SirHenry2 | 05.07.2015 10:51 | Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-07-05 11:17:48
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 Crucial_CT240M500SSD1 rev.MU03 223,57GB
Running: Gmer-19357.exe; Driver: C:\Users\Gustav\AppData\Local\Temp\kgdcipob.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1640] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075492ab1 5 bytes JMP 000000010012f182
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2604] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 00000000750c8781 8 bytes [31, C0, C2, 04, 00, 90, 90, ...]
.text C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe[2640] C:\Windows\syswow64\PsApi.dll!GetModuleFileNameExW + 17 00000000749f1401 2 bytes JMP 750eb21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe[2640] C:\Windows\syswow64\PsApi.dll!EnumProcessModules + 17 00000000749f1419 2 bytes JMP 750eb346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe[2640] C:\Windows\syswow64\PsApi.dll!GetModuleInformation + 17 00000000749f1431 2 bytes JMP 75168f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe[2640] C:\Windows\syswow64\PsApi.dll!GetModuleInformation + 42 00000000749f144a 2 bytes CALL 750c489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe[2640] C:\Windows\syswow64\PsApi.dll!EnumDeviceDrivers + 17 00000000749f14dd 2 bytes JMP 75168822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe[2640] C:\Windows\syswow64\PsApi.dll!GetDeviceDriverBaseNameA + 17 00000000749f14f5 2 bytes JMP 751689f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe[2640] C:\Windows\syswow64\PsApi.dll!QueryWorkingSetEx + 17 00000000749f150d 2 bytes JMP 75168718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe[2640] C:\Windows\syswow64\PsApi.dll!GetDeviceDriverBaseNameW + 17 00000000749f1525 2 bytes JMP 75168ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe[2640] C:\Windows\syswow64\PsApi.dll!GetModuleBaseNameW + 17 00000000749f153d 2 bytes JMP 750dfca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe[2640] C:\Windows\syswow64\PsApi.dll!EnumProcesses + 17 00000000749f1555 2 bytes JMP 750e68ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe[2640] C:\Windows\syswow64\PsApi.dll!GetProcessMemoryInfo + 17 00000000749f156d 2 bytes JMP 75168fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe[2640] C:\Windows\syswow64\PsApi.dll!GetPerformanceInfo + 17 00000000749f1585 2 bytes JMP 75168b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe[2640] C:\Windows\syswow64\PsApi.dll!QueryWorkingSet + 17 00000000749f159d 2 bytes JMP 751686dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe[2640] C:\Windows\syswow64\PsApi.dll!GetModuleBaseNameA + 17 00000000749f15b5 2 bytes JMP 750dfd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe[2640] C:\Windows\syswow64\PsApi.dll!GetModuleFileNameExA + 17 00000000749f15cd 2 bytes JMP 750eb2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe[2640] C:\Windows\syswow64\PsApi.dll!GetProcessImageFileNameW + 20 00000000749f16b2 2 bytes JMP 75168ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe[2640] C:\Windows\syswow64\PsApi.dll!GetProcessImageFileNameW + 31 00000000749f16bd 2 bytes JMP 75168671 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\system32\PnkBstrA.exe[3612] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000749f1401 2 bytes JMP 750eb21b C:\Windows\syswow64\kernel32.dll
.text C:\Windows\system32\PnkBstrA.exe[3612] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000749f1419 2 bytes JMP 750eb346 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\system32\PnkBstrA.exe[3612] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000749f1431 2 bytes JMP 75168f29 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\system32\PnkBstrA.exe[3612] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000749f144a 2 bytes CALL 750c489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Windows\system32\PnkBstrA.exe[3612] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000749f14dd 2 bytes JMP 75168822 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\system32\PnkBstrA.exe[3612] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000749f14f5 2 bytes JMP 751689f8 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\system32\PnkBstrA.exe[3612] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000749f150d 2 bytes JMP 75168718 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\system32\PnkBstrA.exe[3612] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000749f1525 2 bytes JMP 75168ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\system32\PnkBstrA.exe[3612] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000749f153d 2 bytes JMP 750dfca8 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\system32\PnkBstrA.exe[3612] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000749f1555 2 bytes JMP 750e68ef C:\Windows\syswow64\kernel32.dll
.text C:\Windows\system32\PnkBstrA.exe[3612] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000749f156d 2 bytes JMP 75168fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\system32\PnkBstrA.exe[3612] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000749f1585 2 bytes JMP 75168b42 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\system32\PnkBstrA.exe[3612] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000749f159d 2 bytes JMP 751686dc C:\Windows\syswow64\kernel32.dll
.text C:\Windows\system32\PnkBstrA.exe[3612] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000749f15b5 2 bytes JMP 750dfd41 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\system32\PnkBstrA.exe[3612] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000749f15cd 2 bytes JMP 750eb2dc C:\Windows\syswow64\kernel32.dll
.text C:\Windows\system32\PnkBstrA.exe[3612] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000749f16b2 2 bytes JMP 75168ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\system32\PnkBstrA.exe[3612] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000749f16bd 2 bytes JMP 75168671 C:\Windows\syswow64\kernel32.dll
---- Threads - GMER 2.1 ----
Thread C:\Windows\System32\svchost.exe [3736:6340] 000007fef7c29688
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x8B 0x8D 0xB5 0x03 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x17 0xD8 0x63 0x15 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xD7 0x8D 0x4D 0x76 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x72 0x86 0x6C 0xE0 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x8B 0x8D 0xB5 0x03 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x17 0xD8 0x63 0x15 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xD7 0x8D 0x4D 0x76 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x72 0x86 0x6C 0xE0 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
---- EOF - GMER 2.1 ---- Code:
ComboFix 15-06-30.01 - Gustav 05.07.2015 11:40:24.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8079.6299 [GMT 2:00]
ausgeführt von:: C:\Users\Gustav\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
FW: avast! Antivirus *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
C:\ProgramData\ntuser.pol
((((((((((((((((((((((( Dateien erstellt von 2015-06-05 bis 2015-07-05 ))))))))))))))))))))))))))))))
2015-07-05 09:43:21 . 2015-07-05 09:43:21 -------- d-----w- C:\Users\Default\AppData\Local\temp
2015-07-05 09:43:21 . 2015-07-05 09:43:21 -------- d-----w- C:\Users\Administrator\AppData\Local\temp
2015-07-05 09:39:24 . 2015-07-05 09:39:24 -------- d-----w- C:\Program Files\{F3D4780F-89FF-47DA-B5C2-665C7DAEC81B}
2015-07-05 09:39:24 . 2015-07-05 09:39:24 -------- d-----w- C:\Program Files (x86)\{54D19A04-A4A2-45E1-8A19-1CC49AFAED2A}
2015-07-04 23:31:29 . 2015-07-04 23:31:29 -------- d-----w- C:\Program Files (x86)\Windows Kits
2015-07-04 23:28:43 . 2015-07-04 23:28:43 -------- d-----w- C:\Program Files\NetWorx
2015-07-04 23:28:43 . 2015-06-15 07:25:50 70120 ----a-w- C:\Windows\system32\drivers\networx.sys
2015-07-04 17:15:03 . 2015-07-04 17:15:03 -------- d-----w- C:\RegBackup
2015-07-04 17:13:43 . 2015-07-05 09:00:34 -------- d-----w- C:\FRST
2015-07-04 16:03:23 . 2015-07-04 16:03:23 -------- d-----w- C:\ProgramData\Malwarebytes
2015-07-04 15:48:20 . 2015-07-05 01:37:48 -------- d-----w- C:\AdwCleaner
2015-07-03 13:59:39 . 2015-07-03 13:59:39 -------- d-----w- C:\Users\Gustav\AppData\Local\ESN
2015-07-03 12:05:32 . 2015-06-12 07:50:55 12221144 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C1E511E5-B6D9-4B44-9721-A266CC4AF473}\mpengine.dll
2015-06-30 16:17:53 . 2015-06-30 16:18:38 -------- d-----w- C:\Program Files (x86)\Blizzard
2015-06-28 12:06:20 . 2015-06-28 12:06:20 -------- d-----w- C:\Users\Gustav\AppData\Local\Blizzard
2015-06-28 09:10:51 . 2015-06-28 09:10:51 -------- d-----w- C:\Users\Gustav\AppData\Roaming\AVG
2015-06-28 09:10:45 . 2015-06-28 09:10:45 -------- d-----w- C:\Users\Gustav\AppData\Local\Avg
2015-06-28 09:10:34 . 2015-06-28 09:10:58 -------- d-----w- C:\ProgramData\AVG
2015-06-28 09:10:15 . 2015-06-28 09:10:15 434208 ----a-w- C:\Windows\system32\DnsBlockA.dll
2015-06-28 09:10:15 . 2015-06-28 09:10:15 433696 ----a-w- C:\Windows\system32\DnsBlockB.dll
2015-06-28 09:10:15 . 2015-06-28 09:10:15 343584 ----a-w- C:\Windows\SysWow64\DnsBlockB.dll
2015-06-28 09:10:15 . 2015-06-28 09:10:15 343584 ----a-w- C:\Windows\SysWow64\DnsBlockA.dll
2015-06-28 09:10:15 . 2015-06-28 09:10:15 -------- d-----w- C:\Users\Gustav\AppData\Local\DnsBlock
2015-06-28 09:10:13 . 2015-06-28 09:10:13 149024 ----a-w- C:\Windows\system32\DnsBlockUpdateSvc.exe
2015-06-27 19:55:25 . 2015-06-27 19:55:29 -------- d-----w- C:\Program Files (x86)\Common Files\Blizzard Entertainment
2015-06-22 19:33:55 . 2015-05-19 03:29:01 46768 ----a-w- C:\Windows\system32\drivers\nvvad64v.sys
2015-06-22 19:33:55 . 2015-05-19 03:14:42 57520 ----a-w- C:\Windows\SysWow64\nvaudcap32v.dll
2015-06-21 09:40:57 . 2015-06-21 09:40:57 -------- d-----w- C:\Users\Gustav\AppData\Roaming\OpenOffice
2015-06-21 09:40:05 . 2015-06-21 09:40:09 -------- d-----w- C:\Program Files (x86)\OpenOffice 4
2015-06-20 22:18:11 . 2015-06-24 18:17:12 -------- d-----w- C:\Users\Gustav\AppData\Local\Fallout3
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
2015-07-03 14:05:58 . 2014-07-01 14:50:58 76152 ----a-w- C:\Windows\system32\PnkBstrA.exe
2015-07-03 14:05:47 . 2014-05-28 21:33:17 226168 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2015-07-03 14:05:41 . 2014-05-28 21:33:17 214392 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2015-06-30 16:17:18 . 2014-05-28 21:33:17 76888 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2015-06-28 14:37:55 . 2014-09-28 20:37:34 778416 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2015-06-28 14:37:55 . 2014-09-26 18:57:35 142512 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2015-06-27 19:12:07 . 2014-05-09 21:26:56 442264 ----a-w- C:\Windows\system32\drivers\aswsp.sys
2015-06-24 11:36:43 . 2014-10-07 14:20:18 1320120 ----a-w- C:\Windows\SysWow64\nvspcap.dll
2015-06-24 11:36:42 . 2014-10-07 14:22:22 1316000 ----a-w- C:\Windows\SysWow64\nvspbridge.dll
2015-06-24 11:36:31 . 2014-10-07 14:20:18 1571696 ----a-w- C:\Windows\system32\nvspcap64.dll
2015-06-24 11:36:30 . 2014-10-07 14:22:22 1756424 ----a-w- C:\Windows\system32\nvspbridge64.dll
2015-06-20 19:27:56 . 2014-05-15 16:14:47 140135120 ----a-w- C:\Windows\system32\MRT.exe
2015-05-28 07:04:11 . 2015-06-02 18:41:09 982856 ----a-w- C:\Windows\SysWow64\NvIFR.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 974480 ----a-w- C:\Windows\SysWow64\NvFBC.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 939080 ----a-w- C:\Windows\SysWow64\nvumdshim.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 503408 ----a-w- C:\Windows\system32\nvEncodeAPI64.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 42719888 ----a-w- C:\Windows\system32\nvcompiler.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 408208 ----a-w- C:\Windows\system32\NvIFROpenGL.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 407112 ----a-w- C:\Windows\SysWow64\nvEncodeAPI.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 37741712 ----a-w- C:\Windows\SysWow64\nvcompiler.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 364176 ----a-w- C:\Windows\SysWow64\NvIFROpenGL.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 31552 ----a-w- C:\Windows\system32\nvhdap64.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 30480528 ----a-w- C:\Windows\system32\nvoglv64.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 2986392 ----a-w- C:\Windows\SysWow64\nvapi.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 2932368 ----a-w- C:\Windows\system32\nvcuvid.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 2599056 ----a-w- C:\Windows\SysWow64\nvcuvid.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 22946960 ----a-w- C:\Windows\SysWow64\nvoglv32.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 195912 ----a-w- C:\Windows\system32\drivers\nvhda64v.sys
2015-05-28 07:04:11 . 2015-06-02 18:41:09 1898312 ----a-w- C:\Windows\system32\nvdispco6435306.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 175880 ----a-w- C:\Windows\system32\nvinitx.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 16185352 ----a-w- C:\Windows\system32\nvopencl.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 15864064 ----a-w- C:\Windows\system32\nvd3dumx.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 1557832 ----a-w- C:\Windows\system32\nvdispgenco6435306.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 154256 ----a-w- C:\Windows\SysWow64\nvinit.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 150648 ----a-w- C:\Windows\system32\nvoglshim64.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 14495448 ----a-w- C:\Windows\system32\nvcuda.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 13304280 ----a-w- C:\Windows\SysWow64\nvopencl.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 128512 ----a-w- C:\Windows\SysWow64\nvoglshim32.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 11830512 ----a-w- C:\Windows\SysWow64\nvcuda.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 1099808 ----a-w- C:\Windows\system32\nvumdshimx.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 10995528 ----a-w- C:\Windows\system32\drivers\nvlddmkm.sys
2015-05-28 07:04:11 . 2015-06-02 18:41:09 1059984 ----a-w- C:\Windows\system32\NvIFR64.dll
2015-05-28 07:04:11 . 2015-06-02 18:41:09 1050440 ----a-w- C:\Windows\system32\NvFBC64.dll
2015-05-28 07:04:11 . 2015-02-11 23:22:18 14987528 ----a-w- C:\Windows\SysWow64\nvwgf2um.dll
2015-05-28 07:04:11 . 2014-10-08 15:25:09 1558848 ----a-w- C:\Windows\system32\nvhdagenco6420103.dll
2015-05-28 07:04:11 . 2014-06-10 19:28:22 17486856 ----a-w- C:\Windows\system32\nvwgf2umx.dll
2015-05-28 07:04:11 . 2014-06-10 19:28:21 12852152 ----a-w- C:\Windows\SysWow64\nvd3dum.dll
2015-05-28 07:04:11 . 2014-04-28 20:35:17 3379680 ----a-w- C:\Windows\system32\nvapi64.dll
2015-05-28 04:15:30 . 2014-04-28 20:36:17 937288 ----a-w- C:\Windows\system32\nvvsvc.exe
2015-05-28 04:15:29 . 2014-04-28 20:36:17 62608 ----a-w- C:\Windows\system32\nvshext.dll
2015-05-28 04:15:29 . 2014-04-28 20:36:17 385168 ----a-w- C:\Windows\system32\nvmctray.dll
2015-05-28 04:15:29 . 2014-04-28 20:36:17 3491984 ----a-w- C:\Windows\system32\nvsvc64.dll
2015-05-28 04:15:29 . 2014-04-28 20:36:17 2558608 ----a-w- C:\Windows\system32\nvsvcr.dll
2015-05-28 04:15:28 . 2014-04-28 20:36:17 6872904 ----a-w- C:\Windows\system32\nvcpl.dll
2015-05-28 03:52:27 . 2015-06-02 18:43:15 571024 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2015-05-27 10:48:20 . 2014-04-28 20:36:17 4408727 ----a-w- C:\Windows\system32\nvcoproc.bin
2015-05-19 11:26:37 . 2015-05-19 11:26:37 30352 ----a-w- C:\Windows\system32\drivers\dtlitescsibus.sys
2015-05-19 11:26:37 . 2014-09-07 10:31:36 381608 ----a-w- C:\Windows\system32\drivers\sptd.sys
2015-05-19 03:14:42 . 2014-04-28 20:36:53 61616 ----a-w- C:\Windows\system32\nvaudcap64v.dll
2015-05-10 20:17:19 . 2015-05-10 20:17:19 0 ---ha-w- C:\Users\Gustav\AppData\Local\BIT9352.tmp
2015-05-09 03:13:33 . 2015-06-20 19:27:13 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2015-05-05 01:29:39 . 2015-05-13 23:20:53 342016 ----a-w- C:\Windows\system32\schannel.dll
2015-05-05 01:12:49 . 2015-05-13 23:20:53 248832 ----a-w- C:\Windows\SysWow64\schannel.dll
2015-05-01 13:17:03 . 2015-05-13 23:21:15 124112 ----a-w- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-01 13:16:41 . 2015-05-13 23:21:15 102608 ----a-w- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-04-25 21:57:17 . 2015-04-25 21:57:17 364472 ----a-w- C:\Windows\system32\aswBoot.exe
2015-04-25 21:57:17 . 2014-05-10 09:20:14 29168 ----a-w- C:\Windows\system32\drivers\aswHwid.sys
2015-04-25 21:57:17 . 2014-05-09 21:26:56 93528 ----a-w- C:\Windows\system32\drivers\aswRdr2.sys
2015-04-25 21:57:17 . 2014-05-09 21:26:56 89944 ----a-w- C:\Windows\system32\drivers\aswMonFlt.sys
2015-04-25 21:57:17 . 2014-05-09 21:26:56 65736 ----a-w- C:\Windows\system32\drivers\aswRvrt.sys
2015-04-25 21:57:17 . 2014-05-09 21:26:56 272248 ----a-w- C:\Windows\system32\drivers\aswVmm.sys
2015-04-25 21:57:17 . 2014-05-09 21:26:56 137288 ----a-w- C:\Windows\system32\drivers\aswStm.sys
2015-04-25 21:57:16 . 2015-04-25 21:57:16 43112 ----a-w- C:\Windows\avastSS.scr
2015-04-25 21:57:15 . 2014-05-09 21:26:56 1047320 ----a-w- C:\Windows\system32\drivers\aswSnx.sys
2015-04-20 03:17:07 . 2015-05-13 23:20:50 1647104 ----a-w- C:\Windows\system32\DWrite.dll
2015-04-20 03:17:07 . 2015-05-13 23:20:50 1179136 ----a-w- C:\Windows\system32\FntCache.dll
2015-04-20 02:56:29 . 2015-05-13 23:20:50 1250816 ----a-w- C:\Windows\SysWow64\DWrite.dll
2015-04-18 03:10:57 . 2015-05-13 23:20:53 460800 ----a-w- C:\Windows\system32\certcli.dll
2015-04-18 02:56:57 . 2015-05-13 23:20:53 342016 ----a-w- C:\Windows\SysWow64\certcli.dll
2015-04-13 03:28:33 . 2015-05-13 23:20:48 328704 ----a-w- C:\Windows\system32\services.exe
2015-04-10 19:42:30 . 2014-11-17 15:38:50 348672 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2015-04-09 00:58:18 . 2015-04-19 14:37:08 1895568 ----a-w- C:\Windows\system32\nvdispco6435012.dll
2015-04-09 00:58:18 . 2015-04-19 14:37:08 1557648 ----a-w- C:\Windows\system32\nvdispgenco6435012.dll
2015-04-08 03:29:07 . 2015-05-13 23:20:49 275456 ----a-w- C:\Windows\system32\InkEd.dll
2015-04-08 03:14:07 . 2015-05-13 23:20:48 216064 ----a-w- C:\Windows\SysWow64\InkEd.dll
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}]
2015-07-05 09:39:24 346112 ----a-w- C:\Program Files (x86)\{54D19A04-A4A2-45E1-8A19-1CC49AFAED2A}\{397B39BE-9D62-4FE2-A100-E022853577AE}.bin
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GamingMouseEditor"="C:\Program Files (x86)\GamingMouseEditor\GamingMouseEditor\GamingMouseEditor.exe" [2013-04-09 15:55:18 3352576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="C:\Windows\UpdReg.EXE" [2000-05-10 23:00:00 90112]
"Sound Blaster Recon3Di SBX Control Panel"="C:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\SBRcni.exe" [2012-11-28 11:21:38 976896]
"USB3MON"="C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2013-04-26 02:25:54 292848]
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe" [2015-05-11 15:10:42 5515496]
"GamingKeyboard"="C:\Program Files (x86)\SHARKOON Skiller\GameMon.exe" [2012-06-07 09:22:00 1803264]
"LogMeIn Hamachi Ui"="C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2015-03-30 13:29:02 3978600]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Killer Network Manager.lnk - C:\Windows\Installer\{401FADAA-1C16-4721-9F02-19067E1A1CA8}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe -minimize [2015-4-19 72040]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
R1 UsbCharger;UsbCharger;C:\Windows\system32\DRIVERS\UsbCharger.sys;C:\Windows\SYSNATIVE\DRIVERS\UsbCharger.sys [x]
R2 aswStm;aswStm;C:\Windows\system32\drivers\aswStm.sys;C:\Windows\SYSNATIVE\drivers\aswStm.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe;C:\Program Files\Intel\iCLS Client\HeciServer.exe [x]
R2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe;C:\Program Files (x86)\Skype\Updater\Updater.exe [x]
R3 AppleChargerSrv;AppleChargerSrv;C:\Windows\system32\AppleChargerSrv.exe;C:\Windows\SYSNATIVE\AppleChargerSrv.exe [x]
R3 BEService;BattlEye Service;C:\Program Files (x86)\Common Files\BattlEye\BEService.exe;C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [x]
R3 cpuz134;cpuz134;C:\Users\Gustav\AppData\Local\Temp\cpuz134\cpuz134_x64.sys;C:\Users\Gustav\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x]
R3 cpuz136;cpuz136;C:\Windows\TEMP\cpuz136\cpuz136_x64.sys;C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [x]
R3 cpuz138;cpuz138;C:\Windows\TEMP\cpuz138\cpuz138_x64.sys;C:\Windows\TEMP\cpuz138\cpuz138_x64.sys [x]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [x]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x]
R3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus;C:\Windows\system32\DRIVERS\dtlitescsibus.sys;C:\Windows\SYSNATIVE\DRIVERS\dtlitescsibus.sys [x]
R3 EasyAntiCheat;EasyAntiCheat;C:\Windows\system32\EasyAntiCheat.exe;C:\Windows\SYSNATIVE\EasyAntiCheat.exe [x]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe;C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [x]
R3 GPU-Z;GPU-Z;C:\Users\Gustav\AppData\Local\Temp\GPU-Z.sys;C:\Users\Gustav\AppData\Local\Temp\GPU-Z.sys [x]
R3 GPUZ;GPUZ;C:\Windows\TEMP\GPUZ.sys;C:\Windows\TEMP\GPUZ.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\system32\IEEtwCollector.exe;C:\Windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [x]
R3 KinectCamera;Kinect for Windows Camera Driver;C:\Windows\system32\Drivers\kinectcamera.sys;C:\Windows\SYSNATIVE\Drivers\kinectcamera.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\Windows\system32\drivers\MBAMSwissArmy.sys;C:\Windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 MFE_RR;MFE_RR;C:\Users\Gustav\AppData\Local\Temp\mfe_rr.sys;C:\Users\Gustav\AppData\Local\Temp\mfe_rr.sys [x]
R3 NTIOLib_1_0_4;NTIOLib_1_0_4;C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys;C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [x]
R3 Origin Client Service;Origin Client Service;C:\Users\Gustav\Origin\OriginClientService.exe;C:\Users\Gustav\Origin\OriginClientService.exe [x]
R3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys;C:\Windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WSDScan;WSD-Scanunterstützung durch UMB;C:\Windows\system32\DRIVERS\WSDScan.sys;C:\Windows\SYSNATIVE\DRIVERS\WSDScan.sys [x]
R4 sptd;sptd;C:\Windows\\SystemRoot\System32\Drivers\sptd.sys;C:\Windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 iaStorA;iaStorA;C:\Windows\system32\DRIVERS\iaStorA.sys;C:\Windows\SYSNATIVE\DRIVERS\iaStorA.sys [x]
S0 iaStorF;iaStorF;C:\Windows\system32\DRIVERS\iaStorF.sys;C:\Windows\SYSNATIVE\DRIVERS\iaStorF.sys [x]
S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;C:\Windows\system32\DRIVERS\iusb3hcs.sys;C:\Windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S1 AppleCharger;AppleCharger;C:\Windows\system32\DRIVERS\AppleCharger.sys;C:\Windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
S1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys;C:\Windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys;C:\Windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 BfLwf;Qualcomm Atheros Bandwidth Control;C:\Windows\system32\DRIVERS\bflwfx64.sys;C:\Windows\SYSNATIVE\DRIVERS\bflwfx64.sys [x]
S1 networx;networx;C:\Windows\system32\drivers\networx.sys;C:\Windows\SYSNATIVE\drivers\networx.sys [x]
S2 aswHwid;avast! HardwareID;C:\Windows\system32\drivers\aswHwid.sys;C:\Windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;C:\Windows\system32\drivers\aswMonFlt.sys;C:\Windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 c2cautoupdatesvc;Skype Click to Call Updater;C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe;C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [x]
S2 c2cpnrsvc;Skype Click to Call PNR Service;C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe;C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [x]
S2 CtHdaSvc;SB Recon3D Service;C:\Windows\sysWow64\CtHdaSvc.exe;C:\Windows\sysWow64\CtHdaSvc.exe [x]
S2 DnsBlockUpdateSvc;DnsBlock Update Service;C:\Windows\system32\DnsBlockUpdateSvc.exe;C:\Windows\SYSNATIVE\DnsBlockUpdateSvc.exe [x]
S2 GfExperienceService;NVIDIA GeForce Experience Service;C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;E:\Games\hirez\HiPatchService.exe;E:\Games\hirez\HiPatchService.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 KinectManagement;Kinect Management;C:\Program Files\Microsoft Kinect Drivers\Service\KinectManagementService.exe;C:\Program Files\Microsoft Kinect Drivers\Service\KinectManagementService.exe [x]
S2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
S2 NvNetworkService;NVIDIA Network Service;C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 Qualcomm Atheros Killer Service V2;Qualcomm Atheros Killer Service V2;C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe;C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 VBoxAswDrv;VBoxAsw Support Driver;C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys;C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [x]
S3 AvastVBoxSvc;AvastVBox COM Service;C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe;C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [x]
S3 cthda;SB Recon3D HDAudio;C:\Windows\system32\drivers\cthda.sys;C:\Windows\SYSNATIVE\drivers\cthda.sys [x]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys;C:\Windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S3 GameKB;SHARKOON Skiller;C:\Windows\system32\drivers\GameKB.sys;C:\Windows\SYSNATIVE\drivers\GameKB.sys [x]
S3 IntcDAud;Intel(R) Display-Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys;C:\Windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;C:\Windows\system32\DRIVERS\iusb3hub.sys;C:\Windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;C:\Windows\system32\DRIVERS\iusb3xhc.sys;C:\Windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 Ke2200;NDIS Miniport Driver for the Killer e2200 PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\e22w7x64.sys;C:\Windows\SYSNATIVE\DRIVERS\e22w7x64.sys [x]
S3 NvStreamKms;NvStreamKms;C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);C:\Windows\system32\drivers\nvvad64v.sys;C:\Windows\SYSNATIVE\drivers\nvvad64v.sys [x]
Inhalt des "geplante Tasks" Ordners
2015-07-05 C:\Windows\Tasks\Adobe Flash Player Updater.job
- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-28 20:37:34 . 2015-06-28 14:37:55]
--------- X64 Entries -----------
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}]
2015-07-05 09:39:24 429056 ----a-w- C:\Program Files\{F3D4780F-89FF-47DA-B5C2-665C7DAEC81B}\{E7DD8569-8785-409D-A673-9AF3422CA3E4}.bin
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2015-04-25 21:57:17 722400 ----a-w- C:\Program Files\AVAST Software\Avast\ashShA64.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2013-10-03 19:35:12 391152]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2013-10-03 19:35:10 771056]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2013-10-03 19:35:11 769520]
"XboxStat"="C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 15:57:30 825184]
"Nvtmru"="C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [BU]
"NvBackend"="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2015-06-24 11:37:29 2754704]
"NetWorx"="C:\Program Files\NetWorx\networx.exe" [2015-07-01 07:25:24 6607040]
"ShadowPlay"="C:\Windows\system32\nvspcap64.dll" [2015-06-24 11:36:31 1571696]
------- Zusätzlicher Suchlauf -------
uLocal Page = C:\Windows\system32\blank.htm
uStart Page = https://www.google.com/?trackid=sp-006
mStart Page = https://www.google.com/?trackid=sp-006
mSearch Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
mSearch Bar = https://www.google.com/?trackid=sp-006
IE: An OneNote s&enden - C:\PROGRA~1\MIF5BA~1\Office15\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - C:\PROGRA~1\MIF5BA~1\Office15\EXCEL.EXE/3000
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
FF - ProfilePath - C:\Users\Gustav\AppData\Roaming\Mozilla\Firefox\Profiles\zq1nlzuj.default-1436025345253\
- - - - Entfernte verwaiste Registrierungseinträge - - - -
Toolbar-10 - (no file)
ShellIconOverlayIdentifiers-{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} - (no file)
AddRemove-DAEMON Tools Lite - C:\Program Files (x86)\DAEMON Tools Lite\uninst.exe
AddRemove-VideoPad - C:\Program Files (x86)\NCH Software\VideoPad\videopad.exe
--------------------- Gesperrte Registrierungsschluessel ---------------------
[HKEY_USERS\S-1-5-21-506285681-3122066857-1050854625-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:18,cf,c4,aa,3d,32,19,64,5d,42,b8,e2,b3,d5,80,1f,1e,03,1c,63,8e,f3,a0,
71,c6,db,9d,dd,2a,5a,73,34,a5,c8,2e,fb,bb,01,c3,1b,fb,3b,00,83,64,c4,a3,ab,\
"??"=hex:07,4e,23,13,a3,c6,19,5e,83,21,50,1c,62,84,70,28
[HKEY_USERS\S-1-5-21-506285681-3122066857-1050854625-1000\Software\SecuROM\License information*]
"datasecu"=hex:da,9a,e1,0d,bc,aa,9a,bf,22,cc,ed,31,4a,d1,83,33,bb,16,25,b1,cf,
c5,b6,06,d4,56,42,b5,a6,ce,bf,ac,95,e9,0d,6a,22,2c,fd,09,6d,b8,48,31,17,46,\
"rkeysecu"=hex:7e,77,0c,00,78,c8,a2,e6,16,3f,86,9b,0e,4f,b1,4a
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
Zeit der Fertigstellung: 2015-07-05 11:44:25
ComboFix-quarantined-files.txt 2015-07-05 09:44:25
ComboFix2.txt 2015-07-04 22:57:43
Vor Suchlauf: 15 Verzeichnis(se), 63.122.272.256 Bytes frei |