Combofix Logfile: Code:
ComboFix 14-01-27.02 - Daniel 28.01.2014 16:26:50.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.8184.2206 [GMT 1:00]
ausgeführt von:: c:\users\Daniel\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Daniel\AppData\Local\Temp\10d2ca4a-28d7-4d81-8c1e-dc42bb6c83fc\CliSecureRT64.dll
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-12-28 bis 2014-01-28 ))))))))))))))))))))))))))))))
.
.
2014-01-28 15:43 . 2014-01-28 15:43 -------- d-----w- c:\users\DefaultAppPool\AppData\Local\temp
2014-01-28 15:43 . 2014-01-28 15:43 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-01-28 12:24 . 2014-01-28 12:24 -------- d-----w- c:\users\Daniel\AppData\Local\Cosa_Nostra
2014-01-28 10:59 . 2014-01-28 10:59 -------- d-----w- c:\users\Daniel\AppData\Local\Blizzard Entertainment
2014-01-28 10:59 . 2014-01-28 10:59 -------- d-----w- c:\users\Daniel\AppData\Local\Battle.net
2014-01-28 10:59 . 2014-01-28 10:59 -------- d-----w- c:\users\Daniel\AppData\Roaming\Battle.net
2014-01-28 10:58 . 2014-01-28 10:58 -------- d-----w- c:\programdata\Blizzard Entertainment
2014-01-28 10:58 . 2014-01-28 10:58 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment
2014-01-28 10:55 . 2014-01-28 10:55 -------- d-----w- c:\programdata\Battle.net
2014-01-28 03:27 . 2014-01-28 03:27 -------- d-----w- c:\program files (x86)\MySQL
2014-01-28 02:34 . 2014-01-28 05:31 -------- d-----w- c:\users\Daniel\AppData\Roaming\FileZilla
2014-01-27 22:07 . 2014-01-27 22:07 -------- d-----w- c:\program files (x86)\ESET
2014-01-27 22:01 . 2014-01-28 09:39 -------- d-----w- c:\users\Daniel\AppData\Roaming\QuickScan
2014-01-27 21:03 . 2014-01-27 21:03 -------- d-----w- c:\programdata\Malwarebytes
2014-01-27 21:03 . 2014-01-27 22:00 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2014-01-27 21:03 . 2014-01-27 21:36 119000 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-01-27 21:02 . 2014-01-27 21:33 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-01-26 23:50 . 2014-01-26 23:50 -------- d-----w- C:\FRST
2014-01-26 17:56 . 2014-01-26 17:56 -------- d-----w- c:\users\Daniel\AppData\Local\SymbolSourceSymbols
2014-01-26 17:56 . 2014-01-26 17:56 -------- d-----w- c:\users\Daniel\AppData\Local\RefSrcSymbols
2014-01-26 17:56 . 2014-01-26 17:57 -------- d-----w- c:\users\Daniel\AppData\Roaming\JetBrains
2014-01-26 17:56 . 2014-01-26 17:56 -------- d-----w- c:\users\Daniel\AppData\Local\JetBrains
2014-01-15 14:47 . 2014-01-15 14:47 -------- d--h--w- c:\program files (x86)\Common Files\EAInstaller
2014-01-15 14:46 . 2014-01-15 14:46 189248 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-01-15 14:46 . 2014-01-15 14:46 189248 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-01-15 14:46 . 2014-01-15 14:46 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2014-01-15 14:25 . 2014-01-15 14:25 -------- d-----w- c:\users\Daniel\AppData\Local\Origin
2014-01-15 14:16 . 2014-01-15 14:16 -------- d-----w- c:\programdata\EA Core
2014-01-15 14:16 . 2014-01-15 14:50 -------- d-----w- c:\programdata\EA Logs
2014-01-15 14:16 . 2014-01-15 14:16 -------- d-----w- c:\programdata\Electronic Arts
2014-01-15 14:12 . 2014-01-15 14:12 -------- d-----w- c:\users\Daniel\AppData\Local\ESN
2014-01-15 14:12 . 2014-01-15 14:12 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins
2014-01-13 21:42 . 2014-01-13 21:42 -------- d-----w- c:\users\Daniel\AppData\Local\Black_Tree_Gaming
2014-01-13 19:02 . 2014-01-14 22:08 -------- d-----w- c:\users\Daniel\AppData\Local\Skyrim
2014-01-11 09:20 . 1997-03-24 16:42 314368 ----a-w- c:\windows\IsUninst.exe
2014-01-11 08:53 . 2014-01-11 08:53 -------- d-----w- c:\users\Daniel\AppData\Roaming\Hex-Rays
2014-01-10 19:56 . 2014-01-12 19:44 -------- d-----w- c:\users\Daniel\AppData\Roaming\Awesomium
2014-01-10 19:30 . 2014-01-10 19:30 -------- d-----w- c:\programdata\Elder Scrolls Online
2014-01-07 18:03 . 2014-01-07 18:03 -------- d-----w- c:\users\Daniel\AppData\Roaming\Crypto Obfuscator For .Net v2012 R2
2014-01-07 18:03 . 2014-01-07 18:03 -------- d-----w- c:\users\Daniel\AppData\Local\SkinSoft
2014-01-06 15:06 . 2014-01-06 15:06 409600 ----a-r- c:\users\Daniel\AppData\Roaming\Microsoft\Installer\{F149CF33-0074-4AF8-AC1C-AE51086D4E25}\SliQEmailLinkClick_F553E8ECFC61412F965137651E73CF0E.exe
2014-01-06 15:06 . 2014-01-06 15:06 409600 ----a-r- c:\users\Daniel\AppData\Roaming\Microsoft\Installer\{F149CF33-0074-4AF8-AC1C-AE51086D4E25}\SliQEmailLinkClick_52AB910A415D44CBAEA63829349710C3.exe
2014-01-06 15:06 . 2014-01-06 15:06 409600 ----a-r- c:\users\Daniel\AppData\Roaming\Microsoft\Installer\{F149CF33-0074-4AF8-AC1C-AE51086D4E25}\ARPPRODUCTICON.exe
2014-01-03 22:54 . 2014-01-03 22:54 42184 ----a-w- c:\windows\system32\drivers\taphss6.sys
2014-01-03 16:16 . 2014-01-03 16:16 -------- d-----w- c:\program files (x86)\TeamViewer
2014-01-02 06:06 . 2014-01-02 06:06 -------- d-----w- c:\users\Daniel\AppData\Roaming\Notepad++
2013-12-31 17:21 . 2014-01-27 22:15 -------- d-----w- c:\users\Daniel\AppData\Local\CrashDumps
2013-12-31 05:52 . 2013-12-31 05:52 -------- d-----w- c:\users\Daniel\AppData\Roaming\Avira
2013-12-31 05:51 . 2013-12-09 10:37 84720 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-12-31 05:51 . 2013-12-09 10:37 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-12-31 05:51 . 2013-12-09 10:37 131576 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-12-31 05:51 . 2013-12-09 10:37 108440 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-12-31 05:51 . 2013-12-31 05:51 -------- d-----w- c:\programdata\Avira
2013-12-31 05:51 . 2013-12-31 05:51 -------- d-----w- c:\program files (x86)\Avira
2013-12-31 01:16 . 2014-01-02 11:11 -------- d-----w- c:\users\Daniel\AppData\Local\FMOD Studio
2013-12-30 20:36 . 2014-01-26 18:06 -------- d-----w- c:\users\Daniel\AppData\Roaming\Wireshark
2013-12-30 20:28 . 2013-12-30 20:28 -------- d-----w- c:\program files (x86)\WinPcap
2013-12-29 20:07 . 2013-12-29 20:22 -------- d-----w- c:\users\Daniel\AppData\Local\Gapotchenko
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-27 21:29 . 2013-12-01 21:39 4194304 ----a-w- c:\windows\ServiceProfiles\NetworkService\msmqlog.bin
2013-11-23 13:52 . 2013-11-23 13:52 27760 ----a-w- c:\windows\system32\drivers\ggsemc.sys
2013-11-23 13:52 . 2013-11-23 13:52 1721576 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2013-11-23 13:52 . 2013-11-23 13:52 14448 ----a-w- c:\windows\system32\drivers\ggflt.sys
2013-11-18 17:53 . 2013-11-18 17:53 1089632 ----a-w- c:\programdata\Microsoft\WDExpress\11.0\1031\ResourceCache.dll
2013-11-15 18:19 . 2013-11-15 18:19 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2013-11-09 18:43 . 2013-11-09 18:43 97280 ----a-w- c:\windows\system32\mshtmled.dll
2013-11-09 18:43 . 2013-11-09 18:43 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-11-09 18:43 . 2013-11-09 18:43 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-11-09 18:43 . 2013-11-09 18:43 89600 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-11-09 18:43 . 2013-11-09 18:43 855552 ----a-w- c:\windows\system32\jscript.dll
2013-11-09 18:43 . 2013-11-09 18:43 81408 ----a-w- c:\windows\system32\icardie.dll
2013-11-09 18:43 . 2013-11-09 18:43 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-11-09 18:43 . 2013-11-09 18:43 762368 ----a-w- c:\windows\system32\ieapfltr.dll
2013-11-09 18:43 . 2013-11-09 18:43 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-11-09 18:43 . 2013-11-09 18:43 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-11-09 18:43 . 2013-11-09 18:43 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-11-09 18:43 . 2013-11-09 18:43 67072 ----a-w- c:\windows\system32\iesetup.dll
2013-11-09 18:43 . 2013-11-09 18:43 62976 ----a-w- c:\windows\system32\pngfilt.dll
2013-11-09 18:43 . 2013-11-09 18:43 61952 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-11-09 18:43 . 2013-11-09 18:43 61440 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-11-09 18:43 . 2013-11-09 18:43 603136 ----a-w- c:\windows\system32\msfeeds.dll
2013-11-09 18:43 . 2013-11-09 18:43 599552 ----a-w- c:\windows\system32\vbscript.dll
2013-11-09 18:43 . 2013-11-09 18:43 53248 ----a-w- c:\windows\system32\jsproxy.dll
2013-11-09 18:43 . 2013-11-09 18:43 526336 ----a-w- c:\windows\system32\ieui.dll
2013-11-09 18:43 . 2013-11-09 18:43 523264 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-11-09 18:43 . 2013-11-09 18:43 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-11-09 18:43 . 2013-11-09 18:43 51712 ----a-w- c:\windows\system32\ie4uinit.exe
2013-11-09 18:43 . 2013-11-09 18:43 51200 ----a-w- c:\windows\system32\imgutil.dll
2013-11-09 18:43 . 2013-11-09 18:43 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-11-09 18:43 . 2013-11-09 18:43 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-11-09 18:43 . 2013-11-09 18:43 452096 ----a-w- c:\windows\system32\dxtmsft.dll
2013-11-09 18:43 . 2013-11-09 18:43 441856 ----a-w- c:\windows\system32\html.iec
2013-11-09 18:43 . 2013-11-09 18:43 39936 ----a-w- c:\windows\system32\iernonce.dll
2013-11-09 18:43 . 2013-11-09 18:43 3959296 ----a-w- c:\windows\system32\jscript9.dll
2013-11-09 18:43 . 2013-11-09 18:43 38400 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-11-09 18:43 . 2013-11-09 18:43 361984 ----a-w- c:\windows\SysWow64\html.iec
2013-11-09 18:43 . 2013-11-09 18:43 2876928 ----a-w- c:\windows\SysWow64\jscript9.dll
2013-11-09 18:43 . 2013-11-09 18:43 281600 ----a-w- c:\windows\system32\dxtrans.dll
2013-11-09 18:43 . 2013-11-09 18:43 27648 ----a-w- c:\windows\system32\licmgr10.dll
2013-11-09 18:43 . 2013-11-09 18:43 270848 ----a-w- c:\windows\system32\iedkcs32.dll
2013-11-09 18:43 . 2013-11-09 18:43 2706432 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-11-09 18:43 . 2013-11-09 18:43 2706432 ----a-w- c:\windows\system32\mshtml.tlb
2013-11-09 18:43 . 2013-11-09 18:43 2647552 ----a-w- c:\windows\system32\iertutil.dll
2013-11-09 18:43 . 2013-11-09 18:43 247296 ----a-w- c:\windows\system32\webcheck.dll
2013-11-09 18:43 . 2013-11-09 18:43 235008 ----a-w- c:\windows\system32\url.dll
2013-11-09 18:43 . 2013-11-09 18:43 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-11-09 18:43 . 2013-11-09 18:43 226304 ----a-w- c:\windows\system32\elshyph.dll
2013-11-09 18:43 . 2013-11-09 18:43 2241024 ----a-w- c:\windows\system32\wininet.dll
2013-11-09 18:43 . 2013-11-09 18:43 216064 ----a-w- c:\windows\system32\msls31.dll
2013-11-09 18:43 . 2013-11-09 18:43 197120 ----a-w- c:\windows\system32\msrating.dll
2013-11-09 18:43 . 2013-11-09 18:43 19252224 ----a-w- c:\windows\system32\mshtml.dll
2013-11-09 18:43 . 2013-11-09 18:43 185344 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-11-09 18:43 . 2013-11-09 18:43 1767936 ----a-w- c:\windows\SysWow64\wininet.dll
2013-11-09 18:43 . 2013-11-09 18:43 173568 ----a-w- c:\windows\system32\ieUnatt.exe
2013-11-09 18:43 . 2013-11-09 18:43 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-11-09 18:43 . 2013-11-09 18:43 158720 ----a-w- c:\windows\SysWow64\msls31.dll
2013-11-09 18:43 . 2013-11-09 18:43 15404544 ----a-w- c:\windows\system32\ieframe.dll
2013-11-09 18:43 . 2013-11-09 18:43 1509376 ----a-w- c:\windows\system32\inetcpl.cpl
2013-11-09 18:43 . 2013-11-09 18:43 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-11-09 18:43 . 2013-11-09 18:43 149504 ----a-w- c:\windows\system32\occache.dll
2013-11-09 18:43 . 2013-11-09 18:43 144896 ----a-w- c:\windows\system32\wextract.exe
2013-11-09 18:43 . 2013-11-09 18:43 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-11-09 18:43 . 2013-11-09 18:43 1400416 ----a-w- c:\windows\system32\ieapfltr.dat
2013-11-09 18:43 . 2013-11-09 18:43 138752 ----a-w- c:\windows\SysWow64\wextract.exe
2013-11-09 18:43 . 2013-11-09 18:43 13824 ----a-w- c:\windows\system32\mshta.exe
2013-11-09 18:43 . 2013-11-09 18:43 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-11-09 18:43 . 2013-11-09 18:43 136704 ----a-w- c:\windows\system32\iesysprep.dll
2013-11-09 18:43 . 2013-11-09 18:43 1365504 ----a-w- c:\windows\system32\urlmon.dll
2013-11-09 18:43 . 2013-11-09 18:43 136192 ----a-w- c:\windows\system32\iepeers.dll
2013-11-09 18:43 . 2013-11-09 18:43 135680 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-11-09 18:43 . 2013-11-09 18:43 12800 ----a-w- c:\windows\SysWow64\mshta.exe
2013-11-09 18:43 . 2013-11-09 18:43 12800 ----a-w- c:\windows\system32\msfeedssync.exe
2013-11-09 18:43 . 2013-11-09 18:43 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-11-09 18:43 . 2013-11-09 18:43 109056 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-11-09 18:43 . 2013-11-09 18:43 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-11-09 18:43 . 2013-11-09 18:43 102912 ----a-w- c:\windows\system32\inseng.dll
2013-11-09 18:40 . 2013-11-09 18:40 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-11-09 18:40 . 2013-11-09 18:40 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-11-09 18:40 . 2013-11-09 18:40 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2013-11-09 18:40 . 2013-11-09 18:40 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2013-11-09 18:40 . 2013-11-09 18:40 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-11-09 18:40 . 2013-11-09 18:40 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-11-09 18:40 . 2013-11-09 18:40 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-11-09 18:40 . 2013-11-09 18:40 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-11-09 18:40 . 2013-11-09 18:40 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2013-11-09 18:40 . 2013-11-09 18:40 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2013-11-09 18:40 . 2013-11-09 18:40 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-11-09 18:40 . 2013-11-09 18:40 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-11-09 18:40 . 2013-11-09 18:40 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-11-09 18:40 . 2013-11-09 18:40 3928064 ----a-w- c:\windows\system32\d2d1.dll
2013-11-09 18:40 . 2013-11-09 18:40 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2013-11-09 18:40 . 2013-11-09 18:40 363008 ----a-w- c:\windows\system32\dxgi.dll
2013-11-09 18:40 . 2013-11-09 18:40 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-11-09 18:40 . 2013-11-09 18:40 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-11-09 18:40 . 2013-11-09 18:40 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2013-11-09 18:40 . 2013-11-09 18:40 333312 ----a-w- c:\windows\system32\d3d10_1core.dll
2013-11-09 18:40 . 2013-11-09 18:40 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-11-09 18:40 . 2013-11-09 18:40 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-11-09 18:40 . 2013-11-09 18:40 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-11-18 20587168]
"EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\x64\3\E_YATIIVE.EXE" [2012-02-27 283232]
"SteelSeries Engine"="e:\steelseries\SteelSeries Engine\SteelSeriesEngine.exe" [2013-11-05 242688]
"puush"="e:\puush\puush.exe" [2013-12-22 567880]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2013-08-30 766208]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-12-09 684600]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys;c:\windows\SYSNATIVE\DRIVERS\ggflt.sys [x]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys;c:\windows\SYSNATIVE\Drivers\ANDROIDUSB.sys [x]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys;c:\windows\SYSNATIVE\DRIVERS\htcnprot.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R4 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 AODDriver4.2;AODDriver4.2;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x]
S2 EPSON_PM_RPCV4_05;EPSON V3 Service4(05);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE [x]
S2 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\EscSvc64.exe;c:\windows\SYSNATIVE\EscSvc64.exe [x]
S2 HTCMonitorService;HTCMonitorService;e:\htc sync manager\HSMServiceEntry.exe;e:\htc sync manager\HSMServiceEntry.exe [x]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys;c:\windows\SYSNATIVE\drivers\npf.sys [x]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys;c:\windows\SYSNATIVE\DRIVERS\amdhub30.sys [x]
S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys;c:\windows\SYSNATIVE\DRIVERS\amdxhc.sys [x]
S3 busenum;SteelBusSvc;c:\windows\system32\DRIVERS\SteelBus64.sys;c:\windows\SYSNATIVE\DRIVERS\SteelBus64.sys [x]
S3 SAlphamHid;SteelHIDSvc;c:\windows\system32\DRIVERS\SAlpham64.sys;c:\windows\SYSNATIVE\DRIVERS\SAlpham64.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
S3 WSDScan;WSD-Scanunterstützung durch UMB;c:\windows\system32\drivers\WSDScan.sys;c:\windows\SYSNATIVE\drivers\WSDScan.sys [x]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-01-16 23:13 1211672 ----a-w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.76\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-10-19 14:56]
.
2014-01-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-10-19 14:56]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2013-10-18 13657304]
"MsmqIntCert"="mqrt.dll" [2010-11-21 247808]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.188.1
FF - ProfilePath - c:\users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default\
FF - ExtSQL: 2013-12-14 14:42; SQLiteManager@mrinalkant.blogspot.com; c:\users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default\extensions\SQLiteManager@mrinalkant.blogspot.com.xpi
FF - user.js: extensions.Softonic.tlbrSrchUrl - hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=526426fd000000000000dc9c52072e08&q=
FF - user.js: extensions.Softonic.id - 526426fd000000000000dc9c52072e08
FF - user.js: extensions.Softonic.appId - {7ABBFE1C-E485-44AA-8F36-353751B4124D}
FF - user.js: extensions.Softonic.instlDay - 16024
FF - user.js: extensions.Softonic.vrsn - 1.8.21.14
FF - user.js: extensions.Softonic.vrsni - 1.8.21.14
FF - user.js: extensions.Softonic.vrsnTs - 1.8.21.1419:20
FF - user.js: extensions.Softonic.prtnrId - softonic
FF - user.js: extensions.Softonic.prdct - Softonic
FF - user.js: extensions.Softonic.aflt - OC
FF - user.js: extensions.Softonic.smplGrp - none
FF - user.js: extensions.Softonic.tlbrId - opencandy2013
FF - user.js: extensions.Softonic.instlRef - MOY00621
FF - user.js: extensions.Softonic.dfltLng - de
FF - user.js: extensions.Softonic.excTlbr - false
FF - user.js: extensions.Softonic.ffxUnstlRst - false
FF - user.js: extensions.Softonic.admin - false
FF - user.js: extensions.Softonic.autoRvrt - false
FF - user.js: extensions.Softonic.rvrt - false
FF - user.js: extensions.Softonic.hmpg - true
FF - user.js: extensions.Softonic.hmpgUrl - hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=526426fd000000000000dc9c52072e08
FF - user.js: extensions.Softonic.dfltSrch - true
FF - user.js: extensions.Softonic.srchPrvdr - Search the web (Softonic)
FF - user.js: extensions.Softonic.dnsErr - true
FF - user.js: extensions.Softonic.newTab - true
FF - user.js: extensions.Softonic.newTabUrl - hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=526426fd000000000000dc9c52072e08
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-UpdaterEX - c:\users\Daniel\AppData\Roaming\UpdaterEX\UpdateProc\UpdateTask.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:09,cb,c2,5c,ae,1b,cf,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,dd,4c,37,e9,30,df,87,4e,b2,b7,13,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,dd,4c,37,e9,30,df,87,4e,b2,b7,13,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-01-28 17:12:39
ComboFix-quarantined-files.txt 2014-01-28 16:12
.
Vor Suchlauf: 11 Verzeichnis(se), 10.199.166.976 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 10.043.396.096 Bytes frei
.
- - End Of File - - D808E57512C96D139F6D8A964D2AE805
5FB38429D5D77768867C76DCBDB35194
MBar Log (28.01.2014 / 17:29): Code:
Malwarebytes Anti-Rootkit BETA 1.07.0.1009
www.malwarebytes.org
Database version: v2014.01.27.09
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16721
Dennis :: DANIEL-PC [administrator]
28.01.2014 17:16:12
mbar-log-2014-01-28 (17-16-12).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 263637
Time elapsed: 12 minute(s), 18 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end) |