Valarauco | 12.09.2013 18:01 | Hier der Log zu Combofix: Code:
ComboFix 13-09-12.01 - Marion 12.09.2013 18:28:38.1.4 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.1910.810 [GMT 2:00]
ausgeführt von:: c:\users\Marion\Desktop\ComboFix.exe
AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton 360 *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Infizierte Kopie von c:\windows\system32\drivers\ntfs.sys wurde gefunden und desinfiziert
Kopie von - c:\combofix\HarddiskVolumeShadowCopy1_!Windows!System32!drivers!ntfs.sys wurde wiederhergestellt
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-08-12 bis 2013-09-12 ))))))))))))))))))))))))))))))
.
.
2013-09-11 21:42 . 2013-09-11 21:42 -------- d-----w- C:\FRST
2013-09-11 21:07 . 2013-09-11 21:23 -------- d-----w- C:\AdwCleaner
2013-08-25 14:31 . 2013-09-10 17:02 -------- d--h--w- c:\users\Marion\AppData\Roaming\Fcyfm
2013-08-21 17:00 . 2013-08-21 17:04 -------- d-----w- c:\users\Marion\AppData\Roaming\FlashPlayer
2013-08-18 19:35 . 2013-08-18 19:35 -------- d-----w- c:\program files\iPod
2013-08-18 19:35 . 2013-08-18 19:39 -------- d-----w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-08-18 19:35 . 2013-08-18 19:39 -------- d-----w- c:\program files\iTunes
2013-08-18 19:28 . 2013-07-25 08:57 1620992 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-08-18 19:28 . 2013-07-09 04:50 652800 ----a-w- c:\windows\system32\rpcrt4.dll
2013-08-18 19:28 . 2013-07-09 04:46 1166848 ----a-w- c:\windows\system32\crypt32.dll
2013-08-18 19:28 . 2013-07-09 04:52 175104 ----a-w- c:\windows\system32\wintrust.dll
2013-08-18 19:28 . 2013-07-09 04:46 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2013-08-18 19:28 . 2013-07-09 04:46 103936 ----a-w- c:\windows\system32\cryptnet.dll
2013-08-18 19:27 . 2013-07-09 05:03 3913664 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-08-18 19:27 . 2013-07-09 05:03 3968960 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-08-18 19:27 . 2013-07-09 04:53 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-08-18 19:26 . 2013-07-06 05:05 1293760 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-08-18 19:25 . 2013-07-19 01:41 2048 ----a-w- c:\windows\system32\tzres.dll
2013-08-18 19:24 . 2013-06-15 03:38 31232 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-10 19:04 . 2012-04-13 21:04 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-10 19:04 . 2012-02-24 21:57 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-18 19:15 . 2013-03-12 17:23 564432 ----a-w- c:\programdata\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe
2013-07-09 16:50 . 2013-07-09 16:50 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-07-09 16:50 . 2012-09-21 23:24 867240 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-07-09 16:50 . 2012-04-17 09:49 789416 ----a-w- c:\windows\system32\deployJava1.dll
2013-06-19 17:04 . 2013-01-26 13:55 142496 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2013-08-18 19:19 1724616 ----a-w- c:\program files\Microsoft Office 15\root\office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2013-08-18 19:19 1724616 ----a-w- c:\program files\Microsoft Office 15\root\office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2013-08-18 19:19 1724616 ----a-w- c:\program files\Microsoft Office 15\root\office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 130736 ----a-w- c:\users\Marion\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 130736 ----a-w- c:\users\Marion\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 130736 ----a-w- c:\users\Marion\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-06-21 19875432]
"AmazonMP3DownloaderHelper"="c:\users\Marion\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe" [2013-05-22 400704]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2011-07-20 505720]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-01-31 137752]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-01-31 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-01-31 172568]
"IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-01-15 284696]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-09-03 767312]
"IJNetworkScanUtility"="c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe" [2009-09-28 140640]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2011-03-14 2565520]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2011-08-04 1612920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-08-16 152392]
.
c:\users\Marion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
An OneNote senden.lnk - c:\program files\Microsoft Office 15\root\office15\ONENOTEM.EXE /tsr [2013-8-18 158896]
Dropbox.lnk - c:\users\Marion\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-25 27776968]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
VR-NetWorld Auftragsprüfung.lnk - c:\program files\VR-NetWorld\vrtoolcheckorder.exe /autostart [2012-6-25 1136640]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
.
R2 dsiasrv;DSM CM Inventory Agent;c:\program files\Dell\SysMgt\dsia\bin\DsiaSrv32.exe [2011-11-02 149400]
R2 risdpcie;risdpcie;c:\windows\system32\DRIVERS\risdpe86.sys [2010-03-19 59904]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-06-21 162408]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\1404000.028\SYMDS.SYS [2013-05-21 367704]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\1404000.028\SYMEFA.SYS [2013-05-23 934488]
S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20130903.002\BHDrvx86.sys [2013-09-03 1097816]
S1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\N360\1404000.028\ccSetx86.sys [2013-04-16 134744]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20130910.001\IDSvix86.sys [2013-08-21 392792]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\1404000.028\Ironx86.SYS [2013-03-05 175264]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\N360\1404000.028\SYMNETS.SYS [2013-04-25 339544]
S2 ATService;AuthenTec Fingerprint Service;c:\program files\Fingerprint Sensor\AtService.exe [2010-03-03 1803584]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-01-15 13336]
S2 ldam;ldam;c:\program files\logoDIDACT\Agent\bin\ldam.exe [2011-05-19 1264640]
S2 N360;Norton 360;c:\program files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe [2013-05-21 144368]
S2 OfficeSvc;Microsoft Office-Dienst;c:\program files\Microsoft Office 15\ClientX86\integratedoffice.exe [2013-06-09 1316024]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-04-14 2564376]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2011-05-18 40320]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-08-27 108120]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2010-02-26 132480]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-08-31 269824]
S3 ldkbfltr;logoDIDACT Keyboard Filter;c:\windows\system32\DRIVERS\ldkbfltr.sys [2011-05-19 18584]
S3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\DRIVERS\mcvidrv.sys [2012-10-11 34432]
S3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv.sys [2013-01-31 22656]
S3 NETwNs32;___ Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows 7 32-Bit;c:\windows\system32\DRIVERS\NETwNs32.sys [2010-07-14 6814720]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
Inhalt des "geplante Tasks" Ordners
.
2013-09-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-13 19:04]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.myfanfiction.de/profile/Valarauco
uInternet Settings,ProxyOverride = *.local;<local>
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\program files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\program files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
TCP: DhcpNameServer = 195.234.128.7 195.234.128.16
FF - ProfilePath - c:\users\Marion\AppData\Roaming\Mozilla\Firefox\Profiles\az0ybbv7.default-1350768270900\
FF - prefs.js: browser.startup.homepage - hxxp://www.myfanfiction.de/profile/Valarauco
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
MSConfigStartUp-Adobe ARM - c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\20.4.0.40\diMaster.dll\" /prefetch:1"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1963063443-3218842457-3514764407-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. mùT €eÖ¿Ÿ±r*&ݵ9V&µ=,ri¤¥Z´´1È8®€ÞÚÉÁ#ò¤)nyV¬á)Òš”%°<Tä*$~~ÁM>=«é?4k\†Ù§k^XÆH'?_¸à5ó®‰ãt¾°²Ô\-kb¨í%¿ÙL/»(Z2I-Çúûâhÿ~ùT €™]ó=Ó8zBR©£–Þšþe{-Y[DÕõÝBÑnn¤¾Ófg2î,ƒ®èº0*§åX
ӃĺaÕæƒR²{Ø/ÜIª¼Ÿ<—-ãܲ4jþ›kHÚ.…yâ"ÛJ²Ö4µñ.¤¢R²ÞýÌÂãk1ÜÌ}qÜlGco¤ÿÿ]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1963063443-3218842457-3514764407-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. mùT €eÖ¿Ÿ±r*&ݵ9V&µ=,ri¤¥Z´´1È8®€ÞÚÉÁ#ò¤)nyV¬á)Òš”%°<Tä*$~~ÁM>=«é?4k\†Ù§k^XÆH'?_¸à5ó®‰ãt¾°²Ô\-kb¨í%¿ÙL/»(Z2I-Çúûâhÿ~ùT €™]ó=Ó8zBR©£–Þšþe{-Y[DÕõÝBÑnn¤¾Ófg2î,ƒ®èº0*§åX
ӃĺaÕæƒR²{Ø/ÜIª¼Ÿ<—-ãܲ4jþ›kHÚ.…yâ"ÛJ²Ö4µñ.¤¢R²ÞýÌÂãk1ÜÌ}qÜlGco¤ÿÿ\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-1963063443-3218842457-3514764407-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\. mùT €eÖ¿Ÿ±r*&ݵ9V&µ=,ri¤¥Z´´1È8®€ÞÚÉÁ#ò¤)nyV¬á)Òš”%°<Tä*$~~ÁM>=«é?4k\†Ù§k^XÆH'?_¸à5ó®‰ãt¾°²Ô\-kb¨í%¿ÙL/»(Z2I-Çúûâhÿ~ùT €™]ó=Ó8zBR©£–Þšþe{-Y[DÕõÝBÑnn¤¾Ófg2î,ƒ®èº0*§åX
ӃĺaÕæƒR²{Ø/ÜIª¼Ÿ<—-ãܲ4jþ›kHÚ.…yâ"ÛJ²Ö4µñ.¤¢R²ÞýÌÂãk1ÜÌ}qÜlGco¤ÿÿ]
"0"=hex:66,69,6c,65,3a,2f,2f,2f,46,3a,2f,54,61,69,6f,25,32,30,43,72,75,7a,25,
32,30,2d,25,32,30,54,72,6f,75,62,6c,65,6d,61,6b,65,72,25,32,30,48,44,5f,48,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-1963063443-3218842457-3514764407-1000\Software\SecuROM\License information*]
"datasecu"=hex:14,01,9b,c9,ef,7c,03,3f,73,cc,f7,0d,d2,92,74,ee,16,15,30,31,24,
57,09,42,22,20,62,f6,bd,58,31,32,5d,88,44,e0,85,27,8c,0a,54,6e,9e,38,f1,b9,\
"rkeysecu"=hex:93,30,87,ec,b1,f4,26,8d,93,43,99,53,20,39,1d,da
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_168_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_168_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(4104)
c:\users\Marion\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\WLANExt.exe
c:\windows\system32\conhost.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\conhost.exe
c:\windows\servicing\TrustedInstaller.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\HidFind.exe
c:\program files\DellTPad\Apntex.exe
c:\windows\system32\conhost.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-09-12 18:49:22 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2013-09-12 16:49
.
Vor Suchlauf: 9.832.394.752 Bytes frei
Nach Suchlauf: 9.614.163.968 Bytes frei
.
- - End Of File - - 07357AE74A1AE9EC2DF3F93C804403F3
A36C5E4F47E84449FF07ED3517B43A31 |