Hier nun die Logfile von ComboFix:    Code:  
 ComboFix 13-12-13.01 - Fabian 13.12.2013  20:19:41.1.4 - x64 
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.49.1031.18.4094.2275 [GMT 1:00] 
ausgeführt von:: c:\users\Fabian\Desktop\ComboFix.exe 
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F} 
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} 
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} 
. 
. 
(((((((((((((((((((((((   Dateien erstellt von 2013-11-13 bis 2013-12-13  )))))))))))))))))))))))))))))) 
. 
. 
2013-12-13 19:28 . 2013-12-13 19:28        --------        d-----w-        c:\users\UpdatusUser\AppData\Local\temp 
2013-12-13 19:28 . 2013-12-13 19:28        --------        d-----w-        c:\users\Fabian\AppData\Local\temp 
2013-12-13 19:28 . 2013-12-13 19:28        --------        d-----w-        c:\users\Default\AppData\Local\temp 
2013-12-13 19:17 . 2013-12-13 19:18        --------        d-----w-        C:\32788R22FWJFW 
2013-12-13 17:40 . 2013-11-08 03:12        10285968        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DA7E220A-22C4-45F1-933B-429505B9AA96}\mpengine.dll 
2013-12-13 16:45 . 2013-12-13 16:45        --------        d-----w-        C:\FRST 
2013-12-11 00:42 . 2013-10-30 02:10        2776064        ----a-w-        c:\windows\system32\win32k.sys 
2013-12-11 00:42 . 2013-10-11 04:27        144384        ----a-w-        c:\windows\system32\wshom.ocx 
2013-12-11 00:42 . 2013-10-11 04:26        198656        ----a-w-        c:\windows\system32\scrrun.dll 
2013-12-11 00:42 . 2013-10-11 02:19        166912        ----a-w-        c:\windows\system32\wscript.exe 
2013-12-11 00:42 . 2013-10-11 02:19        147968        ----a-w-        c:\windows\system32\cscript.exe 
2013-12-11 00:42 . 2013-10-11 02:08        131072        ----a-w-        c:\windows\SysWow64\wshom.ocx 
2013-12-11 00:42 . 2013-10-11 00:35        135168        ----a-w-        c:\windows\SysWow64\cscript.exe 
2013-12-11 00:42 . 2013-10-11 00:35        155648        ----a-w-        c:\windows\SysWow64\wscript.exe 
2013-12-11 00:42 . 2013-10-11 02:08        36864        ----a-w-        c:\windows\SysWow64\wshcon.dll 
2013-12-11 00:42 . 2013-10-11 02:08        172032        ----a-w-        c:\windows\SysWow64\scrrun.dll 
2013-12-11 00:42 . 2013-10-22 09:31        79360        ----a-w-        c:\windows\system32\imagehlp.dll 
2013-12-11 00:42 . 2013-10-22 07:19        158208        ----a-w-        c:\windows\SysWow64\imagehlp.dll 
2013-12-11 00:41 . 2013-10-30 04:34        374784        ----a-w-        c:\windows\system32\SysFxUI.dll 
2013-12-11 00:41 . 2013-10-30 03:55        122368        ----a-w-        c:\windows\system32\drivers\drmk.sys 
2013-12-11 00:41 . 2013-10-30 02:33        218112        ----a-w-        c:\windows\system32\drivers\portcls.sys 
2013-12-11 00:22 . 2013-12-11 00:22        --------        d-----w-        c:\users\Fabian\AppData\Roaming\TrojanHunter 
2013-12-10 22:09 . 2013-12-10 22:10        --------        d-----w-        c:\programdata\TrojanHunter 
2013-12-10 22:09 . 2013-12-10 22:11        --------        d-----w-        c:\program files (x86)\TrojanHunter 5.5 
2013-12-10 21:06 . 2013-11-08 03:12        10285968        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 
2013-12-06 13:33 . 2013-10-18 18:16        965000        ------w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7D7DC38B-43C6-4727-8135-B7445B7C65A3}\gapaengine.dll 
2013-11-15 15:08 . 2013-10-11 04:23        462848        ----a-w-        c:\windows\system32\IKEEXT.DLL 
2013-11-15 15:08 . 2013-10-11 04:23        781824        ----a-w-        c:\windows\system32\FWPUCLNT.DLL 
2013-11-15 15:08 . 2013-10-11 02:07        596480        ----a-w-        c:\windows\SysWow64\FWPUCLNT.DLL 
2013-11-15 15:08 . 2013-10-03 15:02        1278976        ----a-w-        c:\windows\system32\crypt32.dll 
2013-11-15 15:08 . 2013-10-03 12:45        993792        ----a-w-        c:\windows\SysWow64\crypt32.dll 
2013-11-15 15:08 . 2013-10-03 15:03        389632        ----a-w-        c:\windows\system32\gdi32.dll 
2013-11-15 15:08 . 2013-10-03 12:46        304128        ----a-w-        c:\windows\SysWow64\gdi32.dll 
2013-11-15 15:08 . 2013-09-04 02:31        404992        ----a-w-        c:\windows\system32\drivers\afd.sys 
. 
. 
. 
((((((((((((((((((((((((((((((((((((   Find3M Bericht   )))))))))))))))))))))))))))))))))))))))))))))))))))))) 
. 
2013-12-13 16:05 . 2006-11-02 12:35        90708896        ----a-w-        c:\windows\system32\mrt.exe 
2013-12-10 23:28 . 2012-03-29 08:17        692616        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe 
2013-12-10 23:28 . 2012-02-24 14:08        71048        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl 
2013-11-19 10:21 . 2012-02-23 18:32        267936        ------w-        c:\windows\system32\MpSigStub.exe 
2013-10-30 04:34 . 2008-01-21 02:46        1386496        ----a-w-        c:\windows\system32\WMALFXGFXDSP.dll 
2013-10-18 18:16 . 2012-06-12 08:10        965000        ------w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 
2013-10-15 20:06 . 2013-10-15 20:06        96168        ----a-w-        c:\windows\SysWow64\WindowsAccessBridge-32.dll 
2013-09-27 08:53 . 2013-09-27 08:53        248240        ----a-w-        c:\windows\system32\drivers\MpFilter.sys 
2013-09-27 08:53 . 2011-04-27 14:25        134944        ----a-w-        c:\windows\system32\drivers\NisDrvWFP.sys 
. 
. 
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   )))))))))))))))))))))))))))))))))))))))) 
. 
. 
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.  
REGEDIT4 
. 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1555968] 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] 
"AVMWlanClient"="c:\program files (x86)\avmwlanstick\wlangui.exe" [2010-10-22 2105344] 
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] 
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720] 
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208] 
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] 
"iTunesHelper"="d:\program files (x86)\iTunes\iTunesHelper.exe" [2013-11-01 152392] 
. 
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ 
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768] 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] 
"EnableUIADesktopToggle"= 0 (0x0) 
. 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] 
@="Service" 
. 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] 
@="Service" 
. 
--- Andere Dienste/Treiber im Speicher --- 
. 
*NewlyCreated* - UXDIIPOD 
*Deregistered* - uxdiipod 
. 
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] 
hpdevmgmt        REG_MULTI_SZ           hpqcxs08 hpqddsvc 
. 
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs 
Themes 
. 
Inhalt des "geplante Tasks" Ordners 
. 
2013-12-13 c:\windows\Tasks\Adobe Flash Player Updater.job 
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 23:28] 
. 
. 
--------- X64 Entries ----------- 
. 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-08-26 12681320] 
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 1266912] 
. 
------- Zusätzlicher Suchlauf ------- 
. 
uLocal Page = c:\windows\system32\blank.htm 
mLocal Page = c:\windows\SysWOW64\blank.htm 
uInternet Settings,ProxyOverride = fritz.box;*.local 
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000 
TCP: DhcpNameServer = 192.168.0.1 
FF - ProfilePath - c:\users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\hvczz6lh.default\ 
FF - prefs.js: browser.search.selectedEngine - Google 
FF - prefs.js: browser.startup.homepage - msn.de 
FF - ExtSQL: !HIDDEN! 2012-03-04 10:16; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 
. 
- - - - Entfernte verwaiste Registrierungseinträge - - - - 
. 
Wow6432Node-HKCU-Run-WMPNSCFG - c:\program files (x86)\Windows Media Player\WMPNSCFG.exe 
SafeBoot-WudfPf 
SafeBoot-WudfRd 
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe 
. 
. 
. 
--------------------- Gesperrte Registrierungsschluessel --------------------- 
. 
[HKEY_USERS\S-1-5-21-2251248673-3584426014-1863489444-1000\Software\SecuROM\License information*] 
"datasecu"=hex:99,71,d7,f9,9b,29,de,62,3f,8f,53,89,66,d0,8e,68,20,7c,1d,47,9a, 
   d1,37,a3,0a,32,56,7d,75,c0,c4,6c,fa,c5,9c,da,c5,bf,53,04,51,5e,2b,de,b0,b3,\ 
"rkeysecu"=hex:53,27,31,b3,b9,b5,85,f8,69,69,5a,e8,8f,52,d3,28 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] 
@Denied: (A 2) (Everyone) 
@="FlashBroker" 
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] 
"Enabled"=dword:00000001 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] 
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] 
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] 
@Denied: (A 2) (Everyone) 
@="IFlashBroker5" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] 
@="{00020424-0000-0000-C000-000000000046}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] 
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" 
"Version"="1.0" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] 
@Denied: (A 2) (Everyone) 
@="FlashBroker" 
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] 
"Enabled"=dword:00000001 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] 
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] 
@Denied: (A 2) (Everyone) 
@="Shockwave Flash Object" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx" 
"ThreadingModel"="Apartment" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] 
@="0" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] 
@="ShockwaveFlash.ShockwaveFlash.11" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] 
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] 
@="1.0" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] 
@="ShockwaveFlash.ShockwaveFlash" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] 
@Denied: (A 2) (Everyone) 
@="Macromedia Flash Factory Object" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx" 
"ThreadingModel"="Apartment" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] 
@="FlashFactory.FlashFactory.1" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] 
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] 
@="1.0" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] 
@="FlashFactory.FlashFactory" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] 
@Denied: (A 2) (Everyone) 
@="IFlashBroker5" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] 
@="{00020424-0000-0000-C000-000000000046}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] 
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" 
"Version"="1.0" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] 
@Denied: (A 2) (Everyone) 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] 
@="Shockwave Flash" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] 
@Denied: (A 2) (Everyone) 
@="" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] 
@="FlashBroker" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes] 
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59, 
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ 
. 
Zeit der Fertigstellung: 2013-12-13  20:40:57 
ComboFix-quarantined-files.txt  2013-12-13 19:40 
. 
Vor Suchlauf: 9 Verzeichnis(se), 38.726.721.536 Bytes frei 
Nach Suchlauf: 14 Verzeichnis(se), 39.756.500.992 Bytes frei 
. 
- - End Of File - - 952D51E252613F4F1CAD08075B88FDDB 
5C616939100B85E558DA92B899A0FC36      |