Coffeetogo | 02.04.2015 21:37 | Großes Dankeschön :) Code:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015
Ran by Ringo at 2015-04-02 21:59:48 Run:1
Running from C:\Users\Ringo\Desktop
Loaded Profiles: Ringo (Available profiles: Ringo)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
HKLM Group Policy restriction on software: C:\Program Files (x86)\Common Files\G DATA <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Avira <====== ATTENTION
HKLM Group Policy restriction on software: C:\Program Files (x86)\Symantec <====== ATTENTION
HKLM Group Policy restriction on software: C:\Program Files\Avira <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\G DATA <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Symantec <====== ATTENTION
HKLM Group Policy restriction on software: C:\Program Files (x86)\G DATA <====== ATTENTION
*****************
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
==== End of Fixlog 21:59:48 ==== Avira konnte ich nicht deaktivieren, Combofixwarnung, hier der Log. Code:
ComboFix 15-04-01.01 - Ringo 02.04.2015 22:04:59.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3946.2654 [GMT 2:00]
ausgeführt von:: c:\users\Ringo\Desktop\ComboFix.exe
AV: Avira Antivirus *Enabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Antivirus *Enabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\INSTALL.LOG
c:\windows\IsUn0407.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2015-03-02 bis 2015-04-02 ))))))))))))))))))))))))))))))
.
.
2015-04-02 20:18 . 2015-04-02 20:18 -------- d-----w- c:\program files (x86)\Avira
2015-04-02 15:05 . 2015-04-02 19:59 -------- d-----w- C:\FRST
2015-04-02 13:09 . 2015-04-02 13:09 -------- d-----w- c:\users\Ringo\AppData\Roaming\InstallShield
2015-04-01 16:05 . 2015-04-01 16:05 -------- d-----w- C:\RegBackup
2015-03-30 15:38 . 2015-04-01 17:23 136408 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-03-30 15:37 . 2015-03-17 04:15 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2015-03-30 15:37 . 2015-03-17 04:15 107736 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-03-30 15:37 . 2015-03-17 04:15 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2015-03-30 15:37 . 2015-03-30 15:37 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2015-03-30 15:37 . 2015-03-30 15:37 -------- d-----w- c:\programdata\Malwarebytes
2015-03-29 23:02 . 2015-03-29 23:02 -------- d-----w- c:\users\Ringo\AppData\Roaming\AMD
2015-03-29 22:52 . 2015-03-29 22:52 -------- d-----w- c:\programdata\ATI
2015-03-29 22:51 . 2015-03-29 22:51 -------- d-----w- c:\users\Ringo\AppData\Roaming\library_dir
2015-03-29 22:50 . 2015-03-29 22:50 -------- d-----w- c:\programdata\AMD
2015-03-29 22:50 . 2015-03-29 22:50 -------- d-----w- c:\program files (x86)\AMD AVT
2015-03-29 22:47 . 2015-03-29 22:47 -------- d-----w- c:\program files (x86)\AMD
2015-03-29 22:40 . 2015-03-29 22:40 -------- d-----w- c:\windows\SysWow64\wbem\it-IT
2015-03-29 22:40 . 2015-03-29 22:40 -------- d-----w- c:\windows\SysWow64\wbem\fr-FR
2015-03-29 22:40 . 2015-03-29 22:40 -------- d-----w- c:\windows\system32\wbem\it-IT
2015-03-29 22:40 . 2015-03-29 22:40 -------- d-----w- c:\windows\system32\wbem\fr-FR
2015-03-29 22:38 . 2015-04-02 20:18 -------- d-----w- c:\programdata\Package Cache
2015-03-29 22:38 . 2015-03-29 22:42 -------- d-----w- c:\program files\AMD
2015-03-29 18:31 . 2015-03-30 16:15 -------- d-----w- C:\AdwCleaner
2015-03-29 18:00 . 2015-03-29 18:11 -------- d-----w- c:\program files\PC Health Advisor
2015-03-26 15:27 . 2015-03-26 15:27 -------- d-----w- C:\DAEMON Tools Lite
2015-03-25 11:32 . 2015-03-11 04:06 677888 ----a-w- c:\windows\system32\generaltel.dll
2015-03-25 11:32 . 2015-03-11 04:06 760832 ----a-w- c:\windows\system32\invagent.dll
2015-03-25 11:32 . 2015-03-11 04:06 414720 ----a-w- c:\windows\system32\devinv.dll
2015-03-25 11:32 . 2015-03-11 04:06 943616 ----a-w- c:\windows\system32\appraiser.dll
2015-03-25 11:32 . 2015-03-11 04:05 30720 ----a-w- c:\windows\system32\acmigration.dll
2015-03-25 11:32 . 2015-03-11 04:05 227328 ----a-w- c:\windows\system32\aepdu.dll
2015-03-25 11:32 . 2015-03-11 04:02 1107456 ----a-w- c:\windows\system32\aeinv.dll
2015-03-25 11:32 . 2015-03-11 04:05 192000 ----a-w- c:\windows\system32\aepic.dll
2015-03-12 13:12 . 2015-03-12 13:12 -------- d-----w- c:\windows\Grim Tales 6 - The Vengeance Collectors Edition
2015-03-11 10:00 . 2015-01-31 03:48 3179520 ----a-w- c:\windows\system32\rdpcorets.dll
2015-03-11 10:00 . 2015-01-31 03:48 16384 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2015-03-11 10:00 . 2015-01-30 23:56 243200 ----a-w- c:\windows\system32\rdpudd.dll
2015-03-11 10:00 . 2015-02-03 03:31 215552 ----a-w- c:\windows\system32\ubpm.dll
2015-03-11 10:00 . 2015-02-03 03:12 171520 ----a-w- c:\windows\SysWow64\ubpm.dll
2015-03-11 10:00 . 2015-02-13 05:22 14177280 ----a-w- c:\windows\system32\shell32.dll
2015-03-06 22:21 . 2015-03-06 22:21 0 ----a-w- c:\windows\SysWow64\RENCFD1.tmp
2015-03-06 22:16 . 2015-03-06 22:16 -------- d-----w- c:\program files (x86)\Common Files\Java
2015-03-06 20:56 . 2015-03-06 20:56 -------- d-----w- C:\SymCache
2015-03-03 20:49 . 2015-01-09 03:14 91136 ----a-w- c:\windows\system32\wdi.dll
2015-03-03 20:49 . 2015-01-09 03:14 950272 ----a-w- c:\windows\system32\perftrack.dll
2015-03-03 20:49 . 2015-01-09 03:14 29696 ----a-w- c:\windows\system32\powertracker.dll
2015-03-03 20:49 . 2015-01-09 02:48 76800 ----a-w- c:\windows\SysWow64\wdi.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-03-18 17:56 . 2012-04-03 04:20 778928 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2015-03-18 17:56 . 2011-05-18 15:17 142512 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-03-11 11:55 . 2011-04-28 13:07 122905848 ----a-w- c:\windows\system32\MRT.exe
2015-03-06 22:13 . 2014-07-17 21:44 111016 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2015-03-04 10:25 . 2013-12-12 08:31 44088 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2015-03-04 10:25 . 2013-12-12 08:31 132120 ----a-w- c:\windows\system32\drivers\avipbb.sys
2015-03-04 10:25 . 2013-12-12 08:31 128536 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2015-01-27 23:36 . 2015-02-11 10:05 1239720 ----a-w- c:\windows\system32\aitstatic.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2013-05-08 41056]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2015-04-01 726320]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2015-02-10 335232]
"StartCCC"="c:\program files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-11-20 767176]
"Avira Systray"="c:\program files (x86)\Avira\My Avira\Avira.OE.Systray.exe" [2015-02-12 127792]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
R1 SSHDRV65;SSHDRV65;c:\windows\system32\drivers\SSHDRV65.sys;c:\windows\SYSNATIVE\drivers\SSHDRV65.sys [x]
R2 AntiVirMailService;Avira Email-Schutz;c:\program files\Avira\AntiVir Desktop\avmailc7.exe;c:\program files\Avira\AntiVir Desktop\avmailc7.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
R3 KMWDFILTERV1;HIDUASServiceDesc;c:\windows\system32\DRIVERS\RPGMOUSEV1.sys;c:\windows\SYSNATIVE\DRIVERS\RPGMOUSEV1.sys [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 PCD65X10;PCD65X10;c:\users\Ringo\AppData\Local\Temp\PCD65X10.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X10.sys [x]
R3 PCD65X11;PCD65X11;c:\users\Ringo\AppData\Local\Temp\PCD65X11.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X11.sys [x]
R3 PCD65X12;PCD65X12;c:\users\Ringo\AppData\Local\Temp\PCD65X12.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X12.sys [x]
R3 PCD65X13;PCD65X13;c:\users\Ringo\AppData\Local\Temp\PCD65X13.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X13.sys [x]
R3 PCD65X14;PCD65X14;c:\users\Ringo\AppData\Local\Temp\PCD65X14.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X14.sys [x]
R3 PCD65X15;PCD65X15;c:\users\Ringo\AppData\Local\Temp\PCD65X15.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X15.sys [x]
R3 PCD65X16;PCD65X16;c:\users\Ringo\AppData\Local\Temp\PCD65X16.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X16.sys [x]
R3 PCD65X17;PCD65X17;c:\users\Ringo\AppData\Local\Temp\PCD65X17.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X17.sys [x]
R3 PCD65X18;PCD65X18;c:\users\Ringo\AppData\Local\Temp\PCD65X18.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X18.sys [x]
R3 PCD65X19;PCD65X19;c:\users\Ringo\AppData\Local\Temp\PCD65X19.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X19.sys [x]
R3 PCD65X2;PCD65X2;c:\users\Ringo\AppData\Local\Temp\PCD65X2.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X2.sys [x]
R3 PCD65X20;PCD65X20;c:\users\Ringo\AppData\Local\Temp\PCD65X20.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X20.sys [x]
R3 PCD65X21;PCD65X21;c:\users\Ringo\AppData\Local\Temp\PCD65X21.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X21.sys [x]
R3 PCD65X22;PCD65X22;c:\users\Ringo\AppData\Local\Temp\PCD65X22.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X22.sys [x]
R3 PCD65X23;PCD65X23;c:\users\Ringo\AppData\Local\Temp\PCD65X23.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X23.sys [x]
R3 PCD65X24;PCD65X24;c:\users\Ringo\AppData\Local\Temp\PCD65X24.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X24.sys [x]
R3 PCD65X25;PCD65X25;c:\users\Ringo\AppData\Local\Temp\PCD65X25.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X25.sys [x]
R3 PCD65X26;PCD65X26;c:\users\Ringo\AppData\Local\Temp\PCD65X26.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X26.sys [x]
R3 PCD65X27;PCD65X27;c:\users\Ringo\AppData\Local\Temp\PCD65X27.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X27.sys [x]
R3 PCD65X28;PCD65X28;c:\users\Ringo\AppData\Local\Temp\PCD65X28.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X28.sys [x]
R3 PCD65X29;PCD65X29;c:\users\Ringo\AppData\Local\Temp\PCD65X29.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X29.sys [x]
R3 PCD65X3;PCD65X3;c:\users\Ringo\AppData\Local\Temp\PCD65X3.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X3.sys [x]
R3 PCD65X30;PCD65X30;c:\users\Ringo\AppData\Local\Temp\PCD65X30.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X30.sys [x]
R3 PCD65X31;PCD65X31;c:\users\Ringo\AppData\Local\Temp\PCD65X31.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X31.sys [x]
R3 PCD65X32;PCD65X32;c:\users\Ringo\AppData\Local\Temp\PCD65X32.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X32.sys [x]
R3 PCD65X33;PCD65X33;c:\users\Ringo\AppData\Local\Temp\PCD65X33.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X33.sys [x]
R3 PCD65X34;PCD65X34;c:\users\Ringo\AppData\Local\Temp\PCD65X34.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X34.sys [x]
R3 PCD65X35;PCD65X35;c:\users\Ringo\AppData\Local\Temp\PCD65X35.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X35.sys [x]
R3 PCD65X36;PCD65X36;c:\users\Ringo\AppData\Local\Temp\PCD65X36.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X36.sys [x]
R3 PCD65X37;PCD65X37;c:\users\Ringo\AppData\Local\Temp\PCD65X37.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X37.sys [x]
R3 PCD65X38;PCD65X38;c:\users\Ringo\AppData\Local\Temp\PCD65X38.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X38.sys [x]
R3 PCD65X39;PCD65X39;c:\users\Ringo\AppData\Local\Temp\PCD65X39.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X39.sys [x]
R3 PCD65X4;PCD65X4;c:\users\Ringo\AppData\Local\Temp\PCD65X4.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X4.sys [x]
R3 PCD65X40;PCD65X40;c:\users\Ringo\AppData\Local\Temp\PCD65X40.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X40.sys [x]
R3 PCD65X41;PCD65X41;c:\users\Ringo\AppData\Local\Temp\PCD65X41.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X41.sys [x]
R3 PCD65X42;PCD65X42;c:\users\Ringo\AppData\Local\Temp\PCD65X42.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X42.sys [x]
R3 PCD65X43;PCD65X43;c:\users\Ringo\AppData\Local\Temp\PCD65X43.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X43.sys [x]
R3 PCD65X44;PCD65X44;c:\users\Ringo\AppData\Local\Temp\PCD65X44.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X44.sys [x]
R3 PCD65X45;PCD65X45;c:\users\Ringo\AppData\Local\Temp\PCD65X45.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X45.sys [x]
R3 PCD65X46;PCD65X46;c:\users\Ringo\AppData\Local\Temp\PCD65X46.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X46.sys [x]
R3 PCD65X47;PCD65X47;c:\users\Ringo\AppData\Local\Temp\PCD65X47.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X47.sys [x]
R3 PCD65X5;PCD65X5;c:\users\Ringo\AppData\Local\Temp\PCD65X5.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X5.sys [x]
R3 PCD65X6;PCD65X6;c:\users\Ringo\AppData\Local\Temp\PCD65X6.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X6.sys [x]
R3 PCD65X7;PCD65X7;c:\users\Ringo\AppData\Local\Temp\PCD65X7.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X7.sys [x]
R3 PCD65X8;PCD65X8;c:\users\Ringo\AppData\Local\Temp\PCD65X8.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X8.sys [x]
R3 PCD65X9;PCD65X9;c:\users\Ringo\AppData\Local\Temp\PCD65X9.sys;c:\users\Ringo\AppData\Local\Temp\PCD65X9.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
R4 AntiVirWebService;Avira Browser-Schutz;c:\program files\Avira\AntiVir Desktop\avwebg7.exe;c:\program files\Avira\AntiVir Desktop\avwebg7.exe [x]
R4 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
R4 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys;c:\windows\SYSNATIVE\Drivers\SABI.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe;c:\program files\Avira\AntiVir Desktop\sched.exe [x]
S2 Avira.OE.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [x]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x]
S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [x]
S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-03-21 10:23 1061704 ----a-w- c:\program files (x86)\Google\Chrome\Application\41.0.2272.101\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2015-04-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 17:56]
.
2015-04-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-07 11:05]
.
2015-04-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-07 11:05]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-14 11046504]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-12-07 5889816]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.facebook.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.178.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-qtwejr - (no file)
Wow6432Node-HKLM-Run-G Data AntiVirus Tray Application - c:\program files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe
Wow6432Node-HKLM-Run-GDFirewallTray - c:\program files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-Mount&Blade - d:\spiele\Mount&Blade\uninstall.exe
AddRemove-World of Warcraft - c:\program files (x86)\Common Files\Blizzard Entertainment\World of Warcraft\Uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-76830181-1066914796-2057996457-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:33,41,3a,25,65,00,6a,b8,35,a3,31,35,1a,c3,23,7c,f1,d4,ee,f3,a6,bc,5b,
09,ad,c0,61,db,35,b8,ad,fb,e0,3f,98,3d,86,f9,20,b0,e8,ef,e0,17,fd,8b,79,60,\
"??"=hex:0a,b9,d7,2a,9f,a3,5c,15,af,43,50,01,d3,5c,b9,eb
.
[HKEY_USERS\S-1-5-21-76830181-1066914796-2057996457-1001\Software\SecuROM\License information*]
"datasecu"=hex:62,e3,0b,fd,30,9e,77,ee,57,a8,24,ac,e8,09,0d,c1,dc,33,67,7c,cc,
b5,42,9d,e3,13,d6,24,fb,12,f4,a0,b6,9a,06,d2,1b,c5,77,94,81,9d,83,29,88,9c,\
"rkeysecu"=hex:26,13,b9,b4,72,dc,a2,73,03,f6,25,b1,35,e6,0a,27
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Component Based Servicing\ApplicabilityEvaluationCache\Package_for_KB2952664~31bf3856ad364e35~amd64~~6.1.9.6]
@DACL=(02 0000)
"ApplicabilityState"=dword:00000070
"CurrentState"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\SysWOW64\UAService7.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2015-04-02 22:30:46 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2015-04-02 20:30
.
Vor Suchlauf: 16 Verzeichnis(se), 37.880.635.392 Bytes frei
Nach Suchlauf: 21 Verzeichnis(se), 39.211.466.752 Bytes frei
.
- - End Of File - - FD2F8049688890D95E280180DEA5D553 |