Hallo,
bis hier schon mal vielen Dank!!! :dankeschoen: Dir auf jeden Fall einen schönen Feierabend.
Muss morgen arbeiten und kann erst am späten Nachmittag wieder an den Rechner. Melde mich!
So, der Scan und die Logdatei haben etwas gedauert. - ComboFix meldete nach dem Neustart des Rechners folgendes: "Bereite Logdatei vor. Starte keine anderen Programme, bevor ComobFix fertig ist." Aufgrund des Neustars sind allerdings einige Autostarts gelaufen (Thunderbird, ...).
Nachfolgend der Log: Code:
Combofix Logfile:
Code:
ComboFix 15-05-13.01 - Laptop 1 14.05.2015 20:28:03.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8124.4529 [GMT 2:00]
ausgeführt von:: c:\users\Laptop 1\Desktop\ComboFix.exe
AV: Avira Antivirus *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Antivirus *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
c:\users\Laptop 1\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\users\Laptop 1\AppData\Roaming\Microsoft\Windows\Recent\TNG Intranet Netz bs ssbolalik.url
c:\users\LAPTOP~1\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
c:\windows\IsUn0407.exe
c:\windows\msdownld.tmp
c:\windows\security\Database\tmp.edb
c:\windows\wininit.ini
.
.
((((((((((((((((((((((( Dateien erstellt von 2015-04-14 bis 2015-05-14 ))))))))))))))))))))))))))))))
.
.
2015-05-14 18:39 . 2015-05-14 18:39 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-05-14 12:50 . 2015-05-14 12:56 -------- d-----w- C:\FRST
2015-05-13 17:43 . 2015-05-01 13:17 124112 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 17:43 . 2015-05-01 13:16 102608 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 17:25 . 2015-05-13 17:25 328704 ----a-w- c:\windows\system32\services.exe
2015-05-13 17:24 . 2015-05-13 17:24 3204608 ----a-w- c:\windows\system32\win32k.sys
2015-05-13 17:16 . 2015-04-04 06:25 12032440 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B1E194A3-98BD-4BC5-8539-73EE362260CC}\mpengine.dll
2015-05-10 08:46 . 2015-05-10 08:46 -------- d-----w- c:\program files (x86)\Buhl finance
2015-05-01 18:10 . 2015-05-01 18:10 229608 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
2015-04-25 10:19 . 2015-04-25 10:19 82944 ----a-w- c:\windows\system32\dwmapi.dll
2015-04-25 10:19 . 2015-04-25 10:19 67584 ----a-w- c:\windows\SysWow64\dwmapi.dll
2015-04-25 10:19 . 2015-04-25 10:19 1632768 ----a-w- c:\windows\system32\dwmcore.dll
2015-04-25 10:19 . 2015-04-25 10:19 1372160 ----a-w- c:\windows\SysWow64\dwmcore.dll
2015-04-25 10:18 . 2015-04-25 10:18 2543104 ----a-w- c:\windows\system32\wpdshext.dll
2015-04-25 10:18 . 2015-04-25 10:18 2311168 ----a-w- c:\windows\SysWow64\wpdshext.dll
2015-04-25 10:18 . 2015-04-25 10:18 1195008 ----a-w- c:\windows\system32\drivers\UMDF\WpdMtpDr.dll
2015-04-15 06:34 . 2015-04-15 06:34 754688 ----a-w- c:\windows\system32\drivers\http.sys
2015-04-15 06:33 . 2015-04-15 06:33 79360 ----a-w- c:\windows\system32\clfsw32.dll
2015-04-15 06:33 . 2015-04-15 06:33 58880 ----a-w- c:\windows\SysWow64\clfsw32.dll
2015-04-15 06:33 . 2015-04-15 06:33 367552 ----a-w- c:\windows\system32\clfs.sys
2015-04-15 00:35 . 2015-04-15 00:35 18645184 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\MSO.DLL
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-05-14 09:02 . 2015-04-08 18:59 136408 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-05-13 17:47 . 2011-08-17 16:24 140425016 ----a-w- c:\windows\system32\MRT.exe
2015-05-13 17:25 . 2015-05-13 17:25 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2015-05-13 17:24 . 2015-05-13 17:24 470528 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2015-05-13 17:24 . 2015-05-13 17:24 309248 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2015-05-13 17:24 . 2015-05-13 17:24 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2015-05-13 17:24 . 2015-05-13 17:24 2178560 ----a-w- c:\windows\apppatch\AcGenral.dll
2015-05-13 17:24 . 2015-05-13 17:24 103424 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2015-05-13 17:19 . 2015-04-08 18:59 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2015-05-13 17:19 . 2015-04-08 18:59 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2015-05-13 17:19 . 2015-04-08 18:59 107736 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-05-07 18:19 . 2013-04-04 17:02 152744 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2015-05-07 18:19 . 2013-04-04 17:02 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2015-05-07 18:19 . 2013-04-04 17:02 132120 ----a-w- c:\windows\system32\drivers\avipbb.sys
2015-04-22 17:14 . 2011-08-17 16:09 295552 ------w- c:\windows\system32\MpSigStub.exe
2015-04-15 06:28 . 2012-04-21 10:06 778416 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2015-04-15 06:28 . 2011-08-18 10:44 142512 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-04-14 01:38 . 2015-04-14 01:38 1217192 ----a-w- c:\windows\SysWow64\FM20.DLL
2015-04-09 19:08 . 2015-04-09 19:08 977624 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2015-04-09 19:08 . 2015-04-09 19:08 73800 ----a-w- c:\windows\system32\RtNicProp64.dll
2015-04-09 19:08 . 2011-08-17 14:00 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2015-04-09 19:01 . 2015-04-09 19:01 1298136 ----a-w- c:\windows\system32\RTCOM64.dll
2015-04-09 19:01 . 2015-04-09 19:01 2808176 ----a-w- c:\windows\system32\RltkAPO64.dll
2015-04-09 19:01 . 2015-04-09 19:01 1708248 ----a-w- c:\windows\system32\RCoInstII64.dll
2015-04-09 19:01 . 2015-04-09 19:00 2902040 ----a-w- c:\windows\system32\FMAPO64.dll
2015-04-09 19:01 . 2015-04-09 19:01 4408792 ----a-w- c:\windows\system32\drivers\RTKVHD64.sys
2015-04-09 19:01 . 2015-04-09 19:01 2888920 ----a-w- c:\windows\system32\RtPgEx64.dll
2015-04-09 19:01 . 2015-04-09 19:01 2702040 ----a-w- c:\windows\system32\RTSnMg64.cpl
2015-04-09 19:01 . 2015-04-09 19:00 1945856 ----a-w- c:\windows\system32\MBAPO264.dll
2015-04-09 19:01 . 2015-04-09 19:00 1713920 ----a-w- c:\windows\SysWow64\MBAPO232.dll
2015-04-09 19:01 . 2015-04-09 19:01 72113152 ----a-w- c:\windows\system32\RCORES64.dat
2015-04-08 19:10 . 2015-04-08 19:10 957952 ----a-w- c:\windows\system32\appraiser.dll
2015-04-08 19:10 . 2015-04-08 19:10 769536 ----a-w- c:\windows\system32\invagent.dll
2015-04-08 19:10 . 2015-04-08 19:10 726528 ----a-w- c:\windows\system32\generaltel.dll
2015-04-08 19:10 . 2015-04-08 19:10 419840 ----a-w- c:\windows\system32\devinv.dll
2015-04-08 19:10 . 2015-04-08 19:10 30720 ----a-w- c:\windows\system32\acmigration.dll
2015-04-08 19:10 . 2015-04-08 19:10 192000 ----a-w- c:\windows\system32\aepic.dll
2015-04-08 19:10 . 2015-04-08 19:10 227328 ----a-w- c:\windows\system32\aepdu.dll
2015-04-08 19:10 . 2015-04-08 19:10 1111552 ----a-w- c:\windows\system32\aeinv.dll
2015-04-07 17:54 . 2013-05-07 16:59 44088 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2015-04-01 17:48 . 2011-11-10 15:57 41248 ----a-w- c:\windows\system32\cmdcsr.dll
2015-04-01 17:47 . 2014-05-15 16:03 358104 ----a-w- c:\windows\system32\cmdvrt64.dll
2015-04-01 17:46 . 2014-05-15 16:03 45784 ----a-w- c:\windows\system32\cmdkbd64.dll
2015-04-01 17:45 . 2014-05-15 16:03 288472 ----a-w- c:\windows\SysWow64\cmdvrt32.dll
2015-04-01 17:45 . 2014-05-15 16:03 40664 ----a-w- c:\windows\SysWow64\cmdkbd32.dll
2015-03-29 15:50 . 2015-03-29 15:50 622224 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2015-03-29 15:49 . 2011-08-19 17:34 935056 ----a-w- c:\windows\system32\nvvsvc.exe
2015-03-29 15:48 . 2015-03-29 15:47 970384 ----a-w- c:\windows\system32\NvIFR64.dll
2015-03-29 15:48 . 2015-03-29 15:47 944784 ----a-w- c:\windows\system32\NvFBC64.dll
2015-03-29 15:48 . 2015-03-29 15:47 930448 ----a-w- c:\windows\SysWow64\NvIFR.dll
2015-03-29 15:48 . 2015-03-29 15:47 3303448 ----a-w- c:\windows\system32\nvapi64.dll
2015-03-29 15:48 . 2015-03-29 15:47 2906928 ----a-w- c:\windows\SysWow64\nvapi.dll
2015-03-29 15:48 . 2015-03-29 15:47 25460880 ----a-w- c:\windows\system32\nvcompiler.dll
2015-03-29 15:48 . 2015-03-29 15:47 909512 ----a-w- c:\windows\SysWow64\NvFBC.dll
2015-03-29 15:48 . 2015-03-29 15:47 1896136 ----a-w- c:\windows\system32\nvdispco6434788.dll
2015-03-29 15:48 . 2015-03-29 15:47 18580512 ----a-w- c:\windows\system32\nvwgf2umx.dll
2015-03-29 15:48 . 2015-03-29 15:47 13297144 ----a-w- c:\windows\system32\nvopencl.dll
2015-03-29 15:48 . 2015-03-29 15:47 10775080 ----a-w- c:\windows\SysWow64\nvopencl.dll
2015-03-29 15:48 . 2015-03-29 15:47 10262160 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2015-03-29 15:48 . 2015-03-29 15:47 3611792 ----a-w- c:\windows\system32\nvcuvid.dll
2015-03-29 15:48 . 2015-03-29 15:47 3249352 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2015-03-29 15:48 . 2015-02-09 18:02 16022016 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2015-03-29 15:48 . 2015-03-29 15:47 32114888 ----a-w- c:\windows\system32\nvoglv64.dll
2015-03-29 15:48 . 2015-03-29 15:47 17258024 ----a-w- c:\windows\system32\nvd3dumx.dll
2015-03-29 15:48 . 2015-03-29 15:47 1557648 ----a-w- c:\windows\system32\nvdispgenco6434788.dll
2015-03-29 15:48 . 2015-03-29 15:47 24775368 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2015-03-29 15:48 . 2015-03-29 15:47 13210080 ----a-w- c:\windows\system32\nvcuda.dll
2015-03-29 15:48 . 2015-03-29 15:47 10715864 ----a-w- c:\windows\SysWow64\nvcuda.dll
2015-03-29 15:48 . 2015-03-29 15:47 20466376 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2015-03-29 15:48 . 2015-03-29 15:47 14121624 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2015-03-29 15:25 . 2015-03-29 15:25 1895240 ----a-w- c:\windows\system32\nvdispco6434752.dll
2015-03-29 15:25 . 2015-03-29 15:25 1557648 ----a-w- c:\windows\system32\nvdispgenco6434752.dll
2015-03-29 14:43 . 2015-03-29 14:42 11523584 ----a-w- c:\windows\system32\drivers\NETwsw01.sys
2015-03-29 13:29 . 2014-12-11 13:15 3218800 ----a-w- c:\windows\system32\RtkApi64.dll
2015-03-29 13:29 . 2014-12-11 13:15 631000 ----a-w- c:\windows\system32\RtDataProc64.dll
2015-03-27 19:46 . 2011-08-18 13:33 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2015-03-27 19:46 . 2011-08-18 13:33 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2015-03-24 16:39 . 2011-10-07 13:55 1236816 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2015-03-23 19:18 . 2012-01-30 16:05 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2015-03-23 19:18 . 2012-01-30 16:05 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2015-03-22 17:14 . 2014-03-05 04:37 19104256 ----a-w- c:\windows\SysWow64\FAHScreensaver.scr
2015-03-22 10:28 . 2015-03-22 10:28 92672 ----a-w- c:\windows\system32\CNQ9601I.DLL
2015-03-22 10:28 . 2015-03-22 10:28 495104 ----a-w- c:\windows\system32\CNQ9601L.DLL
2015-03-22 10:28 . 2015-03-22 10:28 235008 ----a-w- c:\windows\system32\CNQ9601O.DLL
2015-03-22 10:28 . 2015-03-22 10:28 17920 ----a-w- c:\windows\system32\CNHMCA6.DLL
2015-03-22 10:28 . 2015-03-22 10:28 1342976 ----a-w- c:\windows\system32\CNQ9601C.DLL
2015-03-22 10:28 . 2008-09-10 23:39 244736 ----a-w- c:\windows\system32\CNQ9601Y.DLL
2015-03-13 19:41 . 2014-10-20 20:43 1756424 ----a-w- c:\windows\system32\nvspbridge64.dll
2015-03-13 19:41 . 2014-10-20 20:43 1514528 ----a-w- c:\windows\system32\nvspcap64.dll
2015-03-13 19:41 . 2014-10-20 20:43 1316184 ----a-w- c:\windows\SysWow64\nvspbridge.dll
2015-03-13 19:41 . 2014-10-20 20:43 1278920 ----a-w- c:\windows\SysWow64\nvspcap.dll
2015-03-13 16:16 . 2011-08-19 17:34 6861968 ----a-w- c:\windows\system32\nvcpl.dll
2015-03-13 16:16 . 2011-08-19 17:34 3526856 ----a-w- c:\windows\system32\nvsvc64.dll
2015-03-13 16:16 . 2011-08-19 17:34 62608 ----a-w- c:\windows\system32\nvshext.dll
2015-03-13 16:16 . 2011-08-19 17:34 386248 ----a-w- c:\windows\system32\nvmctray.dll
2015-03-13 16:16 . 2011-08-19 17:34 2559808 ----a-w- c:\windows\system32\nvsvcr.dll
2015-03-11 13:10 . 2014-10-20 20:41 4246327 ----a-w- c:\windows\system32\nvcoproc.bin
2015-03-10 17:41 . 2015-03-10 17:41 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
2015-03-10 17:41 . 2015-03-10 17:41 46080 ----a-w- c:\windows\system32\atmlib.dll
2015-03-10 17:41 . 2015-03-10 17:41 41984 ----a-w- c:\windows\system32\lpk.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"BirdieSync"="c:\program files (x86)\BirdieSync\BirdieSync.exe" [2012-11-20 1118208]
"TrueCrypt"="c:\program files\TrueCrypt\TrueCrypt.exe" [2014-04-21 1516496]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2015-02-09 7404312]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-03 284696]
"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2011-04-13 503942]
"Desktop Disc Tool"="c:\program files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2009-12-15 498160]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2015-05-07 728312]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2014-10-02 421888]
"Avira Systray"="c:\program files (x86)\Avira\My Avira\Avira.OE.Systray.exe" [2015-04-09 129272]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-12-28 1022152]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Mozilla Thunderbird.lnk - c:\program files (x86)\Mozilla Thunderbird\thunderbird.exe [2015-4-3 389744]
Offene Vorgänge - Verknüpfung.lnk - c:\users\Laptop 1\Desktop\Offene Vorgänge [2011-11-14] [Folder]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@=""
.
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys;c:\windows\SYSNATIVE\drivers\SBREdrv.sys [x]
R2 AntiVirMailService;Avira Email-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avmailc7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avmailc7.exe [x]
R2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 cpudrv64;cpudrv64;c:\program files (x86)\SystemRequirementsLab\cpudrv64.sys;c:\program files (x86)\SystemRequirementsLab\cpudrv64.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 DisplayLinkUsbPort;DisplayLink USB Device;c:\windows\system32\DRIVERS\DisplayLinkUsbPort_5.6.31854.0.sys;c:\windows\SYSNATIVE\DRIVERS\DisplayLinkUsbPort_5.6.31854.0.sys [x]
R3 dlcdbus;DisplayLink Composite USB Bus Driver driver (WDM);c:\windows\system32\DRIVERS\dlcdbus.sys;c:\windows\SYSNATIVE\DRIVERS\dlcdbus.sys [x]
R3 ewsercd;Huawei DataCard USB Serial Port;c:\windows\system32\DRIVERS\ewsercd.sys;c:\windows\SYSNATIVE\DRIVERS\ewsercd.sys [x]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\SysWOW64\FsUsbExDisk.SYS;c:\windows\SysWOW64\FsUsbExDisk.SYS [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys;c:\windows\SYSNATIVE\DRIVERS\ggflt.sys [x]
R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys;c:\windows\SYSNATIVE\DRIVERS\ewusbfake.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
R3 LAN9500;LAN9500 USB 2.0 to Ethernet 10/100 Adapter Service;c:\windows\system32\DRIVERS\lan9500-x64-n620f.sys;c:\windows\SYSNATIVE\DRIVERS\lan9500-x64-n620f.sys [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 NETw5s64;Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows 7 64-Bit;c:\windows\system32\DRIVERS\NETw5s64.sys;c:\windows\SYSNATIVE\DRIVERS\NETw5s64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2014.SP3e\RpcAgentSrv.exe;c:\program files\SiSoftware\SiSoftware Sandra Lite 2014.SP3e\RpcAgentSrv.exe [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys;c:\windows\SYSNATIVE\drivers\gfibto.sys [x]
S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorA.sys [x]
S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorF.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S0 SamsungRapidDiskFltr;SAMSUNG RAPID Mode Disk Filter Driver;c:\windows\system32\DRIVERS\SamsungRapidDiskFltr.sys;c:\windows\SYSNATIVE\DRIVERS\SamsungRapidDiskFltr.sys [x]
S0 SamsungRapidFSFltr;SamsungRapidFSFltr;c:\windows\system32\DRIVERS\SamsungRapidFSFltr.sys;c:\windows\SYSNATIVE\DRIVERS\SamsungRapidFSFltr.sys [x]
S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys;c:\windows\SYSNATIVE\DRIVERS\stdcfltn.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [x]
S2 ALDITALKVerbindungsassistent_Service;ALDITALKVerbindungsassistent_Service;c:\program files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe;c:\program files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 Avira.OE.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [x]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 RtkAudioService;Realtek Audio Service;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe [x]
S2 SamsungRapidSvc;Samsung RAPID Mode Service;c:\windows\system32\RAPID\SamsungRapidSvc.exe;c:\windows\SYSNATIVE\RAPID\SamsungRapidSvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x]
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys;c:\windows\SYSNATIVE\DRIVERS\Accelern.sys [x]
S3 AVer7231_x64;AVerMedia 7231 capture service;c:\windows\system32\DRIVERS\AVer7231_x64.sys;c:\windows\SYSNATIVE\DRIVERS\AVer7231_x64.sys [x]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys;c:\windows\SYSNATIVE\DRIVERS\CtClsFlt.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys;c:\windows\SYSNATIVE\DRIVERS\qicflt.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys [x]
S3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
Inhalt des "geplante Tasks" Ordners
.
2015-05-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-21 06:28]
.
2015-05-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-18 17:30]
.
2015-05-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-18 17:30]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2015-04-09 8447192]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2015-04-09 1392496]
"FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-09-24 727664]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2015-03-29 2585744]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2015-03-13 1514528]
"SamsungRapidApp"="c:\program files (x86)\RAPID\CacheFilter\SamsungRapidApp.exe" [2015-02-09 281776]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: An OneNote s&enden - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: Free YouTube Download - c:\users\Laptop 1\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Laptop 1\AppData\Roaming\Mozilla\Firefox\Profiles\287muvzo.default-1362154688318\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxps://www.google.de/?gws_rd=ssl
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-MyFreeCodec - c:\program files (x86)\MyFree Codec\1.0b beta\uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_169_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_169_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_169_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_169_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_169.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.17"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_169.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_169.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_169.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\SysWOW64\bgsvcgen.exe
c:\program files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2015-05-14 20:58:35 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2015-05-14 18:58
.
Vor Suchlauf: 13 Verzeichnis(se), 307.375.828.992 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 307.364.892.672 Bytes frei
.
- - End Of File - - 71F2845673298FE304E20DFE76F6EADD --- --- --- |