Jetzt hat's geklappt.
Combofix hat allerdings mehrfach die Meldung "Failed to get Data for 'EnableLUA'" ausgegeben.
Hier der Log: Code:
ComboFix 10-07-28.04 - Administrator 29.07.2010 18:17:10.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3070.2202 [GMT 2:00]
ausgeführt von:: c:\users\Administrator\Desktop\cofi.exe
SP: Windows-Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Administrator\AppData\Roaming\EDA404E935DDDDF88EF95503A843866B
c:\users\Administrator\AppData\Roaming\EDA404E935DDDDF88EF95503A843866B\enemies-names.txt
c:\users\Administrator\AppData\Roaming\EDA404E935DDDDF88EF95503A843866B\local.ini
c:\windows\hide.exe
.
((((((((((((((((((((((( Dateien erstellt von 2010-06-28 bis 2010-07-29 ))))))))))))))))))))))))))))))
.
2010-07-29 16:21 . 2010-07-29 16:21 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2010-07-29 16:21 . 2010-07-29 16:21 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-07-27 16:08 . 2010-07-27 16:10 -------- d-----w- C:\cofi
2010-07-27 15:46 . 2010-07-27 15:46 -------- d-----w- C:\_OTL
2010-07-26 16:34 . 2010-07-26 22:08 952 --sha-w- c:\windows\system32\KGyGaAvL.sys
2010-07-26 16:32 . 2010-07-26 16:32 -------- d-----w- c:\program files\RPG Maker
2010-07-26 14:02 . 2010-07-26 14:02 -------- d-----w- c:\program files\IrfanView
2010-07-25 20:55 . 2010-07-25 20:55 -------- d-----w- c:\users\Administrator\AppData\Roaming\Malwarebytes
2010-07-25 20:55 . 2010-04-29 10:19 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-25 20:55 . 2010-07-25 20:55 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2010-07-25 20:55 . 2010-07-25 20:55 -------- d-----w- c:\programdata\Malwarebytes
2010-07-25 20:55 . 2010-04-29 10:19 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-25 19:29 . 2010-07-25 19:29 -------- d-----w- c:\windows\Sun
2010-07-25 16:52 . 2010-07-28 23:10 1 ----a-w- c:\users\Administrator\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-07-25 16:52 . 2010-07-25 16:52 -------- d-----w- c:\users\Administrator\AppData\Roaming\OpenOffice.org
2010-07-25 16:49 . 2010-07-28 23:21 -------- d-----w- c:\program files\OpenOffice.org 3
2010-07-25 16:48 . 2010-07-25 16:48 -------- d-----w- c:\program files\Common Files\Java
2010-07-25 16:48 . 2010-07-25 16:48 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-07-25 16:48 . 2010-07-25 16:48 -------- d-----w- c:\program files\Java
2010-07-25 00:09 . 2010-07-25 00:09 -------- d-----w- c:\users\Eigenes\Zeug
2010-07-23 22:12 . 2010-07-23 22:12 -------- d-----w- c:\users\Administrator\AppData\Roaming\Wireshark
2010-07-23 21:49 . 2010-07-25 21:17 -------- d-----w- c:\users\Eigenes\Tools
2010-07-23 21:23 . 2010-07-23 21:23 -------- d-----w- c:\program files\WinPcap
2010-07-23 21:22 . 2010-07-23 21:23 -------- d-----w- c:\program files\Wireshark
2010-07-23 19:11 . 2010-07-27 20:15 -------- d-----w- c:\users\Administrator\AppData\Roaming\Nettalk
2010-07-23 19:09 . 2010-07-23 19:11 -------- d-----w- c:\program files\Nettalk
2010-07-23 18:12 . 2010-07-23 18:12 0 ----a-w- c:\windows\nsreg.dat
2010-07-23 18:12 . 2010-07-23 18:12 -------- d-----w- c:\users\Administrator\AppData\Local\Mozilla
2010-07-23 17:46 . 2010-07-23 17:47 -------- d-----w- c:\program files\EXP AudioEditor
2010-07-23 17:46 . 2010-07-23 17:46 161149 ----a-w- c:\windows\Expstudio Audio Editor FREE Uninstaller.exe
2010-07-23 17:46 . 2010-07-23 17:46 -------- d-----w- c:\windows\system32\EXP
2010-07-23 17:31 . 2010-07-23 17:31 -------- d-----w- c:\users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers
2010-07-23 17:31 . 2010-07-23 17:33 -------- d-----w- c:\program files\YouTube Converter
2010-07-23 17:31 . 2010-07-23 17:32 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2010-07-23 00:48 . 2010-07-28 23:22 -------- d-----w- c:\users\Administrator\AppData\Roaming\vlc
2010-07-21 14:24 . 2010-07-21 14:24 1861000 ----a-w- c:\programdata\Nexon\Common\NMService.exe
2010-07-21 14:24 . 2010-07-21 14:24 1774992 ----a-w- c:\programdata\Nexon\Common\nmconew.dll
2010-07-20 21:41 . 2010-07-26 22:52 -------- d-----w- c:\users\Administrator\AppData\Roaming\Media Player Classic
2010-07-20 03:45 . 2010-07-20 03:47 -------- d-----w- c:\users\Administrator\AppData\Roaming\Miranda
2010-07-20 03:44 . 2010-07-20 03:44 -------- d-----w- c:\program files\Miranda IM
2010-07-14 14:57 . 2010-07-16 13:58 -------- d-----w- c:\windows\Downloaded Installations
2010-07-14 14:38 . 2005-01-03 15:43 4682 ----a-w- c:\windows\system32\npptNT2.sys
2010-07-14 14:37 . 2010-07-14 14:37 -------- d-----w- c:\program files\Common Files\INCA Shared
2010-07-14 14:20 . 2010-07-14 14:20 -------- d-----w- c:\program files\IZArc
2010-07-14 14:02 . 2010-07-14 14:21 -------- d-----w- c:\program files\TeamSpeak3
2010-07-14 13:42 . 2010-07-14 13:42 -------- d-----w- c:\windows\system32\ca-ES
2010-07-14 13:42 . 2010-07-14 13:42 -------- d-----w- c:\windows\system32\eu-ES
2010-07-14 13:42 . 2010-07-14 13:42 -------- d-----w- c:\windows\system32\vi-VN
2010-07-14 13:24 . 2010-07-14 13:24 -------- d-----w- c:\windows\system32\EventProviders
2010-07-14 13:22 . 2009-04-11 06:28 29184 ----a-w- c:\windows\system32\wsepno.dll
2010-07-14 13:08 . 2008-05-27 04:59 18904 ----a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin
2010-07-14 13:07 . 2010-07-14 13:07 -------- d-----w- c:\program files\Microsoft.NET
2010-07-14 13:05 . 2010-05-01 14:13 2037248 ----a-w- c:\windows\system32\win32k.sys
2010-07-14 12:41 . 2008-01-19 07:33 227840 ----a-w- c:\windows\system32\msconfig.exe
2010-07-14 12:40 . 2008-01-19 07:35 35328 ----a-w- c:\windows\system32\mspatcha.dll
2010-07-14 12:40 . 2008-01-19 07:34 305152 ----a-w- c:\windows\system32\msdelta.dll
2010-07-14 12:40 . 2008-01-19 07:34 258560 ----a-w- c:\windows\system32\dpx.dll
2010-07-14 12:40 . 2006-11-02 09:39 6656 ----a-w- c:\windows\system32\kbd106.dll
2010-07-14 12:23 . 2010-03-05 14:01 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-07-14 12:00 . 2010-07-14 12:00 377344 ----a-w- c:\windows\system32\winhttp.dll
2010-07-14 11:59 . 2010-07-14 11:59 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-07-14 08:18 . 2010-07-14 08:18 3 ------w- c:\windows\AFirst.cmd
2010-07-14 08:18 . 2007-11-16 01:54 17733320 ------w- c:\windows\eRy.exe
2010-07-14 08:18 . 2007-11-27 10:23 86016 ------w- c:\windows\SetSpkDefault.exe
2010-07-14 08:18 . 2007-04-26 15:02 294 ------w- c:\windows\offline.reg
2010-07-14 08:18 . 2007-01-15 12:28 336 ------w- c:\windows\ACERTOURREMINDERRUN.REG
2010-07-14 08:18 . 2010-07-13 22:32 1289 ------w- c:\windows\CLEANUP.CMD
2010-07-14 08:18 . 2002-11-14 14:32 55808 ------w- c:\windows\devcon.exe
2010-07-14 06:54 . 2010-07-14 06:54 -------- d-----w- c:\users\Administrator\Catalog
2010-07-14 06:43 . 2010-07-14 06:43 -------- d-----w- c:\users\Administrator\Report Files
2010-07-14 05:01 . 2010-07-14 05:01 -------- d-----w- c:\programdata\NVIDIA Corporation
2010-07-14 05:01 . 2010-07-14 05:06 -------- d-----w- c:\program files\NVIDIA Corporation
2010-07-14 05:00 . 2010-06-07 23:57 795104 ------w- c:\windows\system32\dpinst.exe
2010-07-14 05:00 . 2010-06-07 23:57 56936 ------w- c:\windows\system32\OpenCL.dll
2010-07-14 05:00 . 2010-06-07 23:57 10888168 ------w- c:\windows\system32\drivers\nvlddmkm.sys
2010-07-14 05:00 . 2010-06-07 23:57 4967528 ------w- c:\windows\system32\nvwgf2um.dll
2010-07-14 05:00 . 2010-06-07 23:57 15764072 ------w- c:\windows\system32\nvoglv32.dll
2010-07-14 05:00 . 2010-06-07 23:57 4513384 ------w- c:\windows\system32\nvcuda.dll
2010-07-14 05:00 . 2010-06-07 23:57 2632296 ------w- c:\windows\system32\nvcuvenc.dll
2010-07-14 05:00 . 2010-06-07 23:57 232040 ------w- c:\windows\system32\nvcod1921.dll
2010-07-14 05:00 . 2010-06-07 23:57 232040 ------w- c:\windows\system32\nvcod.dll
2010-07-14 05:00 . 2010-06-07 23:57 2145896 ------w- c:\windows\system32\nvcuvid.dll
2010-07-14 05:00 . 2010-06-07 23:57 10263144 ------w- c:\windows\system32\nvcompiler.dll
2010-07-14 04:55 . 2010-07-14 04:55 -------- d-----w- c:\users\Administrator\Bluetooth Software
2010-07-14 04:55 . 2010-07-29 13:56 12 ----a-w- c:\windows\bthservsdp.dat
2010-07-14 04:49 . 2010-07-18 01:38 69840 ----a-w- c:\users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-14 04:39 . 2010-07-14 12:19 -------- d-----w- c:\users\Administrator\TaskBar Menüs
2010-07-14 04:34 . 2010-07-14 04:34 -------- d-----w- c:\users\Administrator\AppData\Local\Opera
2010-07-14 04:22 . 2010-07-14 04:22 -------- d-----w- c:\users\Public\Roaming
2010-07-14 04:22 . 2010-07-14 04:22 -------- d-----w- c:\users\Default\Roaming
2010-07-14 04:22 . 2010-07-14 04:22 -------- d-----w- c:\programdata\Roaming
2010-07-14 04:22 . 2010-07-14 04:22 -------- d-----w- c:\program files\Cisco
2010-07-14 04:22 . 2010-07-14 04:22 -------- d-----w- c:\programdata\Intel
2010-07-14 04:22 . 2010-07-14 04:22 -------- d-----w- c:\program files\Common Files\Intel
2010-07-14 04:21 . 2010-07-14 04:21 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-07-14 04:21 . 2010-07-14 04:21 23552 ----a-w- c:\windows\system32\lpk.dll
2010-07-14 04:21 . 2010-07-14 04:21 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-07-14 04:21 . 2010-07-14 04:21 10240 ----a-w- c:\windows\system32\dciman32.dll
2010-07-14 04:18 . 2010-07-14 04:18 61440 ----a-w- c:\windows\system32\winipsec.dll
2010-07-14 04:18 . 2010-07-14 04:18 272896 ----a-w- c:\windows\system32\polstore.dll
2010-07-14 04:17 . 2010-07-14 04:17 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-07-14 04:17 . 2010-07-14 04:17 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-07-14 04:17 . 2010-07-14 04:17 17920 ----a-w- c:\windows\system32\netevent.dll
2010-07-14 04:17 . 2010-07-14 04:17 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2010-07-14 04:17 . 2010-07-14 04:17 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2010-07-14 04:17 . 2010-07-14 04:17 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2010-07-14 04:17 . 2010-07-14 04:17 19968 ----a-w- c:\windows\system32\ARP.EXE
2010-07-14 04:17 . 2010-07-14 04:17 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2010-07-14 04:17 . 2010-07-14 04:17 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2010-07-14 04:17 . 2010-07-14 04:17 105984 ----a-w- c:\windows\system32\netiohlp.dll
2010-07-14 04:17 . 2010-07-14 04:17 10240 ----a-w- c:\windows\system32\finger.exe
2010-07-14 04:15 . 2010-07-14 04:15 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2010-07-14 04:15 . 2010-07-14 04:15 68096 ----a-w- c:\windows\system32\wlanhlp.dll
2010-07-14 04:15 . 2010-07-14 04:15 65024 ----a-w- c:\windows\system32\wlanapi.dll
2010-07-14 04:15 . 2010-07-14 04:15 513536 ----a-w- c:\windows\system32\wlansvc.dll
2010-07-14 04:15 . 2010-07-14 04:15 302592 ----a-w- c:\windows\system32\wlansec.dll
2010-07-14 04:15 . 2010-07-14 04:15 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2010-07-14 04:15 . 2010-07-14 04:15 15181 ----a-w- c:\windows\system32\gatherWirelessInfo.vbs
2010-07-14 04:14 . 2010-07-14 04:14 1248768 ----a-w- c:\windows\system32\msxml3.dll
2010-07-14 04:14 . 2010-07-14 04:14 2048 ----a-w- c:\windows\system32\msxml3r.dll
2010-07-14 04:14 . 2010-07-14 04:14 1401856 ----a-w- c:\windows\system32\msxml6.dll
2010-07-14 04:14 . 2010-07-14 04:14 2048 ----a-w- c:\windows\system32\msxml6r.dll
2010-07-14 04:13 . 2010-07-14 04:13 218624 ----a-w- c:\windows\system32\msv1_0.dll
2010-07-14 04:12 . 2010-07-14 04:12 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-07-14 04:12 . 2010-07-14 04:12 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-29 16:20 . 2006-11-02 15:33 628742 ----a-w- c:\windows\system32\perfh007.dat
2010-07-29 16:20 . 2006-11-02 15:33 126260 ----a-w- c:\windows\system32\perfc007.dat
2010-07-29 01:37 . 2010-07-15 01:57 -------- d-----w- c:\users\Administrator\AppData\Roaming\uTorrent
2010-07-25 03:35 . 2010-07-15 01:44 -------- d-----w- c:\program files\XnView
2010-07-23 00:48 . 2010-07-15 02:41 -------- d-----w- c:\program files\VLC Player
2010-07-16 13:59 . 2010-07-14 14:58 -------- d-----w- c:\program files\Common Files\Macromedia
2010-07-16 13:59 . 2010-07-14 14:58 -------- d-----w- c:\program files\Macromedia
2010-07-15 02:44 . 2010-07-15 02:44 -------- d-----w- c:\program files\CCCP
2010-07-15 01:57 . 2010-07-15 01:57 -------- d-----w- c:\program files\uTorrent
2010-07-15 01:55 . 2010-07-15 01:55 -------- d-----w- c:\program files\WinSCP
2010-07-15 01:44 . 2010-07-15 01:44 -------- d-----w- c:\users\Administrator\AppData\Roaming\XnView
2010-07-15 00:53 . 2010-07-15 00:53 -------- d-----w- c:\programdata\Nexon
2010-07-14 13:42 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2010-07-14 13:42 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2010-07-14 13:42 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2010-07-14 13:42 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2010-07-14 13:42 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2010-07-14 13:42 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2010-07-14 13:42 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-07-14 13:42 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-07-14 12:48 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2010-07-14 12:48 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2010-07-14 12:01 . 2007-12-21 08:16 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-14 11:53 . 2007-12-21 09:23 -------- d-----w- c:\program files\Common Files\NewTech Infosystems
2010-07-14 05:03 . 2007-12-21 08:08 -------- d-----w- c:\programdata\NVIDIA
2010-07-14 03:27 . 2010-07-14 03:27 2560 ----a-w- c:\windows\AppPatch\AcRes.dll
2010-07-13 23:34 . 2007-12-21 09:49 -------- d-----w- c:\programdata\Microsoft Help
2010-07-13 23:11 . 2007-12-21 09:58 -------- d-----w- c:\programdata\Symantec
2010-07-13 22:58 . 2007-12-21 09:32 -------- d-----w- c:\programdata\CyberLink
2010-07-13 22:28 . 2010-07-13 22:28 -------- d-sh--we c:\programdata\Vorlagen
2010-07-13 22:28 . 2010-07-13 22:28 -------- d-sh--we c:\programdata\Startmenü
2010-07-13 22:28 . 2010-07-13 22:28 -------- d-sh--we c:\programdata\Favoriten
2010-07-13 22:28 . 2010-07-13 22:28 -------- d-sh--we c:\programdata\Dokumente
2010-07-13 22:28 . 2010-07-13 22:28 -------- d-sh--we c:\programdata\Anwendungsdaten
2010-07-13 22:28 . 2010-07-13 22:28 -------- d-sh--we c:\program files\Gemeinsame Dateien
2010-07-13 22:23 . 2010-07-13 22:23 319456 ------w- c:\windows\DIFxAPI.dll
2010-07-13 22:23 . 2010-07-13 22:23 315392 ------w- c:\windows\HideWin.exe
2010-07-13 22:23 . 2010-07-13 22:23 -------- d-----w- c:\program files\Realtek
2010-06-07 23:57 . 2010-07-14 05:00 10920 ------w- c:\windows\system32\drivers\nvBridge.kmd
2010-06-07 23:57 . 2007-12-21 15:45 600680 ------w- c:\windows\system32\nvudisp.exe
2010-06-07 23:57 . 2007-12-21 15:45 9712744 ------w- c:\windows\system32\nvd3dum.dll
2010-06-07 23:57 . 2007-12-21 15:45 1592424 ------w- c:\windows\system32\nvapi.dll
2010-06-07 15:47 . 2010-06-07 15:47 66664 ------w- c:\windows\system32\nvshext.dll
2010-06-07 15:47 . 2010-06-07 15:47 255592 ------w- c:\windows\system32\nvhotkey.dll
2010-06-07 15:47 . 2010-06-07 15:47 1691752 ------w- c:\windows\system32\nvsvcr.dll
2010-06-07 15:47 . 2010-06-07 15:47 13917800 ------w- c:\windows\system32\nvcpl.dll
2010-06-07 15:47 . 2010-06-07 15:47 1331816 ------w- c:\windows\system32\nvsvc.dll
2010-06-07 15:47 . 2010-06-07 15:47 129640 ------w- c:\windows\system32\nvvsvc.exe
2010-06-07 15:47 . 2010-06-07 15:47 110696 ------w- c:\windows\system32\nvmctray.dll
2010-05-28 10:58 . 2007-12-21 15:45 600680 ------w- c:\windows\system32\nvuninst.exe
2010-05-26 17:06 . 2010-07-14 13:06 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-07-14 13:06 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-04 05:59 . 2010-07-14 12:11 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 05:55 . 2010-07-14 12:11 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-05-04 05:55 . 2010-07-14 12:11 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-05-04 04:31 . 2010-07-14 12:11 133632 ----a-w- c:\windows\system32\ieUnatt.exe
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-12-14 102400]
"RtHDVCpl"="RtHDVCpl.exe" [2007-12-14 4702208]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-01-02 707080]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-3-29 719664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Acer VCM.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk
backup=c:\windows\pss\Acer VCM.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk
backup=c:\windows\pss\Empowering Technology Launcher.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Administrator^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
path=c:\users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2007-12-14 08:55 174616 ------w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PLFSet]
2007-04-25 11:47 45056 ----a-w- c:\windows\PLFSet.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-01-11 13:21 246504 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-19 07:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
2009-04-11 06:28 2153472 ----a-w- c:\windows\System32\oobefldr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-19 07:33 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):f4,8c,0a,b0,a6,2d,cb,01
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [x]
R3 A310;AVerMedia A310 DVB-T;c:\windows\system32\DRIVERS\AVerA310USB.sys [2007-07-10 26368]
R3 BDASwCap;AVerMedia A310 BDA DVBT Capture Device;c:\windows\system32\drivers\AVerA310Cap.sys [2007-07-10 42240]
R3 dump_wmimmc;dump_wmimmc;c:\games\Dragonica\Release\GameGuard\dump_wmimmc.sys [x]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 50704]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2010-06-07 3549224]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2007-12-14 179712]
S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]
S3 winbondcir;Winbond IR Transceiver;c:\windows\system32\DRIVERS\winbondcir.sys [2007-12-14 43008]
--- Andere Dienste/Treiber im Speicher ---
*Deregistered* - gdtssxcd
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = about:blank
mStart Page = hxxp://de.intl.acer.yahoo.com
IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Free YouTube to Mp3 Converter - c:\users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\q8siash0.default\
FF - prefs.js: browser.startup.homepage -
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\VLC Player\npvlc.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX Richtlinien ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
HKLM-Run-eRecoveryService - (no file)
HKU-Default-Run-Acer Tour Reminder - c:\acer\AcerTour\Reminder.exe
MSConfigStartUp-MChk - c:\windows\system32\ozsop.exe
MSConfigStartUp-RTHDBPL - c:\users\Administrator\AppData\Roaming\SystemProc\lsass.exe
MSConfigStartUp-setupupdate70700 - c:\users\Administrator\AppData\Roaming\EDA404E935DDDDF88EF95503A843866B\setupupdate70700.exe
MSConfigStartUp-sta - bzsop.dll
MSConfigStartUp-szetyj67v - c:\windows\system32\szetyj67v.exe
MSConfigStartUp-szetyj67vx - c:\windows\system32\szetyj67vx.exe
MSConfigStartUp-tghlig - c:\users\ADMINI~1\AppData\Local\Temp\msgciutr.dll
MSConfigStartUp-vhyfjuec - c:\users\Administrator\AppData\Local\easyqxgxr\pfyscintssd.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2010-07-29 18:21
Windows 6.0.6002 Service Pack 2 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\gdtssxcd]
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3e,2e,06,22,cd,4d,88,4e,ab,f4,36,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3e,2e,06,22,cd,4d,88,4e,ab,f4,36,\
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASF"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASX"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AU"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\vlc.exe"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\MSPaint.exe"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.CDA"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2V\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.M3U"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MOD\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (Administrator)
"Progid"="VLC.mp3"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice]
@Denied: (2) (Administrator)
"Progid"="XnView.png"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AU"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WAV"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WAX"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASF"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMA"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMD"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMS"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMV"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASX"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmz\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMZ"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpl\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WPL"
[HKEY_USERS\S-1-5-21-1015238528-2963362459-2859341902-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WVX"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
- - - - - - - > 'Explorer.exe'(1876)
c:\windows\system32\btmmhook.dll
.
Zeit der Fertigstellung: 2010-07-29 18:23:21
ComboFix-quarantined-files.txt 2010-07-29 16:23
Vor Suchlauf: 6 Verzeichnis(se), 116.703.678.464 Bytes frei
Nach Suchlauf: 12 Verzeichnis(se), 116.334.886.912 Bytes frei
- - End Of File - - 451ACD996B8F2F175B03E7440A5C63BE |