Code:
ComboFix 13-12-17.02 - PAULO 18.12.2013 10:09:24.1.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.41.1031.18.3069.1132 [GMT 1:00]
ausgeführt von:: c:\users\PAULO\Desktop\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\SafeSaver
c:\program files\SafeSaver\sprote~1.dll.ftf
c:\users\PAULO\AppData\Local\Temp\c25e8b3d-33a7-42bf-85e6-6880c6753136\CliSecureRT.dll
c:\users\PAULO\AppData\Roaming\Mozilla\Firefox\Profiles\r709548e.default\extensions\yoaa7_ofz@mutpeuyeqht-.org
c:\users\PAULO\AppData\Roaming\Mozilla\Firefox\Profiles\r709548e.default\extensions\yoaa7_ofz@mutpeuyeqht-.org\bootstrap.js
c:\users\PAULO\AppData\Roaming\Mozilla\Firefox\Profiles\r709548e.default\extensions\yoaa7_ofz@mutpeuyeqht-.org\chrome.manifest
c:\users\PAULO\AppData\Roaming\Mozilla\Firefox\Profiles\r709548e.default\extensions\yoaa7_ofz@mutpeuyeqht-.org\install.rdf
c:\windows\unin0407.exe
.
.
((((((((((((((((((((((((((((((((((((((( Treiber/Dienste )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_RKHIT
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-11-18 bis 2013-12-18 ))))))))))))))))))))))))))))))
.
.
2013-12-18 09:20 . 2013-12-18 09:20 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-12-17 16:53 . 2013-12-04 02:57 7760024 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8B26911E-6AC1-4482-B1AA-2CFAD85D680D}\mpengine.dll
2013-12-17 10:47 . 2013-12-17 10:47 -------- d-----w- c:\users\PAULO\AppData\Local\Opera Software
2013-12-17 10:46 . 2013-12-17 10:46 -------- d-----w- c:\users\PAULO\AppData\Roaming\Opera Software
2013-12-17 01:13 . 2013-12-17 01:13 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2013-12-16 14:50 . 2013-12-16 14:50 83808 ----a-w- c:\windows\system32\NicInE6.dll
2013-12-16 14:50 . 2013-12-16 14:50 232296 ----a-w- c:\windows\system32\drivers\e1e6032.sys
2013-12-16 14:35 . 2013-12-16 14:35 9619872 ----a-w- c:\windows\system32\nvopencl.dll
2013-12-16 14:35 . 2013-12-16 14:35 893728 ----a-w- c:\windows\system32\nvdispgenco3233182.dll
2013-12-16 14:35 . 2013-12-16 14:35 22951200 ----a-w- c:\windows\system32\nvoglv32.dll
2013-12-16 14:35 . 2013-12-16 14:35 10446112 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2013-12-16 14:35 . 2013-12-16 14:35 1049888 ----a-w- c:\windows\system32\nvdispco3233182.dll
2013-12-16 14:35 . 2013-12-16 14:35 9663656 ----a-w- c:\windows\system32\nvcuda.dll
2013-12-16 14:35 . 2013-12-16 14:35 2947872 ----a-w- c:\windows\system32\nvcuvid.dll
2013-12-16 14:35 . 2013-12-16 14:35 2747680 ----a-w- c:\windows\system32\nvcuvenc.dll
2013-12-16 14:35 . 2013-12-16 14:35 17560352 ----a-w- c:\windows\system32\nvcompiler.dll
2013-12-16 14:33 . 2013-12-17 10:59 -------- d-----w- c:\program files\FileHippo.com
2013-12-16 14:15 . 2013-12-16 14:15 -------- d-----w- C:\FRST
2013-12-16 12:28 . 2013-12-16 12:29 -------- d-----w- C:\5dc6eb3b0a3bdca6bc002fb2174d
2013-12-16 10:49 . 2013-12-16 10:49 -------- d-----w- c:\users\PAULO\AppData\Local\Secunia PSI
2013-12-16 10:44 . 2013-12-16 10:44 -------- d-----w- c:\program files\Secunia
2013-12-13 02:31 . 2013-12-13 02:31 4583424 ----a-w- c:\windows\system32\GPhotos.scr
2013-12-06 17:32 . 2013-12-06 17:32 -------- d-----w- c:\program files\7-Zip
2013-12-06 15:54 . 2013-12-06 15:54 -------- d-----w- c:\users\PAULO\AppData\Local\Logitech® Webcam-Software
2013-12-04 13:19 . 2013-12-16 10:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-12-04 13:19 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-12-04 13:19 . 2013-12-04 13:19 -------- d-----w- c:\program files\Tweaking.com
2013-11-25 20:43 . 2013-11-25 20:43 -------- d-----w- C:\MGADiagToolOutput
2013-11-25 20:42 . 2003-03-25 05:00 9216 ----a-w- c:\windows\proxycfg.exe
2013-11-25 20:42 . 2013-11-25 20:43 -------- d-----w- C:\AULOGS
2013-11-25 19:55 . 2013-12-17 10:46 -------- d-----w- c:\program files\CCleaner
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-18 09:05 . 2013-07-03 17:42 410528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-12-18 09:05 . 2013-07-03 17:42 54832 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2013-12-18 09:05 . 2013-07-03 17:42 57672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-12-18 09:05 . 2013-07-03 17:42 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-12-18 09:05 . 2013-07-03 17:42 180248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-12-18 09:05 . 2013-07-03 17:42 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-12-18 09:05 . 2013-07-03 17:42 270240 ----a-w- c:\windows\system32\aswBoot.exe
2013-12-18 09:05 . 2013-07-03 17:41 43152 ----a-w- c:\windows\avastSS.scr
2013-12-16 14:50 . 2007-09-24 07:42 317240 ----a-w- c:\windows\system32\Prounstl.exe
2013-12-16 14:35 . 2013-02-25 22:22 15862272 ----a-w- c:\windows\system32\nvwgf2um.dll
2013-12-16 14:35 . 2013-02-25 22:22 15218504 ----a-w- c:\windows\system32\nvd3dum.dll
2013-12-16 14:35 . 2013-02-25 22:22 2697248 ----a-w- c:\windows\system32\nvapi.dll
2013-12-16 10:44 . 2012-04-04 22:28 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-12-16 10:44 . 2011-05-25 01:58 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-11-19 02:33 . 2009-10-02 16:01 230048 ------w- c:\windows\system32\MpSigStub.exe
2013-11-16 16:42 . 2013-07-03 17:42 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-11-11 14:26 . 2010-04-03 16:27 4321056 ----a-w- c:\windows\system32\nvcpl.dll
2013-11-11 14:26 . 2010-04-03 16:27 3036960 ----a-w- c:\windows\system32\nvsvc.dll
2013-11-11 14:26 . 2010-04-03 16:27 664352 ----a-w- c:\windows\system32\nvvsvc.exe
2013-11-11 14:26 . 2010-04-03 16:27 209184 ----a-w- c:\windows\system32\nvmctray.dll
2013-11-11 14:26 . 2009-09-19 04:15 62752 ----a-w- c:\windows\system32\nvshext.dll
2013-10-14 18:41 . 2013-09-17 09:58 21576 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2013-10-08 05:51 . 2012-06-16 17:39 873384 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-10-08 05:51 . 2010-04-18 14:50 796072 ----a-w- c:\windows\system32\deployJava1.dll
2013-10-08 05:50 . 2013-10-20 12:03 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-09-27 14:36 . 2013-09-27 14:36 53248 ----a-r- c:\users\PAULO\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2007-03-12 17:59 . 2007-03-12 17:59 299008 ----a-w- c:\program files\navigram_register.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}"= "c:\program files\AVAST Software\Avast\aswWebRepIE.dll" [2013-12-18 1138536]
.
[HKEY_CLASSES_ROOT\clsid\{cc1a175a-e45b-41ed-a30c-c9b1d7a0c02f}]
[HKEY_CLASSES_ROOT\TypeLib\{6B795924-95E7-4D31-8521-407360C3AA0B}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-12-18 09:05 259464 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-11-14 20584608]
"KiesPDLR"="c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-05-04 21392]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"MyDriveConnect.exe"="c:\program files\MyDrive Connect\MyDriveConnect.exe" [2013-10-21 473496]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-14 68856]
"FileHippo.com"="c:\program files\FileHippo.com\UpdateChecker.exe" [2012-11-23 307712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SSDMonitor"="c:\program files\Common Files\PC Tools\sMonitor\SSDMonitor.exe" [2010-09-16 104408]
"AVMWlanClient"="c:\program files\avmwlanstick\wlangui.exe" [2010-10-22 2105344]
"IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2012-02-29 56088]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 1821576]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2013-05-01 421888]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
"DivXMediaServer"="c:\program files\DivX\DivX Media Server\DivXMediaServer.exe" [2013-09-11 450560]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2013-09-16 295512]
"LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2011-11-11 205336]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2013-08-29 1861968]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2013-12-18 3764024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPath"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoFileAssociate"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 6]
2013-04-18 18:38 491840 ----a-w- c:\program files\IObit\Advanced SystemCare 6\ASCTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
2012-11-05 14:27 89184 ----a-w- c:\program files\Microsoft Office\Office14\BCSSync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXMediaServer]
2013-09-11 03:09 450560 ----a-w- c:\program files\DivX\DivX Media Server\DivXMediaServer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2013-08-29 00:23 1861968 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2013-07-02 07:16 254336 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe"
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" /hide
"Swisscom LiveUpdate"=c:\program files\Swisscom\LiveUpdate\SwisscomLiveUpdate.exe
"Swisscom Quick Help"=c:\program files\Swisscom\Quick Help\SwisscomQuickHelp.exe /auto
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2795511429-1016840749-3435742708-1000]
"EnableNotificationsRef"=dword:00000001
.
R3 3xHybrid;3xHybrid service;c:\windows\system32\DRIVERS\3xHybrid.sys [2009-08-26 1025920]
S2 ACEDRV08;ACEDRV08;c:\windows\system32\drivers\ACEDRV08.sys [2008-11-26 108768]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-16 01:44 1210320 ----a-w- c:\program files\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-12-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 10:44]
.
2013-12-16 c:\windows\Tasks\Driver Booster Update.job
- c:\program files\IObit\Driver Booster\AutoUpdate.exe [2013-12-16 10:01]
.
2012-12-08 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2795511429-1016840749-3435742708-1000Core.job
- c:\users\PAULO\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-02-26 18:16]
.
2012-12-08 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2795511429-1016840749-3435742708-1000UA.job
- c:\users\PAULO\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-02-26 18:16]
.
2013-12-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 21:44]
.
2013-12-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 21:44]
.
.
------- Zusätzlicher Suchlauf -------
.
uDefault_Search_URL = hxxp://www.google.com/ie
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: An OneNote s&enden - c:\progra~1\MI1933~1\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MI1933~1\Office14\EXCEL.EXE/3000
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: microsoft.com\update
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.1.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} - hxxp://www.powerchallenge.com/applet/PowerLoader.cab
DPF: {B9F79165-A264-4C4A-A211-133A5E8D647F} - hxxp://services.bluewin.ch/securitychecker/fscax.cab
FF - ProfilePath - c:\users\PAULO\AppData\Roaming\Mozilla\Firefox\Profiles\r709548e.default\
FF - prefs.js: keyword.enabled - false
FF - ExtSQL: 2013-10-19 13:06; toolbar@gmx.net; c:\users\PAULO\AppData\Roaming\Mozilla\Firefox\Profiles\r709548e.default\extensions\toolbar@gmx.net.xpi
FF - ExtSQL: 2013-11-01 15:44; idme@abine.com; c:\users\PAULO\AppData\Roaming\Mozilla\Firefox\Profiles\r709548e.default\extensions\idme@abine.com
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{09152f0b-739c-4dec-a245-1aa8a37594f1} - (no file)
SafeBoot-Lavasoft Ad-Aware Service
MSConfigStartUp-IObit Malware Fighter - c:\program files\IObit\IObit Malware Fighter\IMF.exe
MSConfigStartUp-SpywareTerminatorShield - c:\program files\spyware terminator\spywareterminatorshield.exe
MSConfigStartUp-SpywareTerminatorUpdater - c:\program files\spyware terminator\spywareterminatorupdate.exe
AddRemove-Swisscom Quick Help - c:\programdata\{D61DF0B8-23A1-439C-84C4-35F3EF31A430}\SwisscomQuickHelp_Setup.exe
AddRemove-{8F8AB607-DBA4-4367-BDB0-D1E827BE2D9A} - c:\programdata\{D61DF0B8-23A1-439C-84C4-35F3EF31A430}\SwisscomQuickHelp_Setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2013-12-18 10:26
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,
27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b
"{759D9886-0C6F-4498-BAB6-4A5F47C6C72F}"=hex:51,66,7a,6c,4c,1d,38,12,e8,9b,8e,
71,5d,42,f6,01,c5,a0,09,1f,42,98,83,3b
"{E16DC1FE-7C34-43F2-B754-F3AD12DDF97C}"=hex:51,66,7a,6c,4c,1d,38,12,90,c2,7e,
e5,06,32,9c,06,c8,42,b0,ed,17,83,bd,68
"{326E768D-4182-46FD-9C16-1449A49795F4}"=hex:51,66,7a,6c,4c,1d,38,12,e3,75,7d,
36,b0,0f,93,03,e3,00,57,09,a1,c9,d1,e0
"{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}"=hex:51,66,7a,6c,4c,1d,38,12,c3,d3,96,
33,cd,f1,98,02,c0,4d,e6,c7,c4,3c,ba,cd
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,
ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3
"{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}"=hex:51,66,7a,6c,4c,1d,38,12,2d,dd,7a,
ab,6a,33,56,03,c9,ec,8d,26,b0,f3,64,49
"{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,38,12,5b,ab,e0,
b0,13,40,37,0c,c5,34,01,f3,05,d0,46,eb
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:ed,9f,ee,98,a3,06,cd,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c9,c4,53,c2,44,c5,11,45,a1,cf,0c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,25,a0,3c,33,d1,8b,16,4e,89,9e,0c,\
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.HTM"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.HTM"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.MHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.MHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.URL"
.
[HKEY_USERS\S-1-5-21-2795511429-1016840749-3435742708-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:e2,cf,6d,72,7e,04,01,26,b8,70,ae,e9,c3,3d,7d,3c,c8,af,fa,c7,d5,15,a7,
17,66,36,ef,58,0d,6f,7c,dd,c4,86,fe,4b,d9,3f,ff,bf,9c,eb,cb,35,90,09,2d,51,\
"??"=hex:34,0c,ff,a5,64,83,bc,41,55,a4,c3,32,b1,3a,3e,47
.
[HKEY_USERS\S-1-5-21-2795511429-1016840749-3435742708-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:c9,07,9e,0a,05,8b,9b,c8,fa,cf,7a,b3,ab,cd,a6,38,20,54,fe,4e,c8,
df,be,5c,71,a3,4e,99,a3,1e,61,14,d8,db,a7,34,98,86,f8,6b,ae,71,6c,04,4c,1f,\
"rkeysecu"=hex:84,df,29,69,c3,16,e8,40,40,d9,33,e0,1a,59,cb,16
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet005\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
c:\windows\servicing\TrustedInstaller.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\avmwlanstick\WlanNetService.exe
c:\windows\ehome\ehRecvr.exe
c:\windows\ehome\ehsched.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\windows\system32\IProsetMonitor.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe
c:\program files\RealNetworks\RealDownloader\rndlresolversvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Home Cinema\TV Enhance\Kernel\TV\TVECapSvc.exe
c:\progra~1\COMMON~1\X10\Common\x10nets.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Home Cinema\TV Enhance\Kernel\TV\TVESched.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-12-18 10:31:47 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2013-12-18 09:31
.
Vor Suchlauf: 25 Verzeichnis(se), 830'486'818'816 Bytes frei
Nach Suchlauf: 28 Verzeichnis(se), 830'959'079'424 Bytes frei
.
- - End Of File - - 0FE18691247AE5B5B30CAD102C392177
5C616939100B85E558DA92B899A0FC36 |