Alle Ratschläge befolgt.
Hier das Log:
Combofix Logfile: Code:
ComboFix 10-07-22.01 - *** 22.07.2010 22:02:45.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.2045.1317 [GMT 2:00]
ausgeführt von:: c:\users\***\Desktop\cofi.exe
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows-Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.dll
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.drv
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\cid.sys
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\CLSV.drv
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\CLSV.tmp
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\DBOLE.dll
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\DBOLE.tmp
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\delfile.drv
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\dudl.tmp
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\eb.drv
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\eb.sys
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\energy.dll
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\energy.drv
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\energy.exe
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\exec.exe
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\exec.tmp
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\fan.tmp
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\fix.dll
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\FW.dll
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\FW.drv
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\gid.exe
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\grid.tmp
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\hymt.sys
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\kernel32.dll
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\kernel32.drv
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\kernel32.exe
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\kernel32.tmp
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\pal.sys
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\PE.dll
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\PE.exe
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\PE.tmp
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\ppal.dll
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\runddl.dll
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\runddl.tmp
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\sld.drv
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\sld.exe
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\std.dll
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\tjd.drv
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\tjd.sys
c:\windows\system32\st325614.dll
.
((((((((((((((((((((((((((((((((((((((( Treiber/Dienste )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_Boonty Games
((((((((((((((((((((((( Dateien erstellt von 2010-06-22 bis 2010-07-22 ))))))))))))))))))))))))))))))
.
2010-07-22 18:26 . 2010-07-22 18:26 -------- d-----w- C:\_OTL
2010-07-19 12:28 . 2010-07-19 15:33 -------- d-----w- c:\program files\trend micro
2010-07-19 12:28 . 2010-07-19 12:31 -------- d-----w- C:\rsit
2010-07-19 12:26 . 2010-07-19 12:26 -------- d-----w- c:\program files\CCleaner
2010-07-19 11:52 . 2010-07-19 11:52 -------- d-----w- c:\users\***\AppData\Roaming\Malwarebytes
2010-07-19 11:52 . 2010-04-29 10:19 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-19 11:52 . 2010-07-19 11:52 -------- d-----w- c:\programdata\Malwarebytes
2010-07-19 11:52 . 2010-07-19 11:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-19 11:52 . 2010-04-29 10:19 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-18 21:44 . 2010-07-18 21:45 -------- d-----w- c:\programdata\Exorcist DS
2010-07-18 18:22 . 2010-07-19 15:27 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-07-18 18:22 . 2010-07-18 18:28 -------- d-----w- c:\program files\Spybot - Search & Destroy
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-22 20:16 . 2008-05-30 11:32 12 ----a-w- c:\windows\bthservsdp.dat
2010-07-22 18:05 . 2008-07-02 09:49 -------- d-----w- c:\users\***\AppData\Roaming\ICQ
2010-07-20 13:16 . 2009-05-30 20:18 -------- d-----w- c:\users\***\AppData\Roaming\Skype
2010-07-20 12:16 . 2008-07-05 13:36 -------- d-----w- c:\users\***\AppData\Roaming\ICQ
2010-07-20 12:16 . 2009-05-30 20:19 -------- d-----w- c:\users\***\AppData\Roaming\skypePM
2010-07-19 11:42 . 2009-08-14 21:32 -------- d-----w- c:\program files\Avira
2010-07-18 21:42 . 2010-04-20 20:55 -------- d-----w- c:\program files\DEUTSCHLAND SPIELT
2010-07-15 18:30 . 2010-07-15 18:30 20 ----a-w- c:\users\***\AppData\Roaming\hwzypv.dat
2010-07-07 08:18 . 2008-06-16 19:16 11914 ----a-w- c:\users\***\AppData\Roaming\wklnhst.dat
2010-07-04 13:27 . 2009-02-25 14:48 -------- d-----r- c:\program files\Skype
2010-07-04 10:18 . 2009-09-09 18:23 -------- d-----w- c:\program files\ICQ6.5
2010-06-26 11:47 . 2009-02-25 14:48 -------- d-----w- c:\users\***\AppData\Roaming\Skype
2010-06-26 11:45 . 2009-02-25 14:50 -------- d-----w- c:\users\***\AppData\Roaming\skypePM
2010-06-23 14:11 . 2008-05-30 17:55 -------- d-----w- c:\programdata\Roxio
2010-06-23 14:01 . 2006-11-02 15:33 618442 ----a-w- c:\windows\system32\perfh007.dat
2010-06-23 14:01 . 2006-11-02 15:33 122648 ----a-w- c:\windows\system32\perfc007.dat
2010-06-21 15:21 . 2010-06-21 15:21 -------- d-----w- c:\users\***\AppData\Roaming\ProtectDisc
2010-06-12 19:37 . 2010-06-12 19:37 -------- d-----w- c:\users\***\AppData\Roaming\UNOUndercover
2010-06-12 19:37 . 2010-03-28 22:06 -------- d-----w- c:\users\***\AppData\Roaming\Zylom
2010-06-09 18:53 . 2010-01-20 19:58 -------- d-----w- c:\program files\ICQ7.0
2010-06-05 18:51 . 2010-06-05 18:51 -------- d-----w- c:\users\***\AppData\Roaming\Octoshape
2010-05-21 12:14 . 2009-10-03 23:40 221568 ------w- c:\windows\system32\MpSigStub.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-05-30 17:44 . 2008-05-30 17:44 76 --sh--r- c:\windows\CT4CET.bin
2007-02-22 01:55 . 2007-02-22 01:55 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ICQ"="c:\program files\ICQ7.0\ICQ.exe" [2010-06-08 133368]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-05-09 36864]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-09-13 405504]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-3-14 110592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Users^***^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CurseClientStartup.ccip]
path=c:\users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
backup=c:\windows\pss\CurseClientStartup.ccip.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 00:04 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
2008-03-20 16:46 217544 ----a-w- c:\program files\Alcohol Soft\Alcohol 120\AxCmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
2007-07-02 11:29 159744 ----a-w- c:\program files\DellTPad\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2008-07-24 15:02 490952 ----a-w- c:\program files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DELL Webcam Manager]
2007-07-27 14:43 118784 ------w- c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-19 07:33 125952 ----a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
2009-11-16 15:36 172792 ----a-w- c:\program files\ICQ6.5\ICQ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
2006-07-11 10:15 3144800 ------w- c:\program files\ICQLite\ICQLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2006-10-03 09:35 221184 ----a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2006-10-03 09:37 81920 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 15:33 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-02-22 03:46 13515296 ----a-w- c:\windows\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVHotkey]
2008-02-22 03:46 92704 ----a-w- c:\windows\System32\nvhotkey.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-02-22 03:46 92704 ----a-w- c:\windows\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
2008-02-22 03:46 166432 ----a-w- c:\windows\System32\nvsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Octoshape Streaming Services]
2009-01-08 13:44 70936 ----a-w- c:\users\***\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEM02Mon.exe]
2007-05-09 15:01 36864 ----a-w- c:\windows\OEM02Mon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2007-11-01 13:39 189736 ------w- c:\program files\Dell\MediaDirect\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
2006-11-05 09:22 221184 ----a-w- c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-07-14 17:04 1217784 ----a-w- c:\program files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"VistaSp2"=hex(b):ba,a8,f4,4d,53,e5,c9,01
R2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [x]
R2 gupdate1cacec2fe26d700;Google Update Service (gupdate1cacec2fe26d700);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-28 133104]
R3 GarenaPEngine;GarenaPEngine;c:\users\***\AppData\Local\Temp\FKS6EA4.tmp [x]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2008-09-10 717296]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2007-09-20 73728]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [2009-08-24 185640]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Inhalt des "geplante Tasks" Ordners
2010-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-28 22:06]
2010-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-28 22:06]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://start.icq.com/
uInternet Settings,ProxyOverride = *.local
DPF: {226ACC34-3194-40E2-9AE8-834FCFE9E80D} - hxxp://games.bigfishgames.com/en_mysteryofsharkisla/online/MysteryOfSharkIslandWeb.1.0.0.8.cab
DPF: {7D4733C0-C43B-4A81-AF43-F9B20D1F8348} - hxxp://www.octoshape.com/files/octosetupGotFrag.cab
FF - ProfilePath - c:\users\***\AppData\Roaming\Mozilla\Firefox\Profiles\3ejtw2ll.default\
FF - prefs.js: browser.startup.homepage - hxxp://start.icq.com/skins/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\programdata\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX Richtlinien ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
WebBrowser-{ECDEE021-0D17-467F-A1FF-C7A115230949} - (no file)
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2010-07-22 22:17
Windows 6.0.6002 Service Pack 2 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\users\***\AppData\Local\Temp\FKS6EA4.tmp"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
[HKEY_USERS\S-1-5-21-1666829011-3442692542-773869868-1000\Software\SecuROM\License information*]
"datasecu"=hex:83,4f,60,f8,d8,64,53,8d,f1,15,f6,39,d7,09,ab,1f,a2,52,f7,4f,0b,
82,39,cb,28,df,39,22,bc,2d,a3,03,9f,89,49,97,e9,08,e3,53,8b,d0,1a,97,f0,32,\
"rkeysecu"=hex:c7,39,b3,04,40,b2,dc,0e,d5,1b,66,62,43,cf,8e,5a
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
- - - - - - - > 'Explorer.exe'(3044)
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\WLANExt.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\STacSV.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\system32\conime.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2010-07-22 22:29:00 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2010-07-22 20:28
Vor Suchlauf: 18 Verzeichnis(se), 36.455.649.280 Bytes frei
Nach Suchlauf: 21 Verzeichnis(se), 36.099.608.576 Bytes frei
- - End Of File - - 92963641832D06A61974DDA8D81CE3FE --- --- --- |