|
Log-Analyse und Auswertung: Win32.Downloader.Gen infiziertWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
07.01.2014, 21:01 | #1 |
| Win32.Downloader.Gen infiziert Hallo und frohes Neues Spybot meldete mir den Win32.Downloader.Gen, den ich auch mit dem Programm ohne Probleme entfernen konnte (benutze meistens nur das Standardkonto). Doch bin ich mir nicht sicher ob er wirklich weg ist und nicht noch andere Schadsoftware hochgeladen wurde. Meine externe Festplatte habe ich noch nicht geprüft und nicht mehr benutzt. im voraus für die Hilfe. P.S: Zwar benutze ich den Laptop auch etwas beruflich, es ist aber kein gewerblicher PC. Teatimer habe ich ausgestellt und hoffe das ich alles richtig gemacht habe. MfG Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 19:40 on 07/01/2014 (Boss) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 05-01-2014 Ran by Boss (administrator) on ARBEIT-PC on 07-01-2014 19:44:32 Running from C:\Users\Boss.Arbeit-PC\Desktop\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe () C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe () C:\Program Files\ATK Hotkey\ASLDRSrv.exe () C:\Program Files\ATKGFNEX\GFNEXSrv.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files\Canon\IJPLM\ijplmsvc.exe (Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (SlimWare Utilities, Inc.) C:\Program Files\SlimDrivers\SlimDrivers.exe () C:\Program Files\ASUS\ASUS Live Update\ALU.exe (ATK0100) C:\Program Files\ATK Hotkey\HControl.exe () C:\Program Files\ATKOSD2\ATKOSD2.exe () C:\Program Files\Wireless Console 2\wcourier.exe (ATK) C:\Program Files\P4G\BatteryLife.exe (ATK) C:\Program Files\ASUS\Splendid\ACMON.exe (ASUS) C:\Windows\System32\ASUSTPE.exe (ASUSTeK) C:\Windows\System32\ACEngSvr.exe () C:\Program Files\ATK Hotkey\ATKOSD.exe () C:\Program Files\ATK Hotkey\KBFiltr.exe (Glarysoft Ltd) C:\Program Files\Glary Utilities 3\Integrator.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corporation) C:\Windows\System32\sdclt.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\conime.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [amd_dc_opt] - C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD) HKLM\...\Run: [ASUSTPE] - C:\Windows\System32\ASUSTPE.exe [106496 2007-01-17] (ASUS) HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [857648 2007-03-01] (Synaptics, Inc.) HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10996368 2000-01-01] (Realtek Semiconductor) HKLM\...\Run: [Conime] - C:\Windows\System32\conime.exe [69120 2009-04-11] (Microsoft Corporation) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2013-12-22] (AVAST Software) HKU\Boss\...\Run: [SpybotSD TeaTimer] - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [ 2009-03-05] (Safer-Networking Ltd.) HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\Gast\...\Run: [SpybotSD TeaTimer] - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [ 2009-03-05] (Safer-Networking Ltd.) HKU\Gast-Surfer\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\Weltnetz\...\Run: [SpybotSD TeaTimer] - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [ 2009-03-05] (Safer-Networking Ltd.) HKU\Weltnetz\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [ 2008-01-19] (Microsoft Corporation) HKU\Weltnetz\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\System32\spool\drivers\w32x86\3\E_TATIHVE.EXE [ 2012-07-12] (SEIKO EPSON CORPORATION) Startup: C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk ShortcutTarget: OpenOffice.org 3.0.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File) Startup: C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.lnk ShortcutTarget: OpenOffice.org 3.4.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File) Startup: C:\Users\Weltnetz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk.disabled ShortcutTarget: OpenOffice.org 3.2.lnk.disabled -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File) Startup: C:\Users\Weltnetz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk.disabled ShortcutTarget: OpenOffice.org 3.3.lnk.disabled -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File) Startup: C:\Users\Weltnetz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File) Startup: C:\Users\Weltnetz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.lnk.disabled ShortcutTarget: OpenOffice.org 3.4.lnk.disabled -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File) BootExecute: autocheck autochk * BootDefrag.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://isearch.glarysoft.com/?src=iehome HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://isearch.glarysoft.com/?src=iehome HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://isearch.glarysoft.com/?src=iehome SearchScopes: HKLM - DefaultScope {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch SearchScopes: HKLM - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch SearchScopes: HKCU - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\EPSON Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\EPSON Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [147456] (Apple Inc.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default FF SelectedSearchEngine: Google FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q= FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=6.0.12.775 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/npracplug;version=1.0.0.0 - C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll (RealNetworks) FF Plugin: @real.com/nprjplug;version=1.0.3.775 - C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprphtml5videoshim;version=1.0.0.0 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.775 - C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\searchplugins\askcom.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\glarysearch.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Unblock YouTube - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\ich@maltegoetz.de FF Extension: No Name - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\staged FF Extension: BrowserProtect - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\browserprotect@browserprotect.com.xpi FF Extension: Ghostery - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\firefox@ghostery.com.xpi FF Extension: Google/Yandex search link fix - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\jid0-XWJxt5VvCXkKzQK99PhZqAn7Xbg@jetpack.xpi FF Extension: Restart Firefox - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\restart@restart.org.xpi FF Extension: Malware Search - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\{27c60876-b5c9-4335-b4f3-52b26782220c}.xpi FF Extension: NoScript - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF Extension: Adblock Plus - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: BetterPrivacy - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi FF Extension: Tab Mix Plus - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF ========================== Services (Whitelisted) ================= R2 ADSMService; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [73728 2007-05-18] () R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-02-06] () R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-05-15] () R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-22] (AVAST Software) R2 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [99936 2006-11-10] () R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) S2 CLTNetCnService; "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [x] ==================== Drivers (Whitelisted) ==================== R0 AsDsm; C:\Windows\System32\Drivers\AsDsm.sys [27504 2007-04-25] (Windows (R) Codename Longhorn DDK provider) R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [11632 2007-02-05] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2013-12-22] (AVAST Software) R1 AswRdr; C:\Windows\system32\drivers\aswRdr.sys [54832 2013-12-22] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49944 2013-11-25] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [775952 2013-12-22] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [410528 2013-12-22] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57672 2013-12-22] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [180248 2013-12-22] () R0 BootDefragDriver; C:\Windows\System32\drivers\BootDefragDriver.sys [14080 2013-10-24] (<Glarysoft Ltd>) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [5632 2007-01-24] ( ) S3 KMWDFILTER; C:\Windows\System32\DRIVERS\KMWDFILTER.sys [17408 2008-10-09] (Windows (R) Codename Longhorn DDK provider) R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100) S3 ProcObsrv; C:\Program Files\Glary Utilities 3\ProcObsrv.sys [11552 2013-10-28] (Glarysoft Ltd) S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1737984 2007-03-06] () S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [13464 2014-01-07] () S3 vsdatant; C:\Windows\system32\vsdatant.sys [394192 2007-03-09] (Zone Labs, LLC) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [x] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [x] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 RTSTOR; system32\drivers\RTSTOR.SYS [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-07 19:44 - 2014-01-07 19:44 - 00000000 ____D C:\FRST 2014-01-07 19:35 - 2014-01-07 19:35 - 00000470 _____ C:\Users\Boss.Arbeit-PC\Downloads\defogger_disable.log 2014-01-07 19:35 - 2014-01-07 19:35 - 00000000 _____ C:\Users\Boss.Arbeit-PC\defogger_reenable 2014-01-07 19:32 - 2014-01-07 19:32 - 00050477 _____ C:\Users\Boss.Arbeit-PC\Downloads\Defogger.exe 2013-12-23 16:25 - 2013-12-23 16:52 - 00000000 ____D C:\AdwCleaner 2013-12-23 15:00 - 2013-12-23 15:00 - 00006943 _____ C:\Users\Weltnetz\Desktop\hijackthis.log 2013-12-23 14:59 - 2013-12-23 14:59 - 00388608 _____ (Trend Micro Inc.) C:\Users\Weltnetz\Desktop\hijackthis.exe 2013-12-22 21:59 - 2013-12-22 21:59 - 00000000 _____ C:\Windows\setuperr.log 2013-12-22 21:59 - 2013-12-22 21:59 - 00000000 _____ C:\Windows\setupact.log 2013-12-22 21:58 - 2013-12-22 21:58 - 00000000 ____D C:\Users\Boss.Arbeit-PC\AppData\Roaming\AVAST Software 2013-12-17 09:47 - 2013-12-17 09:47 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-12-16 22:43 - 2013-11-15 00:13 - 12344320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-16 22:43 - 2013-11-14 23:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-16 22:43 - 2013-11-14 23:50 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-16 22:43 - 2013-11-14 23:43 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-16 22:43 - 2013-11-14 23:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-16 22:43 - 2013-11-14 23:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-16 22:43 - 2013-11-14 23:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-16 22:43 - 2013-11-14 23:40 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-16 22:43 - 2013-11-14 23:38 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-16 22:43 - 2013-11-14 23:38 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-16 22:43 - 2013-11-14 23:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-16 22:43 - 2013-11-14 23:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-16 22:43 - 2013-11-14 23:36 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-16 22:43 - 2013-11-14 23:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-16 22:43 - 2013-11-14 23:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-16 22:43 - 2013-11-14 23:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-16 22:08 - 2013-12-16 22:08 - 00010240 _____ C:\Users\Weltnetz\Desktop\Wochenplan 2014--3KW.xls 2013-12-16 11:53 - 2013-10-30 03:12 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2013-12-16 11:53 - 2013-10-30 02:43 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-16 11:53 - 2013-10-30 01:43 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-16 11:53 - 2013-10-30 01:35 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-16 11:53 - 2013-10-22 08:19 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-16 11:53 - 2013-10-11 03:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-16 11:53 - 2013-10-11 03:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-16 11:53 - 2013-10-11 03:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wshcon.dll 2013-12-16 11:53 - 2013-10-11 01:35 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-16 11:53 - 2013-10-11 01:35 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe ==================== One Month Modified Files and Folders ======= 2014-01-07 19:44 - 2014-01-07 19:44 - 00000000 ____D C:\FRST 2014-01-07 19:41 - 2010-11-22 13:39 - 00056312 _____ C:\Users\Boss.Arbeit-PC\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-07 19:37 - 2012-08-27 09:43 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-07 19:35 - 2014-01-07 19:35 - 00000470 _____ C:\Users\Boss.Arbeit-PC\Downloads\defogger_disable.log 2014-01-07 19:35 - 2014-01-07 19:35 - 00000000 _____ C:\Users\Boss.Arbeit-PC\defogger_reenable 2014-01-07 19:35 - 2010-11-22 13:36 - 00000000 ____D C:\Users\Boss.Arbeit-PC 2014-01-07 19:32 - 2014-01-07 19:32 - 00050477 _____ C:\Users\Boss.Arbeit-PC\Downloads\Defogger.exe 2014-01-07 19:25 - 2011-01-12 14:35 - 00000000 ____D C:\Users\Boss.Arbeit-PC\AppData\Roaming\Macromedia 2014-01-07 19:19 - 2008-05-24 16:38 - 01773434 _____ C:\Windows\WindowsUpdate.log 2014-01-07 19:16 - 2013-10-08 06:35 - 00000320 _____ C:\Windows\Tasks\GlaryInitialize 3.job 2014-01-07 19:16 - 2013-10-08 06:35 - 00000000 ____D C:\Program Files\Glary Utilities 3 2014-01-07 19:16 - 2013-01-14 11:17 - 00000384 _____ C:\Windows\Tasks\SlimDrivers Startup.job 2014-01-07 19:15 - 2011-04-05 07:25 - 00049340 _____ C:\ProgramData\nvModes.001 2014-01-07 19:15 - 2011-03-01 10:14 - 00013464 _____ C:\Windows\system32\Drivers\SWDUMon.sys 2014-01-07 19:14 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-07 19:14 - 2006-11-02 13:47 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-07 19:14 - 2006-11-02 13:47 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-07 19:12 - 2007-04-18 09:33 - 00000012 _____ C:\Windows\bthservsdp.dat 2014-01-07 19:12 - 2006-11-02 14:01 - 00032534 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-07 19:09 - 2008-05-24 17:14 - 00045056 _____ C:\Windows\system32\acovcnt.exe 2014-01-07 14:49 - 2010-11-22 13:18 - 00000000 ____D C:\Users\Weltnetz\AppData\Roaming\Macromedia 2013-12-23 20:47 - 2011-04-05 07:25 - 00049340 _____ C:\ProgramData\nvModes.dat 2013-12-23 20:09 - 2012-07-15 21:49 - 00000000 ____D C:\Program Files\FRITZ! 2013-12-23 20:05 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20140107-192252.backup 2013-12-23 20:00 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20131223-200515.backup 2013-12-23 19:57 - 2013-11-17 20:11 - 00082228 _____ C:\Windows\PFRO.log 2013-12-23 18:12 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20131223-200034.backup 2013-12-23 18:07 - 2010-09-28 11:34 - 00000011 _____ C:\Windows\BRVIDEO.INI 2013-12-23 18:07 - 2010-09-28 11:27 - 00000088 _____ C:\Windows\Brownie.ini 2013-12-23 18:04 - 2011-03-01 11:17 - 00000000 ____D C:\Users\Boss.Arbeit-PC\AppData\Roaming\GlarySoft 2013-12-23 16:54 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20131223-181240.backup 2013-12-23 16:52 - 2013-12-23 16:25 - 00000000 ____D C:\AdwCleaner 2013-12-23 16:40 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20131223-165456.backup 2013-12-23 15:00 - 2013-12-23 15:00 - 00006943 _____ C:\Users\Weltnetz\Desktop\hijackthis.log 2013-12-23 14:59 - 2013-12-23 14:59 - 00388608 _____ (Trend Micro Inc.) C:\Users\Weltnetz\Desktop\hijackthis.exe 2013-12-23 11:28 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20131223-164059.backup 2013-12-22 23:40 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20131223-112820.backup 2013-12-22 23:31 - 2013-03-10 20:24 - 00000000 ____D C:\Users\Weltnetz\Desktop\Revisionen 13 2013-12-22 23:31 - 2013-01-07 16:36 - 00000000 ____D C:\Users\Weltnetz\Desktop\Wochenpläne 2013 2013-12-22 21:59 - 2013-12-22 21:59 - 00000000 _____ C:\Windows\setuperr.log 2013-12-22 21:59 - 2013-12-22 21:59 - 00000000 _____ C:\Windows\setupact.log 2013-12-22 21:58 - 2013-12-22 21:58 - 00000000 ____D C:\Users\Boss.Arbeit-PC\AppData\Roaming\AVAST Software 2013-12-22 21:51 - 2013-11-25 18:44 - 00001840 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-12-22 21:51 - 2013-03-19 09:46 - 00180248 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-12-22 21:51 - 2012-12-15 16:11 - 00410528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-12-22 21:51 - 2012-12-15 16:10 - 00775952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-12-22 21:51 - 2012-12-15 16:10 - 00270240 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-12-22 21:51 - 2012-12-15 16:10 - 00067824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-12-22 21:51 - 2012-12-15 16:10 - 00057672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-12-22 21:51 - 2012-12-15 16:10 - 00054832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr.sys 2013-12-22 21:51 - 2012-12-15 16:10 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-12-19 09:53 - 2012-04-26 17:52 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-12-17 09:47 - 2013-12-17 09:47 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-12-17 09:40 - 2006-11-02 13:47 - 00261944 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-17 09:35 - 2013-01-14 12:53 - 00000000 ____D C:\Windows\system32\RTCOM 2013-12-16 22:47 - 2013-08-15 20:38 - 00000000 ____D C:\Windows\system32\MRT 2013-12-16 22:44 - 2006-11-02 11:24 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-12-16 22:08 - 2013-12-16 22:08 - 00010240 _____ C:\Users\Weltnetz\Desktop\Wochenplan 2014--3KW.xls 2013-12-16 13:37 - 2012-04-04 12:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-12-16 13:37 - 2011-08-18 08:27 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-12-11 12:05 - 2006-11-02 11:33 - 01445352 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-10 09:51 - 2011-10-07 13:43 - 00000000 ____D C:\Users\Weltnetz\Desktop\Arbeit Some content of TEMP: ==================== C:\Users\Gast\AppData\Local\Temp\FlashPlayerUpdate.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-07 19:22 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 05-01-2014 Ran by Boss at 2014-01-07 19:45:27 Running from C:\Users\Boss.Arbeit-PC\Desktop\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== 32 Bit HP CIO Components Installer (Version: 2.1.5 - Hewlett-Packard) Hidden Adobe Flash Player 11 ActiveX (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Reader XI (11.0.05) - Deutsch (Version: 11.0.05 - Adobe Systems Incorporated) AnotherUnzipper - Deinstallation (Version: 2.20 - Mathias Gerlach [aborange.de]) ASUS Data Security Manager (Version: 1.00.0004 - ASUS) ASUS InstantFun (Version: 1.0.0014 - ASUS) ASUS Live Update (Version: 2.5.1 - ASUS) ASUS Splendid Video Enhancement Technology (Version: 1.02.15 - ASUSTeK) ASUS Touch Pad Extra (Version: - ) Asus_Camera_ScreenSaver (Version: 2.0.0006 - ASUS) Atheros Client Installation Program (Version: 7.0 - Atheros) ATK Generic Function Service (Version: 1.00.0006 - ATK) ATK Hotkey (Version: 1.00.0012 - ATK) ATK Media (Version: - ) ATKOSD2 (Version: 6.64.1.4 - ATK) Auslogics Disk Defrag (Version: 3.6 - Auslogics Software Pty Ltd) avast! Free Antivirus (Version: 9.0.2011 - Avast Software) Benutzerhandbuch EPSON BX635FWD Series (Version: - ) Bonjour (Version: 1.0.106 - Apple Inc.) BufferChm (Version: 100.0.170.000 - Hewlett-Packard) Hidden Canon iP4700 series Printer Driver (Version: - ) Canon MP140 series (Version: - ) Canon MP140 series Benutzerregistrierung (Version: - ) CCleaner (Version: 3.02 - Piriform) Cisco EAP-FAST Module (Version: 2.2.10 - Cisco Systems, Inc.) Cisco LEAP Module (Version: 1.0.16 - Cisco Systems, Inc.) Cisco PEAP Module (Version: 1.1.3 - Cisco Systems, Inc.) Cities of Earth 3D Screensaver v. 2.1 (Version: - Screenomania.com) D2500 (Version: 100.0.206.000 - Ihr Firmenname) Hidden D2500_Help (Version: 100.0.206.000 - Hewlett-Packard) Hidden Defraggler (Version: 2.01 - Piriform) DeviceDiscovery (Version: 110.0.180.000 - Hewlett-Packard) Hidden DeviceManagementQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden DJ_SF_03_D2500_ProductContext (Version: 100.0.215.000 - Hewlett-Packard) Hidden DJ_SF_03_D2500_Software (Version: 100.0.206.000 - Hewlett-Packard) Hidden DJ_SF_03_D2500_Software_Min (Version: 100.0.206.000 - Hewlett-Packard) Hidden dj_sf_software_req (Version: 90.0.235.000 - Hewlett-Packard) Hidden Download Navigator (Version: 1.1.0 - SEIKO EPSON CORPORATION) Druckerdeinstallation für EPSON BX635FWD Series (Version: - SEIKO EPSON Corporation) Dual-Core Optimizer (Version: 1.1.4.0169 - AMD) Epson Connect Printer Setup (Version: 1.1.0 - SEIKO EPSON CORPORATION) Epson Easy Photo Print 2 (Version: 2.3.0.0 - SEIKO EPSON CORPORATION) Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (Version: 1.00.0000 - SEIKO EPSON CORPORATION2) Epson Event Manager (Version: 2.50.0001 - SEIKO EPSON CORPORATION) Epson FAX Utility (Version: 1.20.00 - SEIKO EPSON CORPORATION) Epson PC-FAX Driver (Version: - ) EPSON Scan (Version: - Seiko Epson Corporation) EpsonNet Print (Version: 2.4j - SEIKO EPSON CORPORATION) Free Windows Tuner v2.000 (Version: - FreeWindowsTuner.com) Glary Utilities 3.9.4 (Version: 3.9.4.144 - Glarysoft Ltd) HP Deskjet D2500 Printer Driver Software 10.0 Rel .3 (Version: 10.0 - HP) HP Deskjet Printer Driver Software 9.0 (Version: 9.0 - HP) HP Imaging Device Functions 10.0 (Version: 10.0 - HP) Java 7 Update 45 (Version: 7.0.450 - Oracle) Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden JavaFX 2.1.1 (Version: 2.1.1 - Oracle Corporation) LifeFrame2 (Version: 2.0.15 - ASUS) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.5 SP1 (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 (Version: 9.0.21022.218 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Motorola SM56 Speakerphone Modem (Version: 6.12.25.06 - Motorola Inc) Mozilla Firefox 26.0 (x86 de) (Version: 26.0 - Mozilla) Mozilla Maintenance Service (Version: 26.0 - Mozilla) MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation) Netzwerkhandbuch EPSON BX635FWD Series (Version: - ) NVIDIA Drivers (Version: 1.7 - ) OpenOffice 4.0.0 (Version: 4.00.9702 - Apache Software Foundation) PC Inspector File Recovery (Version: 4.0 - ) PIXMA Extended Survey Program (Version: - ) Power4Gear eXtreme (Version: 1.00.0010 - ATK) PowerForPhone (Version: 1.0.0.12 - PowerForPhone) QuickTime (Version: 7.74.80.86 - Apple Inc.) RealPlayer (Version: - RealNetworks) Realtek High Definition Audio Driver (Version: 6.0.1.6662 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (Version: 6.1.7600.30122 - Realtek Semiconductor Corp.) RealUpgrade 1.0 (Version: 1.0.0 - RealNetworks, Inc.) Hidden SlimDrivers (Version: 2.2.30877 - SlimWare Utilities, Inc.) Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0 - Adobe Systems Incorporated) Spybot - Search & Destroy (Version: 1.6.2 - Safer Networking Limited) Status (Version: 110.0.180.000 - Hewlett-Packard) Hidden Synaptics Pointing Device Driver (Version: 9.1.19.0 - Synaptics) Toolbox (Version: 100.0.170.000 - Hewlett-Packard) Hidden TrayApp (Version: 110.0.180.000 - Hewlett-Packard) Hidden UnloadSupport (Version: 10.0.0 - Hewlett-Packard) Hidden Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3 - Microsoft Corporation) USB2.0 UVC 1.3M WebCam (Version: - ) WebReg (Version: 100.0.170.000 - Hewlett-Packard) Hidden Windows Media Player Firefox Plugin (Version: 1.0.0.8 - Microsoft Corp) WinFlash (Version: - ) Wireless Console 2 (Version: 2.0.8 - ATK) WMBackup 0.99.15 (Version: - Heiko Schröder Softwareentwicklung) ==================== Restore Points ========================= 16-12-2013 21:42:14 Windows Update 19-12-2013 10:57:57 Geplanter Prüfpunkt 20-12-2013 13:14:17 Windows Update 22-12-2013 17:55:35 Geplanter Prüfpunkt 22-12-2013 20:50:12 avast! antivirus system restore point 23-12-2013 11:50:36 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2006-11-02 11:23 - 2014-01-07 19:22 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1000gratisproben.com 127.0.0.1 www.1001namen.com 127.0.0.1 1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 100sexlinks.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 10sek.com 127.0.0.1 www.10sek.com 127.0.0.1 www.1-2005-search.com 127.0.0.1 1-2005-search.com 127.0.0.1 123haustiereundmehr.com 127.0.0.1 www.123haustiereundmehr.com 127.0.0.1 123moviedownload.com 127.0.0.1 www.123moviedownload.com There are 1000 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: {13219898-38CB-4E6B-A8F0-68AC20B8CEFA} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-309777827-4204377080-2083972359-1003 => C:\Program Files\Real\RealUpgrade\realupgrade.exe [2010-06-03] (RealNetworks, Inc.) Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {2B53AE16-C503-4DE0-B1A8-D560F6C86F66} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-309777827-4204377080-2083972359-1003 => C:\Program Files\Real\RealUpgrade\realupgrade.exe [2010-06-03] (RealNetworks, Inc.) Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-19] (Microsoft Corporation) Task: {63D7CCD8-A237-4FEA-A1FF-B1344FCDF64D} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {66D09381-24D3-46E9-B933-BD11E3247174} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance => C:\Program Files\TuneUp Utilities 2010\OneClick.exe Task: {94D8AD20-0DBC-4D23-B2C9-F6F90637E293} - System32\Tasks\SlimDrivers Startup => C:\Program Files\SlimDrivers\SlimDrivers.exe [2013-07-10] (SlimWare Utilities, Inc.) Task: {A2DA1C95-90CA-4139-A3E2-9C21DF8E7A44} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-12-22] (AVAST Software) Task: {A376438B-E1BE-40CA-AD30-155DA1060DD2} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2009-01-07] (Microsoft Corporation) Task: {AB4E3F3E-78A7-4E3E-B078-E058C146E88A} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated) Task: {B5A65FD6-3790-496E-996E-8F54A1027E37} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-309777827-4204377080-2083972359-1002 => C:\Program Files\Real\RealUpgrade\realupgrade.exe [2010-06-03] (RealNetworks, Inc.) Task: {B7EAA4AB-530C-4C46-A2C4-A74F570D8800} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {C1F11BDE-754B-4E60-85FD-982799F74A17} - System32\Tasks\Microsoft\Windows\RestartManager\{79C16614-A257-4088-94E9-CE7AAA08CE37} => C:\Windows\System32\RmClient.exe [2006-11-02] (Microsoft Corporation) Task: {C6EEBA15-D27C-4E51-8A33-F9DCF321A359} - System32\Tasks\GlaryInitialize 3 => C:\Program Files\Glary Utilities 3\Initialize.exe [2013-10-28] (Glarysoft Ltd) Task: {CA12BE04-2916-4F6E-BACF-62F16AA9217B} - System32\Tasks\ASUS Live Update => C:\Program Files\ASUS\ASUS Live Update\ALU.exe [2007-02-09] () Task: {CF154614-0FC3-41EC-B689-092D36DA9334} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-309777827-4204377080-2083972359-1000 => C:\Program Files\Real\RealUpgrade\realupgrade.exe [2010-06-03] (RealNetworks, Inc.) Task: {E191F776-83C7-4B9C-9C3B-876D7A0AC9C8} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-309777827-4204377080-2083972359-1000 => C:\Program Files\Real\RealUpgrade\realupgrade.exe [2010-06-03] (RealNetworks, Inc.) Task: {E30EA9C0-05BB-4547-AEC1-F8FC349067D0} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Weltnetz => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-05] () Task: {F8763C55-2139-4375-B638-23643238D222} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-16] (Adobe Systems Incorporated) Task: {FF652D4C-F1F1-4270-B0D1-B7CEB28C9157} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-309777827-4204377080-2083972359-1002 => C:\Program Files\Real\RealUpgrade\realupgrade.exe [2010-06-03] (RealNetworks, Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GlaryInitialize 3.job => C:\Program Files\Glary Utilities 3\Initialize.exe Task: C:\Windows\Tasks\SlimDrivers Startup.job => C:\Program Files\SlimDrivers\SlimDrivers.exe ==================== Loaded Modules (whitelisted) ============= 2008-05-24 17:02 - 2007-06-15 18:28 - 00147456 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt.dll 2008-05-24 17:02 - 2007-06-02 01:08 - 00143360 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll 2013-10-28 09:37 - 2013-10-28 09:37 - 00080160 _____ () C:\Program Files\Glary Utilities 3\zlib1.dll 2013-11-25 18:43 - 2013-11-25 18:43 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2013-12-17 09:47 - 2013-12-17 09:47 - 03559024 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (12/22/2013 09:50:11 PM) (Source: VSS) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005. Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {070e1857-1dc1-46e4-99c2-3b31209d38b0} Error: (12/22/2013 07:00:03 PM) (Source: Windows Backup) (User: ) Description: Die Dateisicherung ist aufgrund eines Fehlers beim Schreiben in das Sicherungsziel F:\ fehlgeschlagen. Fehler: Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006) Error: (12/21/2013 01:57:10 PM) (Source: Windows Search Service) (User: ) Description: Die Aktualisierung kann nicht gestartet werden, da kein Zugriff auf die Inhaltsquellen bestand. Beheben Sie die Fehler, und starten Sie die Aktualisierung erneut. Kontext: Anwendung, SystemIndex Katalog Error: (12/17/2013 09:50:56 AM) (Source: Windows Backup) (User: ) Description: Die Dateisicherung ist aufgrund eines Fehlers beim Schreiben in das Sicherungsziel F:\ fehlgeschlagen. Fehler: Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006) Error: (12/09/2013 03:54:18 PM) (Source: Windows Backup) (User: ) Description: Die Dateisicherung ist aufgrund eines Fehlers beim Schreiben in das Sicherungsziel F:\ fehlgeschlagen. Fehler: Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006) Error: (12/06/2013 02:53:54 PM) (Source: Windows Search Service) (User: ) Description: Die Aktualisierung kann nicht gestartet werden, da kein Zugriff auf die Inhaltsquellen bestand. Beheben Sie die Fehler, und starten Sie die Aktualisierung erneut. Kontext: Anwendung, SystemIndex Katalog Error: (12/05/2013 10:53:16 AM) (Source: Windows Backup) (User: ) Description: Die Dateisicherung ist aufgrund eines Fehlers beim Schreiben in das Sicherungsziel F:\ fehlgeschlagen. Fehler: Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006) Error: (11/27/2013 10:52:16 AM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\WELTNETZ\APPDATA\ROAMING\MICROSOFT\WINDOWS\RECENT\DORNHHOFF.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (11/27/2013 10:52:16 AM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\WELTNETZ\APPDATA\ROAMING\MICROSOFT\WINDOWS\RECENT\DORNHHOFF.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (11/25/2013 08:01:31 PM) (Source: Windows Backup) (User: ) Description: Die Dateisicherung ist aufgrund eines Fehlers beim Schreiben in das Sicherungsziel F:\ fehlgeschlagen. Fehler: Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006) System errors: ============= Error: (01/07/2014 07:16:25 PM) (Source: Service Control Manager) (User: ) Description: HP CUE DeviceDiscovery Service Error: (01/07/2014 06:45:25 PM) (Source: Service Control Manager) (User: ) Description: HP CUE DeviceDiscovery Service Error: (01/07/2014 01:41:52 PM) (Source: Service Control Manager) (User: ) Description: HP CUE DeviceDiscovery Service Error: (12/23/2013 08:23:24 PM) (Source: Service Control Manager) (User: ) Description: HP CUE DeviceDiscovery Service Error: (12/23/2013 07:58:56 PM) (Source: Service Control Manager) (User: ) Description: HP CUE DeviceDiscovery Service Error: (12/23/2013 04:59:59 PM) (Source: Service Control Manager) (User: ) Description: HP CUE DeviceDiscovery Service Error: (12/23/2013 04:48:42 PM) (Source: Service Control Manager) (User: ) Description: HP CUE DeviceDiscovery Service Error: (12/23/2013 04:44:04 PM) (Source: DCOM) (User: ) Description: {F40211E8-05C9-4430-B832-041A5ECD7FA2} Error: (12/23/2013 04:25:22 PM) (Source: Service Control Manager) (User: ) Description: HP CUE DeviceDiscovery Service Error: (12/23/2013 11:11:21 AM) (Source: Service Control Manager) (User: ) Description: HP CUE DeviceDiscovery Service Microsoft Office Sessions: ========================= Error: (12/22/2013 09:50:11 PM) (Source: VSS)(User: ) Description: 0x80070005 Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {070e1857-1dc1-46e4-99c2-3b31209d38b0} Error: (12/22/2013 07:00:03 PM) (Source: Windows Backup)(User: ) Description: F:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006) Error: (12/21/2013 01:57:10 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Error: (12/17/2013 09:50:56 AM) (Source: Windows Backup)(User: ) Description: F:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006) Error: (12/09/2013 03:54:18 PM) (Source: Windows Backup)(User: ) Description: F:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006) Error: (12/06/2013 02:53:54 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Error: (12/05/2013 10:53:16 AM) (Source: Windows Backup)(User: ) Description: F:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006) Error: (11/27/2013 10:52:16 AM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\WELTNETZ\APPDATA\ROAMING\MICROSOFT\WINDOWS\RECENT\DORNHHOFF.LNK Error: (11/27/2013 10:52:16 AM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\WELTNETZ\APPDATA\ROAMING\MICROSOFT\WINDOWS\RECENT\DORNHHOFF.LNK Error: (11/25/2013 08:01:31 PM) (Source: Windows Backup)(User: ) Description: F:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und die Hardwarekonfiguration. (0x81000006) ==================== Memory info =========================== Percentage of memory in use: 46% Total physical RAM: 2942.52 MB Available physical RAM: 1583.27 MB Total Pagefile: 6111.26 MB Available Pagefile: 4781.76 MB Total Virtual: 2047.88 MB Available Virtual: 1898.59 MB ==================== Drives ================================ Drive c: (VistaOS) (Fixed) (Total:55.89 GB) (Free:9.93 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (DATA) (Fixed) (Total:49.06 GB) (Free:44.24 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 112 GB) (Disk ID: FDEF043A) Partition 1: (Not Active) - (Size=7 GB) - (Type=1C) Partition 2: (Active) - (Size=56 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=49 GB) - (Type=OF Extended) ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2014-01-07 20:18:57 Windows 6.0.6002 Service Pack 2 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3 WDC_WD1200BEVS-22UST0 rev.01.01A01 111,79GB Running: gmer_2.1.19163.exe; Driver: C:\Users\BOSS~1.ARB\AppData\Local\Temp\awliqpow.sys ---- System - GMER 2.1 ---- SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwAddBootEntry [0x9353FAD0] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0x935405AE] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwCreateEvent [0x9354C5E0] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwCreateEventPair [0x9354C62C] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0x9354C7C6] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwCreateMutant [0x9354C54E] SSDT \??\C:\Windows\system32\drivers\aswSP.sys ZwCreateSection [0x9337B386] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwCreateSemaphore [0x9354C596] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwCreateThread [0x93540AE4] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwCreateTimer [0x9354C780] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwDebugActiveProcess [0x9354139C] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0x9353FB36] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwDuplicateObject [0x93544B32] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwLoadDriver [0x9353F71E] SSDT \??\C:\Windows\system32\drivers\aswSP.sys ZwMapViewOfSection [0x9337B466] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwModifyBootEntry [0x9353FB9C] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0x93544F28] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0x93541E2C] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenEvent [0x9354C60A] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenEventPair [0x9354C64E] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0x9354C7EA] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenMutant [0x9354C574] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenProcess [0x9354442C] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenSection [0x9354C6FE] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenSemaphore [0x9354C5BE] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenThread [0x93544814] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenTimer [0x9354C7A4] SSDT \??\C:\Windows\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0x9337B20A] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwQueryObject [0x93541CF8] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwQueueApcThread [0x9354184E] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0x9353FC02] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwSetBootOptions [0x9353FC68] SSDT \??\C:\Windows\system32\drivers\aswSP.sys ZwSetContextThread [0x9337B562] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwSetSystemInformation [0x9353F7B8] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0x9353F98E] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwShutdownSystem [0x9353F91C] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwSuspendProcess [0x93541566] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwSuspendThread [0x935416C8] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwSystemDebugControl [0x9353FA16] SSDT \??\C:\Windows\system32\drivers\aswSP.sys ZwTerminateProcess [0x9337B2D8] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwTerminateThread [0x935411F6] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwVdmControl [0x9353FCCE] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwWriteVirtualMemory [0x9354060A] SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwCreateThreadEx [0x93540D00] ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!KeSetEvent + 10D 838B3758 4 Bytes [D0, FA, 53, 93] {SAR DL, 0x1; PUSH EBX; XCHG EBX, EAX} .text ntkrnlpa.exe!KeSetEvent + 191 838B37DC 4 Bytes [AE, 05, 54, 93] .text ntkrnlpa.exe!KeSetEvent + 1D1 838B381C 8 Bytes [E0, C5, 54, 93, 2C, C6, 54, ...] {LOOPNZ 0xffffffc7; PUSH ESP; XCHG EBX, EAX; SUB AL, 0xc6; PUSH ESP; XCHG EBX, EAX} .text ntkrnlpa.exe!KeSetEvent + 1DD 838B3828 4 Bytes [C6, C7, 54, 93] {MOV BH, 0x54; XCHG EBX, EAX} .text ntkrnlpa.exe!KeSetEvent + 1F5 838B3840 4 Bytes [4E, C5, 54, 93] .text ... .text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x9040A340, 0x3EE587, 0xE8000020] ---- User code sections - GMER 2.1 ---- .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[256] kernel32.dll!GetBinaryTypeW + 70 76FB2447 1 Byte [62] .text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[288] kernel32.dll!GetBinaryTypeW + 70 76FB2447 1 Byte [62] .text C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE[452] kernel32.dll!GetBinaryTypeW + 70 76FB2447 1 Byte [62] .text C:\Windows\system32\svchost.exe[508] kernel32.dll!GetBinaryTypeW + 70 76FB2447 1 Byte [62] .text C:\Program Files\Bonjour\mDNSResponder.exe[524] kernel32.dll!GetBinaryTypeW + 70 76FB2447 1 Byte [62] .text ... ---- Devices - GMER 2.1 ---- AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys AttachedDevice \Driver\tdx \Device\Tcp aswTdi.sys AttachedDevice \Driver\tdx \Device\Udp aswTdi.sys AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\ControlSet001\Services\BTHPORT\Parameters\Keys\0018f337f16b (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0018f337f16b (not active ControlSet) Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0018f337f16b Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\0018f337f16b (not active ControlSet) Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\0018f337f16b (not active ControlSet) Reg HKLM\SYSTEM\ControlSet006\Services\BTHPORT\Parameters\Keys\0018f337f16b (not active ControlSet) Reg HKLM\SYSTEM\ControlSet007\Services\BTHPORT\Parameters\Keys\0018f337f16b (not active ControlSet) Reg HKLM\SYSTEM\ControlSet008\Services\BTHPORT\Parameters\Keys\0018f337f16b (not active ControlSet) Reg HKLM\SYSTEM\ControlSet009\Services\BTHPORT\Parameters\Keys\0018f337f16b (not active ControlSet) Reg HKLM\SYSTEM\ControlSet010\Services\BTHPORT\Parameters\Keys\0018f337f16b (not active ControlSet) ---- EOF - GMER 2.1 ---- Geändert von Virenkill (07.01.2014 um 21:43 Uhr) Grund: Rechtschreibung |
08.01.2014, 07:37 | #2 |
/// the machine /// TB-Ausbilder | Win32.Downloader.Gen infiziert hi,
__________________Scan mit Combofix
__________________ |
08.01.2014, 17:51 | #3 |
| Win32.Downloader.Gen infiziert Hallo
__________________Vielen Dank für die Schnelle Antwort. P.S: Bitte teilen Sie mir mit, wann ich die externe Festplatte wieder anschließen soll, auf dieser mache ich die komplette PC Sicherung. P.S.S. Ich fühle mich äußerst positiv genötigt, hier zu Spenden. Code:
ATTFilter ComboFix 14-01-08.02 - Boss 08.01.2014 16:47:29.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.2943.1968 [GMT 1:00] ausgeführt von:: c:\users\Boss.Arbeit-PC\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B} SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Weltnetz\4.0 c:\windows\IsUn0407.exe c:\windows\msvcr71.dll c:\windows\NCLAUNCH.EXe c:\windows\system32\AutoRun.inf c:\windows\system32\ccrpTmr6.dll c:\windows\system32\sm56co85.txt D:\install.exe . . ((((((((((((((((((((((( Dateien erstellt von 2013-12-08 bis 2014-01-08 )))))))))))))))))))))))))))))) . . 2014-01-08 16:15 . 2014-01-08 16:15 -------- d-----w- c:\users\Weltnetz\AppData\Local\temp 2014-01-08 16:15 . 2014-01-08 16:15 -------- d-----w- c:\users\Boss.Arbeit-PC\AppData\Local\temp 2014-01-07 18:44 . 2014-01-07 18:44 -------- d-----w- C:\FRST 2013-12-23 15:25 . 2013-12-23 15:52 -------- d-----w- C:\AdwCleaner 2013-12-22 20:58 . 2013-12-22 20:58 -------- d-----w- c:\users\Boss.Arbeit-PC\AppData\Roaming\AVAST Software 2013-12-20 13:15 . 2013-12-04 02:57 7760024 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6DDBDDC5-ED5C-4029-9554-24A038454120}\mpengine.dll 2013-12-16 10:53 . 2013-10-30 00:35 2050560 ----a-w- c:\windows\system32\win32k.sys 2013-12-16 10:53 . 2013-10-30 02:12 335360 ----a-w- c:\windows\system32\SysFxUI.dll 2013-12-16 10:53 . 2013-10-30 01:43 130048 ----a-w- c:\windows\system32\drivers\drmk.sys 2013-12-16 10:53 . 2013-10-30 00:43 167936 ----a-w- c:\windows\system32\drivers\portcls.sys 2013-12-16 10:53 . 2013-10-11 02:08 36864 ----a-w- c:\windows\system32\wshcon.dll 2013-12-16 10:53 . 2013-10-11 02:08 131072 ----a-w- c:\windows\system32\wshom.ocx 2013-12-16 10:53 . 2013-10-11 02:08 172032 ----a-w- c:\windows\system32\scrrun.dll 2013-12-16 10:53 . 2013-10-11 00:35 135168 ----a-w- c:\windows\system32\cscript.exe 2013-12-16 10:53 . 2013-10-11 00:35 155648 ----a-w- c:\windows\system32\wscript.exe 2013-12-16 10:53 . 2013-10-22 07:19 158208 ----a-w- c:\windows\system32\imagehlp.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-01-07 18:09 . 2008-05-24 16:14 45056 ----a-w- c:\windows\system32\acovcnt.exe 2013-12-22 20:51 . 2013-03-19 08:46 180248 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2013-12-22 20:51 . 2012-12-15 15:11 410528 ----a-w- c:\windows\system32\drivers\aswSP.sys 2013-12-22 20:51 . 2012-12-15 15:10 54832 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2013-12-22 20:51 . 2012-12-15 15:10 57672 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2013-12-22 20:51 . 2012-12-15 15:10 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2013-12-22 20:51 . 2012-12-15 15:10 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-12-22 20:51 . 2012-12-15 15:10 43152 ----a-w- c:\windows\avastSS.scr 2013-12-22 20:51 . 2012-12-15 15:10 270240 ----a-w- c:\windows\system32\aswBoot.exe 2013-12-16 12:37 . 2012-04-04 11:06 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-12-16 12:37 . 2011-08-18 07:27 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-11-25 17:44 . 2013-03-19 08:46 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-11-19 02:33 . 2009-10-05 06:43 230048 ------w- c:\windows\system32\MpSigStub.exe 2013-10-30 02:13 . 2006-11-02 10:25 1304064 ----a-w- c:\windows\system32\WMALFXGFXDSP.dll 2013-10-28 08:38 . 2013-10-08 05:35 101664 ----a-w- c:\windows\system32\BootDefrag.exe 2013-10-24 02:30 . 2013-11-17 12:07 14080 ----a-w- c:\windows\system32\drivers\BootDefragDriver.sys 2013-10-22 17:41 . 2013-10-22 17:42 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2013-10-11 02:08 . 2013-11-15 09:48 444928 ----a-w- c:\windows\system32\IKEEXT.DLL 2013-10-11 02:07 . 2013-11-15 09:48 596480 ----a-w- c:\windows\system32\FWPUCLNT.DLL 2010-09-20 08:48 . 2010-09-20 08:49 774144 ----a-w- c:\program files\RngInterstitial.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-12-22 20:51 259464 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1] @="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}" [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}] 2007-06-02 00:08 143360 ----a-w- c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824] "ASUSTPE"="c:\windows\system32\ASUSTPE.exe" [2007-01-16 106496] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2000-01-01 13548064] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-01 857648] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2000-01-01 10996368] "Conime"="c:\windows\system32\conime.exe" [2009-04-11 69120] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2013-12-22 3764024] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk * \0BootDefrag.exe . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare Software.lnk] backup=c:\windows\pss\Kodak EasyShare Software.lnk.CommonStartup backupExtension=.CommonStartup HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2013-04-04 21:06 958576 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] 2000-01-01 00:00 92704 ----a-w- c:\windows\System32\nvmctray.dll . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2013-05-01 01:59 421888 ----a-w- c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL] 2009-10-26 13:46 1458176 ----a-w- c:\program files\Motorola\SMSERIAL\sm56hlpr.exe . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Skytel"=Skytel.exe "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "ASUS Camera ScreenSaver"=c:\windows\ASScrProlog.exe "ASUS Screen Saver Protector"=c:\windows\ASScrPro.exe "BrStsWnd"=c:\program files\Brownie\BrstsWnd.exe Autorun "NvSvc"=RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot "NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit "Windows Defender"=%ProgramFiles%\Windows Defender\MSASCui.exe -hide . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "AntiVirusOverride"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Inhalt des "geplante Tasks" Ordners . 2014-01-08 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 12:37] . 2014-01-08 c:\windows\Tasks\GlaryInitialize 3.job - c:\program files\Glary Utilities 3\Initialize.exe [2013-10-28 08:36] . 2014-01-08 c:\windows\Tasks\SlimDrivers Startup.job - c:\program files\SlimDrivers\SlimDrivers.exe [2013-07-10 06:58] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = about:blank mStart Page = hxxp://isearch.glarysoft.com/?src=iehome TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q= FF - prefs.js: network.proxy.type - 0 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . c:\users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe c:\users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe SafeBoot-WudfPf SafeBoot-WudfRd . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2014-01-08 17:15 Windows 6.0.6002 Service Pack 2 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . . C:\ADSM_PData_0150 . Scan erfolgreich abgeschlossen versteckte Dateien: 1 . ************************************************************************** . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.0_03" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.0_04" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.0_05" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_01" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_01" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_02" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_02" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_03" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_03" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_04" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_04" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_05" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_05" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_06" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_06" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_07" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_07" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_08" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_08" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_09" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_09" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_10" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_10" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_11" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_11" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_12" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_12" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_13" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_13" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_14" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_14" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_15" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_15" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_16" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_16" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_17" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_17" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_18" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_18" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_19" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_19" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_20" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_20" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_21" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_21" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_01" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_01" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_02" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_02" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_03" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_03" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_04" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_04" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_01" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_01" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_02" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_02" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_03" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_03" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_04" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_04" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_05" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_05" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_06" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_06" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_07" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_07" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_01" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_01" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_02" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_02" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_03" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_03" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_04" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_04" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_05" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_05" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_06" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_06" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_07" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_07" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_08" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_08" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_09" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_09" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_10" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_10" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_11" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_11" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_12" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_12" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_13" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_13" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_14" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_14" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_15" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_15" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_16" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_16" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_17" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_17" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_18" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_18" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_19" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_19" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_20" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_20" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_21" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_21" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_22" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_22" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_23" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_23" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_24" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_24" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_25" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_25" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_26" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_26" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_27" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_27" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_28" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_28" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_29" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_29" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_30" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_30" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_31" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_31" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_32" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_32" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_33" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_33" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_34" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_34" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_35" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_35" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_36" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_36" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_37" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_37" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_38" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_38" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_39" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_39" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_40" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_40" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0041-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_41" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0041-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_41" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0042-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_42" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0042-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_42" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0043-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_43" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0043-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_43" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_01" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_01" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_01" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_02" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_02" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_02" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_03" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_03" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_03" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_04" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_04" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_04" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_05" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_05" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_05" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_06" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_06" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_06" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_07" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_07" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_07" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_08" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_08" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_08" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_09" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_09" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_09" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_10" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_10" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_10" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_11" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_11" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_11" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_12" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_12" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_12" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_13" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_13" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_13" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_14" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_14" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_14" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_15" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_15" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_15" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_16" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_16" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_16" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_17" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_17" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_17" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_18" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_18" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_18" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_19" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_19" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_19" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_20" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_20" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_20" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_21" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_21" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_21" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_22" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_22" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_22" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_23" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_23" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_23" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_24" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_24" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_24" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_25" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_25" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_25" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_26" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_26" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_26" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_27" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_27" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_27" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_28" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_28" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_28" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_29" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_29" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_29" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_30" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_30" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_30" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_31" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_31" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0031-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_31" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_32" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_32" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0032-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_32" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_33" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_33" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0033-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_33" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_34" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_34" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0034-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_34" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_35" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_35" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0035-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_35" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_36" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_36" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0036-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_36" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_37" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_37" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0037-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_37" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_38" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_38" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0038-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_38" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_39" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_39" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0039-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_39" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_40" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_40" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0040-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_40" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0041-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_41" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0041-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_41" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0041-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_41" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0042-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_42" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0042-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_42" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0042-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_42" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0043-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_43" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0043-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_43" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0043-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_43" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0044-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_44" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0044-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_44" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0044-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_44" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0045-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_45" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0045-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_45" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0045-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_45" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0046-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_46" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0046-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_46" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0046-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_46" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0047-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_47" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0047-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_47" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0047-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_47" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0048-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_48" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0048-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_48" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0048-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_48" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0049-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_49" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0049-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_49" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0049-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_49" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0050-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_50" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0050-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_50" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0050-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_50" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0051-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_51" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0051-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_51" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0051-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_51" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0052-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_52" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0052-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_52" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0052-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_52" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0053-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_53" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0053-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_53" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0053-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_53" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0054-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_54" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0054-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_54" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0054-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_54" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0055-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_55" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0055-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_55" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0055-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_55" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_01" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_01" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_01" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_02" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_02" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_02" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_03" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_03" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_03" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_04" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_04" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_04" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_05" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_05" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_05" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_06" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_06" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_06" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_07" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_07" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_07" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_08" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_08" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_08" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_09" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_09" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_09" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_10" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_10" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_10" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_11" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_11" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_11" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_12" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_12" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_12" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_13" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_13" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_13" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_14" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_14" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_14" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_15" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_15" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_15" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_16" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_16" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_16" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_17" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_17" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_17" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_18" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_18" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_18" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_19" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_19" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_19" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_20" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_20" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_20" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_21" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_21" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_21" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_22" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_22" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_22" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_23" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_23" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_23" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_24" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_24" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_24" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_25" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_25" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_25" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_26" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_26" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_26" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_27" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_27" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_27" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_28" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_28" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0028-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_28" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_29" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_29" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_29" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_30" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_30" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_30" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_31" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_31" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_31" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_32" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_32" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_32" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_33" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_33" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_33" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_34" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_34" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_34" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_35" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_35" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_35" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_36" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_36" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0036-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_36" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_37" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_37" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_37" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_38" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_38" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_38" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_39" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_39" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_39" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_40" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_40" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0040-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_40" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0041-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_41" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0041-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_41" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0041-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_41" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0042-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_42" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0042-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_42" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0042-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_42" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_43" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_43" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_43" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0044-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_44" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0044-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_44" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0044-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_44" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_45" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_45" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_45" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0046-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_46" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0046-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_46" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0046-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_46" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0047-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_47" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0047-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_47" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0047-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_47" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0048-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_48" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0048-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_48" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0048-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_48" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0049-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_49" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0049-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_49" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0049-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_49" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0050-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_50" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0050-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_50" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0050-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_50" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0051-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_51" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0051-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_51" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0051-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_51" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0052-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_52" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0052-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_52" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0052-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_52" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0053-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_53" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0053-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_53" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0053-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_53" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0054-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_54" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0054-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_54" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0054-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_54" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0055-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_55" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0055-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_55" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0055-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_55" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0056-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_56" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0056-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_56" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0056-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_56" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0057-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_57" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0057-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_57" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0057-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_57" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0058-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_58" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0058-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_58" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0058-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_58" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0059-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_59" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0059-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_59" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0059-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_59" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0060-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_60" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0060-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_60" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0060-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_60" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0061-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_61" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0061-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_61" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0061-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_61" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0062-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_62" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0062-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_62" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0062-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_62" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0063-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_63" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0063-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_63" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0063-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_63" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0064-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_64" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0064-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_64" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0064-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_64" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0065-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_65" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0065-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_65" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0065-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_65" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0016-0000-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_01" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_01" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_01" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_02" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_02" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0002-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_02" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_03" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_03" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0003-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_03" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_04" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_04" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0004-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_04" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_05" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_05" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0005-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_05" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_06" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_06" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0006-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_06" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_07" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_07" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0007-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_07" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_08" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_08" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0008-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_08" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_09" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_09" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0009-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_09" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_10" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_10" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0010-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_10" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_11" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_11" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0011-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_11" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_12" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_12" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0012-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_12" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_13" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_13" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_13" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_14" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_14" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0014-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_14" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_15" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_15" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0015-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_15" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_16" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_16" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0016-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_16" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_17" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_17" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0017-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_17" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_18" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_18" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0018-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_18" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_19" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_19" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0019-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_19" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_20" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_20" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0020-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_20" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_21" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_21" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0021-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_21" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_22" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_22" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0022-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_22" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_23" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_23" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0023-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_23" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_24" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_24" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0024-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_24" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_25" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_25" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_25" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_26" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_26" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0026-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_26" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_27" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_27" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0027-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_27" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_28" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_28" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0028-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_28" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_29" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_29" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0029-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_29" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_30" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_30" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0030-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_30" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_31" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_31" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0031-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_31" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_32" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_32" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0032-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_32" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_33" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_33" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0033-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_33" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_34" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_34" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0034-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_34" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_35" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_35" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0035-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_35" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_36" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_36" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0036-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_36" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_37" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_37" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0037-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_37" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_38" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_38" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0038-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_38" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_39" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_39" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0039-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_39" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_40" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_40" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0040-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_40" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0041-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_41" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0041-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_41" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0041-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_41" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0042-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_42" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0042-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_42" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0042-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_42" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0043-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_43" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0043-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_43" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0043-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_43" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0044-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_44" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0044-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_44" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0044-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_44" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_45" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0045-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_45" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-0045-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_45" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-309777827-4204377080-2083972359-1003_Classes\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}] @DACL=(02 0000) @="Java Plug-in 1.3.0_02" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . Zeit der Fertigstellung: 2014-01-08 17:19:04 ComboFix-quarantined-files.txt 2014-01-08 16:19 . Vor Suchlauf: 9 Verzeichnis(se), 10.276.663.296 Bytes frei Nach Suchlauf: 13 Verzeichnis(se), 10.269.921.280 Bytes frei . - - End Of File - - 9F772B21E5C95C79E875A9E6F6C2677D 5C616939100B85E558DA92B899A0FC36 Geändert von Virenkill (08.01.2014 um 17:57 Uhr) |
09.01.2014, 12:16 | #4 |
/// the machine /// TB-Ausbilder | Win32.Downloader.Gen infiziert Die klemmen wir nachher beim onlinescan an, dann kann man die grad mal mit scannen Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.01.2014, 21:48 | #5 |
| Win32.Downloader.Gen infiziert Hallo Die geforderten Logs Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.01.09.06 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Boss :: ARBEIT-PC [Administrator] Schutz: Aktiviert 09.01.2014 19:19:37 mbam-log-2014-01-09 (19-19-37).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 305358 Laufzeit: 8 Minute(n), 38 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Code:
ATTFilter # AdwCleaner v3.016 - Bericht erstellt am 09/01/2014 um 19:41:20 # Aktualisiert 23/12/2013 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzername : Boss - ARBEIT-PC # Gestartet von : C:\Users\Boss.Arbeit-PC\Desktop\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Conduit Datei Gelöscht : C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\browserprotect@browserprotect.com.xpi Datei Gelöscht : C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\searchplugins\Askcom.xml ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Toolbar Schlüssel Gelöscht : HKCU\Software\FLEXnet Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0} Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\464AA55239C100F32AF2D438EDDC0F47 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5652BA3D5FB98AE31B337BF0AF939856 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EB95E1AFCBABE3DB9ECCC669B99494 ***** [ Browser ] ***** -\\ Internet Explorer v9.0.8112.16526 Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] -\\ Mozilla Firefox v26.0 (de) [ Datei : C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\prefs.js ] Zeile gelöscht : user_pref("CT2319825..clientLogIsEnabled", true); Zeile gelöscht : user_pref("CT2319825..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent"); Zeile gelöscht : user_pref("CT2319825..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation"); Zeile gelöscht : user_pref("CT2319825.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Zeile gelöscht : user_pref("CT2319825.CT2319825", "CT2319825"); Zeile gelöscht : user_pref("CT2319825.CurrentServerDate", "16-5-2011"); Zeile gelöscht : user_pref("CT2319825.DialogsAlignMode", "LTR"); Zeile gelöscht : user_pref("CT2319825.DialogsGetterLastCheckTime", "Mon May 16 2011 09:01:07 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.DownloadReferralCookieData", ""); Zeile gelöscht : user_pref("CT2319825.EMailNotifierPollDate", "Mon May 16 2011 09:01:07 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.FeedPollDate11908299", "Mon May 16 2011 09:01:25 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.FirstServerDate", "16-5-2011"); Zeile gelöscht : user_pref("CT2319825.FirstTime", true); Zeile gelöscht : user_pref("CT2319825.FirstTimeFF3", true); Zeile gelöscht : user_pref("CT2319825.FixPageNotFoundErrors", false); Zeile gelöscht : user_pref("CT2319825.GroupingServerCheckInterval", 1440); Zeile gelöscht : user_pref("CT2319825.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Zeile gelöscht : user_pref("CT2319825.HasUserGlobalKeys", true); Zeile gelöscht : user_pref("CT2319825.Initialize", true); Zeile gelöscht : user_pref("CT2319825.InitializeCommonPrefs", true); Zeile gelöscht : user_pref("CT2319825.InstallationAndCookieDataSentCount", 1); Zeile gelöscht : user_pref("CT2319825.InstalledDate", "Mon May 16 2011 09:01:09 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.InvalidateCache", false); Zeile gelöscht : user_pref("CT2319825.IsGrouping", false); Zeile gelöscht : user_pref("CT2319825.IsMulticommunity", false); Zeile gelöscht : user_pref("CT2319825.IsOpenThankYouPage", true); Zeile gelöscht : user_pref("CT2319825.IsOpenUninstallPage", true); Zeile gelöscht : user_pref("CT2319825.LanguagePackLastCheckTime", "Mon May 16 2011 09:01:09 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.LanguagePackReloadIntervalMM", 1440); Zeile gelöscht : user_pref("CT2319825.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx"); Zeile gelöscht : user_pref("CT2319825.LastLogin_3.3.3.2", "Mon May 16 2011 09:01:08 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.LatestVersion", "3.3.3.2"); Zeile gelöscht : user_pref("CT2319825.Locale", "de"); Zeile gelöscht : user_pref("CT2319825.MCDetectTooltipHeight", "83"); Zeile gelöscht : user_pref("CT2319825.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Zeile gelöscht : user_pref("CT2319825.MCDetectTooltipWidth", "295"); Zeile gelöscht : user_pref("CT2319825.RadioIsPodcast", false); Zeile gelöscht : user_pref("CT2319825.RadioLastCheckTime", "Mon May 16 2011 09:01:10 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.RadioLastUpdateIPServer", "3"); Zeile gelöscht : user_pref("CT2319825.RadioLastUpdateServer", "129224641269630000"); Zeile gelöscht : user_pref("CT2319825.RadioMediaID", "11949532"); Zeile gelöscht : user_pref("CT2319825.RadioMediaType", "Media Player"); Zeile gelöscht : user_pref("CT2319825.RadioMenuSelectedID", "EBRadioMenu_CT231982511949532"); Zeile gelöscht : user_pref("CT2319825.RadioStationName", "1Live"); Zeile gelöscht : user_pref("CT2319825.RadioStationURL", "hxxp://gffstream.ic.llnwd.net/stream/gffstream_stream_wdr_einslive_a"); Zeile gelöscht : user_pref("CT2319825.SearchFromAddressBarIsInit", true); Zeile gelöscht : user_pref("CT2319825.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&q="); Zeile gelöscht : user_pref("CT2319825.SearchInNewTabEnabled", true); Zeile gelöscht : user_pref("CT2319825.SearchInNewTabIntervalMM", 1440); Zeile gelöscht : user_pref("CT2319825.SearchInNewTabLastCheckTime", "Mon May 16 2011 09:01:09 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID"); Zeile gelöscht : user_pref("CT2319825.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID"); Zeile gelöscht : user_pref("CT2319825.ServiceMapLastCheckTime", "Mon May 16 2011 09:01:04 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.SettingsLastCheckTime", "Mon May 16 2011 09:01:05 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.SettingsLastUpdate", "1300873232"); Zeile gelöscht : user_pref("CT2319825.ThirdPartyComponentsInterval", 504); Zeile gelöscht : user_pref("CT2319825.ThirdPartyComponentsLastCheck", "Mon May 16 2011 09:01:04 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.ThirdPartyComponentsLastUpdate", "1255344657"); Zeile gelöscht : user_pref("CT2319825.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2319825"); Zeile gelöscht : user_pref("CT2319825.UserID", "UN24597810772625465"); Zeile gelöscht : user_pref("CT2319825.WeatherNetwork", ""); Zeile gelöscht : user_pref("CT2319825.WeatherPollDate", "Mon May 16 2011 09:01:10 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.WeatherUnit", "C"); Zeile gelöscht : user_pref("CT2319825.alertChannelId", "715912"); Zeile gelöscht : user_pref("CT2319825.approveUntrustedApps", true); Zeile gelöscht : user_pref("CT2319825.backendstorage.id", "39363735313839"); Zeile gelöscht : user_pref("CT2319825.generalConfigFromLogin", "{\"SocialDomains\":\"social.conduit.com;apps.conduit.com;services.apps.conduit.com\",\"AppsDetectionUrlPattern\":\"hxxp://appdownload.conduit.com/\"}"); Zeile gelöscht : user_pref("CT2319825.globalFirstTimeInfoLastCheckTime", "Mon May 16 2011 09:01:10 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.isAppTrackingManagerOn", true); Zeile gelöscht : user_pref("CT2319825.myStuffEnabled", true); Zeile gelöscht : user_pref("CT2319825.myStuffPublihserMinWidth", 400); Zeile gelöscht : user_pref("CT2319825.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID"); Zeile gelöscht : user_pref("CT2319825.myStuffServiceIntervalMM", 1440); Zeile gelöscht : user_pref("CT2319825.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT"); Zeile gelöscht : user_pref("CT2319825.testingCtid", ""); Zeile gelöscht : user_pref("CT2319825.toolbarAppMetaDataLastCheckTime", "Mon May 16 2011 09:01:05 GMT+0200"); Zeile gelöscht : user_pref("CT2319825.toolbarContextMenuLastCheckTime", "Mon May 16 2011 09:01:10 GMT+0200"); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2319825", "\"1282729563\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=de", "L+tncv4eqt6Qm5T3dzChdA=="); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=de", "poKjTfHs0NrVUIalKI8jyg=="); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=de", "D/tN3YiKFksK+RjZytPhIA=="); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=de", "ZdrYrsEQox0wVf3yXX8zTQ=="); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"803651ba7facb1:0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3.2", "\"07b2625f8cb1:0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.3.2", "\"07b2625f8cb1:0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2319825", "\"634402944764300000\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "634356118310000000"); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2319825/CT2319825", "\"1300873232\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer_dead.gif", "\"0a8c48d3330c81:0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.gif", "\"0e2106f3030c81:0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif", "\"0f475394430c81:0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif", "\"08d9ef44430c81:0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif", "\"066e8863030c81:0\""); Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"634410529136300000\""); Zeile gelöscht : user_pref("CommunityToolbar.EngineHiddenByUser", true); Zeile gelöscht : user_pref("CommunityToolbar.EngineOwner", ""); Zeile gelöscht : user_pref("CommunityToolbar.EngineOwnerGuid", ""); Zeile gelöscht : user_pref("CommunityToolbar.EngineOwnerToolbarId", ""); Zeile gelöscht : user_pref("CommunityToolbar.IsEngineShown", true); Zeile gelöscht : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true); Zeile gelöscht : user_pref("CommunityToolbar.OriginalEngineOwner", ""); Zeile gelöscht : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", ""); Zeile gelöscht : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", ""); Zeile gelöscht : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", ""); Zeile gelöscht : user_pref("CommunityToolbar.ToolbarsList", "CT2319825"); Zeile gelöscht : user_pref("CommunityToolbar.ToolbarsList2", "CT2319825"); Zeile gelöscht : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Mon May 16 2011 09:01:08 GMT+0200"); Zeile gelöscht : user_pref("CommunityToolbar.alert.alertEnabled", false); Zeile gelöscht : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com"); Zeile gelöscht : user_pref("CommunityToolbar.alert.locale", "en"); Zeile gelöscht : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440); Zeile gelöscht : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Mon May 16 2011 09:01:04 GMT+0200"); Zeile gelöscht : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1303303927"); Zeile gelöscht : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20); Zeile gelöscht : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com"); Zeile gelöscht : user_pref("CommunityToolbar.alert.showTrayIcon", false); Zeile gelöscht : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300); Zeile gelöscht : user_pref("CommunityToolbar.alert.userId", "c5848d84-8a3a-4e7e-8104-d0380584d132"); Zeile gelöscht : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Mon May 16 2011 09:01:10 GMT+0200"); Zeile gelöscht : user_pref("CommunityToolbar.globalUserId", "656deec4-b699-4167-aea6-89192a5a354d"); Zeile gelöscht : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Zeile gelöscht : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); ************************* AdwCleaner[R0].txt - [14463 octets] - [23/12/2013 16:26:01] AdwCleaner[R1].txt - [14524 octets] - [23/12/2013 16:34:56] AdwCleaner[R2].txt - [14585 octets] - [23/12/2013 16:52:12] AdwCleaner[R3].txt - [14277 octets] - [09/01/2014 19:38:49] AdwCleaner[S0].txt - [14165 octets] - [09/01/2014 19:41:20] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [14226 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.0 (01.07.2014:1) OS: Windows Vista (TM) Home Premium x86 Ran by Boss on 09.01.2014 at 20:24:30,94 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Boss.Arbeit-PC\AppData\Roaming\mozilla\firefox\profiles\h76ekbgp.default\minidumps [5 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 09.01.2014 at 20:30:01,77 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-01-2014 01 Ran by Boss (administrator) on ARBEIT-PC on 09-01-2014 21:08:03 Running from C:\Users\Boss.Arbeit-PC\Desktop\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe () C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe () C:\Program Files\ATK Hotkey\ASLDRSrv.exe () C:\Program Files\ATKGFNEX\GFNEXSrv.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files\Canon\IJPLM\ijplmsvc.exe (Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (ATK0100) C:\Program Files\ATK Hotkey\HControl.exe () C:\Program Files\ATKOSD2\ATKOSD2.exe () C:\Program Files\Wireless Console 2\wcourier.exe (ATK) C:\Program Files\P4G\BatteryLife.exe (ATK) C:\Program Files\ASUS\Splendid\ACMON.exe (ASUSTeK) C:\Windows\System32\ACEngSvr.exe () C:\Program Files\ATK Hotkey\ATKOSD.exe () C:\Program Files\ATK Hotkey\KBFiltr.exe (ASUS) C:\Windows\System32\ASUSTPE.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Microsoft Corporation) C:\Windows\System32\conime.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2013-12-22] (AVAST Software) HKLM\...\Run: [Skytel] - Skytel.exe HKLM\...\Run: [amd_dc_opt] - C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [857648 2007-03-01] (Synaptics, Inc.) HKU\Boss\...\Run: [SpybotSD TeaTimer] - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [ 2009-03-05] (Safer-Networking Ltd.) HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\Gast\...\Run: [SpybotSD TeaTimer] - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [ 2009-03-05] (Safer-Networking Ltd.) HKU\Gast-Surfer\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\Weltnetz\...\Run: [SpybotSD TeaTimer] - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [ 2009-03-05] (Safer-Networking Ltd.) HKU\Weltnetz\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [ 2008-01-19] (Microsoft Corporation) HKU\Weltnetz\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\System32\spool\drivers\w32x86\3\E_TATIHVE.EXE [ 2012-07-12] (SEIKO EPSON CORPORATION) Startup: C:\Users\Weltnetz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk.disabled ShortcutTarget: OpenOffice.org 3.2.lnk.disabled -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File) Startup: C:\Users\Weltnetz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk.disabled ShortcutTarget: OpenOffice.org 3.3.lnk.disabled -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File) Startup: C:\Users\Weltnetz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File) Startup: C:\Users\Weltnetz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.lnk.disabled ShortcutTarget: OpenOffice.org 3.4.lnk.disabled -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\EPSON Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\EPSON Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [147456] (Apple Inc.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default FF SelectedSearchEngine: Google FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q= FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=6.0.12.775 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/npracplug;version=1.0.0.0 - C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll (RealNetworks) FF Plugin: @real.com/nprjplug;version=1.0.3.775 - C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprphtml5videoshim;version=1.0.0.0 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.775 - C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\glarysearch.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Unblock YouTube - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\ich@maltegoetz.de FF Extension: Ghostery - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\firefox@ghostery.com.xpi FF Extension: Google/Yandex search link fix - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\jid0-XWJxt5VvCXkKzQK99PhZqAn7Xbg@jetpack.xpi FF Extension: Restart Firefox - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\restart@restart.org.xpi FF Extension: Malware Search - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\{27c60876-b5c9-4335-b4f3-52b26782220c}.xpi FF Extension: NoScript - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF Extension: Adblock Plus - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: BetterPrivacy - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi FF Extension: Tab Mix Plus - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF ========================== Services (Whitelisted) ================= R2 ADSMService; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [73728 2007-05-18] () R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-02-06] () R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-05-15] () R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-22] (AVAST Software) R2 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [99936 2006-11-10] () S2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) S2 CLTNetCnService; "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [x] ==================== Drivers (Whitelisted) ==================== R0 AsDsm; C:\Windows\System32\Drivers\AsDsm.sys [27504 2007-04-25] (Windows (R) Codename Longhorn DDK provider) R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [11632 2007-02-05] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2013-12-22] (AVAST Software) R1 AswRdr; C:\Windows\system32\drivers\aswRdr.sys [54832 2013-12-22] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49944 2013-11-25] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [775952 2013-12-22] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [410528 2013-12-22] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57672 2013-12-22] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [180248 2013-12-22] () R0 BootDefragDriver; C:\Windows\System32\drivers\BootDefragDriver.sys [14080 2013-10-24] (<Glarysoft Ltd>) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [5632 2007-01-24] ( ) S3 KMWDFILTER; C:\Windows\System32\DRIVERS\KMWDFILTER.sys [17408 2008-10-09] (Windows (R) Codename Longhorn DDK provider) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100) S3 ProcObsrv; C:\Program Files\Glary Utilities 3\ProcObsrv.sys [11552 2013-10-28] (Glarysoft Ltd) S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1737984 2007-03-06] () S3 vsdatant; C:\Windows\system32\vsdatant.sys [394192 2007-03-09] (Zone Labs, LLC) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-19] (Microsoft Corporation) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 catchme; \??\C:\Users\BOSS~1.ARB\AppData\Local\Temp\catchme.sys [x] S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [x] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [x] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 RTSTOR; system32\drivers\RTSTOR.SYS [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-09 20:30 - 2014-01-09 20:30 - 00001089 _____ C:\Users\Boss.Arbeit-PC\Desktop\JRT.txt 2014-01-09 20:24 - 2014-01-09 20:24 - 00000000 ____D C:\Windows\ERUNT 2014-01-09 20:01 - 2014-01-08 17:15 - 00000027 _____ C:\Windows\system32\Drivers\etc\hosts.20140109-200132.backup 2014-01-09 19:07 - 2014-01-09 19:07 - 00000000 ____D C:\Users\Boss.Arbeit-PC\AppData\Roaming\Malwarebytes 2014-01-09 19:06 - 2014-01-09 19:06 - 00000873 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-09 19:06 - 2014-01-09 19:06 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-09 19:06 - 2014-01-09 19:06 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2014-01-09 19:06 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-08 17:19 - 2014-01-08 17:19 - 00118429 _____ C:\ComboFix.txt 2014-01-08 16:43 - 2014-01-08 17:19 - 00000000 ____D C:\Qoobox 2014-01-08 16:43 - 2014-01-08 17:19 - 00000000 ____D C:\ComboFix 2014-01-08 16:43 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-08 16:43 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-08 16:43 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-08 16:43 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-08 16:43 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-08 16:43 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-08 16:43 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-08 16:43 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-08 16:42 - 2014-01-08 17:17 - 00000000 ____D C:\Windows\erdnt 2014-01-08 16:24 - 2014-01-08 16:25 - 05162308 ____R (Swearware) C:\Users\Boss.Arbeit-PC\Desktop\ComboFix.exe 2014-01-07 19:44 - 2014-01-09 21:07 - 00000000 ____D C:\FRST 2014-01-07 19:35 - 2014-01-07 19:35 - 00000470 _____ C:\Users\Boss.Arbeit-PC\Downloads\defogger_disable.log 2014-01-07 19:35 - 2014-01-07 19:35 - 00000000 _____ C:\Users\Boss.Arbeit-PC\defogger_reenable 2014-01-07 19:32 - 2014-01-07 19:32 - 00050477 _____ C:\Users\Boss.Arbeit-PC\Downloads\Defogger.exe 2013-12-23 16:25 - 2014-01-09 19:41 - 00000000 ____D C:\AdwCleaner 2013-12-23 15:00 - 2013-12-23 15:00 - 00006943 _____ C:\Users\Weltnetz\Desktop\hijackthis.log 2013-12-23 14:59 - 2013-12-23 14:59 - 00388608 _____ (Trend Micro Inc.) C:\Users\Weltnetz\Desktop\hijackthis.exe 2013-12-22 21:59 - 2013-12-22 21:59 - 00000000 _____ C:\Windows\setuperr.log 2013-12-22 21:59 - 2013-12-22 21:59 - 00000000 _____ C:\Windows\setupact.log 2013-12-22 21:58 - 2013-12-22 21:58 - 00000000 ____D C:\Users\Boss.Arbeit-PC\AppData\Roaming\AVAST Software 2013-12-17 09:47 - 2013-12-17 09:47 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-12-16 22:43 - 2013-11-15 00:13 - 12344320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-16 22:43 - 2013-11-14 23:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-16 22:43 - 2013-11-14 23:50 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-16 22:43 - 2013-11-14 23:43 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-16 22:43 - 2013-11-14 23:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-16 22:43 - 2013-11-14 23:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-16 22:43 - 2013-11-14 23:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-16 22:43 - 2013-11-14 23:40 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-16 22:43 - 2013-11-14 23:38 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-16 22:43 - 2013-11-14 23:38 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-16 22:43 - 2013-11-14 23:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-16 22:43 - 2013-11-14 23:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-16 22:43 - 2013-11-14 23:36 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-16 22:43 - 2013-11-14 23:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-16 22:43 - 2013-11-14 23:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-16 22:43 - 2013-11-14 23:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-16 22:08 - 2013-12-16 22:08 - 00010240 _____ C:\Users\Weltnetz\Desktop\Wochenplan 2014--3KW.xls 2013-12-16 11:53 - 2013-10-30 03:12 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2013-12-16 11:53 - 2013-10-30 02:43 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-16 11:53 - 2013-10-30 01:43 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-16 11:53 - 2013-10-30 01:35 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-16 11:53 - 2013-10-22 08:19 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-16 11:53 - 2013-10-11 03:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-16 11:53 - 2013-10-11 03:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-16 11:53 - 2013-10-11 03:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wshcon.dll 2013-12-16 11:53 - 2013-10-11 01:35 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-16 11:53 - 2013-10-11 01:35 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe ==================== One Month Modified Files and Folders ======= 2014-01-09 21:07 - 2014-01-07 19:44 - 00000000 ____D C:\FRST 2014-01-09 20:57 - 2012-08-27 09:43 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-09 20:30 - 2014-01-09 20:30 - 00001089 _____ C:\Users\Boss.Arbeit-PC\Desktop\JRT.txt 2014-01-09 20:24 - 2014-01-09 20:24 - 00000000 ____D C:\Windows\ERUNT 2014-01-09 20:23 - 2011-04-05 07:25 - 00049340 _____ C:\ProgramData\nvModes.001 2014-01-09 20:23 - 2008-05-24 16:38 - 01839693 _____ C:\Windows\WindowsUpdate.log 2014-01-09 20:22 - 2011-01-12 14:35 - 00000000 ____D C:\Users\Boss.Arbeit-PC\AppData\Roaming\Macromedia 2014-01-09 19:45 - 2013-10-08 06:35 - 00000320 _____ C:\Windows\Tasks\GlaryInitialize 3.job 2014-01-09 19:44 - 2008-05-24 17:14 - 00045056 _____ C:\Windows\system32\acovcnt.exe 2014-01-09 19:43 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-09 19:43 - 2006-11-02 13:47 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-09 19:43 - 2006-11-02 13:47 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-09 19:42 - 2007-04-18 09:33 - 00000012 _____ C:\Windows\bthservsdp.dat 2014-01-09 19:42 - 2006-11-02 14:01 - 00032534 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-09 19:41 - 2013-12-23 16:25 - 00000000 ____D C:\AdwCleaner 2014-01-09 19:07 - 2014-01-09 19:07 - 00000000 ____D C:\Users\Boss.Arbeit-PC\AppData\Roaming\Malwarebytes 2014-01-09 19:06 - 2014-01-09 19:06 - 00000873 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-09 19:06 - 2014-01-09 19:06 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-09 19:06 - 2014-01-09 19:06 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2014-01-08 17:26 - 2013-10-08 06:35 - 00000000 ____D C:\Program Files\Glary Utilities 3 2014-01-08 17:25 - 2013-11-17 20:11 - 00082774 _____ C:\Windows\PFRO.log 2014-01-08 17:19 - 2014-01-08 17:19 - 00118429 _____ C:\ComboFix.txt 2014-01-08 17:19 - 2014-01-08 16:43 - 00000000 ____D C:\Qoobox 2014-01-08 17:19 - 2014-01-08 16:43 - 00000000 ____D C:\ComboFix 2014-01-08 17:19 - 2006-11-02 12:18 - 00000000 ___RD C:\Users\Public 2014-01-08 17:17 - 2014-01-08 16:42 - 00000000 ____D C:\Windows\erdnt 2014-01-08 17:15 - 2014-01-09 20:01 - 00000027 _____ C:\Windows\system32\Drivers\etc\hosts.20140109-200132.backup 2014-01-08 17:15 - 2006-11-02 11:23 - 00000215 _____ C:\Windows\system.ini 2014-01-08 17:14 - 2010-11-17 20:00 - 00000000 ____D C:\Users\Weltnetz 2014-01-08 16:25 - 2014-01-08 16:24 - 05162308 ____R (Swearware) C:\Users\Boss.Arbeit-PC\Desktop\ComboFix.exe 2014-01-07 19:41 - 2010-11-22 13:39 - 00056312 _____ C:\Users\Boss.Arbeit-PC\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-07 19:35 - 2014-01-07 19:35 - 00000470 _____ C:\Users\Boss.Arbeit-PC\Downloads\defogger_disable.log 2014-01-07 19:35 - 2014-01-07 19:35 - 00000000 _____ C:\Users\Boss.Arbeit-PC\defogger_reenable 2014-01-07 19:35 - 2010-11-22 13:36 - 00000000 ____D C:\Users\Boss.Arbeit-PC 2014-01-07 19:32 - 2014-01-07 19:32 - 00050477 _____ C:\Users\Boss.Arbeit-PC\Downloads\Defogger.exe 2014-01-07 19:22 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20140107-220044.backup 2014-01-07 14:49 - 2010-11-22 13:18 - 00000000 ____D C:\Users\Weltnetz\AppData\Roaming\Macromedia 2013-12-23 20:47 - 2011-04-05 07:25 - 00049340 _____ C:\ProgramData\nvModes.dat 2013-12-23 20:09 - 2012-07-15 21:49 - 00000000 ____D C:\Program Files\FRITZ! 2013-12-23 20:05 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20140107-192252.backup 2013-12-23 20:00 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20131223-200515.backup 2013-12-23 18:12 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20131223-200034.backup 2013-12-23 18:07 - 2010-09-28 11:34 - 00000011 _____ C:\Windows\BRVIDEO.INI 2013-12-23 18:07 - 2010-09-28 11:27 - 00000088 _____ C:\Windows\Brownie.ini 2013-12-23 18:04 - 2011-03-01 11:17 - 00000000 ____D C:\Users\Boss.Arbeit-PC\AppData\Roaming\GlarySoft 2013-12-23 16:54 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20131223-181240.backup 2013-12-23 16:40 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20131223-165456.backup 2013-12-23 15:00 - 2013-12-23 15:00 - 00006943 _____ C:\Users\Weltnetz\Desktop\hijackthis.log 2013-12-23 14:59 - 2013-12-23 14:59 - 00388608 _____ (Trend Micro Inc.) C:\Users\Weltnetz\Desktop\hijackthis.exe 2013-12-23 11:28 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20131223-164059.backup 2013-12-22 23:40 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20131223-112820.backup 2013-12-22 23:31 - 2013-03-10 20:24 - 00000000 ____D C:\Users\Weltnetz\Desktop\Revisionen 13 2013-12-22 23:31 - 2013-01-07 16:36 - 00000000 ____D C:\Users\Weltnetz\Desktop\Wochenpläne 2013 2013-12-22 21:59 - 2013-12-22 21:59 - 00000000 _____ C:\Windows\setuperr.log 2013-12-22 21:59 - 2013-12-22 21:59 - 00000000 _____ C:\Windows\setupact.log 2013-12-22 21:58 - 2013-12-22 21:58 - 00000000 ____D C:\Users\Boss.Arbeit-PC\AppData\Roaming\AVAST Software 2013-12-22 21:51 - 2013-11-25 18:44 - 00001840 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-12-22 21:51 - 2013-03-19 09:46 - 00180248 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-12-22 21:51 - 2012-12-15 16:11 - 00410528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-12-22 21:51 - 2012-12-15 16:10 - 00775952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-12-22 21:51 - 2012-12-15 16:10 - 00270240 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-12-22 21:51 - 2012-12-15 16:10 - 00067824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-12-22 21:51 - 2012-12-15 16:10 - 00057672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-12-22 21:51 - 2012-12-15 16:10 - 00054832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr.sys 2013-12-22 21:51 - 2012-12-15 16:10 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-12-19 09:53 - 2012-04-26 17:52 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-12-17 09:47 - 2013-12-17 09:47 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-12-17 09:40 - 2006-11-02 13:47 - 00261944 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-17 09:35 - 2013-01-14 12:53 - 00000000 ____D C:\Windows\system32\RTCOM 2013-12-16 22:47 - 2013-08-15 20:38 - 00000000 ____D C:\Windows\system32\MRT 2013-12-16 22:44 - 2006-11-02 11:24 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-12-16 22:08 - 2013-12-16 22:08 - 00010240 _____ C:\Users\Weltnetz\Desktop\Wochenplan 2014--3KW.xls 2013-12-16 13:37 - 2012-04-04 12:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-12-16 13:37 - 2011-08-18 08:27 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-12-11 12:05 - 2006-11-02 11:33 - 01445352 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-10 09:51 - 2011-10-07 13:43 - 00000000 ____D C:\Users\Weltnetz\Desktop\Arbeit Some content of TEMP: ==================== C:\Users\Boss.Arbeit-PC\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-09 19:51 ==================== End Of Log ============================ --- --- --- --- --- --- DANKE Geändert von Virenkill (09.01.2014 um 22:01 Uhr) Grund: Verschönerung |
10.01.2014, 12:10 | #6 |
/// the machine /// TB-Ausbilder | Win32.Downloader.Gen infiziertESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Win32.Downloader.Gen infiziert |
20.01.2014, 21:04 | #7 |
| Win32.Downloader.Gen infiziert Hallo Da bin ich wieder Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=a1c6808c21acb24bb0e25beb6a8c04a6 # engine=16709 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-19 07:42:10 # local_time=2014-01-19 08:42:10 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=774 16777213 85 77 2418370 6962214 0 0 # compatibility_mode=5892 16776638 100 100 862082 227693258 0 0 # compatibility_mode=9217 16777214 25 14 163085518 164450160 0 0 # scanned=149110 # found=0 # cleaned=0 # scan_time=16291 Code:
ATTFilter Results of screen317's Security Check version 0.99.79 Windows Vista Service Pack 2 x86 (UAC is enabled) Internet Explorer 9 Internet Explorer 8 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` MVPS Hosts File Spybot - Search & Destroy CCleaner JavaFX 2.1.1 Java 7 Update 45 Java version out of Date! Adobe Flash Player 12.0.0.43 Adobe Reader 9 Adobe Reader XI Mozilla Firefox (26.0) ````````Process Check: objlist.exe by Laurent```````` Spybot Teatimer.exe is disabled! AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-01-2014 04 Ran by Boss (administrator) on ARBEIT-PC on 19-01-2014 21:33:26 Running from C:\Users\Boss.Arbeit-PC\Desktop\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe () C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe () C:\Program Files\ATK Hotkey\ASLDRSrv.exe () C:\Program Files\ATKGFNEX\GFNEXSrv.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files\Canon\IJPLM\ijplmsvc.exe (Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (ATK0100) C:\Program Files\ATK Hotkey\HControl.exe () C:\Program Files\ATKOSD2\ATKOSD2.exe () C:\Program Files\Wireless Console 2\wcourier.exe (ATK) C:\Program Files\P4G\BatteryLife.exe (ATK) C:\Program Files\ASUS\Splendid\ACMON.exe () C:\Program Files\ATK Hotkey\ATKOSD.exe () C:\Program Files\ATK Hotkey\KBFiltr.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (ASUSTeK) C:\Windows\System32\ACEngSvr.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Windows\System32\conime.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2013-12-22] (AVAST Software) HKLM\...\Run: [amd_dc_opt] - C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [857648 2007-03-01] (Synaptics, Inc.) HKU\Boss\...\Run: [SpybotSD TeaTimer] - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [ 2009-03-05] (Safer-Networking Ltd.) HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\system32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\Gast\...\Run: [SpybotSD TeaTimer] - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [ 2009-03-05] (Safer-Networking Ltd.) HKU\Gast-Surfer\...\Run: [WindowsWelcomeCenter] - C:\Windows\system32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\Weltnetz\...\Run: [SpybotSD TeaTimer] - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [ 2009-03-05] (Safer-Networking Ltd.) HKU\Weltnetz\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [ 2008-01-19] (Microsoft Corporation) HKU\Weltnetz\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\system32\spool\DRIVERS\W32X86\3\E_TATIHVE.EXE [ 2012-07-12] (SEIKO EPSON CORPORATION) Startup: C:\Users\Weltnetz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk.disabled ShortcutTarget: OpenOffice.org 3.2.lnk.disabled -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File) Startup: C:\Users\Weltnetz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk.disabled ShortcutTarget: OpenOffice.org 3.3.lnk.disabled -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File) Startup: C:\Users\Weltnetz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File) Startup: C:\Users\Weltnetz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.lnk.disabled ShortcutTarget: OpenOffice.org 3.4.lnk.disabled -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [147456] (Apple Inc.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default FF SelectedSearchEngine: Google FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q= FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_43.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=6.0.12.775 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/npracplug;version=1.0.0.0 - C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll (RealNetworks) FF Plugin: @real.com/nprjplug;version=1.0.3.775 - C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprphtml5videoshim;version=1.0.0.0 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.775 - C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npracplug.dll (RealNetworks) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprjplug.dll (RealNetworks, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll (RealNetworks, Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\glarysearch.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Unblock YouTube - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\ich@maltegoetz.de [2013-12-22] FF Extension: Ghostery - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\firefox@ghostery.com.xpi [2013-09-25] FF Extension: Google/Yandex search link fix - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\jid0-XWJxt5VvCXkKzQK99PhZqAn7Xbg@jetpack.xpi [2012-10-22] FF Extension: Restart Firefox - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\restart@restart.org.xpi [2011-04-10] FF Extension: Malware Search - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\{27c60876-b5c9-4335-b4f3-52b26782220c}.xpi [2012-10-22] FF Extension: NoScript - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2011-05-16] FF Extension: Adblock Plus - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011-05-16] FF Extension: BetterPrivacy - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2011-05-16] FF Extension: Tab Mix Plus - C:\Users\Boss.Arbeit-PC\AppData\Roaming\Mozilla\Firefox\Profiles\h76ekbgp.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2011-05-16] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010-09-20] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-12-15] ========================== Services (Whitelisted) ================= R2 ADSMService; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [73728 2007-05-18] () R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-02-06] () R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-05-15] () R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-22] (AVAST Software) R2 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [99936 2006-11-10] () R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) S2 CLTNetCnService; "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [x] ==================== Drivers (Whitelisted) ==================== R0 AsDsm; C:\Windows\System32\Drivers\AsDsm.sys [27504 2007-04-25] (Windows (R) Codename Longhorn DDK provider) R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [11632 2007-02-05] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2013-12-22] (AVAST Software) R1 AswRdr; C:\Windows\system32\drivers\aswRdr.sys [54832 2013-12-22] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49944 2013-11-25] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [775952 2013-12-22] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [410528 2013-12-22] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57672 2013-12-22] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [180248 2013-12-22] () R0 BootDefragDriver; C:\Windows\System32\drivers\BootDefragDriver.sys [14080 2013-10-24] (<Glarysoft Ltd>) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [5632 2007-01-24] ( ) S3 KMWDFILTER; C:\Windows\System32\DRIVERS\KMWDFILTER.sys [17408 2008-10-09] (Windows (R) Codename Longhorn DDK provider) R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100) R3 ProcObsrv; C:\Program Files\Glary Utilities 3\ProcObsrv.sys [11552 2013-10-28] (Glarysoft Ltd) S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1737984 2007-03-06] () S3 vsdatant; C:\Windows\system32\vsdatant.sys [394192 2007-03-09] (Zone Labs, LLC) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-19] (Microsoft Corporation) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [x] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [x] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 RTSTOR; system32\drivers\RTSTOR.SYS [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-19 21:25 - 2014-01-19 21:25 - 00001029 _____ C:\Users\Boss.Arbeit-PC\Desktop\securitycheckup.txt 2014-01-19 16:06 - 2014-01-19 16:06 - 00000000 ____D C:\Program Files\ESET 2014-01-15 18:23 - 2014-01-15 18:26 - 00000000 ____D C:\Users\Weltnetz\Desktop\Wochenplan 2014 2014-01-09 20:24 - 2014-01-09 20:24 - 00000000 ____D C:\Windows\ERUNT 2014-01-09 20:01 - 2014-01-08 17:15 - 00000027 _____ C:\Windows\system32\Drivers\etc\hosts.20140109-200132.backup 2014-01-09 19:07 - 2014-01-09 19:07 - 00000000 ____D C:\Users\Boss.Arbeit-PC\AppData\Roaming\Malwarebytes 2014-01-09 19:06 - 2014-01-09 19:06 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-08 17:19 - 2014-01-08 17:19 - 00118429 _____ C:\ComboFix.txt 2014-01-08 16:43 - 2014-01-08 17:19 - 00000000 ____D C:\Qoobox 2014-01-08 16:43 - 2014-01-08 17:19 - 00000000 ____D C:\ComboFix 2014-01-08 16:43 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-08 16:43 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-08 16:43 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-08 16:43 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-08 16:43 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-08 16:43 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-08 16:43 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-08 16:43 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-08 16:42 - 2014-01-08 17:17 - 00000000 ____D C:\Windows\erdnt 2014-01-08 16:24 - 2014-01-08 16:25 - 05162308 ____R (Swearware) C:\Users\Boss.Arbeit-PC\Desktop\ComboFix.exe 2014-01-07 19:44 - 2014-01-19 21:28 - 00000000 ____D C:\FRST 2014-01-07 19:35 - 2014-01-07 19:35 - 00000470 _____ C:\Users\Boss.Arbeit-PC\Downloads\defogger_disable.log 2014-01-07 19:35 - 2014-01-07 19:35 - 00000000 _____ C:\Users\Boss.Arbeit-PC\defogger_reenable 2014-01-07 19:32 - 2014-01-07 19:32 - 00050477 _____ C:\Users\Boss.Arbeit-PC\Downloads\Defogger.exe 2013-12-23 16:25 - 2014-01-09 19:41 - 00000000 ____D C:\AdwCleaner 2013-12-22 21:59 - 2013-12-22 21:59 - 00000000 _____ C:\Windows\setuperr.log 2013-12-22 21:59 - 2013-12-22 21:59 - 00000000 _____ C:\Windows\setupact.log 2013-12-22 21:58 - 2013-12-22 21:58 - 00000000 ____D C:\Users\Boss.Arbeit-PC\AppData\Roaming\AVAST Software ==================== One Month Modified Files and Folders ======= 2014-01-19 21:30 - 2011-01-12 14:35 - 00000000 ____D C:\Users\Boss.Arbeit-PC\AppData\Roaming\Macromedia 2014-01-19 21:28 - 2014-01-07 19:44 - 00000000 ____D C:\FRST 2014-01-19 21:25 - 2014-01-19 21:25 - 00001029 _____ C:\Users\Boss.Arbeit-PC\Desktop\securitycheckup.txt 2014-01-19 21:19 - 2008-05-24 16:38 - 01984357 _____ C:\Windows\WindowsUpdate.log 2014-01-19 21:01 - 2006-11-02 13:47 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-19 21:01 - 2006-11-02 13:47 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-19 20:37 - 2012-08-27 09:43 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-19 16:06 - 2014-01-19 16:06 - 00000000 ____D C:\Program Files\ESET 2014-01-19 16:05 - 2011-04-05 07:25 - 00049340 _____ C:\ProgramData\nvModes.001 2014-01-19 16:03 - 2012-04-04 12:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-01-19 16:03 - 2011-08-18 08:27 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-01-19 16:03 - 2011-01-12 14:31 - 00000000 ____D C:\Users\Boss.Arbeit-PC\AppData\Local\Adobe 2014-01-19 15:07 - 2013-10-08 06:35 - 00000320 _____ C:\Windows\Tasks\GlaryInitialize 3.job 2014-01-19 15:07 - 2013-10-08 06:35 - 00000000 ____D C:\Program Files\Glary Utilities 3 2014-01-19 15:01 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-19 14:58 - 2007-04-18 09:33 - 00000012 _____ C:\Windows\bthservsdp.dat 2014-01-19 14:58 - 2006-11-02 14:01 - 00032534 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-19 14:57 - 2006-11-02 11:33 - 01445352 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-16 06:30 - 2008-05-24 17:14 - 00045056 _____ C:\Windows\system32\acovcnt.exe 2014-01-15 21:40 - 2010-11-22 13:18 - 00000000 ____D C:\Users\Weltnetz\AppData\Roaming\Macromedia 2014-01-15 21:11 - 2013-01-07 16:36 - 00000000 ____D C:\Users\Weltnetz\Desktop\Wochenpläne 2013 2014-01-15 19:09 - 2011-10-07 13:43 - 00000000 ____D C:\Users\Weltnetz\Desktop\Arbeit 2014-01-15 18:26 - 2014-01-15 18:23 - 00000000 ____D C:\Users\Weltnetz\Desktop\Wochenplan 2014 2014-01-15 18:22 - 2011-01-26 10:50 - 00000000 ____D C:\Users\Weltnetz\Desktop\System 2014-01-15 18:21 - 2013-03-10 20:24 - 00000000 ____D C:\Users\Weltnetz\Desktop\Revisionen 13 2014-01-09 20:24 - 2014-01-09 20:24 - 00000000 ____D C:\Windows\ERUNT 2014-01-09 19:41 - 2013-12-23 16:25 - 00000000 ____D C:\AdwCleaner 2014-01-09 19:07 - 2014-01-09 19:07 - 00000000 ____D C:\Users\Boss.Arbeit-PC\AppData\Roaming\Malwarebytes 2014-01-09 19:06 - 2014-01-09 19:06 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-08 17:25 - 2013-11-17 20:11 - 00082774 _____ C:\Windows\PFRO.log 2014-01-08 17:19 - 2014-01-08 17:19 - 00118429 _____ C:\ComboFix.txt 2014-01-08 17:19 - 2014-01-08 16:43 - 00000000 ____D C:\Qoobox 2014-01-08 17:19 - 2014-01-08 16:43 - 00000000 ____D C:\ComboFix 2014-01-08 17:19 - 2006-11-02 12:18 - 00000000 ___RD C:\Users\Public 2014-01-08 17:17 - 2014-01-08 16:42 - 00000000 ____D C:\Windows\erdnt 2014-01-08 17:15 - 2014-01-09 20:01 - 00000027 _____ C:\Windows\system32\Drivers\etc\hosts.20140109-200132.backup 2014-01-08 17:15 - 2006-11-02 11:23 - 00000215 _____ C:\Windows\system.ini 2014-01-08 17:14 - 2010-11-17 20:00 - 00000000 ____D C:\Users\Weltnetz 2014-01-08 16:25 - 2014-01-08 16:24 - 05162308 ____R (Swearware) C:\Users\Boss.Arbeit-PC\Desktop\ComboFix.exe 2014-01-07 19:41 - 2010-11-22 13:39 - 00056312 _____ C:\Users\Boss.Arbeit-PC\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-07 19:35 - 2014-01-07 19:35 - 00000470 _____ C:\Users\Boss.Arbeit-PC\Downloads\defogger_disable.log 2014-01-07 19:35 - 2014-01-07 19:35 - 00000000 _____ C:\Users\Boss.Arbeit-PC\defogger_reenable 2014-01-07 19:35 - 2010-11-22 13:36 - 00000000 ____D C:\Users\Boss.Arbeit-PC 2014-01-07 19:32 - 2014-01-07 19:32 - 00050477 _____ C:\Users\Boss.Arbeit-PC\Downloads\Defogger.exe 2014-01-07 19:22 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20140107-220044.backup 2013-12-23 20:47 - 2011-04-05 07:25 - 00049340 _____ C:\ProgramData\nvModes.dat 2013-12-23 20:09 - 2012-07-15 21:49 - 00000000 ____D C:\Program Files\FRITZ! 2013-12-23 20:05 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20140107-192252.backup 2013-12-23 20:00 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20131223-200515.backup 2013-12-23 18:12 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20131223-200034.backup 2013-12-23 18:07 - 2010-09-28 11:34 - 00000011 _____ C:\Windows\BRVIDEO.INI 2013-12-23 18:07 - 2010-09-28 11:27 - 00000088 _____ C:\Windows\Brownie.ini 2013-12-23 18:04 - 2011-03-01 11:17 - 00000000 ____D C:\Users\Boss.Arbeit-PC\AppData\Roaming\GlarySoft 2013-12-23 16:54 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20131223-181240.backup 2013-12-23 16:40 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20131223-165456.backup 2013-12-23 11:28 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20131223-164059.backup 2013-12-22 23:40 - 2006-11-02 11:23 - 00450597 ____R C:\Windows\system32\Drivers\etc\hosts.20131223-112820.backup 2013-12-22 21:59 - 2013-12-22 21:59 - 00000000 _____ C:\Windows\setuperr.log 2013-12-22 21:59 - 2013-12-22 21:59 - 00000000 _____ C:\Windows\setupact.log 2013-12-22 21:58 - 2013-12-22 21:58 - 00000000 ____D C:\Users\Boss.Arbeit-PC\AppData\Roaming\AVAST Software 2013-12-22 21:51 - 2013-11-25 18:44 - 00001840 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-12-22 21:51 - 2013-03-19 09:46 - 00180248 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-12-22 21:51 - 2012-12-15 16:11 - 00410528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-12-22 21:51 - 2012-12-15 16:10 - 00775952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-12-22 21:51 - 2012-12-15 16:10 - 00270240 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-12-22 21:51 - 2012-12-15 16:10 - 00067824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-12-22 21:51 - 2012-12-15 16:10 - 00057672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-12-22 21:51 - 2012-12-15 16:10 - 00054832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr.sys 2013-12-22 21:51 - 2012-12-15 16:10 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr Some content of TEMP: ==================== |
21.01.2014, 11:55 | #8 |
/// the machine /// TB-Ausbilder | Win32.Downloader.Gen infiziert Java updaten. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Win32.Downloader.Gen infiziert |
adblock, andere, applaus, canon, device driver, entferne, entfernen, externe, externe festplatte, festplatte, frohes, infiziert, konnte, laptop, launch, melde, nicht mehr, nicht sicher, platte, plug-in, probleme, programm, safer networking, schadsoftware, win, win32.downloader.gen, wirklich |