Big Evil | 21.04.2012 15:57 | Combofix :
Combofix Logfile: Code:
ComboFix 12-04-20.03 - Ullby 21.04.2012 16:40:17.1.4 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1252.49.1031.18.4095.2483 [GMT 2:00]
ausgeführt von:: c:\users\Ullby\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Ullby\AppData\Local\assembly\tmp
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\auth.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\burnlib.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\dsp_sps.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\enc_aacplus.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\enc_flac.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\enc_lame.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\enc_vorbis.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\enc_wav.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\enc_wma.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\gen_classicart.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\gen_crasher.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\gen_ff.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\gen_find_on_disk.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\gen_hotkeys.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\gen_jumpex.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\gen_ml.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\gen_nopro.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\gen_orgler.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\gen_skinmanager.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\gen_timerestore.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\gen_tray.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\gen_undo.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\in_avi.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\in_cdda.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\in_dshow.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\in_flac.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\in_flv.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\in_linein.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\in_midi.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\in_mkv.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\in_mod.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\in_mp3.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\in_mp4.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\in_nsv.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\in_swf.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\in_vorbis.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\in_wav.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\in_wave.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\in_wm.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\in_wv.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ml_addons.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ml_autotag.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ml_bookmarks.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ml_devices.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ml_disc.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ml_downloads.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ml_enqplay.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ml_history.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ml_impex.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ml_local.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ml_nowplaying.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ml_online.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ml_orb.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ml_playlists.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ml_plg.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ml_pmp.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ml_rg.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ml_transcode.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ml_wire.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\ombrowser.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\out_disk.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\out_ds.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\out_wave.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\playlist.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\pmp_activesync.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\pmp_android.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\pmp_ipod.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\pmp_njb.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\pmp_p4s.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\pmp_usb.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\pmp_wifi.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\tagz.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\vis_avs.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\vis_milk2.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\vis_nsfs.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\winamp.lng
c:\users\Ullby\AppData\Local\Temp\WLZ9B63.tmp\winampa.lng
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
c:\windows\assembly\temp\@
c:\windows\assembly\temp\cfg.ini
c:\windows\jestertb.dll
c:\windows\security\Database\tmp.edb
c:\windows\system32\dds_trash_log.cmd
c:\windows\system32\drivers\etc\hosts.ics
E:\install.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-03-21 bis 2012-04-21 ))))))))))))))))))))))))))))))
.
.
2012-04-21 14:46 . 2012-04-21 14:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-04-20 21:34 . 2012-04-20 21:34 -------- d-----w- c:\windows\system32\appmgmt
2012-04-20 21:29 . 2012-04-20 21:29 -------- d-----w- c:\programdata\Battle.net
2012-04-19 15:02 . 2012-04-19 15:03 -------- d-----w- C:\FRST
2012-04-14 00:18 . 2012-04-14 00:18 -------- d-----we c:\windows\system64
2012-04-09 18:14 . 2012-04-09 20:09 -------- d-----w- c:\programdata\EA Logs
2012-04-04 14:20 . 2012-04-13 22:27 8741536 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-04 05:45 . 2012-04-13 22:27 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-03-24 17:59 . 2012-03-24 17:59 -------- d-----w- c:\programdata\ATI
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-21 13:31 . 2010-12-22 17:42 283304 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-04-21 13:31 . 2010-12-22 14:45 283304 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-04-21 13:31 . 2010-12-22 14:45 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-04-13 22:27 . 2011-05-18 14:34 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-09 18:24 . 2010-12-22 14:45 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-02-15 10:01 . 2012-02-15 10:01 52736 ----a-w- c:\windows\system32\drivers\usbaapl64.sys
2012-02-15 10:01 . 2012-02-15 10:01 4547944 ----a-w- c:\windows\system32\usbaaplrc.dll
2012-02-14 21:05 . 2012-02-14 21:05 69632 ----a-w- c:\windows\system32\OpenVideo64.dll
2012-02-14 21:05 . 2012-02-14 21:05 59904 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2012-02-14 21:05 . 2012-02-14 21:05 61952 ----a-w- c:\windows\system32\OVDecode64.dll
2012-02-14 21:05 . 2012-02-14 21:05 54784 ----a-w- c:\windows\SysWow64\OVDecode.dll
2012-02-14 21:05 . 2012-02-14 21:05 16507904 ----a-w- c:\windows\system32\amdocl64.dll
2012-02-14 21:04 . 2012-02-14 21:04 13238272 ----a-w- c:\windows\SysWow64\amdocl.dll
2012-02-14 21:03 . 2012-02-14 21:03 54272 ----a-w- c:\windows\system32\OpenCL.dll
2012-02-14 21:03 . 2012-02-14 21:03 48128 ----a-w- c:\windows\SysWow64\OpenCL.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
R3 AODDriver4.0;AODDriver4.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 RTL8023x64;Realtek 10/100-Netzwerkkartenfamilie-NDIS-x64-Treiber;c:\windows\system32\DRIVERS\Rtnic64.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-13 253088]
R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
R4 AMD FUEL Service;AMD FUEL Service;c:\users\Ullby\Desktop\ATI.ACE\Fuel\Fuel.Service.exe [2012-02-14 361984]
R4 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-05-01 136360]
R4 ICQ Service;ICQ Service;c:\program files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-09-06 247096]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S2 AODDriver4.1;AODDriver4.1;c:\users\Ullby\Desktop\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-01-03 55936]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 RTL8167;Realtek 8167 NT-Treiber;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
Inhalt des "geplante Tasks" Ordners
.
2012-04-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 22:27]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
deltafw
igfx
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.de/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = 146.57.249.98:3128
uInternet Settings,ProxyOverride = *.local
IE: Free YouTube Download - c:\users\Ullby\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\Ullby\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files (x86)\ICQ7.2\ICQ7.4\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{90F8E880-893B-44CF-BF30-5746AD3DFE08}: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{CEF2B0CE-5603-4E6D-BB42-C7CAF0FB67C4}: NameServer = 192.168.1.1
FF - ProfilePath - c:\users\Ullby\AppData\Roaming\Mozilla\Firefox\Profiles\xwqt6cjl.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: network.proxy.ftp - 146.57.249.98
FF - prefs.js: network.proxy.ftp_port - 3128
FF - prefs.js: network.proxy.http - 146.57.249.98
FF - prefs.js: network.proxy.http_port - 3128
FF - prefs.js: network.proxy.socks - 146.57.249.98
FF - prefs.js: network.proxy.socks_port - 3128
FF - prefs.js: network.proxy.ssl - 146.57.249.98
FF - prefs.js: network.proxy.ssl_port - 3128
FF - prefs.js: network.proxy.type - 0
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-Free Audio CD Burner_is1 - c:\program files (x86)\DVDVideoSoft\Free Audio CD Burner\unins000.exe
AddRemove-Free Video to MP3 Converter_is1 - c:\program files (x86)\DVDVideoSoft\Free Video to MP3 Converter\unins000.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2452620630-2399284679-4211720528-1001\Software\SecuROM\License information*]
"datasecu"=hex:f7,a1,4a,9f,63,41,1c,31,dd,0f,ca,9c,f6,be,e9,3c,2d,4d,b0,5f,67,
1b,02,ec,2d,27,8b,23,dc,97,97,6b,72,b7,80,b7,ea,02,05,f5,19,d8,9a,c8,3d,60,\
"rkeysecu"=hex:16,26,5d,b5,22,2f,fc,e5,ad,7e,7d,5d,97,08,4d,e1
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-04-21 16:54:18 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2012-04-21 14:54
.
Vor Suchlauf: 2.141.478.912 Bytes frei
Nach Suchlauf: 1.946.578.944 Bytes frei
.
- - End Of File - - 33A3F21EFD2E6BE5D589D4D1673C1B74 --- --- --- |