Ryder,
ich habe die Schritte ausgeführt. Eine Meldung ist gekommen, dass Avira einen Registryeintrag zu meiner Sicherheit blockiert hat, obwohl es laut Windows Sicherheitscenter (Systemsteuerung) deaktiviert war. Ich bin mir nicht sicher, ob es die Arbeit von Combofix gestört hat, da es ansonsten fehlerfrei durchgelaufen ist. Ist es in Ordnung so?
Anbei das gewünschte Logfile: Code:
ComboFix 13-04-06.02 - Marcus 06.04.2013 18:41:08.1.4 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.8190.6700 [GMT 2:00]
ausgeführt von:: c:\users\Marcus\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AV: Lavasoft Ad-Aware *Disabled/Updated* {445B48C3-0FA4-6B16-8F07-6506F305D800}
FW: Lavasoft Ad-Aware *Disabled* {7C60C9E6-45CB-6A4E-A458-CC330DD69F7B}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Lavasoft Ad-Aware *Disabled/Updated* {FF3AA927-299E-6498-B5B7-5E74888292BD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\ll0_gkp.pad
c:\windows\SysWow64\tmpEFE9.tmp
c:\windows\SysWow64\tmpF019.tmp
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-03-06 bis 2013-04-06 ))))))))))))))))))))))))))))))
.
.
2013-04-06 16:52 . 2013-04-06 16:52 -------- d-----w- c:\users\Marcus\AppData\Local\temp
2013-04-06 16:52 . 2013-04-06 16:52 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-04-06 16:52 . 2013-04-06 16:52 -------- d-----w- c:\users\PC Administrator\AppData\Local\temp
2013-04-06 16:52 . 2013-04-06 16:52 -------- d-----w- c:\users\Guest\AppData\Local\temp
2013-04-06 16:21 . 2013-04-06 16:38 -------- d-----w- C:\32788R22FWJFW
2013-04-05 14:07 . 2013-04-05 14:07 357 ----a-w- c:\windows\DeleteOnReboot.bat
2013-04-04 21:39 . 2013-04-04 21:39 -------- d-----w- c:\program files (x86)\plugins
2013-04-04 21:31 . 2013-04-04 21:31 -------- d-----w- c:\users\Marcus\AppData\Local\Macromedia
2013-04-04 21:23 . 2013-04-04 21:23 -------- d-----w- c:\users\Marcus\AppData\Roaming\RealNetworks
2013-04-04 21:22 . 2013-04-04 21:22 -------- d-----w- c:\program files (x86)\RealNetworks
2013-04-04 21:22 . 2013-04-04 21:22 -------- d-----w- c:\programdata\RealNetworks
2013-04-04 21:22 . 2013-04-04 21:22 -------- d-----w- c:\program files (x86)\Common Files\xing shared
2013-04-04 21:22 . 2013-04-04 21:22 153736 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppl3260.dll
2013-04-04 21:21 . 2013-04-04 21:21 124504 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nprpplugin.dll
2013-04-04 21:07 . 2013-04-04 21:07 -------- d-----w- c:\users\Marcus\AppData\Roaming\Avira
2013-04-04 21:04 . 2013-04-04 20:57 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-04-04 21:04 . 2013-04-04 20:57 130016 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-04-04 21:04 . 2013-04-04 20:57 100712 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-04-04 21:04 . 2013-04-04 21:04 -------- d-----w- c:\programdata\Avira
2013-04-04 21:04 . 2013-04-04 21:04 -------- d-----w- c:\program files (x86)\Avira
2013-04-04 20:44 . 2013-04-04 20:44 -------- d-----w- c:\programdata\Ubisoft
2013-04-04 16:26 . 2013-04-04 16:26 -------- d-----w- c:\programdata\McAfee
2013-04-04 16:24 . 2013-04-04 16:24 861088 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-04-04 16:24 . 2013-04-04 16:24 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-04-04 16:17 . 2013-04-04 16:17 -------- d-----w- c:\programdata\Apple
2013-04-04 16:17 . 2013-04-04 16:17 -------- d-----w- c:\program files (x86)\Apple Software Update
2013-04-04 15:24 . 2013-04-04 15:24 -------- d-----w- c:\users\Marcus\AppData\Roaming\Malwarebytes
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-04 21:55 . 2012-04-28 12:53 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-04-04 21:55 . 2012-04-28 12:53 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-04-04 21:21 . 2008-03-20 01:29 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
2013-04-04 21:21 . 2008-03-20 01:26 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
2013-04-04 16:24 . 2010-04-26 16:04 782240 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-09-12 18:38 . 2010-09-05 12:16 89048 ----a-w- c:\program files\nssutil3.dll
2011-09-12 18:38 . 2010-09-05 12:16 646104 ----a-w- c:\program files\nss3.dll
2011-09-12 18:38 . 2010-09-05 12:16 505816 ----a-w- c:\program files\sqlite3.dll
2011-09-12 18:38 . 2010-09-05 12:16 367576 ----a-w- c:\program files\nssckbi.dll
2011-09-12 18:38 . 2010-09-05 12:16 246744 ----a-w- c:\program files\updater.exe
2011-09-12 18:38 . 2010-09-05 12:16 21976 ----a-w- c:\program files\plc4.dll
2011-09-12 18:38 . 2010-09-05 12:16 203736 ----a-w- c:\program files\nspr4.dll
2011-09-12 18:38 . 2010-09-05 12:16 19416 ----a-w- c:\program files\xpcom.dll
2011-09-12 18:38 . 2010-09-05 12:16 19416 ----a-w- c:\program files\plds4.dll
2011-09-12 18:38 . 2010-09-05 12:16 16856 ----a-w- c:\program files\plugin-container.exe
2011-09-12 18:38 . 2010-09-05 12:16 166872 ----a-w- c:\program files\softokn3.dll
2011-09-12 18:38 . 2010-09-05 12:16 142296 ----a-w- c:\program files\ssl3.dll
2011-09-12 18:38 . 2010-09-05 12:16 11810264 ----a-w- c:\program files\xul.dll
2011-09-12 18:38 . 2010-09-05 12:16 105432 ----a-w- c:\program files\smime3.dll
2011-09-12 18:38 . 2010-09-05 12:16 105432 ----a-w- c:\program files\nssdbm3.dll
2011-09-12 18:38 . 2010-09-05 12:16 912344 ----a-w- c:\program files\firefox.exe
2011-09-12 18:38 . 2010-09-05 12:16 719832 ----a-w- c:\program files\mozcrt19.dll
2011-09-12 18:38 . 2010-09-05 12:16 719832 ----a-w- c:\program files\mozcpp19.dll
2011-09-12 18:38 . 2010-09-05 12:16 269272 ----a-w- c:\program files\freebl3.dll
2011-09-12 18:38 . 2010-09-05 12:16 107480 ----a-w- c:\program files\crashreporter.exe
2011-09-12 18:38 . 2010-09-05 12:16 1000920 ----a-w- c:\program files\js3250.dll
2011-09-12 18:38 . 2010-09-05 12:16 19416 ----a-w- c:\program files\AccessibleMarshal.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1555968]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-04-04 345312]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2012-4-20 1207312]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service]
@="Ad-Aware Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
.
R3 !SASCORE;SAS Core Service;c:\program files (x86)\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672]
R4 Ad-Aware Service;Ad-Aware Service;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe [2012-09-20 1236368]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Themes
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-04 15:23 1642448 ----a-w- c:\program files (x86)\Google\Chrome\Application\26.0.1410.43\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-04-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-28 21:55]
.
2013-04-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-13 19:37]
.
2013-04-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-13 19:37]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OODIIcon]
@="{14A94384-BBED-47ed-86C0-6BF63FD892D0}"
[HKEY_CLASSES_ROOT\CLSID\{14A94384-BBED-47ed-86C0-6BF63FD892D0}]
2009-06-23 06:24 129792 ----a-w- c:\program files\OO Software\DiskImage\oodishi.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 16141344]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 82464]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-05-15 7832608]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-05-15 1833504]
"CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-17 767312]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://safesearchr.lavasoft.com/?source=3336ca5f&tbp=homepage&toolbarid=adawaretb&v=2_2&u=7B368EF5B662A8E823B64A507B0CC1AC
mLocal Page = %SystemRoot%\system32\blank.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
Trusted Zone: corel.com
Trusted Zone: corel.com\www
Trusted Zone: google.de\www
Trusted Zone: intervideo.com
Trusted Zone: intervideo.com\www
Trusted Zone: microsoft.com\*.update
Trusted Zone: microsoft.com\update
Trusted Zone: microsoft.com\windowsupdate
Trusted Zone: windowsupdate.com\download
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Marcus\AppData\Roaming\Mozilla\Firefox\Profiles\bavm2oje.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://safesearchr.lavasoft.com/?source=3336ca5f&tbp=url&toolbarid=adawaretb&u=7B368EF5B662A8E823B64A507B0CC1AC&q=
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-WMPNSCFG - c:\program files (x86)\Windows Media Player\WMPNSCFG.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_bc2.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD\000.fcl"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\SysWow64\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,2b,4f,ba,e6,19,
e5,6b,af,e2,63,26,f1,3f,c8,ff,68,9f,75,e4,b4,16,34,12,2f,e2,63,26,f1,3f,c8,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\SysWow64\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,03,0a,a5,c2,31,
ee,7b,64,6a,9c,d6,61,af,45,84,18,46,a8,cb,64,3a,9c,06,ae,6a,9c,d6,61,af,45,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\SysWow64\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,10,5e,13,28,0c,
ce,47,29,ff,7c,85,e0,43,d4,0e,fe,f4,9d,34,1c,de,f5,bc,c9,ff,7c,85,e0,43,d4,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\SysWow64\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,9c,0c,08,d6,40,
ee,b5,e1,86,8c,21,01,be,91,eb,e7,46,8e,52,74,18,c3,ac,49,86,8c,21,01,be,91,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\SysWow64\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,51,77,5d,79,d7,
c3,0f,b0,f5,1d,4d,73,a8,13,5c,05,f4,35,4c,83,91,8a,5b,b0,f5,1d,4d,73,a8,13,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\SysWow64\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:50,93,e5,ab,ec,6a,4e,ab,71,0b,b2,e4,e8,
53,c3,55,df,20,58,62,78,6b,cf,c8,bb,40,bf,97,96,68,e9,7e,df,20,58,62,78,6b,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\SysWow64\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,77,e4,f2,eb,80,
33,4e,48,fb,a7,78,e6,12,2f,9a,ea,96,82,f0,49,61,bd,c8,7b,fb,a7,78,e6,12,2f,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\SysWow64\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,77,7f,97,99,33,
9b,5c,cf,01,3a,48,fc,e8,04,4a,f1,f7,03,9f,99,7d,1c,37,92,01,3a,48,fc,e8,04,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\SysWow64\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,ad,5b,34,08,5e,
45,10,07,f6,0f,4e,58,98,5b,89,c9,fc,ae,72,df,de,80,91,04,f6,0f,4e,58,98,5b,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\SysWow64\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,e9,9e,eb,de,95,
71,0c,15,3d,ce,ea,26,2d,45,aa,78,79,37,13,ec,71,e8,31,ce,3d,ce,ea,26,2d,45,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\SysWow64\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,e6,6e,3c,18,c3,
31,1a,3e,2a,b7,cc,b5,b9,7f,41,e7,9c,13,61,47,c1,0e,23,80,2a,b7,cc,b5,b9,7f,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\SysWow64\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,14,30,65,4a,fe,
76,1a,07,6c,43,2d,1e,aa,22,2f,9c,02,80,f9,d7,1c,82,1d,46,6c,43,2d,1e,aa,22,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODI03.00.00.01PRO"="4ED84CEF96A0B8F4E7B1EBC3FDB806457E5E7FFC51D34BB46CF83DDC03683399B07DCD2A8BAEB8274348C0C326E4C80C3CABD4CBDAB13220C6128F58DE0AE62462B1A93E3DAA0A0E7C4A4467542554EC527EF137A5FBC2CDA5B09182EDC893464179711513781F77CEA5CDC7DF97EE34F8CC16AA16A935ADDF7405B6C0170AAF613C8C186AA37C71AA2A098193FD72F31CF14F1302555B707EFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A9C6AECB7A5D1407A9C6AECB7A5D1407FEBC9E127BECC74C3E0A1DC695A4AEBDC6940D5D7341FD1E92E412CD07429AF27CBD637B836B9CC6E954298B2D62CC221CDDE02EF2D9133D11E7553F16177806F77AA5AB6B3E2E74329659B49EF8342E677E89FA135E037C254B17D747BACB0D96D6EE8F589DC50D40F5624583B98E07D97D8D514694171C2A1D4E55868A2106FB07C6304F9A516B2369FCB3198BC9850CB77534A359DC93DE3EF36663F4C624B110BA0BFA5A7E9E4B3EE5E7C1E8173477DECF1BE699A78CE6E48730918050CBA24ED8112595446B0E925EC3835FEAD47AF62E716DDA8DE2CA9B0D49E943141AA0EE3427411AD8C6A45AA99588917EDBD7582516BB3467A773BF883EE6692F5D5E7465A662493860AC5F11A59D354F72B5B0CF5BF6CE55A33382870FA8367E9576B708DB4398A393A7BA612D35969E731E01CA096B6CB7CC3CE91730737A26FBE2E2BB88BE919FF67B5DEB59669171F1019D38D9075FB5D2A451C88930218D798673A46157CF7250710B844EE89990AF2EAF3DFCDD8EB81769E3B576E8255F2EA4BCE88F3286291B35DA04A09CB409A6DDB28494A575EFADE9A4F6484F968B6BE46636AF95FA1588D9B946D9817D2C83AA793B393A24CCE169E9ABC1369945B7D46A3AD3F104497AD5E72DF93FA290A591A692F51ABC85AF8EDB769B94E7024E64172AFED5911D097F779DF09FE40DA3763441C7E777154A65FA7D02884CFD1CE711BD2DF6242E0017CFFEA58E1BC0441E6FFEA3EA9E3815DC166C9451A738C6974DAE482E50DBDEBC2FBEF120B00C0435778B6F8D12F12CC8D470E6D16EF4211017BDB37840CB58F4A34DA40A239315C7C127865F4508DAE0B0BD819129B9B8D18C2F4377B0E2552B121F002505C059C919983992BF0524C0F58AE0BE73D24A42A2CA40ED7350EFAB31ACB7EFFAC06C919728487E1C36BCE5491174A77DCE48A71EDA68466C8378A70D73F70C420698D82FA56D1F892F0E359D9021C18B01DAAF1B306B0E97AFF13584735EBFA6435F3EA3DF50114CC536F63ECA3E2276015B6B079DEEF37FCD154DCDB1FB748BF3F4448F2E9298BA1307D449071786AA29D74D25FB8C4EC61B4CCC6EB6583966534251DDEAC61D4076845FAF8F6CCEA899"
"OODI04.00.00.01PRO"="079169AABDC1FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A9C6AECB7A5D1407A9C6AECB7A5D1407A9C6AECB7A5D140758ED4B5D5EDDAE8A0C02CE44540FAF5C598A3EDC63B51C5AE55AD7C1B7D8BE0690248A0DD5099649D260C95B7D287BA4AFFEEE29280EBBB0ABECAA79076B63F2E2E708D09F0D7C7526A501F6EE656E4024C69F98A0EAE9933019AEA857C2DD7C09AF7D1C01BC88B1BBC436F1BD240D471371B90A55579FAE8F2D1651C1B54184FE2788B743DD09B314678F7682B77CE597450EAECF53FEC228ACFB4B6293C88084ADAA3E32AAEFC6EDE818075D68895A96BCCF0B1F544C239C4CDA3F579D4E7A9CD7C9A09ED05447CE5ABEF7EDEF21F73383157B56416DB9D4F8142F4506D58D11EBADA0DC73ED29808054F15AFC5826DAFB5B2B0B756F01FA4EEBEA53F8826C6EE605D8C6271D7210D38FF0CCB465DFB9BB809DD743038900A18A9A2D919DDC837661B237F5E13D4E808C4872AB22B4418CC8285D6C7B7915F7FB38826213B7E47FB6EE905FE2B651E6471AFCED0EC8AAEBDA733B29CF87B28CB11487EEF56A6B1ADF2237546AA3709C24DFA17A4C51EC8B427F9B271D7F14CDFE4FF2B079F4310F1AB2923AE4D7CAE8E7661CC4A31C4750EE1C2585A2C2375D9CE28194F66E99E0865D8FEC663FBF49BE4FA633FE86BC5334708A57C44560912717F27C6CFEC542A9312039235776EDB50E06A1EC8493E2C8F4FB260B8F16F69E0B893CF8642099EE133861F5B2D63B3FEC7EDEA01D538149F7306CA13D24CAE8330E9EE1EFD2832239D09ADBF68DC9B28759AC71EC4DE2B31CE39CD77F18FE4C544B5E9006CFCE752FE49077DE0C66C94FE4C25AA012F0EB5652972299473BF50C122E92A1C9007DD6F7DF8E3989902309734D787DF7CABAEFC038986447D9F746B433174EB94EB4630C1C8AE77BFE414C596A915B1940490875C8764CF468C3C58B84F42E5BA4775BAB49FA61A2970A08F02C89A354D6A88FBA899BD0EC2B34A3733123F62F22879BE1E38FAFFD7848FA179BEDD54A49CBCB5F2F8D87141784C9C93A4070F91C8A5340571FEFD2F12ABAAEB26B0762840958B4E1F19791D6D4F5F2928BF942988907DB87A4562B0843AF1CDF565C46A99D21933C17BDCF4AAABB57256B035653730DCC49BBA8547408184A86A512E40FA768D550E94AFE82ED8162CE6891C33D17932FE6A8C0DDA2D382A6FEF3F7EFBD2BC359A0012291466A0383602F3FE0F72B97A49FCF8C9EB2E55522937FF0DCF28F1E0225923BBE90514DAE1F113944DC4AEED0A3BA10AEFADEC832022CF3E5209F34354B7B240110B644DBC2023FCBF470C0DD1B195FEB82C6E952FE000C8BEB0B195EF1BB7D18A61320857A9BA99681FD08779D3CA57606"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
Zeit der Fertigstellung: 2013-04-06 18:55:18
ComboFix-quarantined-files.txt 2013-04-06 16:55
.
Vor Suchlauf: 8 Verzeichnis(se), 402.902.335.488 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 404.383.522.816 Bytes frei
.
- - End Of File - - 2189FAF96EAF6448AF53FF39C0113216 Vielen Dank für deine Hilfe! |