SebastianW | 27.05.2012 18:40 | Hallo,
Hier die Combofix.txt Code:
ComboFix 12-05-27.02 - *** 27.05.2012 18:48:44.1.4 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.3326.1983 [GMT 2:00]
ausgeführt von:: c:\users\***\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\auth.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\burnlib.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\dsp_sps.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\enc_fhgaac.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\enc_flac.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\enc_lame.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\enc_vorbis.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\enc_wav.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\enc_wma.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\gen_classicart.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\gen_crasher.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\gen_ff.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\gen_find_on_disk.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\gen_hotkeys.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\gen_jumpex.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\gen_ml.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\gen_nopro.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\gen_orgler.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\gen_skinmanager.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\gen_timerestore.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\gen_tray.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\gen_undo.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\in_avi.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\in_cdda.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\in_dshow.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\in_flac.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\in_flv.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\in_linein.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\in_midi.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\in_mkv.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\in_mod.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\in_mp3.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\in_mp4.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\in_nsv.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\in_swf.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\in_vorbis.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\in_wav.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\in_wave.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\in_wm.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\in_wv.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ml_addons.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ml_autotag.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ml_bookmarks.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ml_devices.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ml_disc.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ml_downloads.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ml_enqplay.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ml_history.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ml_impex.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ml_local.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ml_nowplaying.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ml_online.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ml_orb.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ml_playlists.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ml_plg.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ml_pmp.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ml_rg.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ml_transcode.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ml_wire.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\ombrowser.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\out_disk.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\out_ds.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\out_wave.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\playlist.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\pmp_activesync.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\pmp_android.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\pmp_ipod.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\pmp_njb.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\pmp_p4s.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\pmp_usb.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\pmp_wifi.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\tagz.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\vis_avs.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\vis_milk2.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\vis_nsfs.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\winamp.lng
c:\users\SEBAST~1\AppData\Local\Temp\WLZ1DF3.tmp\winampa.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\auth.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\burnlib.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\dsp_sps.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\enc_fhgaac.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\enc_flac.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\enc_lame.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\enc_vorbis.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\enc_wav.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\enc_wma.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\gen_classicart.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\gen_crasher.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\gen_ff.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\gen_find_on_disk.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\gen_hotkeys.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\gen_jumpex.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\gen_ml.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\gen_nopro.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\gen_orgler.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\gen_skinmanager.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\gen_timerestore.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\gen_tray.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\gen_undo.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\in_avi.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\in_cdda.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\in_dshow.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\in_flac.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\in_flv.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\in_linein.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\in_midi.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\in_mkv.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\in_mod.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\in_mp3.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\in_mp4.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\in_nsv.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\in_swf.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\in_vorbis.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\in_wav.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\in_wave.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\in_wm.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\in_wv.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ml_addons.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ml_autotag.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ml_bookmarks.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ml_devices.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ml_disc.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ml_downloads.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ml_enqplay.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ml_history.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ml_impex.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ml_local.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ml_nowplaying.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ml_online.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ml_orb.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ml_playlists.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ml_plg.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ml_pmp.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ml_rg.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ml_transcode.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ml_wire.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\ombrowser.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\out_disk.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\out_ds.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\out_wave.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\playlist.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\pmp_activesync.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\pmp_android.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\pmp_ipod.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\pmp_njb.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\pmp_p4s.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\pmp_usb.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\pmp_wifi.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\tagz.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\vis_avs.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\vis_milk2.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\vis_nsfs.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\winamp.lng
c:\users\***\AppData\Local\Temp\WLZ1DF3.tmp\winampa.lng
c:\windows\IsUn0407.exe
c:\windows\PFRO.log
c:\windows\system32\roboot.exe
c:\windows\unin0407.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-04-27 bis 2012-05-27 ))))))))))))))))))))))))))))))
.
.
2012-05-27 16:59 . 2012-05-27 16:59 -------- d-----w- c:\users\***\AppData\Local\temp
2012-05-27 16:59 . 2012-05-27 16:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-05-17 22:40 . 2012-05-17 22:41 -------- d-----w- c:\users\***\AppData\Local\Google
2012-05-17 22:40 . 2012-05-17 22:40 -------- d-----w- c:\program files\Google
2012-05-17 10:34 . 2012-05-17 10:46 -------- d-----w- C:\_OTL
2012-05-11 21:51 . 2012-03-30 10:23 1291632 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-05-11 21:51 . 2012-03-31 04:30 1221632 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2012-05-11 21:51 . 2012-03-31 04:29 936960 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2012-05-11 21:51 . 2012-03-31 04:29 989184 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2012-05-11 21:51 . 2012-03-31 04:29 969216 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2012-05-11 21:51 . 2012-03-31 04:39 3968368 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-11 21:51 . 2012-03-31 04:39 3913072 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-11 21:51 . 2012-03-31 02:36 2343424 ----a-w- c:\windows\system32\win32k.sys
2012-05-11 21:51 . 2012-03-17 07:27 56176 ----a-w- c:\windows\system32\drivers\partmgr.sys
2012-05-11 21:51 . 2012-03-03 05:31 1077248 ----a-w- c:\windows\system32\DWrite.dll
2012-05-09 13:33 . 2012-05-09 13:50 -------- d-----w- c:\users\***\AppData\Roaming\calibre
2012-05-09 13:33 . 2012-05-09 13:33 -------- d-----w- c:\program files\Calibre2
2012-05-09 12:41 . 2011-04-13 13:38 110992 ----a-w- c:\program files\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru\components\abhelperxpcom.dll
2012-05-09 12:41 . 2011-04-13 13:38 151952 ----a-w- c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
2012-05-09 12:41 . 2012-05-09 13:19 115369 ----a-w- c:\windows\system32\drivers\klin.dat
2012-05-09 12:41 . 2012-05-09 13:19 97961 ----a-w- c:\windows\system32\drivers\klick.dat
2012-05-09 12:40 . 2012-05-27 16:37 -------- d-----w- c:\programdata\Kaspersky Lab
2012-05-09 12:40 . 2012-05-09 12:40 -------- d-----w- c:\program files\Kaspersky Lab
2012-05-06 09:59 . 2012-05-06 09:59 -------- d-----w- c:\program files\Microsoft
2012-05-04 10:40 . 2012-04-13 07:36 6734704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{928593B5-9C99-4F39-9475-32AF45ABCC6D}\mpengine.dll
2012-05-02 00:46 . 2012-05-02 00:46 4472832 ----a-w- c:\windows\system32\GPhotos.scr
2012-04-30 20:48 . 2012-04-30 20:48 -------- d-----w- c:\programdata\OMSI AM
2012-04-30 20:48 . 2012-04-30 20:48 -------- d-----w- c:\users\***\AppData\Local\OMSI AM
2012-04-30 20:48 . 2012-04-30 20:48 -------- d-----w- c:\program files\OMSI Addon Manager
2012-04-30 20:14 . 2012-04-30 20:17 -------- d-----w- c:\program files\Verkehrs Gigant GOLD
2012-04-30 13:56 . 2012-04-30 13:56 -------- d-----w- c:\program files\Aerosoft
2012-04-29 18:54 . 2012-04-29 18:54 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-04-29 18:54 . 2012-04-29 18:54 157352 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice_installer.exe
2012-04-29 18:54 . 2012-04-29 18:54 129976 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-27 09:44 . 2011-05-03 14:50 24944 ----a-w- c:\windows\system32\drivers\GVTDrv.sys
2012-05-27 09:43 . 2011-05-04 10:08 17488 ----a-w- c:\windows\gdrv.sys
2012-05-05 13:08 . 2012-04-02 17:38 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-05 13:08 . 2011-05-29 10:07 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-03 12:17 . 2011-05-07 23:13 17488 ----a-w- c:\windows\etdrv.sys
2012-04-04 13:56 . 2011-09-23 19:51 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-05 21:24 . 2012-03-05 21:24 715038 ----a-w- c:\windows\unins000.exe
2012-03-01 05:46 . 2012-04-11 20:41 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-03-01 05:37 . 2012-04-11 20:41 172544 ----a-w- c:\windows\system32\wintrust.dll
2012-03-01 05:33 . 2012-04-11 20:41 159232 ----a-w- c:\windows\system32\imagehlp.dll
2012-03-01 05:29 . 2012-04-11 20:41 5120 ----a-w- c:\windows\system32\wmi.dll
2012-02-29 19:21 . 2012-02-29 19:21 42392 ----a-w- c:\windows\system32\xfcodec.dll
2012-02-28 05:38 . 2012-04-11 17:56 981504 ----a-w- c:\windows\system32\wininet.dll
2012-02-28 03:52 . 2012-04-11 17:56 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2012-04-29 18:54 . 2011-05-03 15:18 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"Sony PC Companion"="c:\program files\Sony\Sony PC Companion\PCCompanion.exe" [2012-03-14 446136]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCU"="c:\program files\DeviceVM\Browser Configuration Utility\BCU.exe" [2009-10-15 375000]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-07-28 9398888]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-12-09 74752]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 2213160]
"lxczbmgr.exe"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2009-04-27 74408]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-01-25 421160]
"CmCardRun"="c:\windows\system32\CmWatch.exe" [2003-09-16 229376]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-07-28 336384]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-02-28 1987976]
"HTC Sync Loader"="c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2012-04-01 634880]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Security Suite CBE 11\avp.exe" [2011-04-13 387696]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"EasyTuneVI"="c:\program files\Gigabyte\ET6\ETCall.exe" [2007-07-26 20480]
.
c:\users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office Outlook 2007.lnk - c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe [2011-5-3 845584]
OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
2011-08-01 08:28 124480 ----a-w- c:\program files\ICQ7.5\ICQ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-12-13 17:10 1688872 ----a-w- c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R0 GVTDrv;GVTDrv; [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2010-08-16 101904]
R3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [2011-07-19 225280]
R3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [x]
R3 easytether;easytether;c:\windows\system32\DRIVERS\easytthr.sys [x]
R3 etdrv;etdrv;c:\windows\etdrv.sys [2012-05-03 17488]
R3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\DRIVERS\ew_usbenumfilter.sys [2011-12-13 11136]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2011-12-27 13224]
S0 BMLoad;Bytemobile Boot Time Load Driver;c:\windows\system32\drivers\BMLoad.sys [2011-12-13 13184]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [2010-04-27 19496]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-07-16 218688]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-07-28 176128]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-07-28 291840]
S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2011-06-24 39424]
S2 BCUService;Browser Configuration Utility Service;c:\program files\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-10-15 223464]
S2 ES lite Service;ES lite Service for program management.;c:\program files\Gigabyte\EasySaver\ESSVR.EXE [2009-08-24 68136]
S3 amdiox86;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox86.sys [2010-02-18 37944]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-07-28 8396800]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-07-28 247296]
S3 AODDriver;AODDriver;c:\program files\Gigabyte\ET6\i386\AODDriver.sys [2010-03-12 36864]
.
.
Inhalt des "geplante Tasks" Ordners
.
2012-05-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 13:08]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = my.daemon-search.com
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Free YouTube to iPhone Converter - c:\users\***\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoiphoneconverter.htm
IE: Free YouTube to MP3 Converter - c:\users\***\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Hinzufügen zu Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Security Suite CBE 11\ie_banner_deny.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: Interfaces\{43B9D79D-4929-4659-B5F7-CE2EB24BE78A}: NameServer = 10.129.32.1 10.111.81.129
FF - ProfilePath - c:\users\***\AppData\Roaming\Mozilla\Firefox\Profiles\hzj3d2ey.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.simforum.de/
FF - prefs.js: network.proxy.http - 84.41.108.74
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.type - 0
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=108298
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - acbbaa260000000000001c6f6587bf84
FF - user.js: extensions.BabylonToolbar_i.hardId - acbbaa260000000000001c6f6587bf84
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15368
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.170:00
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
MSConfigStartUp-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
MSConfigStartUp-EADM - c:\program files\Origin\Origin.exe
MSConfigStartUp-Sony Ericsson PC Suite - c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
AddRemove-Adobe Photoshop 6.0 - c:\windows\ISUN0407.EXE
AddRemove-BattlEye for OA - c:\program files\Bohemia Interactive\ArmAExpansion\BattlEye\UnInstallBE.exe
AddRemove-Crysis 2 German Patch Installation 1.00 - b:\program files\Crysis2\Uninstall.exe
AddRemove-Dead Island MULTI-7 Untertitel-Patch Incl. Patch & Crack 1.2.0 für die UNLOCKED Version 1.00 - b:\program files\Black_Box\Dead Island\Uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3670287685-878628291-3504229498-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:a1,a8,fe,60,6c,53,8d,33,47,01,fb,73,26,3e,5f,ce,ca,49,93,f8,c5,10,b9,
c1,14,96,a8,a9,3c,d6,6d,e8,8b,0a,59,8f,59,18,42,50,06,ff,07,de,40,c5,5a,ff,\
"??"=hex:5d,2e,bc,00,9b,07,bc,9c,34,34,87,88,c9,ab,ca,0d
.
[HKEY_USERS\S-1-5-21-3670287685-878628291-3504229498-1000\Software\SecuROM\License information*]
"datasecu"=hex:59,15,aa,79,70,fb,a8,f6,48,68,26,a6,01,5e,38,68,c6,31,64,32,b5,
01,03,a3,05,26,62,5d,9b,3b,9a,7c,a0,47,30,2f,f4,ab,87,a2,6a,c3,3e,6f,06,6b,\
"rkeysecu"=hex:41,36,0c,57,3e,a1,e3,d1,18,7f,44,fe,e5,5d,18,70
.
[HKEY_USERS\S-1-5-21-3670287685-878628291-3504229498-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\b:\Program Files\Battlefield 3\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\imageformats]
"qgif4.dll"=multi:"2011-10-10T17:42\00gif\00\00"
"qico4.dll"=multi:"2011-10-10T17:42\00ico\00\00"
"qjpeg4.dll"=multi:"2011-10-10T17:42\00jpeg\00jpg\00\00"
.
[HKEY_USERS\S-1-5-21-3670287685-878628291-3504229498-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QTextCodecFactoryInterface:\b:\Program Files\Battlefield 3\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\codecs]
"qcncodecs4.dll"=multi:"2011-10-10T17:42\00GB18030\00GBK\00GB2312\00CP936\00MS936\00windows-936\00MIB: 114\00MIB: 113\00MIB: 2025\00\00"
"qkrcodecs4.dll"=multi:"2011-10-10T17:42\00EUC-KR\00cp949\00MIB: 38\00MIB: -949\00\00"
"qtwcodecs4.dll"=multi:"2011-10-10T17:42\00Big5\00Big5-HKSCS\00Big5-ETen\00CP950\00MIB: 2026\00MIB: 2101\00\00"
.
[HKEY_USERS\S-1-5-21-3670287685-878628291-3504229498-1000\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\b:\program files\Battlefield 3\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\codecs]
"qcncodecs4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
"qjpcodecs4.dll"=multi:"40602\000\00Windows msvc release full-config\002011-10-10T17:42\00\00"
"qjpcodecsd4.dll"=multi:"40703\001\00Windows msvc debug full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
"qkrcodecs4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
"qtwcodecs4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
.
[HKEY_USERS\S-1-5-21-3670287685-878628291-3504229498-1000\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\b:\program files\Battlefield 3\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\imageformats]
"Microsoft.VC80.CRT.manifest"=multi:"0\001\00unknown\002011-10-10T17:42\00\00"
"msvcr80.dll"=multi:"0\001\00unknown\002011-10-10T17:42\00\00"
"qgif4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
"qico4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
"qjpeg4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T17:42\00\00"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-05-27 19:10:37
ComboFix-quarantined-files.txt 2012-05-27 17:10
.
Vor Suchlauf: 13 Verzeichnis(se), 330.339.737.600 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 330.238.042.112 Bytes frei
.
- - End Of File - - 213EA6507E334592DFBB9D7D94692FC2 |