Code:
ComboFix 13-08-12.01 - Schneball 12.08.2013 21:59:17.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3562.1805 [GMT 2:00]
ausgeführt von:: c:\users\Schneball\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\DealPly
c:\program files (x86)\DealPly\uninst.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-07-12 bis 2013-08-12 ))))))))))))))))))))))))))))))
.
.
2013-08-12 20:08 . 2013-08-12 20:08 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-12 20:06 . 2013-08-12 20:06 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3DB292C2-E4A8-4D7B-B596-254FDB72E6F4}\offreg.dll
2013-08-12 19:54 . 2013-08-12 19:54 -------- d-s---w- c:\windows\SysWow64\Microsoft
2013-08-12 19:36 . 2013-08-12 19:36 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-08-12 19:36 . 2013-08-12 19:36 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-08-12 18:43 . 2013-08-12 18:43 -------- d-----w- C:\FRST
2013-08-12 18:09 . 2013-08-12 18:09 -------- d-----w- c:\program files (x86)\Common Files\logishrd
2013-08-12 18:09 . 2013-08-12 18:09 -------- d-----w- c:\program files\Common Files\logishrd
2013-08-12 17:43 . 2013-08-12 17:43 -------- d-----w- C:\cabs
2013-08-12 17:43 . 2013-08-12 17:43 -------- d-----w- c:\users\Schneball\AppData\Local\DealPlyLive
2013-08-12 17:43 . 2013-08-12 17:43 -------- d-----w- c:\users\Schneball\AppData\Roaming\mysearchdial
2013-08-12 17:43 . 2013-08-12 17:56 -------- d-----w- c:\program files (x86)\MyPC Backup
2013-08-09 06:19 . 2013-07-15 01:34 9460976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3DB292C2-E4A8-4D7B-B596-254FDB72E6F4}\mpengine.dll
2013-08-04 09:50 . 2013-08-04 09:50 -------- d-----w- c:\users\Schneball\AppData\Roaming\simplitec
2013-08-04 09:47 . 2013-08-04 09:47 -------- d-----w- c:\users\Schneball\AppData\Roaming\MAGIX
2013-08-04 09:47 . 2013-08-04 09:47 -------- d-----w- c:\users\Schneball\AppData\Local\MAGIX
2013-08-04 09:47 . 2013-08-04 09:47 -------- d-----w- c:\program files (x86)\Common Files\MAGIX Services
2013-08-04 09:47 . 2013-08-04 09:47 -------- d-----w- c:\programdata\MAGIX
2013-08-04 09:47 . 2013-08-04 09:50 -------- d-----w- c:\programdata\simplitec
2013-07-24 05:09 . 2013-05-09 08:58 287840 ----a-w- c:\windows\system32\aswBoot.exe
2013-07-24 05:08 . 2013-07-24 05:08 -------- d-----w- c:\program files\AVAST Software
2013-07-24 05:07 . 2013-07-24 05:08 -------- d-----w- c:\programdata\AVAST Software
2013-07-22 14:53 . 2013-07-22 15:01 -------- d-----w- c:\windows\system32\MRT
2013-07-22 14:50 . 2013-07-22 14:50 -------- d-----w- c:\users\Schneball\AppData\Roaming\Malwarebytes
2013-07-22 14:50 . 2013-07-22 14:50 -------- d-----w- c:\programdata\Malwarebytes
2013-07-22 14:46 . 2013-07-22 14:46 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-07-22 14:46 . 2013-07-22 14:46 -------- d-----w- c:\program files (x86)\Java
2013-07-22 14:45 . 2013-07-22 14:45 -------- d-----w- c:\windows\IrfanView
2013-07-22 14:40 . 2013-07-22 14:40 -------- d-----w- c:\users\Schneball\AppData\Local\Secunia PSI
2013-07-22 14:40 . 2013-07-22 14:40 -------- d-----w- c:\program files (x86)\Secunia
2013-07-22 09:58 . 2013-07-22 09:58 -------- d-----w- c:\programdata\APN
2013-07-22 09:57 . 2013-07-23 14:54 -------- d-----w- c:\programdata\Avira
2013-07-22 06:19 . 2013-07-22 14:20 -------- d-----w- c:\windows\ERUNT
2013-07-20 05:40 . 2013-07-20 05:40 -------- d-----w- c:\program files\Enigma Software Group
2013-07-19 08:21 . 2013-07-19 10:19 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2013-07-17 16:11 . 2013-07-17 16:11 -------- d-----w- c:\windows\SysWow64\Extensions
2013-07-17 16:11 . 2013-07-17 16:11 -------- d-----w- c:\windows\SysWow64\searchplugins
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-22 14:46 . 2012-07-06 09:11 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-07-22 14:46 . 2011-08-01 10:25 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-07-03 08:32 . 2013-07-03 08:32 18456 ----a-w- c:\windows\system32\drivers\psi_mf_amd64.sys
2013-06-23 22:57 . 2011-12-29 14:41 78277128 ----a-w- c:\windows\system32\MRT.exe
2013-06-11 23:43 . 2013-07-13 04:49 1767936 ----a-w- c:\windows\SysWow64\wininet.dll
2013-06-11 23:43 . 2013-07-13 04:50 2877440 ----a-w- c:\windows\SysWow64\jscript9.dll
2013-06-11 23:42 . 2013-07-13 04:50 61440 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-06-11 23:42 . 2013-07-13 04:50 109056 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-06-11 23:26 . 2013-07-13 04:50 51712 ----a-w- c:\windows\system32\ie4uinit.exe
2013-06-11 23:26 . 2013-07-13 04:49 2241024 ----a-w- c:\windows\system32\wininet.dll
2013-06-11 23:26 . 2013-07-13 04:49 1365504 ----a-w- c:\windows\system32\urlmon.dll
2013-06-11 23:25 . 2013-07-13 04:49 19238912 ----a-w- c:\windows\system32\mshtml.dll
2013-06-11 23:25 . 2013-07-13 04:50 603136 ----a-w- c:\windows\system32\msfeeds.dll
2013-06-11 23:25 . 2013-07-13 04:50 855552 ----a-w- c:\windows\system32\jscript.dll
2013-06-11 23:25 . 2013-07-13 04:50 3958784 ----a-w- c:\windows\system32\jscript9.dll
2013-06-11 23:25 . 2013-07-13 04:49 53248 ----a-w- c:\windows\system32\jsproxy.dll
2013-06-11 23:25 . 2013-07-13 04:50 526336 ----a-w- c:\windows\system32\ieui.dll
2013-06-11 23:25 . 2013-07-13 04:50 67072 ----a-w- c:\windows\system32\iesetup.dll
2013-06-11 23:25 . 2013-07-13 04:50 39936 ----a-w- c:\windows\system32\iernonce.dll
2013-06-11 23:25 . 2013-07-13 04:50 136704 ----a-w- c:\windows\system32\iesysprep.dll
2013-06-11 23:25 . 2013-07-13 04:50 2648576 ----a-w- c:\windows\system32\iertutil.dll
2013-06-11 23:25 . 2013-07-13 04:49 15404032 ----a-w- c:\windows\system32\ieframe.dll
2013-06-11 22:51 . 2013-07-13 04:50 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-06-11 22:50 . 2013-07-13 04:50 89600 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-06-07 03:22 . 2013-07-13 04:50 2706432 ----a-w- c:\windows\system32\mshtml.tlb
2013-06-07 02:37 . 2013-07-13 04:50 2706432 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-06-05 03:34 . 2013-07-12 05:15 3153920 ----a-w- c:\windows\system32\win32k.sys
2013-06-04 06:00 . 2013-07-12 05:15 624128 ----a-w- c:\windows\system32\qedit.dll
2013-06-04 04:53 . 2013-07-12 05:15 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2013-05-16 12:32 . 2013-06-02 18:33 1277744 ------w- c:\windows\system32\dmwu.exe_old
2013-05-16 12:31 . 2013-06-02 18:33 35328 ------w- c:\windows\system32\ImHttpComm.dll_old
2013-05-16 12:02 . 2011-02-19 21:51 608080 ----a-w- c:\windows\system32\msvcp100.dll
2013-05-16 12:02 . 2011-02-18 23:52 829264 ----a-w- c:\windows\system32\msvcr100.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOPI.EXE"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2011-05-16 846936]
"NokiaSuite.exe"="c:\program files (x86)\Nokia\Nokia Suite\NokiaSuite.exe" [2012-12-21 1090040]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"NBAgent"="c:\program files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" [2011-06-29 1409424]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-04-20 336384]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2010-11-29 1294712]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"PDFPrint"="c:\program files (x86)\PDF24\pdf24.exe" [2012-12-12 163000]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-05-11 958576]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOPI.EXE"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2011-05-16 846936]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2013-7-3 563416]
Toshiba Places Icon Utility.lnk - c:\program files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe [2011-8-1 1492352]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
"EnableSecureUIAPath"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-02 07:45 1173456 ----a-w- c:\program files (x86)\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-08-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-12 19:36]
.
2013-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-01 11:10]
.
2013-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-01 11:10]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2011-02-10 1546720]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-01-12 11775592]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-01-10 2186856]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-12-08 710040]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"Toshiba Registration"="c:\program files\TOSHIBA\Registration\ToshibaReminder.exe" [2011-08-01 150992]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://start.mysearchdial.com/?f=1&a=dnldmsd&cd=2XzuyEtN2Y1L1QzuyByE0D0EtB0BzyyBtDyBtCtDyEyBzy0DtN0D0Tzu0CyDzytDtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr=783048151&ir=
mStart Page = hxxp://start.mysearchdial.com/?f=1&a=dnldmsd&cd=2XzuyEtN2Y1L1QzuyByE0D0EtB0BzyyBtDyBtCtDyEyBzy0DtN0D0Tzu0CyDzytDtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr=783048151&ir=
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: An OneNote s&enden - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000
IE: Zu TOSHIBA Bulletin Board hinzufügen - c:\program files\TOSHIBA\BulletinBoard\TosBBCom.dll/1000
TCP: DhcpNameServer = 192.168.178.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe
HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-HSON - c:\program files (x86)\TOSHIBA\TBS\HSON.exe
HKLM-Run-TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe
HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-08-12 22:13:26
ComboFix-quarantined-files.txt 2013-08-12 20:13
.
Vor Suchlauf: 10 Verzeichnis(se), 238.914.031.616 Bytes frei
Nach Suchlauf: 12 Verzeichnis(se), 238.297.276.416 Bytes frei
.
- - End Of File - - F3FCCE23AC5EE14E51EF4595C5CB56E5
A36C5E4F47E84449FF07ED3517B43A31 |