|
Log-Analyse und Auswertung: BKA Sperrfenster - Vista - weitere VirenfundeWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
14.01.2014, 18:30 | #1 |
| BKA Sperrfenster - Vista - weitere Virenfunde Hallo, beim Surfen am Laptop (Vista Home Premium - Firefox) einer Freundin öffnete sich ein BKA-Fenster, das sich nicht mehr schliessen ließ. Ich habe den Rechner neu gestartet. Nach normalem Hochfahren habe ich mit Avira Free Antivirus gescannt. Es gab 4 Funde. Avira: Code:
ATTFilter Exportierte Ereignisse: 14.01.2014 16:57 [System-Scanner] Malware gefunden Die Datei 'C:\Users\Johannes Dölling\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\1595ef5d-50efe3dd' enthielt einen Virus oder unerwünschtes Programm 'Java/Lamar.djg.10' [virus]. Durchgeführte Aktion(en): Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4577d18e.qua' verschoben! 14.01.2014 16:57 [System-Scanner] Malware gefunden Die Datei 'C:\Users\Johannes Dölling\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\4b46ce6e-66363013' enthielt einen Virus oder unerwünschtes Programm 'EXP/CVE-2010-3544' [exploit]. Durchgeführte Aktion(en): Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '5de7fe1c.qua' verschoben! 14.01.2014 16:57 [System-Scanner] Malware gefunden Die Datei 'C:\Users\Johannes Dölling\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\3490cb5b-32395a85' enthielt einen Virus oder unerwünschtes Programm 'Java/Lamar.Dld.33' [virus]. Durchgeführte Aktion(en): Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '17288b65.qua' verschoben! 14.01.2014 16:57 [System-Scanner] Malware gefunden Die Datei 'C:\Users\Johannes Dölling\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\1f12d18-2c357442' enthielt einen Virus oder unerwünschtes Programm 'Java/Lamar.Dld.33' [virus]. Durchgeführte Aktion(en): Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '7117c495.qua' verschoben! Habe nun mit FRST gescannt. FRST FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-01-2014 02 Ran by Johannes Dölling (administrator) on FRANZISKA on 14-01-2014 17:01:08 Running from C:\Users\Johannes Dölling\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe () C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe () C:\Program Files\ATK Hotkey\ASLDRSrv.exe () C:\Program Files\ATKGFNEX\GFNEXSrv.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe () C:\Program Files\ASUS\ASUS Live Update\ALU.exe (ATK0100) C:\Program Files\ATK Hotkey\HControl.exe () C:\Program Files\ATKOSD2\ATKOSD2.exe () C:\Program Files\Wireless Console 2\wcourier.exe (ASUS) C:\Program Files\ASUS\ASUS CopyProtect\ASPG.exe (ATK) C:\Program Files\P4G\BatteryLife.exe (ATK) C:\Program Files\ASUS\Splendid\ACMON.exe (ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (ASUSTeK) C:\Windows\System32\ACEngSvr.exe (UASSOFT.COM) C:\Programme\Mouse Driver\KMWDSrv.exe () D:\CDBurnerXP\NMSAccessU.exe () C:\Program Files\ATK Hotkey\ATKOSD.exe () C:\Windows\System32\PSIService.exe (Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe () C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe () C:\Program Files\ATK Hotkey\KBFiltr.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ASUS) C:\Program Files\ASUS\ATK Media\DMedia.exe (ASUS) C:\Windows\System32\ASUSTPE.exe () C:\Windows\ASScrPro.exe (UASSOFT.COM) C:\Programme\Mouse Driver\StartAutorun.exe (UASSOFT.COM) C:\Programme\Mouse Driver\KMCONFIG.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe () C:\Program Files\Mobile Partner\Mobile Partner.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (UASSOFT.COM) C:\Programme\Mouse Driver\KMProcess.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090908-0900\soffice.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Google Inc.) C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Google Inc.) C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-01-21] (Advanced Micro Devices, Inc.) HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4853760 2008-01-07] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-12-06] (Synaptics, Inc.) HKLM\...\Run: [ATKMEDIA] - C:\Program Files\ASUS\ATK Media\DMedia.exe [159744 2008-06-25] (ASUS) HKLM\...\Run: [ASUSTPE] - C:\Windows\system32\ASUSTPE.exe [106496 2007-10-12] (ASUS) HKLM\...\Run: [ASUS Camera ScreenSaver] - C:\Windows\AsScrProlog.exe [47672 2008-12-23] () HKLM\...\Run: [ASUS Screen Saver Protector] - C:\Windows\ASScrPro.exe [33136 2008-12-23] () HKLM\...\Run: [KMCONFIG] - C:\Programme\Mouse Driver\StartAutorun.exe KMConfig.exe HKLM\...\Run: [Adobe Reader Speed Launcher] - D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-17] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2008-12-23] (Google Inc.) HKCU\...\Run: [Google Update] - C:\Users\Johannes Dölling\AppData\Local\Google\Update\GoogleUpdate.exe [133104 2009-02-27] (Google Inc.) HKCU\...\Run: [Mobile Partner] - C:\Program Files\Mobile Partner\Mobile Partner.exe [114688 2008-12-03] () HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [SODCPreLoad] - D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090908-0900\preload.exe [40960 2009-11-04] () MountPoints2: F - F:\AutoRun.exe MountPoints2: {11b78e2a-dfa1-11df-85b4-002354f3c1e2} - F:\AutoRun.exe MountPoints2: {4b82529b-0bbd-11de-ae6a-002354f3c1e2} - H:\setup.exe MountPoints2: {538afd0c-21fa-11df-bf00-806e6f6e6963} - F:\AutoRun.exe MountPoints2: {5a7c4336-074c-11df-95c3-806e6f6e6963} - F:\AutoRun.exe MountPoints2: {9217a147-091f-11df-86af-002354f3c1e2} - F:\AutoRun.exe MountPoints2: {9c80fe57-f217-11de-acfb-002354f3c1e2} - F:\setup.exe MountPoints2: {afd1eefe-0674-11de-ab40-002354f3c1e2} - G:\setup.exe MountPoints2: {afd1ef00-0674-11de-ab40-002354f3c1e2} - G:\setup.exe MountPoints2: {b68e198f-0976-11de-90da-002354f3c1e2} - F:\setup.exe MountPoints2: {b799f050-c5ff-11e2-a94f-ece509db6cc3} - I:\Startme.exe MountPoints2: {b7e3b79e-eff4-11de-8bd2-002354f3c1e2} - F:\AutoRun.exe MountPoints2: {b7e3b7c1-eff4-11de-8bd2-002354f3c1e2} - F:\AutoRun.exe MountPoints2: {b7e3b7f7-eff4-11de-8bd2-002354f3c1e2} - F:\setup.exe MountPoints2: {b7e3b7fa-eff4-11de-8bd2-002354f3c1e2} - F:\setup.exe MountPoints2: {b7e3b801-eff4-11de-8bd2-002354f3c1e2} - F:\setup.exe MountPoints2: {b7e3b80b-eff4-11de-8bd2-002354f3c1e2} - F:\setup.exe MountPoints2: {bc20654c-0501-11df-a85f-002354f3c1e2} - F:\AutoRun.exe MountPoints2: {bc20654e-0501-11df-a85f-002354f3c1e2} - F:\AutoRun.exe MountPoints2: {cc860e9d-0381-11df-8483-002354f3c1e2} - F:\AutoRun.exe MountPoints2: {cc860ea1-0381-11df-8483-002354f3c1e2} - F:\AutoRun.exe MountPoints2: {e4298290-0b3c-11de-9aff-806e6f6e6963} - F:\setup.exe MountPoints2: {e4f7b505-0651-11de-9b4a-002354f3c1e2} - G:\setup.exe MountPoints2: {e4f7b507-0651-11de-9b4a-002354f3c1e2} - H:\setup.exe HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\system32\oobefldr.dll [ 2009-04-10] (Microsoft Corporation) HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\system32\oobefldr.dll [ 2009-04-10] (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.avira.com/?l=dis&o=APN10395&gct=hp&dc=EU&locale=de_DE HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://de.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.live.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.live.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60347 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS SearchScopes: HKLM - DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS SearchScopes: HKLM - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS SearchScopes: HKLM - {CF739809-1C6C-47C0-85B9-569DBB141420} URL = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101720&gct=&gc=1&q={searchTerms}&crm=1 SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?FORM=IEFM1&q={searchTerms} SearchScopes: HKCU - {0D504953-A679-45E9-9837-A43C7990D539} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&form=MS8TDF&pc=MS8TDF&src=IE-SearchBox SearchScopes: HKCU - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} URL = hxxp://www.crawler.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=60347 SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS_deDE316 SearchScopes: HKCU - {CF739809-1C6C-47C0-85B9-569DBB141420} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10395&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=^ABT&apn_dtid=^YYYYYY^YY^DE&apn_uid=7e992d1a-5914-4972-833e-d10fbc181b0a&apn_sauid=5FC9DDB6-66D9-4265-84A6-B10FD11DDD83 BHO: No Name - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - No Name - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - No File Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU - No Name - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File Toolbar: HKCU - No Name - {FE063DB9-4EC0-403E-8DD8-394C54984B2C} - No File Toolbar: HKCU - No Name - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\..\Interfaces\{8A08AC01-849F-4B73-A414-6262E9CA0755}: [NameServer]212.23.115.84 212.23.115.148 FireFox: ======== FF ProfilePath: C:\Users\Johannes Dölling\AppData\Roaming\Mozilla\Firefox\Profiles\iwu6igek.default FF SearchEngineOrder.1: Ask.com FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @google.com/npPicasa2,version=2.0.0 - C:\Program Files\Picasa2\npPicasa2.dll No File FF Plugin: @google.com/npPicasa3,version=3.0.0 - D:\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google) FF Plugin: @videolan.org/vlc,version=2.0.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - D:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Johannes Dölling\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Johannes Dölling\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Johannes Dölling\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Johannes Dölling\AppData\Roaming\Mozilla\Firefox\Profiles\iwu6igek.default\searchplugins\askcom.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Microsoft .NET Framework Assistant - C:\Users\Johannes Dölling\AppData\Roaming\Mozilla\Firefox\Profiles\iwu6igek.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-07-07] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] Chrome: ======= CHR HomePage: hxxp://search.avira.com/?l=dis&o=APN10395&gct=hp&dc=EU&locale=de_DE CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Johannes D\u00F6lling\AppData\Local\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Users\Johannes D\u00F6lling\AppData\Local\Google\Chrome\Application\31.0.1650.63\pdf.dll No File CHR Plugin: (Shockwave Flash) - C:\Users\Johannes D\u00F6lling\AppData\Local\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) CHR Plugin: (Google Updater) - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google) CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\3.0.50106.0\npctrl.dll No File CHR Plugin: (Unity Player) - C:\Users\Johannes D\u00F6lling\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File CHR Plugin: (Google Update) - C:\Users\Johannes D\u00F6lling\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Plugin: (Picasa) - D:\Picasa3\npPicasa3.dll (Google, Inc.) CHR Extension: (YouTube) - C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 [2013-04-10] CHR Extension: (Google Search) - C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 [2013-03-28] CHR Extension: (AdBlock) - C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0 [2013-11-30] CHR Extension: (Google Wallet) - C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 [2013-12-19] CHR Extension: (Gmail) - C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 [2012-11-10] CHR StartMenuInternet: Google Chrome - C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\Application\chrome.exe ========================== Services (Whitelisted) ================= R2 ADSMService; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [73728 2007-05-18] () R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-17] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-28] (Avira Operations GmbH & Co. KG) R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-02-06] () R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () R2 KMWDSERVICE; C:\Programme\Mouse Driver\KMWDSrv.exe [1821696 2009-10-09] (UASSOFT.COM) R2 NMSAccessU; D:\CDBurnerXP\NMSAccessU.exe [71096 2008-10-20] () R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] () R2 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] () ==================== Drivers (Whitelisted) ==================== R3 Afc; C:\Windows\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.) R0 AsDsm; C:\Windows\System32\Drivers\AsDsm.sys [29752 2007-08-11] (Windows (R) Codename Longhorn DDK provider) R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-28] (Avira Operations GmbH & Co. KG) R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [20936 2007-08-03] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15928 2008-06-03] ( ) R3 KMWDFILTERx86; C:\Windows\System32\DRIVERS\KMWDFILTER.sys [22144 2009-10-09] (Windows (R) Codename Longhorn DDK provider) R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15416 2008-05-29] (Windows (R) Codename Longhorn DDK provider) R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100) S3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [14736 2009-05-09] (Microsoft Corporation) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1772544 2008-05-22] () R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-05] (Avira GmbH) S3 AtiDCM; \??\E:\VGA\Bin\atidcmxx.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 Point32; system32\DRIVERS\point32k.sys [x] S3 USBAAPL; System32\Drivers\usbaapl.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-14 16:59 - 2014-01-14 17:00 - 00000494 _____ C:\Users\Johannes Dölling\Desktop\defogger_disable.log 2014-01-14 16:59 - 2014-01-14 16:59 - 00000000 _____ C:\Users\Johannes Dölling\defogger_reenable 2014-01-14 16:14 - 2014-01-14 16:14 - 00377856 _____ C:\Users\Johannes Dölling\Desktop\6qc1tqbz.exe 2014-01-14 16:14 - 2014-01-14 16:14 - 00050477 _____ C:\Users\Johannes Dölling\Desktop\Defogger.exe 2014-01-14 15:48 - 2014-01-14 15:51 - 00035363 _____ C:\Users\Johannes Dölling\Desktop\Addition.txt 2014-01-14 15:46 - 2014-01-14 17:01 - 00020595 _____ C:\Users\Johannes Dölling\Desktop\FRST.txt 2014-01-14 15:45 - 2014-01-14 15:45 - 00000000 ____D C:\FRST 2014-01-14 15:44 - 2014-01-14 15:44 - 01219584 _____ (Farbar) C:\Users\Johannes Dölling\Desktop\FRST.exe 2014-01-12 15:08 - 2014-01-12 15:08 - 00943872 _____ C:\Users\Johannes Dölling\Downloads\Unlocker-Setup.exe 2014-01-12 14:45 - 2014-01-12 14:45 - 00218129 _____ C:\Users\Johannes Dölling\Downloads\h2testw_1.4.zip 2014-01-12 14:45 - 2014-01-12 14:45 - 00000000 ____D C:\Users\Johannes Dölling\Downloads\h2testw_1.4 2014-01-12 14:43 - 2014-01-12 14:43 - 00027125 _____ C:\Users\Johannes Dölling\Downloads\h2test16.zip 2014-01-12 14:43 - 2014-01-12 14:43 - 00000000 ____D C:\Users\Johannes Dölling\Downloads\h2test16 2014-01-11 15:40 - 2014-01-11 15:40 - 00098304 _____ (Hewlett-Packard Company) C:\Users\Johannes Dölling\Downloads\HPUSBFW_v2.2.3.exe 2014-01-08 16:12 - 2014-01-08 16:14 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\TEMP STICK 2013-12-20 09:57 - 2013-12-20 09:57 - 00000000 ____D C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2014-01-14 17:01 - 2014-01-14 15:46 - 00020595 _____ C:\Users\Johannes Dölling\Desktop\FRST.txt 2014-01-14 17:00 - 2014-01-14 16:59 - 00000494 _____ C:\Users\Johannes Dölling\Desktop\defogger_disable.log 2014-01-14 17:00 - 2009-02-27 14:10 - 00000440 ____H C:\Windows\Tasks\User_Feed_Synchronization-{A5623927-08F0-4775-B2C2-9E9464CC5961}.job 2014-01-14 16:59 - 2014-01-14 16:59 - 00000000 _____ C:\Users\Johannes Dölling\defogger_reenable 2014-01-14 16:59 - 2009-02-27 13:51 - 00000000 ____D C:\Users\Johannes Dölling 2014-01-14 16:52 - 2009-07-01 10:33 - 00001164 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-923187990-3832292030-1982360621-1000UA.job 2014-01-14 16:25 - 2006-11-02 13:47 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-14 16:24 - 2006-11-02 13:47 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-14 16:14 - 2014-01-14 16:14 - 00377856 _____ C:\Users\Johannes Dölling\Desktop\6qc1tqbz.exe 2014-01-14 16:14 - 2014-01-14 16:14 - 00050477 _____ C:\Users\Johannes Dölling\Desktop\Defogger.exe 2014-01-14 15:51 - 2014-01-14 15:48 - 00035363 _____ C:\Users\Johannes Dölling\Desktop\Addition.txt 2014-01-14 15:45 - 2014-01-14 15:45 - 00000000 ____D C:\FRST 2014-01-14 15:44 - 2014-01-14 15:44 - 01219584 _____ (Farbar) C:\Users\Johannes Dölling\Desktop\FRST.exe 2014-01-14 14:31 - 2008-12-23 17:38 - 01544962 _____ C:\Windows\WindowsUpdate.log 2014-01-14 14:25 - 2009-12-26 13:36 - 00065536 _____ C:\Windows\system32\Ikeext.etl 2014-01-14 14:25 - 2009-03-01 17:12 - 00045056 _____ C:\Windows\system32\acovcnt.exe 2014-01-14 14:25 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-14 14:23 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-14 14:23 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\tracing 2014-01-14 12:52 - 2009-07-01 10:33 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-923187990-3832292030-1982360621-1000Core.job 2014-01-14 12:35 - 2009-12-23 19:58 - 00001052 _____ C:\Windows\Tasks\Google Software Updater.job 2014-01-14 10:37 - 2011-06-26 20:25 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\HUHU 2014-01-14 10:36 - 2011-10-25 13:22 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\Stuhudium 2014-01-14 10:36 - 2011-05-21 15:22 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\neo 2014-01-14 10:35 - 2010-11-18 19:26 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\André Arbeit 2014-01-14 10:25 - 2013-06-25 11:51 - 00000000 ____D C:\Users\Johannes Dölling\AppData\Roaming\Dropbox 2014-01-13 00:26 - 2012-09-19 20:37 - 00000000 ____D C:\Users\Johannes Dölling\AppData\Roaming\vlc 2014-01-12 15:08 - 2014-01-12 15:08 - 00943872 _____ C:\Users\Johannes Dölling\Downloads\Unlocker-Setup.exe 2014-01-12 14:45 - 2014-01-12 14:45 - 00218129 _____ C:\Users\Johannes Dölling\Downloads\h2testw_1.4.zip 2014-01-12 14:45 - 2014-01-12 14:45 - 00000000 ____D C:\Users\Johannes Dölling\Downloads\h2testw_1.4 2014-01-12 14:43 - 2014-01-12 14:43 - 00027125 _____ C:\Users\Johannes Dölling\Downloads\h2test16.zip 2014-01-12 14:43 - 2014-01-12 14:43 - 00000000 ____D C:\Users\Johannes Dölling\Downloads\h2test16 2014-01-11 15:46 - 2009-03-01 17:14 - 00000680 _____ C:\Users\Johannes Dölling\AppData\Local\d3d9caps.dat 2014-01-11 15:40 - 2014-01-11 15:40 - 00098304 _____ (Hewlett-Packard Company) C:\Users\Johannes Dölling\Downloads\HPUSBFW_v2.2.3.exe 2014-01-11 00:19 - 2006-11-02 11:33 - 01418806 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-11 00:12 - 2009-02-27 18:05 - 00097280 _____ C:\Users\Johannes Dölling\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-01-08 16:14 - 2014-01-08 16:12 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\TEMP STICK 2014-01-06 22:29 - 2010-01-13 16:04 - 00000000 ____D C:\Users\Johannes Dölling\AppData\Roaming\Skype 2014-01-06 20:47 - 2009-06-17 13:54 - 00000000 ____D C:\Users\Johannes Dölling\AppData\Roaming\skypePM 2013-12-31 17:42 - 2012-11-13 20:38 - 00000000 ____D C:\Users\Johannes Dölling\AppData\Roaming\Mp3tag 2013-12-27 19:12 - 2010-09-09 22:55 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\Arbeit Franzi 2013-12-21 17:07 - 2012-05-07 21:45 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-12-20 09:57 - 2013-12-20 09:57 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-12-19 14:45 - 2013-09-03 16:22 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\Ripped 2013-12-17 15:40 - 2013-08-05 21:43 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-12-17 15:40 - 2013-08-05 21:43 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-12-17 10:43 - 2013-12-10 10:57 - 00011871 _____ C:\Users\Johannes Dölling\Documents\Kautionsverzicht.odt 2013-12-15 13:06 - 2012-10-02 07:43 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-12-15 13:06 - 2011-05-21 10:58 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl Files to move or delete: ==================== C:\Users\Johannes Dölling\AppData\Roaming\desktop.ini Some content of TEMP: ==================== C:\Users\Johannes Dölling\AppData\Local\Temp\avgnt.exe C:\Users\Johannes Dölling\AppData\Local\Temp\sdanircmdc.exe C:\Users\Johannes Dölling\AppData\Local\Temp\sdapskill.exe C:\Users\Johannes Dölling\AppData\Local\Temp\SkypeSetup.exe C:\Users\Johannes Dölling\AppData\Local\Temp\Unlocker1.9.2.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-14 14:32 ==================== End Of Log ============================ Addition Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 13-01-2014 02 Ran by Johannes Dölling at 2014-01-14 15:48:24 Running from C:\Users\Johannes Dölling\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== µTorrent (Version: 2.0.0 - ) Activation Assistant for the 2007 Microsoft Office suites (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden Adobe Flash Player 10 ActiveX (Version: 10.0.32.18 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Reader 9.5.5 - Deutsch (Version: 9.5.5 - Adobe Systems Incorporated) Adobe SVG Viewer 3.0 (Version: 3.0 - ) Adobe® Photoshop® Album Starter Edition 3.2 (Version: 3.2.0 - Adobe Systems, Inc.) Hidden Adobe® Photoshop® Album Starter Edition 3.2 (Version: 3.2.0 - hxxp://www.adobe.de) Album Art Downloader XUI 1.00 (Version: 1.00 - hxxp://sourceforge.net/projects/album-art) Anti-Twin (Installation 30.06.2012) (Version: - Joerg Rosenthal, Germany) ASUS CopyProtect (Version: 1.0.0007 - ASUS) ASUS Data Security Manager (Version: 1.00.0006 - ASUS) ASUS LifeFrame3 (Version: 3.0.10 - ASUS) ASUS Live Update (Version: 2.5.6 - ASUS) ASUS Power4Gear eXtreme (Version: 1.0.18 - ASUS) ASUS SmartLogon (Version: 1.0.0005 - ASUS) ASUS Splendid Video Enhancement Technology (Version: 1.02.0021 - ASUS) ASUS Touch Pad Extra (Version: - ) ASUS Virtual Camera (Version: 1.0.10 - asus) Asus_Camera_ScreenSaver (Version: 2.0.0008 - ASUS) Atheros Client Installation Program (Version: 7.0 - Atheros) ATK Generic Function Service (Version: 1.00.0008 - ATK) ATK Hotkey (Version: 1.00.0012 - ATK) ATK Media (Version: 2.0.0000 - ASUS) ATKOSD2 (Version: 6.64.1.4 - ATK) Avira Free Antivirus (Version: 14.0.2.286 - Avira) Borland Database Engine (Version: 1.0.0 - Borland) Catalyst Control Center Core Implementation (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Graphics Full Existing (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Graphics Full New (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Graphics Light (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Graphics Previews Common (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Graphics Previews Vista (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization Chinese Standard (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization Chinese Traditional (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization Czech (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization Danish (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization Dutch (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization Finnish (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization French (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization German (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization Greek (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization Hungarian (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization Italian (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization Japanese (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization Korean (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization Norwegian (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization Polish (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization Portuguese (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization Russian (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization Spanish (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization Swedish (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization Thai (Version: 2008.0309.2141.36947 - ATI) Hidden Catalyst Control Center Localization Turkish (Version: 2008.0309.2141.36947 - ATI) Hidden CCC Help Chinese Standard (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help Chinese Traditional (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help Czech (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help Danish (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help Dutch (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help English (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help Finnish (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help French (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help German (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help Greek (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help Hungarian (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help Italian (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help Japanese (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help Korean (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help Norwegian (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help Polish (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help Portuguese (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help Russian (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help Spanish (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help Swedish (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help Thai (Version: 2008.0309.2140.36947 - ATI) Hidden CCC Help Turkish (Version: 2008.0309.2140.36947 - ATI) Hidden ccc-Branding (Version: 1.00.0000 - ATI) ccc-core-static (Version: 2008.0309.2141.36947 - ATI) Hidden ccc-utility (Version: 2008.0309.2141.36947 - ATI) Hidden CCleaner (Version: 3.28 - Piriform) CDBurnerXP (Version: 4.2.4.1255 - CDBurnerXP) Cisco EAP-FAST Module (Version: 2.1.6 - Cisco Systems, Inc.) Cisco LEAP Module (Version: 1.0.12 - Cisco Systems, Inc.) Cisco PEAP Module (Version: 1.0.13 - Cisco Systems, Inc.) CloneSpy 2.63 (Version: - CloneSpy) DesignPro 5 (Version: 5.3.705 - Avery Dennison) Hidden DirSync 2.96 (Version: - Stephen Kalisch) DivX-Setup (Version: 1.0.1.4 - DivX, Inc. ) DolbyFiles (Version: 2.0 - Nero AG) Hidden Dropbox (Version: 2.2.13 - Dropbox, Inc.) ElsterFormular (Version: 14.3.11574 - Landesfinanzdirektion Thüringen) Exact Audio Copy 0.99pb5 (Version: 0.99pb5 - Andre Wiethoff) Free M4a to MP3 Converter 7.0 (Version: - ManiacTools.com) Free RAR Extract Frog (Version: 1.80 - Philipp Winterberg) FreeRIP3 3.70 (Version: 3.70 - GreenTree Applications SRL) Google Chrome (Version: 31.0.1650.63 - Google Inc.) Google Earth (Version: 5.0.11733.9347 - Google) Google Updater (Version: 2.4.2432.1652 - Google Inc.) Grand Prix 3 (Version: - ) IBM Lotus Symphony (Version: 1.3.09251 - IBM) IrfanView (remove only) (Version: 4.28 - Irfan Skiljan) Java 7 Update 45 (Version: 7.0.450 - Oracle) Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden JavaFX 2.1.1 (Version: 2.1.1 - Oracle Corporation) LightScribe System Software 1.14.17.1 (Version: 1.14.17.1 - LightScribe) LingoPad 2.5.1 (Build 325) (Version: 2.5.1 - Lingo4you GbR) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.5 SP1 (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Office 2000 Premium (Version: 9.00.2816 - Microsoft Corporation) Microsoft Office Word Viewer 2003 (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft Search Enhancement Pack (Version: 1.3.59.0 - Microsoft Corporation) Hidden Microsoft Silverlight (Version: 4.1.10329.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336 - Microsoft Corporation) Hidden Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Mobile Partner (Version: 11.300.05.11.52 - Huawei Technologies Co.,Ltd) Mouse Driver (Version: 5.1 - Driver Builder) Mouse Driver (Version: 5.1 - Driver Builder) Hidden Mozilla Firefox 26.0 (x86 de) (Version: 26.0 - Mozilla) Mozilla Maintenance Service (Version: 26.0 - Mozilla) Mp3tag v2.53 (Version: v2.53 - Florian Heidenreich) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation) NB Probe (Version: - ) neroxml (Version: 1.0.0 - Nero AG) Hidden OpenOffice.org 3.1 (Version: 3.1.9420 - OpenOffice.org) Picasa 3 (Version: 3.8 - Google, Inc.) Railroad Tycoon II - Platinum (Version: - ) Railroad Tycoon II (Version: - ) Realtek High Definition Audio Driver (Version: 6.0.1.5543 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (Version: - Realtek Semiconductor Corp.) Recuva (Version: 1.45 - Piriform) Skins (Version: 2008.0309.2141.36947 - ATI) Hidden Skype™ 5.1 (Version: 5.1.112 - Skype Technologies S.A.) Synaptics Pointing Device Driver (Version: 10.1.8.0 - Synaptics) TagScanner 5.1.620 (Version: - Sergey Serkov) TreeSize Free V2.7 (Version: 2.7 - JAM Software) Unity Web Player (Version: - Unity Technologies ApS) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1 - Microsoft Corporation) USB2.0 UVC 1.3M WebCam (Version: - ) VC80CRTRedist - 8.0.50727.4053 (Version: 1.1.0 - DivX, Inc) Hidden VLC media player 2.0.3 (Version: 2.0.3 - VideoLAN) Winamp (Version: 5.572 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (Version: 1.0.0.1 - Nullsoft, Inc) Windows 7 Upgrade Advisor (Version: 2.0.3001.0 - Microsoft Corporation) WinFlash (Version: - ) Wireless Console 2 (Version: 2.0.10 - ATK) ==================== Restore Points ========================= 20-12-2013 18:37:43 Geplanter Prüfpunkt 25-12-2013 16:11:55 Geplanter Prüfpunkt 29-12-2013 14:54:51 Geplanter Prüfpunkt 02-01-2014 17:13:46 Geplanter Prüfpunkt 03-01-2014 09:27:33 Geplanter Prüfpunkt 03-01-2014 23:26:05 Geplanter Prüfpunkt 05-01-2014 14:03:18 Geplanter Prüfpunkt 06-01-2014 11:48:14 Geplanter Prüfpunkt 08-01-2014 19:41:13 Geplanter Prüfpunkt 09-01-2014 12:07:04 Geplanter Prüfpunkt 10-01-2014 11:10:58 Geplanter Prüfpunkt 12-01-2014 17:43:33 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {0957C17D-379C-43F4-8EAC-4D2289E88B70} - System32\Tasks\ASUS Live Update => C:\Program Files\ASUS\ASUS Live Update\ALU.exe [2007-11-30] () Task: {0BBD28FE-71B3-4293-AAFE-A67D2C6A45B0} - System32\Tasks\Registration Trigger IBM Lotus Symphony Task => D:\Program Files\IBM\Lotus\Symphony\framework\rcp\rcplauncher.exe [2009-05-25] () Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {2D4E4A26-D5A6-4358-8AB7-8C8AD21B260A} - System32\Tasks\Install_NSS => C:\Program Files\DivX\Symantec\scstubinstaller.exe [2010-03-08] (Symantec Corporation) Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {4B1D5F59-F038-4A2F-9B42-0A656B3275C1} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-923187990-3832292030-1982360621-1000UA => C:\Users\Johannes Dölling\AppData\Local\Google\Update\GoogleUpdate.exe [2009-02-27] (Google Inc.) Task: {73233862-81E7-4136-B74C-386D6AE0324D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-923187990-3832292030-1982360621-1000Core => C:\Users\Johannes Dölling\AppData\Local\Google\Update\GoogleUpdate.exe [2009-02-27] (Google Inc.) Task: {75413A4E-A439-4CCD-89ED-0E7BA7825D2A} - System32\Tasks\CCleanerSkipUAC => D:\CCleaner\CCleaner.exe [2013-02-25] (Piriform Ltd) Task: {956847E8-6DC5-49F0-8CF9-674C70F6E02F} - System32\Tasks\Secunia PSI Logon Task => D:\PSI\psi.exe Task: {BCE647C2-0E6E-4B3A-AC25-E59365C27171} - System32\Tasks\Google Software Updater => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-10-07] (Google) Task: {C282D2BF-E0BA-49B1-B71A-7F23D7097AA0} - System32\Tasks\Microsoft_Hardware_Launch_rundll32_exe => Rundll32.exe url.dll,OpenURL hxxp://go.microsoft.com/fwlink/?LinkId=116866 Task: {CA0E97DC-DA62-491F-AAEC-9C02F7774B81} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => C:\Program Files\Microsoft IntelliPoint\IPoint.exe Task: {CC918611-23A7-4516-A999-90E8BBF44A04} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files\ASUS\SmartLogon\sensorsrv.exe [2008-06-18] (ASUS) Task: {E038F4D4-FC14-43C1-BF2A-5C90FE9C0980} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: {FA6E5377-33C6-4D56-883F-56638FE91F81} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Johannes Dölling => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-10] (Microsoft Corporation) Task: C:\Windows\Tasks\Google Software Updater.job => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-923187990-3832292030-1982360621-1000Core.job => C:\Users\Johannes Dölling\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-923187990-3832292030-1982360621-1000UA.job => C:\Users\Johannes Dölling\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Install_NSS.job => C:\Program Files\DivX\Symantec\scstubinstaller.exe Task: C:\Windows\Tasks\User_Feed_Synchronization-{A5623927-08F0-4775-B2C2-9E9464CC5961}.job => C:\Windows\system32\msfeedssync.exe ==================== Loaded Modules (whitelisted) ============= 2008-12-23 20:00 - 2007-06-15 19:28 - 00147456 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt.dll 2008-12-23 20:00 - 2007-06-02 02:08 - 00143360 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll 2008-12-23 20:00 - 2007-08-08 11:52 - 00331776 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\AdsmendecExt.dll 2008-03-09 15:01 - 2008-03-09 15:01 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll 2010-01-18 22:10 - 2007-08-23 16:39 - 00014848 ____R () C:\Program Files\Mobile Partner\isaputrace.dll 2010-01-18 22:10 - 2008-12-03 14:50 - 00098304 _____ () C:\Program Files\Mobile Partner\DeviceMgrPlugin.dll 2010-01-18 22:10 - 2008-12-03 14:49 - 00118784 _____ () C:\Program Files\Mobile Partner\NetInfoPlugin.dll 2010-01-18 22:10 - 2008-12-03 14:46 - 00086016 _____ () C:\Program Files\Mobile Partner\DialUpPlugin.dll 2010-01-18 22:10 - 2008-12-03 14:51 - 00057344 _____ () C:\Program Files\Mobile Partner\ConfigFilePlugin.dll 2010-01-18 22:10 - 2008-12-03 14:37 - 00856064 _____ () C:\Program Files\Mobile Partner\NDISAPI.dll 2010-01-18 22:10 - 2008-11-08 15:15 - 00151552 ____R () C:\Program Files\Mobile Partner\DetectDev.dll 2010-01-18 22:10 - 2008-11-08 15:15 - 00552960 ____R () C:\Program Files\Mobile Partner\atcomm.dll 2010-01-18 22:10 - 2008-11-08 15:15 - 00061440 ____R () C:\Program Files\Mobile Partner\XCodec.dll 2010-01-18 22:10 - 2008-11-08 15:15 - 00061440 ____R () C:\Program Files\Mobile Partner\DeviceOperate.dll 2010-01-18 22:10 - 2008-12-03 14:54 - 00135168 _____ () C:\Program Files\Mobile Partner\LocaleMgrPlugin.dll 2010-01-18 22:10 - 2008-12-03 14:53 - 00032768 _____ () C:\Program Files\Mobile Partner\NotifyServicePlugin.dll 2010-01-18 22:10 - 2008-12-03 14:45 - 00159744 _____ () C:\Program Files\Mobile Partner\DeviceMgrUIPlugin.dll 2010-01-18 22:10 - 2007-07-31 15:50 - 00090112 ____R () C:\Program Files\Mobile Partner\FileManager.dll 2010-01-18 22:10 - 2008-12-03 14:54 - 00159744 _____ () C:\Program Files\Mobile Partner\SMSPlugin.dll 2007-03-29 11:17 - 2007-03-29 11:17 - 00106496 _____ () C:\Programme\Mouse Driver\keydll.dll 2008-06-16 08:06 - 2008-06-16 08:06 - 00053248 _____ () C:\Programme\Mouse Driver\MouseHook.dll 2009-11-04 12:51 - 2009-11-04 12:51 - 02400323 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.infra.win32_3.5.0.20090908-0900\vcl645mi.dll 2009-11-04 12:52 - 2009-11-04 12:52 - 01794123 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.system.win32_3.5.0.20090908-0900\udkservice1.dll 2009-11-04 12:52 - 2009-11-04 12:52 - 00073794 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.system.win32_3.5.0.20090908-0900\vos3MSC.dll 2009-11-04 12:52 - 2009-11-04 12:52 - 01749055 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.system.win32_3.5.0.20090908-0900\sal3.dll 2009-11-04 12:52 - 2009-11-04 12:52 - 00098304 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.system.win32_3.5.0.20090908-0900\uwinapi.dll 2009-11-04 12:52 - 2009-11-04 12:52 - 00147524 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.system.win32_3.5.0.20090908-0900\reg3.dll 2009-11-04 12:51 - 2009-11-04 12:51 - 01437784 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.system.win32_3.5.0.20090908-0900\log4pt.dll 2009-11-04 12:51 - 2009-11-04 12:51 - 02981961 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.infra.win32_3.5.0.20090908-0900\svt645mi.dll 2009-11-04 12:51 - 2009-11-04 12:51 - 01224776 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.infra.win32_3.5.0.20090908-0900\tk645mi.dll 2009-11-04 12:51 - 2009-11-04 12:51 - 06660166 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.framework.win32_3.5.0.20090908-0900\sfx645mi.dll 2009-11-04 12:51 - 2009-11-04 12:51 - 02326598 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.infra.win32_3.5.0.20090908-0900\sb645mi.dll 2009-11-04 12:51 - 2009-11-04 12:51 - 00299083 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.infra.win32_3.5.0.20090908-0900\xcr645mi.dll 2009-11-04 12:51 - 2009-11-04 12:51 - 00413764 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.infra.win32_3.5.0.20090908-0900\so645mi.dll 2009-11-04 12:51 - 2009-11-04 12:51 - 00286792 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.infra.win32_3.5.0.20090908-0900\go645mi.dll 2009-11-04 12:51 - 2009-11-04 12:51 - 00647244 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.system.win32_3.5.0.20090908-0900\basicservice.uno.dll 2009-11-04 12:51 - 2009-11-04 12:51 - 00049230 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.system.win32_3.5.0.20090908-0900\jvmaccess3MSC.dll 2009-11-04 12:51 - 2009-11-04 12:51 - 02854984 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.infra.win32_3.5.0.20090908-0900\ucpchelp1.dll 2009-11-04 12:52 - 2009-11-04 12:52 - 00286720 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.system.win32_3.5.0.20090908-0900\xerces-depdom_2_6.dll 2009-11-04 12:52 - 2009-11-04 12:52 - 00036864 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.system.win32_3.5.0.20090908-0900\xslt4cMessages_1_7_0.dll 2009-11-04 12:52 - 2009-11-04 12:52 - 00032837 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.system.win32_3.5.0.20090908-0900\rmcxt3.dll 2009-11-04 12:51 - 2009-11-04 12:51 - 01716292 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.infra.win32_3.5.0.20090908-0900\sax.uno.dll 2009-11-04 12:51 - 2009-11-04 12:51 - 01601610 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090908-0900\desktp645mi.dll 2009-11-04 12:51 - 2009-11-04 12:51 - 00397382 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.framework.win32_3.5.0.20090908-0900\ofa645mi.dll 2009-11-04 12:51 - 2009-11-04 12:51 - 08671299 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.framework.win32_3.5.0.20090908-0900\svx645mi.dll 2009-11-04 12:51 - 2009-11-04 12:51 - 01921103 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.infra.win32_3.5.0.20090908-0900\i18npool645mi.dll 2009-11-04 12:51 - 2009-11-04 12:51 - 00204883 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090908-0900\oleautobridge.uno.dll 2009-11-04 12:51 - 2009-11-04 12:51 - 00094283 _____ () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.system.win32_3.5.0.20090908-0900\emser645mi.dll 2007-03-07 02:03 - 2007-03-07 02:03 - 00016384 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll 2013-12-20 09:57 - 2013-12-20 09:57 - 03559024 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2013-12-04 20:52 - 2013-12-04 03:48 - 04055504 _____ () C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\Application\31.0.1650.63\pdf.dll 2013-12-04 20:52 - 2013-12-04 03:48 - 00399312 _____ () C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll 2013-12-04 20:52 - 2013-12-04 03:47 - 01619408 _____ () C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: 6TO4 Adapter Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver ==================== Event log errors: ========================= Application errors: ================== Error: (01/14/2014 02:26:31 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/14/2014 10:34:38 AM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\JOHANNES DÖLLING\DESKTOP\WOHNUNG\BILDER NEUE WOHNUNG\$TEST$55082> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (01/14/2014 09:32:06 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/13/2014 02:28:30 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/12/2014 02:19:57 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/11/2014 08:19:27 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/11/2014 03:44:42 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/11/2014 02:19:49 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/11/2014 00:29:21 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/11/2014 00:22:27 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (01/14/2014 02:29:52 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT) Description: 0x80070032 Error: (01/14/2014 09:34:27 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT) Description: 0x80070032 Error: (01/14/2014 00:23:43 AM) (Source: DCOM) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (01/13/2014 02:30:33 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT) Description: 0x80070032 Error: (01/12/2014 02:22:54 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT) Description: 0x80070032 Error: (01/11/2014 08:22:27 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT) Description: 0x80070032 Error: (01/11/2014 03:47:00 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT) Description: 0x80070032 Error: (01/11/2014 02:21:43 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT) Description: 0x80070032 Error: (01/11/2014 00:31:15 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT) Description: 0x80070032 Error: (01/11/2014 00:24:53 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT) Description: 0x80070032 Microsoft Office Sessions: ========================= Error: (01/14/2014 02:26:31 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/14/2014 10:34:38 AM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\JOHANNES DÖLLING\DESKTOP\WOHNUNG\BILDER NEUE WOHNUNG\$TEST$55082 Error: (01/14/2014 09:32:06 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/13/2014 02:28:30 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/12/2014 02:19:57 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/11/2014 08:19:27 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/11/2014 03:44:42 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/11/2014 02:19:49 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/11/2014 00:29:21 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/11/2014 00:22:27 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 CodeIntegrity Errors: =================================== Date: 2013-05-22 11:19:54.718 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-05-22 11:19:54.546 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-05-22 11:19:54.296 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-05-22 11:19:54.078 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-05-22 11:19:53.890 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22167_none_b36dd19b7fae39c7\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-05-22 11:19:53.734 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22167_none_b36dd19b7fae39c7\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-05-22 11:19:53.527 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22167_none_b36dd19b7fae39c7\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-05-22 11:19:53.338 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22167_none_b36dd19b7fae39c7\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-05-22 11:19:53.143 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18311_none_b3144862666d6db3\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-05-22 11:19:52.985 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18311_none_b3144862666d6db3\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 60% Total physical RAM: 3070.54 MB Available physical RAM: 1226.36 MB Total Pagefile: 6343.35 MB Available Pagefile: 4370.2 MB Total Virtual: 2047.88 MB Available Virtual: 1904.21 MB ==================== Drives ================================ Drive c: (VistaOS) (Fixed) (Total:116.44 GB) (Free:33.63 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (DATA) (Fixed) (Total:106.67 GB) (Free:36.62 GB) NTFS Drive f: (Mobile Partner) (CDROM) (Total:0.02 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 233 GB) (Disk ID: 97646C29) Partition 1: (Not Active) - (Size=10 GB) - (Type=1C) Partition 2: (Active) - (Size=116 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=107 GB) - (Type=OF Extended) ==================== End Of Log ============================ Ich werde jetzt noch mit GMER scannen. Wäre schön wenn sich jemand der Thematik annehmen könnte. Hier noch das GMER-Log: Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2014-01-14 18:20:58 Windows 6.0.6002 Service Pack 2 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-2 ST9250320AS rev.0303 232,89GB Running: 6qc1tqbz.exe; Driver: C:\Users\JOHANN~1\AppData\Local\Temp\kgldrpog.sys ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- Files - GMER 2.1 ---- File C:\Users\Johannes Dölling\Gesicherte Musik 0 bytes File C:\Users\Johannes Dölling\Gesichertes Dokument 0 bytes File C:\Users\Johannes Dölling\Gesichertes Video 0 bytes ---- EOF - GMER 2.1 ---- |
14.01.2014, 18:52 | #2 | |
/// the machine /// TB-Ausbilder | BKA Sperrfenster - Vista - weitere Virenfunde hi,
__________________Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ |
14.01.2014, 19:23 | #3 |
| BKA Sperrfenster - Vista - weitere Virenfunde Hallo,
__________________schonmal danke für die schnelle Antwort. ComboFix: Code:
ATTFilter ComboFix 14-01-14.02 - Johannes Dölling 14.01.2014 19:03:20.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3071.2025 [GMT 1:00] ausgeführt von:: c:\users\Johannes D÷lling\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\Common Files\ASPG_icon.ico c:\windows\msvcr71.dll c:\windows\unin0407.exe . . ((((((((((((((((((((((( Dateien erstellt von 2013-12-14 bis 2014-01-14 )))))))))))))))))))))))))))))) . . 2014-01-14 18:13 . 2014-01-14 18:13 -------- d-----w- c:\users\Johannes Dölling\AppData\Local\temp 2014-01-14 18:13 . 2014-01-14 18:13 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-01-14 18:13 . 2014-01-14 18:13 -------- d-----w- c:\users\ADMINI~1\AppData\Local\temp 2014-01-14 14:45 . 2014-01-14 14:45 -------- d-----w- C:\FRST . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-01-14 17:23 . 2009-03-01 16:12 45056 ----a-w- c:\windows\system32\acovcnt.exe 2013-12-17 14:40 . 2013-08-05 20:43 90400 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2013-12-17 14:40 . 2013-08-05 20:43 135648 ----a-w- c:\windows\system32\drivers\avipbb.sys 2013-12-15 12:06 . 2012-10-02 06:43 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-12-15 12:06 . 2011-05-21 09:58 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-11-28 22:05 . 2013-08-05 20:43 37352 ----a-w- c:\windows\system32\drivers\avkmgr.sys 2008-07-02 03:28 . 2008-07-02 03:28 61440 ----a-w- c:\program files\Common Files\CPInstallAction.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1] @="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}" [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}] 2007-06-02 01:08 143360 ----a-w- c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-13 23:00 130736 ----a-w- c:\users\Johannes Dölling\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-13 23:00 130736 ----a-w- c:\users\Johannes Dölling\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-13 23:00 130736 ----a-w- c:\users\Johannes Dölling\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-23 39408] "Mobile Partner"="c:\program files\Mobile Partner\Mobile Partner.exe" [2008-12-03 114688] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "SODCPreLoad"="d:\program files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090908-0900\preload.exe" [2009-11-04 40960] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440] "RtHDVCpl"="RtHDVCpl.exe" [2008-01-07 4853760] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1029416] "ATKMEDIA"="c:\program files\ASUS\ATK Media\DMedia.exe" [2008-06-25 159744] "ASUSTPE"="c:\windows\system32\ASUSTPE.exe" [2007-10-12 106496] "ASUS Camera ScreenSaver"="c:\windows\AsScrProlog.exe" [2008-12-23 47672] "ASUS Screen Saver Protector"="c:\windows\ASScrPro.exe" [2008-12-23 33136] "KMCONFIG"="c:\programme\Mouse Driver\StartAutorun.exe" [2008-05-29 212992] "Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2013-05-08 41056] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-12-17 684600] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^Users^Johannes Dölling^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk] path=c:\users\Johannes Dölling\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk backup=c:\windows\pss\OpenOffice.org 3.1.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2013-04-04 21:06 958576 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader] 2007-03-16 09:45 63712 ----a-w- d:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2013-05-08 21:20 41056 ----a-w- d:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate] 2010-04-12 22:46 1135912 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe] 2008-01-21 02:25 125952 ----a-w- c:\windows\ehome\ehtray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update] 2009-02-27 16:05 133104 ----atw- c:\users\Johannes Dölling\AppData\Local\Google\Update\GoogleUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel] 2008-06-09 18:16 2363392 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NB Probe] 2008-06-21 01:30 813624 ----a-w- c:\program files\ASUS\NB Probe\NBProbe.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SODCPreLoad] 2009-11-04 11:51 40960 ----a-w- d:\program files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090908-0900\preload.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2013-07-02 07:16 254336 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] 2008-12-23 18:05 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG] 2008-01-21 02:25 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled] "Corel File Shell Monitor"=d:\program files\Corel\Corel MediaOne\CorelIOMonitor.exe "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot "QuickTime Task"="d:\program files\QuickTime\QTTask.exe" -atboottime . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2008-06-09 18:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . Inhalt des "geplante Tasks" Ordners . 2014-01-14 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-23 10:22] . 2010-04-27 c:\windows\Tasks\Install_NSS.job - c:\program files\DivX\Symantec\scstubinstaller.exe [2010-03-08 18:00] . 2014-01-14 c:\windows\Tasks\User_Feed_Synchronization-{A5623927-08F0-4775-B2C2-9E9464CC5961}.job - c:\windows\system32\msfeedssync.exe [2009-12-09 04:59] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://search.avira.com/?l=dis&o=APN10395&gct=hp&dc=EU&locale=de_DE uDefault_Search_URL = hxxp://www.google.com/ie mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html FF - ProfilePath - c:\users\Johannes Dölling\AppData\Roaming\Mozilla\Firefox\Profiles\iwu6igek.default\ FF - prefs.js: browser.startup.homepage - about:home FF - ExtSQL: !HIDDEN! 2009-06-24 13:09; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension . - - - - Entfernte verwaiste Registrierungseinträge - - - - . AddRemove-LingoPad_is1 - d:\lingopad\unins000.exe AddRemove-Railroad Tycoon II - c:\windows\unin0407.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2014-01-14 19:13 Windows 6.0.6002 Service Pack 2 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . . C:\ADSM_PData_0150 . Scan erfolgreich abgeschlossen versteckte Dateien: 1 . ************************************************************************** . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,57,c8,f1,da,3d,54,a0,4a,bf,eb,5b,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,57,c8,f1,da,3d,54,a0,4a,bf,eb,5b,\ "6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,57,c8,f1,da,3d,54,a0,4a,bf,eb,5b,\ . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice] @Denied: (2) (LocalSystem) @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) "Progid"="ACDSee Photo Manager 2009.arw" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice] @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) @Denied: (2) (LocalSystem) "Progid"="PhotoViewer.FileAssoc.Bitmap" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice] @Denied: (2) (LocalSystem) @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) "Progid"="ACDSee Photo Manager 2009.cr2" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice] @Denied: (2) (LocalSystem) @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) "Progid"="ACDSee Photo Manager 2009.crw" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Photo Manager 2009.cur" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice] @Denied: (2) (LocalSystem) @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) "Progid"="ACDSee Photo Manager 2009.dcr" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Photo Manager 2009.dib" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice] @Denied: (2) (LocalSystem) @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) "Progid"="ACDSee Photo Manager 2009.dng" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Photo Manager 2009.emf" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Photo Manager 2009.erf" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Photo Manager 2009.fpx" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice] @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) @Denied: (2) (LocalSystem) "Progid"="PhotoViewer.FileAssoc.Gif" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Photo Manager 2009.jfif" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice] @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) @Denied: (2) (LocalSystem) "Progid"="PhotoViewer.FileAssoc.Jpeg" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice] @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) @Denied: (2) (LocalSystem) "Progid"="PhotoViewer.FileAssoc.Jpeg" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice] @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) @Denied: (2) (LocalSystem) "Progid"="PhotoshopAlbumSE3.JpegFile" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice] @Denied: (2) (LocalSystem) @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) "Progid"="ACDSee Photo Manager 2009.kdc" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice] @Denied: (2) (LocalSystem) @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) "Progid"="ACDSee Photo Manager 2009.mrw" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice] @Denied: (2) (LocalSystem) @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) "Progid"="ACDSee Photo Manager 2009.nef" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice] @Denied: (2) (LocalSystem) @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) "Progid"="ACDSee Photo Manager 2009.orf" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice] @Denied: (2) (LocalSystem) @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) "Progid"="ACDSee Photo Manager 2009.pef" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice] @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) @Denied: (2) (LocalSystem) "Progid"="PhotoViewer.FileAssoc.Png" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice] @Denied: (2) (LocalSystem) @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) "Progid"="ACDSee Photo Manager 2009.raf" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice] @Denied: (2) (LocalSystem) @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) "Progid"="ACDSee Photo Manager 2009.raw" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Photo Manager 2009.rle" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice] @Denied: (2) (LocalSystem) @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) "Progid"="ACDSee Photo Manager 2009.sr2" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice] @Denied: (2) (LocalSystem) @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) "Progid"="ACDSee Photo Manager 2009.tga" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice] @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) @Denied: (2) (LocalSystem) "Progid"="PhotoViewer.FileAssoc.Tiff" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice] @Denied: (2) (S-1-5-21-923187990-3832292030-1982360621-1000) @Denied: (2) (LocalSystem) "Progid"="PhotoViewer.FileAssoc.Tiff" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Photo Manager 2009.ttc" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Photo Manager 2009.ttf" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Photo Manager 2009.wmf" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.0_03" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.0_04" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.0_05" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_01" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_01" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_02" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_02" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_03" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_03" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_04" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_04" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_05" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_05" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_06" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_06" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_07" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_07" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_08" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_08" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_09" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_09" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_10" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_10" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_11" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_11" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_12" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_12" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_13" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_13" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_14" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_14" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_15" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_15" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_16" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_16" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_17" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_17" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_18" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_18" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_19" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_19" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_20" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_20" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_21" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_21" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_01" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_01" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_02" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_02" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_03" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_03" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_04" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_04" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_01" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_01" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_02" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_02" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_03" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_03" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_04" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_04" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_05" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_05" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_06" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_06" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_07" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_07" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_01" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_01" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_02" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_02" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_03" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_03" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_04" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_04" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_05" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_05" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_06" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_06" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_07" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_07" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_08" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_08" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_09" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_09" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_10" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_10" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_11" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_11" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_12" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_12" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_13" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_13" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_14" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_14" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_15" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_15" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_16" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_16" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_17" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_17" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_18" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_18" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_19" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_19" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_20" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_20" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_21" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_21" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_22" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_22" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_23" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_23" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_24" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_24" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_25" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_25" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_26" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_26" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_27" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_27" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_28" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_28" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_29" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_29" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_30" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_30" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_31" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_31" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_32" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_32" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_33" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_33" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_34" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_34" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_35" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_35" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_36" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_36" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_37" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_37" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_38" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_38" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_39" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_39" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_40" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_40" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0041-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_41" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0041-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_41" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0042-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_42" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0042-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_42" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0043-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_43" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0043-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_43" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_01" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_01" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_01" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_02" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_02" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_02" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_03" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_03" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_03" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_04" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_04" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_04" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_05" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_05" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_05" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_06" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_06" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_06" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_07" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_07" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_07" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_08" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_08" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_08" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_09" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_09" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_09" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_10" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_10" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_10" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_11" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_11" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_11" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_12" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_12" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_12" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_13" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_13" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_13" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_14" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_14" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_14" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_15" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_15" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_15" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_16" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_16" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_16" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_17" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_17" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_17" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_18" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_18" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_18" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_19" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_19" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_19" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_20" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_20" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_20" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_21" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_21" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_21" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_22" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_22" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_22" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_23" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_23" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_23" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_24" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_24" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_24" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_25" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_25" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_25" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_26" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_26" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_26" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_27" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_27" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_27" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_28" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_28" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_28" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_29" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_29" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_29" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_30" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_30" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_30" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_31" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_31" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0031-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_31" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_32" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_32" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0032-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_32" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_33" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_33" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0033-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_33" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_34" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_34" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0034-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_34" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_35" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_35" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0035-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_35" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_36" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_36" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0036-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_36" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_37" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_37" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0037-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_37" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_38" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_38" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0038-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_38" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_39" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_39" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0039-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_39" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_40" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_40" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0040-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_40" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0041-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_41" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0041-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_41" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0041-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_41" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0042-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_42" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0042-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_42" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0042-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_42" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0043-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_43" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0043-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_43" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0043-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_43" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0044-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_44" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0044-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_44" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0044-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_44" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0045-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_45" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0045-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_45" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0045-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_45" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0046-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_46" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0046-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_46" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0046-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_46" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0047-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_47" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0047-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_47" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0047-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_47" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0048-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_48" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0048-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_48" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0048-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_48" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0049-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_49" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0049-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_49" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0049-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_49" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0050-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_50" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0050-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_50" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0050-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_50" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0051-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_51" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0051-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_51" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0051-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_51" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0052-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_52" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0052-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_52" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0052-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_52" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0053-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_53" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0053-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_53" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0053-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_53" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0054-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_54" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0054-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_54" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0054-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_54" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0055-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_55" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0055-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_55" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0055-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_55" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_01" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_01" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_01" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_02" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_02" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_02" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_03" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_03" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_03" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_04" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_04" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_04" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_05" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_05" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_05" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_06" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_06" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_06" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_07" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_07" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_07" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_08" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_08" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_08" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_09" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_09" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_09" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_10" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_10" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_10" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_11" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_11" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_11" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_12" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_12" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_12" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_13" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_13" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_13" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_14" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_14" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_14" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_15" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_15" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_15" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_16" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_16" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_16" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_17" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_17" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_17" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_18" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_18" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_18" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_19" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_19" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_19" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_20" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_20" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_20" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_21" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_21" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_21" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_22" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_22" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_22" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_23" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_23" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_23" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_24" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_24" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_24" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_25" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_25" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_25" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_26" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_26" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_26" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_27" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_27" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_27" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_28" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_28" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0028-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_28" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_29" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_29" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_29" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_30" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_30" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_30" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_31" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_31" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_31" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_32" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_32" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_32" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_33" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_33" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_33" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_34" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_34" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_34" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_35" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_35" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_35" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_36" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_36" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0036-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_36" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_37" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_37" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_37" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_38" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_38" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_38" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_39" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_39" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_39" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_40" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_40" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0040-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_40" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0041-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_41" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0041-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_41" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0041-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_41" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0042-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_42" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0042-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_42" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0042-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_42" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_43" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_43" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_43" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0044-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_44" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0044-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_44" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0044-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_44" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_45" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_45" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_45" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0046-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_46" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0046-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_46" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0046-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_46" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0047-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_47" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0047-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_47" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0047-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_47" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0048-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_48" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0048-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_48" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0048-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_48" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0049-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_49" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0049-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_49" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0049-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_49" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0050-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_50" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0050-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_50" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0050-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_50" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0051-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_51" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0051-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_51" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0051-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_51" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0052-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_52" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0052-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_52" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0052-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_52" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0053-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_53" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0053-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_53" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0053-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_53" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0054-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_54" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0054-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_54" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0054-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_54" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0055-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_55" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0055-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_55" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0055-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_55" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0056-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_56" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0056-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_56" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0056-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_56" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0057-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_57" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0057-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_57" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0057-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_57" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0058-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_58" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0058-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_58" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0058-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_58" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0059-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_59" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0059-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_59" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0059-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_59" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0060-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_60" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0060-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_60" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0060-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_60" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0061-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_61" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0061-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_61" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0061-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_61" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0062-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_62" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0062-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_62" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0062-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_62" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0063-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_63" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0063-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_63" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0063-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_63" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0064-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_64" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0064-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_64" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0064-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_64" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0065-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_65" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0065-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_65" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0065-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_65" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0016-0000-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_01" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_01" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_01" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_02" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_02" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0002-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_02" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_03" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_03" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0003-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_03" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_04" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_04" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0004-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_04" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_05" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_05" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0005-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_05" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_06" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_06" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0006-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_06" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_07" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_07" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0007-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_07" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_08" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_08" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0008-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_08" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_09" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_09" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0009-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_09" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_10" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_10" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0010-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_10" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_11" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_11" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0011-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_11" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_12" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_12" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0012-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_12" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_13" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_13" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_13" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_14" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_14" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0014-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_14" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_15" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_15" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0015-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_15" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_16" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_16" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0016-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_16" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_17" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_17" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0017-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_17" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_18" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_18" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0018-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_18" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_19" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_19" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0019-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_19" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_20" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_20" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0020-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_20" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_21" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_21" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0021-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_21" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_22" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_22" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0022-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_22" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_23" |
14.01.2014, 19:24 | #4 |
| BKA Sperrfenster - Vista - weitere Virenfunde ComboFix continued: Code:
ATTFilter . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_23" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0023-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_23" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_24" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_24" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0024-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_24" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_25" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_25" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_25" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_26" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_26" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0026-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_26" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_27" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_27" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0027-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_27" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_28" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_28" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0028-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_28" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_29" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_29" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0029-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_29" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_30" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_30" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0030-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_30" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_31" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_31" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0031-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_31" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_32" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_32" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0032-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_32" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_33" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_33" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0033-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_33" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_34" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_34" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0034-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_34" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_35" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_35" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0035-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_35" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_36" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_36" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0036-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_36" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_37" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_37" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0037-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_37" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_38" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_38" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0038-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_38" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_39" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_39" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0039-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_39" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_40" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_40" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0040-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_40" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0041-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_41" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0041-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_41" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0041-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_41" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0042-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_42" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0042-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_42" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0042-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_42" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0043-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_43" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0043-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_43" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0043-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_43" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0044-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_44" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0044-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_44" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0044-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_44" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_45" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0045-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_45" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0045-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_45" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-923187990-3832292030-1982360621-1000_Classes\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}] @DACL=(02 0000) @="Java Plug-in 1.3.0_02" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Zeit der Fertigstellung: 2014-01-14 19:15:49 ComboFix-quarantined-files.txt 2014-01-14 18:15 . Vor Suchlauf: 8 Verzeichnis(se), 35.163.430.912 Bytes frei Nach Suchlauf: 12 Verzeichnis(se), 34.950.938.624 Bytes frei . - - End Of File - - AD959793F38C2B2F1CABAD2FCF37129D 64B1E91C5C6C2157642651010728F90F |
15.01.2014, 12:28 | #5 |
/// the machine /// TB-Ausbilder | BKA Sperrfenster - Vista - weitere Virenfunde Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.01.2014, 13:15 | #6 |
| BKA Sperrfenster - Vista - weitere Virenfunde Habe alle Scans durchgeführt. mbam Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.01.15.04 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 8.0.6001.18865 Johannes Dölling :: FRANZISKA [Administrator] Schutz: Aktiviert 15.01.2014 12:35:23 mbam-log-2014-01-15 (12-35-23).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Dateisystem | Heuristiks/Extra | PUP | PUM Deaktivierte Suchlaufeinstellungen: Registrierung | HeuristiKs/Shuriken | P2P Durchsuchte Objekte: 215573 Laufzeit: 9 Minute(n), 3 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Johannes Dölling\AppData\Roaming\AD ON Multimedia\eBay Shortcuts\eBayShortcuts.exe (Adware.ADON) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter # AdwCleaner v3.017 - Bericht erstellt am 15/01/2014 um 12:55:30 # Aktualisiert 12/01/2014 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzername : Johannes Dölling - FRANZISKA # Gestartet von : C:\Users\Johannes Dölling\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\FreeRIP Ordner Gelöscht : C:\Program Files\AskTBar Ordner Gelöscht : C:\Program Files\FreeRIP3 Ordner Gelöscht : C:\Users\Johannes Dölling\AppData\Roaming\AD ON Multimedia Datei Gelöscht : C:\Users\Johannes Dölling\AppData\Roaming\Microsoft\Windows\Start Menu\eBay.lnk Datei Gelöscht : C:\Program Files\Mozilla Firefox\Components\AskSearch.js Datei Gelöscht : C:\Users\Johannes Dölling\AppData\Roaming\Mozilla\Firefox\Profiles\iwu6igek.default\searchplugins\Askcom.xml ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BCE647C2-0E6E-4B3A-AC25-E59365C27171} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201F27D4-3704-41D6-89C1-AA35E39143ED} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3041D03E-FD4B-44E0-B742-2D9B88305F98} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063DB1-4EC0-403E-8DD8-394C54984B2C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063DB9-4EC0-403E-8DD8-394C54984B2C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{201F27D4-3704-41D6-89C1-AA35E39143ED} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3041D03E-FD4B-44E0-B742-2D9B88305F98} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063DB1-4EC0-403E-8DD8-394C54984B2C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063DB9-4EC0-403E-8DD8-394C54984B2C} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420} Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{FE063DB9-4EC0-403E-8DD8-394C54984B2C}] Schlüssel Gelöscht : HKCU\Software\MarketPrecision Schlüssel Gelöscht : HKCU\Software\MGShareware Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKLM\Software\MarketPrecision Schlüssel Gelöscht : HKLM\Software\MGShareware Schlüssel Gelöscht : HKLM\Software\Uniblue Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{501451DE-5808-4599-B544-8BD0915B6B24}_is1 Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{501451DE-5808-4599-B544-8BD0915B6B24}_is1 Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536 ***** [ Browser ] ***** -\\ Internet Explorer v8.0.6001.18865 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] -\\ Mozilla Firefox v26.0 (de) [ Datei : C:\Users\Johannes Dölling\AppData\Roaming\Mozilla\Firefox\Profiles\iwu6igek.default\prefs.js ] -\\ Google Chrome v [ Datei : C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht : homepage ************************* AdwCleaner[R0].txt - [6275 octets] - [15/01/2014 12:54:18] AdwCleaner[S0].txt - [6089 octets] - [15/01/2014 12:55:30] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6149 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.0 (01.07.2014:1) OS: Windows Vista (TM) Home Premium x86 Ran by Johannes D”lling on 15.01.2014 at 13:02:40,97 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0D504953-A679-45E9-9837-A43C7990D539} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\apn" Successfully deleted: [Folder] "C:\Users\Johannes D”lling\appdata\local\apn" ~~~ FireFox Emptied folder: C:\Users\Johannes D”lling\AppData\Roaming\mozilla\firefox\profiles\iwu6igek.default\minidumps [248 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 15.01.2014 at 13:09:07,27 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-01-2014 02 Ran by Johannes Dölling (administrator) on FRANZISKA on 15-01-2014 13:10:23 Running from C:\Users\Johannes Dölling\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (ASUS) C:\Program Files\ASUS\SmartLogon\smartlogon.exe () C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe () C:\Program Files\ATK Hotkey\ASLDRSrv.exe () C:\Program Files\ATKGFNEX\GFNEXSrv.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (UASSOFT.COM) C:\Programme\Mouse Driver\KMWDSrv.exe () C:\Program Files\ASUS\ASUS Live Update\ALU.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (ATK0100) C:\Program Files\ATK Hotkey\HControl.exe () C:\Program Files\ATKOSD2\ATKOSD2.exe () C:\Program Files\Wireless Console 2\wcourier.exe (ASUS) C:\Program Files\ASUS\ASUS CopyProtect\ASPG.exe (ATK) C:\Program Files\P4G\BatteryLife.exe (ATK) C:\Program Files\ASUS\Splendid\ACMON.exe () D:\CDBurnerXP\NMSAccessU.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe () C:\Windows\System32\PSIService.exe (Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (ASUSTeK) C:\Windows\System32\ACEngSvr.exe () C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe () C:\Program Files\ATK Hotkey\ATKOSD.exe () C:\Program Files\ATK Hotkey\KBFiltr.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ASUS) C:\Program Files\ASUS\ATK Media\DMedia.exe (ASUS) C:\Windows\System32\ASUSTPE.exe () C:\Windows\ASScrPro.exe (UASSOFT.COM) C:\Programme\Mouse Driver\StartAutorun.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe () C:\Program Files\Mobile Partner\Mobile Partner.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (UASSOFT.COM) C:\Programme\Mouse Driver\KMCONFIG.exe (UASSOFT.COM) C:\Programme\Mouse Driver\KMProcess.exe () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090908-0900\soffice.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-01-21] (Advanced Micro Devices, Inc.) HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4853760 2008-01-07] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-12-06] (Synaptics, Inc.) HKLM\...\Run: [ATKMEDIA] - C:\Program Files\ASUS\ATK Media\DMedia.exe [159744 2008-06-25] (ASUS) HKLM\...\Run: [ASUSTPE] - C:\Windows\system32\ASUSTPE.exe [106496 2007-10-12] (ASUS) HKLM\...\Run: [ASUS Camera ScreenSaver] - C:\Windows\AsScrProlog.exe [47672 2008-12-23] () HKLM\...\Run: [ASUS Screen Saver Protector] - C:\Windows\ASScrPro.exe [33136 2008-12-23] () HKLM\...\Run: [KMCONFIG] - C:\Programme\Mouse Driver\StartAutorun.exe KMConfig.exe HKLM\...\Run: [Adobe Reader Speed Launcher] - D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-17] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2008-12-23] (Google Inc.) HKCU\...\Run: [Mobile Partner] - C:\Program Files\Mobile Partner\Mobile Partner.exe [114688 2008-12-03] () HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [SODCPreLoad] - D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090908-0900\preload.exe [40960 2009-11-04] () HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\system32\oobefldr.dll [ 2009-04-10] (Microsoft Corporation) HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\system32\oobefldr.dll [ 2009-04-10] (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.live.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS_deDE316 BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - No Name - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - No File Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) FireFox: ======== FF ProfilePath: C:\Users\Johannes Dölling\AppData\Roaming\Mozilla\Firefox\Profiles\iwu6igek.default FF SearchEngineOrder.1: Ask.com FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @google.com/npPicasa2,version=2.0.0 - C:\Program Files\Picasa2\npPicasa2.dll No File FF Plugin: @google.com/npPicasa3,version=3.0.0 - D:\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google) FF Plugin: @videolan.org/vlc,version=2.0.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - D:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Johannes Dölling\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Johannes Dölling\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Johannes Dölling\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Microsoft .NET Framework Assistant - C:\Users\Johannes Dölling\AppData\Roaming\Mozilla\Firefox\Profiles\iwu6igek.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-07-07] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Johannes D\u00F6lling\AppData\Local\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Users\Johannes D\u00F6lling\AppData\Local\Google\Chrome\Application\31.0.1650.63\pdf.dll No File CHR Plugin: (Shockwave Flash) - C:\Users\Johannes D\u00F6lling\AppData\Local\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) CHR Plugin: (Google Updater) - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google) CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\3.0.50106.0\npctrl.dll No File CHR Plugin: (Unity Player) - C:\Users\Johannes D\u00F6lling\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File CHR Plugin: (Google Update) - C:\Users\Johannes D\u00F6lling\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Plugin: (Picasa) - D:\Picasa3\npPicasa3.dll (Google, Inc.) CHR Extension: (YouTube) - C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 [2013-04-10] CHR Extension: (Google Search) - C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 [2013-03-28] CHR Extension: (AdBlock) - C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.18_0 [2014-01-14] CHR Extension: (Google Wallet) - C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 [2013-12-19] CHR Extension: (Gmail) - C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 [2012-11-10] CHR StartMenuInternet: Google Chrome - C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\Application\chrome.exe ========================== Services (Whitelisted) ================= R2 ADSMService; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [73728 2007-05-18] () R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-17] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-28] (Avira Operations GmbH & Co. KG) R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-02-06] () R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () R2 KMWDSERVICE; C:\Programme\Mouse Driver\KMWDSrv.exe [1821696 2009-10-09] (UASSOFT.COM) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NMSAccessU; D:\CDBurnerXP\NMSAccessU.exe [71096 2008-10-20] () R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] () R2 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] () ==================== Drivers (Whitelisted) ==================== R3 Afc; C:\Windows\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.) R0 AsDsm; C:\Windows\System32\Drivers\AsDsm.sys [29752 2007-08-11] (Windows (R) Codename Longhorn DDK provider) R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-28] (Avira Operations GmbH & Co. KG) R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [20936 2007-08-03] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15928 2008-06-03] ( ) R3 KMWDFILTERx86; C:\Windows\System32\DRIVERS\KMWDFILTER.sys [22144 2009-10-09] (Windows (R) Codename Longhorn DDK provider) R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15416 2008-05-29] (Windows (R) Codename Longhorn DDK provider) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100) S3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [14736 2009-05-09] (Microsoft Corporation) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1772544 2008-05-22] () R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-05] (Avira GmbH) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S3 AtiDCM; \??\E:\VGA\Bin\atidcmxx.sys [x] S3 catchme; \??\C:\Users\JOHANN~1\AppData\Local\Temp\catchme.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 Point32; system32\DRIVERS\point32k.sys [x] S3 USBAAPL; System32\Drivers\usbaapl.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-15 13:09 - 2014-01-15 13:09 - 00001385 _____ C:\Users\Johannes Dölling\Desktop\JRT.txt 2014-01-15 13:02 - 2014-01-15 13:02 - 00000000 ____D C:\Windows\ERUNT 2014-01-15 13:00 - 2014-01-15 13:00 - 00006229 _____ C:\Users\Johannes Dölling\Desktop\AdwCleaner[S0].txt 2014-01-15 12:31 - 2014-01-15 12:31 - 00000000 ____D C:\Users\Johannes Dölling\AppData\Roaming\Malwarebytes 2014-01-15 12:30 - 2014-01-15 12:30 - 00000913 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-15 12:30 - 2014-01-15 12:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-15 12:30 - 2014-01-15 12:30 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2014-01-15 12:30 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-15 10:04 - 2014-01-15 10:04 - 02347384 _____ (ESET) C:\Users\Johannes Dölling\Desktop\esetsmartinstaller_enu.exe 2014-01-15 10:04 - 2014-01-15 10:04 - 00987410 _____ C:\Users\Johannes Dölling\Desktop\SecurityCheck.exe 2014-01-14 20:08 - 2014-01-15 12:55 - 00000000 ____D C:\AdwCleaner 2014-01-14 19:53 - 2014-01-14 19:53 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Johannes Dölling\Desktop\mbam-setup-1.75.0.1300.exe 2014-01-14 19:53 - 2014-01-14 19:53 - 01236282 _____ C:\Users\Johannes Dölling\Desktop\adwcleaner.exe 2014-01-14 19:53 - 2014-01-14 19:53 - 01037068 _____ (Thisisu) C:\Users\Johannes Dölling\Desktop\JRT.exe 2014-01-14 19:27 - 2014-01-15 12:47 - 00000982 _____ C:\Windows\PFRO.log 2014-01-14 19:17 - 2014-01-14 19:17 - 00128375 _____ C:\Users\Johannes Dölling\Desktop\combofix.txt 2014-01-14 19:15 - 2014-01-14 19:15 - 00128375 _____ C:\ComboFix.txt 2014-01-14 18:59 - 2014-01-14 19:15 - 00000000 ____D C:\Qoobox 2014-01-14 18:59 - 2014-01-14 19:15 - 00000000 ____D C:\ComboFix 2014-01-14 18:59 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-14 18:59 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-14 18:59 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-14 18:59 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-14 18:59 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-14 18:59 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-14 18:59 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-14 18:59 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-14 18:58 - 2014-01-14 19:14 - 00000000 ____D C:\Windows\erdnt 2014-01-14 18:57 - 2014-01-14 18:58 - 05165717 ____R (Swearware) C:\Users\Johannes Dölling\Desktop\ComboFix.exe 2014-01-14 18:22 - 2014-01-14 18:23 - 00134664 _____ C:\Windows\Minidump\Mini011414-01.dmp 2014-01-14 18:22 - 2014-01-14 18:22 - 243146244 _____ C:\Windows\MEMORY.DMP 2014-01-14 18:20 - 2014-01-14 18:20 - 00000634 _____ C:\Users\Johannes Dölling\Desktop\GMER.log 2014-01-14 17:40 - 2014-01-14 17:40 - 00062733 _____ C:\Users\Johannes Dölling\Desktop\Für alle Hilfesuchenden! Was muss ich vor der Eröffnung eines Themas beachten - Trojaner-Board.htm 2014-01-14 17:17 - 2014-01-14 17:17 - 00003202 _____ C:\Users\Johannes Dölling\Desktop\Ereignisse.txt 2014-01-14 16:59 - 2014-01-14 17:00 - 00000494 _____ C:\Users\Johannes Dölling\Desktop\defogger_disable.log 2014-01-14 16:59 - 2014-01-14 16:59 - 00000000 _____ C:\Users\Johannes Dölling\defogger_reenable 2014-01-14 16:14 - 2014-01-14 16:14 - 00377856 _____ C:\Users\Johannes Dölling\Desktop\6qc1tqbz.exe 2014-01-14 16:14 - 2014-01-14 16:14 - 00050477 _____ C:\Users\Johannes Dölling\Desktop\Defogger.exe 2014-01-14 15:48 - 2014-01-14 15:51 - 00035363 _____ C:\Users\Johannes Dölling\Desktop\Addition.txt 2014-01-14 15:46 - 2014-01-15 13:10 - 00016862 _____ C:\Users\Johannes Dölling\Desktop\FRST.txt 2014-01-14 15:45 - 2014-01-14 15:45 - 00000000 ____D C:\FRST 2014-01-14 15:44 - 2014-01-14 15:44 - 01219584 _____ (Farbar) C:\Users\Johannes Dölling\Desktop\FRST.exe 2014-01-12 15:08 - 2014-01-12 15:08 - 00943872 _____ C:\Users\Johannes Dölling\Downloads\Unlocker-Setup.exe 2014-01-12 14:45 - 2014-01-12 14:45 - 00218129 _____ C:\Users\Johannes Dölling\Downloads\h2testw_1.4.zip 2014-01-12 14:45 - 2014-01-12 14:45 - 00000000 ____D C:\Users\Johannes Dölling\Downloads\h2testw_1.4 2014-01-12 14:43 - 2014-01-12 14:43 - 00027125 _____ C:\Users\Johannes Dölling\Downloads\h2test16.zip 2014-01-12 14:43 - 2014-01-12 14:43 - 00000000 ____D C:\Users\Johannes Dölling\Downloads\h2test16 2014-01-11 15:40 - 2014-01-11 15:40 - 00098304 _____ (Hewlett-Packard Company) C:\Users\Johannes Dölling\Downloads\HPUSBFW_v2.2.3.exe 2014-01-08 16:12 - 2014-01-08 16:14 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\TEMP STICK 2013-12-20 09:57 - 2013-12-20 09:57 - 00000000 ____D C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2014-01-15 13:10 - 2014-01-14 15:46 - 00016862 _____ C:\Users\Johannes Dölling\Desktop\FRST.txt 2014-01-15 13:10 - 2009-02-27 14:10 - 00000440 ____H C:\Windows\Tasks\User_Feed_Synchronization-{A5623927-08F0-4775-B2C2-9E9464CC5961}.job 2014-01-15 13:09 - 2014-01-15 13:09 - 00001385 _____ C:\Users\Johannes Dölling\Desktop\JRT.txt 2014-01-15 13:02 - 2014-01-15 13:02 - 00000000 ____D C:\Windows\ERUNT 2014-01-15 13:02 - 2008-12-23 17:38 - 01565283 _____ C:\Windows\WindowsUpdate.log 2014-01-15 13:00 - 2014-01-15 13:00 - 00006229 _____ C:\Users\Johannes Dölling\Desktop\AdwCleaner[S0].txt 2014-01-15 13:00 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\tracing 2014-01-15 12:57 - 2009-12-26 13:36 - 00065536 _____ C:\Windows\system32\Ikeext.etl 2014-01-15 12:57 - 2009-03-01 17:12 - 00045056 _____ C:\Windows\system32\acovcnt.exe 2014-01-15 12:57 - 2006-11-02 13:47 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-15 12:57 - 2006-11-02 13:47 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-15 12:56 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-15 12:55 - 2014-01-14 20:08 - 00000000 ____D C:\AdwCleaner 2014-01-15 12:55 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-15 12:47 - 2014-01-14 19:27 - 00000982 _____ C:\Windows\PFRO.log 2014-01-15 12:47 - 2006-11-02 13:37 - 00000000 ____D C:\Windows\DigitalLocker 2014-01-15 12:35 - 2009-12-23 19:58 - 00001052 _____ C:\Windows\Tasks\Google Software Updater.job 2014-01-15 12:31 - 2014-01-15 12:31 - 00000000 ____D C:\Users\Johannes Dölling\AppData\Roaming\Malwarebytes 2014-01-15 12:30 - 2014-01-15 12:30 - 00000913 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-15 12:30 - 2014-01-15 12:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-15 12:30 - 2014-01-15 12:30 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2014-01-15 10:04 - 2014-01-15 10:04 - 02347384 _____ (ESET) C:\Users\Johannes Dölling\Desktop\esetsmartinstaller_enu.exe 2014-01-15 10:04 - 2014-01-15 10:04 - 00987410 _____ C:\Users\Johannes Dölling\Desktop\SecurityCheck.exe 2014-01-14 19:53 - 2014-01-14 19:53 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Johannes Dölling\Desktop\mbam-setup-1.75.0.1300.exe 2014-01-14 19:53 - 2014-01-14 19:53 - 01236282 _____ C:\Users\Johannes Dölling\Desktop\adwcleaner.exe 2014-01-14 19:53 - 2014-01-14 19:53 - 01037068 _____ (Thisisu) C:\Users\Johannes Dölling\Desktop\JRT.exe 2014-01-14 19:17 - 2014-01-14 19:17 - 00128375 _____ C:\Users\Johannes Dölling\Desktop\combofix.txt 2014-01-14 19:15 - 2014-01-14 19:15 - 00128375 _____ C:\ComboFix.txt 2014-01-14 19:15 - 2014-01-14 18:59 - 00000000 ____D C:\Qoobox 2014-01-14 19:15 - 2014-01-14 18:59 - 00000000 ____D C:\ComboFix 2014-01-14 19:15 - 2006-11-02 12:18 - 00000000 __RHD C:\Users\Default 2014-01-14 19:15 - 2006-11-02 12:18 - 00000000 ___RD C:\Users\Public 2014-01-14 19:14 - 2014-01-14 18:58 - 00000000 ____D C:\Windows\erdnt 2014-01-14 19:14 - 2006-11-02 11:23 - 00000215 _____ C:\Windows\system.ini 2014-01-14 18:58 - 2014-01-14 18:57 - 05165717 ____R (Swearware) C:\Users\Johannes Dölling\Desktop\ComboFix.exe 2014-01-14 18:23 - 2014-01-14 18:22 - 00134664 _____ C:\Windows\Minidump\Mini011414-01.dmp 2014-01-14 18:22 - 2014-01-14 18:22 - 243146244 _____ C:\Windows\MEMORY.DMP 2014-01-14 18:22 - 2010-07-03 13:04 - 00000000 ____D C:\Windows\Minidump 2014-01-14 18:20 - 2014-01-14 18:20 - 00000634 _____ C:\Users\Johannes Dölling\Desktop\GMER.log 2014-01-14 17:40 - 2014-01-14 17:40 - 00062733 _____ C:\Users\Johannes Dölling\Desktop\Für alle Hilfesuchenden! Was muss ich vor der Eröffnung eines Themas beachten - Trojaner-Board.htm 2014-01-14 17:17 - 2014-01-14 17:17 - 00003202 _____ C:\Users\Johannes Dölling\Desktop\Ereignisse.txt 2014-01-14 17:00 - 2014-01-14 16:59 - 00000494 _____ C:\Users\Johannes Dölling\Desktop\defogger_disable.log 2014-01-14 16:59 - 2014-01-14 16:59 - 00000000 _____ C:\Users\Johannes Dölling\defogger_reenable 2014-01-14 16:59 - 2009-02-27 13:51 - 00000000 ____D C:\Users\Johannes Dölling 2014-01-14 16:14 - 2014-01-14 16:14 - 00377856 _____ C:\Users\Johannes Dölling\Desktop\6qc1tqbz.exe 2014-01-14 16:14 - 2014-01-14 16:14 - 00050477 _____ C:\Users\Johannes Dölling\Desktop\Defogger.exe 2014-01-14 15:51 - 2014-01-14 15:48 - 00035363 _____ C:\Users\Johannes Dölling\Desktop\Addition.txt 2014-01-14 15:45 - 2014-01-14 15:45 - 00000000 ____D C:\FRST 2014-01-14 15:44 - 2014-01-14 15:44 - 01219584 _____ (Farbar) C:\Users\Johannes Dölling\Desktop\FRST.exe 2014-01-14 10:37 - 2011-06-26 20:25 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\HUHU 2014-01-14 10:36 - 2011-10-25 13:22 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\Stuhudium 2014-01-14 10:36 - 2011-05-21 15:22 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\neo 2014-01-14 10:35 - 2010-11-18 19:26 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\André Arbeit 2014-01-14 10:25 - 2013-06-25 11:51 - 00000000 ____D C:\Users\Johannes Dölling\AppData\Roaming\Dropbox 2014-01-13 00:26 - 2012-09-19 20:37 - 00000000 ____D C:\Users\Johannes Dölling\AppData\Roaming\vlc 2014-01-12 15:08 - 2014-01-12 15:08 - 00943872 _____ C:\Users\Johannes Dölling\Downloads\Unlocker-Setup.exe 2014-01-12 14:45 - 2014-01-12 14:45 - 00218129 _____ C:\Users\Johannes Dölling\Downloads\h2testw_1.4.zip 2014-01-12 14:45 - 2014-01-12 14:45 - 00000000 ____D C:\Users\Johannes Dölling\Downloads\h2testw_1.4 2014-01-12 14:43 - 2014-01-12 14:43 - 00027125 _____ C:\Users\Johannes Dölling\Downloads\h2test16.zip 2014-01-12 14:43 - 2014-01-12 14:43 - 00000000 ____D C:\Users\Johannes Dölling\Downloads\h2test16 2014-01-11 15:46 - 2009-03-01 17:14 - 00000680 _____ C:\Users\Johannes Dölling\AppData\Local\d3d9caps.dat 2014-01-11 15:40 - 2014-01-11 15:40 - 00098304 _____ (Hewlett-Packard Company) C:\Users\Johannes Dölling\Downloads\HPUSBFW_v2.2.3.exe 2014-01-11 00:19 - 2006-11-02 11:33 - 01418806 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-11 00:12 - 2009-02-27 18:05 - 00097280 _____ C:\Users\Johannes Dölling\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-01-08 16:14 - 2014-01-08 16:12 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\TEMP STICK 2014-01-06 22:29 - 2010-01-13 16:04 - 00000000 ____D C:\Users\Johannes Dölling\AppData\Roaming\Skype 2014-01-06 20:47 - 2009-06-17 13:54 - 00000000 ____D C:\Users\Johannes Dölling\AppData\Roaming\skypePM 2013-12-31 17:42 - 2012-11-13 20:38 - 00000000 ____D C:\Users\Johannes Dölling\AppData\Roaming\Mp3tag 2013-12-27 19:12 - 2010-09-09 22:55 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\Arbeit Franzi 2013-12-21 17:07 - 2012-05-07 21:45 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-12-20 09:57 - 2013-12-20 09:57 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-12-19 14:45 - 2013-09-03 16:22 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\Ripped 2013-12-17 15:40 - 2013-08-05 21:43 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-12-17 15:40 - 2013-08-05 21:43 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-12-17 10:43 - 2013-12-10 10:57 - 00011871 _____ C:\Users\Johannes Dölling\Documents\Kautionsverzicht.odt Files to move or delete: ==================== C:\Users\Johannes Dölling\AppData\Roaming\desktop.ini Some content of TEMP: ==================== C:\Users\Johannes Dölling\AppData\Local\temp\avgnt.exe C:\Users\Johannes Dölling\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-15 13:04 ==================== End Of Log ============================ --- --- --- --- --- --- |
16.01.2014, 08:38 | #7 |
/// the machine /// TB-Ausbilder | BKA Sperrfenster - Vista - weitere VirenfundeESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.01.2014, 12:50 | #8 |
| BKA Sperrfenster - Vista - weitere Virenfunde Soweit alles erledigt: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=6c17d887ce4eb04580939b3fc4f9748b # engine=16670 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-16 10:38:03 # local_time=2014-01-16 11:38:03 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=1799 16775165 100 95 7809 135639167 3787 0 # compatibility_mode=5892 16776574 100 100 13544865 227401411 0 0 # scanned=206959 # found=1 # cleaned=0 # scan_time=5862 sh=094FF3D3AE313F640D44B8A44D7CBCE8AC2D3E23 ft=1 fh=13b4713adb041630 vn="multiple threats" ac=I fn="G:\System Volume Information\_restore{FD4B6D3A-53C8-49CA-A734-B08F5C2CB81C}\RP954\A0143057.exe" Code:
ATTFilter Results of screen317's Security Check version 0.99.78 Windows Vista Service Pack 2 x86 (UAC is enabled) Internet Explorer 8 Out of date! Internet Explorer 8 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` CloneSpy 2.63 Malwarebytes Anti-Malware Version 1.75.0.1300 CCleaner JavaFX 2.1.1 Java 7 Update 45 Adobe Flash Player 10 Flash Player out of Date! Adobe Flash Player 11.9.900.170 Adobe Reader 9 Adobe Reader out of Date! Mozilla Firefox (26.0) Google Chrome 31.0.1650.57 Google Chrome 31.0.1650.63 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-01-2014 03 Ran by Johannes Dölling (administrator) on FRANZISKA on 16-01-2014 12:46:20 Running from C:\Users\Johannes Dölling\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) =================== (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe () C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe () C:\Program Files\ATK Hotkey\ASLDRSrv.exe () C:\Program Files\ATKGFNEX\GFNEXSrv.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (ATK0100) C:\Program Files\ATK Hotkey\HControl.exe () C:\Program Files\ATKOSD2\ATKOSD2.exe () C:\Program Files\Wireless Console 2\wcourier.exe (ASUS) C:\Program Files\ASUS\ASUS CopyProtect\ASPG.exe (ATK) C:\Program Files\P4G\BatteryLife.exe (ATK) C:\Program Files\ASUS\Splendid\ACMON.exe () C:\Program Files\ASUS\ASUS Live Update\ALU.exe (ASUSTeK) C:\Windows\System32\ACEngSvr.exe (ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (UASSOFT.COM) C:\Programme\Mouse Driver\KMWDSrv.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe () D:\CDBurnerXP\NMSAccessU.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe () C:\Program Files\ATK Hotkey\ATKOSD.exe () C:\Windows\System32\PSIService.exe (Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe () C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe () C:\Program Files\ATK Hotkey\KBFiltr.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ASUS) C:\Program Files\ASUS\ATK Media\DMedia.exe (ASUS) C:\Windows\System32\ASUSTPE.exe () C:\Windows\ASScrPro.exe (UASSOFT.COM) C:\Programme\Mouse Driver\StartAutorun.exe (UASSOFT.COM) C:\Programme\Mouse Driver\KMCONFIG.exe (UASSOFT.COM) C:\Programme\Mouse Driver\KMProcess.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe () C:\Program Files\Mobile Partner\Mobile Partner.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe () D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090908-0900\soffice.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Google Inc.) C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-01-21] (Advanced Micro Devices, Inc.) HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4853760 2008-01-07] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-12-06] (Synaptics, Inc.) HKLM\...\Run: [ATKMEDIA] - C:\Program Files\ASUS\ATK Media\DMedia.exe [159744 2008-06-25] (ASUS) HKLM\...\Run: [ASUSTPE] - C:\Windows\system32\ASUSTPE.exe [106496 2007-10-12] (ASUS) HKLM\...\Run: [ASUS Camera ScreenSaver] - C:\Windows\AsScrProlog.exe [47672 2008-12-23] () HKLM\...\Run: [ASUS Screen Saver Protector] - C:\Windows\ASScrPro.exe [33136 2008-12-23] () HKLM\...\Run: [KMCONFIG] - C:\Programme\Mouse Driver\StartAutorun.exe KMConfig.exe HKLM\...\Run: [Adobe Reader Speed Launcher] - D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-17] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2008-12-23] (Google Inc.) HKCU\...\Run: [Mobile Partner] - C:\Program Files\Mobile Partner\Mobile Partner.exe [114688 2008-12-03] () HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [SODCPreLoad] - D:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090908-0900\preload.exe [40960 2009-11-04] () HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\system32\oobefldr.dll [ 2009-04-10] (Microsoft Corporation) HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\system32\oobefldr.dll [ 2009-04-10] (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.live.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUS_deDE316 BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - No Name - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - No File Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\..\Interfaces\{8A08AC01-849F-4B73-A414-6262E9CA0755}: [NameServer]212.23.115.150 212.23.115.132 FireFox: ======== FF ProfilePath: C:\Users\Johannes Dölling\AppData\Roaming\Mozilla\Firefox\Profiles\iwu6igek.default FF SearchEngineOrder.1: Ask.com FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @google.com/npPicasa2,version=2.0.0 - C:\Program Files\Picasa2\npPicasa2.dll No File FF Plugin: @google.com/npPicasa3,version=3.0.0 - D:\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google) FF Plugin: @videolan.org/vlc,version=2.0.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - D:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Johannes Dölling\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Johannes Dölling\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Johannes Dölling\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Microsoft .NET Framework Assistant - C:\Users\Johannes Dölling\AppData\Roaming\Mozilla\Firefox\Profiles\iwu6igek.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-07-07] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Johannes D\u00F6lling\AppData\Local\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Users\Johannes D\u00F6lling\AppData\Local\Google\Chrome\Application\31.0.1650.63\pdf.dll No File CHR Plugin: (Shockwave Flash) - C:\Users\Johannes D\u00F6lling\AppData\Local\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) CHR Plugin: (Google Updater) - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google) CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\3.0.50106.0\npctrl.dll No File CHR Plugin: (Unity Player) - C:\Users\Johannes D\u00F6lling\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File CHR Plugin: (Google Update) - C:\Users\Johannes D\u00F6lling\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Plugin: (Picasa) - D:\Picasa3\npPicasa3.dll (Google, Inc.) CHR Extension: (YouTube) - C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 [2013-04-10] CHR Extension: (Google Search) - C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 [2013-03-28] CHR Extension: (AdBlock) - C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.18_0 [2014-01-14] CHR Extension: (Google Wallet) - C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 [2013-12-19] CHR Extension: (Gmail) - C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 [2012-11-10] CHR StartMenuInternet: Google Chrome - C:\Users\Johannes Dölling\AppData\Local\Google\Chrome\Application\chrome.exe ========================== Services (Whitelisted) ================= R2 ADSMService; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [73728 2007-05-18] () R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-17] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-28] (Avira Operations GmbH & Co. KG) R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-02-06] () R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () R2 KMWDSERVICE; C:\Programme\Mouse Driver\KMWDSrv.exe [1821696 2009-10-09] (UASSOFT.COM) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NMSAccessU; D:\CDBurnerXP\NMSAccessU.exe [71096 2008-10-20] () R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] () R2 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] () ==================== Drivers (Whitelisted) ==================== R3 Afc; C:\Windows\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.) R0 AsDsm; C:\Windows\System32\Drivers\AsDsm.sys [29752 2007-08-11] (Windows (R) Codename Longhorn DDK provider) R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-28] (Avira Operations GmbH & Co. KG) R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [20936 2007-08-03] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15928 2008-06-03] ( ) R3 KMWDFILTERx86; C:\Windows\System32\DRIVERS\KMWDFILTER.sys [22144 2009-10-09] (Windows (R) Codename Longhorn DDK provider) R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15416 2008-05-29] (Windows (R) Codename Longhorn DDK provider) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100) S3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [14736 2009-05-09] (Microsoft Corporation) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1772544 2008-05-22] () R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-05] (Avira GmbH) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S3 AtiDCM; \??\E:\VGA\Bin\atidcmxx.sys [x] S3 catchme; \??\C:\Users\JOHANN~1\AppData\Local\Temp\catchme.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 Point32; system32\DRIVERS\point32k.sys [x] S3 USBAAPL; System32\Drivers\usbaapl.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-16 12:46 - 2014-01-16 12:46 - 00017776 _____ C:\Users\Johannes Dölling\Desktop\FRST.txt 2014-01-16 12:45 - 2014-01-16 12:45 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\FRST-OlderVersion 2014-01-16 12:44 - 2014-01-16 12:44 - 00001223 _____ C:\Users\Johannes Dölling\Desktop\checkup.txt 2014-01-16 12:29 - 2014-01-16 12:29 - 00001260 _____ C:\Users\Johannes Dölling\Desktop\checkup1st.txt 2014-01-15 15:01 - 2014-01-15 15:01 - 00707006 _____ C:\Users\Johannes Dölling\Desktop\delfix.exe 2014-01-15 14:10 - 2012-06-02 23:19 - 01933848 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-01-15 14:10 - 2012-06-02 23:19 - 00053784 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-01-15 14:10 - 2012-06-02 23:19 - 00045080 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2014-01-15 14:10 - 2012-06-02 23:12 - 02422272 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-01-15 14:09 - 2012-06-02 23:19 - 00577048 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-01-15 14:09 - 2012-06-02 23:19 - 00035864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2014-01-15 14:09 - 2012-06-02 23:12 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-01-15 14:09 - 2012-06-02 15:19 - 00171904 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-01-15 14:09 - 2012-06-02 15:12 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-01-15 14:04 - 2014-01-15 14:04 - 00000000 _____ C:\Windows\setuperr.log 2014-01-15 14:04 - 2014-01-15 14:04 - 00000000 _____ C:\Windows\setupact.log 2014-01-15 13:09 - 2014-01-15 13:09 - 00001385 _____ C:\Users\Johannes Dölling\Desktop\JRT.txt 2014-01-15 13:02 - 2014-01-15 13:02 - 00000000 ____D C:\Windows\ERUNT 2014-01-15 13:00 - 2014-01-15 13:00 - 00006229 _____ C:\Users\Johannes Dölling\Desktop\AdwCleaner[S0].txt 2014-01-15 12:31 - 2014-01-15 12:31 - 00000000 ____D C:\Users\Johannes Dölling\AppData\Roaming\Malwarebytes 2014-01-15 12:30 - 2014-01-15 12:30 - 00000913 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-15 12:30 - 2014-01-15 12:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-15 12:30 - 2014-01-15 12:30 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2014-01-15 12:30 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-15 10:04 - 2014-01-15 10:04 - 02347384 _____ (ESET) C:\Users\Johannes Dölling\Desktop\esetsmartinstaller_enu.exe 2014-01-15 10:04 - 2014-01-15 10:04 - 00987410 _____ C:\Users\Johannes Dölling\Desktop\SecurityCheck.exe 2014-01-14 20:08 - 2014-01-15 12:55 - 00000000 ____D C:\AdwCleaner 2014-01-14 19:53 - 2014-01-14 19:53 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Johannes Dölling\Desktop\mbam-setup-1.75.0.1300.exe 2014-01-14 19:53 - 2014-01-14 19:53 - 01236282 _____ C:\Users\Johannes Dölling\Desktop\adwcleaner.exe 2014-01-14 19:53 - 2014-01-14 19:53 - 01037068 _____ (Thisisu) C:\Users\Johannes Dölling\Desktop\JRT.exe 2014-01-14 19:27 - 2014-01-15 12:47 - 00000982 _____ C:\Windows\PFRO.log 2014-01-14 19:17 - 2014-01-14 19:17 - 00128375 _____ C:\Users\Johannes Dölling\Desktop\combofix.txt 2014-01-14 19:15 - 2014-01-14 19:15 - 00128375 _____ C:\ComboFix.txt 2014-01-14 18:59 - 2014-01-14 19:15 - 00000000 ____D C:\Qoobox 2014-01-14 18:59 - 2014-01-14 19:15 - 00000000 ____D C:\ComboFix 2014-01-14 18:59 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-14 18:59 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-14 18:59 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-14 18:59 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-14 18:59 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-14 18:59 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-14 18:59 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-14 18:59 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-14 18:58 - 2014-01-14 19:14 - 00000000 ____D C:\Windows\erdnt 2014-01-14 18:57 - 2014-01-14 18:58 - 05165717 ____R (Swearware) C:\Users\Johannes Dölling\Desktop\ComboFix.exe 2014-01-14 18:22 - 2014-01-14 18:23 - 00134664 _____ C:\Windows\Minidump\Mini011414-01.dmp 2014-01-14 18:22 - 2014-01-14 18:22 - 243146244 _____ C:\Windows\MEMORY.DMP 2014-01-14 18:20 - 2014-01-14 18:20 - 00000634 _____ C:\Users\Johannes Dölling\Desktop\GMER.log 2014-01-14 17:40 - 2014-01-14 17:40 - 00062733 _____ C:\Users\Johannes Dölling\Desktop\Für alle Hilfesuchenden! Was muss ich vor der Eröffnung eines Themas beachten - Trojaner-Board.htm 2014-01-14 17:17 - 2014-01-14 17:17 - 00003202 _____ C:\Users\Johannes Dölling\Desktop\Ereignisse.txt 2014-01-14 16:59 - 2014-01-14 17:00 - 00000494 _____ C:\Users\Johannes Dölling\Desktop\defogger_disable.log 2014-01-14 16:59 - 2014-01-14 16:59 - 00000000 _____ C:\Users\Johannes Dölling\defogger_reenable 2014-01-14 16:14 - 2014-01-14 16:14 - 00377856 _____ C:\Users\Johannes Dölling\Desktop\6qc1tqbz.exe 2014-01-14 16:14 - 2014-01-14 16:14 - 00050477 _____ C:\Users\Johannes Dölling\Desktop\Defogger.exe 2014-01-14 15:48 - 2014-01-14 15:51 - 00035363 _____ C:\Users\Johannes Dölling\Desktop\Addition.txt 2014-01-14 15:45 - 2014-01-16 12:45 - 00000000 ____D C:\FRST 2014-01-14 15:44 - 2014-01-16 12:45 - 01221120 _____ (Farbar) C:\Users\Johannes Dölling\Desktop\FRST.exe 2014-01-12 15:08 - 2014-01-12 15:08 - 00943872 _____ C:\Users\Johannes Dölling\Downloads\Unlocker-Setup.exe 2014-01-12 14:45 - 2014-01-12 14:45 - 00218129 _____ C:\Users\Johannes Dölling\Downloads\h2testw_1.4.zip 2014-01-12 14:45 - 2014-01-12 14:45 - 00000000 ____D C:\Users\Johannes Dölling\Downloads\h2testw_1.4 2014-01-12 14:43 - 2014-01-12 14:43 - 00027125 _____ C:\Users\Johannes Dölling\Downloads\h2test16.zip 2014-01-12 14:43 - 2014-01-12 14:43 - 00000000 ____D C:\Users\Johannes Dölling\Downloads\h2test16 2014-01-11 15:40 - 2014-01-11 15:40 - 00098304 _____ (Hewlett-Packard Company) C:\Users\Johannes Dölling\Downloads\HPUSBFW_v2.2.3.exe 2014-01-08 16:12 - 2014-01-08 16:14 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\TEMP STICK 2013-12-20 09:57 - 2013-12-20 09:57 - 00000000 ____D C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2014-01-16 12:46 - 2014-01-16 12:46 - 00017776 _____ C:\Users\Johannes Dölling\Desktop\FRST.txt 2014-01-16 12:45 - 2014-01-16 12:45 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\FRST-OlderVersion 2014-01-16 12:45 - 2014-01-14 15:45 - 00000000 ____D C:\FRST 2014-01-16 12:45 - 2014-01-14 15:44 - 01221120 _____ (Farbar) C:\Users\Johannes Dölling\Desktop\FRST.exe 2014-01-16 12:45 - 2009-02-27 14:10 - 00000440 ____H C:\Windows\Tasks\User_Feed_Synchronization-{A5623927-08F0-4775-B2C2-9E9464CC5961}.job 2014-01-16 12:44 - 2014-01-16 12:44 - 00001223 _____ C:\Users\Johannes Dölling\Desktop\checkup.txt 2014-01-16 12:30 - 2008-12-23 17:38 - 01610111 _____ C:\Windows\WindowsUpdate.log 2014-01-16 12:29 - 2014-01-16 12:29 - 00001260 _____ C:\Users\Johannes Dölling\Desktop\checkup1st.txt 2014-01-16 12:22 - 2006-11-02 11:33 - 01418806 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-16 11:28 - 2006-11-02 13:47 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-16 11:28 - 2006-11-02 13:47 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-16 09:29 - 2009-03-01 17:12 - 00045056 _____ C:\Windows\system32\acovcnt.exe 2014-01-16 09:28 - 2009-12-26 13:36 - 00065536 _____ C:\Windows\system32\Ikeext.etl 2014-01-16 09:28 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-16 01:58 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-16 01:31 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\tracing 2014-01-15 17:35 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\rescache 2014-01-15 17:16 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\de-DE 2014-01-15 15:01 - 2014-01-15 15:01 - 00707006 _____ C:\Users\Johannes Dölling\Desktop\delfix.exe 2014-01-15 14:04 - 2014-01-15 14:04 - 00000000 _____ C:\Windows\setuperr.log 2014-01-15 14:04 - 2014-01-15 14:04 - 00000000 _____ C:\Windows\setupact.log 2014-01-15 13:09 - 2014-01-15 13:09 - 00001385 _____ C:\Users\Johannes Dölling\Desktop\JRT.txt 2014-01-15 13:02 - 2014-01-15 13:02 - 00000000 ____D C:\Windows\ERUNT 2014-01-15 13:00 - 2014-01-15 13:00 - 00006229 _____ C:\Users\Johannes Dölling\Desktop\AdwCleaner[S0].txt 2014-01-15 12:55 - 2014-01-14 20:08 - 00000000 ____D C:\AdwCleaner 2014-01-15 12:47 - 2014-01-14 19:27 - 00000982 _____ C:\Windows\PFRO.log 2014-01-15 12:47 - 2006-11-02 13:37 - 00000000 ____D C:\Windows\DigitalLocker 2014-01-15 12:35 - 2009-12-23 19:58 - 00001052 _____ C:\Windows\Tasks\Google Software Updater.job 2014-01-15 12:31 - 2014-01-15 12:31 - 00000000 ____D C:\Users\Johannes Dölling\AppData\Roaming\Malwarebytes 2014-01-15 12:30 - 2014-01-15 12:30 - 00000913 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-15 12:30 - 2014-01-15 12:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-15 12:30 - 2014-01-15 12:30 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2014-01-15 10:04 - 2014-01-15 10:04 - 02347384 _____ (ESET) C:\Users\Johannes Dölling\Desktop\esetsmartinstaller_enu.exe 2014-01-15 10:04 - 2014-01-15 10:04 - 00987410 _____ C:\Users\Johannes Dölling\Desktop\SecurityCheck.exe 2014-01-14 19:53 - 2014-01-14 19:53 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Johannes Dölling\Desktop\mbam-setup-1.75.0.1300.exe 2014-01-14 19:53 - 2014-01-14 19:53 - 01236282 _____ C:\Users\Johannes Dölling\Desktop\adwcleaner.exe 2014-01-14 19:53 - 2014-01-14 19:53 - 01037068 _____ (Thisisu) C:\Users\Johannes Dölling\Desktop\JRT.exe 2014-01-14 19:17 - 2014-01-14 19:17 - 00128375 _____ C:\Users\Johannes Dölling\Desktop\combofix.txt 2014-01-14 19:15 - 2014-01-14 19:15 - 00128375 _____ C:\ComboFix.txt 2014-01-14 19:15 - 2014-01-14 18:59 - 00000000 ____D C:\Qoobox 2014-01-14 19:15 - 2014-01-14 18:59 - 00000000 ____D C:\ComboFix 2014-01-14 19:15 - 2006-11-02 12:18 - 00000000 __RHD C:\Users\Default 2014-01-14 19:15 - 2006-11-02 12:18 - 00000000 ___RD C:\Users\Public 2014-01-14 19:14 - 2014-01-14 18:58 - 00000000 ____D C:\Windows\erdnt 2014-01-14 19:14 - 2006-11-02 11:23 - 00000215 _____ C:\Windows\system.ini 2014-01-14 18:58 - 2014-01-14 18:57 - 05165717 ____R (Swearware) C:\Users\Johannes Dölling\Desktop\ComboFix.exe 2014-01-14 18:23 - 2014-01-14 18:22 - 00134664 _____ C:\Windows\Minidump\Mini011414-01.dmp 2014-01-14 18:22 - 2014-01-14 18:22 - 243146244 _____ C:\Windows\MEMORY.DMP 2014-01-14 18:22 - 2010-07-03 13:04 - 00000000 ____D C:\Windows\Minidump 2014-01-14 18:20 - 2014-01-14 18:20 - 00000634 _____ C:\Users\Johannes Dölling\Desktop\GMER.log 2014-01-14 17:40 - 2014-01-14 17:40 - 00062733 _____ C:\Users\Johannes Dölling\Desktop\Für alle Hilfesuchenden! Was muss ich vor der Eröffnung eines Themas beachten - Trojaner-Board.htm 2014-01-14 17:17 - 2014-01-14 17:17 - 00003202 _____ C:\Users\Johannes Dölling\Desktop\Ereignisse.txt 2014-01-14 17:00 - 2014-01-14 16:59 - 00000494 _____ C:\Users\Johannes Dölling\Desktop\defogger_disable.log 2014-01-14 16:59 - 2014-01-14 16:59 - 00000000 _____ C:\Users\Johannes Dölling\defogger_reenable 2014-01-14 16:59 - 2009-02-27 13:51 - 00000000 ____D C:\Users\Johannes Dölling 2014-01-14 16:14 - 2014-01-14 16:14 - 00377856 _____ C:\Users\Johannes Dölling\Desktop\6qc1tqbz.exe 2014-01-14 16:14 - 2014-01-14 16:14 - 00050477 _____ C:\Users\Johannes Dölling\Desktop\Defogger.exe 2014-01-14 15:51 - 2014-01-14 15:48 - 00035363 _____ C:\Users\Johannes Dölling\Desktop\Addition.txt 2014-01-14 10:37 - 2011-06-26 20:25 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\HUHU 2014-01-14 10:36 - 2011-10-25 13:22 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\Stuhudium 2014-01-14 10:36 - 2011-05-21 15:22 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\neo 2014-01-14 10:35 - 2010-11-18 19:26 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\André Arbeit 2014-01-14 10:25 - 2013-06-25 11:51 - 00000000 ____D C:\Users\Johannes Dölling\AppData\Roaming\Dropbox 2014-01-13 00:26 - 2012-09-19 20:37 - 00000000 ____D C:\Users\Johannes Dölling\AppData\Roaming\vlc 2014-01-12 15:08 - 2014-01-12 15:08 - 00943872 _____ C:\Users\Johannes Dölling\Downloads\Unlocker-Setup.exe 2014-01-12 14:45 - 2014-01-12 14:45 - 00218129 _____ C:\Users\Johannes Dölling\Downloads\h2testw_1.4.zip 2014-01-12 14:45 - 2014-01-12 14:45 - 00000000 ____D C:\Users\Johannes Dölling\Downloads\h2testw_1.4 2014-01-12 14:43 - 2014-01-12 14:43 - 00027125 _____ C:\Users\Johannes Dölling\Downloads\h2test16.zip 2014-01-12 14:43 - 2014-01-12 14:43 - 00000000 ____D C:\Users\Johannes Dölling\Downloads\h2test16 2014-01-11 15:46 - 2009-03-01 17:14 - 00000680 _____ C:\Users\Johannes Dölling\AppData\Local\d3d9caps.dat 2014-01-11 15:40 - 2014-01-11 15:40 - 00098304 _____ (Hewlett-Packard Company) C:\Users\Johannes Dölling\Downloads\HPUSBFW_v2.2.3.exe 2014-01-11 00:12 - 2009-02-27 18:05 - 00097280 _____ C:\Users\Johannes Dölling\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-01-08 16:14 - 2014-01-08 16:12 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\TEMP STICK 2014-01-06 22:29 - 2010-01-13 16:04 - 00000000 ____D C:\Users\Johannes Dölling\AppData\Roaming\Skype 2014-01-06 20:47 - 2009-06-17 13:54 - 00000000 ____D C:\Users\Johannes Dölling\AppData\Roaming\skypePM 2013-12-31 17:42 - 2012-11-13 20:38 - 00000000 ____D C:\Users\Johannes Dölling\AppData\Roaming\Mp3tag 2013-12-27 19:12 - 2010-09-09 22:55 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\Arbeit Franzi 2013-12-21 17:07 - 2012-05-07 21:45 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-12-20 09:57 - 2013-12-20 09:57 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-12-19 14:45 - 2013-09-03 16:22 - 00000000 ____D C:\Users\Johannes Dölling\Desktop\Ripped 2013-12-17 15:40 - 2013-08-05 21:43 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-12-17 15:40 - 2013-08-05 21:43 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-12-17 10:43 - 2013-12-10 10:57 - 00011871 _____ C:\Users\Johannes Dölling\Documents\Kautionsverzicht.odt Files to move or delete: ==================== C:\Users\Johannes Dölling\AppData\Roaming\desktop.ini Some content of TEMP: ==================== C:\Users\Johannes Dölling\AppData\Local\temp\avgnt.exe C:\Users\Johannes Dölling\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-16 09:34 ==================== End Of Log ============================ --- --- --- --- --- --- ESET hat was auf meiner externen Platte gefunden. Wie wird da jetzt weiter verfahren? Ach und mir ist aufgefallen, das sich MBAM mit den Standardeinstellungen als PRO-14-Tage-Testversion installiert und sich automatisch mit Windows startet. So läuft auch der Dateisystemschutz im Hintergrund. Muß der auch für Scans deaktiviert sein (ESET zum Beispiel)??? Gruß Gumminmann |
17.01.2014, 12:01 | #9 |
/// the machine /// TB-Ausbilder | BKA Sperrfenster - Vista - weitere Virenfunde FLash, Adobe und Windows updaten. MBAM passt so, brauchte nit ausstellen. ESET Fund entfernen wir mit Delfix. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Users\Johannes Dölling\AppData\Roaming\desktop.ini Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.01.2014, 14:54 | #10 |
| BKA Sperrfenster - Vista - weitere Virenfunde Hallo, der Fix mit FRST hat funktioniert, allerdings wurde die Fixlog.txt mit gelöscht, daher kann ich sie nicht posten. Die Datei auf der externen Platte, die von ESET beanstandet wurde, wurde jedoch NICHT von DelFix beseitigt. Soll ich die jetzt manuell löschen? Gruß Gummimann |
18.01.2014, 07:35 | #11 |
/// the machine /// TB-Ausbilder | BKA Sperrfenster - Vista - weitere Virenfunde genau, manuell löschen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
18.01.2014, 20:22 | #12 |
| BKA Sperrfenster - Vista - weitere Virenfunde Okay, damit wäre alles erledigt, denke ich. Danke für deine Hilfe schrauber. +Gummimann |
19.01.2014, 10:43 | #13 |
/// the machine /// TB-Ausbilder | BKA Sperrfenster - Vista - weitere Virenfunde Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu BKA Sperrfenster - Vista - weitere Virenfunde |
4d36e972-e325-11ce-bfc1-08002be10318, adblock, adware.adon, avira, cdburnerxp, device driver, downloader, exp/cve-2010-3544, flash player, homepage, installation, java/lamar.djg.10, java/lamar.dld.33, malware, mozilla, programm, realtek, registry, required, secunia psi, software, svchost.exe, symantec, vista, windows |