Problemkind4 | 01.06.2014 14:29 | Ich verstehe das Programm nicht so ganz :|
Ich habe alle anweisungen befolgt bin aber ab der Stelle mit Addit.... nicht mehr weiter gekommen.
Was muss ich machen nachdem das Programm (revo) installiert und gestartet worden ist?
Soll ich jedes meiner Progrtamme löschen?
Ich habe jetzt alles so gemacht wie es beschrieben wurde auch mit combofix... Code:
ComboFix 14-05-29.01 - Maschiene 01.06.2014 15:16:13.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4045.2106 [GMT 2:00]
ausgeführt von:: c:\users\Maschiene\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\MASCHI~1\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\users\Maschiene\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\users\Maschiene\AppData\Local\TempDIR
c:\users\Maschiene\AppData\Local\TempDIR\Offercast2821_NDV_.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-05-01 bis 2014-06-01 ))))))))))))))))))))))))))))))
.
.
2014-06-01 13:21 . 2014-06-01 13:21 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-06-01 01:48 . 2014-06-01 01:48 -------- d-----w- c:\program files (x86)\VS Revo Group
2014-05-31 13:14 . 2014-05-31 13:14 -------- d-----w- c:\users\Maschiene\AppData\Local\ESN
2014-05-31 13:14 . 2014-05-31 13:14 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins
2014-05-31 13:13 . 2014-05-31 13:13 -------- d-----w- c:\programdata\EA Core
2014-05-31 13:13 . 2014-05-31 18:01 -------- d-----w- c:\programdata\EA Logs
2014-05-31 09:06 . 2014-05-31 09:06 -------- d--h--w- c:\program files (x86)\Common Files\EAInstaller
2014-05-31 00:12 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-05-31 00:12 . 2014-05-31 00:12 -------- d-----w- C:\AdwCleaner
2014-05-31 00:10 . 2014-05-31 00:10 -------- d-----w- c:\users\Maschiene\AppData\Roaming\Avira
2014-05-31 00:04 . 2014-05-09 09:16 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2014-05-31 00:04 . 2014-05-09 09:16 130584 ----a-w- c:\windows\system32\drivers\avipbb.sys
2014-05-31 00:04 . 2014-05-09 09:16 112080 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2014-05-29 18:58 . 2014-05-29 19:13 -------- d-----w- c:\program files (x86)\Origin Games
2014-05-29 18:57 . 2014-06-01 00:01 -------- d-----w- c:\users\Maschiene\AppData\Roaming\Origin
2014-05-29 18:57 . 2014-05-29 18:58 -------- d-----w- c:\users\Maschiene\AppData\Local\Origin
2014-05-29 18:52 . 2014-06-01 00:17 -------- d-----w- c:\programdata\Origin
2014-05-29 18:52 . 2014-05-31 02:24 -------- d-----w- c:\program files (x86)\Origin
2014-05-28 15:20 . 2014-05-30 22:19 -------- d-----w- c:\users\Maschiene\AppData\Roaming\BoL
2014-05-27 13:43 . 2014-05-27 13:43 -------- d-----w- c:\program files\Enigma Software Group
2014-05-27 13:42 . 2014-05-28 10:50 -------- d-----w- c:\windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-05-27 13:42 . 2014-05-27 13:42 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2014-05-26 18:48 . 2014-06-01 01:52 -------- d-----w- C:\FRST
2014-05-25 22:28 . 2014-05-25 22:28 -------- d-----w- C:\Games
2014-05-25 22:23 . 2014-05-30 23:37 -------- d-----w- c:\users\Maschiene\AppData\Local\Black_Tree_Gaming
2014-05-25 22:23 . 2014-05-25 22:23 -------- d-----w- c:\users\Maschiene\AppData\Local\Programs
2014-05-25 20:08 . 2013-01-18 01:27 16344 ----a-w- c:\windows\system32\drivers\IntelMEFWVer.dll
2014-05-25 20:08 . 2014-05-25 20:08 -------- d-----w- c:\programdata\Intel
2014-05-25 20:08 . 2014-05-25 20:08 -------- d-----w- c:\program files\Intel
2014-05-25 20:07 . 2014-05-25 20:07 -------- d-----w- c:\program files (x86)\Common Files\postureAgent
2014-05-25 20:07 . 2014-05-25 20:08 -------- d-----w- c:\program files (x86)\Intel
2014-05-25 20:07 . 2012-07-13 08:56 62784 ----a-w- c:\windows\system32\drivers\HECIx64.sys
2014-05-25 19:50 . 2013-11-26 14:49 73800 ----a-w- c:\windows\system32\RtNicProp64.dll
2014-05-25 19:50 . 2013-11-26 14:49 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2014-05-25 19:46 . 2013-11-26 14:49 888536 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2014-05-24 23:56 . 2014-05-31 13:13 -------- d-----w- c:\programdata\Electronic Arts
2014-05-24 12:57 . 2014-05-24 12:57 -------- d-----w- c:\program files (x86)\Microsoft WSE
2014-05-24 12:44 . 2014-05-30 23:40 -------- d-----w- c:\program files (x86)\Electronic Arts
2014-05-23 18:03 . 2014-05-29 19:22 -------- d-----w- c:\users\Maschiene\AppData\Roaming\starcheat
2014-05-17 16:00 . 2014-05-17 16:00 -------- d-----w- c:\users\Maschiene\AppData\Local\Chromium
2014-05-16 02:43 . 2014-05-31 18:03 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-05-16 02:42 . 2014-05-31 13:15 -------- d-----w- c:\users\Maschiene\AppData\Local\PunkBuster
2014-05-16 02:18 . 2014-05-31 18:03 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-05-16 02:18 . 2014-05-31 18:01 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-05-16 02:18 . 2014-05-31 09:06 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2014-05-16 00:28 . 2014-05-16 00:28 -------- d-----w- c:\program files (x86)\EA Games
2014-05-15 21:44 . 2014-05-15 21:44 -------- d-----w- c:\programdata\BlueStacks
2014-05-15 21:44 . 2014-05-15 21:44 -------- d-----w- c:\program files (x86)\BlueStacks
2014-05-15 21:44 . 2014-05-15 21:44 -------- d-----w- c:\users\Maschiene\AppData\Local\Bluestacks
2014-05-15 01:03 . 2014-05-06 04:40 23544320 ----a-w- c:\windows\system32\mshtml.dll
2014-05-15 01:03 . 2014-05-06 03:00 84992 ----a-w- c:\windows\system32\mshtmled.dll
2014-05-15 01:03 . 2014-05-06 04:17 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-05-15 01:03 . 2014-05-06 03:07 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2014-05-14 18:35 . 2014-05-14 18:36 -------- d-----w- c:\program files (x86)\MTA San Andreas 1.3
2014-05-14 18:35 . 2014-05-14 18:36 -------- d---a-w- c:\programdata\MTA San Andreas All
2014-05-10 22:39 . 2014-05-10 22:39 -------- d-----w- c:\users\Maschiene\AppData\Local\Rockstar Games
2014-05-10 22:37 . 2014-05-10 22:37 -------- d--h--r- c:\users\Maschiene\AppData\Roaming\SecuROM
2014-05-10 17:11 . 2014-05-10 17:11 -------- d-sh--w- c:\programdata\SecuROM
2014-05-10 17:08 . 2014-05-24 22:25 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2014-05-10 17:08 . 2014-05-10 17:08 -------- d-----w- c:\windows\SysWow64\xlive
2014-05-10 15:34 . 2004-10-22 00:17 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll
2014-05-10 15:34 . 2004-10-22 00:17 274432 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll
2014-05-10 15:34 . 2004-10-22 00:16 180224 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll
2014-05-10 15:34 . 2004-10-22 00:16 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2014-05-10 15:34 . 2004-10-22 00:18 749568 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll
2014-05-10 15:34 . 2014-05-10 15:34 323716 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll
2014-05-10 15:34 . 2014-05-10 15:34 192644 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll
2014-05-10 11:46 . 2014-05-29 17:52 -------- d-----w- c:\users\Maschiene\AppData\Local\Skyrim
2014-05-10 02:48 . 2014-05-10 02:48 -------- d-----w- c:\program files\Microsoft Xbox 360 Accessories
2014-05-10 02:26 . 2014-05-10 02:26 -------- d-----w- c:\program files\CCleaner
2014-05-10 01:42 . 2014-05-14 19:09 -------- d-----w- c:\program files (x86)\Rockstar Games
2014-05-10 01:41 . 2014-05-10 01:41 -------- d-sh--w- c:\users\Maschiene\AppData\Local\EmieUserList
2014-05-10 01:41 . 2014-05-10 01:41 -------- d-sh--w- c:\users\Maschiene\AppData\Local\EmieSiteList
2014-05-08 01:00 . 2014-03-06 08:15 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-05-07 11:51 . 2014-06-01 02:06 -------- d-----w- c:\programdata\Firefly Studios
2014-05-07 11:45 . 2014-06-01 02:04 -------- d-----w- c:\program files (x86)\Firefly Studios
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-24 22:27 . 2009-08-18 10:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2014-05-24 22:27 . 2009-08-18 09:24 23264 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-05-15 01:02 . 2014-04-28 14:43 93223848 ----a-w- c:\windows\system32\MRT.exe
2014-05-13 21:59 . 2014-04-29 17:37 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-05-13 21:59 . 2014-04-29 17:37 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-05-01 01:43 . 2014-05-01 01:43 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2014-05-01 01:43 . 2014-05-01 01:43 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2014-05-01 01:43 . 2014-05-01 01:43 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2014-05-01 01:43 . 2014-05-01 01:43 235008 ----a-w- c:\windows\system32\elshyph.dll
2014-05-01 01:43 . 2014-05-01 01:43 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2014-05-01 01:43 . 2014-05-01 01:43 1789440 ----a-w- c:\windows\SysWow64\wininet.dll
2014-05-01 01:42 . 2014-05-01 01:42 942592 ----a-w- c:\windows\system32\jsIntl.dll
2014-05-01 01:42 . 2014-05-01 01:42 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-05-01 01:42 . 2014-05-01 01:42 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2014-05-01 01:42 . 2014-05-01 01:42 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2014-05-01 01:42 . 2014-05-01 01:42 752640 ----a-w- c:\windows\system32\jscript9diag.dll
2014-05-01 01:42 . 2014-05-01 01:42 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2014-05-01 01:42 . 2014-05-01 01:42 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2014-05-01 01:42 . 2014-05-01 01:42 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2014-05-01 01:42 . 2014-05-01 01:42 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2014-05-01 01:42 . 2014-05-01 01:42 592896 ----a-w- c:\windows\SysWow64\jscript9diag.dll
2014-05-01 01:42 . 2014-05-01 01:42 5784064 ----a-w- c:\windows\system32\jscript9.dll
2014-05-01 01:42 . 2014-05-01 01:42 574976 ----a-w- c:\windows\system32\ieui.dll
2014-05-01 01:42 . 2014-05-01 01:42 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2014-05-01 01:42 . 2014-05-01 01:42 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2014-05-01 01:42 . 2014-05-01 01:42 51200 ----a-w- c:\windows\system32\jsproxy.dll
2014-05-01 01:42 . 2014-05-01 01:42 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2014-05-01 01:42 . 2014-05-01 01:42 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-05-01 01:42 . 2014-05-01 01:42 455168 ----a-w- c:\windows\SysWow64\vbscript.dll
2014-05-01 01:42 . 2014-05-01 01:42 4254720 ----a-w- c:\windows\SysWow64\jscript9.dll
2014-05-01 01:42 . 2014-05-01 01:42 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2014-05-01 01:42 . 2014-05-01 01:42 337408 ----a-w- c:\windows\SysWow64\html.iec
2014-05-01 01:42 . 2014-05-01 01:42 32256 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2014-05-01 01:42 . 2014-05-01 01:42 2767360 ----a-w- c:\windows\system32\iertutil.dll
2014-05-01 01:42 . 2014-05-01 01:42 247808 ----a-w- c:\windows\system32\msls31.dll
2014-05-01 01:42 . 2014-05-01 01:42 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2014-05-01 01:42 . 2014-05-01 01:42 2260480 ----a-w- c:\windows\system32\wininet.dll
2014-05-01 01:42 . 2014-05-01 01:42 1967104 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2014-05-01 01:42 . 2014-05-01 01:42 195584 ----a-w- c:\windows\system32\msrating.dll
2014-05-01 01:42 . 2014-05-01 01:42 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2014-05-01 01:42 . 2014-05-01 01:42 1400832 ----a-w- c:\windows\system32\urlmon.dll
2014-05-01 01:42 . 2014-05-01 01:42 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2014-05-01 01:42 . 2014-05-01 01:42 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2014-05-01 01:42 . 2014-05-01 01:42 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2014-05-01 01:42 . 2014-05-01 01:42 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-05-01 01:42 . 2014-05-01 01:42 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2014-05-01 01:42 . 2014-05-01 01:42 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2014-05-01 01:42 . 2014-05-01 01:42 105984 ----a-w- c:\windows\system32\iesysprep.dll
2014-05-01 01:42 . 2014-05-01 01:42 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2014-05-01 01:42 . 2014-05-01 01:42 846336 ----a-w- c:\windows\system32\ieapfltr.dll
2014-05-01 01:42 . 2014-05-01 01:42 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2014-05-01 01:42 . 2014-05-01 01:42 81408 ----a-w- c:\windows\system32\icardie.dll
2014-05-01 01:42 . 2014-05-01 01:42 774144 ----a-w- c:\windows\system32\jscript.dll
2014-05-01 01:42 . 2014-05-01 01:42 77312 ----a-w- c:\windows\system32\tdc.ocx
2014-05-01 01:42 . 2014-05-01 01:42 66048 ----a-w- c:\windows\system32\iesetup.dll
2014-05-01 01:42 . 2014-05-01 01:42 628736 ----a-w- c:\windows\system32\msfeeds.dll
2014-05-01 01:42 . 2014-05-01 01:42 62464 ----a-w- c:\windows\system32\pngfilt.dll
2014-05-01 01:42 . 2014-05-01 01:42 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2014-05-01 01:42 . 2014-05-01 01:42 586240 ----a-w- c:\windows\system32\ie4uinit.exe
2014-05-01 01:42 . 2014-05-01 01:42 548352 ----a-w- c:\windows\system32\vbscript.dll
2014-05-01 01:42 . 2014-05-01 01:42 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll
2014-05-01 01:42 . 2014-05-01 01:42 48128 ----a-w- c:\windows\system32\imgutil.dll
2014-05-01 01:42 . 2014-05-01 01:42 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2014-05-01 01:42 . 2014-05-01 01:42 413696 ----a-w- c:\windows\system32\html.iec
2014-05-01 01:42 . 2014-05-01 01:42 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2014-05-01 01:42 . 2014-05-01 01:42 38400 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2014-05-01 01:42 . 2014-05-01 01:42 33792 ----a-w- c:\windows\system32\iernonce.dll
2014-05-01 01:42 . 2014-05-01 01:42 30208 ----a-w- c:\windows\system32\licmgr10.dll
2014-05-01 01:42 . 2014-05-01 01:42 296960 ----a-w- c:\windows\system32\dxtrans.dll
2014-05-01 01:42 . 2014-05-01 01:42 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2014-05-01 01:42 . 2014-05-01 01:42 243200 ----a-w- c:\windows\system32\webcheck.dll
2014-05-01 01:42 . 2014-05-01 01:42 235520 ----a-w- c:\windows\system32\url.dll
2014-05-01 01:42 . 2014-05-01 01:42 2043904 ----a-w- c:\windows\system32\inetcpl.cpl
2014-05-01 01:42 . 2014-05-01 01:42 167424 ----a-w- c:\windows\system32\iexpress.exe
2014-05-01 01:42 . 2014-05-01 01:42 147968 ----a-w- c:\windows\system32\occache.dll
2014-05-01 01:42 . 2014-05-01 01:42 143872 ----a-w- c:\windows\system32\wextract.exe
2014-05-01 01:42 . 2014-05-01 01:42 139264 ----a-w- c:\windows\system32\ieUnatt.exe
2014-05-01 01:42 . 2014-05-01 01:42 13824 ----a-w- c:\windows\system32\mshta.exe
2014-05-01 01:42 . 2014-05-01 01:42 135680 ----a-w- c:\windows\system32\iepeers.dll
2014-05-01 01:42 . 2014-05-01 01:42 13551104 ----a-w- c:\windows\system32\ieframe.dll
2014-05-01 01:42 . 2014-05-01 01:42 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2014-05-01 01:42 . 2014-05-01 01:42 111616 ----a-w- c:\windows\system32\ieetwcollector.exe
2014-05-01 01:42 . 2014-05-01 01:42 101376 ----a-w- c:\windows\system32\inseng.dll
2014-05-01 01:26 . 2014-05-01 01:26 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-05-01 01:26 . 2014-05-01 01:26 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-05-01 01:26 . 2014-05-01 01:26 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2014-05-01 01:26 . 2014-05-01 01:26 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2014-05-01 01:26 . 2014-05-01 01:26 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-05-01 01:26 . 2014-05-01 01:26 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-05-01 01:26 . 2014-05-01 01:26 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-05-01 01:26 . 2014-05-01 01:26 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-05-01 01:26 . 2014-05-01 01:26 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2014-05-01 01:26 . 2014-05-01 01:26 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-05-01 01:26 . 2014-05-01 01:26 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-05-01 01:26 . 2014-05-01 01:26 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2014-05-01 01:26 . 2014-05-01 01:26 363008 ----a-w- c:\windows\system32\dxgi.dll
2014-05-01 01:26 . 2014-05-01 01:26 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-05-01 01:26 . 2014-05-01 01:26 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-05-01 01:26 . 2014-05-01 01:26 333312 ----a-w- c:\windows\system32\d3d10_1core.dll
2014-05-01 01:26 . 2014-05-01 01:26 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2014-02-10 20922016]
"HydraVisionDesktopManager"="c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [2013-03-28 389120]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-04-16 642656]
"Avira Systray"="c:\program files (x86)\Avira\My Avira\Avira.OE.Systray.exe" [2014-05-05 182352]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-05-09 737872]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 ATICDSDr;ATICDSDr;c:\users\MASCHI~1\AppData\Local\Temp\ATICDSDr.sys;c:\users\MASCHI~1\AppData\Local\Temp\ATICDSDr.sys [x]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 FairplayKD;FairplayKD;c:\programdata\MTA San Andreas All\Common\temp\FairplayKD.sys;c:\programdata\MTA San Andreas All\Common\temp\FairplayKD.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x]
R3 ScreamBAudioSvc;ScreamBee Audio;c:\windows\system32\drivers\ScreamingBAudio64.sys;c:\windows\SYSNATIVE\drivers\ScreamingBAudio64.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 Avira.OE.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [x]
S2 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
S2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [x]
S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [x]
S2 BstHdUpdaterSvc;BlueStacks Updater Service;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-05-20 23:08 1091912 ----a-w- c:\program files (x86)\Google\Chrome\Application\35.0.1916.114\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-06-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-29 21:59]
.
2014-05-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-04-28 15:46]
.
2014-05-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-04-28 15:46]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2013-11-04 7204568]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mDefault_Search_URL = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.google.com
TCP: DhcpNameServer = 10.1.1.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3372416275-4010862124-415154746-1000\Software\SecuROM\License information*]
"datasecu"=hex:1c,c4,48,19,4a,52,cb,a1,ac,0d,a8,ab,c1,7c,9d,4a,48,1c,1f,94,fe,
21,4a,76,63,ea,ea,c2,17,61,37,07,d4,dd,8c,e6,87,5d,69,34,5e,80,08,6b,17,cb,\
"rkeysecu"=hex:e0,ed,45,34,34,b8,d2,00,b3,d2,01,41,ca,46,be,00
.
[HKEY_LOCAL_MACHINE\SOFTWARE\BlueStacks]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.9"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil9f.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil9f.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}]
@Denied: (A 2) (Everyone)
@="IFlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\BlueStacks\HD-Service.exe
c:\program files (x86)\BlueStacks\HD-Network.exe
c:\program files (x86)\BlueStacks\HD-BlockDevice.exe
c:\program files (x86)\BlueStacks\HD-SharedFolder.exe
c:\program files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2014-06-01 15:27:39 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2014-06-01 13:27
.
Vor Suchlauf: 12 Verzeichnis(se), 112.717.893.632 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 119.117.320.192 Bytes frei
.
- - End Of File - - E21BF07EE4F77E929F88537E0833C211
A36C5E4F47E84449FF07ED3517B43A31 |