Hallo :)
schon fertig. Code:
Combofix Logfile:
Code:
ComboFix 14-10-29.01 - .....02.11.2014 13:48:17.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.2039.1084 [GMT 1:00]
ausgeführt von:: c:\users....\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-10-02 bis 2014-11-02 ))))))))))))))))))))))))))))))
.
.
2014-11-02 12:54 . 2014-11-02 12:54 -------- d-----w- c:\users\Public\AppData\Local\temp
2014-11-02 12:54 . 2014-11-02 12:54 -------- d-----w- c:\users\hedev\AppData\Local\temp
2014-11-02 12:54 . 2014-11-02 12:54 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-11-01 19:03 . 2014-11-01 19:08 -------- d-----w- C:\FRST
2014-10-28 09:15 . 2014-10-28 09:15 -------- d-----w- c:\program files (x86)\Common Files\Java
2014-10-28 09:14 . 2014-10-28 09:14 98216 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-10-28 06:57 . 2014-10-28 06:57 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2014-10-28 06:57 . 2014-10-28 06:57 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2014-10-28 06:57 . 2014-10-28 06:57 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2014-10-28 06:57 . 2014-10-28 06:57 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2014-10-28 06:57 . 2014-10-28 06:57 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2014-10-28 06:56 . 2014-10-28 06:57 -------- d-----w- c:\program files (x86)\QuickTime
2014-10-28 06:56 . 2014-10-28 06:56 -------- d-----w- c:\programdata\Apple Computer
2014-10-22 17:58 . 2014-10-22 17:58 -------- d-----w- c:\users\.....\AppData\Local\Skype
2014-10-22 17:57 . 2014-10-22 17:57 -------- d-----w- c:\program files (x86)\Common Files\Skype
2014-10-22 17:57 . 2014-10-22 17:57 -------- d-----r- c:\program files (x86)\Skype
2014-10-22 17:44 . 2014-10-22 17:44 -------- d-sh--w- c:\users\....\AppData\Local\EmieUserList
2014-10-22 17:44 . 2014-10-22 17:44 -------- d-sh--w- c:\users\....\AppData\Local\EmieSiteList
2014-10-15 14:51 . 2014-07-07 02:07 14632960 ----a-w- c:\windows\system32\wmp.dll
2014-10-15 14:50 . 2014-07-07 02:06 102912 ----a-w- c:\program files\Windows Media Player\wmpshare.exe
2014-10-15 14:49 . 2014-07-17 02:07 681984 ----a-w- c:\windows\system32\termsrv.dll
2014-10-15 14:49 . 2014-07-17 02:07 235520 ----a-w- c:\windows\system32\winsta.dll
2014-10-15 14:49 . 2014-07-17 02:07 150528 ----a-w- c:\windows\system32\rdpcorekmts.dll
2014-10-15 14:49 . 2014-07-17 01:40 157696 ----a-w- c:\windows\SysWow64\winsta.dll
2014-10-15 14:49 . 2014-07-17 01:21 212480 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2014-10-15 14:49 . 2014-07-17 02:07 86528 ----a-w- c:\windows\system32\TSpkg.dll
2014-10-15 14:49 . 2014-07-17 02:07 455168 ----a-w- c:\windows\system32\winlogon.exe
2014-10-15 14:49 . 2014-07-17 01:39 65536 ----a-w- c:\windows\SysWow64\TSpkg.dll
2014-10-15 14:49 . 2014-07-17 02:07 22016 ----a-w- c:\windows\system32\credssp.dll
2014-10-15 14:49 . 2014-07-17 01:39 17408 ----a-w- c:\windows\SysWow64\credssp.dll
2014-10-15 14:49 . 2014-07-17 01:21 39936 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2014-10-15 14:48 . 2014-06-18 22:23 73880 ----a-w- c:\windows\system32\mscories.dll
2014-10-15 14:48 . 2014-06-18 22:23 1943696 ----a-w- c:\windows\system32\dfshim.dll
2014-10-15 14:48 . 2014-06-18 22:23 156312 ----a-w- c:\windows\system32\mscorier.dll
2014-10-15 14:48 . 2014-06-18 22:23 81560 ----a-w- c:\windows\SysWow64\mscories.dll
2014-10-15 14:48 . 2014-06-18 22:23 156824 ----a-w- c:\windows\SysWow64\mscorier.dll
2014-10-15 14:48 . 2014-06-18 22:23 1131664 ----a-w- c:\windows\SysWow64\dfshim.dll
2014-10-15 14:44 . 2014-08-30 02:10 6583296 ----a-w- c:\windows\system32\mstscax.dll
2014-10-15 14:44 . 2014-08-30 01:50 5702656 ----a-w- c:\windows\SysWow64\mstscax.dll
2014-10-15 14:44 . 2014-09-29 00:58 3198976 ----a-w- c:\windows\system32\win32k.sys
2014-10-15 14:43 . 2014-09-04 05:23 424448 ----a-w- c:\windows\system32\rastls.dll
2014-10-15 14:43 . 2014-09-04 05:04 372736 ----a-w- c:\windows\SysWow64\rastls.dll
2014-10-15 14:43 . 2014-09-13 01:58 77312 ----a-w- c:\windows\system32\packager.dll
2014-10-15 14:43 . 2014-09-13 01:40 67072 ----a-w- c:\windows\SysWow64\packager.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-11-02 07:03 . 2010-03-25 17:36 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2014-11-02 07:03 . 2010-06-04 13:54 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2014-11-01 07:10 . 2010-03-18 12:37 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2014-11-01 07:09 . 2010-05-19 11:07 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2014-11-01 07:09 . 2010-03-18 12:37 1236816 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2014-10-30 14:28 . 2010-06-04 13:54 1236816 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2014-10-28 05:34 . 2010-03-17 07:28 275080 ------w- c:\windows\system32\MpSigStub.exe
2014-10-21 04:05 . 2014-09-10 03:58 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-10-21 04:05 . 2014-09-10 03:58 701104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-10-15 14:53 . 2010-03-19 12:48 103265616 ----a-w- c:\windows\system32\MRT.exe
2014-10-02 13:23 . 2014-10-02 13:23 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2014-10-02 13:23 . 2014-10-02 13:23 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
2014-09-10 03:55 . 2014-08-23 11:55 10036224 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2014-08-23 13:37 . 2012-11-03 09:42 427360 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-08-23 13:37 . 2014-05-10 13:31 92008 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-08-23 13:37 . 2014-05-10 13:31 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-08-23 13:37 . 2013-03-18 15:08 224896 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-08-23 13:37 . 2013-03-18 15:08 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-08-23 13:37 . 2012-11-03 09:41 1041168 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-08-23 13:37 . 2012-11-03 09:41 79184 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-08-23 13:37 . 2011-03-05 11:40 307344 ----a-w- c:\windows\system32\aswBoot.exe
2014-08-23 13:37 . 2012-11-03 09:41 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-08-23 13:37 . 2014-08-23 13:37 43152 ----a-w- c:\windows\avastSS.scr
2014-08-23 02:07 . 2014-08-30 05:31 404480 ----a-w- c:\windows\system32\gdi32.dll
2014-08-23 01:45 . 2014-08-30 05:31 311808 ----a-w- c:\windows\SysWow64\gdi32.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2014-10-01 22058080]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-08-28 2252800]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-07-04 641704]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-08-23 4085896]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"MobileBroadband"="c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" [2013-02-05 76288]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2014-10-02 421888]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2014-09-26 271744]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 DAUpdaterSvc;Dragon Age: Origins - Inhaltsupdater;c:\program files (x86)\Electronic Arts\Dragon Age Origins\\bin_ship\DAUpdaterSvc.Service.exe;c:\program files (x86)\Electronic Arts\Dragon Age Origins\\bin_ship\DAUpdaterSvc.Service.exe [x]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys;c:\windows\SYSNATIVE\DRIVERS\ew_hwusbdev.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys;c:\windows\SYSNATIVE\drivers\massfilter.sys [x]
R3 nmwcdcx64;Nokia USB Generic;c:\windows\system32\drivers\ccdcmbox64.sys;c:\windows\SYSNATIVE\drivers\ccdcmbox64.sys [x]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\ccdcmbx64.sys;c:\windows\SYSNATIVE\drivers\ccdcmbx64.sys [x]
R3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys;c:\program files\PeerBlock\pbfilter.sys [x]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys;c:\windows\SYSNATIVE\DRIVERS\psi_mf.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe;c:\program files (x86)\Secunia\PSI\PSIA.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 UXDCMN;UXDCMN;c:\users\.....\Desktop\_WinStress\UXDCMN.SYS;c:\users\....\Desktop\_WinStress\UXDCMN.SYS [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 FoxitCloudUpdateService;Foxit Cloud Safe Update Service;c:\program files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe;c:\program files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [x]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe;c:\program files (x86)\Secunia\PSI\sua.exe [x]
S2 VmbService;Vodafone-Mobile-Broadband-Dienst;c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe;c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\DRIVERS\ew_usbenumfilter.sys;c:\windows\SYSNATIVE\DRIVERS\ew_usbenumfilter.sys [x]
S3 huawei_cdcacm;huawei_cdcacm;c:\windows\system32\DRIVERS\ew_jucdcacm.sys;c:\windows\SYSNATIVE\DRIVERS\ew_jucdcacm.sys [x]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys;c:\windows\SYSNATIVE\DRIVERS\ew_jubusenum.sys [x]
S3 huawei_ext_ctrl;huawei_ext_ctrl;c:\windows\system32\DRIVERS\ew_juextctrl.sys;c:\windows\SYSNATIVE\DRIVERS\ew_juextctrl.sys [x]
S3 huawei_wwanecm;huawei_wwanecm;c:\windows\system32\DRIVERS\ew_juwwanecm.sys;c:\windows\SYSNATIVE\DRIVERS\ew_juwwanecm.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-10-29 05:19 1089352 ----a-w- c:\program files (x86)\Google\Chrome\Application\38.0.2125.111\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-11-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-10 04:05]
.
2014-11-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-29 08:08]
.
2014-11-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-29 08:08]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-08-23 13:37 634872 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-11 689488]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~1\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 139.7.30.125 139.7.30.126
TCP: Interfaces\{A8B9CA59-B048-48EE-A13B-A136A18DA48B}: NameServer = 139.7.30.125 139.7.30.126
FF - ProfilePath - c:\users\.....\AppData\Roaming\Mozilla\Firefox\Profiles\ecy3sklo.default\
FF - prefs.js: browser.search.defaulturl - hxxps://de.search.yahoo.com/yhs/search
FF - prefs.js: browser.search.selectedEngine - Yahoo! (Avast)
FF - prefs.js: browser.startup.homepage - hxxp://www.web.de/
FF - prefs.js: keyword.URL - hxxps://de.search.yahoo.com/yhs/search
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2504710067-1709549152-2115112438-1000\Software\SecuROM\License information*]
"datasecu"=hex:b4,ba,77,cb,8a,36,a5,72,98,76,3d,8a,b8,02,62,76,a7,e5,a5,51,e0,
0c,dd,7a,d3,cb,21,77,13,a6,7e,b6,35,e2,ca,8a,c0,8c,a8,4d,b5,22,54,b5,4c,56,\
"rkeysecu"=hex:64,b6,bd,e1,3e,80,9e,c4,40,b4,90,83,87,8e,33,49
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-11-02 13:57:30
ComboFix-quarantined-files.txt 2014-11-02 12:57
.
Vor Suchlauf: 18 Verzeichnis(se), 800.004.481.024 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 799.744.466.944 Bytes frei
.
- - End Of File - - 82610AFB6487F069A29DEA4979F48AF9 --- --- ---
A36C5E4F47E84449FF07ED3517B43A31 Zitat:
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten..
| Da kam nichts, lief alles ganz normal.
mfg
Lyna |