schäfler | 14.09.2015 16:26 | Code:
ComboFix 15-09-07.01 - Anwender 14.09.2015 17:10:53.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.8172.6227 [GMT 2:00]
ausgeführt von:: c:\users\Anwender\Desktop\ComboFix.exe
AV: Avira Antivirus *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Antivirus *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((( Dateien erstellt von 2015-08-14 bis 2015-09-14 ))))))))))))))))))))))))))))))
.
.
2015-09-14 15:19 . 2015-09-14 15:19 -------- dc----w- c:\users\Default\AppData\Local\temp
2015-09-10 15:40 . 2015-09-10 19:58 1110016 ----a-w- c:\windows\system32\schedsvc.dll
2015-09-10 15:38 . 2015-09-10 19:59 1737216 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2015-09-10 15:27 . 2015-09-10 19:54 49664 ----a-w- c:\program files\Internet Explorer\DiagnosticsHub_is.dll
2015-09-10 15:19 . 2015-09-10 19:52 1941504 ----a-w- c:\windows\system32\authui.dll
2015-09-10 15:19 . 2015-09-10 19:52 1805824 ----a-w- c:\windows\SysWow64\authui.dll
2015-09-10 15:19 . 2015-09-10 19:52 115136 ----a-w- c:\windows\system32\consent.exe
2015-09-10 15:19 . 2015-09-10 19:52 70656 ----a-w- c:\windows\system32\appinfo.dll
2015-09-10 15:18 . 2015-09-10 19:52 2004480 ----a-w- c:\windows\system32\msxml6.dll
2015-09-10 15:18 . 2015-09-10 19:52 1887232 ----a-w- c:\windows\system32\msxml3.dll
2015-09-10 15:18 . 2015-09-10 19:52 2048 ----a-w- c:\windows\SysWow64\msxml6r.dll
2015-09-10 15:18 . 2015-09-10 19:52 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
2015-09-10 15:18 . 2015-09-10 19:52 2048 ----a-w- c:\windows\system32\msxml6r.dll
2015-09-10 15:18 . 2015-09-10 19:52 2048 ----a-w- c:\windows\system32\msxml3r.dll
2015-09-10 15:18 . 2015-09-10 19:52 1391104 ----a-w- c:\windows\SysWow64\msxml6.dll
2015-09-10 15:18 . 2015-09-10 19:52 1241088 ----a-w- c:\windows\SysWow64\msxml3.dll
2015-09-10 13:01 . 2015-09-10 14:33 692672 ----a-w- c:\windows\system32\winload.efi
2015-09-10 13:01 . 2015-09-10 14:33 63488 ----a-w- c:\windows\system32\setbcdlocale.dll
2015-09-10 13:01 . 2015-09-10 14:33 616360 ----a-w- c:\windows\system32\winresume.efi
2015-09-10 13:01 . 2015-09-10 14:33 61440 ----a-w- c:\windows\system32\drivers\appid.sys
2015-09-10 13:01 . 2015-09-10 14:33 59392 ----a-w- c:\windows\system32\appidapi.dll
2015-09-10 13:01 . 2015-09-10 14:33 50688 ----a-w- c:\windows\SysWow64\appidapi.dll
2015-09-10 13:01 . 2015-09-10 14:33 32768 ----a-w- c:\windows\system32\appidsvc.dll
2015-09-10 13:01 . 2015-09-10 14:33 17920 ----a-w- c:\windows\system32\appidcertstorecheck.exe
2015-09-10 13:01 . 2015-09-10 14:33 147456 ----a-w- c:\windows\system32\appidpolicyconverter.exe
2015-08-17 21:37 . 2015-08-17 21:37 -------- dc----w- c:\users\Anwender\AppData\Roaming\aipai
2015-08-17 21:37 . 2015-08-17 21:37 -------- dc----w- C:\SmartPixel
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-09-11 19:48 . 2015-03-17 13:17 113880 -c--a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-09-10 19:53 . 2015-09-10 15:39 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2015-08-26 16:37 . 2010-06-24 09:33 134753440 -c--a-w- c:\windows\system32\mrt.exe
2015-08-12 01:10 . 2015-08-11 19:24 774656 ----a-w- c:\windows\system32\invagent.dll
2015-08-12 01:10 . 2015-08-11 19:24 743424 ----a-w- c:\windows\system32\generaltel.dll
2015-08-12 01:10 . 2015-08-11 19:24 69120 ----a-w- c:\windows\system32\acmigration.dll
2015-08-12 01:10 . 2015-08-11 19:24 437760 ----a-w- c:\windows\system32\devinv.dll
2015-08-12 01:10 . 2015-08-11 19:24 1116672 ----a-w- c:\windows\system32\appraiser.dll
2015-08-12 01:10 . 2015-08-11 19:24 227328 ----a-w- c:\windows\system32\aepdu.dll
2015-08-12 01:10 . 2015-08-11 19:24 17344 ----a-w- c:\windows\system32\CompatTelRunner.exe
2015-08-12 01:10 . 2015-08-11 19:24 1148416 ----a-w- c:\windows\system32\aeinv.dll
2015-08-12 01:09 . 2015-08-11 19:24 856064 ----a-w- c:\windows\SysWow64\rdvidcrl.dll
2015-08-12 01:09 . 2015-08-11 19:24 7077376 ----a-w- c:\windows\system32\mstscax.dll
2015-08-12 01:09 . 2015-08-11 19:24 6131200 ----a-w- c:\windows\SysWow64\mstscax.dll
2015-08-12 01:09 . 2015-08-11 19:24 1057792 ----a-w- c:\windows\system32\rdvidcrl.dll
2015-08-12 01:09 . 2015-08-11 19:24 62976 ----a-w- c:\windows\system32\tsgqec.dll
2015-08-12 01:09 . 2015-08-11 19:24 53248 ----a-w- c:\windows\SysWow64\tsgqec.dll
2015-08-12 01:09 . 2015-08-11 19:24 429568 ----a-w- c:\windows\system32\wksprt.exe
2015-08-12 01:09 . 2015-08-12 01:09 124624 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 01:09 . 2015-08-12 01:09 103120 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 01:08 . 2015-08-11 19:23 1743360 ----a-w- c:\windows\system32\sysmain.dll
2015-08-12 01:08 . 2015-08-11 19:23 94656 ----a-w- c:\windows\system32\drivers\mountmgr.sys
2015-08-12 01:08 . 2015-08-11 19:23 11264 ----a-w- c:\windows\system32\msmmsp.dll
2015-08-12 01:07 . 2015-08-11 19:23 52736 ----a-w- c:\windows\system32\basesrv.dll
2015-08-12 01:06 . 2015-08-11 19:20 82432 ----a-w- c:\windows\SysWow64\davclnt.dll
2015-08-12 01:06 . 2015-08-11 19:20 260096 ----a-w- c:\windows\system32\WebClnt.dll
2015-08-12 01:06 . 2015-08-11 19:20 206848 ----a-w- c:\windows\SysWow64\WebClnt.dll
2015-08-12 01:06 . 2015-08-11 19:20 102912 ----a-w- c:\windows\system32\davclnt.dll
2015-08-12 01:06 . 2015-08-11 19:20 1648128 ----a-w- c:\windows\system32\DWrite.dll
2015-08-12 01:06 . 2015-08-11 19:20 1251328 ----a-w- c:\windows\SysWow64\DWrite.dll
2015-08-12 01:06 . 2015-08-11 19:20 1180160 ----a-w- c:\windows\system32\FntCache.dll
2015-08-12 01:06 . 2015-08-11 19:20 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2015-08-12 01:06 . 2015-08-11 19:20 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2015-08-12 01:05 . 2015-08-11 19:20 193536 ----a-w- c:\windows\system32\notepad.exe
2015-08-12 01:05 . 2015-08-11 19:20 193536 ----a-w- c:\windows\notepad.exe
2015-08-12 01:05 . 2015-08-11 19:20 179712 ----a-w- c:\windows\SysWow64\notepad.exe
2015-08-12 01:05 . 2015-08-11 19:20 14177280 ----a-w- c:\windows\system32\shell32.dll
2015-08-12 01:00 . 2015-08-11 19:20 493504 ----a-w- c:\windows\system32\mcupdate_GenuineIntel.dll
2015-07-24 17:53 . 2014-03-03 15:54 162528 -c--a-w- c:\windows\system32\drivers\avgntflt.sys
2015-07-24 17:53 . 2014-03-03 15:54 141416 -c--a-w- c:\windows\system32\drivers\avipbb.sys
2015-07-15 21:18 . 2015-07-15 08:50 254976 ----a-w- c:\windows\system32\cewmdm.dll
2015-07-15 21:18 . 2015-07-15 08:50 210432 ----a-w- c:\windows\SysWow64\cewmdm.dll
2015-07-15 21:18 . 2015-07-15 08:49 3180544 ----a-w- c:\windows\system32\rdpcorets.dll
2015-07-15 21:18 . 2015-07-15 08:49 16384 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2015-07-15 21:17 . 2015-07-15 08:49 404992 ----a-w- c:\windows\system32\gdi32.dll
2015-07-15 21:17 . 2015-07-15 08:49 312320 ----a-w- c:\windows\SysWow64\gdi32.dll
2015-07-15 21:16 . 2015-07-15 08:46 2087424 ----a-w- c:\windows\system32\ole32.dll
2015-07-15 21:16 . 2015-07-15 08:46 1414656 ----a-w- c:\windows\SysWow64\ole32.dll
2015-07-15 21:16 . 2015-07-15 08:45 229376 ----a-w- c:\windows\system32\wintrust.dll
2015-07-15 21:16 . 2015-07-15 08:45 188416 ----a-w- c:\windows\system32\cryptsvc.dll
2015-07-15 21:16 . 2015-07-15 08:45 179200 ----a-w- c:\windows\SysWow64\wintrust.dll
2015-07-15 21:16 . 2015-07-15 08:45 1480192 ----a-w- c:\windows\system32\crypt32.dll
2015-07-15 21:16 . 2015-07-15 08:45 143872 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2015-07-15 21:16 . 2015-07-15 08:45 140288 ----a-w- c:\windows\system32\cryptnet.dll
2015-07-15 21:16 . 2015-07-15 08:45 1174528 ----a-w- c:\windows\SysWow64\crypt32.dll
2015-07-15 21:16 . 2015-07-15 08:45 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2015-07-15 21:15 . 2015-07-15 08:45 73216 ----a-w- c:\windows\SysWow64\msiexec.exe
2015-07-15 21:15 . 2015-07-15 08:45 504320 ----a-w- c:\windows\system32\msihnd.dll
2015-07-15 21:15 . 2015-07-15 08:45 337408 ----a-w- c:\windows\SysWow64\msihnd.dll
2015-07-15 21:15 . 2015-07-15 08:45 3242496 ----a-w- c:\windows\system32\msi.dll
2015-07-15 21:15 . 2015-07-15 08:45 2364416 ----a-w- c:\windows\SysWow64\msi.dll
2015-07-15 21:15 . 2015-07-15 08:45 128000 ----a-w- c:\windows\system32\msiexec.exe
2015-07-15 21:15 . 2015-07-15 08:45 25088 ----a-w- c:\windows\SysWow64\msimsg.dll
2015-07-15 21:15 . 2015-07-15 08:45 25088 ----a-w- c:\windows\system32\msimsg.dll
2015-06-18 06:41 . 2015-03-17 13:17 63704 -c--a-w- c:\windows\system32\drivers\mwac.sys
2015-06-18 06:41 . 2015-03-17 13:17 109272 -c--a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-06-18 06:41 . 2015-03-17 13:17 25816 -c--a-w- c:\windows\system32\drivers\mbam.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EADM"="c:\program files (x86)\Origin\Origin.exe" [2015-08-22 3632112]
"Spotify Web Helper"="c:\users\Anwender\AppData\Roaming\Spotify\SpotifyWebHelper.exe" [2015-09-04 2018360]
"Octoshape Streaming Services"="c:\users\Anwender\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2014-08-01 500016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2015-08-26 782008]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2014-10-07 507776]
"bdruninstaller"="c:\program files\Common Files\Bitdefender\SetupInformation\downloader\setuplauncher.exe" [2014-06-06 676568]
.
c:\users\Anwender\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Tintenwarnungen überwachen - HP Deskjet 3070 B611 series.lnk - c:\windows\system32\RunDll32.exe "c:\program files\HP\HP Deskjet 3070 B611 series\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=CN181336LP05MQ;CONNECTION=USB;MONITOR=1; [2009-7-14 45568]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux9"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0auto_reactivate \\?\Volume{f7c68f79-a48d-11e3-9e6d-806e6f6e6963}\bootwiz\asrm.bin
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
R2 AntiVirMailService;Avira Email-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avmailc7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avmailc7.exe [x]
R2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys;c:\windows\SYSNATIVE\DRIVERS\afcdp.sys [x]
R3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys;c:\windows\SYSNATIVE\DRIVERS\amdhub30.sys [x]
R3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys;c:\windows\SYSNATIVE\DRIVERS\amdxhc.sys [x]
R3 athur;Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x]
R3 AX88772B;ASIX AX88772B USB2.0 to Fast Ethernet Adapter;c:\windows\system32\DRIVERS\ax88772b.sys;c:\windows\SYSNATIVE\DRIVERS\ax88772b.sys [x]
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
R3 e1kexpress;Intel(R) Network Connections Driver K;c:\windows\system32\DRIVERS\e1k62x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1k62x64.sys [x]
R3 EasyAntiCheat;EasyAntiCheat;c:\windows\system32\EasyAntiCheat.exe;c:\windows\SYSNATIVE\EasyAntiCheat.exe [x]
R3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys;c:\windows\SYSNATIVE\drivers\IntcHdmi.sys [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 MRV6X64P;Vista 64-bits Native WiFi Driver;c:\windows\system32\DRIVERS\MRVW13C.sys;c:\windows\SYSNATIVE\DRIVERS\MRVW13C.sys [x]
R3 netr28x;Ralink 802.11n-Drahtlostreiber für Windows Vista;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x]
R3 Origin Client Service;Origin Client Service;c:\program files (x86)\Origin\OriginClientService.exe;c:\program files (x86)\Origin\OriginClientService.exe [x]
R3 PciSPorts;High-Speed PCI Serial Port;c:\windows\system32\DRIVERS\PciSPorts.sys;c:\windows\SYSNATIVE\DRIVERS\PciSPorts.sys [x]
R3 Ph3xIB64;Philips 713x VU PCI TV Card;c:\windows\system32\DRIVERS\Ph3xIB64.sys;c:\windows\SYSNATIVE\DRIVERS\Ph3xIB64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 rt61x64;RT61 Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr6164.sys;c:\windows\SYSNATIVE\DRIVERS\netr6164.sys [x]
R3 RTL8023x64;Realtek 10/100-Netzwerkkartenfamilie-NDIS-x64-Treiber;c:\windows\system32\DRIVERS\Rtnic64.sys;c:\windows\SYSNATIVE\DRIVERS\Rtnic64.sys [x]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8192su.sys [x]
R3 RTL85n64;Realtek 8180/8185 Extensible 802.11-Drahtlosgerätetreiber;c:\windows\system32\DRIVERS\RTL85n64.sys;c:\windows\SYSNATIVE\DRIVERS\RTL85n64.sys [x]
R3 RtlWlanu;Realtek Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\rtwlanu.sys;c:\windows\SYSNATIVE\DRIVERS\rtwlanu.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 afcdpsrv;Acronis Nonstop Backup Service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [x]
R4 syncagentsrv;Acronis Sync Agent Service;c:\program files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe;c:\program files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S0 fltsrv;Acronis Storage Filter Management;c:\windows\system32\DRIVERS\fltsrv.sys;c:\windows\SYSNATIVE\DRIVERS\fltsrv.sys [x]
S0 tib;Acronis TIB Manager;c:\windows\system32\DRIVERS\tib.sys;c:\windows\SYSNATIVE\DRIVERS\tib.sys [x]
S0 tib_mounter;Acronis TIB Mounter;c:\windows\system32\DRIVERS\tib_mounter.sys;c:\windows\SYSNATIVE\DRIVERS\tib_mounter.sys [x]
S0 vididr;Acronis Virtual Disk;c:\windows\system32\DRIVERS\vididr.sys;c:\windows\SYSNATIVE\DRIVERS\vididr.sys [x]
S0 vidsflt;Acronis Disk Storage Filter;c:\windows\system32\DRIVERS\vidsflt.sys;c:\windows\SYSNATIVE\DRIVERS\vidsflt.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 AODDriver4.2;AODDriver4.2;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
S2 Apple Mobile Device Service;Apple Mobile Device Service;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [x]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x]
S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [x]
S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
S3 LADF_CaptureOnly;LADF Capture Filter Driver;c:\windows\system32\DRIVERS\ladfGSCamd64.sys;c:\windows\SYSNATIVE\DRIVERS\ladfGSCamd64.sys [x]
S3 LADF_RenderOnly;LADF Render Filter Driver;c:\windows\system32\DRIVERS\ladfGSRamd64.sys;c:\windows\SYSNATIVE\DRIVERS\ladfGSRamd64.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-09-05 07:36 997704 -c--a-w- c:\program files (x86)\Google\Chrome\Application\45.0.2454.85\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2015-09-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-05-06 13:26]
.
2015-09-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-05-06 13:26]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncError]
@="{934BC6C0-FEC2-4df5-A100-961DE2C8A0ED}"
[HKEY_CLASSES_ROOT\CLSID\{934BC6C0-FEC2-4df5-A100-961DE2C8A0ED}]
2013-08-07 15:04 2827776 ---ha-w- c:\program files (x86)\Acronis\TrueImageHome\tishell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncInProgress]
@="{00F848DC-B1D4-4892-9C25-CAADC86A215D}"
[HKEY_CLASSES_ROOT\CLSID\{00F848DC-B1D4-4892-9C25-CAADC86A215D}]
2013-08-07 15:04 2827776 ---ha-w- c:\program files (x86)\Acronis\TrueImageHome\tishell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncOk]
@="{71573297-552E-46fc-BE3D-3DFAF88D47B7}"
[HKEY_CLASSES_ROOT\CLSID\{71573297-552E-46fc-BE3D-3DFAF88D47B7}]
2013-08-07 15:04 2827776 ---ha-w- c:\program files (x86)\Acronis\TrueImageHome\tishell64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2014-03-03 682840]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2014-03-03 13662936]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2014-10-14 12697368]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2015-06-29 170280]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Anwender\AppData\Roaming\Mozilla\Firefox\Profiles\hdervz85.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1701067893-481638138-2713998442-1000\Software\SecuROM\License information*]
"datasecu"=hex:a4,42,27,b6,74,21,2f,02,8f,35,2d,ad,ad,61,79,8a,4a,e6,f8,84,d1,
dd,bc,d7,b7,b8,f6,86,36,56,a8,c6,5b,02,bc,8c,b6,07,38,fb,7e,4e,01,a7,c2,df,\
"rkeysecu"=hex:92,0d,55,86,4b,a3,95,fd,7d,7f,e7,9c,24,44,ab,52
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2015-09-14 17:23:35
ComboFix-quarantined-files.txt 2015-09-14 15:23
.
Vor Suchlauf: 13 Verzeichnis(se), 722.929.737.728 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 724.025.008.128 Bytes frei
.
- - End Of File - - D4205271417494F53C47D2EBE42F516F soll ich die anderen beiden programme TDSS killer und FRST nochmal starten da ich diese nicht auf dem desktop ausgeführt habe? |