ComboFix 11-01-08.04 - amir 09.01.2011 8:39.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3070.1909 [GMT 1:00]
ausgeführt von:: D:\Cofi.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\desktop.ini
c:\windows\system32\Cache
c:\windows\system32\KBL.LOG
c:\windows\system32\Temp
.
((((((((((((((((((((((( Dateien erstellt von 2010-12-09 bis 2011-01-09 ))))))))))))))))))))))))))))))
.
2011-01-09 07:43 . 2011-01-09 07:43 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-09 07:43 . 2011-01-09 07:43 -------- d-----w- c:\users\amir\AppData\Local\temp
2011-01-07 07:51 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8BF6C4A1-8E1E-43EF-8EB4-18774A8D506F}\mpengine.dll
2011-01-05 22:42 . 2011-01-05 22:42 -------- d-----w- c:\users\amir\Recorded TV
2010-12-23 16:33 . 2010-12-23 16:33 1222408 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-12-22 22:19 . 2010-12-22 22:19 -------- d-----w- c:\program files\Common Files\Skype
2010-12-22 22:19 . 2010-12-22 22:19 -------- d-----r- c:\program files\Skype
2010-12-15 17:20 . 2010-11-03 10:51 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2010-12-15 16:56 . 2010-10-12 15:53 33280 ----a-w- c:\program files\Windows Mail\wabfind.dll
2010-12-15 16:56 . 2010-10-12 13:41 66048 ----a-w- c:\program files\Windows Mail\wabmig.exe
2010-12-15 16:56 . 2010-10-12 13:41 515584 ----a-w- c:\program files\Windows Mail\wab.exe
2010-12-15 16:52 . 2010-10-18 13:31 2038272 ----a-w- c:\windows\system32\win32k.sys
2010-12-15 16:43 . 2010-10-28 13:27 292352 ----a-w- c:\windows\system32\atmfd.dll
2010-12-15 16:43 . 2010-10-28 15:44 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-12-15 16:43 . 2010-06-16 15:30 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-12-15 16:24 . 2010-10-18 13:37 81920 ----a-w- c:\windows\system32\consent.exe
2010-12-15 15:45 . 2010-05-04 19:13 231424 ----a-w- c:\windows\system32\msshsq.dll
2010-12-11 20:54 . 2010-12-11 20:54 -------- d-----w- c:\users\amir\AppData\Local\MigWiz
2010-12-10 14:45 . 2010-12-10 14:45 15712 ----a-w- c:\program files\Common Files\Windows Live\.cache\f198fbb61cb987801\MeshBetaRemover.exe
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-21 18:41 . 2010-11-02 16:58 135096 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-12-03 17:17 . 2010-12-03 17:17 53248 ----a-r- c:\users\amir\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2010-11-22 12:53 . 2010-11-02 16:58 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-11-13 21:21 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2010-11-13 21:21 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2010-11-10 02:49 . 2010-11-10 02:49 4323040 ----a-w- c:\windows\system32\drivers\lvuvc.sys
2010-11-10 02:49 . 2010-11-10 02:49 539232 ----a-w- c:\windows\system32\LVUI2RC.dll
2010-11-10 02:49 . 2010-11-10 02:49 543328 ----a-w- c:\windows\system32\LVUI2.dll
2010-11-10 02:48 . 2010-11-10 02:48 283744 ----a-w- c:\windows\system32\drivers\lvrs.sys
2010-11-10 02:47 . 2010-11-10 02:47 195168 ----a-w- c:\windows\system32\lvci13101216.dll
2010-11-10 02:47 . 2010-11-10 02:47 416352 ----a-w- c:\windows\system32\lvcodec2.dll
2010-11-10 02:46 . 2010-11-10 02:46 20704 ----a-w- c:\windows\system32\drivers\lvbusflt.sys
2010-11-10 02:45 . 2010-11-10 02:45 102744 ----a-w- c:\windows\system32\LogiDPPApp.exe
2010-11-10 02:45 . 2010-11-10 02:45 10871128 ----a-w- c:\windows\system32\LogiDPP.dll
2010-11-10 02:45 . 2010-11-10 02:45 316248 ----a-w- c:\windows\system32\DevManagerCore.dll
2010-11-10 02:32 . 2010-11-10 02:32 38238 ----a-w- c:\windows\system32\Repository.reg
2010-11-09 16:36 . 2010-11-09 16:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2010-11-09 16:35 . 2010-11-09 16:35 45056 ----a-w- c:\windows\system32\drivers\de-DE\http.sys.mui
2010-11-05 23:17 . 2010-11-05 23:17 62464 ----a-w- c:\windows\system32\l3codeca.acm
2010-11-05 23:17 . 2010-11-05 23:17 220672 ----a-w- c:\windows\system32\l3codecp.acm
2010-11-05 23:16 . 2010-11-05 23:16 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-11-05 23:15 . 2010-11-05 23:15 98304 ----a-w- c:\windows\system32\cabview.dll
2010-11-05 23:15 . 2010-11-05 23:15 37888 ----a-w- c:\windows\system32\printcom.dll
2010-11-05 23:14 . 2010-11-05 23:14 14848 ----a-w- c:\windows\system32\wshrm.dll
2010-11-05 23:14 . 2010-11-05 23:14 43520 ----a-w- c:\windows\system32\msdxm.tlb
2010-11-05 23:14 . 2010-11-05 23:14 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2010-11-05 23:14 . 2010-11-05 23:14 18432 ----a-w- c:\windows\system32\amcompat.tlb
2010-11-05 23:13 . 2010-11-05 23:13 7680 ----a-w- c:\windows\system32\spwmp.dll
2010-11-05 23:13 . 2010-11-05 23:13 4096 ----a-w- c:\windows\system32\msdxm.ocx
2010-11-05 23:13 . 2010-11-05 23:13 4096 ----a-w- c:\windows\system32\dxmasf.dll
2010-11-05 23:13 . 2010-11-05 23:13 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-11-05 23:13 . 2010-11-05 23:13 332288 ----a-w- c:\windows\system32\msdrm.dll
2010-11-05 23:13 . 2010-11-05 23:13 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-11-05 23:13 . 2010-11-05 23:13 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-11-05 23:13 . 2010-11-05 23:13 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-11-05 23:13 . 2010-11-05 23:13 518144 ----a-w- c:\windows\system32\RMActivate.exe
2010-11-05 23:13 . 2010-11-05 23:13 471552 ----a-w- c:\windows\system32\secproc.dll
2010-11-05 23:13 . 2010-11-05 23:13 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-11-05 23:13 . 2010-11-05 23:13 471552 ----a-w- c:\windows\system32\secproc_isv.dll
2010-11-02 21:03 . 2010-11-02 21:03 23552 ----a-w- c:\windows\system32\lpk.dll
2010-11-02 21:03 . 2010-11-02 21:03 10240 ----a-w- c:\windows\system32\dciman32.dll
2010-11-02 21:00 . 2010-11-02 21:00 61440 ----a-w- c:\windows\system32\winipsec.dll
2010-11-02 21:00 . 2010-11-02 21:00 272896 ----a-w- c:\windows\system32\polstore.dll
2010-11-02 20:58 . 2010-11-02 20:58 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2010-11-02 20:58 . 2010-11-02 20:58 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2010-11-02 20:58 . 2010-11-02 20:58 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2010-11-02 20:58 . 2010-11-02 20:58 19968 ----a-w- c:\windows\system32\ARP.EXE
2010-11-02 20:58 . 2010-11-02 20:58 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2010-11-02 20:58 . 2010-11-02 20:58 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2010-11-02 20:58 . 2010-11-02 20:58 105984 ----a-w- c:\windows\system32\netiohlp.dll
2010-11-02 20:58 . 2010-11-02 20:58 10240 ----a-w- c:\windows\system32\finger.exe
2010-11-02 20:55 . 2010-11-02 20:55 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2010-11-02 20:55 . 2010-11-02 20:55 68096 ----a-w- c:\windows\system32\wlanhlp.dll
2010-11-02 20:55 . 2010-11-02 20:55 65024 ----a-w- c:\windows\system32\wlanapi.dll
2010-11-02 20:55 . 2010-11-02 20:55 513536 ----a-w- c:\windows\system32\wlansvc.dll
2010-11-02 20:55 . 2010-11-02 20:55 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2010-11-02 20:55 . 2010-11-02 20:55 302592 ----a-w- c:\windows\system32\wlansec.dll
2010-11-02 20:55 . 2010-11-02 20:55 15181 ----a-w- c:\windows\system32\gatherWirelessInfo.vbs
2010-11-02 20:55 . 2010-11-02 20:55 1401856 ----a-w- c:\windows\system32\msxml6.dll
2010-11-02 20:55 . 2010-11-02 20:55 2048 ----a-w- c:\windows\system32\msxml6r.dll
2010-11-02 20:55 . 2010-11-02 20:55 2048 ----a-w- c:\windows\system32\msxml3r.dll
2010-11-02 20:54 . 2010-11-02 20:54 218624 ----a-w- c:\windows\system32\msv1_0.dll
2010-11-02 20:53 . 2010-11-02 20:53 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-11-02 20:53 . 2010-11-02 20:53 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-11-02 20:53 . 2010-11-02 20:53 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-11-02 20:52 . 2010-11-02 20:52 98816 ----a-w- c:\windows\system32\mfps.dll
2010-11-02 20:52 . 2010-11-02 20:52 53248 ----a-w- c:\windows\system32\rrinstaller.exe
2010-11-02 20:52 . 2010-11-02 20:52 2868224 ----a-w- c:\windows\system32\mf.dll
2010-11-02 20:52 . 2010-11-02 20:52 2048 ----a-w- c:\windows\system32\mferror.dll
2010-11-02 20:52 . 2010-11-02 20:52 24576 ----a-w- c:\windows\system32\mfpmp.exe
2010-11-02 20:50 . 2010-11-02 20:50 71680 ----a-w- c:\windows\system32\atl.dll
2010-11-02 20:46 . 2010-11-02 20:46 160256 ----a-w- c:\windows\system32\wkssvc.dll
2010-11-02 20:45 . 2010-11-02 20:45 53248 ----a-w- c:\windows\system32\tsgqec.dll
2010-11-02 20:45 . 2010-11-02 20:45 136192 ----a-w- c:\windows\system32\aaclient.dll
2010-11-02 20:45 . 2010-11-02 20:45 2066432 ----a-w- c:\windows\system32\mstscax.dll
2010-11-02 20:43 . 2010-11-02 20:43 714240 ----a-w- c:\windows\system32\timedate.cpl
2010-11-02 20:39 . 2010-11-02 20:39 69632 ----a-w- c:\windows\system32\Mpeg2Data.ax
2010-11-02 20:36 . 2010-11-02 20:36 623616 ----a-w- c:\windows\system32\localspl.dll
2010-11-02 20:34 . 2010-11-02 20:34 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-11-02 20:33 . 2010-11-02 20:33 499712 ----a-w- c:\windows\system32\kerberos.dll
2010-11-02 20:33 . 2010-11-02 20:33 175104 ----a-w- c:\windows\system32\wdigest.dll
2010-11-02 20:33 . 2010-11-02 20:33 9728 ----a-w- c:\windows\system32\lsass.exe
2010-11-02 20:33 . 2010-11-02 20:33 72704 ----a-w- c:\windows\system32\secur32.dll
2010-11-02 20:33 . 2010-11-02 20:33 439864 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2010-11-02 20:33 . 2010-11-02 20:33 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2010-11-02 20:31 . 2010-11-02 20:31 1793536 ----a-w- c:\windows\system32\NlsLexicons0045.dll
2010-11-02 20:31 . 2010-11-02 20:31 1808896 ----a-w- c:\windows\system32\NlsLexicons0046.dll
2010-11-02 20:31 . 2010-11-02 20:31 1558016 ----a-w- c:\windows\system32\NlsLexicons0049.dll
2010-11-02 20:31 . 2010-11-02 20:31 1411072 ----a-w- c:\windows\system32\NlsLexicons0047.dll
2010-11-02 20:31 . 2010-11-02 20:31 1236992 ----a-w- c:\windows\system32\NlsLexicons0020.dll
2010-11-02 20:31 . 2010-11-02 20:31 1782272 ----a-w- c:\windows\system32\NlsLexicons0039.dll
2010-11-02 20:31 . 2010-11-02 20:31 5499904 ----a-w- c:\windows\system32\NlsLexicons0022.dll
2010-11-02 20:31 . 2010-11-02 20:31 2136064 ----a-w- c:\windows\system32\NlsLexicons0021.dll
2010-11-02 20:31 . 2010-11-02 20:31 7964672 ----a-w- c:\windows\system32\NlsLexicons0024.dll
2010-11-02 20:31 . 2010-11-02 20:31 5791232 ----a-w- c:\windows\system32\NlsLexicons0026.dll
2010-11-02 20:31 . 2010-11-02 20:31 6224896 ----a-w- c:\windows\system32\NlsLexicons0027.dll
2010-11-02 20:31 . 2010-11-02 20:31 4175872 ----a-w- c:\windows\system32\NlsLexicons0010.dll
2010-11-02 20:31 . 2010-11-02 20:31 2466816 ----a-w- c:\windows\system32\NlsLexicons0011.dll
2010-11-02 20:31 . 2010-11-02 20:31 4981248 ----a-w- c:\windows\system32\NlsLexicons0013.dll
2010-11-02 20:31 . 2010-11-02 20:31 3331072 ----a-w- c:\windows\system32\NlsLexicons0018.dll
2003-06-05 22:15 . 2008-09-16 19:39 1785856 ----a-w- c:\program files\internet explorer\plugins\ielesrun.dll
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Mobile Partner"="c:\program files\Mobile Partner\Mobile Partner.exe" [2009-12-15 536576]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-02 281768]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
c:\users\amir\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech . Produktregistrierung.lnk - c:\program files\Logitech\Ereg\eReg.exe [2009-11-16 517384]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux5"=wdmaud.drv
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 22:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-19 07:33 125952 ----a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 10:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWS]
2010-05-07 17:35 165208 ----a-w- c:\program files\Logitech\LWS\Webcam Software\LWS.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-12-04 01:42 13556256 ----a-w- c:\windows\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-12-04 01:42 92704 ----a-w- c:\windows\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
2008-12-04 01:42 711200 ----a-w- c:\windows\System32\nvsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OnScreenDisplay]
2007-09-04 11:54 554320 ----a-w- c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2007-09-30 18:34 181544 ----a-w- c:\program files\Hp\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-12-03 15:46 14944136 ----a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
2009-10-26 13:46 1458176 ----a-w- c:\program files\Motorola\SMSERIAL\sm56hlpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-07-12 03:00 132496 ----a-w- c:\program files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPStart]
2007-09-15 08:29 102400 ----a-w- c:\program files\Synaptics\SynTP\SynTPStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WAWifiMessage]
2007-01-08 14:53 311296 ----a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
2009-04-11 06:28 2153472 ----a-w- c:\windows\System32\oobefldr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-19 07:33 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2216660671-4077720701-4065719445-1000]
"EnableNotificationsRef"=dword:00000002
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-11-30 136176]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2008-08-26 717296]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-11-02 135336]
S3 CompFilter;UVCCompositeFilter;c:\windows\system32\DRIVERS\lvbusflt.sys [2010-11-10 20704]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-10-12 101120]
S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Inhalt des "geplante Tasks" Ordners
2011-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-30 21:24]
2011-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-30 21:24]
2011-01-09 c:\windows\Tasks\User_Feed_Synchronization-{0ED85C16-7323-4B07-BA9B-3830A26B503E}.job
- c:\windows\system32\msfeedssync.exe [2010-12-15 04:25]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.de/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=81&bd=Pavilion&pf=laptop
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Translate this web page with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
IE: Translate with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
FF - ProfilePath - c:\users\amir\AppData\Roaming\Mozilla\Firefox\Profiles\qz5v60r0.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=15627
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
Google
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?babsrc=adbartrp&AF=15627&q=
FF - prefs.js: network.proxy.type - 0
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
HKLM-Run-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2011-01-09 08:44
Windows 6.0.6002 Service Pack 2 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Zeit der Fertigstellung: 2011-01-09 08:46:03
ComboFix-quarantined-files.txt 2011-01-09 07:45
Vor Suchlauf: 9 Verzeichnis(se), 157.503.696.896 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 157.446.045.696 Bytes frei
- - End Of File - - 95F88001789880FCA5B8BFC3113AEABF