Roland11 | 02.06.2014 19:20 | Hi schrauber,
ich hab den Windows Defender, Windows-Firewall und Avira deaktiviert und es kam folgende Meldung von Avira wo Combofix durchgelaufen ist.
"Der Administrator hat per Sicherheitsrichtlinie den Zugriff auf die Registry blockiert."
hier ist der Log von Combofix: Code:
ComboFix 14-05-29.01 - Schwefel 02.06.2014 19:53:17.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.8076.6539 [GMT 2:00]
ausgeführt von:: c:\users\Schwefel\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Schwefel\AppData\Roaming\siw_sdk.dll
c:\windows\wininit.ini
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-05-02 bis 2014-06-02 ))))))))))))))))))))))))))))))
.
.
2014-06-02 17:55 . 2014-06-02 17:55 -------- d-----w- c:\users\DefaultAppPool\AppData\Local\temp
2014-06-02 17:55 . 2014-06-02 17:55 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-06-02 15:36 . 2014-06-02 15:37 -------- d-----w- C:\FRST
2014-06-02 15:08 . 2014-06-02 15:08 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DE4136DD-F8EF-4943-ABAF-DBC20910D169}\offreg.dll
2014-06-02 15:04 . 2014-06-02 15:04 -------- d-----w- c:\users\Schwefel\AppData\Roaming\OpenOffice
2014-06-02 15:04 . 2014-06-02 15:04 -------- d-----w- c:\program files (x86)\OpenOffice 4
2014-05-31 14:13 . 2014-05-31 14:13 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-05-31 14:13 . 2014-05-31 14:13 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-05-30 14:32 . 2014-05-30 14:32 -------- d-----w- c:\program files\CCleaner
2014-05-30 14:30 . 2014-05-30 14:35 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2
2014-05-30 10:48 . 2014-05-30 13:14 -------- d-----w- c:\program files (x86)\VS Revo Group
2014-05-30 09:33 . 2014-04-30 23:20 10702536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DE4136DD-F8EF-4943-ABAF-DBC20910D169}\mpengine.dll
2014-05-27 23:06 . 2014-06-02 13:49 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-05-27 23:05 . 2014-05-27 23:05 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-05-27 23:05 . 2014-05-12 05:26 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-05-27 23:05 . 2014-05-12 05:26 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-05-17 15:39 . 2014-05-17 15:39 -------- d-sh--w- c:\users\Schwefel\AppData\Local\EmieUserList
2014-05-17 15:39 . 2014-05-17 15:39 -------- d-sh--w- c:\users\Schwefel\AppData\Local\EmieSiteList
2014-05-14 18:28 . 2014-05-06 04:40 23544320 ----a-w- c:\windows\system32\mshtml.dll
2014-05-14 18:28 . 2014-05-06 04:17 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-05-14 18:28 . 2014-05-06 03:00 84992 ----a-w- c:\windows\system32\mshtmled.dll
2014-05-14 18:28 . 2014-05-06 03:07 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2014-05-07 00:35 . 2014-05-15 09:31 -------- d-s---w- c:\windows\system32\CompatTel
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-27 12:15 . 2013-08-27 13:03 130584 ----a-w- c:\windows\system32\drivers\avipbb.sys
2014-05-27 12:15 . 2013-08-27 13:03 112080 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2014-05-14 18:27 . 2012-12-13 08:31 93223848 ----a-w- c:\windows\system32\MRT.exe
2014-05-12 05:25 . 2013-04-08 14:09 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-03-31 07:35 . 2010-11-21 03:27 270496 ------w- c:\windows\system32\MpSigStub.exe
2014-03-06 09:31 . 2014-04-29 18:54 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2014-03-06 08:59 . 2014-04-29 18:54 66048 ----a-w- c:\windows\system32\iesetup.dll
2014-03-06 08:57 . 2014-04-29 18:54 548352 ----a-w- c:\windows\system32\vbscript.dll
2014-03-06 08:57 . 2014-04-29 18:54 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll
2014-03-06 08:53 . 2014-04-29 18:54 2767360 ----a-w- c:\windows\system32\iertutil.dll
2014-03-06 08:40 . 2014-04-29 18:54 51200 ----a-w- c:\windows\system32\jsproxy.dll
2014-03-06 08:39 . 2014-04-29 18:54 33792 ----a-w- c:\windows\system32\iernonce.dll
2014-03-06 08:32 . 2014-04-29 18:54 574976 ----a-w- c:\windows\system32\ieui.dll
2014-03-06 08:29 . 2014-04-29 18:54 139264 ----a-w- c:\windows\system32\ieUnatt.exe
2014-03-06 08:29 . 2014-04-29 18:54 111616 ----a-w- c:\windows\system32\ieetwcollector.exe
2014-03-06 08:28 . 2014-04-29 18:54 752640 ----a-w- c:\windows\system32\jscript9diag.dll
2014-03-06 08:15 . 2014-04-29 18:54 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-03-06 08:11 . 2014-04-29 18:54 5784064 ----a-w- c:\windows\system32\jscript9.dll
2014-03-06 08:09 . 2014-04-29 18:54 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2014-03-06 08:03 . 2014-04-29 18:54 586240 ----a-w- c:\windows\system32\ie4uinit.exe
2014-03-06 08:02 . 2014-04-29 18:54 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2014-03-06 08:02 . 2014-04-29 18:54 455168 ----a-w- c:\windows\SysWow64\vbscript.dll
2014-03-06 08:01 . 2014-04-29 18:54 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2014-03-06 07:56 . 2014-04-29 18:54 38400 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2014-03-06 07:48 . 2014-04-29 18:54 195584 ----a-w- c:\windows\system32\msrating.dll
2014-03-06 07:46 . 2014-04-29 18:54 4254720 ----a-w- c:\windows\SysWow64\jscript9.dll
2014-03-06 07:42 . 2014-04-29 18:54 296960 ----a-w- c:\windows\system32\dxtrans.dll
2014-03-06 07:38 . 2014-04-29 18:54 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2014-03-06 07:36 . 2014-04-29 18:54 592896 ----a-w- c:\windows\SysWow64\jscript9diag.dll
2014-03-06 07:21 . 2014-04-29 18:54 628736 ----a-w- c:\windows\system32\msfeeds.dll
2014-03-06 07:13 . 2014-04-29 18:54 32256 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2014-03-06 07:11 . 2014-04-29 18:54 2043904 ----a-w- c:\windows\system32\inetcpl.cpl
2014-03-06 06:53 . 2014-04-29 18:54 13551104 ----a-w- c:\windows\system32\ieframe.dll
2014-03-06 06:40 . 2014-04-29 18:54 1967104 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2014-03-06 06:22 . 2014-04-29 18:54 2260480 ----a-w- c:\windows\system32\wininet.dll
2014-03-06 05:58 . 2014-04-29 18:54 1400832 ----a-w- c:\windows\system32\urlmon.dll
2014-03-06 05:50 . 2014-04-29 18:54 846336 ----a-w- c:\windows\system32\ieapfltr.dll
2014-03-06 05:41 . 2014-04-29 18:54 1789440 ----a-w- c:\windows\SysWow64\wininet.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-02-26 291608]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-05-27 737872]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2013-12-06 766208]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 ikbevent;Intel Upper keyboard Class Filter Driver;c:\windows\system32\DRIVERS\ikbevent.sys;c:\windows\SYSNATIVE\DRIVERS\ikbevent.sys [x]
R3 imsevent;Intel Upper Mouse Class Filter Driver;c:\windows\system32\DRIVERS\imsevent.sys;c:\windows\SYSNATIVE\DRIVERS\imsevent.sys [x]
R3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
R3 ISCT;Intel(R) Smart Connect Technology Device Driver;c:\windows\system32\DRIVERS\ISCTD64.sys;c:\windows\SYSNATIVE\DRIVERS\ISCTD64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Microsoft Virtual 3D Video Transport Driver;c:\windows\system32\drivers\Synth3dVsc.sys;c:\windows\SYSNATIVE\drivers\Synth3dVsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;Remote Deskotop USB Hub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
S0 asahci64;asahci64;c:\windows\system32\DRIVERS\asahci64.sys;c:\windows\SYSNATIVE\DRIVERS\asahci64.sys [x]
S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorA.sys [x]
S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorF.sys [x]
S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-10-17 13307496]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-14 172144]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-12-14 399984]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-14 441968]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Schwefel\AppData\Roaming\Mozilla\Firefox\Profiles\a9a27afx.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-Steam App 300 - e:\steam\steam.exe
AddRemove-Steam App 570 - e:\steam\steam.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3725082610-1877465288-1235946033-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.* Z*w*i*s*c*h*e*n*s*p*i*e*l*)*\OpenWithList]
@Class="Shell"
"a"="Mp3tag.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-3725082610-1877465288-1235946033-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\SecuROM\License information*]
"datasecu"=hex:a0,ae,6f,32,62,74,49,42,24,af,22,38,b9,7e,01,69,13,d1,a9,58,3b,
a5,8a,28,a4,d3,3f,cd,2b,d5,a2,55,7e,70,a0,49,e4,9d,5e,35,b2,c4,4f,96,44,86,\
"rkeysecu"=hex:58,b3,e4,37,77,3f,bf,66,ed,13,dc,82,7e,f6,b5,b0
.
[HKEY_USERS\S-1-5-21-3725082610-1877465288-1235946033-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.* Z*w*i*s*c*h*e*n*s*p*i*e*l*)*\OpenWithList]
@Class="Shell"
"a"="Mp3tag.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-3725082610-1877465288-1235946033-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\SecuROM\License information*]
"datasecu"=hex:a0,ae,6f,32,62,74,49,42,24,af,22,38,b9,7e,01,69,13,d1,a9,58,3b,
a5,8a,28,a4,d3,3f,cd,2b,d5,a2,55,7e,70,a0,49,e4,9d,5e,35,b2,c4,4f,96,44,86,\
"rkeysecu"=hex:58,b3,e4,37,77,3f,bf,66,ed,13,dc,82,7e,f6,b5,b0
.
[HKEY_USERS\S-1-5-21-3725082610-1877465288-1235946033-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.* Z*w*i*s*c*h*e*n*s*p*i*e*l*)*\OpenWithList]
@Class="Shell"
"a"="Mp3tag.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-3725082610-1877465288-1235946033-1001\Software\SecuROM\License information*]
"datasecu"=hex:a0,ae,6f,32,62,74,49,42,24,af,22,38,b9,7e,01,69,13,d1,a9,58,3b,
a5,8a,28,a4,d3,3f,cd,2b,d5,a2,55,7e,70,a0,49,e4,9d,5e,35,b2,c4,4f,96,44,86,\
"rkeysecu"=hex:58,b3,e4,37,77,3f,bf,66,ed,13,dc,82,7e,f6,b5,b0
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-06-02 19:56:37
ComboFix-quarantined-files.txt 2014-06-02 17:56
.
Vor Suchlauf: 10 Verzeichnis(se), 82.094.116.864 Bytes frei
Nach Suchlauf: 13 Verzeichnis(se), 82.099.355.648 Bytes frei
.
- - End Of File - - 8848A60725F9DEC5A479974C16A01A24
A36C5E4F47E84449FF07ED3517B43A31 Grüße Roland. |