du bist ein Schatz!!!
Also ich hab ja selber auch recherchiert und folgendes hab ich schon gemacht:
ComboFix: Code:
Combofix Logfile:
Code:
ComboFix 14-06-24.01 - User 25.06.2014 17:16:07.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.8073.4848 [GMT 2:00]
ausgeführt von:: d:\downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Java\jre7\bin\jp2ssv.dll
c:\programdata\Roaming
c:\users\User\AppData\Local\assembly\tmp
c:\windows\security\Database\tmp.edb
c:\windows\SysWow64\Inetde.dll
E:\install.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-05-25 bis 2014-06-25 ))))))))))))))))))))))))))))))
.
.
2014-06-25 15:19 . 2014-06-25 15:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-06-25 11:57 . 2014-06-25 13:01 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2014-06-25 10:17 . 2014-06-25 10:19 -------- d-----w- C:\FRST
2014-06-24 14:57 . 2014-06-24 20:32 -------- d-----w- c:\programdata\wjin
2014-06-24 14:57 . 2014-06-24 19:37 -------- d-----w- c:\programdata\vhtarhu
2014-06-24 10:12 . 2014-06-24 11:05 -------- d-----w- c:\programdata\doyao
2014-06-24 00:01 . 2014-06-24 00:02 -------- d-----w- c:\program files (x86)\Rising
2014-06-23 21:22 . 2014-06-24 14:57 -------- d-----w- c:\programdata\dwqplug
2014-06-23 21:22 . 2014-06-24 14:57 -------- d-----w- c:\programdata\wddyol
2014-06-23 21:22 . 2014-06-23 21:22 -------- d-----w- c:\programdata\iql
2014-06-23 20:49 . 2014-06-24 20:32 -------- d-----w- c:\program files (x86)\WinHTTrack
2014-06-22 19:58 . 2014-06-24 20:32 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2014-06-21 17:56 . 2014-06-21 17:56 -------- d-----w- c:\programdata\newbackup
2014-06-21 17:44 . 2014-06-21 17:44 -------- d-----w- c:\programdata\managecapsule
2014-06-21 17:08 . 2014-06-21 17:08 -------- d-----w- c:\programdata\ibackupvhd
2014-06-21 17:08 . 2014-06-21 17:08 -------- d-----w- c:\programdata\logsaver
2014-06-21 15:54 . 2014-06-21 15:54 -------- d-----w- c:\programdata\ftw
2014-06-21 13:52 . 2014-06-21 13:52 -------- d-----w- c:\programdata\explauncher
2014-06-21 13:52 . 2014-06-21 13:52 -------- d-----w- c:\programdata\launcher
2014-06-21 13:48 . 2014-06-21 13:48 -------- d-----w- c:\program files\Paragon Software
2014-06-21 13:31 . 2014-06-21 13:37 -------- d-----w- c:\program files (x86)\Nero
2014-06-21 13:31 . 2014-06-21 13:46 -------- d-----w- c:\program files (x86)\Common Files\Nero
2014-06-21 13:31 . 2014-06-21 13:32 -------- d-----w- c:\programdata\Nero
2014-06-21 13:00 . 2014-06-21 13:00 -------- d-----w- c:\program files (x86)\CDBurnerXP
2014-06-21 13:00 . 2014-06-21 13:00 -------- d-----w- c:\programdata\Canneverbe Limited
2014-06-17 17:02 . 2014-06-17 17:03 -------- d-----w- c:\program files (x86)\FileZilla FTP Client
2014-06-17 16:40 . 2014-06-17 16:40 -------- d-----w- c:\programdata\Power Soft
2014-06-17 16:40 . 2014-06-17 16:40 -------- d-----w- c:\program files (x86)\Power Soft
2014-06-17 15:37 . 2014-06-17 15:37 -------- d-----w- c:\program files\003
2014-06-17 15:06 . 2014-06-17 15:06 -------- d-----w- c:\program files (x86)\Cheat Engine 6.3
2014-06-17 14:52 . 2014-06-17 14:52 -------- d-----w- c:\program files (x86)\TomTom HOME 2
2014-06-17 14:52 . 2014-06-17 14:52 -------- d-----w- c:\program files (x86)\TomTom International B.V
2014-06-15 11:00 . 2014-06-15 11:00 -------- d-----w- c:\program files (x86)\Tesseract-OCR
2014-06-15 11:00 . 2014-06-15 11:00 -------- d-----w- c:\program files (x86)\JDownloader
2014-06-14 18:21 . 2014-06-14 18:54 -------- d-----w- C:\Rainmeter
2014-06-14 13:00 . 2014-06-14 13:00 -------- d-----w- c:\program files (x86)\DeskSpace
2014-06-13 17:32 . 2014-06-13 17:32 -------- d-----w- c:\program files (x86)\Alastria Software
2014-06-13 16:53 . 2014-06-13 16:53 -------- d-----w- c:\program files\Rainlendar2
2014-06-13 16:46 . 2014-06-16 10:53 23365632 ----a-w- c:\windows\system32\imageres.dll
2014-06-13 16:40 . 2014-06-13 16:40 -------- d-----w- c:\programdata\Stardock
2014-06-13 16:40 . 2014-06-19 11:32 -------- d-----w- c:\program files (x86)\Stardock
2014-06-12 16:31 . 2014-06-12 16:37 -------- d-----w- C:\HP Universal Print Driver
2014-06-12 16:06 . 2008-05-07 17:59 99840 ----a-w- c:\windows\system32\Spool\prtprocs\x64\HPZPPLHN.DLL
2014-06-12 14:51 . 2014-06-12 14:53 -------- d-----w- c:\program files (x86)\Klebezettel NG
2014-06-12 10:21 . 2014-06-12 10:21 -------- d-----w- c:\program files (x86)\Software4u
2014-06-12 09:29 . 2014-06-12 09:29 -------- dc----w- c:\windows\system32\DRVSTORE
2014-06-12 09:29 . 2012-08-21 11:01 33240 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2014-06-12 09:29 . 2014-06-12 09:29 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-06-12 09:29 . 2014-06-12 09:29 -------- d-----w- c:\program files (x86)\iTunes
2014-06-12 09:29 . 2014-06-12 09:29 -------- d-----w- c:\program files\iPod
2014-06-12 09:29 . 2014-06-12 09:29 -------- d-----w- c:\program files\iTunes
2014-06-12 09:29 . 2014-06-12 09:29 -------- d-----w- c:\programdata\Apple Computer
2014-06-12 09:29 . 2014-06-12 09:29 -------- d-----w- c:\program files (x86)\Apple Software Update
2014-06-12 09:29 . 2014-06-12 09:29 -------- d-----w- c:\program files\Common Files\Apple
2014-06-12 09:28 . 2014-06-12 09:29 -------- d-----w- c:\program files (x86)\Common Files\Apple
2014-06-10 22:43 . 2014-06-10 22:43 -------- d-----w- c:\program files (x86)\Microsoft OneDrive
2014-06-10 22:43 . 2014-06-10 22:43 -------- d-----w- c:\programdata\Microsoft OneDrive
2014-06-10 17:47 . 2014-06-10 17:47 -------- d-----w- c:\program files\Common Files\DESIGNER
2014-06-09 15:50 . 2014-06-09 15:50 -------- d-----w- c:\windows\PCHEALTH
2014-06-09 15:49 . 2014-06-09 15:49 -------- d-----w- c:\program files\Microsoft Analysis Services
2014-06-09 15:49 . 2014-06-09 15:49 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2014-06-09 15:49 . 2014-06-09 15:50 -------- d-----w- c:\program files\Microsoft Office
2014-06-09 15:48 . 2014-06-09 15:48 -------- d-----r- C:\MSOCache
2014-06-08 20:00 . 2014-06-24 20:32 -------- d-----w- c:\program files (x86)\RocketDock
2014-06-08 19:59 . 2011-02-25 06:19 2871808 ----a-w- c:\windows\explorer_edit_w7sbc.exe
2014-06-08 19:59 . 2011-02-25 06:19 2871808 ----a-w- c:\windows\explorer_backup_w7sbc.exe
2014-06-08 19:59 . 2011-02-25 06:19 2871808 ----a-w- c:\windows\explorer.exe
2014-06-08 19:59 . 2011-02-25 06:19 2871808 ----a-w- c:\windows\explorer.backup.exe
2014-06-08 18:04 . 2014-06-08 18:04 -------- d-----w- c:\program files (x86)\Tor
2014-06-08 17:54 . 2014-06-08 17:54 -------- d-----w- c:\program files (x86)\Driver Identifier
2014-06-08 17:21 . 2014-06-08 17:21 -------- d-----w- c:\program files (x86)\QUALCOMM
2014-06-08 17:21 . 2014-06-08 17:21 -------- d-----w- c:\programdata\QUALCOMM
2014-06-08 17:13 . 2014-06-24 20:32 -------- d--h--w- c:\windows\system32\WLANProfiles
2014-06-08 17:13 . 2014-06-08 17:13 -------- d-----w- c:\users\Public\Roaming
2014-06-08 17:13 . 2014-06-08 17:13 -------- d-----w- c:\users\Default\Roaming
2014-06-08 17:12 . 2014-06-08 17:12 -------- d-----w- c:\program files\Intel
2014-06-08 17:12 . 2014-06-08 17:12 -------- d-----w- c:\program files\Common Files\Intel
2014-06-08 17:12 . 2014-06-08 17:12 -------- d-----w- c:\program files (x86)\Cisco
2014-06-08 17:09 . 2014-06-08 17:20 -------- d-----w- c:\program files (x86)\Dell
2014-06-08 17:09 . 2014-06-19 09:46 -------- d-----w- c:\windows\{69093D49-3DD1-4FB5-A378-0D4DB4CF86EA}
2014-06-08 16:51 . 2012-08-10 13:44 482128 ----a-w- c:\windows\system32\drivers\e1c62x64.sys
2014-06-08 16:51 . 2012-08-09 11:56 101224 ----a-w- c:\windows\system32\NicInstC.dll
2014-06-08 16:51 . 2012-08-09 07:54 73032 ----a-w- c:\windows\system32\e1cmsg.dll
2014-06-08 15:07 . 2014-06-08 18:26 925184 ----a-w- c:\windows\expstart.exe
2014-06-08 14:37 . 2010-11-21 03:23 2851840 ----a-w- c:\windows\system32\themeui.dll.backup
2014-06-08 14:37 . 2009-07-14 01:41 332288 ----a-w- c:\windows\system32\uxtheme.dll.backup
2014-06-08 14:37 . 2009-07-14 01:41 44544 ----a-w- c:\windows\system32\themeservice.dll.backup
2014-06-08 14:29 . 2014-06-08 14:32 -------- d-----w- c:\windows\W7SBC
2014-06-08 13:57 . 2014-06-08 13:57 -------- d-----w- c:\program files (x86)\MSXML 4.0
2014-06-08 13:53 . 2014-06-08 13:53 -------- d-----w- c:\program files\CCleaner
2014-06-08 13:52 . 2014-06-08 13:52 -------- d-----w- c:\program files (x86)\TeamViewer
2014-06-08 13:40 . 2003-04-18 16:06 8192 ----a-w- c:\windows\SysWow64\srvany.exe
2014-06-08 13:40 . 2010-08-13 15:25 223848 ----a-w- c:\windows\SysWow64\SDIOAssist.exe
2014-06-08 13:40 . 2003-04-18 16:05 32256 ----a-w- c:\windows\SysWow64\instsrv.exe
2014-06-08 13:40 . 2014-06-08 13:40 -------- d-----w- c:\windows\SysWow64\SDA
2014-06-08 13:40 . 2014-06-08 13:40 -------- d-----w- c:\program files (x86)\O2Micro
2014-06-08 13:39 . 2014-06-08 13:39 -------- d-----w- c:\program files\IDT
2014-06-07 19:25 . 2013-12-24 23:09 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2014-06-07 19:25 . 2013-12-24 22:48 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2014-06-07 19:25 . 2013-11-23 18:26 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2014-06-07 19:25 . 2013-11-23 17:47 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2014-06-07 19:25 . 2013-11-22 22:48 3928064 ----a-w- c:\windows\system32\d2d1.dll
2014-06-07 19:25 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\SysWow64\explorer.exe
2014-06-07 19:25 . 2013-11-26 08:16 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2014-06-07 17:55 . 2014-06-24 20:32 -------- d-----w- c:\windows\AutoKMS
2014-06-07 17:54 . 2014-06-07 17:54 -------- d-----w- c:\programdata\Microsoft Toolkit
2014-06-07 15:48 . 2014-06-07 17:02 -------- d-----w- c:\programdata\Folderico
2014-06-07 15:48 . 2014-06-07 15:48 -------- d-----w- c:\program files (x86)\Folderico
2014-06-07 15:26 . 2014-06-07 15:26 -------- d-----w- c:\program files (x86)\IrfanView
2014-06-07 15:22 . 2014-06-07 15:22 -------- d-----w- c:\program files (x86)\NexusFont
2014-06-07 15:12 . 2014-06-07 15:12 -------- d-----w- c:\program files (x86)\Tools&More
2014-06-07 14:58 . 2008-01-29 04:57 450560 ----a-w- c:\windows\SysWow64\fldrvw90.ocx
2014-06-07 14:58 . 2014-06-07 15:13 -------- d-----w- c:\program files (x86)\AllDup
2014-06-07 14:58 . 2014-06-07 15:13 -------- d-----w- c:\programdata\AllDup
2014-06-07 14:58 . 2010-10-13 03:42 2369456 ----a-w- c:\windows\SysWow64\Codejock.CommandBars.v13.4.2.ocx
2014-06-07 14:58 . 2010-08-20 18:53 86016 ----a-w- c:\windows\SysWow64\mtSplitter.ocx
2014-06-07 14:58 . 2010-06-11 07:50 89888 ----a-w- c:\windows\SysWow64\mtFrame.ocx
2014-06-07 14:58 . 2010-06-01 11:45 1005088 ----a-w- c:\windows\SysWow64\TList8.ocx
2014-06-07 14:58 . 2010-03-25 07:33 171752 ----a-w- c:\windows\SysWow64\mtRTF2.ocx
2014-06-07 14:58 . 2009-10-12 21:02 44736 ----a-w- c:\windows\SysWow64\mtSubclass.dll
2014-06-07 14:58 . 2009-10-12 21:01 77504 ----a-w- c:\windows\SysWow64\mtScrollContainer.ocx
2014-06-07 14:42 . 2014-06-12 09:29 -------- d-----w- c:\programdata\Apple
2014-06-07 14:42 . 2014-06-07 14:42 -------- d-----w- c:\program files\Bonjour
2014-06-07 14:42 . 2014-06-07 14:42 -------- d-----w- c:\program files (x86)\Bonjour
2014-06-07 14:42 . 2014-06-07 14:42 -------- d-----w- c:\program files (x86)\AirVideoServer HD
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-06-08 14:37 . 2010-11-21 03:23 2851840 ----a-w- c:\windows\system32\themeui.dll
2014-06-08 14:37 . 2009-07-13 23:55 332288 ----a-w- c:\windows\system32\uxtheme.dll
2014-06-08 14:37 . 2009-07-13 23:54 44544 ----a-w- c:\windows\system32\themeservice.dll
2014-05-02 02:37 . 2010-11-21 03:23 116736 ----a-w- c:\windows\system32\drivers\UMDF\WUDFUsbccidDriver.dll
2014-03-31 07:35 . 2010-11-21 03:27 270496 ----a-w- c:\windows\system32\MpSigStub.exe
2012-04-14 06:45 . 2012-04-14 07:02 85504 ----a-w- c:\program files\filterinstaller.exe.64.exe
2012-04-14 06:45 . 2012-04-14 07:02 52312 ----a-w- c:\program files\stdriver32.sys
2012-04-14 06:45 . 2012-04-14 07:02 421888 ----a-w- c:\program files\x264enc2.exe
2012-04-14 06:45 . 2012-04-14 07:02 196608 ----a-w- c:\program files\mp3el2.exe
2012-04-14 06:45 . 2012-04-14 07:02 103512 ----a-w- c:\program files\stdriver64.sys
2012-04-14 06:45 . 2012-04-14 07:02 77824 ----a-w- c:\program files\filterinstaller.exe
2012-04-14 06:45 . 2012-04-14 07:02 69632 ----a-w- c:\program files\debuthooksdll.dll
2012-04-14 06:45 . 2012-04-14 07:02 1778180 ----a-w- c:\program files\uninst.exe
2012-02-16 07:25 . 2012-04-14 07:02 1471592 ----a-w- c:\program files\debutsetup_v1.64.exe
2009-12-18 16:03 . 2012-04-14 07:02 1069060 ----a-w- c:\program files\debut.exe
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2011-02-26 . 3B69712041F3D63605529BD66DC00C48 . 2871808 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[-] 2011-02-25 . 78F13CFE0250EA7308146FA97E0FFFF5 . 2871808 . . [6.1.7600.16385] .. c:\windows\explorer.exe
[7] 2011-02-25 . 332FEAB1435662FC6C672E25BEB37BE3 . 2871808 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[7] 2010-11-21 . AC4C51EB24AA95B77F705AB159189E24 . 2872320 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2014-06-10 22:43 223432 ----a-w- c:\users\User\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2014-06-10 22:43 223432 ----a-w- c:\users\User\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2014-06-10 22:43 223432 ----a-w- c:\users\User\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2012-10-01 18:38 1720976 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2012-10-01 18:38 1720976 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2012-10-01 18:38 1720976 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2014-05-28 23:44 131248 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2014-05-28 23:44 131248 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2014-05-28 23:44 131248 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FalNET G19 Display Manager"="c:\program files (x86)\FalNET G19 Display Manager\FalNET G19 Display Manager.exe" [2014-06-06 1380864]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"AirVideoServerHD"="c:\program files (x86)\AirVideoServer HD\AirVideoServerStarter.exe" [2014-03-10 2141448]
"Digiarty_Software_AirPlayit"="c:\program files\Digiarty\Air_Playit\airplayit.exe" [2012-02-08 10468672]
"SAFE14 Browser Monitor"="c:\program files (x86)\Steganos Safe 14\SteganosBrowserMonitor.exe" [2012-10-02 71168]
"SkyDrive"="c:\users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" [2014-06-10 257224]
"iDevice Manager Launcher"="c:\program files (x86)\Software4u\iDevice Manager\Software4u.IDMLauncher.exe" [2014-03-15 139216]
"Klebezettel NG"="c:\program files (x86)\Klebezettel NG\klebez.exe" [2014-02-20 4418048]
"Rainlendar2"="c:\program files\Rainlendar2\Rainlendar2.exe" [2014-03-16 4411488]
"TomTomHOME.exe"="c:\program files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" [2014-06-05 248176]
"Freebie Notes"="c:\program files (x86)\Power Soft\Freebie Notes\FreebieNotes.exe" [2013-11-13 6343824]
"RocketDock"="c:\program files (x86)\RocketDock\RocketDock.exe" [2007-09-02 495616]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-09-05 937920]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2011-09-05 36760]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2011-09-05 2904984]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2014-05-07 256896]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-05-09 737872]
"BrMfcWnd"="c:\program files (x86)\Brother\Brmfcmon\BrMfcWnd.exe" [2009-08-03 1167360]
"ControlCenter3"="c:\program files (x86)\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688]
"IMSS"="c:\program files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [2013-01-23 113656]
"SAFE14 HotKeys"="c:\program files (x86)\Steganos Safe 14\SteganosHotKeyService.exe" [2012-10-02 84992]
"SAFE14 File Redirection Starter"="c:\program files (x86)\Steganos Safe 14\fredirstarter.exe" [2012-10-02 17408]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2014-05-26 152392]
.
c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
DeskSpace.lnk - c:\program files (x86)\DeskSpace\deskspace.exe [2012-5-28 9092816]
Dropbox.lnk - c:\users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-6-13 33322976]
.
c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled\
Logitech . Produktregistrierung.lnk - c:\program files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe /remind /language=DEU /_WFM="." [2009-11-16 517384]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Snagit 11.lnk - c:\program files (x86)\TechSmith\Snagit 11\Snagit32.exe [2013-1-25 9564528]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 O2SDIOAssist;O2SDIOAssist;c:\windows\SysWOW64\srvany.exe;c:\windows\SysWOW64\srvany.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 SLEE_17_DRIVER;Steganos Live Encryption Engine 17 [Driver];c:\windows\Sleen1764.sys;c:\windows\Sleen1764.sys [x]
S1 Uim_DEVIM;UIM Direct Device Image Plugin;c:\windows\system32\DRIVERS\uim_devim.sys;c:\windows\SYSNATIVE\DRIVERS\uim_devim.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe;c:\program files\IDT\WDM\AESTSr64.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 GatewayAgentService;O&O Gateway Agent Service;c:\program files (x86)\OO Software\Shared\GatewayAgent\ooemcgats.exe;c:\program files (x86)\OO Software\Shared\GatewayAgent\ooemcgats.exe [x]
S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 OODefragAgent;O&O Defrag;c:\program files\OO Software\Defrag\oodag.exe;c:\program files\OO Software\Defrag\oodag.exe [x]
S2 QDLService2kDell;Qualcomm Gobi 2000 Download Service (Dell);c:\program files (x86)\QUALCOMM\QDLService2k\QDLService2kDell.exe;c:\program files (x86)\QUALCOMM\QDLService2k\QDLService2kDell.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 WMCoreService;Mobile Broadband Service;c:\program files (x86)\Dell\Dell WWAN\WMCore\mini_WMCore.exe servicemode;c:\program files (x86)\Dell\Dell WWAN\WMCore\mini_WMCore.exe servicemode [x]
S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x]
S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXHWAZL.sys;c:\windows\SYSNATIVE\DRIVERS\CAXHWAZL.sys [x]
S3 d554gps;Dell Wireless HSPA Mini-Card GPS Port;c:\windows\system32\DRIVERS\d554gps64.sys;c:\windows\SYSNATIVE\DRIVERS\d554gps64.sys [x]
S3 d554scard;Dell Wireless HSPA Mini-Card USIM Port;c:\windows\system32\DRIVERS\d554scard.sys;c:\windows\SYSNATIVE\DRIVERS\d554scard.sys [x]
S3 ecnssndis; Mobile Broadband Driver;c:\windows\system32\Drivers\wwuss64.sys;c:\windows\SYSNATIVE\Drivers\wwuss64.sys [x]
S3 ecnssndisfltr; Mobile Broadband Driver Filter;c:\windows\system32\Drivers\wwussf64.sys;c:\windows\SYSNATIVE\Drivers\wwussf64.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGPBTDD;LGPBTDD.sys Display Driver;c:\windows\system32\Drivers\LGPBTDD.sys;c:\windows\SYSNATIVE\Drivers\LGPBTDD.sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 Mbm3CBus;Dell Wireless 5550 HSPA+ Mini-Card Device (WDM);c:\windows\system32\DRIVERS\Mbm3CBus.sys;c:\windows\SYSNATIVE\DRIVERS\Mbm3CBus.sys [x]
S3 Mbm3DevMt;Dell Wireless HSPA Mini-Card Device Management Driver (WDM);c:\windows\system32\DRIVERS\Mbm3DevMt.sys;c:\windows\SYSNATIVE\DRIVERS\Mbm3DevMt.sys [x]
S3 Mbm3mdfl;Dell Wireless HSPA Mini-Card Modem Filter;c:\windows\system32\DRIVERS\Mbm3mdfl.sys;c:\windows\SYSNATIVE\DRIVERS\Mbm3mdfl.sys [x]
S3 Mbm3Mdm;Dell Wireless HSPA Mini-Card Modem Driver;c:\windows\system32\DRIVERS\Mbm3Mdm.sys;c:\windows\SYSNATIVE\DRIVERS\Mbm3Mdm.sys [x]
S3 O2MDRRDR;O2MDRRDR;c:\windows\system32\DRIVERS\O2MDRw7x64.sys;c:\windows\SYSNATIVE\DRIVERS\O2MDRw7x64.sys [x]
S3 O2SDJRDR;O2SDJRDR;c:\windows\system32\DRIVERS\o2sdjw7x64.sys;c:\windows\SYSNATIVE\DRIVERS\o2sdjw7x64.sys [x]
S3 WwanUsbServ;Mobile Broadband Driver;c:\windows\system32\DRIVERS\WwanUsbMp64.sys;c:\windows\SYSNATIVE\DRIVERS\WwanUsbMp64.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - MBAMSWISSARMY
.
Inhalt des "geplante Tasks" Ordners
.
2014-06-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-07 08:14]
.
2014-06-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-06-06 19:26]
.
2014-06-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-06-06 19:26]
.
2014-06-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4212815359-2683884995-303209184-1000Core.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2014-06-08 14:40]
.
2014-06-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4212815359-2683884995-303209184-1000UA.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2014-06-08 14:40]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2014-06-10 22:43 262344 ----a-w- c:\users\User\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2014-06-10 22:43 262344 ----a-w- c:\users\User\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2014-06-10 22:43 262344 ----a-w- c:\users\User\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2012-10-01 18:37 2322576 ----a-w- c:\progra~1\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2012-10-01 18:37 2322576 ----a-w- c:\progra~1\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2012-10-01 18:37 2322576 ----a-w- c:\progra~1\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2014-05-28 23:44 164016 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2014-05-28 23:44 164016 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2014-05-28 23:44 164016 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2014-05-28 23:44 164016 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2014-01-29 171992]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2014-01-29 399832]
"Persistence"="c:\windows\system32\igfxpers.exe" [2014-01-29 442328]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2014-04-15 10396440]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2013-07-08 708952]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2014-05-19 3100440]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-01-25 525312]
"IntelPROSet"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2012-08-23 4805936]
"OODefragTray"="c:\program files\OO Software\Defrag\oodtray.exe" [2010-09-10 4041032]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.dell.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: An OneNote s&enden - c:\progra~1\MICROS~1\Office15\ONBttnIE.dll/105
IE: An vorhandene PDF-Datei anfügen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: In Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Linkziel in Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~1\Office15\EXCEL.EXE/3000
Trusted Zone: dell.com
TCP: DhcpNameServer = 192.168.1.1
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\7sap0mbh.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
HKLM_Wow6432Node-ActiveSetup-{8A69D345-D564-463c-AFF1-A69D9E530F96} - c:\program files (x86)\Google\Chrome\Application\35.0.1916.114\Installer\chrmstp.exe
AddRemove-{10CD364B-FFCC-48BE-B469-B9622A033075} - c:\programdata\{A3A26C56-02C3-4F76-A033-12EE2FB52AE6}\Fences.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-4212815359-2683884995-303209184-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{094A5CB4-8F65-CA76-E9C0-9BAAA959DAE9}*]
"haocmcfhhmdjjknl"=hex:6e,62,68,65,6a,70,63,6c,6f,70,6b,65,62,70,63,6e,68,66,
6f,6f,63,68,70,69,67,6b,63,6b,70,65,65,69,70,70,6e,6d,61,6a,61,68,69,61,69,\
"jaocmcfhhmdjjknlmjcj"=hex:66,61,68,65,6c,70,6a,66,64,6b,63,61,00,17
"pagclifnkganloilhdadgkoakfngdkko"=hex:64,61,67,65,63,70,70,69,00,6b
.
[HKEY_USERS\S-1-5-21-4212815359-2683884995-303209184-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C7B91D5D-1C71-F361-773C-520D2D16984E}*]
@Allowed: (Read) (RestrictedCode)
"bblnmfcklhgjeibaibcaoifnpebkocafhlem"=hex:6a,61,6b,67,69,67,61,70,70,6a,6c,6c,
6c,69,63,64,6a,70,61,6b,00,00
"abblchlihdgebpejfhicjkpfchdeahknhh"=hex:6a,61,70,68,6d,65,65,61,6e,6f,6d,6b,
62,67,66,64,65,61,70,6c,00,00
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG14.00.00.01PROFESSIONAL"="D137710F79ABC70AAB4FC9F95D87B38B2703DECB4AEC27CE5C4FDA25FB3958594D901C96B640DE9A058B130E7547D606D3CBAC9926C6117D915246F4F87CD808778E4469C0D444D9852D2105601B162DF7321D924881346B4E69F86E837324A6621F40A8DD3925DD0F2DA071066FC81B65DCD85CD7C8AFD8F508B26F2525C4B8A12208841572931086FD647A8EE5A8BFF4672DB3C17B085770195868A94D26954E703B44B33A862DD67E655CE954D7D97E63886AB3AA24CDA9F8F15EA0DB1AEA84539A424C7BD944EC09BCE5C943FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA9C6AECB7A5D1407A6A0AC4980AC79338EDD5E5BE2F6E667A6A0AC4980AC7933F454BF24F5E117E4EE02568FF4B47485BC8396D5E673495BA45FF22C8A440765B34A8CCAEB6E125B163D1C330585AAE974C6E4516171F23066B0BF65DEBAF996F7FE30C47428D6773C35875E0E36DB8B69EDA1A07653D5B314C6A49F51F0D410EC15DB1229E0105C92EF1FA1838ED2AAF709C30291F57AE7D155A964E7F8032C9E05CB2BC7802BE2B14B6CFDFC699D3EDFF7C624C3C8307C29E1D9AEC9F9B5F9FD1A3AF6327FD81793787C6C33B50D70457329AB40508AD984C846F2C42BDF3D617368576E6D0E3B957AE0D50778B71C2D02ECAF5F25E09936B68092CADABAEE02879B9AA66C05427A2DAF9A7BC6F855858399BC1D734E0A702FA2696E6AC139FC9A1C09A93239D569BA838E35CC6EE01B28B852987B322F4E0A46C2EA4FB5FBD3CA365BE609ECD1EB25F7F50249F9372477D96595112FBD49710D609B129A4BEB873B40F550A54671C0308ECF11C187B64A105D7D9C2D21446318F681CF38EC8E14FEDA11F82B77CAB65206AF89B0B24E4E70165A9BD57782B31130423B1BDD6A095B3F15890BDF2F820680DAAFF34EC88516E05E1D1A14AC88A329A61892CD0F502BF7841D97AA3A77F993AB91FCA36CC5A180DAC5AC7CCE5DFD711B40B39FF12BD00485606538E7B7DFCA205383AFDE39B22DC94E04ECD900558F312056EAEEADB0D46018CC9D1DBDEDA65CAB02A4AB5C7293C581DA52A194E0FB1D3B17FB403FB2CF8518EBA31ED4DC172665B468C2028AD28EC0B14FDE105BA4B724D551891BC2D005CB2445969F6B86E8E19F14F750A8FE0A804B3A2EBE84E77E06369E4F51D4A295B119351491594DB39187F5014001203E49AE1F8FBDA19E121EA04C7BC5590B90DAB4D68A746E3C397C778EF920C9B357B5A63B6802F88E373D41F459304C3DF36FA4C14FE3F31551BFBD13E2903D28A578C201FED056F6D64809E79D1DA865E1285AC49CD0368FF4896BED1F0999E21D53561881C68A07FEB8AA295B6BEE9FA0D389DD11018757441CD6BC755224BAD5A078D98050E7E4DE9B9FF00DCE"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-06-25 17:20:39
ComboFix-quarantined-files.txt 2014-06-25 15:20
.
Vor Suchlauf: 13 Verzeichnis(se), 103.209.177.088 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 102.934.028.288 Bytes frei
.
- - End Of File - - 620333D53EFD701F81F9B89797706E4B --- --- ---
A36C5E4F47E84449FF07ED3517B43A31 AdwareCleaner:
AdwCleaner Logfile: Code:
# AdwCleaner v3.213 - Bericht erstellt am 25/06/2014 um 17:29:31
# Aktualisiert 23/06/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : User - User-PC
# Gestartet von : D:\Desktop\adwcleaner_3.213.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\software4u
Ordner Gelöscht : C:\Program Files\003
Ordner Gelöscht : C:\Users\User\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\User\AppData\Roaming\software4u
Ordner Gelöscht : C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com
Ordner Gelöscht : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\obciceimmggglbmelaidpjlmodcebijb
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Mozilla Firefox v29.0.1 (de)
[ Datei : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\7sap0mbh.default\prefs.js ]
-\\ Google Chrome v37.0.2062.0
[ Datei : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [1624 octets] - [25/06/2014 17:26:46]
AdwCleaner[S0].txt - [1499 octets] - [25/06/2014 17:29:31]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1559 octets] ########## --- --- ---
[/CODE]
ESET Code:
ESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7587
# api_version=3.0.2
# EOSSerial=76172f0b884dc6409b2b8d51797865b9
# engine=18879
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-06-26 10:44:16
# local_time=2014-06-26 12:44:16 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Avira Desktop'
# compatibility_mode=1810 16777213 100 100 70525 4152454 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 1669658 155409306 0 0
# scanned=663225
# found=52
# cleaned=0
# scan_time=68867
sh=E9ADBE0526FFA374216D542E0D602E5533482114 ft=1 fh=df26b92e9b512772 vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\debutsetup_v1.64.exe"
sh=1E20CB8C6CFBC05671F0279F4580A6AD8DEE56DF ft=1 fh=9f5b6f0cc5235c49 vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\uninst.exe"
sh=F4D4A4EE23EC8D46EDE2205DDEDF978C96552103 ft=1 fh=86949fba87c26f28 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="D:\Desktop\WinHTTrack - CHIP-Installer.exe"
sh=BEE96291323D129CF104D0FA8ECBE8AAB5E4BCA5 ft=1 fh=c71c001156299171 vn="Win32/Toolbar.AskSBar evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\03 Work\_Desktop Werden\Programme\Nero Ultra Edition v8.0.3.0\Toolbar.exe"
sh=151DCF40EE9B65604F9DE2455FEB6A3773807702 ft=1 fh=bcde3234b1316e9a vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\Opera - CHIP-Installer.exe"
sh=F4D4A4EE23EC8D46EDE2205DDEDF978C96552103 ft=1 fh=86949fba87c26f28 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\WinHTTrack (Webseiten herunterladen).exe"
sh=ABA28F3F4E528B9388604DAA77FE8266DC389585 ft=0 fh=0000000000000000 vn="Variante von Java/Adwind.A Trojaner" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\Anwendungen Desktop\Rainmeter\Skins\WinEight\update\update.jar"
sh=E7218FC3731C96589F30B15429C25EDA9D0C5FC0 ft=1 fh=44f2b697800a060c vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\Brenner - Audio\DeepBurner.exe"
sh=2FFDED46BE3B96B3D8F482B3EF2193BB0A123203 ft=1 fh=8a8ff7b6b1b6c1cf vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\DVD brennen\Funktioniert\FreeVideoToDVDConverter16.exe"
sh=112A4F59BB998C0869312A6782CB240DA513091B ft=1 fh=ad42c3c8de114a8b vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\IPhone - Pad\NEU für IPad Sicherungen iDevice Manager - funktionert nicht\iDevice Manager iPhone Explorer - CHIP-Installer.exe"
sh=C3E986C9521A9B316233660D5928240CCE357CAA ft=1 fh=8962d531049041b4 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\Outlook Backups\MOBackup - CHIP-Installer.exe"
sh=F0C7E09D17BE5B2761E123DE2C0FCC13409A4BA5 ft=1 fh=2682b07d15fee4ab vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\PDF\GPL Ghostscript 64 Bit (für pdfCreator zur Berarbeitung von PDFs).exe"
sh=7AD95CB4E80B611C1FCCF5E00E31F3C5583EE2EE ft=1 fh=84a89a3586440c33 vn="Variante von Win32/DownloadGuide.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\PDF\pdfcreator 1.7.1 (druck in allen programmen).exe"
sh=3D42D88D50A2916D4A27360D5A5C62A1C09C1E41 ft=1 fh=922633ad68ab0444 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\Screenshots\ashampoo_magical (KOSTET Screenshots).exe"
sh=ACC0245A42DF227D4555733B4C8FD4AD92A1151B ft=1 fh=7b51f69847296fef vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\Video + Audio\cdex_151 (wandelt CDs in MP3s um).exe"
sh=73E38F87B22147BB82C7765F75863476E75B9B9A ft=1 fh=9b78355e12c22f81 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\Video + Audio\Bildschirm abfilmen\CamStudio.exe"
sh=B3F76FB12066DC4F51780F3F9DABA5A9018F359F ft=1 fh=70d549a263d539ed vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\Video + Audio\Bildschirm abfilmen\debut video capture\Debut Software NCH.exe"
sh=283FFF1CF5E5F24A6A15139BFFD1B1D35BCC0DEA ft=1 fh=bfa1a31277ad8659 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_Files\Joe 4.0 letzte Freeware Version.exe"
sh=D3E4D80B25C5C0A3AE4A8BBC9E61921669220515 ft=1 fh=2dc5b3d95d4c9a74 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_Grafik\NexusFont (Fontmanager).exe"
sh=A81179DF94786B3D660496244649BEFB2002FAFD ft=1 fh=def5dcfb798dceae vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_organisation + anwendungen\Freebie Notes.exe"
sh=E931C6BE4F9E345B13BD31494AA13C7575C15901 ft=1 fh=06d1cd4d498391bf vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_organisation + anwendungen\Microsoft OneDrive SkyDrive - CHIP-Downloader.exe"
sh=F1EFF6451CED129C0E5C0A510955F234A01158A0 ft=1 fh=332b4278a72373e2 vn="Variante von Win32/Toolbar.Babylon.E evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_organisation + anwendungen\Unlocker1.9.2.exe"
sh=07DA3014E64C489EDBFCEB7368B75D5ED6C44226 ft=1 fh=5c82542f3c4a0a82 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_organisation + anwendungen\_desktop\Fences Letzte Freeware Version - CHIP-Installer.exe"
sh=39E799BA9DB8D77D1E2EBE627FEDE0CF296CE507 ft=1 fh=7173b3d1c11879cb vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_organisation + anwendungen\_desktop\00 nich so gut\ObjectDock - kostet (mac symbolleiste).exe"
sh=131AC05ECFCA62EDFB1E32FD328882F6A13C9D9C ft=1 fh=c71c0011632e8e41 vn="Variante von Win32/InstallCore.OY evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_organisation + anwendungen\_desktop\00 nich so gut\3d innen desktop\Bumptop\BumpTop-2.1-6225_CB-DL-Manager.exe"
sh=0CDB92602B2949E323B9A3425D88EC67F7D63E6C ft=1 fh=149e7fc8a5c00a5b vn="Win32/Somoto.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_organisation + anwendungen\_desktop\00 nich so gut\3d innen desktop\RealDesktop - zu langsam\Real Desktop - Setup.exe"
sh=6F29A55425754BCE3B3EDCE785D19B2C963BC5C2 ft=1 fh=5121968bcf75aa90 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_organisation + anwendungen\_desktop\00 nich so gut\shock-4way 3d (zu alt)\Shock 4Way 3D - CHIP-Installer.exe"
sh=06E9852901075ED704156E475AA7479EF1603110 ft=1 fh=9aabfbcec36d2cff vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_organisation + anwendungen\_desktop\custo pack - windows design ändern zB mac\CustoPack Tools - komplettes design aendern, zb mac.exe"
sh=ABA28F3F4E528B9388604DAA77FE8266DC389585 ft=0 fh=0000000000000000 vn="Variante von Java/Adwind.A Trojaner" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_organisation + anwendungen\_desktop\Rainmeter\Skins\WinEight\update\update.jar"
sh=553AD70C9C2631D4A4BB06493D0C4C4321EC67FA ft=1 fh=f931597085596cad vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_organisation + anwendungen\_desktop\_mac symbolleiste\nexus\Nexus - CHIP-Installer.exe"
sh=E8F8988C24C2C10D08046AC288D9AC0C5885DFA6 ft=1 fh=24c7dbfe65e1b6e8 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_organisation + anwendungen\_desktop\_mac symbolleiste\rocket dock (mac leiste) auf 2. monitor\RocketDock.exe"
sh=40E7FA833F78CC5AD0985E375E8CDA6B06AB9101 ft=1 fh=15ab978f0cf13db0 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_organisation + anwendungen\_desktop\_Ordner HG ändern\AveFolderBG 64 Bit - CHIP-Installer.exe"
sh=8E0464F82EF6BEE018BED978114482231F417397 ft=1 fh=afc34fcb5e4fd155 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_organisation + anwendungen\_desktop\_Ordner HG ändern\Windows 7 Folder Background Changer - CHIP-Installer.exe"
sh=D680C4BBB1694BF4EF4A92C186AA2F32BA0B8D81 ft=1 fh=62fcaf095a9bce76 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_organisation + anwendungen\_desktop\_windows 7 design ändern - Themes\Universal Theme Patcher - CHIP-Installer.exe"
sh=D65437677AD4DFA5AE4D0BA99FCC013CFD8A7336 ft=1 fh=3b42b0edc9ae71ea vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_Sicherheit, System & Schnelligkeit\LogMeIn Hamachi (VPN - versuchen).exe"
sh=F8119CA23D07A0BECEFF7350D9231FCB9382157C ft=1 fh=e32d2a098e2721d9 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_Sicherheit, System & Schnelligkeit\Tor Browser Paket - CHIP-Installer.exe"
sh=ABE731BA3E5E92912CF0C3B6075973A954D2A467 ft=1 fh=0ddcd826aafc1859 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_Sicherheit, System & Schnelligkeit\WOT_web_of_trust_wot-20131118-fx - CHIP-Installer.exe"
sh=2E61DB8A6F9EC5473B422648BDAB2B7640897EEC ft=1 fh=7a3c667d2961cc05 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_Sicherheit, System & Schnelligkeit\XPAntiSpy (verhindert datensendung an ms).exe"
sh=22F7B6545EB7CB7466811EA971232F98F506C2E5 ft=1 fh=e091c27eb3bb786c vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_Sicherheit, System & Schnelligkeit\deinstalliert programme vollständig\Revo Uninstaller - CHIP-Installer.exe"
sh=015D22927D0FD1276B1548AF527130144AB66097 ft=1 fh=72c3fc454c4cc8d3 vn="Variante von Win32/RegistryBooster evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_Sicherheit, System & Schnelligkeit\Pc Scan Systemfehler\registrybooster.exe"
sh=ABA28F3F4E528B9388604DAA77FE8266DC389585 ft=0 fh=0000000000000000 vn="Variante von Java/Adwind.A Trojaner" ac=I fn="E:\Dokumente - Bilder - Work - Inst\Eigene Dokumente\Rainmeter\Skins\WinEight\update\update.jar"
sh=282E43766D30716E793A5122951C2AE76FD8CBCC ft=0 fh=0000000000000000 vn="Win32/DealPly.J evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\Eigene Dokumente\_Programme und Sicherungen\Firefox Lesezeichen\7otfhij7.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}\chrome\content\dealply.xul"
sh=282E43766D30716E793A5122951C2AE76FD8CBCC ft=0 fh=0000000000000000 vn="Win32/DealPly.J evtl. unerwünschte Anwendung" ac=I fn="E:\Dokumente - Bilder - Work - Inst\Eigene Dokumente\_Programme und Sicherungen\Firefox Profil\Profiles\7otfhij7.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}\chrome\content\dealply.xul"
sh=F57E3DF68511ACE24BDDC793426A09BCAD05450D ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="E:\User-PC\Backup Set 2014-06-06 205132\Backup Files 2014-06-06 205132\Backup files 26.zip"
sh=77BA3C6294D4542BAF01908D7D8AAE652C160DE1 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.H evtl. unerwünschte Anwendung" ac=I fn="E:\User-PC\Backup Set 2014-06-06 205132\Backup Files 2014-06-08 080001\Backup files 2.zip"
sh=B8E5778B5922FAAC5C1DE225D85930F8184DC48A ft=0 fh=0000000000000000 vn="HTML/ScrInject.B.Gen Virus" ac=I fn="E:\User-PC\Backup Set 2014-06-06 205132\Backup Files 2014-06-22 080001\Backup files 4.zip"
sh=AA4BFDD1F8EB93F8E293233153905CA67B7F5F7D ft=0 fh=0000000000000000 vn="Win32/Somoto.G evtl. unerwünschte Anwendung" ac=I fn="E:\User-PC\Backup Set 2014-06-06 205132\Backup Files 2014-06-22 080001\Backup files 5.zip" Malwarebytes Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 26.06.2014
Suchlauf-Zeit: 13:38:40
Logdatei: 'Malwarebytes-log.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.26.03
Rootkit Datenbank: v2014.06.23.02
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: User
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 292857
Verstrichene Zeit: 5 Min, 19 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 0
(No malicious items detected)
Dateien: 0
(No malicious items detected)
Physische Sektoren: 0
(No malicious items detected)
(end) Folgende Datei habe ich gelöscht:
sh=ABA28F3F4E528B9388604DAA77FE8266DC389585 ft=0 fh=0000000000000000 vn="Variante von Java/Adwind.A Trojaner" ac=I fn="E:\Dokumente - Bilder - Work - Inst\04 Installationsprogramme\_organisation + anwendungen\_desktop\Rainmeter\Skins\WinEight\update\update.jar"
Folgende war nicht zu finden: sh=B8E5778B5922FAAC5C1DE225D85930F8184DC48A ft=0 fh=0000000000000000 vn="HTML/ScrInject.B.Gen Virus" ac=I fn="E:\User-PC\Backup Set 2014-06-06 205132\Backup Files 2014-06-22 080001\Backup files 4.zip"
War das richtig? :wtf::heilig:
Temp File Cleaner hab ich laufen lassen und dann wollt ich jetzt noch mal Malewarebytes und Antivir laufen lassen. Aber warte erstmal auf deine Antwort... |