Guten Abend
Code:
Alles auswählen Aufklappen ATTFilter
ComboFix 14-05-29.01 - Alexandra 02.06.2014 23:59:05.1.2 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.3932.2834 [GMT 2:00]
ausgeführt von:: c:\users\Alexandra\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-05-02 bis 2014-06-02 ))))))))))))))))))))))))))))))
.
.
2014-06-02 22:05 . 2014-06-02 22:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-06-01 11:03 . 2014-06-01 11:04 -------- d-----w- C:\FRST
2014-05-31 16:29 . 2014-05-31 16:29 -------- d-----w- c:\program files\Unknown Device Identifier
2014-05-31 14:41 . 2014-04-15 13:59 40760 ----a-w- c:\windows\system32\TURegOpt.exe
2014-05-31 14:41 . 2014-04-15 13:59 29496 ----a-w- c:\windows\system32\authuitu.dll
2014-05-31 14:41 . 2014-04-15 13:59 25400 ----a-w- c:\windows\SysWow64\authuitu.dll
2014-05-31 14:41 . 2014-05-31 14:41 -------- d-----w- c:\users\Alexandra\AppData\Roaming\TuneUp Software
2014-05-31 14:41 . 2014-05-31 14:41 -------- d-----w- c:\users\Alexandra\AppData\Local\TuneUp Software
2014-05-31 14:41 . 2014-05-31 14:41 -------- d-----w- c:\program files (x86)\TuneUp Utilities 2014
2014-05-31 14:39 . 2014-05-31 14:42 -------- d-----w- c:\programdata\TuneUp Software
2014-05-31 14:38 . 2014-05-31 14:46 -------- d-sh--w- c:\programdata\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-06-02 22:06 . 2013-01-06 22:53 17920 ----a-w- c:\windows\system32\rpcnetp.exe
2014-06-02 22:06 . 2013-01-06 22:57 58288 ----a-w- c:\windows\SysWow64\rpcnet.dll
2014-05-31 16:04 . 2013-01-06 22:54 17920 ----a-w- c:\windows\SysWow64\rpcnetp.dll
2014-05-31 16:04 . 2013-01-06 22:53 17920 ----a-w- c:\windows\SysWow64\rpcnetp.exe
2014-05-17 18:48 . 2014-01-18 14:52 85328 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-05-17 18:48 . 2013-01-04 00:17 423240 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-05-17 18:48 . 2013-01-04 00:17 1039096 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-05-14 09:38 . 2013-04-19 19:16 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-05-14 09:38 . 2013-04-19 19:16 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-04-30 22:04 . 2013-04-15 22:44 208416 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-04-30 22:04 . 2014-04-30 22:04 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-04-30 22:04 . 2013-04-15 22:44 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-04-30 22:04 . 2013-01-04 00:17 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-04-30 22:04 . 2013-01-04 00:17 79184 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-04-30 22:04 . 2013-01-04 00:17 334648 ----a-w- c:\windows\system32\aswBoot.exe
2014-04-30 22:04 . 2014-04-30 22:04 43152 ----a-w- c:\windows\avastSS.scr
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-11-29 284440]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-05-30 3888648]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Microsoft Virtual 3D Video Transport Driver;c:\windows\system32\drivers\Synth3dVsc.sys;c:\windows\SYSNATIVE\drivers\Synth3dVsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe;c:\program files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [x]
S2 ZAtheros Wlan Agent;ZAtheros Wlan Agent;c:\program files (x86)\Atheros\Ath_WlanAgent.exe;c:\program files (x86)\Atheros\Ath_WlanAgent.exe [x]
S3 bScsiSDa;bScsiSDa;c:\windows\system32\DRIVERS\bScsiSDa.sys;c:\windows\SYSNATIVE\DRIVERS\bScsiSDa.sys [x]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys;c:\program files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
Inhalt des "geplante Tasks" Ordners
.
2014-06-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-04-19 09:38]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-04-30 22:04 290888 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\program files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe" [2013-01-02 7144960]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-04-23 170264]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-04-23 398616]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-04-23 439064]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-02-22 12452456]
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.de/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.0.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-cisczhl - c:\programdata\cisczhl.dat
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\SysWOW64\rpcnet.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2014-06-03 00:10:18 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2014-06-02 22:10
.
Vor Suchlauf: 7 Verzeichnis(se), 169.022.427.136 Bytes frei
Nach Suchlauf: 10 Verzeichnis(se), 168.595.492.864 Bytes frei
.
- - End Of File - - C6E64237E94D8E0BB4FA83BAFEEA1EA9