![]() |
|
Log-Analyse und Auswertung: System Defragmenter: Daten verschwunden.Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
|
![]() | #1 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() System Defragmenter: Daten verschwunden. Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #2 |
| ![]() System Defragmenter: Daten verschwunden. Ok, alles ausgeführt.
__________________Hier das Ergebnis: Code:
ATTFilter ComboFix 11-04-13.06 - mike 14.04.2011 20:01:42.1.2 - x86 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.2047.1499 [GMT 2:00] ausgeführt von:: c:\users\mike\Desktop\cofi.exe AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7} SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\mike\AppData\Local\{1EF9A571-44C1-4809-9AA2-CABE4412709C} c:\users\mike\AppData\Local\{1EF9A571-44C1-4809-9AA2-CABE4412709C}\chrome.manifest c:\users\mike\AppData\Local\{1EF9A571-44C1-4809-9AA2-CABE4412709C}\chrome\content\_cfg.js c:\users\mike\AppData\Local\{1EF9A571-44C1-4809-9AA2-CABE4412709C}\chrome\content\overlay.xul c:\users\mike\AppData\Local\{1EF9A571-44C1-4809-9AA2-CABE4412709C}\install.rdf c:\users\mike\AppData\Roaming\Adobe\plugs c:\users\mike\AppData\Roaming\Adobe\shed . . ((((((((((((((((((((((( Dateien erstellt von 2011-03-14 bis 2011-04-14 )))))))))))))))))))))))))))))) . . 2011-04-14 18:06 . 2011-04-14 18:06 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-04-14 17:54 . 2011-04-14 17:54 -------- d-----w- c:\program files\CCleaner 2011-04-14 14:12 . 2011-04-14 14:13 -------- d-----w- c:\users\mike\AppData\Local\{E93C4D23-9E4D-4BE7-90BD-7A53909A6343} 2011-04-14 02:19 . 2011-03-03 05:38 132608 ----a-w- c:\windows\system32\dnsrslvr.dll 2011-04-14 02:19 . 2011-03-03 05:36 28672 ----a-w- c:\windows\system32\dnscacheugc.exe 2011-04-14 02:19 . 2011-02-18 05:43 428032 ----a-w- c:\windows\system32\vbscript.dll 2011-04-14 02:19 . 2011-02-23 04:48 311808 ----a-w- c:\windows\system32\drivers\srv.sys 2011-04-14 02:19 . 2011-02-23 04:48 310272 ----a-w- c:\windows\system32\drivers\srv2.sys 2011-04-14 02:19 . 2011-02-23 04:47 114176 ----a-w- c:\windows\system32\drivers\srvnet.sys 2011-04-14 02:19 . 2011-02-19 06:30 34304 ----a-w- c:\windows\system32\atmlib.dll 2011-04-14 02:19 . 2011-02-19 04:34 294912 ----a-w- c:\windows\system32\atmfd.dll 2011-04-14 02:12 . 2011-04-14 02:12 -------- d-----w- c:\users\mike\AppData\Local\{E4E31595-88D2-4792-B0E8-5B56EB8C970B} 2011-04-13 14:59 . 2011-04-13 14:59 -------- d-----w- C:\_OTL 2011-04-13 12:36 . 2011-04-13 12:36 -------- d-----w- c:\users\mike\AppData\Roaming\Malwarebytes 2011-04-13 12:35 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-04-13 12:35 . 2011-04-13 12:35 -------- d-----w- c:\programdata\Malwarebytes 2011-04-13 12:35 . 2011-04-13 12:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-04-13 12:35 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-04-13 12:19 . 2011-04-13 12:19 -------- d-----w- c:\users\mike\AppData\Local\{768180EA-32AB-4D78-B635-385E07F0A01A} 2011-04-12 20:05 . 2011-04-12 20:05 -------- d-----w- c:\users\mike\AppData\Roaming\Avira 2011-04-12 19:55 . 2011-03-04 14:11 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys 2011-04-12 19:55 . 2011-03-04 12:36 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2011-04-12 19:55 . 2011-04-12 19:55 -------- d-----w- c:\programdata\Avira 2011-04-12 19:55 . 2011-04-12 19:55 -------- d-----w- c:\program files\Avira 2011-04-12 15:16 . 2011-04-12 15:17 -------- d-----w- c:\users\mike\AppData\Local\{F61D48E0-D4AD-4A59-BF79-DD14D6245EF3} 2011-04-12 14:44 . 2011-03-15 04:05 6792528 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{AB04E67C-10CE-4F7B-9087-68C8BF2920A3}\mpengine.dll 2011-04-12 03:16 . 2011-04-12 03:16 -------- d-----w- c:\users\mike\AppData\Local\{07E61982-0757-464B-A6A0-6527CE9292F6} 2011-04-11 12:25 . 2011-04-11 12:25 -------- d-----w- c:\users\mike\AppData\Local\{059FE0BC-21DC-4C54-8D02-087C9A07109D} 2011-04-10 15:57 . 2011-04-10 15:58 -------- d-----w- c:\users\mike\AppData\Local\{6FAEC9F2-E2F9-43B6-90D6-1C57A87D8240} 2011-04-10 02:36 . 2011-04-10 02:37 -------- d-----w- c:\users\mike\AppData\Local\{5698F50B-B9E5-4273-823F-0D68D2F01FEC} 2011-04-09 09:56 . 2011-04-09 09:56 -------- d-----w- c:\users\mike\AppData\Local\{ED070D34-DFE4-4F20-91D9-E99F18AA1A35} 2011-04-08 20:25 . 2011-04-08 20:25 -------- d-----w- c:\users\mike\AppData\Local\{51138A72-8270-40AB-BD48-9B402E54FFCE} 2011-04-08 08:24 . 2011-04-08 08:24 -------- d-----w- c:\users\mike\AppData\Local\{9CD6AF7D-C088-4A28-9A99-BA19E560B697} 2011-04-07 20:23 . 2011-04-07 20:24 -------- d-----w- c:\users\mike\AppData\Local\{266ED28B-E6C1-4220-9C8A-8C0EBCFEBD48} 2011-04-07 08:23 . 2011-04-07 08:23 -------- d-----w- c:\users\mike\AppData\Local\{180B9564-B396-442E-8A87-04C16A1A8793} 2011-04-06 20:22 . 2011-04-06 20:23 -------- d-----w- c:\users\mike\AppData\Local\{0EDCAFDC-BF70-4503-B155-3631289F0000} 2011-04-06 06:00 . 2011-04-06 06:00 -------- d-----w- c:\users\mike\AppData\Local\{7449BDC1-0CA5-44B1-84B9-870AC615BCDD} 2011-04-05 10:20 . 2011-04-05 10:20 -------- d-----w- c:\users\mike\AppData\Local\{E427D2C8-4C97-44D7-9485-0DAB5F64549B} 2011-04-04 20:14 . 2011-04-04 20:14 -------- d-----w- c:\users\mike\AppData\Local\{D7A19759-55C4-4D21-8D14-B15D0F396B89} 2011-04-04 07:55 . 2011-04-04 07:55 -------- d-----w- c:\users\mike\AppData\Local\{E646AC86-E6E6-43B8-BF14-7BD51ABB7ACF} 2011-04-03 09:33 . 2011-04-03 09:33 -------- d-----w- c:\users\mike\AppData\Local\{65FB1F50-87C0-40C3-AB21-D4B546D398AD} 2011-04-02 16:33 . 2011-04-02 16:33 -------- d-----w- c:\users\mike\AppData\Local\{1E911478-0DAA-4385-ACF8-DD91EFA598F9} 2011-04-02 03:22 . 2011-04-02 03:22 -------- d-----w- c:\users\mike\AppData\Local\{7BA2FC48-5892-4DB9-ACB4-28F5DCE1A66A} 2011-04-01 12:20 . 2011-04-01 12:21 -------- d-----w- c:\users\mike\AppData\Local\{4948BBE8-AB4F-4032-AFDC-BFBF77DBB7AB} 2011-03-31 12:24 . 2011-03-31 12:24 -------- d-----w- c:\users\mike\AppData\Local\{4834C767-8F18-4341-A9AA-30746CAF2C20} 2011-03-30 12:25 . 2011-03-30 12:25 -------- d-----w- c:\users\mike\AppData\Local\{994BD1AD-A51A-4315-9E59-D6009DCE8D08} 2011-03-29 12:33 . 2011-03-29 12:34 -------- d-----w- c:\users\mike\AppData\Local\{3FC0EB9F-C257-4CBC-A71A-413876081236} 2011-03-28 12:19 . 2011-03-28 12:19 -------- d-----w- c:\users\mike\AppData\Local\{5BB6F680-882E-4264-84FA-95EB7F011048} 2011-03-27 18:10 . 2011-03-27 18:10 -------- d-----w- c:\users\mike\AppData\Local\{2BB66A8A-14E5-4252-8757-1727D7128A6C} 2011-03-27 16:49 . 2011-03-27 16:49 -------- d-----w- c:\users\mike\AppData\Local\{B9F68E75-131C-4A91-B062-38824BDA35C7} 2011-03-27 04:48 . 2011-03-27 04:48 -------- d-----w- c:\users\mike\AppData\Local\{37BF7B4A-E352-4782-B266-76BD4B015F52} 2011-03-26 15:29 . 2011-03-26 15:29 -------- d-----w- c:\users\mike\AppData\Local\{07C0076B-ABDD-452A-8F95-15914032AAFB} 2011-03-25 21:16 . 2011-03-25 21:16 -------- d-----w- c:\users\mike\AppData\Local\{A8222740-3E50-4874-8161-64BA63046BAA} 2011-03-25 09:15 . 2011-03-25 09:15 -------- d-----w- c:\users\mike\AppData\Local\{5903A6C1-025B-43E1-883B-CC9E2C9BCFBF} 2011-03-24 21:15 . 2011-03-24 21:15 -------- d-----w- c:\users\mike\AppData\Local\{FF51A546-E57C-4DE4-948C-9E371F4C7EF7} 2011-03-23 23:36 . 2011-03-23 23:36 -------- d-----w- c:\users\mike\AppData\Local\{BBA48236-2316-4BD6-9933-1E5A70B1BF66} 2011-03-23 11:35 . 2011-03-23 11:35 -------- d-----w- c:\users\mike\AppData\Local\{D7916350-4400-4223-B20A-35FC14DBA6C5} 2011-03-22 23:34 . 2011-03-22 23:35 -------- d-----w- c:\users\mike\AppData\Local\{4D6EC84D-A1EA-4B16-8327-369F04276F3A} 2011-03-22 11:34 . 2011-03-22 11:34 -------- d-----w- c:\users\mike\AppData\Local\{4BE02F82-89AD-41C3-BBF0-3D0D5D32EC0A} 2011-03-22 11:24 . 2011-04-14 17:56 -------- d-----w- c:\users\mike\AppData\Roaming\TS3Client 2011-03-22 11:22 . 2011-03-22 11:22 -------- d-----w- c:\program files\TeamSpeak 3 Client 2011-03-22 09:35 . 2011-03-22 09:36 -------- d-----w- c:\users\mike\AppData\Roaming\teamspeak2 2011-03-22 09:35 . 2011-03-22 09:35 34064 ----a-w- c:\windows\system32\lhacm.acm 2011-03-22 09:35 . 2011-03-22 09:35 -------- d-----w- c:\program files\Teamspeak2_RC2 2011-03-21 23:33 . 2011-03-21 23:34 -------- d-----w- c:\users\mike\AppData\Local\{8A573385-CB9C-48FB-A904-923E066E2306} 2011-03-21 11:33 . 2011-03-21 11:33 -------- d-----w- c:\users\mike\AppData\Local\{BA939EB4-00E6-4839-A093-9E98C0137C98} 2011-03-21 11:19 . 2011-03-21 11:20 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment 2011-03-21 11:18 . 2011-03-21 11:39 -------- d-----w- c:\programdata\Blizzard Entertainment 2011-03-20 23:32 . 2011-03-20 23:32 -------- d-----w- c:\users\mike\AppData\Local\{4A90E209-6F8A-47CD-8062-0B596DC4C325} 2011-03-20 11:31 . 2011-03-20 11:32 -------- d-----w- c:\users\mike\AppData\Local\{0855DDDA-1725-4B69-9F2A-6A1A4DFF05E5} 2011-03-19 18:08 . 2011-03-19 18:08 -------- d-----w- c:\users\mike\AppData\Local\{E263A234-008E-426C-87CD-0F9A39561506} 2011-03-19 06:07 . 2011-03-19 06:07 -------- d-----w- c:\users\mike\AppData\Local\{DE187948-41D0-48EF-8B3D-099C46D2756B} 2011-03-18 13:14 . 2011-03-18 13:14 -------- d-----w- c:\users\mike\AppData\Local\{6D93ED1C-FDD1-48D2-92EA-ACCCCE5E49F1} 2011-03-17 13:14 . 2011-03-17 13:15 -------- d-----w- c:\users\mike\AppData\Local\{67A8377E-AF42-4181-844B-FD8316A69BE5} 2011-03-16 21:14 . 2011-03-16 21:15 -------- d-----w- c:\users\mike\AppData\Local\{D0CF9CCB-E179-4B74-BB99-DB1470A41296} 2011-03-16 08:30 . 2011-03-16 08:31 -------- d-----w- c:\users\mike\AppData\Local\{909109BE-0F33-4CB6-B2F8-125DE74CDD99} . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-03-11 11:14 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll 2011-03-08 21:16 . 2010-06-24 10:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-02-19 06:30 . 2011-03-09 08:01 805376 ----a-w- c:\windows\system32\FntCache.dll 2011-02-19 06:30 . 2011-03-09 08:01 1076736 ----a-w- c:\windows\system32\DWrite.dll 2011-02-19 06:30 . 2011-03-09 08:01 739840 ----a-w- c:\windows\system32\d2d1.dll 2011-02-09 01:50 . 2011-02-09 01:50 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-02-03 05:54 . 2011-02-22 08:33 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys 2011-02-02 17:11 . 2010-02-09 20:01 222080 ------w- c:\windows\system32\MpSigStub.exe 2011-01-29 19:18 . 2011-01-29 19:18 218688 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ManyCam"="c:\program files\ManyCam\Bin\ManyCam.exe" [2010-12-21 1739848] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408] "Google Update"="c:\users\mike\AppData\Local\Google\Update\GoogleUpdate.exe" [2011-01-28 136176] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760] "ICQ"="c:\program files\ICQ7.4\ICQ.exe" [2011-03-01 119608] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LManager"="c:\program files\Launch Manager\LManager.exe" [2008-04-02 768520] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-04 281768] "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\herrbert.exe" [2010-12-20 963976] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-01-28 136176] R3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [2005-08-17 7168] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-01-29 218688] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-03-04 135336] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] S2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe [2010-10-15 326704] S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2007-05-16 32256] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - KLMD25 *Deregistered* - klmd25 . Inhalt des "geplante Tasks" Ordners . 2011-04-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-01-28 20:32] . 2011-04-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-01-28 20:32] . 2011-04-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2100560739-1819123127-3695758804-1000Core.job - c:\users\mike\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-30 20:32] . 2011-04-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2100560739-1819123127-3695758804-1000UA.job - c:\users\mike\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-30 20:32] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://de.ask.com?o=102869&l=dis&gct=hp uInternet Settings,ProxyServer = http=;ftp=;https=; IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files\ICQ7.4\ICQ.exe FF - ProfilePath - c:\users\mike\AppData\Roaming\Mozilla\Firefox\Profiles\hvz1ujym.default\ FF - prefs.js: browser.search.selectedEngine - Ask.com FF - prefs.js: browser.startup.homepage - hxxp://de.ask.com?o=102869&l=dis&gct=hp FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=MYC-ST&o=102869&locale=de_DE&apn_uid=8adcccd9-78d0-4181-ba9c-963df8105170&apn_ptnrs=5J&apn_sauid=AD749FDE-86A5-4ABA-9CA6-1DF7B53706C1&apn_dtid=YYYYYYYYDE&q= FF - prefs.js: network.proxy.type - 0 FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} FF - Ext: afurladvisor: afurladvisor@anchorfree.com - c:\program files\Mozilla Firefox\extensions\afurladvisor@anchorfree.com . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EverestDriver] "ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2011-04-14 20:07:51 ComboFix-quarantined-files.txt 2011-04-14 18:07 . Vor Suchlauf: 8 Verzeichnis(se), 23.031.529.472 Bytes frei Nach Suchlauf: 10 Verzeichnis(se), 22.926.438.400 Bytes frei . - - End Of File - - A1CF166E06C2B02DD76F9AC15999C6DE |
![]() |
Themen zu System Defragmenter: Daten verschwunden. |
adobe, antivir, autorun, avg, avgntflt.sys, avira, bho, dateien verschwunden, daten verschwunden, defender, explorer, firefox, flash player, format, ftp, google, helper, home, hotspot, hotspot shield, install.exe, langs, launch, location, logfile, mozilla, nexus, nicht gefunden, nvlddmkm.sys, oldtimer, otl.exe, plug-in, rarsfx0, registry, rundll, saver, sched.exe, searchplugins, security, shell32.dll, software, start menu, studio, system, taskhost.exe, teamspeak, temp, trojan.agent.u, viren, webcheck |