[code]
Combofix Logfile: Code:
ComboFix 12-10-04.02 - *** 07.10.2012 10:26:58.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.49.1031.18.1023.641 [GMT 2:00]
ausgeführt von:: c:\dokumente und einstellungen\***\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\dokumente und einstellungen\Default User\WINDOWS
c:\dokumente und einstellungen\***\4.0
c:\dokumente und einstellungen\***\Eigene Dateien\~WRL0002.tmp
c:\dokumente und einstellungen\***\Eigene Dateien\~WRL0005.tmp
c:\dokumente und einstellungen\***\WINDOWS
c:\windows\IsUn0407.exe
c:\windows\setupapi.log
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
c:\windows\unin0407.exe
c:\windows\winhelp.ini
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-09-07 bis 2012-10-07 ))))))))))))))))))))))))))))))
.
.
2012-10-05 09:54 . 2012-10-05 09:54 -------- d-----w- C:\_OTL
2012-10-02 12:39 . 2012-10-02 12:39 -------- d-----w- c:\programme\ESET
2012-10-01 12:34 . 2012-10-01 12:34 -------- d-----w- c:\programme\Mozilla Maintenance Service
2012-09-29 20:12 . 2012-09-29 20:12 -------- d-----w- c:\dokumente und einstellungen\***\Logs
2012-09-29 20:12 . 2012-09-29 20:12 -------- d-----w- c:\dokumente und einstellungen\***\imvcache
2012-09-29 20:12 . 2012-09-29 20:12 -------- d-----w- c:\dokumente und einstellungen\***\Cache
2012-09-08 18:12 . 2012-09-08 18:12 -------- d-----w- c:\programme\Gemeinsame Dateien\Skype
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-07 15:04 . 2011-08-29 14:32 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-01 10:06 . 2012-09-01 10:06 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-01 10:05 . 2007-05-15 19:37 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-09-01 10:05 . 2010-08-10 17:54 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-29 08:51 . 2012-03-31 07:05 696520 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-29 08:51 . 2011-06-11 15:07 73416 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-28 15:05 . 2005-08-17 12:30 916992 ----a-w- c:\windows\system32\wininet.dll
2012-08-28 15:05 . 2005-08-17 12:29 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-08-28 15:05 . 2005-08-17 12:29 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2005-08-17 12:29 385024 ----a-w- c:\windows\system32\html.iec
2012-09-06 01:26 . 2012-10-01 12:34 266720 ----a-w- c:\programme\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\programme\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-12 65536]
"SpybotSD TeaTimer"="c:\programme\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\programme\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 98394]
"SynTPEnh"="c:\programme\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 688218]
"SoundMAXPnP"="c:\programme\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544]
"AGRSMMSG"="AGRSMMSG.exe" [2005-04-12 88358]
"TPSMain"="TPSMain.exe" [2005-08-03 266240]
"NDSTray.exe"="NDSTray.exe" [BU]
"Tvs"="c:\programme\TOSHIBA\Tvs\TvsTray.exe" [2005-04-05 73728]
"TFncKy"="TFncKy.exe" [BU]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"THotkey"="c:\programme\Toshiba\Toshiba Applet\thotkey.exe" [2005-07-06 356352]
"PadTouch"="c:\programme\TOSHIBA\Touch and Launch\PadExe.exe" [2004-11-17 1077327]
"QuickTime Task"="c:\programme\QuickTime\qttask.exe" [2008-09-06 413696]
"avgnt"="c:\programme\Avira\AntiVir Desktop\avgnt.exe" [2012-07-31 348664]
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^***^Startmenü^Programme^Autostart^Microsoft Office-Schnellstart.lnk]
path=c:\dokumente und einstellungen\***\Startmenü\Programme\Autostart\Microsoft Office-Schnellstart.lnk
backup=c:\windows\pss\Microsoft Office-Schnellstart.lnkStartup
.
[HKLM\~\startupfolder\C:^Dokumente und Einstellungen^***^Startmenü^Programme^Autostart^OpenOffice.org 2.2.lnk]
path=c:\dokumente und einstellungen\***\Startmenü\Programme\Autostart\OpenOffice.org 2.2.lnk
backup=c:\windows\pss\OpenOffice.org 2.2.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2005-06-23 19:33 57344 ----a-w- c:\programme\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVMWlanClient]
2006-06-23 09:24 343552 ----a-w- c:\programme\avmwlanstick\FRITZWLanMini.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2009-10-19 00:12 1983816 ----a-w- c:\programme\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Drag'n'Drop_Autolaunch]
2003-09-15 09:07 118784 ----a-w- c:\programme\Iomega HotBurn Pro\Autolaunch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy-PrintToolBox]
2004-01-14 01:10 409600 ----a-w- c:\programme\Canon\Easy-PrintToolBox\BJPSMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 02:22 1695232 ----a-w- c:\programme\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-09-06 14:09 413696 ----a-w- c:\programme\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
2005-05-13 09:01 118784 ----a-w- c:\programme\Toshiba\TOSHIBA Zoom-Dienstprogramm\SmoothView.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programme\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Programme\\Skype\\Phone\\Skype.exe"=
.
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [18.03.2012 09:35 36000]
R2 AntiVirSchedulerService;Avira Planer;c:\programme\Avira\AntiVir Desktop\sched.exe [18.03.2012 09:35 86224]
R2 BecHelperService;BecHelperService;c:\programme\3 Mobile Broadband\3Connect\BecHelperService.exe [24.03.2010 00:28 1737464]
S2 Ca504av;Mega Camera, WDM Video Capture;c:\windows\system32\Drivers\Ca504av.sys --> c:\windows\system32\Drivers\Ca504av.sys [?]
S2 SkypeUpdate;Skype Updater;c:\programme\Skype\Updater\Updater.exe [13.07.2012 13:28 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [31.03.2012 09:05 250568]
S3 FWLANUSB;AVM FRITZ!WLAN;c:\windows\system32\drivers\fwlanusb.sys [08.05.2010 16:42 264704]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [07.09.2009 16:55 7680]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\programme\McAfee Security Scan\2.0.181\McCHSvc.exe [15.01.2010 14:49 227232]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\programme\Mozilla Maintenance Service\maintenanceservice.exe [01.10.2012 14:34 114144]
S3 osppsvc;Office Software Protection Platform;c:\programme\Gemeinsame Dateien\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09.01.2010 21:37 4640000]
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - dnbudf
.
Inhalt des "geplante Tasks" Ordners
.
2012-10-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 08:51]
.
2008-11-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programme\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
2005-09-23 c:\windows\Tasks\Registrierungserinnerung 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2005-08-17 02:22]
.
2005-09-23 c:\windows\Tasks\Registrierungserinnerung 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2005-08-17 02:22]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page =
uInternet Settings,ProxyOverride = fritz.box;192.168.178.1
IE: &MSN Suche - c:\programme\MSN Toolbar Suite\TB\02.05.0000.1082\de-de\msntb.dll/search.htm
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Easy-WebPrint - Drucken - c:\programme\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Easy-WebPrint - Schnelldruck - c:\programme\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint - Vorschau - c:\programme\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint - Zu Druckliste hinzufügen - c:\programme\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\dokumente und einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\hll6qefd.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - about:home
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
MSConfigStartUp-Adobe Reader Speed Launcher - c:\programme\Adobe\Reader 8.0\Reader\Reader_sl.exe
AddRemove-3D Ultra MiniGolf Deluxe - c:\windows\IsUn0407.exe
AddRemove-Easy-WebPrint - c:\windows\IsUn0407.exe
AddRemove-LucasArts' Curse of Monkey Island - c:\windows\unin0407.exe
AddRemove-Microsoft Interactive Training - c:\windows\IsUn0407.exe
AddRemove-MUSICMATCH Jukebox - c:\windows\IsUn0407.exe
AddRemove-PC-Diagnose-Tool - c:\windows\IsUn0407.exe
AddRemove-Power Saver - c:\windows\IsUn0407.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-10-07 10:32
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Iomega Activity Disk2]
"ImagePath"="\"\""
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##tro-ps-s-7-cifs#sys#datanob]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
"_CommentFromDesktopINI"=""
"_LabelFromDesktopINI"=""
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##tro-ps-s-7-cifs#sys#datanob#ref_sys#Ref_MS_Appl]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
"_CommentFromDesktopINI"=""
"_LabelFromDesktopINI"=""
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##tro-ps-s-7-cifs#sys#datanob#SW_Dev_Tools]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
"_CommentFromDesktopINI"=""
"_LabelFromDesktopINI"=""
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,01,00,01,01,ee,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{016bc767-2c5a-11da-8710-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0fdc8215-c0be-11de-8ee8-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{118c9510-0efb-11dd-8b1c-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{32c785a0-cc5a-11de-8ef6-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,01,00,01,01,ee,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{32c785a1-cc5a-11de-8ef6-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ad72ca2-7fd2-11dd-8c57-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3bd66b20-542e-11da-8726-a32114d7a519}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{43514c60-1492-11da-9478-806d6172696f}]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{43514c61-1492-11da-9478-806d6172696f}]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{52b2a460-1456-11da-8525-806d6172696f}]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{52b2a461-1456-11da-8525-806d6172696f}]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a9b90d2-e5ce-11de-8f18-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6da7d5f0-0308-11dc-885f-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{71635d60-13ba-11da-b664-806d6172696f}]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{71635d61-13ba-11da-b664-806d6172696f}]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7d4b7611-db64-11dd-8ced-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{82ea63b0-41d3-11dd-8ba5-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8b19a6e1-c105-11db-87d9-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{96b92fe0-ca3d-11de-8eeb-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{97867230-40b8-11db-8761-ac350fb0bf1a}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9ee7fea2-ca51-11de-8eed-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9ee7fea3-ca51-11de-8eed-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9ef073e0-886e-11e1-9083-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9efd0a20-2c44-11da-870b-806d6172696f}]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9efd0a21-2c44-11da-870b-806d6172696f}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,cf,5f,5f,5f,5f,cf,cf,5f,5f,
5f,cf,cf,cf,5f,5f,5f,cf,cf,cf,5f,5f,5f,cf,cf,cf,5f,5f,5f,cf,cf,cf,5f,5f,cf,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a02ee100-0f2b-11da-a467-806d6172696f}]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,cf,5f,5f,5f,5f,cf,cf,5f,5f,
5f,cf,cf,cf,5f,5f,5f,cf,cf,cf,5f,5f,cf,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a02ee101-0f2b-11da-a467-806d6172696f}]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a76e5cc0-cb99-11de-8eef-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,01,00,01,01,ee,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a76e5cc3-cb99-11de-8eef-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b2388dd0-1b57-11dd-8b37-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bd2cc67e-75e1-11dc-8973-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5c24c21-0c5c-11df-8f5f-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d3fe9660-cbf1-11de-8ef5-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,01,00,01,01,ee,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d3fe9661-cbf1-11de-8ef5-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d7a09fc7-36d6-11e1-902f-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e0029cf0-92b5-11dd-8c71-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e459d790-5aaf-11df-8fc4-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,01,00,01,01,ee,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ebb78680-caa1-11e1-911c-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1582357080-547377736-1665707571-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ec3ec200-6b2f-11de-8e14-0013ce2858e2}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,\
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}]
@DACL=(02 0000)
"MenuText"="Sun Java Konsole"
"CLSID"="{1FBA04EE-3024-11d2-8F1F-0000F87ABD16}"
"ClsidExtension"="{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBC}"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\Extensions\{2670000A-7350-4f3c-8081-5663EE0C6C49}]
@DACL=(02 0000)
"KeyPath"="Yes"
"ButtonText"="An OneNote senden"
"MenuText"="An OneNote s&enden"
"ToolTip"="An OneNote senden"
"Default Visible"="Yes"
"HotIcon"="c:\\PROGRA~1\\MICROS~2\\Office14\\ONBttnIE.dll,103"
"Icon"="c:\\PROGRA~1\\MICROS~2\\Office14\\ONBttnIE.dll,103"
"CLSID"="{1FBA04EE-3024-11d2-8F1F-0000F87ABD16}"
"ClsidExtension"="{48E73304-E1D6-4330-914C-F5F514E3486C}"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\Extensions\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}]
@DACL=(02 0000)
"KeyPath"="Yes"
"ButtonText"="Verknüpfte &OneNote-Notizen"
"MenuText"="Verknüpfte &OneNote-Notizen"
"ToolTip"="Verknüpfte OneNote-Notizen"
"Default Visible"="Yes"
"HotIcon"="c:\\PROGRA~1\\MICROS~2\\Office14\\ONBTTN~1.DLL,103"
"Icon"="c:\\PROGRA~1\\MICROS~2\\Office14\\ONBTTN~1.DLL,103"
"CLSID"="{1FBA04EE-3024-11d2-8F1F-0000F87ABD16}"
"ClsidExtension"="{FFFDC614-B694-4AE6-AB38-5D6374584B52}"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\Extensions\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}]
@DACL=(02 0000)
"CLSID"="{1FBA04EE-3024-11D2-8F1F-0000F87ABD16}"
"ClsidExtension"="{53707962-6F74-2D53-2644-206D7942484F}"
"Default Visible"="Yes"
"MenuStatusBar"="Configure how Spybot - Search & Destroy protects your IE."
"MenuText"="Spybot - Search & Destroy Configuration"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583}]
@DACL=(02 0000)
"CLSID"="{1FBA04EE-3024-11d2-8F1F-0000F87ABD16}"
"MenuText"="@xpsp3res.dll,-20001"
"Exec"="%windir%\\Network Diagnostic\\xpnetdiag.exe"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}]
@DACL=(02 0000)
"ButtonText"="Messenger"
"CLSID"="{1FBA04EE-3024-11D2-8F1F-0000F87ABD16}"
"Default Visible"="Yes"
"Exec"="c:\\Programme\\Messenger\\msmsgs.exe"
"HotIcon"="c:\\Programme\\Messenger\\msmsgs.exe,302"
"Icon"="c:\\Programme\\Messenger\\msmsgs.exe,301"
"MenuText"="Windows Messenger"
"ToolTip"="Windows Messenger"
.
[HKEY_LOCAL_MACHINE\software\OldTimer Tools\OTL\Files]
@DACL=(02 0000)
"c:\\Programme\\Mozilla Firefox\\extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}\\chrome"=""
"c:\\Programme\\Mozilla Firefox\\extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}\\amulet-jslib"=""
"c:\\Programme\\Mozilla Firefox\\extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}"=""
"c:\\Programme\\Mozilla Firefox\\extensions"=""
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(832)
c:\windows\system32\Ati2evxx.dll
.
Zeit der Fertigstellung: 2012-10-07 10:35:14
ComboFix-quarantined-files.txt 2012-10-07 08:34
.
Vor Suchlauf: 30 Verzeichnis(se), 40.769.617.920 Bytes frei
Nach Suchlauf: 34 Verzeichnis(se), 40.722.956.288 Bytes frei
.
WindowsXP-KB310994-SP2-Home-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 2B9D4AF6F72C68FE6F8A20549919B3FA --- --- --- |