siggihagen
Neuer Benutzer
hallo
habe einen acer extensa 5235 betriebssystem windows 7 64 bit ... bekomme immer eine meldung das die festplatte einen fehler hat und ein s.m.a.r.t ereignis .... habe windows security durchlaufen lassen keine viren oder trojaner ... habe das bs neu aufgezogen und eine festplattenprüfung durchgeführt ... laut protokoll liegen keine fehler vor und die festplatte in ordnung .... habe auch combofix durchlaufen lassen ... weis jemand rat ???
combofix bericht
habe einen acer extensa 5235 betriebssystem windows 7 64 bit ... bekomme immer eine meldung das die festplatte einen fehler hat und ein s.m.a.r.t ereignis .... habe windows security durchlaufen lassen keine viren oder trojaner ... habe das bs neu aufgezogen und eine festplattenprüfung durchgeführt ... laut protokoll liegen keine fehler vor und die festplatte in ordnung .... habe auch combofix durchlaufen lassen ... weis jemand rat ???
combofix bericht
Code:
28.08.2013 13:30:57.1.1 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.49.1031.18.1977.1157 [GMT 2:00] ausgeführt von:: c:\users\siggi\AppData\Local\Temp\rmi\download-ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F} SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((( Dateien erstellt von 2013-07-28 bis 2013-08-28 )))))))))))))))))))))))))))))) . . 2013-08-28 11:38 . 2013-08-28 11:38 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-08-27 06:22 . 2013-08-27 06:22 -------- d-----w- C:\ac1f61e063bba59f3309858bc7 2013-08-27 05:40 . 2013-08-27 05:40 -------- d-----w- c:\program files\Microsoft Silverlight 2013-08-27 05:40 . 2013-08-27 05:40 -------- d-----w- c:\program files (x86)\Microsoft Silverlight 2013-08-27 04:04 . 2013-08-27 04:04 -------- d-----w- c:\windows\de-DE 2013-08-27 04:04 . 2013-08-27 04:04 -------- d-----w- c:\windows\SysWow64\XPSViewer 2013-08-27 04:04 . 2013-08-27 04:04 -------- d-----w- c:\windows\SysWow64\wbem\de-DE 2013-08-27 04:04 . 2013-08-27 04:04 -------- d-----w- c:\windows\SysWow64\drivers\UMDF\de-DE 2013-08-27 04:04 . 2013-08-27 04:04 -------- d-----w- c:\windows\SysWow64\drivers\de-DE 2013-08-27 04:04 . 2013-08-27 04:04 -------- d-----w- c:\windows\SysWow64\de 2013-08-27 04:04 . 2013-08-27 04:04 -------- d-----w- c:\windows\SysWow64\0407 2013-08-27 04:04 . 2013-08-27 04:04 -------- d-----w- c:\windows\system32\0407 2013-08-27 04:04 . 2013-08-27 04:04 -------- d-----w- c:\windows\system32\drivers\de-DE 2013-08-27 04:04 . 2013-08-27 04:04 -------- d-----w- c:\windows\system32\drivers\UMDF\de-DE 2013-08-27 04:04 . 2013-08-27 04:04 -------- d-----w- c:\windows\system32\wbem\de-DE 2013-08-27 04:04 . 2013-08-27 04:04 -------- d-----w- c:\windows\system32\de 2013-08-27 04:02 . 2013-08-27 04:02 3584 ----a-w- c:\windows\system32\Spool\prtprocs\x64\de-DE\LXKPTPRC.DLL.mui 2013-08-27 03:50 . 2013-08-27 03:50 -------- d-----w- c:\windows\NAPP_Dism_Log 2013-08-27 02:51 . 2013-08-27 03:02 -------- d-----r- C:\Backup 2013-08-26 22:01 . 2013-08-26 22:01 76232 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{747F170E-6E6D-4E20-AF0B-89DEF4624DEB}\offreg.dll 2013-08-26 21:08 . 2011-11-19 15:07 77312 ----a-w- c:\windows\system32\packager.dll 2013-08-26 21:08 . 2011-11-19 14:06 67072 ----a-w- c:\windows\SysWow64\packager.dll 2013-08-26 20:43 . 2013-08-26 20:42 941720 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6C24C921-2A38-4957-AA9D-237CBEDD788F}\gapaengine.dll 2013-08-26 20:43 . 2013-08-05 23:58 9515512 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{747F170E-6E6D-4E20-AF0B-89DEF4624DEB}\mpengine.dll 2013-08-26 20:41 . 2013-05-02 15:29 278800 ------w- c:\windows\system32\MpSigStub.exe 2013-08-26 20:32 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll 2013-08-26 20:32 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe 2013-08-26 20:32 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll 2013-08-26 20:32 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll 2013-08-26 20:31 . 2012-06-02 13:19 186752 ----a-w- c:\windows\system32\wuwebv.dll 2013-08-26 20:31 . 2012-06-02 13:15 36864 ----a-w- c:\windows\system32\wuapp.exe 2013-08-26 20:30 . 2013-08-26 20:30 -------- d-----w- c:\program files (x86)\Microsoft Security Client 2013-08-26 20:30 . 2013-08-26 20:31 -------- d-----w- c:\program files\Microsoft Security Client 2013-08-26 20:30 . 2010-04-09 11:06 1898376 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-08-26 20:30 . 2010-04-09 11:06 374664 ----a-w- c:\windows\system32\drivers\netio.sys 2013-08-26 20:26 . 2013-08-26 20:26 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service 2013-08-26 20:03 . 2013-08-26 20:03 -------- d-----w- c:\program files (x86)\Microsoft Small Business 2013-08-26 19:57 . 2013-08-26 19:59 -------- d-----w- c:\program files\Microsoft SQL Server 2013-08-26 19:57 . 2013-08-26 20:00 -------- d-----w- c:\program files (x86)\Microsoft SQL Server 2013-08-26 19:52 . 2013-08-26 19:52 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8 2013-08-26 19:47 . 2013-08-26 19:47 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition 2013-08-26 19:46 . 2013-08-26 19:46 -------- d-----w- c:\program files (x86)\Microsoft 2013-08-26 19:45 . 2013-08-26 19:45 -------- d-----w- c:\program files (x86)\Windows Live SkyDrive 2013-08-26 19:45 . 2013-08-26 19:49 -------- d-----w- c:\program files (x86)\Windows Live 2013-08-26 19:43 . 2013-08-26 19:43 -------- d-----w- c:\program files (x86)\Common Files\Windows Live 2013-08-26 19:34 . 2013-08-26 19:34 -------- d-----w- c:\program files (x86)\OEM 2013-08-26 19:33 . 2013-08-26 19:33 -------- d-----w- c:\program files\Acer Accessory Store 2013-08-26 19:32 . 2013-08-26 19:38 -------- d-----w- c:\users\Saskia 2013-08-26 18:41 . 2013-08-26 18:41 3 ----a-w- c:\windows\system32\PLD_Framework.cmd 2013-08-26 18:37 . 2013-08-26 18:37 -------- d-----w- c:\windows\SysWow64\x64 2013-08-26 18:37 . 2013-08-26 18:37 -------- d-----w- c:\windows\SysWow64\Lang 2013-08-26 18:37 . 2010-08-25 17:45 948760 ----a-w- c:\windows\SysWow64\igxpun.exe 2013-08-25 13:03 . 2013-08-25 13:03 -------- d---a-w- C:\book 2013-08-25 12:59 . 2013-08-25 12:59 -------- d-sh--we C:\Programme 2013-08-25 12:59 . 2013-08-25 12:59 -------- d-sh--we C:\Dokumente und Einstellungen . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-08-27 04:02 . 2013-08-27 04:02 2560 ----a-w- c:\windows\SysWow64\drivers\de-DE\qwavedrv.sys.mui 2013-08-27 04:01 . 2013-08-27 04:01 2560 ----a-w- c:\windows\SysWow64\drivers\de-DE\scfilter.sys.mui 2013-08-27 04:01 . 2013-08-27 04:01 5632 ----a-w- c:\windows\SysWow64\drivers\de-DE\ndiscap.sys.mui 2013-08-27 04:01 . 2013-08-27 04:01 51712 ----a-w- c:\windows\SysWow64\drivers\de-DE\tcpip.sys.mui 2013-08-27 04:00 . 2013-08-27 04:00 29696 ----a-w- c:\windows\SysWow64\drivers\de-DE\bfe.dll.mui 2013-08-27 04:00 . 2013-08-27 04:00 16896 ----a-w- c:\windows\SysWow64\drivers\de-DE\pacer.sys.mui 2013-06-18 19:50 . 2013-06-18 19:50 247216 ----a-w- c:\windows\system32\drivers\MpFilter.sys 2013-06-18 19:50 . 2013-06-18 19:50 139616 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0}] 2009-06-10 21:23 278864 ----a-w- c:\windows\System32\mscoree.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Browser Infrastructure Helper"="c:\users\Saskia\AppData\Local\Smartbar\Application\SnapDo.exe" [2013-08-04 21024] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2009-09-24 825864] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Acer VCM.lnk - c:\program files (x86)\Acer\Acer VCM\AcerVCM.exe [2010-4-8 704032] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys;c:\windows\SYSNATIVE\DRIVERS\NETw5s64.sys [x] R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x] R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x] R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [x] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x] R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys;c:\windows\SYSNATIVE\DRIVERS\Rts516xIR.sys [x] S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [x] S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe;c:\program files (x86)\Acer\Registration\GREGsvc.exe [x] S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [x] S2 RS_Service;Raw Socket Service;c:\program files (x86)\Acer\Acer VCM\RS_Service.exe;c:\program files (x86)\Acer\Acer VCM\RS_Service.exe [x] S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] . . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2009-07-20 503864] "Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-02-26 818720] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-07-18 1356240] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 161304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 415256] . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://[URL="http://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=6148de7f-4e36-8642-19d0-66779bdf56b7&searchtype=hp&installDate=28/08/2013"]feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=6148de7f-4e36-8642-19d0-66779bdf56b7&searchtype=hp&installDate=28/08/2013[/URL] uLocal Page = c:\windows\system32\blank.htm mDefault_Page_URL = hxxp://[URL="http://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=extensa_5235&r=27360813v006l04e3z135i4621u321"]homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=extensa_5235&r=27360813v006l04e3z135i4621u321[/URL] mStart Page = hxxp://[URL="http://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=extensa_5235&r=27360813v006l04e3z135i4621u321"]homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=extensa_5235&r=27360813v006l04e3z135i4621u321[/URL] mLocal Page = c:\windows\SysWOW64\blank.htm uSearchAssistant = hxxp://[URL="http://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=6148de7f-4e36-8642-19d0-66779bdf56b7&searchtype=ds&q=%7BsearchTerms%7D&installDate=28/08/2013"]feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=6148de7f-4e36-8642-19d0-66779bdf56b7&searchtype=ds&q={searchTerms}&installDate=28/08/2013[/URL] TCP: DhcpNameServer = [URL="http://192.168.0.1/"]192.168.0.1[/URL] FF - ProfilePath - c:\users\Saskia\AppData\Roaming\Mozilla\Firefox\Profiles\m61raaxo.default\ FF - prefs.js: browser.startup.homepage - hxxp://[URL="http://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=6148de7f-4e36-8642-19d0-66779bdf56b7&searchtype=hp&installDate=28/08/2013"]feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=6148de7f-4e36-8642-19d0-66779bdf56b7&searchtype=hp&installDate=28/08/2013[/URL] FF - prefs.js: browser.search.selectedEngine - Web Search FF - prefs.js: keyword.URL - hxxp://[URL="http://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=6148de7f-4e36-8642-19d0-66779bdf56b7&searchtype=ds&installDate=28/08/2013&q="]feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=6148de7f-4e36-8642-19d0-66779bdf56b7&searchtype=ds&installDate=28/08/2013&q=[/URL] . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) Toolbar-Locked - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] @Denied: (A 2) (Everyone) @="IFlashBroker3" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-08-28 13:48:03 ComboFix-quarantined-files.txt 2013-08-28 11:48 . Vor Suchlauf: 10 Verzeichnis(se), 113.469.734.912 Bytes frei Nach Suchlauf: 15 Verzeichnis(se), 114.477.453.312 Bytes frei . - - End Of File - - 74AAC0FCA7397D98A0E04BF0E0438450 A36C5E4F47E84449FF07ED3517B43A31
Zuletzt bearbeitet von einem Moderator: