ComboFix 12-07-29.02 - Vitali 29.07.2012 20:20:52.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3070.2066 [GMT 2:00]
ausgeführt von:: c:\users\Vitali\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\14D92D366D.sys
.
----- Datei Replikatoren -----
.
c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
c:\program files\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\10665\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\10665\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\10665\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\10665\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\1082\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\1082\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\1082\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\1082\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\13353\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\13353\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\13353\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\13353\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\13854\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\13854\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\13854\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\13854\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\14962\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\14962\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\14962\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\14962\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\15874\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\15874\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\15874\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\15874\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\20124\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\20124\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\20124\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\20124\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\2032\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\2032\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\2032\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\2032\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\20331\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\20331\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\20331\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\20331\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\21629\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\21629\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\21629\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\21629\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\22315\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\22315\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\22315\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\22315\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\23695\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\23695\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\23695\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\23695\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\24202\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\24202\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\24202\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\24202\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\28080\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\28080\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\28080\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\28080\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\28169\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\28169\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\28169\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\28169\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\30325\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\30325\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\30325\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\30325\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\32007\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\32007\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\32007\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\32007\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\32420\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\32420\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\32420\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\32420\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\3539\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\3539\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\3539\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\3539\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\7118\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\7118\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\7118\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\7118\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\7410\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\7410\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\7410\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.1\7410\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\10665\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\10665\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\10665\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\10665\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\1082\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\1082\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\1082\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\1082\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\13353\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\13353\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\13353\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\13353\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\13854\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\13854\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\13854\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\13854\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\14962\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\14962\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\14962\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\14962\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\15874\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\15874\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\15874\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\15874\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\20124\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\20124\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\20124\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\20124\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\2032\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\2032\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\2032\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\2032\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\20331\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\20331\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\20331\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\20331\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\21629\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\21629\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\21629\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\21629\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\22315\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\22315\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\22315\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\22315\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\23695\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\23695\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\23695\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\23695\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\24202\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\24202\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\24202\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\24202\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\28080\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\28080\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\28080\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\28080\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\28169\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\28169\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\28169\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\28169\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\30325\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\30325\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\30325\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\30325\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\32007\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\32007\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\32007\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\32007\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\32420\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\32420\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\32420\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\32420\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\3539\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\3539\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\3539\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\3539\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\7118\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\7118\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\7118\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\7118\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\7410\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\7410\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\7410\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.1\7410\ReaderUpdater.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-06-28 bis 2012-07-29 ))))))))))))))))))))))))))))))
.
.
2012-07-29 18:27 . 2012-07-29 18:27 56200 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7CECA258-096A-4AFB-85E1-E5CA6A5C4228}\offreg.dll
2012-07-29 18:27 . 2012-07-29 18:29 -------- d-----w- c:\users\Vitali\AppData\Local\temp
2012-07-29 18:12 . 2012-06-29 08:44 6891424 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7CECA258-096A-4AFB-85E1-E5CA6A5C4228}\mpengine.dll
2012-07-29 10:45 . 2012-07-29 11:57 -------- d-----w- C:\FRST
2012-07-26 23:09 . 2012-07-26 23:10 -------- d---a-w- C:\tmbrfix
2012-07-26 17:35 . 2012-07-26 17:35 -------- d-----w- c:\programdata\AVS4YOU
2012-07-26 17:35 . 2012-07-26 17:35 -------- d-----w- c:\users\Vitali\AppData\Roaming\AVS4YOU
2012-07-26 17:35 . 2012-07-26 17:35 -------- d-----w- c:\program files\AVS4YOU
2012-07-26 17:35 . 2012-07-26 17:35 -------- d-----w- c:\program files\Common Files\AVSMedia
2012-07-26 17:35 . 2011-06-23 11:25 24576 ----a-w- c:\windows\system32\msxml3a.dll
2012-07-25 21:57 . 2012-07-25 21:58 -------- d-----w- C:\f2fd1fc9ca196f230987ce
2012-07-15 17:06 . 2012-07-15 22:08 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0
2012-07-05 17:51 . 2012-07-05 17:51 -------- d-----w- c:\users\Gast\AppData\Roaming\Lexware
2012-07-05 17:51 . 2012-07-05 17:51 -------- d-----w- c:\users\Gast\AppData\Local\Lexware
2012-07-05 17:17 . 2012-07-05 17:16 713784 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{739F64CE-F2D9-4BA9-BAD8-2DB6B462F67E}\gapaengine.dll
2012-07-05 17:16 . 2012-05-30 18:41 6762896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-07-05 17:13 . 2012-07-05 17:14 -------- d-----w- c:\program files\Microsoft Security Client
2012-07-05 05:24 . 2012-07-05 05:24 -------- d-----w- c:\program files\Common Files\Java
2012-07-05 05:24 . 2012-07-05 05:24 -------- d-----w- c:\program files\Oracle
2012-07-04 21:20 . 2012-07-04 21:20 -------- d-sh--w- c:\windows\system32\%APPDATA%
2012-07-02 19:28 . 2012-07-02 20:44 -------- d-----w- c:\programdata\Norton
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-04 21:11 . 2012-03-31 12:02 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-04 21:11 . 2011-07-16 12:11 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-02 22:19 . 2012-06-27 16:58 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-27 16:58 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-27 16:58 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-27 16:58 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-27 16:58 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-06-27 16:58 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-06-27 16:58 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-27 16:58 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:12 . 2012-06-27 16:58 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-05-31 10:25 . 2011-01-24 19:33 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-05-17 22:45 . 2012-06-24 21:48 1800192 ----a-w- c:\windows\system32\jscript9.dll
2012-05-17 22:35 . 2012-06-24 21:48 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-05-17 22:35 . 2012-06-24 21:48 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-05-17 22:29 . 2012-06-24 21:48 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-05-17 22:24 . 2012-06-24 21:48 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-05-15 01:05 . 2012-06-24 17:32 2343936 ----a-w- c:\windows\system32\win32k.sys
2012-05-13 22:10 . 2012-05-13 22:10 476960 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-05-04 17:29 . 2011-01-25 19:56 687504 ----a-w- c:\windows\system32\deployJava1.dll
2012-05-01 04:44 . 2012-06-24 17:32 164352 ----a-w- c:\windows\system32\profsvc.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Akamai NetSession Interface"="c:\users\Vitali\AppData\Local\Akamai\netsession_win.exe" [2012-05-26 4327744]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 648072]
"LexwareInfoService"="c:\program files\Common Files\Lexware\Update Manager\LxUpdateManager.exe" [2010-09-15 339312]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
.
c:\users\Vitali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2011-9-2 227712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [x]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
R3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\DRIVERS\s0016bus.sys [x]
R3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0016mdfl.sys [x]
R3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0016mdm.sys [x]
R3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0016mgmt.sys [x]
R3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\DRIVERS\s0016nd5.sys [x]
R3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0016obex.sys [x]
R3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\DRIVERS\s0016unic.sys [x]
R3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [x]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [x]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [x]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [x]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [x]
S2 DevoloNetworkService;devolo Network Service;c:\program files\devolo\dlan\devolonetsvc.exe [x]
S2 NPF_devolo;NetGroup Packet Filter Driver (devolo);c:\windows\system32\drivers\npf_devolo.sys [x]
S2 UsbClientService;UsbClientService;c:\program files\Synology\Assistant\UsbClientService.exe [x]
S3 busenum;Synology Virtual USB Hub;c:\windows\system32\DRIVERS\busenum.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
Akamai REG_MULTI_SZ Akamai
.
Inhalt des "geplante Tasks" Ordners
.
2012-07-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-13 13:34]
.
2012-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-13 13:34]
.
2012-07-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2306216949-1828932197-290674133-1000Core.job
- c:\users\Vitali\AppData\Local\Google\Update\GoogleUpdate.exe [2011-07-16 08:56]
.
2012-07-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2306216949-1828932197-290674133-1000UA.job
- c:\users\Vitali\AppData\Local\Google\Update\GoogleUpdate.exe [2011-07-16 08:56]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://
www.google.com/
uInternet Settings,ProxyOverride = 127.0.0.1:9421;<local>
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Vitali\AppData\Roaming\Mozilla\Firefox\Profiles\9n8f5017.default\
FF - prefs.js: browser.search.selectedEngine - google.de PWS
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.de/
FF - prefs.js: network.proxy.type - 4
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM-Run-Adobe ARM - c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
AddRemove-PyQt GPL v4.8.3 for Python v2.7 (x86) - c:\python27\Lib\site-packages\PyQt4\bin\Uninstall.exe
AddRemove-xampp - n:\xampp\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_4f7fccd.dll"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2306216949-1828932197-290674133-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*a*ï|çx]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-2306216949-1828932197-290674133-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*a*ï|çx\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2306216949-1828932197-290674133-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.*a*ï|çx]
"0"=hex:66,69,6c,65,3a,2f,2f,2f,4e,3a,2f,73,65,68,65,6e,2f,54,61,74,6f,72,74,
2f,32,30,31,32,30,31,30,31,5f,54,61,74,6f,72,74,2d,54,25,43,33,25,42,36,64,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-07-29 20:31:51 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2012-07-29 18:31
.
Vor Suchlauf: 16 Verzeichnis(se), 49.553.113.088 Bytes frei
Nach Suchlauf: 20 Verzeichnis(se), 50.219.458.560 Bytes frei
.
- - End Of File - - 4BB39601344CAF8557AF4DA6632A686D