| Memphistus | 12.02.2012 18:23 | So,
Ich habe jetzt den Combofix mit dem Script ausgeführt, diesmal kam aber komischerweise keine Fehlermeldung wegen Avast...
hier der Log: Code:
ComboFix 12-02-11.03 - Meik 12.02.2012 18:15:26.2.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.49.1031.18.8138.6579 [GMT 1:00]
ausgeführt von:: c:\users\Meik\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Meik\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-01-12 bis 2012-02-12 ))))))))))))))))))))))))))))))
.
.
2012-02-12 17:18 . 2012-02-12 17:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-11 16:05 . 2012-02-11 16:05 -------- d-----w- C:\_OTL
2012-02-09 16:59 . 2012-02-09 16:59 -------- d-----w- c:\program files (x86)\ESET
2012-02-09 16:13 . 2012-02-09 16:13 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-02-09 16:13 . 2012-02-09 16:13 -------- d-----w- c:\programdata\Malwarebytes
2012-02-09 16:13 . 2011-12-10 14:24 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-09 15:01 . 2012-02-09 15:01 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2012-02-09 14:54 . 2012-02-09 14:54 -------- d-----w- c:\program files (x86)\Common Files\Steam
2012-02-09 10:27 . 2012-02-09 10:27 -------- d-----w- c:\program files (x86)\7-Zip
2012-02-09 08:24 . 2012-02-09 08:24 -------- d-----w- c:\program files (x86)\Google
2012-02-09 08:24 . 2011-11-28 17:53 304472 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-02-09 08:24 . 2011-11-28 17:51 24408 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-02-09 08:24 . 2011-11-28 17:52 42328 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-02-09 08:24 . 2011-11-28 17:52 58712 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-02-09 08:24 . 2011-11-28 18:01 256960 ----a-w- c:\windows\system32\aswBoot.exe
2012-02-09 08:24 . 2011-11-28 17:54 591192 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-02-09 08:24 . 2011-11-28 17:52 66904 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-02-09 08:24 . 2011-11-28 18:01 41184 ----a-w- c:\windows\avastSS.scr
2012-02-09 08:24 . 2011-11-28 18:01 199816 ----a-w- c:\windows\SysWow64\aswBoot.exe
2012-02-09 08:24 . 2012-02-09 08:24 -------- d-----w- c:\programdata\AVAST Software
2012-02-09 08:24 . 2012-02-09 08:24 -------- d-----w- c:\program files\AVAST Software
2012-02-09 08:23 . 2012-02-09 08:23 -------- d-----w- c:\windows\system32\appmgmt
2012-02-09 03:33 . 2012-02-09 03:33 -------- d-----w- c:\program files (x86)\Microsoft WSE
2012-02-08 13:55 . 2012-02-08 13:55 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-02-08 13:55 . 2012-02-08 13:55 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2012-02-08 13:55 . 2012-02-08 13:55 -------- d-----w- c:\programdata\DAEMON Tools Lite
2012-02-07 15:08 . 2012-02-07 15:08 -------- d-----w- c:\program files (x86)\VideoLAN
2012-02-07 14:46 . 2012-02-07 14:46 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-02-07 14:46 . 2012-02-07 14:46 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-02-07 14:46 . 2012-02-07 14:46 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-02-07 14:46 . 2012-02-07 14:46 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-02-07 14:46 . 2012-02-07 14:46 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-02-07 14:46 . 2012-02-07 14:46 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-02-07 14:46 . 2012-02-07 14:46 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-02-07 14:46 . 2012-02-07 14:46 -------- d-----w- c:\program files (x86)\QuickTime
2012-01-25 13:52 . 2012-01-25 13:52 -------- d-----w- c:\windows\Sun
2012-01-22 10:38 . 2012-01-22 10:38 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
2012-01-22 10:36 . 2012-01-22 10:36 -------- d-----w- c:\program files (x86)\AMD APP
2012-01-22 10:35 . 2012-01-22 10:35 -------- d-----w- C:\ATI
2012-01-21 13:25 . 2012-01-21 13:25 -------- d-----w- c:\program files (x86)\Adobe Story
2012-01-21 13:24 . 2012-01-21 13:26 -------- d-----w- c:\program files\Common Files\Adobe
2012-01-21 13:23 . 2012-01-21 13:23 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR
2012-01-21 13:21 . 2012-01-21 13:25 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2012-01-20 18:54 . 2012-01-20 18:54 -------- d-----w- c:\programdata\CanonBJ
2012-01-20 18:54 . 2009-07-14 01:40 84992 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNBPP4.DLL
2012-01-20 18:15 . 2012-01-20 18:15 -------- d-----w- c:\programdata\Sony
2012-01-20 18:15 . 2012-01-20 18:15 -------- d-----w- c:\program files (x86)\Sony
2012-01-20 18:15 . 2012-01-20 18:15 -------- d-----w- c:\program files\Sony
2012-01-19 22:12 . 2012-01-19 22:12 -------- d-----w- c:\programdata\ASUS OC Profiles
2012-01-19 21:52 . 2012-01-19 21:52 16896 ----a-w- c:\windows\AsTaskSched.dll
2012-01-19 21:50 . 2010-11-08 13:57 14464 ----a-w- c:\windows\system32\drivers\AiChargerPlus.sys
2012-01-19 21:50 . 2008-12-02 19:05 184320 ----a-w- c:\windows\SysWow64\drivers\UpdateHelper.dll
2012-01-19 21:49 . 2012-01-19 21:49 -------- d-----w- c:\programdata\ASUS
2012-01-19 21:49 . 2012-01-19 21:49 -------- d-----w- c:\program files (x86)\ASUS
2012-01-19 21:49 . 2010-08-24 07:16 13440 ----a-r- c:\windows\SysWow64\drivers\AsIO.sys
2012-01-19 21:49 . 2010-06-29 07:41 28672 ----a-r- c:\windows\SysWow64\AsIO.dll
2012-01-19 21:49 . 2008-01-04 05:34 11832 ------w- c:\windows\SysWow64\drivers\AsInsHelp64.sys
2012-01-19 21:47 . 2012-02-09 01:46 -------- d-----w- c:\program files (x86)\JDownloader
2012-01-19 21:37 . 2012-01-21 20:02 -------- d-----w- C:\Fraps
2012-01-19 21:15 . 2012-01-19 21:15 -------- d-sh--w- c:\programdata\SecuROM
2012-01-19 21:15 . 2012-01-19 21:15 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2012-01-19 21:14 . 2012-01-19 21:15 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2012-01-19 21:14 . 2012-01-19 21:14 -------- d-----w- c:\windows\SysWow64\xlive
2012-01-19 20:53 . 2011-11-30 01:21 8822856 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DF8A2FC3-958E-4F10-86EE-9B79155C66AB}\mpengine.dll
2012-01-19 20:53 . 2011-11-15 13:29 270720 ------w- c:\windows\system32\MpSigStub.exe
2012-01-19 20:33 . 2012-01-19 20:33 -------- d-----w- c:\programdata\ATI
2012-01-19 20:32 . 2012-01-19 20:32 0 ----a-w- c:\windows\ativpsrm.bin
2012-01-19 20:28 . 2012-01-19 20:28 -------- d-----w- c:\program files (x86)\My Company Name
2012-01-19 20:26 . 2012-01-19 20:26 -------- d-----w- c:\program files (x86)\ATI Technologies
2012-01-19 20:26 . 2012-01-19 20:26 -------- d-----w- c:\program files\Common Files\ATI Technologies
2012-01-19 20:26 . 2010-11-16 23:04 115216 ----a-w- c:\windows\system32\drivers\AtihdW76.sys
2012-01-19 20:26 . 2011-11-10 02:18 58880 ----a-w- c:\windows\system32\coinst.dll
2012-01-19 20:23 . 2012-01-19 20:23 -------- d-----w- c:\program files (x86)\ASM104xUSB3
2012-01-19 20:22 . 2011-04-21 18:17 74272 ----a-w- c:\windows\system32\RtNicProp64.dll
2012-01-19 20:22 . 2011-04-21 18:17 471144 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2012-01-19 20:22 . 2011-04-21 18:17 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2012-01-19 20:19 . 2012-01-20 17:40 -------- dc----w- c:\windows\system32\DRVSTORE
2012-01-19 20:19 . 2010-12-16 04:06 47232 ----a-r- c:\windows\system32\drivers\usbfilter.sys
2012-01-19 20:19 . 2012-01-19 20:19 -------- d-----w- c:\program files\ATI
2012-01-19 20:12 . 2012-02-09 15:01 -------- d-----w- c:\users\Meik
2012-01-19 20:12 . 2012-01-19 20:12 -------- d-----w- c:\windows\SysWow64\Adobe
2012-01-19 20:11 . 2012-01-19 20:11 455680 ----a-w- c:\windows\system32\deploytk.dll
2012-01-19 20:11 . 2012-01-19 20:11 -------- d-----w- c:\program files\Java
2012-01-19 20:11 . 2012-01-19 20:11 411368 ----a-w- c:\windows\SysWow64\deploytk.dll
2012-01-19 20:11 . 2012-01-19 20:11 -------- d-----w- c:\program files (x86)\Java
2012-01-19 20:10 . 2012-01-19 20:10 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((( SnapShot@2012-02-12_15.28.36 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:54 . 2012-02-12 17:19 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-02-12 15:27 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-02-12 17:19 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-02-12 15:27 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-02-12 17:19 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-02-12 15:27 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-19 20:36 . 2012-02-12 15:51 26456 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-02-12 15:51 31008 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2012-01-19 20:24 . 2012-02-12 15:49 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-01-19 20:24 . 2012-02-12 15:28 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-01-19 20:24 . 2012-02-12 15:49 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2012-01-19 20:24 . 2012-02-12 15:28 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2012-01-19 20:24 . 2012-02-12 15:28 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-19 20:24 . 2012-02-12 15:49 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-19 20:24 . 2012-02-12 15:49 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-01-19 20:24 . 2012-02-12 15:28 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-01-19 20:24 . 2012-02-12 15:28 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-19 20:24 . 2012-02-12 15:49 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-19 20:16 . 2012-02-12 15:51 6720 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1943331422-757434833-6866547-1000_UserData.bin
- 2012-02-12 15:27 . 2012-02-12 15:27 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-02-12 17:19 . 2012-02-12 17:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:36 . 2012-02-12 15:54 607530 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2012-02-12 14:05 607530 c:\windows\system32\perfh009.dat
+ 2009-07-14 17:58 . 2012-02-12 15:54 645502 c:\windows\system32\perfh007.dat
- 2009-07-14 17:58 . 2012-02-12 14:05 645502 c:\windows\system32\perfh007.dat
+ 2009-07-14 02:36 . 2012-02-12 15:54 103908 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2012-02-12 14:05 103908 c:\windows\system32\perfc009.dat
- 2009-07-14 17:58 . 2012-02-12 14:05 126822 c:\windows\system32\perfc007.dat
+ 2009-07-14 17:58 . 2012-02-12 15:54 126822 c:\windows\system32\perfc007.dat
- 2009-07-14 05:01 . 2012-02-12 15:26 322272 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-02-12 17:18 322272 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 02:34 . 2012-02-11 15:57 9961472 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2012-02-12 16:43 9961472 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2012-02-09 08:26 . 2012-02-12 17:18 5073553 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1943331422-757434833-6866547-1000-8192.dat
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-01-24 3478336]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-11-25 98304]
"ASUS AiChargerPlus Execute"="c:\program files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe" [2010-11-08 465536]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-01-16 421736]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R2 gupdate;Google Update-Dienst (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-09 136176]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-09 136176]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
S0 AiChargerPlus;ASUS Charger Plus Driver;c:\windows\system32\DRIVERS\AiChargerPlus.sys [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [x]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-03 918144]
S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-02 915584]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [x]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2012-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-09 08:24]
.
2012-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-09 08:24]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 134384 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-19 11613288]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.2.1 192.168.2.1
FF - ProfilePath - c:\users\Meik\AppData\Roaming\Mozilla\Firefox\Profiles\ba7vtxnj.default\
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1943331422-757434833-6866547-1000\Software\SecuROM\License information*]
"datasecu"=hex:e5,6d,90,d2,fa,1a,ef,a9,fe,48,98,56,e4,e6,48,24,f8,9e,62,29,05,
e2,31,4b,44,4e,ac,cb,3c,d3,89,cf,fe,74,d1,63,85,25,6c,18,36,6b,bd,a2,5d,43,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}]
@Denied: (A 2) (Everyone)
@="IFlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib]
@="{6EF568F4-D437-4466-AA63-A3645136D93E}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\DAODx.exe
c:\program files (x86)\ASUS\AI Suite II\AsRoutineController.exe
c:\program files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe
c:\program files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe
c:\program files (x86)\ASUS\AI Suite II\AI Suite II.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-02-12 18:22:03 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2012-02-12 17:22
ComboFix2.txt 2012-02-12 15:30
.
Vor Suchlauf: 11 Verzeichnis(se), 34.436.530.176 Bytes frei
Nach Suchlauf: 12 Verzeichnis(se), 34.217.402.368 Bytes frei
.
- - End Of File - - BBB9DCB2456827930AB33933ADDA4FCD |