Gewissen | 13.08.2011 12:35 | Die log.txt:
Combofix Logfile: Code:
ComboFix 11-08-13.01 - **** 13.08.2011 13:15:08.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3582.2438 [GMT 2:00]
ausgeführt von:: c:\users\****\Downloads\ComboFix.exe
AV: Kaspersky Security Suite CBE 11 *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}
FW: Kaspersky Security Suite CBE 11 *Disabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}
SP: Kaspersky Security Suite CBE 11 *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Autorun.inf
C:\downloader.exe
C:\readme.txt
C:\setup.exe
c:\windows\IsUn0407.exe
c:\windows\system32\Cache
c:\windows\system32\logs
.
.
((((((((((((((((((((((( Dateien erstellt von 2011-07-13 bis 2011-08-13 ))))))))))))))))))))))))))))))
.
.
2011-08-13 11:24 . 2011-08-13 11:24 -------- d-----w- c:\users\****\AppData\Local\temp
2011-08-12 14:48 . 2011-08-12 14:48 -------- d-----w- c:\program files\ESET
2011-08-12 09:02 . 2011-07-13 03:39 6881616 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{290E5EF8-8B85-4D93-8836-F32D456F169D}\mpengine.dll
2011-08-11 10:48 . 2011-08-11 10:48 -------- d-----w- c:\programdata\Tages
2011-08-11 10:44 . 2011-08-11 10:44 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2011-08-11 10:44 . 2011-08-11 10:44 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2011-08-11 08:29 . 2011-07-06 15:31 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-11 08:29 . 2011-06-17 16:03 375808 ----a-w- c:\windows\system32\winsrv.dll
2011-08-11 08:29 . 2011-06-06 10:59 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-08-11 08:29 . 2011-06-20 08:54 3602832 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-08-11 08:29 . 2011-06-20 08:54 3550096 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-08-11 08:29 . 2011-06-17 20:13 905104 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-10 19:00 . 2011-08-10 19:00 -------- d-----w- c:\users\****\AppData\Roaming\Malwarebytes
2011-08-10 19:00 . 2011-07-06 17:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-10 19:00 . 2011-08-10 19:00 -------- d-----w- c:\programdata\Malwarebytes
2011-08-10 19:00 . 2011-08-10 19:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-10 19:00 . 2011-07-06 17:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-10 14:18 . 2011-08-10 14:18 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-08-10 14:18 . 2011-08-10 14:18 22328 ----a-w- c:\users\****\AppData\Roaming\PnkBstrK.sys
2011-08-10 14:18 . 2011-08-10 14:18 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-08-10 14:18 . 2011-08-10 14:18 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-08-10 14:18 . 2011-08-10 14:18 669184 ----a-w- c:\windows\system32\pbsvc.exe
2011-08-10 14:17 . 2011-08-10 14:40 -------- d-----w- c:\programdata\Media Center Programs
2011-08-10 14:06 . 2011-08-10 14:06 -------- d-----w- c:\program files\Electronic Arts
2011-08-10 09:44 . 2011-08-10 09:44 -------- d-----w- c:\program files\Opticon
2011-08-06 19:53 . 2011-08-06 19:53 -------- d-----w- c:\program files\SimCity4 StartupManager
2011-08-04 14:08 . 2011-08-04 15:19 -------- d-----w- c:\programdata\SecTaskMan
2011-08-03 18:45 . 2011-08-03 18:45 -------- d-----w- c:\program files\Lionhead Studios Ltd
2011-07-30 00:45 . 2011-07-30 01:45 -------- d-----w- c:\users\****\AppData\Roaming\Skype
2011-07-30 00:45 . 2011-07-30 00:45 -------- d-----r- c:\program files\Skype
2011-07-30 00:45 . 2011-07-30 00:45 -------- d-----w- c:\programdata\Skype
2011-07-17 08:46 . 2011-07-21 12:29 -------- d-----w- c:\program files\GfK Internet-Monitor
2011-07-14 13:40 . 2011-07-14 13:40 -------- d-----w- c:\program files\Maxis
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-10 14:40 . 2010-07-08 14:02 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2011-06-24 14:20 . 2011-05-19 13:46 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-02 17:53 . 2011-06-02 17:53 94208 ----a-w- c:\windows\system32\dpl100.dll
2011-06-02 13:34 . 2011-07-13 12:05 2043392 ----a-w- c:\windows\system32\win32k.sys
2011-05-25 07:24 . 2011-06-10 20:12 615528 ----a-w- c:\windows\system32\nvvsvc.exe
2011-05-25 07:24 . 2011-06-10 20:12 2560616 ----a-w- c:\windows\system32\nvsvcr.dll
2011-05-25 07:24 . 2011-06-10 20:12 2557544 ----a-w- c:\windows\system32\nvsvc.dll
2011-05-25 07:24 . 2011-06-10 20:12 66664 ----a-w- c:\windows\system32\nvshext.dll
2011-05-25 07:24 . 2011-06-10 20:12 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-05-25 07:24 . 2011-06-10 20:12 3693672 ----a-w- c:\windows\system32\nvcpl.dll
2011-05-25 07:24 . 2011-06-10 20:12 543336 ----a-w- c:\windows\system32\easyupdatusapiu.dll
2011-05-25 07:24 . 2011-06-10 20:11 6555240 ----a-w- c:\windows\system32\nvwgf2um.dll
2011-05-25 07:24 . 2011-06-10 20:11 57960 ----a-w- c:\windows\system32\OpenCL.dll
2011-05-25 07:24 . 2011-06-10 20:11 16456296 ----a-w- c:\windows\system32\nvoglv32.dll
2011-05-25 07:24 . 2011-06-10 20:11 899688 ----a-w- c:\windows\system32\nvdispco3220150.dll
2011-05-25 07:24 . 2011-06-10 20:11 865896 ----a-w- c:\windows\system32\nvgenco322090.dll
2011-05-25 07:24 . 2011-06-10 20:11 11992680 ----a-w- c:\windows\system32\nvd3dum.dll
2011-05-25 07:24 . 2011-06-10 20:11 10589800 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2011-05-25 07:24 . 2011-06-10 20:11 2804328 ----a-w- c:\windows\system32\nvcuvid.dll
2011-05-25 07:24 . 2011-06-10 20:11 5301352 ----a-w- c:\windows\system32\nvcuda.dll
2011-05-25 07:24 . 2011-06-10 20:11 2335848 ----a-w- c:\windows\system32\nvapi.dll
2011-05-25 07:24 . 2011-06-10 20:11 2082408 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-05-25 07:24 . 2011-06-10 20:11 13011560 ----a-w- c:\windows\system32\nvcompiler.dll
2011-05-25 07:24 . 2011-06-10 20:11 12392 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2011-05-24 17:14 . 2010-07-08 09:30 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-05-19 14:18 . 2011-05-19 14:18 218688 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-06-16 04:32 . 2011-06-19 23:32 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\****\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\****\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\****\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\****\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Security Suite CBE 11\avp.exe" [2011-04-13 387696]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~1\KASPER~1\KASPER~1\kloehk.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ocs_SM
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 10:55 937920 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5.5ServiceManager]
2011-01-12 05:08 1523360 ----a-w- c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-03-21 18:56 1230704 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-04-08 10:59 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
2010-02-19 11:37 517096 ----a-w- c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
"RfxSrvTray"="c:\program files\Tobit Radio.fx\Client\rfx-tray.exe"
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
"Steam"="c:\program files\Steam\Steam.exe" -silent
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"SwitchBoard"=c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-419034727-2576159466-3780662473-1000]
"EnableNotificationsRef"=dword:00000002
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-07-15 14216]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-07-15 8456]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-03-31 36608]
R3 optousb;OPTO ELECTRONICS optousb;c:\windows\system32\DRIVERS\optousb.sys [2009-08-26 18432]
R3 optovcm;OPTO ELECTRONICS optovcm;c:\windows\system32\DRIVERS\optovcm.sys [2009-08-26 26368]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys [x]
R3 sc4stupmngrService;SimCity4 Startup Manager Service;c:\program files\SimCity4 StartupManager\sumservice.exe [2007-06-03 133120]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2010-02-24 10064]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R4 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-03-31 233472]
R4 GfK-Reporting-Service;GfK-Reporting-Service;c:\program files\GfK Internet-Monitor\GfK-Reporting.exe [2011-01-20 102400]
R4 GfK-Update-Service;GfK-Update-Service;c:\program files\GfK Internet-Monitor\GfK-Updater.exe [2011-01-20 180224]
R4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-10-04 135664]
R4 pr2agqwb;Loki Drivers Auto Removal (pr2agqwb);c:\windows\system32\pr2agqwb.exe svc [x]
R4 pr2agqwc;Loki Drivers Auto Removal (pr2agqwc);c:\windows\system32\pr2agqwc.exe svc [x]
R4 Radio.fx;Radio.fx Server;c:\program files\Tobit Radio.fx\Server\rfx-server.exe [2011-02-28 3577688]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-30 691696]
R4 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R4 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2011-01-12 1051968]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 hotcore3;hc3ServiceName;c:\windows\system32\DRIVERS\hotcore3.sys [2010-09-15 40560]
S0 pe3agqwb;Loki Environment Driver (pe3agqwb);c:\windows\system32\drivers\pe3agqwb.sys [2008-02-25 64616]
S0 pe3agqwc;Loki Environment Driver (pe3agqwc);c:\windows\system32\drivers\pe3agqwc.sys [2007-05-16 64880]
S0 ps6agqwc;Loki Synchronization Driver (ps6agqwc);c:\windows\system32\drivers\ps6agqwc.sys [2007-08-02 68208]
S0 ps7agqwb;Loki Synchronization Driver (ps7agqwb);c:\windows\system32\drivers\ps7agqwb.sys [2008-02-25 68208]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-05-19 218688]
S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2010-06-09 11352]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2010-04-22 22104]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-25 2214504]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-02 19984]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-07-06 22712]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2000-01-01 181792]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Inhalt des "geplante Tasks" Ordners
.
2011-08-13 c:\windows\Tasks\AbelssoftPreloader.job
- c:\program files\WashAndGo\AbelssoftPreloader.exe [2011-06-05 12:58]
.
2010-10-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-04 23:37]
.
2010-10-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-04 23:37]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2475029
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\****\AppData\Roaming\Mozilla\Firefox\Profiles\v6lrncg4.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Amazon.de
FF - prefs.js: browser.startup.homepage - www.google.de
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: network.proxy.type - 0
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
URLSearchHooks-{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2011-08-13 13:24
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien:
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-419034727-2576159466-3780662473-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:98,00,6d,56,38,ef,ac,8d,60,5c,02,da,20,c1,99,57,f0,8e,98,0c,b2,65,8d,
af,59,60,84,50,77,ad,1f,76,8e,c4,f2,0c,31,06,b4,eb,d9,da,b3,2b,94,92,72,81,\
"??"=hex:a1,5e,47,db,25,65,bb,27,8b,92,55,34,10,3f,d9,49
.
[HKEY_USERS\S-1-5-21-419034727-2576159466-3780662473-1000\Software\SecuROM\License information*]
"datasecu"=hex:c3,b8,76,c1,8a,b4,f8,4c,b6,cd,1c,5f,36,ee,89,fa,fb,7d,85,2f,f8,
fd,10,0a,c4,99,3e,d5,e4,9d,80,ad,eb,15,8c,43,0e,d2,ec,79,53,dc,92,03,b6,bb,\
"rkeysecu"=hex:fc,c0,7e,17,05,7d,fc,b5,1a,af,54,29,89,3b,60,32
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Zeit der Fertigstellung: 2011-08-13 13:26:35
ComboFix-quarantined-files.txt 2011-08-13 11:26
.
Vor Suchlauf: 19 Verzeichnis(se), 157.463.117.824 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 157.806.198.784 Bytes frei
.
Current=2 Default=2 Failed=8 LastKnownGood=6 Sets=1,2,3,4,5,6,8,27
- - End Of File - - 919994E9E9EDB74456139152078AEA3E[/QUOTE] --- --- --- |