Combofix Teil2: Code:
((((((((((((((((((((((((((((( SnapShot@2010-07-29_16.18.02 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-07-29 21:28 . 2010-07-29 21:28 16384 c:windowsTempPerflib_Perfdata_684.dat
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerURLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\programme\Vuze_Remote\tbVuze.dll" [2010-04-15 2515552]
[HKEY_CLASSES_ROOTclsid{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_LOCAL_MACHINE~Browser Helper Objects{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2010-04-15 10:33 2515552 ----a-w- c:programmeVuze_RemotetbVuze.dll
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\programme\Vuze_Remote\tbVuze.dll" [2010-04-15 2515552]
[HKEY_CLASSES_ROOTclsid{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerToolbarWebbrowser]
"{BA14329E-9550-4989-B3F2-9732E92D17CC}"= "c:\programme\Vuze_Remote\tbVuze.dll" [2010-04-15 2515552]
[HKEY_CLASSES_ROOTclsid{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"DAEMON Tools Lite"="c:\programme\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"Jet Detection"="c:\sbaudigy\PROGRAM\ADGJDet.exe" [2001-10-03 28672]
"CTStartup"="c:\programme\Creative\Splash Screen\CTEaxSpl.EXE" [2001-12-19 28672]
"Profiler"="c:\programme\Saitek\Software\Profiler.exe" [2004-10-20 159744]
"SaiSmart"="c:\programme\Saitek\Software\SaiSmart.exe" [2004-10-20 98304]
"SaiMfd"="c:\programme\Saitek\Software\SaiMfd.exe" [2004-10-20 135168]
"LifeCam"="c:\programme\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"avgnt"="c:\programme\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
"RivaTunerStartupDaemon"="c:\benchmarks\RivaTuner v2.09\RivaTuner.exe" [2008-04-28 2707456]
"ISUSPM Startup"="c:\programme\Gemeinsame Dateien\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"VX1000"="c:\windows\vVX1000.exe" [2007-04-10 709992]
"AppleSyncNotifier"="c:\programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"GrooveMonitor"="c:\programme\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"QuickTime Task"="c:\programme\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\itunes\iTunesHelper.exe" [2009-10-28 141600]
"Adobe Reader Speed Launcher"="c:\programme\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-07-17 55824]
"NvMediaCenter"="NvMCTray.dll" [2010-04-03 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-03 13670504]
"DivXUpdate"="c:\programme\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalWdfLoadGroup]
@=""
[HKLM~startupfolderC:^Dokumente und Einstellungen^Akki^Startmenü^Programme^Autostart^OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk]
path=c:dokumente und einstellungenAkkiStartmenüProgrammeAutostartOneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
backup=c:windowspssOneNote 2007 Bildschirmausschnitt- und Startprogramm.lnkStartup
[HKLM~startupfolderC:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Adobe Gamma Loader.lnk]
path=c:dokumente und einstellungenAll UsersStartmenüProgrammeAutostartAdobe Gamma Loader.lnk
backup=c:windowspssAdobe Gamma Loader.lnkCommon Startup
[HKLM~startupfolderC:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^ASUS WiFi-AP Solo.lnk]
path=c:dokumente und einstellungenAll UsersStartmenüProgrammeAutostartASUS WiFi-AP Solo.lnk
backup=c:windowspssASUS WiFi-AP Solo.lnkCommon Startup
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAdobe Reader Speed Launcher]
2010-06-20 02:04 35760 ----a-w- c:programmeAdobeReader 9.0Readerreader_sl.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregBgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-08-03 10:51 202024 ----a-w- c:programmeGemeinsame DateienNeroLibNMBgMonitor.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregCTHelper]
2009-03-04 10:45 19456 ----a-w- c:windowssystem32CtHelper.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregCTxfiHlp]
2006-08-11 12:56 18944 ----a-w- c:windowssystem32CTXFIHLP.EXE
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregGrooveMonitor]
2008-10-25 09:44 31072 ----a-w- c:programmeMicrosoft OfficeOffice12GrooveMonitor.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNBKeyScan]
2007-08-08 07:25 1828136 ----a-w- c:brennprogrammeNero 8Nero BackItUpNBKeyScan.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNeroFilterCheck]
2007-03-01 13:57 153136 ----a-w- c:programmeGemeinsame DateienNeroLibNeroCheck.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNvMediaCenter]
2010-04-03 17:23 110696 ----a-w- c:windowssystem32nvmctray.dll
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregPowerStrip]
2007-07-14 09:35 730360 ----a-w- c:benchmarksPowerStripPStrip.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregRivaTunerStartupDaemon]
2009-02-25 17:55 2781184 ----a-w- c:programmeRivaTuner v2.24RivaTuner.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSunJavaUpdateSched]
2009-03-09 03:19 148888 ----a-w- c:programmeJavajre6binjusched.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregVX1000]
2007-04-10 21:46 709992 ----a-w- c:windowsvVX1000.exe
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programme\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programme\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programme\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"e:\\IL-2 Sturmovik 1946\\il2fb.exe"=
"e:\\Pro Evolution Soccer 2008\\PES2008.exe"=
"c:\\Programme\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Programme\\Microsoft LifeCam\\LifeExp.exe"=
"e:\\World Series of Poker TOC\\WSOPTOC.exe"=
"e:\\Theatre Of War\\ToW.exe"=
"f:\\T34vsTiger\\TvsT.exe"=
"c:\\Programme\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Programme\\Azureus\\Azureus.exe"=
"e:\\Dead Space\\Dead Space.exe"=
"c:\\Programme\\Bonjour\\mDNSResponder.exe"=
"e:\\Batman Arkham Asylum\\Binaries\\ShippingPC-BmGame.exe"=
"e:\\Rome - Total War\\RomeTW-ALX.exe"=
"f:\\Pro Evolution Soccer 2010\\pes2010.exe"=
"c:\\iTunes\\iTunes.exe"=
"c:\\Programme\\Skype\\Phone\\Skype.exe"=
"f:\\Dragon Age\\bin_ship\\daorigins.exe"=
"f:\\Dragon Age\\DAOriginsLauncher.exe"=
"f:\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"e:\\ANNO 1404\\tools\\Anno4Web.exe"=
"f:\\Assassins Creed 2\\AssassinsCreedIIGame.exe"=
"f:\\Assassins Creed 2\\AssassinsCreedII.exe"=
"f:\\Assassins Creed 2\\UPlayBrowser.exe"=
"c:\\Programme\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"e:\\Tom Clancy's Splinter Cell Conviction\\src\\system\\conviction_game.exe"=
"e:\\Tom Clancy's Splinter Cell Conviction\\src\\system\\gu.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Planer;c:programmeAviraAntiVir Desktopsched.exe [17.03.2009 19:59 135336]
R2 PStrip;PSTRIP;c:windowssystem32driverspstrip.sys [15.07.2007 03:37 27992]
R3 COMMONFX.SYS;COMMONFX.SYS;c:windowssystem32driversCOMMONFX.sys [04.03.2009 14:42 99352]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:windowssystem32driversCTAUDFX.sys [04.03.2009 14:42 555032]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:windowssystem32driversCTSBLFX.sys [04.03.2009 14:42 566296]
R3 npusbio;npusbio;c:windowssystem32driversnpusbio.sys [27.09.2009 15:45 36384]
S3 COMMONFX;COMMONFX;c:windowssystem32driversCOMMONFX.sys [04.03.2009 14:42 99352]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:programmeGemeinsame DateienCreative Labs SharedServiceCTAELicensing.exe [20.04.2009 16:46 79360]
S3 CTAUDFX;CTAUDFX;c:windowssystem32driversCTAUDFX.sys [04.03.2009 14:42 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:windowssystem32driversCTERFXFX.sys [04.03.2009 14:42 100888]
S3 CTERFXFX;CTERFXFX;c:windowssystem32driversCTERFXFX.sys [04.03.2009 14:42 100888]
S3 CTSBLFX;CTSBLFX;c:windowssystem32driversCTSBLFX.sys [04.03.2009 14:42 566296]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;f:dragon agebin_shipdaupdatersvc.service.exe [13.11.2009 14:22 25832]
S3 NPUSB;NPUSB;c:windowssystem32driversnpusb.sys [06.05.2008 19:41 15360]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:windowssystem32driversRTL8187.sys [02.05.2008 18:50 176128]
S3 SaiH0255;SaiH0255;c:windowssystem32driversSaiH0255.sys [05.05.2008 19:57 121984]
S4 sptd;sptd;c:windowssystem32driverssptd.sys [03.05.2008 19:42 691696]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSvchost - NetSvcs
UxTuneUp
.
Inhalt des "geplante Tasks" Ordners
2010-07-29 c:windowsTasks1-Klick-Wartung.job
- c:zusatzTuneUp Utilities 2008OneClickStarter.exe [2008-05-03 16:47]
2008-07-21 c:windowsTasksMicrosoft_Hardware_Launch_LifeExp_exe.job
- c:programmeMicrosoft LifeCamLifeExp.exe [2007-05-17 21:45]
2010-01-01 c:windowsTasksMicrosoft_Hardware_Launch_vVX1000_exe.job
- c:windowsvVX1000.exe [2008-07-21 21:46]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.dufpy.com
uInternet Settings,ProxyOverride = *.local
IE: Nach Microsoft E&xel exportieren - c:progra~1MICROS~2Office12EXCEL.EXE/3000
TCP: {C003CB0F-22D1-4F0A-BB98-4F63CBB89F02} = 192.168.2.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:dokumente und einstellungenAkkiAnwendungsdatenMozillaFirefoxProfiles0dkdlpsc.default
FF - prefs.js: browser.search.selectedEngine - eBay
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - component: c:dokumente und einstellungenAkkiAnwendungsdatenMozillaFirefoxProfiles0dkdlpsc.defaultextensions{ba14329e-9550-4989-b3f2-9732e92d17cc}componentsFFExternalAlert.dll
FF - component: c:dokumente und einstellungenAkkiAnwendungsdatenMozillaFirefoxProfiles0dkdlpsc.defaultextensions{ba14329e-9550-4989-b3f2-9732e92d17cc}componentsRadioWMPCore.dll
FF - plugin: c:itunesMozilla Pluginsnpitunes.dll
FF - plugin: c:programmeDivXDivX Plus Web Playernpdivx32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:windowsMicrosoft.NETFrameworkv3.5Windows Presentation FoundationDotNetAssistantExtension
---- FIREFOX Richtlinien ----
c:firefoxgreprefsall.js - pref("ui.use_native_colors", true);
c:firefoxgreprefsall.js - pref("network.IDN.whitelist.lu", true);
c:firefoxgreprefsall.js - pref("network.IDN.whitelist.nu", true);
c:firefoxgreprefsall.js - pref("network.IDN.whitelist.nz", true);
c:firefoxgreprefsall.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:firefoxgreprefsall.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:firefoxgreprefsall.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:firefoxgreprefsall.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:firefoxgreprefsall.js - pref("network.IDN.whitelist.tel", true);
c:firefoxgreprefsall.js - pref("network.auth.force-generic-ntlm", false);
c:firefoxgreprefsall.js - pref("network.proxy.type", 5);
c:firefoxgreprefsall.js - pref("network.buffer.cache.count", 24);
c:firefoxgreprefsall.js - pref("network.buffer.cache.size", 4096);
c:firefoxgreprefsall.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:firefoxgreprefsall.js - pref("svg.smil.enabled", false);
c:firefoxgreprefsall.js - pref("accelerometer.enabled", true);
c:firefoxgreprefssecurity-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:firefoxgreprefssecurity-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:firefoxgreprefssecurity-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:firefoxgreprefssecurity-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:firefoxdefaultspreffirefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:firefoxdefaultspreffirefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:firefoxdefaultspreffirefox.js - pref("plugins.update.notifyUser", false);
c:firefoxdefaultspreffirefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:firefoxdefaultspreffirefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:firefoxdefaultspreffirefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:firefoxdefaultspreffirefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:firefoxdefaultspreffirefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2010-07-29 23:31
Windows 5.1.2600 Service Pack 3 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
CTStartup = c:programmeCreativeSplash ScreenCTEaxSpl.EXE /run???????h??????s??????w? ?w???????w???w4???????.??w4???????4???TA?s4????????&????????? ??? ?????????????????5?7~e?7~????????????a??????C@??????????s??????????s????&??A??s?&???C@?x???`|?w\?????@
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
[HKEY_USERS\S-1-5-21-1757981266-2077806209-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:61,9a,53,c6,fc,3e,90,20,ff,63,d9,4f,bc,bc,a7,8a,82,47,45,c9,36,e5,23,
aa,ae,b8,43,31,5e,ad,3d,ed,77,a0,6e,e2,a3,f0,54,67,d5,9b,c6,5d,b6,b8,52,42,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
[HKEY_USERS\S-1-5-21-1757981266-2077806209-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:b9,45,04,a4,06,3a,2a,79,a0,ec,ad,3a,25,de,f5,66,df,77,d1,7c,5f,
08,64,3d,3f,23,5e,76,bf,26,99,b7,48,da,4a,07,f9,6d,bf,2c,f3,04,95,3b,89,5c,\
"rkeysecu"=hex:c2,cf,3b,ed,e8,ef,68,03,0c,90,9a,71,fa,62,8e,8b
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \D25BC253F035D347]
"1"=hex:6a,0b,56,13,c1,93,dc,9c,fb,61,a2,a0,e4,ff,91,20,60,bf,2f,c2,35,91,ae,
25
"2"=hex:fb,e6,50,7f,41,f4,51,a7,7f,ec,2d,f9,42,45,3a,02,3a,b7,45,15,3f,9d,8b,
c3
"3"=hex:6a,0b,56,13,c1,93,dc,9c,fb,61,a2,a0,e4,ff,91,20,5d,f5,58,d1,21,e0,48,
8b,38,57,44,9c,4e,8d,78,88,fd,f1,01,9d,86,d8,b5,cb,d9,bf,23,55,4a,bb,31,1f
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \D25BC253F035D347\0BB4AB33ED50D261F5C8A2C244CF5435]
"1"=hex:df,c7,3a,96,ab,66,13,d2,36,78,6c,b8,10,1c,c4,b0,41,14,92,53,8b,f4,9f,
53,ff,8f,6c,08,d5,ab,f1,06
"2"=hex:7d,73,4a,d4,1d,ee,c7,5a
"3"=hex:81,20,8f,ab,28,6a,52,9c
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:bf,e5,23,7b,b0,66,d6,fc,bc,64,22,fb,7e,d3,39,3e,a3,00,33,13,c0,21,f4,
51,6c,4e,0c,96,e2,dd,ad,8a,b6,c4,05,e8,5a,bd,9a,e9,d4,1a,3d,68,9d,00,32,20
"7"=hex:97,e4,84,cd,95,83,bf,82,bd,04,75,27,c9,a8,72,b1,55,38,49,8a,a6,16,a2,
28,28,eb,ee,eb,0f,d6,d6,b8,f4,df,4a,8d,b5,18,4f,2a,0d,c4,ee,cf,81,df,fe,df,\
"8"=hex:f4,00,a4,1f,f7,25,cd,0f,57,fc,c4,65,80,17,5e,c1,53,04,b1,f8,af,ae,1f,
e8,b6,14,18,f6,06,6f,91,34,22,a7,97,d7,c2,a9,65,7c,3c,9e,3b,e0,88,a1,87,c8
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:b6,dd,00,4d,9d,38,11,d1
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:81,20,8f,ab,28,6a,52,9c
"13"=hex:81,20,8f,ab,28,6a,52,9c
"14"=hex:81,20,8f,ab,28,6a,52,9c
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:81,20,8f,ab,28,6a,52,9c
"22"=hex:81,20,8f,ab,28,6a,52,9c
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \D25BC253F035D347\C4838B3D951212E6CDEE180D9201C56E]
"1"=hex:07,1f,1a,27,85,96,85,c3,38,71,53,58,52,6e,65,80,4c,0f,9a,93,b5,f7,5b,
e0
"2"=hex:af,48,68,fb,0f,c8,42,37
"3"=hex:81,20,8f,ab,28,6a,52,9c
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:bf,e5,23,7b,b0,66,d6,fc,bc,64,22,fb,7e,d3,39,3e,a3,00,33,13,c0,21,f4,
51,6c,4e,0c,96,e2,dd,ad,8a,b6,c4,05,e8,5a,bd,9a,e9,d4,1a,3d,68,9d,00,32,20
"7"=hex:6a,0b,56,13,c1,93,dc,9c,fb,61,a2,a0,e4,ff,91,20,56,a7,02,9d,f0,a0,1d,
cc,28,d9,b1,18,9e,f1,8d,e8,54,e6,61,27,95,2e,52,cc,1c,f7,fa,64,bd,24,b7,82,\
"8"=hex:66,7d,d2,ce,a1,ac,d6,d8,15,33,49,a2,19,f2,db,fe,1d,ed,b1,0d,31,f2,d3,
c2,91,32,0a,fc,38,8f,2a,b6,f2,5d,73,01,67,d4,34,b1,b0,11,c5,89,89,4b,de,e9,\
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:b6,dd,00,4d,9d,38,11,d1
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:81,20,8f,ab,28,6a,52,9c
"13"=hex:81,20,8f,ab,28,6a,52,9c
"14"=hex:81,20,8f,ab,28,6a,52,9c
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:81,20,8f,ab,28,6a,52,9c
"22"=hex:81,20,8f,ab,28,6a,52,9c
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \D25BC253F035D347\DF7B54A6112C2A0959607A574D3D99D6]
"1"=hex:05,a5,52,27,27,68,21,41,63,83,05,15,ef,55,2c,92
"2"=hex:af,48,68,fb,0f,c8,42,37
"3"=hex:81,20,8f,ab,28,6a,52,9c
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:bf,e5,23,7b,b0,66,d6,fc,bc,64,22,fb,7e,d3,39,3e,a3,00,33,13,c0,21,f4,
51,6c,4e,0c,96,e2,dd,ad,8a,b6,c4,05,e8,5a,bd,9a,e9,d4,1a,3d,68,9d,00,32,20
"7"=hex:6a,0b,56,13,c1,93,dc,9c,fb,61,a2,a0,e4,ff,91,20,56,a7,02,9d,f0,a0,1d,
cc,28,d9,b1,18,9e,f1,8d,e8,54,e6,61,27,95,2e,52,cc,1c,f7,fa,64,bd,24,b7,82,\
"8"=hex:66,7d,d2,ce,a1,ac,d6,d8,15,33,49,a2,19,f2,db,fe,1d,ed,b1,0d,31,f2,d3,
c2,91,32,0a,fc,38,8f,2a,b6,f2,5d,73,01,67,d4,34,b1,ad,a2,bd,96,61,05,7a,43,\
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:b6,dd,00,4d,9d,38,11,d1
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:81,20,8f,ab,28,6a,52,9c
"13"=hex:81,20,8f,ab,28,6a,52,9c
"14"=hex:81,20,8f,ab,28,6a,52,9c
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:81,20,8f,ab,28,6a,52,9c
"22"=hex:81,20,8f,ab,28,6a,52,9c
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
- - - - - - - > 'explorer.exe'(4052)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\programme\Creative\Shared Files\CTAudSvc.exe
c:\programme\Avira\AntiVir Desktop\avguard.exe
c:\programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\programme\Bonjour\mDNSResponder.exe
c:\programme\Java\jre6\bin\jqs.exe
c:\programme\Avira\AntiVir Desktop\avshadow.exe
c:\programme\Microsoft LifeCam\MSCamS32.exe
c:\brennprogramme\Nero 8\Nero BackItUp\NBService.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\System32\wbem\wmiapsrv.exe
c:\windows\system32\RunDLL32.exe
c:\programme\iPod\bin\iPodService.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2010-07-29 23:31:36 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2010-07-29 21:31
ComboFix2.txt 2010-07-29 16:19
Vor Suchlauf: 20 Verzeichnis(se), 62.869.753.856 Bytes frei
Nach Suchlauf: 21 Verzeichnis(se), 62.737.551.360 Bytes frei
- - End Of File - - BF587DA6ED5D3D297EE81C2309CEA6DD |