|
Log-Analyse und Auswertung: Rechner hakt und hat AussetzerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
01.02.2014, 19:46 | #1 |
| Rechner hakt und hat Aussetzer Hallo, eigentlich ist mein Problem nicht sonderlicht dramatisch, da ich jedoch sensible Daten auf meinem Rechner habe, möchte ich gern mein System mit Eurer Hilfe prüfen. Es wäre nett, wenn sich jemand von Euch meine Logfiles anschauen könnte. Vielen Dank! Problembeschreibung: Seit einige Tagen hakt der Rechner manchmal (Windows 7) und hat Aussetzer, so dass er für 30-60 Sekunden auf keine Eingabe reagiert. Manchmal setzt sogar die Maus aus, was dann den Eindruck erweckt, als hätte sicher der Rechner aufgehängt. Das ganze passiert relativ selten, aber immer mal wieder. Nach einigen Sekunden geht's dann aber wieder. Auch lädt der Browser, also die Anwendung an sich, manchmal ziemlich langsam. Der Virenscanner (Avira) hat keine auffälligen Dateien gefunden. Logfiles defogger_disable.log Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 18:49 on 01/02/2014 (tcee) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- FRST.log FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2014 03 Ran by benutzername (administrator) on benutzername-THINK on 01-02-2014 18:52:31 Running from C:\Users\benutzername\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CamMute.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (FileHippo.com) C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Lenovo) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe (Lenovo Group Limited) C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ForteConfig] - C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] () HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2011-03-14] (Conexant systems, Inc.) HKLM\...\Run: [LENOVO.TPKNRRES] - C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [60920 2013-05-29] (Lenovo Group Limited) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated) HKLM-x32\...\Run: [PWMTRV] - rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-17] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-01-20] (Apple Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1502850821-2927420759-2148834354-1001\...\Run: [AdobeBridge] - [x] HKU\S-1-5-21-1502850821-2927420759-2148834354-1001\...\Run: [FileHippo.com] - C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe [307712 2012-11-23] (FileHippo.com) AppInit_DLLs: C:\Windows\System32\nvinitx.dll,C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [245872 2013-11-15] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [201576 2013-11-15] (NVIDIA Corporation) Lsa: [Notification Packages] scecli ACGina ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com/welcome/thinkpad SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENP SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENP BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.) DPF: HKLM-x32 {12193C65-F0E1-4DD1-AD4E-DB73C6911011} file:///H:/Mydlink/activeX/DCP.cab DPF: HKLM-x32 {7191F0AC-D686-46A8-BFCC-EA61778C74DD} file:///H:/Mydlink/activeX/aplugLiteDL.cab Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101714.dll (Amazon.com, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Default Full Zoom Level - C:\Users\benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default\Extensions\{D9A7CBEC-DE1A-444f-A092-844461596C4D} [2013-05-28] FF Extension: Firebug - C:\Users\benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default\Extensions\firebug@software.joehewitt.com.xpi [2012-05-06] FF Extension: NoScript - C:\Users\benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2012-08-22] FF Extension: MeasureIt - C:\Users\benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default\Extensions\{75CEEE46-9B64-46f8-94BF-54012DE155F0}.xpi [2012-07-09] FF HKLM-x32\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ [] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-17] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-14] (Avira Operations GmbH & Co. KG) S4 bckwfs; C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe [2649840 2013-03-01] (Blue Coat Systems, Inc.) R2 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [218112 2013-08-20] () S4 DozeSvc; C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [478056 2012-02-27] (Lenovo.) S4 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [133992 2011-07-12] (Lenovo Group Limited) S4 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [30184 2013-08-08] () S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-02-08] () S4 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22376 2013-06-26] () R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3386608 2013-02-08] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG) R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [284448 2013-11-15] (NVIDIA Corporation) R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [41536 2009-09-24] (Lenovo (United States) Inc.) S2 bckd; system32\drivers\bckd.sys [x] S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-01 18:52 - 2014-02-01 18:53 - 00014337 _____ () C:\Users\benutzername\Desktop\FRST.txt 2014-02-01 18:52 - 2014-02-01 18:52 - 00000000 ____D () C:\FRST 2014-02-01 18:50 - 2014-02-01 18:50 - 00000022 _____ () C:\Windows\S.dirmngr 2014-02-01 18:49 - 2014-02-01 18:49 - 00000470 _____ () C:\Users\benutzername\Desktop\defogger_disable.log 2014-02-01 14:36 - 2014-02-01 14:36 - 00380416 _____ () C:\Users\benutzername\Desktop\Gmer-19357.exe 2014-02-01 14:34 - 2014-02-01 14:34 - 02080256 _____ (Farbar) C:\Users\benutzername\Desktop\FRST64.exe 2014-02-01 14:33 - 2014-02-01 14:34 - 00050477 _____ () C:\Users\benutzername\Desktop\Defogger.exe 2014-01-29 12:37 - 2014-01-29 12:37 - 00000976 _____ () C:\Users\benutzername\Desktop\terminal.lnk 2014-01-24 12:18 - 2014-01-24 12:19 - 00000057 _____ () C:\Users\benutzername\Desktop\Kaufen.txt 2014-01-23 11:32 - 2014-01-23 11:33 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-01-23 11:32 - 2014-01-23 11:33 - 00000000 ____D () C:\Program Files\iTunes 2014-01-23 11:32 - 2014-01-23 11:33 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-01-23 11:32 - 2014-01-23 11:32 - 00000000 ____D () C:\Program Files\iPod 2014-01-23 11:15 - 2014-01-23 11:15 - 00000000 ____D () C:\Users\benutzername\elan2013 2014-01-23 11:14 - 2014-01-23 11:14 - 00000000 ____D () C:\Program Files\REHADAT 2014-01-21 09:59 - 2014-01-21 09:59 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-01-21 09:50 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 09:37 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys ==================== One Month Modified Files and Folders ======= 2014-02-01 18:53 - 2014-02-01 18:52 - 00014337 _____ () C:\Users\benutzername\Desktop\FRST.txt 2014-02-01 18:53 - 2013-10-16 12:18 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-01 18:52 - 2014-02-01 18:52 - 00000000 ____D () C:\FRST 2014-02-01 18:51 - 2013-10-16 12:18 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-01 18:50 - 2014-02-01 18:50 - 00000022 _____ () C:\Windows\S.dirmngr 2014-02-01 18:50 - 2012-04-14 15:30 - 00115054 _____ () C:\Windows\setupact.log 2014-02-01 18:50 - 2012-03-30 03:55 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-01 18:50 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-01 18:49 - 2014-02-01 18:49 - 00000470 _____ () C:\Users\benutzername\Desktop\defogger_disable.log 2014-02-01 18:49 - 2012-03-30 03:40 - 01940023 _____ () C:\Windows\WindowsUpdate.log 2014-02-01 18:10 - 2013-01-05 16:36 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-01 14:39 - 2009-07-14 05:45 - 00031072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-01 14:39 - 2009-07-14 05:45 - 00031072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-01 14:36 - 2014-02-01 14:36 - 00380416 _____ () C:\Users\benutzername\Desktop\Gmer-19357.exe 2014-02-01 14:34 - 2014-02-01 14:34 - 02080256 _____ (Farbar) C:\Users\benutzername\Desktop\FRST64.exe 2014-02-01 14:34 - 2014-02-01 14:33 - 00050477 _____ () C:\Users\benutzername\Desktop\Defogger.exe 2014-01-29 12:37 - 2014-01-29 12:37 - 00000976 _____ () C:\Users\benutzername\Desktop\terminal.lnk 2014-01-28 21:03 - 2012-03-30 13:23 - 00699682 _____ () C:\Windows\system32\perfh007.dat 2014-01-28 21:03 - 2012-03-30 13:23 - 00149790 _____ () C:\Windows\system32\perfc007.dat 2014-01-28 21:03 - 2009-07-14 06:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-01-24 12:19 - 2014-01-24 12:18 - 00000057 _____ () C:\Users\benutzername\Desktop\Kaufen.txt 2014-01-23 14:07 - 2012-05-12 16:37 - 00000000 ____D () C:\Program Files (x86)\phase5 2014-01-23 11:34 - 2012-04-15 07:54 - 00000000 ____D () C:\Users\benutzername\AppData\Local\Adobe 2014-01-23 11:33 - 2014-01-23 11:32 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-01-23 11:33 - 2014-01-23 11:32 - 00000000 ____D () C:\Program Files\iTunes 2014-01-23 11:33 - 2014-01-23 11:32 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-01-23 11:32 - 2014-01-23 11:32 - 00000000 ____D () C:\Program Files\iPod 2014-01-23 11:32 - 2013-01-05 16:36 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-01-23 11:32 - 2012-04-15 07:46 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-01-23 11:32 - 2012-04-15 07:46 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-01-23 11:28 - 2013-07-12 17:42 - 00000000 ____D () C:\ProgramData\Apple 2014-01-23 11:25 - 2013-07-12 17:45 - 00000000 ____D () C:\Users\benutzername\AppData\Roaming\Apple Computer 2014-01-23 11:15 - 2014-01-23 11:15 - 00000000 ____D () C:\Users\benutzername\elan2013 2014-01-23 11:15 - 2012-04-14 07:02 - 00000000 ____D () C:\Users\benutzername 2014-01-23 11:14 - 2014-01-23 11:14 - 00000000 ____D () C:\Program Files\REHADAT 2014-01-21 10:03 - 2012-03-30 03:56 - 00000000 ____D () C:\Windows\SysWOW64\NV 2014-01-21 10:03 - 2012-03-30 03:56 - 00000000 ____D () C:\Windows\system32\NV 2014-01-21 10:02 - 2010-11-21 04:47 - 01091704 _____ () C:\Windows\PFRO.log 2014-01-21 09:59 - 2014-01-21 09:59 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-01-21 09:55 - 2012-03-30 03:54 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-01-21 09:52 - 2012-03-30 03:54 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-01-21 09:51 - 2013-12-11 08:36 - 01594964 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-01-21 09:50 - 2012-03-30 03:58 - 00000000 ____D () C:\ProgramData\Adobe 2014-01-21 09:44 - 2012-07-20 08:49 - 00000000 ____D () C:\xampp 2014-01-15 12:35 - 2009-07-14 05:45 - 04950184 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-15 09:42 - 2013-07-11 07:17 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-15 09:38 - 2012-04-14 16:44 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-15 09:31 - 2012-08-17 13:03 - 00001456 _____ () C:\Users\benutzername\AppData\Local\Adobe Für Web speichern 13.0 Prefs ZeroAccess: C:\Windows\Installer\{56d76256-d551-d3c2-818a-fa84f69dc1cd} ZeroAccess: C:\Users\benutzername\AppData\Local\{56d76256-d551-d3c2-818a-fa84f69dc1cd} Some content of TEMP: ==================== C:\Users\benutzername\AppData\Local\Temp\AskSLib.dll C:\Users\benutzername\AppData\Local\Temp\avgnt.exe C:\Users\benutzername\AppData\Local\Temp\pyl1D54.tmp.exe C:\Users\benutzername\AppData\Local\Temp\AskSLib.dll C:\Users\benutzername\AppData\Local\Temp\avgnt.exe C:\Users\benutzername\AppData\Local\Temp\gwunstal.exe C:\Users\benutzername\AppData\Local\Temp\install_flashplayer11x32_mssd_aaa_aih.exe C:\Users\benutzername\AppData\Local\Temp\k9-webprotection-4.4.268.exe C:\Users\benutzername\AppData\Local\Temp\MouseKeyboardCenterx64_1031.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-29 18:32 ==================== End Of Log ============================ Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-02-2014 03 Ran by Benutzername at 2014-02-01 18:54:12 Running from C:\Users\Benutzername\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0 - Igor Pavlov) Adobe AIR (x32 Version: 4.0.0.1390 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 4.0.0.1390 - Adobe Systems Incorporated) Hidden Adobe Flash Player 12 ActiveX (x32 Version: 12.0.0.38 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (x32 Version: 12.0.0.43 - Adobe Systems Incorporated) Adobe Photoshop CS6 (x32 Version: 13.0 - Adobe Systems Incorporated) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) (x32 Version: 11.0.06 - Adobe Systems Incorporated) Amazon MP3-Downloader 1.0.17 (x32 Version: 1.0.17 - Amazon Services LLC) Anzeige am Bildschirm (Version: 6.70.00 - ) Apple Application Support (x32 Version: 3.0 - Apple Inc.) Apple Mobile Device Support (Version: 7.1.0.32 - Apple Inc.) Apple Software Update (x32 Version: 2.1.3.127 - Apple Inc.) AudibleManager (x32 Version: 1998929134.48.56.6499218 - Audible, Inc.) Avira Free Antivirus (x32 Version: 14.0.2.286 - Avira) Blue Coat K9 Web Protection (Version: 4.4.268 - Blue Coat Systems, Inc.) Bonjour (Version: 3.0.0.10 - Apple Inc.) Broadcom InConcert Maestro (Version: 1.0.1.1500 - Broadcom Corporation) Burn.Now 4.5 (x32 Version: 4.5.0 - Corel Corporation) Hidden Canon Inkjet Printer Driver Add-On Module (Version: - ) Canon My Printer (x32 Version: - ) CanoScan Toolbox Ver4.9 (x32 Version: - ) Citrix Online Plug-in (DV) (x32 Version: 12.3.0.8 - Citrix Systems, Inc.) Hidden Citrix Online Plug-in (HDX) (x32 Version: 12.3.0.8 - Citrix Systems, Inc.) Hidden Citrix Online Plug-in (Web) (x32 Version: 12.3.0.8 - Citrix Systems, Inc.) Hidden Conexant 20672 SmartAudio HD (Version: 8.32.23.2 - Conexant) Corel Burn.Now Lenovo Edition (x32 Version: 4.5.0 - Corel Corporation) Corel WinDVD (x32 Version: 10.0.5.890 - Corel Inc.) Create Recovery Media (x32 Version: 1.20.0.00 - Lenovo Group Limited) Deutsch (DE) + Pali (Version: 1.0.3.40 - Frank Snow) Dienstprogramm "ThinkPad UltraNav" (x32 Version: 2.13.0 - Lenovo) Disable AMT Profile Synchronization Pop-up for Windows XP/Vista/7 (Version: 1.00 - ) ElsterFormular (x32 Version: 14.1.11318 - Landesfinanzdirektion Thüringen) FileHippo.com Update Checker (x32 Version: - ) FileZilla Client 3.7.3 (x32 Version: 3.7.3 - Tim Kosse) Forex Tester 2.8.10 (x32 Version: - Forex Tester Software) Free YouTube to MP3 Converter version 3.12.0.128 (x32 Version: 3.12.0.128 - DVDVideoSoft Ltd.) FreeRIP MP3 Converter 4.3 (x32 Version: 4.3 - GreenTree Applications SRL) Google Earth Plug-in (x32 Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden Gpg4win (2.2.0) (x32 Version: 2.2.0 - The Gpg4win Project) GPL Ghostscript (Version: 9.10 - Artifex Software Inc.) Guitar Pro 6 (x32 Version: - Arobas Music) HP Officejet Pro 8600 - Grundlegende Software für das Gerät (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Officejet Pro 8600 Hilfe (x32 Version: 28.0.0 - Hewlett Packard) HP Update (x32 Version: 5.003.003.001 - Hewlett-Packard) I.R.I.S. OCR (x32 Version: 12.3.4.0 - HP) Image Resizer Powertoy Clone for Windows (64 bit) (Version: 2.1.1 - Brice Lambson) Integrated Camera Driver Installer Package Ver.1.1.0.1147 (x32 Version: 1.1.0.1147 - RICOH) Integrated Camera TWAIN (x32 Version: 1.0.11.1223 - Chicony Electronics Co.,Ltd.) Intel(R) Control Center (x32 Version: 1.2.1.1007 - Intel Corporation) Intel(R) Identity Protection Technology 1.1.2.0 (x32 Version: 1.1.2.0 - Intel Corporation) Intel(R) Management Engine Components (x32 Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (x32 Version: 8.15.10.2321 - Intel Corporation) Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (Version: 15.6.1.0536 - Intel Corporation) Hidden Intel(R) PROSet/Wireless WiFi Software Driver (Version: 15.06.1000.0167 - Intel Corporation) Hidden Intel® PROSet/Wireless Software (x32 Version: 15.6.1 - Intel Corporation) Intel® PROSet/Wireless WiFi Software (Version: 15.06.1000.0142 - Intel Corporation) Hidden iTunes (Version: 11.1.4.62 - Apple Inc.) Java 7 Update 51 (64-bit) (Version: 7.0.510 - Oracle) Java 7 Update 9 (x32 Version: 7.0.90 - Oracle) Java Auto Updater (x32 Version: 2.1.9.0 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 31 (x32 Version: 6.0.310 - Oracle) KaloMa 4.94 (x32 Version: - Frank Böpple) Lenovo Auto Scroll Utility (Version: 1.11 - ) Lenovo Patch Utility (x32 Version: 1.0.1.1 - Lenovo Group Limited) Lenovo Patch Utility (x32 Version: 1.3.1.1 - Lenovo Group Limited) Lenovo Patch Utility 64 bit (Version: 1.2.0.1 - Lenovo Group Limited) Lenovo Patch Utility 64 bit (Version: 1.3.1.1 - Lenovo Group Limited) Lenovo Power Management Driver (Version: 1.67.04.04 - ) Lenovo Solution Center (Version: 2.2.002.00 - Lenovo Group Limited) Lenovo System Interface Driver (Version: 1.05 - ) Lenovo System Update (x32 Version: 5.02.0018 - Lenovo) Lenovo User Guide (x32 Version: 1.0.0008.00 - Ihr Firmenname) Logitech Media Server 7.7.2 (x32 Version: 7.7.2 - Logitech) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft PowerPoint Viewer (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft-Maus- und Tastatur-Center (Version: 2.2.173.0 - Microsoft Corporation) Microsoft-Maus- und Tastatur-Center (Version: 2.2.173.0 - Microsoft Corporation) Hidden Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 24.2.0 - Mozilla) Mozilla Thunderbird 24.2.0 (x86 de) (x32 Version: 24.2.0 - Mozilla) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation) NVIDIA 3D Vision Treiber 312.69 (Version: 312.69 - NVIDIA Corporation) NVIDIA Grafiktreiber 312.69 (Version: 312.69 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.2.23.3 (Version: 1.2.23.3 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.124.810 - NVIDIA Corporation) Hidden NVIDIA Optimus 1.11.3 (Version: 1.11.3 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1269 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 312.69 (Version: 312.69 - NVIDIA Corporation) Hidden NVIDIA Update Components (Version: 1.11.3 - NVIDIA Corporation) Hidden OpenOffice 4.0.1 (x32 Version: 4.01.9714 - Apache Software Foundation) OpenOffice 4.0.1 Language Pack (German) (x32 Version: 4.01.9714 - Apache Software Foundation) Oracle VM VirtualBox 4.1.18 (Version: 4.1.18 - Oracle Corporation) PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden PDF24 Creator 5.3.0 (x32 Version: - PDF24.org) Phase 5 HTML-Editor (x32 Version: 5.6.2.3 - Systemberatung Schommer) RapidBoot (Version: 1.11 - Lenovo) Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7 (Version: 1.00 - ) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden RICOH_Media_Driver_v2.14.18.01 (x32 Version: 2.14.18.01 - RICOH) ThinkPad Bluetooth with Enhanced Data Rate Software (Version: 6.4.0.1500 - Broadcom Corporation) ThinkPad Energie-Manager (x32 Version: 3.67 - ) ThinkPad FullScreen Magnifier (Version: 2.40 - ) ThinkPad UltraNav Driver (Version: 16.2.19.7 - ) ThinkVantage Access Connections (x32 Version: 6.01 - Lenovo) ThinkVantage AutoLock (Version: 1.05 - Lenovo) ThinkVantage Communications Utility (Version: 2.11.0.0 - Lenovo) ThinkVantage System für aktiven Festplattenschutz (Version: 1.73 - Lenovo) VLC media player 2.1.2 (Version: 2.1.2 - VideoLAN) Winamp (x32 Version: 5.666 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1 - Nullsoft, Inc) Windows-Treiberpaket - Intel (e1cexpress) Net (12/21/2010 11.8.84.0) (Version: 12/21/2010 11.8.84.0 - Intel) Windows-Treiberpaket - Intel System (09/10/2010 9.2.0.1011) (Version: 09/10/2010 9.2.0.1011 - Intel) Windows-Treiberpaket - Intel System (11/20/2010 9.2.0.1016) (Version: 11/20/2010 9.2.0.1016 - Intel) Windows-Treiberpaket - Intel USB (12/21/2010 9.2.0.1021) (Version: 12/21/2010 9.2.0.1021 - Intel) Windows-Treiberpaket - Lenovo 1.61.00.11 (11/11/2010 1.61.00.11) (Version: 11/11/2010 1.61.00.11 - Lenovo) Windows-Treiberpaket - Synaptics (SynTP) Mouse (05/19/2011 15.3.8.0) (Version: 05/19/2011 15.3.8.0 - Synaptics) ==================== Restore Points ========================= 15-01-2014 08:37:56 Windows Update 21-01-2014 08:49:01 Installed Adobe Reader XI. 21-01-2014 08:58:22 Installed Java 7 Update 51 (64-bit) ==================== Hosts content: ========================== 2009-07-14 03:34 - 2012-07-16 14:05 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {0AAC0C8F-17F9-44D9-8633-99800402F7B4} - System32\Tasks\awareness6 Task: {0EFF2205-FC92-44C3-9847-11F40B84514D} - System32\Tasks\MCP => C:\Program Files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe Task: {1949FBA0-C3CD-4D95-8CF4-D8C1EC416BE7} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation) Task: {1BF94E8A-9370-4315-AFAE-C59B52FBA257} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [2013-06-26] () Task: {29234F52-000F-4C8A-974E-D2863C65887A} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2013-08-08] (Lenovo) Task: {318162B0-C188-48B9-8C15-C72C0806DE17} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-16] (Google Inc.) Task: {3316434C-3712-4FC7-A669-6C670554C817} - System32\Tasks\be aware! 19 Task: {3B6F8732-8E3E-481A-B032-D48CCB0ABCA7} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe Task: {3EA94329-78C3-4A77-80AB-3269078D89FB} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation) Task: {4B4C0661-488F-4734-B69A-5A185DD7BB55} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2013-08-08] () Task: {4D1E8C33-37C0-4DE5-A9D6-0356BF31A31D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-16] (Google Inc.) Task: {5E241B72-DD17-4ABF-9A35-042ED30B2E01} - System32\Tasks\be aware! Task: {61294AAE-7DAC-42BD-9822-5DE8BD747EE3} - System32\Tasks\PMTask => C:\Program Files (x86)\ThinkPad\Utilities\PWMIDTSV.EXE [2012-02-27] (Lenovo Group Limited) Task: {68F382CD-8ABB-42E9-8DE2-A46F91908E53} - System32\Tasks\Microsoft\Windows\PLA\LSC Memory => Rundll32.exe C:\Windows\system32\pla.dll,PlaHost "LSC Memory" "$(Arg0)" Task: {6BE59280-6519-4482-B234-3FF1A1372790} - System32\Tasks\aware00 Task: {76E282E5-6E12-4B64-8961-BEF23A694991} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation) Task: {8594D661-1412-43A1-A9D5-0614214D5250} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2013-08-08] (Lenovo) Task: {880D2868-EE2E-4A74-9A7A-CE4EED02188D} - System32\Tasks\awareness5 Task: {88CB84E9-B6C5-443D-A74D-E1F81679658C} - System32\Tasks\awareness4 Task: {898DC75A-40B7-447B-8546-FC4D0E134300} - System32\Tasks\awareness3 Task: {A29BF6F0-A657-47DB-970D-04ACBBF9A0AD} - System32\Tasks\be aware 16 Task: {B8D51834-255C-4F7F-A4B0-E0B06BF29BAB} - System32\Tasks\AdobeAAMUpdater-1.0-Benutzername-THINK-Benutzername => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-03-21] (Adobe Systems Incorporated) Task: {C175891A-98B5-4499-AA27-0AE01A93EB64} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-23] (Adobe Systems Incorporated) Task: {CC9B9E00-0D49-4D00-8EC0-D45AF6454684} - System32\Tasks\Awareness1 Task: {CE893D65-78EE-4A76-B74F-22666E11AA10} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation) Task: {D509974F-B4A2-4F4D-B101-5F462082506D} - System32\Tasks\Awareness2 Task: {D5E18281-C555-4285-9DFC-0CC5EB556E1D} - System32\Tasks\be aware! 17 Task: {EBE7144C-7860-422B-AFA9-292E85F0A8A7} - System32\Tasks\be aware! 18 Task: {FB7DC5DC-1E7F-4A05-BFD7-F51EF09F2B08} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-05-13] (Microsoft) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2010-01-02 15:42 - 2010-01-02 15:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2012-03-30 03:54 - 2011-03-06 12:07 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2012-03-30 03:57 - 2012-02-27 19:07 - 00055808 ____N () C:\Program Files (x86)\ThinkPad\Utilities\GR\PWMRT64V.DLL 2012-10-19 11:50 - 2012-09-19 18:17 - 00397088 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-01-20 13:16 - 2014-01-20 13:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2013-08-20 10:59 - 2013-08-20 10:59 - 00221184 _____ () C:\Program Files (x86)\GNU\GnuPG\libksba-8.dll 2013-08-20 10:56 - 2013-08-20 10:56 - 00037888 _____ () C:\Program Files (x86)\GNU\GnuPG\libgpg-error-0.dll 2013-08-20 10:54 - 2013-08-20 10:54 - 00050176 _____ () C:\Program Files (x86)\GNU\GnuPG\libw32pth-0.dll 2013-08-20 10:58 - 2013-08-20 10:58 - 00069632 _____ () C:\Program Files (x86)\GNU\GnuPG\libassuan-0.dll 2013-08-20 10:59 - 2013-08-20 10:59 - 00628224 _____ () C:\Program Files (x86)\GNU\GnuPG\libgcrypt-11.dll 2013-03-18 16:26 - 2013-03-18 16:26 - 00092456 _____ () C:\Program Files (x86)\Lenovo\Access Connections\AcWrpc.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: bckd Description: bckd Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: bckd Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (02/01/2014 06:50:43 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/01/2014 01:39:16 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/01/2014 09:30:39 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/31/2014 10:01:57 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/31/2014 05:35:17 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 5990 Error: (01/31/2014 05:35:17 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 5990 Error: (01/31/2014 05:35:17 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (01/31/2014 05:35:16 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 4992 Error: (01/31/2014 05:35:16 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 4992 Error: (01/31/2014 05:35:16 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second System errors: ============= Error: (02/01/2014 06:50:40 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "bckd" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (02/01/2014 01:39:10 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "bckd" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (02/01/2014 09:30:36 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "bckd" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (01/31/2014 10:01:52 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "bckd" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (01/31/2014 03:45:42 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "bckd" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (01/31/2014 11:33:31 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "bckd" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (01/31/2014 08:32:17 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "bckd" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (01/30/2014 09:05:27 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "bckd" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (01/30/2014 07:21:03 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "bckd" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (01/30/2014 01:47:42 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "bckd" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Microsoft Office Sessions: ========================= Error: (02/01/2014 06:50:43 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/01/2014 01:39:16 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/01/2014 09:30:39 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/31/2014 10:01:57 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/31/2014 05:35:17 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 5990 Error: (01/31/2014 05:35:17 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 5990 Error: (01/31/2014 05:35:17 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (01/31/2014 05:35:16 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 4992 Error: (01/31/2014 05:35:16 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 4992 Error: (01/31/2014 05:35:16 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second CodeIntegrity Errors: =================================== Date: 2012-07-16 15:05:01.912 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-07-16 15:05:01.874 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 23% Total physical RAM: 8075.23 MB Available physical RAM: 6208.5 MB Total Pagefile: 16148.65 MB Available Pagefile: 14199.23 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: (Windows7_OS) (Fixed) (Total:100 GB) (Free:26.54 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (data) (Fixed) (Total:348.67 GB) (Free:328.54 GB) NTFS Drive q: (Lenovo_Recovery) (Fixed) (Total:15.62 GB) (Free:5.11 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: B2FF4958) Partition 1: (Active) - (Size=1 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=100 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=349 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=16 GB) - (Type=07 NTFS) ==================== End Of Log ============================ gmer.log Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-02-01 19:19:31 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 HITACHI_ rev.JF3Z 465,76GB Running: Gmer-19357.exe; Driver: C:\Users\Benutzername\AppData\Local\Temp\kgtiyaow.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074c91465 2 bytes [C9, 74] .text C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe[2584] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074c914bb 2 bytes [C9, 74] .text ... * 2 .text C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe[1336] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074c91465 2 bytes [C9, 74] .text C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe[1336] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074c914bb 2 bytes [C9, 74] .text ... * 2 .text C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe[5368] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074c91465 2 bytes [C9, 74] .text C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe[5368] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074c914bb 2 bytes [C9, 74] .text ... * 2 ---- Threads - GMER 2.1 ---- Thread C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [3744:4752] 000007fef4233e0c Thread C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [3744:4220] 000007fef4233e0c Thread C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [3744:4224] 000007feedcec680 Thread C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [3796:5068] 000007feedcec680 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\7ce9d3b79452 Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\7ce9d3b79452 (not active ControlSet) ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ---- Viele Grüße wenjin |
01.02.2014, 20:36 | #2 | |
/// the machine /// TB-Ausbilder | Rechner hakt und hat Aussetzer hi,
__________________Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ |
02.02.2014, 08:40 | #3 |
| Rechner hakt und hat Aussetzer Hallo schrauber,
__________________erstmal vielen Dank für Deine Hilfe. Im Anhang (wg. der Größe) das Combofix-Log. Danke und schönen Sonntag wenjin |
03.02.2014, 10:04 | #4 |
/// the machine /// TB-Ausbilder | Rechner hakt und hat Aussetzer Hi, Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.02.2014, 10:56 | #5 |
| Rechner hakt und hat Aussetzer Hallo, hatte irgendwo gelesen, dass man die Logs als Anhang posten soll, falls zu groß. Hier die combofix.txt in zwei Teilen (die anderen Aufgaben erledige ich später). Vielen Dank soweit! Combofix - Teil 1 Code:
ATTFilter ComboFix 14-02-01.01 - Benutzername 02.02.2014 8:07.3.8 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.8075.6118 [GMT 1:00] ausgeführt von:: c:\users\Benutzername\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\Lenovo\Lenovo Solution Center\Microsoft Fix it\FixitUi\_desktop.ini c:\programdata\Roaming . . ((((((((((((((((((((((( Dateien erstellt von 2014-01-02 bis 2014-02-02 )))))))))))))))))))))))))))))) . . 2014-02-02 07:18 . 2014-02-02 07:18 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2014-02-02 07:18 . 2014-02-02 07:18 -------- d-----w- c:\users\Benutzername\AppData\Local\temp 2014-02-02 07:18 . 2014-02-02 07:18 -------- d-----w- c:\users\Public\AppData\Local\temp 2014-02-02 07:18 . 2014-02-02 07:18 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-02-01 17:52 . 2014-02-01 17:54 -------- d-----w- C:\FRST 2014-01-23 10:32 . 2014-01-23 10:32 -------- d-----w- c:\program files\iPod 2014-01-23 10:32 . 2014-01-23 10:33 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-01-23 10:32 . 2014-01-23 10:33 -------- d-----w- c:\program files\iTunes 2014-01-23 10:32 . 2014-01-23 10:33 -------- d-----w- c:\program files (x86)\iTunes 2014-01-23 10:15 . 2014-01-23 10:15 -------- d-----w- c:\users\Benutzername\elan2013 2014-01-23 10:14 . 2014-01-23 10:14 -------- d-----w- c:\program files\REHADAT 2014-01-21 08:59 . 2014-01-21 08:59 312744 ----a-w- c:\windows\system32\javaws.exe 2014-01-21 08:59 . 2014-01-21 08:59 189352 ----a-w- c:\windows\system32\javaw.exe 2014-01-21 08:59 . 2014-01-21 08:59 189352 ----a-w- c:\windows\system32\java.exe 2014-01-21 08:59 . 2014-01-21 08:59 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2014-01-21 08:50 . 2013-11-26 11:40 376768 ----a-w- c:\windows\system32\drivers\netio.sys 2014-01-15 08:37 . 2013-11-27 01:41 53248 ----a-w- c:\windows\system32\drivers\usbehci.sys 2014-01-15 08:37 . 2013-11-27 01:41 325120 ----a-w- c:\windows\system32\drivers\usbport.sys 2014-01-15 08:37 . 2013-11-27 01:41 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys 2014-01-15 08:37 . 2013-11-27 01:41 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2014-01-15 08:37 . 2013-11-27 01:41 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys 2014-01-15 08:37 . 2013-11-27 01:41 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys 2014-01-15 08:37 . 2013-11-27 01:41 7808 ----a-w- c:\windows\system32\drivers\usbd.sys 2014-01-15 08:37 . 2013-11-26 10:32 3156480 ----a-w- c:\windows\system32\win32k.sys . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-01-23 10:32 . 2012-04-15 06:46 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-01-23 10:32 . 2012-04-15 06:46 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-01-15 08:38 . 2012-04-14 15:44 86054176 ----a-w- c:\windows\system32\MRT.exe 2013-12-17 13:13 . 2013-05-06 09:29 84720 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2013-12-17 13:13 . 2013-03-30 08:52 131576 ----a-w- c:\windows\system32\drivers\avipbb.sys 2013-12-17 13:13 . 2013-03-30 08:52 108440 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2013-11-26 11:54 . 2013-12-11 07:31 23183360 ----a-w- c:\windows\system32\mshtml.dll 2013-11-26 10:19 . 2013-12-11 07:31 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2013-11-26 10:18 . 2013-12-11 07:31 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2013-11-26 09:48 . 2013-12-11 07:31 66048 ----a-w- c:\windows\system32\iesetup.dll 2013-11-26 09:46 . 2013-12-11 07:31 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll 2013-11-26 09:41 . 2013-12-11 07:31 2764288 ----a-w- c:\windows\system32\iertutil.dll 2013-11-26 09:29 . 2013-12-11 07:31 53760 ----a-w- c:\windows\system32\jsproxy.dll 2013-11-26 09:27 . 2013-12-11 07:31 33792 ----a-w- c:\windows\system32\iernonce.dll 2013-11-26 09:23 . 2013-12-11 07:31 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb 2013-11-26 09:21 . 2013-12-11 07:31 574976 ----a-w- c:\windows\system32\ieui.dll 2013-11-26 09:18 . 2013-12-11 07:31 139264 ----a-w- c:\windows\system32\ieUnatt.exe 2013-11-26 09:18 . 2013-12-11 07:31 111616 ----a-w- c:\windows\system32\ieetwcollector.exe 2013-11-26 09:16 . 2013-12-11 07:31 708608 ----a-w- c:\windows\system32\jscript9diag.dll 2013-11-26 08:57 . 2013-12-11 07:31 218624 ----a-w- c:\windows\system32\ie4uinit.exe 2013-11-26 08:35 . 2013-12-11 07:30 5769216 ----a-w- c:\windows\system32\jscript9.dll 2013-11-26 08:28 . 2013-12-11 07:31 553472 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2013-11-26 08:16 . 2013-12-11 07:30 4243968 ----a-w- c:\windows\SysWow64\jscript9.dll 2013-11-26 08:02 . 2013-12-11 07:31 1995264 ----a-w- c:\windows\system32\inetcpl.cpl 2013-11-26 07:48 . 2013-12-11 07:31 12996608 ----a-w- c:\windows\system32\ieframe.dll 2013-11-26 07:32 . 2013-12-11 07:31 1928192 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2013-11-26 07:07 . 2013-12-11 07:31 2334208 ----a-w- c:\windows\system32\wininet.dll 2013-11-26 06:40 . 2013-12-11 07:31 1395200 ----a-w- c:\windows\system32\urlmon.dll 2013-11-26 06:34 . 2013-12-11 07:31 817664 ----a-w- c:\windows\system32\ieapfltr.dll 2013-11-26 06:33 . 2013-12-11 07:31 1820160 ----a-w- c:\windows\SysWow64\wininet.dll 2013-11-23 18:26 . 2013-12-11 07:03 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2013-11-23 17:47 . 2013-12-11 07:03 465920 ----a-w- c:\windows\system32\WMPhoto.dll 2013-11-15 09:53 . 2013-11-15 09:53 15051216 ----a-w- c:\windows\system32\nvwgf2umx.dll 2013-11-15 09:53 . 2013-11-15 09:53 12641480 ----a-w- c:\windows\SysWow64\nvwgf2um.dll 2013-11-15 09:53 . 2013-11-15 09:53 961192 ----a-w- c:\windows\SysWow64\nvumdshim.dll 2013-11-15 09:53 . 2013-11-15 09:53 1107440 ----a-w- c:\windows\system32\nvumdshimx.dll 2013-11-15 09:52 . 2013-11-15 09:52 6264144 ----a-w- c:\windows\SysWow64\nvopencl.dll 2013-11-15 09:52 . 2013-11-15 09:52 30496 ----a-w- c:\windows\system32\drivers\nvpciflt.sys 2013-11-15 09:52 . 2013-11-15 09:52 7566624 ----a-w- c:\windows\system32\nvopencl.dll 2013-11-15 09:52 . 2013-11-15 09:52 26940704 ----a-w- c:\windows\system32\nvoglv64.dll 2013-11-15 09:52 . 2013-11-15 09:52 20461344 ----a-w- c:\windows\SysWow64\nvoglv32.dll 2013-11-15 09:52 . 2013-11-15 09:52 284448 ----a-w- c:\windows\system32\drivers\nvkflt.sys 2013-11-15 09:52 . 2013-11-15 09:52 245872 ----a-w- c:\windows\system32\nvinitx.dll 2013-11-15 09:52 . 2013-11-15 09:52 201576 ----a-w- c:\windows\SysWow64\nvinit.dll 2013-11-15 09:52 . 2013-11-15 09:52 11137824 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys 2013-11-15 09:52 . 2013-11-15 09:52 1814304 ----a-w- c:\windows\system32\nvdispco6431269.dll 2013-11-15 09:52 . 2013-11-15 09:52 1511712 ----a-w- c:\windows\system32\nvdispgenco6431269.dll 2013-11-15 09:52 . 2013-11-15 09:52 2907936 ----a-w- c:\windows\system32\nvcuvid.dll 2013-11-15 09:52 . 2013-11-15 09:52 2723616 ----a-w- c:\windows\SysWow64\nvcuvid.dll 2013-11-15 09:52 . 2013-11-15 09:52 2346784 ----a-w- c:\windows\system32\nvcuvenc.dll 2013-11-15 09:52 . 2013-11-15 09:52 1987360 ----a-w- c:\windows\SysWow64\nvcuvenc.dll 2013-11-15 09:52 . 2013-11-15 09:52 18005208 ----a-w- c:\windows\system32\nvd3dumx.dll 2013-11-15 09:52 . 2013-11-15 09:52 15095440 ----a-w- c:\windows\SysWow64\nvd3dum.dll 2013-11-15 09:52 . 2013-11-15 09:52 9393856 ----a-w- c:\windows\system32\nvcuda.dll 2013-11-15 09:52 . 2013-11-15 09:52 7935352 ----a-w- c:\windows\SysWow64\nvcuda.dll 2013-11-15 09:52 . 2013-11-15 09:52 17560352 ----a-w- c:\windows\SysWow64\nvcompiler.dll 2013-11-15 09:52 . 2013-11-15 09:52 25256224 ----a-w- c:\windows\system32\nvcompiler.dll 2013-11-15 09:52 . 2013-11-15 09:52 2511312 ----a-w- c:\windows\SysWow64\nvapi.dll 2013-11-15 09:52 . 2013-02-28 00:47 2832720 ----a-w- c:\windows\system32\nvapi64.dll 2013-11-12 07:03 . 2013-11-12 07:03 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-11-12 07:03 . 2013-11-12 07:03 194048 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-11-12 07:02 . 2013-11-12 07:02 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2013-11-12 07:02 . 2013-11-12 07:02 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll 2013-11-12 07:02 . 2013-11-12 07:02 235008 ----a-w- c:\windows\system32\elshyph.dll 2013-11-12 07:02 . 2013-11-12 07:02 182272 ----a-w- c:\windows\SysWow64\msls31.dll 2013-11-12 07:02 . 2013-11-12 07:02 62464 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-11-12 07:02 . 2013-11-12 07:02 61952 ----a-w- c:\windows\SysWow64\iesetup.dll 2013-11-12 07:02 . 2013-11-12 07:02 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2013-11-12 07:02 . 2013-11-12 07:02 337408 ----a-w- c:\windows\SysWow64\html.iec 2013-11-12 07:02 . 2013-11-12 07:02 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-11-12 07:02 . 2013-11-12 07:02 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2013-11-12 07:02 . 2013-11-12 07:02 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2013-11-12 07:02 . 2013-11-12 07:02 454656 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-11-12 07:02 . 2013-11-12 07:02 36352 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-11-12 07:02 . 2013-11-12 07:02 151552 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-11-12 07:02 . 2013-11-12 07:02 139264 ----a-w- c:\windows\SysWow64\wextract.exe 2013-11-12 07:02 . 2013-11-12 07:02 13312 ----a-w- c:\windows\SysWow64\mshta.exe 2013-11-12 07:02 . 2013-11-12 07:02 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-11-12 07:02 . 2013-11-12 07:02 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-11-12 07:02 . 2013-11-12 07:02 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-11-12 07:02 . 2013-11-12 07:02 942592 ----a-w- c:\windows\system32\jsIntl.dll 2013-11-12 07:02 . 2013-11-12 07:02 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll 2013-11-12 07:02 . 2013-11-12 07:02 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2013-11-12 07:02 . 2013-11-12 07:02 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-11-12 07:02 . 2013-11-12 07:02 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-11-12 07:02 . 2013-11-12 07:02 247808 ----a-w- c:\windows\system32\msls31.dll 2013-11-12 07:02 . 2013-11-12 07:02 195584 ----a-w- c:\windows\system32\msrating.dll 2013-11-12 07:02 . 2013-11-12 07:02 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-11-12 07:02 . 2013-11-12 07:02 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-11-12 07:02 . 2013-11-12 07:02 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-11-12 07:02 . 2013-11-12 07:02 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-11-12 07:02 . 2013-11-12 07:02 13312 ----a-w- c:\windows\system32\msfeedssync.exe 2013-11-12 07:02 . 2013-11-12 07:02 131072 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-11-12 07:02 . 2013-11-12 07:02 105984 ----a-w- c:\windows\system32\iesysprep.dll 2013-11-12 07:02 . 2013-11-12 07:02 84992 ----a-w- c:\windows\system32\mshtmled.dll 2013-11-12 07:02 . 2013-11-12 07:02 81408 ----a-w- c:\windows\system32\icardie.dll 2013-11-12 07:02 . 2013-11-12 07:02 616104 ----a-w- c:\windows\system32\ieapfltr.dat 2013-11-12 07:02 . 2013-11-12 07:02 453120 ----a-w- c:\windows\system32\dxtmsft.dll 2013-11-12 07:02 . 2013-11-12 07:02 413696 ----a-w- c:\windows\system32\html.iec 2013-11-12 07:02 . 2013-11-12 07:02 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}] 2013-01-30 14:49 281760 ----a-w- c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "FileHippo.com"="c:\program files (x86)\FileHippo.com\UpdateChecker.exe" [2012-11-23 307712] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "PWMTRV"="c:\progra~2\ThinkPad\UTILIT~1\PWMTR64V.DLL" [2012-02-27 1631808] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-12-17 684600] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-12-21 959904] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2014-01-20 152392] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36.sys] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro36Crusader] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro36CrusaderBoot] @="" . R2 bckd;bckd;c:\windows\system32\drivers\bckd.sys;c:\windows\SYSNATIVE\drivers\bckd.sys [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 HyperW7Svc;HyperW7 Service;c:\program files\Lenovo\RapidBoot\HyperW7Svc64.exe;c:\program files\Lenovo\RapidBoot\HyperW7Svc64.exe [x] R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protokoll;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x] R3 BTWAMPFL;BTWAMPFL;c:\windows\system32\DRIVERS\btwampfl.sys;c:\windows\SYSNATIVE\DRIVERS\btwampfl.sys [x] R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x] R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [x] R3 PwmEWSvc;Cisco EnergyWise Enabler;c:\program files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE;c:\program files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R4 bckwfs;Blue Coat K9 Web Protection;c:\program files\Blue Coat K9 Web Protection\k9filter.exe;c:\program files\Blue Coat K9 Web Protection\k9filter.exe [x] R4 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg64.exe;c:\windows\SYSNATIVE\CxAudMsg64.exe [x] R4 DozeSvc;Lenovo Doze Mode Service;c:\program files (x86)\ThinkPad\Utilities\DZSVC64.EXE;c:\program files (x86)\ThinkPad\Utilities\DZSVC64.EXE [x] R4 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [x] R4 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction;c:\program files\Lenovo\Communications Utility\TPKNRSVC.exe;c:\program files\Lenovo\Communications Utility\TPKNRSVC.exe [x] R4 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;c:\program files\LENOVO\VIRTSCRL\lvvsst.exe;c:\program files\LENOVO\VIRTSCRL\lvvsst.exe [x] R4 LSCWinService;LSCWinService;c:\program files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe;c:\program files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [x] R4 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] R4 TPHKLOAD;Lenovo Hotkey Client Loader;c:\program files\LENOVO\HOTKEY\TPHKLOAD.exe;c:\program files\LENOVO\HOTKEY\TPHKLOAD.exe [x] S0 DzHDD64;DzHDD64;c:\windows\System32\DRIVERS\DzHDD64.sys;c:\windows\SYSNATIVE\DRIVERS\DzHDD64.sys [x] S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x] S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM64.sys;c:\windows\SYSNATIVE\DRIVERS\ApsHM64.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiifx64.sys;c:\windows\SYSNATIVE\DRIVERS\smiifx64.sys [x] S1 nvkflt;nvkflt;c:\windows\system32\DRIVERS\nvkflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvkflt.sys [x] S1 PHCORE;PHCORE;c:\program files\Lenovo\RapidBoot\PHCORE64.SYS;c:\program files\Lenovo\RapidBoot\PHCORE64.SYS [x] S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxDrv.sys [x] S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxUSBMon.sys [x] S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x] S2 DirMngr;DirMngr;c:\program files (x86)\GNU\GnuPG\dirmngr.exe;c:\program files (x86)\GNU\GnuPG\dirmngr.exe [x] S2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe [x] S2 LENOVO.CAMMUTE;Lenovo Camera Mute;c:\program files\Lenovo\Communications Utility\CAMMUTE.exe;c:\program files\Lenovo\Communications Utility\CAMMUTE.exe [x] S2 regi;regi;c:\windows\system32\drivers\regi.sys;c:\windows\SYSNATIVE\drivers\regi.sys [x] S2 risdxc;risdxc;c:\windows\system32\DRIVERS\risdxc64.sys;c:\windows\SYSNATIVE\DRIVERS\risdxc64.sys [x] S2 SAService;Conexant SmartAudio service;c:\windows\system32\SAsrv.exe;c:\windows\SYSNATIVE\SAsrv.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 TPHKSVC;Anzeige am Bildschirm;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x] S3 5U877;USB Video Device;c:\windows\system32\DRIVERS\5U877.sys;c:\windows\SYSNATIVE\DRIVERS\5U877.sys [x] S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed - Virtueller Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x] S3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x] S3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\DRIVERS\Tvti2c.sys;c:\windows\SYSNATIVE\DRIVERS\Tvti2c.sys [x] S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x] S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2014-02-02 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-15 10:32] . 2014-02-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-10-16 11:17] . 2014-02-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-10-16 11:17] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}] 2013-01-30 14:49 342176 ----a-w- c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ForteConfig"="c:\program files\Conexant\ForteConfig\fmapp.exe" [2010-10-26 49056] "SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2011-03-14 316032] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-03-10 167960] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-03-10 391704] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-03-10 418840] "LENOVO.TPKNRRES"="c:\program files\Lenovo\Communications Utility\TPKNRRES.exe" [2013-05-29 60920] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\nvinitx.dll c:\windows\System32\nvinitx.dll . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Free YouTube Download - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm IE: Free YouTube to MP3 Converter - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm IE: {{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll TCP: DhcpNameServer = 192.168.2.1 DPF: {12193C65-F0E1-4DD1-AD4E-DB73C6911011} - file:///H:/Mydlink/activeX/DCP.cab FF - ProfilePath - c:\users\Benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default\ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKCU-Run-AdobeBridge - (no file) Wow6432Node-HKLM-Run-<NO NAME> - (no file) HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.0_03" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.0_04" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.0_05" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_01" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_01" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_02" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_02" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_03" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_03" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_04" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_04" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_05" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_05" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_06" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_06" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_07" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_07" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_08" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_08" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_09" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_09" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_10" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_10" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_11" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_11" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_12" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_12" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_13" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_13" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_14" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_14" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_15" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_15" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_16" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_16" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_17" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_17" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_18" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_18" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_19" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_19" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_20" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_20" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_21" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_21" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_01" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_01" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_02" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_02" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_03" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_03" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_04" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_04" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_01" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_01" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_02" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_02" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_03" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_03" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_04" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_04" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_05" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_05" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_06" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_06" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_07" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_07" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_01" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_01" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_02" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_02" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_03" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_03" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_04" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_04" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_05" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_05" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_06" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_06" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_07" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_07" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_08" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_08" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_09" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_09" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_10" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_10" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_11" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_11" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_12" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_12" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_13" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_13" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_14" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_14" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_15" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_15" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_16" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_16" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_17" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_17" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_18" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_18" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_19" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_19" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_20" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_20" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_21" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_21" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_22" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_22" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_23" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_23" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_24" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_24" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_25" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_25" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_26" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_26" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_27" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_27" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_28" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_28" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_29" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_29" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_30" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_30" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_31" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_31" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_32" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_32" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_33" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_33" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_34" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_34" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_35" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_35" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_36" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_36" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_37" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_37" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_38" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_38" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_39" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_39" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_40" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_40" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0041-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_41" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0041-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_41" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0042-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_42" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0042-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_42" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0043-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_43" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-0043-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_43" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_01" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_01" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_01" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_02" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_02" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_02" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_03" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_03" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_03" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_04" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_04" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_04" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_05" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_05" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_05" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_06" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_06" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_06" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_07" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_07" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_07" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_08" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_08" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_08" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_09" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_09" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_09" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_10" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_10" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_10" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_11" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_11" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_11" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_12" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_12" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_12" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_13" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_13" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_13" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_14" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_14" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_14" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_15" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_15" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_15" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_16" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_16" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_16" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_17" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_17" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_17" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_18" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_18" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_18" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_19" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_19" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_19" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_20" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_20" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_20" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_21" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_21" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_21" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_22" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_22" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_22" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_23" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_23" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_23" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_24" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_24" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_24" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_25" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_25" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_25" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_26" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_26" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_26" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_27" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_27" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_27" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_28" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_28" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_28" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_29" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_29" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_29" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_30" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_30" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_30" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_31" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_31" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0031-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_31" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_32" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_32" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0032-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_32" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_33" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_33" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0033-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_33" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_34" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_34" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0034-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_34" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_35" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_35" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0035-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_35" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_36" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_36" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0036-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_36" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_37" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_37" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0037-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_37" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_38" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_38" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0038-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_38" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_39" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_39" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0039-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_39" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_40" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_40" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0040-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_40" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0041-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_41" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0041-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_41" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0041-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_41" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0042-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_42" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0042-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_42" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0042-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_42" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0043-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_43" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0043-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_43" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0043-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_43" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0044-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_44" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0044-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_44" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0044-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_44" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0045-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_45" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0045-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_45" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0045-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_45" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0046-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_46" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0046-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_46" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0046-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_46" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0047-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_47" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0047-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_47" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0047-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_47" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0048-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_48" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0048-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_48" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0048-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_48" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0049-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_49" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0049-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_49" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0049-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_49" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0050-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_50" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0050-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_50" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0050-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_50" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0051-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_51" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0051-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_51" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0051-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_51" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0052-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_52" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0052-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_52" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0052-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_52" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0053-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_53" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0053-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_53" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0053-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_53" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0054-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_54" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0054-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_54" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0054-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_54" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0055-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_55" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0055-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_55" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0055-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_55" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0056-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_56" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0056-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_56" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0056-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_56" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0057-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_57" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0057-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_57" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0057-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_57" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0058-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_58" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0058-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_58" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0058-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_58" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0059-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_59" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0059-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_59" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0059-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_59" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0060-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_60" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0060-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_60" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0060-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_60" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0061-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_61" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0061-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_61" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-0061-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_61" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_01" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_01" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_01" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_02" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_02" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_02" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_03" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_03" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_03" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_04" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_04" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_04" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_05" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_05" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_05" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_06" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_06" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_06" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_07" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_07" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_07" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_08" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_08" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_08" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_09" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_09" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_09" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_10" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_10" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_10" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_11" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_11" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_11" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_12" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_12" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_12" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_13" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_13" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_13" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_14" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_14" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_14" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_15" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_15" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_15" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_16" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_16" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_16" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_17" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_17" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_17" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_18" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_18" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_18" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_19" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_19" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_19" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_20" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_20" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_20" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_21" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_21" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_21" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_22" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_22" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_22" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_23" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_23" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_23" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_24" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_24" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_24" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_25" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_25" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_25" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_26" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_26" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_26" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_27" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_27" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_27" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_28" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_28" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0028-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_28" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_29" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_29" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_29" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_30" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_30" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_30" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_31" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_31" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_31" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_32" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_32" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_32" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_33" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_33" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_33" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_34" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_34" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_34" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_35" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_35" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_35" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_36" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_36" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0036-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_36" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_37" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_37" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_37" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_38" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_38" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_38" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_39" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_39" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_39" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_40" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_40" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0040-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_40" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0041-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_41" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0041-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_41" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0041-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_41" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0042-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_42" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0042-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_42" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0042-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_42" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_43" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_43" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_43" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0044-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_44" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0044-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_44" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0044-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_44" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_45" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_45" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_45" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0046-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_46" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0046-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_46" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0046-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_46" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0047-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_47" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0047-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_47" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0047-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_47" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0048-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_48" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0048-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_48" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0048-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_48" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0049-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_49" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0049-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_49" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0049-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_49" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0050-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_50" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0050-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_50" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0050-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_50" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0051-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_51" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0051-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_51" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0051-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_51" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0052-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_52" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0052-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_52" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0052-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_52" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0053-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_53" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0053-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_53" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0053-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_53" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0054-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_54" . |
03.02.2014, 15:45 | #6 |
| Rechner hakt und hat Aussetzer Combofix - Teil 2 Code:
ATTFilter [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0054-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_54" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0054-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_54" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0055-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_55" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0055-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_55" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0055-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_55" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0056-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_56" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0056-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_56" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0056-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_56" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0057-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_57" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0057-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_57" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0057-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_57" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0058-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_58" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0058-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_58" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0058-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_58" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0059-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_59" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0059-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_59" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0059-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_59" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0060-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_60" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0060-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_60" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0060-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_60" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0061-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_61" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0061-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_61" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0061-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_61" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0062-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_62" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0062-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_62" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0062-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_62" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0063-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_63" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0063-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_63" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0063-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_63" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0064-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_64" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0064-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_64" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0064-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_64" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0065-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_65" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0065-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_65" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0065-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_65" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0066-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_66" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0066-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_66" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0066-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_66" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0067-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_67" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0067-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_67" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0067-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_67" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0068-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_68" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0068-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_68" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0068-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_68" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0069-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_69" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0069-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_69" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0069-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_69" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0070-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_70" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0070-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_70" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0070-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_70" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0071-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_71" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0071-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_71" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-0071-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_71" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0016-0000-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_01" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_01" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_01" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_02" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_02" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0002-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_02" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_03" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_03" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0003-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_03" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_04" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_04" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0004-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_04" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_05" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_05" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0005-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_05" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_06" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_06" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0006-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_06" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_07" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_07" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0007-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_07" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_08" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_08" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0008-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_08" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_09" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_09" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0009-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_09" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_10" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_10" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0010-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_10" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_11" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_11" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0011-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_11" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_12" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_12" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0012-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_12" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_13" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_13" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_13" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_14" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_14" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0014-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_14" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_15" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_15" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0015-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_15" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_16" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_16" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0016-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_16" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_17" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_17" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0017-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_17" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_18" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_18" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0018-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_18" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_19" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_19" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0019-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_19" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_20" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_20" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0020-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_20" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_21" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_21" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0021-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_21" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_22" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_22" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0022-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_22" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_23" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_23" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0023-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_23" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_24" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_24" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0024-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_24" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_25" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_25" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_25" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_26" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_26" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0026-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_26" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_27" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_27" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0027-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_27" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_28" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_28" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0028-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_28" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_29" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_29" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0029-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_29" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_30" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_30" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0030-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_30" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_31" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_31" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0031-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_31" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_32" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_32" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0032-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_32" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_33" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_33" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0033-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_33" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_34" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_34" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0034-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_34" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_35" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_35" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0035-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_35" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_36" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_36" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0036-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_36" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_37" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_37" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0037-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_37" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_38" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_38" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0038-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_38" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_39" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_39" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0039-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_39" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_40" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_40" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0040-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_40" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0041-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_41" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0041-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_41" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0041-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_41" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0042-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_42" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0042-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_42" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0042-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_42" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0043-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_43" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0043-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_43" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0043-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_43" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0044-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_44" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0044-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_44" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0044-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_44" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_45" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0045-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_45" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0045-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_45" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0046-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_46" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0046-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_46" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0046-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_46" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0047-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_47" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0047-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_47" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0047-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_47" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0048-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_48" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0048-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_48" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0048-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_48" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0049-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_49" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0049-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_49" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0049-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_49" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0050-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_50" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0050-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_50" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0050-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_50" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0051-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_51" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0051-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_51" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-0051-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_51" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-1502850821-2927420759-2148834354-1001_Classes\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}] @DACL=(02 0000) @="Java Plug-in 1.3.0_02" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_38_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_38_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_38_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_38_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\windows\SysWOW64\SAsrv.exe c:\program files (x86)\Lenovo\Access Connections\AcSvc.exe c:\program files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe . ************************************************************************** . Zeit der Fertigstellung: 2014-02-02 08:33:54 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2014-02-02 07:33 . Vor Suchlauf: 21 Verzeichnis(se), 27.657.695.232 Bytes frei Nach Suchlauf: 23 Verzeichnis(se), 29.633.802.240 Bytes frei . - - End Of File - - FCA6C1BF69B8A1318F557D7D52E271EA Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.02.03.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16476 Benutzername :: Benutzer-THINK [Administrator] 03.02.2014 14:53:31 mbam-log-2014-02-03 (14-53-31).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 258814 Laufzeit: 7 Minute(n), 49 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter # AdwCleaner v3.018 - Bericht erstellt am 03/02/2014 um 15:12:50 # Updated 28/01/2014 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Benutzername - Benutzername-THINK # Gestartet von : C:\Users\Benutzername\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Partner Ordner Gelöscht : C:\Program Files (x86)\FreeRIP Ordner Gelöscht : C:\Users\Benutzername\AppData\Roaming\dvdvideosoftiehelpers ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_pocket-killbox_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_pocket-killbox_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Softonic ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v26.0 (de) [ Datei : C:\Users\Benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default\prefs.js ] [ Datei : C:\Users\Benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\26598o8d.default\prefs.js ] [ Datei : C:\Users\Benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\lsxerknw.Benutzername\prefs.js ] ************************* AdwCleaner[R0].txt - [2515 octets] - [03/02/2014 15:10:54] AdwCleaner[S0].txt - [2383 octets] - [03/02/2014 15:12:50] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2443 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.0 (01.07.2014:1) OS: Windows 7 Professional x64 Ran by Benutzername on 03.02.2014 at 15:21:44,19 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\caphyon ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\apn" Successfully deleted: [Empty Folder] C:\Users\Benutzername\appdata\local\{56d76256-d551-d3c2-818a-fa84f69dc1cd} ~~~ FireFox Emptied folder: C:\Users\Benutzername\AppData\Roaming\mozilla\firefox\profiles\upm9xjxr.default\minidumps [59 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 03.02.2014 at 15:39:26,06 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2014 03 Ran by Benutzername (administrator) on Benutzername-THINK on 03-02-2014 15:42:19 Running from C:\Users\Benutzername\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CamMute.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Lenovo Group Limited) C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE (Lenovo) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ForteConfig] - C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] () HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2011-03-14] (Conexant systems, Inc.) HKLM\...\Run: [LENOVO.TPKNRRES] - C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [60920 2013-05-29] (Lenovo Group Limited) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated) HKLM-x32\...\Run: [PWMTRV] - rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-17] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [] - [x] Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1502850821-2927420759-2148834354-1001\...\Run: [FileHippo.com] - C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe [307712 2012-11-23] (FileHippo.com) AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [245872 2013-11-15] (NVIDIA Corporation) AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [245872 2013-11-15] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [201576 2013-11-15] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com/welcome/thinkpad StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENP BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {12193C65-F0E1-4DD1-AD4E-DB73C6911011} file:///H:/Mydlink/activeX/DCP.cab DPF: HKLM-x32 {7191F0AC-D686-46A8-BFCC-EA61778C74DD} file:///H:/Mydlink/activeX/aplugLiteDL.cab Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File FF Plugin: adobe.com/AdobeAAMDetect_x86_64 - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101714.dll (Amazon.com, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Default Full Zoom Level - C:\Users\Benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default\Extensions\{D9A7CBEC-DE1A-444f-A092-844461596C4D} [2013-05-28] FF Extension: Firebug - C:\Users\Benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default\Extensions\firebug@software.joehewitt.com.xpi [2012-05-06] FF Extension: NoScript - C:\Users\Benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2012-08-22] FF Extension: MeasureIt - C:\Users\Benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default\Extensions\{75CEEE46-9B64-46f8-94BF-54012DE155F0}.xpi [2012-07-09] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-17] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-14] (Avira Operations GmbH & Co. KG) S4 bckwfs; C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe [2649840 2013-03-01] (Blue Coat Systems, Inc.) R2 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [218112 2013-08-20] () S4 DozeSvc; C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [478056 2012-02-27] (Lenovo.) S4 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [133992 2011-07-12] (Lenovo Group Limited) S4 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [30184 2013-08-08] () S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-02-08] () S4 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22376 2013-06-26] () R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3386608 2013-02-08] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [284448 2013-11-15] (NVIDIA Corporation) R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [41536 2009-09-24] (Lenovo (United States) Inc.) S2 bckd; system32\drivers\bckd.sys [x] S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-03 15:39 - 2014-02-03 15:39 - 00000990 _____ () C:\Users\Benutzername\Desktop\JRT.txt 2014-02-03 15:21 - 2014-02-03 15:21 - 01037068 _____ (Thisisu) C:\Users\Benutzername\Desktop\JRT.exe 2014-02-03 15:21 - 2014-02-03 15:21 - 00000000 ____D () C:\Windows\ERUNT 2014-02-03 15:14 - 2014-02-03 15:14 - 00000022 _____ () C:\Windows\S.dirmngr 2014-02-03 15:10 - 2014-02-03 15:13 - 00000000 ____D () C:\AdwCleaner 2014-02-03 15:10 - 2014-02-03 15:10 - 01166132 _____ () C:\Users\Benutzername\Desktop\adwcleaner.exe 2014-02-03 14:51 - 2014-02-03 14:51 - 00001124 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-03 14:51 - 2014-02-03 14:51 - 00001124 _____ () C:\ProgramData\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-03 14:51 - 2014-02-03 14:51 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-03 14:51 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-02 08:35 - 2014-02-02 08:35 - 00145970 _____ () C:\Users\Benutzername\Desktop\combofix.txt 2014-02-02 08:33 - 2014-02-02 08:33 - 00145931 _____ () C:\ComboFix.txt 2014-02-02 08:05 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-02-02 08:05 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-02-02 08:05 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-02-02 08:05 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-02-02 08:05 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-02-02 08:05 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-02-02 08:05 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-02-02 08:05 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-02-02 08:04 - 2014-02-02 08:34 - 00000000 ____D () C:\Qoobox 2014-02-02 08:02 - 2014-02-02 08:03 - 05179159 ____R (Swearware) C:\Users\Benutzername\Desktop\ComboFix.exe 2014-02-01 19:25 - 2014-02-01 19:25 - 00000242 _____ () C:\Users\Benutzername\Desktop\defogger_enable.log 2014-02-01 19:19 - 2014-02-01 19:36 - 00002974 _____ () C:\Users\Benutzername\Desktop\gmer.log 2014-02-01 18:54 - 2014-02-01 19:35 - 00026040 _____ () C:\Users\Benutzername\Desktop\Addition.txt 2014-02-01 18:52 - 2014-02-03 15:42 - 00013830 _____ () C:\Users\Benutzername\Desktop\FRST.txt 2014-02-01 18:52 - 2014-02-03 15:42 - 00000000 ____D () C:\FRST 2014-02-01 18:49 - 2014-02-01 18:49 - 00000470 _____ () C:\Users\Benutzername\Desktop\defogger_disable.log 2014-02-01 14:36 - 2014-02-01 14:36 - 00380416 _____ () C:\Users\Benutzername\Desktop\Gmer-19357.exe 2014-02-01 14:34 - 2014-02-01 14:34 - 02080256 _____ (Farbar) C:\Users\Benutzername\Desktop\FRST64.exe 2014-02-01 14:33 - 2014-02-01 14:34 - 00050477 _____ () C:\Users\Benutzername\Desktop\Defogger.exe 2014-01-29 12:37 - 2014-01-29 12:37 - 00000976 _____ () C:\Users\Benutzername\Desktop\terminal.lnk 2014-01-24 12:18 - 2014-01-24 12:19 - 00000057 _____ () C:\Users\Benutzername\Desktop\Kaufen.txt 2014-01-23 11:32 - 2014-01-23 11:33 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-01-23 11:32 - 2014-01-23 11:33 - 00000000 ____D () C:\Program Files\iTunes 2014-01-23 11:32 - 2014-01-23 11:33 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-01-23 11:32 - 2014-01-23 11:32 - 00000000 ____D () C:\Program Files\iPod 2014-01-23 11:15 - 2014-01-23 11:15 - 00000000 ____D () C:\Users\Benutzername\elan2013 2014-01-23 11:14 - 2014-01-23 11:14 - 00000000 ____D () C:\Program Files\REHADAT 2014-01-21 09:59 - 2014-01-21 09:59 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-01-21 09:50 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 09:37 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys ==================== One Month Modified Files and Folders ======= 2014-02-03 15:43 - 2014-02-01 18:52 - 00013830 _____ () C:\Users\Benutzername\Desktop\FRST.txt 2014-02-03 15:42 - 2014-02-01 18:52 - 00000000 ____D () C:\FRST 2014-02-03 15:39 - 2014-02-03 15:39 - 00000990 _____ () C:\Users\Benutzername\Desktop\JRT.txt 2014-02-03 15:21 - 2014-02-03 15:21 - 01037068 _____ (Thisisu) C:\Users\Benutzername\Desktop\JRT.exe 2014-02-03 15:21 - 2014-02-03 15:21 - 00000000 ____D () C:\Windows\ERUNT 2014-02-03 15:21 - 2009-07-14 05:45 - 00031072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-03 15:21 - 2009-07-14 05:45 - 00031072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-03 15:18 - 2012-03-30 13:23 - 00699682 _____ () C:\Windows\system32\perfh007.dat 2014-02-03 15:18 - 2012-03-30 13:23 - 00149790 _____ () C:\Windows\system32\perfc007.dat 2014-02-03 15:18 - 2009-07-14 06:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-03 15:17 - 2012-03-30 03:40 - 01985944 _____ () C:\Windows\WindowsUpdate.log 2014-02-03 15:14 - 2014-02-03 15:14 - 00000022 _____ () C:\Windows\S.dirmngr 2014-02-03 15:14 - 2013-10-16 12:18 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-03 15:14 - 2012-04-14 15:30 - 00115446 _____ () C:\Windows\setupact.log 2014-02-03 15:14 - 2012-03-30 03:55 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-03 15:14 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-03 15:13 - 2014-02-03 15:10 - 00000000 ____D () C:\AdwCleaner 2014-02-03 15:10 - 2014-02-03 15:10 - 01166132 _____ () C:\Users\Benutzername\Desktop\adwcleaner.exe 2014-02-03 15:10 - 2013-01-05 16:36 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-03 14:53 - 2013-10-16 12:18 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-03 14:51 - 2014-02-03 14:51 - 00001124 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-03 14:51 - 2014-02-03 14:51 - 00001124 _____ () C:\ProgramData\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-03 14:51 - 2014-02-03 14:51 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-02 08:44 - 2012-04-14 12:44 - 00000000 ____D () C:\Users\Benutzername\AppData\Roaming\Adobe 2014-02-02 08:43 - 2012-03-30 03:58 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-02-02 08:40 - 2012-04-15 07:54 - 00000000 ____D () C:\Users\Benutzername\AppData\Local\Adobe 2014-02-02 08:35 - 2014-02-02 08:35 - 00145970 _____ () C:\Users\Benutzername\Desktop\combofix.txt 2014-02-02 08:34 - 2014-02-02 08:04 - 00000000 ____D () C:\Qoobox 2014-02-02 08:33 - 2014-02-02 08:33 - 00145931 _____ () C:\ComboFix.txt 2014-02-02 08:26 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2014-02-02 08:25 - 2010-11-21 04:47 - 01092244 _____ () C:\Windows\PFRO.log 2014-02-02 08:25 - 2009-07-14 03:34 - 65536000 _____ () C:\Windows\system32\config\SOFTWARE.bak 2014-02-02 08:25 - 2009-07-14 03:34 - 17563648 _____ () C:\Windows\system32\config\SYSTEM.bak 2014-02-02 08:25 - 2009-07-14 03:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak 2014-02-02 08:25 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak 2014-02-02 08:25 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak 2014-02-02 08:24 - 2012-07-16 13:17 - 00000000 ____D () C:\Windows\erdnt 2014-02-02 08:03 - 2014-02-02 08:02 - 05179159 ____R (Swearware) C:\Users\Benutzername\Desktop\ComboFix.exe 2014-02-02 08:03 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-02-01 19:36 - 2014-02-01 19:19 - 00002974 _____ () C:\Users\Benutzername\Desktop\gmer.log 2014-02-01 19:35 - 2014-02-01 18:54 - 00026040 _____ () C:\Users\Benutzername\Desktop\Addition.txt 2014-02-01 19:25 - 2014-02-01 19:25 - 00000242 _____ () C:\Users\Benutzername\Desktop\defogger_enable.log 2014-02-01 19:25 - 2012-04-14 07:02 - 00000000 ____D () C:\Users\Benutzername 2014-02-01 18:49 - 2014-02-01 18:49 - 00000470 _____ () C:\Users\Benutzername\Desktop\defogger_disable.log 2014-02-01 14:36 - 2014-02-01 14:36 - 00380416 _____ () C:\Users\Benutzername\Desktop\Gmer-19357.exe 2014-02-01 14:34 - 2014-02-01 14:34 - 02080256 _____ (Farbar) C:\Users\Benutzername\Desktop\FRST64.exe 2014-02-01 14:34 - 2014-02-01 14:33 - 00050477 _____ () C:\Users\Benutzername\Desktop\Defogger.exe 2014-01-29 12:37 - 2014-01-29 12:37 - 00000976 _____ () C:\Users\Benutzername\Desktop\terminal.lnk 2014-01-24 12:19 - 2014-01-24 12:18 - 00000057 _____ () C:\Users\Benutzername\Desktop\Kaufen.txt 2014-01-23 14:07 - 2012-05-12 16:37 - 00000000 ____D () C:\Program Files (x86)\phase5 2014-01-23 11:33 - 2014-01-23 11:32 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-01-23 11:33 - 2014-01-23 11:32 - 00000000 ____D () C:\Program Files\iTunes 2014-01-23 11:33 - 2014-01-23 11:32 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-01-23 11:32 - 2014-01-23 11:32 - 00000000 ____D () C:\Program Files\iPod 2014-01-23 11:32 - 2013-01-05 16:36 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-01-23 11:32 - 2012-04-15 07:46 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-01-23 11:32 - 2012-04-15 07:46 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-01-23 11:28 - 2013-07-12 17:42 - 00000000 ____D () C:\ProgramData\Apple 2014-01-23 11:25 - 2013-07-12 17:45 - 00000000 ____D () C:\Users\Benutzername\AppData\Roaming\Apple Computer 2014-01-23 11:15 - 2014-01-23 11:15 - 00000000 ____D () C:\Users\Benutzername\elan2013 2014-01-23 11:14 - 2014-01-23 11:14 - 00000000 ____D () C:\Program Files\REHADAT 2014-01-21 10:03 - 2012-03-30 03:56 - 00000000 ____D () C:\Windows\SysWOW64\NV 2014-01-21 10:03 - 2012-03-30 03:56 - 00000000 ____D () C:\Windows\system32\NV 2014-01-21 09:59 - 2014-01-21 09:59 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-01-21 09:55 - 2012-03-30 03:54 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-01-21 09:52 - 2012-03-30 03:54 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-01-21 09:51 - 2013-12-11 08:36 - 01594964 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-01-21 09:50 - 2012-03-30 03:58 - 00000000 ____D () C:\ProgramData\Adobe 2014-01-21 09:44 - 2012-07-20 08:49 - 00000000 ____D () C:\xampp 2014-01-15 12:35 - 2009-07-14 05:45 - 04950184 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-15 09:42 - 2013-07-11 07:17 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-15 09:38 - 2012-04-14 16:44 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-15 09:31 - 2012-08-17 13:03 - 00001456 _____ () C:\Users\Benutzername\AppData\Local\Adobe Für Web speichern 13.0 Prefs ZeroAccess: C:\Windows\Installer\{56d76256-d551-d3c2-818a-fa84f69dc1cd} ZeroAccess: C:\Users\Benutzername\AppData\Local\{56d76256-d551-d3c2-818a-fa84f69dc1cd} Some content of TEMP: ==================== C:\Users\Benutzername\AppData\Local\Temp\avgnt.exe C:\Users\Benutzername\AppData\Local\Temp\AAMHelper.exe C:\Users\Benutzername\AppData\Local\Temp\AdobeApplicationManager.exe C:\Users\Benutzername\AppData\Local\Temp\avgnt.exe C:\Users\Benutzername\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-29 18:32 ==================== End Of Log ============================ --- --- --- Geändert von wenjin (03.02.2014 um 15:18 Uhr) |
04.02.2014, 11:37 | #7 |
/// the machine /// TB-Ausbilder | Rechner hakt und hat AussetzerESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.02.2014, 10:34 | #8 |
| Rechner hakt und hat Aussetzer Schöner Mist: hab heute nacht den ESET-Scan laufen lassen und habe heute morgen - schlaftrunken - beim Schließen des Programms die Option "Uninstall after close" o.s.ä. geklickt. Futsch und weg war die Log.txt. Auch ein Recovery-Tool konnte sie nicht wiederherstellen. Ich weiß nur, dass mir das Programm am Ende anzeigte, keine Bedrohungen gefunden zu haben. Soll ich den Scan trotzdem nochmal laufen lassen? Ansonsten läuft der Rechner wieder ganz normal. Auch der Browser hat keine Aussetzer mehr. Und hier noch die checkup.txt: Code:
ATTFilter Results of screen317's Security Check version 0.99.79 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Java(TM) 6 Update 31 Java 7 Update 9 Java version out of Date! Adobe Flash Player 12.0.0.44 Flash Player out of Date! Adobe Reader XI Mozilla Firefox (27.0) Mozilla Thunderbird (24.3.0) Google Chrome 18.0.1025.162 ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Und hier noch die neue FRST.txt: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-02-2014 Ran by Benutzername (administrator) on Benutzername-THINK on 08-02-2014 10:36:05 Running from C:\Users\Benutzername\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CamMute.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Lenovo Group Limited) C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Lenovo) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe (Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ForteConfig] - C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] () HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2011-03-14] (Conexant systems, Inc.) HKLM\...\Run: [LENOVO.TPKNRRES] - C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [60920 2013-05-29] (Lenovo Group Limited) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-12-10] (Adobe Systems Incorporated) HKLM-x32\...\Run: [PWMTRV] - rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-17] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [] - [X] Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1502850821-2927420759-2148834354-1001\...\Run: [FileHippo.com] - C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe [307712 2012-11-23] (FileHippo.com) AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [245872 2013-11-15] (NVIDIA Corporation) AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [245872 2013-11-15] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [201576 2013-11-15] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com/welcome/thinkpad StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENP BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {12193C65-F0E1-4DD1-AD4E-DB73C6911011} file:///H:/Mydlink/activeX/DCP.cab DPF: HKLM-x32 {7191F0AC-D686-46A8-BFCC-EA61778C74DD} file:///H:/Mydlink/activeX/aplugLiteDL.cab Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_44.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File FF Plugin: adobe.com/AdobeAAMDetect_x86_64 - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101714.dll (Amazon.com, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Default Full Zoom Level - C:\Users\Benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default\Extensions\{D9A7CBEC-DE1A-444f-A092-844461596C4D} [2013-05-28] FF Extension: Firebug - C:\Users\Benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default\Extensions\firebug@software.joehewitt.com.xpi [2012-05-06] FF Extension: NoScript - C:\Users\Benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2012-08-22] FF Extension: MeasureIt - C:\Users\Benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default\Extensions\{75CEEE46-9B64-46f8-94BF-54012DE155F0}.xpi [2012-07-09] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-17] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-14] (Avira Operations GmbH & Co. KG) S4 bckwfs; C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe [2649840 2013-03-01] (Blue Coat Systems, Inc.) R2 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [218112 2013-08-20] () S4 DozeSvc; C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [478056 2012-02-27] (Lenovo.) S4 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [133992 2011-07-12] (Lenovo Group Limited) S4 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [30184 2013-08-08] () S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S4 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-02-08] () S4 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22376 2013-06-26] () R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3386608 2013-02-08] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [284448 2013-11-15] (NVIDIA Corporation) R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [41536 2009-09-24] (Lenovo (United States) Inc.) S2 bckd; system32\drivers\bckd.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-08 10:35 - 2014-02-08 10:35 - 00000000 ____D () C:\Users\Benutzername\Desktop\FRST-OlderVersion 2014-02-08 10:03 - 2014-02-08 10:03 - 00987425 _____ () C:\Users\Benutzername\Desktop\SecurityCheck.exe 2014-02-07 22:50 - 2014-02-07 22:50 - 00000022 _____ () C:\Windows\S.dirmngr 2014-02-04 19:10 - 2014-02-04 19:10 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-02-04 19:09 - 2014-02-04 19:09 - 02347384 _____ (ESET) C:\Users\Benutzername\Desktop\esetsmartinstaller_enu.exe 2014-02-03 15:39 - 2014-02-03 15:39 - 00000990 _____ () C:\Users\Benutzername\Desktop\JRT.txt 2014-02-03 15:21 - 2014-02-03 15:21 - 01037068 _____ (Thisisu) C:\Users\Benutzername\Desktop\JRT.exe 2014-02-03 15:21 - 2014-02-03 15:21 - 00000000 ____D () C:\Windows\ERUNT 2014-02-03 15:10 - 2014-02-03 15:13 - 00000000 ____D () C:\AdwCleaner 2014-02-03 15:10 - 2014-02-03 15:10 - 01166132 _____ () C:\Users\Benutzername\Desktop\adwcleaner.exe 2014-02-03 14:51 - 2014-02-03 14:51 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-03 14:51 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-02 08:35 - 2014-02-02 08:35 - 00145970 _____ () C:\Users\Benutzername\Desktop\combofix.txt 2014-02-02 08:33 - 2014-02-02 08:33 - 00145931 _____ () C:\ComboFix.txt 2014-02-02 08:05 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-02-02 08:05 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-02-02 08:05 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-02-02 08:05 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-02-02 08:05 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-02-02 08:05 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-02-02 08:05 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-02-02 08:05 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-02-02 08:04 - 2014-02-02 08:34 - 00000000 ____D () C:\Qoobox 2014-02-02 08:02 - 2014-02-02 08:03 - 05179159 ____R (Swearware) C:\Users\Benutzername\Desktop\ComboFix.exe 2014-02-01 19:25 - 2014-02-01 19:25 - 00000242 _____ () C:\Users\Benutzername\Desktop\defogger_enable.log 2014-02-01 19:19 - 2014-02-01 19:36 - 00002974 _____ () C:\Users\Benutzername\Desktop\gmer.log 2014-02-01 18:54 - 2014-02-01 19:35 - 00026040 _____ () C:\Users\Benutzername\Desktop\Addition.txt 2014-02-01 18:52 - 2014-02-08 10:36 - 00014130 _____ () C:\Users\Benutzername\Desktop\FRST.txt 2014-02-01 18:52 - 2014-02-08 10:36 - 00000000 ____D () C:\FRST 2014-02-01 18:49 - 2014-02-01 18:49 - 00000470 _____ () C:\Users\Benutzername\Desktop\defogger_disable.log 2014-02-01 14:36 - 2014-02-01 14:36 - 00380416 _____ () C:\Users\Benutzername\Desktop\Gmer-19357.exe 2014-02-01 14:34 - 2014-02-08 10:35 - 02079744 _____ (Farbar) C:\Users\Benutzername\Desktop\FRST64.exe 2014-02-01 14:33 - 2014-02-01 14:34 - 00050477 _____ () C:\Users\Benutzername\Desktop\Defogger.exe 2014-01-29 12:37 - 2014-01-29 12:37 - 00000976 _____ () C:\Users\Benutzername\Desktop\terminal.lnk 2014-01-24 12:18 - 2014-01-24 12:19 - 00000057 _____ () C:\Users\Benutzername\Desktop\Kaufen.txt 2014-01-23 11:32 - 2014-01-23 11:33 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-01-23 11:32 - 2014-01-23 11:33 - 00000000 ____D () C:\Program Files\iTunes 2014-01-23 11:32 - 2014-01-23 11:33 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-01-23 11:32 - 2014-01-23 11:32 - 00000000 ____D () C:\Program Files\iPod 2014-01-23 11:15 - 2014-01-23 11:15 - 00000000 ____D () C:\Users\Benutzername\elan2013 2014-01-23 11:14 - 2014-01-23 11:14 - 00000000 ____D () C:\Program Files\REHADAT 2014-01-21 09:59 - 2014-01-21 09:59 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-01-21 09:50 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 09:37 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys ==================== One Month Modified Files and Folders ======= 2014-02-08 10:36 - 2014-02-01 18:52 - 00014130 _____ () C:\Users\Benutzername\Desktop\FRST.txt 2014-02-08 10:36 - 2014-02-01 18:52 - 00000000 ____D () C:\FRST 2014-02-08 10:35 - 2014-02-08 10:35 - 00000000 ____D () C:\Users\Benutzername\Desktop\FRST-OlderVersion 2014-02-08 10:35 - 2014-02-01 14:34 - 02079744 _____ (Farbar) C:\Users\Benutzername\Desktop\FRST64.exe 2014-02-08 10:17 - 2012-04-14 07:02 - 00000000 ____D () C:\Users\Benutzername 2014-02-08 10:13 - 2013-08-07 19:50 - 00000000 ____D () C:\Program Files\Recuva 2014-02-08 10:10 - 2013-01-05 16:36 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-08 10:03 - 2014-02-08 10:03 - 00987425 _____ () C:\Users\Benutzername\Desktop\SecurityCheck.exe 2014-02-08 10:03 - 2012-04-15 07:54 - 00000000 ____D () C:\Users\Benutzername\AppData\Local\Adobe 2014-02-08 10:02 - 2013-01-05 16:36 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-08 10:02 - 2012-04-15 07:46 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-08 10:02 - 2012-04-15 07:46 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-08 09:53 - 2013-10-16 12:18 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-08 09:48 - 2012-07-23 12:56 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-02-08 09:46 - 2012-07-23 12:59 - 00000000 ____D () C:\Program Files\Adobe Photoshop CS6 (64 Bit) 2014-02-08 09:46 - 2012-07-23 12:57 - 00000000 ____D () C:\Program Files (x86)\Adobe Extension Manager CS6 2014-02-08 07:31 - 2012-04-14 07:05 - 00000000 ____D () C:\Users\Benutzername\AppData\Local\VirtualStore 2014-02-08 07:13 - 2012-03-30 03:40 - 02068504 _____ () C:\Windows\WindowsUpdate.log 2014-02-07 22:57 - 2009-07-14 05:45 - 00031072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-07 22:57 - 2009-07-14 05:45 - 00031072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-07 22:50 - 2014-02-07 22:50 - 00000022 _____ () C:\Windows\S.dirmngr 2014-02-07 22:50 - 2013-10-16 12:18 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-07 22:50 - 2012-04-14 15:30 - 00115894 _____ () C:\Windows\setupact.log 2014-02-07 22:50 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-07 16:55 - 2012-04-14 19:40 - 00000000 ____D () C:\Users\Benutzername\AppData\Local\VirtualStore 2014-02-07 09:11 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-02-06 16:00 - 2012-05-06 07:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-06 16:00 - 2010-11-21 04:47 - 01092638 _____ () C:\Windows\PFRO.log 2014-02-05 16:25 - 2013-11-17 08:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-05 16:24 - 2013-12-11 20:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-02-04 19:10 - 2014-02-04 19:10 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-02-04 19:09 - 2014-02-04 19:09 - 02347384 _____ (ESET) C:\Users\Benutzername\Desktop\esetsmartinstaller_enu.exe 2014-02-04 16:18 - 2012-03-30 13:23 - 00699682 _____ () C:\Windows\system32\perfh007.dat 2014-02-04 16:18 - 2012-03-30 13:23 - 00149790 _____ () C:\Windows\system32\perfc007.dat 2014-02-04 16:18 - 2009-07-14 06:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-03 15:39 - 2014-02-03 15:39 - 00000990 _____ () C:\Users\Benutzername\Desktop\JRT.txt 2014-02-03 15:21 - 2014-02-03 15:21 - 01037068 _____ (Thisisu) C:\Users\Benutzername\Desktop\JRT.exe 2014-02-03 15:21 - 2014-02-03 15:21 - 00000000 ____D () C:\Windows\ERUNT 2014-02-03 15:14 - 2012-03-30 03:55 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-03 15:13 - 2014-02-03 15:10 - 00000000 ____D () C:\AdwCleaner 2014-02-03 15:10 - 2014-02-03 15:10 - 01166132 _____ () C:\Users\Benutzername\Desktop\adwcleaner.exe 2014-02-03 14:51 - 2014-02-03 14:51 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-02 08:44 - 2012-04-14 12:44 - 00000000 ____D () C:\Users\Benutzername\AppData\Roaming\Adobe 2014-02-02 08:43 - 2012-03-30 03:58 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-02-02 08:35 - 2014-02-02 08:35 - 00145970 _____ () C:\Users\Benutzername\Desktop\combofix.txt 2014-02-02 08:34 - 2014-02-02 08:04 - 00000000 ____D () C:\Qoobox 2014-02-02 08:33 - 2014-02-02 08:33 - 00145931 _____ () C:\ComboFix.txt 2014-02-02 08:26 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2014-02-02 08:25 - 2009-07-14 03:34 - 65536000 _____ () C:\Windows\system32\config\SOFTWARE.bak 2014-02-02 08:25 - 2009-07-14 03:34 - 17563648 _____ () C:\Windows\system32\config\SYSTEM.bak 2014-02-02 08:25 - 2009-07-14 03:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak 2014-02-02 08:25 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak 2014-02-02 08:25 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak 2014-02-02 08:24 - 2012-07-16 13:17 - 00000000 ____D () C:\Windows\erdnt 2014-02-02 08:03 - 2014-02-02 08:02 - 05179159 ____R (Swearware) C:\Users\Benutzername\Desktop\ComboFix.exe 2014-02-02 08:03 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-02-01 19:36 - 2014-02-01 19:19 - 00002974 _____ () C:\Users\Benutzername\Desktop\gmer.log 2014-02-01 19:35 - 2014-02-01 18:54 - 00026040 _____ () C:\Users\Benutzername\Desktop\Addition.txt 2014-02-01 19:25 - 2014-02-01 19:25 - 00000242 _____ () C:\Users\Benutzername\Desktop\defogger_enable.log 2014-02-01 18:49 - 2014-02-01 18:49 - 00000470 _____ () C:\Users\Benutzername\Desktop\defogger_disable.log 2014-02-01 14:36 - 2014-02-01 14:36 - 00380416 _____ () C:\Users\Benutzername\Desktop\Gmer-19357.exe 2014-02-01 14:34 - 2014-02-01 14:33 - 00050477 _____ () C:\Users\Benutzername\Desktop\Defogger.exe 2014-01-29 12:37 - 2014-01-29 12:37 - 00000976 _____ () C:\Users\Benutzername\Desktop\terminal.lnk 2014-01-24 12:19 - 2014-01-24 12:18 - 00000057 _____ () C:\Users\Benutzername\Desktop\Kaufen.txt 2014-01-23 14:07 - 2012-05-12 16:37 - 00000000 ____D () C:\Program Files (x86)\phase5 2014-01-23 11:33 - 2014-01-23 11:32 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-01-23 11:33 - 2014-01-23 11:32 - 00000000 ____D () C:\Program Files\iTunes 2014-01-23 11:33 - 2014-01-23 11:32 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-01-23 11:32 - 2014-01-23 11:32 - 00000000 ____D () C:\Program Files\iPod 2014-01-23 11:28 - 2013-07-12 17:42 - 00000000 ____D () C:\ProgramData\Apple 2014-01-23 11:25 - 2013-07-12 17:45 - 00000000 ____D () C:\Users\Benutzername\AppData\Roaming\Apple Computer 2014-01-23 11:15 - 2014-01-23 11:15 - 00000000 ____D () C:\Users\Benutzername\elan2013 2014-01-23 11:14 - 2014-01-23 11:14 - 00000000 ____D () C:\Program Files\REHADAT 2014-01-21 10:03 - 2012-03-30 03:56 - 00000000 ____D () C:\Windows\SysWOW64\NV 2014-01-21 10:03 - 2012-03-30 03:56 - 00000000 ____D () C:\Windows\system32\NV 2014-01-21 09:59 - 2014-01-21 09:59 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-01-21 09:55 - 2012-03-30 03:54 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-01-21 09:52 - 2012-03-30 03:54 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-01-21 09:51 - 2013-12-11 08:36 - 01594964 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-01-21 09:50 - 2012-03-30 03:58 - 00000000 ____D () C:\ProgramData\Adobe 2014-01-21 09:44 - 2012-07-20 08:49 - 00000000 ____D () C:\xampp 2014-01-15 12:35 - 2009-07-14 05:45 - 04950184 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-15 09:42 - 2013-07-11 07:17 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-15 09:38 - 2012-04-14 16:44 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-15 09:31 - 2012-08-17 13:03 - 00001456 _____ () C:\Users\Benutzername\AppData\Local\Adobe Für Web speichern 13.0 Prefs ZeroAccess: C:\Windows\Installer\{56d76256-d551-d3c2-818a-fa84f69dc1cd} ZeroAccess: C:\Users\Benutzername\AppData\Local\{56d76256-d551-d3c2-818a-fa84f69dc1cd} Some content of TEMP: ==================== C:\Users\Benutzername\AppData\Local\Temp\avgnt.exe C:\Users\Benutzername\AppData\Local\Temp\AAMHelper.exe C:\Users\Benutzername\AppData\Local\Temp\AdobeApplicationManager.exe C:\Users\Benutzername\AppData\Local\Temp\avgnt.exe C:\Users\Benutzername\AppData\Local\Temp\install_flashplayer12x32_mssd_aaa_aih.exe C:\Users\Benutzername\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-08 07:48 ==================== End Of Log ============================ --- --- --- --- --- --- Geändert von wenjin (08.02.2014 um 10:40 Uhr) |
09.02.2014, 08:33 | #9 |
/// the machine /// TB-Ausbilder | Rechner hakt und hat Aussetzer Passt schon. Java updaten, Flash ist ne Falschanzeige. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter ZeroAccess: C:\Windows\Installer\{56d76256-d551-d3c2-818a-fa84f69dc1cd} ZeroAccess: C:\Users\Benutzername\AppData\Local\{56d76256-d551-d3c2-818a-fa84f69dc1cd} Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.02.2014, 10:07 | #10 |
| Rechner hakt und hat Aussetzer Hallo, hier die Fixlog.txt. Hatte es versehentlich zweimal laufen lassen. Vielleicht wurde deswegen die eine Datei nicht gefunden (weil bereits beim ersten Mal gelöscht/verschoben?) Java habe ich aktualisiert. Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-02-2014 Ran by tcee at 2014-02-09 09:59:56 Run:2 Running from C:\Users\tcee\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** ZeroAccess: C:\Windows\Installer\{56d76256-d551-d3c2-818a-fa84f69dc1cd} ZeroAccess: C:\Users\Benutzername\AppData\Local\{56d76256-d551-d3c2-818a-fa84f69dc1cd} ***************** "C:\Windows\Installer\{56d76256-d551-d3c2-818a-fa84f69dc1cd}" => File/Directory not found. C:\Users\Benutzername\AppData\Local\{56d76256-d551-d3c2-818a-fa84f69dc1cd} => Moved successfully. ==== End of Fixlog ==== FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-02-2014 Ran by Benutzername (administrator) on Benutzername-THINK on 09-02-2014 10:02:51 Running from C:\Users\Benutzername\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CamMute.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Lenovo) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe (Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (FileHippo.com) C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Lenovo Group Limited) C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ForteConfig] - C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] () HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2011-03-14] (Conexant systems, Inc.) HKLM\...\Run: [LENOVO.TPKNRRES] - C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [60920 2013-05-29] (Lenovo Group Limited) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-12-10] (Adobe Systems Incorporated) HKLM-x32\...\Run: [PWMTRV] - rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-17] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [] - [X] Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1502850821-2927420759-2148834354-1001\...\Run: [FileHippo.com] - C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe [307712 2012-11-23] (FileHippo.com) AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [245872 2013-11-15] (NVIDIA Corporation) AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [245872 2013-11-15] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [201576 2013-11-15] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com/welcome/thinkpad StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENP BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {12193C65-F0E1-4DD1-AD4E-DB73C6911011} file:///H:/Mydlink/activeX/DCP.cab DPF: HKLM-x32 {7191F0AC-D686-46A8-BFCC-EA61778C74DD} file:///H:/Mydlink/activeX/aplugLiteDL.cab Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_44.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File FF Plugin: adobe.com/AdobeAAMDetect_x86_64 - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101714.dll (Amazon.com, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Default Full Zoom Level - C:\Users\Benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default\Extensions\{D9A7CBEC-DE1A-444f-A092-844461596C4D} [2013-05-28] FF Extension: Firebug - C:\Users\Benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default\Extensions\firebug@software.joehewitt.com.xpi [2012-05-06] FF Extension: NoScript - C:\Users\Benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2012-08-22] FF Extension: MeasureIt - C:\Users\Benutzername\AppData\Roaming\Mozilla\Firefox\Profiles\upm9xjxr.default\Extensions\{75CEEE46-9B64-46f8-94BF-54012DE155F0}.xpi [2012-07-09] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-17] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-14] (Avira Operations GmbH & Co. KG) S4 bckwfs; C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe [2649840 2013-03-01] (Blue Coat Systems, Inc.) R2 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [218112 2013-08-20] () S4 DozeSvc; C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [478056 2012-02-27] (Lenovo.) S4 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [133992 2011-07-12] (Lenovo Group Limited) S4 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [30184 2013-08-08] () S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S4 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-02-08] () S4 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22376 2013-06-26] () R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3386608 2013-02-08] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [284448 2013-11-15] (NVIDIA Corporation) R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [41536 2009-09-24] (Lenovo (United States) Inc.) S2 bckd; system32\drivers\bckd.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-09 09:13 - 2014-02-09 09:13 - 00000022 _____ () C:\Windows\S.dirmngr 2014-02-08 10:35 - 2014-02-08 10:35 - 00000000 ____D () C:\Users\Benutzername\Desktop\FRST-OlderVersion 2014-02-08 10:03 - 2014-02-08 10:03 - 00987425 _____ () C:\Users\Benutzername\Desktop\SecurityCheck.exe 2014-02-04 19:09 - 2014-02-04 19:09 - 02347384 _____ (ESET) C:\Users\Benutzername\Desktop\esetsmartinstaller_enu.exe 2014-02-03 15:39 - 2014-02-03 15:39 - 00000990 _____ () C:\Users\Benutzername\Desktop\JRT.txt 2014-02-03 15:21 - 2014-02-03 15:21 - 01037068 _____ (Thisisu) C:\Users\Benutzername\Desktop\JRT.exe 2014-02-03 15:21 - 2014-02-03 15:21 - 00000000 ____D () C:\Windows\ERUNT 2014-02-03 15:10 - 2014-02-03 15:13 - 00000000 ____D () C:\AdwCleaner 2014-02-03 15:10 - 2014-02-03 15:10 - 01166132 _____ () C:\Users\Benutzername\Desktop\adwcleaner.exe 2014-02-03 14:51 - 2014-02-03 14:51 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-03 14:51 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-02 08:35 - 2014-02-02 08:35 - 00145970 _____ () C:\Users\Benutzername\Desktop\combofix.txt 2014-02-02 08:33 - 2014-02-02 08:33 - 00145931 _____ () C:\ComboFix.txt 2014-02-02 08:05 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-02-02 08:05 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-02-02 08:05 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-02-02 08:05 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-02-02 08:05 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-02-02 08:05 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-02-02 08:05 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-02-02 08:05 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-02-02 08:04 - 2014-02-02 08:34 - 00000000 ____D () C:\Qoobox 2014-02-02 08:02 - 2014-02-02 08:03 - 05179159 ____R (Swearware) C:\Users\Benutzername\Desktop\ComboFix.exe 2014-02-01 19:25 - 2014-02-01 19:25 - 00000242 _____ () C:\Users\Benutzername\Desktop\defogger_enable.log 2014-02-01 19:19 - 2014-02-01 19:36 - 00002974 _____ () C:\Users\Benutzername\Desktop\gmer.log 2014-02-01 18:54 - 2014-02-01 19:35 - 00026040 _____ () C:\Users\Benutzername\Desktop\Addition.txt 2014-02-01 18:52 - 2014-02-09 10:02 - 00013966 _____ () C:\Users\Benutzername\Desktop\FRST.txt 2014-02-01 18:52 - 2014-02-09 10:02 - 00000000 ____D () C:\FRST 2014-02-01 18:49 - 2014-02-01 18:49 - 00000470 _____ () C:\Users\Benutzername\Desktop\defogger_disable.log 2014-02-01 14:36 - 2014-02-01 14:36 - 00380416 _____ () C:\Users\Benutzername\Desktop\Gmer-19357.exe 2014-02-01 14:34 - 2014-02-08 10:35 - 02079744 _____ (Farbar) C:\Users\Benutzername\Desktop\FRST64.exe 2014-02-01 14:33 - 2014-02-01 14:34 - 00050477 _____ () C:\Users\Benutzername\Desktop\Defogger.exe 2014-01-29 12:37 - 2014-01-29 12:37 - 00000976 _____ () C:\Users\Benutzername\Desktop\terminal.lnk 2014-01-24 12:18 - 2014-01-24 12:19 - 00000057 _____ () C:\Users\Benutzername\Desktop\Kaufen.txt 2014-01-23 11:32 - 2014-01-23 11:33 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-01-23 11:32 - 2014-01-23 11:33 - 00000000 ____D () C:\Program Files\iTunes 2014-01-23 11:32 - 2014-01-23 11:33 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-01-23 11:32 - 2014-01-23 11:32 - 00000000 ____D () C:\Program Files\iPod 2014-01-23 11:15 - 2014-01-23 11:15 - 00000000 ____D () C:\Users\Benutzername\elan2013 2014-01-23 11:14 - 2014-01-23 11:14 - 00000000 ____D () C:\Program Files\REHADAT 2014-01-21 09:59 - 2014-01-21 09:59 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-01-21 09:50 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 09:37 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 09:37 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys ==================== One Month Modified Files and Folders ======= 2014-02-09 10:03 - 2014-02-01 18:52 - 00013966 _____ () C:\Users\Benutzername\Desktop\FRST.txt 2014-02-09 10:02 - 2014-02-01 18:52 - 00000000 ____D () C:\FRST 2014-02-09 09:56 - 2013-10-16 12:18 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-09 09:54 - 2013-10-16 12:18 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-09 09:21 - 2009-07-14 05:45 - 00031072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-09 09:21 - 2009-07-14 05:45 - 00031072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-09 09:13 - 2014-02-09 09:13 - 00000022 _____ () C:\Windows\S.dirmngr 2014-02-09 09:13 - 2012-04-14 15:30 - 00116006 _____ () C:\Windows\setupact.log 2014-02-09 09:13 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-08 21:30 - 2012-03-30 03:40 - 02087807 _____ () C:\Windows\WindowsUpdate.log 2014-02-08 21:10 - 2013-01-05 16:36 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-08 14:02 - 2010-11-21 04:47 - 01093998 _____ () C:\Windows\PFRO.log 2014-02-08 10:35 - 2014-02-08 10:35 - 00000000 ____D () C:\Users\Benutzername\Desktop\FRST-OlderVersion 2014-02-08 10:35 - 2014-02-01 14:34 - 02079744 _____ (Farbar) C:\Users\Benutzername\Desktop\FRST64.exe 2014-02-08 10:17 - 2012-04-14 07:02 - 00000000 ____D () C:\Users\Benutzername 2014-02-08 10:13 - 2013-08-07 19:50 - 00000000 ____D () C:\Program Files\Recuva 2014-02-08 10:03 - 2014-02-08 10:03 - 00987425 _____ () C:\Users\Benutzername\Desktop\SecurityCheck.exe 2014-02-08 10:03 - 2012-04-15 07:54 - 00000000 ____D () C:\Users\Benutzername\AppData\Local\Adobe 2014-02-08 10:02 - 2013-01-05 16:36 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-08 10:02 - 2012-04-15 07:46 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-08 10:02 - 2012-04-15 07:46 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-08 09:48 - 2012-07-23 12:56 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-02-08 09:46 - 2012-07-23 12:59 - 00000000 ____D () C:\Program Files\Adobe Photoshop CS6 (64 Bit) 2014-02-08 09:46 - 2012-07-23 12:57 - 00000000 ____D () C:\Program Files (x86)\Adobe Extension Manager CS6 2014-02-08 07:31 - 2012-04-14 07:05 - 00000000 ____D () C:\Users\Benutzername\AppData\Local\VirtualStore 2014-02-07 16:55 - 2012-04-14 19:40 - 00000000 ____D () C:\Users\Benutzername\AppData\Local\VirtualStore 2014-02-07 09:11 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-02-06 16:00 - 2012-05-06 07:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-05 16:25 - 2013-11-17 08:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-05 16:24 - 2013-12-11 20:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-02-04 19:09 - 2014-02-04 19:09 - 02347384 _____ (ESET) C:\Users\Benutzername\Desktop\esetsmartinstaller_enu.exe 2014-02-04 16:18 - 2012-03-30 13:23 - 00699682 _____ () C:\Windows\system32\perfh007.dat 2014-02-04 16:18 - 2012-03-30 13:23 - 00149790 _____ () C:\Windows\system32\perfc007.dat 2014-02-04 16:18 - 2009-07-14 06:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-03 15:39 - 2014-02-03 15:39 - 00000990 _____ () C:\Users\Benutzername\Desktop\JRT.txt 2014-02-03 15:21 - 2014-02-03 15:21 - 01037068 _____ (Thisisu) C:\Users\Benutzername\Desktop\JRT.exe 2014-02-03 15:21 - 2014-02-03 15:21 - 00000000 ____D () C:\Windows\ERUNT 2014-02-03 15:14 - 2012-03-30 03:55 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-03 15:13 - 2014-02-03 15:10 - 00000000 ____D () C:\AdwCleaner 2014-02-03 15:10 - 2014-02-03 15:10 - 01166132 _____ () C:\Users\Benutzername\Desktop\adwcleaner.exe 2014-02-03 14:51 - 2014-02-03 14:51 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-02 08:44 - 2012-04-14 12:44 - 00000000 ____D () C:\Users\Benutzername\AppData\Roaming\Adobe 2014-02-02 08:43 - 2012-03-30 03:58 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-02-02 08:35 - 2014-02-02 08:35 - 00145970 _____ () C:\Users\Benutzername\Desktop\combofix.txt 2014-02-02 08:34 - 2014-02-02 08:04 - 00000000 ____D () C:\Qoobox 2014-02-02 08:33 - 2014-02-02 08:33 - 00145931 _____ () C:\ComboFix.txt 2014-02-02 08:26 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2014-02-02 08:25 - 2009-07-14 03:34 - 65536000 _____ () C:\Windows\system32\config\SOFTWARE.bak 2014-02-02 08:25 - 2009-07-14 03:34 - 17563648 _____ () C:\Windows\system32\config\SYSTEM.bak 2014-02-02 08:25 - 2009-07-14 03:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak 2014-02-02 08:25 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak 2014-02-02 08:25 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak 2014-02-02 08:24 - 2012-07-16 13:17 - 00000000 ____D () C:\Windows\erdnt 2014-02-02 08:03 - 2014-02-02 08:02 - 05179159 ____R (Swearware) C:\Users\Benutzername\Desktop\ComboFix.exe 2014-02-02 08:03 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-02-01 19:36 - 2014-02-01 19:19 - 00002974 _____ () C:\Users\Benutzername\Desktop\gmer.log 2014-02-01 19:35 - 2014-02-01 18:54 - 00026040 _____ () C:\Users\Benutzername\Desktop\Addition.txt 2014-02-01 19:25 - 2014-02-01 19:25 - 00000242 _____ () C:\Users\Benutzername\Desktop\defogger_enable.log 2014-02-01 18:49 - 2014-02-01 18:49 - 00000470 _____ () C:\Users\Benutzername\Desktop\defogger_disable.log 2014-02-01 14:36 - 2014-02-01 14:36 - 00380416 _____ () C:\Users\Benutzername\Desktop\Gmer-19357.exe 2014-02-01 14:34 - 2014-02-01 14:33 - 00050477 _____ () C:\Users\Benutzername\Desktop\Defogger.exe 2014-01-29 12:37 - 2014-01-29 12:37 - 00000976 _____ () C:\Users\Benutzername\Desktop\terminal.lnk 2014-01-24 12:19 - 2014-01-24 12:18 - 00000057 _____ () C:\Users\Benutzername\Desktop\Kaufen.txt 2014-01-23 14:07 - 2012-05-12 16:37 - 00000000 ____D () C:\Program Files (x86)\phase5 2014-01-23 11:33 - 2014-01-23 11:32 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-01-23 11:33 - 2014-01-23 11:32 - 00000000 ____D () C:\Program Files\iTunes 2014-01-23 11:33 - 2014-01-23 11:32 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-01-23 11:32 - 2014-01-23 11:32 - 00000000 ____D () C:\Program Files\iPod 2014-01-23 11:28 - 2013-07-12 17:42 - 00000000 ____D () C:\ProgramData\Apple 2014-01-23 11:25 - 2013-07-12 17:45 - 00000000 ____D () C:\Users\Benutzername\AppData\Roaming\Apple Computer 2014-01-23 11:15 - 2014-01-23 11:15 - 00000000 ____D () C:\Users\Benutzername\elan2013 2014-01-23 11:14 - 2014-01-23 11:14 - 00000000 ____D () C:\Program Files\REHADAT 2014-01-21 10:03 - 2012-03-30 03:56 - 00000000 ____D () C:\Windows\SysWOW64\NV 2014-01-21 10:03 - 2012-03-30 03:56 - 00000000 ____D () C:\Windows\system32\NV 2014-01-21 09:59 - 2014-01-21 09:59 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-21 09:59 - 2014-01-21 09:59 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-01-21 09:55 - 2012-03-30 03:54 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-01-21 09:52 - 2012-03-30 03:54 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-01-21 09:51 - 2013-12-11 08:36 - 01594964 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-01-21 09:50 - 2012-03-30 03:58 - 00000000 ____D () C:\ProgramData\Adobe 2014-01-21 09:44 - 2012-07-20 08:49 - 00000000 ____D () C:\xampp 2014-01-15 12:35 - 2009-07-14 05:45 - 04950184 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-15 09:42 - 2013-07-11 07:17 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-15 09:38 - 2012-04-14 16:44 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-15 09:31 - 2012-08-17 13:03 - 00001456 _____ () C:\Users\Benutzername\AppData\Local\Adobe Für Web speichern 13.0 Prefs Some content of TEMP: ==================== C:\Users\Benutzername\AppData\Local\Temp\avgnt.exe C:\Users\Benutzername\AppData\Local\Temp\AAMHelper.exe C:\Users\Benutzername\AppData\Local\Temp\AdobeApplicationManager.exe C:\Users\Benutzername\AppData\Local\Temp\avgnt.exe C:\Users\Benutzername\AppData\Local\Temp\install_flashplayer12x32_mssd_aaa_aih.exe C:\Users\Benutzername\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-08 07:48 ==================== End Of Log ============================ --- --- --- --- --- --- Geändert von wenjin (09.02.2014 um 10:14 Uhr) |
10.02.2014, 08:12 | #11 |
/// the machine /// TB-Ausbilder | Rechner hakt und hat Aussetzer Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.02.2014, 09:09 | #12 |
| Rechner hakt und hat Aussetzer Vielen Dank Schrauber, Du bist große klasse! Kannst Du mir noch sagen, ob etwas mit meinem Rechner war oder bin ich glimpflich davon gekommen? |
10.02.2014, 17:41 | #13 |
/// the machine /// TB-Ausbilder | Rechner hakt und hat Aussetzer Das war schon einiges los. Passwörter ändern ist Pflicht, aber sonst ist alles grün
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
11.02.2014, 08:58 | #14 |
| Rechner hakt und hat Aussetzer Hallo Schrauber, kannst Du das präzisieren? Der Admin unserer Firma möchte nämlich, dass ich ihm Bericht erstatte. Würde mich aber auch persönlich interessieren, was genau meinen Rechner befallen hatte. |
11.02.2014, 19:00 | #15 |
/// the machine /// TB-Ausbilder | Rechner hakt und hat Aussetzer Das war ein Firmenrechner???? Warum sagst Du das nit? Oder hab ich das überlesen? Auf jeden Fall dein Glück, Firmenrechner kosten normal im Vorraus, denn die IT Abteilung der Firma wird dafür bezahlt, aber wir machen deren Arbeit für Lau, verstehste Das war viel drauf, Adware und Kram. Das "übelste" war das Zero Access Rootkit.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Rechner hakt und hat Aussetzer |
4d36e972-e325-11ce-bfc1-08002be10318, antivir, antivirus, avira, bildschirm, bonjour, browser, combofix, converter, dvdvideosoft ltd., error, failed, feedback, festplatte, flash player, gmer.log, maus, mozilla, officejet, problem, programm, pwmtr64v.dll, registry, rundll, scan, security, sekunden, software, svchost.exe, system, teredo, virtualbox, windows |