Liste der Anhänge anzeigen (Anzahl: 2) Wären ComboFix lief hab ich mehrmals die Meldung erhalten "Commandline Standard Stream Splitter Funktioniert nicht mehr". Ich musste diese Meldung mit "Programm schließen" bestätigen, da der Scann sonst nicht weiter lief. Ich hoffe es war nicht falsch gewesen.
Zusätzlich hab ich jetzt auf meiner C-Partition im Root Ordner angezeigt, die ich dort bisher nie sah, neu sind oder systemseitig versteckt waren. :wtf: (siehe Anhang) Das Gleiche trifft auch auf die anderen Festplatten bzw. Partitionen zu, bei denen z.B. der Ordner "$Recycle.Bin" jetzt sichtbar ist. :confused:
Hier die ist die ComboFix.txt: Code:
ComboFix 14-04-20.01 - GrenSo 24.04.2014 19:51:54.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.16381.13644 [GMT 2:00]
ausgeführt von:: c:\users\GrenSo\Desktop\ComboFix.exe
AV: ESET Endpoint Antivirus 5.0 *Disabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
SP: ESET Endpoint Antivirus 5.0 *Disabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
. ADS - Windows: deleted 192 bytes in 1 streams.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe
c:\programdata\1355435896.bdinstall.bin
c:\programdata\1355488374.bdinstall.bin
c:\programdata\1355767018.10424.bin
c:\programdata\1355767018.6652.bin
c:\programdata\1355767018.6884.bin
c:\programdata\1355767018.7104.bin
c:\programdata\1355767854.bdinstall.bin
c:\users\GrenSo\AppData\Roaming\0ad
c:\users\GrenSo\AppData\Roaming\0ad\config\user.cfg
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-03-24 bis 2014-04-24 ))))))))))))))))))))))))))))))
.
.
2014-04-23 21:09 . 2014-04-22 09:26 46704 ----a-w- c:\program files (x86)\Mozilla Firefox\browser\components\browsercomps.dll
2014-04-23 17:26 . 2014-04-24 17:43 -------- d-----w- C:\FRST
2014-04-23 16:57 . 2014-04-23 16:57 -------- d-----w- c:\program files (x86)\TP-LINK
2014-04-22 21:04 . 2014-04-22 21:04 -------- d-----w- c:\users\GrenSo\AppData\Roaming\Apple Computer
2014-04-22 21:01 . 2014-04-22 21:01 -------- d-s---w- c:\windows\system32\CompatTel
2014-04-22 21:01 . 2014-04-14 02:24 465408 ----a-w- c:\windows\system32\aepdu.dll
2014-04-22 21:01 . 2014-04-14 02:19 424448 ----a-w- c:\windows\system32\aeinv.dll
2014-04-18 19:08 . 2014-04-18 19:08 -------- d-----w- c:\program files\ESET
2014-04-18 18:41 . 2014-04-18 18:41 -------- d-sh--w- c:\users\GrenSo\AppData\Local\EmieUserList
2014-04-18 18:41 . 2014-04-18 18:41 -------- d-sh--w- c:\users\GrenSo\AppData\Local\EmieSiteList
2014-04-18 17:18 . 2014-04-18 17:18 901848 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2014-04-18 17:18 . 2014-04-18 17:18 73800 ----a-w- c:\windows\system32\RtNicProp64.dll
2014-04-18 17:04 . 2014-04-18 17:04 2101848 ----a-w- c:\windows\system32\WavesGUILib64.dll
2014-04-18 17:04 . 2014-04-18 17:04 946392 ----a-w- c:\windows\system32\RCoInstII64.dll
2014-04-18 17:04 . 2014-04-18 17:04 624344 ----a-w- c:\windows\system32\RtDataProc64.dll
2014-04-18 17:04 . 2014-04-18 17:04 3872984 ----a-w- c:\windows\system32\drivers\RTKVHD64.sys
2014-04-18 17:04 . 2014-04-18 17:04 2792152 ----a-w- c:\windows\system32\RtkAPO64.dll
2014-04-18 17:04 . 2014-04-18 17:04 1286872 ----a-w- c:\windows\system32\RTCOM64.dll
2014-04-18 17:04 . 2014-04-18 17:04 1024216 ----a-w- c:\windows\system32\RtkApi64.dll
2014-04-18 17:04 . 2014-04-18 17:04 2770976 ----a-w- c:\windows\system32\FMAPO64.dll
2014-04-18 17:04 . 2014-04-18 17:04 2037336 ----a-w- c:\windows\system32\MaxxAudioEQ64.dll
2014-04-18 17:04 . 2014-04-18 17:04 1033304 ----a-w- c:\windows\system32\MaxxAudioAPOShell64.dll
2014-04-18 15:39 . 2014-03-25 13:27 254240 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2014-04-18 15:39 . 2014-03-25 13:24 128288 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2014-04-18 15:35 . 2014-04-18 15:35 -------- dc-h--w- c:\programdata\{727C5CC8-3A5E-4517-BA8B-35A93F9B2EBD}
2014-04-18 15:28 . 2014-04-18 15:28 -------- d-----w- c:\program files (x86)\Common Files\Java
2014-04-18 15:28 . 2014-04-18 15:28 98216 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-04-17 19:46 . 2014-03-04 09:44 362496 ----a-w- c:\windows\system32\wow64win.dll
2014-04-17 19:46 . 2014-03-04 09:44 243712 ----a-w- c:\windows\system32\wow64.dll
2014-04-17 19:46 . 2014-03-04 09:44 13312 ----a-w- c:\windows\system32\wow64cpu.dll
2014-04-17 19:46 . 2014-03-04 09:44 16384 ----a-w- c:\windows\system32\ntvdm64.dll
2014-04-17 19:46 . 2014-03-04 09:44 1163264 ----a-w- c:\windows\system32\kernel32.dll
2014-04-17 19:46 . 2014-03-04 09:17 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2014-04-17 19:46 . 2014-03-04 09:16 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2014-04-17 19:46 . 2014-03-04 09:16 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2014-04-17 19:46 . 2014-03-04 08:09 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2014-04-17 19:46 . 2014-03-04 08:09 2048 ----a-w- c:\windows\SysWow64\user.exe
2014-04-17 19:38 . 2014-01-24 02:37 1684928 ----a-w- c:\windows\system32\drivers\ntfs.sys
2014-04-17 19:38 . 2014-02-04 02:35 190912 ----a-w- c:\windows\system32\drivers\storport.sys
2014-04-17 19:38 . 2014-02-04 02:35 274880 ----a-w- c:\windows\system32\drivers\msiscsi.sys
2014-04-17 19:38 . 2014-02-04 02:35 27584 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2014-04-17 19:38 . 2014-02-04 02:28 2048 ----a-w- c:\windows\system32\iologmsg.dll
2014-04-17 19:38 . 2014-02-04 02:00 2048 ----a-w- c:\windows\SysWow64\iologmsg.dll
2014-04-16 03:02 . 2014-04-16 03:02 354656 ----a-w- c:\windows\SysWow64\DivXControlPanelApplet.cpl
2014-03-30 16:28 . 2014-03-07 14:38 18400 ----a-w- c:\windows\system32\drivers\ocztrimfilter.sys
2014-03-30 16:28 . 2014-03-07 14:38 132608 ----a-w- c:\windows\system32\OczTrimCoinstaller.dll
2014-03-30 16:28 . 2014-03-07 14:38 75056 ----a-w- c:\windows\system32\drivers\ocz10xx.sys
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-04-24 18:00 . 2013-03-04 07:00 115370 ----a-w- c:\users\GrenSo\Network_Meter_Data.js
2014-04-24 17:57 . 2013-10-15 17:15 48154 ----a-w- c:\users\GrenSo\IP_Log_Data.js
2014-04-24 16:36 . 2014-02-09 18:32 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-04-18 17:18 . 2012-09-16 16:17 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2014-04-18 15:35 . 2013-09-27 18:00 49752 ----a-w- c:\windows\system32\drivers\AntiLog64.sys
2014-04-18 15:33 . 2014-01-14 23:54 111016 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2014-04-18 15:33 . 2014-03-19 22:05 313256 ----a-w- c:\windows\system32\javaws.exe
2014-04-18 15:33 . 2014-01-14 23:54 191400 ----a-w- c:\windows\system32\javaw.exe
2014-04-18 15:33 . 2014-01-14 23:54 190888 ----a-w- c:\windows\system32\java.exe
2014-04-18 15:13 . 2013-03-09 13:59 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-04-18 15:13 . 2013-03-09 13:59 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-04-17 19:46 . 2012-09-16 18:01 90655440 ----a-w- c:\windows\system32\MRT.exe
2014-04-03 07:51 . 2014-02-09 18:32 63192 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-04-03 07:51 . 2014-02-09 18:32 88280 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-04-03 07:50 . 2012-09-17 17:04 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-03-25 13:24 . 2014-03-25 13:24 156448 ----a-w- c:\windows\system32\drivers\VBoxNetFlt.sys
2014-03-25 13:24 . 2014-03-25 13:24 141600 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2014-03-25 13:20 . 2014-03-25 13:20 204064 ----a-w- c:\windows\system32\VBoxNetFltNobj.dll
2014-03-14 11:08 . 2012-09-16 16:52 6656 ----a-w- c:\windows\system32\lpcio.dll
2014-03-12 20:40 . 2014-03-12 20:40 1958616 ----a-w- c:\windows\system32\RTSnMg64.cpl
2014-03-12 20:40 . 2014-03-12 20:40 2825432 ----a-w- c:\windows\system32\RtPgEx64.dll
2014-03-12 20:40 . 2014-03-12 20:40 397592 ----a-w- c:\windows\system32\MBWrp64.dll
2014-03-12 16:10 . 2014-03-19 22:29 127872 ----a-w- c:\windows\system32\amdhcp64.dll
2014-03-12 16:10 . 2014-03-19 22:29 117560 ----a-w- c:\windows\SysWow64\amdhcp32.dll
2014-03-12 16:10 . 2014-03-19 22:29 78432 ----a-w- c:\windows\system32\atimpc64.dll
2014-03-12 16:10 . 2014-03-19 22:29 78432 ----a-w- c:\windows\system32\amdpcom64.dll
2014-03-12 16:10 . 2014-03-19 22:29 71704 ----a-w- c:\windows\SysWow64\atimpc32.dll
2014-03-12 16:10 . 2014-03-19 22:29 71704 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2014-03-12 16:10 . 2014-03-19 22:29 126336 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2014-03-12 16:10 . 2013-01-02 22:05 143304 ----a-w- c:\windows\system32\atiuxp64.dll
2014-03-12 16:10 . 2014-03-19 22:29 116024 ----a-w- c:\windows\system32\atiu9p64.dll
2014-03-12 16:10 . 2013-01-02 22:05 98496 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2014-03-12 16:10 . 2013-01-02 22:05 1329352 ----a-w- c:\windows\system32\aticfx64.dll
2014-03-12 16:10 . 2013-01-02 22:05 1106872 ----a-w- c:\windows\SysWow64\aticfx32.dll
2014-03-12 16:10 . 2013-01-02 22:05 10176088 ----a-w- c:\windows\system32\atidxx64.dll
2014-03-12 16:10 . 2014-03-19 22:29 8764440 ----a-w- c:\windows\SysWow64\atidxx32.dll
2014-03-12 16:10 . 2013-01-02 22:05 10145128 ----a-w- c:\windows\SysWow64\atiumdva.dll
2014-03-12 16:10 . 2013-01-02 22:05 6716264 ----a-w- c:\windows\SysWow64\atiumdag.dll
2014-03-12 16:10 . 2014-01-31 21:06 10899112 ----a-w- c:\windows\system32\atiumd6a.dll
2014-03-12 16:10 . 2014-01-31 21:06 7892000 ----a-w- c:\windows\system32\atiumd64.dll
2014-03-12 16:06 . 2014-03-19 22:29 273632 ----a-w- c:\windows\system32\drivers\amdacpksd.sys
2014-03-12 16:04 . 2014-03-19 22:29 13929984 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2014-03-12 15:50 . 2014-03-19 22:29 230912 ----a-w- c:\windows\system32\clinfo.exe
2014-03-12 15:49 . 2014-03-19 22:29 98816 ----a-w- c:\windows\system32\OpenVideo64.dll
2014-03-12 15:49 . 2014-03-19 22:29 83456 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2014-03-12 15:49 . 2014-03-19 22:29 86528 ----a-w- c:\windows\system32\OVDecode64.dll
2014-03-12 15:49 . 2014-03-19 22:29 73216 ----a-w- c:\windows\SysWow64\OVDecode.dll
2014-03-12 15:49 . 2014-03-19 22:29 28425216 ----a-w- c:\windows\system32\amdocl64.dll
2014-03-12 15:47 . 2014-03-19 22:29 23903744 ----a-w- c:\windows\SysWow64\amdocl.dll
2014-03-12 15:44 . 2014-03-19 22:29 65024 ----a-w- c:\windows\system32\OpenCL.dll
2014-03-12 15:44 . 2014-03-19 22:29 58880 ----a-w- c:\windows\SysWow64\OpenCL.dll
2014-03-12 15:27 . 2014-03-19 22:29 27490304 ----a-w- c:\windows\system32\atio6axx.dll
2014-03-12 15:24 . 2014-03-19 22:29 368640 ----a-w- c:\windows\system32\atiapfxx.exe
2014-03-12 15:24 . 2014-03-19 22:29 62464 ----a-w- c:\windows\system32\aticalrt64.dll
2014-03-12 15:24 . 2014-03-19 22:29 52224 ----a-w- c:\windows\SysWow64\aticalrt.dll
2014-03-12 15:24 . 2014-03-19 22:29 55808 ----a-w- c:\windows\system32\aticalcl64.dll
2014-03-12 15:24 . 2014-03-19 22:29 49152 ----a-w- c:\windows\SysWow64\aticalcl.dll
2014-03-12 15:23 . 2014-03-19 22:29 15716352 ----a-w- c:\windows\system32\aticaldd64.dll
2014-03-12 15:20 . 2014-03-19 22:29 126464 ----a-w- c:\windows\system32\mantle64.dll
2014-03-12 15:20 . 2014-03-19 22:29 14302208 ----a-w- c:\windows\SysWow64\aticaldd.dll
2014-03-12 15:20 . 2014-03-19 22:29 113152 ----a-w- c:\windows\SysWow64\mantle32.dll
2014-03-12 15:19 . 2014-03-19 22:29 5393408 ----a-w- c:\windows\system32\amdmantle64.dll
2014-03-12 15:07 . 2014-03-19 22:29 23108608 ----a-w- c:\windows\SysWow64\atioglxx.dll
2014-03-12 15:06 . 2014-03-19 22:29 4319744 ----a-w- c:\windows\SysWow64\amdmantle32.dll
2014-03-12 15:03 . 2014-01-31 20:06 442368 ----a-w- c:\windows\system32\atidemgy.dll
2014-03-12 15:03 . 2014-03-19 22:29 31232 ----a-w- c:\windows\system32\atimuixx.dll
2014-03-12 15:03 . 2014-03-19 22:29 586240 ----a-w- c:\windows\system32\atieclxx.exe
2014-03-12 15:02 . 2014-03-19 22:29 240128 ----a-w- c:\windows\system32\atiesrxx.exe
2014-03-12 15:00 . 2014-03-19 22:29 190976 ----a-w- c:\windows\system32\atitmm64.dll
2014-03-12 14:53 . 2014-03-19 22:29 81920 ----a-w- c:\windows\system32\mantleaxl64.dll
2014-03-12 14:53 . 2014-03-19 22:29 79360 ----a-w- c:\windows\SysWow64\mantleaxl32.dll
2014-03-12 14:50 . 2014-03-19 22:29 44544 ----a-w- c:\windows\system32\amdmmcl6.dll
2014-03-12 14:50 . 2014-03-19 22:29 35840 ----a-w- c:\windows\SysWow64\amdmmcl.dll
2014-03-12 14:34 . 2014-01-31 19:37 806912 ----a-w- c:\windows\system32\coinst_13.350.dll
2014-03-12 14:27 . 2014-01-31 19:30 1148416 ----a-w- c:\windows\system32\atiadlxx.dll
2014-03-12 14:26 . 2014-03-19 22:29 828416 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2014-03-12 14:26 . 2014-03-19 22:29 75264 ----a-w- c:\windows\system32\atig6pxx.dll
2014-03-12 14:26 . 2014-03-19 22:29 69632 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2014-03-12 14:26 . 2014-03-19 22:29 69632 ----a-w- c:\windows\system32\atiglpxx.dll
2014-03-12 14:26 . 2014-03-19 22:29 146432 ----a-w- c:\windows\system32\atig6txx.dll
2014-03-12 14:25 . 2014-03-19 22:29 133120 ----a-w- c:\windows\SysWow64\atigktxx.dll
2014-03-12 14:25 . 2014-03-19 22:29 636928 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2014-03-12 14:24 . 2014-03-19 22:29 95744 ----a-w- c:\windows\system32\amdave64.dll
2014-03-12 14:24 . 2014-03-19 22:29 90112 ----a-w- c:\windows\SysWow64\amdave32.dll
2014-03-12 14:24 . 2014-03-19 22:29 89088 ----a-w- c:\windows\system32\atisamu64.dll
2014-03-12 14:24 . 2014-03-19 22:29 80896 ----a-w- c:\windows\SysWow64\atisamu32.dll
2014-03-12 14:20 . 2014-03-19 22:29 43520 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2014-03-12 11:00 . 2014-03-12 11:00 51200 ----a-w- c:\windows\system32\kdbsdk64.dll
2014-03-12 10:55 . 2014-03-12 10:55 38912 ----a-w- c:\windows\SysWow64\kdbsdk32.dll
2014-03-10 17:17 . 2013-12-04 21:17 128288 ----a-w- c:\windows\system32\IObitSmartDefragExtension.dll
2014-03-04 09:17 . 2014-04-17 19:46 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2014-03-01 20:16 . 2013-04-20 08:59 2 --shatr- c:\windows\winstart.bat
2014-02-07 01:23 . 2014-03-11 19:58 3156480 ----a-w- c:\windows\system32\win32k.sys
2014-02-04 02:32 . 2014-03-11 19:58 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-02-04 02:32 . 2014-03-11 19:58 624128 ----a-w- c:\windows\system32\qedit.dll
2014-02-04 02:04 . 2014-03-11 19:58 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2014-02-04 02:04 . 2014-03-11 19:58 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2014-01-29 02:32 . 2014-03-11 19:58 484864 ----a-w- c:\windows\system32\wer.dll
2014-01-29 02:06 . 2014-03-11 19:58 381440 ----a-w- c:\windows\SysWow64\wer.dll
2014-01-28 02:32 . 2014-03-11 19:58 228864 ----a-w- c:\windows\system32\wwansvc.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2014-04-18 15:44 223432 ----a-w- c:\users\GrenSo\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2014-04-18 15:44 223432 ----a-w- c:\users\GrenSo\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2014-04-18 15:44 223432 ----a-w- c:\users\GrenSo\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"RocketDock"="c:\program files (x86)\RocketDock\RocketDock.exe" [2007-09-02 495616]
"NokiaSuite.exe"="c:\program files (x86)\Nokia\Nokia Suite\NokiaSuite.exe" [2013-10-02 1090912]
"PeerBlock"="c:\program files\PeerBlock\peerblock.exe" [2014-01-14 2513992]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2014-02-18 759496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Diamondback"="c:\program files (x86)\Razer\Diamondback\Razer\Diamondback\razerhid.exe" [2009-10-09 226816]
"Reclusa"="c:\program files (x86)\Razer\Reclusa\razerhid.exe" [2010-01-12 292352]
"adm_tray.exe"="c:\program files (x86)\Acronis\DriveMonitor\adm_tray.exe" [2011-02-24 470120]
"LWS"="c:\program files (x86)\Logitech\LWS\Webcam Software\LWS.exe" [2012-09-12 204136]
"NaturalPoint"="c:\program files (x86)\NaturalPoint\TrackIR4\TrackIR.exe" [2012-10-11 1152592]
"TrueImageMonitor.exe"="c:\program files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" [2013-03-27 6405376]
"VC10Player"="c:\program files (x86)\Virtual CD v10\System\VC10Play.exe" [2011-10-19 411976]
"AcronisTibMounterMonitor"="c:\program files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe" [2013-01-10 1105848]
"AntiLogger"="c:\program files (x86)\AntiLogger\AntiLogger.exe" [2014-03-26 19362728]
"EMET Agent"="c:\program files (x86)\EMET 4.0\EMET_agent.exe" [2013-06-14 78496]
"KeyScrambler"="c:\program files (x86)\KeyScrambler\keyscrambler.exe" [2013-11-14 508144]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-03-12 767200]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2014-04-23 1825984]
"DivXMediaServer"="c:\program files (x86)\DivX\DivX Media Server\DivXMediaServer.exe" [2014-04-03 450560]
.
c:\users\GrenSo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
FastStone Capture.lnk - c:\program files (x86)\FastStone Capture\FSCapture.exe -Silent [2014-2-8 1281536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SmartDefragBootTime.exe
.
R1 ESProtectionDriver;Malwarebytes Anti-Exploit; [x]
R2 AODService;AODService;c:\program files (x86)\AMD\OverDrive\AODAssist.exe;c:\program files (x86)\AMD\OverDrive\AODAssist.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]
R3 atillk64;atillk64; [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x]
R3 BingDesktopUpdate;Bing Desktop Update service;c:\program files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe;c:\program files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [x]
R3 cleanhlp;cleanhlp;c:\program files (x86)\EMSISOFT EMERGENCY KIT\RUN\cleanhlp64.sys;c:\program files (x86)\EMSISOFT EMERGENCY KIT\RUN\cleanhlp64.sys [x]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys;c:\windows\SYSNATIVE\DRIVERS\ew_hwusbdev.sys [x]
R3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\DRIVERS\ew_usbenumfilter.sys;c:\windows\SYSNATIVE\DRIVERS\ew_usbenumfilter.sys [x]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys;c:\windows\SYSNATIVE\DRIVERS\ewusbnet.sys [x]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\SystemInfo\FMSISvc.exe;c:\program files (x86)\Futuremark\SystemInfo\FMSISvc.exe [x]
R3 HH10Help.sys;HH10Help.sys;c:\windows\system32\drivers\HH10Help.sys;c:\windows\SYSNATIVE\drivers\HH10Help.sys [x]
R3 huawei_cdcacm;huawei_cdcacm;c:\windows\system32\DRIVERS\ew_jucdcacm.sys;c:\windows\SYSNATIVE\DRIVERS\ew_jucdcacm.sys [x]
R3 huawei_ext_ctrl;huawei_ext_ctrl;c:\windows\system32\DRIVERS\ew_juextctrl.sys;c:\windows\SYSNATIVE\DRIVERS\ew_juextctrl.sys [x]
R3 huawei_wwanecm;huawei_wwanecm;c:\windows\system32\DRIVERS\ew_juwwanecm.sys;c:\windows\SYSNATIVE\DRIVERS\ew_juwwanecm.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MEMSWEEP2;MEMSWEEP2; [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys;c:\windows\SYSNATIVE\DRIVERS\ss_bbus.sys [x]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ss_bmdfl.sys [x]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ss_bmdm.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VBoxUSB;VirtualBox USB;c:\windows\system32\Drivers\VBoxUSB.sys;c:\windows\SYSNATIVE\Drivers\VBoxUSB.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0; [x]
R3 WN111v2;NETGEAR WN111v2 USB2.0 Wireless Card Service;c:\windows\system32\DRIVERS\WN111v2w7x.sys;c:\windows\SYSNATIVE\DRIVERS\WN111v2w7x.sys [x]
R4 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [x]
R4 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [x]
R4 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe [x]
R4 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
R4 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\nlssrv32.exe;c:\windows\SysWOW64\nlssrv32.exe [x]
R4 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S0 fltsrv;Acronis Storage Filter Management;c:\windows\system32\DRIVERS\fltsrv.sys;c:\windows\SYSNATIVE\DRIVERS\fltsrv.sys [x]
S0 fsbts;fsbts;c:\windows\system32\Drivers\fsbts.sys;c:\windows\SYSNATIVE\Drivers\fsbts.sys [x]
S0 ocz10xx;ocz10xx;c:\windows\system32\DRIVERS\ocz10xx.sys;c:\windows\SYSNATIVE\DRIVERS\ocz10xx.sys [x]
S0 ocztrimfilter;OCZ PCIe SSD Trim Filter;c:\windows\system32\DRIVERS\ocztrimfilter.sys;c:\windows\SYSNATIVE\DRIVERS\ocztrimfilter.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
S0 tib;Acronis TIB Manager;c:\windows\system32\DRIVERS\tib.sys;c:\windows\SYSNATIVE\DRIVERS\tib.sys [x]
S0 tib_mounter;Acronis TIB Mounter;c:\windows\system32\DRIVERS\tib_mounter.sys;c:\windows\SYSNATIVE\DRIVERS\tib_mounter.sys [x]
S0 vididr;Acronis Virtual Disk;c:\windows\system32\DRIVERS\vididr.sys;c:\windows\SYSNATIVE\DRIVERS\vididr.sys [x]
S0 vidsflt;Acronis Disk Storage Filter;c:\windows\system32\DRIVERS\vidsflt.sys;c:\windows\SYSNATIVE\DRIVERS\vidsflt.sys [x]
S1 A2DDA;A2 Direct Disk Access Support Driver;c:\program files (x86)\EMSISOFT EMERGENCY KIT\RUN\a2ddax64.sys;c:\program files (x86)\EMSISOFT EMERGENCY KIT\RUN\a2ddax64.sys [x]
S1 AntiLog32;AntiLog32;c:\windows\system32\drivers\AntiLog64.sys;c:\windows\SYSNATIVE\drivers\AntiLog64.sys [x]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO64A.SYS;c:\windows\SYSNATIVE\drivers\HWiNFO64A.SYS [x]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxDrv.sys [x]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxUSBMon.sys [x]
S1 vdrv1000;vdrv1000;c:\windows\system32\DRIVERS\vdrv1000.sys;c:\windows\SYSNATIVE\DRIVERS\vdrv1000.sys [x]
S2 {329F96B6-DF1E-4328-BFDA-39EA953C1312};Power Control [2012/11/30 20:38];c:\program files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl;c:\program files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [x]
S2 afcdpsrv;Acronis Nonstop Backup Service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AODDriver4.2.0;AODDriver4.2.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
S2 AODDriver4.3.0;AODDriver4.3.0;c:\program files (x86)\AMD\OverDrive\amd64\AODDriver2.sys;c:\program files (x86)\AMD\OverDrive\amd64\AODDriver2.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe;c:\program files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe [x]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfpr.sys [x]
S2 ESHASRV;ESET SHA Service;c:\program files\ESET\ESET Endpoint Antivirus\EShaSrv.exe;c:\program files\ESET\ESET Endpoint Antivirus\EShaSrv.exe [x]
S2 iprip;RIP-Überwachung;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys;c:\windows\SYSNATIVE\drivers\npf.sys [x]
S2 ntk_PowerDVD;ntk_PowerDVD;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [x]
S2 syncagentsrv;Acronis Sync Agent Service;c:\program files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe;c:\program files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [x]
S2 VC10SecS;Virtual CD v10 Management Service;c:\program files (x86)\Virtual CD v10\System\VC10SecS.exe;c:\program files (x86)\Virtual CD v10\System\VC10SecS.exe [x]
S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys;c:\windows\SYSNATIVE\DRIVERS\afcdp.sys [x]
S3 ALSysIO;ALSysIO;c:\users\GrenSo\AppData\Local\Temp\ALSysIO64.sys;c:\users\GrenSo\AppData\Local\Temp\ALSysIO64.sys [x]
S3 AmdLLD64;AMD Low Level Device Driver;c:\windows\system32\DRIVERS\AmdLLD64.sys;c:\windows\SYSNATIVE\DRIVERS\AmdLLD64.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys;c:\windows\SYSNATIVE\DRIVERS\ew_jubusenum.sys [x]
S3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys;c:\windows\SYSNATIVE\drivers\keyscrambler.sys [x]
S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
S3 LVUVC64;Logitech QuickCam Pro 9000(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
S3 MTKSCVAD;Ralink Virtual Audio device;c:\windows\system32\drivers\mtkvadx.sys;c:\windows\SYSNATIVE\drivers\mtkvadx.sys [x]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x]
S3 npusbio;npusbio;c:\windows\system32\Drivers\npusbio_x64.sys;c:\windows\SYSNATIVE\Drivers\npusbio_x64.sys [x]
S3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys;c:\program files\PeerBlock\pbfilter.sys [x]
S3 Razerlow;Razer Pro|Solutions;c:\windows\system32\drivers\Razerlow.sys;c:\windows\SYSNATIVE\drivers\Razerlow.sys [x]
S3 RecFltr;Reclusa Keyboard;c:\windows\system32\drivers\RecFltr.sys;c:\windows\SYSNATIVE\drivers\RecFltr.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x]
S3 vcd10bus;Virtual CD v10 Bus Enumerator;c:\windows\system32\DRIVERS\vcd10bus.sys;c:\windows\SYSNATIVE\DRIVERS\vcd10bus.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - MBAMSWISSARMY
*NewlyCreated* - MBAMWEBACCESSCONTROL
*NewlyCreated* - PBFILTER
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
2014-03-14 11:07 2471744 ----a-w- c:\program files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1]
@="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}"
[HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}]
2014-03-20 10:24 667808 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2]
@="{853B7E05-C47D-4985-909A-D0DC5C6D7303}"
[HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}]
2014-03-20 10:24 667808 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3]
@="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}"
[HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}]
2014-03-20 10:24 667808 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2014-04-18 15:44 262344 ----a-w- c:\users\GrenSo\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2014-04-18 15:44 262344 ----a-w- c:\users\GrenSo\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2014-04-18 15:44 262344 ----a-w- c:\users\GrenSo\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncError]
@="{934BC6C0-FEC2-4df5-A100-961DE2C8A0ED}"
[HKEY_CLASSES_ROOT\CLSID\{934BC6C0-FEC2-4df5-A100-961DE2C8A0ED}]
2013-03-27 22:53 2827832 ----a-w- c:\program files (x86)\Acronis\TrueImageHome\tishell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncInProgress]
@="{00F848DC-B1D4-4892-9C25-CAADC86A215D}"
[HKEY_CLASSES_ROOT\CLSID\{00F848DC-B1D4-4892-9C25-CAADC86A215D}]
2013-03-27 22:53 2827832 ----a-w- c:\program files (x86)\Acronis\TrueImageHome\tishell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncOk]
@="{71573297-552E-46fc-BE3D-3DFAF88D47B7}"
[HKEY_CLASSES_ROOT\CLSID\{71573297-552E-46fc-BE3D-3DFAF88D47B7}]
2013-03-27 22:53 2827832 ----a-w- c:\program files (x86)\Acronis\TrueImageHome\tishell64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power Monitor"="c:\program files (x86)\AMD\AMD Power Monitor\AMD Power Monitor.exe" [2009-05-21 624640]
"lxcgmon.exe"="c:\program files (x86)\Lexmark 2300 Series\lxcgmon.exe" [2007-04-29 205744]
"EzPrint"="c:\program files (x86)\Lexmark 2300 Series\ezprint.exe" [2007-04-29 103344]
"Acronis Scheduler2 Service"="c:\program files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" [2013-02-15 517912]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2014-04-18 13667032]
"egui"="c:\program files\ESET\ESET Endpoint Antivirus\egui.exe" [2013-10-07 4148664]
"LXCGCATS"="c:\windows\system32\spool\DRIVERS\x64\3\LXCGtime.dll" [2007-02-22 28672]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -
TCP: DhcpNameServer = 192.168.66.1
FF - ProfilePath - c:\users\GrenSo\AppData\Roaming\Mozilla\Firefox\Profiles\0rm2ca40.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.winboard.org/|hxxp://www.fcenergie.de/content/home
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2014-02-25 21:43; adsremoval@adsremoval.net; c:\users\GrenSo\AppData\Roaming\Mozilla\Firefox\Profiles\0rm2ca40.default\extensions\adsremoval@adsremoval.net
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-HydraVisionDesktopManager - c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe
Wow6432Node-HKLM-Run-HydraVisionDesktopManager - c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe
SafeBoot-CleanHlp
SafeBoot-CleanHlp.sys
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{329F96B6-DF1E-4328-BFDA-39EA953C1312}]
"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vdrv1000]
"ImagePath"="system32\DRIVERS\vdrv1000.sys"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1996915005-1308554187-4098229939-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:9c,20,6c,08,0e,30,4b,24,1c,8c,bc,b2,b3,ce,18,09,7b,96,33,a9,26,5e,a9,
37,8a,0e,d8,4b,ab,7c,e3,38,af,a6,08,31,97,0f,6c,33,13,9c,33,29,11,f2,a6,7c,\
"??"=hex:c4,e0,56,06,6b,cf,19,49,40,b5,75,48,46,dc,9c,42
.
[HKEY_USERS\S-1-5-21-1996915005-1308554187-4098229939-1000\Software\SecuROM\License information*]
"datasecu"=hex:9f,c1,28,1f,fa,07,79,13,d8,3d,17,5c,0e,1f,47,7a,7b,9b,f3,9c,91,
0a,52,cf,0a,9d,f3,14,b6,8c,4f,41,6b,ca,54,0f,78,b7,b0,5b,1b,40,8b,11,2c,2c,\
"rkeysecu"=hex:4c,c4,58,99,09,8a,46,48,d1,fd,d5,26,d7,4b,06,7f
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_199_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_199_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_75_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_75_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:cd,e0,af,e6,b2,0d,09,5b,07,cf,82,1b,b4,cb,f0,46,f2,e5,e7,8f,25,
12,cb,9a,00,7c,6d,a6,4a,50,a8,a7,a3,69,dc,d7,da,15,59,36,84,83,0f,19,08,3d,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_199_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_199_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_75_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_75_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_199.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.13"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_199.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_199.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_199.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:cd,e0,af,e6,b2,0d,09,5b,07,cf,82,1b,b4,cb,f0,46,f2,e5,e7,8f,25,
12,cb,9a,00,7c,6d,a6,4a,50,a8,a7,a3,69,dc,d7,da,15,59,36,84,83,0f,19,08,3d,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Windows Live\Family Safety\fsssvc.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
c:\program files (x86)\Malwarebytes Anti-Malware\mbam.exe
c:\program files (x86)\FastStone Capture\FSCapture.exe
c:\program files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe
c:\program files (x86)\Razer\Reclusa\razertra.exe
c:\program files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
c:\program files (x86)\Razer\Diamondback\Razer\Diamondback\razerofa.exe
c:\program files (x86)\Virtual CD v10\System\VC10Tray.exe
c:\program files (x86)\PC Connectivity Solution\ServiceLayer.exe
c:\program files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
c:\program files (x86)\Razer\Diamondback\Razer\Diamondback\razertra.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2014-04-24 20:17:57 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2014-04-24 18:17
.
Vor Suchlauf: 9 Verzeichnis(se), 113.184.772.096 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 112.714.428.416 Bytes frei
.
- - End Of File - - 6D0B8A53586524156E97A24F9DCC65AC |