vitus333 | 10.10.2012 07:09 | Hallo cosinus,
anbei die Logdatei von Combofix. Leider funktionieren die verschiedenen Ordner noch immer nicht...
Combofix Logfile: Code:
ComboFix 12-10-08.03 - * 10.10.2012 7:36.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.2804.2085 [GMT 2:00]
ausgeführt von:: c:\users\*\Desktop\ComboFix.exe
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\*\videos\vlc-1.1.11-win32.exe
c:\windows\$NtUninstallKB29222$
c:\windows\$NtUninstallKB29222$\195300660
c:\windows\$NtUninstallKB29222$\3261968459\@
c:\windows\$NtUninstallKB29222$\3261968459\bckfg.tmp
c:\windows\$NtUninstallKB29222$\3261968459\cfg.ini
c:\windows\$NtUninstallKB29222$\3261968459\Desktop.ini
c:\windows\$NtUninstallKB29222$\3261968459\keywords
c:\windows\$NtUninstallKB29222$\3261968459\kwrd.dll
c:\windows\$NtUninstallKB29222$\3261968459\L\xadqgnnk
c:\windows\$NtUninstallKB29222$\3261968459\U\00000001.@
c:\windows\$NtUninstallKB29222$\3261968459\U\00000002.@
c:\windows\$NtUninstallKB29222$\3261968459\U\00000004.@
c:\windows\$NtUninstallKB29222$\3261968459\U\80000000.@
c:\windows\$NtUninstallKB29222$\3261968459\U\80000004.@
c:\windows\$NtUninstallKB29222$\3261968459\U\80000032.@
c:\windows\IsUn0407.exe
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-09-10 bis 2012-10-10 ))))))))))))))))))))))))))))))
.
.
2012-10-10 05:54 . 2012-10-10 05:54 29904 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1D6EBCB9-1679-4DC3-BE57-E3176420E59A}\MpKsl803654d6.sys
2012-10-10 05:50 . 2012-10-10 05:54 -------- d-----w- c:\users\*\AppData\Local\temp
2012-10-10 05:50 . 2012-10-10 05:50 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-10-10 05:50 . 2012-10-10 05:50 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-10-10 05:36 . 2012-10-10 05:36 29904 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1D6EBCB9-1679-4DC3-BE57-E3176420E59A}\MpKslf63a307a.sys
2012-10-09 19:30 . 2012-08-30 08:17 6980552 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1D6EBCB9-1679-4DC3-BE57-E3176420E59A}\mpengine.dll
2012-10-08 06:23 . 2012-08-30 08:17 6980552 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-10-04 08:16 . 2012-10-04 08:16 -------- d-----w- C:\_OTL
2012-09-28 08:36 . 2012-09-28 08:36 -------- d-----w- c:\program files\ESET
2012-09-26 06:24 . 2012-08-21 20:12 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
2012-09-23 05:49 . 2012-08-24 06:43 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-09-23 05:49 . 2012-08-24 07:34 140936 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2012-09-23 05:49 . 2012-08-24 06:47 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-09-23 05:49 . 2012-08-24 06:48 194048 ----a-w- c:\program files\Internet Explorer\IEShims.dll
2012-09-23 05:49 . 2012-08-24 06:47 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-09-12 07:58 . 2012-02-09 12:17 713784 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C61DB505-D973-4658-8FD1-6923D2EF8934}\gapaengine.dll
2012-09-12 07:51 . 2012-10-03 04:37 -------- d-----w- c:\program files\Microsoft Security Client
2012-09-12 07:02 . 2012-09-12 07:02 -------- d-----w- C:\ConvertTemp
2012-09-12 07:00 . 2012-09-12 07:02 -------- d-----w- C:\Output
2012-09-12 06:59 . 2012-09-12 06:59 -------- d-----w- c:\program files\Free Htm-Html to Image Jpg-Jpeg Converter
2012-09-12 06:58 . 2012-10-04 08:16 -------- d-----w- c:\program files\blekkotb_031
2012-09-12 06:58 . 2012-09-12 06:58 -------- d-----w- c:\users\*\AppData\Local\blekkotb_031
2012-09-12 06:36 . 2012-09-12 06:37 8281168 ----a-w- c:\programdata\Microsoft\BingBar\BBSvc\7.1.391.0oemBingBarSetup-Partner.EXE
2012-09-12 06:28 . 2012-08-22 17:16 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-09-12 06:28 . 2012-07-04 19:45 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-12 06:28 . 2012-08-22 17:16 1292144 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-12 06:28 . 2012-08-22 17:16 240496 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-12 06:28 . 2012-08-22 17:16 187760 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-12 06:28 . 2012-08-02 16:57 490496 ----a-w- c:\windows\system32\d3d10level9.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-09 06:33 . 2012-06-08 10:53 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-09 06:33 . 2011-07-04 21:05 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-07 15:04 . 2011-12-08 19:01 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-30 20:03 . 2012-08-30 20:03 193552 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-30 20:03 . 2012-03-20 18:44 99272 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2012-08-10 17:26 . 2012-08-10 17:26 486512 ----a-w- c:\windows\system32\NBMatS1SDK.dll
2012-08-10 17:26 . 2012-08-10 17:26 29232 ----a-w- c:\windows\system32\drivers\FPSensor.sys
2012-08-10 17:26 . 2012-08-10 17:26 60976 ----a-w- c:\windows\system32\drivers\mwlPSDVDisk.sys
2012-08-10 17:26 . 2012-08-10 17:26 18992 ----a-w- c:\windows\system32\drivers\mwlPSDFilter.sys
2012-08-10 17:26 . 2012-08-10 17:26 16432 ----a-w- c:\windows\system32\drivers\mwlPSDNserv.sys
2012-07-18 17:47 . 2012-08-18 16:40 2345984 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Akamai NetSession Interface"="c:\users\*\AppData\Local\Akamai\netsession_win.exe" [2012-08-10 4440896]
"Window Hide Tool"="c:\program files\Window Hide Tool\Window Hide Tool.exe" [2008-01-18 307200]
"Spotify Web Helper"="c:\*\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-08-18 1193176]
"Steam"="c:\program files\Steam\Steam.exe" [2012-08-23 1353080]
"Facebook Update"="c:\users\*\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-09-09 138096]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-04-13 1808784]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-04-21 281768]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-10 142680]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-10 176472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-10 175448]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"VitaKeyTSR"="c:\program files\EgisTec BioExcess\EgisTSR.exe" [2010-05-28 376176]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
.
c:\users\*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Facebook Messenger.lnk - c:\users\*\AppData\Local\Facebook\Messenger\2.1.4651.0\FacebookMessenger.exe [2012-9-25 247728]
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
VPN Client.lnk - c:\windows\Installer\{1CE60928-8325-49A8-8B06-633E48DD2B67}\Icon3E5562ED7.ico [2011-10-12 6144]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [x]
R3 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\7.1.391.0\SeaPort.exe [x]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S2 ABBYY.Licensing.PDFTransformer.Classic.3.0;ABBYY PDF Transformer 3.0 - Lizenzierungsdienst;c:\program files\ABBYY PDF Transformer 3.0\NetworkLicenseServer.exe [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [x]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [x]
S2 BBSvc;BingBar Service;c:\program files\Microsoft\BingBar\7.1.391.0\BBSvc.exe [x]
S2 EgisTec Data Security Service;EgisTec Data Security Service;c:\program files\EgisTec BioExcess\EgisDSService.exe [x]
S2 EgisTec Service;EgisTec Service;c:\program files\EgisTec BioExcess\EgisService.exe [x]
S2 FPSensor;EgisTec-Corp Fingerprint Reader Driver (FPSensor.sys);c:\windows\system32\Drivers\FPSensor.sys [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x86.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - MPKSL803654D6
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Inhalt des "geplante Tasks" Ordners
.
2012-10-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-08 06:33]
.
2012-10-09 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2839828771-2084243830-3291675471-1000Core.job
- c:\users\Vitus Sproten\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-09-09 20:05]
.
2012-10-10 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2839828771-2084243830-3291675471-1000UA.job
- c:\users\Vitus Sproten\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-09-09 20:05]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.de/
uInternet Settings,ProxyOverride = <local>
IE: &Citavi Picker... - file://c:\programdata\Swiss Academic Software\Citavi Picker\Internet Explorer\ShowContextMenu.html
IE: Free YouTube Download - c:\users\*\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to MP3 Converter - c:\users\*\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Zur Filterliste hinzufügen (WebWasher) - hxxp://-Web.Washer-/ie_add
TCP: DhcpNameServer = 212.87.96.9 217.21.186.202
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKCU-Run-RDReminder - (no file)
HKCU-Run-KPeerNexonEU - c:\nexon\NEXON_EU_Downloader\nxEULauncher.exe
HKLM-Run-PDFPrint - c:\program files\PDF24\pdf24.exe
AddRemove-8461-7759-5462-8226 - c:\program files\Vuze\uninstall.exe
AddRemove-Dll-Files.com Fixer_is1 - c:\program files\Dll-Files.com Fixer\unins000.exe
AddRemove-eSpeak_is1 - c:\program files\eSpeak\unins000.exe
AddRemove-FIFA MANAGER 10_is1 - c:\program files\FIFA MANAGER 10\unins000.exe
AddRemove-Fraps - c:\fraps\uninstall.exe
AddRemove-IrfanView - c:\program files\IrfanView\iv_uninstall.exe
AddRemove-NetDevil_LEGO_Universe_is1 - c:\program files\LEGO Software\LEGO Universe\uninstall.exe
AddRemove-SimCity 3000 - c:\windows\IsUn0407.exe
AddRemove-SMS Free Sender_is1 - c:\program files\SMS Free Sender\unins000.exe
AddRemove-Untis 2011 - c:\program files\Untis\2011\uninstall.exe
AddRemove-{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1 - c:\program files\PDF24\unins000.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_5891ae0.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{04533bf9-c276-11e0-b121-f0def119d7dc}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{236b843c-bc13-11e0-849c-f0def119d7dc}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2ceb97ca-b1de-11e0-80ac-f0def119d7dc}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2ceb97d0-b1de-11e0-80ac-f0def119d7dc}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2ceb980e-b1de-11e0-80ac-f0def119d7dc}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{446a82f8-0a1f-11e1-823b-00059a3c7800}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5e16f381-6468-11e1-a9cc-f0def119d7dc}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{608834fc-d6f7-11e0-aae9-f0def119d7dc}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{73de3fb7-27fc-11e1-a742-f0def119d7dc}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{73de3fbc-27fc-11e1-a742-f0def119d7dc}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8431e353-a350-11e0-8960-806e6f6e6963}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8431e354-a350-11e0-8960-806e6f6e6963}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8431e357-a350-11e0-8960-806e6f6e6963}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{898d3a34-13af-11e1-9534-f0def119d7dc}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{92c2ce46-defa-11e0-bce8-f0def119d7dc}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aaaf675f-e55b-11e1-9069-f0def119d7dc}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ae0d9465-15be-11e1-aa69-f0def119d7dc}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bffdf649-a3cf-11e0-98bf-f0def119d7dc}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bffdf656-a3cf-11e0-98bf-f0def119d7dc}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-2839828771-2084243830-3291675471-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:9b,8d,2b,74,2e,cc,cf,97,1e,98,1f,de,67,9b,c4,ad,a5,a7,e6,05,63,
6b,86,d3,81,d7,e6,b4,4a,09,49,79,18,57,2e,90,2f,39,34,41,ae,10,da,ce,1c,b1,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\conhost.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\system32\taskhost.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\conhost.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\conhost.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\program files\Common Files\Steam\SteamService.exe
c:\windows\system32\sppsvc.exe
c:\program files\Microsoft Security Client\MpCmdRun.exe
c:\windows\system32\taskhost.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-10-10 08:01:30 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2012-10-10 06:01
.
Vor Suchlauf: 14 Verzeichnis(se), 336.068.591.616 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 335.418.753.024 Bytes frei
.
- - End Of File - - 3F58CBC72DA09FEC73E40576C25B033E [/CODE]
--- --- ---
Danke im Voraus |