Hallo
Combofix lief durch, nach Neustart habe ich jedoch immer noch dieses Piepen. Code:
ComboFix 14-10-15.01 - vinzelberg 15.10.2014 10:49:45.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3933.2742 [GMT 2:00]
ausgeführt von:: f:\viren\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\DSC_0687.jpg
c:\program files (x86)\PriceLess
c:\program files (x86)\PriceLess\Uf.dat
c:\program files (x86)\PriceLess\Uf.tlb
c:\programdata\PriceLess
c:\programdata\PriceLess\Cko.dat
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\background.html
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\content.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\GtXz0qj.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\lsdb.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\background.html
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\content.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\GtXz0qj.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\background.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\content.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\GtXz0qj.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\manifest.json
c:\users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj
c:\users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\background.html
c:\users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\content.js
c:\users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\GtXz0qj.js
c:\users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\lsdb.js
c:\users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\manifest.json
c:\users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj
c:\users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\background.html
c:\users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\content.js
c:\users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\GtXz0qj.js
c:\users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\lsdb.js
c:\users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\manifest.json
c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj
c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\background.html
c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\content.js
c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\GtXz0qj.js
c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\lsdb.js
c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\background.html
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\content.js
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\GtXz0qj.js
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\GtXz0qj.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\GtXz0qj.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\manifest.json
c:\users\vinzelberg\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj
c:\users\vinzelberg\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\background.html
c:\users\vinzelberg\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\content.js
c:\users\vinzelberg\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\GtXz0qj.js
c:\users\vinzelberg\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\lsdb.js
c:\users\vinzelberg\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\manifest.json
c:\users\vinzelberg\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj
c:\users\vinzelberg\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\background.html
c:\users\vinzelberg\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\content.js
c:\users\vinzelberg\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\GtXz0qj.js
c:\users\vinzelberg\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\lsdb.js
c:\users\vinzelberg\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\manifest.json
c:\users\vinzelberg\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj
c:\users\vinzelberg\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\background.html
c:\users\vinzelberg\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\content.js
c:\users\vinzelberg\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\GtXz0qj.js
c:\users\vinzelberg\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\lsdb.js
c:\users\vinzelberg\AppData\Local\Google\Chrome\User Data\Default\Extensions\egppalejglgnodakjglepgajmlbdminj\5.2\manifest.json
c:\users\vinzelberg\AppData\Local\nsp4C11.tmp
c:\users\vinzelberg\AppData\Roaming\2433f433
c:\users\vinzelberg\AppData\Roaming\Mozilla\Firefox\Profiles\5bnvv592.default\extensions\iea-30@ewfrkcbyjjmb.co.uk
c:\users\vinzelberg\AppData\Roaming\Mozilla\Firefox\Profiles\5bnvv592.default\extensions\iea-30@ewfrkcbyjjmb.co.uk\bootstrap.js
c:\users\vinzelberg\AppData\Roaming\Mozilla\Firefox\Profiles\5bnvv592.default\extensions\iea-30@ewfrkcbyjjmb.co.uk\chrome.manifest
c:\users\vinzelberg\AppData\Roaming\Mozilla\Firefox\Profiles\5bnvv592.default\extensions\iea-30@ewfrkcbyjjmb.co.uk\content\bg.js
c:\users\vinzelberg\AppData\Roaming\Mozilla\Firefox\Profiles\5bnvv592.default\extensions\iea-30@ewfrkcbyjjmb.co.uk\install.rdf
c:\users\vinzelberg\IE11-Windows6.1-x64-de-de (1).exe
c:\users\vinzelberg\Setup.exe
c:\windows\security\Database\tmp.edb
D:\install.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-09-15 bis 2014-10-15 ))))))))))))))))))))))))))))))
.
.
2014-10-15 08:55 . 2014-10-15 08:55 -------- d-----w- c:\users\Gast\AppData\Local\temp
2014-10-15 08:55 . 2014-10-15 08:55 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-10-15 08:54 . 2014-10-15 08:54 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{330EF92F-CD56-43A6-AD41-DE9FF82D1898}\offreg.dll
2014-10-15 08:09 . 2014-10-15 08:10 -------- d-----w- C:\FRST
2014-10-15 06:50 . 2014-10-15 06:50 -------- d-----w- c:\windows\ERUNT
2014-10-15 06:33 . 2014-10-15 06:33 -------- d-----w- c:\windows\SysWow64\wbem\Logs
2014-10-14 14:46 . 2014-10-15 07:59 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0
2014-10-14 10:58 . 2014-09-09 02:05 11578928 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{330EF92F-CD56-43A6-AD41-DE9FF82D1898}\mpengine.dll
2014-10-05 13:31 . 2013-12-10 23:48 38200 ----a-w- c:\windows\system32\uxt4568.tmp
2014-10-05 13:28 . 2014-10-05 13:28 -------- d-----w- c:\users\vinzelberg\AppData\Roaming\TuneUp Software
2014-10-05 13:25 . 2014-10-15 08:00 -------- d-----w- c:\programdata\TuneUp Software
2014-10-05 13:25 . 2014-10-05 13:37 -------- d-sh--w- c:\programdata\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
2014-10-05 13:06 . 2014-10-05 13:06 -------- d-----w- c:\users\vinzelberg\AppData\Roaming\COMPUTER BILD PC-Aufräumer 2014
2014-10-02 09:46 . 2014-09-25 02:08 371712 ----a-w- c:\windows\system32\qdvd.dll
2014-10-02 09:46 . 2014-09-25 01:40 519680 ----a-w- c:\windows\SysWow64\qdvd.dll
2014-09-25 09:41 . 2014-09-09 22:11 2048 ----a-w- c:\windows\system32\tzres.dll
2014-09-25 09:41 . 2014-09-09 21:47 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2014-09-22 10:27 . 2014-09-22 10:27 6144 ----a-w- c:\windows\system32\HdmiCoin.dll
2014-09-22 10:27 . 2014-09-22 10:27 145408 ----a-w- c:\windows\system32\drivers\IntcHdmi.sys
2014-09-22 09:51 . 2014-09-22 09:51 -------- d-----w- c:\users\vinzelberg\AppData\Roaming\ProductData
2014-09-22 09:50 . 2014-09-22 09:50 -------- d-----w- c:\users\vinzelberg\AppData\Roaming\Apple Computer
2014-09-22 09:49 . 2014-09-22 09:49 -------- d-----w- c:\programdata\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2014-09-22 09:49 . 2014-09-22 09:49 -------- d-----w- c:\programdata\ProductData
2014-09-22 09:49 . 2014-09-22 09:49 73800 ----a-w- c:\windows\system32\RtNicProp64.dll
2014-09-22 09:49 . 2014-09-22 09:49 941272 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2014-09-22 09:39 . 2014-09-22 09:39 14952 ----a-w- c:\windows\system32\RtkCoLDR64.dll
2014-09-22 09:29 . 2014-09-22 09:29 90112 ----a-w- c:\windows\system32\igfxCoIn_v2869.dll
2014-09-22 09:27 . 2014-09-22 09:27 -------- d-----w- c:\program files\Synaptics
2014-09-22 09:27 . 2014-09-22 09:27 1795952 ----a-w- c:\windows\system32\WdfCoInstaller01011.dll
2014-09-22 09:27 . 2014-09-22 09:27 34544 ----a-w- c:\windows\system32\drivers\Smb_driver_Intel.sys
2014-09-22 09:21 . 2014-09-22 09:49 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2014-09-22 09:17 . 2014-09-23 07:51 -------- d-----w- c:\programdata\IObit
2014-09-22 09:17 . 2014-09-22 09:49 -------- d-----w- c:\users\vinzelberg\AppData\Roaming\IObit
2014-09-22 09:17 . 2014-10-04 08:19 -------- d-----w- c:\program files (x86)\IObit
2014-09-21 19:50 . 2014-10-15 07:57 -------- d-----w- c:\program files (x86)\HD-Quality-v3
2014-09-20 07:54 . 2014-09-20 07:54 -------- d-----w- c:\programdata\532605f3fe317669
2014-09-20 07:54 . 2014-09-20 07:54 -------- d-----w- c:\users\vinzelberg\AppData\Local\Comodo
2014-09-20 07:54 . 2014-09-20 07:54 -------- d-----w- c:\users\Gast\AppData\Local\Comodo
2014-09-20 07:54 . 2014-09-20 07:54 -------- d-----w- c:\users\Administrator\AppData\Local\Comodo
2014-09-20 07:54 . 2014-09-20 07:54 -------- d-----w- c:\users\Gast\AppData\Local\Google
2014-09-20 07:54 . 2014-09-20 07:54 -------- d-----w- c:\users\HomeGroupUser$
2014-09-20 07:54 . 2014-09-20 07:54 -------- d-----w- c:\users\Administrator\AppData\Local\Google
2014-09-17 13:58 . 2014-09-20 08:08 -------- d--h--w- c:\users\Public\Temp
2014-09-17 13:57 . 2014-10-04 08:31 -------- d-----w- c:\program files (x86)\videos+ MediaPlayer+
2014-09-16 10:51 . 2014-09-17 09:19 -------- d-----w- c:\programdata\Kaspersky Lab
2014-09-16 10:38 . 2014-09-16 10:40 176562784 ----a-w- c:\users\vinzelberg\kis15.0.0.463de_6508.exe
2014-09-15 08:59 . 2014-09-17 09:27 -------- d-----w- c:\program files (x86)\G Data
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-09-22 09:29 . 2009-11-24 20:35 953912 ----a-w- c:\windows\SysWow64\igxpun.exe
2014-09-22 09:29 . 2009-08-27 06:53 4722176 ----a-w- c:\windows\system32\igd10umd64.dll
2014-09-15 07:06 . 2010-02-08 10:56 278152 ------w- c:\windows\system32\MpSigStub.exe
2014-09-12 07:43 . 2010-06-09 15:10 101694776 ----a-w- c:\windows\system32\MRT.exe
2014-09-05 02:10 . 2014-09-12 07:25 578048 ----a-w- c:\windows\system32\aepdu.dll
2014-09-05 02:05 . 2014-09-12 07:25 424448 ----a-w- c:\windows\system32\aeinv.dll
2014-09-03 08:47 . 2011-03-28 16:36 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-08-23 02:07 . 2014-09-01 12:03 404480 ----a-w- c:\windows\system32\gdi32.dll
2014-08-23 01:45 . 2014-09-01 12:03 311808 ----a-w- c:\windows\SysWow64\gdi32.dll
2014-08-23 00:59 . 2014-09-01 12:03 3163648 ----a-w- c:\windows\system32\win32k.sys
2014-08-11 10:15 . 2010-03-24 11:58 737280 ----a-w- c:\windows\iun6002.exe
2014-08-01 11:53 . 2014-09-12 07:26 1031168 ----a-w- c:\windows\system32\TSWorkspace.dll
2014-08-01 11:35 . 2014-09-12 07:26 793600 ----a-w- c:\windows\SysWow64\TSWorkspace.dll
2014-07-31 23:41 . 2014-08-14 06:21 348856 ----a-w- c:\windows\system32\iedkcs32.dll
2014-07-25 14:52 . 2014-08-14 06:21 23645696 ----a-w- c:\windows\system32\mshtml.dll
2014-07-25 14:02 . 2014-08-14 06:21 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-07-25 14:01 . 2014-08-14 06:21 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2014-07-25 13:30 . 2014-08-14 06:21 66048 ----a-w- c:\windows\system32\iesetup.dll
2014-07-25 13:28 . 2014-08-14 06:21 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll
2014-07-25 13:28 . 2014-08-14 06:21 548352 ----a-w- c:\windows\system32\vbscript.dll
2014-07-25 13:25 . 2014-08-14 06:21 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2014-07-25 13:25 . 2014-08-14 06:21 2774528 ----a-w- c:\windows\system32\iertutil.dll
2014-07-25 13:11 . 2014-08-14 06:21 51200 ----a-w- c:\windows\system32\jsproxy.dll
2014-07-25 13:10 . 2014-08-14 06:21 33792 ----a-w- c:\windows\system32\iernonce.dll
2014-07-25 13:04 . 2014-08-14 06:21 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2014-07-25 13:03 . 2014-08-14 06:21 598016 ----a-w- c:\windows\system32\ieui.dll
2014-07-25 13:00 . 2014-08-14 06:21 139264 ----a-w- c:\windows\system32\ieUnatt.exe
2014-07-25 13:00 . 2014-08-14 06:21 111616 ----a-w- c:\windows\system32\ieetwcollector.exe
2014-07-25 12:59 . 2014-08-14 06:21 758272 ----a-w- c:\windows\system32\jscript9diag.dll
2014-07-25 12:47 . 2014-08-14 06:21 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-07-25 12:40 . 2014-08-14 06:21 452096 ----a-w- c:\windows\system32\dxtmsft.dll
2014-07-25 12:34 . 2014-08-14 06:21 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2014-07-25 12:34 . 2014-08-14 06:21 455168 ----a-w- c:\windows\SysWow64\vbscript.dll
2014-07-25 12:33 . 2014-08-14 06:21 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2014-07-25 12:30 . 2014-08-14 06:21 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2014-07-25 12:28 . 2014-08-14 06:21 5824512 ----a-w- c:\windows\system32\jscript9.dll
2014-07-25 12:28 . 2014-08-14 06:21 72704 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2014-07-25 12:19 . 2014-08-14 06:21 195584 ----a-w- c:\windows\system32\msrating.dll
2014-07-25 12:17 . 2014-08-14 06:21 85504 ----a-w- c:\windows\system32\mshtmled.dll
2014-07-25 12:10 . 2014-08-14 06:21 292864 ----a-w- c:\windows\system32\dxtrans.dll
2014-07-25 12:10 . 2014-08-14 06:21 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2014-07-25 12:08 . 2014-08-14 06:21 597504 ----a-w- c:\windows\SysWow64\jscript9diag.dll
2014-07-25 12:06 . 2014-08-14 06:21 4204032 ----a-w- c:\windows\SysWow64\jscript9.dll
2014-07-25 11:47 . 2014-08-14 06:21 631808 ----a-w- c:\windows\system32\msfeeds.dll
2014-07-25 11:43 . 2014-08-14 06:21 60416 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2014-07-25 11:42 . 2014-08-14 06:21 692736 ----a-w- c:\windows\system32\ie4uinit.exe
2014-07-25 11:39 . 2014-08-14 06:21 2087936 ----a-w- c:\windows\system32\inetcpl.cpl
2014-07-25 11:39 . 2014-08-14 06:21 1249280 ----a-w- c:\windows\system32\mshtmlmedia.dll
2014-07-25 11:23 . 2014-08-14 06:21 13547008 ----a-w- c:\windows\system32\ieframe.dll
2014-07-25 11:07 . 2014-08-14 06:21 2001920 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2014-07-25 11:07 . 2014-08-14 06:21 1068032 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2014-07-25 10:52 . 2014-08-14 06:21 2266624 ----a-w- c:\windows\system32\wininet.dll
2014-07-25 10:26 . 2014-08-14 06:21 1431040 ----a-w- c:\windows\system32\urlmon.dll
2014-07-25 10:17 . 2014-08-14 06:21 846336 ----a-w- c:\windows\system32\ieapfltr.dll
2014-07-25 10:05 . 2014-08-14 06:21 1792512 ----a-w- c:\windows\SysWow64\wininet.dll
2014-07-25 00:35 . 2014-07-25 00:35 875688 ----a-w- c:\windows\SysWow64\msvcr120_clr0400.dll
2014-07-24 21:47 . 2014-07-24 21:47 869544 ----a-w- c:\windows\system32\msvcr120_clr0400.dll
2014-07-21 16:07 . 2012-01-28 15:35 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2014-07-21 16:07 . 2012-01-28 15:35 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2009-12-26 21:43 . 2014-09-13 16:13 245760 ----a-w- c:\program files (x86)\Uninstall Ask Toolbar.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2009-08-12 352256]
"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2009-06-02 423936]
"KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2009-01-13 34088]
.
c:\users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
.
c:\users\vinzelberg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2009-2-26 97680]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 BrYNSvc;BrYNSvc;c:\program files (x86)\Browny02\BrYNSvc.exe;c:\program files (x86)\Browny02\BrYNSvc.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys;c:\windows\SYSNATIVE\DRIVERS\psi_mf.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys;c:\windows\SYSNATIVE\DRIVERS\Rts516xIR.sys [x]
R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R4 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
R4 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe;c:\program files (x86)\Secunia\PSI\PSIA.exe [x]
S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys;c:\windows\SYSNATIVE\DRIVERS\tos_sps64.sys [x]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [x]
S2 ConfigFree Gadget Service;ConfigFree Gadget Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe;c:\program files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe [x]
S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [x]
S2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe;c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [x]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe;c:\program files\TOSHIBA\TECO\TecoService.exe [x]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys;c:\windows\SYSNATIVE\DRIVERS\TVALZFL.sys [x]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys;c:\windows\SYSNATIVE\drivers\IntcHdmi.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8187B.sys [x]
S3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys [x]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [x]
S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [x]
.
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2009-08-13 570680]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2009-08-05 497504]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2014-09-22 13672152]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-03 709976]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2009-08-06 1050000]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaReminder.exe" [2009-07-30 134032]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2014-09-22 163384]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2014-09-22 387640]
"Persistence"="c:\windows\system32\igfxpers.exe" [2014-09-22 418360]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
mDefault_Page_URL = hxxp://www.google.com
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:14144;https=127.0.0.1:14144
uSearchAssistant = hxxp://www.google.com
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.192.241
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-10 - (no file)
SafeBoot-mcmscsvc
SafeBoot-MCODS
BHO-{11111111-1111-1111-1111-110611421101} - (no file)
Toolbar-10 - (no file)
HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe
HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe
AddRemove-Hornil StylePix - c:\program files\Hornil\StylePix\Uninstall.exe
AddRemove-SmootherWeb - c:\smootherweb\Uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,46,82,ad,b0,76,b4,f8,4f,a5,bc,60,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,46,82,ad,b0,76,b4,f8,4f,a5,bc,60,\
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10w_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10w_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-10-15 10:57:44
ComboFix-quarantined-files.txt 2014-10-15 08:57
.
Vor Suchlauf: 17 Verzeichnis(se), 188.204.580.864 Bytes frei
Nach Suchlauf: 20 Verzeichnis(se), 187.799.412.736 Bytes frei
.
- - End Of File - - F3913521372F7AF8D1D407D0FA2E62B1
A36C5E4F47E84449FF07ED3517B43A31 Problem gelöst.
Scheinbar muss ADW Cleaner irgendwas im Soundtreiber gelöscht haben, bzw eine Schadsoftware hatte dort Wurzeln geschlagen.
Habe nun einfach den Soundtreiber deinstalliert und neu installiert und nun sind die Logs sauber und die Ohren tun nicht mehr weh :taenzer:
Dankesehr für die Hilfe |