Code:
ComboFix 11-12-22.01 - Rambo 22.12.2011 12:29:21.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.8183.6586 [GMT 1:00]
ausgeführt von:: c:\users\Rambo\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\ntuser.dat
c:\users\Rambo\AppData\Roaming\chrtmp
.
.
((((((((((((((((((((((( Dateien erstellt von 2011-11-22 bis 2011-12-22 ))))))))))))))))))))))))))))))
.
.
2011-12-21 20:55 . 2011-12-21 20:55 -------- d-----w- C:\_OTL
2011-12-20 20:55 . 2011-12-20 20:55 -------- d-----w- c:\program files (x86)\ESET
2011-12-20 18:13 . 2011-12-20 18:13 -------- d-----w- c:\users\Rambo\AppData\Roaming\Avira
2011-12-20 18:08 . 2011-12-09 11:40 27760 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2011-12-20 18:08 . 2011-12-09 11:40 130760 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-12-20 18:08 . 2011-12-09 11:40 97312 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-12-20 18:08 . 2011-12-20 18:08 -------- d-----w- c:\programdata\Avira
2011-12-20 18:08 . 2011-12-20 18:08 -------- d-----w- c:\program files (x86)\Avira
2011-12-20 17:44 . 2011-12-20 17:45 -------- d-----w- c:\users\Rambo\AppData\Local\Google
2011-12-20 01:48 . 2011-12-20 01:48 -------- d-----w- c:\users\Rambo\AppData\Roaming\Malwarebytes
2011-12-20 01:48 . 2011-12-20 01:48 -------- d-----w- c:\programdata\Malwarebytes
2011-12-20 01:48 . 2011-12-20 01:48 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-12-20 01:48 . 2011-08-31 16:00 25416 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-12 03:12 . 2011-11-21 11:40 8822856 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FCDF302D-EA1F-49A9-97CE-10BB722E23E7}\mpengine.dll
2011-12-11 22:14 . 2011-12-11 22:14 -------- d-----w- c:\program files (x86)\THQ
2011-11-28 16:47 . 2011-11-28 17:09 -------- d-----w- c:\users\Rambo\AppData\Roaming\vlc
2011-11-26 22:27 . 2011-11-26 22:27 -------- d-----w- c:\program files (x86)\VirtualDJ
2011-11-25 19:13 . 2011-11-25 19:13 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2011-11-25 19:13 . 2011-11-25 19:13 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2011-11-25 19:13 . 2011-11-25 19:13 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2011-11-25 19:13 . 2011-11-25 19:13 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2011-11-25 19:13 . 2011-11-25 19:13 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2011-11-25 19:13 . 2011-11-25 19:13 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2011-11-25 19:13 . 2011-11-25 19:13 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2011-11-25 19:13 . 2011-11-25 19:13 -------- d-----w- c:\program files (x86)\QuickTime
2011-11-25 19:06 . 2011-11-25 19:06 -------- d-----w- c:\program files (x86)\Apple Software Update
2011-11-23 15:42 . 2011-11-23 15:42 -------- d-----w- c:\windows\system32\Macromed
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-22 11:37 . 2011-01-15 01:47 25640 ----a-w- c:\windows\gdrv.sys
2011-12-07 02:06 . 2010-02-09 22:35 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-11-23 15:42 . 2011-06-08 14:25 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-02 06:23 . 2011-11-02 06:23 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-11-02 06:23 . 2011-11-02 06:23 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-11-02 06:23 . 2011-11-02 06:23 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-11-02 06:23 . 2011-11-02 06:23 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-11-02 06:23 . 2011-11-02 06:23 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-11-02 06:23 . 2011-11-02 06:23 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-11-02 06:23 . 2011-11-02 06:23 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-11-02 06:23 . 2011-11-02 06:23 1798144 ----a-w- c:\windows\SysWow64\jscript9.dll
2011-11-02 06:23 . 2011-11-02 06:23 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-11-02 06:23 . 2011-11-02 06:23 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
2011-11-02 06:23 . 2011-11-02 06:23 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-11-02 06:23 . 2011-11-02 06:23 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-11-02 06:23 . 2011-11-02 06:23 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-11-02 06:23 . 2011-11-02 06:23 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-11-02 06:23 . 2011-11-02 06:23 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-11-02 06:23 . 2011-11-02 06:23 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-11-02 06:23 . 2011-11-02 06:23 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-11-02 06:23 . 2011-11-02 06:23 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-11-02 06:23 . 2011-11-02 06:23 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-11-02 06:23 . 2011-11-02 06:23 448512 ----a-w- c:\windows\system32\html.iec
2011-11-02 06:23 . 2011-11-02 06:23 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-11-02 06:23 . 2011-11-02 06:23 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-11-02 06:23 . 2011-11-02 06:23 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-02 06:23 . 2011-11-02 06:23 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-11-02 06:23 . 2011-11-02 06:23 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-11-02 06:23 . 2011-11-02 06:23 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-11-02 06:23 . 2011-11-02 06:23 2309120 ----a-w- c:\windows\system32\jscript9.dll
2011-11-02 06:23 . 2011-11-02 06:23 222208 ----a-w- c:\windows\system32\msls31.dll
2011-11-02 06:23 . 2011-11-02 06:23 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-11-02 06:23 . 2011-11-02 06:23 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-11-02 06:23 . 2011-11-02 06:23 160256 ----a-w- c:\windows\system32\wextract.exe
2011-11-02 06:23 . 2011-11-02 06:23 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-11-02 06:23 . 2011-11-02 06:23 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-11-02 06:23 . 2011-11-02 06:23 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-11-02 06:23 . 2011-11-02 06:23 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-11-02 06:23 . 2011-11-02 06:23 1389056 ----a-w- c:\windows\system32\wininet.dll
2011-11-02 06:23 . 2011-11-02 06:23 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-11-02 06:23 . 2011-11-02 06:23 12288 ----a-w- c:\windows\system32\mshta.exe
2011-11-02 06:23 . 2011-11-02 06:23 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-11-02 06:23 . 2011-11-02 06:23 114176 ----a-w- c:\windows\system32\admparse.dll
2011-11-02 06:23 . 2011-11-02 06:23 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-11-02 06:23 . 2011-11-02 06:23 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-10-24 13:29 . 2011-10-24 13:29 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2011-10-24 13:29 . 2011-10-24 13:29 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
2011-10-15 23:57 . 2011-10-15 23:57 235 ----a-w- c:\windows\SysWow64\nxEuUninstall.bat
2011-10-15 23:57 . 2011-10-15 23:57 446464 ----a-w- c:\windows\NEXON_EU_DownloaderUpdater.exe
2011-10-15 08:53 . 2011-11-01 02:32 837952 ----a-w- c:\windows\system32\easyupdatusapiu64.dll
2011-10-15 08:53 . 2011-11-01 02:31 7581504 ----a-w- c:\windows\system32\nvcuda.dll
2011-10-15 08:53 . 2011-11-01 02:31 7041856 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2011-10-15 08:53 . 2011-11-01 02:31 68928 ----a-w- c:\windows\system32\OpenCL.dll
2011-10-15 08:53 . 2011-11-01 02:31 61248 ----a-w- c:\windows\SysWow64\OpenCL.dll
2011-10-15 08:53 . 2011-11-01 02:31 5578560 ----a-w- c:\windows\SysWow64\nvcuda.dll
2011-10-15 08:53 . 2011-11-01 02:31 2542912 ----a-w- c:\windows\system32\nvcuvid.dll
2011-10-15 08:53 . 2011-11-01 02:31 24796992 ----a-w- c:\windows\system32\nvcompiler.dll
2011-10-15 08:53 . 2011-11-01 02:31 24742720 ----a-w- c:\windows\system32\nvoglv64.dll
2011-10-15 08:53 . 2011-11-01 02:31 2458432 ----a-w- c:\windows\SysWow64\nvapi.dll
2011-10-15 08:53 . 2011-11-01 02:31 2401088 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2011-10-15 08:53 . 2011-11-01 02:31 2232128 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-10-15 08:53 . 2011-11-01 02:31 2099520 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2011-10-15 08:53 . 2011-11-01 02:31 18871616 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2011-10-15 08:53 . 2011-11-01 02:31 17248576 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2011-10-15 08:53 . 2011-11-01 02:31 15693120 ----a-w- c:\windows\system32\nvd3dumx.dll
2011-10-15 08:53 . 2011-11-01 02:31 1533248 ----a-w- c:\windows\system32\nvdispco64.dll
2011-10-15 08:53 . 2011-11-01 02:31 1454400 ----a-w- c:\windows\system32\nvgenco64.dll
2011-10-15 08:53 . 2011-11-01 02:31 12971840 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2011-10-15 08:53 . 2010-05-06 10:26 8791360 ----a-w- c:\windows\system32\nvwgf2umx.dll
2011-10-15 08:53 . 2010-05-06 10:26 2808128 ----a-w- c:\windows\system32\nvapi64.dll
2011-10-15 08:53 . 2010-05-06 10:26 13205312 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2011-10-15 08:53 . 2010-04-28 16:49 5067584 ----a-w- c:\windows\system32\nvsvc64.dll
2011-10-15 08:53 . 2010-04-28 16:49 3074368 ----a-w- c:\windows\system32\nvsvcr.dll
2011-10-15 08:53 . 2010-04-28 16:49 222528 ----a-w- c:\windows\system32\nvmctray.dll
2011-10-15 08:53 . 2010-04-28 16:49 1640768 ----a-w- c:\windows\system32\nvvsvc.exe
2011-10-15 08:53 . 2010-04-28 16:49 137536 ----a-w- c:\windows\system32\nvshext.dll
2011-10-15 08:53 . 2010-04-28 16:49 10406208 ----a-w- c:\windows\system32\nvcpl.dll
2011-10-14 23:54 . 2011-10-14 23:54 321856 ----a-w- c:\windows\SysWow64\nvStreaming.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-10-02 284696]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-01-19 43632]
"BCU"="c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" [2009-10-15 375000]
"NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-10-21 106496]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-12-09 258512]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"DES2"="c:\program files (x86)\GIGABYTE\EnergySaver2\des2.exe" [2010-03-01 354856]
"SDBOK"="c:\program files (x86)\GIGABYTE\smart6\dbios\run.exe" [2009-07-06 207400]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x]
R3 appliandMP;appliandMP;c:\windows\system32\DRIVERS\appliand.sys [x]
R3 dump_wmimmc;dump_wmimmc;c:\program files (x86)\Cabal Online\GameGuard\dump_wmimmc.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 etdrv;etdrv;c:\windows\etdrv.sys [2011-02-01 25640]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2011-07-19 30528]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\rtl8187.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-12-09 86224]
S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-10-15 223464]
S2 DES2 Service;DES2 Service for Energy Saving.;c:\program files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [2009-06-17 68136]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-10-02 13336]
S2 JMB36X;JMB36X;c:\windows\SysWOW64\XSrvSetup.exe [2010-01-19 72304]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
S2 Smart TimeLock;Smart TimeLock Service;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [2009-10-13 114688]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2011-12-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1108714154-2074935787-2652410400-1000Core.job
- c:\users\Rambo\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-20 17:44]
.
2011-12-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1108714154-2074935787-2652410400-1000UA.job
- c:\users\Rambo\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-20 17:44]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-03-26 10135584]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.de/
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = local;*.local
IE: Free YouTube Download - c:\users\Rambo\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to MP3 Converter - c:\users\Rambo\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Öffnen mit WordPerfect - c:\program files (x86)\WordPerfect Office X3\Programs\WPLauncher.hta
TCP: DhcpNameServer = 192.168.1.1 193.189.244.194 193.189.244.202
FF - ProfilePath - c:\users\Rambo\AppData\Roaming\Mozilla\Firefox\Profiles\ts2hm3og.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-Uninstall_is1 - c:\program files (x86)\Common Files\DVDVideoSoft\unins000.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1108714154-2074935787-2652410400-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B08315AE-D4B8-3790-F6B8-351B4EABF241}*]
"halkalefdmpdcbmn"=hex:69,61,66,6c,6e,6d,63,61,64,6f,64,6b,66,65,61,66,6d,6c,
00,77
"iajlglhkipbohjibig"=hex:63,61,65,6c,6c,6c,00,00
"iafmgmkjeigjolbpjl"=hex:69,61,6b,6e,63,64,65,67,61,6e,70,61,6d,6d,68,6d,63,67,
00,77
"dbkkmccidellldlcfimpomegmldjinhcjjbfihpg"=hex:68,61,61,62,64,6a,62,6e,6e,66,
67,70,6d,6d,62,65,00,00
"jbkkmccidellldlcfimpllgkbmnpnfennboojhnfhnaenkajjkcc"=hex:68,61,61,62,64,6a,
62,6e,6e,66,67,70,6d,6d,62,65,00,00
"dbkkmccidellldlcfimpnknimlmlbnpdckeihgjg"=hex:62,61,6c,6d,00,00
.
[HKEY_USERS\S-1-5-21-1108714154-2074935787-2652410400-1000\Software\SecuROM\License information*]
"datasecu"=hex:41,61,ad,51,b5,41,eb,7f,d8,9e,bc,1d,ad,19,d2,a1,5e,bc,b9,3c,4f,
a8,fd,2c,db,d7,d2,69,1f,a4,76,f4,cc,77,3e,eb,a2,ef,c6,2c,57,be,3f,b3,ff,54,\
"rkeysecu"=hex:29,5e,d3,a4,52,d7,ca,da,9f,67,fa,ee,b5,6b,58,d4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\SysWOW64\PSIService.exe
c:\program files (x86)\GIGABYTE\smart6\dbios\SDBMSG.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2011-12-22 12:41:20 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2011-12-22 11:41
.
Vor Suchlauf: 15 Verzeichnis(se), 271.665.119.232 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 271.133.011.968 Bytes frei
.
- - End Of File - - 437FA0D5E47B12440F919A93572F9F39 |