Mr.X 1991 | 11.09.2010 15:30 | nein ich benutz kein onlinebanking
hier mein combofix log
Combofix Logfile: Code:
ComboFix 10-09-09.04 - Berkay 2010-09-11 15:54:29.2.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1031.18.2045.787 [GMT 2:00]
ausgeführt von:: c:\users\*****\Desktop\ComboFix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows-Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((( Dateien erstellt von 2010-08-11 bis 2010-09-11 ))))))))))))))))))))))))))))))
.
2010-09-11 14:03 . 2010-09-11 14:14 -------- d-----w- c:\users\*****\AppData\Local\temp
2010-09-11 14:03 . 2010-09-11 14:03 -------- d-----w- c:\users\IUSR_NMPR\AppData\Local\temp
2010-09-11 14:03 . 2010-09-11 14:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-11 14:03 . 2010-09-11 14:03 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2010-09-10 10:43 . 2010-09-10 10:43 -------- d-----w- c:\users\*****\AppData\Local\Sunbelt Software
2010-09-10 10:42 . 2010-09-10 10:42 -------- dc-h--w- c:\programdata\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2010-09-10 10:42 . 2010-08-12 12:16 2979848 -c--a-w- c:\programdata\{ECC164E0-3133-4C70-A831-F08DB2940F70}\Ad-AwareInstall.exe
2010-09-08 21:41 . 2010-09-10 21:24 -------- d-----w- c:\program files\Luxor
2010-09-08 14:09 . 2010-09-08 14:10 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-09-08 14:08 . 2010-09-08 15:30 -------- d-----w- c:\users\*****\AppData\Roaming\DAEMON Tools Lite
2010-09-08 14:08 . 2010-09-08 14:09 -------- d-----w- c:\programdata\DAEMON Tools Lite
2010-09-07 15:37 . 2010-09-07 15:37 -------- d-----w- c:\users\*****\AppData\Roaming\BearShare
2010-09-07 15:36 . 2010-08-08 13:12 3534061 -c--a-w- c:\programdata\{26FF3095-882A-4FBE-8936-50F7CEC5EA49}\BearShare_V9_de_Setup.exe
2010-09-07 15:35 . 2010-09-07 15:35 -------- d-----w- c:\programdata\BearShare
2010-09-07 15:35 . 2010-09-07 15:36 -------- dc-h--w- c:\programdata\{26FF3095-882A-4FBE-8936-50F7CEC5EA49}
2010-09-07 15:34 . 2010-09-07 15:34 -------- d-----w- c:\users\****\AppData\Local\PackageAware
2010-09-07 15:34 . 2010-07-09 23:02 101888 -c--a-w- c:\programdata\{26FF3095-882A-4FBE-8936-50F7CEC5EA49}\OFFLINE\mIDEFunc.dll\mEXEFunc.dll
2010-09-07 15:34 . 2010-07-09 23:02 438272 -c--a-w- c:\programdata\{26FF3095-882A-4FBE-8936-50F7CEC5EA49}\OFFLINE\mMSI.dll\mMSIExec.dll
2010-09-07 15:34 . 2010-07-09 23:01 508416 -c--a-w- c:\programdata\{26FF3095-882A-4FBE-8936-50F7CEC5EA49}\OFFLINE\mDown.dll\mDownExec.dll
2010-09-07 12:18 . 2010-09-07 12:18 -------- d-----w- c:\users\******\AppData\Local\pcsx2
2010-09-04 11:57 . 2010-09-04 12:27 -------- d-----w- c:\users\*****\AppData\Local\pcsx2
2010-09-04 11:57 . 2010-06-02 02:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2010-09-04 11:57 . 2010-06-02 02:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2010-09-04 11:57 . 2010-06-02 02:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2010-09-04 11:57 . 2010-05-26 09:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2010-09-04 11:57 . 2010-05-26 09:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2010-09-04 11:57 . 2010-05-26 09:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2010-09-04 11:57 . 2010-05-26 09:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2010-09-04 11:57 . 2010-05-26 09:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2010-09-04 11:56 . 2010-09-04 12:25 -------- d-----w- c:\program files\PCSX2 0.9.7
2010-09-03 20:40 . 2010-08-26 12:40 21312 ----a-w- c:\windows\system32\authuitu.dll
2010-09-03 20:40 . 2010-08-26 12:40 30016 ----a-w- c:\windows\system32\uxtuneup.dll
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-11 13:46 . 2007-07-16 09:47 -------- d-----w- c:\programdata\NVIDIA
2010-09-11 13:38 . 2010-06-04 19:34 -------- d-----w- c:\program files\Internet Download Manager
2010-09-11 13:38 . 2010-06-04 19:34 -------- d-----w- c:\users\*****\AppData\Roaming\DMCache
2010-09-11 13:34 . 2010-02-05 16:33 53294 ----a-w- c:\programdata\nvModes.dat
2010-09-11 10:25 . 2008-04-06 19:20 104744 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-09-10 10:32 . 2009-02-07 23:25 -------- d-----w- c:\program files\CCleaner
2010-09-09 22:36 . 2006-11-02 15:33 638510 ----a-w- c:\windows\system32\perfh007.dat
2010-09-09 22:36 . 2006-11-02 15:33 130462 ----a-w- c:\windows\system32\perfc007.dat
2010-09-08 22:09 . 2010-06-04 19:34 -------- d-----w- c:\users\*****\AppData\Roaming\IDM
2010-09-08 21:47 . 2007-12-26 16:49 -------- d-----w- c:\programdata\MumboJumbo
2010-09-08 16:28 . 2007-12-16 19:59 -------- d-----w- c:\users\*****\AppData\Roaming\BitTorrent
2010-09-08 14:10 . 2007-09-10 11:29 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-09-04 18:22 . 2007-06-18 08:56 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-04 16:37 . 2010-05-31 13:54 -------- d-----w- c:\program files\SEGA
2010-09-04 11:57 . 2009-05-08 19:05 -------- d-----w- c:\program files\Electronic Arts
2010-09-03 22:23 . 2008-12-25 11:33 -------- d-----w- c:\programdata\Microsoft Help
2010-09-03 22:19 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-09-03 20:40 . 2010-04-04 09:16 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-08-26 12:45 . 2010-04-04 09:16 30528 ----a-w- c:\windows\system32\TURegOpt.exe
2010-08-12 12:15 . 2010-06-05 10:42 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-08-12 12:15 . 2009-01-24 12:38 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-07-26 21:54 . 2010-06-30 21:56 52224 ----a-w- c:\users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\ctxfrrbe.*****\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\FFExternalAlert.dll
2010-07-26 21:54 . 2010-06-30 21:56 101376 ----a-w- c:\users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\ctxfrrbe.*****\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCore.dll
2010-07-25 19:24 . 2009-05-10 20:20 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2010-07-20 21:23 . 2008-01-20 18:01 1356 ----a-w- c:\users\*****\AppData\Local\d3d9caps.dat
2010-06-26 06:05 . 2010-09-03 20:32 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-26 06:02 . 2010-09-03 20:32 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-06-26 06:02 . 2010-09-03 20:32 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-06-26 04:25 . 2010-09-03 20:32 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-06-23 14:24 . 2010-06-23 14:24 501936 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtbC563.tmp.exe
2010-06-21 13:37 . 2010-09-03 20:32 2037760 ----a-w- c:\windows\system32\win32k.sys
2010-06-18 17:31 . 2010-09-03 20:32 36864 ----a-w- c:\windows\system32\rtutils.dll
2010-06-18 15:04 . 2010-09-03 20:32 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-18 15:04 . 2010-09-03 20:32 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-06-16 16:04 . 2010-09-03 20:32 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-06-16 13:24 . 2010-06-16 13:24 1079048 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2008-12-19 22:05 . 2007-08-13 07:39 848 --sha-w- c:\windows\System32\KGyGaAvL.sys
2007-04-17 08:30 . 2007-04-17 08:30 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E601996F-E400-41CA-804B-CD6373A7EEE2}]
2010-02-10 01:34 750256 ----a-w- c:\program files\kikin\ie_kikin.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-01 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-10 4468736]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-09-10 864624]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
"AVMWlanClient"="c:\program files\avmwlanstick\wlangui.exe" [2009-05-07 1904640]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoFileAssociate"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0lsdelete\0DfSDKBt
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
"Getdo"=rundll32.exe "c:\users\*****\AppData\Roaming\Adobe\Update\flacor.dat""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"CCUTRAYICON"=c:\program files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"GnabTray"=c:\program files\Common Files\Gnab\Service\GnabTray.exe -checkstart
"NMSSupport"="c:\program files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
R2 appdrvrem01;Application Driver Auto Removal Service (01);c:\windows\System32\appdrvrem01.exe svc [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 135664]
R3 athrusb;Atheros Wireless LAN USB device driver;c:\windows\system32\DRIVERS\athrusb.sys [2006-12-22 449536]
R3 avmeject;AVM Eject;c:\windows\system32\drivers\avmeject.sys [2009-05-07 4352]
R3 DHTRACE;Intel(R) DHTrace Controller;c:\program files\Common Files\Intel\IntelDH\bin\DHTraceController.exe [2007-04-06 39896]
R3 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2007-02-12 208896]
R3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [2005-08-17 7168]
R3 FWLANUSB;AVM FRITZ!WLAN;c:\windows\system32\DRIVERS\fwlanusb.sys [2007-01-26 265088]
R3 NMSCore;Intel(R) NMSCore;c:\program files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe [2007-04-06 313816]
R3 QualityManager;Intel(R) Quality Manager;c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\qualitymanager.exe [2007-04-06 272856]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-09-08 691696]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-08-12 64288]
S0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\System32\drivers\sfdrv01a.sys [2006-07-05 63352]
S1 appdrv01;Application Driver (01);c:\windows\system32\Drivers\appdrv01.sys [2009-09-03 2915944]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
S2 GnabService;GnabService;c:\program files\common files\gnab\service\servicecontroller.exe [2007-04-13 36864]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2009-10-29 1074568]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-09-10 1355928]
S2 nmsunidr;UniDriver for NMS;c:\windows\system32\DRIVERS\nmsunidr.sys [2007-02-18 5376]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-01-11 240232]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-08-26 1051968]
S3 IntelDH;IntelDH Driver;c:\windows\system32\Drivers\IntelDH.sys [2007-06-18 5504]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2009-10-14 10064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Inhalt des "geplante Tasks" Ordners
2010-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 11:30]
2010-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 11:30]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://dsl-start.computerbild.de/
mWindow Title = Microsoft Internet Explorer
IE: Add to Windows &Live Favorites - hxxp://favorites.live.com/quickadd.aspx
IE: Download aller Links mit IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV-Videoinhalt mit IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download mit IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Free YouTube to Mp3 Converter - c:\users\Berkay\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Öffnen mit WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta
IE: {{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} - c:\program files\kikin\ie_kikin.dll
LSP: c:\windows\system32\wpclsp.dll
Trusted Zone: microsoft.com
Trusted Zone: microsoft.com\*.update
Trusted Zone: microsoft.com\*.windowsupdate
Trusted Zone: windowsupdate.com
FF - ProfilePath - c:\users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\ctxfrrbe.*****\
FF - component: c:\users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\ctxfrrbe.Berkay\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\FFExternalAlert.dll
FF - component: c:\users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\ctxfrrbe.Berkay\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCore.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX Richtlinien ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2010-09-11 16:14
Windows 6.0.6002 Service Pack 2 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
[HKEY_USERS\S-1-5-21-2649846486-4142026674-4246215158-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:40,af,4a,ff,cb,09,59,c6,34,b0,6b,5d,43,bb,bc,da,ef,4a,8b,c4,cd,47,6c,
b9,d5,e1,58,d1,21,cd,f8,91,2f,13,f5,84,20,ff,1b,99,be,bf,1b,42,8e,0d,d7,14,\
"??"=hex:0b,96,6f,65,30,35,a9,b9,75,ef,24,88,7f,9f,e2,23
[HKEY_USERS\S-1-5-21-2649846486-4142026674-4246215158-1003\Software\SecuROM\License information*]
"datasecu"=hex:29,e9,cb,ca,61,56,30,06,3c,70,50,db,e9,34,8e,91,af,b1,52,c0,74,
79,c6,4e,4d,f1,24,c5,f8,a1,90,e3,e7,bd,16,e0,4f,ac,d1,51,a0,4d,2d,22,d5,75,\
"rkeysecu"=hex:65,69,66,fd,7f,55,31,34,53,b1,d2,6f,8a,94,d9,8c
[HKEY_USERS\S-1-5-21-2649846486-4142026674-4246215158-1003_Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):2a,05,d9,4c,6a,f1,25,24,cb,06,8d,9e,ac,b1,e9,8f,8c,00,a2,79,b5,
e1,b0,c6,a6,41,38,3e,4a,5e,3d,bb,ec,29,ac,50,4a,8f,a2,05,00,00,00,00,00,00,\
[HKEY_USERS\S-1-5-21-2649846486-4142026674-4246215158-1003_Classes\CLSID\{fd1a8fd6-7966-4234-9766-ac93d02cf114}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:000000b7
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,ab,4a,25,2e,10,52,06,07,2e,4d,91,eb,9e,ca,8f,8d,bf,92,bb,47,e4,ca,\
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Zeit der Fertigstellung: 2010-09-11 16:24:35
ComboFix-quarantined-files.txt 2010-09-11 14:24
Vor Suchlauf: 16 Verzeichnis(se), 54,870,421,504 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 50,622,541,824 Bytes frei
- - End Of File - - C81DAFCF7DAEAE5A9F22FBE5C7F607F6 --- --- --- |