Logs:
Combofix Logfile: Code:
ComboFix 12-10-04.02 - Henza 04.10.2012 16:40:34.1.3 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.4094.2802 [GMT 2:00]
ausgeführt von:: c:\users\Henza\Desktop\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Henza\AppData\Roaming\Microsoft\Windows\Recent\PaulsConversionAndEarlyTravels_1.mat
c:\windows\SysWow64\setup.ini
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-09-04 bis 2012-10-04 ))))))))))))))))))))))))))))))
.
.
2012-10-04 14:44 . 2012-10-04 14:44 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-10-04 13:34 . 2012-10-04 13:34 -------- d-----w- C:\_OTL
2012-10-03 16:56 . 2012-10-03 16:56 -------- d-----w- c:\program files (x86)\ESET
2012-10-03 16:41 . 2012-10-03 16:41 -------- d-----w- c:\users\Henza\AppData\Roaming\Avira
2012-10-03 16:36 . 2012-09-24 07:58 27800 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-10-03 16:36 . 2012-09-13 13:52 99248 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-10-03 16:36 . 2012-09-13 13:52 129576 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-10-03 16:36 . 2012-10-03 16:36 -------- d-----w- c:\programdata\Avira
2012-10-03 16:36 . 2012-10-03 16:36 -------- d-----w- c:\program files (x86)\Avira
2012-10-03 15:05 . 2012-10-03 15:05 -------- d-----w- c:\users\Henza\AppData\Roaming\Malwarebytes
2012-10-03 15:05 . 2012-10-03 15:05 -------- d-----w- c:\programdata\Malwarebytes
2012-10-03 15:05 . 2012-10-03 15:05 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-10-03 15:05 . 2012-09-07 15:04 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-10-02 14:34 . 2012-08-30 07:27 9308616 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F5EB0067-80DC-4C22-A684-181212197C20}\mpengine.dll
2012-09-26 12:16 . 2012-08-21 21:01 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
2012-09-25 12:25 . 2012-09-25 12:25 -------- d-----w- c:\users\Tina\AppData\Roaming\Apple Computer
2012-09-20 19:19 . 2012-09-20 19:19 -------- d-----w- c:\users\Henza\AppData\Roaming\Apple Computer
2012-09-20 15:29 . 2012-09-20 15:29 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-09-20 15:29 . 2012-09-20 15:29 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-09-20 15:29 . 2012-09-20 15:29 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-09-20 15:29 . 2012-09-20 15:29 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-09-20 15:29 . 2012-09-20 15:29 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-09-20 15:29 . 2012-09-20 15:29 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-09-20 15:29 . 2012-09-20 15:29 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-09-20 15:29 . 2012-09-20 15:29 -------- d-----w- c:\program files (x86)\QuickTime
2012-09-20 15:29 . 2012-09-20 15:29 -------- d-----w- c:\programdata\Apple Computer
2012-09-20 15:28 . 2012-09-20 15:28 -------- d-----w- c:\program files (x86)\Common Files\Apple
2012-09-20 15:28 . 2012-09-20 15:28 -------- d-----w- c:\users\Henza\AppData\Local\Apple
2012-09-20 15:28 . 2012-09-20 15:28 -------- d-----w- c:\programdata\Apple
2012-09-20 15:28 . 2012-09-20 15:28 -------- d-----w- c:\program files (x86)\Apple Software Update
2012-09-12 12:51 . 2012-08-22 18:12 950128 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-09-12 12:51 . 2012-07-04 20:26 41472 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-12 12:51 . 2012-08-02 17:58 574464 ----a-w- c:\windows\system32\d3d10level9.dll
2012-09-12 12:51 . 2012-08-02 16:57 490496 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2012-09-12 12:51 . 2012-08-22 18:12 1913200 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-12 12:51 . 2012-08-22 18:12 376688 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-12 12:51 . 2012-08-22 18:12 288624 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-03 16:12 . 2011-06-10 23:51 30528 ----a-w- c:\windows\GVTDrv64.sys
2012-10-03 16:12 . 2011-06-10 23:50 25640 ----a-w- c:\windows\gdrv.sys
2012-09-20 17:20 . 2012-03-30 07:32 696240 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-09-20 17:20 . 2011-06-06 23:00 73136 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-09-15 12:11 . 2011-06-10 13:44 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2012-09-12 16:37 . 2011-06-07 16:03 64462936 ----a-w- c:\windows\system32\MRT.exe
2012-07-18 18:15 . 2012-08-15 11:04 3148800 ----a-w- c:\windows\system32\win32k.sys
2012-07-14 17:14 . 2012-07-14 17:14 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2012-07-14 14:31 . 2011-06-10 23:51 25640 ----a-w- c:\windows\etdrv.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\users\Henza\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\users\Henza\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\users\Henza\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\users\Henza\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"PivotSoftware"="c:\program files (x86)\Portrait Displays\Pivot Software\wpctrl.exe" [2009-03-03 694824]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-09-25 386336]
.
c:\users\Henza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Henza\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-7-25 26909544]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R1 ntiomin;ntiomin; [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-20 250288]
R3 ALSysIO;ALSysIO;c:\users\Henza\AppData\Local\Temp\ALSysIO64.sys [x]
R3 AODDriver;AODDriver;c:\program files (x86)\GIGABYTE\ET6\amd64\AODDriver.sys [2010-03-12 52280]
R3 DrvAgent64;DrvAgent64;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS [2011-06-07 21712]
R3 etdrv;etdrv;c:\windows\etdrv.sys [2012-07-14 25640]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2012-10-03 30528]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-07 114144]
R3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2011.SP4c\RpcAgentSrv.exe [2008-08-14 93848]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2012-09-24 27800]
S1 Uim_VIM;UIM Virtual Image Plugin;c:\windows\system32\Drivers\uim_vimx64.sys [2011-11-17 352816]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-09-25 84256]
S2 PdiService;Portrait Displays SDK Service;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2009-12-17 109168]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-05-15 382272]
S3 netr28ux;RT2870 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr28ux.sys [2009-09-15 1061888]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2011-03-03 174184]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-11-11 408680]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-04-03 34872]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
Inhalt des "geplante Tasks" Ordners
.
2012-10-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 17:20]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 97792 ----a-w- c:\users\Henza\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 97792 ----a-w- c:\users\Henza\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 97792 ----a-w- c:\users\Henza\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 97792 ----a-w- c:\users\Henza\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1680976]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-06-11 12503184]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Free YouTube Download - c:\users\Henza\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to MP3 Converter - c:\users\Henza\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Henza\AppData\Roaming\Mozilla\Firefox\Profiles\uwjav3ui.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - prefs.js: network.proxy.type - 0
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0d9d5966-218b-11e1-8097-6cf04979d4d4}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0d9d596a-218b-11e1-8097-6cf04979d4d4}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0daf3ba0-4d00-11e1-86b4-6cf04979d4d4}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{204ab306-3d6f-11e1-8241-6cf04979d4d4}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{49f4b9a6-9864-11e1-a86c-6cf04979d4d4}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5536e596-a7e1-11e0-a383-6cf04979d4d4}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{582cd24f-4110-11e1-b0a6-6cf04979d4d4}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{582cd259-4110-11e1-b0a6-6cf04979d4d4}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5daf2f43-903f-11e0-b513-806e6f6e6963}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5daf2f44-903f-11e0-b513-806e6f6e6963}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5daf2f44-903f-11e0-b513-806e6f6e6963}\shell]
@DACL=(02 0000)
@="None"
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5daf2f45-903f-11e0-b513-806e6f6e6963}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5daf2f46-903f-11e0-b513-806e6f6e6963}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5daf2f5c-903f-11e0-b513-806e6f6e6963}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5ec76a3a-f9b7-11e1-ae67-806e6f6e6963}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{68e340de-41d6-11e1-ab0e-806e6f6e6963}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{68e340df-41d6-11e1-ab0e-806e6f6e6963}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7092b517-af86-11e0-a514-6cf04979d4d4}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8fbb30ad-a6f3-11e0-b86e-6cf04979d4d4}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8fdf1afa-2e25-11e1-8288-6cf04979d4d4}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a4e37d25-a480-11e0-88a9-6cf04979d4d4}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cc9d4b41-1cc6-11e1-b805-6cf04979d4d4}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cd112736-3d2f-11e1-ada4-6cf04979d4d4}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cd11273a-3d2f-11e1-ada4-6cf04979d4d4}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cd11273c-3d2f-11e1-ada4-6cf04979d4d4}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f2bc9d26-d896-11e0-a06e-6cf04979d4d4}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fc749272-9610-11e0-9fc1-6cf04979d4d4}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:b4,6a,f2,0b,44,7a,8e,6c,34,03,f9,3d,ff,dc,36,c1,29,f1,54,07,6b,42,62,
0d,f7,14,cb,c7,79,dd,3c,fe,aa,51,41,ae,88,b3,15,84,f3,2b,01,19,55,cf,eb,86,\
"??"=hex:5d,2e,bc,00,9b,07,bc,9c,34,34,87,88,c9,ab,ca,0d
.
[HKEY_USERS\S-1-5-21-1310969408-53706401-2217804473-1000\Software\SecuROM\License information*]
"datasecu"=hex:0f,0d,50,50,b1,12,fa,59,e9,1c,58,08,39,cb,e8,b5,c7,1f,de,a2,34,
16,4d,a4,55,97,23,4f,8b,19,b1,5e,e3,25,9f,2d,c0,db,f5,df,8d,69,29,93,4a,bd,\
"rkeysecu"=hex:d6,65,ad,e9,2b,f4,a0,77,91,d7,fb,9d,b8,cc,11,b1
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\OldTimer Tools\OTL\Files]
@DACL=(02 0000)
"h:\\autorun.exe"=""
"h:\\autorun.inf"=""
"c:\\$Recycle.Bin\\LocalSystem"=""
"c:\\Users\\Henza\\AppData\\Local\\Temp\\FXSAPIDebugLogFile.txt"=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\Security]
@DACL=(02 0000)
@SACL=
"Security"=hex:01,00,14,80,90,00,00,00,a0,00,00,00,14,00,00,00,34,00,00,00,02,
00,20,00,01,00,00,00,02,c0,18,00,00,00,0c,00,01,02,00,00,00,00,00,05,20,00,\
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-10-04 16:50:00 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2012-10-04 14:50
.
Vor Suchlauf: 13 Verzeichnis(se), 87.092.428.800 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 86.545.612.800 Bytes frei
.
- - End Of File - - 45E25588D1DE385ACDD4AF6C2C968C6E [/CODE]
--- --- ---
Komisch das es noch reste von Avast gab, die ihn gestört haben, obwohl ich es deinstalliert hette mit dem Tool. |