Kaskadeking | 05.04.2014 16:06 | ComboFix Log: Code:
ComboFix 14-04-05.01 - Kaskadeking 05.04.2014 16:50:31.1.1 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.6143.4749 [GMT 2:00]
ausgeführt von:: c:\users\Kaskadeking\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
FW: avast! Antivirus *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-03-05 bis 2014-04-05 ))))))))))))))))))))))))))))))
.
.
2014-04-05 14:58 . 2014-04-05 14:58 -------- d-----w- c:\users\hedev\AppData\Local\temp
2014-04-05 14:58 . 2014-04-05 14:58 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-04-05 14:25 . 2014-04-05 14:27 -------- d-----w- C:\FRST
2014-04-05 11:41 . 2014-04-05 11:41 -------- d--h--r- c:\users\Kaskadeking\AppData\Roaming\SecuROM
2014-04-05 09:01 . 2014-04-05 09:01 -------- d-----w- c:\programdata\NovaTech Network
2014-04-05 08:58 . 2014-04-05 08:58 -------- d-----w- c:\program files (x86)\Novawave
2014-04-04 17:38 . 2014-04-04 17:43 -------- d-----w- c:\users\Kaskadeking\AppData\Roaming\Dexpot
2014-04-04 17:37 . 2014-04-04 17:43 -------- d-----w- c:\program files (x86)\Dexpot
2014-04-04 17:24 . 2014-04-04 20:15 -------- d-----w- c:\users\Kaskadeking\AppData\Local\Freemake Music Box
2014-04-04 17:24 . 2014-04-04 17:24 -------- d-----w- c:\programdata\Freemake
2014-04-04 17:24 . 2014-04-04 17:24 -------- d-----w- c:\program files (x86)\Freemake
2014-04-04 17:08 . 2014-04-04 17:08 -------- d-----w- c:\program files\Axantum
2014-04-04 12:13 . 2014-03-07 04:43 10521840 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B684D582-03EF-4543-B78D-12C1D9A3355B}\mpengine.dll
2014-04-03 16:23 . 2014-04-03 17:03 -------- d-----w- c:\programdata\SecTaskMan
2014-04-02 16:54 . 2014-04-02 16:54 -------- d-----w- c:\program files (x86)\Cheat Engine 6.3
2014-04-02 16:17 . 2014-04-02 16:17 -------- d-----w- c:\programdata\InstallMate
2014-03-31 12:51 . 2014-03-31 12:58 -------- d-----w- c:\users\Kaskadeking\AppData\Local\gamemaker_studio
2014-03-31 12:51 . 2014-03-31 12:51 -------- d-----w- c:\programdata\gamemaker_studio
2014-03-30 14:21 . 2014-03-30 14:21 -------- d-----w- c:\windows\SysWow64\xlive
2014-03-30 14:21 . 2014-03-30 14:21 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2014-03-30 13:30 . 2014-03-30 13:30 -------- d-----w- c:\programdata\Codemasters
2014-03-30 11:29 . 2014-04-05 10:35 -------- d-----w- c:\program files (x86)\Minecraft Manager
2014-03-30 11:18 . 2014-03-30 11:18 -------- d-----w- c:\program files (x86)\Inno Setup 5
2014-03-30 08:59 . 2014-03-30 08:59 -------- d-----w- c:\users\Kaskadeking\Source
2014-03-29 19:21 . 2014-03-29 19:21 43152 ----a-w- c:\windows\avastSS.scr
2014-03-29 12:58 . 2014-03-29 12:58 -------- d-----w- c:\program files (x86)\Fiddler2
2014-03-27 14:02 . 2014-03-27 14:02 -------- d-----w- c:\users\Kaskadeking\AppData\Roaming\updateSystem.NET
2014-03-27 13:15 . 2014-03-27 13:15 -------- d-----w- c:\program files\updateSystem.NET
2014-03-23 12:32 . 2014-03-23 12:43 -------- d-----w- c:\program files (x86)\S4League
2014-03-23 12:32 . 2003-08-15 15:02 69632 ------w- c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe
2014-03-23 12:32 . 2003-08-15 14:57 212992 ------w- c:\program files (x86)\Common Files\InstallShield\UpdateService\ISDM.exe
2014-03-23 12:32 . 2003-08-15 15:01 380928 ------w- c:\program files (x86)\Common Files\InstallShield\UpdateService\agent.exe
2014-03-23 12:31 . 2003-09-03 01:28 724992 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iKernel.dll
2014-03-23 12:31 . 2003-09-03 01:27 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\ctor.dll
2014-03-23 12:31 . 2003-09-03 01:26 266240 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iscript.dll
2014-03-23 12:31 . 2003-09-03 01:26 192512 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iuser.dll
2014-03-23 12:31 . 2003-09-03 01:25 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe
2014-03-23 12:31 . 2003-09-03 01:23 32768 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll
2014-03-23 12:31 . 2014-03-23 12:31 311428 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\Setup.dll
2014-03-23 12:31 . 2014-03-23 12:31 184452 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iGdi.dll
2014-03-19 17:41 . 2014-04-01 16:30 -------- d-----w- C:\Games
2014-03-19 17:38 . 2014-03-19 17:38 -------- d-----w- c:\users\Kaskadeking\AppData\Roaming\QuickScan
2014-03-19 17:08 . 2014-03-21 13:33 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird
2014-03-18 16:46 . 2014-04-01 16:28 -------- d-----w- c:\users\Kaskadeking\AppData\Roaming\Cobalt
2014-03-18 16:45 . 2014-04-01 16:28 -------- d-----w- c:\program files (x86)\Oxeye Games
2014-03-16 12:45 . 2014-04-05 13:54 -------- d-----w- c:\users\Kaskadeking\AppData\Roaming\.minecraft
2014-03-15 18:27 . 2014-03-16 09:23 -------- d-----w- c:\users\Kaskadeking\AppData\Roaming\streamripper
2014-03-15 18:19 . 2014-03-16 09:21 -------- d-----w- c:\program files (x86)\Common Files\PX Storage Engine
2014-03-15 18:19 . 2014-03-16 09:21 -------- d-----w- c:\program files (x86)\Winamp
2014-03-13 11:33 . 2014-03-13 11:33 -------- d-----w- c:\users\Kaskadeking\AppData\Roaming\.TCLauncher
2014-03-12 15:07 . 2014-03-12 15:07 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2014-03-12 14:38 . 2014-03-12 14:38 -------- d-----w- C:\NVIDIA
2014-03-12 11:42 . 2014-02-04 02:32 624128 ----a-w- c:\windows\system32\qedit.dll
2014-03-12 11:42 . 2014-02-04 02:04 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2014-03-09 09:35 . 2014-03-09 09:35 85016 ---ha-w- c:\windows\system32\drivers\PROCMON23.SYS
2014-03-09 09:28 . 2014-03-09 09:28 -------- d-----w- c:\users\Kaskadeking\AppData\Roaming\Wireshark
2014-03-09 09:27 . 2014-03-09 09:27 -------- d-----w- c:\program files (x86)\WinPcap
2014-03-09 09:26 . 2014-03-09 09:27 -------- d-----w- c:\program files\Wireshark
2014-03-08 08:53 . 2014-04-04 17:19 -------- d-----w- c:\users\Kaskadeking\Stuff
2014-03-07 15:25 . 2014-03-07 15:26 -------- d-----w- c:\program files (x86)\BlueStacks
2014-03-07 15:24 . 2014-03-07 15:24 -------- d-----w- c:\users\Kaskadeking\AppData\Local\Bluestacks
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-30 13:41 . 2009-08-18 10:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2014-03-30 13:41 . 2009-08-18 09:24 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-03-29 19:21 . 2013-12-24 09:37 84816 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-03-29 19:21 . 2013-12-24 09:37 208928 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-03-29 19:21 . 2013-12-24 09:37 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-03-29 19:21 . 2013-12-24 09:37 79184 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-03-29 19:21 . 2013-12-24 09:37 423240 ----a-w- c:\windows\system32\drivers\aswSP.sys
2014-03-29 19:21 . 2013-12-24 09:37 1039096 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-03-29 19:21 . 2013-12-24 09:37 334648 ----a-w- c:\windows\system32\aswBoot.exe
2014-03-29 19:21 . 2013-12-24 09:37 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-03-18 19:45 . 2014-02-08 19:53 90015360 ----a-w- c:\windows\system32\MRT.exe
2014-03-11 17:36 . 2013-11-16 10:41 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-03-11 17:36 . 2013-11-16 10:41 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-03-05 12:19 . 2014-03-05 12:19 925184 ----a-w- c:\windows\expstart.exe
2014-03-05 12:00 . 2009-07-13 23:55 332288 ----a-w- c:\windows\system32\uxtheme.dll
2014-03-05 12:00 . 2013-11-18 16:08 2851840 ----a-w- c:\windows\system32\themeui.dll
2014-03-05 12:00 . 2009-07-13 23:54 44544 ----a-w- c:\windows\system32\themeservice.dll
2014-03-04 14:35 . 2014-02-18 19:18 15783992 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2014-03-04 14:35 . 2014-02-05 15:28 2715264 ----a-w- c:\windows\SysWow64\nvapi.dll
2014-03-04 14:35 . 2010-01-12 04:03 3093280 ----a-w- c:\windows\system32\nvapi64.dll
2014-03-04 14:35 . 2010-01-12 04:03 18302384 ----a-w- c:\windows\system32\nvwgf2umx.dll
2014-03-04 14:35 . 2010-01-12 04:03 14709720 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2014-03-04 13:06 . 2010-01-11 22:19 6714312 ----a-w- c:\windows\system32\nvcpl.dll
2014-03-04 13:06 . 2010-01-11 22:19 3497816 ----a-w- c:\windows\system32\nvsvc64.dll
2014-03-04 13:05 . 2010-01-11 22:19 922968 ----a-w- c:\windows\system32\nvvsvc.exe
2014-03-04 13:05 . 2010-01-11 22:19 64968 ----a-w- c:\windows\system32\nvshext.dll
2014-03-04 13:05 . 2010-01-11 22:19 2558808 ----a-w- c:\windows\system32\nvsvcr.dll
2014-03-04 13:05 . 2010-01-11 22:19 386336 ----a-w- c:\windows\system32\nvmctray.dll
2014-03-04 11:32 . 2014-02-18 19:24 599840 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2014-02-13 16:12 . 2014-02-13 16:12 1139040 ----a-w- c:\programdata\Microsoft\WDExpress\12.0\1031\ResourceCache.dll
2014-02-08 18:34 . 2014-02-18 19:18 1885472 ----a-w- c:\windows\system32\nvdispco6433489.dll
2014-02-08 18:34 . 2014-02-18 19:18 1515296 ----a-w- c:\windows\system32\nvdispgenco6433489.dll
2014-02-03 06:45 . 2014-03-05 17:34 129944 ----a-w- c:\windows\system32\drivers\scdemu.sys
2014-01-16 13:16 . 2014-01-16 13:16 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-01-16 13:14 . 2014-01-16 13:15 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2014-01-16 13:14 . 2014-01-16 13:15 312744 ----a-w- c:\windows\system32\javaws.exe
2014-01-16 13:14 . 2014-01-16 13:15 189352 ----a-w- c:\windows\system32\javaw.exe
2014-01-16 13:14 . 2014-01-16 13:15 189352 ----a-w- c:\windows\system32\java.exe
2014-01-11 11:10 . 2014-01-11 11:10 381440 ----a-w- c:\windows\system32\drivers\sptd.sys
2014-01-11 10:45 . 2014-01-11 10:45 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\Kaskadeking\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\Kaskadeking\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\Kaskadeking\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files (x86)\RocketDock\RocketDock.exe" [2007-09-02 495616]
"Sysinternals Desktops"="c:\users\Kaskadeking\Desktop\Desktops.exe" [2012-10-17 116824]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-03-29 3854640]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2014-02-03 377368]
"BlueStacks Agent"="c:\program files (x86)\BlueStacks\HD-Agent.exe" [2014-02-18 815888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SpUninstallDeleteDir"="rmdir" [X]
.
c:\users\Kaskadeking\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Dropbox.lnk - c:\users\Kaskadeking\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-3-19 32667896]
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2013-10-29 36536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer5"=wdmaud.drv
.
R2 ????????t;????4????t;???????????????????????????;??????????????????????????? [x]
R2 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 WiseBootAssistant;Wise Boot Assistant;c:\program files (x86)\Wise\Wise Care 365\BootTime.exe;c:\program files (x86)\Wise\Wise Care 365\BootTime.exe [x]
R3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R3 DfSdkS;Defragmentation-Service;c:\program files (x86)\Ashampoo\Ashampoo WinOptimizer 10\DfsdkS64.exe;c:\program files (x86)\Ashampoo\Ashampoo WinOptimizer 10\DfsdkS64.exe [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x]
R3 VsEtwService120;Visual Studio ETW-Ereignisauflistungsdienst;c:\program files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe;c:\program files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys;c:\windows\SYSNATIVE\DRIVERS\vmci.sys [x]
S0 vsock;vSockets Driver;c:\windows\system32\drivers\vsock.sys;c:\windows\SYSNATIVE\drivers\vsock.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxDrv.sys [x]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxUSBMon.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [x]
S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [x]
S2 BstHdUpdaterSvc;BlueStacks Updater Service;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe [x]
S2 HerculesWiFi;HerculesWiFi;c:\windows\SysWOW64\\HerculesWiFiService.exe;c:\windows\SysWOW64\\HerculesWiFiService.exe [x]
S2 HFGService;Handsfree Headset Service;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys;c:\windows\SYSNATIVE\drivers\npf.sys [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [x]
S3 BthAudioHF;BthAudioHF-Dienst;c:\windows\system32\DRIVERS\BthAudioHF.sys;c:\windows\SYSNATIVE\DRIVERS\BthAudioHF.sys [x]
S3 BthAvrcp;Bluetooth-AVRCP-Profil;c:\windows\system32\DRIVERS\BthAvrcp.sys;c:\windows\SYSNATIVE\DRIVERS\BthAvrcp.sys [x]
S3 csr_a2dp;Bluetooth-AV-Profil;c:\windows\system32\drivers\bthav.sys;c:\windows\SYSNATIVE\drivers\bthav.sys [x]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\rtwlanu.sys;c:\windows\SYSNATIVE\DRIVERS\rtwlanu.sys [x]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - PROCEXP152
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-03-15 18:55 1150280 ----a-w- c:\program files (x86)\Google\Chrome\Application\33.0.1750.154\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-04-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-16 17:36]
.
2014-04-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-01-11 12:36]
.
2014-04-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-01-11 12:36]
.
2013-12-23 c:\windows\Tasks\Wise Turbo Checker.job
- c:\program files (x86)\Wise\Wise Care 365\WiseTurbo.exe [2013-12-23 13:38]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-03-29 19:21 290888 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2013-12-10 2279712]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2013-12-10 1100248]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = www.bing.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <-loopback>
LSP: %windir%\system32\vsocklib.dll
TCP: DhcpNameServer = 192.168.178.1
TCP: Interfaces\{6F19C187-7861-4839-A7CF-716C1C6FEECE}\642716E6B4562737: NameServer = 8.8.8.8,8.8.4.4
FF - ProfilePath - c:\users\Kaskadeking\AppData\Roaming\Mozilla\Firefox\Profiles\3tx73yav.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxps://www.google.de
FF - prefs.js: network.proxy.type - 2
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
.
.
Binary file temp00 matches
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WiseBootAssistant ]
"ImagePath"="???????????????????????????"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,7d,33,df,0d,ad,89,52,45,af,c1,59,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,af,f3,68,06,b9,b5,48,44,9a,d5,7b,\
.
[HKEY_USERS\S-1-5-21-4058871879-2829469030-3260525534-1000\Software\SecuROM\License information*]
"datasecu"=hex:b1,66,08,81,65,31,4b,69,de,b8,6f,e2,29,a8,12,25,fc,74,f7,dc,55,
47,e6,31,f0,da,ef,59,86,31,db,21,a9,a5,3e,ad,d1,f7,43,e4,06,9e,b3,85,41,f4,\
"rkeysecu"=hex:0f,1f,98,1e,ef,c1,26,5a,c6,da,42,0e,d3,79,52,56
.
[HKEY_LOCAL_MACHINE\SOFTWARE\BlueStacks]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WiseBootAssistant*]
"Type"=dword:00000110
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=expand:"???????????????????????????"
"DisplayName"="????4????t\""
"WOW64"=dword:00000001
"ObjectName"="LocalSystem"
.
Zeit der Fertigstellung: 2014-04-05 17:00:45
ComboFix-quarantined-files.txt 2014-04-05 15:00
.
Vor Suchlauf: 12 Verzeichnis(se), 119.848.435.712 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 119.403.376.640 Bytes frei
.
- - End Of File - - AD851F4D00EEBD997CEF2F86D15D59D3
A36C5E4F47E84449FF07ED3517B43A31 EDIT: Ich weiß jetzt wo das Geräusch herkommt. Irgendwie hat NoScript einfach die Checkbox "Klang ausgeben, wenn Skripte blockiert werden" aktiviert was dann diesen merkwürdigen Ton von sich gibt. Ist also damit gelöst >.< |