combofix hat trotz ausgeschaltetem antivir gemeckert, dass er angeschaltet ist und stört.
hier das log Code:
ComboFix 14-02-20.01 - Jana 21.02.2014 13:25:32.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3033.1366 [GMT 1:00]
ausgeführt von:: c:\users\Jana\Desktop\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_omfoidjpeklpjhlhabhcomekbkclkbec_0
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_omfoidjpeklpjhlhabhcomekbkclkbec_0\1
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_omfoidjpeklpjhlhabhcomekbkclkbec_0\2
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\background.html
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\chromeCoreFilesIndex.txt
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\crossriderManifest.json
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\manifest.xml
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins.json
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\1_base.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\102_dealply_m.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\103_intext_5_m.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\104_jollywallet_m.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\105_corticas_m.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\108_icm_m.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\119_similar_web_m.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\123_intext_adv_m.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\13_CrossriderAppUtils.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\14_CrossriderUtils.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\155_ibario_pops_m.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\158_50onred_ads_only_no_fb_m.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\17_jQuery.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\177_crossriderDashboard.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\178_revizer_ws_dynamic_m.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\179_revizer_p_dynamic_m.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\180_bpo_serp_m.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\182_openUrl.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\183_tabsWrapper.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\184_noproblemppc_m.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\19_CHAppAPIWrapper.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\191_ciuvo_m.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\194_retargeting_bi_m.js.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\195_icm_convertmedia_m.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\207_dbWrapper.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\208_gam_manager.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\21_debug.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\22_resources.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\28_initializer.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\4_jquery_1_7_1.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\47_resources_background.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\64_appApiMessage.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\7_hooks.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\72_appApiValidation.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\78_CrossriderInfo.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\80_CHPopupAppAPI.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\87_ginyas_wrapper.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\9_search_engine_hook.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\91_monetizationLoader.js.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\93_superfish_no_coupons_m.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\plugins\97_resourceApiWrapper.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\userCode\background.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\extensionData\userCode\extension.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\icons\actions\1.png
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\icons\icon128.png
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\icons\icon16.png
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\icons\icon48.png
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\api\chrome.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\api\cookie.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\api\message.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\api\monitor.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\api\pageAction.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\api\pageActionBG.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\background.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\lib\app_api.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\lib\bg_app_api.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\lib\consts.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\lib\cookie_store.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\lib\crossriderAPI.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\lib\delegate.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\lib\events.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\lib\extensionDataStore.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\lib\installer.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\lib\logFile.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\lib\logging.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\lib\onBGDocumentLoad.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\lib\popupResource\newPopup.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\lib\popupResource\popup.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\lib\reports.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\lib\storageWrapper.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\lib\updateManager.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\lib\util.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\lib\xhr.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\main.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\js\platformVersion.js
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\manifest.json
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.26.165_0\popup.html
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\omfoidjpeklpjhlhabhcomekbkclkbec\CURRENT
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\omfoidjpeklpjhlhabhcomekbkclkbec\LOG.old
c:\users\Jana\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\windows\IsUn0407.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-01-21 bis 2014-02-21 ))))))))))))))))))))))))))))))
.
.
2014-02-21 12:33 . 2014-02-21 12:33 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-02-21 01:35 . 2013-12-21 09:53 548864 ----a-w- c:\windows\system32\vbscript.dll
2014-02-21 01:35 . 2013-12-21 08:56 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2014-02-20 23:16 . 2014-02-20 23:18 -------- d-----w- C:\FRST
2014-02-20 19:57 . 2013-12-24 23:09 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2014-02-20 19:57 . 2013-12-24 22:48 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2014-02-20 19:57 . 2013-11-26 08:16 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2014-02-20 19:57 . 2013-11-22 22:48 3928064 ----a-w- c:\windows\system32\d2d1.dll
2014-02-20 19:42 . 2014-02-20 19:44 -------- d-----w- c:\program files (x86)\Re-markit
2014-01-25 16:06 . 2014-01-25 16:06 -------- d-----w- c:\program files (x86)\Uninstaller
2014-01-25 15:55 . 2014-02-20 23:36 -------- d-----w- c:\program files (x86)\MyPC Backup
2014-01-25 15:54 . 2014-01-25 15:55 -------- d-----w- c:\programdata\IePluginService
2014-01-25 15:54 . 2014-01-25 15:54 -------- d-----w- c:\program files (x86)\SupTab
2014-01-25 15:54 . 2014-01-25 15:54 -------- d-----w- c:\programdata\WPM
2014-01-25 15:54 . 2014-01-25 16:04 -------- d-----w- c:\users\Jana\AppData\Roaming\VOPackage
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-02-21 01:43 . 2013-07-18 18:43 88567024 ----a-w- c:\windows\system32\MRT.exe
2013-12-20 13:57 . 2013-05-07 12:10 84720 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-12-20 13:57 . 2013-04-03 12:54 131576 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-12-20 13:57 . 2013-04-03 12:54 108440 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-12-18 15:18 . 2013-12-18 15:18 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-12-18 15:18 . 2013-12-18 15:18 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-12-18 15:18 . 2013-12-18 15:18 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-12-18 15:18 . 2013-12-18 15:18 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2013-12-18 15:18 . 2013-12-18 15:18 235008 ----a-w- c:\windows\system32\elshyph.dll
2013-12-18 15:18 . 2013-12-18 15:18 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2013-12-18 15:18 . 2013-12-18 15:18 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-12-18 15:18 . 2013-12-18 15:18 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-12-18 15:18 . 2013-12-18 15:18 337408 ----a-w- c:\windows\SysWow64\html.iec
2013-12-18 15:18 . 2013-12-18 15:18 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-12-18 15:18 . 2013-12-18 15:18 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-12-18 15:18 . 2013-12-18 15:18 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-12-18 15:18 . 2013-12-18 15:18 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2013-12-18 15:18 . 2013-12-18 15:18 942592 ----a-w- c:\windows\system32\jsIntl.dll
2013-12-18 15:18 . 2013-12-18 15:18 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-12-18 15:18 . 2013-12-18 15:18 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-12-18 15:18 . 2013-12-18 15:18 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2013-12-18 15:18 . 2013-12-18 15:18 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-12-18 15:18 . 2013-12-18 15:18 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-12-18 15:18 . 2013-12-18 15:18 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2013-12-18 15:18 . 2013-12-18 15:18 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-12-18 15:18 . 2013-12-18 15:18 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-12-18 15:18 . 2013-12-18 15:18 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-12-18 15:18 . 2013-12-18 15:18 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-12-18 15:18 . 2013-12-18 15:18 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-12-18 15:18 . 2013-12-18 15:18 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-12-18 15:18 . 2013-12-18 15:18 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-12-18 15:18 . 2013-12-18 15:18 247808 ----a-w- c:\windows\system32\msls31.dll
2013-12-18 15:18 . 2013-12-18 15:18 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2013-12-18 15:18 . 2013-12-18 15:18 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-12-18 15:18 . 2013-12-18 15:18 105984 ----a-w- c:\windows\system32\iesysprep.dll
2013-12-18 15:18 . 2013-12-18 15:18 84992 ----a-w- c:\windows\system32\mshtmled.dll
2013-12-18 15:18 . 2013-12-18 15:18 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-12-18 15:18 . 2013-12-18 15:18 81408 ----a-w- c:\windows\system32\icardie.dll
2013-12-18 15:18 . 2013-12-18 15:18 774144 ----a-w- c:\windows\system32\jscript.dll
2013-12-18 15:18 . 2013-12-18 15:18 62464 ----a-w- c:\windows\system32\pngfilt.dll
2013-12-18 15:18 . 2013-12-18 15:18 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2013-12-18 15:18 . 2013-12-18 15:18 48128 ----a-w- c:\windows\system32\imgutil.dll
2013-12-18 15:18 . 2013-12-18 15:18 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2013-12-18 15:18 . 2013-12-18 15:18 413696 ----a-w- c:\windows\system32\html.iec
2013-12-18 15:18 . 2013-12-18 15:18 30208 ----a-w- c:\windows\system32\licmgr10.dll
2013-12-18 15:18 . 2013-12-18 15:18 296960 ----a-w- c:\windows\system32\dxtrans.dll
2013-12-18 15:18 . 2013-12-18 15:18 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2013-12-18 15:18 . 2013-12-18 15:18 243200 ----a-w- c:\windows\system32\webcheck.dll
2013-12-18 15:18 . 2013-12-18 15:18 235520 ----a-w- c:\windows\system32\url.dll
2013-12-18 15:18 . 2013-12-18 15:18 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-12-18 15:18 . 2013-12-18 15:18 147968 ----a-w- c:\windows\system32\occache.dll
2013-12-18 15:18 . 2013-12-18 15:18 143872 ----a-w- c:\windows\system32\wextract.exe
2013-12-18 15:18 . 2013-12-18 15:18 13824 ----a-w- c:\windows\system32\mshta.exe
2013-12-18 15:18 . 2013-12-18 15:18 135680 ----a-w- c:\windows\system32\iepeers.dll
2013-12-18 15:18 . 2013-12-18 15:18 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-12-18 15:18 . 2013-12-18 15:18 101376 ----a-w- c:\windows\system32\inseng.dll
2013-12-18 14:17 . 2013-12-18 14:17 49940480 ----a-w- c:\program files (x86)\GUT451B.tmp
2013-11-27 01:41 . 2014-01-14 23:53 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-11-27 01:41 . 2014-01-14 23:53 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-11-27 01:41 . 2014-01-14 23:53 53248 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-11-27 01:41 . 2014-01-14 23:53 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-11-27 01:41 . 2014-01-14 23:53 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-11-27 01:41 . 2014-01-14 23:53 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-11-27 01:41 . 2014-01-14 23:53 7808 ----a-w- c:\windows\system32\drivers\usbd.sys
2013-11-26 19:08 . 2013-04-03 12:54 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-11-26 11:40 . 2014-01-14 23:53 376768 ----a-w- c:\windows\system32\drivers\netio.sys
2013-11-26 10:32 . 2014-01-14 23:53 3156480 ----a-w- c:\windows\system32\win32k.sys
2013-11-23 18:26 . 2013-12-18 14:29 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-11-23 17:47 . 2013-12-18 14:29 465920 ----a-w- c:\windows\system32\WMPhoto.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{11111111-1111-1111-1111-110311341126}]
2013-07-18 09:27 752488 ----a-w- c:\program files (x86)\Plus-HD-2.3\Plus-HD-2.3-bho.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
2014-01-14 09:04 513136 ----a-w- c:\program files (x86)\SupTab\SupTab.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-08-06 21:03 220632 ----a-w- c:\users\Jana\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-08-06 21:03 220632 ----a-w- c:\users\Jana\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-08-06 21:03 220632 ----a-w- c:\users\Jana\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-02-20 689744]
"CanonQuickMenu"="c:\program files (x86)\Canon\Quick Menu\CNQMMAIN.EXE" [2012-09-27 1279120]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
TMMonitor.lnk - c:\program files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe [2013-2-20 258048]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R1 mdnocztl;mdnocztl;c:\windows\system32\drivers\mdnocztl.sys;c:\windows\SYSNATIVE\drivers\mdnocztl.sys [x]
R2 BackupStack;Computer Backup (MyPC Backup);c:\program files (x86)\MyPC Backup\BackupStack.exe;c:\program files (x86)\MyPC Backup\BackupStack.exe [x]
R2 IePluginService;IePlugin Service;c:\programdata\IePluginService\PluginService.exe;c:\programdata\IePluginService\PluginService.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 Wpm;Wpm Service;c:\programdata\WPM\wprotectmanager.exe;c:\programdata\WPM\wprotectmanager.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RTL2832U_IRHID;HID Infrared Remote Receiver;c:\windows\system32\DRIVERS\RTL2832U_IRHID.sys;c:\windows\SYSNATIVE\DRIVERS\RTL2832U_IRHID.sys [x]
R3 RTL2832UBDA;REALTEK 2832U BDA Driver;c:\windows\system32\drivers\RTL2832UBDA.sys;c:\windows\SYSNATIVE\drivers\RTL2832UBDA.sys [x]
R3 RTL2832UUSB;REALTEK 2832U USB Driver;c:\windows\system32\Drivers\RTL2832UUSB.sys;c:\windows\SYSNATIVE\Drivers\RTL2832UUSB.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WSDScan;WSD-Scanunterstützung durch UMB;c:\windows\system32\drivers\WSDScan.sys;c:\windows\SYSNATIVE\drivers\WSDScan.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
S2 Re-markit;Re-markit;c:\program files (x86)\Re-markit\Re-markit155.exe;c:\program files (x86)\Re-markit\Re-markit155.exe [x]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys;c:\windows\SYSNATIVE\DRIVERS\dc3d.sys [x]
S3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-02-21 01:25 1150280 ----a-w- c:\program files (x86)\Google\Chrome\Application\33.0.1750.117\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-09-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-11 15:29]
.
2014-02-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cefbfc5c0febb0.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-04-25 15:55]
.
2014-02-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-04-25 15:55]
.
2013-12-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-158286940-76762465-4253388147-1000Core1cefbfc5c124d10.job
- c:\users\Jana\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-19 18:24]
.
2014-02-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-158286940-76762465-4253388147-1000UA.job
- c:\users\Jana\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-19 18:24]
.
2014-02-21 c:\windows\Tasks\Plus-HD-2.3-chromeinstaller.job
- c:\program files (x86)\Plus-HD-2.3\Plus-HD-2.3-chromeinstaller.exe [2013-07-18 09:26]
.
2014-02-21 c:\windows\Tasks\Plus-HD-2.3-codedownloader.job
- c:\program files (x86)\Plus-HD-2.3\Plus-HD-2.3-codedownloader.exe [2013-07-18 09:27]
.
2014-02-21 c:\windows\Tasks\Plus-HD-2.3-enabler.job
- c:\program files (x86)\Plus-HD-2.3\Plus-HD-2.3-enabler.exe [2013-07-18 18:19]
.
2014-02-21 c:\windows\Tasks\Plus-HD-2.3-updater.job
- c:\program files (x86)\Plus-HD-2.3\Plus-HD-2.3-updater.exe [2013-07-18 09:27]
.
2014-02-21 c:\windows\Tasks\Re-markit Update.job
- c:\program files (x86)\Re-markit\ReMarkit_up.exe [2014-01-25 19:42]
.
2014-02-21 c:\windows\Tasks\Re-markit_wd.job
- c:\program files (x86)\Re-markit\Re-markit_wd.exe [2014-02-20 19:42]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-08-06 21:03 244696 ----a-w- c:\users\Jana\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-08-06 21:03 244696 ----a-w- c:\users\Jana\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-08-06 21:03 244696 ----a-w- c:\users\Jana\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-11 162328]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-11 386584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 417304]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.awesomehp.com/?type=hp&ts=1390665229&from=tugs&uid=WDCXWD5000BEVT-22ZAT0_WD-WX80AB94322743227
mDefault_Search_URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1390665229&from=tugs&uid=WDCXWD5000BEVT-22ZAT0_WD-WX80AB94322743227&q={searchTerms}
mDefault_Page_URL = hxxp://www.awesomehp.com/?type=hp&ts=1390665229&from=tugs&uid=WDCXWD5000BEVT-22ZAT0_WD-WX80AB94322743227
mStart Page = hxxp://www.awesomehp.com/?type=hp&ts=1390665229&from=tugs&uid=WDCXWD5000BEVT-22ZAT0_WD-WX80AB94322743227
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.awesomehp.com/web/?type=ds&ts=1390665229&from=tugs&uid=WDCXWD5000BEVT-22ZAT0_WD-WX80AB94322743227&q={searchTerms}
uInternet Settings,ProxyServer = http=127.0.0.1:13828
uSearchAssistant = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=fcd4b034-e89f-49be-b42f-ab644c7f0311&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=07/05/2013&type=hp1000
TCP: DhcpNameServer = 192.168.0.1 192.168.0.2
.
.
------- Dateityp-Verknüpfung -------
.
JSEFile=%SystemRoot%\SysWow64\CScript.exe "%1" %*
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKLM-Run-IR_SERVER - c:\progra~2\Realtek\REALTE~1\IR_SERVER.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-Adobe Photoshop 7.0 - c:\windows\ISUN0407.EXE
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-158286940-76762465-4253388147-1000\Software\SecuROM\License information*]
"datasecu"=hex:cb,6d,c5,d5,62,68,2c,77,80,f7,ad,47,e3,94,60,15,a6,16,07,39,2c,
1f,af,b7,f7,99,fc,66,a5,99,ec,c8,a0,a3,b1,4f,0b,df,a7,1a,2d,03,e5,eb,60,f7,\
"rkeysecu"=hex:6f,4c,0a,3c,16,26,46,67,34,31,3e,7a,4e,27,d0,a7
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-02-21 13:37:36
ComboFix-quarantined-files.txt 2014-02-21 12:37
.
Vor Suchlauf: 9 Verzeichnis(se), 262.356.877.312 Bytes frei
Nach Suchlauf: 12 Verzeichnis(se), 264.559.763.456 Bytes frei
.
- - End Of File - - CBB30FEB1257352F93E56BC9378EA55D
A36C5E4F47E84449FF07ED3517B43A31 |