|
Log-Analyse und Auswertung: GreatSaver infiziertWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
10.01.2014, 15:42 | #1 |
| GreatSaver infiziert Ich habe ausversehen greatsaver installiert. Maßnahmen: Junkware Remove tool, ADWCleaner, MAM quickscan, FRST, GMER, defogger, bei Programme suchen (nicht gefunden). Addition: FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-01-2014 Ran by 00yoshi at 2014-01-10 14:20:50 Running from C:\Users\00yoshi\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0 - Igor Pavlov) Adobe AIR (x32 Version: 3.7.0.1860 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.7.0.1860 - Adobe Systems Incorporated) Hidden Adobe Download Assistant (x32 Version: 1.2.3 - Adobe Systems Incorporated) Adobe Download Assistant (x32 Version: 1.2.3 - Adobe Systems Incorporated) Hidden Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.152 - Adobe Systems Incorporated) Adobe Photoshop CS6 (x32 Version: 13.0 - Adobe Systems Incorporated) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (x32 Version: 12.0.4.144 - Adobe Systems, Inc.) AIDA64 Extreme v4.00 (x32 Version: 4.00 - FinalWire Ltd.) Alice-Installationsdateien entfernen (x32 Version: - ) AntiBrowserSpy (x32 Version: 4.0.110 - Abelssoft) Ashampoo Burning Studio (x32 Version: 10.0.10 - Ashampoo GmbH & Co. KG) Ashampoo Photo Commander (x32 Version: 9.2.0 - Ashampoo GmbH & Co. KG) Ashampoo Photo Optimizer (x32 Version: 4.0.0 - Ashampoo GmbH & Co. KG) Ashampoo Registry Cleaner v.1.0.0 (x32 Version: 1.0.0 - Ashampoo GmbH & Co. KG) Ashampoo Snap (x32 Version: 4.3.0 - Ashampoo GmbH & Co. KG) Asmedia ASM104x USB 3.0 Host Controller Driver (x32 Version: 1.12.5.0 - Asmedia Technology) Audacity 2.0.3 (x32 Version: 2.0.3 - Audacity Team) Bluetooth Stack for Windows by Toshiba (Version: v5.10.14 - ) Camtasia Studio 7 (x32 Version: 7.0.1 - TechSmith Corporation) Camtasia Studio 8 (x32 Version: 8.0.4.1060 - TechSmith Corporation) CCleaner (Version: 3.19 - Piriform) COMPUTERBILD Alles-Öffner (x32 Version: 1.0.8 - J3S) COMPUTERBILD Alles-Öffner (x32 Version: 1.0.8 - J3S) Hidden COMPUTERBILD-Abzockschutz (x32 Version: 1.0.42 - J3S) Corel Graphics - Windows Shell Extension (x32 Version: 15.2.0.686 - Corel Corporation) Corel Graphics - Windows Shell Extension (x32 Version: 15.2.686 - Corel Corporation) Hidden Corel Graphics - Windows Shell Extension 64 Bit (Version: 15.2.686 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Common (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Connect (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Custom Data (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - DE (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Draw (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - EN (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - ES (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Extra Content (x32 Version: - Corel Corporation) CorelDRAW Essentials X5 - Extra Content (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Filters (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - FR (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - IPM (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - IT (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - PHOTO-PAINT (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Redist (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Setup Files (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - WT (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 (x32 Version: 15.2.0.686 - Corel Corporation) CorelDRAW Essentials X5 (x32 Version: 15.3 - Corel Corporation) Hidden Counter-Strike 1.6 (x32 Version: - ) Counter-Strike Xtreme V6 (x32 Version: - ) Craften Terminal 3.4.5011.37604 (x32 Version: 3.4.5011.37604 - Craften.de) Crazy Machines II - Gold (x32 Version: 1.03 - FAKT Software GmbH) CS16 Full v32.1 Non-Steam (x32 Version: - ) CyberLink LabelPrint (x32 Version: 2.5.3418 - CyberLink Corp.) CyberLink LabelPrint (x32 Version: 2.5.3418 - CyberLink Corp.) Hidden CyberLink MediaEspresso (x32 Version: 6.5.1817_38674 - CyberLink Corp.) CyberLink MediaEspresso (x32 Version: 6.5.1817_38674 - CyberLink Corp.) Hidden CyberLink Power2Go (x32 Version: 7.0.0.1327 - CyberLink Corp.) CyberLink Power2Go (x32 Version: 7.0.0.1327 - CyberLink Corp.) Hidden CyberLink PowerDVD Copy (x32 Version: 1.5.1306 - CyberLink Corp.) CyberLink PowerDVD Copy (x32 Version: 1.5.1306 - CyberLink Corp.) Hidden CyberLink PowerRecover (x32 Version: 5.5.4125 - CyberLink Corp.) CyberLink PowerRecover (x32 Version: 5.5.4125 - CyberLink Corp.) Hidden CyberLink YouPaint (x32 Version: 1.2.1928 - CyberLink Corp.) CyberLink YouPaint (x32 Version: 1.2.1928 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dropbox (HKCU Version: 2.4.10 - Dropbox, Inc.) Entity Framework Tools for Visual Studio 2013 (x32 Version: 12.0.20912.0 - Microsoft Corporation) Erforderliche Komponenten für SSDT (x32 Version: 11.1.3000.0 - Microsoft Corporation) EVEREST Home Edition v2.20 (x32 Version: 2.20 - Lavalys Inc) FileZilla Client 3.7.1 (x32 Version: 3.7.1 - FileZilla Project) foobar2000 v1.2.4 (x32 Version: 1.2.4 - Peter Pawlowski) Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Free Screen To Video V 2.0 (x32 Version: 2.0.0.0 - Koyote Soft) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotografii uslugi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Game Booster 3 (x32 Version: 3.4 - IObit) Google Chrome (x32 Version: 31.0.1650.63 - Google Inc.) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden Greenfish Icon Editor Pro 3.25 (x32 Version: - Greenfish Corporation) Haskell Platform 2013.2.0.0 (x32 Version: - Haskell.org) dingeeee 3.7 (Version: 3.7.8.208 - SurfRight B.V.) Hotfix für Microsoft Visual Basic 2010 Express - DEU (KB2635973) (x32 Version: 1 - Microsoft Corporation) HP Foto- und Bildbearbeitung 2.0 - All-in-One (x32 Version: 1.10.0000 - Hewlett-Packard Company) Hidden HP Foto- und Bildbearbeitung 2.0 All-in-One Treiber (x32 Version: 1.10.0000 - Hewlett-Packard Company) Hidden HTML Tester (HKCU Version: 1.0.0.2 - HTML Tester) IIS 8.0 Express (Version: 8.0.1557 - Microsoft Corporation) IIS Express Application Compatibility Database for x64 (Version: - ) IIS Express Application Compatibility Database for x86 (Version: - ) Installer (HKCU Version: 1.0.0.0 - Installer) Intel(R) Management Engine Components (x32 Version: 7.0.0.1144 - Intel Corporation) Intel(R) Rapid Storage Technology (x32 Version: 10.5.0.1026 - Intel Corporation) Internetbrowser(testversion) (HKCU Version: 1.0.0.2 - 00yoshi) Java 7 Update 45 (64-bit) (Version: 7.0.450 - Oracle) Java 7 Update 45 (x32 Version: 7.0.450 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 45 (x32 Version: 6.0.450 - Oracle) Java(TM) 7 (64-bit) (Version: 7.0.0 - Oracle) Java(TM) SE Development Kit 6 Update 45 (x32 Version: 1.6.0.450 - Oracle) JavaFX 2.1.0 (64-bit) (Version: 2.1.0 - Oracle Corporation) JavaFX 2.1.0 SDK (64-bit) (Version: 2.1.0 - Oracle Corporation) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden K-Lite Codec Pack 7.0.0 (Standard) (x32 Version: 7.0.0 - ) L&H TTS3000 Deutsch (x32 Version: - ) League of Legends (x32 Version: 1.02.0000 - Riot Games) League of Legends (x32 Version: 1.3 - Riot Games) LogMeIn Hamachi (x32 Version: 2.1.0.166 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.1.0.166 - LogMeIn, Inc.) Hidden Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation) Media converter (x32 Version: - ) MediaConverter 1.3.2 (x32 Version: 1.3.2 - SoMud) MediaFire Express (x32 Version: 0.15.4.4888 - MediaFire) Medion Home Cinema (x32 Version: 8.0.2926 - CyberLink Corp.) Medion Home Cinema (x32 Version: 8.0.2926 - CyberLink Corp.) Hidden Microsoft .NET Framework 4 Multi-Targeting Pack (x32 Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4.5 Multi-Targeting Pack (x32 Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK - DEU Lang Pack (x32 Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK (x32 Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (x32 Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (Deutsch) (x32 Version: 4.5.51641 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (x32 Version: 4.5.51641 - Microsoft Corporation) Microsoft Antimalware Service DE-DE Language Pack (Version: 3.0.8402.2 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (x32 Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Exchange Web Services Managed API 2.0 (x32 Version: 15.0.516.14 - Microsoft Corporation) Hidden Microsoft Flight Simulator 2002 (x32 Version: - ) Microsoft Help Viewer 1.0 Language Pack - DEU (Version: 1.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.0 Language Pack - DEU (Version: 1.0.30319 - Microsoft Corporation) Hidden Microsoft Help Viewer 1.1 (Version: 1.1.40219 - Microsoft Corporation) Microsoft Help Viewer 1.1 (Version: 1.1.40219 - Microsoft Corporation) Hidden Microsoft Help Viewer 1.1 Language Pack - DEU (Version: 1.1.40219 - Microsoft Corporation) Microsoft Help Viewer 1.1 Language Pack - DEU (Version: 1.1.40219 - Microsoft Corporation) Hidden Microsoft Help Viewer 2.1 (x32 Version: 2.1.21005 - Microsoft Corporation) Microsoft Help Viewer 2.1 (x32 Version: 2.1.21005 - Microsoft Corporation) Hidden Microsoft Help Viewer 2.1 Sprachpaket - DEU (x32 Version: 2.1.21005 - Microsoft Corporation) Microsoft Help Viewer 2.1 Sprachpaket - DEU (x32 Version: 2.1.21005 - Microsoft Corporation) Hidden Microsoft Identity Extensions (Version: 2.0.1459.0 - Microsoft Corporation) Hidden Microsoft Office 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Excel Viewer (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft PowerPoint Viewer (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Security Client (Version: 4.4.0304.0 - Microsoft Corporation) Hidden Microsoft Security Client DE-DE Language Pack (Version: 2.1.1116.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (Version: 4.4.304.0 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Silverlight 5 SDK - DEU (x32 Version: 5.0.61118.0 - Microsoft Corporation) Microsoft SkyDrive (HKCU Version: 16.4.6010.0727 - Microsoft Corporation) Microsoft Small Basic v0.6 (x32 Version: 0.6 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2008 (x32 Version: - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Browser (x32 Version: 10.3.5500.0 - Microsoft Corporation) Microsoft SQL Server 2008 Common Files (x32 Version: 10.3.5500.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Database Engine Services (x32 Version: 10.3.5500.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Database Engine Shared (x32 Version: 10.3.5500.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Native Client (Version: 10.3.5500.0 - Microsoft Corporation) Microsoft SQL Server 2008 R2 Management Objects (x32 Version: 10.50.1750.9 - Microsoft Corporation) Microsoft SQL Server 2008 RsFx Driver (x32 Version: 10.3.5500.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Setup Support Files (x32 Version: 10.3.5500.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (x32 Version: 11.1.2902.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (x64) (Version: 11.1.2902.0 - Microsoft Corporation) Microsoft SQL Server 2012 Express LocalDB (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (x32 Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (x64) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL ScriptDom (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 T-SQL-Sprachdienst (x32 Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP1 Design Tools English (x32 Version: 3.5.5692.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP1 English (x32 Version: 3.5.5692.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 DEU (x32 Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 x64 DEU (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 x64 DEU (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft SQL Server Data Tools - DEU (12.0.30919.1) (x32 Version: 12.0.30919.1 - Microsoft Corporation) Microsoft SQL Server Data Tools Build Utilities - DEU (12.0.30919.1) (x32 Version: 12.0.30919.1 - Microsoft Corporation) Microsoft SQL Server System CLR Types (x32 Version: 10.50.1750.9 - Microsoft Corporation) Microsoft SQL Server System CLR Types (x64) (Version: 10.50.1600.1 - Microsoft Corporation) Microsoft SQL Server VSS Writer (Version: 10.3.5500.0 - Microsoft Corporation) Microsoft Visual Basic 2010 Express - DEU (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Basic 2010 Express - DEU (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden Microsoft Visual C++ Compilers 2010 Standard - enu - x86 (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (x32 Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU (Version: - Microsoft Corporation) Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU (Version: 9.0.30729 - Microsoft Corporation) Hidden Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU Service Pack 1 (KB945140) (x32 Version: 1 - Microsoft Corporation) Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Express Prerequisites x64 - DEU (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Service Pack 1 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Service Pack 1 (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.40820 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.40825 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU (Version: 10.0.40820 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (Version: 10.0.40820 - Microsoft Corporation) Microsoft Web Deploy 3.5 (Version: 3.1237.1762 - Microsoft Corporation) Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu (Version: 3.5.30729 - Microsoft Corporation) Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32 (Version: 6.1.5295.17011 - Microsoft Corporation) Microsoft XNA Framework Redistributable 3.0 (x32 Version: 3.0.11010.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (x32 Version: 4.0.20823.0 - Microsoft Corporation) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft-System-CLR-Typen für SQL Server 2012 (x32 Version: 11.1.3366.16 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2012 (x64) (Version: 11.1.3366.16 - Microsoft Corporation) Minecraft Editor 64 bits (Version: 1.8.0 - Axialmedia) Minecraft Recipe Creator (HKCU Version: 1.0.0.6 - Christopher Everitt) Minecraft Texturepack Editor (x32 Version: - ) Minecraft2d extented (HKCU Version: 1.0.0.0 - Minecraft2d extented) MinecraftAlpha (x32 Version: - ) MiniTool Partition Wizard Home Edition 7.1 (x32 Version: - MiniTool Solution Ltd.) MODINSTALLER (HKCU Version: 1.0.0.0 - Technikminer) Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden myMugle (x32 Version: 3.0.0.0 - Computer Business Solutions) Notepad++ (x32 Version: 6.1.3 - ) NVIDIA 3D Vision Treiber 331.65 (Version: 331.65 - NVIDIA Corporation) NVIDIA Grafiktreiber 331.65 (Version: 331.65 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.18.0 (Version: 1.3.18.0 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.11.0621 - NVIDIA Corporation) Hidden NVIDIA PhysX System Software 9.11.0621 (Version: 9.11.0621 - NVIDIA Corporation) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3165 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 331.65 (Version: 331.65 - NVIDIA Corporation) Hidden NVIDIA Update 1.15.2 (Version: 1.15.2 - NVIDIA Corporation) NVIDIA Update Components (Version: 1.15.2 - NVIDIA Corporation) Hidden Open Freely (Version: 1.0 - Download Freely, LLC) Open XML SDK 2.5 for Microsoft Office (x32 Version: 2.5.5631 - Microsoft Corporation) Hidden Paint.NET v3.5.11 (Version: 3.61.0 - dotPDN LLC) Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 (Deutsch) (x32 Version: 4.5.50932 - Microsoft Corporation) PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden PlayReady PC Runtime amd64 (Version: 1.3.0 - Microsoft Corporation) Poczta uslugi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Postal 2 STP - Free Multiplayer Edition (x32 Version: - ) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek High Definition Audio Driver (x32 Version: 6.0.1.6368 - Realtek Semiconductor Corp.) Secunia PSI (3.0.0.4001) (x32 Version: 3.0.0.4001 - Secunia) server auto ip (HKCU Version: 1.0.0.2 - server auto ip) Service Pack 3 für SQL Server 2008 (KB2546951) (x32 Version: 10.3.5500.0 - Microsoft Corporation) SharePoint Client Components (Version: 15.0.4481.1505 - Microsoft Corporation) Hidden SharpDX (x32 Version: 2.5.0 - SharpDX) SigmaTel MSCN Audio Player (x32 Version: - ) Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.) SmartFTP Client (Version: 4.1.1320.0 - SmartSoft Ltd.) Spelling Dictionaries Support For Adobe Reader X (x32 Version: 10.0.0 - Adobe Systems Incorporated) Spiel2 (HKCU Version: 1.0.0.0 - Spiel2) Sprechprogramm (HKCU Version: 1.0.0.0 - Sprechprogramm) Sql Server Customer Experience Improvement Program (x32 Version: 10.3.5500.0 - Microsoft Corporation) Hidden Start (HKCU Version: 1.0.0.1 - Start) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden TeamSpeak 3 Client (Version: 3.0.11.1 - TeamSpeak Systems GmbH) TeamViewer 9 (x32 Version: 9.0.24482 - TeamViewer) Techne (HKCU Version: 1.3.0.15 - ZeuX and r4wk) TmNationsForever (x32 Version: - Nadeo) TmSunriseDemoMag 1.4.5 (x32 Version: - Nadeo) Ultimate Browser (HKCU Version: 1.0.0.0 - Ultimate Browser) Unigine Valley Benchmark version 1.0 (x32 Version: 1.0 - Unigine Corp.) Unity Web Player (HKCU Version: - Unity Technologies ApS) Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU (x32 Version: 4.0.8080.0 - Microsoft Corporation) VLC media player 2.1.0 (x32 Version: 2.1.0 - VideoLAN) WCF RIA Services V1.0 SP2 (x32 Version: 4.1.62812.0 - Microsoft Corporation) Websiteclicker (HKCU Version: 1.0.0.0 - Websiteclicker) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotograf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven sähköposti (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden WinRAR 4.01 (32-Bit) (x32 Version: 4.01.0 - win.rar GmbH) WorldPainter 1.2.5 (Version: 1.2.5 - pepsoft.org) S?????? f?t???af??? t?? Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ==================== Restore Points ========================= 28-12-2013 14:58:55 Windows Update 01-01-2014 11:47:47 Windows Update 04-01-2014 19:07:54 Windows Update 08-01-2014 08:15:42 Microsoft SQL Server 2012 Command Line Utilities wurde entfernt. 08-01-2014 19:44:53 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2013-12-06 13:01 - 00000865 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 google-analytics.com ==================== Scheduled Tasks (whitelisted) ============= Task: {31F1DB6D-AB3B-4D6E-B0E5-2C8500B361B4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-14] (Google Inc.) Task: {421201ED-2AB8-46F7-9D54-8705CD4CB5B8} - \Dealply No Task File Task: {4C61322B-F811-4F12-AB4E-62E62078723E} - System32\Tasks\AdobeAAMUpdater-1.0-00yoshisPC-00yoshi => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2012-09-20] (Adobe Systems Incorporated) Task: {88A0DEF9-9A59-44E3-8A87-F1CFF07322D7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-07] (Adobe Systems Incorporated) Task: {91D73C45-2EDB-4192-A266-0FB73C3B64AF} - System32\Tasks\YourFile DownloaderUpdate => C:\Program Files (x86)\YourFileDownloader\YourFileUpdater.exe <==== ATTENTION Task: {B7282210-9ABB-4F65-8FFF-91654F170006} - System32\Tasks\PCMeter\Startup => C:\Users\00yoshi\AppData\Local\Temp\Rar$EX26.952\PCMeter\PCMeterV0.3.exe <==== ATTENTION Task: {C2D7B5BC-EEBC-4306-99BC-BB4FE30A143E} - System32\Tasks\Game_Booster_AutoUpdate => C:\Program Files (x86)\IObit\Game Booster 3\Autoupdate.exe [2013-06-24] () Task: {D88B83B1-49FB-49B8-9F83-3F549C74E636} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-14] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2010-01-02 15:42 - 2010-01-02 15:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2013-04-02 08:05 - 2012-08-14 15:19 - 07027664 _____ () C:\Program Files (x86)\AntiBrowserSpy\Commons.dll 2013-04-02 08:05 - 2012-08-14 15:19 - 00177616 _____ () C:\Program Files (x86)\AntiBrowserSpy\AbBrowserLibs.dll 2013-04-02 08:05 - 2012-08-14 15:19 - 00028112 _____ () C:\Program Files (x86)\AntiBrowserSpy\VersionInfo.dll 2013-04-02 08:05 - 2012-08-14 15:19 - 00012752 _____ () C:\Program Files (x86)\AntiBrowserSpy\AbProcessManager.dll 2014-01-05 14:09 - 2014-01-05 14:09 - 00306176 _____ () C:\Users\00yoshi\Desktop\atlauncher\Instances\ASolitaryCraft\bin\natives\lwjgl64.dll 2014-01-05 14:09 - 2014-01-05 14:09 - 00382464 _____ () C:\Users\00yoshi\Desktop\atlauncher\Instances\ASolitaryCraft\bin\natives\OpenAL64.dll 2013-10-27 18:11 - 2013-10-27 18:11 - 00012520 _____ () C:\Users\00yoshi\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\CoreTempReader.dll 2013-10-27 18:11 - 2013-10-27 18:11 - 00015080 _____ () C:\Users\00yoshi\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\GetCoreTempInfoNET.dll 2013-10-27 18:11 - 2013-10-27 18:11 - 00014056 _____ () C:\Users\00yoshi\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\SystemInfo.dll 2010-08-03 23:39 - 2010-08-03 23:39 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2010-08-03 23:39 - 2010-08-03 23:39 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2013-08-23 20:01 - 2013-08-23 20:01 - 25100288 _____ () C:\Users\00yoshi\AppData\Roaming\Dropbox\bin\libcef.dll 2014-01-09 21:37 - 2013-12-05 20:36 - 03559024 _____ () C:\Program Files (x86)\MF\mozjs.dll 2013-08-15 07:46 - 2013-08-15 07:46 - 00172544 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\f7b8fe4da9013ce331d3363fe18a775d\IsdiInterop.ni.dll 2011-08-11 21:01 - 2011-04-30 08:28 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2013-06-18 21:08 - 2013-06-18 21:08 - 00093696 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll 2013-12-07 11:57 - 2013-12-07 11:57 - 16237448 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:430C6D84 AlternateDataStreams: C:\ProgramData\Temp:DFC5A2B2 ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== Faulty Device Manager Devices ============= Name: Hamachi Network Interface Description: Hamachi Network Interface Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: LogMeIn, Inc. Service: hamachi Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (01/10/2014 01:43:31 PM) (Source: Windows Search Service) (User: ) Description: Windows Search wird aufgrund eines Problems bei der Indizierung The catalog is corrupt beendet. Details: Der Inhaltsindexkatalog ist fehlerhaft. 0xc0041801 (0xc0041801) Error: (01/10/2014 01:43:31 PM) (Source: Windows Search Service) (User: ) Description: Vom Suchdienst wurden beschädigte Datendateien im Index {id=2350} erkannt. Vom Dienst wird versucht, dieses Problem durch Neuerstellung des Indexes automatisch zu beheben. Details: Der Inhaltsindexkatalog ist fehlerhaft. 0xc0041801 (0xc0041801) System errors: ============= Error: (01/10/2014 01:26:15 PM) (Source: NETLOGON) (User: ) Description: Dieser Computer ist als Mitglied einer Arbeitsgruppe konfiguriert, nicht als Mitglied einer Domäne. Der Anmeldedienst braucht bei dieser Konfiguration nicht gestartet zu sein. Error: (01/09/2014 10:33:06 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "dingeeee 3.7 Crusader (Boot)" wurde mit folgendem dienstspezifischem Fehler beendet: %%0. Error: (01/09/2014 10:32:48 PM) (Source: NETLOGON) (User: ) Description: Dieser Computer ist als Mitglied einer Arbeitsgruppe konfiguriert, nicht als Mitglied einer Domäne. Der Anmeldedienst braucht bei dieser Konfiguration nicht gestartet zu sein. Microsoft Office Sessions: ========================= Error: (01/10/2014 01:43:31 PM) (Source: Windows Search Service)(User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. 0xc0041801 (0xc0041801) The catalog is corrupt Error: (01/10/2014 01:43:31 PM) (Source: Windows Search Service)(User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. 0xc0041801 (0xc0041801) 2350 CodeIntegrity Errors: =================================== Date: 2013-10-27 18:16:34.988 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\00yoshi\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-10-27 18:16:34.942 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\00yoshi\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-10-27 18:16:34.622 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-10-27 18:16:34.576 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 82% Total physical RAM: 8173.64 MB Available physical RAM: 1462.44 MB Total Pagefile: 20430.82 MB Available Pagefile: 12345.18 MB Total Virtual: 8192 MB Available Virtual: 8191.78 MB ==================== Drives ================================ Drive c: (Boot) (Fixed) (Total:1811.92 GB) (Free:1473.69 GB) NTFS Drive d: (Recover) (Fixed) (Total:50 GB) (Free:24.38 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 1863 GB) (Disk ID: 2BD2C32A) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=-253492199424) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=50 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=1 GB) - (Type=12) ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2014-01-10 14:46:30 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST2000DL rev.CC45 1863,02GB Running: z05euqx3.exe; Driver: C:\Users\00yoshi\AppData\Local\Temp\pgrirpoc.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800039fb000 45 bytes [00, 00, 15, 02, 46, 69, 6C, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff800039fb02f 18 bytes [00, 00, 00, 00, 00, 00, 00, ...] ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[3676] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077131465 2 bytes [13, 77] .text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[3676] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000771314bb 2 bytes [13, 77] .text ... * 2 .text C:\Program Files (x86)\Windows Sidebar\sidebar.exe[3384] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077131465 2 bytes [13, 77] .text C:\Program Files (x86)\Windows Sidebar\sidebar.exe[3384] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000771314bb 2 bytes [13, 77] .text ... * 2 .text C:\Users\00yoshi\AppData\Roaming\Dropbox\bin\Dropbox.exe[4088] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 69 0000000077131465 2 bytes [13, 77] .text C:\Users\00yoshi\AppData\Roaming\Dropbox\bin\Dropbox.exe[4088] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 155 00000000771314bb 2 bytes [13, 77] .text ... * 2 .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2840] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077131465 2 bytes [13, 77] .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2840] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000771314bb 2 bytes [13, 77] .text ... * 2 ---- Threads - GMER 2.1 ---- Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:1172] 00000000779e3e85 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:1592] 00000000779e2e65 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:1984] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:1272] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:1484] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:1868] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:1856] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:1540] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:1988] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2084] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2096] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2112] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2124] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2128] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2160] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2312] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2316] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2636] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2644] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2524] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2656] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2664] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2668] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2992] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:3016] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2412] 00000000779e3e85 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2424] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2332] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2532] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2572] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2136] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:2388] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:3316] 0000000072b829e1 Thread c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [1884:3792] 0000000072b829e1 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ---- FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-01-2014 Ran by 00yoshi (administrator) on 00yoshiSPC on 10-01-2014 14:19:51 Running from C:\Users\00yoshi\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (CyberLink) C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft) C:\Program Files (x86)\AntiBrowserSpy\AntiBrowserSpyBrowserMaske.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Sidebar\sidebar.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Dropbox, Inc.) C:\Users\00yoshi\AppData\Roaming\Dropbox\bin\Dropbox.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Mozilla Corporation) C:\Program Files (x86)\MF\firefox.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\javaw.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\javaw.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\System32\msconfig.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Mozilla Corporation) C:\Program Files (x86)\MF\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe () C:\Program Files (x86)\WinRAR\WinRAR.exe (Sysinternals - www.sysinternals.com) C:\Users\00yoshi\AppData\Local\Temp\Rar$EX77.816\autoruns.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MedionReminder] - C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe [443688 2011-05-26] (CyberLink) HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [444904 2012-09-20] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-04-30] (Intel Corporation) HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-03] (CyberLink) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\RunOnce: [MedionReminder] - C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe /DeleteRunKey [443688 2011-05-26] (CyberLink) HKCU\...\Run: [AdobeBridge] - [x] HKCU\...\Run: [BrowserMask] - C:\Program Files (x86)\AntiBrowserSpy\AntiBrowserSpyBrowserMaske.exe [101328 2012-08-14] (Microsoft) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKCU\...\Run: [Windows Security Center] - C:\Windows\system32\DCSCMIN\qCYDNSwdpMdt\IMDCSC.exe HKCU\...\Winlogon: [Shell] explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION HKCU\...\Policies\system: [LogonHoursAction] 2 HKCU\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 MountPoints2: J - J:\LaunchU3.exe -a MountPoints2: {4c37b416-a10a-11e2-93a8-742f68a8ddc1} - J:\LaunchU3.exe -a HKU\Default\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] () HKU\Default\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs HKU\Default User\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] () HKU\Default User\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs Startup: C:\Users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\00yoshi\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: CBAbzockschutz.InitToolbarBHO - {2e250b90-0e7a-42a3-9d65-e39f9f227fa4} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - COMPUTERBILD-Abzockschutz - {353e2a48-6254-4bd3-88f4-3b51a0ca7870} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: 127.0.0.1 google-analytics.com Tcpip\..\Interfaces\{84BF9EDE-124A-499C-AED4-CA030D3CFE4D}: [NameServer]62.109.121.1 62.109.121.2 FireFox: ======== FF ProfilePath: C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default FF NewTab: about:blank FF Homepage: hxxp://web.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.0.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\00yoshi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF SearchPlugin: C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: greAtsaaveR - C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\Extensions\rge@vwige.net FF Extension: Lightbeam - C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\Extensions\jid1-F9UJ2thwoAm5gQ@jetpack.xpi FF Extension: XJZ Survey Remover - C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\Extensions\survey-remover@gmx.com.xpi FF Extension: WEB.DE MailCheck - C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\Extensions\toolbar@web.de.xpi FF Extension: NoScript - C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF Extension: Adblock Plus - C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: COMPUTERBILD-Abzockschutz - C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\Extensions\{d49175b3-3fd8-43b8-b28e-da5d47f3c398}.xpi FF Extension: QuickJava - C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\Extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBA} FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\MF\firefox.exe Chrome: ======= CHR DefaultSearchProvider: Web CHR DefaultSearchURL: hxxp://www.google.com CHR DefaultNewTabURL: CHR Extension: (greAtsaaveR) - C:\Users\00yoshi\AppData\Local\Google\Chrome\User Data\Default\Extensions\belcdgkhhmfeilamilifdjfdillmmcjg\2.7 CHR Extension: (Google Wallet) - C:\Users\00yoshi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 CHR HKLM-x32\...\Chrome\Extension: [ibnmbpihhamedhophbnjjpidokcknoid] - C:\Program Files (x86)\AP Suggestor\APSuggestor.crx ==================== Services (Whitelisted) ================= S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [15768 2010-02-03] (Microsoft Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation) R2 MSSQL$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [43028328 2011-09-22] (Microsoft Corporation) S4 msvsmon90; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [4737024 2008-07-29] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation) S4 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1328736 2012-09-24] (Secunia) S4 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [656480 2012-09-24] (Secunia) S4 SQLAgent$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [370024 2011-09-22] (Microsoft Corporation) S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [x] ==================== Drivers (Whitelisted) ==================== S3 DCamUSBET; C:\Windows\System32\DRIVERS\etDevice64.sys [527744 2007-07-23] (eMPIA Technology, Inc.) S3 FiltUSBET; C:\Windows\System32\DRIVERS\etFilter64.sys [281088 2007-06-14] (eMPIA Technology Inc.) S3 dingeeee37; C:\Windows\system32\drivers\dingeeee37.sys [32512 2014-01-09] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation) S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19936 2012-01-18] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [13280 2012-01-18] () S3 ScanUSBET; C:\Windows\System32\DRIVERS\etScan64.sys [9216 2007-07-23] (eMPIA Technology, Inc.) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S3 WinRing0_1_2_0; C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [14544 2010-11-01] (OpenLibSys.org) S4 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] S0 nvpciflt; system32\DRIVERS\nvpciflt.sys [x] ========================== Drivers MD5 ======================= C:\Windows\system32\drivers\1394ohci.sys ==> MD5 is legit C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit C:\Windows\system32\drivers\adp94xx.sys ==> MD5 is legit C:\Windows\system32\drivers\adpahci.sys ==> MD5 is legit C:\Windows\system32\drivers\adpu320.sys ==> MD5 is legit C:\Windows\SysWow64\drivers\Afc.sys 6CCD1135320109D6B219F1A6E04AD9F6 C:\Windows\system32\drivers\afd.sys 79059559E89D06E8B80CE2944BE20228 C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit C:\Windows\system32\drivers\amdk8.sys ==> MD5 is legit C:\Windows\system32\drivers\amdppm.sys ==> MD5 is legit C:\Windows\system32\drivers\amdsata.sys D4121AE6D0C0E7E13AA221AA57EF2D49 C:\Windows\system32\drivers\amdsbs.sys ==> MD5 is legit C:\Windows\System32\drivers\amdxata.sys 540DAF1CEA6094886D72126FD7C33048 C:\Windows\system32\drivers\appid.sys ==> MD5 is legit C:\Windows\system32\drivers\arc.sys ==> MD5 is legit C:\Windows\system32\drivers\arcsas.sys ==> MD5 is legit C:\Windows\system32\drivers\asmthub3.sys 0AA7A996792FB0287B33A57A8093AE44 C:\Windows\system32\drivers\asmtxhci.sys 125DC3ABF5BFCCFE82AD17D078E0B9EC C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit C:\Windows\system32\drivers\atapi.sys ==> MD5 is legit C:\Windows\system32\drivers\bxvbda.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\b57nd60a.sys ==> MD5 is legit C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit C:\Windows\system32\drivers\blbdrive.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit C:\Windows\system32\drivers\BrFiltLo.sys ==> MD5 is legit C:\Windows\system32\drivers\BrFiltUp.sys ==> MD5 is legit C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit C:\Windows\system32\drivers\bthmodem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit C:\Windows\system32\drivers\circlass.sys ==> MD5 is legit C:\Windows\System32\CLFS.sys ==> MD5 is legit C:\Windows\system32\drivers\CmBatt.sys ==> MD5 is legit C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit C:\Windows\System32\Drivers\cng.sys EBF28856F69CF094A902F884CF989706 C:\Windows\system32\drivers\compbatt.sys ==> MD5 is legit C:\Windows\system32\drivers\CompositeBus.sys ==> MD5 is legit C:\Windows\system32\drivers\crcdisk.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\etDevice64.sys 04F1DC6D20E145FB29C9536A5E4FDA90 C:\Windows\System32\Drivers\dfsc.sys ==> MD5 is legit C:\Windows\System32\drivers\discache.sys ==> MD5 is legit C:\Windows\System32\drivers\disk.sys ==> MD5 is legit C:\Windows\system32\drivers\drmkaud.sys ==> MD5 is legit C:\Windows\System32\drivers\dxgkrnl.sys 88612F1CE3BF42256913BF6E61C70D52 C:\Windows\system32\drivers\evbda.sys ==> MD5 is legit C:\Windows\system32\drivers\elxstor.sys ==> MD5 is legit C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit C:\Windows\System32\Drivers\exfat.sys ==> MD5 is legit C:\Windows\System32\Drivers\fastfat.sys ==> MD5 is legit C:\Windows\system32\drivers\fdc.sys ==> MD5 is legit C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\etFilter64.sys 059B282B748D5E027B60E276CF424BAD C:\Windows\system32\drivers\flpydisk.sys ==> MD5 is legit C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit C:\Windows\System32\Drivers\Fs_Rec.sys 6BD9295CC032DD3077C671FCCF579A7B C:\Windows\System32\DRIVERS\fvevol.sys 8F6322049018354F45F05A2FD2D4E5E0 C:\Windows\system32\drivers\gagp30kx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\hamachi.sys 1E6438D4EA6E1174A3B3B1EDC4DE660B C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit C:\Windows\System32\drivers\HdAudio.sys 975761C778E33CD22498059B91E7373A C:\Windows\system32\drivers\HDAudBus.sys ==> MD5 is legit C:\Windows\system32\drivers\HidBatt.sys ==> MD5 is legit C:\Windows\system32\drivers\hidbth.sys ==> MD5 is legit C:\Windows\system32\drivers\hidir.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 is legit C:\Windows\system32\drivers\dingeeee37.sys FCE2251FE4464DCAA2F4684F19A8EE9B C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit C:\Windows\System32\drivers\HTTP.sys ==> MD5 is legit C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit C:\Windows\system32\drivers\i8042prt.sys ==> MD5 is legit C:\Windows\System32\drivers\iaStor.sys 26CF4275034214ECEDD8EC17B0A18A99 C:\Windows\system32\drivers\iaStorV.sys AAAF44DB3BD0B9D1FB6969B23ECC8366 C:\Windows\System32\DRIVERS\igdkmd64.sys ==> MD5 is legit C:\Windows\system32\drivers\iirsp.sys ==> MD5 is legit C:\Windows\System32\drivers\RTKVHD64.sys 8F6ED52134EBB4CE2953EC37C9275497 C:\Windows\system32\drivers\intelide.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit C:\Windows\system32\drivers\msiscsi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\kbdhid.sys ==> MD5 is legit C:\Windows\System32\Drivers\ksecdd.sys 8F489706472F7E9A06BAAA198703FA64 C:\Windows\System32\Drivers\ksecpkg.sys 868A2CAAB12EFC7A021682BCA0EEC54C C:\Windows\system32\drivers\ksthunk.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_fc.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_sas.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_sas2.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_scsi.sys ==> MD5 is legit C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit C:\Windows\system32\drivers\mbam.sys 0BB97D43299910CBFBA59C461B99B910 C:\Windows\system32\drivers\megasas.sys ==> MD5 is legit C:\Windows\system32\drivers\MegaSR.sys ==> MD5 is legit C:\Windows\system32\drivers\HECIx64.sys A6518DCC42F7A6E999BB3BEA8FD87567 C:\Windows\System32\drivers\modem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit C:\Windows\System32\drivers\mountmgr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\MpFilter.sys C6B88D62F20AC646C6BD5C032EC2FAF9 C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\mrxdav.sys 1A4F75E63C9FB84B85DFFC6B63FD5404 C:\Windows\System32\DRIVERS\mrxsmb.sys A5D9106A73DC88564C825D317CAC68AC C:\Windows\System32\DRIVERS\mrxsmb10.sys D711B3C1D5F42C0C2415687BE09FC163 C:\Windows\System32\DRIVERS\mrxsmb20.sys 9423E9D355C8D303E76B8CFBD8A5C30C C:\Windows\system32\drivers\msahci.sys ==> MD5 is legit C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit C:\Windows\system32\drivers\mssmbios.sys ==> MD5 is legit C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit C:\Windows\system32\drivers\MTConfig.sys ==> MD5 is legit C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit C:\Windows\System32\drivers\ndis.sys 760E38053BF56E501D562B70AD796B88 C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit C:\Windows\system32\drivers\nfrd960.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\NisDrvWFP.sys ACE8C64C57E4A711473C8BC10ADF692B C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit C:\Windows\System32\Drivers\Ntfs.sys B98F8C6E31CD07B2E6F71F7F648E38C0 C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit C:\Windows\System32\drivers\nvhda64v.sys 1F07B814C0BB5AABA703ABFF1F31F2E8 C:\Windows\System32\DRIVERS\nvlddmkm.sys E71E299FF15390E585BACF2C18F55078 C:\Windows\system32\drivers\nvraid.sys 0A92CB65770442ED0DC44834632F66AD C:\Windows\system32\drivers\nvstor.sys DAB0E87525C10052BF65F06152F37E4A C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit C:\Windows\system32\drivers\parport.sys ==> MD5 is legit C:\Windows\System32\drivers\partmgr.sys E9766131EEADE40A27DC27D2D68FBA9C C:\Windows\System32\drivers\pci.sys ==> MD5 is legit C:\Windows\system32\drivers\pciide.sys ==> MD5 is legit C:\Windows\system32\drivers\pcmcia.sys ==> MD5 is legit C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit C:\Windows\System32\drivers\peauth.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit C:\Windows\system32\drivers\processr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\psi_mf.sys FB46E9A827A8799EBD7BFA9128C91F37 C:\Windows\system32\pwdrvio.sys FF40216A382B30CC39372B889AE1F785 C:\Windows\system32\pwdspio.sys BD08A9CDF23502B1C141D52D9D6A6648 C:\Windows\system32\drivers\ql2300.sys ==> MD5 is legit C:\Windows\system32\drivers\ql40xx.sys ==> MD5 is legit C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit C:\Windows\system32\drivers\rdpbus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpvideominiport.sys 313F68E1A3E6345A4F47A36B07062F34 C:\Windows\System32\Drivers\RDPWD.sys E61608AA35E98999AF9AAEEEA6114B0A C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\Rt64win7.sys E50CFB92986DCAB49DE93788FD695813 C:\Windows\System32\DRIVERS\RTL8192su.sys B3F36B4B3F192EA87DDC119F3A0B3E45 C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\etScan64.sys 7AD81DB1549878DEEAAECED63981C8FC C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\serenum.sys ==> MD5 is legit C:\Windows\system32\drivers\serial.sys ==> MD5 is legit C:\Windows\system32\drivers\sermouse.sys ==> MD5 is legit C:\Windows\system32\drivers\sffdisk.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_sd.sys ==> MD5 is legit C:\Windows\system32\drivers\sfloppy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\Sftfslh.sys 2046AA7491DE7EFA4D70E615D9BC9D09 C:\Windows\System32\DRIVERS\Sftplaylh.sys 0E0446BC4D51BE4263ACB7E33491191C C:\Windows\System32\DRIVERS\Sftredirlh.sys C5FB982CD266E604ED3142102C26D62C C:\Windows\System32\DRIVERS\Sftvollh.sys 2575511AF67AA1FA068CCC4918E2C2A3 C:\Windows\system32\drivers\SiSRaid2.sys ==> MD5 is legit C:\Windows\system32\drivers\sisraid4.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\srv.sys 441FBA48BFF01FDB9D5969EBC1838F0B C:\Windows\System32\DRIVERS\srv2.sys B4ADEBBF5E3677CCE9651E0F01F7CC28 C:\Windows\System32\DRIVERS\srvnet.sys 27E461F0BE5BFF5FC737328F749538C3 C:\Windows\system32\drivers\stexstor.sys ==> MD5 is legit C:\Windows\system32\drivers\swenum.sys ==> MD5 is legit C:\Windows\System32\drivers\tcpip.sys 40AF23633D197905F03AB5628C558C51 C:\Windows\System32\DRIVERS\tcpip.sys 40AF23633D197905F03AB5628C558C51 C:\Windows\System32\drivers\tcpipreg.sys 1B16D0BD9841794A6E0CDE0CEF744ABC C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit C:\Windows\System32\drivers\tdtcp.sys 51C5ECEB1CDEE2468A1748BE550CFBC8 C:\Windows\System32\DRIVERS\tdx.sys ==> MD5 is legit C:\Windows\system32\drivers\termdd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\tosporte.sys C14882C535E97B180ACA9FC716C228FB C:\Windows\System32\DRIVERS\tosrfbd.sys A2242F46131F3BEE3D1DA279B74111BA C:\Windows\System32\Drivers\tosrfbnp.sys 0716088A07A468FFF2DBFCA1DE55C0B6 C:\Windows\System32\Drivers\tosrfcom.sys 98C10D5862C4C5E58A9E09BEB07FB6C5 C:\Windows\System32\DRIVERS\Tosrfhid.sys 33C90B98B74D01D179E1963A5BF5EDF9 C:\Windows\System32\DRIVERS\tosrfnds.sys 95552D0B11C70846299DCA2FF0082205 C:\Windows\System32\drivers\tosrfsnd.sys A99D0670095414C7B3244DC3D0314ACB C:\Windows\System32\DRIVERS\tosrfusb.sys A69030B8F4C73C475E81A35F93C9C964 C:\Windows\System32\DRIVERS\tssecsrv.sys 4CE278FC9671BA81A138D70823FCAA09 C:\Windows\System32\drivers\tsusbflt.sys 17C6B51CBCCDED95B3CC14E22791F85E C:\Windows\system32\drivers\TsUsbGD.sys AD64450A4ABE076F5CB34CC08EEACB07 C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit C:\Windows\system32\drivers\uagp35.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\umbus.sys ==> MD5 is legit C:\Windows\system32\drivers\umpass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\usbccgp.sys ACCEA6BC68D0C9A78EB97EE159028B4E C:\Windows\system32\drivers\usbcir.sys 80B0F7D5CCF86CEB5D402EAAF61FEC31 C:\Windows\system32\drivers\usbehci.sys 311C1DD1088E55BEAE15954D17F50646 C:\Windows\System32\DRIVERS\usbhub.sys 280E90CBF4B2DDD169F0728CB44D726F C:\Windows\system32\drivers\usbohci.sys 9406D801042FAF859CF81B2C886413DC C:\Windows\System32\DRIVERS\usbprint.sys ==> MD5 is legit C:\Windows\system32\drivers\usbscan.sys 9661DA76B4531B2DA272ECCE25A8AF24 C:\Windows\System32\DRIVERS\USBSTOR.SYS FED648B01349A3C8395A5169DB5FB7D6 C:\Windows\system32\drivers\usbuhci.sys A83D0EC9AE4C31704442099D40BA2471 C:\Windows\System32\Drivers\usbvideo.sys 1F775DA4CF1A3A1834207E975A72E9D7 C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit C:\Windows\System32\drivers\vga.sys ==> MD5 is legit C:\Windows\system32\drivers\vhdmp.sys ==> MD5 is legit C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit C:\Windows\System32\drivers\volsnap.sys ==> MD5 is legit C:\Windows\system32\drivers\vsmraid.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwifibus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwififlt.sys ==> MD5 is legit C:\Windows\system32\drivers\wacompen.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\system32\drivers\wd.sys ==> MD5 is legit C:\Windows\System32\drivers\Wdf01000.sys E2C933EDBC389386EBE6D2BA953F43D8 C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit C:\Windows\SysWow64\drivers\wimmount.sys ==> MD5 is legit C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys 0C0195C48B6B8582FA6F6373032118DA C:\Windows\System32\DRIVERS\WinUsb.sys FE88B288356E7B47B74B13372ADD906D C:\Windows\system32\drivers\wmiacpi.sys ==> MD5 is legit C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wsvd.sys 82E8F5AA03DF7DBDB8A33F700D5D8CDA C:\Windows\System32\drivers\WudfPf.sys AB886378EEB55C6C75B4F2D14B6C869F C:\Windows\System32\DRIVERS\WUDFRd.sys DDA4CAF29D8C0A297F886BFE561E6659 ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-10 14:19 - 2014-01-10 14:20 - 00035322 _____ C:\Users\00yoshi\Downloads\FRST.txt 2014-01-10 14:19 - 2014-01-10 14:19 - 00050477 _____ C:\Users\00yoshi\Downloads\Defogger.exe 2014-01-10 14:19 - 2014-01-10 14:19 - 00000000 ____D C:\FRST 2014-01-10 14:18 - 2014-01-10 14:19 - 01932166 _____ (Farbar) C:\Users\00yoshi\Downloads\FRST64.exe 2014-01-10 13:52 - 2014-01-10 13:52 - 00550371 _____ C:\Users\00yoshi\Downloads\Autoruns.zip 2014-01-09 22:32 - 2014-01-09 22:32 - 00032512 _____ C:\Windows\system32\Drivers\dingeeee37.sys 2014-01-09 22:23 - 2014-01-09 22:23 - 00012092 _____ C:\Windows\system32\.crusader 2014-01-09 21:56 - 2014-01-09 21:56 - 00001909 _____ C:\Users\Public\Desktop\dingeeee.lnk 2014-01-09 21:56 - 2014-01-09 21:56 - 00000000 ____D C:\Program Files\dingeeee 2014-01-09 21:55 - 2014-01-09 22:31 - 00000000 ____D C:\ProgramData\dingeeee 2014-01-09 21:55 - 2014-01-09 21:55 - 10264904 _____ (SurfRight B.V.) C:\Users\00yoshi\Downloads\dingeeee_x64.exe 2014-01-09 21:51 - 2014-01-09 21:51 - 00017693 _____ C:\Users\00yoshi\Desktop\JRT.txt 2014-01-09 21:45 - 2014-01-09 21:45 - 01037068 _____ (Thisisu) C:\Users\00yoshi\Downloads\JRT.exe 2014-01-09 21:45 - 2014-01-09 21:45 - 00000000 ____D C:\Windows\ERUNT 2014-01-09 21:37 - 2014-01-09 21:37 - 00001054 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-09 21:37 - 2014-01-09 21:37 - 00000000 ____D C:\Program Files (x86)\MF 2014-01-09 21:30 - 2014-01-09 21:30 - 23867560 _____ (Mozilla) C:\Users\00yoshi\Downloads\Firefox Setup 26.0.exe 2014-01-08 20:31 - 2014-01-08 22:00 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Temporary Projects 2014-01-08 16:15 - 2014-01-08 16:36 - 00000000 ____D C:\AdwCleaner 2014-01-08 16:15 - 2014-01-08 16:15 - 01233962 _____ C:\Users\00yoshi\Downloads\adwcleaner_3.016.exe 2014-01-05 15:31 - 2014-01-05 15:31 - 00000000 ____D C:\ProgramData\SoftWarehouse 2014-01-05 15:24 - 2014-01-07 20:17 - 00000000 ____D C:\ProgramData\InstallMate 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$ 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast\AppData\Local\Torch 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\Torch 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\ProgramData\504c2cf8db11ac3b 2014-01-04 14:56 - 2014-01-04 14:56 - 00018589 _____ C:\Users\00yoshi\Downloads\169_EW-Biomes.rar 2014-01-04 14:55 - 2014-01-04 14:55 - 08037055 _____ C:\Users\00yoshi\Downloads\Millenaire5.1.11.zip 2014-01-03 22:51 - 2014-01-03 22:52 - 00000000 ____D C:\Users\00yoshi\Desktop\GoingBeyond1_Tutorial 2014-01-03 22:50 - 2014-01-03 22:50 - 00790625 _____ C:\Users\00yoshi\Downloads\GoingBeyond1_Tutorial_Sample.zip 2014-01-03 22:44 - 2014-01-03 22:44 - 00193521 _____ C:\Users\00yoshi\Downloads\einfuehrung(1).zip 2014-01-03 22:24 - 2014-01-03 22:24 - 01358498 _____ C:\Users\00yoshi\Downloads\3DModel Source(1).zip 2014-01-03 22:08 - 2014-01-03 22:08 - 01358498 _____ C:\Users\00yoshi\Downloads\3DModel Source.zip 2014-01-03 18:54 - 2014-01-03 18:54 - 00569372 _____ (DotExE ) C:\Users\00yoshi\Downloads\MoonTools.exe 2014-01-02 17:03 - 2010-08-09 20:14 - 00089600 _____ (SoftwareDesign-Solution) C:\Users\00yoshi\Desktop\TextEffectsLib.dll 2014-01-02 17:02 - 2014-01-02 17:02 - 00043731 _____ C:\Users\00yoshi\Downloads\TextEffectsLib_1.1.0.0.zip 2014-01-02 16:59 - 2014-01-02 16:59 - 00117423 _____ C:\Users\00yoshi\Downloads\TextEffectsLibDemo_1.1.0.0.zip 2014-01-02 16:09 - 2014-01-02 16:09 - 00018432 _____ (MT Soft) C:\Users\00yoshi\Desktop\ZipLib.dll 2014-01-02 15:15 - 2014-01-02 15:16 - 36293880 _____ (Dropbox, Inc.) C:\Users\00yoshi\Downloads\Dropbox 2.4.10(1).exe 2013-12-31 00:10 - 2013-12-31 00:12 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Start 2013-12-31 00:08 - 2013-12-31 00:08 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\nUpdate 2013-12-30 23:49 - 2013-12-30 23:55 - 00000000 ____D C:\Users\00yoshi\Desktop\Updates f�r Programme 2013-12-30 23:21 - 2013-12-30 23:22 - 36293880 _____ (Dropbox, Inc.) C:\Users\00yoshi\Downloads\Dropbox 2.4.10.exe 2013-12-30 23:17 - 2013-12-30 23:17 - 00369345 _____ C:\Users\00yoshi\Downloads\nUpdate.rar 2013-12-30 22:53 - 2013-12-30 22:54 - 33841433 _____ C:\Users\00yoshi\Downloads\Minecraft_Modpack_1.6.2.rar 2013-12-27 22:24 - 2013-12-27 22:24 - 00095068 _____ C:\Users\00yoshi\Desktop\Paintball.jar 2013-12-27 13:26 - 2013-12-27 13:26 - 01927709 _____ C:\Users\00yoshi\Downloads\samp03x_svr_R2_win32.zip 2013-12-27 12:47 - 2013-12-27 12:47 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer 2013-12-27 12:45 - 2013-12-27 12:46 - 12022145 _____ C:\Users\00yoshi\Downloads\sa-mp-0.3x-R1-2-install.exe 2013-12-22 17:50 - 2013-12-22 17:50 - 00017266 _____ C:\Users\00yoshi\Downloads\3DAnimation2(1).zip 2013-12-22 16:25 - 2013-12-22 16:25 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft2d extented 2013-12-21 23:32 - 2014-01-05 21:29 - 00000000 ____D C:\Users\00yoshi\Desktop\DirectX Tutorialserie 1 Device erstellen 2013-12-21 23:32 - 2013-12-21 23:32 - 00073915 _____ C:\Users\00yoshi\Downloads\DirectX Tutorialserie 1 Device erstellen.zip 2013-12-21 22:54 - 2013-12-21 22:54 - 00004162 _____ C:\Users\00yoshi\Desktop\lol.txt 2013-12-21 12:45 - 2013-12-21 12:45 - 00025750 _____ C:\Users\00yoshi\Documents\Unbenannt.camproj 2013-12-20 22:42 - 2013-12-20 22:42 - 00159671 _____ C:\Users\00yoshi\Downloads\Thaumcraft-Extras-0.3.2a (1).zip 2013-12-20 20:34 - 2013-12-20 20:34 - 00072476 _____ C:\Users\00yoshi\Downloads\Forge_NBTEditv1.6.4.0.zip 2013-12-20 20:07 - 2013-12-20 20:07 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-12-20 20:07 - 2013-12-20 20:07 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-12-20 19:50 - 2013-12-20 19:51 - 30694824 _____ (Oracle Corporation) C:\Users\00yoshi\Downloads\jre-7u45-windows-x64.exe 2013-12-20 19:49 - 2013-12-20 19:50 - 00042746 _____ C:\Users\00yoshi\Downloads\Fix Java File Types.zip 2013-12-20 18:10 - 2013-12-20 18:10 - 15200059 _____ C:\Users\00yoshi\Downloads\Tropicraft v3.0.5(1).zip 2013-12-20 18:05 - 2013-12-20 18:06 - 15200059 _____ C:\Users\00yoshi\Downloads\Tropicraft v3.0.5.zip 2013-12-20 15:52 - 2014-01-09 21:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-20 14:14 - 2013-12-20 14:14 - 00716592 _____ () C:\Users\00yoshi\Downloads\GitHubSetup.exe 2013-12-19 08:21 - 2014-01-04 00:21 - 00000075 _____ C:\Users\00yoshi\AppData\Roaming\WB.CFG 2013-12-17 19:49 - 2013-12-17 19:49 - 02231448 _____ C:\Users\00yoshi\Downloads\minecraftforge-installer-1.6.4-9.11.1.916.jar 2013-12-17 19:48 - 2013-12-17 19:50 - 00037357 _____ C:\Users\00yoshi\Downloads\Somnia-Pre2b.jar 2013-12-15 17:02 - 2013-12-15 17:02 - 02205757 _____ C:\Users\00yoshi\Downloads\Railcraft_1.5.1-7.0.0.0.jar 2013-12-15 17:02 - 2013-12-15 17:02 - 00014347 _____ C:\Users\00yoshi\Downloads\util^iChunUtil1.0.0.zip 2013-12-15 17:02 - 2013-12-15 17:02 - 00014347 _____ C:\Users\00yoshi\Downloads\util^iChunUtil1.0.0(1).zip 2013-12-14 22:04 - 2010-08-04 00:08 - 00015360 _____ (Vincent Casser / VCware) C:\Users\00yoshi\Desktop\FastGraphicsLib.dll 2013-12-14 21:50 - 2013-12-14 21:50 - 00005759 _____ C:\Users\00yoshi\Downloads\FastGraphicsLib.zip 2013-12-13 23:21 - 2013-12-13 23:21 - 00111351 _____ C:\Users\00yoshi\Downloads\ip pinger.rar 2013-12-13 22:16 - 2013-12-13 22:18 - 139921513 _____ C:\Users\00yoshi\Downloads\rockyou.txt 2013-12-13 22:11 - 2013-12-13 22:14 - 60498886 _____ C:\Users\00yoshi\Downloads\rockyou.txt.bz2 2013-12-13 22:11 - 2013-12-13 22:11 - 03149586 _____ C:\Users\00yoshi\Downloads\cain.txt 2013-12-13 22:10 - 2013-12-13 22:10 - 01069968 _____ C:\Users\00yoshi\Downloads\cain.txt.bz2 2013-12-13 18:00 - 2013-12-13 18:05 - 00383816 _____ C:\Users\00yoshi\Downloads\CoreTemp64.zip 2013-12-13 17:50 - 2013-12-13 17:52 - 46946304 _____ C:\Users\00yoshi\Downloads\Elektro-Training.exe 2013-12-13 17:19 - 2013-12-13 17:19 - 00006691 _____ C:\Users\00yoshi\Downloads\ZipLib.zip 2013-12-13 12:57 - 2013-12-13 18:12 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Minecraft_texturepack_edi 2013-12-13 11:38 - 2013-12-13 11:38 - 00002750 _____ C:\Users\00yoshi\Unigine_Valley_Benchmark_1.0_20131213_1138.html 2013-12-11 09:27 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-12-11 09:27 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-12-11 09:27 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2013-12-11 09:27 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-12-11 09:26 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-11 09:26 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-11 09:26 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-11 09:26 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-11 09:26 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-11 09:26 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-11 09:26 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-11 09:26 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-11 09:26 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-11 09:26 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-11 09:26 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-11 09:26 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-11 09:26 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-11 09:26 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-11 09:26 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-11 09:26 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-11 09:26 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-11 09:26 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-11 09:26 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-11 09:26 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-11 09:26 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-11 09:26 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-11 09:26 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-11 09:26 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-11 09:26 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-11 09:26 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-11 09:26 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-11 09:26 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-11 09:26 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-11 09:26 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-11 09:26 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-11 09:00 - 2013-12-13 18:03 - 01065984 _____ C:\Users\00yoshi\AppData\Local\file__0.localstorage 2013-12-11 09:00 - 2013-12-11 09:03 - 00000000 ____D C:\Users\00yoshi\Valley 2013-12-11 08:54 - 2013-12-11 08:54 - 00002117 _____ C:\Users\Public\Desktop\Valley Benchmark 1.0.lnk 2013-12-11 08:54 - 2013-12-11 08:54 - 00000000 ____D C:\Program Files (x86)\Unigine 2013-12-11 08:28 - 2013-12-11 08:47 - 358226169 _____ (Unigine Corp. ) C:\Users\00yoshi\Downloads\Unigine-Valley-10.exe 2013-12-11 08:28 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-12-11 08:28 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-12-11 08:28 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-11 08:28 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-12-11 08:28 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-11 08:28 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-11 08:28 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-11 08:28 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-11 08:28 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-11 08:28 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-11 08:28 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-11 08:28 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-11 08:28 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-11 08:28 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-11 08:28 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-11 08:28 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-11 08:28 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-11 08:28 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-11 08:28 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys ==================== One Month Modified Files and Folders ======= 2014-01-10 14:20 - 2014-01-10 14:19 - 00035322 _____ C:\Users\00yoshi\Downloads\FRST.txt 2014-01-10 14:19 - 2014-01-10 14:19 - 00050477 _____ C:\Users\00yoshi\Downloads\Defogger.exe 2014-01-10 14:19 - 2014-01-10 14:19 - 00000000 ____D C:\FRST 2014-01-10 14:19 - 2014-01-10 14:18 - 01932166 _____ (Farbar) C:\Users\00yoshi\Downloads\FRST64.exe 2014-01-10 14:17 - 2013-07-28 17:40 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\Skype 2014-01-10 14:04 - 2009-07-14 05:45 - 00017152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-10 14:04 - 2009-07-14 05:45 - 00017152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-10 13:54 - 2013-07-01 10:47 - 00003122 _____ C:\Windows\System32\Tasks\YourFile DownloaderUpdate 2014-01-10 13:52 - 2014-01-10 13:52 - 00550371 _____ C:\Users\00yoshi\Downloads\Autoruns.zip 2014-01-10 13:44 - 2012-01-28 11:17 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Paint.NET 2014-01-10 13:36 - 2012-01-25 17:27 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Adobe 2014-01-10 13:34 - 2012-05-18 07:14 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-10 13:32 - 2012-01-14 17:57 - 02066069 _____ C:\Windows\WindowsUpdate.log 2014-01-10 13:29 - 2012-01-14 18:00 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-10 13:28 - 2013-11-10 20:10 - 00000000 ____D C:\Users\00yoshi\Desktop\atlauncher 2014-01-10 13:28 - 2013-01-29 18:38 - 00000000 ___RD C:\Users\00yoshi\Dropbox 2014-01-10 13:28 - 2013-01-29 18:37 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\Dropbox 2014-01-10 13:26 - 2012-01-14 18:00 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-10 13:26 - 2011-09-05 23:24 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-10 13:26 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-09 22:32 - 2014-01-09 22:32 - 00032512 _____ C:\Windows\system32\Drivers\dingeeee37.sys 2014-01-09 22:32 - 2012-04-26 14:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-09 22:31 - 2014-01-09 21:55 - 00000000 ____D C:\ProgramData\dingeeee 2014-01-09 22:23 - 2014-01-09 22:23 - 00012092 _____ C:\Windows\system32\.crusader 2014-01-09 21:56 - 2014-01-09 21:56 - 00001909 _____ C:\Users\Public\Desktop\dingeeee.lnk 2014-01-09 21:56 - 2014-01-09 21:56 - 00000000 ____D C:\Program Files\dingeeee 2014-01-09 21:55 - 2014-01-09 21:55 - 10264904 _____ (SurfRight B.V.) C:\Users\00yoshi\Downloads\dingeeee_x64.exe 2014-01-09 21:51 - 2014-01-09 21:51 - 00017693 _____ C:\Users\00yoshi\Desktop\JRT.txt 2014-01-09 21:45 - 2014-01-09 21:45 - 01037068 _____ (Thisisu) C:\Users\00yoshi\Downloads\JRT.exe 2014-01-09 21:45 - 2014-01-09 21:45 - 00000000 ____D C:\Windows\ERUNT 2014-01-09 21:37 - 2014-01-09 21:37 - 00001054 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-09 21:37 - 2014-01-09 21:37 - 00000000 ____D C:\Program Files (x86)\MF 2014-01-09 21:37 - 2013-12-20 15:52 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2014-01-09 21:30 - 2014-01-09 21:30 - 23867560 _____ (Mozilla) C:\Users\00yoshi\Downloads\Firefox Setup 26.0.exe 2014-01-08 22:00 - 2014-01-08 20:31 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Temporary Projects 2014-01-08 16:36 - 2014-01-08 16:15 - 00000000 ____D C:\AdwCleaner 2014-01-08 16:15 - 2014-01-08 16:15 - 01233962 _____ C:\Users\00yoshi\Downloads\adwcleaner_3.016.exe 2014-01-08 14:08 - 2010-11-21 04:47 - 00437350 _____ C:\Windows\PFRO.log 2014-01-08 08:36 - 2013-10-09 11:48 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\.minecraft 2014-01-07 20:17 - 2014-01-05 15:24 - 00000000 ____D C:\ProgramData\InstallMate 2014-01-07 16:50 - 2012-01-14 18:00 - 00000000 ____D C:\Program Files\Google 2014-01-07 16:50 - 2012-01-14 18:00 - 00000000 ____D C:\Program Files (x86)\Google 2014-01-06 19:48 - 2012-01-14 18:55 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Google 2014-01-05 21:29 - 2013-12-21 23:32 - 00000000 ____D C:\Users\00yoshi\Desktop\DirectX Tutorialserie 1 Device erstellen 2014-01-05 15:31 - 2014-01-05 15:31 - 00000000 ____D C:\ProgramData\SoftWarehouse 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$ 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast\AppData\Local\Torch 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\Torch 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\ProgramData\504c2cf8db11ac3b 2014-01-04 14:56 - 2014-01-04 14:56 - 00018589 _____ C:\Users\00yoshi\Downloads\169_EW-Biomes.rar 2014-01-04 14:55 - 2014-01-04 14:55 - 08037055 _____ C:\Users\00yoshi\Downloads\Millenaire5.1.11.zip 2014-01-04 00:21 - 2013-12-19 08:21 - 00000075 _____ C:\Users\00yoshi\AppData\Roaming\WB.CFG 2014-01-04 00:04 - 2012-05-31 19:18 - 00000000 ____D C:\Users\00yoshi\Lange Nacht Der Wissenschaften 01-Dateien 2014-01-03 22:52 - 2014-01-03 22:51 - 00000000 ____D C:\Users\00yoshi\Desktop\GoingBeyond1_Tutorial 2014-01-03 22:50 - 2014-01-03 22:50 - 00790625 _____ C:\Users\00yoshi\Downloads\GoingBeyond1_Tutorial_Sample.zip 2014-01-03 22:44 - 2014-01-03 22:44 - 00193521 _____ C:\Users\00yoshi\Downloads\einfuehrung(1).zip 2014-01-03 22:24 - 2014-01-03 22:24 - 01358498 _____ C:\Users\00yoshi\Downloads\3DModel Source(1).zip 2014-01-03 22:08 - 2014-01-03 22:08 - 01358498 _____ C:\Users\00yoshi\Downloads\3DModel Source.zip 2014-01-03 18:54 - 2014-01-03 18:54 - 00569372 _____ (DotExE ) C:\Users\00yoshi\Downloads\MoonTools.exe 2014-01-02 17:04 - 2013-10-19 12:49 - 00000000 ____D C:\Users\00yoshi\Desktop\Unbenutzt 2014-01-02 17:02 - 2014-01-02 17:02 - 00043731 _____ C:\Users\00yoshi\Downloads\TextEffectsLib_1.1.0.0.zip 2014-01-02 16:59 - 2014-01-02 16:59 - 00117423 _____ C:\Users\00yoshi\Downloads\TextEffectsLibDemo_1.1.0.0.zip 2014-01-02 16:09 - 2014-01-02 16:09 - 00018432 _____ (MT Soft) C:\Users\00yoshi\Desktop\ZipLib.dll 2014-01-02 16:01 - 2012-11-30 18:17 - 00000000 ____D C:\Users\00yoshi\Documents\Visual Studio 2010 2014-01-02 15:16 - 2014-01-02 15:15 - 36293880 _____ (Dropbox, Inc.) C:\Users\00yoshi\Downloads\Dropbox 2.4.10(1).exe 2014-01-02 00:17 - 2012-11-22 15:06 - 00015872 _____ C:\Users\00yoshi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-12-31 00:12 - 2013-12-31 00:10 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Start 2013-12-31 00:08 - 2013-12-31 00:08 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\nUpdate 2013-12-30 23:55 - 2013-12-30 23:49 - 00000000 ____D C:\Users\00yoshi\Desktop\Updates f�r Programme 2013-12-30 23:50 - 2012-12-28 13:39 - 00000000 ____D C:\Users\00yoshi\Desktop\Der ganze Rest 2013-12-30 23:43 - 2013-01-29 18:37 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-12-30 23:43 - 2012-01-14 18:05 - 00000000 ___RD C:\Users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-12-30 23:22 - 2013-12-30 23:21 - 36293880 _____ (Dropbox, Inc.) C:\Users\00yoshi\Downloads\Dropbox 2.4.10.exe 2013-12-30 23:17 - 2013-12-30 23:17 - 00369345 _____ C:\Users\00yoshi\Downloads\nUpdate.rar 2013-12-30 22:54 - 2013-12-30 22:53 - 33841433 _____ C:\Users\00yoshi\Downloads\Minecraft_Modpack_1.6.2.rar 2013-12-27 22:24 - 2013-12-27 22:24 - 00095068 _____ C:\Users\00yoshi\Desktop\Paintball.jar 2013-12-27 13:26 - 2013-12-27 13:26 - 01927709 _____ C:\Users\00yoshi\Downloads\samp03x_svr_R2_win32.zip 2013-12-27 12:47 - 2013-12-27 12:47 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer 2013-12-27 12:47 - 2012-05-20 19:55 - 00000000 ____D C:\Users\00yoshi\Documents\GTA San Andreas User Files 2013-12-27 12:46 - 2013-12-27 12:45 - 12022145 _____ C:\Users\00yoshi\Downloads\sa-mp-0.3x-R1-2-install.exe 2013-12-26 01:29 - 2013-04-13 21:41 - 00000000 ____D C:\Users\00yoshi\AppData\Local\CrashDumps 2013-12-26 00:12 - 2013-04-13 23:05 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\vlc 2013-12-23 11:20 - 2013-12-07 12:06 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Minecraft2d_extented 2013-12-22 17:50 - 2013-12-22 17:50 - 00017266 _____ C:\Users\00yoshi\Downloads\3DAnimation2(1).zip 2013-12-22 16:25 - 2013-12-22 16:25 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft2d extented 2013-12-22 16:25 - 2012-06-22 13:07 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Deployment 2013-12-21 23:32 - 2013-12-21 23:32 - 00073915 _____ C:\Users\00yoshi\Downloads\DirectX Tutorialserie 1 Device erstellen.zip 2013-12-21 22:54 - 2013-12-21 22:54 - 00004162 _____ C:\Users\00yoshi\Desktop\lol.txt 2013-12-21 12:45 - 2013-12-21 12:45 - 00025750 _____ C:\Users\00yoshi\Documents\Unbenannt.camproj 2013-12-21 12:11 - 2011-05-16 15:04 - 00766056 _____ C:\Windows\system32\perfh007.dat 2013-12-21 12:11 - 2011-05-16 15:04 - 00175028 _____ C:\Windows\system32\perfc007.dat 2013-12-21 12:11 - 2009-07-14 06:13 - 01808962 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-20 22:42 - 2013-12-20 22:42 - 00159671 _____ C:\Users\00yoshi\Downloads\Thaumcraft-Extras-0.3.2a (1).zip 2013-12-20 20:34 - 2013-12-20 20:34 - 00072476 _____ C:\Users\00yoshi\Downloads\Forge_NBTEditv1.6.4.0.zip 2013-12-20 20:16 - 2013-11-16 12:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox.bak 2013-12-20 20:07 - 2013-12-20 20:07 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-12-20 20:07 - 2013-12-20 20:07 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-12-20 20:07 - 2013-10-07 00:03 - 00000000 ____D C:\ProgramData\Oracle 2013-12-20 20:07 - 2012-04-03 21:15 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-12-20 20:07 - 2012-04-03 21:15 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-12-20 20:07 - 2012-04-03 21:14 - 00000000 ____D C:\Program Files\Java 2013-12-20 19:51 - 2013-12-20 19:50 - 30694824 _____ (Oracle Corporation) C:\Users\00yoshi\Downloads\jre-7u45-windows-x64.exe 2013-12-20 19:50 - 2013-12-20 19:49 - 00042746 _____ C:\Users\00yoshi\Downloads\Fix Java File Types.zip 2013-12-20 18:10 - 2013-12-20 18:10 - 15200059 _____ C:\Users\00yoshi\Downloads\Tropicraft v3.0.5(1).zip 2013-12-20 18:06 - 2013-12-20 18:05 - 15200059 _____ C:\Users\00yoshi\Downloads\Tropicraft v3.0.5.zip 2013-12-20 14:39 - 2013-11-01 16:18 - 00000000 ____D C:\Users\00yoshi\Desktop\vbdateien 2013-12-20 14:14 - 2013-12-20 14:14 - 00716592 _____ () C:\Users\00yoshi\Downloads\GitHubSetup.exe 2013-12-19 09:13 - 2013-04-01 18:25 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\FTB modpack 2013-12-17 19:50 - 2013-12-17 19:48 - 00037357 _____ C:\Users\00yoshi\Downloads\Somnia-Pre2b.jar 2013-12-17 19:49 - 2013-12-17 19:49 - 02231448 _____ C:\Users\00yoshi\Downloads\minecraftforge-installer-1.6.4-9.11.1.916.jar 2013-12-17 17:00 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-15 17:02 - 2013-12-15 17:02 - 02205757 _____ C:\Users\00yoshi\Downloads\Railcraft_1.5.1-7.0.0.0.jar 2013-12-15 17:02 - 2013-12-15 17:02 - 00014347 _____ C:\Users\00yoshi\Downloads\util^iChunUtil1.0.0.zip 2013-12-15 17:02 - 2013-12-15 17:02 - 00014347 _____ C:\Users\00yoshi\Downloads\util^iChunUtil1.0.0(1).zip 2013-12-14 21:50 - 2013-12-14 21:50 - 00005759 _____ C:\Users\00yoshi\Downloads\FastGraphicsLib.zip 2013-12-14 15:56 - 2013-07-25 15:48 - 00000000 ____D C:\Windows\system32\MRT 2013-12-14 15:53 - 2011-07-18 21:31 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-14 13:27 - 2013-12-08 00:27 - 00000680 __RSH C:\Users\00yoshi\ntuser.pol 2013-12-14 13:27 - 2012-01-14 18:05 - 00000000 ____D C:\Users\00yoshi 2013-12-13 23:21 - 2013-12-13 23:21 - 00111351 _____ C:\Users\00yoshi\Downloads\ip pinger.rar 2013-12-13 22:18 - 2013-12-13 22:16 - 139921513 _____ C:\Users\00yoshi\Downloads\rockyou.txt 2013-12-13 22:14 - 2013-12-13 22:11 - 60498886 _____ C:\Users\00yoshi\Downloads\rockyou.txt.bz2 2013-12-13 22:11 - 2013-12-13 22:11 - 03149586 _____ C:\Users\00yoshi\Downloads\cain.txt 2013-12-13 22:10 - 2013-12-13 22:10 - 01069968 _____ C:\Users\00yoshi\Downloads\cain.txt.bz2 2013-12-13 20:59 - 2013-11-10 15:40 - 00000000 ____D C:\ProgramData\Package Cache 2013-12-13 20:59 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\MSBuild 2013-12-13 20:58 - 2013-11-10 15:51 - 00000000 ____D C:\Windows\system32\1031 2013-12-13 20:58 - 2013-11-10 15:51 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 12.0 2013-12-13 20:58 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-12-13 20:57 - 2012-11-30 17:49 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs 2013-12-13 20:54 - 2012-11-30 17:52 - 00000000 ____D C:\Windows\system32\1033 2013-12-13 20:51 - 2013-11-10 15:54 - 00000000 ____D C:\Windows\SysWOW64\1031 2013-12-13 20:39 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\MSBuild 2013-12-13 20:27 - 2012-01-14 18:00 - 00094208 _____ C:\Users\Default\AppData\Local\GDIPFONTCACHEV1.DAT 2013-12-13 20:27 - 2012-01-14 18:00 - 00094208 _____ C:\Users\Default User\AppData\Local\GDIPFONTCACHEV1.DAT 2013-12-13 18:12 - 2013-12-13 12:57 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Minecraft_texturepack_edi 2013-12-13 18:05 - 2013-12-13 18:00 - 00383816 _____ C:\Users\00yoshi\Downloads\CoreTemp64.zip 2013-12-13 18:03 - 2013-12-11 09:00 - 01065984 _____ C:\Users\00yoshi\AppData\Local\file__0.localstorage 2013-12-13 17:52 - 2013-12-13 17:50 - 46946304 _____ C:\Users\00yoshi\Downloads\Elektro-Training.exe 2013-12-13 17:19 - 2013-12-13 17:19 - 00006691 _____ C:\Users\00yoshi\Downloads\ZipLib.zip 2013-12-13 11:38 - 2013-12-13 11:38 - 00002750 _____ C:\Users\00yoshi\Unigine_Valley_Benchmark_1.0_20131213_1138.html 2013-12-12 17:42 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-11 14:07 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-12-11 14:06 - 2009-07-14 05:45 - 05004344 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-11 09:03 - 2013-12-11 09:00 - 00000000 ____D C:\Users\00yoshi\Valley 2013-12-11 08:54 - 2013-12-11 08:54 - 00002117 _____ C:\Users\Public\Desktop\Valley Benchmark 1.0.lnk 2013-12-11 08:54 - 2013-12-11 08:54 - 00000000 ____D C:\Program Files (x86)\Unigine 2013-12-11 08:47 - 2013-12-11 08:28 - 358226169 _____ (Unigine Corp. ) C:\Users\00yoshi\Downloads\Unigine-Valley-10.exe Files to move or delete: ==================== C:\Users\00yoshi\MyCraft.exe Some content of TEMP: ==================== C:\Users\00yoshi\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== BCD ================================ Windows-Start-Manager --------------------- Bezeichner {bootmgr} device partition=\Device\HarddiskVolume1 description Windows Boot Manager locale de-DE inherit {globalsettings} default {current} resumeobject {81be9816-e38b-11e0-af49-99356d797b37} displayorder {current} toolsdisplayorder {memdiag} timeout 30 Windows-Startladeprogramm ------------------------- Bezeichner {current} device partition=C: path \Windows\system32\winload.exe description Windows 7 locale de-DE inherit {bootloadersettings} recoverysequence {81be9818-e38b-11e0-af49-99356d797b37} recoveryenabled Yes osdevice partition=C: systemroot \Windows resumeobject {81be9816-e38b-11e0-af49-99356d797b37} nx OptIn vga No quietboot No usefirmwarepcisettings No bootlog No sos No Windows-Startladeprogramm ------------------------- Bezeichner {81be9818-e38b-11e0-af49-99356d797b37} device ramdisk=[C:]\Recovery\81be9818-e38b-11e0-af49-99356d797b37\Winre.wim,{81be9819-e38b-11e0-af49-99356d797b37} path \windows\system32\winload.exe description Windows Recovery Environment inherit {bootloadersettings} osdevice ramdisk=[C:]\Recovery\81be9818-e38b-11e0-af49-99356d797b37\Winre.wim,{81be9819-e38b-11e0-af49-99356d797b37} systemroot \windows nx OptIn winpe Yes Wiederaufnahme aus dem Ruhezustand ---------------------------------- Bezeichner {81be9816-e38b-11e0-af49-99356d797b37} device partition=C: path \Windows\system32\winresume.exe description Windows Resume Application locale de-DE inherit {resumeloadersettings} filedevice partition=C: filepath \hiberfil.sys debugoptionenabled No Windows-Speichertestprogramm ---------------------------- Bezeichner {memdiag} device partition=\Device\HarddiskVolume1 path \boot\memtest.exe description Windows Memory Diagnostic locale de-DE inherit {globalsettings} badmemoryaccess Yes EMS-Einstellungen ----------------- Bezeichner {emssettings} bootems Yes Debuggereinstellungen --------------------- Bezeichner {dbgsettings} debugtype Serial debugport 1 baudrate 115200 RAM-Defekte ----------- Bezeichner {badmemory} Globale Einstellungen --------------------- Bezeichner {globalsettings} inherit {dbgsettings} {emssettings} {badmemory} Startladeprogramm-Einstellungen ------------------------------- Bezeichner {bootloadersettings} inherit {globalsettings} {hypervisorsettings} Hypervisoreinstellungen ------------------- Bezeichner {hypervisorsettings} hypervisordebugtype Serial hypervisordebugport 1 hypervisorbaudrate 115200 Einstellungen zur Ladeprogrammfortsetzung ----------------------------------------- Bezeichner {resumeloadersettings} inherit {globalsettings} Ger�teoptionen -------------- Bezeichner {81be9819-e38b-11e0-af49-99356d797b37} description Ramdisk Options ramdisksdidevice partition=C: ramdisksdipath \Recovery\81be9818-e38b-11e0-af49-99356d797b37\boot.sdi LastRegBack: 2014-01-01 22:01 ==================== End Of Log ============================ --- --- --- Langsam ertrage ich es nicht mehr, dass pop-up's und neue tabs kommen und sachen grün unterstrichen sind, aber wenn man mit der maus draufgeht, erscheint ein grner kreis und nichts weiter passiert. Ich hab firefox nochmal in einem anderen Ordner installiert, hat nichts gebracht. MBAM und JRT im anhang. Geändert von 00yoshi (10.01.2014 um 15:44 Uhr) Grund: paar sachen verbessern |
10.01.2014, 16:06 | #2 |
/// the machine /// TB-Ausbilder | GreatSaver infiziert hi,
__________________Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.
__________________ |
10.01.2014, 17:16 | #3 |
| GreatSaver infiziert p.s. der ordner für meinen namen heißt nicht 00yoshi, wollte den namen ändern.
__________________Log im anhang. War zu lang. vb kann die assemblydatei nicht mehr finden. ;( Geändert von 00yoshi (10.01.2014 um 17:29 Uhr) |
11.01.2014, 13:11 | #4 |
/// the machine /// TB-Ausbilder | GreatSaver infiziert Hi, Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
11.01.2014, 13:52 | #5 |
| GreatSaver infiziertCode:
ATTFilter ComboFix 14-01-08.03 - 00yoshi 10.01.2014 16:52:20.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8174.5811 [GMT 1:00] ausgeführt von:: c:\users\00yoshi\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F} SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\install.exe c:\programdata\WindowsApplication1 c:\programdata\WindowsApplication1\WindowsApplication1\1.0.0.0\testtest.pcxntype c:\programdata\WindowsApplication1\WindowsApplication1\1.0.0.0\testtest.txt c:\users\00yoshi\4.0 c:\users\00yoshi\AppData\Roaming\r58Ies.tmp c:\users\00yoshi\AppData\Roaming\WindowsApplication1 c:\users\00yoshi\AppData\Roaming\WindowsApplication1\WindowsApplication1\1.0.0.0\block c:\users\00yoshi\AppData\Roaming\WindowsApplication1\WindowsApplication1\1.0.0.0\kombis c:\users\00yoshi\AppData\Roaming\WindowsApplication1\WindowsApplication1\1.0.0.0\kombis.dat c:\users\00yoshi\AppData\Roaming\WindowsApplication1\WindowsApplication1\1.0.0.0\name c:\users\00yoshi\AppData\Roaming\WindowsApplication1\WindowsApplication1\1.0.0.0\pw c:\users\00yoshi\MyCraft.exe c:\windows\SysWow64\frapsvid.dll c:\windows\SysWow64\rnaph.dll c:\windows\SysWow64\tmp8017.tmp c:\windows\SysWow64\tmpD845.tmp c:\windows\SysWow64\tmpEE1C.tmp c:\windows\SysWow64\tmpEE2D.tmp . . ((((((((((((((((((((((( Dateien erstellt von 2013-12-10 bis 2014-01-10 )))))))))))))))))))))))))))))) . . 2014-01-10 16:00 . 2014-01-10 16:00 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2014-01-10 16:00 . 2014-01-10 16:00 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-01-10 15:32 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{949BDFCB-A142-44C2-A208-09AC9DD05905}\mpengine.dll 2014-01-10 13:19 . 2014-01-10 13:19 -------- d-----w- C:\FRST 2014-01-09 21:32 . 2014-01-09 21:32 32512 ----a-w- c:\windows\system32\drivers\hitmanpro37.sys 2014-01-09 20:56 . 2014-01-09 20:56 -------- d-----w- c:\program files\HitmanPro 2014-01-09 20:55 . 2014-01-09 21:31 -------- d-----w- c:\programdata\HitmanPro 2014-01-09 20:45 . 2014-01-09 20:45 -------- d-----w- c:\windows\ERUNT 2014-01-09 20:37 . 2014-01-09 20:37 -------- d-----w- c:\program files (x86)\MF 2014-01-08 19:45 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2014-01-08 15:15 . 2014-01-08 15:36 -------- d-----w- C:\AdwCleaner 2014-01-05 14:31 . 2014-01-05 14:31 -------- d-----w- c:\programdata\SoftWarehouse 2014-01-05 14:24 . 2014-01-05 14:24 -------- d-----w- c:\users\UpdatusUser\AppData\Local\Google 2014-01-05 14:24 . 2014-01-05 14:24 -------- d-----w- c:\users\UpdatusUser\AppData\Local\Comodo 2014-01-05 14:24 . 2014-01-05 14:24 -------- d-----w- c:\users\HomeGroupUser$ 2014-01-05 14:24 . 2014-01-05 14:24 -------- d-----w- c:\users\Gast 2014-01-05 14:24 . 2014-01-05 14:24 -------- d-----w- c:\users\00yoshi\AppData\Local\Comodo 2014-01-05 14:24 . 2014-01-05 14:24 -------- d-----w- c:\programdata\504c2cf8db11ac3b 2014-01-05 14:24 . 2014-01-05 14:24 -------- d-----w- c:\users\Administrator 2014-01-05 14:24 . 2014-01-07 19:17 -------- d-----w- c:\programdata\InstallMate 2013-12-30 23:10 . 2013-12-30 23:12 -------- d-----w- c:\users\00yoshi\AppData\Local\Start 2013-12-30 23:08 . 2013-12-30 23:08 -------- d-----w- c:\users\00yoshi\AppData\Roaming\nUpdate 2013-12-20 19:07 . 2013-12-20 19:07 312744 ----a-w- c:\windows\system32\javaws.exe 2013-12-20 19:07 . 2013-12-20 19:07 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2013-12-13 11:57 . 2013-12-13 17:12 -------- d-----w- c:\users\00yoshi\AppData\Local\Minecraft_texturepack_edi . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-12-20 19:07 . 2012-04-03 20:15 189352 ----a-w- c:\windows\system32\javaw.exe 2013-12-20 19:07 . 2012-04-03 20:15 189352 ----a-w- c:\windows\system32\java.exe 2013-12-14 14:53 . 2011-07-18 20:31 90708896 ----a-w- c:\windows\system32\MRT.exe 2013-12-07 10:57 . 2012-05-18 06:14 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-12-07 10:57 . 2011-08-10 19:09 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-11-26 11:54 . 2013-12-11 08:26 23183360 ----a-w- c:\windows\system32\mshtml.dll 2013-11-26 10:19 . 2013-12-11 08:26 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2013-11-26 10:18 . 2013-12-11 08:26 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2013-11-26 09:48 . 2013-12-11 08:26 66048 ----a-w- c:\windows\system32\iesetup.dll 2013-11-26 09:46 . 2013-12-11 08:26 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll 2013-11-26 09:41 . 2013-12-11 08:26 2764288 ----a-w- c:\windows\system32\iertutil.dll 2013-11-26 09:29 . 2013-12-11 08:26 53760 ----a-w- c:\windows\system32\jsproxy.dll 2013-11-26 09:27 . 2013-12-11 08:26 33792 ----a-w- c:\windows\system32\iernonce.dll 2013-11-26 09:23 . 2013-12-11 08:26 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb 2013-11-26 09:21 . 2013-12-11 08:26 574976 ----a-w- c:\windows\system32\ieui.dll 2013-11-26 09:18 . 2013-12-11 08:26 139264 ----a-w- c:\windows\system32\ieUnatt.exe 2013-11-26 09:18 . 2013-12-11 08:26 111616 ----a-w- c:\windows\system32\ieetwcollector.exe 2013-11-26 09:16 . 2013-12-11 08:26 708608 ----a-w- c:\windows\system32\jscript9diag.dll 2013-11-26 08:57 . 2013-12-11 08:26 218624 ----a-w- c:\windows\system32\ie4uinit.exe 2013-11-26 08:35 . 2013-12-11 08:26 5769216 ----a-w- c:\windows\system32\jscript9.dll 2013-11-26 08:28 . 2013-12-11 08:26 553472 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2013-11-26 08:16 . 2013-12-11 08:26 4243968 ----a-w- c:\windows\SysWow64\jscript9.dll 2013-11-26 08:02 . 2013-12-11 08:26 1995264 ----a-w- c:\windows\system32\inetcpl.cpl 2013-11-26 07:48 . 2013-12-11 08:26 12996608 ----a-w- c:\windows\system32\ieframe.dll 2013-11-26 07:32 . 2013-12-11 08:26 1928192 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2013-11-26 07:07 . 2013-12-11 08:26 2334208 ----a-w- c:\windows\system32\wininet.dll 2013-11-26 06:40 . 2013-12-11 08:26 1395200 ----a-w- c:\windows\system32\urlmon.dll 2013-11-26 06:34 . 2013-12-11 08:26 817664 ----a-w- c:\windows\system32\ieapfltr.dll 2013-11-26 06:33 . 2013-12-11 08:26 1820160 ----a-w- c:\windows\SysWow64\wininet.dll 2013-11-23 18:26 . 2013-12-11 07:28 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2013-11-23 17:47 . 2013-12-11 07:28 465920 ----a-w- c:\windows\system32\WMPhoto.dll 2013-11-19 10:21 . 2010-11-21 03:27 267936 ------w- c:\windows\system32\MpSigStub.exe 2013-11-19 06:59 . 2013-11-19 06:59 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-11-19 06:59 . 2013-11-19 06:59 194048 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-11-19 06:59 . 2013-11-19 06:59 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2013-11-19 06:59 . 2013-11-19 06:59 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll 2013-11-19 06:59 . 2013-11-19 06:59 62464 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-11-19 06:59 . 2013-11-19 06:59 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2013-11-19 06:59 . 2013-11-19 06:59 337408 ----a-w- c:\windows\SysWow64\html.iec 2013-11-19 06:59 . 2013-11-19 06:59 235008 ----a-w- c:\windows\system32\elshyph.dll 2013-11-19 06:59 . 2013-11-19 06:59 182272 ----a-w- c:\windows\SysWow64\msls31.dll 2013-11-19 06:59 . 2013-11-19 06:59 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-11-19 06:59 . 2013-11-19 06:59 942592 ----a-w- c:\windows\system32\jsIntl.dll 2013-11-19 06:59 . 2013-11-19 06:59 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll 2013-11-19 06:59 . 2013-11-19 06:59 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2013-11-19 06:59 . 2013-11-19 06:59 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-11-19 06:59 . 2013-11-19 06:59 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2013-11-19 06:59 . 2013-11-19 06:59 61952 ----a-w- c:\windows\SysWow64\iesetup.dll 2013-11-19 06:59 . 2013-11-19 06:59 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-11-19 06:59 . 2013-11-19 06:59 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2013-11-19 06:59 . 2013-11-19 06:59 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-11-19 06:59 . 2013-11-19 06:59 454656 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-11-19 06:59 . 2013-11-19 06:59 36352 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-11-19 06:59 . 2013-11-19 06:59 247808 ----a-w- c:\windows\system32\msls31.dll 2013-11-19 06:59 . 2013-11-19 06:59 195584 ----a-w- c:\windows\system32\msrating.dll 2013-11-19 06:59 . 2013-11-19 06:59 151552 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-11-19 06:59 . 2013-11-19 06:59 139264 ----a-w- c:\windows\SysWow64\wextract.exe 2013-11-19 06:59 . 2013-11-19 06:59 13312 ----a-w- c:\windows\SysWow64\mshta.exe 2013-11-19 06:59 . 2013-11-19 06:59 13312 ----a-w- c:\windows\system32\msfeedssync.exe 2013-11-19 06:59 . 2013-11-19 06:59 131072 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-11-19 06:59 . 2013-11-19 06:59 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-11-19 06:59 . 2013-11-19 06:59 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-11-19 06:59 . 2013-11-19 06:59 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-11-19 06:59 . 2013-11-19 06:59 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-11-19 06:59 . 2013-11-19 06:59 84992 ----a-w- c:\windows\system32\mshtmled.dll 2013-11-19 06:59 . 2013-11-19 06:59 83968 ----a-w- c:\windows\system32\MshtmlDac.dll 2013-11-19 06:59 . 2013-11-19 06:59 81408 ----a-w- c:\windows\system32\icardie.dll 2013-11-19 06:59 . 2013-11-19 06:59 774144 ----a-w- c:\windows\system32\jscript.dll 2013-11-19 06:59 . 2013-11-19 06:59 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-11-19 06:59 . 2013-11-19 06:59 626176 ----a-w- c:\windows\system32\msfeeds.dll 2013-11-19 06:59 . 2013-11-19 06:59 62464 ----a-w- c:\windows\system32\pngfilt.dll 2013-11-19 06:59 . 2013-11-19 06:59 616104 ----a-w- c:\windows\system32\ieapfltr.dat 2013-11-19 06:59 . 2013-11-19 06:59 548352 ----a-w- c:\windows\system32\vbscript.dll 2013-11-19 06:59 . 2013-11-19 06:59 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-11-19 06:59 . 2013-11-19 06:59 48128 ----a-w- c:\windows\system32\imgutil.dll 2013-11-19 06:59 . 2013-11-19 06:59 453120 ----a-w- c:\windows\system32\dxtmsft.dll 2013-11-19 06:59 . 2013-11-19 06:59 413696 ----a-w- c:\windows\system32\html.iec 2013-11-19 06:59 . 2013-11-19 06:59 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2013-11-19 06:59 . 2013-11-19 06:59 30208 ----a-w- c:\windows\system32\licmgr10.dll 2013-11-19 06:59 . 2013-11-19 06:59 296960 ----a-w- c:\windows\system32\dxtrans.dll 2013-11-19 06:59 . 2013-11-19 06:59 263376 ----a-w- c:\windows\system32\iedkcs32.dll 2013-11-19 06:59 . 2013-11-19 06:59 243200 ----a-w- c:\windows\system32\webcheck.dll 2013-11-19 06:59 . 2013-11-19 06:59 235520 ----a-w- c:\windows\system32\url.dll 2013-11-19 06:59 . 2013-11-19 06:59 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-11-19 06:59 . 2013-11-19 06:59 147968 ----a-w- c:\windows\system32\occache.dll 2013-11-19 06:59 . 2013-11-19 06:59 143872 ----a-w- c:\windows\system32\wextract.exe 2013-11-19 06:59 . 2013-11-19 06:59 13824 ----a-w- c:\windows\system32\mshta.exe 2013-11-19 06:59 . 2013-11-19 06:59 135680 ----a-w- c:\windows\system32\iepeers.dll 2013-11-19 06:59 . 2013-11-19 06:59 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-11-19 06:59 . 2013-11-19 06:59 105984 ----a-w- c:\windows\system32\iesysprep.dll 2013-11-19 06:59 . 2013-11-19 06:59 101376 ----a-w- c:\windows\system32\inseng.dll 2013-11-12 02:23 . 2013-12-11 07:28 2048 ----a-w- c:\windows\system32\tzres.dll 2013-11-12 02:07 . 2013-12-11 07:28 2048 ----a-w- c:\windows\SysWow64\tzres.dll 2013-11-10 15:26 . 2013-11-10 15:26 2904512 ----a-w- c:\programdata\Microsoft\VisualStudio\12.0\1031\ResourceCache.dll 2013-10-30 02:32 . 2013-12-11 07:28 335360 ----a-w- c:\windows\system32\msieftp.dll 2013-10-30 02:19 . 2013-12-11 07:28 301568 ----a-w- c:\windows\SysWow64\msieftp.dll 2013-10-30 01:24 . 2013-12-11 07:28 3155968 ----a-w- c:\windows\system32\win32k.sys 2013-10-28 11:53 . 2011-09-05 22:23 18286416 ----a-w- c:\windows\system32\nvwgf2umx.dll 2013-10-28 11:53 . 2011-09-05 22:23 15855568 ----a-w- c:\windows\SysWow64\nvwgf2um.dll 2013-10-28 11:53 . 2013-10-28 11:53 1435504 ----a-w- c:\windows\system32\nvumdshimx.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2012-08-20 12:30 220608 ----a-w- c:\users\00yoshi\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2012-08-20 12:30 220608 ----a-w- c:\users\00yoshi\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2012-08-20 12:30 220608 ----a-w- c:\users\00yoshi\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 131248 ----a-w- c:\users\00yoshi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 131248 ----a-w- c:\users\00yoshi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 131248 ----a-w- c:\users\00yoshi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BrowserMask"="c:\program files (x86)\AntiBrowserSpy\AntiBrowserSpyBrowserMaske.exe" [2012-08-14 101328] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-11-14 20584608] "Sidebar"="c:\program files (x86)\Windows Sidebar\sidebar.exe" [2010-11-21 1174016] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-04-30 284440] "CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2010-08-03 107816] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] . c:\users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\00yoshi\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-12-18 30714312] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth Manager.lnk - c:\program files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-5-22 2756608] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg . R0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 c2wts;Claims to Windows Token Service;c:\program files\Windows Identity Foundation\v3.5\c2wtshost.exe;c:\program files\Windows Identity Foundation\v3.5\c2wtshost.exe [x] R3 DCamUSBET;ET USB 2760 Camera;c:\windows\system32\DRIVERS\etDevice64.sys;c:\windows\SYSNATIVE\DRIVERS\etDevice64.sys [x] R3 FiltUSBET;ET USB Device Lower Filter;c:\windows\system32\DRIVERS\etFilter64.sys;c:\windows\SYSNATIVE\DRIVERS\etFilter64.sys [x] R3 hitmanpro37;HitmanPro 3.7 Support Driver;c:\windows\system32\drivers\hitmanpro37.sys;c:\windows\SYSNATIVE\drivers\hitmanpro37.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x] R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x] R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys;c:\windows\SYSNATIVE\DRIVERS\psi_mf.sys [x] R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys;c:\windows\SYSNATIVE\pwdrvio.sys [x] R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys;c:\windows\SYSNATIVE\pwdspio.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 ScanUSBET;ET USB Still Image Capture Device;c:\windows\system32\DRIVERS\etScan64.sys;c:\windows\SYSNATIVE\DRIVERS\etScan64.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [x] R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys;c:\windows\SYSNATIVE\DRIVERS\wsvd.sys [x] R4 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x] R4 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x] R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE;c:\program files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [x] R4 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe;c:\program files (x86)\Secunia\PSI\PSIA.exe [x] R4 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe;c:\program files (x86)\Secunia\PSI\sua.exe [x] R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE;c:\program files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [x] R4 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\drivers\asmthub3.sys;c:\windows\SYSNATIVE\drivers\asmthub3.sys [x] S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\drivers\asmtxhci.sys;c:\windows\SYSNATIVE\drivers\asmtxhci.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8192su.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - PGRIRPOC *Deregistered* - pgrirpoc . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-12-05 19:23 1210320 ----a-w- c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-01-10 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-18 10:57] . 2014-01-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-14 17:00] . 2014-01-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-14 17:00] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2012-08-20 12:30 244672 ----a-w- c:\users\00yoshi\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2012-08-20 12:30 244672 ----a-w- c:\users\00yoshi\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2012-08-20 12:30 244672 ----a-w- c:\users\00yoshi\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 164016 ----a-w- c:\users\00yoshi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 164016 ----a-w- c:\users\00yoshi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 164016 ----a-w- c:\users\00yoshi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 164016 ----a-w- c:\users\00yoshi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MedionReminder"="c:\program files (x86)\CyberLink\PowerRecover\Reminder.exe" [2011-05-25 443688] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 1266912] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-09-20 444904] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "MedionReminder"="c:\program files (x86)\CyberLink\PowerRecover\Reminder.exe" [2011-05-25 443688] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm uSearchAssistant = hxxp://www.google.com IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 FF - ProfilePath - c:\users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\ FF - prefs.js: browser.search.defaulturl - google.de FF - prefs.js: browser.startup.homepage - hxxp://web.de/ FF - ExtSQL: 2013-12-06 09:06; {E6C1199F-E687-42da-8C24-E7770CC3AE66}; c:\users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKCU-Run-AdobeBridge - (no file) HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.0_03" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.0_04" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.0_05" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_01" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_01" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_02" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_02" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_03" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_03" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_04" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_04" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_05" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_05" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_06" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_06" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_07" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_07" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_08" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_08" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_09" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_09" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_10" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_10" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_11" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_11" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_12" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_12" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_13" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_13" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_14" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_14" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_15" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_15" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_16" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_16" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_17" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_17" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_18" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_18" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_19" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_19" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_20" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_20" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_21" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_21" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_01" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_01" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_02" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_02" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_03" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_03" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_04" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_04" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_01" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_01" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_02" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_02" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_03" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_03" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_04" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_04" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_05" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_05" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_06" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_06" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_07" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_07" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_01" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_01" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_02" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_02" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_03" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_03" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_04" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_04" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_05" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_05" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_06" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_06" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_07" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_07" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_08" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_08" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_09" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_09" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_10" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_10" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_11" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_11" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_12" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_12" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_13" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_13" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_14" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_14" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_15" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_15" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_16" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_16" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_17" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_17" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_18" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_18" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_19" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_19" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_20" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_20" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_21" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_21" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_22" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_22" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_23" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_23" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_24" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_24" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_25" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_25" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_26" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_26" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_27" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_27" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_28" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_28" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_29" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_29" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_30" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_30" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_31" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_31" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_32" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_32" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_33" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_33" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_34" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_34" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_35" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_35" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_36" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_36" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_37" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_37" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_38" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_38" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_39" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_39" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_40" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_40" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0041-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_41" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0041-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_41" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0042-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_42" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0042-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_42" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0043-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_43" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-0043-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_43" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_01" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_01" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_01" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_02" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_02" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_02" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_03" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_03" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_03" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_04" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_04" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_04" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_05" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_05" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_05" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_06" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_06" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_06" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_07" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_07" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_07" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_08" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_08" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_08" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_09" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_09" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_09" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_10" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_10" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_10" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_11" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_11" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_11" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_12" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_12" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_12" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_13" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_13" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_13" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_14" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_14" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_14" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_15" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_15" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_15" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_16" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_16" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_16" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_17" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_17" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_17" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_18" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_18" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_18" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_19" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_19" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_19" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_20" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_20" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_20" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_21" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_21" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_21" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_22" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_22" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_22" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_23" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_23" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_23" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_24" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_24" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_24" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_25" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_25" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_25" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_26" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_26" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_26" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_27" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_27" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_27" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_28" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_28" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_28" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_29" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_29" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_29" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_30" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_30" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_30" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_31" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_31" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0031-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_31" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_32" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_32" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0032-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_32" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_33" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_33" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0033-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_33" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_34" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_34" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0034-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_34" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_35" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_35" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0035-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_35" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_36" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_36" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0036-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_36" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_37" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_37" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0037-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_37" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_38" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_38" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0038-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_38" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_39" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_39" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0039-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_39" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_40" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_40" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0040-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_40" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0041-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_41" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0041-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_41" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0041-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_41" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0042-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_42" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0042-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_42" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0042-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_42" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0043-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_43" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0043-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_43" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0043-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_43" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0044-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_44" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0044-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_44" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0044-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_44" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0045-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_45" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0045-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_45" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0045-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_45" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0046-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_46" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0046-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_46" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0046-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_46" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0047-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_47" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0047-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_47" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0047-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_47" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0048-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_48" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0048-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_48" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0048-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_48" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0049-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_49" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0049-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_49" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0049-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_49" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0050-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_50" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0050-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_50" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0050-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_50" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0051-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_51" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0051-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_51" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0051-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_51" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0052-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_52" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0052-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_52" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0052-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_52" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0053-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_53" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0053-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_53" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0053-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_53" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0054-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_54" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0054-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_54" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0054-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_54" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0055-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_55" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0055-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_55" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-0055-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_55" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_01" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_01" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_01" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_02" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_02" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_02" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_03" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_03" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_03" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_04" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_04" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_04" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_05" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_05" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_05" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_06" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_06" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_06" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_07" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_07" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_07" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_08" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_08" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_08" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_09" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_09" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_09" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_10" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_10" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_10" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_11" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_11" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_11" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_12" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_12" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_12" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_13" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_13" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_13" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_14" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_14" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_14" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_15" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_15" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_15" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_16" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_16" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_16" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_17" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_17" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_17" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_18" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_18" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_18" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_19" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_19" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_19" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_20" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_20" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_20" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_21" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBB}] |
11.01.2014, 13:53 | #6 |
| GreatSaver infiziertCode:
ATTFilter @DACL=(02 0000) @="Java Plug-in 1.6.0_21" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_21" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_22" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_22" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_22" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_23" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_23" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_23" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_24" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_24" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_24" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_25" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_25" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_25" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_26" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_26" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_26" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_27" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_27" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_27" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_28" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_28" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0028-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_28" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_29" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_29" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_29" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_30" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_30" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_30" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_31" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_31" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_31" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_32" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_32" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_32" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_33" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_33" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_33" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_34" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_34" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_34" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_35" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_35" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_35" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_36" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_36" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0036-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_36" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_37" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_37" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_37" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_38" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_38" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_38" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_39" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_39" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_39" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_40" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_40" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0040-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_40" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0041-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_41" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0041-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_41" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0041-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_41" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0042-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_42" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0042-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_42" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0042-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_42" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_43" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_43" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_43" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0044-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_44" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0044-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_44" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0044-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_44" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_45" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_45" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_45" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0046-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_46" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0046-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_46" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0046-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_46" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0047-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_47" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0047-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_47" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0047-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_47" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0048-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_48" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0048-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_48" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0048-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_48" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0049-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_49" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0049-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_49" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0049-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_49" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0050-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_50" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0050-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_50" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0050-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_50" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0051-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_51" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0051-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_51" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0051-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_51" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0052-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_52" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0052-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_52" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0052-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_52" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0053-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_53" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0053-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_53" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0053-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_53" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0054-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_54" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0054-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_54" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0054-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_54" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0055-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_55" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0055-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_55" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0055-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_55" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0056-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_56" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0056-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_56" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0056-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_56" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0057-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_57" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0057-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_57" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0057-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_57" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0058-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_58" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0058-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_58" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0058-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_58" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0059-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_59" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0059-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_59" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0059-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_59" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0060-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_60" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0060-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_60" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0060-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_60" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0061-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_61" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0061-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_61" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0061-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_61" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0062-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_62" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0062-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_62" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0062-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_62" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0063-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_63" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0063-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_63" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0063-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_63" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0064-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_64" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0064-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_64" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0064-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_64" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0065-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_65" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0065-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_65" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-0065-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_65" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0016-0000-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_01" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_01" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_01" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_02" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_02" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0002-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_02" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_03" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_03" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0003-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_03" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_04" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_04" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0004-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_04" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_05" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_05" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0005-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_05" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_06" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_06" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0006-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_06" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_07" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_07" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0007-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_07" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_08" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_08" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0008-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_08" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_09" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_09" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0009-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_09" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_10" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_10" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0010-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_10" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_11" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_11" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0011-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_11" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_12" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_12" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0012-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_12" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_13" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_13" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_13" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_14" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_14" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0014-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_14" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_15" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_15" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0015-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_15" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_16" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_16" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0016-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_16" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_17" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_17" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0017-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_17" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_18" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_18" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0018-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_18" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_19" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_19" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0019-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_19" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_20" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_20" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0020-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_20" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_21" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_21" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0021-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_21" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_22" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_22" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0022-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_22" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_23" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_23" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0023-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_23" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_24" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_24" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0024-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_24" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_25" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_25" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_25" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_26" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_26" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0026-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_26" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_27" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_27" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0027-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_27" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_28" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_28" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0028-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_28" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_29" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_29" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0029-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_29" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_30" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_30" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0030-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_30" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_31" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_31" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0031-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_31" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_32" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_32" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0032-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_32" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_33" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_33" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0033-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_33" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_34" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_34" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0034-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_34" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_35" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_35" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0035-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_35" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_36" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_36" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0036-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_36" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_37" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_37" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0037-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_37" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_38" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_38" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0038-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_38" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_39" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_39" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0039-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_39" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_40" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_40" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0040-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_40" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0041-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_41" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0041-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_41" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0041-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_41" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0042-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_42" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0042-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_42" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0042-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_42" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0043-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_43" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0043-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_43" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0043-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_43" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0044-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_44" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0044-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_44" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0044-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_44" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_45" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0045-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_45" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-0045-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_45" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-2821466197-509347794-3075133886-1002_Classes\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}] @DACL=(02 0000) @="Java Plug-in 1.3.0_02" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-01-10 17:05:13 ComboFix-quarantined-files.txt 2014-01-10 16:05 . Vor Suchlauf: 20 Verzeichnis(se), 1.581.544.321.024 Bytes frei Nach Suchlauf: 24 Verzeichnis(se), 1.582.204.063.744 Bytes frei . - - End Of File - - C10B76F7A94FFAF35E5DCF3F72DED3BE |
12.01.2014, 08:05 | #7 |
/// the machine /// TB-Ausbilder | GreatSaver infiziert ok
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
12.01.2014, 13:12 | #8 |
| GreatSaver infiziert MAM: Code:
ATTFilter Malwarebytes Anti-Malware (PRO) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.01.12.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16476 00yoshi :: 00YOSHIPC [Administrator] Schutz: Aktiviert 12.01.2014 11:16:35 mbam-log-2014-01-12 (11-16-35).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 278231 Laufzeit: 13 Minute(n), 10 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) ADWCleaner: Code:
ATTFilter # AdwCleaner v3.016 - Bericht erstellt am 12/01/2014 um 13:07:26 # Aktualisiert 23/12/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : 00yoshi - 00YOSHIPC # Gestartet von : C:\Users\00yoshi\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\00yoshi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk Datei Gelöscht : C:\Windows\System32\Tasks\NCH Software ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v26.0 (de) [ Datei : C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\prefs.js ] Zeile gelöscht : user_pref("extensions._CZWPTV9iReU.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};if(window.self.location.protocol.indexOf('hxxp')>-1 && window.self==window.[...] -\\ Google Chrome v31.0.1650.63 [ Datei : C:\Users\00yoshi\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [32893 octets] - [08/01/2014 16:16:04] AdwCleaner[R1].txt - [1463 octets] - [12/01/2014 11:37:44] AdwCleaner[S0].txt - [31969 octets] - [08/01/2014 16:35:56] AdwCleaner[S1].txt - [1384 octets] - [12/01/2014 13:07:26] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1444 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.0 (01.07.2014:1) OS: Windows 7 Home Premium x64 Ran by 00yoshi on 12.01.2014 at 13:14:25,02 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ FireFox Successfully deleted the following from C:\Users\00yoshi\AppData\Roaming\mozilla\firefox\profiles\wyp1suyn.default\prefs.js user_pref("extensions._CZWPTV9iReU.epoch", "1389615150"); user_pref("extensions._CZWPTV9iReU.scode", "(function(){try{if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};}catch(e){};if(window.self.location.protocol.i user_pref("extensions._CZWPTV9iReU.url", "hxxp://syncer-jpi.info/sync2/?q=hfZ9oeDGDzrMCyVUojw8rHUMg708BNmGWj8wmihGheDUojw9rdwEqjw9rTnFqGhIC7n0rjnErjwGrjsFrTwEtNhVCT94tMVKhd98q ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 12.01.2014 at 13:19:40,79 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Geändert von 00yoshi (12.01.2014 um 13:21 Uhr) |
12.01.2014, 13:26 | #9 |
| GreatSaver infiziert Neues FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-01-2014 Ran by 00yoshi (administrator) on 00YOSHIPC on 12-01-2014 13:23:21 Running from C:\Users\00yoshi\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft) C:\Program Files (x86)\AntiBrowserSpy\AntiBrowserSpyBrowserMaske.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Sidebar\sidebar.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (Dropbox, Inc.) C:\Users\00yoshi\AppData\Roaming\Dropbox\bin\Dropbox.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Mozilla Corporation) C:\Program Files (x86)\MF\firefox.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MedionReminder] - C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe [443688 2011-05-26] (CyberLink) HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-04-30] (Intel Corporation) HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-03] (CyberLink) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\RunOnce: [MedionReminder] - C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe /DeleteRunKey [443688 2011-05-26] (CyberLink) HKCU\...\Run: [BrowserMask] - C:\Program Files (x86)\AntiBrowserSpy\AntiBrowserSpyBrowserMaske.exe [101328 2012-08-14] (Microsoft) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKCU\...\Policies\system: [LogonHoursAction] 2 HKCU\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\Default\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] () HKU\Default\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs HKU\Default User\...\RunOnce: [HKCU] - C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] () HKU\Default User\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs Startup: C:\Users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\00yoshi\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: CBAbzockschutz.InitToolbarBHO - {2e250b90-0e7a-42a3-9d65-e39f9f227fa4} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - COMPUTERBILD-Abzockschutz - {353e2a48-6254-4bd3-88f4-3b51a0ca7870} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\..\Interfaces\{84BF9EDE-124A-499C-AED4-CA030D3CFE4D}: [NameServer]62.109.121.2 62.109.121.1 FireFox: ======== FF ProfilePath: C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default FF NewTab: about:blank FF Homepage: hxxp://web.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.0.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\00yoshi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF SearchPlugin: C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: greAtsaaveR - C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\Extensions\rge@vwige.net [2014-01-05] FF Extension: Lightbeam - C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\Extensions\jid1-F9UJ2thwoAm5gQ@jetpack.xpi [2013-10-06] FF Extension: XJZ Survey Remover - C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\Extensions\survey-remover@gmx.com.xpi [2013-10-12] FF Extension: WEB.DE MailCheck - C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\Extensions\toolbar@web.de.xpi [2012-02-13] FF Extension: NoScript - C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-06-29] FF Extension: Adblock Plus - C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-03-11] FF Extension: COMPUTERBILD-Abzockschutz - C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\Extensions\{d49175b3-3fd8-43b8-b28e-da5d47f3c398}.xpi [2013-04-02] FF Extension: QuickJava - C:\Users\00yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\wyp1suyn.default\Extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi [2013-12-06] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBA} [2013-12-20] FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\MF\firefox.exe Chrome: ======= CHR DefaultSearchProvider: Web CHR DefaultSearchURL: hxxp://www.google.com CHR DefaultNewTabURL: CHR Extension: (greAtsaaveR) - C:\Users\00yoshi\AppData\Local\Google\Chrome\User Data\Default\Extensions\belcdgkhhmfeilamilifdjfdillmmcjg\2.7 [2014-01-05] CHR Extension: (Google Wallet) - C:\Users\00yoshi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 [2013-12-17] CHR HKLM-x32\...\Chrome\Extension: [ibnmbpihhamedhophbnjjpidokcknoid] - C:\Program Files (x86)\AP Suggestor\APSuggestor.crx [2013-12-17] ==================== Services (Whitelisted) ================= S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [15768 2010-02-03] (Microsoft Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation) R2 MSSQL$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [43028328 2011-09-22] (Microsoft Corporation) S4 msvsmon90; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [4737024 2008-07-29] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation) S4 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1328736 2012-09-24] (Secunia) S4 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [656480 2012-09-24] (Secunia) S4 SQLAgent$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [370024 2011-09-22] (Microsoft Corporation) S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [x] ==================== Drivers (Whitelisted) ==================== S3 DCamUSBET; C:\Windows\System32\DRIVERS\etDevice64.sys [527744 2007-07-23] (eMPIA Technology, Inc.) S3 FiltUSBET; C:\Windows\System32\DRIVERS\etFilter64.sys [281088 2007-06-14] (eMPIA Technology Inc.) S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [32512 2014-01-09] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation) S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19936 2012-01-18] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [13280 2012-01-18] () S3 ScanUSBET; C:\Windows\System32\DRIVERS\etScan64.sys [9216 2007-07-23] (eMPIA Technology, Inc.) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S3 WinRing0_1_2_0; C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [14544 2010-11-01] (OpenLibSys.org) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S4 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] S0 nvpciflt; system32\DRIVERS\nvpciflt.sys [x] ========================== Drivers MD5 ======================= C:\Windows\system32\drivers\1394ohci.sys ==> MD5 is legit C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit C:\Windows\system32\drivers\adp94xx.sys ==> MD5 is legit C:\Windows\system32\drivers\adpahci.sys ==> MD5 is legit C:\Windows\system32\drivers\adpu320.sys ==> MD5 is legit C:\Windows\SysWow64\drivers\Afc.sys 6CCD1135320109D6B219F1A6E04AD9F6 C:\Windows\system32\drivers\afd.sys 79059559E89D06E8B80CE2944BE20228 C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit C:\Windows\system32\drivers\amdk8.sys ==> MD5 is legit C:\Windows\system32\drivers\amdppm.sys ==> MD5 is legit C:\Windows\system32\drivers\amdsata.sys D4121AE6D0C0E7E13AA221AA57EF2D49 C:\Windows\system32\drivers\amdsbs.sys ==> MD5 is legit C:\Windows\System32\drivers\amdxata.sys 540DAF1CEA6094886D72126FD7C33048 C:\Windows\system32\drivers\appid.sys ==> MD5 is legit C:\Windows\system32\drivers\arc.sys ==> MD5 is legit C:\Windows\system32\drivers\arcsas.sys ==> MD5 is legit C:\Windows\system32\drivers\asmthub3.sys 0AA7A996792FB0287B33A57A8093AE44 C:\Windows\system32\drivers\asmtxhci.sys 125DC3ABF5BFCCFE82AD17D078E0B9EC C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit C:\Windows\system32\drivers\atapi.sys ==> MD5 is legit C:\Windows\system32\drivers\bxvbda.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\b57nd60a.sys ==> MD5 is legit C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit C:\Windows\system32\drivers\blbdrive.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit C:\Windows\system32\drivers\BrFiltLo.sys ==> MD5 is legit C:\Windows\system32\drivers\BrFiltUp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bridge.sys 5C2F352A4E961D72518261257AAE204B C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit C:\Windows\system32\drivers\bthmodem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit C:\Windows\system32\drivers\circlass.sys ==> MD5 is legit C:\Windows\System32\CLFS.sys ==> MD5 is legit C:\Windows\system32\drivers\CmBatt.sys ==> MD5 is legit C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit C:\Windows\System32\Drivers\cng.sys EBF28856F69CF094A902F884CF989706 C:\Windows\system32\drivers\compbatt.sys ==> MD5 is legit C:\Windows\system32\drivers\CompositeBus.sys ==> MD5 is legit C:\Windows\system32\drivers\crcdisk.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\etDevice64.sys 04F1DC6D20E145FB29C9536A5E4FDA90 C:\Windows\System32\Drivers\dfsc.sys ==> MD5 is legit C:\Windows\System32\drivers\discache.sys ==> MD5 is legit C:\Windows\System32\drivers\disk.sys ==> MD5 is legit C:\Windows\system32\drivers\drmkaud.sys ==> MD5 is legit C:\Windows\System32\drivers\dxgkrnl.sys 88612F1CE3BF42256913BF6E61C70D52 C:\Windows\system32\drivers\evbda.sys ==> MD5 is legit C:\Windows\system32\drivers\elxstor.sys ==> MD5 is legit C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit C:\Windows\System32\Drivers\exfat.sys ==> MD5 is legit C:\Windows\System32\Drivers\fastfat.sys ==> MD5 is legit C:\Windows\system32\drivers\fdc.sys ==> MD5 is legit C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\etFilter64.sys 059B282B748D5E027B60E276CF424BAD C:\Windows\system32\drivers\flpydisk.sys ==> MD5 is legit C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit C:\Windows\System32\Drivers\Fs_Rec.sys 6BD9295CC032DD3077C671FCCF579A7B C:\Windows\System32\DRIVERS\fvevol.sys 8F6322049018354F45F05A2FD2D4E5E0 C:\Windows\system32\drivers\gagp30kx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\hamachi.sys 1E6438D4EA6E1174A3B3B1EDC4DE660B C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit C:\Windows\System32\drivers\HdAudio.sys 975761C778E33CD22498059B91E7373A C:\Windows\system32\drivers\HDAudBus.sys ==> MD5 is legit C:\Windows\system32\drivers\HidBatt.sys ==> MD5 is legit C:\Windows\system32\drivers\hidbth.sys ==> MD5 is legit C:\Windows\system32\drivers\hidir.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 is legit C:\Windows\system32\drivers\hitmanpro37.sys FCE2251FE4464DCAA2F4684F19A8EE9B C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit C:\Windows\System32\drivers\HTTP.sys ==> MD5 is legit C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit C:\Windows\system32\drivers\i8042prt.sys ==> MD5 is legit C:\Windows\System32\drivers\iaStor.sys 26CF4275034214ECEDD8EC17B0A18A99 C:\Windows\system32\drivers\iaStorV.sys AAAF44DB3BD0B9D1FB6969B23ECC8366 C:\Windows\System32\DRIVERS\igdkmd64.sys ==> MD5 is legit C:\Windows\system32\drivers\iirsp.sys ==> MD5 is legit C:\Windows\System32\drivers\RTKVHD64.sys 8F6ED52134EBB4CE2953EC37C9275497 C:\Windows\system32\drivers\intelide.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit C:\Windows\system32\drivers\msiscsi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\kbdhid.sys ==> MD5 is legit C:\Windows\System32\Drivers\ksecdd.sys 8F489706472F7E9A06BAAA198703FA64 C:\Windows\System32\Drivers\ksecpkg.sys 868A2CAAB12EFC7A021682BCA0EEC54C C:\Windows\system32\drivers\ksthunk.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_fc.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_sas.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_sas2.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_scsi.sys ==> MD5 is legit C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit C:\Windows\system32\drivers\mbam.sys 0BB97D43299910CBFBA59C461B99B910 C:\Windows\system32\drivers\megasas.sys ==> MD5 is legit C:\Windows\system32\drivers\MegaSR.sys ==> MD5 is legit C:\Windows\system32\drivers\HECIx64.sys A6518DCC42F7A6E999BB3BEA8FD87567 C:\Windows\System32\drivers\modem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit C:\Windows\System32\drivers\mountmgr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\MpFilter.sys C6B88D62F20AC646C6BD5C032EC2FAF9 C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\mrxdav.sys 1A4F75E63C9FB84B85DFFC6B63FD5404 C:\Windows\System32\DRIVERS\mrxsmb.sys A5D9106A73DC88564C825D317CAC68AC C:\Windows\System32\DRIVERS\mrxsmb10.sys D711B3C1D5F42C0C2415687BE09FC163 C:\Windows\System32\DRIVERS\mrxsmb20.sys 9423E9D355C8D303E76B8CFBD8A5C30C C:\Windows\system32\drivers\msahci.sys ==> MD5 is legit C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit C:\Windows\system32\drivers\mssmbios.sys ==> MD5 is legit C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit C:\Windows\system32\drivers\MTConfig.sys ==> MD5 is legit C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit C:\Windows\System32\drivers\ndis.sys 760E38053BF56E501D562B70AD796B88 C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit C:\Windows\system32\drivers\nfrd960.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\NisDrvWFP.sys ACE8C64C57E4A711473C8BC10ADF692B C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit C:\Windows\System32\Drivers\Ntfs.sys B98F8C6E31CD07B2E6F71F7F648E38C0 C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit C:\Windows\System32\drivers\nvhda64v.sys 1F07B814C0BB5AABA703ABFF1F31F2E8 C:\Windows\System32\DRIVERS\nvlddmkm.sys E71E299FF15390E585BACF2C18F55078 C:\Windows\system32\drivers\nvraid.sys 0A92CB65770442ED0DC44834632F66AD C:\Windows\system32\drivers\nvstor.sys DAB0E87525C10052BF65F06152F37E4A C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit C:\Windows\system32\drivers\parport.sys ==> MD5 is legit C:\Windows\System32\drivers\partmgr.sys E9766131EEADE40A27DC27D2D68FBA9C C:\Windows\System32\drivers\pci.sys ==> MD5 is legit C:\Windows\system32\drivers\pciide.sys ==> MD5 is legit C:\Windows\system32\drivers\pcmcia.sys ==> MD5 is legit C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit C:\Windows\System32\drivers\peauth.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit C:\Windows\system32\drivers\processr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\psi_mf.sys FB46E9A827A8799EBD7BFA9128C91F37 C:\Windows\system32\pwdrvio.sys FF40216A382B30CC39372B889AE1F785 C:\Windows\system32\pwdspio.sys BD08A9CDF23502B1C141D52D9D6A6648 C:\Windows\system32\drivers\ql2300.sys ==> MD5 is legit C:\Windows\system32\drivers\ql40xx.sys ==> MD5 is legit C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit C:\Windows\system32\drivers\rdpbus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpvideominiport.sys 313F68E1A3E6345A4F47A36B07062F34 C:\Windows\System32\Drivers\RDPWD.sys E61608AA35E98999AF9AAEEEA6114B0A C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\Rt64win7.sys E50CFB92986DCAB49DE93788FD695813 C:\Windows\System32\DRIVERS\RTL8192su.sys B3F36B4B3F192EA87DDC119F3A0B3E45 C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\etScan64.sys 7AD81DB1549878DEEAAECED63981C8FC C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\serenum.sys ==> MD5 is legit C:\Windows\system32\drivers\serial.sys ==> MD5 is legit C:\Windows\system32\drivers\sermouse.sys ==> MD5 is legit C:\Windows\system32\drivers\sffdisk.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_sd.sys ==> MD5 is legit C:\Windows\system32\drivers\sfloppy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\Sftfslh.sys 2046AA7491DE7EFA4D70E615D9BC9D09 C:\Windows\System32\DRIVERS\Sftplaylh.sys 0E0446BC4D51BE4263ACB7E33491191C C:\Windows\System32\DRIVERS\Sftredirlh.sys C5FB982CD266E604ED3142102C26D62C C:\Windows\System32\DRIVERS\Sftvollh.sys 2575511AF67AA1FA068CCC4918E2C2A3 C:\Windows\system32\drivers\SiSRaid2.sys ==> MD5 is legit C:\Windows\system32\drivers\sisraid4.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\srv.sys 441FBA48BFF01FDB9D5969EBC1838F0B C:\Windows\System32\DRIVERS\srv2.sys B4ADEBBF5E3677CCE9651E0F01F7CC28 C:\Windows\System32\DRIVERS\srvnet.sys 27E461F0BE5BFF5FC737328F749538C3 C:\Windows\system32\drivers\stexstor.sys ==> MD5 is legit C:\Windows\system32\drivers\swenum.sys ==> MD5 is legit C:\Windows\System32\drivers\tcpip.sys 40AF23633D197905F03AB5628C558C51 C:\Windows\System32\DRIVERS\tcpip.sys 40AF23633D197905F03AB5628C558C51 C:\Windows\System32\drivers\tcpipreg.sys 1B16D0BD9841794A6E0CDE0CEF744ABC C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit C:\Windows\System32\drivers\tdtcp.sys 51C5ECEB1CDEE2468A1748BE550CFBC8 C:\Windows\System32\DRIVERS\tdx.sys ==> MD5 is legit C:\Windows\system32\drivers\termdd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\tosporte.sys C14882C535E97B180ACA9FC716C228FB C:\Windows\System32\DRIVERS\tosrfbd.sys A2242F46131F3BEE3D1DA279B74111BA C:\Windows\System32\Drivers\tosrfbnp.sys 0716088A07A468FFF2DBFCA1DE55C0B6 C:\Windows\System32\Drivers\tosrfcom.sys 98C10D5862C4C5E58A9E09BEB07FB6C5 C:\Windows\System32\DRIVERS\Tosrfhid.sys 33C90B98B74D01D179E1963A5BF5EDF9 C:\Windows\System32\DRIVERS\tosrfnds.sys 95552D0B11C70846299DCA2FF0082205 C:\Windows\System32\drivers\tosrfsnd.sys A99D0670095414C7B3244DC3D0314ACB C:\Windows\System32\DRIVERS\tosrfusb.sys A69030B8F4C73C475E81A35F93C9C964 C:\Windows\System32\DRIVERS\tssecsrv.sys 4CE278FC9671BA81A138D70823FCAA09 C:\Windows\System32\drivers\tsusbflt.sys 17C6B51CBCCDED95B3CC14E22791F85E C:\Windows\system32\drivers\TsUsbGD.sys AD64450A4ABE076F5CB34CC08EEACB07 C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit C:\Windows\system32\drivers\uagp35.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\umbus.sys ==> MD5 is legit C:\Windows\system32\drivers\umpass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\usbccgp.sys ACCEA6BC68D0C9A78EB97EE159028B4E C:\Windows\system32\drivers\usbcir.sys 80B0F7D5CCF86CEB5D402EAAF61FEC31 C:\Windows\system32\drivers\usbehci.sys 311C1DD1088E55BEAE15954D17F50646 C:\Windows\System32\DRIVERS\usbhub.sys 280E90CBF4B2DDD169F0728CB44D726F C:\Windows\system32\drivers\usbohci.sys 9406D801042FAF859CF81B2C886413DC C:\Windows\System32\DRIVERS\usbprint.sys ==> MD5 is legit C:\Windows\system32\drivers\usbscan.sys 9661DA76B4531B2DA272ECCE25A8AF24 C:\Windows\System32\DRIVERS\USBSTOR.SYS FED648B01349A3C8395A5169DB5FB7D6 C:\Windows\system32\drivers\usbuhci.sys A83D0EC9AE4C31704442099D40BA2471 C:\Windows\System32\Drivers\usbvideo.sys 1F775DA4CF1A3A1834207E975A72E9D7 C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit C:\Windows\System32\drivers\vga.sys ==> MD5 is legit C:\Windows\system32\drivers\vhdmp.sys ==> MD5 is legit C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit C:\Windows\System32\drivers\volsnap.sys ==> MD5 is legit C:\Windows\system32\drivers\vsmraid.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwifibus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwififlt.sys ==> MD5 is legit C:\Windows\system32\drivers\wacompen.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\system32\drivers\wd.sys ==> MD5 is legit C:\Windows\System32\drivers\Wdf01000.sys E2C933EDBC389386EBE6D2BA953F43D8 C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit C:\Windows\SysWOW64\drivers\wimmount.sys ==> MD5 is legit C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys 0C0195C48B6B8582FA6F6373032118DA C:\Windows\System32\DRIVERS\WinUsb.sys FE88B288356E7B47B74B13372ADD906D C:\Windows\system32\drivers\wmiacpi.sys ==> MD5 is legit C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wsvd.sys 82E8F5AA03DF7DBDB8A33F700D5D8CDA C:\Windows\System32\drivers\WudfPf.sys AB886378EEB55C6C75B4F2D14B6C869F C:\Windows\System32\DRIVERS\WUDFRd.sys DDA4CAF29D8C0A297F886BFE561E6659 ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-12 13:23 - 2014-01-12 13:23 - 00000000 ____D C:\Users\00yoshi\Downloads\FRST-OlderVersion 2014-01-12 13:19 - 2014-01-12 13:19 - 00001186 _____ C:\Users\00yoshi\Desktop\JRT.txt 2014-01-12 13:13 - 2014-01-12 13:13 - 01037068 _____ (Thisisu) C:\Users\00yoshi\Downloads\JRT(1).exe 2014-01-12 11:36 - 2014-01-12 11:36 - 01233962 _____ C:\Users\00yoshi\Desktop\adwcleaner.exe 2014-01-12 11:23 - 2014-01-12 11:24 - 19924817 _____ C:\Users\00yoshi\Downloads\craftbukkit-1.7.2-R0.3-20140106.202339-8.jar 2014-01-11 10:45 - 2014-01-11 10:47 - 00000000 ____D C:\ProgramData\SecTaskMan 2014-01-11 10:45 - 2014-01-11 10:45 - 02365840 _____ C:\Users\00yoshi\Downloads\SecurityTaskManager_Setup(1).exe 2014-01-11 10:45 - 2014-01-11 10:45 - 00000000 ____D C:\Program Files (x86)\Security Task Manager 2014-01-10 18:36 - 2014-01-12 13:09 - 00000392 _____ C:\Windows\setupact.log 2014-01-10 18:36 - 2014-01-10 18:37 - 00473584 _____ C:\Windows\Minidump\011014-21730-01.dmp 2014-01-10 18:36 - 2014-01-10 18:36 - 663286171 _____ C:\Windows\MEMORY.DMP 2014-01-10 18:36 - 2014-01-10 18:36 - 00000000 ____D C:\Windows\Minidump 2014-01-10 18:36 - 2014-01-10 18:36 - 00000000 _____ C:\Windows\setuperr.log 2014-01-10 17:18 - 2014-01-10 17:18 - 00000000 ____D C:\Users\00yoshi\Desktop\log's 2014-01-10 17:17 - 2014-01-10 17:17 - 00011254 _____ C:\Users\00yoshi\Downloads\Neuer ZIP-komprimierter Ordner.zip 2014-01-10 17:15 - 2014-01-10 17:17 - 00011254 _____ C:\Users\00yoshi\Desktop\Neuer ZIP-komprimierter Ordner.zip 2014-01-10 17:05 - 2014-01-10 17:16 - 00141705 _____ C:\ComboFix.txt 2014-01-10 16:40 - 2014-01-10 17:06 - 00000000 ____D C:\ComboFix 2014-01-10 16:40 - 2014-01-10 17:05 - 00000000 ____D C:\Qoobox 2014-01-10 16:40 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-10 16:40 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-10 16:40 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-10 16:40 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-10 16:40 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-10 16:40 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-10 16:40 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-10 16:40 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-10 16:39 - 2014-01-10 17:01 - 00000000 ____D C:\Windows\erdnt 2014-01-10 16:18 - 2014-01-10 16:19 - 05162489 ____R (Swearware) C:\Users\00yoshi\Desktop\ComboFix.exe 2014-01-10 14:22 - 2014-01-10 14:22 - 00000474 _____ C:\Users\00yoshi\Downloads\defogger_disable.log 2014-01-10 14:22 - 2014-01-10 14:22 - 00000000 _____ C:\Users\00yoshi\defogger_reenable 2014-01-10 14:20 - 2014-01-10 14:22 - 00035575 _____ C:\Users\00yoshi\Downloads\Addition.txt 2014-01-10 14:19 - 2014-01-12 13:24 - 00034834 _____ C:\Users\00yoshi\Downloads\FRST.txt 2014-01-10 14:19 - 2014-01-12 13:23 - 00000000 ____D C:\FRST 2014-01-10 14:19 - 2014-01-10 14:19 - 00050477 _____ C:\Users\00yoshi\Downloads\Defogger.exe 2014-01-10 14:18 - 2014-01-12 13:23 - 02075136 _____ (Farbar) C:\Users\00yoshi\Downloads\FRST64.exe 2014-01-10 13:52 - 2014-01-10 13:52 - 00550371 _____ C:\Users\00yoshi\Downloads\Autoruns.zip 2014-01-09 22:32 - 2014-01-09 22:32 - 00032512 _____ C:\Windows\system32\Drivers\hitmanpro37.sys 2014-01-09 22:23 - 2014-01-09 22:23 - 00012092 _____ C:\Windows\system32\.crusader 2014-01-09 21:56 - 2014-01-09 21:56 - 00001909 _____ C:\Users\Public\Desktop\HitmanPro.lnk 2014-01-09 21:56 - 2014-01-09 21:56 - 00000000 ____D C:\Program Files\HitmanPro 2014-01-09 21:55 - 2014-01-09 22:31 - 00000000 ____D C:\ProgramData\HitmanPro 2014-01-09 21:55 - 2014-01-09 21:55 - 10264904 _____ (SurfRight B.V.) C:\Users\00yoshi\Downloads\HitmanPro_x64.exe 2014-01-09 21:45 - 2014-01-09 21:45 - 01037068 _____ (Thisisu) C:\Users\00yoshi\Downloads\JRT.exe 2014-01-09 21:45 - 2014-01-09 21:45 - 00000000 ____D C:\Windows\ERUNT 2014-01-09 21:37 - 2014-01-09 21:37 - 00001054 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-09 21:37 - 2014-01-09 21:37 - 00000000 ____D C:\Program Files (x86)\MF 2014-01-09 21:30 - 2014-01-09 21:30 - 23867560 _____ (Mozilla) C:\Users\00yoshi\Downloads\Firefox Setup 26.0.exe 2014-01-08 16:15 - 2014-01-12 13:07 - 00000000 ____D C:\AdwCleaner 2014-01-08 16:15 - 2014-01-08 16:15 - 01233962 _____ C:\Users\00yoshi\Downloads\adwcleaner_3.016.exe 2014-01-05 15:31 - 2014-01-05 15:31 - 00000000 ____D C:\ProgramData\SoftWarehouse 2014-01-05 15:24 - 2014-01-07 20:17 - 00000000 ____D C:\ProgramData\InstallMate 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$ 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast\AppData\Local\Torch 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\Torch 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\ProgramData\504c2cf8db11ac3b 2014-01-04 14:56 - 2014-01-04 14:56 - 00018589 _____ C:\Users\00yoshi\Downloads\169_EW-Biomes.rar 2014-01-04 14:55 - 2014-01-04 14:55 - 08037055 _____ C:\Users\00yoshi\Downloads\Millenaire5.1.11.zip 2014-01-03 22:50 - 2014-01-03 22:50 - 00790625 _____ C:\Users\00yoshi\Downloads\GoingBeyond1_Tutorial_Sample.zip 2014-01-03 22:44 - 2014-01-03 22:44 - 00193521 _____ C:\Users\00yoshi\Downloads\einfuehrung(1).zip 2014-01-03 22:24 - 2014-01-03 22:24 - 01358498 _____ C:\Users\00yoshi\Downloads\3DModel Source(1).zip 2014-01-03 22:08 - 2014-01-03 22:08 - 01358498 _____ C:\Users\00yoshi\Downloads\3DModel Source.zip 2014-01-03 18:54 - 2014-01-03 18:54 - 00569372 _____ (DotExE ) C:\Users\00yoshi\Downloads\MoonTools.exe 2014-01-02 17:03 - 2010-08-09 20:14 - 00089600 _____ (SoftwareDesign-Solution) C:\Users\00yoshi\Desktop\TextEffectsLib.dll 2014-01-02 17:02 - 2014-01-02 17:02 - 00043731 _____ C:\Users\00yoshi\Downloads\TextEffectsLib_1.1.0.0.zip 2014-01-02 16:59 - 2014-01-02 16:59 - 00117423 _____ C:\Users\00yoshi\Downloads\TextEffectsLibDemo_1.1.0.0.zip 2014-01-02 16:09 - 2014-01-02 16:09 - 00018432 _____ (MT Soft) C:\Users\00yoshi\Desktop\ZipLib.dll 2014-01-02 15:15 - 2014-01-02 15:16 - 36293880 _____ (Dropbox, Inc.) C:\Users\00yoshi\Downloads\Dropbox 2.4.10(1).exe 2013-12-31 00:10 - 2013-12-31 00:12 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Start 2013-12-31 00:08 - 2013-12-31 00:08 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\nUpdate 2013-12-30 23:21 - 2013-12-30 23:22 - 36293880 _____ (Dropbox, Inc.) C:\Users\00yoshi\Downloads\Dropbox 2.4.10.exe 2013-12-30 23:17 - 2013-12-30 23:17 - 00369345 _____ C:\Users\00yoshi\Downloads\nUpdate.rar 2013-12-30 22:53 - 2013-12-30 22:54 - 33841433 _____ C:\Users\00yoshi\Downloads\Minecraft_Modpack_1.6.2.rar 2013-12-27 22:24 - 2013-12-27 22:24 - 00095068 _____ C:\Users\00yoshi\Desktop\Paintball.jar 2013-12-27 13:26 - 2013-12-27 13:26 - 01927709 _____ C:\Users\00yoshi\Downloads\samp03x_svr_R2_win32.zip 2013-12-27 12:47 - 2013-12-27 12:47 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer 2013-12-27 12:45 - 2013-12-27 12:46 - 12022145 _____ C:\Users\00yoshi\Downloads\sa-mp-0.3x-R1-2-install.exe 2013-12-22 17:50 - 2013-12-22 17:50 - 00017266 _____ C:\Users\00yoshi\Downloads\3DAnimation2(1).zip 2013-12-22 16:25 - 2013-12-22 16:25 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft2d extented 2013-12-21 23:32 - 2013-12-21 23:32 - 00073915 _____ C:\Users\00yoshi\Downloads\DirectX Tutorialserie 1 Device erstellen.zip 2013-12-21 22:54 - 2013-12-21 22:54 - 00004162 _____ C:\Users\00yoshi\Desktop\lol.txt 2013-12-21 12:45 - 2013-12-21 12:45 - 00025750 _____ C:\Users\00yoshi\Documents\Unbenannt.camproj 2013-12-20 22:42 - 2013-12-20 22:42 - 00159671 _____ C:\Users\00yoshi\Downloads\Thaumcraft-Extras-0.3.2a (1).zip 2013-12-20 20:34 - 2013-12-20 20:34 - 00072476 _____ C:\Users\00yoshi\Downloads\Forge_NBTEditv1.6.4.0.zip 2013-12-20 20:07 - 2013-12-20 20:07 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-12-20 20:07 - 2013-12-20 20:07 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-12-20 19:50 - 2013-12-20 19:51 - 30694824 _____ (Oracle Corporation) C:\Users\00yoshi\Downloads\jre-7u45-windows-x64.exe 2013-12-20 19:49 - 2013-12-20 19:50 - 00042746 _____ C:\Users\00yoshi\Downloads\Fix Java File Types.zip 2013-12-20 18:10 - 2013-12-20 18:10 - 15200059 _____ C:\Users\00yoshi\Downloads\Tropicraft v3.0.5(1).zip 2013-12-20 18:05 - 2013-12-20 18:06 - 15200059 _____ C:\Users\00yoshi\Downloads\Tropicraft v3.0.5.zip 2013-12-20 15:52 - 2014-01-09 21:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-20 14:14 - 2013-12-20 14:14 - 00716592 _____ () C:\Users\00yoshi\Downloads\GitHubSetup.exe 2013-12-19 08:21 - 2014-01-04 00:21 - 00000075 _____ C:\Users\00yoshi\AppData\Roaming\WB.CFG 2013-12-17 19:49 - 2013-12-17 19:49 - 02231448 _____ C:\Users\00yoshi\Downloads\minecraftforge-installer-1.6.4-9.11.1.916.jar 2013-12-17 19:48 - 2013-12-17 19:50 - 00037357 _____ C:\Users\00yoshi\Downloads\Somnia-Pre2b.jar 2013-12-15 17:02 - 2013-12-15 17:02 - 02205757 _____ C:\Users\00yoshi\Downloads\Railcraft_1.5.1-7.0.0.0.jar 2013-12-15 17:02 - 2013-12-15 17:02 - 00014347 _____ C:\Users\00yoshi\Downloads\util^iChunUtil1.0.0.zip 2013-12-15 17:02 - 2013-12-15 17:02 - 00014347 _____ C:\Users\00yoshi\Downloads\util^iChunUtil1.0.0(1).zip 2013-12-14 22:04 - 2010-08-04 00:08 - 00015360 _____ (Vincent Casser / VCware) C:\Users\00yoshi\Desktop\FastGraphicsLib.dll 2013-12-14 21:50 - 2013-12-14 21:50 - 00005759 _____ C:\Users\00yoshi\Downloads\FastGraphicsLib.zip 2013-12-13 23:21 - 2013-12-13 23:21 - 00111351 _____ C:\Users\00yoshi\Downloads\ip pinger.rar 2013-12-13 22:16 - 2013-12-13 22:18 - 139921513 _____ C:\Users\00yoshi\Downloads\rockyou.txt 2013-12-13 22:11 - 2013-12-13 22:14 - 60498886 _____ C:\Users\00yoshi\Downloads\rockyou.txt.bz2 2013-12-13 22:11 - 2013-12-13 22:11 - 03149586 _____ C:\Users\00yoshi\Downloads\cain.txt 2013-12-13 22:10 - 2013-12-13 22:10 - 01069968 _____ C:\Users\00yoshi\Downloads\cain.txt.bz2 2013-12-13 18:00 - 2013-12-13 18:05 - 00383816 _____ C:\Users\00yoshi\Downloads\CoreTemp64.zip 2013-12-13 17:50 - 2013-12-13 17:52 - 46946304 _____ C:\Users\00yoshi\Downloads\Elektro-Training.exe 2013-12-13 17:19 - 2013-12-13 17:19 - 00006691 _____ C:\Users\00yoshi\Downloads\ZipLib.zip 2013-12-13 12:57 - 2013-12-13 18:12 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Minecraft_texturepack_edi 2013-12-13 11:38 - 2013-12-13 11:38 - 00002750 _____ C:\Users\00yoshi\Unigine_Valley_Benchmark_1.0_20131213_1138.html ==================== One Month Modified Files and Folders ======= 2014-01-12 13:24 - 2014-01-10 14:19 - 00034834 _____ C:\Users\00yoshi\Downloads\FRST.txt 2014-01-12 13:23 - 2014-01-12 13:23 - 00000000 ____D C:\Users\00yoshi\Downloads\FRST-OlderVersion 2014-01-12 13:23 - 2014-01-10 14:19 - 00000000 ____D C:\FRST 2014-01-12 13:23 - 2014-01-10 14:18 - 02075136 _____ (Farbar) C:\Users\00yoshi\Downloads\FRST64.exe 2014-01-12 13:21 - 2013-07-28 17:40 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\Skype 2014-01-12 13:19 - 2014-01-12 13:19 - 00001186 _____ C:\Users\00yoshi\Desktop\JRT.txt 2014-01-12 13:16 - 2009-07-14 05:45 - 00017152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-12 13:16 - 2009-07-14 05:45 - 00017152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-12 13:13 - 2014-01-12 13:13 - 01037068 _____ (Thisisu) C:\Users\00yoshi\Downloads\JRT(1).exe 2014-01-12 13:12 - 2013-01-29 18:38 - 00000000 ___RD C:\Users\00yoshi\Dropbox 2014-01-12 13:12 - 2013-01-29 18:37 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\Dropbox 2014-01-12 13:12 - 2012-01-14 17:57 - 01098477 _____ C:\Windows\WindowsUpdate.log 2014-01-12 13:09 - 2014-01-10 18:36 - 00000392 _____ C:\Windows\setupact.log 2014-01-12 13:09 - 2012-01-14 18:00 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-12 13:09 - 2011-09-05 23:24 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-12 13:09 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-12 13:07 - 2014-01-08 16:15 - 00000000 ____D C:\AdwCleaner 2014-01-12 12:34 - 2012-05-18 07:14 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-12 12:29 - 2012-01-14 18:00 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-12 11:36 - 2014-01-12 11:36 - 01233962 _____ C:\Users\00yoshi\Desktop\adwcleaner.exe 2014-01-12 11:24 - 2014-01-12 11:23 - 19924817 _____ C:\Users\00yoshi\Downloads\craftbukkit-1.7.2-R0.3-20140106.202339-8.jar 2014-01-12 11:22 - 2012-01-25 17:27 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Adobe 2014-01-12 11:19 - 2013-10-09 11:48 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\.minecraft 2014-01-11 10:47 - 2014-01-11 10:45 - 00000000 ____D C:\ProgramData\SecTaskMan 2014-01-11 10:45 - 2014-01-11 10:45 - 02365840 _____ C:\Users\00yoshi\Downloads\SecurityTaskManager_Setup(1).exe 2014-01-11 10:45 - 2014-01-11 10:45 - 00000000 ____D C:\Program Files (x86)\Security Task Manager 2014-01-11 09:51 - 2013-11-10 20:10 - 00000000 ____D C:\Users\00yoshi\Desktop\atlauncher 2014-01-10 18:40 - 2012-06-22 13:07 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Apps\2.0 2014-01-10 18:37 - 2014-01-10 18:36 - 00473584 _____ C:\Windows\Minidump\011014-21730-01.dmp 2014-01-10 18:36 - 2014-01-10 18:36 - 663286171 _____ C:\Windows\MEMORY.DMP 2014-01-10 18:36 - 2014-01-10 18:36 - 00000000 ____D C:\Windows\Minidump 2014-01-10 18:36 - 2014-01-10 18:36 - 00000000 _____ C:\Windows\setuperr.log 2014-01-10 18:36 - 2010-11-21 04:47 - 00438620 _____ C:\Windows\PFRO.log 2014-01-10 17:19 - 2013-11-01 16:18 - 00000000 ____D C:\Users\00yoshi\Desktop\vbdateien 2014-01-10 17:19 - 2013-10-19 12:49 - 00000000 ____D C:\Users\00yoshi\Desktop\Unbenutzt 2014-01-10 17:18 - 2014-01-10 17:18 - 00000000 ____D C:\Users\00yoshi\Desktop\log's 2014-01-10 17:17 - 2014-01-10 17:17 - 00011254 _____ C:\Users\00yoshi\Downloads\Neuer ZIP-komprimierter Ordner.zip 2014-01-10 17:17 - 2014-01-10 17:15 - 00011254 _____ C:\Users\00yoshi\Desktop\Neuer ZIP-komprimierter Ordner.zip 2014-01-10 17:16 - 2014-01-10 17:05 - 00141705 _____ C:\ComboFix.txt 2014-01-10 17:06 - 2014-01-10 16:40 - 00000000 ____D C:\ComboFix 2014-01-10 17:05 - 2014-01-10 16:40 - 00000000 ____D C:\Qoobox 2014-01-10 17:05 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2014-01-10 17:01 - 2014-01-10 16:39 - 00000000 ____D C:\Windows\erdnt 2014-01-10 17:00 - 2012-01-14 18:05 - 00000000 ____D C:\Users\00yoshi 2014-01-10 17:00 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2014-01-10 16:19 - 2014-01-10 16:18 - 05162489 ____R (Swearware) C:\Users\00yoshi\Desktop\ComboFix.exe 2014-01-10 14:22 - 2014-01-10 14:22 - 00000474 _____ C:\Users\00yoshi\Downloads\defogger_disable.log 2014-01-10 14:22 - 2014-01-10 14:22 - 00000000 _____ C:\Users\00yoshi\defogger_reenable 2014-01-10 14:22 - 2014-01-10 14:20 - 00035575 _____ C:\Users\00yoshi\Downloads\Addition.txt 2014-01-10 14:19 - 2014-01-10 14:19 - 00050477 _____ C:\Users\00yoshi\Downloads\Defogger.exe 2014-01-10 13:54 - 2013-07-01 10:47 - 00003122 _____ C:\Windows\System32\Tasks\YourFile DownloaderUpdate 2014-01-10 13:52 - 2014-01-10 13:52 - 00550371 _____ C:\Users\00yoshi\Downloads\Autoruns.zip 2014-01-10 13:44 - 2012-01-28 11:17 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Paint.NET 2014-01-09 22:32 - 2014-01-09 22:32 - 00032512 _____ C:\Windows\system32\Drivers\hitmanpro37.sys 2014-01-09 22:32 - 2012-04-26 14:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-09 22:31 - 2014-01-09 21:55 - 00000000 ____D C:\ProgramData\HitmanPro 2014-01-09 22:23 - 2014-01-09 22:23 - 00012092 _____ C:\Windows\system32\.crusader 2014-01-09 21:56 - 2014-01-09 21:56 - 00001909 _____ C:\Users\Public\Desktop\HitmanPro.lnk 2014-01-09 21:56 - 2014-01-09 21:56 - 00000000 ____D C:\Program Files\HitmanPro 2014-01-09 21:55 - 2014-01-09 21:55 - 10264904 _____ (SurfRight B.V.) C:\Users\00yoshi\Downloads\HitmanPro_x64.exe 2014-01-09 21:45 - 2014-01-09 21:45 - 01037068 _____ (Thisisu) C:\Users\00yoshi\Downloads\JRT.exe 2014-01-09 21:45 - 2014-01-09 21:45 - 00000000 ____D C:\Windows\ERUNT 2014-01-09 21:37 - 2014-01-09 21:37 - 00001054 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-09 21:37 - 2014-01-09 21:37 - 00000000 ____D C:\Program Files (x86)\MF 2014-01-09 21:37 - 2013-12-20 15:52 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2014-01-09 21:30 - 2014-01-09 21:30 - 23867560 _____ (Mozilla) C:\Users\00yoshi\Downloads\Firefox Setup 26.0.exe 2014-01-08 16:15 - 2014-01-08 16:15 - 01233962 _____ C:\Users\00yoshi\Downloads\adwcleaner_3.016.exe 2014-01-07 20:17 - 2014-01-05 15:24 - 00000000 ____D C:\ProgramData\InstallMate 2014-01-07 16:50 - 2012-01-14 18:00 - 00000000 ____D C:\Program Files\Google 2014-01-07 16:50 - 2012-01-14 18:00 - 00000000 ____D C:\Program Files (x86)\Google 2014-01-06 19:48 - 2012-01-14 18:55 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Google 2014-01-05 15:31 - 2014-01-05 15:31 - 00000000 ____D C:\ProgramData\SoftWarehouse 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\HomeGroupUser$ 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast\AppData\Local\Torch 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Gast 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\Torch 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\Comodo 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\Users\Administrator 2014-01-05 15:24 - 2014-01-05 15:24 - 00000000 ____D C:\ProgramData\504c2cf8db11ac3b 2014-01-04 14:56 - 2014-01-04 14:56 - 00018589 _____ C:\Users\00yoshi\Downloads\169_EW-Biomes.rar 2014-01-04 14:55 - 2014-01-04 14:55 - 08037055 _____ C:\Users\00yoshi\Downloads\Millenaire5.1.11.zip 2014-01-04 00:21 - 2013-12-19 08:21 - 00000075 _____ C:\Users\00yoshi\AppData\Roaming\WB.CFG 2014-01-04 00:04 - 2012-05-31 19:18 - 00000000 ____D C:\Users\00yoshi\Lange Nacht Der Wissenschaften 01-Dateien 2014-01-03 22:50 - 2014-01-03 22:50 - 00790625 _____ C:\Users\00yoshi\Downloads\GoingBeyond1_Tutorial_Sample.zip 2014-01-03 22:44 - 2014-01-03 22:44 - 00193521 _____ C:\Users\00yoshi\Downloads\einfuehrung(1).zip 2014-01-03 22:24 - 2014-01-03 22:24 - 01358498 _____ C:\Users\00yoshi\Downloads\3DModel Source(1).zip 2014-01-03 22:08 - 2014-01-03 22:08 - 01358498 _____ C:\Users\00yoshi\Downloads\3DModel Source.zip 2014-01-03 18:54 - 2014-01-03 18:54 - 00569372 _____ (DotExE ) C:\Users\00yoshi\Downloads\MoonTools.exe 2014-01-02 17:02 - 2014-01-02 17:02 - 00043731 _____ C:\Users\00yoshi\Downloads\TextEffectsLib_1.1.0.0.zip 2014-01-02 16:59 - 2014-01-02 16:59 - 00117423 _____ C:\Users\00yoshi\Downloads\TextEffectsLibDemo_1.1.0.0.zip 2014-01-02 16:09 - 2014-01-02 16:09 - 00018432 _____ (MT Soft) C:\Users\00yoshi\Desktop\ZipLib.dll 2014-01-02 16:01 - 2012-11-30 18:17 - 00000000 ____D C:\Users\00yoshi\Documents\Visual Studio 2010 2014-01-02 15:16 - 2014-01-02 15:15 - 36293880 _____ (Dropbox, Inc.) C:\Users\00yoshi\Downloads\Dropbox 2.4.10(1).exe 2014-01-02 00:17 - 2012-11-22 15:06 - 00015872 _____ C:\Users\00yoshi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-12-31 00:12 - 2013-12-31 00:10 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Start 2013-12-31 00:08 - 2013-12-31 00:08 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\nUpdate 2013-12-30 23:50 - 2012-12-28 13:39 - 00000000 ____D C:\Users\00yoshi\Desktop\Der ganze Rest 2013-12-30 23:43 - 2013-01-29 18:37 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-12-30 23:43 - 2012-01-14 18:05 - 00000000 ___RD C:\Users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-12-30 23:22 - 2013-12-30 23:21 - 36293880 _____ (Dropbox, Inc.) C:\Users\00yoshi\Downloads\Dropbox 2.4.10.exe 2013-12-30 23:17 - 2013-12-30 23:17 - 00369345 _____ C:\Users\00yoshi\Downloads\nUpdate.rar 2013-12-30 22:54 - 2013-12-30 22:53 - 33841433 _____ C:\Users\00yoshi\Downloads\Minecraft_Modpack_1.6.2.rar 2013-12-27 22:24 - 2013-12-27 22:24 - 00095068 _____ C:\Users\00yoshi\Desktop\Paintball.jar 2013-12-27 13:26 - 2013-12-27 13:26 - 01927709 _____ C:\Users\00yoshi\Downloads\samp03x_svr_R2_win32.zip 2013-12-27 12:47 - 2013-12-27 12:47 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer 2013-12-27 12:47 - 2012-05-20 19:55 - 00000000 ____D C:\Users\00yoshi\Documents\GTA San Andreas User Files 2013-12-27 12:46 - 2013-12-27 12:45 - 12022145 _____ C:\Users\00yoshi\Downloads\sa-mp-0.3x-R1-2-install.exe 2013-12-26 01:29 - 2013-04-13 21:41 - 00000000 ____D C:\Users\00yoshi\AppData\Local\CrashDumps 2013-12-26 00:12 - 2013-04-13 23:05 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\vlc 2013-12-23 11:20 - 2013-12-07 12:06 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Minecraft2d_extented 2013-12-22 17:50 - 2013-12-22 17:50 - 00017266 _____ C:\Users\00yoshi\Downloads\3DAnimation2(1).zip 2013-12-22 16:25 - 2013-12-22 16:25 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft2d extented 2013-12-22 16:25 - 2012-06-22 13:07 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Deployment 2013-12-21 23:32 - 2013-12-21 23:32 - 00073915 _____ C:\Users\00yoshi\Downloads\DirectX Tutorialserie 1 Device erstellen.zip 2013-12-21 22:54 - 2013-12-21 22:54 - 00004162 _____ C:\Users\00yoshi\Desktop\lol.txt 2013-12-21 12:45 - 2013-12-21 12:45 - 00025750 _____ C:\Users\00yoshi\Documents\Unbenannt.camproj 2013-12-21 12:11 - 2011-05-16 15:04 - 00766056 _____ C:\Windows\system32\perfh007.dat 2013-12-21 12:11 - 2011-05-16 15:04 - 00175028 _____ C:\Windows\system32\perfc007.dat 2013-12-21 12:11 - 2009-07-14 06:13 - 01808962 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-20 22:42 - 2013-12-20 22:42 - 00159671 _____ C:\Users\00yoshi\Downloads\Thaumcraft-Extras-0.3.2a (1).zip 2013-12-20 20:34 - 2013-12-20 20:34 - 00072476 _____ C:\Users\00yoshi\Downloads\Forge_NBTEditv1.6.4.0.zip 2013-12-20 20:16 - 2013-11-16 12:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox.bak 2013-12-20 20:07 - 2013-12-20 20:07 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-12-20 20:07 - 2013-12-20 20:07 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-12-20 20:07 - 2013-10-07 00:03 - 00000000 ____D C:\ProgramData\Oracle 2013-12-20 20:07 - 2012-04-03 21:15 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-12-20 20:07 - 2012-04-03 21:15 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-12-20 20:07 - 2012-04-03 21:14 - 00000000 ____D C:\Program Files\Java 2013-12-20 19:51 - 2013-12-20 19:50 - 30694824 _____ (Oracle Corporation) C:\Users\00yoshi\Downloads\jre-7u45-windows-x64.exe 2013-12-20 19:50 - 2013-12-20 19:49 - 00042746 _____ C:\Users\00yoshi\Downloads\Fix Java File Types.zip 2013-12-20 18:10 - 2013-12-20 18:10 - 15200059 _____ C:\Users\00yoshi\Downloads\Tropicraft v3.0.5(1).zip 2013-12-20 18:06 - 2013-12-20 18:05 - 15200059 _____ C:\Users\00yoshi\Downloads\Tropicraft v3.0.5.zip 2013-12-20 14:14 - 2013-12-20 14:14 - 00716592 _____ () C:\Users\00yoshi\Downloads\GitHubSetup.exe 2013-12-19 09:13 - 2013-04-01 18:25 - 00000000 ____D C:\Users\00yoshi\AppData\Roaming\FTB modpack 2013-12-17 19:50 - 2013-12-17 19:48 - 00037357 _____ C:\Users\00yoshi\Downloads\Somnia-Pre2b.jar 2013-12-17 19:49 - 2013-12-17 19:49 - 02231448 _____ C:\Users\00yoshi\Downloads\minecraftforge-installer-1.6.4-9.11.1.916.jar 2013-12-17 17:00 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-15 17:02 - 2013-12-15 17:02 - 02205757 _____ C:\Users\00yoshi\Downloads\Railcraft_1.5.1-7.0.0.0.jar 2013-12-15 17:02 - 2013-12-15 17:02 - 00014347 _____ C:\Users\00yoshi\Downloads\util^iChunUtil1.0.0.zip 2013-12-15 17:02 - 2013-12-15 17:02 - 00014347 _____ C:\Users\00yoshi\Downloads\util^iChunUtil1.0.0(1).zip 2013-12-14 21:50 - 2013-12-14 21:50 - 00005759 _____ C:\Users\00yoshi\Downloads\FastGraphicsLib.zip 2013-12-14 15:56 - 2013-07-25 15:48 - 00000000 ____D C:\Windows\system32\MRT 2013-12-14 15:53 - 2011-07-18 21:31 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-14 13:27 - 2013-12-08 00:27 - 00000680 __RSH C:\Users\00yoshi\ntuser.pol 2013-12-13 23:21 - 2013-12-13 23:21 - 00111351 _____ C:\Users\00yoshi\Downloads\ip pinger.rar 2013-12-13 22:18 - 2013-12-13 22:16 - 139921513 _____ C:\Users\00yoshi\Downloads\rockyou.txt 2013-12-13 22:14 - 2013-12-13 22:11 - 60498886 _____ C:\Users\00yoshi\Downloads\rockyou.txt.bz2 2013-12-13 22:11 - 2013-12-13 22:11 - 03149586 _____ C:\Users\00yoshi\Downloads\cain.txt 2013-12-13 22:10 - 2013-12-13 22:10 - 01069968 _____ C:\Users\00yoshi\Downloads\cain.txt.bz2 2013-12-13 20:59 - 2013-11-10 15:40 - 00000000 ____D C:\ProgramData\Package Cache 2013-12-13 20:59 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\MSBuild 2013-12-13 20:58 - 2013-11-10 15:51 - 00000000 ____D C:\Windows\system32\1031 2013-12-13 20:58 - 2013-11-10 15:51 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 12.0 2013-12-13 20:58 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-12-13 20:57 - 2012-11-30 17:49 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs 2013-12-13 20:54 - 2012-11-30 17:52 - 00000000 ____D C:\Windows\system32\1033 2013-12-13 20:51 - 2013-11-10 15:54 - 00000000 ____D C:\Windows\SysWOW64\1031 2013-12-13 20:39 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\MSBuild 2013-12-13 20:27 - 2012-01-14 18:00 - 00094208 _____ C:\Users\Default\AppData\Local\GDIPFONTCACHEV1.DAT 2013-12-13 20:27 - 2012-01-14 18:00 - 00094208 _____ C:\Users\Default User\AppData\Local\GDIPFONTCACHEV1.DAT 2013-12-13 18:12 - 2013-12-13 12:57 - 00000000 ____D C:\Users\00yoshi\AppData\Local\Minecraft_texturepack_edi 2013-12-13 18:05 - 2013-12-13 18:00 - 00383816 _____ C:\Users\00yoshi\Downloads\CoreTemp64.zip 2013-12-13 18:03 - 2013-12-11 09:00 - 01065984 _____ C:\Users\00yoshi\AppData\Local\file__0.localstorage 2013-12-13 17:52 - 2013-12-13 17:50 - 46946304 _____ C:\Users\00yoshi\Downloads\Elektro-Training.exe 2013-12-13 17:19 - 2013-12-13 17:19 - 00006691 _____ C:\Users\00yoshi\Downloads\ZipLib.zip 2013-12-13 11:38 - 2013-12-13 11:38 - 00002750 _____ C:\Users\00yoshi\Unigine_Valley_Benchmark_1.0_20131213_1138.html Some content of TEMP: ==================== C:\Users\00yoshi\AppData\Local\Temp\elodnno3.dll C:\Users\00yoshi\AppData\Local\Temp\Quarantine.exe C:\Users\00yoshi\AppData\Local\Temp\v3ytxki6.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== BCD ================================ Windows-Start-Manager --------------------- Bezeichner {bootmgr} device partition=\Device\HarddiskVolume1 description Windows Boot Manager locale de-DE inherit {globalsettings} default {current} resumeobject {81be9816-e38b-11e0-af49-99356d797b37} displayorder {current} toolsdisplayorder {memdiag} timeout 30 Windows-Startladeprogramm ------------------------- Bezeichner {current} device partition=C: path \Windows\system32\winload.exe description Windows 7 locale de-DE inherit {bootloadersettings} recoverysequence {81be9818-e38b-11e0-af49-99356d797b37} recoveryenabled Yes osdevice partition=C: systemroot \Windows resumeobject {81be9816-e38b-11e0-af49-99356d797b37} nx OptIn vga No quietboot No usefirmwarepcisettings No bootlog No sos No Windows-Startladeprogramm ------------------------- Bezeichner {81be9818-e38b-11e0-af49-99356d797b37} device ramdisk=[C:]\Recovery\81be9818-e38b-11e0-af49-99356d797b37\Winre.wim,{81be9819-e38b-11e0-af49-99356d797b37} path \windows\system32\winload.exe description Windows Recovery Environment inherit {bootloadersettings} osdevice ramdisk=[C:]\Recovery\81be9818-e38b-11e0-af49-99356d797b37\Winre.wim,{81be9819-e38b-11e0-af49-99356d797b37} systemroot \windows nx OptIn winpe Yes Wiederaufnahme aus dem Ruhezustand ---------------------------------- Bezeichner {81be9816-e38b-11e0-af49-99356d797b37} device partition=C: path \Windows\system32\winresume.exe description Windows Resume Application locale de-DE inherit {resumeloadersettings} filedevice partition=C: filepath \hiberfil.sys debugoptionenabled No Windows-Speichertestprogramm ---------------------------- Bezeichner {memdiag} device partition=\Device\HarddiskVolume1 path \boot\memtest.exe description Windows Memory Diagnostic locale de-DE inherit {globalsettings} badmemoryaccess Yes EMS-Einstellungen ----------------- Bezeichner {emssettings} bootems Yes Debuggereinstellungen --------------------- Bezeichner {dbgsettings} debugtype Serial debugport 1 baudrate 115200 RAM-Defekte ----------- Bezeichner {badmemory} Globale Einstellungen --------------------- Bezeichner {globalsettings} inherit {dbgsettings} {emssettings} {badmemory} Startladeprogramm-Einstellungen ------------------------------- Bezeichner {bootloadersettings} inherit {globalsettings} {hypervisorsettings} Hypervisoreinstellungen ------------------- Bezeichner {hypervisorsettings} hypervisordebugtype Serial hypervisordebugport 1 hypervisorbaudrate 115200 Einstellungen zur Ladeprogrammfortsetzung ----------------------------------------- Bezeichner {resumeloadersettings} inherit {globalsettings} Ger„teoptionen -------------- Bezeichner {81be9819-e38b-11e0-af49-99356d797b37} description Ramdisk Options ramdisksdidevice partition=C: ramdisksdipath \Recovery\81be9818-e38b-11e0-af49-99356d797b37\boot.sdi LastRegBack: 2014-01-01 22:01 ==================== End Of Log ============================ Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-01-2014 Ran by 00yoshi at 2014-01-12 13:24:45 Running from C:\Users\00yoshi\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0 - Igor Pavlov) Adobe AIR (x32 Version: 3.7.0.1860 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.7.0.1860 - Adobe Systems Incorporated) Hidden Adobe Download Assistant (x32 Version: 1.2.3 - Adobe Systems Incorporated) Adobe Download Assistant (x32 Version: 1.2.3 - Adobe Systems Incorporated) Hidden Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.152 - Adobe Systems Incorporated) Adobe Photoshop CS6 (x32 Version: 13.0 - Adobe Systems Incorporated) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (x32 Version: 12.0.4.144 - Adobe Systems, Inc.) AIDA64 Extreme v4.00 (x32 Version: 4.00 - FinalWire Ltd.) Alice-Installationsdateien entfernen (x32 Version: - ) AntiBrowserSpy (x32 Version: 4.0.110 - Abelssoft) Ashampoo Burning Studio (x32 Version: 10.0.10 - Ashampoo GmbH & Co. KG) Ashampoo Photo Commander (x32 Version: 9.2.0 - Ashampoo GmbH & Co. KG) Ashampoo Photo Optimizer (x32 Version: 4.0.0 - Ashampoo GmbH & Co. KG) Ashampoo Registry Cleaner v.1.0.0 (x32 Version: 1.0.0 - Ashampoo GmbH & Co. KG) Ashampoo Snap (x32 Version: 4.3.0 - Ashampoo GmbH & Co. KG) Asmedia ASM104x USB 3.0 Host Controller Driver (x32 Version: 1.12.5.0 - Asmedia Technology) Audacity 2.0.3 (x32 Version: 2.0.3 - Audacity Team) Bluetooth Stack for Windows by Toshiba (Version: v5.10.14 - ) Camtasia Studio 7 (x32 Version: 7.0.1 - TechSmith Corporation) Camtasia Studio 8 (x32 Version: 8.0.4.1060 - TechSmith Corporation) CCleaner (Version: 3.19 - Piriform) COMPUTERBILD Alles-Öffner (x32 Version: 1.0.8 - J3S) COMPUTERBILD Alles-Öffner (x32 Version: 1.0.8 - J3S) Hidden COMPUTERBILD-Abzockschutz (x32 Version: 1.0.42 - J3S) Corel Graphics - Windows Shell Extension (x32 Version: 15.2.0.686 - Corel Corporation) Corel Graphics - Windows Shell Extension (x32 Version: 15.2.686 - Corel Corporation) Hidden Corel Graphics - Windows Shell Extension 64 Bit (Version: 15.2.686 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Common (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Connect (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Custom Data (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - DE (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Draw (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - EN (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - ES (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Extra Content (x32 Version: - Corel Corporation) CorelDRAW Essentials X5 - Extra Content (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Filters (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - FR (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - IPM (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - IT (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - PHOTO-PAINT (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Redist (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Setup Files (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 - WT (x32 Version: 15.3 - Corel Corporation) Hidden CorelDRAW Essentials X5 (x32 Version: 15.2.0.686 - Corel Corporation) CorelDRAW Essentials X5 (x32 Version: 15.3 - Corel Corporation) Hidden Counter-Strike 1.6 (x32 Version: - ) Counter-Strike Xtreme V6 (x32 Version: - ) Craften Terminal 3.4.5011.37604 (x32 Version: 3.4.5011.37604 - Craften.de) Crazy Machines II - Gold (x32 Version: 1.03 - FAKT Software GmbH) CS16 Full v32.1 Non-Steam (x32 Version: - ) CyberLink LabelPrint (x32 Version: 2.5.3418 - CyberLink Corp.) CyberLink LabelPrint (x32 Version: 2.5.3418 - CyberLink Corp.) Hidden CyberLink MediaEspresso (x32 Version: 6.5.1817_38674 - CyberLink Corp.) CyberLink MediaEspresso (x32 Version: 6.5.1817_38674 - CyberLink Corp.) Hidden CyberLink Power2Go (x32 Version: 7.0.0.1327 - CyberLink Corp.) CyberLink Power2Go (x32 Version: 7.0.0.1327 - CyberLink Corp.) Hidden CyberLink PowerDVD Copy (x32 Version: 1.5.1306 - CyberLink Corp.) CyberLink PowerDVD Copy (x32 Version: 1.5.1306 - CyberLink Corp.) Hidden CyberLink PowerRecover (x32 Version: 5.5.4125 - CyberLink Corp.) CyberLink PowerRecover (x32 Version: 5.5.4125 - CyberLink Corp.) Hidden CyberLink YouPaint (x32 Version: 1.2.1928 - CyberLink Corp.) CyberLink YouPaint (x32 Version: 1.2.1928 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dropbox (HKCU Version: 2.4.10 - Dropbox, Inc.) Entity Framework Tools for Visual Studio 2013 (x32 Version: 12.0.20912.0 - Microsoft Corporation) Erforderliche Komponenten für SSDT (x32 Version: 11.1.3000.0 - Microsoft Corporation) EVEREST Home Edition v2.20 (x32 Version: 2.20 - Lavalys Inc) FileZilla Client 3.7.1 (x32 Version: 3.7.1 - FileZilla Project) foobar2000 v1.2.4 (x32 Version: 1.2.4 - Peter Pawlowski) Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Free Screen To Video V 2.0 (x32 Version: 2.0.0.0 - Koyote Soft) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotografii uslugi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Game Booster 3 (x32 Version: 3.4 - IObit) Google Chrome (x32 Version: 31.0.1650.63 - Google Inc.) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden Greenfish Icon Editor Pro 3.25 (x32 Version: - Greenfish Corporation) Haskell Platform 2013.2.0.0 (x32 Version: - Haskell.org) HitmanPro 3.7 (Version: 3.7.8.208 - SurfRight B.V.) Hotfix für Microsoft Visual Basic 2010 Express - DEU (KB2635973) (x32 Version: 1 - Microsoft Corporation) HP Foto- und Bildbearbeitung 2.0 - All-in-One (x32 Version: 1.10.0000 - Hewlett-Packard Company) Hidden HP Foto- und Bildbearbeitung 2.0 All-in-One Treiber (x32 Version: 1.10.0000 - Hewlett-Packard Company) Hidden HTML Tester (HKCU Version: 1.0.0.2 - HTML Tester) IIS 8.0 Express (Version: 8.0.1557 - Microsoft Corporation) IIS Express Application Compatibility Database for x64 (Version: - ) IIS Express Application Compatibility Database for x86 (Version: - ) Installer (HKCU Version: 1.0.0.0 - Installer) Intel(R) Management Engine Components (x32 Version: 7.0.0.1144 - Intel Corporation) Intel(R) Rapid Storage Technology (x32 Version: 10.5.0.1026 - Intel Corporation) Internetbrowser(testversion) (HKCU Version: 1.0.0.2 - 00yoshi) Java 7 Update 45 (64-bit) (Version: 7.0.450 - Oracle) Java 7 Update 45 (x32 Version: 7.0.450 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 45 (x32 Version: 6.0.450 - Oracle) Java(TM) 7 (64-bit) (Version: 7.0.0 - Oracle) Java(TM) SE Development Kit 6 Update 45 (x32 Version: 1.6.0.450 - Oracle) JavaFX 2.1.0 (64-bit) (Version: 2.1.0 - Oracle Corporation) JavaFX 2.1.0 SDK (64-bit) (Version: 2.1.0 - Oracle Corporation) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden K-Lite Codec Pack 7.0.0 (Standard) (x32 Version: 7.0.0 - ) L&H TTS3000 Deutsch (x32 Version: - ) League of Legends (x32 Version: 1.02.0000 - Riot Games) League of Legends (x32 Version: 1.3 - Riot Games) LogMeIn Hamachi (x32 Version: 2.1.0.166 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.1.0.166 - LogMeIn, Inc.) Hidden Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation) Media converter (x32 Version: - ) MediaConverter 1.3.2 (x32 Version: 1.3.2 - SoMud) MediaFire Express (x32 Version: 0.15.4.4888 - MediaFire) Medion Home Cinema (x32 Version: 8.0.2926 - CyberLink Corp.) Medion Home Cinema (x32 Version: 8.0.2926 - CyberLink Corp.) Hidden Microsoft .NET Framework 4 Multi-Targeting Pack (x32 Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4.5 Multi-Targeting Pack (x32 Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK - DEU Lang Pack (x32 Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK (x32 Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (x32 Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (Deutsch) (x32 Version: 4.5.51641 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (x32 Version: 4.5.51641 - Microsoft Corporation) Microsoft Antimalware Service DE-DE Language Pack (Version: 3.0.8402.2 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (x32 Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Exchange Web Services Managed API 2.0 (x32 Version: 15.0.516.14 - Microsoft Corporation) Hidden Microsoft Flight Simulator 2002 (x32 Version: - ) Microsoft Help Viewer 1.0 Language Pack - DEU (Version: 1.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.0 Language Pack - DEU (Version: 1.0.30319 - Microsoft Corporation) Hidden Microsoft Help Viewer 1.1 (Version: 1.1.40219 - Microsoft Corporation) Microsoft Help Viewer 1.1 (Version: 1.1.40219 - Microsoft Corporation) Hidden Microsoft Help Viewer 1.1 Language Pack - DEU (Version: 1.1.40219 - Microsoft Corporation) Microsoft Help Viewer 1.1 Language Pack - DEU (Version: 1.1.40219 - Microsoft Corporation) Hidden Microsoft Help Viewer 2.1 (x32 Version: 2.1.21005 - Microsoft Corporation) Microsoft Help Viewer 2.1 (x32 Version: 2.1.21005 - Microsoft Corporation) Hidden Microsoft Help Viewer 2.1 Sprachpaket - DEU (x32 Version: 2.1.21005 - Microsoft Corporation) Microsoft Help Viewer 2.1 Sprachpaket - DEU (x32 Version: 2.1.21005 - Microsoft Corporation) Hidden Microsoft Identity Extensions (Version: 2.0.1459.0 - Microsoft Corporation) Hidden Microsoft Office 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Excel Viewer (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft PowerPoint Viewer (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Security Client (Version: 4.4.0304.0 - Microsoft Corporation) Hidden Microsoft Security Client DE-DE Language Pack (Version: 2.1.1116.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (Version: 4.4.304.0 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Silverlight 5 SDK - DEU (x32 Version: 5.0.61118.0 - Microsoft Corporation) Microsoft SkyDrive (HKCU Version: 16.4.6010.0727 - Microsoft Corporation) Microsoft Small Basic v0.6 (x32 Version: 0.6 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2008 (x32 Version: - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Browser (x32 Version: 10.3.5500.0 - Microsoft Corporation) Microsoft SQL Server 2008 Common Files (x32 Version: 10.3.5500.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Database Engine Services (x32 Version: 10.3.5500.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Database Engine Shared (x32 Version: 10.3.5500.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Native Client (Version: 10.3.5500.0 - Microsoft Corporation) Microsoft SQL Server 2008 R2 Management Objects (x32 Version: 10.50.1750.9 - Microsoft Corporation) Microsoft SQL Server 2008 RsFx Driver (x32 Version: 10.3.5500.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Setup Support Files (x32 Version: 10.3.5500.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (x32 Version: 11.1.2902.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (x64) (Version: 11.1.2902.0 - Microsoft Corporation) Microsoft SQL Server 2012 Express LocalDB (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (x32 Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (x64) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL ScriptDom (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 T-SQL-Sprachdienst (x32 Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP1 Design Tools English (x32 Version: 3.5.5692.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP1 English (x32 Version: 3.5.5692.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 DEU (x32 Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 x64 DEU (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 x64 DEU (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft SQL Server Data Tools - DEU (12.0.30919.1) (x32 Version: 12.0.30919.1 - Microsoft Corporation) Microsoft SQL Server Data Tools Build Utilities - DEU (12.0.30919.1) (x32 Version: 12.0.30919.1 - Microsoft Corporation) Microsoft SQL Server System CLR Types (x32 Version: 10.50.1750.9 - Microsoft Corporation) Microsoft SQL Server System CLR Types (x64) (Version: 10.50.1600.1 - Microsoft Corporation) Microsoft SQL Server VSS Writer (Version: 10.3.5500.0 - Microsoft Corporation) Microsoft Visual Basic 2010 Express - DEU (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Basic 2010 Express - DEU (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden Microsoft Visual C++ Compilers 2010 Standard - enu - x86 (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (x32 Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU (Version: - Microsoft Corporation) Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU (Version: 9.0.30729 - Microsoft Corporation) Hidden Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU Service Pack 1 (KB945140) (x32 Version: 1 - Microsoft Corporation) Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Express Prerequisites x64 - DEU (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Service Pack 1 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Service Pack 1 (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.40820 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.40825 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU (Version: 10.0.40820 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (Version: 10.0.40820 - Microsoft Corporation) Microsoft Web Deploy 3.5 (Version: 3.1237.1762 - Microsoft Corporation) Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu (Version: 3.5.30729 - Microsoft Corporation) Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32 (Version: 6.1.5295.17011 - Microsoft Corporation) Microsoft XNA Framework Redistributable 3.0 (x32 Version: 3.0.11010.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (x32 Version: 4.0.20823.0 - Microsoft Corporation) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft-System-CLR-Typen für SQL Server 2012 (x32 Version: 11.1.3366.16 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2012 (x64) (Version: 11.1.3366.16 - Microsoft Corporation) Minecraft Editor 64 bits (Version: 1.8.0 - Axialmedia) Minecraft Recipe Creator (HKCU Version: 1.0.0.6 - Christopher Everitt) Minecraft Texturepack Editor (x32 Version: - ) Minecraft2d extented (HKCU Version: 1.0.0.0 - Minecraft2d extented) MinecraftAlpha (x32 Version: - ) MiniTool Partition Wizard Home Edition 7.1 (x32 Version: - MiniTool Solution Ltd.) MODINSTALLER (HKCU Version: 1.0.0.0 - Technikminer) Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden myMugle (x32 Version: 3.0.0.0 - Computer Business Solutions) Notepad++ (x32 Version: 6.1.3 - ) NVIDIA 3D Vision Treiber 331.65 (Version: 331.65 - NVIDIA Corporation) NVIDIA Grafiktreiber 331.65 (Version: 331.65 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.18.0 (Version: 1.3.18.0 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.11.0621 - NVIDIA Corporation) Hidden NVIDIA PhysX System Software 9.11.0621 (Version: 9.11.0621 - NVIDIA Corporation) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3165 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 331.65 (Version: 331.65 - NVIDIA Corporation) Hidden NVIDIA Update 1.15.2 (Version: 1.15.2 - NVIDIA Corporation) NVIDIA Update Components (Version: 1.15.2 - NVIDIA Corporation) Hidden Open Freely (Version: 1.0 - Download Freely, LLC) Open XML SDK 2.5 for Microsoft Office (x32 Version: 2.5.5631 - Microsoft Corporation) Hidden Paint.NET v3.5.11 (Version: 3.61.0 - dotPDN LLC) Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.5.1 (Deutsch) (x32 Version: 4.5.50932 - Microsoft Corporation) PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden PlayReady PC Runtime amd64 (Version: 1.3.0 - Microsoft Corporation) Poczta uslugi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Postal 2 STP - Free Multiplayer Edition (x32 Version: - ) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek High Definition Audio Driver (x32 Version: 6.0.1.6368 - Realtek Semiconductor Corp.) Secunia PSI (3.0.0.4001) (x32 Version: 3.0.0.4001 - Secunia) Security Task Manager 1.8g (x32 Version: 1.8g - Neuber Software) server auto ip (HKCU Version: 1.0.0.2 - server auto ip) Service Pack 3 für SQL Server 2008 (KB2546951) (x32 Version: 10.3.5500.0 - Microsoft Corporation) SharePoint Client Components (Version: 15.0.4481.1505 - Microsoft Corporation) Hidden SharpDX (x32 Version: 2.5.0 - SharpDX) SigmaTel MSCN Audio Player (x32 Version: - ) Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.) SmartFTP Client (Version: 4.1.1320.0 - SmartSoft Ltd.) Spelling Dictionaries Support For Adobe Reader X (x32 Version: 10.0.0 - Adobe Systems Incorporated) Spiel2 (HKCU Version: 1.0.0.0 - Spiel2) Sprechprogramm (HKCU Version: 1.0.0.0 - Sprechprogramm) Sql Server Customer Experience Improvement Program (x32 Version: 10.3.5500.0 - Microsoft Corporation) Hidden Start (HKCU Version: 1.0.0.1 - Start) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden TeamSpeak 3 Client (Version: 3.0.11.1 - TeamSpeak Systems GmbH) TeamViewer 9 (x32 Version: 9.0.24482 - TeamViewer) Techne (HKCU Version: 1.3.0.15 - ZeuX and r4wk) TmNationsForever (x32 Version: - Nadeo) TmSunriseDemoMag 1.4.5 (x32 Version: - Nadeo) Ultimate Browser (HKCU Version: 1.0.0.0 - Ultimate Browser) Unigine Valley Benchmark version 1.0 (x32 Version: 1.0 - Unigine Corp.) Unity Web Player (HKCU Version: - Unity Technologies ApS) Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU (x32 Version: 4.0.8080.0 - Microsoft Corporation) VLC media player 2.1.0 (x32 Version: 2.1.0 - VideoLAN) WCF RIA Services V1.0 SP2 (x32 Version: 4.1.62812.0 - Microsoft Corporation) Websiteclicker (HKCU Version: 1.0.0.0 - Websiteclicker) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotograf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven sähköposti (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden WinRAR 4.01 (32-Bit) (x32 Version: 4.01.0 - win.rar GmbH) WorldPainter 1.2.5 (Version: 1.2.5 - pepsoft.org) S?????? f?t???af??? t?? Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ==================== Restore Points ========================= 28-12-2013 14:58:55 Windows Update 01-01-2014 11:47:47 Windows Update 04-01-2014 19:07:54 Windows Update 08-01-2014 08:15:42 Microsoft SQL Server 2012 Command Line Utilities wurde entfernt. 08-01-2014 19:44:53 Windows Update 12-01-2014 10:25:19 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2014-01-10 17:00 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {31F1DB6D-AB3B-4D6E-B0E5-2C8500B361B4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-14] (Google Inc.) Task: {421201ED-2AB8-46F7-9D54-8705CD4CB5B8} - \Dealply No Task File Task: {4C61322B-F811-4F12-AB4E-62E62078723E} - System32\Tasks\AdobeAAMUpdater-1.0-00yoshisPC-00yoshi => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-09-20] (Adobe Systems Incorporated) Task: {88A0DEF9-9A59-44E3-8A87-F1CFF07322D7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-07] (Adobe Systems Incorporated) Task: {91D73C45-2EDB-4192-A266-0FB73C3B64AF} - System32\Tasks\YourFile DownloaderUpdate => C:\Program Files (x86)\YourFileDownloader\YourFileUpdater.exe <==== ATTENTION Task: {B7282210-9ABB-4F65-8FFF-91654F170006} - System32\Tasks\PCMeter\Startup => C:\Users\00yoshi\AppData\Local\Temp\Rar$EX26.952\PCMeter\PCMeterV0.3.exe <==== ATTENTION Task: {C2D7B5BC-EEBC-4306-99BC-BB4FE30A143E} - System32\Tasks\Game_Booster_AutoUpdate => C:\Program Files (x86)\IObit\Game Booster 3\AutoUpdate.exe [2013-06-24] () Task: {D88B83B1-49FB-49B8-9F83-3F549C74E636} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-01-14] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-04-02 08:05 - 2012-08-14 15:19 - 07027664 _____ () C:\Program Files (x86)\AntiBrowserSpy\Commons.dll 2013-04-02 08:05 - 2012-08-14 15:19 - 00177616 _____ () C:\Program Files (x86)\AntiBrowserSpy\AbBrowserLibs.dll 2013-04-02 08:05 - 2012-08-14 15:19 - 00028112 _____ () C:\Program Files (x86)\AntiBrowserSpy\VersionInfo.dll 2013-04-02 08:05 - 2012-08-14 15:19 - 00012752 _____ () C:\Program Files (x86)\AntiBrowserSpy\AbProcessManager.dll 2010-01-02 15:42 - 2010-01-02 15:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2013-10-27 18:11 - 2013-10-27 18:11 - 00012520 _____ () C:\Users\00yoshi\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\CoreTempReader.dll 2013-10-27 18:11 - 2013-10-27 18:11 - 00015080 _____ () C:\Users\00yoshi\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\GetCoreTempInfoNET.dll 2013-10-27 18:11 - 2013-10-27 18:11 - 00014056 _____ () C:\Users\00yoshi\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\SystemInfo.dll 2010-08-03 23:39 - 2010-08-03 23:39 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2010-08-03 23:39 - 2010-08-03 23:39 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2013-08-23 20:01 - 2013-08-23 20:01 - 25100288 _____ () C:\Users\00yoshi\AppData\Roaming\Dropbox\bin\libcef.dll 2013-08-15 07:46 - 2013-08-15 07:46 - 00172544 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\f7b8fe4da9013ce331d3363fe18a775d\IsdiInterop.ni.dll 2011-08-11 21:01 - 2011-04-30 08:28 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2014-01-09 21:37 - 2013-12-05 20:36 - 03559024 _____ () C:\Program Files (x86)\MF\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:430C6D84 AlternateDataStreams: C:\ProgramData\Temp:DFC5A2B2 ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== Faulty Device Manager Devices ============= Name: Hamachi Network Interface Description: Hamachi Network Interface Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: LogMeIn, Inc. Service: hamachi Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (01/12/2014 01:19:46 PM) (Source: CVHSVC) (User: ) Description: Nur zur Information. (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: Der Servername oder die Serveradresse konnte nicht verarbeitet werden. System errors: ============= Microsoft Office Sessions: ========================= Error: (01/12/2014 01:19:46 PM) (Source: CVHSVC)(User: ) Description: (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: Der Servername oder die Serveradresse konnte nicht verarbeitet werden. CodeIntegrity Errors: =================================== Date: 2014-01-10 17:00:03.782 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-10 17:00:03.720 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-10-27 18:16:34.988 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\00yoshi\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-10-27 18:16:34.942 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\00yoshi\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-10-27 18:16:34.622 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-10-27 18:16:34.576 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 30% Total physical RAM: 8173.64 MB Available physical RAM: 5687.13 MB Total Pagefile: 32747.82 MB Available Pagefile: 30144.62 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (Boot) (Fixed) (Total:1811.92 GB) (Free:1460.01 GB) NTFS Drive d: (Recover) (Fixed) (Total:50 GB) (Free:24.38 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 1863 GB) (Disk ID: 2BD2C32A) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=-253492199424) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=50 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=1 GB) - (Type=12) ==================== End Of Log ============================ |
12.01.2014, 20:18 | #10 |
| GreatSaver infiziert Grüne striche sind weg. Aber die pop-up's und neue tab's kommen immernoch. Geändert von 00yoshi (12.01.2014 um 20:20 Uhr) Grund: noch was... |
13.01.2014, 12:16 | #11 |
/// the machine /// TB-Ausbilder | GreatSaver infiziert In welchem Browser?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.01.2014, 13:54 | #12 |
| GreatSaver infiziert sorry,hab irgendwie deine antwort nicht gesehen. FireFox EDIT das war ja auf der 2. seite, deswegen hab ichs nicht gesehen Jetzt fängt meine maus wieder an stecken zu bleiben. und der zeiger wird manchmal so bunt. |
18.01.2014, 07:28 | #13 |
/// the machine /// TB-Ausbilder | GreatSaver infiziert Firefox komplett deinstallieren, keine Daten behalten, neu installieren, dann: https://support.mozilla.org/de/kb/fi...einfach-loesen ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.01.2014, 21:48 | #14 |
| GreatSaver infiziert Da ist keine log datei bei eset. (ich hab nach schliessen deinstallieren gedrückt) |
23.01.2014, 19:22 | #15 |
/// the machine /// TB-Ausbilder | GreatSaver infiziert Dann frisches FRST bitte. Wurde bei ESET was gefunden?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu GreatSaver infiziert |
4d36e972-e325-11ce-bfc1-08002be10318, abelssoft, adblock, administrator, adware, bootmgr, converter, cpu, desktop, entfernen, error, excel, explorer, firefox, flash player, ftp, great, hdaudio.sys, helper, home, homepage, junkware, koyote, neue tabs, newtab, nvpciflt.sys, photoshop, plug-in, popup, registry, saver, security, server, services.exe, software, svchost.exe, temp, texturepack, usb, usbvideo.sys, windows, winlogon.exe |