-2D167624E3D9}"=hex:51,66,7a,6c,4c,1d,38,12,4d,0e,7e,
9a,40,73,fa,0f,d1,09,6e,56,73,7a,a7,cd
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{E33CF602-D945-461A-83F0-819F76A199F8}"=hex:51,66,7a,6c,4c,1d,38,12,6c,f5,2f,
e7,77,97,74,03,fc,e6,c2,df,73,ff,dd,ec
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
"{4F3ED5CD-0726-42A9-87F5-D13F3D2976AC}"=hex:51,66,7a,6c,4c,1d,38,12,a3,d6,2d,
4b,14,49,c7,07,f8,e3,92,7f,38,77,32,b8
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:57,ae,01,6a,ff,be,ce,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c1,f0,69,b0,f4,4b,ff,4e,b1,59,54,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c1,f0,69,b0,f4,4b,ff,4e,b1,59,54,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-02-02 10:37:10
ComboFix-quarantined-files.txt 2014-02-02 09:37
.
Vor Suchlauf: 28 Verzeichnis(se), 311.042.117.632 Bytes frei
Nach Suchlauf: 31 Verzeichnis(se), 311.350.788.096 Bytes frei
.
- - End Of File - - 1514083D61BBD912392F6570DF8B7FDD
A36C5E4F47E84449FF07ED3517B43A31 Der reine Suchlauf hat fast ne Stunde gedauert. Alleine die Log erstellung fast 15 min. Ist das normal?
Hab jetzt auf dem Desktop einen Systemordner namens Heimnetzgruppe! ISt das normal oder warum habe ich den plötzlich?
Alles so in Ordnung?
Danke
Ciao Roberto |