Code:
ComboFix 13-08-31.01 - Nico 01.09.2013 2:45.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.8109.6157 [GMT 2:00]
ausgeführt von:: c:\users\Nico\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}
FW: Kaspersky Internet Security *Disabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}
SP: Kaspersky Internet Security *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\tmpCD7B.tmp
c:\windows\SysWow64\tmpD03A.tmp
.
Infizierte Kopie von c:\windows\SysWow64\mshtml.dll wurde gefunden und desinfiziert
Kopie von - c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.16635_none_9b672bc0c70576a6\mshtml.dll wurde wiederhergestellt
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-08-01 bis 2013-09-01 ))))))))))))))))))))))))))))))
.
.
2013-09-01 01:02 . 2013-09-01 01:02 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-31 19:26 . 2013-08-31 19:26 -------- d-----w- C:\FRST
2013-08-30 13:28 . 2013-08-30 13:28 -------- d-----w- c:\windows\system32\appmgmt
2013-08-30 11:54 . 2013-08-06 08:58 9515512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8CADA4E4-495D-4F0F-BFFE-E56005CD0750}\mpengine.dll
2013-08-27 21:09 . 2013-08-27 21:09 -------- d-----w- c:\program files\WinRAR
2013-08-25 22:55 . 2013-08-25 22:55 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2013-08-20 12:32 . 2013-08-20 12:32 -------- d-----w- c:\programdata\EA Core
2013-08-20 12:06 . 2013-08-20 12:02 447752 ----a-w- c:\windows\SysWow64\vp6vfw.dll
2013-08-18 23:16 . 2013-08-18 23:16 -------- d-----w- c:\program files\GIMP 2
2013-08-18 00:41 . 2013-08-18 00:41 -------- d-----w- c:\programdata\Rockstar Games
2013-08-18 00:41 . 2013-08-18 00:41 -------- d-----w- c:\program files (x86)\Rockstar Games
2013-08-17 19:45 . 2013-08-17 19:45 -------- d-----w- c:\program files (x86)\SquareEnix
2013-08-15 22:29 . 2013-08-15 22:29 -------- d-----w- c:\program files (x86)\VstPlugins
2013-08-15 22:29 . 2013-03-12 10:47 1431552 ----a-w- c:\windows\SysWow64\rewire.dll
2013-08-15 22:29 . 2013-08-15 22:29 -------- d-----w- c:\program files\Image-Line
2013-08-15 22:29 . 2009-09-15 09:14 1554944 ----a-w- c:\windows\SysWow64\vorbis.acm
2013-08-15 22:29 . 2013-08-15 22:29 -------- d-----w- c:\program files (x86)\DSPRobotics
2013-08-15 22:27 . 2013-08-15 22:29 -------- d-----w- c:\program files (x86)\Image-Line
2013-08-15 20:54 . 2013-08-15 20:54 -------- d-----w- c:\program files (x86)\Common Files\BattlEye
2013-08-15 20:51 . 2013-08-15 20:51 -------- d-----w- c:\programdata\Bohemia Interactive Studio
2013-08-15 01:01 . 2013-08-15 01:02 -------- d-----w- c:\windows\system32\MRT
2013-08-14 21:07 . 2013-07-09 05:52 224256 ----a-w- c:\windows\system32\wintrust.dll
2013-08-14 21:07 . 2013-07-09 05:46 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2013-08-14 21:07 . 2013-07-09 05:46 1472512 ----a-w- c:\windows\system32\crypt32.dll
2013-08-14 21:07 . 2013-07-09 05:46 139776 ----a-w- c:\windows\system32\cryptnet.dll
2013-08-14 21:07 . 2013-07-09 04:52 175104 ----a-w- c:\windows\SysWow64\wintrust.dll
2013-08-14 21:07 . 2013-07-09 04:46 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2013-08-14 21:07 . 2013-07-09 04:46 1166848 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-08-14 21:07 . 2013-07-09 04:46 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2013-08-14 20:46 . 2013-08-18 09:07 -------- d-----w- c:\program files (x86)\Origin Games
2013-08-14 20:34 . 2013-08-16 05:53 -------- d-----w- c:\programdata\Origin
2013-08-14 20:34 . 2013-08-14 20:34 -------- d-----w- c:\programdata\Electronic Arts
2013-08-14 20:34 . 2013-08-30 20:39 -------- d-----w- c:\program files (x86)\Origin
2013-08-13 21:39 . 2013-08-31 19:21 -------- d-----w- c:\program files (x86)\Battle.net
2013-08-12 15:33 . 2013-08-12 15:33 -------- d-----w- c:\program files\VideoLAN
2013-08-09 22:47 . 2013-08-09 23:39 -------- d-----w- c:\program files (x86)\Cube World
2013-08-09 22:47 . 2013-08-09 22:47 -------- d-----w- c:\programdata\Picroma
2013-08-09 04:24 . 2013-08-27 21:15 -------- d-----w- c:\program files (x86)\DevPro
2013-08-08 22:52 . 2013-08-08 22:52 -------- d-----w- c:\programdata\Sony
2013-08-08 22:52 . 2013-08-08 22:52 -------- d-----w- c:\program files\Sony
2013-08-08 22:52 . 2013-08-08 22:52 -------- d-----w- c:\program files (x86)\Sony
2013-08-07 00:23 . 2013-08-07 00:23 -------- d-----w- c:\windows\SysWow64\searchplugins
2013-08-07 00:23 . 2013-08-07 00:23 -------- d-----w- c:\windows\SysWow64\Extensions
2013-08-07 00:23 . 2013-08-07 00:23 -------- d-----w- c:\programdata\Babylon
2013-08-07 00:23 . 2013-08-27 13:46 -------- d-----w- c:\program files (x86)\Common Files\DVDVideoSoft
2013-08-07 00:23 . 2013-08-27 13:46 -------- d-----w- c:\program files (x86)\DVDVideoSoft
2013-08-05 22:08 . 2013-08-05 22:08 -------- d-----w- c:\program files (x86)\Microsoft XNA
2013-08-05 19:09 . 2013-08-05 19:09 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2013-08-05 16:08 . 2013-08-05 16:09 -------- d-----w- c:\programdata\Intenium
2013-08-05 16:07 . 2013-08-05 16:09 -------- d-----w- c:\program files (x86)\DEUTSCHLAND SPIELT
2013-08-05 16:07 . 2013-08-05 16:07 -------- d-----w- c:\program files (x86)\OXXOGames
2013-08-04 12:43 . 2013-08-04 12:46 -------- d-----w- c:\program files (x86)\puush
2013-08-04 10:04 . 2013-08-07 13:20 -------- d-----w- c:\program files\TeamSpeak 3 Client
2013-08-04 09:03 . 2008-07-31 08:41 238088 ----a-w- c:\windows\SysWow64\xactengine3_2.dll
2013-08-04 09:03 . 2008-07-31 08:41 177672 ----a-w- c:\windows\system32\xactengine3_2.dll
2013-08-04 09:03 . 2008-07-31 08:41 72200 ----a-w- c:\windows\system32\XAPOFX1_1.dll
2013-08-04 09:03 . 2008-07-31 08:40 513544 ----a-w- c:\windows\system32\XAudio2_2.dll
2013-08-04 09:03 . 2008-07-12 06:18 540688 ----a-w- c:\windows\system32\d3dx10_39.dll
2013-08-04 09:03 . 2008-07-12 06:18 1942552 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2013-08-04 09:03 . 2008-07-12 06:18 4992520 ----a-w- c:\windows\system32\D3DX9_39.dll
2013-08-04 07:49 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
2013-08-04 07:49 . 2013-04-02 22:51 1643520 ----a-w- c:\windows\system32\DWrite.dll
2013-08-04 07:36 . 2013-09-01 01:04 -------- d-----w- c:\programdata\Kaspersky Lab
2013-08-04 07:36 . 2013-08-04 07:36 -------- d-----w- c:\program files (x86)\Kaspersky Lab
2013-08-04 07:36 . 2013-08-04 08:05 637272 ----a-w- c:\windows\system32\drivers\klif.sys
2013-08-04 07:22 . 2013-08-04 07:22 -------- d-----w- c:\windows\SysWow64\wbem\en-US
2013-08-04 07:22 . 2013-08-04 07:22 -------- d-----w- c:\windows\system32\wbem\en-US
2013-08-04 06:44 . 2013-08-04 06:44 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-04 06:41 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2013-08-04 06:39 . 2006-02-03 06:43 3830992 ----a-w- c:\windows\system32\d3dx9_29.dll
2013-08-04 06:39 . 2005-12-05 16:09 3815120 ----a-w- c:\windows\system32\d3dx9_28.dll
2013-08-04 06:39 . 2005-07-22 17:59 3807440 ----a-w- c:\windows\system32\d3dx9_27.dll
2013-08-04 06:39 . 2005-05-26 13:34 3767504 ----a-w- c:\windows\system32\d3dx9_26.dll
2013-08-04 06:39 . 2005-05-26 13:34 2297552 ----a-w- c:\windows\SysWow64\d3dx9_26.dll
2013-08-04 06:39 . 2005-03-18 15:19 3823312 ----a-w- c:\windows\system32\d3dx9_25.dll
2013-08-04 06:39 . 2005-02-05 17:45 3544272 ----a-w- c:\windows\system32\d3dx9_24.dll
2013-08-04 06:38 . 2012-12-16 17:11 46080 ----a-w- c:\windows\system32\atmlib.dll
2013-08-04 06:38 . 2012-12-16 14:45 367616 ----a-w- c:\windows\system32\atmfd.dll
2013-08-04 06:38 . 2012-12-16 14:13 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2013-08-04 06:38 . 2012-12-16 14:13 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2013-08-04 06:38 . 2010-09-30 10:41 100864 ----a-w- c:\windows\system32\fontsub.dll
2013-08-04 06:38 . 2010-09-30 06:47 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
2013-08-04 06:37 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2013-08-04 06:37 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll
2013-08-04 06:37 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2013-08-04 06:37 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2013-08-04 06:37 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2013-08-04 06:37 . 2013-08-04 06:37 -------- d-----w- c:\program files (x86)\Dotjosh Studios
2013-08-04 06:33 . 2013-08-04 06:33 -------- d-----w- c:\program files (x86)\Microsoft.NET
2013-08-04 01:37 . 2010-12-23 10:42 1118720 ----a-w- c:\windows\system32\sbe.dll
2013-08-04 01:36 . 2011-05-24 11:42 404480 ----a-w- c:\windows\system32\umpnpmgr.dll
2013-08-03 21:17 . 2013-08-13 21:43 -------- d-----w- c:\program files (x86)\World of Warcraft Public Test
2013-08-03 20:08 . 2013-08-03 20:08 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-08-03 20:08 . 2013-08-03 20:08 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-08-03 20:08 . 2013-08-03 20:08 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-08-03 20:08 . 2013-08-03 20:08 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-08-03 20:08 . 2013-08-03 20:08 -------- d-----w- c:\program files (x86)\Java
2013-08-03 19:21 . 2013-08-03 18:32 -------- d-----w- c:\windows\Panther
2013-08-03 19:17 . 2013-08-11 12:49 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2013-08-03 19:17 . 2013-08-10 13:29 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird
2013-08-03 19:13 . 2008-07-31 08:41 68616 ----a-w- c:\windows\SysWow64\XAPOFX1_1.dll
2013-08-03 19:13 . 2008-07-31 08:40 509448 ----a-w- c:\windows\SysWow64\XAudio2_2.dll
2013-08-03 19:13 . 2008-07-12 06:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll
2013-08-03 19:13 . 2008-07-12 06:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2013-08-03 19:13 . 2008-07-12 06:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll
2013-08-03 19:13 . 2013-08-03 19:13 -------- d-sh--w- c:\windows\SysWow64\AI_RecycleBin
2013-08-03 19:13 . 2013-08-03 19:13 -------- d-----w- C:\Riot Games
2013-08-03 19:10 . 2013-08-03 19:10 -------- d-----w- c:\program files (x86)\Pando Networks
2013-08-03 19:10 . 2013-08-13 21:39 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment
2013-08-03 19:10 . 2013-08-04 12:49 -------- d-----w- c:\program files (x86)\World of Warcraft
2013-08-03 19:10 . 2013-08-03 19:10 -------- d-----w- c:\programdata\Blizzard Entertainment
2013-08-03 19:09 . 2013-08-03 19:10 -------- d-----w- c:\programdata\Battle.net
2013-08-03 19:09 . 2013-08-31 22:43 -------- d-----w- c:\program files (x86)\Steam
2013-08-03 19:09 . 2013-08-30 12:30 -------- d-----w- c:\program files (x86)\Common Files\Steam
2013-08-03 19:07 . 2013-08-30 13:38 -------- d-----w- c:\programdata\Skype
2013-08-03 19:02 . 2013-08-03 19:03 -------- d-----w- c:\program files (x86)\Google
2013-08-03 18:53 . 2013-08-03 18:53 -------- d-----w- c:\programdata\Creative
2013-08-03 18:52 . 2000-05-10 23:00 90112 ------w- c:\windows\Updreg.EXE
2013-08-03 18:52 . 2013-08-03 18:52 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2013-08-03 18:52 . 2013-08-03 18:52 445016 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2013-08-03 18:52 . 2013-08-03 18:52 123480 ----a-w- c:\windows\system32\OpenAL32.dll
2013-08-03 18:52 . 2013-08-03 18:52 109144 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2013-08-03 18:52 . 2012-01-13 09:23 1944064 ------w- c:\windows\system32\Sens_oal.dll
2013-08-03 18:52 . 2012-01-13 09:21 2906586 ------w- c:\windows\SysWow64\Sens_oal.dll
2013-08-03 18:49 . 2013-08-03 18:49 -------- d-----w- c:\program files (x86)\Common Files\Intel Corporation
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-09 04:45 . 2013-08-14 21:04 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-05-20 284440]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"Sound Blaster Z-Series Control Panel"="c:\program files (x86)\Creative\Sound Blaster Z-Series\Sound Blaster Z-Series Control Panel\SBZ.exe" [2012-10-01 724480]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [2013-08-04 206448]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-05-11 958576]
.
c:\users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
CurseClientStartup.ccip [2013-8-16 0]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux7"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x]
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [x]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys;c:\windows\SYSNATIVE\DRIVERS\kl2.sys [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
S2 CtHdaSvc;Sound Blaster Service;c:\windows\sysWow64\CtHdaSvc.exe;c:\windows\sysWow64\CtHdaSvc.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 cthda;Sound Blaster HDAudio;c:\windows\system32\drivers\cthda.sys;c:\windows\SYSNATIVE\drivers\cthda.sys [x]
S3 cthdb;SB Recon3D PCIe Audio Bus Filter;c:\windows\system32\DRIVERS\cthdb.sys;c:\windows\SYSNATIVE\DRIVERS\cthdb.sys [x]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-30 22:07 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.62\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-03 19:02]
.
2013-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-03 19:02]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-06-17 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-06-17 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-06-17 416024]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-06-07 11858536]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.bing.com
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.2.1 192.168.2.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-BattlEye for A2 - c:\program files (x86)\Steam\steamapps\common\Arma 2BattlEye\UnInstallBE.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1998980303-2150308348-719436732-1000\Software\SecuROM\License information*]
"datasecu"=hex:3a,cc,eb,a0,66,ff,cf,27,04,bb,5e,4d,b8,f2,61,66,41,75,9a,77,60,
2e,1c,e1,6b,79,a6,9b,8b,ec,e9,9a,dc,01,d1,c7,55,c1,63,1c,37,d9,b1,cd,d2,72,\
"rkeysecu"=hex:22,62,4c,be,4b,a8,71,aa,b3,29,06,e4,5b,6f,bb,69
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-09-01 03:08:18 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2013-09-01 01:08
.
Vor Suchlauf: 9 Verzeichnis(se), 685.264.850.944 Bytes frei
Nach Suchlauf: 12 Verzeichnis(se), 685.713.784.832 Bytes frei
.
- - End Of File - - 8AD8C49FF8520B70234165618A3C97EE |