tschobeuter | 18.10.2012 19:17 | Na endlich, jetzt hat es geklappt.
Start im Abgesicherten Modus ging nicht per F-Taste. Ich muust den Rechner "abwürgen" um dann das Menue zur Auswahl des abgesichterten Modus zu bekommen.
Im abgesicherten Modus dann ComboFix neu runtergeladen und gestartet.
Dann kam die Meldung, dass mein Virenscanner läuft. In der Taskleiste war er aber nicht sichtbar. Also im Taskmanager nachgeschaut und auch da nix gefunden.
In der Verzweiflung habe ich dann halt auf eigenes Risiko trotz Virenscanner Combofix laufen lassen und siehe da, es ist durchgelaufen und nach dem Neustart geht alles wie vorher. Anbei das ComboFix-log: Code:
ComboFix 12-10-18.03 - Reiner 18.10.2012 19:59:09.3.3 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.49.1031.18.3070.2467 [GMT 2:00]
ausgeführt von:: c:\dokumente und einstellungen\Reiner\Desktop\Bundestrojaner\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2013 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\dokumente und einstellungen\All Users\Anwendungsdaten\TEMP
c:\dokumente und einstellungen\Christine\4.0
c:\dokumente und einstellungen\Christine\WINDOWS
c:\dokumente und einstellungen\Reiner\WINDOWS
c:\programme\INSTALL.LOG
c:\programme\Setup.exe
c:\programme\sys
c:\programme\sys\access.avi
c:\programme\sys\Addins\MMActiveMap-ger.dll
c:\programme\sys\Addins\MMActiveMap.dll
c:\programme\sys\Addins\MMMapOrganizer-ger.dll
c:\programme\sys\Addins\MMMapOrganizer.dll
c:\programme\sys\Addins\MMOutlook-ger.dll
c:\programme\sys\Addins\MMOutlook.dll
c:\programme\sys\Addins\MMPPExport-ger.dll
c:\programme\sys\Addins\MMPPExport.dll
c:\programme\sys\Addins\MMProject-ger.dll
c:\programme\sys\Addins\MMProject.dll
c:\programme\sys\Addins\MMToolkit-ger.dll
c:\programme\sys\Addins\MMToolkit.dll
c:\programme\sys\Addins\MMWordIE-ger.dll
c:\programme\sys\Addins\MMWordIE.dll
c:\programme\sys\Addins\RegisterAddIn.bat
c:\programme\sys\Addins\UnregisterAddIn.bat
c:\programme\sys\browser.htm
c:\programme\sys\BSCOutline.class
c:\programme\sys\codes\code-p1.bmp
c:\programme\sys\codes\code-p1.emf
c:\programme\sys\codes\code-p2.bmp
c:\programme\sys\codes\code-p2.emf
c:\programme\sys\codes\code-p3.bmp
c:\programme\sys\codes\code-p3.emf
c:\programme\sys\codes\code-p4.bmp
c:\programme\sys\codes\code-p4.emf
c:\programme\sys\codes\code-p5.bmp
c:\programme\sys\codes\code-p5.emf
c:\programme\sys\codes\code-p6.bmp
c:\programme\sys\codes\code-p6.emf
c:\programme\sys\codes\code-p7.bmp
c:\programme\sys\codes\code-p7.emf
c:\programme\sys\codes\code-p8.bmp
c:\programme\sys\codes\code-p8.emf
c:\programme\sys\codes\code-p9.bmp
c:\programme\sys\codes\code-p9.emf
c:\programme\sys\codes\code-pa.bmp
c:\programme\sys\codes\code-pa.emf
c:\programme\sys\codes\code-pb.bmp
c:\programme\sys\codes\code-pb.emf
c:\programme\sys\codes\code-pc.bmp
c:\programme\sys\codes\code-pc.emf
c:\programme\sys\codes\code1.bmp
c:\programme\sys\codes\code1.emf
c:\programme\sys\codes\code10.bmp
c:\programme\sys\codes\code10.emf
c:\programme\sys\codes\code11.bmp
c:\programme\sys\codes\code11.emf
c:\programme\sys\codes\code12.bmp
c:\programme\sys\codes\code12.emf
c:\programme\sys\codes\code13.bmp
c:\programme\sys\codes\code13.emf
c:\programme\sys\codes\code14.bmp
c:\programme\sys\codes\code14.emf
c:\programme\sys\codes\code15.bmp
c:\programme\sys\codes\code15.emf
c:\programme\sys\codes\code16.bmp
c:\programme\sys\codes\code16.emf
c:\programme\sys\codes\code17.bmp
c:\programme\sys\codes\code17.emf
c:\programme\sys\codes\code18.bmp
c:\programme\sys\codes\code18.emf
c:\programme\sys\codes\code19.bmp
c:\programme\sys\codes\code19.emf
c:\programme\sys\codes\code2.bmp
c:\programme\sys\codes\code2.emf
c:\programme\sys\codes\code20.bmp
c:\programme\sys\codes\code20.emf
c:\programme\sys\codes\code21.bmp
c:\programme\sys\codes\code21.emf
c:\programme\sys\codes\code22.bmp
c:\programme\sys\codes\code22.emf
c:\programme\sys\codes\code23.bmp
c:\programme\sys\codes\code23.emf
c:\programme\sys\codes\code24.bmp
c:\programme\sys\codes\code24.emf
c:\programme\sys\codes\code25.bmp
c:\programme\sys\codes\code25.emf
c:\programme\sys\codes\code26.bmp
c:\programme\sys\codes\code26.emf
c:\programme\sys\codes\code27.bmp
c:\programme\sys\codes\code27.emf
c:\programme\sys\codes\code28.bmp
c:\programme\sys\codes\code28.emf
c:\programme\sys\codes\code29.bmp
c:\programme\sys\codes\code29.emf
c:\programme\sys\codes\code3.bmp
c:\programme\sys\codes\code3.emf
c:\programme\sys\codes\code30.bmp
c:\programme\sys\codes\code30.emf
c:\programme\sys\codes\code31.bmp
c:\programme\sys\codes\code31.emf
c:\programme\sys\codes\code32.bmp
c:\programme\sys\codes\code32.emf
c:\programme\sys\codes\code33.bmp
c:\programme\sys\codes\code33.emf
c:\programme\sys\codes\code34.bmp
c:\programme\sys\codes\code34.emf
c:\programme\sys\codes\code35.bmp
c:\programme\sys\codes\code35.emf
c:\programme\sys\codes\code36.bmp
c:\programme\sys\codes\code36.emf
c:\programme\sys\codes\code37.bmp
c:\programme\sys\codes\code37.emf
c:\programme\sys\codes\code38.bmp
c:\programme\sys\codes\code38.emf
c:\programme\sys\codes\code39.bmp
c:\programme\sys\codes\code39.emf
c:\programme\sys\codes\code4.bmp
c:\programme\sys\codes\code4.emf
c:\programme\sys\codes\code40.bmp
c:\programme\sys\codes\code40.emf
c:\programme\sys\codes\code41.bmp
c:\programme\sys\codes\code41.emf
c:\programme\sys\codes\code42.bmp
c:\programme\sys\codes\code42.emf
c:\programme\sys\codes\code43.bmp
c:\programme\sys\codes\code43.emf
c:\programme\sys\codes\code5.bmp
c:\programme\sys\codes\code5.emf
c:\programme\sys\codes\code6.bmp
c:\programme\sys\codes\code6.emf
c:\programme\sys\codes\code7.bmp
c:\programme\sys\codes\code7.emf
c:\programme\sys\codes\code8.bmp
c:\programme\sys\codes\code8.emf
c:\programme\sys\codes\code9.bmp
c:\programme\sys\codes\code9.emf
c:\programme\sys\codes\Thumbs.db
c:\programme\sys\Demo.exe
c:\programme\sys\help-maps\Hier beginnen!.mmp
c:\programme\sys\help-maps\HTML-Export.mmp
c:\programme\sys\help-maps\Infomap-Brainstorming.mmp
c:\programme\sys\help-maps\Infomap-Information.mmp
c:\programme\sys\help-maps\Infomap-Meeting-Organisation.mmp
c:\programme\sys\help-maps\Infomap-Projekt-Planung.mmp
c:\programme\sys\help-maps\locations.wmf
c:\programme\sys\help-maps\MM Mobile.mmp
c:\programme\sys\help-maps\Modernes Portrait.pot
c:\programme\sys\help-maps\MS Project-Import.mmp
c:\programme\sys\help-maps\Outlook-Aufgaben-Import.mmp
c:\programme\sys\help-maps\Power-Auswahl-Filter.mmp
c:\programme\sys\help-maps\PowerPoint-Export.mmp
c:\programme\sys\help-maps\QuickStart-Hilfe-Map.mmp
c:\programme\sys\help-maps\Schnelleinstieg (Stiftmodus).mmp
c:\programme\sys\help-maps\Schnelleinstieg.mmp
c:\programme\sys\help-maps\Thumbs.db
c:\programme\sys\help-maps\Tipps und Tricks.mmp
c:\programme\sys\help-maps\Word-Import.mmp
c:\programme\sys\htmlcode.gif
c:\programme\sys\jre\1.1\bin\cs_sb.jar
c:\programme\sys\jre\1.1\bin\javai.dll
c:\programme\sys\jre\1.1\bin\javakey.exe
c:\programme\sys\jre\1.1\bin\JdbcOdbc.dll
c:\programme\sys\jre\1.1\bin\jpeg.dll
c:\programme\sys\jre\1.1\bin\jre.exe
c:\programme\sys\jre\1.1\bin\jrew.exe
c:\programme\sys\jre\1.1\bin\math.dll
c:\programme\sys\jre\1.1\bin\MMConferenceSBHost.dll
c:\programme\sys\jre\1.1\bin\mmedia.dll
c:\programme\sys\jre\1.1\bin\net.dll
c:\programme\sys\jre\1.1\bin\rmiregistry.exe
c:\programme\sys\jre\1.1\bin\symcjit.dll
c:\programme\sys\jre\1.1\bin\sysresource.dll
c:\programme\sys\jre\1.1\bin\winawt.dll
c:\programme\sys\jre\1.1\bin\zip.dll
c:\programme\sys\jre\1.1\CHANGES
c:\programme\sys\jre\1.1\COPYRIGHT
c:\programme\sys\jre\1.1\lib\awt.properties
c:\programme\sys\jre\1.1\lib\content-types.properties
c:\programme\sys\jre\1.1\lib\DeIsL1.isu
c:\programme\sys\jre\1.1\lib\DeIsL2.isu
c:\programme\sys\jre\1.1\lib\font.properties
c:\programme\sys\jre\1.1\lib\rt.jar
c:\programme\sys\jre\1.1\lib\security\java.security
c:\programme\sys\jre\1.1\lib\serialver.properties
c:\programme\sys\jre\1.1\LICENSE
c:\programme\sys\jre\1.1\README
c:\programme\sys\Map Galerie.exe
c:\programme\sys\mindmap.emf
c:\programme\sys\PictureStock.rtf
c:\programme\sys\PrintForms.ini
c:\programme\sys\spell\Sscege.tlx
c:\programme\sys\spell\sscege2.clx
c:\programme\sys\spell\Sscegeo.tlx
c:\programme\sys\spell\sscegeo2.clx
c:\programme\sys\Symbolspatch45.ini
c:\programme\sys\Templates45-1.ini
c:\programme\sys\Templates45-2.ini
c:\programme\sys\Thumbs.db
c:\programme\sys\title.emf
c:\programme\sys\title.ini
c:\programme\sys\viewlets\AccessKnowledge.viewlet
c:\programme\sys\viewlets\AccessKnowledge_viewlet.html
c:\programme\sys\viewlets\Autolayout.viewlet
c:\programme\sys\viewlets\Autolayout_viewlet.html
c:\programme\sys\viewlets\BranchLength.viewlet
c:\programme\sys\viewlets\BranchLength_viewlet.html
c:\programme\sys\viewlets\Conference.viewlet
c:\programme\sys\viewlets\Conference_viewlet.html
c:\programme\sys\viewlets\EmailMap.viewlet
c:\programme\sys\viewlets\EmailMap_viewlet.html
c:\programme\sys\viewlets\ExportText.viewlet
c:\programme\sys\viewlets\ExportText_viewlet.html
c:\programme\sys\viewlets\FirstUser.viewlet
c:\programme\sys\viewlets\FirstUser_viewlet.html
c:\programme\sys\viewlets\FTPMap.viewlet
c:\programme\sys\viewlets\FTPMap_viewlet.html
c:\programme\sys\viewlets\GetStarted.viewlet
c:\programme\sys\viewlets\GetStarted_viewlet.html
c:\programme\sys\viewlets\Hyperlinks.viewlet
c:\programme\sys\viewlets\Hyperlinks_viewlet.html
c:\programme\sys\viewlets\MultiMap.viewlet
c:\programme\sys\viewlets\MultiMap_viewlet.html
c:\programme\sys\viewlets\Palm.viewlet
c:\programme\sys\viewlets\Palm_viewlet.html
c:\programme\sys\viewlets\PowerSelect.viewlet
c:\programme\sys\viewlets\PowerSelect_viewlet.html
c:\programme\sys\viewlets\Presentation.viewlet
c:\programme\sys\viewlets\Presentation_viewlet.html
c:\programme\sys\viewlets\PrintMap.viewlet
c:\programme\sys\viewlets\PrintMap_viewlet.html
c:\programme\sys\viewlets\PriorBranch.viewlet
c:\programme\sys\viewlets\PriorBranch_viewlet.html
c:\programme\sys\viewlets\PriorSym.viewlet
c:\programme\sys\viewlets\PriorSym_viewlet.html
c:\programme\sys\viewlets\ProjectSync.viewlet
c:\programme\sys\viewlets\ProjectSync_viewlet.html
c:\programme\sys\viewlets\Rearrange.viewlet
c:\programme\sys\viewlets\Rearrange_viewlet.html
c:\programme\sys\viewlets\standardPro.vbs
c:\programme\sys\viewlets\SummFocus.viewlet
c:\programme\sys\viewlets\SummFocus_viewlet.html
c:\programme\sys\viewlets\Thumbs.db
c:\programme\sys\viewlets\vb20.jar
c:\programme\sys\viewlets\Ziparc.viewlet
c:\programme\sys\viewlets\Ziparc_viewlet.html
c:\windows\IsUn0407.exe
c:\windows\jestertb.dll
c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\Cache
c:\windows\system32\Cache\1a05564a7dd8f01c.fb
c:\windows\system32\Cache\272512937d9e61a4.fb
c:\windows\system32\Cache\287204568329e189.fb
c:\windows\system32\Cache\28bc8f716fd76a47.fb
c:\windows\system32\Cache\2c53092c95605355.fb
c:\windows\system32\Cache\31a0997e9a5b5eb3.fb
c:\windows\system32\Cache\32c84fe32bb74d60.fb
c:\windows\system32\Cache\3917078cb68ec657.fb
c:\windows\system32\Cache\590ba23ce359fd0c.fb
c:\windows\system32\Cache\610289e025a3ee9a.fb
c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\system32\Cache\6d03dad1035885d3.fb
c:\windows\system32\Cache\a8556537add6dfc5.fb
c:\windows\system32\Cache\ad10a52aff5e038d.fb
c:\windows\system32\Cache\c1fa887b03019701.fb
c:\windows\system32\Cache\c4d28dca2e7648be.fb
c:\windows\system32\Cache\d201ef9910cd39de.fb
c:\windows\system32\Cache\d2e94710a5708128.fb
c:\windows\system32\Cache\d79b9dfe81484ec4.fb
c:\windows\system32\Cache\d9a1279339068b13.fb
c:\windows\system32\Cache\f998975c9cc711ee.fb
c:\windows\system32\dllcache\dlimport.exe
c:\windows\system32\dllcache\wmpvis.dll
c:\windows\system32\FlashPlayerInstaller.exe
c:\windows\system32\msstdfmt.dll
c:\windows\system32\PowerToyReadme.htm
c:\windows\system32\ReadMe.txt
c:\windows\WindowsUpdate.log
D:\install.exe
.
-- Vorheriger Suchlauf --
.
Infizierte Kopie von c:\windows\system32\ntdll.dll wurde gefunden und desinfiziert
Kopie von - c:\windows\$hf_mig$\KB2393802\SP3QFE\ntdll.dll wurde wiederhergestellt
.
--------
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-09-18 bis 2012-10-18 ))))))))))))))))))))))))))))))
.
.
2012-10-14 18:33 . 2012-10-14 18:33 -------- d-----w- c:\dokumente und einstellungen\All Users\Favoriten
2012-10-07 12:07 . 2012-10-07 12:07 -------- d-----w- c:\dokumente und einstellungen\Reiner\Anwendungsdaten\AVG2013
2012-10-07 11:59 . 2012-10-07 11:59 -------- d-----w- c:\windows\system32\config\systemprofile\Anwendungsdaten\AVG2013
2012-10-07 11:59 . 2012-10-07 11:59 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\AVG Secure Search
2012-10-07 11:59 . 2012-10-07 11:59 -------- d-----w- c:\dokumente und einstellungen\Reiner\Anwendungsdaten\AVG Secure Search
2012-10-07 11:59 . 2012-10-07 11:59 27496 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2012-10-07 11:59 . 2012-10-07 11:59 -------- d-----w- c:\programme\Gemeinsame Dateien\AVG Secure Search
2012-10-07 11:59 . 2012-10-07 11:59 -------- d-----w- c:\programme\AVG Secure Search
2012-10-07 11:56 . 2012-10-07 11:59 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\AVG2013
2012-10-07 11:51 . 2012-10-07 11:51 -------- d-----w- c:\dokumente und einstellungen\Reiner\Lokale Einstellungen\Anwendungsdaten\MFAData
2012-10-07 11:51 . 2012-10-07 11:51 -------- d-----w- c:\dokumente und einstellungen\Reiner\Lokale Einstellungen\Anwendungsdaten\Avg2013
2012-10-07 11:29 . 2012-10-07 11:29 -------- d-----w- C:\_OTL
2012-10-07 11:26 . 2012-10-07 11:26 -------- d-----w- c:\dokumente und einstellungen\LocalService\Anwendungsdaten\TuneUp Software
2012-10-03 12:24 . 2012-05-29 11:09 31584 ----a-w- c:\windows\system32\TURegOpt.exe
2012-10-03 12:24 . 2012-10-03 12:24 -------- d-----w- c:\dokumente und einstellungen\Reiner\Anwendungsdaten\TuneUp Software
2012-10-03 12:24 . 2012-10-03 12:24 -------- d-----w- c:\programme\TuneUp Utilities 2012
2012-10-03 12:24 . 2012-10-03 12:24 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\TuneUp Software
2012-10-03 12:24 . 2012-10-03 12:24 -------- d-sh--w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2012-10-01 19:42 . 2012-10-01 19:42 -------- d-----w- c:\programme\Gemeinsame Dateien\Java
2012-10-01 19:41 . 2012-10-01 19:41 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-10-01 19:41 . 2012-10-01 19:41 477168 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-10-01 19:41 . 2012-10-01 19:41 -------- d-----w- c:\programme\Java
2012-09-23 16:43 . 2012-09-23 16:43 -------- d-----w- c:\programme\ESET
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-05 01:26 . 2011-12-23 11:32 93536 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2012-10-02 01:30 . 2012-02-22 03:25 159712 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2012-10-01 19:41 . 2010-09-14 05:19 473072 ----a-w- c:\windows\system32\deployJava1.dll
2012-09-23 17:50 . 2012-04-07 09:55 696240 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-23 17:50 . 2011-05-20 07:54 73136 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-21 01:46 . 2012-03-19 03:17 164832 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2012-09-21 01:46 . 2012-08-09 11:56 177376 ----a-w- c:\windows\system32\drivers\avglogx.sys
2012-09-21 01:45 . 2011-12-23 11:32 19936 ----a-w- c:\windows\system32\drivers\avgidsshimx.sys
2012-09-21 01:45 . 2012-04-19 02:50 55008 ----a-w- c:\windows\system32\drivers\avgidshx.sys
2012-09-14 01:05 . 2012-01-31 02:46 35552 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2012-09-13 01:11 . 2011-12-23 11:32 177504 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2012-09-07 15:04 . 2012-09-16 14:27 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-27 19:03 . 2002-03-05 16:27 832512 ----a-w- c:\windows\system32\wininet.dll
2012-08-27 19:03 . 1979-12-31 22:00 1830912 ----a-w- c:\windows\system32\inetcpl.cpl
2012-08-27 19:03 . 2006-04-03 20:32 78336 ----a-w- c:\windows\system32\ieencode.dll
2012-08-27 19:03 . 1979-12-31 22:00 17408 ----a-w- c:\windows\system32\corpol.dll
2012-08-24 13:53 . 1979-12-31 22:00 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-08-23 06:26 . 2001-08-18 02:28 2030080 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-08-23 06:26 . 1979-12-31 22:00 2151424 ----a-w- c:\windows\system32\ntoskrnl.exe
2007-06-04 08:54 . 2007-06-04 08:54 5810216 ----a-w- c:\programme\Firefox Setup 2.0.0.4.exe
2007-05-11 17:18 . 2007-05-11 17:18 5804232 ----a-w- c:\programme\Firefox Setup 2.0.0.3.exe
2007-01-19 19:55 . 2007-01-19 19:55 14843696 ----a-w- c:\programme\IE7-WindowsXP-x86-deu.exe
2007-01-19 19:43 . 2007-01-19 19:43 27066664 ----a-w- c:\programme\PowerPointViewer.exe
2006-11-15 16:48 . 2006-11-15 16:48 6042312 ----a-w- c:\programme\FirefoxGoogleToolbarSetup.exe
2006-11-14 17:49 . 2006-11-14 17:49 155648 ----a-w- c:\programme\Symantec Security.exe
2005-12-05 16:00 . 2005-12-05 16:00 74448 ----a-w- c:\programme\DSETUP.dll
2005-12-05 16:00 . 2005-12-05 16:00 484560 ----a-w- c:\programme\DXSETUP.exe
2005-12-05 16:00 . 2005-12-05 16:00 2247888 ----a-w- c:\programme\dsetup32.dll
2003-07-01 17:32 . 2003-07-01 17:32 4073984 ----a-w- c:\programme\Antivir.exe
2003-01-31 13:24 . 2004-11-20 14:31 1171456 ----a-w- c:\programme\mmlang-ger.dll
2002-12-20 14:08 . 2004-11-20 14:31 3207168 ----a-w- c:\programme\MindMan.exe
2002-12-13 09:47 . 2004-11-20 14:31 290816 ----a-w- c:\programme\Hts32mm.dll
2002-12-13 09:47 . 2004-11-20 14:31 761856 ----a-w- c:\programme\Ter32mm.dll
2002-11-05 03:00 . 2002-11-05 03:00 1822520 ----a-w- c:\programme\INSTMSIW.EXE
2002-11-05 03:00 . 2002-11-05 03:00 18135040 ----a-w- c:\programme\QCL.MSI
2002-11-05 03:00 . 2002-11-05 03:00 1708856 ----a-w- c:\programme\INSTMSIA.EXE
2002-03-29 18:57 . 2004-11-20 14:31 1379900 ----a-w- c:\programme\MMConferenceProvider.dll
2002-03-22 07:07 . 2004-11-20 14:31 172032 ----a-w- c:\programme\Ssce5332.dll
2001-05-24 10:59 . 2004-11-20 14:31 162304 ----a-w- c:\programme\UNWISE.EXE
2001-05-02 07:41 . 2004-11-20 14:31 221184 ----a-w- c:\programme\Vic32.dll
2000-12-28 10:35 . 2004-11-20 14:31 157149 ----a-w- c:\programme\WiseUpdt.exe
2000-10-03 13:29 . 2004-11-20 14:31 96768 ----a-w- c:\programme\dunzip32.dll
2000-10-03 13:29 . 2004-11-20 14:31 262144 ----a-w- c:\programme\adfactry.dll
2000-10-03 13:29 . 2004-11-20 14:31 124416 ----a-w- c:\programme\dzip32.dll
2000-07-03 16:42 . 2004-11-20 14:31 53760 ----a-w- c:\programme\sfxfe32.exe
2000-02-05 18:08 . 2004-11-20 14:31 77312 ----a-w- c:\programme\sfxbe322.dll
2012-07-18 15:36 . 2011-05-09 14:42 136672 ----a-w- c:\programme\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-10-07 11:59 1734240 ----a-w- c:\programme\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\programme\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll" [2012-10-07 1734240]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AutoStartNPSAgent"="c:\programme\Samsung\Samsung New PC Studio\NPSAgent.exe" [2010-07-04 95576]
"SpeedBitVideoAccelerator"="c:\programme\SpeedBit Video Accelerator\VideoAccelerator.exe" [2012-03-19 1494216]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"ANIWZCS2Service"="c:\programme\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]
"RTHDCPL"="RTHDCPL.EXE" [2009-11-17 18789408]
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"TkBellExe"="c:\programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" [2010-10-16 202256]
"Microsoft Works Update Detection"="c:\programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-17 50688]
"APSDaemon"="c:\programme\Gemeinsame Dateien\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"PMBVolumeWatcher"="c:\programme\Sony\PMB\PMBVolumeWatcher.exe" [2010-03-24 599328]
"HP Software Update"="c:\programme\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"Adobe Photo Downloader"="c:\programme\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-10 67488]
"SunJavaUpdateSched"="c:\programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" [2012-01-18 254696]
"AVG_UI"="c:\programme\AVG\AVG2013\avgui.exe" [2012-10-10 3116152]
"vProt"="c:\programme\AVG Secure Search\vprot.exe" [2012-10-07 947808]
"ROC_ROC_NT"="c:\programme\AVG Secure Search\ROC_ROC_NT.exe" [2012-10-07 856160]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\
MindManager PDF Writer.lnk - c:\programme\Mindjet\MindManager 5\sys\PDF\ENU\W2K\PDFSaver.exe [2003-2-21 61440]
WISO Mein Steuer-Sparbuch heute.lnk - c:\programme\WISO\Steuersoftware 2012\mshaktuell.exe [2012-3-13 1370224]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2013\avgrsx.exe /sync /restart
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"PhilipsSongbirdLauncher"=c:\programme\Philips\Philips Songbird\extensions\philips-autoplay@philips.com\application\PhilipsSongbirdLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"UVS10 Preload"=c:\programme\Ulead Systems\Ulead VideoStudio SE DVD\uvPL.exe
"iTunesHelper"="c:\programme\iTunes\iTunesHelper.exe"
"vProt"="c:\programme\AVG Secure Search\vprot.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\System32\\dpnsvr.exe"=
"c:\\Programme\\Samsung\\Samsung New PC Studio\\npsasvr.exe"=
"c:\\Programme\\Samsung\\Samsung New PC Studio\\npsvsvr.exe"=
"c:\\Dokumente und Einstellungen\\Christine\\Anwendungsdaten\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Programme\\Gemeinsame Dateien\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Programme\\Bonjour\\mDNSResponder.exe"=
"c:\\Programme\\iTunes\\iTunes.exe"=
"c:\\Programme\\iMesh Applications\\iMesh\\iMesh.exe"=
"c:\\Programme\\iMesh Applications\\MediaBar\\Datamngr\\ToolBar\\dtUser.exe"=
"c:\\Programme\\AVG\\AVG2013\\avgmfapx.exe"=
"c:\\Programme\\AVG\\AVG2013\\avgnsx.exe"=
"c:\\Programme\\AVG\\AVG2013\\avgdiagex.exe"=
"c:\\Programme\\AVG\\AVG2013\\avgemcx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [19.04.2012 04:50 55008]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [09.08.2012 13:56 177376]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [31.01.2012 04:46 35552]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [19.03.2012 05:17 164832]
R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [07.10.2012 13:59 27496]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [23.12.2011 13:32 177504]
S1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [23.12.2011 13:32 19936]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [22.02.2012 05:25 159712]
S2 Automatisches LiveUpdate - Scheduler;Automatisches LiveUpdate - Scheduler;"c:\programme\Symantec\LiveUpdate\ALUSchedulerSvc.exe" --> c:\programme\Symantec\LiveUpdate\ALUSchedulerSvc.exe [?]
S2 AVGIDSAgent;AVGIDSAgent;c:\programme\AVG\AVG2013\avgidsagent.exe [02.10.2012 03:32 5783672]
S2 avgwd;AVG WatchDog;c:\programme\AVG\AVG2013\avgwdsvc.exe [02.10.2012 03:32 193568]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [23.04.2010 07:30 238952]
S2 gupdate;Google Update Service (gupdate);c:\programme\Google\Update\GoogleUpdate.exe [12.11.2010 19:19 136176]
S2 KMWDSERVICE;Keyboard And Mouse Communication Service;c:\programme\Multimedia Mouse Driver\KMWDSrv.exe [10.10.2008 20:16 204800]
S2 MBAMScheduler;MBAMScheduler;c:\programme\Malwarebytes' Anti-Malware\mbamscheduler.exe [16.09.2012 16:27 399432]
S2 MBAMService;MBAMService;c:\programme\Malwarebytes' Anti-Malware\mbamservice.exe [16.09.2012 16:27 676936]
S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\programme\Sony\PMB\PMBDeviceInfoProvider.exe [24.10.2009 03:18 360224]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\programme\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [29.05.2012 13:09 1528672]
S2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm --> c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm [?]
S2 vToolbarUpdater12.2.6;vToolbarUpdater12.2.6;c:\programme\Gemeinsame Dateien\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe [07.10.2012 13:59 722528]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [07.04.2012 11:55 250288]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [04.12.2009 20:22 1684736]
S3 FlashUSB;FlashUSB;c:\windows\system32\drivers\FlashUSB.sys [15.02.2011 15:49 16896]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [23.04.2010 07:30 36608]
S3 gupdatem;Google Update-Dienst (gupdatem);c:\programme\Google\Update\GoogleUpdate.exe [12.11.2010 19:19 136176]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [16.09.2012 16:27 22856]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\programme\Mozilla Maintenance Service\maintenanceservice.exe [10.05.2012 12:02 113120]
S3 s1029bus;Sony Ericsson Device 1029 driver (WDM);c:\windows\system32\drivers\s1029bus.sys [18.07.2010 14:11 90280]
S3 s1029mdfl;Sony Ericsson Device 1029 USB WMC Modem Filter;c:\windows\system32\drivers\s1029mdfl.sys [18.07.2010 14:11 15016]
S3 s1029mdm;Sony Ericsson Device 1029 USB WMC Modem Driver;c:\windows\system32\drivers\s1029mdm.sys [18.07.2010 14:11 122280]
S3 s1029mgmt;Sony Ericsson Device 1029 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1029mgmt.sys [18.07.2010 14:11 115880]
S3 s1029nd5;Sony Ericsson Device 1029 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1029nd5.sys [18.07.2010 14:10 26024]
S3 s1029obex;Sony Ericsson Device 1029 USB WMC OBEX Interface;c:\windows\system32\drivers\s1029obex.sys [18.07.2010 14:11 111912]
S3 s1029unic;Sony Ericsson Device 1029 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1029unic.sys [18.07.2010 14:11 116904]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [06.04.2011 11:00 98432]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [06.04.2011 11:00 14848]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [06.04.2011 11:00 123648]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\programme\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys [08.05.2012 15:21 10064]
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - PARPORT
.
Inhalt des "geplante Tasks" Ordners
.
2012-10-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-07 17:50]
.
2012-10-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programme\Google\Update\GoogleUpdate.exe [2010-11-12 17:19]
.
2012-10-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programme\Google\Update\GoogleUpdate.exe [2010-11-12 17:19]
.
2012-10-16 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-874574627-2650805779-3784137826-1006.job
- c:\programme\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
.
2012-10-16 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-874574627-2650805779-3784137826-1007.job
- c:\programme\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
.
2012-10-16 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-874574627-2650805779-3784137826-1017.job
- c:\programme\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
.
2012-10-16 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-874574627-2650805779-3784137826-1018.job
- c:\programme\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
.
2012-10-16 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-874574627-2650805779-3784137826-1019.job
- c:\programme\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
.
2012-09-16 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-874574627-2650805779-3784137826-1006.job
- c:\programme\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
.
2012-10-05 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-874574627-2650805779-3784137826-1007.job
- c:\programme\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
.
2012-08-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-874574627-2650805779-3784137826-1017.job
- c:\programme\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
.
2012-10-03 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-874574627-2650805779-3784137826-1018.job
- c:\programme\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
.
2012-08-10 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-874574627-2650805779-3784137826-1019.job
- c:\programme\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
.
2012-10-13 c:\windows\Tasks\ReclaimerUpdateFiles_Reiner.job
- c:\dokumente und einstellungen\Reiner\Anwendungsdaten\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe [2012-10-13 14:08]
.
2012-10-13 c:\windows\Tasks\ReclaimerUpdateXML_Reiner.job
- c:\dokumente und einstellungen\Reiner\Anwendungsdaten\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe [2012-10-13 14:08]
.
.
------- Zusätzlicher Suchlauf -------
.
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://go.1und1.de/suchbox/1und1suche?su=%s
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
LSP: c:\programme\SpeedBit Video Accelerator\SBLSP.dll
Trusted Zone: chip.de\www
TCP: DhcpNameServer = 192.168.178.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\programme\Gemeinsame Dateien\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {2F0D96B4-7D9D-4767-A657-F7ECC9114887} - hxxp://haustein.dyndns.org/IPCamPluginDMPT.cab
FF - ProfilePath - c:\dokumente und einstellungen\Reiner\Anwendungsdaten\Mozilla\Firefox\Profiles\q091o1qh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - ExtSQL: 2012-10-01 21:41; {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}; c:\programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
FF - ExtSQL: !HIDDEN! 2006-11-15 18:50; {3112ca9c-de6d-4884-a869-9855de68056c}; c:\programme\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - ExtSQL: !HIDDEN! 2009-08-09 12:16; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - user.js: yahoo.homepage.dontask - true
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file)
AddRemove-DiskAid_is1 - k:\diskaid\DiskAid\unins000.exe
AddRemove-HyperCam 2 - k:\\UnHyCam2.exe
AddRemove-Microsoft Interactive Training - c:\windows\IsUn0407.exe
AddRemove-RealVNC_is1 - k:\vnc4\VNC4\unins000.exe
AddRemove-TuneAid_is1 - k:\diskaid\TuneAid\unins000.exe
AddRemove-01_Simmental - c:\programme\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\programme\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\programme\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\programme\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - c:\programme\Samsung\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - c:\programme\Samsung\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - c:\programme\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - c:\programme\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - c:\programme\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\programme\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\programme\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - c:\programme\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - c:\programme\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - c:\programme\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - c:\programme\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-21_Searsburg - c:\programme\Samsung\USB Drivers\21_Searsburg\Uninstall.exe
AddRemove-22_WiBro_WiMAX - c:\programme\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-10-18 20:03
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
.
c:\dokume~1\Reiner\LOKALE~1\Temp\catchme.dll 53248 bytes executable
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 1
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\A]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\J]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\L]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{09288922-9577-11dd-9019-806d6172696f}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{09288923-9577-11dd-9019-a2868279f30b}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{09288924-9577-11dd-9019-a2868279f30b}]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{09288925-9577-11dd-9019-a2868279f30b}]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{09288926-9577-11dd-9019-a2868279f30b}]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1552b324-cf01-11df-938d-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{16ecaa8c-fed1-11e0-9469-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
"_LabelFromReg"="Jaci"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{26fb3c7a-5e3c-11d6-b74c-00038a000015}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
df,df,df,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,cf,5f,5f,5f,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{26fb3c7b-5e3c-11d6-b74c-00038a000015}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
df,df,df,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,cf,5f,5f,5f,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{392d8fae-e108-11de-9204-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3d88846c-fff7-11e1-94d6-e5a0a0689281}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3d88846d-fff7-11e1-94d6-e5a0a0689281}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3d88846f-fff7-11e1-94d6-e5a0a0689281}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3d888471-fff7-11e1-94d6-e5a0a0689281}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3d888472-fff7-11e1-94d6-e5a0a0689281}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3d8e9f6a-4ee0-11d6-bf03-806d6172696f}]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3d8e9f6b-4ee0-11d6-bf03-806d6172696f}]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,01,00,01,01,ee,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3d8e9f6c-4ee0-11d6-bf03-806d6172696f}]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3d8e9f6d-4ee0-11d6-bf03-806d6172696f}]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3d8e9f6e-4ee0-11d6-bf03-806d6172696f}]
@DACL=(02 0000)
@SACL=
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{440d5b14-f805-11db-a3b8-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{446576b2-462a-11d9-9fff-00e0187490ee}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
df,df,df,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,00,5f,5f,5f,5f,01,00,ee,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{44c7d94e-70e6-11e1-9485-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{703a4204-3efb-11dd-9e4a-806d6172696f}]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{703a4205-3efb-11dd-9e4a-806d6172696f}]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77c009d4-1bcb-11e0-93e2-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{82072a72-9641-11dd-901f-001fd05bd8e5}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{87b4dc8a-d418-11e1-94ca-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8cf189e4-5437-11d6-b744-00038a000015}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
df,df,df,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,cf,5f,5f,5f,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8cf189e5-5437-11d6-b744-00038a000015}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
df,df,df,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,cf,5f,5f,5f,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8dbb4b38-4981-11df-92b3-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{950b3a1e-5228-11d6-b73f-806d6172696f}]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9c737ee4-bb9f-11dc-a462-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9d18cacc-df9b-11e0-9464-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9eea4acc-3f00-11dd-9090-806d6172696f}]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9eea4acd-3f00-11dd-9090-806d6172696f}]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ad4a14b4-82e9-11d6-9c49-806d6172696f}]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ad4a14b5-82e9-11d6-9c49-806d6172696f}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_LabelFromReg"="Daten"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ad4a14b7-82e9-11d6-9c49-806d6172696f}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ad4a14b8-82e9-11d6-9c49-806d6172696f}]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ad4a14b9-82e9-11d6-9c49-806d6172696f}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ad4a14ba-82e9-11d6-9c49-806d6172696f}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b3ecae87-2b91-11e0-93f0-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{babee2ba-3ef9-11dd-a49f-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bd5cc036-9526-11e1-949b-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c6285194-8ab0-11df-9335-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c97ef248-cb41-11dc-a472-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ca90b564-2485-11da-a0e7-00e0187490ee}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
"_LabelFromReg"="07159800761"
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{df54cad1-d61b-11e1-94cb-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ee50f0e1-159d-11e1-946e-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{eed6243d-7254-11e1-948a-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fd261d45-ba9b-11e1-94c3-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-874574627-2650805779-3784137826-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ffb1b92c-9290-11df-9340-00179ab813b6}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
"_CommentFromDesktopINI"="Enthält Filme und andere Videodateien."
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•6~*]
"7040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(716)
c:\windows\system32\Ati2evxx.dll
.
Zeit der Fertigstellung: 2012-10-18 20:04:55
ComboFix-quarantined-files.txt 2012-10-18 18:04
.
Vor Suchlauf: 21 Verzeichnis(se), 63.670.489.088 Bytes frei
Nach Suchlauf: 25 Verzeichnis(se), 64.016.617.472 Bytes frei
.
- - End Of File - - C9D7224A06F830A36124BA7639EA42F1 |