hi habe den scan gemacht
und keine maus oder tastatur verwendet. Code:
ComboFix 12-03-18.04 - Robin 19.03.2012 18:10:06.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4095.2895 [GMT 1:00]
ausgeführt von:: c:\users\Robin\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-02-19 bis 2012-03-19 ))))))))))))))))))))))))))))))
.
.
2012-03-19 17:13 . 2012-03-19 17:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-03-19 16:12 . 2012-03-19 16:13 -------- d-----w- c:\program files\Core Temp
2012-03-17 09:31 . 2012-03-17 09:31 -------- d-----w- c:\program files (x86)\7-Zip
2012-03-17 09:27 . 2012-03-17 09:27 -------- d-----w- C:\_OTL
2012-03-16 09:44 . 2012-02-20 00:05 8643640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{93CA4E39-1C82-4176-B393-38F33324CD83}\mpengine.dll
2012-03-15 02:47 . 2012-03-15 02:47 -------- d-----w- c:\program files (x86)\Common Files\logishrd
2012-03-15 02:47 . 2012-03-15 02:47 -------- d-----w- c:\program files\Common Files\logishrd
2012-03-14 20:17 . 2012-03-14 20:17 -------- d-----w- c:\program files (x86)\ESET
2012-03-14 20:16 . 2011-11-19 15:20 5559152 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-14 20:16 . 2011-11-19 14:50 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-03-14 20:16 . 2011-11-19 14:50 3913584 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-03-14 19:10 . 2012-03-14 19:10 -------- d-----w- c:\programdata\Malwarebytes
2012-03-14 19:10 . 2012-03-14 19:10 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-03-14 19:10 . 2011-12-10 14:24 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-14 19:08 . 2012-02-03 04:34 3145728 ----a-w- c:\windows\system32\win32k.sys
2012-03-14 19:08 . 2012-02-10 06:36 1544192 ----a-w- c:\windows\system32\DWrite.dll
2012-03-14 19:08 . 2012-02-10 05:38 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll
2012-03-14 19:07 . 2012-02-17 06:38 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-03-14 19:07 . 2012-02-17 05:34 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-03-14 19:07 . 2012-02-17 04:58 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-14 19:07 . 2012-02-17 04:57 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-03-14 19:07 . 2012-01-25 06:38 77312 ----a-w- c:\windows\system32\rdpwsx.dll
2012-03-14 19:07 . 2012-01-25 06:38 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-03-14 19:07 . 2012-01-25 06:33 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-03-14 02:14 . 2010-06-02 03:55 77656 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2012-03-14 02:14 . 2010-06-02 03:55 74072 ----a-w- c:\windows\SysWow64\XAPOFX1_5.dll
2012-03-14 02:14 . 2010-06-02 03:55 527192 ----a-w- c:\windows\SysWow64\XAudio2_7.dll
2012-03-14 02:14 . 2010-06-02 03:55 518488 ----a-w- c:\windows\system32\XAudio2_7.dll
2012-03-14 02:14 . 2010-06-02 03:55 239960 ----a-w- c:\windows\SysWow64\xactengine3_7.dll
2012-03-14 02:14 . 2010-06-02 03:55 176984 ----a-w- c:\windows\system32\xactengine3_7.dll
2012-03-14 02:14 . 2010-05-26 10:41 2526056 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2012-03-14 02:14 . 2010-05-26 10:41 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll
2012-03-14 01:42 . 2012-03-14 01:42 22360 ----a-w- c:\windows\SysWow64\X3DAudio1_7.dll
2012-03-14 01:29 . 2012-03-14 01:36 -------- d-----w- C:\The Elder Scrolls V- Skyrim
2012-03-14 01:16 . 2012-03-14 01:27 -------- d-----w- c:\program files (x86)\The Elder Scrolls V- Skyrim
2012-03-14 01:02 . 2012-03-14 01:03 -------- d-----w- c:\program files (x86)\Common Files\Steam
2012-03-13 20:34 . 2012-03-15 11:05 -------- d-----w- c:\users\UpdatusUser
2012-03-13 20:33 . 2012-02-29 21:00 3089728 ----a-w- c:\windows\system32\nvsvc64.dll
2012-03-13 20:33 . 2012-02-29 21:00 6074176 ----a-w- c:\windows\system32\nvcpl.dll
2012-03-13 20:33 . 2012-02-29 20:59 889664 ----a-w- c:\windows\system32\nvvsvc.exe
2012-03-13 20:33 . 2012-02-29 20:59 63296 ----a-w- c:\windows\system32\nvshext.dll
2012-03-13 20:33 . 2012-02-29 20:59 2561856 ----a-w- c:\windows\system32\nvsvcr.dll
2012-03-13 20:33 . 2012-02-29 20:59 118080 ----a-w- c:\windows\system32\nvmctray.dll
2012-03-13 20:33 . 2012-02-29 20:59 2515790 ----a-w- c:\windows\system32\nvcoproc.bin
2012-03-13 20:33 . 2012-03-13 20:33 -------- d-----w- c:\programdata\NVIDIA Corporation
2012-03-13 20:23 . 2012-03-13 20:33 -------- d-----w- C:\NVIDIA
2012-03-13 19:59 . 2012-03-13 20:18 -------- d-----w- c:\program files (x86)\Driver Cleaner Pro
2012-03-13 10:14 . 2012-01-09 12:43 606208 ----a-w- c:\windows\SysWow64\xvidcore.dll
2012-03-13 10:14 . 2012-01-09 12:43 139264 ----a-w- c:\windows\SysWow64\xvid.ax
2012-03-13 10:14 . 2006-07-17 23:00 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
2012-03-13 10:14 . 2004-04-05 09:31 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
2012-03-13 10:14 . 2012-03-13 10:14 -------- d-----w- c:\program files (x86)\Moyea
2012-03-13 05:09 . 2012-03-13 05:09 -------- d-----w- c:\program files\GIMP-2.0
2012-03-08 13:49 . 2012-03-08 13:49 -------- d-----w- c:\windows\SysWow64\wbem\en-US
2012-03-08 13:49 . 2012-03-08 13:49 -------- d-----w- c:\windows\system32\wbem\en-US
2012-03-07 16:46 . 2012-03-07 16:46 -------- d-----w- c:\program files (x86)\Common Files\Skype
2012-03-07 16:46 . 2012-03-07 16:46 -------- d-----r- c:\program files (x86)\Skype
2012-03-07 16:46 . 2012-03-07 16:46 -------- d-----w- c:\programdata\Skype
2012-03-07 14:28 . 2012-01-03 07:03 810496 ----a-w- c:\windows\system32\xvidcore.dll
2012-03-07 14:28 . 2012-01-03 07:03 80896 ----a-w- c:\windows\system32\ff_vfw.dll
2012-03-07 14:28 . 2012-01-03 07:03 183808 ----a-w- c:\windows\system32\xvidvfw.dll
2012-03-07 14:28 . 2012-01-03 07:03 389120 ----a-w- c:\windows\SysWow64\actskn43.ocx
2012-03-07 14:28 . 2012-01-03 07:03 389120 ----a-w- c:\windows\system32\actskn43.ocx
2012-03-07 14:28 . 2012-03-07 14:28 -------- d-----w- c:\program files (x86)\SplitCam
2012-03-07 14:06 . 2012-03-07 14:20 -------- d-----w- c:\programdata\WebcamMax
2012-03-07 14:01 . 2012-03-07 19:20 -------- d-----w- c:\program files (x86)\7.1.0.0
2012-03-07 13:09 . 2004-03-08 23:00 152848 ----a-w- c:\windows\SysWow64\COMDLG32.OCX
2012-03-07 13:09 . 2004-03-08 22:00 132880 ----a-w- c:\windows\SysWow64\MSINET.OCX
2012-03-07 13:09 . 2004-03-08 22:00 1081616 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2012-03-07 13:09 . 2012-03-07 13:09 -------- d-----w- c:\program files (x86)\Common Files\Web Solution Mart
2012-03-07 05:48 . 2012-03-07 12:17 -------- d-----w- c:\program files (x86)\PC Tools
2012-03-07 05:42 . 2012-03-07 12:17 -------- d-----w- c:\program files (x86)\Common Files\PC Tools
2012-03-07 05:42 . 2012-02-24 09:36 230952 ----a-w- c:\windows\system32\drivers\PCTSD64.sys
2012-03-07 05:41 . 2012-03-07 06:03 -------- d-----w- c:\programdata\PC Tools
2012-03-07 04:59 . 2012-03-07 05:40 -------- dc----w- c:\windows\system32\DRVSTORE
2012-03-07 04:59 . 2012-03-07 04:59 55384 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2012-03-07 04:53 . 2012-03-07 04:59 -------- d-----w- c:\programdata\Lavasoft
2012-03-07 04:04 . 2012-03-08 17:10 -------- d-----w- c:\program files (x86)\Pidgin
2012-03-07 01:53 . 2012-03-07 01:53 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-03-07 01:52 . 2012-03-07 01:52 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-03-07 01:52 . 2012-03-07 01:52 -------- d-----w- c:\program files (x86)\Java
2012-03-07 00:55 . 2012-03-19 17:00 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-03-07 00:55 . 2012-03-07 00:55 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2012-03-06 02:03 . 2012-03-06 02:03 -------- d-----w- c:\program files (x86)\Microsoft.NET
2012-03-05 16:46 . 2012-03-05 16:46 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2012-03-05 11:53 . 2012-03-05 11:53 -------- d-----w- c:\program files (x86)\SlimBrowser
2012-03-05 09:18 . 2012-03-05 09:18 -------- d-----w- c:\windows\system32\SPReview
2012-03-05 09:17 . 2012-03-05 09:17 -------- d-----w- c:\windows\system32\EventProviders
2012-03-04 12:13 . 2010-11-20 13:33 951680 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-03-04 12:12 . 2010-11-20 13:34 71552 ----a-w- c:\windows\system32\drivers\volmgr.sys
2012-03-04 12:11 . 2010-11-20 13:33 155008 ----a-w- c:\windows\system32\drivers\mpio.sys
2012-03-04 12:10 . 2010-11-20 13:27 36352 ----a-w- c:\windows\system32\wdiasqmmodule.dll
2012-03-04 12:09 . 2010-11-20 12:21 189952 ----a-w- c:\windows\SysWow64\wdscore.dll
2012-03-04 12:09 . 2010-11-20 13:26 399872 ----a-w- c:\windows\system32\dpx.dll
2012-03-04 12:09 . 2010-11-20 12:21 189952 ----a-w- c:\windows\SysWow64\sqmapi.dll
2012-03-04 12:09 . 2010-11-20 12:21 363008 ----a-w- c:\windows\SysWow64\wbemcomn.dll
2012-03-04 12:09 . 2010-11-20 12:21 189952 ----a-w- c:\program files (x86)\Windows Portable Devices\sqmapi.dll
2012-03-04 12:09 . 2010-11-20 12:19 606208 ----a-w- c:\windows\SysWow64\wbem\fastprox.dll
2012-03-04 12:07 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll
2012-03-04 12:07 . 2010-11-20 13:27 244736 ----a-w- c:\program files\Windows Portable Devices\sqmapi.dll
2012-03-04 12:07 . 2010-11-20 13:27 244736 ----a-w- c:\windows\system32\sqmapi.dll
2012-03-04 09:44 . 2011-02-19 12:05 1139200 ----a-w- c:\windows\system32\FntCache.dll
2012-03-04 09:44 . 2011-02-19 12:04 902656 ----a-w- c:\windows\system32\d2d1.dll
2012-03-04 09:44 . 2011-02-19 06:30 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2012-03-03 12:44 . 2011-03-25 03:29 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2012-03-03 12:44 . 2011-03-25 03:29 98816 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2012-03-03 12:44 . 2011-03-25 03:29 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2012-03-03 12:44 . 2011-03-25 03:29 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys
2012-03-03 12:44 . 2011-03-25 03:29 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2012-03-03 12:44 . 2011-03-25 03:29 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2012-03-03 02:28 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2012-03-03 02:14 . 2010-12-23 10:42 961024 ----a-w- c:\windows\system32\CPFilters.dll
2012-03-03 02:13 . 2011-10-26 05:21 43520 ----a-w- c:\windows\system32\csrsrv.dll
2012-03-03 02:12 . 2011-04-22 22:15 27520 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2012-03-03 02:11 . 2011-05-24 11:42 404480 ----a-w- c:\windows\system32\umpnpmgr.dll
2012-03-03 02:08 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-03-03 02:08 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-03-02 19:44 . 2012-03-02 19:44 -------- d-----w- c:\program files (x86)\ICQ6Toolbar
2012-03-02 19:44 . 2012-03-02 19:44 -------- d-----w- c:\programdata\ICQ
2012-03-02 19:40 . 2012-03-02 19:45 -------- d-----w- c:\program files (x86)\ICQ7.7
2012-03-02 11:24 . 2012-03-02 11:24 -------- d-----w- c:\windows\SysWow64\QuickTime
2012-03-02 11:24 . 2012-03-02 11:25 -------- d-----w- c:\programdata\TechSmith
2012-03-02 11:24 . 2012-03-02 11:24 -------- d-----w- c:\program files (x86)\QuickTime
2012-03-02 11:24 . 2012-03-02 11:24 -------- d-----w- c:\program files (x86)\Common Files\TechSmith Shared
2012-03-02 11:24 . 2012-03-02 11:24 -------- d-----w- c:\program files (x86)\TechSmith
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-05 09:24 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-03-05 09:24 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-03-02 09:34 . 2009-08-18 11:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2012-03-02 09:34 . 2009-08-18 10:24 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-01-18 05:44 . 2012-01-18 05:44 540960 ----a-w- c:\windows\SysWow64\LVUI2RC.dll
2012-01-18 05:44 . 2012-01-18 05:44 545056 ----a-w- c:\windows\SysWow64\LVUI2.dll
2012-01-18 05:44 . 2012-01-18 05:44 561440 ----a-w- c:\windows\system32\LVUIRC64.dll
2012-01-18 05:44 . 2012-01-18 05:44 4865568 ----a-w- c:\windows\system32\drivers\lvuvc64.sys
2012-01-18 05:44 . 2012-01-18 05:44 769312 ----a-w- c:\windows\system32\LVUI64.dll
2012-01-18 05:44 . 2012-01-18 05:44 351136 ----a-w- c:\windows\system32\drivers\lvrs64.sys
2012-01-18 05:44 . 2012-01-18 05:44 307488 ----a-w- c:\windows\SysWow64\lvcodec2.dll
2012-01-18 05:44 . 2012-01-18 05:44 263456 ----a-w- c:\windows\system32\lvco13311044.dll
2012-01-18 05:44 . 2012-01-18 05:44 176416 ----a-w- c:\windows\system32\lvcod64.dll
2012-01-18 05:44 . 2012-01-18 05:44 336408 ----a-w- c:\windows\SysWow64\DevManagerCore.dll
2012-01-18 05:44 . 2012-01-18 05:44 336408 ----a-w- c:\windows\system32\DevManagerCore.dll
2012-01-18 05:44 . 2012-01-18 05:44 10920984 ----a-w- c:\windows\SysWow64\LogiDPP.dll
2012-01-18 05:44 . 2012-01-18 05:44 10920984 ----a-w- c:\windows\system32\LogiDPP.dll
2012-01-18 05:44 . 2012-01-18 05:44 104472 ----a-w- c:\windows\SysWow64\LogiDPPApp.exe
2012-01-18 05:44 . 2012-01-18 05:44 104472 ----a-w- c:\windows\system32\LogiDPPApp.exe
2012-01-18 05:23 . 2012-01-18 05:23 38958 ----a-w- c:\windows\system32\Repository.reg
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{A02B5E09-122E-4A2D-B996-D997485B8C9E}]
2012-02-28 17:11 269312 ----a-w- c:\users\Robin\AppData\LocalLow\Flagfox\IE\Flagfox.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-02-13 3481408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-07 4241512]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]
R3 ALSysIO;ALSysIO;c:\users\Robin\AppData\Local\Temp\ALSysIO64.sys [x]
R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [x]
R3 LVUVC64;Logitech HD Webcam C510(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [x]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam_x64.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 FlagfoxUpdater;Flagfox Updater;c:\users\Robin\AppData\LocalLow\Flagfox\IE\FlagfoxUpdater.exe [2012-02-28 18432]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-03-01 2348352]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-29 382272]
S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-01-18 450848]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-07 00:15 135408 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page =
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files (x86)\ICQ7.7\ICQ.exe
TCP: DhcpNameServer = 192.168.0.1
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3752288333-708083476-1710006870-1000\Software\SecuROM\License information*]
"datasecu"=hex:51,61,cc,75,07,db,89,fd,0d,69,f4,14,17,19,52,52,53,0f,28,8b,42,
f1,19,f0,55,93,ef,fc,00,12,82,5a,9b,a0,f8,17,65,11,d3,50,5d,2b,1a,32,1e,35,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-03-19 18:17:33 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2012-03-19 17:17
.
Vor Suchlauf: 9 Verzeichnis(se), 112.393.822.208 Bytes frei
Nach Suchlauf: 12 Verzeichnis(se), 112.277.676.032 Bytes frei
.
- - End Of File - - E9A397C92D285160F2E951C24B5FF8B8 |