| Tobias Ruder |  01.09.2013 12:53 |         Code:  
 ComboFix 13-08-31.01 - Tobias Ruder 01.09.2013  13:44:58.1.2 - x64 
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.3765.2076 [GMT 2:00] 
ausgeführt von:: c:\users\Tobias Ruder\Desktop\ComboFix.exe 
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} 
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} 
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} 
 * Neuer Wiederherstellungspunkt wurde erstellt 
. 
. 
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   )))))))))))))))))))))))))))))))))))))))))))))))) 
. 
. 
c:\program files (x86)\PricePeep 
c:\program files (x86)\PricePeep\installer.ico 
c:\program files (x86)\PricePeep\prICepeep.dll 
c:\program files (x86)\PricePeep\uninstall.exe 
c:\program files (x86)\PricePeep\unutil.exe 
c:\programdata\Roaming 
c:\users\Public\AlexaNSISPlugin.1192.dll 
c:\windows\SysWow64\System32\MASetupCleaner.exe 
c:\windows\SysWow64\System32\muzapp.exe 
. 
. 
(((((((((((((((((((((((   Dateien erstellt von 2013-08-01 bis 2013-09-01  )))))))))))))))))))))))))))))) 
. 
. 
2013-09-01 11:49 . 2013-09-01 11:49        --------        d-----w-        c:\users\Default\AppData\Local\temp 
2013-09-01 07:11 . 2013-09-01 07:11        --------        d-----w-        C:\FRST 
2013-08-31 15:37 . 2013-08-31 15:37        83672        ----a-w-        c:\windows\system32\drivers\avnetflt.sys 
2013-08-31 15:37 . 2013-08-31 15:37        --------        d-----w-        c:\users\Tobias Ruder\AppData\Roaming\Avira 
2013-08-31 15:36 . 2013-08-31 15:34        28600        ----a-w-        c:\windows\system32\drivers\avkmgr.sys 
2013-08-31 15:36 . 2013-08-31 15:34        130016        ----a-w-        c:\windows\system32\drivers\avipbb.sys 
2013-08-31 15:36 . 2013-08-31 15:34        100712        ----a-w-        c:\windows\system32\drivers\avgntflt.sys 
2013-08-31 15:36 . 2013-08-31 15:36        --------        d-----w-        c:\programdata\Avira 
2013-08-31 15:36 . 2013-08-31 15:36        --------        d-----w-        c:\program files (x86)\Avira 
2013-08-31 15:29 . 2013-08-06 08:58        9515512        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{9262BE9C-33A0-4F08-96AC-03B5A23F6C3E}\mpengine.dll 
2013-08-29 13:27 . 2013-08-29 13:27        --------        d-----w-        c:\users\Tobias Ruder\AppData\Roaming\WordToPDF 
2013-08-29 13:18 . 2010-06-17 19:56        87040        ----a-w-        c:\windows\system32\redmonnt.dll 
2013-08-29 13:18 . 2010-06-17 19:56        46080        ----a-w-        c:\windows\system32\unredmon.exe 
2013-08-29 13:18 . 2013-08-29 13:19        --------        d-----w-        c:\users\Tobias Ruder\AppData\Roaming\FreePDF 
2013-08-29 13:18 . 2013-08-29 13:19        --------        d-----w-        c:\program files (x86)\FreePDF_XP 
2013-08-23 09:57 . 2013-08-23 09:57        --------        d-----r-        C:\MSOCache 
2013-08-16 14:29 . 2013-08-18 07:07        --------        d-----w-        c:\program files (x86)\Mozilla Maintenance Service 
2013-08-16 13:34 . 2013-08-16 13:34        --------        d-----w-        c:\users\Tobias Ruder\AppData\Local\Freemium 
2013-08-16 13:33 . 2013-06-27 05:14        31816        ----a-w-        c:\windows\Launcher.exe 
2013-08-16 13:31 . 2013-08-16 13:32        --------        d-----w-        c:\program files (x86)\SoftwareUpdater 
2013-08-16 13:31 . 2013-08-16 13:31        --------        d-----w-        c:\programdata\FreeSystemUtilities 
2013-08-16 13:31 . 2013-08-16 13:31        --------        d-----w-        c:\program files (x86)\Covus Freemium 
2013-08-16 13:31 . 2013-08-16 13:31        --------        d-----w-        c:\programdata\Package Cache 
2013-08-16 13:30 . 2013-08-16 13:31        --------        d-----w-        c:\users\Tobias Ruder\AppData\Local\DownloadGuide 
2013-08-15 12:57 . 2013-08-16 14:19        1688        ----a-w-        c:\windows\system32\ASOROSet.bin 
2013-08-14 13:06 . 2013-07-09 05:46        1472512        ----a-w-        c:\windows\system32\crypt32.dll 
2013-08-14 13:05 . 2013-07-09 05:03        3913664        ----a-w-        c:\windows\SysWow64\ntoskrnl.exe 
2013-08-13 21:46 . 2013-08-13 21:46        --------        d-----w-        c:\users\Tobias Ruder\AppData\Roaming\Fighters 
2013-08-13 21:46 . 2013-08-13 21:46        --------        d-----w-        c:\programdata\Fighters 
2013-08-13 21:46 . 2013-08-13 21:46        --------        d-----w-        c:\program files\Fighters 
2013-08-13 08:18 . 2013-08-13 08:18        --------        d-----w-        c:\program files (x86)\Google Books Downloader 
2013-08-13 07:32 . 2013-08-15 10:24        --------        d-----w-        c:\windows\system32\MRT 
. 
. 
. 
((((((((((((((((((((((((((((((((((((   Find3M Bericht   )))))))))))))))))))))))))))))))))))))))))))))))))))))) 
. 
2013-08-21 14:59 . 2012-04-19 15:57        692104        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe 
2013-08-21 14:59 . 2011-07-27 03:05        71048        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl 
2013-08-05 14:14 . 2011-10-28 06:56        78161360        ----a-w-        c:\windows\system32\MRT.exe 
2013-07-09 04:45 . 2013-08-14 13:05        44032        ----a-w-        c:\windows\apppatch\acwow64.dll 
2013-06-24 19:10 . 2013-06-24 19:10        96168        ----a-w-        c:\windows\SysWow64\WindowsAccessBridge-32.dll 
2013-06-24 19:10 . 2012-07-21 19:32        867240        ----a-w-        c:\windows\SysWow64\npdeployJava1.dll 
2013-06-24 19:10 . 2011-10-25 15:31        789416        ----a-w-        c:\windows\SysWow64\deployJava1.dll 
2013-06-24 04:46 . 2013-06-24 04:46        226304        ----a-w-        c:\windows\system32\elshyph.dll 
2013-06-24 04:46 . 2013-06-24 04:46        185344        ----a-w-        c:\windows\SysWow64\elshyph.dll 
2013-06-24 04:46 . 2013-06-24 04:46        158720        ----a-w-        c:\windows\SysWow64\msls31.dll 
2013-06-24 04:46 . 2013-06-24 04:46        1054720        ----a-w-        c:\windows\system32\MsSpellCheckingFacility.exe 
2013-06-24 04:46 . 2013-06-24 04:46        73728        ----a-w-        c:\windows\SysWow64\SetIEInstalledDate.exe 
2013-06-24 04:46 . 2013-06-24 04:46        719360        ----a-w-        c:\windows\SysWow64\mshtmlmedia.dll 
2013-06-24 04:46 . 2013-06-24 04:46        61952        ----a-w-        c:\windows\SysWow64\tdc.ocx 
2013-06-24 04:46 . 2013-06-24 04:46        523264        ----a-w-        c:\windows\SysWow64\vbscript.dll 
2013-06-24 04:46 . 2013-06-24 04:46        48640        ----a-w-        c:\windows\SysWow64\mshtmler.dll 
2013-06-24 04:46 . 2013-06-24 04:46        38400        ----a-w-        c:\windows\SysWow64\imgutil.dll 
2013-06-24 04:46 . 2013-06-24 04:46        361984        ----a-w-        c:\windows\SysWow64\html.iec 
2013-06-24 04:46 . 2013-06-24 04:46        23040        ----a-w-        c:\windows\SysWow64\licmgr10.dll 
2013-06-24 04:46 . 2013-06-24 04:46        150528        ----a-w-        c:\windows\SysWow64\iexpress.exe 
2013-06-24 04:46 . 2013-06-24 04:46        1441280        ----a-w-        c:\windows\SysWow64\inetcpl.cpl 
2013-06-24 04:46 . 2013-06-24 04:46        138752        ----a-w-        c:\windows\SysWow64\wextract.exe 
2013-06-24 04:46 . 2013-06-24 04:46        137216        ----a-w-        c:\windows\SysWow64\ieUnatt.exe 
2013-06-24 04:46 . 2013-06-24 04:46        12800        ----a-w-        c:\windows\SysWow64\mshta.exe 
2013-06-24 04:46 . 2013-06-24 04:46        110592        ----a-w-        c:\windows\SysWow64\IEAdvpack.dll 
2013-06-24 04:46 . 2013-06-24 04:46        97280        ----a-w-        c:\windows\system32\mshtmled.dll 
2013-06-24 04:46 . 2013-06-24 04:46        92160        ----a-w-        c:\windows\system32\SetIEInstalledDate.exe 
2013-06-24 04:46 . 2013-06-24 04:46        905728        ----a-w-        c:\windows\system32\mshtmlmedia.dll 
2013-06-24 04:46 . 2013-06-24 04:46        81408        ----a-w-        c:\windows\system32\icardie.dll 
2013-06-24 04:46 . 2013-06-24 04:46        762368        ----a-w-        c:\windows\system32\ieapfltr.dll 
2013-06-24 04:46 . 2013-06-24 04:46        62976        ----a-w-        c:\windows\system32\pngfilt.dll 
2013-06-24 04:46 . 2013-06-24 04:46        599552        ----a-w-        c:\windows\system32\vbscript.dll 
2013-06-24 04:46 . 2013-06-24 04:46        52224        ----a-w-        c:\windows\system32\msfeedsbs.dll 
2013-06-24 04:46 . 2013-06-24 04:46        51200        ----a-w-        c:\windows\system32\imgutil.dll 
2013-06-24 04:46 . 2013-06-24 04:46        48640        ----a-w-        c:\windows\system32\mshtmler.dll 
2013-06-24 04:46 . 2013-06-24 04:46        452096        ----a-w-        c:\windows\system32\dxtmsft.dll 
2013-06-24 04:46 . 2013-06-24 04:46        441856        ----a-w-        c:\windows\system32\html.iec 
2013-06-24 04:46 . 2013-06-24 04:46        281600        ----a-w-        c:\windows\system32\dxtrans.dll 
2013-06-24 04:46 . 2013-06-24 04:46        27648        ----a-w-        c:\windows\system32\licmgr10.dll 
2013-06-24 04:46 . 2013-06-24 04:46        270848        ----a-w-        c:\windows\system32\iedkcs32.dll 
2013-06-24 04:46 . 2013-06-24 04:46        247296        ----a-w-        c:\windows\system32\webcheck.dll 
2013-06-24 04:46 . 2013-06-24 04:46        235008        ----a-w-        c:\windows\system32\url.dll 
2013-06-24 04:46 . 2013-06-24 04:46        216064        ----a-w-        c:\windows\system32\msls31.dll 
2013-06-24 04:46 . 2013-06-24 04:46        197120        ----a-w-        c:\windows\system32\msrating.dll 
2013-06-24 04:46 . 2013-06-24 04:46        173568        ----a-w-        c:\windows\system32\ieUnatt.exe 
2013-06-24 04:46 . 2013-06-24 04:46        167424        ----a-w-        c:\windows\system32\iexpress.exe 
2013-06-24 04:46 . 2013-06-24 04:46        1509376        ----a-w-        c:\windows\system32\inetcpl.cpl 
2013-06-24 04:46 . 2013-06-24 04:46        149504        ----a-w-        c:\windows\system32\occache.dll 
2013-06-24 04:46 . 2013-06-24 04:46        144896        ----a-w-        c:\windows\system32\wextract.exe 
2013-06-24 04:46 . 2013-06-24 04:46        1400416        ----a-w-        c:\windows\system32\ieapfltr.dat 
2013-06-24 04:46 . 2013-06-24 04:46        13824        ----a-w-        c:\windows\system32\mshta.exe 
2013-06-24 04:46 . 2013-06-24 04:46        136192        ----a-w-        c:\windows\system32\iepeers.dll 
2013-06-24 04:46 . 2013-06-24 04:46        135680        ----a-w-        c:\windows\system32\IEAdvpack.dll 
2013-06-24 04:46 . 2013-06-24 04:46        12800        ----a-w-        c:\windows\system32\msfeedssync.exe 
2013-06-24 04:46 . 2013-06-24 04:46        102912        ----a-w-        c:\windows\system32\inseng.dll 
2013-06-24 04:46 . 2013-06-24 04:46        77312        ----a-w-        c:\windows\system32\tdc.ocx 
2013-06-05 03:34 . 2013-07-12 16:23        3153920        ----a-w-        c:\windows\system32\win32k.sys 
2013-06-04 06:00 . 2013-07-12 16:26        624128        ----a-w-        c:\windows\system32\qedit.dll 
2013-06-04 04:53 . 2013-07-12 16:26        509440        ----a-w-        c:\windows\SysWow64\qedit.dll 
2012-12-23 07:41 . 2012-12-23 07:38        123231216        ----a-w-        c:\program files (x86)\World-of-Warcraft-Setup-deDE.exe 
. 
. 
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   )))))))))))))))))))))))))))))))))))))))) 
. 
. 
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.  
REGEDIT4 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{FE163F11-1919-4257-A280-FF5AF8DAEECB}] 
2011-08-25 07:15        50240        ----a-w-        c:\program files (x86)\icq\Internet Explorer\icq.dll 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 
"SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2011-04-02 340848] 
"EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe" [2011-03-29 408432] 
"EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" [2011-03-29 202608] 
"Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928] 
"BackupManagerTray"="c:\program files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe" [2012-01-05 296984] 
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2011-07-01 1103440] 
"ArcadeMovieService"="c:\program files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe" [2011-05-09 177448] 
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] 
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720] 
"DivXMediaServer"="c:\program files (x86)\DivX\DivX Media Server\DivXMediaServer.exe" [2013-05-20 450560] 
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] 
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2013-02-13 1263952] 
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-08-16 152392] 
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-08-31 345144] 
. 
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] 
"IsMyWinLockerReboot"="msiexec.exe" [2010-11-21 73216] 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] 
"ConsentPromptBehaviorAdmin"= 5 (0x5) 
"ConsentPromptBehaviorUser"= 3 (0x3) 
"EnableUIADesktopToggle"= 0 (0x0) 
. 
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] 
"LoadAppInit_DLLs"=1 (0x1) 
. 
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] 
"aux"=wdmaud.drv 
. 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] 
@="" 
. 
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] 
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe [x] 
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] 
R2 SystemStoreService;System Store;c:\program files (x86)\SoftwareUpdater\SystemStore.exe  -displayname System Store -servicename SystemStoreService;c:\program files (x86)\SoftwareUpdater\SystemStore.exe  -displayname System Store -servicename SystemStoreService [x] 
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys;c:\windows\SYSNATIVE\Drivers\ssadadb.sys [x] 
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x] 
R3 EgisTec Ticket Service;EgisTec Ticket Service;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [x] 
R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x] 
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x] 
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssadbus.sys [x] 
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdfl.sys [x] 
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdm.sys [x] 
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys;c:\windows\SYSNATIVE\DRIVERS\ssadserd.sys [x] 
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] 
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] 
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] 
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] 
R4 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x] 
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] 
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] 
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x] 
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x] 
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x] 
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] 
S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [x] 
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x] 
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [x] 
S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe;c:\program files (x86)\Acer\Registration\GREGsvc.exe [x] 
S2 ICQ Service;ICQ Service;c:\program files (x86)\ICQ6Toolbar\ICQ Service.exe;c:\program files (x86)\ICQ6Toolbar\ICQ Service.exe [x] 
S2 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x] 
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x] 
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe;c:\program files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [x] 
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] 
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\drivers\HECIx64.sys;c:\windows\SYSNATIVE\drivers\HECIx64.sys [x] 
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x] 
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] 
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] 
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x] 
. 
. 
Inhalt des "geplante Tasks" Ordners 
. 
2013-09-01 c:\windows\Tasks\Adobe Flash Player Updater.job 
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-19 14:59] 
. 
. 
--------- X64 Entries ----------- 
. 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-05-09 168216] 
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-05-09 392472] 
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-05-09 416024] 
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-06-09 11860072] 
"IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-05-02 1935120] 
"Power Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2011-05-10 1831528] 
. 
------- Zusätzlicher Suchlauf ------- 
. 
uStart Page = hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1376659977718.000007&tguid=46364-3869-1376659977718-AB0078FA47CB886A15497805D3C0E763 
uLocal Page = c:\windows\system32\blank.htm 
uDefault_Search_URL = hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1376659977718.000007&tguid=46364-3869-1376659977718-AB0078FA47CB886A15497805D3C0E763&q= 
mDefault_Search_URL = hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1376659977718.000007&tguid=46364-3869-1376659977718-AB0078FA47CB886A15497805D3C0E763&q= 
mStart Page = hxxp://search.certified-toolbar.com?si=46364&st=home&tid=3869&ver=3.7&ts=1376659977718.000007&tguid=46364-3869-1376659977718-AB0078FA47CB886A15497805D3C0E763 
mLocal Page = c:\windows\SysWOW64\blank.htm 
mSearch Page = hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1376659977718.000007&tguid=46364-3869-1376659977718-AB0078FA47CB886A15497805D3C0E763&q= 
mSearch Bar = hxxp://search.certified-toolbar.com?si=46364&st=chrome&tid=3869&ver=3.7&ts=1376659977718.000007&tguid=46364-3869-1376659977718-AB0078FA47CB886A15497805D3C0E763&q= 
uInternet Settings,ProxyOverride = *.local 
IE: An OneNote s&enden - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105 
IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~4\OFFICE11\EXCEL.EXE/3000 
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000 
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files (x86)\ICQ7.6\ICQ.exe 
LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll 
TCP: DhcpNameServer = 192.168.2.1 
FF - ProfilePath - c:\users\Tobias Ruder\AppData\Roaming\Mozilla\Firefox\Profiles\kf2367uv.default\ 
FF - user.js: extensions.autoDisableScopes - 0 
FF - user.js: extensions.shownSelectionUI - true 
. 
- - - - Entfernte verwaiste Registrierungseinträge - - - - 
. 
BHO-{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} - c:\program files (x86)\PricePeep\pricepeep.dll 
Toolbar-Locked - (no file) 
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start 
Toolbar-Locked - (no file) 
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe 
AddRemove-PricePeep - c:\program files (x86)\PricePeep\uninstall.exe 
. 
. 
. 
--------------------- Gesperrte Registrierungsschluessel --------------------- 
. 
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] 
@Denied: (A 2) (Everyone) 
@="FlashBroker" 
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] 
"Enabled"=dword:00000001 
. 
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] 
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] 
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] 
@Denied: (A 2) (Everyone) 
@="IFlashBroker5" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] 
@="{00020424-0000-0000-C000-000000000046}" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] 
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" 
"Version"="1.0" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{722b3793-5367-4446-b6bb-db89b05c1f24}\LocalServer32] 
@DACL=(02 0000) 
@=expand:"%SystemRoot%\\System32\\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {722b3793-5367-4446-b6bb-db89b05c1f24}" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] 
@Denied: (A 2) (Everyone) 
@="FlashBroker" 
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] 
"Enabled"=dword:00000001 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] 
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] 
@Denied: (A 2) (Everyone) 
@="Shockwave Flash Object" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx" 
"ThreadingModel"="Apartment" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] 
@="0" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] 
@="ShockwaveFlash.ShockwaveFlash.11" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] 
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] 
@="1.0" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] 
@="ShockwaveFlash.ShockwaveFlash" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] 
@Denied: (A 2) (Everyone) 
@="Macromedia Flash Factory Object" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx" 
"ThreadingModel"="Apartment" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] 
@="FlashFactory.FlashFactory.1" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] 
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] 
@="1.0" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] 
@="FlashFactory.FlashFactory" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] 
@Denied: (A 2) (Everyone) 
@="IFlashBroker5" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] 
@="{00020424-0000-0000-C000-000000000046}" 
. 
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] 
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" 
"Version"="1.0" 
. 
[HKEY_LOCAL_MACHINE\software\McAfee] 
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 
   00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ 
. 
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] 
@Denied: (A) (Everyone) 
. 
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] 
@Denied: (A) (Everyone) 
. 
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] 
@Denied: (A) (Users) 
@Denied: (A) (Everyone) 
@Allowed: (B 1 2 3 4 5) (S-1-5-20) 
"BlindDial"=dword:00000000 
. 
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] 
@Denied: (Full) (Everyone) 
. 
Zeit der Fertigstellung: 2013-09-01  13:51:46 
ComboFix-quarantined-files.txt  2013-09-01 11:51 
. 
Vor Suchlauf: 14 Verzeichnis(se), 350.847.082.496 Bytes frei 
Nach Suchlauf: 20 Verzeichnis(se), 350.341.685.248 Bytes frei 
. 
- - End Of File - - 4FE68B66D0841E0258BEAD7B55C00686   Vielen Dank bisher!    |