| 
 Vielen Dank für Deine Hilfe. 
Hier die ComboFix log:    Code: 
 ComboFix 15-07-18.01 - Robert 19.07.2015  16:36:04.4.2 - x86Microsoft Windows XP Professional  5.1.2600.3.1252.49.1031.18.2046.1139 [GMT 2:00]
 ausgeführt von:: c:\dokumente und einstellungen\Robert\Desktop\ComboFix.exe
 AV: Avira Antivirus *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
 * Neuer Wiederherstellungspunkt wurde erstellt
 .
 .
 ((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
 .
 .
 c:\dokume~1\Robert\LOKALE~1\Temp\avgnt.exe\Avira.OE.ExtApi.dll
 c:\dokumente und einstellungen\Robert\Lokale Einstellungen\temp\avgnt.exe\Avira.OE.ExtApi.dll
 .
 .
 (((((((((((((((((((((((   Dateien erstellt von 2015-06-19 bis 2015-07-19  ))))))))))))))))))))))))))))))
 .
 .
 2015-07-14 19:23 . 2015-07-14 19:25        --------        d-----w-        C:\FRST
 .
 .
 .
 ((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
 .
 2015-07-14 19:04 . 2012-07-10 23:12        778416        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
 2015-07-14 19:04 . 2011-10-27 19:33        142512        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
 2015-06-10 10:31 . 2013-08-06 15:05        136728        ----a-w-        c:\windows\system32\drivers\avipbb.sys
 2015-06-10 10:31 . 2013-08-06 15:05        108448        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
 2015-05-31 12:33 . 2013-08-06 15:05        37896        ----a-w-        c:\windows\system32\drivers\avkmgr.sys
 2007-11-09 14:10 . 2015-07-16 18:14        30288        ----a-w-        c:\programme\mozilla firefox\plugins\cgpcfg.dll
 2007-11-09 14:10 . 2015-07-16 18:14        79440        ----a-w-        c:\programme\mozilla firefox\plugins\CgpCore.dll
 2007-11-09 14:10 . 2015-07-16 18:14        75344        ----a-w-        c:\programme\mozilla firefox\plugins\confmgr.dll
 2007-11-09 14:10 . 2015-07-16 18:14        140880        ----a-w-        c:\programme\mozilla firefox\plugins\ctxmui.dll
 2007-11-09 14:10 . 2015-07-16 18:14        42576        ----a-w-        c:\programme\mozilla firefox\plugins\icafile.dll
 2007-11-09 14:10 . 2015-07-16 18:14        50768        ----a-w-        c:\programme\mozilla firefox\plugins\icalogon.dll
 2007-11-09 14:10 . 2015-07-16 18:14        34384        ----a-w-        c:\programme\mozilla firefox\plugins\logging.dll
 2007-11-09 14:11 . 2015-07-16 18:14        685648        ----a-w-        c:\programme\mozilla firefox\plugins\sslsdk_b.dll
 2007-11-09 14:11 . 2015-07-16 18:14        30288        ----a-w-        c:\programme\mozilla firefox\plugins\TcpPServ.dll
 .
 .
 ((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
 .
 .
 *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
 REGEDIT4
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"]
 @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
 [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
 2015-02-11 01:12        152544        ----a-w-        c:\dokumente und einstellungen\Robert\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"]
 @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
 [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
 2015-02-11 01:12        152544        ----a-w-        c:\dokumente und einstellungen\Robert\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"]
 @="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
 [HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
 2015-02-11 01:12        152544        ----a-w-        c:\dokumente und einstellungen\Robert\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"]
 @="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
 [HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
 2015-02-11 01:12        152544        ----a-w-        c:\dokumente und einstellungen\Robert\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"]
 @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
 [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
 2015-02-11 01:12        152544        ----a-w-        c:\dokumente und einstellungen\Robert\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"]
 @="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
 [HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
 2015-02-11 01:12        152544        ----a-w-        c:\dokumente und einstellungen\Robert\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"]
 @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
 [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
 2015-02-11 01:12        152544        ----a-w-        c:\dokumente und einstellungen\Robert\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"]
 @="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
 [HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
 2015-02-11 01:12        152544        ----a-w-        c:\dokumente und einstellungen\Robert\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll
 .
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "swg"="c:\programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-13 68856]
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "SynTPEnh"="c:\programme\Synaptics\SynTP\SynTPEnh.exe" [2007-06-03 851968]
 "OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-05-09 36864]
 "SigmatelSysTrayApp"="stsystra.exe" [2007-06-06 405504]
 "KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
 "CoolSwitch"="c:\windows\system32\taskswitch.exe" [2002-03-19 45632]
 "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-11-29 55824]
 "NvMediaCenter"="NvMCTray.dll" [2011-01-07 111208]
 "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-01-07 13880424]
 "NVHotkey"="nvHotkey.dll" [2011-01-07 178792]
 "nwiz"="c:\programme\NVIDIA Corporation\nView\nwiz.exe" [2010-11-04 1753192]
 "ISUSPM Startup"="c:\progra~1\gemein~1\instal~1\update~1\isuspm.exe" [2006-10-03 221184]
 "avgnt"="c:\programme\Avira\AntiVir Desktop\avgnt.exe" [2015-06-10 730416]
 "QuickTime Task"="c:\programme\QuickTime\qttask.exe" [2010-11-29 421888]
 "Avira Systray"="c:\programme\Avira\Launcher\Avira.Systray.exe" [2015-06-02 134368]
 .
 [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
 "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
 .
 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
 Source= c:\dokumente und einstellungen\Robert\Eigene Dateien\Eigene Bilder\Wallpaper Chip\Reise\Shara Full HD Apple Summer Desktop.jpg
 FriendlyName=
 .
 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
 Source= c:\dokumente und einstellungen\Robert\Eigene Dateien\Eigene Bilder\Wallpaper Chip\wallpaper_abstrakt\original style hd wallpapers 3.jpg
 FriendlyName=
 .
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
 @="Driver"
 .
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
 @="Service"
 .
 [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^BTTray.lnk]
 path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\BTTray.lnk
 backup=c:\windows\pss\BTTray.lnkCommon Startup
 .
 [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Google Updater.lnk]
 path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Google Updater.lnk
 backup=c:\windows\pss\Google Updater.lnkCommon Startup
 .
 [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Logitech SetPoint.lnk]
 path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Logitech SetPoint.lnk
 backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
 .
 [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Microsoft Office.lnk]
 path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Microsoft Office.lnk
 backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
 .
 [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^VPN Client.lnk]
 path=c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\VPN Client.lnk
 backup=c:\windows\pss\VPN Client.lnkCommon Startup
 .
 [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^Robert^Startmenü^Programme^Autostart^Dropbox.lnk]
 path=c:\dokumente und einstellungen\Robert\Startmenü\Programme\Autostart\Dropbox.lnk
 backup=c:\windows\pss\Dropbox.lnkStartup
 .
 [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^Robert^Startmenü^Programme^Autostart^HcwSyncIt.lnk]
 path=c:\dokumente und einstellungen\Robert\Startmenü\Programme\Autostart\HcwSyncIt.lnk
 backup=c:\windows\pss\HcwSyncIt.lnkStartup
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
 c:\programme\Gemeinsame Dateien\Nokia\MPlatform\NokiaMServer [X]
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
 2013-05-11 10:37        958576        ----a-w-        c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
 c:\programme\Adobe\Reader 9.0\Reader\Reader_sl.exe [BU]
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
 2015-06-10 10:31        730416        ----a-w-        c:\programme\Avira\AntiVir Desktop\avgnt.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
 2004-12-02 17:23        102400        ------w-        c:\programme\Creative\MediaSource\Detector\CTDetect.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
 2008-04-14 02:22        15360        ----a-w-        c:\windows\system32\ctfmon.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
 2013-03-14 08:23        3672640        ----a-w-        c:\programme\DAEMON Tools Lite\DTLite.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
 2007-03-15 11:09        460784        ----a-w-        c:\programme\DellSupport\DSAgnt.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter]
 2009-05-21 08:55        206064        ----a-w-        c:\programme\Dell Support Center\bin\sprtcmd.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
 2007-11-15 08:24        16384        ----a-w-        c:\programme\Dell Support Center\gs_agent\custom\dsca.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FreePDF Assistant]
 2014-01-09 18:40        374784        ----a-w-        c:\programme\FreePDF_XP\fpassist.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
 2007-10-09 15:31        1862144        ----a-w-        c:\programme\Google\Google Desktop Search\GoogleDesktop.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
 2007-02-21 10:17        970752        ----a-w-        c:\programme\Intel\Wireless\Bin\iFrmewrk.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
 2007-02-21 10:19        819200        ----a-w-        c:\programme\Intel\Wireless\Bin\ZCfgSvc.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
 2006-10-03 10:35        221184        ----a-w-        c:\progra~1\GEMEIN~1\INSTAL~1\UPDATE~1\ISUSPM.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
 2006-10-03 10:37        81920        ----a-w-        c:\programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE2]
 2003-05-08 09:00        49152        ----a-w-        c:\programme\Scanner\ScanSoft\OmniPageSE2.0\opwareSE2.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
 2007-04-16 15:10        184320        ------w-        c:\programme\DELL\MediaDirect\PCMService.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
 2010-11-29 16:38        421888        ----a-w-        c:\programme\QuickTime\QTTask.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify]
 2015-04-15 11:41        7112248        ----a-w-        c:\dokumente und einstellungen\Robert\Anwendungsdaten\Spotify\Spotify.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify Web Helper]
 2015-04-15 11:42        2018360        ----a-w-        c:\dokumente und einstellungen\Robert\Anwendungsdaten\Spotify\SpotifyWebHelper.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
 2013-07-02 08:16        254336        ----a-w-        c:\programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
 2007-10-13 11:33        68856        ----a-w-        c:\programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zBrowser Launcher]
 2004-03-18 08:33        892928        ----a-w-        c:\programme\Logitech\iTouch\iTouch.exe
 .
 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
 "%windir%\\system32\\sessmgr.exe"=
 "c:\\Programme\\DELL\\MediaDirect\\PCMService.exe"=
 "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
 "c:\\Games\\Warcraft III\\Frozen Throne.exe"=
 "c:\\Games\\Warcraft III\\Warcraft III.exe"=
 "c:\\Programme\\Look@LAN\\LookAtLan.exe"=
 "c:\\Programme\\IVT Corporation\\BlueSoleil\\BlueSoleil_.exe"=
 "c:\\Games\\Counter-Strike 1.5\\cstrike.exe"=
 "c:\\Games\\UnrealTournament an robert\\System\\UnrealTournament.exe"=
 "c:\\Games\\Age of Empries 2\\age2_x1\\age2_x1.icd"=
 "c:\\Games\\Steam\\SteamApps\\[E-MAIL ADRESSE]\\counter-strike source\\hl2.exe"=
 "c:\\Games\\StarCraft II\\StarCraft II.exe"=
 "c:\\Programme\\Google\\Google Earth\\client\\googleearth.exe"=
 "c:\\Games\\Clonk Endeavour\\Clonk.exe"=
 "c:\\Dokumente und Einstellungen\\Robert\\Anwendungsdaten\\Spotify\\spotify.exe"=
 "c:\\Games\\Age of Empries 2\\age2_x1\\age2_x1.exe"=
 "c:\\Games\\Age of Empries 2\\age2_x1_1.0e_1920x1080.exe"=
 "c:\\Dokumente und Einstellungen\\All Users\\Anwendungsdaten\\Battle.net\\Agent\\Agent.1363\\Agent.exe"=
 "c:\\Games\\StarCraft II\\StarCraft II Public Test.exe"=
 "c:\\Programme\\Mozilla Firefox\\plugin-container.exe"=
 "c:\\Games\\BF2 Demo\\BF2.exe"=
 "c:\\Games\\Steam\\SteamApps\\common\\Counter-Strike Global Offensive\\csgo.exe"=
 "c:\\Programme\\Bonjour\\mDNSResponder.exe"=
 "c:\\Programme\\Airfoil\\Airfoil.exe"=
 "c:\\Programme\\Airfoil\\AirfoilSpeakers.exe"=
 "c:\\Programme\\TeamViewer\\Version4\\TeamViewer.exe"=
 "c:\\Dokumente und Einstellungen\\All Users\\Anwendungsdaten\\Battle.net\\Agent\\Agent.2380\\Agent.exe"=
 "c:\\Games\\StarCraft II\\Versions\\Base26490\\SC2.exe"=
 "c:\\Games\\Steam\\Steam.exe"=
 "c:\\Games\\Steam\\SteamApps\\common\\Half-Life\\hl.exe"=
 "c:\\Dokumente und Einstellungen\\Robert\\Anwendungsdaten\\Dropbox\\bin\\Dropbox.exe"=
 "c:\\Programme\\Skype\\Phone\\Skype.exe"=
 "c:\\WINDOWS\\system32\\muzapp.exe"=
 "c:\\Programme\\Mozilla Firefox\\firefox.exe"=
 .
 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
 "3587:TCP"= 3587:TCP:Windows Peer-zu-Peer-Gruppierung
 "3540:UDP"= 3540:UDP:Peer Name Resolution-Protokoll (PNRP)
 "6112:TCP"= 6112:TCP:WC3
 "6112:UDP"= 6112:UDP:Warcraft2
 "61313:TCP"= 61313:TCP:PC Remote Server XP
 .
 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
 "AllowInboundEchoRequest"= 1 (0x1)
 .
 R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [06.08.2013 17:05 37896]
 R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [18.09.2013 12:57 242240]
 R2 AntiVirSchedulerService;Avira Planer;c:\programme\Avira\AntiVir Desktop\sched.exe [06.08.2013 17:05 450808]
 R2 Avira.ServiceHost;Avira Service Host;c:\programme\Avira\Launcher\Avira.ServiceHost.exe [02.06.2015 17:14 217280]
 R2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [28.07.2010 22:22 20328]
 R2 HRService;Haufe iDesk-Service in c:\programme\Haufe\iDesk\iDeskService\Zope;c:\programme\Haufe\iDesk\iDeskService\ideskservice.exe [03.07.2013 20:02 12800]
 R2 Iprip;RIP-Überwachung;c:\windows\System32\svchost.exe -k netsvcs [13.08.2004 13:40 14336]
 R2 Skype C2C Service;Skype C2C Service;c:\dokumente und einstellungen\All Users\Anwendungsdaten\Skype\Toolbars\Skype C2C Service\c2c_service.exe [02.10.2012 13:13 3064000]
 R3 RRNetCapMP;RRNetCapMP;c:\windows\system32\drivers\rrnetcap.sys [11.06.2014 17:31 32936]
 S2 AntiVirMailService;Avira Email-Schutz;c:\programme\Avira\AntiVir Desktop\avmailc.exe [09.04.2015 22:15 825136]
 S2 AntiVirWebService;Avira Browser-Schutz;c:\programme\Avira\AntiVir Desktop\avwebgrd.exe [06.08.2013 17:05 1187336]
 S2 SkypeUpdate;Skype Updater;c:\programme\Skype\Updater\Updater.exe [03.04.2014 20:21 315008]
 S3 ALSysIO;ALSysIO;\??\c:\dokume~1\Robert\LOKALE~1\Temp\ALSysIO.sys --> c:\dokume~1\Robert\LOKALE~1\Temp\ALSysIO.sys [?]
 S3 filtertdidriver;filtertdidriver;c:\windows\system32\drivers\ewfiltertdidriver.sys --> c:\windows\system32\drivers\ewfiltertdidriver.sys [?]
 S3 GarenaPEngine;GarenaPEngine;\??\c:\dokume~1\Robert\LOKALE~1\Temp\FKX1D3.tmp --> c:\dokume~1\Robert\LOKALE~1\Temp\FKX1D3.tmp [?]
 S3 hcw17bda;Hauppauge SMS1000-based;c:\windows\system32\drivers\hcw17bda.sys [31.05.2010 22:24 51072]
 S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys --> c:\windows\system32\DRIVERS\ewusbdev.sys [?]
 S3 RRNetCap;RRNetCap Service;c:\windows\system32\drivers\rrnetcap.sys [11.06.2014 17:31 32936]
 S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [15.05.2008 16:03 717296]
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
 p2psvc        REG_MULTI_SZ           p2psvc p2pimsvc p2pgasvc PNRPSvc
 HPZ12        REG_MULTI_SZ           Pml Driver HPZ12 Net Driver HPZ12
 .
 Inhalt des "geplante Tasks" Ordners
 .
 2015-07-19 c:\windows\Tasks\Ende des Supports für Microsoft Windows XP –  Benachrichtigung – Anmeldung.job
 - c:\windows\system32\xp_eos.exe [2014-03-06 23:28]
 .
 2015-02-08 c:\windows\Tasks\Ende des Supports für Microsoft Windows XP – Monatliche Benachrichtigung.job
 - c:\windows\system32\xp_eos.exe [2014-03-06 23:28]
 .
 2015-07-14 c:\windows\Tasks\Google Software Updater.job
 - c:\programme\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-10-13 19:32]
 .
 2015-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
 - c:\programme\Google\Update\GoogleUpdate.exe [2009-11-07 00:00]
 .
 2015-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
 - c:\programme\Google\Update\GoogleUpdate.exe [2009-11-07 00:00]
 .
 .
 ------- Zusätzlicher Suchlauf -------
 .
 uStart Page = hxxp://www.google.de/
 mSearch Bar = hxxp://www.google.com/ie
 uInternet Connection Wizard,ShellNext = hxxp://www.google.de/ig/dell?hl=de&client=dell-row&channel=de&ibd=1071009
 uInternet Settings,ProxyOverride = *.local
 uSearchAssistant = hxxp://www.google.com/ie
 uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
 IE: Free YouTube Download - c:\dokumente und einstellungen\Robert\Anwendungsdaten\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
 IE: Senden an &Bluetooth-Gerät... - c:\programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
 LSP: c:\programme\Avira\AntiVir Desktop\avsda.dll
 FF - ProfilePath - c:\dokumente und einstellungen\Robert\Anwendungsdaten\Mozilla\Firefox\Profiles\88xg4le6.default\
 FF - prefs.js: browser.search.defaulturl -
 FF - prefs.js: browser.search.selectedEngine -
 FF - prefs.js: browser.startup.homepage - www.google.de
 FF - ExtSQL: !HIDDEN! 2009-09-02 08:20; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
 FF - user.js: network.cookie.cookieBehavior - 0
 FF - user.js: privacy.clearOnShutdown.cookies - false
 FF - user.js: security.warn_viewing_mixed - false
 FF - user.js: security.warn_viewing_mixed.show_once - false
 FF - user.js: security.warn_submit_insecure - false
 FF - user.js: security.warn_submit_insecure.show_once - false
 .
 - - - - Entfernte verwaiste Registrierungseinträge - - - -
 .
 MSConfigStartUp-ApnTBMon - c:\programme\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
 MSConfigStartUp-Avira Systray - c:\programme\Avira\My Avira\Avira.OE.Systray.exe
 MSConfigStartUp-HW_OPENEYE_OUC_T-Mobile Internet Manager - c:\programme\T-Mobile\T-Mobile Internet Manager\UpdateDog\ouc.exe
 MSConfigStartUp-KiesAirMessage - c:\programme\Samsung\Kies\KiesAirMessage.exe
 MSConfigStartUp-KiesPreload - c:\programme\Samsung\Kies\Kies.exe
 MSConfigStartUp-KiesTrayAgent - c:\programme\Samsung\Kies\KiesTrayAgent.exe
 MSConfigStartUp-Zune Launcher - c:\programme\Zune\ZuneLauncher.exe
 AddRemove-Redirection Port Monitor - c:\windows\system32\unredmon.exe
 AddRemove-Soft-Central SC-PassUnleash - c:\programme\Soft-Central\SC-PassUnleash\Uninstall
 AddRemove-_is1 - c:\programme\Gemeinsame Dateien\DVDVideoSoft\lib\Uninstall.exe
 .
 .
 .
 **************************************************************************
 .
 catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
 Rootkit scan 2015-07-19 16:52
 Windows 5.1.2600 Service Pack 3 NTFS
 .
 Scanne versteckte Prozesse...
 .
 Scanne versteckte Autostarteinträge...
 .
 Scanne versteckte Dateien...
 .
 .
 c:\windows\TEMP\00000000-43B150C2 9478136 bytes
 c:\windows\TEMP\00000000-442C8E8A 6163104 bytes executable
 .
 Scan erfolgreich abgeschlossen
 versteckte Dateien: 2
 .
 **************************************************************************
 .
 [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
 "ImagePath"="\??\c:\dokume~1\Robert\LOKALE~1\Temp\FKX1D3.tmp"
 .
 --------------------- Gesperrte Registrierungsschluessel ---------------------
 .
 [HKEY_USERS\S-1-5-21-3038138035-1488556073-2664149668-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Electronic Arts\C*o*m*m*a*n*d* *&* *C*o*n*q*u*e*r* *3* *T*i*b*e*r*i*u*m* *W*a*r*s*"!\Kundendienst]
 "Order"=hex:08,00,00,00,02,00,00,00,b8,02,00,00,01,00,00,00,04,00,00,00,de,00,
 00,00,00,00,00,00,d0,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,be,00,32,\
 .
 [HKEY_USERS\S-1-5-21-3038138035-1488556073-2664149668-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
 "??"=hex:00,49,54,bf,94,e0,91,e7,cb,ee,46,13,c7,4e,65,af,20,da,4a,01,1d,4b,f9,
 ff,32,66,be,3f,a0,43,91,08,67,13,11,4b,25,3d,04,dc,24,7b,0d,fe,f0,f9,8d,06,\
 "??"=hex:f2,f0,1a,9c,c1,46,0d,27,38,d5,c0,2a,1f,97,57,07
 .
 [HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
 "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
 00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
 .
 [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
 "OOSAFEERASE02.00.00.01MSWINDOWS"="58BDEFC58806C68760D54CAA33AC54EDD02FFE8BFA92FEBB61F223DB4457651B73DC6954E5E11D6C1C9BF96474ED138B3E81E0DA24DD89F638078B72C1EA14B29998D7A2AB153A0BF0B9B245EF75159CA670C70B624C0934E30EBF3F5AF28C7991B68BDEEB0DFC6E6149C678C0948736E30C2664F8341D36B92C71489A6AFC014B1098EC1A87441512FACCDD66719BE3F5F630650E3F69B4B1981849742199CDD59257E4911975EFCE0F1C0C418187A47EE8623E2EE912DCE5A2EFAD3BB71B5866BE63128DA9F865055DD24A1A15846C452C79D6C786C34E9827F61CA827BB0E56A91EF332743C4F45CED194994B50A135A0F7C62FFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933BA7FD869164D67945D575E7D6A3B9808FEBC9E127BECC74CF87A9C16CA4B2A86F0B1A4438BF13253523E4E3353276FE316AEF92A32201C9194C86E068088149A89F125D40E73120371A56B03A45AA6852EF7C81754AE999A82B143751AEF8606D5F1E2C04BE2D37BD168944457CCF8534B9AD5EBD83E0EC6F439ACCE78FA34CAEB067C4B18DA4C6B91CE97B156D774C0AFEE387EE18EE274F46832A013E587CF3C8904DBE13A7FDEA1A2352DA51BDCA772507EC6241DB864DDCCCB1C72339ADE0458027C2621A54C48B220B7D5FAA7C2FC1EAAE2682FE33C5FF4681937A6BFA65A55705B7AF72E891ED100FB929D7F34903C2F928DCCEA06FD77EA8E914BF9B926653E4D84E73A51125671C3156EC37FBD91F6BB83C0892D116C281D48EC838FA6F24E487F5E1FC4E59B05802F9C060DEC0A5FE6CF1E2E8443F06A84B59CC7006AEBF8E6BB8D6666AF7E3EC4441C8C29D69637C08CB57EC295A4EF2C4930E74C57C009679BECCC1E57E394C94E2252848C2A451AE523D0FDDB2CEA9D044038142668BB2E17B5C5369DB0746AD72B86336FBA42681DBF30373D3101057D2A41DF63DA46C13866F3DE12D0BEA681F50B2EB7C6DBC309AC5DCCB660CC37DD8EBE986F174E4DA041B3AB1B324723808677516E4C31E9914ECB0616E85BA865D3230E801EEE9E014B919472C7D4A79CA293DCF1CED83BB3CC210C00012FF264A211F19D76382921504FF22688A49F3156E076F7575C3C0293BAEBEC603E54436761DAA4A82C04DD5E6107176EE51BB0711125846F371820D3A796A844F2AEFA5421C24643C26AA54671F5FB77BDCD9C850A55F3A85B98C9012C6152ED2B081ADD918706D7E43A7A1EDEC4DE29C2108FE966D874952D3049D33E075D20390B433DA56D3F7B74F675C239E09C86025EB43B7462874E867402488AA59224E104AC6F871A1CC843C7414EC697E79DFBD6CBD7378B86EDB31CE89D6F3B0DC760659F3612179EDB17F71DA6819E457A24BE2BE165D01B16F5"
 .
 --------------------- Durch laufende Prozesse gestartete DLLs ---------------------
 .
 - - - - - - - > 'lsass.exe'(244)
 c:\programme\Avira\AntiVir Desktop\avsda.dll
 .
 - - - - - - - > 'explorer.exe'(2232)
 c:\dokumente und einstellungen\Robert\Anwendungsdaten\Dropbox\bin\DropboxExt.25.dll
 c:\windows\system32\webcheck.dll
 c:\programme\Avira\AntiVir Desktop\avsda.dll
 c:\windows\system32\WPDShServiceObj.dll
 c:\windows\system32\btncopy.dll
 c:\windows\system32\PortableDeviceTypes.dll
 c:\windows\system32\PortableDeviceApi.dll
 .
 ------------------------ Weitere laufende Prozesse ------------------------
 .
 c:\programme\Avira\AntiVir Desktop\avguard.exe
 c:\programme\Avira\AntiVir Desktop\avshadow.exe
 c:\windows\system32\nvsvc32.exe
 c:\programme\Intel\Wireless\Bin\EvtEng.exe
 c:\programme\Intel\Wireless\Bin\S24EvMon.exe
 c:\programme\Intel\Wireless\Bin\WLKeeper.exe
 c:\windows\System32\SCardSvr.exe
 c:\programme\Bonjour\mDNSResponder.exe
 c:\programme\WIDCOMM\Bluetooth Software\bin\btwdins.exe
 c:\windows\system32\CTsvcCDA.EXE
 c:\programme\VPN Client\cvpnd.exe
 c:\programme\Java\jre7\bin\jqs.exe
 c:\programme\Haufe\iDesk\iDeskService\ideskpython.exe
 c:\programme\Intel\Wireless\Bin\RegSrvc.exe
 c:\windows\system32\tcpsvcs.exe
 c:\programme\Dell Support Center\bin\sprtsvc.exe
 c:\windows\system32\wbem\wmiapsrv.exe
 c:\windows\stsystra.exe
 c:\windows\system32\RunDLL32.exe
 c:\windows\system32\rundll32.exe
 c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
 .
 **************************************************************************
 .
 Zeit der Fertigstellung: 2015-07-19  16:59:24 - PC wurde neu gestartet
 ComboFix-quarantined-files.txt  2015-07-19 14:59
 ComboFix2.txt  2012-07-05 21:05
 ComboFix3.txt  2011-02-06 17:54
 .
 Vor Suchlauf: 3.273.125.888 Bytes frei
 Nach Suchlauf: 3.879.579.648 Bytes frei
 .
 - - End Of File - - C94791034278320924B9C0BCAB5F29C2
 5CB90281D1A59B251F6603134774EEC3
 |