vinnolowell | 14.01.2016 14:00 | Code:
ComboFix 16-01-07.01 - Vincent 14.01.2016 13:39:29.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.4094.1479 [GMT 1:00]
ausgeführt von:: c:\users\Vincent\Downloads\ComboFix.exe
AV: AVG AntiVirus Free Edition *Disabled/Updated* {4D41356F-32AD-7C42-C820-63775EE4F413}
SP: AVG AntiVirus Free Edition *Disabled/Updated* {F620D48B-1497-73CC-F290-58052563BEAE}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\12207674260919470355
c:\programdata\12207674260919470355\cd5b15e575e1c3d0b52bd23e8f2c2afb.ini
c:\programdata\12207674260919470355\d29505caeb4fd80db52bd23e8f2c2afb.ini
.
.
((((((((((((((((((((((( Dateien erstellt von 2015-12-14 bis 2016-01-14 ))))))))))))))))))))))))))))))
.
.
2016-01-14 12:45 . 2016-01-14 12:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-01-14 10:47 . 2016-01-14 12:33 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird
2016-01-14 10:22 . 2016-01-14 11:47 -------- d-----w- C:\FRST
2016-01-13 07:56 . 2015-12-12 18:26 10949120 ----a-w- c:\program files\Internet Explorer\F12Resources.dll
2016-01-11 14:15 . 2016-01-14 08:30 -------- d-----w- c:\program files (x86)\RemoveWAT
2015-12-27 13:37 . 2015-12-27 13:37 -------- d-----r- C:\Sandbox
2015-12-27 13:18 . 2015-12-27 13:18 -------- d-----r- c:\program files (x86)\Skype
2015-12-27 13:18 . 2015-12-27 13:18 -------- d-----w- c:\program files (x86)\Common Files\Skype
2015-12-27 13:02 . 2015-12-27 13:02 381608 ----a-w- c:\windows\system32\drivers\sptd.sys
2015-12-25 01:47 . 2015-12-25 01:47 -------- d-----w- c:\users\Vincent\AppData\Local\GWX
2015-12-24 13:35 . 2015-12-24 13:37 -------- d-s---w- c:\windows\system32\GWX
2015-12-24 13:35 . 2015-12-24 13:35 -------- d-s---w- c:\windows\SysWow64\GWX
2015-12-24 13:15 . 2015-08-05 17:56 22528 ----a-w- c:\windows\system32\icaapi.dll
2015-12-24 13:15 . 2015-08-05 17:06 39936 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2015-12-24 13:10 . 2015-08-27 18:18 2004480 ----a-w- c:\windows\system32\msxml6.dll
2015-12-24 13:10 . 2015-08-27 18:18 1887232 ----a-w- c:\windows\system32\msxml3.dll
2015-12-24 13:10 . 2015-08-27 18:13 2048 ----a-w- c:\windows\system32\msxml6r.dll
2015-12-24 13:10 . 2015-08-27 18:13 2048 ----a-w- c:\windows\system32\msxml3r.dll
2015-12-24 13:10 . 2015-08-27 17:58 1391104 ----a-w- c:\windows\SysWow64\msxml6.dll
2015-12-24 13:10 . 2015-08-27 17:58 1241088 ----a-w- c:\windows\SysWow64\msxml3.dll
2015-12-24 13:10 . 2015-08-27 17:51 2048 ----a-w- c:\windows\SysWow64\msxml6r.dll
2015-12-24 13:10 . 2015-08-27 17:51 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
2015-12-24 12:40 . 2015-11-03 19:04 241664 ----a-w- c:\windows\system32\els.dll
2015-12-24 12:40 . 2015-11-03 18:55 179712 ----a-w- c:\windows\SysWow64\els.dll
2015-12-17 11:36 . 2015-12-17 11:36 -------- d-----w- c:\program files (x86)\Electronic Arts
2015-12-17 08:17 . 2015-12-17 08:26 163644 ----a-w- c:\windows\SysWow64\drivers\SECDRV.SYS
2015-12-17 08:17 . 2015-12-17 08:17 -------- d-sh--w- c:\windows\ftpcache
2015-12-15 15:12 . 2015-12-15 17:33 -------- d-----w- c:\programdata\TmForever
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-01-14 09:28 . 2015-01-18 10:30 25640 ----a-w- c:\windows\gdrv.sys
2016-01-13 20:06 . 2015-01-18 13:28 143671360 ----a-w- c:\windows\system32\MRT.exe
2016-01-07 16:24 . 2015-01-18 11:14 796864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2016-01-07 16:24 . 2015-01-18 11:14 142528 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2016-01-05 11:55 . 2015-02-03 16:40 214392 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2016-01-05 11:55 . 2015-02-03 16:40 214392 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2015-12-30 18:37 . 2016-01-13 07:56 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2015-12-09 18:58 . 2015-12-09 18:58 1070232 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2015-12-08 19:07 . 2009-07-14 00:22 1393152 ----a-w- c:\windows\system32\WMALFXGFXDSP.dll
2015-11-24 09:28 . 2015-04-01 09:00 97888 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2015-11-06 14:50 . 2015-11-06 14:50 184240 ----a-w- c:\windows\system32\drivers\avgdiska.sys
2015-11-06 14:49 . 2015-11-06 14:49 313776 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys
2015-11-06 14:49 . 2015-11-06 14:49 256432 ----a-w- c:\windows\system32\drivers\avgmfx64.sys
2015-10-29 17:50 . 2015-12-24 13:14 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2015-10-29 17:50 . 2015-12-24 13:14 309248 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2015-10-29 17:50 . 2015-12-24 13:14 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2015-10-29 17:50 . 2015-12-24 13:14 103424 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2015-10-29 17:49 . 2015-12-24 13:14 562176 ----a-w- c:\windows\apppatch\AcLayers.dll
2015-10-29 17:49 . 2015-12-24 13:14 470528 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2015-10-29 17:49 . 2015-12-24 13:14 2178560 ----a-w- c:\windows\apppatch\AcGenral.dll
2015-10-29 17:49 . 2015-12-24 13:14 211968 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2015-10-29 17:39 . 2015-12-24 13:14 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2015-10-21 15:16 . 2015-10-21 15:16 284080 ----a-w- c:\windows\system32\drivers\avgldx64.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Spotify Web Helper"="c:\users\Vincent\AppData\Roaming\Spotify\SpotifyWebHelper.exe" [2015-12-29 2346096]
"AirDroid 3"="c:\program files (x86)\AirDroid\AirDroid.exe" [2015-12-23 7739904]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AVG_UI"="c:\program files (x86)\AVG\Av\avgui.exe" [2015-12-09 3855272]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2015-06-08 334896]
"StartCCC"="c:\program files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2015-08-04 767176]
"AvgUi"="c:\program files (x86)\AVG\Framework\Common\avguix.exe" [2015-12-08 1139112]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Mozilla Thunderbird.lnk - c:\program files (x86)\Mozilla Thunderbird\thunderbird.exe [2016-1-14 490952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AvgAMPS;AvgAMPS;c:\program files (x86)\AVG\Av\avgamps.exe;c:\program files (x86)\AVG\Av\avgamps.exe [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 Origin Client Service;Origin Client Service;c:\program files (x86)\Origin\OriginClientService.exe;c:\program files (x86)\Origin\OriginClientService.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 amdkmpfd;AMD PCI Root Bus Lower Filter;c:\windows\system32\DRIVERS\amdkmpfd.sys;c:\windows\SYSNATIVE\DRIVERS\amdkmpfd.sys [x]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsha.sys [x]
S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys;c:\windows\SYSNATIVE\DRIVERS\avgloga.sys [x]
S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 Avgdiska;AVG Disk Driver;c:\windows\system32\DRIVERS\avgdiska.sys;c:\windows\SYSNATIVE\DRIVERS\avgdiska.sys [x]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsdrivera.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgldx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys;c:\windows\SYSNATIVE\DRIVERS\avgtdia.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [x]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 Apple Mobile Device Service;Apple Mobile Device Service;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [x]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\Av\avgidsagent.exe;c:\program files (x86)\AVG\Av\avgidsagent.exe [x]
S2 avgsvc;AVG Service;c:\program files (x86)\AVG\Framework\Common\avgsvca.exe;c:\program files (x86)\AVG\Framework\Common\avgsvca.exe [x]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\Av\avgwdsvcx.exe;c:\program files (x86)\AVG\Av\avgwdsvcx.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 WtuSystemSupport;WtuSystemSupport;c:\program files (x86)\AVG Web TuneUp\WtuSystemSupport.exe;c:\program files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2015-08-19 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-18 16:24]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-06-25 7883296]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = https://mysearch.avg.com/?cid={B9173B14-C565-4FBD-AA06-AACB419AAAAF}&mid=c92e97a1910247cdb5aad16d5b392bc6-06aebd248b02972cb6f5b04162e84b15f81fcf27&lang=de&ds=AVG&coid=avgtbavg&cmpid=0215av&pr=fr&d=2015-02-27 13:56&v=4.1.0.411&pid=wtu&sg=&sap=hp
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Vincent\AppData\Roaming\Mozilla\Firefox\Profiles\2jnyus8b.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: network.proxy.type - 4
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2751165182-406128407-2171943087-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (S-1-5-21-2751165182-406128407-2171943087-1000)
@Denied: (2) (LocalSystem)
"Progid"="ThunderbirdEML"
.
[HKEY_USERS\S-1-5-21-2751165182-406128407-2171943087-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_USERS\S-1-5-21-2751165182-406128407-2171943087-1000\Software\SecuROM\License information*]
"datasecu"=hex:f7,27,c1,37,34,f0,76,38,92,6e,3d,f3,63,a2,87,dc,db,3d,10,da,e1,
f9,86,51,c5,c0,87,b6,29,3f,d0,88,91,5d,5e,ee,1b,63,ac,cc,6e,da,6a,a3,27,27,\
"rkeysecu"=hex:b1,eb,cb,ad,f2,17,be,b4,81,bc,16,18,52,92,fb,73
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2016-01-14 13:49:33
ComboFix-quarantined-files.txt 2016-01-14 12:49
.
Vor Suchlauf: 16 Verzeichnis(se), 46.266.220.544 Bytes frei
Nach Suchlauf: 23 Verzeichnis(se), 49.556.017.152 Bytes frei
.
- - End Of File - - 940A8F2F43C69DDAFA7B9AA9B2EB183A
A36C5E4F47E84449FF07ED3517B43A31 Ich hoffe, dass das das Dokument ist, welches sie benötigen :) |