| Mr.X 1991 |  11.09.2010 15:30 |        nein ich benutz kein onlinebanking  
hier mein combofix log  
Combofix Logfile:   Code:  
 ComboFix 10-09-09.04 - Berkay 2010-09-11  15:54:29.2.4 - x86 
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1031.18.2045.787 [GMT 2:00] 
ausgeführt von:: c:\users\*****\Desktop\ComboFix.exe 
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22} 
SP: Windows-Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} 
.   
(((((((((((((((((((((((   Dateien erstellt von 2010-08-11 bis 2010-09-11  )))))))))))))))))))))))))))))) 
.   
2010-09-11 14:03 . 2010-09-11 14:14        --------        d-----w-        c:\users\*****\AppData\Local\temp 
2010-09-11 14:03 . 2010-09-11 14:03        --------        d-----w-        c:\users\IUSR_NMPR\AppData\Local\temp 
2010-09-11 14:03 . 2010-09-11 14:03        --------        d-----w-        c:\users\Default\AppData\Local\temp 
2010-09-11 14:03 . 2010-09-11 14:03        --------        d-----w-        c:\users\Administrator\AppData\Local\temp 
2010-09-10 10:43 . 2010-09-10 10:43        --------        d-----w-        c:\users\*****\AppData\Local\Sunbelt Software 
2010-09-10 10:42 . 2010-09-10 10:42        --------        dc-h--w-        c:\programdata\{ECC164E0-3133-4C70-A831-F08DB2940F70} 
2010-09-10 10:42 . 2010-08-12 12:16        2979848        -c--a-w-        c:\programdata\{ECC164E0-3133-4C70-A831-F08DB2940F70}\Ad-AwareInstall.exe 
2010-09-08 21:41 . 2010-09-10 21:24        --------        d-----w-        c:\program files\Luxor 
2010-09-08 14:09 . 2010-09-08 14:10        --------        d-----w-        c:\program files\DAEMON Tools Lite 
2010-09-08 14:08 . 2010-09-08 15:30        --------        d-----w-        c:\users\*****\AppData\Roaming\DAEMON Tools Lite 
2010-09-08 14:08 . 2010-09-08 14:09        --------        d-----w-        c:\programdata\DAEMON Tools Lite 
2010-09-07 15:37 . 2010-09-07 15:37        --------        d-----w-        c:\users\*****\AppData\Roaming\BearShare 
2010-09-07 15:36 . 2010-08-08 13:12        3534061        -c--a-w-        c:\programdata\{26FF3095-882A-4FBE-8936-50F7CEC5EA49}\BearShare_V9_de_Setup.exe 
2010-09-07 15:35 . 2010-09-07 15:35        --------        d-----w-        c:\programdata\BearShare 
2010-09-07 15:35 . 2010-09-07 15:36        --------        dc-h--w-        c:\programdata\{26FF3095-882A-4FBE-8936-50F7CEC5EA49} 
2010-09-07 15:34 . 2010-09-07 15:34        --------        d-----w-        c:\users\****\AppData\Local\PackageAware 
2010-09-07 15:34 . 2010-07-09 23:02        101888        -c--a-w-        c:\programdata\{26FF3095-882A-4FBE-8936-50F7CEC5EA49}\OFFLINE\mIDEFunc.dll\mEXEFunc.dll 
2010-09-07 15:34 . 2010-07-09 23:02        438272        -c--a-w-        c:\programdata\{26FF3095-882A-4FBE-8936-50F7CEC5EA49}\OFFLINE\mMSI.dll\mMSIExec.dll 
2010-09-07 15:34 . 2010-07-09 23:01        508416        -c--a-w-        c:\programdata\{26FF3095-882A-4FBE-8936-50F7CEC5EA49}\OFFLINE\mDown.dll\mDownExec.dll 
2010-09-07 12:18 . 2010-09-07 12:18        --------        d-----w-        c:\users\******\AppData\Local\pcsx2 
2010-09-04 11:57 . 2010-09-04 12:27        --------        d-----w-        c:\users\*****\AppData\Local\pcsx2 
2010-09-04 11:57 . 2010-06-02 02:55        74072        ----a-w-        c:\windows\system32\XAPOFX1_5.dll 
2010-09-04 11:57 . 2010-06-02 02:55        527192        ----a-w-        c:\windows\system32\XAudio2_7.dll 
2010-09-04 11:57 . 2010-06-02 02:55        239960        ----a-w-        c:\windows\system32\xactengine3_7.dll 
2010-09-04 11:57 . 2010-05-26 09:41        470880        ----a-w-        c:\windows\system32\d3dx10_43.dll 
2010-09-04 11:57 . 2010-05-26 09:41        248672        ----a-w-        c:\windows\system32\d3dx11_43.dll 
2010-09-04 11:57 . 2010-05-26 09:41        2106216        ----a-w-        c:\windows\system32\D3DCompiler_43.dll 
2010-09-04 11:57 . 2010-05-26 09:41        1998168        ----a-w-        c:\windows\system32\D3DX9_43.dll 
2010-09-04 11:57 . 2010-05-26 09:41        1868128        ----a-w-        c:\windows\system32\d3dcsx_43.dll 
2010-09-04 11:56 . 2010-09-04 12:25        --------        d-----w-        c:\program files\PCSX2 0.9.7 
2010-09-03 20:40 . 2010-08-26 12:40        21312        ----a-w-        c:\windows\system32\authuitu.dll 
2010-09-03 20:40 . 2010-08-26 12:40        30016        ----a-w-        c:\windows\system32\uxtuneup.dll   
. 
((((((((((((((((((((((((((((((((((((   Find3M Bericht   )))))))))))))))))))))))))))))))))))))))))))))))))))))) 
. 
2010-09-11 13:46 . 2007-07-16 09:47        --------        d-----w-        c:\programdata\NVIDIA 
2010-09-11 13:38 . 2010-06-04 19:34        --------        d-----w-        c:\program files\Internet Download Manager 
2010-09-11 13:38 . 2010-06-04 19:34        --------        d-----w-        c:\users\*****\AppData\Roaming\DMCache 
2010-09-11 13:34 . 2010-02-05 16:33        53294        ----a-w-        c:\programdata\nvModes.dat 
2010-09-11 10:25 . 2008-04-06 19:20        104744        ----a-w-        c:\windows\system32\GDIPFONTCACHEV1.DAT 
2010-09-10 10:32 . 2009-02-07 23:25        --------        d-----w-        c:\program files\CCleaner 
2010-09-09 22:36 . 2006-11-02 15:33        638510        ----a-w-        c:\windows\system32\perfh007.dat 
2010-09-09 22:36 . 2006-11-02 15:33        130462        ----a-w-        c:\windows\system32\perfc007.dat 
2010-09-08 22:09 . 2010-06-04 19:34        --------        d-----w-        c:\users\*****\AppData\Roaming\IDM 
2010-09-08 21:47 . 2007-12-26 16:49        --------        d-----w-        c:\programdata\MumboJumbo 
2010-09-08 16:28 . 2007-12-16 19:59        --------        d-----w-        c:\users\*****\AppData\Roaming\BitTorrent 
2010-09-08 14:10 . 2007-09-10 11:29        691696        ----a-w-        c:\windows\system32\drivers\sptd.sys 
2010-09-04 18:22 . 2007-06-18 08:56        --------        d--h--w-        c:\program files\InstallShield Installation Information 
2010-09-04 16:37 . 2010-05-31 13:54        --------        d-----w-        c:\program files\SEGA 
2010-09-04 11:57 . 2009-05-08 19:05        --------        d-----w-        c:\program files\Electronic Arts 
2010-09-03 22:23 . 2008-12-25 11:33        --------        d-----w-        c:\programdata\Microsoft Help 
2010-09-03 22:19 . 2006-11-02 11:18        --------        d-----w-        c:\program files\Windows Mail 
2010-09-03 20:40 . 2010-04-04 09:16        --------        d-----w-        c:\program files\TuneUp Utilities 2010 
2010-08-26 12:45 . 2010-04-04 09:16        30528        ----a-w-        c:\windows\system32\TURegOpt.exe 
2010-08-12 12:15 . 2010-06-05 10:42        64288        ----a-w-        c:\windows\system32\drivers\Lbd.sys 
2010-08-12 12:15 . 2009-01-24 12:38        15880        ----a-w-        c:\windows\system32\lsdelete.exe 
2010-07-26 21:54 . 2010-06-30 21:56        52224        ----a-w-        c:\users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\ctxfrrbe.*****\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\FFExternalAlert.dll 
2010-07-26 21:54 . 2010-06-30 21:56        101376        ----a-w-        c:\users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\ctxfrrbe.*****\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCore.dll 
2010-07-25 19:24 . 2009-05-10 20:20        --------        d-----w-        c:\program files\Common Files\DVDVideoSoft 
2010-07-20 21:23 . 2008-01-20 18:01        1356        ----a-w-        c:\users\*****\AppData\Local\d3d9caps.dat 
2010-06-26 06:05 . 2010-09-03 20:32        916480        ----a-w-        c:\windows\system32\wininet.dll 
2010-06-26 06:02 . 2010-09-03 20:32        71680        ----a-w-        c:\windows\system32\iesetup.dll 
2010-06-26 06:02 . 2010-09-03 20:32        109056        ----a-w-        c:\windows\system32\iesysprep.dll 
2010-06-26 04:25 . 2010-09-03 20:32        133632        ----a-w-        c:\windows\system32\ieUnatt.exe 
2010-06-23 14:24 . 2010-06-23 14:24        501936        ----a-w-        c:\programdata\Google\Google Toolbar\Update\gtbC563.tmp.exe 
2010-06-21 13:37 . 2010-09-03 20:32        2037760        ----a-w-        c:\windows\system32\win32k.sys 
2010-06-18 17:31 . 2010-09-03 20:32        36864        ----a-w-        c:\windows\system32\rtutils.dll 
2010-06-18 15:04 . 2010-09-03 20:32        302080        ----a-w-        c:\windows\system32\drivers\srv.sys 
2010-06-18 15:04 . 2010-09-03 20:32        144896        ----a-w-        c:\windows\system32\drivers\srv2.sys 
2010-06-16 16:04 . 2010-09-03 20:32        905088        ----a-w-        c:\windows\system32\drivers\tcpip.sys 
2010-06-16 13:24 . 2010-06-16 13:24        1079048        ----a-w-        c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 
2008-12-19 22:05 . 2007-08-13 07:39        848        --sha-w-        c:\windows\System32\KGyGaAvL.sys 
2007-04-17 08:30 . 2007-04-17 08:30        8192        --sha-w-        c:\windows\Users\Default\NTUSER.DAT 
.   
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   )))))))))))))))))))))))))))))))))))))))) 
. 
. 
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.  
REGEDIT4   
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E601996F-E400-41CA-804B-CD6373A7EEE2}] 
2010-02-10 01:34        750256        ----a-w-        c:\program files\kikin\ie_kikin.dll   
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696] 
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-01 39408]   
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-10 4468736] 
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872] 
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-09-10 864624] 
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792] 
"AVMWlanClient"="c:\program files\avmwlanstick\wlangui.exe" [2009-05-07 1904640] 
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952] 
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]   
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] 
"EnableUIADesktopToggle"= 0 (0x0)   
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] 
"NoResolveTrack"= 1 (0x1) 
"NoFileAssociate"= 0 (0x0)   
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] 
"aux"=wdmaud.drv   
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] 
BootExecute        REG_MULTI_SZ           autocheck autochk *\0lsdelete\0DfSDKBt   
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] 
@="Service"   
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] 
@="Service"   
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] 
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" /background 
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" 
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" 
"ehTray.exe"=c:\windows\ehome\ehTray.exe 
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe 
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet 
"Getdo"=rundll32.exe "c:\users\*****\AppData\Roaming\Adobe\Update\flacor.dat""   
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] 
"CCUTRAYICON"=c:\program files\Intel\IntelDH\CCU\CCU_TrayIcon.exe 
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit 
"GnabTray"=c:\program files\Common Files\Gnab\Service\GnabTray.exe -checkstart 
"NMSSupport"="c:\program files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup 
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" 
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime 
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" 
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" 
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW 
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"   
R2 appdrvrem01;Application Driver Auto Removal Service (01);c:\windows\System32\appdrvrem01.exe svc [x] 
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] 
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 135664] 
R3 athrusb;Atheros Wireless LAN USB device driver;c:\windows\system32\DRIVERS\athrusb.sys [2006-12-22 449536] 
R3 avmeject;AVM Eject;c:\windows\system32\drivers\avmeject.sys [2009-05-07 4352] 
R3 DHTRACE;Intel(R) DHTrace Controller;c:\program files\Common Files\Intel\IntelDH\bin\DHTraceController.exe [2007-04-06 39896] 
R3 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2007-02-12 208896] 
R3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [2005-08-17 7168] 
R3 FWLANUSB;AVM FRITZ!WLAN;c:\windows\system32\DRIVERS\fwlanusb.sys [2007-01-26 265088] 
R3 NMSCore;Intel(R) NMSCore;c:\program files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe [2007-04-06 313816] 
R3 QualityManager;Intel(R) Quality Manager;c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\qualitymanager.exe [2007-04-06 272856] 
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] 
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-09-08 691696] 
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-08-12 64288] 
S0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\System32\drivers\sfdrv01a.sys [2006-07-05 63352] 
S1 appdrv01;Application Driver (01);c:\windows\system32\Drivers\appdrv01.sys [2009-09-03 2915944] 
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336] 
S2 GnabService;GnabService;c:\program files\common files\gnab\service\servicecontroller.exe [2007-04-13 36864] 
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2009-10-29 1074568] 
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-09-10 1355928] 
S2 nmsunidr;UniDriver for NMS;c:\windows\system32\DRIVERS\nmsunidr.sys [2007-02-18 5376] 
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-01-11 240232] 
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-08-26 1051968] 
S3 IntelDH;IntelDH Driver;c:\windows\system32\Drivers\IntelDH.sys [2007-06-18 5504] 
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2009-10-14 10064]     
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] 
LocalServiceAndNoImpersonation        REG_MULTI_SZ           FontCache   
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs 
UxTuneUp 
. 
Inhalt des "geplante Tasks" Ordners   
2010-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job 
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 11:30]   
2010-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job 
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 11:30] 
. 
. 
------- Zusätzlicher Suchlauf ------- 
. 
uStart Page = hxxp://dsl-start.computerbild.de/ 
mWindow Title = Microsoft Internet Explorer 
IE: Add to Windows &Live Favorites - hxxp://favorites.live.com/quickadd.aspx 
IE: Download aller Links mit IDM - c:\program files\Internet Download Manager\IEGetAll.htm 
IE: Download FLV-Videoinhalt mit IDM - c:\program files\Internet Download Manager\IEGetVL.htm 
IE: Download mit IDM - c:\program files\Internet Download Manager\IEExt.htm 
IE: Free YouTube to Mp3 Converter - c:\users\Berkay\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm 
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html 
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 
IE: Öffnen mit WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta 
IE: {{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} - c:\program files\kikin\ie_kikin.dll 
LSP: c:\windows\system32\wpclsp.dll 
Trusted Zone: microsoft.com 
Trusted Zone: microsoft.com\*.update 
Trusted Zone: microsoft.com\*.windowsupdate 
Trusted Zone: windowsupdate.com 
FF - ProfilePath - c:\users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\ctxfrrbe.*****\ 
FF - component: c:\users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\ctxfrrbe.Berkay\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\FFExternalAlert.dll 
FF - component: c:\users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\ctxfrrbe.Berkay\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCore.dll 
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll 
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll 
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll 
FF - plugin: c:\program files\NVIDIA Corporation\3D Vision\npnv3dv.dll 
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll 
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll 
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\   
---- FIREFOX Richtlinien ---- 
FF - user.js: network.http.max-persistent-connections-per-server - 4 
FF - user.js: nglayout.initialpaint.delay - 600 
FF - user.js: content.notify.interval - 600000 
FF - user.js: content.max.tokenizing.time - 1800000 
FF - user.js: content.switch.threshold - 600000 
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);  
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);  
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); 
.   
**************************************************************************   
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net 
Rootkit scan 2010-09-11 16:14 
Windows 6.0.6002 Service Pack 2 NTFS   
Scanne versteckte Prozesse...    
Scanne versteckte Autostarteinträge...    
Scanne versteckte Dateien...    
Scan erfolgreich abgeschlossen 
versteckte Dateien: 0   
**************************************************************************   
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\EverestDriver] 
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt" 
. 
--------------------- Gesperrte Registrierungsschluessel ---------------------   
[HKEY_USERS\S-1-5-21-2649846486-4142026674-4246215158-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] 
"??"=hex:40,af,4a,ff,cb,09,59,c6,34,b0,6b,5d,43,bb,bc,da,ef,4a,8b,c4,cd,47,6c, 
   b9,d5,e1,58,d1,21,cd,f8,91,2f,13,f5,84,20,ff,1b,99,be,bf,1b,42,8e,0d,d7,14,\ 
"??"=hex:0b,96,6f,65,30,35,a9,b9,75,ef,24,88,7f,9f,e2,23   
[HKEY_USERS\S-1-5-21-2649846486-4142026674-4246215158-1003\Software\SecuROM\License information*] 
"datasecu"=hex:29,e9,cb,ca,61,56,30,06,3c,70,50,db,e9,34,8e,91,af,b1,52,c0,74, 
   79,c6,4e,4d,f1,24,c5,f8,a1,90,e3,e7,bd,16,e0,4f,ac,d1,51,a0,4d,2d,22,d5,75,\ 
"rkeysecu"=hex:65,69,66,fd,7f,55,31,34,53,b1,d2,6f,8a,94,d9,8c   
[HKEY_USERS\S-1-5-21-2649846486-4142026674-4246215158-1003_Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}] 
@Denied: (Full) (Everyone) 
@Allowed: (Read) (RestrictedCode) 
"scansk"=hex(0):2a,05,d9,4c,6a,f1,25,24,cb,06,8d,9e,ac,b1,e9,8f,8c,00,a2,79,b5, 
   e1,b0,c6,a6,41,38,3e,4a,5e,3d,bb,ec,29,ac,50,4a,8f,a2,05,00,00,00,00,00,00,\   
[HKEY_USERS\S-1-5-21-2649846486-4142026674-4246215158-1003_Classes\CLSID\{fd1a8fd6-7966-4234-9766-ac93d02cf114}] 
@Denied: (Full) (Everyone) 
@Allowed: (Read) (RestrictedCode) 
"Model"=dword:000000b7 
"Therad"=dword:0000001e 
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26, 
   38,95,44,ab,4a,25,2e,10,52,06,07,2e,4d,91,eb,9e,ca,8f,8d,bf,92,bb,47,e4,ca,\   
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] 
@Denied: (A) (Users) 
@Denied: (A) (Everyone) 
@Allowed: (B 1 2 3 4 5) (S-1-5-20) 
"BlindDial"=dword:00000000   
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] 
@Denied: (A) (Users) 
@Denied: (A) (Everyone) 
@Allowed: (B 1 2 3 4 5) (S-1-5-20) 
"BlindDial"=dword:00000000 
. 
Zeit der Fertigstellung: 2010-09-11  16:24:35 
ComboFix-quarantined-files.txt  2010-09-11 14:24   
Vor Suchlauf: 16 Verzeichnis(se), 54,870,421,504 Bytes frei 
Nach Suchlauf: 22 Verzeichnis(se), 50,622,541,824 Bytes frei   
- - End Of File - - C81DAFCF7DAEAE5A9F22FBE5C7F607F6   --- --- ---    |