Brille65 | 01.09.2015 13:11 | Guten Tag, hier der log Code:
ComboFix 15-09-01.01 - Hermann 01.09.2015 13:34:50.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.16351.10014 [GMT 2:00]
ausgeführt von:: c:\users\Hermann\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
FW: avast! Antivirus *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\users\Hermann\AppData\Local\Temp\INS_2eadcffd.TMP
c:\users\Hermann\AppData\Local\Temp\INS_688c22e0.TMP
c:\users\Hermann\AppData\Local\Temp\INS_73c2be8f.TMP
c:\users\Hermann\AppData\Local\Temp\nvSCPAPI.dll
c:\users\Hermann\AppData\Local\Temp\nvSCPAPI64.dll
c:\users\Hermann\GamersGoMakers.exe
c:\users\Hermann\xobglu32.dll
c:\windows\capsys184523.log
c:\windows\IsUn0407.exe
c:\windows\security\logs\scecomp.log
c:\windows\SysWow64\miccyhook.dll
c:\windows\SysWow64\SET1A0E.tmp
c:\windows\SysWow64\SET5B7.tmp
c:\windows\SysWow64\SETCFD.tmp
c:\windows\windefendam.log
F:\install.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2015-08-01 bis 2015-09-01 ))))))))))))))))))))))))))))))
.
.
2015-09-01 12:07 . 2015-09-01 12:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-09-01 04:01 . 2015-08-25 14:08 574072 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2015-09-01 04:00 . 2015-09-01 04:00 -------- d-----w- c:\windows\LastGood
2015-09-01 00:59 . 2015-09-01 00:59 -------- d-----w- c:\users\Hermann\AppData\Roaming\Octane
2015-09-01 00:59 . 2015-09-01 00:59 -------- d-----w- c:\users\Hermann\AppData\Local\Game.exe_Url_snvcmaaeno2wmkw21ojsmc2vhaeghmtz
2015-08-31 20:58 . 2015-09-01 11:32 -------- d-----w- c:\users\Hermann\AppData\Roaming\uTorrent
2015-08-31 09:44 . 2015-08-31 09:46 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2015-08-31 03:11 . 2015-08-31 03:11 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{580130E7-8361-4273-B548-D4B917AC68A5}\offreg.2840.dll
2015-08-31 03:09 . 2015-07-31 09:21 11745192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{580130E7-8361-4273-B548-D4B917AC68A5}\mpengine.dll
2015-08-30 15:19 . 2015-08-30 15:22 -------- d-----w- C:\FRST
2015-08-30 09:20 . 2015-08-30 09:20 -------- d-----w- c:\users\Hermann\AppData\Roaming\uplay
2015-08-25 11:28 . 2015-08-28 20:02 -------- d-----w- c:\users\Hermann\AppData\Local\Warframe
2015-08-22 21:55 . 2015-08-11 04:52 69416 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2015-08-22 21:55 . 2015-08-11 04:52 50472 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2015-08-19 21:02 . 2015-08-28 23:24 -------- d-----w- c:\program files (x86)\Overwolf
2015-08-19 21:02 . 2015-08-27 11:22 -------- d-----w- c:\program files (x86)\Common Files\Overwolf
2015-08-19 21:01 . 2015-08-19 21:02 -------- d-----w- c:\programdata\Overwolf
2015-08-19 21:01 . 2015-08-30 06:24 -------- d-----w- c:\users\Hermann\AppData\Local\Overwolf
2015-08-14 15:14 . 2015-08-16 19:33 -------- d-----w- c:\users\Hermann\AppData\Roaming\Tropico 5
2015-08-13 16:35 . 2015-08-07 11:06 1558832 ----a-w- c:\windows\system32\nvdispgenco6435560.dll
2015-08-13 16:35 . 2015-08-07 11:06 1898104 ----a-w- c:\windows\system32\nvdispco6435560.dll
2015-08-10 10:29 . 2015-08-10 10:30 -------- d-----w- c:\program files\Virtual Audio Cable
2015-08-10 10:29 . 2015-08-10 10:29 98464 ----a-w- c:\windows\system32\drivers\vrtaucbl.sys
2015-08-10 10:25 . 2015-08-10 10:25 -------- d-----w- c:\program files\Mega-Nerd
2015-08-09 06:41 . 2015-08-14 01:05 -------- d-----w- c:\users\Hermann\AppData\Roaming\Tropico 3
2015-08-04 11:30 . 2015-01-06 16:22 4800000 ----a-w- c:\programdata\Microsoft\Windows\Templates\Bloody5\Setup.exe
2015-08-04 11:29 . 2015-08-04 11:30 -------- d-----w- c:\program files (x86)\Bloody5
2015-08-03 22:00 . 2015-08-03 22:00 -------- d-----w- c:\program files (x86)\MSECache
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-09-01 11:31 . 2014-11-08 11:18 113880 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-08-31 09:42 . 2014-11-08 11:18 109272 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-08-27 00:37 . 2014-11-08 11:29 1423120 ----a-w- c:\windows\SysWow64\nvspcap.dll
2015-08-27 00:37 . 2014-11-08 11:29 1316000 ----a-w- c:\windows\SysWow64\nvspbridge.dll
2015-08-27 00:36 . 2014-11-08 11:29 1756424 ----a-w- c:\windows\system32\nvspbridge64.dll
2015-08-27 00:36 . 2014-11-08 11:29 1710568 ----a-w- c:\windows\system32\nvspcap64.dll
2015-08-25 18:46 . 2015-06-22 22:28 17082392 ----a-w- c:\windows\system32\nvwgf2umx.dll
2015-08-25 18:46 . 2015-06-13 12:44 3112904 ----a-w- c:\windows\SysWow64\nvapi.dll
2015-08-25 18:46 . 2015-03-02 02:48 14635792 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2015-08-25 18:46 . 2014-11-09 20:02 112760 ----a-w- c:\windows\system32\OpenCL.dll
2015-08-25 18:46 . 2014-11-09 20:02 105264 ----a-w- c:\windows\SysWow64\OpenCL.dll
2015-08-25 18:46 . 2014-11-09 19:55 3527696 ----a-w- c:\windows\system32\nvapi64.dll
2015-08-25 18:46 . 2014-11-09 19:55 12515016 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2015-08-25 14:24 . 2014-11-09 20:02 937776 ----a-w- c:\windows\system32\nvvsvc.exe
2015-08-25 14:24 . 2014-11-09 20:02 62584 ----a-w- c:\windows\system32\nvshext.dll
2015-08-25 14:24 . 2014-11-09 20:02 385144 ----a-w- c:\windows\system32\nvmctray.dll
2015-08-25 14:24 . 2014-11-09 20:02 3496752 ----a-w- c:\windows\system32\nvsvc64.dll
2015-08-25 14:24 . 2014-11-09 20:02 2558584 ----a-w- c:\windows\system32\nvsvcr.dll
2015-08-25 14:24 . 2014-11-09 20:02 6884984 ----a-w- c:\windows\system32\nvcpl.dll
2015-08-25 12:35 . 2014-11-09 20:02 5165808 ----a-w- c:\windows\system32\nvcoproc.bin
2015-08-12 02:27 . 2014-11-08 19:20 778440 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2015-08-12 02:27 . 2014-11-08 19:20 142536 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-08-11 04:52 . 2014-11-08 11:22 72504 ----a-w- c:\windows\system32\nvaudcap64v.dll
2015-08-10 10:25 . 2014-12-03 10:43 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2015-08-10 10:25 . 2014-12-03 10:43 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2015-08-10 10:25 . 2014-12-03 10:43 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2015-08-10 10:25 . 2014-12-03 10:43 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2015-08-07 11:06 . 2015-06-22 22:28 17124832 ----a-w- c:\windows\system32\SET55.tmp
2015-08-07 11:06 . 2014-11-09 19:55 3518248 ----a-w- c:\windows\system32\SETDE67.tmp
2015-08-06 18:15 . 2015-03-21 17:51 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2015-08-06 18:15 . 2014-12-22 23:53 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2015-08-06 18:04 . 2014-12-22 23:53 226680 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2015-08-02 17:29 . 2014-12-22 23:53 76152 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2015-07-24 16:49 . 2015-07-24 16:49 76152 ----a-w- c:\windows\system32\PnkBstrA.exe
2015-07-23 04:06 . 2015-08-01 18:14 1898128 ----a-w- c:\windows\system32\nvdispco6435362.dll
2015-07-23 04:06 . 2015-08-01 18:14 1557648 ----a-w- c:\windows\system32\nvdispgenco6435362.dll
2015-07-15 03:19 . 2015-07-24 21:42 41984 ----a-w- c:\windows\system32\lpk.dll
2015-07-15 03:19 . 2015-07-24 21:42 100864 ----a-w- c:\windows\system32\fontsub.dll
2015-07-15 03:19 . 2015-07-24 21:42 14336 ----a-w- c:\windows\system32\dciman32.dll
2015-07-15 03:19 . 2015-07-24 21:42 46080 ----a-w- c:\windows\system32\atmlib.dll
2015-07-15 02:55 . 2015-07-24 21:42 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
2015-07-15 02:55 . 2015-07-24 21:42 10240 ----a-w- c:\windows\SysWow64\dciman32.dll
2015-07-15 02:55 . 2015-07-24 21:42 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2015-07-15 02:54 . 2015-07-24 21:42 25600 ----a-w- c:\windows\SysWow64\lpk.dll
2015-07-15 01:59 . 2015-07-24 21:42 372224 ----a-w- c:\windows\system32\atmfd.dll
2015-07-15 01:52 . 2015-07-24 21:42 299008 ----a-w- c:\windows\SysWow64\atmfd.dll
2015-07-12 04:32 . 2015-07-11 23:40 4096 ----a-w- c:\windows\SysWow64\drivers\nocashio.sys
2015-07-09 17:59 . 2015-07-16 11:03 17856 ----a-w- c:\windows\system32\CompatTelRunner.exe
2015-07-09 17:58 . 2015-07-16 11:03 37888 ----a-w- c:\windows\system32\wups2.dll
2015-07-09 17:58 . 2015-07-16 11:03 36864 ----a-w- c:\windows\system32\wups.dll
2015-07-09 17:58 . 2015-07-16 11:03 192000 ----a-w- c:\windows\system32\wuwebv.dll
2015-07-09 17:58 . 2015-07-16 11:03 98304 ----a-w- c:\windows\system32\wudriver.dll
2015-07-09 17:58 . 2015-07-16 11:03 696320 ----a-w- c:\windows\system32\wuapi.dll
2015-07-09 17:58 . 2015-07-16 11:03 3154944 ----a-w- c:\windows\system32\wucltux.dll
2015-07-09 17:58 . 2015-07-16 11:03 2603008 ----a-w- c:\windows\system32\wuaueng.dll
2015-07-09 17:58 . 2015-07-16 11:03 726528 ----a-w- c:\windows\system32\generaltel.dll
2015-07-09 17:58 . 2015-07-16 11:03 91136 ----a-w- c:\windows\system32\WinSetupUI.dll
2015-07-09 17:58 . 2015-07-16 11:03 765440 ----a-w- c:\windows\system32\invagent.dll
2015-07-09 17:58 . 2015-07-16 11:03 433664 ----a-w- c:\windows\system32\devinv.dll
2015-07-09 17:58 . 2015-07-16 11:03 12288 ----a-w- c:\windows\system32\wu.upgrade.ps.dll
2015-07-09 17:58 . 2015-07-16 11:03 1085440 ----a-w- c:\windows\system32\appraiser.dll
2015-07-09 17:58 . 2015-07-16 11:03 67584 ----a-w- c:\windows\system32\acmigration.dll
2015-07-09 17:58 . 2015-07-16 11:03 227328 ----a-w- c:\windows\system32\aepdu.dll
2015-07-09 17:58 . 2015-07-16 11:03 37376 ----a-w- c:\windows\system32\wuapp.exe
2015-07-09 17:58 . 2015-07-16 11:03 139776 ----a-w- c:\windows\system32\wuauclt.exe
2015-07-09 17:50 . 2015-07-16 11:03 1145856 ----a-w- c:\windows\system32\aeinv.dll
2015-07-09 17:43 . 2015-07-16 11:03 93184 ----a-w- c:\windows\SysWow64\wudriver.dll
2015-07-09 17:43 . 2015-07-16 11:03 30208 ----a-w- c:\windows\SysWow64\wups.dll
2015-07-09 17:43 . 2015-07-16 11:03 173056 ----a-w- c:\windows\SysWow64\wuwebv.dll
2015-07-09 17:43 . 2015-07-16 11:03 566784 ----a-w- c:\windows\SysWow64\wuapi.dll
2015-07-09 17:42 . 2015-07-16 11:03 34816 ----a-w- c:\windows\SysWow64\wuapp.exe
2015-07-04 18:07 . 2015-07-16 11:03 2087424 ----a-w- c:\windows\system32\ole32.dll
2015-07-04 17:48 . 2015-07-16 11:03 1414656 ----a-w- c:\windows\SysWow64\ole32.dll
2015-07-03 06:43 . 2014-11-09 09:21 130333168 ----a-w- c:\windows\system32\MRT.exe
2015-07-02 21:08 . 2015-07-16 11:03 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2015-07-02 20:49 . 2015-07-16 11:03 25193984 ----a-w- c:\windows\system32\mshtml.dll
2015-07-02 20:40 . 2015-07-16 11:03 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2015-07-02 20:23 . 2015-07-16 11:03 2885632 ----a-w- c:\windows\system32\iertutil.dll
2015-07-02 20:12 . 2015-07-16 11:03 615936 ----a-w- c:\windows\system32\ieui.dll
2015-07-02 19:20 . 2015-07-16 11:03 14453248 ----a-w- c:\windows\system32\ieframe.dll
2015-07-02 18:59 . 2015-07-16 11:03 1545728 ----a-w- c:\windows\system32\urlmon.dll
2015-07-01 20:56 . 2015-07-16 11:03 95680 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2015-07-01 20:56 . 2015-07-16 11:03 155584 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2015-07-01 20:49 . 2015-07-16 11:03 210944 ----a-w- c:\windows\system32\wdigest.dll
2015-07-01 20:49 . 2015-07-16 11:03 86528 ----a-w- c:\windows\system32\TSpkg.dll
2015-07-01 20:49 . 2015-07-16 11:03 29184 ----a-w- c:\windows\system32\sspisrv.dll
2015-07-01 20:49 . 2015-07-16 11:03 136192 ----a-w- c:\windows\system32\sspicli.dll
2015-07-01 20:49 . 2015-07-16 11:03 342016 ----a-w- c:\windows\system32\schannel.dll
2015-07-01 20:49 . 2015-07-16 11:03 28160 ----a-w- c:\windows\system32\secur32.dll
2015-07-01 20:49 . 2015-07-16 11:03 1216512 ----a-w- c:\windows\system32\rpcrt4.dll
2015-07-01 20:49 . 2015-07-16 11:03 309760 ----a-w- c:\windows\system32\ncrypt.dll
2015-07-01 20:49 . 2015-07-16 11:03 315392 ----a-w- c:\windows\system32\msv1_0.dll
2015-07-01 20:49 . 2015-07-16 11:03 729088 ----a-w- c:\windows\system32\kerberos.dll
2015-07-01 20:49 . 2015-07-16 11:03 1461760 ----a-w- c:\windows\system32\lsasrv.dll
2015-07-01 20:48 . 2015-07-16 11:03 44032 ----a-w- c:\windows\system32\cryptbase.dll
2015-07-01 20:48 . 2015-07-16 11:03 22016 ----a-w- c:\windows\system32\credssp.dll
2015-07-01 20:47 . 2015-07-16 11:03 31232 ----a-w- c:\windows\system32\lsass.exe
2015-07-01 20:47 . 2015-07-16 11:03 64000 ----a-w- c:\windows\system32\auditpol.exe
2015-07-01 20:43 . 2015-07-16 11:03 60416 ----a-w- c:\windows\system32\msobjs.dll
2015-07-01 20:43 . 2015-07-16 11:03 146432 ----a-w- c:\windows\system32\msaudite.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="f:\programme\Steam\steam.exe" [2015-08-19 2899136]
"OscarEditor"="c:\program files (x86)\MOUSE Editor\MouseEditor.exe" [2012-08-16 3333632]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"Bloody2"="c:\program files (x86)\Bloody5\Bloody5\Bloody5.exe" [2015-06-16 18923008]
"Overwolf"="c:\program files (x86)\Overwolf\Overwolf.exe" [2015-07-19 41200]
"uTorrent"="c:\users\Hermann\AppData\Roaming\uTorrent\uTorrent.exe" [2015-08-31 1699936]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Lightshot"="c:\program files (x86)\Skillbrains\lightshot\Lightshot.exe" [2014-11-18 226560]
"Logitech G35"="c:\program files (x86)\Logitech\G35\G35.exe" [2010-08-10 1811800]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-06-25 5515496]
"TrueImageMonitor.exe"="c:\program files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" [2014-03-06 6421592]
"AcronisTibMounterMonitor"="c:\program files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe" [2013-01-10 1105848]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"StereoLinksInstall"="c:\program files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe" [2015-08-25 1067128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"BlueStacks Agent"=c:\program files (x86)\BlueStacks\HD-Agent.exe
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
.
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys;c:\windows\SYSNATIVE\DRIVERS\afcdp.sys [x]
R3 aswTap;avast! SecureLine TAP Adapter v3;c:\windows\system32\DRIVERS\aswTap.sys;c:\windows\SYSNATIVE\DRIVERS\aswTap.sys [x]
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 EasyAntiCheat;EasyAntiCheat;c:\windows\system32\EasyAntiCheat.exe;c:\windows\SYSNATIVE\EasyAntiCheat.exe [x]
R3 FairplayKD;FairplayKD;c:\programdata\MTA San Andreas All\Common\temp\FairplayKD.sys;c:\programdata\MTA San Andreas All\Common\temp\FairplayKD.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 LADF_CaptureOnly;LADF Capture Filter Driver;c:\windows\system32\DRIVERS\ladfGSCamd64.sys;c:\windows\SYSNATIVE\DRIVERS\ladfGSCamd64.sys [x]
R3 LADF_RenderOnly;LADF Render Filter Driver;c:\windows\system32\DRIVERS\ladfGSRamd64.sys;c:\windows\SYSNATIVE\DRIVERS\ladfGSRamd64.sys [x]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 Origin Client Service;Origin Client Service;f:\programme\Origin\OriginClientService.exe;f:\programme\Origin\OriginClientService.exe [x]
R3 OverwolfUpdater;Overwolf Updater Windows SCM;c:\program files (x86)\Overwolf\OverwolfUpdater.exe;c:\program files (x86)\Overwolf\OverwolfUpdater.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x]
R3 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys;c:\windows\SYSNATIVE\DRIVERS\vmci.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 xhunter1;xhunter1;c:\windows\xhunter1.sys;c:\windows\xhunter1.sys [x]
R4 afcdpsrv;Acronis Nonstop Backup Service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [x]
R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R4 SpotfluxConnectionManager;Spotflux Connection Manager;c:\program files (x86)\Spotflux\services\SpotfluxConnectionManager.exe;c:\program files (x86)\Spotflux\services\SpotfluxConnectionManager.exe [x]
R4 syncagentsrv;Acronis Sync Agent Service;c:\program files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe;c:\program files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [x]
S0 aswNdisFlt;Avast! Firewall Driver;c:\windows\system32\DRIVERS\aswNdisFlt.sys;c:\windows\SYSNATIVE\DRIVERS\aswNdisFlt.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 fltsrv;Acronis Storage Filter Management;c:\windows\system32\DRIVERS\fltsrv.sys;c:\windows\SYSNATIVE\DRIVERS\fltsrv.sys [x]
S0 tib;Acronis TIB Manager;c:\windows\system32\DRIVERS\tib.sys;c:\windows\SYSNATIVE\DRIVERS\tib.sys [x]
S0 tib_mounter;Acronis TIB Mounter;c:\windows\system32\DRIVERS\tib_mounter.sys;c:\windows\SYSNATIVE\DRIVERS\tib_mounter.sys [x]
S0 vididr;Acronis Virtual Disk;c:\windows\system32\DRIVERS\vididr.sys;c:\windows\SYSNATIVE\DRIVERS\vididr.sys [x]
S0 vidsflt;Acronis Disk Storage Filter;c:\windows\system32\DRIVERS\vidsflt.sys;c:\windows\SYSNATIVE\DRIVERS\vidsflt.sys [x]
S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys;c:\windows\SYSNATIVE\drivers\aswKbd.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxDrv.sys [x]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxUSBMon.sys [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 avast! Firewall;Avast Firewall;c:\program files\AVAST Software\Avast\afwServ.exe;c:\program files\AVAST Software\Avast\afwServ.exe [x]
S2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TuneUp.UtilitiesSvc;AVG PC TuneUp Service;c:\program files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe;c:\program files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [x]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys;c:\windows\SYSNATIVE\DRIVERS\asmthub3.sys [x]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys;c:\windows\SYSNATIVE\DRIVERS\asmtxhci.sys [x]
S3 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
S3 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [x]
S3 BstHdUpdaterSvc;BlueStacks Updater Service;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe [x]
S3 easytether;EasyTether Network Adapter;c:\windows\system32\DRIVERS\easytthr.sys;c:\windows\SYSNATIVE\DRIVERS\easytthr.sys [x]
S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys;c:\windows\SYSNATIVE\DRIVERS\vrtaucbl.sys [x]
S3 LADF_DHP2;G35 DHP2 Filter Driver;c:\windows\system32\DRIVERS\ladfDHP2amd64.sys;c:\windows\SYSNATIVE\DRIVERS\ladfDHP2amd64.sys [x]
S3 LADF_SBVM;G35 SBVM Filter Driver;c:\windows\system32\DRIVERS\ladfSBVMamd64.sys;c:\windows\SYSNATIVE\DRIVERS\ladfSBVMamd64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 tapSF0901;Spotflux Virtual Network Device Driver;c:\windows\system32\DRIVERS\tapSF0901.sys;c:\windows\SYSNATIVE\DRIVERS\tapSF0901.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys;c:\program files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [x]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 94899380
*NewlyCreated* - MBAMSWISSARMY
*Deregistered* - 94899380
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-08-22 06:58 993608 ----a-w- c:\program files (x86)\Google\Chrome\Application\44.0.2403.157\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2015-09-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-08 02:27]
.
2015-08-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-07-30 11:52]
.
2015-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-07-30 11:52]
.
2015-07-12 c:\windows\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013.job
- c:\program files (x86)\AVG\AVG PC TuneUp\OneClick.exe [2015-05-15 13:54]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2015-06-24 10:45 722400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2015-08-27 2634872]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2015-08-27 1710568]
"Acronis Scheduler2 Service"="c:\program files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" [2013-02-15 516928]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
Trusted Zone: vizzed.com\www
TCP: DhcpNameServer = 83.169.184.33 83.169.184.97
FF - ProfilePath - c:\users\Hermann\AppData\Roaming\Mozilla\Firefox\Profiles\34052ydq.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-1207664883_is1 - h:\gog games\Gods Will Be Watching\unins000.exe
AddRemove-1207666333_is1 - h:\gog games\Dead State\unins000.exe
AddRemove-ANNO 1602 Königs-Edition - c:\windows\IsUn0407.exe
AddRemove-Cultures2 - c:\windows\IsUn0407.exe
AddRemove-Farming World_is1 - h:\programme\Farming World\unins000.exe
AddRemove-GOGPACKANSTARTOPIA_is1 - h:\gog games\StarTopia\unins000.exe
AddRemove-GOGPACKEMPIREEARTHGOLD_is1 - h:\gog games\Empire Earth Gold Edition\unins000.exe
AddRemove-GOGPACKXENONAUTS_is1 - c:\gog games\Xenonauts\unins000.exe
AddRemove-GT Interactive - Driver - c:\windows\IsUn0407.exe
AddRemove-Hatred MULTi9 1.0 - h:\programme\Hatred\Uninstall.exe
AddRemove-Lionheart_is1 - h:\programme\Lionheart\unins000.exe
AddRemove-NjBTZWNvbmRz_is1 - h:\programme\60 Seconds\unins000.exe
AddRemove-Opera 30.0.1835.59 - h:\programme\Opera\Launcher.exe
AddRemove-Revolver's Wings Of War - h:\programme\Wings of War\Uninstal.exe
AddRemove-Steam App 115210 - h:\programme\Steam\steam.exe
AddRemove-Steam App 12100 - h:\programme\Steam\steam.exe
AddRemove-Steam App 12470 - h:\programme\Steam\steam.exe
AddRemove-Steam App 200510 - h:\programme\Steam\steam.exe
AddRemove-Steam App 203140 - h:\programme\Steam\steam.exe
AddRemove-Steam App 204560 - h:\programme\Steam\steam.exe
AddRemove-Steam App 20540 - h:\programme\Steam\steam.exe
AddRemove-Steam App 205610 - h:\programme\Steam\steam.exe
AddRemove-Steam App 211820 - h:\programme\Steam\steam.exe
AddRemove-Steam App 212680 - h:\programme\Steam\steam.exe
AddRemove-Steam App 214560 - h:\programme\Steam\steam.exe
AddRemove-Steam App 219780 - h:\programme\Steam\steam.exe
AddRemove-Steam App 220 - h:\programme\Steam\steam.exe
AddRemove-Steam App 226120 - h:\programme\Steam\steam.exe
AddRemove-Steam App 227300 - h:\programme\Steam\steam.exe
AddRemove-Steam App 231140 - h:\programme\Steam\steam.exe
AddRemove-Steam App 23490 - h:\programme\Steam\steam.exe
AddRemove-Steam App 239820 - h:\programme\Steam\steam.exe
AddRemove-Steam App 240 - h:\programme\Steam\steam.exe
AddRemove-Steam App 241540 - h:\programme\Steam\steam.exe
AddRemove-Steam App 24240 - h:\programme\Steam\steam.exe
AddRemove-Steam App 246090 - h:\programme\Steam\steam.exe
AddRemove-Steam App 24780 - h:\programme\Steam\steam.exe
AddRemove-Steam App 253710 - h:\programme\Steam\steam.exe
AddRemove-Steam App 253980 - h:\programme\Steam\steam.exe
AddRemove-Steam App 254000 - h:\programme\Steam\steam.exe
AddRemove-Steam App 254020 - h:\programme\Steam\steam.exe
AddRemove-Steam App 254040 - h:\programme\Steam\steam.exe
AddRemove-Steam App 254060 - h:\programme\Steam\steam.exe
AddRemove-Steam App 277430 - h:\programme\Steam\steam.exe
AddRemove-Steam App 27940 - h:\programme\Steam\steam.exe
AddRemove-Steam App 295110 - h:\programme\Steam\steam.exe
AddRemove-Steam App 30 - h:\programme\Steam\steam.exe
AddRemove-Steam App 300 - h:\programme\Steam\steam.exe
AddRemove-Steam App 305390 - h:\programme\Steam\steam.exe
AddRemove-Steam App 310380 - h:\programme\Steam\steam.exe
AddRemove-Steam App 33520 - h:\programme\Steam\steam.exe
AddRemove-Steam App 34010 - h:\programme\Steam\steam.exe
AddRemove-Steam App 346370 - h:\programme\Steam\steam.exe
AddRemove-Steam App 346900 - h:\programme\Steam\steam.exe
AddRemove-Steam App 351800 - h:\programme\Steam\steam.exe
AddRemove-Steam App 380 - h:\programme\Steam\steam.exe
AddRemove-Steam App 4000 - h:\programme\Steam\steam.exe
AddRemove-Steam App 41000 - h:\programme\Steam\steam.exe
AddRemove-Steam App 41010 - h:\programme\Steam\steam.exe
AddRemove-Steam App 420 - h:\programme\Steam\steam.exe
AddRemove-Steam App 42700 - h:\programme\Steam\steam.exe
AddRemove-Steam App 42710 - h:\programme\Steam\steam.exe
AddRemove-Steam App 440 - h:\programme\Steam\steam.exe
AddRemove-Steam App 4560 - h:\programme\Steam\steam.exe
AddRemove-Steam App 46230 - h:\programme\Steam\steam.exe
AddRemove-Steam App 46370 - h:\programme\Steam\steam.exe
AddRemove-Steam App 4850 - h:\programme\Steam\steam.exe
AddRemove-Steam App 57740 - h:\programme\Steam\steam.exe
AddRemove-Steam App 58610 - h:\programme\Steam\steam.exe
AddRemove-Steam App 6000 - h:\programme\Steam\steam.exe
AddRemove-Steam App 6060 - h:\programme\Steam\steam.exe
AddRemove-Steam App 65540 - h:\programme\Steam\steam.exe
AddRemove-Steam App 6860 - h:\programme\Steam\steam.exe
AddRemove-Steam App 70100 - h:\programme\Steam\steam.exe
AddRemove-Steam App 70110 - h:\programme\Steam\steam.exe
AddRemove-Steam App 70120 - h:\programme\Steam\steam.exe
AddRemove-Steam App 71230 - h:\programme\Steam\steam.exe
AddRemove-Steam App 9340 - h:\programme\Steam\steam.exe
AddRemove-Steam App 96100 - h:\programme\Steam\steam.exe
AddRemove-The Good Life_is1 - h:\programme\goodlife\unins000.exe
AddRemove-{024D0ADC-6846-4B7A-B12F-D571DF826068}}_is1 - h:\programme\Aftermath\unins000.exe
AddRemove-{2BB114DA-C718-45FE-8AB9-DEFFF0EA5569}_is1 - h:\programme\Grand Theft Auto San Andreas\unins000.exe
AddRemove-{5FD7B6B3-08C7-4FEE-9C37-A2134C699885}}_is1 - c:\program files (x86)\This War of Mine\unins000.exe
AddRemove-SOE-PlanetSide 2 - h:\programme\Steam\steamapps\common\PlanetSide 2\Uninstaller.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3540704453-1494989713-834082015-1000\Software\SecuROM\License information*]
"datasecu"=hex:25,a8,eb,1a,23,63,75,8a,5f,5f,ad,bc,bb,2b,8e,14,f0,b4,93,11,73,
2e,b8,be,12,d6,16,89,74,cb,c1,c3,62,e8,8e,02,b9,bb,d1,4f,be,0a,b5,d2,5a,62,\
"rkeysecu"=hex:51,0f,74,16,a9,b8,a7,32,76,2f,eb,b2,58,a2,81,5f
.
[HKEY_LOCAL_MACHINE\SOFTWARE\BlueStacks]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2015-09-01 14:09:20
ComboFix-quarantined-files.txt 2015-09-01 12:09
.
Vor Suchlauf: 12 Verzeichnis(se), 220.049.174.528 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 223.599.734.784 Bytes frei
.
- - End Of File - - 5176F29B653558850E68A07C39A4CFDB
605D514C0EB9E594ECCDE224382C660C |