Cypher00 | 17.05.2013 13:56 | Hier der Log von Combofix: Code:
ComboFix 13-05-16.02 - Sabine 17.05.2013 14:26:39.1.2 - x86
Running from: c:\users\Sabine\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\DealPly
c:\program files\DealPly\DealPly.crx
c:\program files\DealPly\DealPlyTune.dll
c:\program files\DealPly\DealPlyUpdate.exe
c:\program files\DealPly\DealPlyUpdate.log
c:\program files\DealPly\DealPlyUpdateRun.exe
c:\program files\DealPly\icon.ico
c:\program files\DealPly\uninst.exe
c:\program files\Incredibar.com
c:\program files\Incredibar.com\incredibar\1.5.11.14\bh\inCRedibar.dll
c:\program files\Incredibar.com\incredibar\1.5.11.14\incredibarApp.dll
c:\program files\Incredibar.com\incredibar\1.5.11.14\incredibarEng.dll
c:\program files\Incredibar.com\incredibar\1.5.11.14\incredibarsrv.exe
c:\program files\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll
c:\program files\Incredibar.com\incredibar\1.5.11.14\uninstall.exe
c:\program files\smartdl
c:\program files\smartdl\cc
c:\program files\smartdl\gunzip.exe
c:\program files\smartdl\installid
c:\program files\smartdl\status-o
c:\program files\smartdl\status
c:\program files\smartdl\TorrentSearch.exe
c:\program files\TSearch
c:\program files\TSearch\client.py
c:\program files\TSearch\easydownload.exe
c:\program files\TSearch\header.bmp
c:\program files\TSearch\libtorrent.pyd
c:\program files\TSearch\python25.dll
c:\program files\TSearch\results
c:\programdata\dsgsdgdsgdsgw.pad
c:\users\Sabine\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
c:\users\Sabine\AppData\Roaming\ie_util.exe
c:\users\Sabine\AppData\Roaming\Uriwik
c:\users\Sabine\AppData\Roaming\Uriwik\anup.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_STEC3
-------\Service_STEC3
.
.
((((((((((((((((((((((((( Files Created from 2013-04-17 to 2013-05-17 )))))))))))))))))))))))))))))))
.
.
2013-05-17 12:38 . 2013-05-17 12:42 -------- d-----w- c:\users\Sabine\AppData\Local\temp
2013-05-17 12:38 . 2013-05-17 12:38 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-05-17 12:38 . 2013-05-17 12:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-05-16 19:09 . 2013-05-16 19:09 -------- d-----w- C:\TDSSKiller Log
2013-05-16 18:48 . 2013-05-13 06:19 7016152 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{16E03CF5-5251-4223-AB02-D7C3EA81F93E}\mpengine.dll
2013-05-16 15:18 . 2013-05-05 19:12 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2013-05-16 00:12 . 2013-04-15 14:20 638328 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-05-16 00:12 . 2013-04-13 10:56 37376 ----a-w- c:\windows\system32\cdd.dll
2013-05-16 00:12 . 2013-04-09 01:36 2049024 ----a-w- c:\windows\system32\win32k.sys
2013-05-16 00:07 . 2013-05-16 21:34 -------- d-----w- c:\users\Sabine\AppData\Roaming\Tayv
2013-05-16 00:07 . 2013-05-16 00:07 -------- d-----w- c:\users\Sabine\AppData\Roaming\Wuqao
2013-05-15 23:04 . 2013-05-15 23:34 -------- d-----w- C:\_OTL
2013-05-15 12:11 . 2013-05-15 12:11 -------- d-----w- c:\users\FH
2013-05-12 12:11 . 2013-05-12 12:11 -------- d-----w- c:\users\Sabine\AppData\Local\Program Files
2013-05-05 21:32 . 2013-05-05 21:32 -------- d-----w- c:\users\Sabine\AppData\Local\Game Dev Tycoon
2013-05-05 16:54 . 2013-05-05 16:56 -------- d-----w- c:\users\Sabine\AppData\Roaming\mysearchdial
2013-05-05 16:54 . 2013-05-05 16:56 -------- d-----w- c:\program files\Mysearchdial
2013-05-04 16:13 . 2013-05-04 16:13 -------- d-----w- c:\users\Public\Games
2013-05-03 09:51 . 2013-05-03 17:05 -------- d-----w- c:\program files\Common Files\PTC
2013-05-03 09:45 . 2013-05-03 09:48 -------- d-----w- c:\users\Sabine\AppData\Local\PTC
2013-05-03 07:37 . 2013-05-03 17:07 -------- d-----w- c:\program files\PTC
2013-05-03 07:22 . 2013-05-03 07:38 -------- d-----w- c:\programdata\PTC
2013-05-03 07:15 . 2013-05-03 07:15 -------- d-----w- c:\progra~2\02517~1
2013-05-02 12:25 . 2013-05-02 12:25 -------- d-----w- c:\progra~2\04113~1
2013-05-01 19:01 . 2013-05-01 19:01 -------- d-----w- c:\program files\mixiedj
2013-05-01 19:01 . 2013-05-01 19:01 -------- d-----w- c:\program files\mixidj
2013-05-01 18:35 . 2013-05-01 19:01 -------- d-----w- c:\users\Sabine\AppData\Roaming\Download Manager
2013-04-30 06:40 . 2013-04-30 06:40 -------- d-----w- c:\progra~2\0A41F~1
2013-04-28 10:25 . 2013-04-28 10:25 -------- d-----w- c:\program files\DomaIQ Uninstaller
2013-04-28 10:24 . 2013-04-28 10:24 -------- d-----w- c:\users\Sabine\AppData\Roaming\player
2013-04-28 10:24 . 2013-04-28 10:24 -------- d-----w- c:\program files\Tuguu SL
2013-04-28 10:23 . 2013-04-28 10:23 -------- d-----w- c:\users\Sabine\AppData\Roaming\Driver Pro
2013-04-28 10:23 . 2013-04-28 10:23 -------- d-----w- c:\program files\Driver Pro
2013-04-28 09:33 . 2013-04-28 09:33 -------- d-----w-0 c:\progra~2\WW0~1
2013-04-27 09:49 . 2013-04-27 09:49 -------- d-----w- c:\progra~2\0321F~1
2013-04-25 10:04 . 2013-04-25 10:04 -------- d-----w- c:\progra~2\0241B~1
2013-04-24 14:30 . 2013-04-24 14:30 -------- d-----w- c:\progra~2\08517~1
2013-04-22 15:24 . 2013-04-22 15:24 -------- d-----w- c:\progra~2\0DF0B~1
2013-04-22 06:05 . 2013-04-22 06:05 -------- d-----w- c:\progra~2\0811B~1
2013-04-21 07:57 . 2013-04-21 07:57 -------- d-----w- c:\progra~2\0601B~1
2013-04-20 16:38 . 2013-04-20 16:38 -------- d-----w- c:\progra~2\UU0~2
2013-04-19 11:09 . 2013-04-19 11:09 -------- d-----w- c:\program files\Common Files\Skype
2013-04-18 15:04 . 2013-04-18 15:04 -------- d-----w-0 c:\progra~2\220B~1.0
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-16 19:10 . 2013-05-16 19:10 23832 ----a-w- C:\TDSSKiller Log.zip
2013-05-15 23:35 . 2012-08-11 14:39 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-15 23:35 . 2012-08-11 14:39 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-05-02 00:06 . 2012-08-10 14:45 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-03-15 15:21 . 2013-03-15 15:21 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-03-15 15:21 . 2012-08-12 21:06 861088 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-03-15 15:21 . 2012-08-12 21:06 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-03-11 13:25 . 2013-04-10 14:52 3603816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-11 13:25 . 2013-04-10 14:52 3551080 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-03-09 03:45 . 2013-04-10 14:52 49152 ----a-w- c:\windows\system32\csrsrv.dll
2013-03-09 01:28 . 2013-04-10 14:52 64000 ----a-w- c:\windows\system32\smss.exe
2013-03-08 03:53 . 2013-04-10 14:52 376320 ----a-w- c:\windows\system32\winsrv.dll
2013-03-08 03:52 . 2013-04-10 14:52 2067968 ----a-w- c:\windows\system32\mstscax.dll
2013-03-03 19:07 . 2013-04-10 14:52 1082232 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-02-25 22:22 . 2013-02-25 22:22 1985824 ----a-w- c:\windows\system32\nvcuvenc.dll
2013-02-25 22:22 . 2012-02-09 20:43 1017120 ----a-w- c:\windows\system32\nvdispco32.dll
2013-02-25 22:22 . 2013-02-25 22:22 6262608 ----a-w- c:\windows\system32\nvopencl.dll
2013-02-25 22:22 . 2012-08-25 09:37 892704 ----a-w- c:\windows\system32\nvdispgenco32.dll
2013-02-25 22:22 . 2012-08-13 13:34 12641992 ----a-w- c:\windows\system32\nvwgf2um.dll
2013-02-25 22:22 . 2012-08-13 13:34 2505144 ----a-w- c:\windows\system32\nvapi.dll
2013-02-25 22:22 . 2012-02-09 20:43 15129960 ----a-w- c:\windows\system32\nvd3dum.dll
2013-02-25 22:22 . 2013-02-25 22:22 7932256 ----a-w- c:\windows\system32\nvcuda.dll
2013-02-25 22:22 . 2013-02-25 22:22 17560352 ----a-w- c:\windows\system32\nvcompiler.dll
2013-02-25 22:22 . 2013-02-25 22:22 20449056 ----a-w- c:\windows\system32\nvoglv32.dll
2013-02-25 22:22 . 2013-02-25 22:22 8939296 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2013-02-25 22:22 . 2013-02-25 22:22 2720544 ----a-w- c:\windows\system32\nvcuvid.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2013-02-08 1520776]
"{cd90bf73-20f6-44ef-993d-bb920303bd2e}"= "c:\program files\Veoh_Web_Player\prxtbVeoh.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_CLASSES_ROOT\clsid\{cd90bf73-20f6-44ef-993d-bb920303bd2e}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{cd90bf73-20f6-44ef-993d-bb920303bd2e}]
2011-05-09 09:49 176936 ----a-w- c:\program files\Veoh_Web_Player\prxtbVeoh.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{cd90bf73-20f6-44ef-993d-bb920303bd2e}"= "c:\program files\Veoh_Web_Player\prxtbVeoh.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{cd90bf73-20f6-44ef-993d-bb920303bd2e}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CD90BF73-20F6-44EF-993D-BB920303BD2E}"= "c:\program files\Veoh_Web_Player\prxtbVeoh.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{cd90bf73-20f6-44ef-993d-bb920303bd2e}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2013-05-03 1635752]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"SpeedUpMyPC"="c:\program files\Uniblue\SpeedUpMyPC\launcher.exe" [2012-04-16 67960]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2012-06-11 4692840]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-02-28 18642024]
"Driver Pro"="c:\program files\Driver Pro\DPLauncher.exe" [2012-10-30 340512]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-07-18 348664]
"EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2008-12-04 665424]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2012-05-29 115032]
"NWTRAY"="NWTRAY.EXE" [2011-11-27 34904]
"iPrint Tray"="c:\windows\system32\iprntctl.exe" [2012-04-25 68184]
"iPrint Event Monitor"="c:\windows\system32\iprntlgn.exe" [2012-04-25 72280]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2013-02-08 1644680]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-12-19 41208]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-12-10 2254768]
"Cisco AnyConnect Secure Mobility Agent for Windows"="c:\program files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" [2012-09-26 522232]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"NuTCSetupEnviron"="c:\progra~1\PTC\MKSTOO~1\bin\ncoeenv.exe" [2009-11-23 37160]
.
c:\users\Sabine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
msconfig.lnk - c:\windows\System32\rundll32.exe [2006-11-2 44544]
OpenOffice.org 3.4.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2012-8-13 1199104]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
LOLRecorder.lnk - c:\program files\LOLReplay\LOLRecorder.exe [2013-2-14 523264]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli iPrntWinCredMan
Authentication Packages REG_MULTI_SZ msv1_0 ncv1_0
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
.
R3 acsint;acsint;c:\windows\system32\DRIVERS\acsint.sys [x]
R3 acsmux;acsmux;c:\windows\system32\DRIVERS\acsmux.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - nciom
*Deregistered* - ncp
*Deregistered* - ncpl
*Deregistered* - ndm
*Deregistered* - ndmndap
*Deregistered* - niam
*Deregistered* - nipctl
*Deregistered* - nscm
*Deregistered* - nsns
*Deregistered* - nsvccost
*Deregistered* - xtxplat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-10 21:29 1642448 ----a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-05-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-11 23:35]
.
2013-05-17 c:\windows\Tasks\FinalTorrent Update Checker.job
- c:\program files\FinalTorrent\FTCheckForUpdates.exe [2012-08-11 12:24]
.
2013-05-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-11-07 13:12]
.
2013-05-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-11-07 13:12]
.
2013-05-17 c:\windows\Tasks\OptimizerProUpdaterTask{2CE03A48-B8B3-4E05-A2FF-7C30D795730E}.job
- c:\programdata\Premium\OptimizerPro\OptimizerPro.exe [2012-12-24 14:50]
.
2013-05-17 c:\windows\Tasks\SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC\spmonitor.exe [2012-09-04 12:27]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.mysearchdial.com/?f=1&a=tugumsd&cd=2XzuyEtN2Y1L1Qzu0B0CyD0F0FyEtD0D0A0FyD0E0AtDzzyDtN0D0Tzu0CyEzytCtN1L2XzutBtFtBtFtCtFyCtCzztN1L1Czu2Z2Y1N2Y1H1B1Q&cr=1207875316&ir=
mStart Page = hxxp://start.mysearchdial.com/?f=1&a=tugumsd&cd=2XzuyEtN2Y1L1Qzu0B0CyD0F0FyEtD0D0A0FyD0E0AtDzzyDtN0D0Tzu0CyEzytCtN1L2XzutBtFtBtFtCtFyCtCzztN1L1Czu2Z2Y1N2Y1H1B1Q&cr=1207875316&ir=
uSearchAssistant = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=33360bb7-7237-4abc-a443-f4f7cfe757f5&affid=111585&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE: Translate this web page with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
IE: Translate with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
LSP: %SystemRoot%\system32\nutafun4.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.178.1
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Optimizer Pro - c:\program files\Optimizer Pro\OptProLauncher.exe
HKCU-Run-GameCenter - c:\program files\Joyvy\GameCenter.exe
HKCU-Run-Oqsaixvivy - c:\users\Sabine\AppData\Roaming\Epmo\tiyv.exe
HKCU-Run-IExplorer Util - c:\users\Sabine\AppData\Roaming\ie_util.exe
HKCU-Run-AmazonMP3DownloaderHelper - c:\users\Sabine\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
HKCU-Run-Kaseums - c:\users\Sabine\AppData\Roaming\Uriwik\anup.exe
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-incredibar - c:\program files\Incredibar.com\incredibar\1.5.11.14\uninstall.exe
AddRemove-Katawa Shoujo - c:\program files\Katawa Shoujo\Uninstall Katawa Shoujo.exe
AddRemove-Optimizer Pro_is1 - c:\program files\Optimizer Pro\unins000.exe
AddRemove-Amazon MP3-Downloader - c:\users\Sabine\AppData\Local\Program Files\Amazon\MP3 Downloader\Uninstall.exe
AddRemove-GoforFiles - c:\program files\GoforFiles\uninstall.exe
AddRemove-YourFileDownloader - c:\program files\YourFileDownloader\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2013-05-17 14:42
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PortmapperService]
"ImagePath"="c:\program files\PTC/PTC Portmapper/i486_nt/obj/portmap.exe"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-338440498-2888063792-2753391560-1000\Software\relic UGP Applications\age\゙0ヨ0・・1*1*\Installation]
"strAbsolutePath"="c:\\age\\マブラヴ11\\"
"strObjectOcean"="c:\\age\\マブラヴ11\\マブラヴ11.rio"
"strIciPath"="c:\\age\\マブラヴ11\\マブラヴ11.rio.ici\00cations"
"strTTFileName"="マブラヴ11.rbt"
"strInstallSourcePath"="i:\\"
"bInstalled"=dword:00000001
"strInstallTypeSelect"="1"
"strInstallSystemType"=""
.
[HKEY_USERS\S-1-5-21-338440498-2888063792-2753391560-1000\Software\relic UGP Applications\age\゙0ヨ0・・1*1*\InstallFont]
"MS Pゴシック%#16%$-B"="マブラヴ11.rio\\MS Pゴシック16B.5RF"
"MS Pゴシック%#24%$-B%$-A"="マブラヴ11.rio\\MS Pゴシック24BA.5RF"
.
[HKEY_USERS\S-1-5-21-338440498-2888063792-2753391560-1000\Software\relic UGP Applications\age\゙0ヨ0・・1*1*\PeculiarToTheApp]
"strTheAppName"="マブラヴ1.1\0011\00E"
.
[HKEY_USERS\S-1-5-21-338440498-2888063792-2753391560-1000\Software\relic UGP Applications\age\゙0ヨ0・・1*1*\rUGPBasic]
"strRugpPluginFolder"="c:\\age\\マブラヴ11\\Plugins"
"bIsIllegalTerminateCheck"=dword:00000000
"nRugpVersion"=dword:0000157c
.
[HKEY_USERS\S-1-5-21-338440498-2888063792-2753391560-1000\Software\relic UGP Applications\age\゙0ヨ0・・1*1*\rvmmBoxSettings]
"nWndFrameLevel"=dword:00000003
"nWndBaseRatioSrc"=dword:000000c0
"nWndBaseRatioDst"=dword:00000006
"nWndBaseColor1"=dword:002020a0
"nWndBaseColor2"=dword:00c0c0ff
"nWndBaseGradation"=dword:00000001
"nFontBlank"=dword:00000002
"nMainFontColor"=dword:ffffffff
"nSelectedFontColor"=dword:ff8090c0
.
[HKEY_USERS\S-1-5-21-338440498-2888063792-2753391560-1000\Software\relic UGP Applications\age\゙0ヨ0・・1*1*\rvmmInstallation]
"strFontCachePath"="c:\\age\\マブラヴ11\\"
"strVirtuaRegistryAbsolutePath"="c:\\age\\マブラヴ11\\Vmreg\\"
.
[HKEY_USERS\S-1-5-21-338440498-2888063792-2753391560-1000\Software\relic UGP Applications\age\゙0ヨ0・・1*1*\rvmmPeculiarToTheApp]
"bCanSettingWindow"=dword:00000001
"bCanSettingFont"=dword:00000001
"bPageOverNext"=dword:00000000
"bUucAccessMasterKey"=dword:00000001
"strLowSpecFont"="MS Pゴシック%#16%$-B"
"strStandardFont"="MS Pゴシック%#24%$-B%$-A"
"bCanSettingSound"=dword:00000001
"bFullScreenMenuOff"=dword:00000000
"bWindowMenuAccessMasterKey"=dword:00000001
.
[HKEY_USERS\S-1-5-21-338440498-2888063792-2753391560-1000\Software\relic UGP Applications\age\゙0ヨ0・・1*1*\rvmmUISettings]
"bFullScreen"=dword:00000001
"dwMainFontStyle"=dword:0000000c
"nTextSpeed"=dword:00000030
"strCurrentMonitorDevice"="\\\\.\\DISPLAY1"
"dwCurrentMonitorFlag"=dword:00000001
"nWindowSize"=dword:00000003
"nFaceWindowSize"=dword:00000003
"isBgm"=dword:00000001
"isEffect"=dword:00000001
"nVoiceLevel"=dword:00000001
"nLayeredEffect"=dword:00000001
"nSeenMsgSkip"=dword:00000000
"nAutoMsgSkip"=dword:00000000
"bMouseTrace"=dword:00000001
.
[HKEY_USERS\S-1-5-21-338440498-2888063792-2753391560-1000\Software\SecuROM\License information*]
"datasecu"=hex:39,89,31,a3,ec,25,e6,40,ab,92,39,0a,71,a7,40,0c,56,b7,cb,75,68,
69,00,d0,4c,2f,19,ad,e6,4b,50,d7,7b,28,2b,69,c2,9c,5c,bf,d1,b9,cb,9b,d7,40,\
"rkeysecu"=hex:cf,fd,36,ed,8f,83,8f,67,d5,d5,68,a4,04,da,e7,c7
.
[HKEY_USERS\S-1-5-21-338440498-2888063792-2753391560-1001\Software\relic UGP Applications\age\゙0ヨ0・・1*1*\Installation]
"strAbsolutePath"="c:\\age\\マブラヴ11\\"
"strObjectOcean"="c:\\age\\マブラヴ11\\マブラヴ11.rio"
"strIciPath"="c:\\age\\マブラヴ11\\マブラヴ11.rio.ici"
"strTTFileName"="マブラヴ11.rbt"
"strInstallSourcePath"="i:\\"
"bInstalled"=dword:00000001
"strInstallTypeSelect"="1"
"strInstallSystemType"=""
.
[HKEY_USERS\S-1-5-21-338440498-2888063792-2753391560-1001\Software\relic UGP Applications\age\゙0ヨ0・・1*1*\InstallFont]
"MS Pゴシック%#24%$-B%$-A"="マブラヴ11.rio\\MS Pゴシック24BA.5RF"
"MS Pゴシック%#16%$-B"="マブラヴ11.rio\\MS Pゴシック16B.5RF"
.
[HKEY_USERS\S-1-5-21-338440498-2888063792-2753391560-1001\Software\relic UGP Applications\age\゙0ヨ0・・1*1*\PeculiarToTheApp]
"strTheAppName"="マブラヴ1.1"
.
[HKEY_USERS\S-1-5-21-338440498-2888063792-2753391560-1001\Software\relic UGP Applications\age\゙0ヨ0・・1*1*\rUGPBasic]
"strRugpPluginFolder"="c:\\age\\マブラヴ11\\Plugins"
"bIsIllegalTerminateCheck"=dword:00000000
"nRugpVersion"=dword:0000157c
.
[HKEY_USERS\S-1-5-21-338440498-2888063792-2753391560-1001\Software\relic UGP Applications\age\゙0ヨ0・・1*1*\rvmmBoxSettings]
"nWndFrameLevel"=dword:00000003
"nWndBaseRatioSrc"=dword:000000c0
"nWndBaseRatioDst"=dword:00000006
"nWndBaseColor1"=dword:002020a0
"nWndBaseColor2"=dword:00c0c0ff
"nWndBaseGradation"=dword:00000001
"nFontBlank"=dword:00000002
"nMainFontColor"=dword:ffffffff
"nSelectedFontColor"=dword:ff8090c0
.
[HKEY_USERS\S-1-5-21-338440498-2888063792-2753391560-1001\Software\relic UGP Applications\age\゙0ヨ0・・1*1*\rvmmInstallation]
"strFontCachePath"="c:\\age\\マブラヴ11\\"
"strVirtuaRegistryAbsolutePath"="c:\\age\\マブラヴ11\\Vmreg\\"
.
[HKEY_USERS\S-1-5-21-338440498-2888063792-2753391560-1001\Software\relic UGP Applications\age\゙0ヨ0・・1*1*\rvmmPeculiarToTheApp]
"strStandardFont"="MS Pゴシック%#24%$-B%$-A"
"strLowSpecFont"="MS Pゴシック%#16%$-B"
"bCanSettingWindow"=dword:00000001
"bCanSettingFont"=dword:00000001
"bPageOverNext"=dword:00000000
"bUucAccessMasterKey"=dword:00000001
"bCanSettingSound"=dword:00000001
"bFullScreenMenuOff"=dword:00000000
"bWindowMenuAccessMasterKey"=dword:00000001
.
[HKEY_USERS\S-1-5-21-338440498-2888063792-2753391560-1001\Software\relic UGP Applications\age\゙0ヨ0・・1*1*\rvmmUISettings]
"dwMainFontStyle"=dword:00000005
"bFullScreen"=dword:00000001
"nTextSpeed"=dword:00000030
"strCurrentMonitorDevice"="\\\\.\\DISPLAY1"
"dwCurrentMonitorFlag"=dword:00000001
"nWindowSize"=dword:00000003
"nFaceWindowSize"=dword:00000003
"isBgm"=dword:00000001
"isEffect"=dword:00000001
"nVoiceLevel"=dword:00000001
"nLayeredEffect"=dword:00000001
"nSeenMsgSkip"=dword:00000001
"nAutoMsgSkip"=dword:00000000
"bMouseTrace"=dword:00000001
DUMPHIVE0.003 (REGF)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'lsass.exe'(632)
c:\windows\system32\NETWIN32.DLL
.
- - - - - - - > 'Explorer.exe'(2892)
c:\program files\SweetIM\Messenger\mgAdaptersProxy.dll
c:\windows\system32\NETWIN32.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
c:\program files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Novell\Client\XTier\Services\XTSvcMgr.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Novell\Client\cusrvc.exe
c:\program files\Giraffic\Veoh_GirafficWatchdog.exe
c:\program files\LogMeIn Hamachi\hamachi-2.exe
c:\program files\Hi-Rez Studios\HiPatchService.exe
c:\windows\system32\iprntsrv.exe
c:\windows\system32\nutsrv4.exe
c:\program files\PTC\PTC Portmapper\i486_nt\obj\portmap.exe
c:\program files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Giraffic\Veoh_Giraffic.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
c:\windows\system32\conime.exe
c:\program files\Epson Software\Event Manager\EEventManager.exe
c:\windows\System32\nwtray.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\ehome\ehmsas.exe
c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\program files\Common Files\Steam\SteamService.exe
.
**************************************************************************
.
Completion time: 2013-05-17 14:52:50 - machine was rebooted
ComboFix-quarantined-files.txt 2013-05-17 12:52
.
Pre-Run: 12 Verzeichnis(se), 574.919.929.856 Bytes frei
Post-Run: 16 Verzeichnis(se), 577.036.746.752 Bytes frei
.
- - End Of File - - 68A2502FC4BD7B92984609376CB040FC |