DarkorbitSup | 22.10.2015 17:21 | Halo lieber Schrauber , das Programm YTD Video Downloader 4.9.2 konnte ich nicht finden und somit auch nicht deinstallieren.
Ich habe grad eine datei gestartet und dann hat mein computer angefangen aufeinmal ein haufen sachen zu öffnen und ich musste den pc ausschalten , jetz haben sich programme installiert die aufeinmal MaxDriver update oder systemhealer heissen, es öffnen sich immer wenn ich klicke werbefenster ;(
Ich habe diese datei als zip bekommen , ich mach sie mal als anhang aber öffne sie bitte nicht. ===== edit: Bitte keine Malware-Anhänge hochladen!
combofix ist fertig : Code:
ComboFix 15-10-21.01 - Marcel 22.10.2015 5:06.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.3767.2662 [GMT -7:00]
ausgeführt von:: c:\users\Marcel\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\END
c:\program files (x86)\Video Tile\Extensions\b8635db9-2694-4837-be3d-4ed3bea8a8ee.dll
c:\programdata\ntuser.pol
c:\programdata\XdjsbA.backup
c:\programdata\XdjsbA.exe
c:\programdata\YbxlwqtR
c:\users\Marcel\AppData\Local\sandex.exe
c:\users\Marcel\AppData\Local\Temp\nsr591A.tmp
c:\windows\m.bat
c:\windows\security\logs\scecomp.log
.
.
((((((((((((((((((((((((((((((((((((((( Treiber/Dienste )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_Serv-U
-------\Service_updqteprodwebdobnloa
.
.
((((((((((((((((((((((( Dateien erstellt von 2015-09-22 bis 2015-10-22 ))))))))))))))))))))))))))))))
.
.
2015-10-22 12:09 . 2015-10-22 12:09 -------- d-----w- c:\users\Marcel\AppData\Local\temp
2015-10-22 12:09 . 2015-10-22 12:09 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-10-22 12:09 . 2015-10-22 12:09 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2015-10-22 11:53 . 2015-10-22 11:55 -------- d-----w- C:\AdwCleaner
2015-10-22 11:50 . 2015-10-22 11:50 -------- d-----w- c:\program files (x86)\RayDld
2015-10-22 11:49 . 2015-10-22 11:50 -------- d-----w- c:\users\Marcel\AppData\Roaming\oursurfing
2015-10-22 11:49 . 2015-10-22 11:49 -------- d-----w- c:\program files\Concom
2015-10-22 11:48 . 2015-10-22 11:48 -------- d-----w- c:\program files (x86)\Video Tile
2015-10-22 11:48 . 2015-10-22 11:48 1850117 ----a-w- c:\windows\chromebrowser.exe
2015-10-21 16:54 . 2015-10-21 16:54 -------- d-----w- c:\users\Marcel\AppData\Roaming\Gyazo
2015-10-21 16:54 . 2015-10-22 06:44 -------- d-----w- c:\program files (x86)\Gyazo
2015-10-21 16:14 . 2015-09-25 18:07 98816 ----a-w- c:\windows\system32\wudriver.dll
2015-09-26 07:19 . 2015-09-26 07:19 -------- d-----w- c:\program files (x86)\SkinPack
2015-09-26 07:19 . 2015-04-29 18:06 147968 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
2015-09-26 07:19 . 2015-07-09 17:57 246784 ----a-w- c:\windows\system32\notepad.exe
2015-09-26 07:19 . 2009-07-14 01:39 6632960 ----a-w- c:\windows\system32\mspaint.exe
2015-09-26 07:19 . 2011-02-25 06:19 2766848 ----a-w- c:\windows\explorer.exe
2015-09-24 17:43 . 2015-09-24 17:43 -------- d-----w- C:\TDSSKiller_Quarantine
2015-09-24 17:39 . 2015-09-25 11:51 -------- d-sh--r- c:\users\Marcel\AppData\Roaming\ApxSvrr0
2015-09-24 17:30 . 2015-09-24 17:30 -------- d-----w- c:\users\Marcel\AppData\Local\Opera Software
2015-09-24 16:44 . 2015-09-24 16:44 -------- d-----w- c:\program files (x86)\Common Files\Java
2015-09-24 16:43 . 2015-09-24 16:43 110688 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2015-09-24 12:33 . 2015-09-24 12:33 -------- d-----w- c:\users\Marcel\AppData\Roaming\Anvsoft
2015-09-24 12:33 . 2015-09-24 12:33 -------- d-----w- c:\program files (x86)\Anvsoft
2015-09-24 12:30 . 2015-09-24 12:30 -------- d-----w- c:\users\Marcel\AppData\Roaming\WindSolutions
2015-09-24 12:29 . 2015-09-24 12:29 -------- d-----w- c:\programdata\WindSolutions
2015-09-23 18:39 . 2015-09-23 18:39 -------- d-----w- c:\users\Marcel\AppData\Local\CEF
2015-09-22 17:14 . 2015-09-22 17:14 -------- d-----w- c:\users\Marcel\AppData\Roaming\FileZilla Server
2015-09-22 17:14 . 2015-09-22 17:31 -------- d-----w- c:\program files (x86)\FileZilla Server
2015-09-22 16:46 . 2015-09-22 16:46 -------- d-----w- c:\program files\RhinoSoft
2015-09-22 16:46 . 2015-09-22 16:46 -------- d-----w- c:\programdata\RhinoSoft
2015-09-22 16:46 . 2015-09-22 16:46 -------- d-----w- c:\users\Marcel\AppData\Local\Programs
2015-09-22 16:41 . 2015-09-22 16:41 -------- d-----w- c:\users\Marcel\AppData\Local\Vitalwerks
2015-09-22 16:41 . 2015-09-22 16:41 -------- d-----w- c:\programdata\Vitalwerks
2015-09-22 16:41 . 2015-09-22 16:41 -------- d-----w- c:\program files (x86)\No-IP
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-10-22 12:09 . 2015-07-12 18:53 113880 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-10-22 06:26 . 2015-05-12 03:14 780488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2015-10-22 06:26 . 2015-05-12 03:14 142536 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-09-29 02:58 . 2015-10-21 16:14 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2015-09-26 07:18 . 2009-07-13 23:54 44544 ----a-w- c:\windows\system32\themeservice.dll
2015-09-26 07:18 . 2010-11-21 03:23 2851840 ----a-w- c:\windows\system32\themeui.dll
2015-09-26 07:18 . 2009-07-13 23:55 332288 ----a-w- c:\windows\system32\uxtheme.dll
2015-09-21 17:43 . 2015-09-21 17:43 23112 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2015-09-06 16:44 . 2015-09-06 16:44 286720 ----a-w- c:\windows\system32\igfxrrom.lrc
2015-09-06 16:44 . 2015-09-06 16:44 286720 ----a-w- c:\windows\system32\igfxrhrv.lrc
2015-09-06 16:44 . 2015-09-06 16:44 2780160 ----a-w- c:\windows\system32\igfxcmjit64.dll
2015-09-06 16:44 . 2015-09-06 16:44 246784 ----a-w- c:\windows\SysWow64\igfxcmrt32.dll
2015-09-06 16:44 . 2015-09-06 16:44 2191872 ----a-w- c:\windows\SysWow64\igfxcmjit32.dll
2015-09-06 16:44 . 2015-09-06 16:44 219136 ----a-w- c:\windows\system32\igfxcmrt64.dll
2015-09-04 19:34 . 2015-09-04 19:34 119808 ----a-r- c:\users\Marcel\AppData\Roaming\Microsoft\Installer\{CCF298AF-9CE1-4B26-B251-486E98A34789}\icons.exe
2015-09-02 09:13 . 2015-09-02 13:06 327847 ----a-w- c:\windows\files5.exe
2015-09-02 03:04 . 2015-09-09 08:41 41984 ----a-w- c:\windows\system32\lpk.dll
2015-09-02 03:04 . 2015-09-09 08:41 100864 ----a-w- c:\windows\system32\fontsub.dll
2015-09-02 03:04 . 2015-09-09 08:41 14336 ----a-w- c:\windows\system32\dciman32.dll
2015-09-02 03:04 . 2015-09-09 08:41 46080 ----a-w- c:\windows\system32\atmlib.dll
2015-09-02 02:48 . 2015-09-09 08:41 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
2015-09-02 02:48 . 2015-09-09 08:41 10240 ----a-w- c:\windows\SysWow64\dciman32.dll
2015-09-02 02:48 . 2015-09-09 08:41 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2015-09-02 02:47 . 2015-09-09 08:41 25600 ----a-w- c:\windows\SysWow64\lpk.dll
2015-09-02 01:51 . 2015-09-09 08:41 3209216 ----a-w- c:\windows\system32\win32k.sys
2015-09-02 01:47 . 2015-09-09 08:41 372736 ----a-w- c:\windows\system32\atmfd.dll
2015-09-02 01:33 . 2015-09-09 08:41 299520 ----a-w- c:\windows\SysWow64\atmfd.dll
2015-08-26 16:01 . 2015-05-14 11:48 37624 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2015-08-23 16:23 . 2015-08-23 16:23 94 --sha-r- c:\windows\system32\service.bat
2015-08-20 05:48 . 2015-08-20 05:48 1409 ----a-w- c:\windows\Fonts\OpenSans-Regular.fot
2015-08-20 05:48 . 2015-08-20 05:48 1409 ----a-w- c:\windows\Fonts\OpenSans-Light.fot
2015-08-20 05:48 . 2015-08-20 05:48 1409 ----a-w- c:\windows\Fonts\OpenSans-Bold.fot
2015-08-16 15:01 . 2015-08-16 15:10 617432 ----a-w- c:\program files (x86)\SDLicense.dll
2015-08-14 21:03 . 2015-09-05 17:08 33472 ----a-w- c:\windows\system32\drivers\VMkbd.sys
2015-08-14 21:03 . 2015-09-05 17:08 391872 ----a-w- c:\windows\SysWow64\vmnat.exe
2015-08-14 21:03 . 2015-09-05 17:08 358080 ----a-w- c:\windows\SysWow64\vmnetdhcp.exe
2015-08-14 21:03 . 2015-09-05 17:08 934080 ----a-w- c:\windows\system32\vnetlib64.dll
2015-08-14 21:03 . 2015-09-05 17:08 66752 ----a-w- c:\windows\system32\drivers\vmx86.sys
2015-08-14 20:43 . 2015-09-05 17:08 26816 ----a-w- c:\windows\system32\drivers\vmnetuserif.sys
2015-08-14 20:43 . 2015-08-14 20:43 49856 ----a-w- c:\windows\system32\vnetinst.dll
2015-08-14 20:43 . 2015-08-14 20:43 81088 ----a-w- c:\windows\system32\vmnetbridge.dll
2015-08-14 20:43 . 2015-08-14 20:43 48832 ----a-w- c:\windows\system32\drivers\vmnetbridge.sys
2015-08-14 20:43 . 2015-08-14 20:43 28864 ----a-w- c:\windows\system32\drivers\vmnetadapter.sys
2015-08-14 20:43 . 2015-08-14 20:43 27328 ----a-w- c:\windows\system32\drivers\vmnet.sys
2015-08-14 01:24 . 2015-09-05 16:57 960808 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2015-08-14 01:24 . 2015-08-14 01:24 117768 ----a-w- c:\windows\system32\drivers\VBoxNetAdp6.sys
2015-08-14 01:24 . 2015-09-05 16:57 138904 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2015-08-14 01:24 . 2015-08-14 01:24 146072 ----a-w- c:\windows\system32\drivers\VBoxNetLwf.sys
2015-08-12 14:45 . 2015-05-15 21:25 132483416 ----a-w- c:\windows\system32\MRT.exe
2015-08-12 12:16 . 2015-08-12 12:16 22200 ----a-w- c:\windows\SysWow64\drivers\DrvAgent64.SYS
2015-08-12 02:27 . 2015-09-05 17:08 57536 ----a-w- c:\windows\system32\drivers\hcmon.sys
2015-08-12 02:27 . 2015-09-05 17:08 46144 ----a-w- c:\windows\system32\drivers\vmusb.sys
2015-08-09 05:10 . 2015-08-09 05:10 96776 ----a-w- c:\windows\SysWow64\mantleaxl32.dll
2015-08-09 05:10 . 2015-08-09 05:10 136216 ----a-w- c:\windows\system32\mantle64.dll
2015-08-09 05:10 . 2015-08-09 05:10 122392 ----a-w- c:\windows\SysWow64\mantle32.dll
2015-08-09 05:10 . 2015-08-09 05:10 102424 ----a-w- c:\windows\system32\mantleaxl64.dll
2015-08-09 05:10 . 2015-08-09 05:10 6486032 ----a-w- c:\windows\system32\amdmantle64.dll
2015-08-09 05:10 . 2015-08-09 05:10 59416 ----a-w- c:\windows\system32\amdmmcl6.dll
2015-08-09 05:10 . 2015-08-09 05:10 5077016 ----a-w- c:\windows\SysWow64\amdmantle32.dll
2015-08-09 05:10 . 2015-08-09 05:10 48144 ----a-w- c:\windows\SysWow64\amdmmcl.dll
2015-08-05 17:56 . 2015-09-11 19:47 1110016 ----a-w- c:\windows\system32\schedsvc.dll
2015-08-05 17:56 . 2015-09-11 19:47 275456 ----a-w- c:\windows\system32\InkEd.dll
2015-08-05 17:40 . 2015-09-11 19:47 216064 ----a-w- c:\windows\SysWow64\InkEd.dll
2015-08-04 08:10 . 2015-09-05 17:08 75512 ----a-w- c:\windows\system32\drivers\vsock.sys
2015-08-04 08:10 . 2015-09-05 17:08 68288 ----a-w- c:\windows\system32\vsocklib.dll
2015-08-04 08:10 . 2015-09-05 17:08 64192 ----a-w- c:\windows\SysWow64\vsocklib.dll
2015-08-04 08:10 . 2015-08-04 08:10 90816 ----a-w- c:\windows\system32\drivers\vmci.sys
2015-07-30 18:06 . 2015-08-12 12:05 1648128 ----a-w- c:\windows\system32\DWrite.dll
2015-07-30 18:06 . 2015-08-12 12:05 1180160 ----a-w- c:\windows\system32\FntCache.dll
2015-07-30 18:06 . 2015-08-12 12:05 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2015-07-30 17:57 . 2015-08-12 12:05 1251328 ----a-w- c:\windows\SysWow64\DWrite.dll
2015-07-30 17:57 . 2015-08-12 12:05 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2015-07-30 13:13 . 2015-08-12 14:49 103120 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-07-30 13:13 . 2015-08-12 14:49 124624 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-07-28 09:48 . 2015-07-28 09:48 12872 ----a-w- c:\windows\system32\bootdelete.exe
2015-07-24 16:14 . 2015-07-12 18:53 107736 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2011-02-26 . 3B69712041F3D63605529BD66DC00C48 . 2871808 . . [6.1.7601.21669] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[-] 2011-02-25 . 517C37C06ED560D7856373203EEBD2F2 . 2766848 . . [6.1.7600.16385] .. c:\windows\explorer.exe
[7] 2011-02-25 . 332FEAB1435662FC6C672E25BEB37BE3 . 2871808 . . [6.1.7601.17567] .. c:\windows\erdnt\cache86\explorer.exe
[7] 2011-02-25 . 332FEAB1435662FC6C672E25BEB37BE3 . 2871808 . . [6.1.7601.17567] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[7] 2010-11-21 . AC4C51EB24AA95B77F705AB159189E24 . 2872320 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLUA"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *
.
R1 VBoxNetAdp;VirtualBox NDIS 6.0 Miniport Service;c:\windows\system32\DRIVERS\VBoxNetAdp6.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp6.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 NoIPDUCService4;NO-IP DUC v4.1.1;c:\program files (x86)\No-IP\ducservice.exe;c:\program files (x86)\No-IP\ducservice.exe [x]
R3 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys;c:\windows\SYSNATIVE\DRIVERS\avc3.sys [x]
R3 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys;c:\windows\SYSNATIVE\DRIVERS\avckf.sys [x]
R3 BazisPortableCDBus;Portable WinCDEmu driver;c:\windows\system32\drivers\BazisPortableCDBus.sys;c:\windows\SYSNATIVE\drivers\BazisPortableCDBus.sys [x]
R3 BcmVWL;Broadcom Virtual Wireless;c:\windows\system32\DRIVERS\bcmvwl64.sys;c:\windows\SYSNATIVE\DRIVERS\bcmvwl64.sys [x]
R3 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
R3 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [x]
R3 BstHdUpdaterSvc;BlueStacks Updater Service;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe [x]
R3 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 DrvAgent64;DrvAgent64;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
R3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys;c:\windows\SYSNATIVE\drivers\mbamchameleon.sys [x]
R3 Origin Client Service;Origin Client Service;c:\program files (x86)\Origin\OriginClientService.exe;c:\program files (x86)\Origin\OriginClientService.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x]
R3 VBoxUSB;VirtualBox USB;c:\windows\system32\Drivers\VBoxUSB.sys;c:\windows\SYSNATIVE\Drivers\VBoxUSB.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
S0 amdkmpfd;AMD PCI Root Bus Lower Filter;c:\windows\system32\DRIVERS\amdkmpfd.sys;c:\windows\SYSNATIVE\DRIVERS\amdkmpfd.sys [x]
S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys;c:\windows\SYSNATIVE\DRIVERS\vmci.sys [x]
S0 vsock;vSockets Driver;c:\windows\system32\drivers\vsock.sys;c:\windows\SYSNATIVE\drivers\vsock.sys [x]
S1 GUBootStartup;GUBootStartup;c:\windows\System32\drivers\GUBootStartup.sys;c:\windows\SYSNATIVE\drivers\GUBootStartup.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxDrv.sys [x]
S1 VBoxNetLwf;VirtualBox NDIS6 Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetLwf.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetLwf.sys [x]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxUSBMon.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 Apple Mobile Device Service;Apple Mobile Device Service;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [x]
S2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [x]
S2 Concom;Concom Service;c:\program files\Concom\Concom.exe;c:\program files\Concom\Concom.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
S2 mfmonitor;mfmonitor;c:\windows\system32\DRIVERS\mfmonitor_x64.sys;c:\windows\SYSNATIVE\DRIVERS\mfmonitor_x64.sys [x]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys;c:\windows\SYSNATIVE\drivers\npf.sys [x]
S2 Service Mgr VideoTile;Service Mgr VideoTile;c:\programdata\260dee10-c5d7-419f-8be9-a3d98ba1c6c6\plugincontainer.exe;c:\programdata\260dee10-c5d7-419f-8be9-a3d98ba1c6c6\plugincontainer.exe [x]
S2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
S2 TheScreenSnapshotService;The Screen Snapshot Service;c:\program files (x86)\ScreenSnapshotTool\1.1.0.10921\ScreenShotServ.exe;c:\program files (x86)\ScreenSnapshotTool\1.1.0.10921\ScreenShotServ.exe [x]
S2 Update Mgr VideoTile;Update Mgr VideoTile;c:\program files (x86)\Common Files\260dee10-c5d7-419f-8be9-a3d98ba1c6c6\updater.exe;c:\program files (x86)\Common Files\260dee10-c5d7-419f-8be9-a3d98ba1c6c6\updater.exe [x]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 avchv;avchv Function Driver;c:\windows\system32\DRIVERS\avchv.sys;c:\windows\SYSNATIVE\DRIVERS\avchv.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys;c:\windows\SYSNATIVE\DRIVERS\igdpmd64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
S3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - MBAMSWISSARMY
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1MediaFireIconError]
@="{5EE8C634-CDC0-453D-9731-DF0B19F4E807}"
[HKEY_CLASSES_ROOT\CLSID\{5EE8C634-CDC0-453D-9731-DF0B19F4E807}]
2015-04-23 13:10 89600 ----a-w- c:\program files (x86)\MediaFire Desktop\MediaFireIcon3_eb889.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1MediaFireIconReadOnly]
@="{7995D0FC-769B-4197-AEC0-991921CB99E1}"
[HKEY_CLASSES_ROOT\CLSID\{7995D0FC-769B-4197-AEC0-991921CB99E1}]
2015-04-23 13:10 89088 ----a-w- c:\program files (x86)\MediaFire Desktop\MediaFireIcon5_eb889.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1MediaFireIconSynched]
@="{9A3B79CB-D899-40B5-8DBC-20447F1ADC8F}"
[HKEY_CLASSES_ROOT\CLSID\{9A3B79CB-D899-40B5-8DBC-20447F1ADC8F}]
2015-04-23 13:10 84992 ----a-w- c:\program files (x86)\MediaFire Desktop\MediaFireIcon_eb889.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1MediaFireIconSyncing]
@="{C4D81971-6B13-4173-AB21-F83AD20CCC04}"
[HKEY_CLASSES_ROOT\CLSID\{C4D81971-6B13-4173-AB21-F83AD20CCC04}]
2015-04-23 13:10 86528 ----a-w- c:\program files (x86)\MediaFire Desktop\MediaFireIcon2_eb889.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MediaFireIconLock]
@="{759F3E92-F4E8-4953-8315-238B8B17E0F3}"
[HKEY_CLASSES_ROOT\CLSID\{759F3E92-F4E8-4953-8315-238B8B17E0F3}]
2015-04-23 13:10 84992 ----a-w- c:\program files (x86)\MediaFire Desktop\MediaFireIcon4_eb889.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mStart Page = hxxp://www.google.com
mSearch Page = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local;<local>
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\wgnetdxg.default-1440833954739\
.
.
------- Dateityp-Verknüpfung -------
.
inifile="%SystemRoot%\system32\NOTEPAD.EXE" %1
txtfile="%SystemRoot%\system32\NOTEPAD.EXE" %1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
SafeBoot-24724025.sys
AddRemove-uTorrent - c:\users\Marcel\AppData\Roaming\uTorrent\uTorrent.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2810977045-1315894760-386528613-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\SecuROM\License information*]
"datasecu"=hex:a0,fb,df,fb,7f,54,54,02,f5,fa,a8,93,bd,cf,e8,46,f9,9d,49,52,38,
94,fe,01,ed,22,d2,bf,3c,6a,f7,93,fc,4b,b7,bb,4f,f5,56,e6,f7,6a,66,39,dc,87,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_USERS\S-1-5-21-2810977045-1315894760-386528613-1000\Software\SecuROM\License information*]
"datasecu"=hex:a0,fb,df,fb,7f,54,54,02,f5,fa,a8,93,bd,cf,e8,46,f9,9d,49,52,38,
94,fe,01,ed,22,d2,bf,3c,6a,f7,93,fc,4b,b7,bb,4f,f5,56,e6,f7,6a,66,39,dc,87,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_USERS\S-1-5-21-2810977045-1315894760-386528613-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,eb,ce,c3,fe,c0,4b,19,4c,b1,c3,26,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,eb,ce,c3,fe,c0,4b,19,4c,b1,c3,26,\
.
[HKEY_LOCAL_MACHINE\software\BlueStacks]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_18_0_0_209_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_18_0_0_209_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_18_0_0_209_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_18_0_0_209_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_209.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.18"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_209.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_209.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_209.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\FileZilla Server\FileZilla Server.exe
c:\program files (x86)\TeamViewer\TeamViewer_Service.exe
c:\windows\SysWOW64\vmnat.exe
c:\program files (x86)\Malwarebytes Anti-Malware\mbam.exe
c:\program files (x86)\ScreenSnapshotTool\1.1.0.10921\ScreenSnapshot.exe
c:\windows\SysWOW64\vmnetdhcp.exe
c:\program files (x86)\VMware\VMware Player\vmware-authd.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2015-10-22 05:12:02 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2015-10-22 12:12
.
Vor Suchlauf: 23 Verzeichnis(se), 31.279.833.088 Bytes frei
Nach Suchlauf: 27 Verzeichnis(se), 31.285.186.560 Bytes frei
.
- - End Of File - - BAFCFC6D34381BC3CE4FF2AF126BA660 Ich bitte um Hilfe ;( |