Schmalle7 | 03.07.2013 20:06 | Hi,
hier erstmal die Textdatei von ComboFix, Schritt 2 mache ich gleich. Code:
ComboFix 13-07-03.01 - ciss 03.07.2013 20:47:35.1.2 - x86
Microsoft Windows 8 Pro 6.2.9200.0.1252.49.1031.18.3071.2051 [GMT 2:00]
ausgeführt von:: c:\users\ciss\Desktop\ComboFix.exe
AV: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\ciss\4.0
c:\users\ciss\Documents\Downloads\Integrated_CT2629906.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-06-03 bis 2013-07-03 ))))))))))))))))))))))))))))))
.
.
2013-07-03 18:54 . 2013-07-03 18:54 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-07-03 18:44 . 2013-07-03 18:44 29904 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2A9C1D57-52E8-4D8E-AD18-A3117009B37B}\MpKsl9bb92288.sys
2013-07-03 14:33 . 2013-07-03 14:33 243888 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10208.bin
2013-07-03 14:20 . 2013-06-12 04:18 7068072 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2A9C1D57-52E8-4D8E-AD18-A3117009B37B}\mpengine.dll
2013-07-03 14:14 . 2013-07-03 14:14 -------- d-----w- C:\FRST
2013-07-03 05:40 . 2013-07-03 05:40 -------- d-----w- C:\_OTL
2013-06-12 15:51 . 2013-05-04 04:57 10788864 ----a-w- c:\windows\system32\Windows.UI.Xaml.dll
2013-06-10 12:16 . 2010-06-02 02:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2013-06-10 12:15 . 2008-05-30 12:11 467984 ----a-w- c:\windows\system32\d3dx10_38.dll
2013-06-09 19:39 . 2013-06-10 12:14 -------- d-----w- c:\programdata\WarThunder
2013-06-09 19:39 . 2013-06-09 19:39 -------- d-----w- c:\users\ciss\AppData\Local\WarThunder
2013-06-09 19:38 . 2013-06-09 19:38 -------- d-----w- c:\users\ciss\AppData\Local\Programs
2013-06-09 10:02 . 2013-06-09 10:10 -------- d-----w- c:\users\ciss\AppData\Local\Google
2013-06-09 10:01 . 2013-06-09 10:02 -------- d-----w- c:\program files\Google
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-16 10:13 . 2013-02-01 15:00 50784 ----a-w- c:\programdata\Microsoft\windowsfiltering\Sqm\Manifest\Sqm3.bin
2013-06-10 15:00 . 2013-03-31 17:16 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2013-06-04 22:09 . 2012-07-26 06:55 78200 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-06-04 22:09 . 2012-07-26 06:55 693112 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-05-29 20:16 . 2012-07-26 06:53 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-02 15:28 . 2013-02-02 10:07 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-04-16 01:15 . 2013-05-16 12:08 1229576 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-04-13 05:56 . 2013-05-16 12:08 444416 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-04-08 23:44 . 2013-05-29 19:36 123880 ----a-w- c:\windows\system32\wscapi.dll
2013-04-08 23:39 . 2013-05-29 19:36 1476024 ----a-w- c:\windows\system32\ntdll.dll
2013-04-08 23:38 . 2013-05-29 19:36 248576 ----a-w- c:\windows\system32\kd_02_10ec.dll
2013-04-08 23:37 . 2013-05-29 19:36 426024 ----a-w- c:\windows\system32\AudioEng.dll
2013-04-08 23:37 . 2013-05-29 19:36 324368 ----a-w- c:\windows\system32\AudioSes.dll
2013-04-08 23:37 . 2013-05-29 19:36 207576 ----a-w- c:\windows\system32\audiodg.exe
2013-04-08 21:52 . 2013-05-29 19:36 302592 ----a-w- c:\windows\system32\SearchProtocolHost.exe
2013-04-08 21:52 . 2013-05-29 19:36 670208 ----a-w- c:\windows\system32\SearchIndexer.exe
2013-04-08 21:52 . 2013-05-29 19:36 614912 ----a-w- c:\windows\system32\RecoveryDrive.exe
2013-04-08 21:52 . 2013-05-29 19:36 171008 ----a-w- c:\windows\system32\SearchFilterHost.exe
2013-04-08 21:52 . 2013-05-29 19:36 106496 ----a-w- c:\windows\system32\Robocopy.exe
2013-04-08 21:52 . 2013-05-29 19:36 300032 ----a-w- c:\windows\system32\conhost.exe
2013-04-08 21:52 . 2013-05-29 19:36 364544 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2013-04-08 21:52 . 2013-05-29 19:36 393216 ----a-w- c:\windows\system32\wpncore.dll
2013-04-08 21:52 . 2013-05-29 19:36 77312 ----a-w- c:\windows\system32\wscsvc.dll
2013-04-08 21:51 . 2013-05-29 19:36 411136 ----a-w- c:\windows\system32\Windows.Networking.dll
2013-04-08 21:51 . 2013-05-29 19:36 268800 ----a-w- c:\windows\system32\Windows.Networking.BackgroundTransfer.dll
2013-04-08 21:51 . 2013-05-29 19:36 2767360 ----a-w- c:\windows\system32\tquery.dll
2013-04-08 21:51 . 2013-05-29 19:36 324096 ----a-w- c:\windows\system32\schannel.dll
2013-04-08 21:51 . 2013-05-29 19:36 942080 ----a-w- c:\windows\system32\schedsvc.dll
2013-04-08 21:51 . 2013-05-29 19:36 1593344 ----a-w- c:\windows\system32\mssrch.dll
2013-04-08 21:51 . 2013-05-29 19:36 403968 ----a-w- c:\windows\system32\mssph.dll
2013-04-08 21:51 . 2013-05-29 19:36 659456 ----a-w- c:\windows\system32\mssvp.dll
2013-04-08 21:51 . 2013-05-29 19:36 186880 ----a-w- c:\windows\system32\mssphtb.dll
2013-04-08 21:51 . 2013-05-29 19:36 35328 ----a-w- c:\windows\system32\mssprxy.dll
2013-04-08 21:51 . 2013-05-29 19:36 10752 ----a-w- c:\windows\system32\msshooks.dll
2013-04-08 21:51 . 2013-05-29 19:36 1113600 ----a-w- c:\windows\system32\MSAudDecMFT.dll
2013-04-08 21:51 . 2013-05-29 19:36 214528 ----a-w- c:\windows\system32\mfreadwrite.dll
2013-04-08 21:51 . 2013-05-29 19:36 361984 ----a-w- c:\windows\system32\MFMediaEngine.dll
2013-04-08 21:51 . 2013-05-29 19:36 656896 ----a-w- c:\windows\system32\kerberos.dll
2013-04-08 21:51 . 2013-05-29 19:36 201216 ----a-w- c:\windows\system32\iuilp.dll
2013-04-08 21:51 . 2013-05-29 19:36 181760 ----a-w- c:\windows\system32\fhengine.dll
2013-04-08 21:51 . 2013-05-29 19:36 239616 ----a-w- c:\windows\system32\fhcfg.dll
2013-04-08 21:51 . 2013-05-29 19:36 41984 ----a-w- c:\windows\system32\fmifs.dll
2013-04-08 21:51 . 2013-05-29 19:36 100352 ----a-w- c:\windows\system32\EncDump.dll
2013-04-08 21:51 . 2013-05-29 19:36 139264 ----a-w- c:\windows\system32\dwmredir.dll
2013-04-08 21:51 . 2013-05-29 19:36 155648 ----a-w- c:\windows\system32\dmvdsitf.dll
2013-04-08 21:51 . 2013-05-29 19:36 598528 ----a-w- c:\windows\system32\audiosrv.dll
2013-04-08 21:51 . 2013-05-29 19:36 136704 ----a-w- c:\windows\system32\AudioEndpointBuilder.dll
2013-04-08 21:40 . 2013-05-29 19:36 3390464 ----a-w- c:\windows\system32\win32k.sys
2013-04-06 04:59 . 2013-05-29 19:36 81920 ----a-w- c:\windows\system32\drivers\hidbth.sys
2013-04-06 04:58 . 2013-05-29 19:36 48640 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2013-04-06 04:57 . 2013-05-29 19:36 494592 ----a-w- c:\windows\system32\drivers\srv2.sys
2013-04-06 04:56 . 2013-05-29 19:36 709632 ----a-w- c:\windows\system32\drivers\PEAuth.sys
2013-04-06 04:55 . 2013-05-29 19:36 196096 ----a-w- c:\windows\system32\drivers\srvnet.sys
2013-04-06 04:55 . 2013-05-29 19:36 70656 ----a-w- c:\windows\system32\drivers\wanarp.sys
2013-04-04 22:07 . 2013-05-29 19:36 457624 ----a-w- c:\windows\system32\ci.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\ciss\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2013-02-27 138096]
"Spotify"="c:\users\ciss\AppData\Roaming\Spotify\Spotify.exe" [2013-06-16 4643328]
"Spotify Web Helper"="c:\users\ciss\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2013-06-16 1104384]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"MobileBroadband"="c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" [2012-03-20 69632]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-05-15 152392]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableCursorSuppression"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [2012-03-16 102784]
R3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\System32\drivers\ew_usbenumfilter.sys [2012-03-16 11136]
R3 huawei_cdcacm;huawei_cdcacm;c:\windows\system32\DRIVERS\ew_jucdcacm.sys [2012-03-16 89856]
R3 huawei_ext_ctrl;huawei_ext_ctrl;c:\windows\System32\drivers\ew_juextctrl.sys [2012-03-16 26624]
R3 huawei_wwanecm;huawei_wwanecm;c:\windows\system32\DRIVERS\ew_juwwanecm.sys [2012-03-16 193536]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl.sys [2012-09-10 18432]
S1 MpKsl9bb92288;MpKsl9bb92288;c:\programdata\Microsoft\Windows Defender\Definition Updates\{2A9C1D57-52E8-4D8E-AD18-A3117009B37B}\MpKsl9bb92288.sys [2013-07-03 29904]
S2 VmbService;Vodafone-Mobile-Broadband-Dienst;c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2012-03-20 8704]
S3 huawei_enumerator;huawei_enumerator;c:\windows\System32\drivers\ew_jubusenum.sys [2012-03-16 73984]
S3 SiSGbeLH;NDIS 6.0-Treiber für SiS191/SiS190-Ethernet-Gerät;c:\windows\system32\DRIVERS\SiSGB6.sys [2012-06-02 48128]
S3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
DcomLaunch REG_MULTI_SZ Power BrokerInfrastructure LSM PlugPlay DeviceInstall DcomLaunch
LocalServiceAndNoImpersonation REG_MULTI_SZ TimeBroker SSDPSRV upnphost SCardSvr BthHFSrv QWAVE fdrespub wcncsvc WSService SensrSvc
LocalServiceNoNetwork REG_MULTI_SZ DPS PLA BFE mpssvc NcdAutoSetup WwanSvc
ICService REG_MULTI_SZ vmicheartbeat vmicrdv
print REG_MULTI_SZ PrintNotify
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
wlidsvc
SystemEventsBroker
DsmSvc
NcaSvc
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalSystemNetworkRestricted
svsvc
AllUserInstallAgent
fhsvc
vmickvpexchange
vmicshutdown
vmicvss
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
bthserv
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalServiceNetworkRestricted
AppIDSvc
wcmsvc
vmictimesync
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
2013-03-06 05:03 17561600 ----a-w- c:\windows\System32\shell32.dll
.
Inhalt des "geplante Tasks" Ordners
.
2013-07-03 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2226582012-2746248457-2725141191-1000Core.job
- c:\users\ciss\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-02-27 19:07]
.
2013-07-03 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2226582012-2746248457-2725141191-1000UA.job
- c:\users\ciss\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-02-27 19:07]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.de/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = 192.168.2.1
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Security\DS\ObjectNames]
@DACL=(02 0000)
@SACL=
"Directory Service Object"=dword:00001e00
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Security\LSA\ObjectNames]
@DACL=(02 0000)
@SACL=
"UserAccountObject"=dword:00001630
"PolicyObject"=dword:00001600
"TrustedDomainObject"=dword:00001620
"AdtSecurity"=dword:00001f00
"SecretObject"=dword:00001610
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Security\SC Manager\ObjectNames]
@DACL=(02 0000)
@SACL=
"SERVICE Object"=dword:00001c10
"SC_MANAGER Object"=dword:00001c00
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Security\Security\ObjectNames]
@DACL=(02 0000)
@SACL=
"Device"=dword:00001100
"WindowStation"=dword:00001a00
"Section"=dword:000011a0
"Event"=dword:00001120
"Desktop"=dword:00001a10
"WaitablePort"=dword:00001170
"Directory"=dword:00001110
"Thread"=dword:000011d0
"EventPair"=dword:00001130
"NamedPipe"=dword:00001140
"Port"=dword:00001170
"File"=dword:00001140
"KeyedEvent"=dword:00001640
"Profile"=dword:00001190
"Channel"=dword:00001400
"WMI Namespace"=dword:00004200
"Timer"=dword:000011e0
"Token"=dword:000011f0
"Job"=dword:00001410
"IoCompletion"=dword:00001300
"Process"=dword:00001180
"Mutant"=dword:00001160
"Type"=dword:00001200
"Semaphore"=dword:000011b0
"ALPC Port"=dword:00001170
"SymbolicLink"=dword:000011c0
"MailSlot"=dword:00001140
"Key"=dword:00001150
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Security\Security Account Manager\ObjectNames]
@DACL=(02 0000)
@SACL=
"SAM_USER"=dword:00001540
"SAM_ALIAS"=dword:00001530
"SAM_GROUP"=dword:00001520
"SAM_DOMAIN"=dword:00001510
"SAM_SERVER"=dword:00001500
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Security\Spooler\ObjectNames]
@DACL=(02 0000)
@SACL=
"Document"=dword:00001b20
"Server"=dword:00001b00
"Printer"=dword:00001b10
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Security\TCP/IP\ObjectNames]
@DACL=(02 0000)
@SACL=
"InternetPort"=dword:00001f80
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\0\Ip]
@DACL=(02 0000)
"ProtocolId"=dword:00000021
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\0\Ipv6]
@DACL=(02 0000)
"ProtocolId"=dword:00000057
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\1\Ip]
@DACL=(02 0000)
"ProtocolId"=dword:00000021
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\1\Ipv6]
@DACL=(02 0000)
"ProtocolId"=dword:00000057
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\10\Ip]
@DACL=(02 0000)
"ProtocolId"=dword:00000021
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\10\Ipv6]
@DACL=(02 0000)
"ProtocolId"=dword:00000057
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\2\Ip]
@DACL=(02 0000)
"ProtocolId"=dword:00000021
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\2\Ipv6]
@DACL=(02 0000)
"ProtocolId"=dword:00000057
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\3\Ip]
@DACL=(02 0000)
"ProtocolId"=dword:00000021
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\3\Ipv6]
@DACL=(02 0000)
"ProtocolId"=dword:00000057
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\4\Ip]
@DACL=(02 0000)
"ProtocolId"=dword:00000021
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\4\Ipv6]
@DACL=(02 0000)
"ProtocolId"=dword:00000057
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\5\Ip]
@DACL=(02 0000)
"ProtocolId"=dword:00000021
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\5\Ipv6]
@DACL=(02 0000)
"ProtocolId"=dword:00000057
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\6\Ip]
@DACL=(02 0000)
"ProtocolId"=dword:00000021
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\6\Ipv6]
@DACL=(02 0000)
"ProtocolId"=dword:00000057
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\7\Ip]
@DACL=(02 0000)
"ProtocolId"=dword:00000021
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\7\Ipv6]
@DACL=(02 0000)
"ProtocolId"=dword:00000057
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\8\Ip]
@DACL=(02 0000)
"ProtocolId"=dword:00000021
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\8\Ipv6]
@DACL=(02 0000)
"ProtocolId"=dword:00000057
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\9\Ip]
@DACL=(02 0000)
"ProtocolId"=dword:00000021
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\Interfaces\9\Ipv6]
@DACL=(02 0000)
"ProtocolId"=dword:00000057
"InterfaceInfo"=hex:01,00,00,00,68,00,00,00,03,00,00,00,05,00,ff,ff,48,00,00,
00,00,00,00,00,40,00,00,00,04,00,ff,ff,04,00,00,00,01,00,00,00,40,00,00,00,\
.
Zeit der Fertigstellung: 2013-07-03 20:57:35
ComboFix-quarantined-files.txt 2013-07-03 18:57
.
Vor Suchlauf: 12 Verzeichnis(se), 49.082.888.192 Bytes frei
Nach Suchlauf: 20 Verzeichnis(se), 48.999.485.440 Bytes frei
.
- - End Of File - - 4F8D90C45EAE33F3571639D9A0B57FF9
5C616939100B85E558DA92B899A0FC36 Grüße!
Kevin |