cloudens | 25.07.2012 18:09 | Gemacht.
Zuerst ist, nachdem sich das Programm geschlossen hatte, ein Problem aufgetreten. Ich konnte keine Programme starten oder ausführen. Nach einem Neustart des Computer war es dann wieder möglich.
hier das Combofix Log: Code:
ComboFix 12-07-26.03 - ** 25.07.2012 18:45:36.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4078.2914 [GMT 2:00]
ausgeführt von:: c:\users\**\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\**\AppData\Roaming\edxLabs
c:\users\**\AppData\Roaming\edxLabs\edxSilkroadLoader5\analyzer\log\12642133.txt
c:\users\**\AppData\Roaming\edxLabs\edxSilkroadLoader5\analyzer\log\12662460.txt
c:\users\**\AppData\Roaming\edxLabs\edxSilkroadLoader5\edxSilkroadLoader5.ini
c:\users\**\AppData\Roaming\edxLabs\edxSilkroadLoader6\edxSilkroadLoader6.ini
c:\users\**\SilkroadOnline_GlobalOfficial_v1_365_LEGEND_8.exe
c:\users\**\SilkroadOnline_SROROfficial_v1_041.exe
D:\install.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-06-25 bis 2012-07-25 ))))))))))))))))))))))))))))))
.
.
2012-07-25 16:48 . 2012-07-25 16:48 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-07-25 16:48 . 2012-07-25 16:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-07-25 15:21 . 2012-07-25 15:22 -------- d-----w- c:\program files\Nightly
2012-07-25 00:57 . 2012-07-25 00:57 -------- d-----w- C:\_OTL
2012-07-24 13:54 . 2012-07-25 16:21 -------- d-----w- c:\users\**\AppData\Roaming\.minecraft
2012-07-24 09:19 . 2012-06-29 10:04 9133488 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0DB76E37-E41E-4080-AE01-7079D3AC358B}\mpengine.dll
2012-07-21 16:26 . 2012-07-21 16:26 -------- d-----w- c:\users\**\AppData\Local\fontconfig
2012-07-21 16:26 . 2012-07-21 16:26 -------- d-----w- c:\users\**\.gimp-2.8
2012-07-21 16:26 . 2012-07-21 16:26 -------- d-----w- c:\users\**\AppData\Local\gegl-0.2
2012-07-21 16:25 . 2012-07-21 16:25 -------- d-----w- c:\program files\GIMP 2
2012-07-21 12:05 . 2012-07-21 12:05 388096 ----a-r- c:\users\**\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-07-21 12:05 . 2012-07-21 12:05 -------- d-----w- c:\program files (x86)\Trend Micro
2012-07-20 23:47 . 2012-07-20 23:49 -------- d-----w- c:\users\**\AppData\Local\mcpatcher
2012-07-20 18:41 . 2012-07-20 18:41 955840 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-07-18 17:51 . 2012-07-18 21:12 -------- d-----w- c:\program files (x86)\Silkroad
2012-07-18 09:01 . 2012-07-21 11:38 -------- d-----w- c:\users\**\AppData\Roaming\uTorrent
2012-07-15 08:04 . 2012-07-21 11:33 -------- d-----w- c:\programdata\eMule
2012-07-15 07:21 . 2012-07-21 11:33 -------- d-----w- c:\users\**\AppData\Local\eMule
2012-07-14 21:36 . 2012-07-14 21:37 -------- d-----w- c:\users\**\ScreenCap
2012-07-12 17:29 . 2009-03-18 15:35 33856 ---ha-w- c:\windows\system32\hamachi.sys
2012-07-12 17:29 . 2012-07-12 17:29 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2012-07-12 15:57 . 2012-07-12 15:57 -------- d-----w- c:\users\**\AppData\Local\Aeria Games
2012-07-12 15:57 . 2012-07-21 11:31 -------- d-----w- c:\programdata\Aeria Games
2012-07-12 15:41 . 2012-07-21 11:31 -------- d-sh--w- c:\windows\SysWow64\AI_RecycleBin
2012-07-12 15:41 . 2012-07-12 15:41 -------- d-----w- c:\users\**\AppData\Roaming\Aeria Games & Entertainment
2012-07-11 08:34 . 2012-06-12 03:08 3148800 ----a-w- c:\windows\system32\win32k.sys
2012-07-11 08:30 . 2012-06-06 06:05 495616 ----a-w- c:\program files\Common Files\System\ado\msadox.dll
2012-07-10 16:59 . 2012-07-10 16:59 -------- d-----w- c:\users\**\AppData\Roaming\LolClient
2012-07-06 10:26 . 2012-07-06 10:26 -------- d-----w- c:\users\**\AppData\Roaming\ts3overlay
2012-07-06 10:23 . 2012-07-17 22:09 -------- d-----w- c:\users\**\AppData\Roaming\TS3Client
2012-07-06 10:21 . 2012-07-06 10:21 -------- d-----w- c:\program files\TeamSpeak 3 Client
2012-07-03 05:36 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2012-07-01 12:08 . 2012-07-01 12:08 -------- d-----w- c:\program files (x86)\Avidemux 2.5
2012-07-01 12:04 . 2012-07-01 12:08 -------- d-----w- c:\users\**\AppData\Roaming\avidemux
2012-07-01 09:00 . 2012-07-01 09:00 -------- d-----w- c:\users\**\AppData\Roaming\AnvSoft
2012-07-01 08:57 . 2012-07-01 08:58 25008400 ----a-w- c:\users\**\AppData\Roaming\Microsoft\Windows\Templates\avc-free.exe
2012-06-27 14:02 . 2012-06-27 14:02 -------- d-----w- c:\users\**\AppData\Roaming\OpenOffice.org
2012-06-27 14:01 . 2012-06-27 14:01 -------- d-----w- c:\program files (x86)\OpenOffice.org 3
2012-06-27 14:00 . 2012-06-27 14:00 -------- d-----w- c:\users\**\OpenOffice.org 3.4 (de) Installation Files
2012-06-27 13:49 . 2012-06-27 13:49 -------- d--h--w- c:\programdata\Common Files
2012-06-27 12:14 . 2012-06-27 13:26 -------- d-----w- c:\program files (x86)\1ClickDownload
2012-06-26 12:27 . 2012-06-26 12:27 -------- d-----w- C:\Programme (x86)
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-25 08:58 . 2012-03-28 11:11 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-25 08:58 . 2011-07-11 10:28 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-20 18:41 . 2012-04-01 14:12 839096 ----a-w- c:\windows\system32\deployJava1.dll
2012-07-20 18:41 . 2012-04-01 14:12 268720 ----a-w- c:\windows\system32\javaws.exe
2012-07-20 18:41 . 2012-04-01 14:12 189360 ----a-w- c:\windows\system32\javaw.exe
2012-07-20 18:41 . 2012-04-01 14:12 188840 ----a-w- c:\windows\system32\java.exe
2012-07-11 08:32 . 2012-01-31 20:01 59701280 ----a-w- c:\windows\system32\MRT.exe
2012-07-03 11:46 . 2012-06-13 11:27 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-02 22:19 . 2012-06-19 04:43 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-19 04:43 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-19 04:43 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-19 04:43 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-19 04:43 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-19 04:43 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-19 04:43 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-19 04:43 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:15 . 2012-06-19 04:43 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-05-31 10:25 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-05-28 19:40 . 2012-05-28 19:40 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2012-05-24 14:36 . 2012-05-24 14:36 1660993 ----a-w- c:\programdata\Microsoft\Windows\Start Menu\Programs\Diablo\drtl109.exe
2012-05-23 20:51 . 2012-05-23 20:51 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-05-08 17:39 . 2012-01-30 21:57 98848 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-05-08 17:39 . 2012-01-30 21:57 132832 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-05-04 11:06 . 2012-06-13 04:35 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 11:00 . 2012-06-16 06:12 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-05-04 10:03 . 2012-06-13 04:35 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03 . 2012-06-13 04:35 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-05-04 09:59 . 2012-06-16 06:12 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-05-01 05:40 . 2012-06-13 04:36 209920 ----a-w- c:\windows\system32\profsvc.dll
2012-04-28 03:55 . 2012-06-13 04:36 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AVMWlanClient"="c:\program files (x86)\avmwlanstick\wlangui.exe" [2010-10-22 2105344]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-05-08 348624]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-06-27 1996200]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"IsMyWinLockerReboot"="msiexec.exe" [2010-11-21 73216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\persistentroutes]
"188.138.106.112,255.255.255.255,192.168.2.102,1"=""
"79.110.87.198,255.255.255.255,192.168.2.102,1"=""
"203.85.0.92,255.255.255.255,192.168.2.102,1"=""
"203.85.93.210,255.255.255.255,192.168.2.102,1"=""
"178.63.49.78,255.255.255.255,192.168.2.102,1"=""
"80.84.58.203,255.255.255.255,192.168.2.102,1"=""
"94.102.0.108,255.255.255.255,192.168.2.102,1"=""
"176.9.9.227,255.255.255.255,192.168.2.102,1"=""
"176.227.199.194,255.255.255.255,192.168.2.102,1"=""
"184.22.200.176,255.255.255.255,192.168.2.102,1"=""
"46.252.196.1,255.255.255.255,192.168.2.102,1"=""
"199.27.134.167,255.255.255.255,192.168.2.102,1"=""
"85.153.48.2,255.255.255.255,192.168.2.102,1"=""
"91.227.4.115,255.255.255.255,192.168.2.102,1"=""
"184.173.197.241,255.255.255.255,192.168.2.102,1"=""
"199.27.135.167,255.255.255.255,192.168.2.102,1"=""
"188.72.213.65,255.255.255.255,192.168.2.102,1"=""
"80.190.202.44,255.255.255.255,192.168.2.102,1"=""
"31.170.162.61,255.255.255.255,192.168.2.102,1"=""
"80.190.202.43,255.255.255.255,192.168.2.102,1"=""
"188.72.201.254,255.255.255.255,192.168.2.102,1"=""
"199.27.134.58,255.255.255.255,192.168.2.102,1"=""
"173.245.60.150,255.255.255.255,192.168.2.102,1"=""
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R1 hugoio64;hugoio64;c:\program files (x86)\i-Menu\hugoio64.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 ICQ Service;ICQ Service;c:\program files (x86)\ICQ6Toolbar\ICQ Service.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-25 250056]
R3 avmeject;AVM Eject;c:\windows\system32\drivers\avmeject.sys [2010-10-22 14120]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 netr28ux;RT2870 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr28ux.sys [2010-07-27 1241952]
R3 netr28x;Ralink 802.11n Wireless Driver for Windows Vista;c:\windows\system32\DRIVERS\netr28x.sys [2009-06-10 620544]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [x]
R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 X6va006;X6va006;c:\users\**\AppData\Local\Temp\006B99E.tmp [x]
R4 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
R4 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-15 158856]
R4 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-02-23 2886528]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-12-15 27760]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-05-23 283200]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-08 86224]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe [2011-05-30 36456]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-06-27 2369960]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-05 13336]
S2 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2011-04-22 244624]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-03-01 2348352]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-20 2656280]
S3 e1cexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver C;c:\windows\system32\DRIVERS\e1c62x64.sys [2012-03-16 514736]
S3 fwlanusbn;FRITZ!WLAN N;c:\windows\system32\DRIVERS\fwlanusbn.sys [2010-10-22 714368]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2012-01-17 188224]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
Inhalt des "geplante Tasks" Ordners
.
2012-07-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-28 08:58]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-11 11580520]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\persistentroutes]
"188.138.106.112,255.255.255.255,192.168.2.102,1"=""
"79.110.87.198,255.255.255.255,192.168.2.102,1"=""
"203.85.0.92,255.255.255.255,192.168.2.102,1"=""
"203.85.93.210,255.255.255.255,192.168.2.102,1"=""
"178.63.49.78,255.255.255.255,192.168.2.102,1"=""
"80.84.58.203,255.255.255.255,192.168.2.102,1"=""
"94.102.0.108,255.255.255.255,192.168.2.102,1"=""
"176.9.9.227,255.255.255.255,192.168.2.102,1"=""
"176.227.199.194,255.255.255.255,192.168.2.102,1"=""
"184.22.200.176,255.255.255.255,192.168.2.102,1"=""
"46.252.196.1,255.255.255.255,192.168.2.102,1"=""
"199.27.134.167,255.255.255.255,192.168.2.102,1"=""
"85.153.48.2,255.255.255.255,192.168.2.102,1"=""
"91.227.4.115,255.255.255.255,192.168.2.102,1"=""
"184.173.197.241,255.255.255.255,192.168.2.102,1"=""
"199.27.135.167,255.255.255.255,192.168.2.102,1"=""
"188.72.213.65,255.255.255.255,192.168.2.102,1"=""
"80.190.202.44,255.255.255.255,192.168.2.102,1"=""
"31.170.162.61,255.255.255.255,192.168.2.102,1"=""
"80.190.202.43,255.255.255.255,192.168.2.102,1"=""
"188.72.201.254,255.255.255.255,192.168.2.102,1"=""
"199.27.134.58,255.255.255.255,192.168.2.102,1"=""
"173.245.60.150,255.255.255.255,192.168.2.102,1"=""
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.com
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://acer.msn.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Free YouTube Download - c:\users\**\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to MP3 Converter - c:\users\**\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
FF - ProfilePath - c:\users\**\AppData\Roaming\Mozilla\Firefox\Profiles\yr0932ev.default\
FF - prefs.js: browser.startup.homepage - www.google.de
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-RAM Defrag - c:\windows\system32\GKSUI20.EXE
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va006]
"ImagePath"="\??\c:\users\**\AppData\Local\Temp\006B99E.tmp"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2147699871-4019207594-3428846617-1000\Software\SecuROM\License information*]
"datasecu"=hex:18,14,15,76,c3,5c,38,54,15,3f,08,2a,e4,cc,c2,d1,72,18,15,7c,0c,
68,af,84,c6,ee,93,b9,b4,df,6c,84,5b,dc,5d,53,70,05,e4,90,57,45,10,b7,fb,9d,\
"rkeysecu"=hex:4c,7a,6a,9a,bd,2e,7c,21,2f,01,cb,1b,cf,b9,18,14
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\avmwlanstick\WlanNetService.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-07-25 18:55:26 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2012-07-25 16:55
.
Vor Suchlauf: 11 Verzeichnis(se), 342.781.300.736 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 342.602.440.704 Bytes frei
.
- - End Of File - - 07DFE3B3C9A7013EB78F2DF97B855659 Und hier das Remove Log: Code:
???? ??? Windows Live
???? Windows Live
????? Windows Live
?????? ??????? ?? Windows Live
???????? ?????????? Windows Live
?????????? Windows Live
??????????? ?? Windows Live
Acer eRecovery Management
Acer Games
Acer Registration
Acer ScreenSaver
Acer Updater
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.3) MUI
Agatha Christie - Death on the Nile
Avidemux 2.5 (32-bit)
Avira Free Antivirus
AVM FRITZ!WLAN
Bejeweled 2 Deluxe
Borderlands
Crazy Chicken Kart 2
D3DX10
DAEMON Tools Lite
FATE
Final Drive: Nitro
Flyff
Fotogalerija Windows Live
Free Studio version 5.3.3
Galeria de Fotografias do Windows Live
Galeria fotografii uslugi Windows Live
Galeria fotogràfica del Windows Live
Galerie de photos Windows Live
Galerie foto Windows Live
Galería fotográfica de Windows Live
Gothic 3 - Götterdämmerung
HiJackThis
Hotkey Utility
ICQ Sparberater
Identity Card
ImgBurn
Insaniquarium Deluxe
Intel(R) Management Engine Components
Intel(R) Rapid Storage Technology
Java Auto Updater
Java(TM) 6 Update 30
Jewel Match 3
John Deere Drive Green
Junk Mail filter update
League of Legends
LG Internet Kit
LogMeIn Hamachi
Malwarebytes Anti-Malware Version 1.62.0.1300
Mesh Runtime
Metin2
Microsoft Office 2010
Microsoft Office Klick-und-Los 2010
Microsoft Office Starter 2010 - Deutsch
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
MinecraftAlpha
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Mystery of Mortlake Mansion
MyWinLocker 4
MyWinLocker Suite
Notepad++
NVIDIA PhysX
Oblivion
OpenOffice.org 3.4
Pcsx2 0.9.6
Penguins!
Plants vs. Zombies - Game of the Year
Poczta uslugi Windows Live
Podstawowe programy Windows Live
Polar Bowler
Pošta Windows Live
Project64 1.6
Raccolta foto di Windows Live
RAM Defrag
Rappelz
Realtek High Definition Audio Driver
S.T.A.L.K.E.R. - Shadow of Chernobyl
S?????? f?t???af??? t?? Windows Live
S4 League_EU
Sacred 2 - Fallen Angel
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2518870)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Shredder
Silkroad
SilkroadR
Skype™ 5.8
Slingo Deluxe
SRWare Iron Version SRWare Iron 17.0.1000.1
Star Wars Empire at War
Star Wars Empire at War Forces of Corruption
TeamViewer 7
Torchlight
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update Installer for WildTangent Games App
Virtual Villagers 4 - The Tree of Life
Wedding Dash
Welcome Center
WildTangent Games App (Acer Games)
Windows Live
Windows Live ???
Windows Live ????
Windows Live Argazki Galeria
Windows Live Communications Platform
Windows Live Essentials
Windows Live Fotótár
Windows Live Fotogalerie
Windows Live Fotogalleri
Windows Live Fotogaléria
Windows Live Fotograf Galerisi
Windows Live Galeria de Fotos
Windows Live Galerija fotografija
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Temel Parçalar
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Liven asennustyökalu
Windows Liven sähköposti
Windows Liven valokuvavalikoima
WinRAR 4.10 (32-Bit)
Zuma Deluxe Ich weis ja nicht warum da soviel aufgezählt wird aber kann es sein dass dies alle meine Programme sind? :D
mfg cloudens |