Code:
ComboFix 15-11-30.01 - buebi 02.12.2015 23:38:12.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8174.6522 [GMT 1:00]
ausgeführt von:: c:\users\buebi\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\END
c:\programdata\@system3.att
c:\users\buebi\AppData\Roaming\Microsoft\Windows\Recent\_how_recover_ieh.HTML
c:\users\buebi\AppData\Roaming\Microsoft\Windows\Recent\_how_recover_ieh.TXT
c:\users\buebi\AppData\Roaming\Microsoft\Windows\Recent\_how_recover_mxh.HTML
c:\users\buebi\AppData\Roaming\Microsoft\Windows\Recent\_how_recover_mxh.TXT
c:\users\buebi\AppData\Roaming\Microsoft\Windows\Recent\_how_recover_pap.HTML
c:\users\buebi\AppData\Roaming\Microsoft\Windows\Recent\_how_recover_pap.TXT
c:\users\buebi\AppData\Roaming\Microsoft\Windows\Recent\_how_recover_txi.HTML
c:\users\buebi\AppData\Roaming\Microsoft\Windows\Recent\_how_recover_txi.TXT
c:\users\buebi\AppData\Roaming\Microsoft\Windows\Recent\_how_recover_xwl.HTML
c:\users\buebi\AppData\Roaming\Microsoft\Windows\Recent\_how_recover_xwl.TXT
c:\users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\_how_recover_ieh.HTML
c:\users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\_how_recover_ieh.TXT
c:\users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\_how_recover_mxh.HTML
c:\users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\_how_recover_mxh.TXT
c:\users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\_how_recover_txi.HTML
c:\users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\_how_recover_txi.TXT
c:\users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\_how_recover_xwl.HTML
c:\users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\_how_recover_xwl.TXT
D:\install.exe
D:\setup.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2015-11-02 bis 2015-12-02 ))))))))))))))))))))))))))))))
.
.
2015-12-01 22:13 . 2015-12-01 23:09 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2015-11-29 19:05 . 2015-11-29 19:05 -------- d-----w- c:\users\buebi\AppData\Local\ElevatedDiagnostics
2015-11-29 18:24 . 2015-11-29 18:24 68104 ----a-w- c:\windows\system32\XAPOFX1_0.dll
2015-11-29 17:58 . 2015-11-29 17:58 -------- d-----w- C:\VTRoot
2015-11-29 15:08 . 2015-11-29 15:08 -------- d-----w- c:\programdata\Shared Space
2015-11-29 15:08 . 2015-11-30 07:51 -------- d-----w- c:\program files\COMODO
2015-11-29 15:07 . 2015-11-29 15:07 -------- d-----w- c:\users\buebi\AppData\Local\Comodo
2015-11-29 15:05 . 2015-11-29 15:09 -------- d-----w- c:\programdata\Comodo
2015-11-29 14:05 . 2015-11-30 07:48 -------- d-----w- c:\program files (x86)\Microsoft
2015-11-29 11:03 . 2015-11-29 11:03 -------- d-----w- c:\program files (x86)\Common Files\Java
2015-11-29 11:03 . 2015-11-29 11:03 110176 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2015-11-29 11:03 . 2015-11-29 11:03 -------- d-----w- c:\program files\Java
2015-11-29 10:53 . 2015-11-29 10:54 1905272 ----a-w- c:\windows\system32\nvdispco6435900.dll
2015-11-29 10:53 . 2015-11-29 10:54 1564792 ----a-w- c:\windows\system32\nvdispgenco6435900.dll
2015-11-29 10:40 . 2015-11-29 10:40 39240 ----a-w- c:\windows\system32\nvhdap64.dll
2015-11-29 10:40 . 2015-11-29 10:40 205456 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
2015-11-29 09:11 . 2015-11-29 09:11 -------- d-----w- c:\programdata\McAfee
2015-11-29 03:24 . 2015-11-29 11:03 -------- d-----w- c:\users\buebi\.oracle_jre_usage
2015-11-28 15:47 . 2015-12-01 22:58 192216 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-11-28 15:47 . 2015-12-01 22:56 109272 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-11-28 15:47 . 2015-11-28 15:47 -------- d-----w- c:\programdata\Malwarebytes
2015-11-28 15:47 . 2015-10-05 08:50 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2015-11-28 15:47 . 2015-10-05 08:50 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2015-11-28 14:51 . 2015-11-28 14:51 -------- d-----w- c:\programdata\{FD6F83C0-EC70-4581-8361-C70CD1AA4B98}
2015-11-26 15:19 . 2015-11-30 08:44 -------- d-----w- C:\FRST
2015-11-24 14:02 . 2015-10-29 09:28 11138400 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4DC505AB-6E9F-440D-967A-3B04408C2F13}\mpengine.dll
2015-11-12 14:41 . 2015-11-03 17:55 3211264 ----a-w- c:\windows\system32\win32k.sys
2015-11-11 14:49 . 2015-10-30 22:58 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2015-11-07 12:40 . 2015-11-07 12:40 37888 ----a-w- c:\windows\system32\wups2.dll
2015-11-04 08:59 . 2015-11-25 19:09 -------- d-----w- c:\programdata\Blizzard Entertainment
2015-11-04 08:58 . 2015-11-26 13:24 -------- d-----w- c:\programdata\Battle.net
2015-11-03 23:06 . 2015-11-25 19:09 -------- d-----w- c:\users\buebi\AppData\Local\CEF
2015-11-03 22:35 . 2015-11-29 11:15 -------- d-----w- c:\users\buebi\AppData\Local\NVIDIA
2015-11-03 22:32 . 2015-11-29 11:16 938800 ----a-w- c:\windows\system32\nvvsvc.exe
2015-11-03 22:32 . 2015-11-14 06:06 6358832 ----a-w- c:\windows\system32\nvcpl.dll
2015-11-03 22:32 . 2015-11-14 06:06 2983032 ----a-w- c:\windows\system32\nvsvc64.dll
2015-11-03 22:32 . 2015-11-14 06:06 62768 ----a-w- c:\windows\system32\nvshext.dll
2015-11-03 22:32 . 2015-11-14 06:06 385144 ----a-w- c:\windows\system32\nvmctray.dll
2015-11-03 22:32 . 2015-11-14 06:06 2554488 ----a-w- c:\windows\system32\nvsvcr.dll
2015-11-03 22:32 . 2015-10-28 08:17 6027430 ----a-w- c:\windows\system32\nvcoproc.bin
2015-11-03 22:32 . 2015-11-29 11:16 112760 ----a-w- c:\windows\system32\OpenCL.dll
2015-11-03 22:32 . 2015-11-29 11:16 105080 ----a-w- c:\windows\SysWow64\OpenCL.dll
2015-11-03 22:32 . 2015-11-29 11:16 -------- d-----w- c:\programdata\NVIDIA Corporation
2015-11-03 22:31 . 2015-11-29 10:40 1572496 ----a-w- c:\windows\system32\nvhdagenco6420103.dll
2015-11-03 11:42 . 2015-11-25 19:26 -------- d-----w- c:\users\buebi\AppData\Local\YSearchUtil
2015-11-03 11:42 . 2015-11-03 11:42 -------- d-----w- c:\program files (x86)\Yahoo!
2015-11-03 11:42 . 2015-11-29 11:18 -------- d-----w- c:\programdata\NVIDIA
2015-11-03 11:40 . 2015-11-03 11:40 97888 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2015-11-03 11:40 . 2015-11-25 19:09 -------- d-----w- c:\programdata\Oracle
2015-11-03 11:40 . 2015-11-03 11:40 -------- d-----w- c:\program files (x86)\Java
2015-11-03 11:37 . 2015-11-03 11:37 584288 ----a-w- c:\users\buebi\JavaSetup8u65.exe
2015-11-03 10:46 . 2015-10-03 05:06 1905456 ----a-w- c:\windows\system32\nvdispco6435850.dll
2015-11-03 10:46 . 2015-10-03 05:06 1564976 ----a-w- c:\windows\system32\nvdispgenco6435850.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-11-29 12:52 . 2015-06-11 00:33 26912 ----a-w- c:\windows\system32\drivers\LGVirHid.sys
2015-11-29 12:52 . 2015-06-11 00:33 68384 ----a-w- c:\windows\system32\drivers\LGJoyXlCore.sys
2015-11-29 12:52 . 2015-06-11 00:33 37408 ----a-w- c:\windows\system32\drivers\LGBusEnum.sys
2015-11-29 12:52 . 2013-03-10 13:21 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2015-11-29 11:17 . 2015-05-25 11:20 14617288 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2015-11-29 11:17 . 2015-05-25 11:20 927440 ----a-w- c:\windows\SysWow64\nvumdshim.dll
2015-11-29 11:17 . 2015-05-25 11:20 24053576 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2015-11-29 11:17 . 2015-05-25 11:20 12852784 ----a-w- c:\windows\SysWow64\nvopencl.dll
2015-11-29 11:17 . 2015-05-25 11:20 128512 ----a-w- c:\windows\SysWow64\nvoglshim32.dll
2015-11-29 11:17 . 2015-05-25 11:20 2573456 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2015-11-29 11:17 . 2015-05-25 11:20 154256 ----a-w- c:\windows\SysWow64\nvinit.dll
2015-11-29 11:17 . 2015-05-25 11:20 12689592 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2015-11-29 11:17 . 2015-05-25 11:20 11380728 ----a-w- c:\windows\SysWow64\nvcuda.dll
2015-11-29 11:17 . 2015-05-25 11:20 25375048 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2015-11-29 11:17 . 2015-05-25 11:20 2935416 ----a-w- c:\windows\SysWow64\nvapi.dll
2015-11-29 11:17 . 2015-05-25 11:20 17176128 ----a-w- c:\windows\system32\nvwgf2umx.dll
2015-11-29 11:17 . 2015-05-25 11:20 1086424 ----a-w- c:\windows\system32\nvumdshimx.dll
2015-11-29 11:17 . 2015-05-25 11:20 31570064 ----a-w- c:\windows\system32\nvoglv64.dll
2015-11-29 11:17 . 2015-05-25 11:20 15716232 ----a-w- c:\windows\system32\nvopencl.dll
2015-11-29 11:17 . 2015-05-25 11:20 970568 ----a-w- c:\windows\SysWow64\NvIFR.dll
2015-11-29 11:17 . 2015-05-25 11:20 962192 ----a-w- c:\windows\SysWow64\NvFBC.dll
2015-11-29 11:17 . 2015-05-25 11:20 150648 ----a-w- c:\windows\system32\nvoglshim64.dll
2015-11-29 11:17 . 2015-05-25 11:20 175880 ----a-w- c:\windows\system32\nvinitx.dll
2015-11-29 11:17 . 2015-05-25 11:20 15818528 ----a-w- c:\windows\system32\nvd3dumx.dll
2015-11-29 11:17 . 2015-05-25 11:20 2896528 ----a-w- c:\windows\system32\nvcuvid.dll
2015-11-29 11:17 . 2015-05-25 11:20 14006752 ----a-w- c:\windows\system32\nvcuda.dll
2015-11-29 11:17 . 2015-05-25 11:20 30397072 ----a-w- c:\windows\system32\nvcompiler.dll
2015-11-29 11:17 . 2015-05-25 11:20 3317344 ----a-w- c:\windows\system32\nvapi64.dll
2015-11-29 11:17 . 2015-05-25 11:20 1047368 ----a-w- c:\windows\system32\NvIFR64.dll
2015-11-29 11:17 . 2015-05-25 11:20 10423952 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2015-11-29 11:17 . 2015-05-25 11:20 1037640 ----a-w- c:\windows\system32\NvFBC64.dll
2015-11-29 10:56 . 2015-05-30 14:20 1898312 ----a-w- c:\windows\system32\nvdispco6435286.dll
2015-11-29 10:56 . 2015-05-30 14:20 1557648 ----a-w- c:\windows\system32\nvdispgenco6435286.dll
2015-11-29 09:10 . 2013-03-12 17:35 780488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2015-11-29 09:10 . 2013-03-12 17:35 142536 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-10-30 15:49 . 2015-10-30 15:49 668784 ----a-w- C:\SecurityScanner.dll
2015-10-29 17:50 . 2015-11-11 14:49 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2015-10-29 17:50 . 2015-11-11 14:49 309248 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2015-10-29 17:50 . 2015-11-11 14:49 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2015-10-29 17:50 . 2015-11-11 14:49 103424 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2015-10-29 17:49 . 2015-11-11 14:49 562176 ----a-w- c:\windows\apppatch\AcLayers.dll
2015-10-29 17:49 . 2015-11-11 14:49 470528 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2015-10-29 17:49 . 2015-11-11 14:49 2178560 ----a-w- c:\windows\apppatch\AcGenral.dll
2015-10-29 17:49 . 2015-11-11 14:49 211968 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2015-10-29 17:39 . 2015-11-11 14:49 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2015-10-20 00:45 . 2015-11-11 14:49 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2015-10-13 12:35 . 2015-10-13 12:35 430808 ----a-w- c:\windows\system32\drivers\asmtxhci.sys
2015-10-13 00:29 . 2015-10-13 00:29 875720 ----a-w- c:\windows\SysWow64\msvcr120_clr0400.dll
2015-10-13 00:22 . 2015-10-13 00:22 869568 ----a-w- c:\windows\system32\msvcr120_clr0400.dll
2015-10-01 18:06 . 2015-10-14 13:07 692672 ----a-w- c:\windows\system32\winload.efi
2015-10-01 18:04 . 2015-10-14 13:07 616360 ----a-w- c:\windows\system32\winresume.efi
2015-10-01 18:00 . 2015-10-14 13:07 63488 ----a-w- c:\windows\system32\setbcdlocale.dll
2015-10-01 18:00 . 2015-10-14 13:07 59392 ----a-w- c:\windows\system32\appidapi.dll
2015-10-01 18:00 . 2015-10-14 13:07 32768 ----a-w- c:\windows\system32\appidsvc.dll
2015-10-01 18:00 . 2015-10-14 13:07 17920 ----a-w- c:\windows\system32\appidcertstorecheck.exe
2015-10-01 18:00 . 2015-10-14 13:07 147456 ----a-w- c:\windows\system32\appidpolicyconverter.exe
2015-10-01 17:50 . 2015-10-14 13:07 50688 ----a-w- c:\windows\SysWow64\appidapi.dll
2015-10-01 17:00 . 2015-10-14 13:07 61440 ----a-w- c:\windows\system32\drivers\appid.sys
2015-09-18 19:22 . 2015-10-15 12:52 25432 ----a-w- c:\windows\system32\CompatTelRunner.exe
2015-09-18 19:19 . 2015-10-15 12:52 700416 ----a-w- c:\windows\system32\invagent.dll
2015-09-18 19:19 . 2015-10-15 12:52 766464 ----a-w- c:\windows\system32\generaltel.dll
2015-09-18 19:19 . 2015-10-15 12:52 503808 ----a-w- c:\windows\system32\devinv.dll
2015-09-18 19:19 . 2015-10-15 12:52 73216 ----a-w- c:\windows\system32\acmigration.dll
2015-09-18 19:19 . 2015-10-15 12:52 1291264 ----a-w- c:\windows\system32\appraiser.dll
2015-09-18 19:09 . 2015-10-15 12:52 1163776 ----a-w- c:\windows\system32\aeinv.dll
2015-09-16 13:31 . 2015-09-16 13:31 39936 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2015-09-16 13:31 . 2015-09-16 13:31 22528 ----a-w- c:\windows\system32\icaapi.dll
2015-09-16 13:30 . 2015-09-16 13:30 984448 ----a-w- c:\windows\system32\ucrtbase.dll
2015-09-16 13:30 . 2015-09-16 13:30 901264 ----a-w- c:\windows\SysWow64\ucrtbase.dll
2015-09-16 13:30 . 2015-09-16 13:30 66400 ----a-w- c:\windows\SysWow64\api-ms-win-crt-private-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 63840 ----a-w- c:\windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 22368 ----a-w- c:\windows\SysWow64\api-ms-win-crt-math-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 20832 ----a-w- c:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 19808 ----a-w- c:\windows\SysWow64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 19808 ----a-w- c:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 17760 ----a-w- c:\windows\SysWow64\api-ms-win-crt-string-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 17760 ----a-w- c:\windows\SysWow64\api-ms-win-crt-stdio-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 17760 ----a-w- c:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 17760 ----a-w- c:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 16224 ----a-w- c:\windows\SysWow64\api-ms-win-crt-runtime-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 16224 ----a-w- c:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 15712 ----a-w- c:\windows\SysWow64\api-ms-win-crt-convert-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 15712 ----a-w- c:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 14176 ----a-w- c:\windows\SysWow64\api-ms-win-crt-time-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 14176 ----a-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-2-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 14176 ----a-w- c:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 14176 ----a-w- c:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 13664 ----a-w- c:\windows\SysWow64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 13664 ----a-w- c:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 12640 ----a-w- c:\windows\SysWow64\api-ms-win-crt-process-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 12640 ----a-w- c:\windows\SysWow64\api-ms-win-crt-heap-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 12640 ----a-w- c:\windows\SysWow64\api-ms-win-crt-conio-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 12640 ----a-w- c:\windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 12640 ----a-w- c:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 12640 ----a-w- c:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 12128 ----a-w- c:\windows\SysWow64\api-ms-win-crt-utility-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 12128 ----a-w- c:\windows\SysWow64\api-ms-win-crt-locale-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 12128 ----a-w- c:\windows\SysWow64\api-ms-win-crt-environment-l1-1-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 12128 ----a-w- c:\windows\SysWow64\api-ms-win-core-synch-l1-2-0.dll
2015-09-16 13:30 . 2015-09-16 13:30 12128 ----a-w- c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-1.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 9"="c:\program files (x86)\IObit\Advanced SystemCare\ASCTray.exe" [2015-11-17 2010912]
"GUDelayStartup"="d:\program files (x86)\Glary Utilities 5\StartupManager.exe" [2015-02-12 37152]
"CCleaner Monitoring"="d:\program files\CCleaner\CCleaner64.exe" [2015-11-16 8591272]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Turbo Key"="c:\program files (x86)\ASUS\Turbo Key\TurboKey.exe" [2009-11-24 1874432]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2015-10-28 1067736]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2015-11-29 597040]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SpUninstallDeleteDir"="rmdir" [X]
.
c:\users\buebi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
CurseClientStartup.ccip [2015-11-29 0]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bigfoot Networks Killer Network Manager.lnk - d:\program files\Bigfoot Networks\Killer Network Manager\KillerNetManager.exe -minimized [2013-10-9 564224]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-disabled]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"ApnTBMon"="c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
"DivXMediaServer"="c:\program files (x86)\DivX\DivX Media Server\DivXMediaServer.exe"
.
R1 VBoxNetAdp;VirtualBox NDIS 6.0 Miniport Service;c:\windows\system32\DRIVERS\VBoxNetAdp6.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp6.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
R2 MBAMService;MBAMService;d:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;d:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys;c:\windows\SYSNATIVE\DRIVERS\asmthub3.sys [x]
R3 cmdvirth;COMODO Virtual Service Manager;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe [x]
R3 DrvAgent64;DrvAgent64;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys;c:\windows\SYSNATIVE\Drivers\TFsExDisk.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R4 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S0 amdide64;amdide64;c:\windows\system32\DRIVERS\amdide64.sys;c:\windows\SYSNATIVE\DRIVERS\amdide64.sys [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys;c:\windows\SYSNATIVE\DRIVERS\cmderd.sys [x]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys;c:\windows\SYSNATIVE\DRIVERS\cmdguard.sys [x]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys;c:\windows\SYSNATIVE\DRIVERS\cmdhlp.sys [x]
S1 GUBootStartup;GUBootStartup;c:\windows\System32\drivers\GUBootStartup.sys;c:\windows\SYSNATIVE\drivers\GUBootStartup.sys [x]
S2 AdvancedSystemCareService9;Advanced SystemCare Service 9;c:\program files (x86)\IObit\Advanced SystemCare\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare\ASCService.exe [x]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [x]
S2 Bigfoot Networks Killer Service;Bigfoot Networks Killer Service;d:\program files\Bigfoot Networks\Killer Network Manager\BFNService.exe;d:\program files\Bigfoot Networks\Killer Network Manager\BFNService.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 LGCoreTemp;Logitech CPU Core Tempurature;c:\program files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys;c:\program files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [x]
S2 LogiRegistryService;Logitech Gaming Registry Service;c:\program files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe;c:\program files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [x]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys;c:\windows\SYSNATIVE\DRIVERS\asmtxhci.sys [x]
S3 BfEdge7x64;Bigfoot Networks Killer Ethernet Service;c:\windows\system32\DRIVERS\Edge7x64.sys;c:\windows\SYSNATIVE\DRIVERS\Edge7x64.sys [x]
S3 BFN7x64;Bigfoot Networks Killer Gaming Service;c:\windows\system32\DRIVERS\Xeno7x64.sys;c:\windows\SYSNATIVE\DRIVERS\Xeno7x64.sys [x]
S3 LGBusEnum;Logitech Gaming Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGJoyXlCore;Logitech Translation Layer Driver (LGS);c:\windows\system32\drivers\LGJoyXlCore.sys;c:\windows\SYSNATIVE\drivers\LGJoyXlCore.sys [x]
S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x]
S3 LGSUsbFilt;Logitech Gaming KMDF USB Filter Driver;c:\windows\system32\DRIVERS\LGSUsbFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSUsbFilt.Sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{A6EADE66-0000-0000-484E-7E8A45000000}]
2015-11-18 16:22 286904 ----a-w- c:\program files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll
.
Inhalt des "geplante Tasks" Ordners
.
2015-11-29 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-12 09:10]
.
2015-11-28 c:\windows\Tasks\GlaryInitialize 5.job
- d:\program files (x86)\Glary Utilities 5\Initialize.exe [2015-02-12 08:03]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2015-11-29 15033976]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cistray.exe" [2015-04-01 1426136]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:Tabs
mDefault_Search_URL = https://safesearch.avira.com/#web/result?source=art&q=
mDefault_Page_URL = https://safesearch.avira.com/#web/result?source=art&q=
mStart Page = https://safesearch.avira.com/#web/result?source=art&q=
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = https://safesearch.avira.com/#web/result?source=art&q=
IE: {{d8f67242-b229-4065-95fa-391b077ed6ca} - {d8f67242-b229-4065-95fa-391b077ed6ca} - mscoree.dll
LSP: %SYSTEMROOT%\system32\BfLLR.dll
TCP: DhcpNameServer = 192.168.178.1
TCP: Interfaces\{4A67349A-00D0-4C9E-B689-69B4EF2FAF4F}: NameServer = 156.154.70.25,156.154.71.25
Handler: abs - {E00957BD-D0E1-4eb9-A025-7743FDC8B27B} - c:\windows\System32\mscoree.dll
FF - ProfilePath - c:\users\buebi\AppData\Roaming\Mozilla\Firefox\Profiles\w33kqme1.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-NPSStartup - (no file)
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.8.150\SSScheduler.exe
HKLM_Wow6432Node-ActiveSetup-{8A69D345-D564-463c-AFF1-A69D9E530F96} - c:\program files (x86)\Google\Chrome\Application\40.0.2214.115\Installer\chrmstp.exe
Toolbar-Locked - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1771663753-3355759307-1885394415-1000_Classes\Drive\ShellEx\FolderExtensions\{F6BF8414-962C-40FE-90F1-B80A7E72DB9A}]
@Denied: (C D 2 3 6) (CreatorAuthority-4)
@Denied: (C D 2 3 6) (Everyone)
@Allowed: (Read) (S-1-5-21-1771663753-3355759307-1885394415-1000)
@SACL=(02 0001)
@Ace=(0x11) (1 3) (S-1-16-12288)
"DriveMask"=dword:ffffffff
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_18_0_0_232_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_18_0_0_232_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Drive\shellex\FolderExtensions\{F6BF8414-962C-40FE-90F1-B80A7E72DB9A}]
@Denied: (C D 2 3 6) (CreatorAuthority-4)
@Denied: (C D 2 3 6) (Everyone)
@SACL=(02 0001)
@Ace=(0x11) (1 3) (S-1-16-12288)
"DriveMask"=dword:ffffffff
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_18_0_0_232_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_18_0_0_232_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_232.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.18"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_232.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_232.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_232.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\COMODO\CIS\Installer\Sym_Cam\CIS]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\CmdAgent\Mode\Configurations]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,59,00,53,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\CmdAgent\Mode\Data]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\CmdAgent\Mode\Options]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\system\Software\COMODO\Cam]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\system\Software\COMODO\Firewall Pro]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,59,00,53,00,\
.
[HKEY_LOCAL_MACHINE\system\VritualRoot\MACHINE\Software\Classes\Drive\ShellEx\FolderExtensions\{F6BF8414-962C-40FE-90F1-B80A7E72DB9A}]
@Denied: (C D 2 3 6) (CreatorAuthority-4)
@Denied: (C D 2 3 6) (Everyone)
@SACL=(02 0001)
@Ace=(0x11) (1 3) (S-1-16-12288)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\IObit\Advanced SystemCare\Monitor.exe
c:\program files (x86)\IObit\Smart Defrag 4\SmartDefrag.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2015-12-03 00:18:19 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2015-12-02 23:18
.
Vor Suchlauf: 4.128.964.608 Bytes frei
Nach Suchlauf: 3.942.727.680 Bytes frei
.
- - End Of File - - 6DB5AE83D3FB4797DF9994E162FC351A
A36C5E4F47E84449FF07ED3517B43A31 so da isses^^
Danke und Gruß Heinz |