Phoenix88 | 27.10.2013 00:02 | ESET Logfile also das was er gefixt hat: Code:
C:\AdwCleaner\Quarantine\C\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\udw3yiz2.default\Extensions\plugin@getwebcake.com\content\overlay.js.vir JS/Adware.Yontoo.C application cleaned by deleting - quarantined
C:\FRST\Quarantine\lt-mkhv@etd-.com\content\bg.js Win32/Adware.MultiPlug.H application cleaned by deleting - quarantined
C:\Users\Markus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\78b8834e-6e581d0b a variant of Java/Exploit.CVE-2013-1493.HV trojan cleaned by deleting - quarantined
C:\Users\Markus\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\78b8834e-6f7a634a a variant of Java/Exploit.CVE-2013-1493.HV trojan cleaned by deleting - quarantined
D:\Local ohne Hamachii\Microsoft\Windows\Temporary Internet Files\Content.IE5\0NMJQ5A2\LyricsPal_1060-8101_v122[1] multiple threats cleaned by deleting - quarantined
D:\Local ohne Hamachii\Temp\lyricsPaltmp.exe multiple threats cleaned by deleting - quarantined
D:\Local ohne Hamachii\Temp\OptimizerPro.exe a variant of Win32/SpeedingUpMyPC.B application cleaned by deleting - quarantined
D:\Programm(x64) C\LyricsPal\128.crx Win32/Adware.AddLyrics.L application deleted - quarantined
D:\Programm(x64) C\LyricsPal\128.dll a variant of Win32/AdWare.AddLyrics.S application cleaned by deleting - quarantined
D:\Programm(x64) C\LyricsPal\128.xpi Win32/Adware.AddLyrics.L application deleted - quarantined
D:\Roaming\Mozilla\Firefox\Profiles\udw3yiz2.default\extensions\lt-mkhv@etd-.com\content\bg.js Win32/Adware.MultiPlug.H application cleaned by deleting - quarantined
D:\Roaming\Mozilla\Firefox\Profiles\udw3yiz2.default\extensions\plugin@getwebcake.com\content\overlay.js JS/Adware.Yontoo.C application cleaned by deleting - quarantined COMBOFIX: Code:
ComboFix 13-10-26.01 - Markus 27.10.2013 0:41.2.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.10193.8255 [GMT 2:00]
ausgeführt von:: c:\users\Markus\Desktop\Adware\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\frapsvid.dll
G:\install.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-09-26 bis 2013-10-26 ))))))))))))))))))))))))))))))
.
.
2013-10-26 22:46 . 2013-10-26 22:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-10-26 11:57 . 2013-10-26 11:57 -------- d-----w- c:\program files (x86)\ESET
2013-10-22 19:39 . 2013-10-22 19:39 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2013-10-22 13:55 . 2013-10-22 13:55 -------- d-----w- c:\users\Markus\AppData\Local\NVIDIA
2013-10-21 20:17 . 2013-10-21 20:17 -------- d-----w- c:\program files (x86)\WinPcap
2013-10-18 21:37 . 2013-10-18 21:37 -------- d-----w- c:\programdata\Stardock
2013-10-18 21:37 . 2013-10-18 21:37 -------- d-----w- c:\programdata\Ironclad Games
2013-10-15 19:43 . 2013-10-15 19:43 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2013-10-13 15:34 . 2013-10-13 15:34 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-10-13 15:33 . 2013-10-13 15:32 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-10-13 15:32 . 2013-10-13 15:32 -------- d-----w- c:\program files (x86)\Java
2013-10-12 19:35 . 2013-10-12 19:35 -------- d-----w- c:\program files (x86)\Pivot Stickfigure Animator
2013-10-11 12:51 . 2013-10-11 12:51 -------- d-----w- c:\program files (x86)\Common Files\Skype
2013-10-11 12:51 . 2013-10-11 12:51 -------- d-----r- c:\program files (x86)\Skype
2013-10-11 12:51 . 2013-10-11 12:51 -------- d-----w- c:\programdata\Skype
2013-10-09 12:51 . 2013-09-08 02:30 1903552 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-10-09 12:50 . 2013-08-29 02:17 5549504 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-10-09 12:46 . 2013-09-04 12:12 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-10-09 12:46 . 2013-09-04 12:11 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-10-09 12:46 . 2013-09-04 12:11 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-10-09 12:46 . 2013-09-04 12:11 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-10-09 12:46 . 2013-09-04 12:11 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-10-09 12:46 . 2013-09-04 12:11 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-10-09 12:46 . 2013-09-04 12:11 7808 ----a-w- c:\windows\system32\drivers\usbd.sys
2013-10-09 12:39 . 2005-04-03 20:59 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2013-10-06 16:54 . 2013-10-06 16:54 -------- d-----w- c:\users\Markus\AppData\Roaming\Easy2Convert
2013-10-06 16:54 . 2013-10-06 16:54 -------- d-----w- c:\program files (x86)\Easy2Convert Software
2013-10-05 11:27 . 2013-10-05 11:27 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2013-10-05 11:26 . 2013-10-19 18:58 -------- d-----w- c:\users\UpdatusUser
2013-10-05 09:49 . 2013-10-05 09:49 -------- d-----w- c:\users\Markus\AppData\Local\LogMeIn
2013-10-05 09:49 . 2013-10-05 09:49 -------- d-----w- c:\programdata\LogMeIn
2013-10-04 14:24 . 2013-10-04 14:24 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2013-10-03 20:57 . 2013-10-03 20:58 -------- d-----w- c:\program files (x86)\Avidemux 2.6
2013-09-29 13:27 . 2013-09-29 13:27 -------- d-----w- c:\users\Markus\AppData\Local\Sony Online Entertainment
2013-09-28 16:45 . 2013-09-28 16:45 -------- d-----w- c:\users\Public\Sony Online Entertainment
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-26 21:34 . 2013-08-16 20:38 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-10-26 21:34 . 2013-08-16 20:16 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-10-26 21:34 . 2013-08-16 20:16 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-10-13 15:32 . 2013-08-17 13:51 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-10-13 15:32 . 2013-08-17 13:51 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-10-09 21:35 . 2013-08-16 19:42 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-10-09 21:35 . 2013-08-16 19:42 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-12 21:55 . 2013-09-05 16:10 447752 ----a-w- c:\windows\SysWow64\vp6vfw.dll
2013-09-12 08:58 . 2013-08-16 19:21 2986672 ----a-w- c:\windows\system32\nvapi64.dll
2013-09-12 08:58 . 2013-02-25 22:32 2630304 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-09-12 08:58 . 2013-02-25 22:32 1412832 ----a-w- c:\windows\system32\nvumdshimx.dll
2013-09-12 08:58 . 2013-02-25 22:32 15901448 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-09-12 08:58 . 2013-02-25 22:32 13628208 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2013-09-12 07:25 . 2013-08-16 19:21 6599968 ----a-w- c:\windows\system32\nvcpl.dll
2013-09-12 07:25 . 2013-08-16 19:21 3452192 ----a-w- c:\windows\system32\nvsvc64.dll
2013-09-12 07:25 . 2013-08-16 19:21 920864 ----a-w- c:\windows\system32\nvvsvc.exe
2013-09-12 07:25 . 2013-08-16 19:21 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-09-12 07:25 . 2013-08-16 19:21 2559776 ----a-w- c:\windows\system32\nvsvcr.dll
2013-09-12 07:25 . 2013-08-16 19:21 219424 ----a-w- c:\windows\system32\nvmctray.dll
2013-09-11 23:17 . 2013-09-11 23:17 571168 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2013-09-11 22:06 . 2013-08-16 19:39 3361114 ----a-w- c:\windows\system32\nvcoproc.bin
2013-09-03 11:50 . 2013-08-17 23:16 81112 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-09-03 11:50 . 2013-08-17 17:10 132088 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-09-03 11:50 . 2013-08-17 17:10 105344 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-08-30 00:06 . 2012-07-17 12:37 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-08-29 01:48 . 2013-10-09 12:50 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-08-22 11:10 . 2013-08-16 18:41 100864 ----a-r- c:\users\Markus\AppData\Roaming\Microsoft\Installer\{68D2A2E2-6B64-4433-8073-0605EB306C1B}\Icon68D2A2E2.exe
2013-08-19 01:16 . 2013-08-19 01:16 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-08-19 01:16 . 2013-08-19 01:16 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-08-19 01:16 . 2013-08-19 01:16 523264 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-08-19 01:16 . 2013-08-19 01:16 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-08-19 01:16 . 2013-08-19 01:16 38400 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-08-19 01:16 . 2013-08-19 01:16 226304 ----a-w- c:\windows\system32\elshyph.dll
2013-08-19 01:16 . 2013-08-19 01:16 185344 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-08-19 01:16 . 2013-08-19 01:16 158720 ----a-w- c:\windows\SysWow64\msls31.dll
2013-08-19 01:16 . 2013-08-19 01:16 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-08-19 01:16 . 2013-08-19 01:16 138752 ----a-w- c:\windows\SysWow64\wextract.exe
2013-08-19 01:16 . 2013-08-19 01:16 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-08-19 01:16 . 2013-08-19 01:16 12800 ----a-w- c:\windows\SysWow64\mshta.exe
2013-08-19 01:16 . 2013-08-19 01:16 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-08-19 01:16 . 2013-08-19 01:16 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-08-19 01:16 . 2013-08-19 01:16 97280 ----a-w- c:\windows\system32\mshtmled.dll
2013-08-19 01:16 . 2013-08-19 01:16 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-08-19 01:16 . 2013-08-19 01:16 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-08-19 01:16 . 2013-08-19 01:16 81408 ----a-w- c:\windows\system32\icardie.dll
2013-08-19 01:16 . 2013-08-19 01:16 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-08-19 01:16 . 2013-08-19 01:16 762368 ----a-w- c:\windows\system32\ieapfltr.dll
2013-08-19 01:16 . 2013-08-19 01:16 62976 ----a-w- c:\windows\system32\pngfilt.dll
2013-08-19 01:16 . 2013-08-19 01:16 61952 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-08-19 01:16 . 2013-08-19 01:16 599552 ----a-w- c:\windows\system32\vbscript.dll
2013-08-19 01:16 . 2013-08-19 01:16 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-08-19 01:16 . 2013-08-19 01:16 51200 ----a-w- c:\windows\system32\imgutil.dll
2013-08-19 01:16 . 2013-08-19 01:16 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-08-19 01:16 . 2013-08-19 01:16 452096 ----a-w- c:\windows\system32\dxtmsft.dll
2013-08-19 01:16 . 2013-08-19 01:16 441856 ----a-w- c:\windows\system32\html.iec
2013-08-19 01:16 . 2013-08-19 01:16 361984 ----a-w- c:\windows\SysWow64\html.iec
2013-08-19 01:16 . 2013-08-19 01:16 281600 ----a-w- c:\windows\system32\dxtrans.dll
2013-08-19 01:16 . 2013-08-19 01:16 27648 ----a-w- c:\windows\system32\licmgr10.dll
2013-08-19 01:16 . 2013-08-19 01:16 270848 ----a-w- c:\windows\system32\iedkcs32.dll
2013-08-19 01:16 . 2013-08-19 01:16 247296 ----a-w- c:\windows\system32\webcheck.dll
2013-08-19 01:16 . 2013-08-19 01:16 235008 ----a-w- c:\windows\system32\url.dll
2013-08-19 01:16 . 2013-08-19 01:16 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-08-19 01:16 . 2013-08-19 01:16 216064 ----a-w- c:\windows\system32\msls31.dll
2013-08-19 01:16 . 2013-08-19 01:16 197120 ----a-w- c:\windows\system32\msrating.dll
2013-08-19 01:16 . 2013-08-19 01:16 173568 ----a-w- c:\windows\system32\ieUnatt.exe
2013-08-19 01:16 . 2013-08-19 01:16 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-08-19 01:16 . 2013-08-19 01:16 1509376 ----a-w- c:\windows\system32\inetcpl.cpl
2013-08-19 01:16 . 2013-08-19 01:16 149504 ----a-w- c:\windows\system32\occache.dll
2013-08-19 01:16 . 2013-08-19 01:16 144896 ----a-w- c:\windows\system32\wextract.exe
2013-08-19 01:16 . 2013-08-19 01:16 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-08-19 01:16 . 2013-08-19 01:16 1400416 ----a-w- c:\windows\system32\ieapfltr.dat
2013-08-19 01:16 . 2013-08-19 01:16 13824 ----a-w- c:\windows\system32\mshta.exe
2013-08-19 01:16 . 2013-08-19 01:16 136192 ----a-w- c:\windows\system32\iepeers.dll
2013-08-19 01:16 . 2013-08-19 01:16 135680 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-08-19 01:16 . 2013-08-19 01:16 12800 ----a-w- c:\windows\system32\msfeedssync.exe
2013-08-19 01:16 . 2013-08-19 01:16 102912 ----a-w- c:\windows\system32\inseng.dll
2013-08-19 01:15 . 2013-08-19 01:15 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-19 01:15 . 2013-08-19 01:15 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-19 01:15 . 2013-08-19 01:15 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2013-08-19 01:15 . 2013-08-19 01:15 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2013-08-19 01:15 . 2013-08-19 01:15 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-19 01:15 . 2013-08-19 01:15 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-19 01:15 . 2013-08-19 01:15 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-08-19 01:15 . 2013-08-19 01:15 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-08-19 01:15 . 2013-08-19 01:15 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2013-08-19 01:15 . 2013-08-19 01:15 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2013-08-19 01:15 . 2013-08-19 01:15 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-08-19 01:15 . 2013-08-19 01:15 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-19 01:15 . 2013-08-19 01:15 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-19 01:15 . 2013-08-19 01:15 3928064 ----a-w- c:\windows\system32\d2d1.dll
2013-08-19 01:15 . 2013-08-19 01:15 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2013-08-19 01:15 . 2013-08-19 01:15 363008 ----a-w- c:\windows\system32\dxgi.dll
2013-08-19 01:15 . 2013-08-19 01:15 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-19 01:15 . 2013-08-19 01:15 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-08-19 01:15 . 2013-08-19 01:15 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2013-08-19 01:15 . 2013-08-19 01:15 333312 ----a-w- c:\windows\system32\d3d10_1core.dll
2013-08-19 01:15 . 2013-08-19 01:15 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-19 01:15 . 2013-08-19 01:15 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-08-19 01:15 . 2013-08-19 01:15 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-08-19 01:15 . 2013-08-19 01:15 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="g:\steam\steam.exe" [2013-10-09 1813928]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"BitTorrent"="c:\users\Markus\AppData\Roaming\BitTorrent\BitTorrent.exe" [2013-07-25 1119056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2012-02-09 5015040]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-02-26 291608]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-09-03 347192]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-09-05 958576]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2013-10-01 2345296]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 L1C;NDIS Miniport Driver for Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
R3 MSICDSetup;MSICDSetup;e:\cdriver64.sys;e:\CDriver64.sys [x]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys;c:\windows\SYSNATIVE\drivers\npf.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe;c:\windows\SYSNATIVE\viakaraokesrv.exe [x]
S3 arusb_win7x;Service For TP-LINK Wireless N Adapter;c:\windows\system32\DRIVERS\arusb_win7x.sys;c:\windows\SYSNATIVE\DRIVERS\arusb_win7x.sys [x]
S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 ScreamBAudioSvc;ScreamBee Audio;c:\windows\system32\drivers\ScreamingBAudio64.sys;c:\windows\SYSNATIVE\drivers\ScreamingBAudio64.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-10-18 13:52 1185744 ----a-w- c:\program files (x86)\Google\Chrome\Application\30.0.1599.101\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-10-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-16 21:35]
.
2013-10-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-16 20:35]
.
2013-10-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-16 20:35]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-08-27 1028896]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: Interfaces\{2DFA82E2-B872-46D3-A252-3F3BAA2C6C05}: NameServer = 192.168.178.2
FF - ProfilePath - c:\users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\udw3yiz2.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Google
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
WebBrowser-{41564952-412D-5637-00A7-7A786E7484D7} - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1463122067-3401198527-1685088311-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:09,63,19,0f,84,97,34,99,c3,0a,a4,83,eb,34,ea,7f,c7,21,8e,82,eb,55,86,
ee,da,14,57,bd,7d,b2,23,d7,e5,69,b8,eb,2c,69,b6,58,ab,bb,89,2c,69,48,72,87,\
"??"=hex:69,6f,5c,46,6a,89,f9,ee,2d,48,e0,10,87,42,1e,12
.
[HKEY_USERS\S-1-5-21-1463122067-3401198527-1685088311-1000\Software\SecuROM\License information*]
"datasecu"=hex:b1,98,34,4c,16,18,39,ce,b6,1b,e1,11,ae,d3,b8,0e,13,f8,cc,10,bb,
c1,ae,ef,ef,6a,3e,6b,10,35,05,d3,6f,41,e4,60,13,b2,69,f4,59,a1,95,d6,79,03,\
"rkeysecu"=hex:f2,3e,ee,d0,46,c0,32,ef,6c,08,69,59,42,8f,fd,61
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-10-27 00:48:27
ComboFix-quarantined-files.txt 2013-10-26 22:48
.
Vor Suchlauf: 10 Verzeichnis(se), 15.948.886.016 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 15.883.149.312 Bytes frei
.
- - End Of File - - 208AF244F3C1770818415AEA1882FE5D
A36C5E4F47E84449FF07ED3517B43A31 |