![]() |
|
Log-Analyse und Auswertung: Sicherheitscenter streikt !Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() Sicherheitscenter streikt ! Hallo, Er lässt sich nicht aktivieren. Höffentlich bringt die Combofix analyse licht ins Dunkle im Vorfeld vielen Dank für ihre Bemühungen. : Combofix Logfile: Code:
ATTFilter ComboFix 13-05-07.02 - Geisens 07.05.2013 20:23:18.2.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3545.2803 [GMT 2:00] ausgeführt von:: I:\ComboFix.exe AV: Kaspersky Internet Security *Enabled/Updated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5} FW: Kaspersky Internet Security *Enabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E} SP: Kaspersky Internet Security *Enabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958} * Neuer Wiederherstellungspunkt wurde erstellt . . ((((((((((((((((((((((( Dateien erstellt von 2013-04-07 bis 2013-05-07 )))))))))))))))))))))))))))))) . . 2013-05-07 18:28 . 2013-05-07 18:28 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-05-07 15:49 . 2013-05-07 16:08 -------- d-----w- c:\users\Geisens\AppData\Local\Diagnostics 2013-05-07 15:20 . 2013-05-07 16:08 -------- d-----w- c:\users\Geisens\AppData\Local\ElevatedDiagnostics 2013-05-07 14:57 . 2013-05-07 14:57 -------- d-----w- c:\program files (x86)\Common Files\Java 2013-05-07 14:57 . 2013-05-07 14:57 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-05-07 14:57 . 2013-05-07 14:57 -------- d-----w- c:\program files (x86)\Java 2013-05-07 13:52 . 2013-05-07 15:05 -------- d-----w- c:\programdata\SecTaskMan 2013-05-07 13:52 . 2013-05-07 13:58 -------- d-----w- c:\program files (x86)\Security Task Manager 2013-05-07 13:37 . 2013-05-07 13:37 69632 ----a-r- c:\users\Geisens\AppData\Roaming\Microsoft\Installer\{84178AE8-C22D-48CB-A6BA-D116FD3FE469}\ARPPRODUCTICON.exe 2013-05-07 13:37 . 2013-05-07 13:37 49152 ----a-r- c:\users\Geisens\AppData\Roaming\Microsoft\Installer\{84178AE8-C22D-48CB-A6BA-D116FD3FE469}\UNINST_Uninstall_Q_336D8C9DB2424DE5BC518E574B25652F.exe 2013-05-07 13:37 . 2013-05-07 13:37 -------- d-----w- c:\users\Geisens\Qtrax 2013-05-07 13:33 . 2013-05-07 13:37 -------- d-----w- c:\users\Geisens\AppData\Local\Downloaded Installations 2013-05-07 13:32 . 2013-05-07 13:32 -------- d-----w- c:\users\Geisens\AppData\Roaming\Video Converter Packages 2013-05-07 13:32 . 2013-05-07 13:32 -------- d-----w- c:\users\Geisens\AppData\Roaming\DSite 2013-05-07 13:32 . 2013-05-07 13:32 -------- d-----w- c:\users\Geisens\AppData\Roaming\DealPly 2013-05-07 13:32 . 2013-05-07 13:32 -------- d-----w- c:\program files (x86)\VideoConverter 2013-05-07 13:32 . 2013-05-07 13:32 -------- d-----w- c:\program files (x86)\LyricsFinder 2013-05-06 20:33 . 2013-05-06 20:33 -------- d-----w- c:\windows\SysWow64\Extensions 2013-05-06 20:33 . 2013-05-06 20:33 -------- d-----w- c:\windows\SysWow64\searchplugins 2013-05-05 16:13 . 2013-05-05 16:15 -------- d-----w- c:\users\Geisens\Haushaltsplan 2013-05-04 07:59 . 2013-05-04 07:59 -------- d-----w- c:\program files (x86)\Delta 2013-05-04 07:59 . 2013-05-04 07:59 -------- d-----w- c:\users\Geisens\AppData\Roaming\Delta 2013-05-04 07:58 . 2013-05-04 07:58 -------- d-----w- c:\programdata\Babylon 2013-05-04 07:58 . 2013-05-04 07:58 -------- d-----w- c:\users\Geisens\AppData\Roaming\Babylon 2013-05-04 07:57 . 2013-05-04 07:57 -------- d-----w- c:\program files (x86)\Common Files\DVDVideoSoft 2013-05-04 07:57 . 2013-05-04 07:57 -------- d-----w- c:\program files (x86)\DVDVideoSoft 2013-04-24 12:56 . 2013-04-12 14:45 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-23 10:39 . 2013-04-23 10:39 -------- d-----w- c:\programdata\AVS4YOU 2013-04-23 10:39 . 2013-04-23 10:39 -------- d-----w- c:\users\Geisens\AppData\Roaming\AVS4YOU 2013-04-23 10:38 . 2012-03-26 10:27 11137024 ----a-w- c:\windows\SysWow64\libmfxsw32.dll 2013-04-23 10:38 . 2010-11-12 18:18 1700352 ----a-w- c:\windows\SysWow64\GdiPlus.dll 2013-04-23 10:38 . 2013-05-07 04:39 -------- d-----w- c:\program files (x86)\AVS4YOU 2013-04-23 10:37 . 2013-05-07 04:39 -------- d-----w- c:\program files (x86)\Common Files\AVSMedia 2013-04-10 08:27 . 2013-02-15 06:08 44032 ----a-w- c:\windows\system32\tsgqec.dll 2013-04-09 17:29 . 2013-04-09 17:29 -------- d-----w- c:\users\Geisens\AppData\Local\Cyberlink 2013-04-09 09:31 . 2013-04-10 09:31 -------- d-----w- c:\windows\SysWow64\jmdp 2013-04-09 09:31 . 2013-04-09 09:31 -------- d-----w- c:\windows\SysWow64\ARFC . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-05-07 14:57 . 2012-01-25 20:13 866720 ----a-w- c:\windows\SysWow64\npdeployJava1.dll 2013-05-07 14:57 . 2011-07-18 21:13 788896 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-04-24 14:07 . 2012-08-13 15:49 178448 ----a-w- c:\windows\system32\drivers\kneps.sys 2013-04-24 14:07 . 2012-06-08 10:38 55056 ----a-w- c:\windows\system32\drivers\kltdi.sys 2013-04-24 14:06 . 2012-08-13 17:24 620128 ----a-w- c:\windows\system32\drivers\klif.sys 2013-04-24 14:06 . 2012-08-13 17:24 90208 ----a-w- c:\windows\system32\drivers\klflt.sys 2013-04-10 21:08 . 2011-07-18 20:31 72702784 ----a-w- c:\windows\system32\MRT.exe 2013-04-07 08:54 . 2012-11-18 15:19 1455408 ----a-w- c:\windows\system32\dmwu.exe 2013-04-07 08:53 . 2012-11-18 15:19 33792 ----a-w- c:\windows\system32\ImHttpComm.dll 2013-04-06 06:48 . 2013-04-06 06:48 97280 ----a-w- c:\windows\system32\mshtmled.dll 2013-04-06 06:48 . 2013-04-06 06:48 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-04-06 06:48 . 2013-04-06 06:48 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-04-06 06:48 . 2013-04-06 06:48 81408 ----a-w- c:\windows\system32\icardie.dll 2013-04-06 06:48 . 2013-04-06 06:48 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-04-06 06:48 . 2013-04-06 06:48 762368 ----a-w- c:\windows\system32\ieapfltr.dll 2013-04-06 06:48 . 2013-04-06 06:48 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-04-06 06:48 . 2013-04-06 06:48 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-04-06 06:48 . 2013-04-06 06:48 62976 ----a-w- c:\windows\system32\pngfilt.dll 2013-04-06 06:48 . 2013-04-06 06:48 61952 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-04-06 06:48 . 2013-04-06 06:48 599552 ----a-w- c:\windows\system32\vbscript.dll 2013-04-06 06:48 . 2013-04-06 06:48 523264 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-04-06 06:48 . 2013-04-06 06:48 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-04-06 06:48 . 2013-04-06 06:48 51200 ----a-w- c:\windows\system32\imgutil.dll 2013-04-06 06:48 . 2013-04-06 06:48 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-04-06 06:48 . 2013-04-06 06:48 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-04-06 06:48 . 2013-04-06 06:48 452096 ----a-w- c:\windows\system32\dxtmsft.dll 2013-04-06 06:48 . 2013-04-06 06:48 441856 ----a-w- c:\windows\system32\html.iec 2013-04-06 06:48 . 2013-04-06 06:48 38400 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-04-06 06:48 . 2013-04-06 06:48 361984 ----a-w- c:\windows\SysWow64\html.iec 2013-04-06 06:48 . 2013-04-06 06:48 281600 ----a-w- c:\windows\system32\dxtrans.dll 2013-04-06 06:48 . 2013-04-06 06:48 27648 ----a-w- c:\windows\system32\licmgr10.dll 2013-04-06 06:48 . 2013-04-06 06:48 270848 ----a-w- c:\windows\system32\iedkcs32.dll 2013-04-06 06:48 . 2013-04-06 06:48 247296 ----a-w- c:\windows\system32\webcheck.dll 2013-04-06 06:48 . 2013-04-06 06:48 235008 ----a-w- c:\windows\system32\url.dll 2013-04-06 06:48 . 2013-04-06 06:48 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-04-06 06:48 . 2013-04-06 06:48 226304 ----a-w- c:\windows\system32\elshyph.dll 2013-04-06 06:48 . 2013-04-06 06:48 216064 ----a-w- c:\windows\system32\msls31.dll 2013-04-06 06:48 . 2013-04-06 06:48 197120 ----a-w- c:\windows\system32\msrating.dll 2013-04-06 06:48 . 2013-04-06 06:48 185344 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-04-06 06:48 . 2013-04-06 06:48 173568 ----a-w- c:\windows\system32\ieUnatt.exe 2013-04-06 06:48 . 2013-04-06 06:48 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-04-06 06:48 . 2013-04-06 06:48 158720 ----a-w- c:\windows\SysWow64\msls31.dll 2013-04-06 06:48 . 2013-04-06 06:48 1509376 ----a-w- c:\windows\system32\inetcpl.cpl 2013-04-06 06:48 . 2013-04-06 06:48 150528 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-04-06 06:48 . 2013-04-06 06:48 149504 ----a-w- c:\windows\system32\occache.dll 2013-04-06 06:48 . 2013-04-06 06:48 144896 ----a-w- c:\windows\system32\wextract.exe 2013-04-06 06:48 . 2013-04-06 06:48 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2013-04-06 06:48 . 2013-04-06 06:48 1400416 ----a-w- c:\windows\system32\ieapfltr.dat 2013-04-06 06:48 . 2013-04-06 06:48 138752 ----a-w- c:\windows\SysWow64\wextract.exe 2013-04-06 06:48 . 2013-04-06 06:48 13824 ----a-w- c:\windows\system32\mshta.exe 2013-04-06 06:48 . 2013-04-06 06:48 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-04-06 06:48 . 2013-04-06 06:48 136192 ----a-w- c:\windows\system32\iepeers.dll 2013-04-06 06:48 . 2013-04-06 06:48 135680 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-04-06 06:48 . 2013-04-06 06:48 12800 ----a-w- c:\windows\SysWow64\mshta.exe 2013-04-06 06:48 . 2013-04-06 06:48 12800 ----a-w- c:\windows\system32\msfeedssync.exe 2013-04-06 06:48 . 2013-04-06 06:48 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-04-06 06:48 . 2013-04-06 06:48 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-04-06 06:48 . 2013-04-06 06:48 102912 ----a-w- c:\windows\system32\inseng.dll 2013-03-13 16:06 . 2011-12-01 21:26 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-03-13 16:06 . 2008-01-01 07:31 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-02-12 05:45 . 2013-03-14 08:18 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-02-12 05:45 . 2013-03-14 08:18 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-02-12 05:45 . 2013-03-14 08:18 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-02-12 05:45 . 2013-03-14 08:18 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-02-12 04:48 . 2013-03-14 08:18 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll 2013-02-12 04:48 . 2013-03-14 08:18 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll 2013-02-12 04:12 . 2013-03-20 19:59 19968 ----a-w- c:\windows\system32\drivers\usb8023.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}] c:\users\Geisens\AppData\LocalLow\CT2625848\ldrtbDVDV.dll [BU] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{398C01F1-E584-46AD-A649-4F78B435DCFE}] 2013-02-27 19:59 109568 ----a-w- c:\program files (x86)\LyricsFinder\lfind.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}] c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll [BU] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}] 2012-07-04 13:03 1310040 ----a-r- c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}] 2013-01-10 22:05 197920 ----a-w- c:\program files (x86)\Yontoo\YontooIEClient.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{F9639E4A-801B-4843-AEE3-03D9DA199E77}"= "c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll" [BU] "{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}"= "c:\users\Geisens\AppData\LocalLow\CT2625848\ldrtbDVDV.dll" [BU] "{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2012-07-04 1310040] . [HKEY_CLASSES_ROOT\clsid\{f9639e4a-801b-4843-aee3-03d9da199e77}] [HKEY_CLASSES_ROOT\Incredibar.dskBnd.1] [HKEY_CLASSES_ROOT\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] [HKEY_CLASSES_ROOT\Incredibar.dskBnd] . [HKEY_CLASSES_ROOT\clsid\{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}] . [HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}] [HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1] [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}] [HKEY_CLASSES_ROOT\SWEETIE.IEToolbar] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2012-11-24 15:18 220632 ----a-w- c:\users\Geisens\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2012-11-24 15:18 220632 ----a-w- c:\users\Geisens\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2012-11-24 15:18 220632 ----a-w- c:\users\Geisens\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe" [2013-01-04 356376] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux3"=wdmaud.drv . R3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\DRIVERS\lgandbus64.sys [2012-03-02 19456] R3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\DRIVERS\lganddiag64.sys [2012-03-02 27648] R3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\DRIVERS\lgandgps64.sys [2012-03-02 27136] R3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\DRIVERS\lgandmodem64.sys [2012-03-02 34304] R3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264] R3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648] R3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960] R3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376] R3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [2010-09-23 129008] R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-05-05 235520] R4 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-05-04 361984] R4 BrYNSvc;BrYNSvc;c:\program files (x86)\Browny02\BrYNSvc.exe [2010-01-25 245760] R4 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R4 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624] R4 CyberLink PowerDVD 10 MS Monitor Service;CyberLink PowerDVD 10 MS Monitor Service;c:\program files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe [2011-04-13 70952] R4 CyberLink PowerDVD 10 MS Service;CyberLink PowerDVD 10 MS Service;c:\program files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe [2011-04-13 312616] R4 IBUpdaterService;IBUpdaterService;c:\windows\system32\dmwu.exe [2013-04-07 1455408] R4 MemeoBackgroundService;MemeoBackgroundService;c:\program files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe [2011-09-28 25824] R4 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776] R4 watchmi;watchmi service;c:\program files (x86)\watchmi\TvdService.exe [2012-01-31 70144] S0 amd_sata;amd_sata;c:\windows\system32\drivers\amd_sata.sys [2011-12-12 82048] S0 amd_xata;amd_xata;c:\windows\system32\drivers\amd_xata.sys [2011-12-12 42624] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2012-08-02 28504] S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys [2013-04-24 55056] S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys [2013-04-24 178448] S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys [2011-10-26 102528] S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136] S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys [2011-10-26 219776] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760] S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys [2013-01-04 29016] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2013-01-04 29528] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-02-16 676968] S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [2010-11-25 694888] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2012-01-14 56448] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-04-10 19:27 1642448 ----a-w- c:\program files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-05-07 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2008-01-01 16:06] . 2013-05-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-27 14:17] . 2013-05-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-27 14:17] . 2013-05-07 c:\windows\Tasks\Lyrics Finder Update.job - c:\program files (x86)\LyricsFinder\LyricsFinderUpdater.exe [2013-02-27 19:59] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2012-11-24 15:18 244696 ----a-w- c:\users\Geisens\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2012-11-24 15:18 244696 ----a-w- c:\users\Geisens\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2012-11-24 15:18 244696 ----a-w- c:\users\Geisens\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService FontCache . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://home.sweetim.com/?crg=3.1010006.10028&barid={6739D974-5F49-11E2-BAD3-D43D7E19BEE5} mLocal Page = c:\windows\SysWOW64\blank.htm IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 TCP: DhcpNameServer = 192.168.2.1 DPF: {5BF3E4A3-7E64-4D53-B512-2E242E837D24} - hxxps://einfach.otto.de/ottoproj/ottomce//bin/activex/MCEControls.cab FF - ProfilePath - c:\users\Geisens\AppData\Roaming\Mozilla\Firefox\Profiles\b4jip9iu.default\ FF - prefs.js: browser.search.defaulturl - FF - prefs.js: browser.search.selectedEngine - Wikipedia (de) FF - prefs.js: browser.startup.homepage - hxxp://www2.delta-search.com/?affID=121562&tt=gc_&babsrc=HP_ss&mntrId=204CE0B9A5E89AE3 FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2625848&SearchSource=2&CUI=UN49480471408670657&UM=&q= FF - ExtSQL: 2013-05-04 09:59; ffxtlbr@delta.com; c:\users\Geisens\AppData\Roaming\Mozilla\Firefox\Profiles\b4jip9iu.default\extensions\ffxtlbr@delta.com FF - ExtSQL: 2013-05-07 15:32; lfind@nijadsoft.net; c:\program files (x86)\LyricsFinder\FF FF - ExtSQL: 2013-05-07 15:32; amo@dealplyshopping.com; c:\users\Geisens\AppData\Roaming\Mozilla\Firefox\Profiles\b4jip9iu.default\extensions\amo@dealplyshopping.com FF - ExtSQL: 2013-05-07 16:30; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Geisens\AppData\Roaming\Mozilla\Firefox\Profiles\b4jip9iu.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF - user.js: extensions.autoDisableScopes - 0 FF - user.js: extensions.shownSelectionUI - true . - - - - Entfernte verwaiste Registrierungseinträge - - - - . AddRemove-ALDI SÜD Mah Jong - c:\windows\system32\Uninstall ALDI SÜD Mah Jong.exe AddRemove-DealPly - c:\program files (x86)\DealPly\uninst.exe AddRemove-incredibar - c:\program files (x86)\Incredibar.com\incredibar\1.5.11.14\uninstall.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE] "ImagePath"="." . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc] "ImagePath"="." . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-05-07 20:35:12 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2013-05-07 18:35 ComboFix2.txt 2013-05-07 17:55 . Vor Suchlauf: 17 Verzeichnis(se), 136.526.700.544 Bytes frei Nach Suchlauf: 19 Verzeichnis(se), 136.421.466.112 Bytes frei . - - End Of File - - A66FF7CF942C2E95B266F39A5A1AB1D5 PS : Kann mit dem Rechner nicht ins Internet, schreibe hier von einem Anderen. |
Themen zu Sicherheitscenter streikt ! |
adobe, avp, browser, combofix, converter, explorer, firefox, flash player, generic, google, helper, home, internet, internet explorer, internet security 2013, kaspersky, kaspersky internet security 2013, monitor, mozilla, port, realtek, security, software, svchost, system, usb, windows |