|
Log-Analyse und Auswertung: Windows 7 Verdach auf Virus/MalwareWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
05.02.2014, 19:43 | #1 |
| Windows 7 Verdach auf Virus/Malware Verdacht auf Virus. Mein Bruder hat eine Datei Heruntergeladen ("sogenannter Hack") Alls ich mit MBAM Quick Scan durchgeführt habe schrieb er 25 Fehler (vermute auf Backdoor Virus) Code:
ATTFilter Malwarebytes Anti-Malware (PRO) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.02.05.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16476 system_ADMIN :: DOMINIK-PC [Administrator] Schutz: Deaktiviert 05.02.2014 18:34:51 MBAM-log-2014-02-05 (18-59-28).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 307822 Laufzeit: 16 Minute(n), 18 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 2 HKCU\Software\DC3_FEXEC (Malware.Trace) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Vittalia\AxtanInstaller (PUP.Optional.BundleInstaller.A) -> Keine Aktion durchgeführt. Infizierte Registrierungswerte: 4 HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|shell (Trojan.FakeAlert) -> Daten: %APPDATA%\Microsoft\update.exe,explorer.exe -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Facebook Update (Backdoor.Agent.DC) -> Daten: %APPDATA%\Microsoft\update.exe -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Facebook Update (Backdoor.Agent.DC) -> Daten: %APPDATA%\Microsoft\update.exe -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|MicroUpdate (Backdoor.Agent.DCEGen) -> Daten: C:\Windows\system32\MSDCSC\wYMgrs8BJouL\wYMgrs8BJouL\msdcsc.exe -> Keine Aktion durchgeführt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 1 C:\Users\system_ADMIN\AppData\Roaming\dclogs (Stolen.Data) -> Keine Aktion durchgeführt. Infizierte Dateien: 18 C:\Users\system_ADMIN\Desktop\Leauge of Legends Hack 2.0 (1).rar (Trojan.Autoit) -> Keine Aktion durchgeführt. C:\$Recycle.Bin\S-1-5-21-1604131726-2387010455-2909821853-1016\$R2JH2WE.exe (Trojan.Autoit) -> Keine Aktion durchgeführt. C:\$Recycle.Bin\S-1-5-21-1604131726-2387010455-2909821853-1016\$RBVG2WF.exe (Rootkit.Agent) -> Keine Aktion durchgeführt. C:\$Recycle.Bin\S-1-5-21-1604131726-2387010455-2909821853-1016\$RGZNMLG.exe (Rootkit.Agent) -> Keine Aktion durchgeführt. C:\$Recycle.Bin\S-1-5-21-1604131726-2387010455-2909821853-1016\$RPOYDJ1.exe (Rootkit.Agent) -> Keine Aktion durchgeführt. C:\$Recycle.Bin\S-1-5-21-1604131726-2387010455-2909821853-1016\$RXLLHBI.exe (PUP.Optional.InstallCore) -> Keine Aktion durchgeführt. C:\Users\system_ADMIN\AppData\Local\Temp\instloffer.exe (PUP.Optional.Vittalia) -> Keine Aktion durchgeführt. C:\Users\system_ADMIN\Downloads\CR_Downloader_fuer_desmume.exe (PUP.Optional.InstallCore) -> Keine Aktion durchgeführt. C:\Users\system_ADMIN\Downloads\HideToolz(2) (1).zip (Rootkit.Agent) -> Keine Aktion durchgeführt. C:\Users\system_ADMIN\Downloads\HideToolz_2_2 (1).zip (Rootkit.Agent) -> Keine Aktion durchgeführt. C:\Users\system_ADMIN\Downloads\HideToolz_v2.2 (1).rar (Rootkit.Agent) -> Keine Aktion durchgeführt. C:\Users\system_ADMIN\Downloads\HideToolz_v2.2.rar (Rootkit.Agent) -> Keine Aktion durchgeführt. C:\Users\system_ADMIN\Downloads\installer_driver_a4tech_xl-750bf_1_0_Deutsch.exe (PUP.Optional.Vittalia) -> Keine Aktion durchgeführt. C:\Users\system_ADMIN\Downloads\installer_driver_a4tech_xl-750f_1_0_Deutsch.exe (PUP.Optional.Vittalia) -> Keine Aktion durchgeführt. C:\Users\system_ADMIN\Downloads\Leauge of Legends Hack 2.0 (1).rar (Trojan.Autoit) -> Keine Aktion durchgeführt. C:\Windows\System32\MSDCSC\msdcsc.exe (Backdoor.Agent.DC) -> Keine Aktion durchgeführt. C:\Windows\SysWOW64\MSDCSC\msdcsc.exe (Backdoor.Agent.DC) -> Keine Aktion durchgeführt. C:\Users\system_ADMIN\AppData\Roaming\dclogs\2014-02-05-4.dc (Stolen.Data) -> Keine Aktion durchgeführt. (Ende) Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-02-2014 Ran by system_ADMIN (administrator) on DOMINIK-PC on 05-02-2014 19:00:00 Running from C:\Users\system_ADMIN\Desktop\Neuer Ordner (8) Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe () C:\Program Files\Mouse\Amoumain.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (ASUS) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (VMware, Inc.) F:\vmware\vmware-authd.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\System32\prevhost.exe (Don HO don.h@free.fr) C:\Program Files (x86)\Notepad++\notepad++.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\taskmgr.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2278504 2011-10-14] (Realtek Semiconductor) HKLM\...\Run: [AtherosBtStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [981664 2011-10-01] (Atheros Communications) HKLM\...\Run: [AthBtTray] - C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [799904 2011-10-01] (Atheros Commnucations) HKLM\...\Run: [WheelMouse] - C:\Program Files\Mouse\Amoumain.exe [196608 2008-03-03] () HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2317312 2011-09-13] (ASUS) HKLM-x32\...\Run: [SonicMasterTray] - C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-01-23] (AVAST Software) HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Windows\system32\MSDCSC\msdcsc.exe,C:\Windows\system32\MSDCSC\wYMgrs8BJouL\msdcsc.exe HKU\S-1-5-21-1604131726-2387010455-2909821853-1016\...\Run: [Overwolf] - C:\Program Files (x86)\Overwolf\Overwolf.exe [35768 2013-12-09] (Overwolf) HKU\S-1-5-21-1604131726-2387010455-2909821853-1016\...\Run: [OscarEditor] - C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe [3340288 2012-03-20] () HKU\S-1-5-21-1604131726-2387010455-2909821853-1016\...\Run: [OscarX7Mouse5Mode] - C:\Program Files (x86)\OscarX7Editor5Mode\OscarX7Editor5Mode\OscarEditor.exe [3521024 2012-03-20] () HKU\S-1-5-21-1604131726-2387010455-2909821853-1016\...\Run: [Facebook Update] - %APPDATA%\Microsoft\update.exe HKU\S-1-5-21-1604131726-2387010455-2909821853-1016\...\Run: [MicroUpdate] - C:\Windows\system32\MSDCSC\wYMgrs8BJouL\wYMgrs8BJouL\msdcsc.exe HKU\S-1-5-21-1604131726-2387010455-2909821853-1016\...\Policies\Explorer\Run: [Facebook Update] - %APPDATA%\Microsoft\update.exe HKU\S-1-5-21-1604131726-2387010455-2909821853-1016\...\MountPoints2: {b43540c2-4f8f-11e1-b469-806e6f6e6963} - E:\MMMTest.EXE HKU\S-1-5-21-1604131726-2387010455-2909821853-1016\...\Winlogon: [Shell] %APPDATA%\Microsoft\update.exe,explorer.exe <==== ATTENTION IFEO\utilman.exe: [Debugger] c:\windows\system32\cmd.exe Startup: C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled () Startup: C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk ShortcutTarget: Facebook Messenger.lnk -> C:\Users\Dominik\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe (Facebook) Startup: C:\Users\system_ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook.lnk ShortcutTarget: Facebook.lnk -> C:\Users\system_ADMIN\AppData\Roaming\Microsoft\update.exe (No File) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.telekom.at/suche HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.aon.at HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {55AFFF2A-7AB3-5413-8C22-511A1448E47F} URL = SearchScopes: HKCU - {55AFFF2A-7AB3-5413-8C22-511A1448E47F} URL = BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: avast! Ad Blocker - {FFCB3198-32F3-4E8B-9539-4324694ED663} - C:\Program Files (x86)\AVAST Software\avast! Ad Blocker IE\Adblocker64.dll (AVAST Software) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: WebEnhance - {814664b0-d93b-4da6-9216-722c56179397} - C:\Program Files (x86)\WebEnhance\webenhance.dll (WebEnhance) BHO-x32: Microsoft Web Test Recorder 10.0 Helper - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation) BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: avast! Ad Blocker - {FFCB3198-32F3-4E8B-9539-4324694ED663} - C:\Program Files (x86)\AVAST Software\avast! Ad Blocker IE\Adblocker32.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 10.0.0.138 FireFox: ======== FF ProfilePath: C:\Users\system_ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\bp9g4ldi.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @Nero.com/KM - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: ZEON/PDF,version=2.0 - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation) FF Plugin HKCU: @eximion.com/KalydoPlayer - C:\Users\system_ADMIN\AppData\Roaming\Kalydo\KalydoPlayer\bin2\npkalydo.dll (Eximion B.V.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Surrf and keaep - C:\Users\system_ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\bp9g4ldi.default\Extensions\lj7arl@qvsfyuoi-.net [2013-12-02] FF Extension: NoScript - C:\Users\system_ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\bp9g4ldi.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-10-05] FF Extension: Adblock Plus - C:\Users\system_ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\bp9g4ldi.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-10-05] FF Extension: avast! Ad Blocker - C:\Program Files (x86)\Mozilla Firefox\extensions\adblocker@avast.com.xpi [2013-11-18] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-05] FF HKLM-x32\...\Firefox\Extensions: [{38e9e285-5266-4fe2-b5b5-c14c29b0cd45}] - C:\Program Files (x86)\WebEnhance\webenhance.xpi FF Extension: No Name - C:\Program Files (x86)\WebEnhance\webenhance.xpi [2013-08-27] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR Extension: (Google Docs) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-01] CHR Extension: (Google Drive) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-01] CHR Extension: (YouTube) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-01] CHR Extension: (Google-Suche) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-01] CHR Extension: (avast! Ad Blocker) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\fplhdcjmbpfkejbhngmlngaecbjmoimd [2013-12-01] CHR Extension: (avast! Online Security) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-12-01] CHR Extension: (Google Wallet) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-01] CHR Extension: (Google Mail) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-01] CHR HKCU\...\Chrome\Extension: [kdfbddbdpnahdahmamlolacimfdbeckk] - C:\Users\system_ADMIN\AppData\Local\CRE\kdfbddbdpnahdahmamlolacimfdbeckk.crx [2013-07-17] CHR HKLM-x32\...\Chrome\Extension: [ejnmnhkgiphcaeefbaooconkceehicfi] - C:\Program Files (x86)\DealPly\DealPly.crx [2013-07-17] CHR HKLM-x32\...\Chrome\Extension: [fplhdcjmbpfkejbhngmlngaecbjmoimd] - C:\Program Files\AVAST Software\Avast\AdBlocker\Chrome\avast-adblocker-chrome.crx [2013-10-05] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2013-11-13] CHR HKLM-x32\...\Chrome\Extension: [kdfbddbdpnahdahmamlolacimfdbeckk] - C:\Users\system_ADMIN\AppData\Local\CRE\kdfbddbdpnahdahmamlolacimfdbeckk.crx [2013-07-17] CHR HKLM-x32\...\Chrome\Extension: [mbegnhpbhfjiaelealfpieodkembdgbj] - C:\Program Files (x86)\WebEnhance\webenhance.crx [2013-08-27] CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= S4 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2011-11-02] (Advanced Micro Devices, Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-23] (AVAST Software) S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) R2 HPSLPSVC; C:\Users\Dominik\AppData\Local\Temp\7zS1DE4\hpslpsvc64.dll [1039360 2011-11-14] (Hewlett-Packard Co.) S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S4 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation) S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [96184 2013-12-09] (Overwolf) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2012-06-24] () R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [186056 2013-10-16] (Sandboxie Holdings, LLC) S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation) S4 SXDS10; C:\Program Files (x86)\Common Files\soft Xpansion\sxds10.exe [234096 2013-10-13] (soft Xpansion) S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) R2 VMAuthdService; F:\vmware\vmware-authd.exe [86096 2013-10-18] (VMware, Inc.) S4 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [158880 2011-10-01] (Atheros) S4 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [X] S4 vToolbarUpdater15.5.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [X] ==================== Drivers (Whitelisted) ==================== R3 AiCharger; C:\Windows\SysWOW64\DRIVERS\AiCharger.sys [17152 2011-10-15] (ASUSTek Computer Inc.) R1 Amfilter; C:\Windows\System32\DRIVERS\Amfltx64.sys [12288 2007-10-15] ((Standard mouse types)) R3 Amusbprt; C:\Windows\System32\DRIVERS\Amusbx64.sys [17920 2008-02-13] (A4Tech Co.,Ltd.) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-01-23] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-11-13] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-13] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-01-23] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-01-23] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-01-23] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-22] () R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [45856 2013-08-16] (AVG Technologies) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-11-01] (DT Soft Ltd) R1 dvdfabio; C:\Windows\system32\drivers\dvdfabio.sys [12776 2012-11-13] (Fengtao Software Inc.) S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2012-06-22] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [200552 2013-10-16] (Sandboxie Holdings, LLC) S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2013-02-12] (Microsoft Corporation) R3 vdrive; C:\Windows\System32\DRIVERS\vdrive.sys [45544 2012-11-13] (Fengtao Software Inc.) R0 vsock; C:\Windows\System32\drivers\vsock.sys [73296 2013-10-08] (VMware, Inc.) S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-26] (Microsoft Corporation) S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] U5 FC95598C7111AAB1.sys; C:\Windows\temp\FC95598C7111AAB1.sys [16256 2013-12-29] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-05 18:57 - 2014-02-05 19:00 - 00000000 ____D () C:\FRST 2014-02-05 18:44 - 2014-02-05 18:45 - 02082304 _____ (Farbar) C:\Users\system_ADMIN\Downloads\FRST64.exe 2014-02-05 18:43 - 2014-02-05 18:43 - 00050477 _____ () C:\Users\system_ADMIN\Downloads\Defogger.exe 2014-02-05 18:43 - 2014-02-05 18:43 - 00000000 _____ () C:\Users\system_ADMIN\defogger_reenable 2014-02-05 18:42 - 2014-02-05 19:00 - 00000000 ____D () C:\Users\system_ADMIN\Desktop\Neuer Ordner (8) 2014-02-05 18:25 - 2014-02-05 18:25 - 00000000 ____D () C:\Windows\SysWOW64\MSDCSC 2014-02-05 18:22 - 2014-02-05 18:22 - 01126956 _____ () C:\Users\system_ADMIN\Downloads\Leauge of Legends Hack 2.0 (1).rar 2014-02-05 18:22 - 2014-02-05 18:22 - 01126956 _____ () C:\Users\system_ADMIN\Desktop\Leauge of Legends Hack 2.0 (1).rar 2014-02-05 18:21 - 2014-02-05 18:21 - 01125660 _____ () C:\Users\system_ADMIN\Downloads\Leauge of Legends Hack 2.0.rar 2014-02-05 10:48 - 2014-02-05 10:49 - 06952512 _____ (TeamViewer GmbH) C:\Users\system_ADMIN\Downloads\TeamViewer_Setup.exe 2014-02-03 17:20 - 2014-02-03 17:20 - 00000000 ____D () C:\ProgramData\Overwolf 2014-02-03 17:17 - 2014-02-03 17:17 - 00000272 _____ () C:\Windows\Tasks\ASUS SmartLogon Console Sensor.job 2014-02-03 10:13 - 2014-02-03 10:13 - 00000849 _____ () C:\Users\system_ADMIN\AppData\Local\recently-used.xbel 2014-02-02 20:07 - 2014-02-02 20:07 - 00281016 _____ () C:\Users\system_ADMIN\Downloads\FuzzyPurp-Redworks-FLOPPY-e8ce09e.zip 2014-01-28 17:08 - 2014-01-28 17:08 - 00000000 ____D () C:\Users\system_ADMIN\Desktop\Neuer Ordner (7) 2014-01-28 17:07 - 2014-01-28 17:07 - 00659797 _____ () C:\Users\system_ADMIN\Downloads\VisualBoyAdvance-1.8.0-beta3.zip 2014-01-28 12:43 - 2014-01-28 12:48 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Local\Temporary Projects 2014-01-26 20:28 - 2014-01-26 20:29 - 00275224 _____ () C:\Windows\Minidump\012614-97438-01.dmp 2014-01-20 21:57 - 2014-01-20 21:57 - 00003935 _____ () C:\Users\system_ADMIN\Downloads\br_easy2.lua 2014-01-20 19:46 - 2014-01-20 19:46 - 00285595 _____ () C:\Users\system_ADMIN\Downloads\CraftOS1.3.1-MultiLauange.zip 2014-01-20 18:26 - 2014-01-20 18:26 - 00118149 _____ () C:\Users\system_ADMIN\Downloads\wmpChrome.crx 2014-01-19 18:56 - 2014-02-04 12:21 - 00003117 _____ () C:\Users\system_ADMIN\AppData\Roaming\PData.MMM 2014-01-19 18:56 - 2014-02-04 12:21 - 00003117 _____ () C:\Users\system_ADMIN\AppData\Roaming\PData.MM1 2014-01-18 13:03 - 2013-02-11 08:06 - 00001114 _____ () C:\Users\system_ADMIN\Desktop\redprobe 2014-01-15 23:19 - 2014-01-15 23:19 - 536870912 _____ () C:\Users\system_ADMIN\Downloads\pkms2.nds 2014-01-15 19:41 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 19:41 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 19:41 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 19:41 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 19:41 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 19:41 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 19:41 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 19:41 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-15 19:41 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-10 17:24 - 2014-01-10 17:24 - 05074125 _____ () C:\Users\system_ADMIN\Downloads\Nodus.zip 2014-01-10 17:07 - 2014-01-10 17:07 - 00057165 _____ () C:\Users\system_ADMIN\Downloads\RadarBro1.5.2.zip 2014-01-10 13:40 - 2014-01-10 13:40 - 00028085 _____ () C:\Users\system_ADMIN\Downloads\AutoSwitch-v4.0.1-mc1.5.2.zip 2014-01-10 13:40 - 2014-01-10 13:40 - 00016258 _____ () C:\Users\system_ADMIN\Downloads\ThebombzenAPI-v2.0.0-mc1.5.2.zip 2014-01-10 11:09 - 2014-01-10 11:09 - 00377553 _____ () C:\Users\system_ADMIN\Downloads\NotEnoughItems 1.5.2.27.jar 2014-01-10 11:09 - 2014-01-10 11:09 - 00314452 _____ () C:\Users\system_ADMIN\Downloads\CodeChickenCore 0.8.7.3.jar 2014-01-10 11:02 - 2014-02-05 09:32 - 02332590 _____ () C:\Users\system_ADMIN\Downloads\TechnicLauncher (1).exe 2014-01-10 10:59 - 2014-01-10 10:59 - 00275231 _____ () C:\Users\system_ADMIN\Downloads\codechickencore_0_8_6_5 (1).jar 2014-01-10 10:47 - 2014-01-10 10:47 - 00899375 _____ () C:\Users\system_ADMIN\Downloads\ForgeMultipart-dev-1.5.2-1.0.0.149.jar 2014-01-10 10:45 - 2014-01-10 10:45 - 00117705 _____ () C:\Users\system_ADMIN\Downloads\WR-CBE Core 1.4.jar 2014-01-10 10:41 - 2014-01-10 10:41 - 00367630 _____ () C:\Users\system_ADMIN\Downloads\notenoughitems_1_5_2_12.jar 2014-01-10 10:41 - 2014-01-10 10:41 - 00367630 _____ () C:\Users\system_ADMIN\Downloads\notenoughitems_1_5_2_12 (1).jar 2014-01-10 10:41 - 2014-01-10 10:41 - 00275231 _____ () C:\Users\system_ADMIN\Downloads\codechickencore_0_8_6_5.jar 2014-01-10 10:22 - 2014-01-10 10:23 - 01997327 _____ () C:\Users\system_ADMIN\Downloads\bcprov-jdk15on-147.jar 2014-01-10 10:14 - 2014-01-10 10:16 - 19092307 _____ () C:\Users\system_ADMIN\Downloads\fmllibs16.zip 2014-01-10 10:09 - 2014-01-10 10:09 - 02189140 _____ () C:\Users\system_ADMIN\Downloads\guava-14.0-rc3 (1).jar 2014-01-10 10:09 - 2014-01-10 10:09 - 00214592 _____ () C:\Users\system_ADMIN\Downloads\asm-all-4.1 (1).jar 2014-01-10 10:09 - 2014-01-10 10:09 - 00091333 _____ () C:\Users\system_ADMIN\Downloads\argo-small-3.2 (1).jar 2014-01-10 10:06 - 2014-01-10 10:07 - 02189140 _____ () C:\Users\system_ADMIN\Downloads\guava-14.0-rc3.jar 2014-01-10 10:06 - 2014-01-10 10:07 - 00214592 _____ () C:\Users\system_ADMIN\Downloads\asm-all-4.1.jar 2014-01-10 10:06 - 2014-01-10 10:07 - 00091333 _____ () C:\Users\system_ADMIN\Downloads\argo-small-3.2.jar 2014-01-10 10:06 - 2014-01-10 10:06 - 00201404 _____ () C:\Users\system_ADMIN\Downloads\deobfuscation_data_1.5.2.zip 2014-01-10 09:59 - 2014-01-10 09:59 - 00252446 _____ () C:\Users\system_ADMIN\Downloads\Rei’s Minimap Mod 1.5.2.zip 2014-01-10 09:56 - 2014-01-10 09:57 - 01975130 _____ () C:\Users\system_ADMIN\Downloads\Minecraft Forge 1.5.2.zip 2014-01-09 23:08 - 2014-01-09 23:08 - 01349598 _____ () C:\Users\system_ADMIN\Documents\Logs-2014-01-09T23-06-47.gz 2014-01-09 19:58 - 2014-01-09 19:58 - 00064379 _____ () C:\Users\system_ADMIN\Downloads\X-RayMod_v040.zip 2014-01-09 19:54 - 2014-01-09 19:54 - 00007934 _____ () C:\Users\system_ADMIN\Downloads\FlyMod_v040.zip 2014-01-09 19:47 - 2014-01-09 19:48 - 01160192 _____ () C:\Users\system_ADMIN\Downloads\X-Ray Mod Installer.exe 2014-01-09 19:37 - 2014-01-09 19:38 - 00064373 _____ () C:\Users\system_ADMIN\Downloads\X-RayMod_v038.zip 2014-01-09 18:06 - 2014-02-01 14:06 - 02406621 _____ () C:\Users\system_ADMIN\Downloads\TechnicLauncher.exe 2014-01-09 15:56 - 2014-01-09 15:57 - 00275112 _____ () C:\Windows\Minidump\010914-37253-01.dmp 2014-01-08 17:07 - 2014-02-05 09:32 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\.technic 2014-01-08 16:06 - 2014-01-08 17:07 - 00000000 ____D () C:\Users\system_ADMIN\Ekahau Site Survey 2014-01-08 16:04 - 2014-01-08 16:04 - 00000000 ____D () C:\Program Files\Ekahau 2014-01-07 12:35 - 2014-01-07 12:35 - 00216033 _____ () C:\Users\system_ADMIN\Downloads\HideToolz_2_2 (1).zip 2014-01-07 12:34 - 2014-01-07 12:34 - 00215311 _____ () C:\Users\system_ADMIN\Downloads\HideToolz_2_2.zip 2014-01-07 09:27 - 2014-01-07 09:27 - 00206537 _____ () C:\Users\system_ADMIN\Downloads\HideToolz_v2.2 (1).rar 2014-01-06 19:28 - 2014-01-06 19:28 - 00858033 _____ () C:\Users\system_ADMIN\Downloads\4Story Macro (1).zip ==================== One Month Modified Files and Folders ======= 2014-02-05 19:00 - 2014-02-05 18:57 - 00000000 ____D () C:\FRST 2014-02-05 19:00 - 2014-02-05 18:42 - 00000000 ____D () C:\Users\system_ADMIN\Desktop\Neuer Ordner (8) 2014-02-05 18:45 - 2014-02-05 18:44 - 02082304 _____ (Farbar) C:\Users\system_ADMIN\Downloads\FRST64.exe 2014-02-05 18:43 - 2014-02-05 18:43 - 00050477 _____ () C:\Users\system_ADMIN\Downloads\Defogger.exe 2014-02-05 18:43 - 2014-02-05 18:43 - 00000000 _____ () C:\Users\system_ADMIN\defogger_reenable 2014-02-05 18:43 - 2013-04-17 20:02 - 00000000 ____D () C:\Users\system_ADMIN 2014-02-05 18:43 - 2013-01-20 22:30 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-05 18:38 - 2012-05-31 12:18 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-05 18:31 - 2012-02-05 01:17 - 01715562 _____ () C:\Windows\WindowsUpdate.log 2014-02-05 18:25 - 2014-02-05 18:25 - 00000000 ____D () C:\Windows\SysWOW64\MSDCSC 2014-02-05 18:25 - 2013-12-21 12:21 - 00001968 _____ () C:\Windows\Sandboxie.ini 2014-02-05 18:24 - 2013-04-17 20:02 - 00000000 ___RD () C:\Users\system_ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-05 18:22 - 2014-02-05 18:22 - 01126956 _____ () C:\Users\system_ADMIN\Downloads\Leauge of Legends Hack 2.0 (1).rar 2014-02-05 18:22 - 2014-02-05 18:22 - 01126956 _____ () C:\Users\system_ADMIN\Desktop\Leauge of Legends Hack 2.0 (1).rar 2014-02-05 18:21 - 2014-02-05 18:21 - 01125660 _____ () C:\Users\system_ADMIN\Downloads\Leauge of Legends Hack 2.0.rar 2014-02-05 16:33 - 2012-05-11 15:22 - 00001146 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1604131726-2387010455-2909821853-1002UA.job 2014-02-05 15:43 - 2013-01-20 22:30 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-05 10:49 - 2014-02-05 10:48 - 06952512 _____ (TeamViewer GmbH) C:\Users\system_ADMIN\Downloads\TeamViewer_Setup.exe 2014-02-05 10:46 - 2009-07-14 05:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-05 10:46 - 2009-07-14 05:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-05 10:45 - 2013-06-01 17:06 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\TeamViewer 2014-02-05 09:32 - 2014-01-10 11:02 - 02332590 _____ () C:\Users\system_ADMIN\Downloads\TechnicLauncher (1).exe 2014-02-05 09:32 - 2014-01-08 17:07 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\.technic 2014-02-04 20:47 - 2013-01-20 22:33 - 00002177 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-02-04 19:33 - 2012-05-11 15:22 - 00001124 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1604131726-2387010455-2909821853-1002Core.job 2014-02-04 12:21 - 2014-01-19 18:56 - 00003117 _____ () C:\Users\system_ADMIN\AppData\Roaming\PData.MMM 2014-02-04 12:21 - 2014-01-19 18:56 - 00003117 _____ () C:\Users\system_ADMIN\AppData\Roaming\PData.MM1 2014-02-04 10:19 - 2013-12-15 15:49 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Local\Purplizer 2014-02-03 17:20 - 2014-02-03 17:20 - 00000000 ____D () C:\ProgramData\Overwolf 2014-02-03 17:18 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-03 17:17 - 2014-02-03 17:17 - 00000272 _____ () C:\Windows\Tasks\ASUS SmartLogon Console Sensor.job 2014-02-03 17:17 - 2013-11-29 16:55 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Local\Overwolf 2014-02-03 17:16 - 2013-03-18 22:40 - 00000000 ____D () C:\ProgramData\VMware 2014-02-03 17:16 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-02-03 17:14 - 2009-07-14 05:51 - 00147710 _____ () C:\Windows\setupact.log 2014-02-03 11:14 - 2013-04-21 08:24 - 00000000 ____D () C:\Users\system_ADMIN\.gimp-2.6 2014-02-03 10:13 - 2014-02-03 10:13 - 00000849 _____ () C:\Users\system_ADMIN\AppData\Local\recently-used.xbel 2014-02-03 10:09 - 2013-10-05 16:56 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-02-02 22:38 - 2012-04-02 15:47 - 00045056 _____ () C:\Windows\SysWOW64\acovcnt.exe 2014-02-02 20:39 - 2013-12-16 17:17 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\AUTOSICH 2014-02-02 20:34 - 2013-04-21 00:08 - 00007595 _____ () C:\Users\system_ADMIN\AppData\Local\resmon.resmoncfg 2014-02-02 20:07 - 2014-02-02 20:07 - 00281016 _____ () C:\Users\system_ADMIN\Downloads\FuzzyPurp-Redworks-FLOPPY-e8ce09e.zip 2014-02-01 14:06 - 2014-01-09 18:06 - 02406621 _____ () C:\Users\system_ADMIN\Downloads\TechnicLauncher.exe 2014-01-29 20:28 - 2013-12-26 16:50 - 00000000 ____D () C:\Users\system_ADMIN\Desktop\Server 2014-01-29 18:23 - 2013-08-23 05:29 - 00000262 _____ () C:\Users\system_ADMIN\Desktop\sad.txt 2014-01-28 17:08 - 2014-01-28 17:08 - 00000000 ____D () C:\Users\system_ADMIN\Desktop\Neuer Ordner (7) 2014-01-28 17:07 - 2014-01-28 17:07 - 00659797 _____ () C:\Users\system_ADMIN\Downloads\VisualBoyAdvance-1.8.0-beta3.zip 2014-01-28 17:05 - 2011-02-19 05:24 - 00780892 _____ () C:\Windows\system32\perfh007.dat 2014-01-28 17:05 - 2011-02-19 05:24 - 00180408 _____ () C:\Windows\system32\perfc007.dat 2014-01-28 17:05 - 2009-07-14 06:13 - 01849474 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-01-28 12:48 - 2014-01-28 12:43 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Local\Temporary Projects 2014-01-28 12:39 - 2013-08-23 06:17 - 00000000 ____D () C:\Users\system_ADMIN\Documents\Visual Studio 2012 2014-01-26 20:41 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-01-26 20:29 - 2014-01-26 20:28 - 00275224 _____ () C:\Windows\Minidump\012614-97438-01.dmp 2014-01-26 20:28 - 2012-06-14 06:09 - 601211795 _____ () C:\Windows\MEMORY.DMP 2014-01-26 20:28 - 2012-06-14 06:09 - 00000000 ____D () C:\Windows\Minidump 2014-01-24 20:19 - 2011-10-19 04:20 - 00751878 _____ () C:\Windows\PFRO.log 2014-01-23 21:47 - 2013-12-22 13:19 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-01-23 21:47 - 2013-10-05 16:56 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-01-23 21:47 - 2013-10-05 16:56 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-01-23 21:47 - 2013-10-05 16:56 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-01-23 21:47 - 2013-10-05 16:56 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-01-23 21:47 - 2013-10-05 16:56 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-01-23 21:47 - 2013-10-05 16:56 - 00001968 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-01-20 21:57 - 2014-01-20 21:57 - 00003935 _____ () C:\Users\system_ADMIN\Downloads\br_easy2.lua 2014-01-20 19:46 - 2014-01-20 19:46 - 00285595 _____ () C:\Users\system_ADMIN\Downloads\CraftOS1.3.1-MultiLauange.zip 2014-01-20 18:26 - 2014-01-20 18:26 - 00118149 _____ () C:\Users\system_ADMIN\Downloads\wmpChrome.crx 2014-01-16 18:28 - 2009-07-14 05:45 - 00522792 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-15 23:19 - 2014-01-15 23:19 - 536870912 _____ () C:\Users\system_ADMIN\Downloads\pkms2.nds 2014-01-15 23:19 - 2014-01-04 17:52 - 00000000 ____D () C:\Users\system_ADMIN\Desktop\ideas1040 2014-01-14 22:22 - 2013-11-29 16:54 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\TS3Client 2014-01-14 22:22 - 2013-11-11 21:19 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\Skype 2014-01-12 19:45 - 2013-11-28 13:01 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\.minecraft 2014-01-10 17:24 - 2014-01-10 17:24 - 05074125 _____ () C:\Users\system_ADMIN\Downloads\Nodus.zip 2014-01-10 17:07 - 2014-01-10 17:07 - 00057165 _____ () C:\Users\system_ADMIN\Downloads\RadarBro1.5.2.zip 2014-01-10 13:40 - 2014-01-10 13:40 - 00028085 _____ () C:\Users\system_ADMIN\Downloads\AutoSwitch-v4.0.1-mc1.5.2.zip 2014-01-10 13:40 - 2014-01-10 13:40 - 00016258 _____ () C:\Users\system_ADMIN\Downloads\ThebombzenAPI-v2.0.0-mc1.5.2.zip 2014-01-10 11:09 - 2014-01-10 11:09 - 00377553 _____ () C:\Users\system_ADMIN\Downloads\NotEnoughItems 1.5.2.27.jar 2014-01-10 11:09 - 2014-01-10 11:09 - 00314452 _____ () C:\Users\system_ADMIN\Downloads\CodeChickenCore 0.8.7.3.jar 2014-01-10 10:59 - 2014-01-10 10:59 - 00275231 _____ () C:\Users\system_ADMIN\Downloads\codechickencore_0_8_6_5 (1).jar 2014-01-10 10:47 - 2014-01-10 10:47 - 00899375 _____ () C:\Users\system_ADMIN\Downloads\ForgeMultipart-dev-1.5.2-1.0.0.149.jar 2014-01-10 10:45 - 2014-01-10 10:45 - 00117705 _____ () C:\Users\system_ADMIN\Downloads\WR-CBE Core 1.4.jar 2014-01-10 10:41 - 2014-01-10 10:41 - 00367630 _____ () C:\Users\system_ADMIN\Downloads\notenoughitems_1_5_2_12.jar 2014-01-10 10:41 - 2014-01-10 10:41 - 00367630 _____ () C:\Users\system_ADMIN\Downloads\notenoughitems_1_5_2_12 (1).jar 2014-01-10 10:41 - 2014-01-10 10:41 - 00275231 _____ () C:\Users\system_ADMIN\Downloads\codechickencore_0_8_6_5.jar 2014-01-10 10:23 - 2014-01-10 10:22 - 01997327 _____ () C:\Users\system_ADMIN\Downloads\bcprov-jdk15on-147.jar 2014-01-10 10:16 - 2014-01-10 10:14 - 19092307 _____ () C:\Users\system_ADMIN\Downloads\fmllibs16.zip 2014-01-10 10:09 - 2014-01-10 10:09 - 02189140 _____ () C:\Users\system_ADMIN\Downloads\guava-14.0-rc3 (1).jar 2014-01-10 10:09 - 2014-01-10 10:09 - 00214592 _____ () C:\Users\system_ADMIN\Downloads\asm-all-4.1 (1).jar 2014-01-10 10:09 - 2014-01-10 10:09 - 00091333 _____ () C:\Users\system_ADMIN\Downloads\argo-small-3.2 (1).jar 2014-01-10 10:07 - 2014-01-10 10:06 - 02189140 _____ () C:\Users\system_ADMIN\Downloads\guava-14.0-rc3.jar 2014-01-10 10:07 - 2014-01-10 10:06 - 00214592 _____ () C:\Users\system_ADMIN\Downloads\asm-all-4.1.jar 2014-01-10 10:07 - 2014-01-10 10:06 - 00091333 _____ () C:\Users\system_ADMIN\Downloads\argo-small-3.2.jar 2014-01-10 10:06 - 2014-01-10 10:06 - 00201404 _____ () C:\Users\system_ADMIN\Downloads\deobfuscation_data_1.5.2.zip 2014-01-10 09:59 - 2014-01-10 09:59 - 00252446 _____ () C:\Users\system_ADMIN\Downloads\Rei’s Minimap Mod 1.5.2.zip 2014-01-10 09:57 - 2014-01-10 09:56 - 01975130 _____ () C:\Users\system_ADMIN\Downloads\Minecraft Forge 1.5.2.zip 2014-01-09 23:08 - 2014-01-09 23:08 - 01349598 _____ () C:\Users\system_ADMIN\Documents\Logs-2014-01-09T23-06-47.gz 2014-01-09 19:58 - 2014-01-09 19:58 - 00064379 _____ () C:\Users\system_ADMIN\Downloads\X-RayMod_v040.zip 2014-01-09 19:54 - 2014-01-09 19:54 - 00007934 _____ () C:\Users\system_ADMIN\Downloads\FlyMod_v040.zip 2014-01-09 19:48 - 2014-01-09 19:47 - 01160192 _____ () C:\Users\system_ADMIN\Downloads\X-Ray Mod Installer.exe 2014-01-09 19:38 - 2014-01-09 19:37 - 00064373 _____ () C:\Users\system_ADMIN\Downloads\X-RayMod_v038.zip 2014-01-09 16:15 - 2013-12-21 12:21 - 00001336 _____ () C:\Users\system_ADMIN\Desktop\Sandboxed Web Browser.lnk 2014-01-09 15:57 - 2014-01-09 15:56 - 00275112 _____ () C:\Windows\Minidump\010914-37253-01.dmp 2014-01-09 15:54 - 2014-01-02 23:51 - 00000000 ____D () C:\Users\system_ADMIN\Desktop\Neuer Ordner (4) 2014-01-09 15:54 - 2013-04-21 00:11 - 00000000 ____D () C:\Users\Administrator 2014-01-09 15:54 - 2012-05-20 05:24 - 00000000 ____D () C:\Users\Gast 2014-01-09 15:54 - 2012-02-05 01:36 - 00000000 ____D () C:\ProgramData\P4G 2014-01-09 15:53 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration 2014-01-08 17:07 - 2014-01-08 16:06 - 00000000 ____D () C:\Users\system_ADMIN\Ekahau Site Survey 2014-01-08 16:04 - 2014-01-08 16:04 - 00000000 ____D () C:\Program Files\Ekahau 2014-01-07 12:35 - 2014-01-07 12:35 - 00216033 _____ () C:\Users\system_ADMIN\Downloads\HideToolz_2_2 (1).zip 2014-01-07 12:34 - 2014-01-07 12:34 - 00215311 _____ () C:\Users\system_ADMIN\Downloads\HideToolz_2_2.zip 2014-01-07 09:50 - 2013-05-02 16:07 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Local\CrashDumps 2014-01-07 09:27 - 2014-01-07 09:27 - 00206537 _____ () C:\Users\system_ADMIN\Downloads\HideToolz_v2.2 (1).rar 2014-01-06 19:28 - 2014-01-06 19:28 - 00858033 _____ () C:\Users\system_ADMIN\Downloads\4Story Macro (1).zip Some content of TEMP: ==================== C:\Users\system_ADMIN\AppData\Local\Temp\instloffer.exe C:\Users\system_ADMIN\AppData\Local\Temp\SkypeSetup.exe C:\Users\system_ADMIN\AppData\Local\Temp\ubiA1BE.tmp.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-31 21:55 ==================== End Of Log ============================ Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 18:43 on 05/02/2014 (system_ADMIN) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-02-2014 Ran by system_ADMIN at 2014-02-05 19:00:56 Running from C:\Users\system_ADMIN\Desktop\Neuer Ordner (8) Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== Tools for .Net 3.5 - DEU Lang Pack (x32 Version: 3.11.50727 - Microsoft Corporation) Hidden Tools for .Net 3.5 (x32 Version: 3.11.50727 - Microsoft Corporation) Hidden 4Story (HKCU Version: 4.02.01.42 - ) 4Story DE 4.2.213 (x32 Version: - ) 5-Mode Oscar Editor (x32 Version: 12.03.0001 - A4Tech) A1 Servicecenter (x32 Version: 1.2.0.30 - A1 Telekom Austria AG) Hidden Adobe Flash Player 11 ActiveX (x32 Version: 11.5.502.135 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) AMD APP SDK Runtime (Version: 2.5.775.2 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Install Manager (Version: 3.0.847.0 - Advanced Micro Devices, Inc.) AMD Fuel (Version: 2011.1102.8.41498 - Advanced Micro Devices, Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.61101.2304 - Advanced Micro Devices, Inc.) Hidden AMD System Monitor (x32 Version: 1.0.8 - Advanced Micro Devices, Inc.) AMD VISION Engine Control Center (x32 Version: 2011.1102.8.41498 - Advanced Micro Devices, Inc.) Hidden aonController (x32 Version: 2.1 - Telekom Austria TA AG) Hidden aonFTP (x32 Version: 1.0 - Telekom Austria TA AG) Hidden aonUpdate (x32 Version: 1.0 - Telekom Austria TA AG) Hidden Aptana Studio 3 (x32 Version: 3.4.2 - Appcelerator, Inc.) ASIO4ALL (x32 Version: 2.10 - Michael Tippach) ASUS AI Recovery (x32 Version: 1.0.19 - ASUS) ASUS FaceLogon (x32 Version: 1.0.0012 - ASUS) ASUS LifeFrame3 (x32 Version: 3.0.27 - ASUS) ASUS Live Update (x32 Version: 3.0.8 - ASUS) ASUS Power4Gear Hybrid (Version: 1.1.50 - ASUS) ASUS Sonic Focus (x32 Version: 1.0.0.5 - Synopsys ) ASUS Splendid Video Enhancement Technology (x32 Version: 1.02.0036 - ASUS) ASUS USB Charger Plus (x32 Version: 2.0.5 - ASUS) ASUS Virtual Camera (x32 Version: 1.0.24 - asus) ASUS WebStorage (x32 Version: 3.0.108.222 - eCareme Technologies, Inc.) ASUS_Screensaver (x32 Version: - ) AsusVibe2.0 (x32 Version: 2.0.7.142 - ASUSTEK) Atheros Bluetooth Suite (64) (Version: 7.04.000.98 - Atheros) ATK Package (x32 Version: 1.0.0027 - ASUS) AutoHotkey 1.1.13.01 (Version: 1.1.13.01 - Lexikos) avast! Ad Blocker (x32 Version: 1.0.0.0 - AVAST Software) avast! Free Antivirus (x32 Version: 9.0.2013 - Avast Software) Blend for Visual Studio 2012 (x32 Version: 5.0.30709.0 - Microsoft Corporation) Hidden Blend for Visual Studio 2012 DEU resources (x32 Version: 5.0.30709.0 - Microsoft Corporation) Hidden Blend for Visual Studio Add-in for Adobe FXG Import (x32 Version: 1.0.40218.0 - Microsoft Corporation) Hidden Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden Blend for Visual Studio SDK for Silverlight 5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden Bonjour (Version: 3.0.0.10 - Apple Inc.) Bubbletown (x32 Version: - Oberon Media) Catalyst Control Center Graphics Previews Common (x32 Version: 2011.1102.8.41498 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2011.1102.8.41498 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2011.1102.8.41498 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Profiles Mobile (x32 Version: 2011.1102.8.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2011.1102.0007.41498 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2011.1102.8.41498 - Advanced Micro Devices, Inc.) Hidden Cheat Engine 6.3 (x32 Version: - Cheat Engine) Control ActiveX de Windows Live Mesh para conexiones remotas (x32 Version: 15.4.5722.2 - Microsoft Corporation) Contrôle ActiveX Windows Live Mesh pour connexions à distance (x32 Version: 15.4.5722.2 - Microsoft Corporation) Controller (x32 Version: 3.0.0.124 - A1 Telekom Austria) Controller (x32 Version: 3.0.0.124 - A1 Telekom Austria) Hidden Controlo ActiveX do Windows Live Mesh para Ligações Remotas (x32 Version: 15.4.5722.2 - Microsoft Corporation) CyberLink LabelPrint (x32 Version: 2.5.3624 - CyberLink Corp.) CyberLink LabelPrint (x32 Version: 2.5.3624 - CyberLink Corp.) Hidden CyberLink Media Suite (x32 Version: 8.0.2926 - CyberLink Corp.) CyberLink Media Suite (x32 Version: 8.0.2926 - CyberLink Corp.) Hidden CyberLink Power2Go (x32 Version: 7.0.0.1126 - CyberLink Corp.) CyberLink Power2Go (x32 Version: 7.0.0.1126 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Lite (x32 Version: 4.45.4.0315 - DT Soft Ltd) Deadtime Stories (x32 Version: - Oberon Media) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32 Version: - Microsoft) Devenv-Ressourcen für Microsoft Visual Studio 2012 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Dotfuscator and Analytics Community Edition (x32 Version: 5.5.4521.29298 - PreEmptive Solutions) Hidden Dotfuscator and Analytics Community Edition Language Pack (x32 Version: 5.5.4521.29298 - PreEmptive Solutions) Hidden Dream Day First Home (x32 Version: - Oberon Media) Dream Vacation Solitaire (x32 Version: - Oberon Media) EE-ZDE (x32 Version: - ) Empire Earth (x32 Version: - ) Entity Framework Designer für Visual Studio 2012 - DEU (x32 Version: 11.1.21009.00 - Microsoft Corporation) Erforderliche Komponenten für SSDT (x32 Version: 11.0.2100.60 - Microsoft Corporation) ETDWare PS/2-X64 8.0.5.1_WHQL (Version: 8.0.5.1 - ELAN Microelectronic Corp.) Facebook Messenger 2.1.4814.0 (x32 Version: 2.1.4814.0 - Facebook) Farm Frenzy 3 - Madagascar (x32 Version: - Oberon Media) Fast Boot (Version: 1.0.10 - ASUS) FileZilla Client 3.7.2 (x32 Version: 3.7.2 - Tim Kosse) Free Mouse Auto Clicker 3.0 (x32 Version: - Advanced Mouse Auto Clicker ltd.) Free Pdf Perfect Prereq (x32 Version: 1.0.0.0 - Covus Freemium GmbH) Free Pdf Perfect Prereq (x32 Version: 1.0.0.0 - Covus Freemium GmbH) Hidden Free Video to MP3 Converter version 5.0.27.717 (x32 Version: 5.0.27.717 - DVDVideoSoft Ltd.) Free YouTube Download version 3.2.8.717 (x32 Version: 3.2.8.717 - DVDVideoSoft Ltd.) Galapago (x32 Version: - Oberon Media) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Game Park Console (x32 Version: 1.2.4.431 - Oberon Media Inc.) GIMP 2.6.12 (Version: 2.6.12 - The GIMP Team) Google Chrome (x32 Version: 32.0.1700.107 - Google Inc.) Google Earth (x32 Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden HP Deskjet 2050 J510 series - Grundlegende Software für das Gerät (Version: 22.50.231.0 - Hewlett-Packard Co.) HP Deskjet 2050 J510 series Hilfe (x32 Version: 140.0.61.61 - Hewlett Packard) IIS 8.0 Express (Version: 8.0.1557 - Microsoft Corporation) IIS Express Application Compatibility Database for x64 (Version: - ) IIS Express Application Compatibility Database for x86 (Version: - ) IncrediMail (x32 Version: 6.2.9.5188 - IncrediMail) Hidden IncrediMail 2.0 (x32 Version: 6.2.9.5188 - IncrediMail Ltd.) Invekos-GIS (x32 Version: 3.1.3.6 - Agrarmarkt Austria) Java 7 Update 40 (64-bit) (Version: 7.0.400 - Oracle) Java 7 Update 45 (x32 Version: 7.0.450 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden JavaFX 2.1.1 (x32 Version: 2.1.1 - Oracle Corporation) JavaScript Tooling (Version: 11.0.60315 - Microsoft Corporation) Hidden JavaScript Tooling (x32 Version: 11.0.60315 - Microsoft Corporation) Hidden JetBrains PhpStorm 6.0.3 (x32 Version: 129.814 - JetBrains s.r.o.) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Kalydo Player 5.09.05 (HKCU Version: 5.09.05 - Eximion B.V.) League of Legends (x32 Version: 3.0.1 - Riot Games ) League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden Linkury Smartbar (x32 Version: 1.6.1.909 - Linkury Inc.) <==== ATTENTION LocalESPC (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden LocalESPCui for de-de (x32 Version: 8.59.25584 - Microsoft) Hidden MAGIX Music Maker Techno Edition 4 Download-Version (x32 Version: 6.0.0.6 - MAGIX AG) Hidden Mahjong Memoirs (x32 Version: - Oberon Media) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Multi-Targeting Pack (x32 Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4.5 (Version: 4.5.50709 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5 DEU Language Pack (Version: 4.5.50709 - Microsoft Corporation) Microsoft .NET Framework 4.5 DEU Language Pack (Version: 4.5.50709 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5 Multi-Targeting Pack (x32 Version: 4.5.50709 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK - DEU Lang Pack (x32 Version: 4.5.50709 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK (x32 Version: 4.5.50709 - Microsoft Corporation) Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (x32 Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft ASP.NET MVC 3 - DEU (x32 Version: 3.0.20105.0 - Microsoft Corporation) Microsoft ASP.NET MVC 3 - Visual Studio 2012 Tools Update - DEU (x32 Version: 3.0.30710.0 - Microsoft Corporation) Hidden Microsoft ASP.NET MVC 3 - Visual Studio 2012 Tools Update (x32 Version: 3.0.30710.0 - Microsoft Corporation) Hidden Microsoft ASP.NET MVC 3 (x32 Version: 3.0.20105.0 - Microsoft Corporation) Microsoft ASP.NET MVC 4 - Visual Studio 2012 Tools - DEU (x32 Version: 4.1.20219.0 - Microsoft Corporation) Hidden Microsoft ASP.NET MVC 4 - Visual Studio 2012 Tools - ENU (x32 Version: 4.1.20219.0 - Microsoft Corporation) Hidden Microsoft ASP.NET MVC 4 Runtime - DEU (x32 Version: 4.0.20710.0 - Microsoft Corporation) Hidden Microsoft ASP.NET MVC 4 Runtime (x32 Version: 4.0.20710.0 - Microsoft Corporation) Hidden Microsoft ASP.NET Web Pages - DEU (x32 Version: 1.0.20105.0 - Microsoft Corporation) Microsoft ASP.NET Web Pages - Visual Studio 2012 Tools - DEU (x32 Version: 1.0.20710.0 - Microsoft Corporation) Hidden Microsoft ASP.NET Web Pages - Visual Studio 2012 Tools (x32 Version: 1.0.20710.0 - Microsoft Corporation) Hidden Microsoft ASP.NET Web Pages (x32 Version: 1.0.20105.0 - Microsoft Corporation) Microsoft ASP.NET Web Pages 2 - Visual Studio 2012 Tools - DEU (x32 Version: 4.1.20219.0 - Microsoft Corporation) Hidden Microsoft ASP.NET Web Pages 2 - Visual Studio 2012 Tools - ENU (x32 Version: 4.1.20219.0 - Microsoft Corporation) Hidden Microsoft ASP.NET Web Pages 2 Runtime - DEU (x32 Version: 2.0.20710.0 - Microsoft Corporation) Hidden Microsoft ASP.NET Web Pages 2 Runtime (x32 Version: 2.0.20715.0 - Microsoft Corporation) Hidden Microsoft Expression Blend SDK for .NET 4 (x32 Version: 2.0.20525.0 - Microsoft Corporation) Hidden Microsoft Expression Blend SDK for Silverlight 4 (x32 Version: 2.0.20525.0 - Microsoft Corporation) Hidden Microsoft Help Viewer 1.0 (Version: 1.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.0 (Version: 1.0.30319 - Microsoft Corporation) Hidden Microsoft Help Viewer 1.0 Language Pack - DEU (Version: 1.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.0 Language Pack - DEU (Version: 1.0.30319 - Microsoft Corporation) Hidden Microsoft Help Viewer 2.0 (x32 Version: 2.0.50727 - Microsoft Corporation) Microsoft Help Viewer 2.0 (x32 Version: 2.0.50727 - Microsoft Corporation) Hidden Microsoft Help Viewer 2.0 Language Pack - DEU (x32 Version: 2.0.50727 - Microsoft Corporation) Microsoft Help Viewer 2.0 Language Pack - DEU (x32 Version: 2.0.50727 - Microsoft Corporation) Hidden Microsoft LightSwitch for Visual Studio 2012 Core (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft LightSwitch for Visual Studio 2012 v3.0 Core (x32 Version: 11.0.60517 - Microsoft Corporation) Hidden Microsoft LightSwitch for Visual Studio 2012 v3.0 CoreRes - DEU (x32 Version: 11.0.60517 - Microsoft Corporation) Hidden Microsoft LightSwitch für Visual Studio 2012 CoreRes - DEU (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft NuGet - Visual Studio 2012 (x32 Version: 2.0.30625.9003 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word Viewer 2003 (x32 Version: 11.0.8173.0 - Microsoft Corporation) Microsoft Portable Library Multi-Targeting Pack (x32 Version: 11.0.60418.17931 - Microsoft Corporation) Hidden Microsoft Portable Library Multi-Targeting Pack Language Pack - deu (x32 Version: 11.0.50709.17929 - Microsoft Corporation) Hidden Microsoft Report Viewer Add-On for Visual Studio 2012 (x32 Version: 11.1.2802.16 - Microsoft Corporation) Hidden Microsoft Report Viewer Add-On für Visual Studio 2012 (x32 Version: 11.1.2802.16 - Microsoft Corporation) Hidden Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Silverlight 4 SDK - Deutsch (x32 Version: 4.0.60310.0 - Microsoft Corporation) Microsoft Silverlight 5 SDK - DEU (x32 Version: 5.0.61118.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2008 (64-bit) (Version: - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Browser (x32 Version: 10.1.2531.0 - Microsoft Corporation) Microsoft SQL Server 2008 Common Files (Version: 10.0.1600.22 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Common Files (Version: 10.1.2531.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Database Engine Services (Version: 10.1.2531.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Database Engine Shared (Version: 10.1.2531.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 Native Client (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft SQL Server 2008 R2 Management Objects (x32 Version: 10.50.1447.4 - Microsoft Corporation) Microsoft SQL Server 2008 RsFx Driver (Version: 10.1.2531.0 - Microsoft Corporation) Hidden Microsoft SQL Server 2012 Command Line Utilities (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (Version: 11.0.2316.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (x32 Version: 11.0.2316.0 - Microsoft Corporation) Microsoft SQL Server 2012 Express LocalDB (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (x32 Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (x64) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL Compiler Service (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL ScriptDom (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 T-SQL Language Service (x32 Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 DEU (x32 Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 x64 DEU (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 x64 DEU (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft SQL Server Data Tools - DEU (11.1.20627.00) (x32 Version: 11.1.20627.00 - Microsoft Corporation) Microsoft SQL Server Data Tools Build Utilities - DEU (11.1.20627.00) (x32 Version: 11.1.20627.00 - Microsoft Corporation) Microsoft SQL Server System CLR Types (x32 Version: 10.50.1600.1 - Microsoft Corporation) Microsoft SQL Server System CLR Types (x64) (Version: 10.50.1600.1 - Microsoft Corporation) Microsoft SQL Server VSS Writer (Version: 10.1.2531.0 - Microsoft Corporation) Microsoft Visual Basic 2010 Express - DEU (x32 Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual Basic 2010 Express - DEU (x32 Version: 10.0.30319 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (x32 Version: 9.0.30411 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Runtime - 10.0.30319 (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Designtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 32bit Compilers - DEU Resources (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 Compilers - DEU Resources (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 Compilers (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 Core Libraries (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 Extended Libraries (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 Microsoft Foundation Class Libraries (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Debug Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Debug Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86-x64 Compilers (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (x32 Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual Studio 2010 Express Prerequisites x64 - DEU (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual Studio 2010 Office Developer Tools (x64) (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Office Developer Tools (x64) Language Pack - DEU (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.40303 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.40308 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU (Version: 10.0.40303 - Microsoft Corporation) Hidden Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (Version: 10.0.40303 - Microsoft Corporation) Microsoft Visual Studio 2012 Devenv (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 IntelliTrace Core amd64 (Version: 11.0.60315 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 IntelliTrace Core x86 (x32 Version: 11.0.60315 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 IntelliTrace Front End x86 (x32 Version: 11.0.60315 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 IntelliTraceFrontEndLoc (x32 Version: 11.0.60315 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 IntelliTraceLoc (Version: 11.0.60315 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 IntelliTraceLoc (x32 Version: 11.0.60315 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 SharePoint Developer Tools (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 SharePoint Developer Tools DEU Language Pack (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 Shell (Minimum) (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 Shell (Minimum) Interop Assemblies (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 Shell-(Mindest)-Ressourcen (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 Tools für SQL Server Compact 4.0 SP1 DEU (x32 Version: 4.0.8876.1 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012-Leistungserfassungstools - DEU (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012-Leistungserfassungstools (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012-Vorbereitung (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Premium 2012 - DEU (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Premium 2012 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Professional 2012 - DEU (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Professional 2012 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Team Foundation Server 2012 Object Model (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual Studio Team Foundation Server 2012 Object Model Language Pack - DEU (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual Studio Team Foundation Server 2012 Storyboarding (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Team Foundation Server 2012 Storyboarding Language Pack - DEU (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Team Foundation Server 2012 Team Explorer (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Team Foundation Server 2012 Team Explorer Language Pack - DEU (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Ultimate 2012 - DEU (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Ultimate 2012 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Ultimate 2012 (x32 Version: 11.0.50727.26 - Microsoft Corporation) Microsoft Visual Studio Ultimate 2012 XAML UI Designer Core (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Ultimate 2012 XAML UI Designer deu Resources (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Web Deploy 3.0 (Version: 3.1236.1631 - Microsoft Corporation) Microsoft Web Deploy dbSqlPackage Provider - DEU (x32 Version: 10.3.20225.0 - Microsoft Corporation) Microsoft Web Developer Tools 2012.2 - Visual Studio 2012 - deu (x32 Version: 1.2.40308.0 - Microsoft Corporation) Hidden Microsoft Web Developer Tools 2012.2 - Visual Studio 2012 (x32 Version: 1.2.40308.0 - Microsoft Corporation) Hidden Microsoft Web Platform Installer 4.0 (Version: 4.0.1622 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2012 (x32 Version: 11.0.2100.60 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2012 (x64) (Version: 11.0.2100.60 - Microsoft Corporation) Mozilla Firefox 25.0.1 (x86 de) (x32 Version: 25.0.1 - Mozilla) Mozilla Maintenance Service (x32 Version: 25.0.1 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation) MySQL Connector Net 6.7.4 (x32 Version: 6.7.4 - Oracle) Nero Audio Pack 1 (x32 Version: 11.0.11500.110.0 - Nero AG) Hidden Nero Blu-ray Player (x32 Version: 12.0.20012 - Nero AG) Hidden Nero Blu-ray Player Help (CHM) (x32 Version: 12.0.9000 - Nero AG) Hidden Nero Core Components (x32 Version: 11.0.20200 - Nero AG) Hidden Nero Kwik Media (x32 Version: 1.18.20100 - Nero AG) Hidden Nero Kwik Media (x32 Version: 12.5.00300 - Nero AG) Nero Kwik Media Help (CHM) (x32 Version: 12.0.12000 - Nero AG) Hidden Nero Kwik Themes Basic (x32 Version: 12.0.11500 - Nero AG) Hidden Nero SharedVideoCodecs (x32 Version: 1.0.12100.2.0 - Nero AG) Hidden Nero Update (x32 Version: 11.0.11800.31.0 - Nero AG) Hidden NetSetMan 3.5.2 (x32 Version: 3.5.2 - Ilja Herlein) Notepad++ (x32 Version: 6.4.3 - Notepad++ Team) Nuance PDF Reader (x32 Version: 6.00.0041 - Nuance Communications, Inc.) NVIDIA PhysX (x32 Version: 9.10.0129 - NVIDIA Corporation) OpenOffice.org 3.4 (x32 Version: 3.4.9590 - OpenOffice.org) OSCAR Editor (x32 Version: 12.03.0004 - A4TECH) Hidden Overwolf (x32 Version: 0.47.284 - Overwolf) Pando Media Booster (x32 Version: 2.6.0.8 - Pando Networks Inc.) Photo Notifier and Animation Creator (x32 Version: 1.0.0.1009 - Ihr Firmenname) Hidden Photo Notifier and Animation Creator (x32 Version: 1.0.0.1009 - IncrediMail Ltd.) PreEmptive Analytics Client German Language Pack (x32 Version: 1.0.2180.1 - PreEmptive Solutions) Hidden PreEmptive Analytics Visual Studio Components (x32 Version: 1.0.2180.1 - PreEmptive Solutions) Hidden Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden Qualcomm Atheros WiFi Driver Installation (x32 Version: 9.2 - Qualcomm Atheros) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (x32 Version: 7.43.321.2011 - Realtek) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6482 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30127 - Realtek Semiconductor Corp.) RocketDock 1.3.5 (x32 Version: - Punk Software) Samsung Kies (x32 Version: 2.6.0.13091_9 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.6.0.13091_9 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (Version: 1.5.27.0 - SAMSUNG Electronics Co., Ltd.) Sandboxie 4.06 (64-bit) (Version: 4.06 - Sandboxie Holdings, LLC) Service Pack 1 für SQL Server 2008 (KB 968369) (64-bit) (Version: 10.1.2531.0 - Microsoft Corporation) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden Skype Click to Call (x32 Version: 5.10.9560 - Skype Technologies S.A.) Skype™ 6.10 (x32 Version: 6.10.104 - Skype Technologies S.A.) Smart-X7 7.80 (Version: - ) Sql Server Customer Experience Improvement Program (Version: 10.1.2531.0 - Microsoft Corporation) Hidden ss helper 1.74 (x32 Version: - Verified Publisher) TeamSpeak 3 Client (Version: 3.0.13 - TeamSpeak Systems GmbH) TeamViewer 8 (x32 Version: 8.0.22298 - TeamViewer) Text-To-Speech-Runtime (x32 Version: 1.0.0.0 - Magix Development GmbH) Tom Clancy's Splinter Cell Conviction (x32 Version: 1.00.000 - Ubisoft) Tom Clancy's Splinter Cell® Blacklist™ (x32 Version: 1.00 - Ubisoft) tools-linux (x32 Version: 9.6.1.1379776 - VMware, Inc.) Hidden TuneUp Utilities 2012 (x32 Version: 12.0.3600.73 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3600.73 - TuneUp Software) Hidden Turbo Fiesta (x32 Version: - Oberon Media) Ubisoft Game Launcher (x32 Version: 1.0.0.0 - UBISOFT) Unterstützungsdateien für Microsoft SQL Server 2008-Setup (Version: 10.1.2731.0 - Microsoft Corporation) Update for Microsoft .NET Framework 4.5 (KB2750147) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4.5 (KB2805221) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4.5 (KB2805226) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Visual Studio 2012 (KB2781514) (x32 Version: 11.0.51219 - Microsoft Corporation) Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (x32 Version: - Microsoft) Uplay (x32 Version: 3.0 - Ubisoft) Virtual Audio Cable 4.9 (Version: - ) VirtualDJ Home FREE (x32 Version: 7.0.5 - Atomix Productions) Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU (x32 Version: 4.0.8080.0 - Microsoft Corporation) Visual Studio 2012 Prerequisites - DEU Language Pack (Version: 11.0.50727 - Microsoft Corporation) Hidden Visual Studio 2012 Prerequisites (Version: 11.0.50727 - Microsoft Corporation) Hidden Visual Studio 2012 Update 3 (KB2707250) (x32 Version: 11.0.60610 - Microsoft Corporation) Visual Studio Extensions for Windows Library for JavaScript (x32 Version: 1.0.9201.20602 - Microsoft Corporation) Hidden VMware Player (Version: 6.0.1 - VMware, Inc.) Hidden VMware Player (x32 Version: 6.0.1 - VMware, Inc) WCF Data Services 5.0 (for OData v3) DEU Language Pack (x32 Version: 5.0.50628.0 - Microsoft Corporation) Hidden WCF Data Services 5.0 (for OData v3) Primary Components (x32 Version: 5.0.50628.0 - Microsoft Corporation) Hidden WCF Data Services Tools for Microsoft Visual Studio 2012 (x32 Version: 5.0.50710.0 - Microsoft Corporation) Hidden WCF Data Services Tools for Visual Studio 11 DEU Language Pack (x32 Version: 5.0.50710.0 - Microsoft Corporation) Hidden WCF RIA Services V1.0 SP2 (x32 Version: 4.1.61829.0 - Microsoft Corporation) WebEnhance (x32 Version: - ) Webocton - Scriptly 0.8.95.6 (x32 Version: 0.8.95.6 - Webocton) Windows App Certification Kit Native Components (Version: 8.59.29736 - Microsoft Corporation) Hidden Windows App Certification Kit x64 (x32 Version: 8.59.29750 - Microsoft Corporation) Hidden Windows Azure Tools for LightSwitch HTML Client for Visual Studio 2012 (x32 Version: 1.8.60301.1601 - Microsoft) Hidden Windows Azure Tools für LightSwitch HTML Client für Visual Studio 2012 (DEU) (x32 Version: 1.8.60301.1601 - Microsoft) Hidden Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Windows Live Family Safety (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (x32 Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3538.0513 - Корпорация Майкрософт) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Runtime Intellisense Content - de-de (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden Windows Software Development Kit (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden Windows Software Development Kit DirectX x64 Remote (Version: 8.59.25584 - Microsoft Corporation) Hidden Windows Software Development Kit DirectX x86 Remote (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden Windows Software Development Kit for Windows Store Apps (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden Windows Software Development Kit for Windows Store Apps DirectX x64 Remote (Version: 8.59.25584 - Microsoft Corporation) Hidden Windows Software Development Kit for Windows Store Apps DirectX x86 Remote (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden Windows XP Targeting with C++ (Version: 11.0.51106 - Microsoft Corporation) Hidden Windows XP Targeting with C++ (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden WinFlash (x32 Version: 2.32.0 - ASUS) WinRAR 5.00 (64-bit) (Version: 5.00.0 - win.rar GmbH) Wireless Console 3 (x32 Version: 3.0.24 - ASUS) World of Goo (x32 Version: - Oberon Media) X7 Oscar Editor (x32 Version: 12.03.0004 - A4TECH) XAMPP (x32 Version: 1.8.2-2 - BitNami) Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (x32 Version: 15.4.5722.2 - Microsoft Corporation) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Элемент управления Windows Live Mesh ActiveX для удаленных подключений (x32 Version: 15.4.5722.2 - Microsoft Corporation) גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים (x32 Version: 15.4.5722.2 - Microsoft Corporation) بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (x32 Version: 15.4.5722.2 - Microsoft Corporation) معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden 適用遠端連線的 Windows Live Mesh ActiveX 控制項 (x32 Version: 15.4.5722.2 - Microsoft Corporation) ==================== Restore Points ========================= 23-01-2014 20:45:14 avast! antivirus system restore point 28-01-2014 16:08:19 Windows Update 31-01-2014 19:07:42 Windows Update 04-02-2014 09:32:20 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2013-09-21 11:30 - 00000910 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 asd.dd www.asd.dd ==================== Scheduled Tasks (whitelisted) ============= Task: {06CCB408-4DC2-40C4-8B70-3E879ED46AD4} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe [2011-10-03] (ASUS) Task: {29653395-2EE8-4296-AD57-B36268544DC1} - System32\Tasks\USBChargerPlus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2011-10-15] (ASUSTek Computer Inc.) Task: {2F70FF1C-3E89-48EE-A5C9-D5BB5C2F35AA} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-01-23] (AVAST Software) Task: {30A573E5-7E75-497E-A2F4-DDC2048801BD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-24] (Adobe Systems Incorporated) Task: {367C5E6C-06FA-4EA6-9B42-7784BA060F57} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-20] (Google Inc.) Task: {4EB48911-5909-45C8-A8C6-E22C3786D391} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation) Task: {5B1B6A91-AEF4-4313-B70F-FC85ECFCB66D} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2011-11-16] (ASUS) Task: {6B7770BC-DC41-4824-8A76-0C4AD5EB2167} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1604131726-2387010455-2909821853-1002UA => C:\Users\Dominik\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.) Task: {742FB6E7-0927-4AFF-9E7A-2493A9771DF4} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2011-11-23] (ASUS) Task: {9B13B335-97EA-49D6-B29D-0C75532DE507} - \DealPlyLiveUpdateTaskMachineUA No Task File Task: {9C1E67F1-8A09-4B37-84B3-E2A9673B79EB} - \Dealply No Task File Task: {D4F5D5B6-E5B8-467A-BE96-3BC90764D9B6} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2013-01-11] (ASUSTek Computer Inc.) Task: {E2442D41-9E74-4BCB-BD3B-1C249BDFC18C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-20] (Google Inc.) Task: {E7D530ED-1C1E-4496-9C96-EDC7AC3F5072} - \DealPlyLiveUpdateTaskMachineCore No Task File Task: {FDE79E0D-9B99-44E7-A33E-AA356DD03214} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1604131726-2387010455-2909821853-1002Core => C:\Users\Dominik\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\ASUS SmartLogon Console Sensor.job => C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1604131726-2387010455-2909821853-1002Core.job => C:\Users\Dominik\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1604131726-2387010455-2909821853-1002UA.job => C:\Users\Dominik\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2010-01-02 15:42 - 2010-01-02 15:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2012-06-18 16:24 - 2012-06-18 16:24 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_05.dll 2009-03-02 03:08 - 2009-03-02 03:08 - 00003584 _____ () C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\LogicNP.PropSheetExtensionHelper_x64.dll 2014-02-05 13:33 - 2014-02-05 10:22 - 02168320 _____ () C:\Program Files\AVAST Software\Avast\defs\14020500\algo.dll 2014-01-02 23:35 - 2007-04-06 13:04 - 00098304 _____ () C:\Program Files\Mouse\Amoures.dll 2011-09-13 22:33 - 2011-09-13 22:33 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll 2013-11-13 17:06 - 2013-11-13 17:06 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2013-10-18 12:46 - 2013-10-18 12:46 - 01260624 _____ () F:\vmware\libxml2.dll 2013-07-27 09:21 - 2013-07-27 09:21 - 01589248 _____ () C:\Program Files (x86)\Notepad++\plugins\DSpellCheck.dll 2011-07-18 22:07 - 2011-07-18 22:07 - 00014336 _____ () C:\Program Files (x86)\Notepad++\plugins\NppExport.dll 2011-09-21 21:46 - 2011-09-21 21:46 - 01673728 _____ () C:\Program Files (x86)\Notepad++\plugins\NppFTP.dll 2014-01-28 17:51 - 2014-01-23 06:56 - 00715544 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\libglesv2.dll 2014-01-28 17:51 - 2014-01-23 06:56 - 00100120 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\libegl.dll 2014-01-28 17:51 - 2014-01-23 06:56 - 04055320 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\pdf.dll 2014-01-28 17:51 - 2014-01-23 06:57 - 00399640 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\ppGoogleNaClPluginChrome.dll 2014-01-28 17:51 - 2014-01-23 06:55 - 01634584 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\ffmpegsumo.dll 2014-01-28 17:51 - 2014-01-23 06:56 - 13615896 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:373E1720 AlternateDataStreams: C:\ProgramData\Temp:D20FFA63 AlternateDataStreams: C:\Users\Dominik\Documents\boot:$WIMMOUNTDATA ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Realtek PCIe GBE Family Controller Description: Realtek PCIe GBE Family Controller Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Realtek Service: RTL8167 Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Microsoft-Adapter für Miniports virtueller WiFis Description: Microsoft-Adapter für Miniports virtueller WiFis Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: vwifimp Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: VMware Virtual Ethernet Adapter for VMnet1 Description: VMware Virtual Ethernet Adapter for VMnet1 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: VMware, Inc. Service: VMnetAdapter Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: VMware Virtual Ethernet Adapter for VMnet8 Description: VMware Virtual Ethernet Adapter for VMnet8 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: VMware, Inc. Service: VMnetAdapter Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (02/04/2014 10:32:21 AM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler . Error: (02/04/2014 10:32:20 AM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler . Error: (01/31/2014 08:07:43 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler . Error: (01/31/2014 08:07:42 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler . Error: (01/28/2014 05:08:20 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler . Error: (01/28/2014 05:08:19 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler . Error: (01/25/2014 04:10:18 PM) (Source: PerfNet) (User: ) Description: Error: (01/23/2014 09:45:40 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler . Error: (01/21/2014 08:44:26 PM) (Source: Application Hang) (User: ) Description: Programm Explorer.EXE, Version 6.1.7601.17567 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 690 Startzeit: 01cf15fee5f09f9c Endzeit: 131 Anwendungspfad: C:\Windows\Explorer.EXE Berichts-ID: 6a8ff278-82d4-11e3-8e41-0008ca3e41e7 Error: (01/21/2014 05:32:34 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler . System errors: ============= Error: (02/03/2014 05:19:02 PM) (Source: Service Control Manager) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "RAS-Verbindungsverwaltung" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (02/03/2014 05:19:02 PM) (Source: Service Control Manager) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows-Verwaltungsinstrumentation" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (02/03/2014 05:19:02 PM) (Source: Service Control Manager) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "IKE- und AuthIP IPsec-Schlüsselerstellungsmodule" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (02/03/2014 05:19:02 PM) (Source: Service Control Manager) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Benutzerprofildienst" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (02/03/2014 05:19:02 PM) (Source: Service Control Manager) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Multimediaklassenplaner" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (02/03/2014 05:18:02 PM) (Source: Service Control Manager) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Server" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (02/03/2014 05:17:02 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows-Verwaltungsinstrumentation" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (02/03/2014 05:17:02 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "TuneUp Designerweiterung" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (02/03/2014 05:17:02 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Designs" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts. Error: (02/03/2014 05:17:02 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Shellhardwareerkennung" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts. Microsoft Office Sessions: ========================= Error: (02/04/2014 10:32:21 AM) (Source: Microsoft-Windows-CAPI2)(User: ) Description: Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler Error: (02/04/2014 10:32:20 AM) (Source: Microsoft-Windows-CAPI2)(User: ) Description: Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler Error: (01/31/2014 08:07:43 PM) (Source: Microsoft-Windows-CAPI2)(User: ) Description: Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler Error: (01/31/2014 08:07:42 PM) (Source: Microsoft-Windows-CAPI2)(User: ) Description: Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler Error: (01/28/2014 05:08:20 PM) (Source: Microsoft-Windows-CAPI2)(User: ) Description: Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler Error: (01/28/2014 05:08:19 PM) (Source: Microsoft-Windows-CAPI2)(User: ) Description: Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler Error: (01/25/2014 04:10:18 PM) (Source: PerfNet)(User: ) Description: Error: (01/23/2014 09:45:40 PM) (Source: Microsoft-Windows-CAPI2)(User: ) Description: Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler Error: (01/21/2014 08:44:26 PM) (Source: Application Hang)(User: ) Description: Explorer.EXE6.1.7601.1756769001cf15fee5f09f9c131C:\Windows\Explorer.EXE6a8ff278-82d4-11e3-8e41-0008ca3e41e7 Error: (01/21/2014 05:32:34 PM) (Source: Microsoft-Windows-CAPI2)(User: ) Description: Details: TraverseDir : Unable to push subdirectory. System Error: Unbekannter Fehler CodeIntegrity Errors: =================================== Date: 2014-02-03 17:14:32.339 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-02-03 17:14:32.089 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-02-02 22:37:44.270 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-02-02 22:37:43.646 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-28 12:31:24.361 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-28 12:31:24.142 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-26 20:28:00.713 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-26 20:28:00.464 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-25 16:15:25.052 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-25 16:15:24.802 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\vrtaucbl.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 49% Total physical RAM: 5608.84 MB Available physical RAM: 2810.9 MB Total Pagefile: 11215.87 MB Available Pagefile: 7892.21 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:300.41 GB) (Free:111.27 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (DATA) (Fixed) (Total:363.45 GB) (Free:345.9 GB) NTFS Drive e: (MMM Test) (CDROM) (Total:0.13 GB) (Free:0 GB) CDFS Drive f: () (Fixed) (Total:147.52 GB) (Free:140.31 GB) NTFS Drive g: (Volume) (Fixed) (Total:150.57 GB) (Free:147.93 GB) NTFS Drive h: (Volume) (Fixed) (Total:9.77 GB) (Free:9.61 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: 125FC5E1) Partition 1: (Not Active) - (Size=25 GB) - (Type=1C) Partition 2: (Active) - (Size=300 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=363 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=10 GB) - (Type=OF Extended) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: C8E0BD52) Partition 1: (Active) - (Size=151 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=148 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Danke in voraus ! |
05.02.2014, 19:46 | #2 |
/// Malwareteam | Windows 7 Verdach auf Virus/MalwareIch habe dein Thema in Arbeit und melde mich so schnell als möglich mit weiteren Anweisungen. Bitte beachte, dass alle meine Antworten zuerst von einem Ausbilder freigegeben werden müssen, bevor ich diese hier posten darf. Dies garantiert, dass Du Hilfe von einem ausgebildeten Helfer bekommst. Ich bedanke mich für deine Geduld
__________________ |
05.02.2014, 23:52 | #3 |
/// Malwareteam | Windows 7 Verdach auf Virus/Malware Hallo Domi22221,
__________________mein Name ist Jonas und ich werde dir bei deiner Bereinigung helfen. Diese kann mit viel Arbeit für dich verbunden sein. Bevor wir anfangen können, lies bitte die Bereinigungsregeln und Hinweise: Regeln zum Ablauf der Bereinigung
Hinweise Wenn du alles gelesen hast, kann es losgehen. Bitte speichere alle Programme auf dem Desktop und führe sie von dort aus.
Schritt 1 Scan mit Combofix
Poste folgende Logfiles in deiner nächsten Antwort:
__________________ |
06.02.2014, 00:12 | #4 |
| Windows 7 Verdach auf Virus/Malware ComboFix installiert und dan kommt nichts :/ |
06.02.2014, 00:47 | #5 | |
/// Malwareteam | Windows 7 Verdach auf Virus/MalwareZitat:
__________________ Gruß, Jonas |
06.02.2014, 18:47 | #6 |
| Windows 7 Verdach auf Virus/Malware Soda hier den log Leider zu groß |
06.02.2014, 18:54 | #7 | |
/// Malwareteam | Windows 7 Verdach auf Virus/MalwareZitat:
__________________ Gruß, Jonas |
06.02.2014, 19:35 | #8 |
| Windows 7 Verdach auf Virus/MalwareCode:
ATTFilter ComboFix 14-02-05.02 - system_ADMIN 06.02.2014 0:33.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.43.1031.18.5609.3727 [GMT 1:00] ausgeführt von:: c:\users\system_ADMIN\Downloads\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B} SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\WebEnhance\weBEnhance.dll c:\users\Dominik\AppData\Local\assembly\tmp c:\users\system_ADMIN\AppData\Local\assembly\tmp c:\windows\SysWow64\MSDCSC c:\windows\SysWow64\MSDCSC\wYMgrs8BJouL\msdcsc.exe D:\install.exe . . ((((((((((((((((((((((( Dateien erstellt von 2014-01-05 bis 2014-02-05 )))))))))))))))))))))))))))))) . . 2014-02-05 23:44 . 2014-02-05 23:44 -------- d-----w- c:\users\Gast\AppData\Local\temp 2014-02-05 23:44 . 2014-02-05 23:44 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-02-05 23:44 . 2014-02-05 23:44 -------- d-----w- c:\users\Administrator\AppData\Local\temp 2014-02-05 23:17 . 2014-02-05 23:17 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3DF275EF-C428-4969-8734-38E6A7D65AAE}\offreg.dll 2014-02-05 17:57 . 2014-02-05 18:01 -------- d-----w- C:\FRST 2014-02-04 09:32 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3DF275EF-C428-4969-8734-38E6A7D65AAE}\mpengine.dll 2014-02-03 16:20 . 2014-02-03 16:20 -------- d-----w- c:\programdata\Overwolf 2014-01-28 11:43 . 2014-01-28 11:48 -------- d-----w- c:\users\system_ADMIN\AppData\Local\Temporary Projects 2014-01-15 18:41 . 2013-11-27 01:41 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys 2014-01-15 18:41 . 2013-11-27 01:41 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2014-01-15 18:41 . 2013-11-27 01:41 53248 ----a-w- c:\windows\system32\drivers\usbehci.sys 2014-01-15 18:41 . 2013-11-27 01:41 325120 ----a-w- c:\windows\system32\drivers\usbport.sys 2014-01-15 18:41 . 2013-11-27 01:41 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys 2014-01-15 18:41 . 2013-11-27 01:41 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys 2014-01-15 18:41 . 2013-11-27 01:41 7808 ----a-w- c:\windows\system32\drivers\usbd.sys 2014-01-15 18:41 . 2013-11-26 10:32 3156480 ----a-w- c:\windows\system32\win32k.sys 2014-01-15 18:41 . 2013-11-26 11:40 376768 ----a-w- c:\windows\system32\drivers\netio.sys 2014-01-08 16:07 . 2014-02-05 08:32 -------- d-----w- c:\users\system_ADMIN\AppData\Roaming\.technic 2014-01-08 15:06 . 2014-01-08 16:07 -------- d-----w- c:\users\system_ADMIN\Ekahau Site Survey 2014-01-08 15:04 . 2014-01-08 15:04 -------- d-----w- c:\program files\Ekahau . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-02-05 21:37 . 2012-04-02 14:47 45056 ----a-w- c:\windows\SysWow64\acovcnt.exe 2014-01-23 20:47 . 2013-12-22 12:19 80184 ----a-w- c:\windows\system32\drivers\aswstm.sys 2014-01-23 20:47 . 2013-10-05 15:56 421704 ----a-w- c:\windows\system32\drivers\aswSP.sys 2014-01-23 20:47 . 2013-10-05 15:56 1038072 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2014-01-23 20:47 . 2013-10-05 15:56 78648 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2014-01-23 20:47 . 2013-10-05 15:56 334136 ----a-w- c:\windows\system32\aswBoot.exe 2014-01-23 20:47 . 2013-10-05 15:56 43152 ----a-w- c:\windows\avastSS.scr 2013-12-31 00:10 . 2013-12-31 00:10 67584 ----a-w- c:\windows\system32\drivers\vrtaucbl.sys 2013-12-24 21:08 . 2012-05-31 11:18 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-12-24 21:08 . 2012-05-31 11:18 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-12-22 12:18 . 2013-10-05 15:56 207904 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2013-12-18 05:13 . 2012-04-06 11:13 270496 ------w- c:\windows\system32\MpSigStub.exe 2013-12-02 02:03 . 2013-12-02 02:03 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-12-02 02:03 . 2013-12-02 02:03 194048 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-12-02 02:03 . 2013-12-02 02:03 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2013-12-02 02:03 . 2013-12-02 02:03 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll 2013-12-02 02:03 . 2013-12-02 02:03 235008 ----a-w- c:\windows\system32\elshyph.dll 2013-12-02 02:03 . 2013-12-02 02:03 182272 ----a-w- c:\windows\SysWow64\msls31.dll 2013-12-02 02:03 . 2013-12-02 02:03 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll 2013-12-02 02:03 . 2013-12-02 02:03 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-12-02 02:03 . 2013-12-02 02:03 62464 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-12-02 02:03 . 2013-12-02 02:03 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2013-12-02 02:03 . 2013-12-02 02:03 61952 ----a-w- c:\windows\SysWow64\iesetup.dll 2013-12-02 02:03 . 2013-12-02 02:03 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2013-12-02 02:03 . 2013-12-02 02:03 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-12-02 02:03 . 2013-12-02 02:03 454656 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-12-02 02:03 . 2013-12-02 02:03 36352 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-12-02 02:03 . 2013-12-02 02:03 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2013-12-02 02:03 . 2013-12-02 02:03 337408 ----a-w- c:\windows\SysWow64\html.iec 2013-12-02 02:03 . 2013-12-02 02:03 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-12-02 02:03 . 2013-12-02 02:03 151552 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-12-02 02:03 . 2013-12-02 02:03 139264 ----a-w- c:\windows\SysWow64\wextract.exe 2013-12-02 02:03 . 2013-12-02 02:03 13312 ----a-w- c:\windows\SysWow64\mshta.exe 2013-12-02 02:03 . 2013-12-02 02:03 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-12-02 02:03 . 2013-12-02 02:03 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-12-02 02:03 . 2013-12-02 02:03 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-12-02 02:03 . 2013-12-02 02:03 942592 ----a-w- c:\windows\system32\jsIntl.dll 2013-12-02 02:03 . 2013-12-02 02:03 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-12-02 02:03 . 2013-12-02 02:03 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2013-12-02 02:03 . 2013-12-02 02:03 84992 ----a-w- c:\windows\system32\mshtmled.dll 2013-12-02 02:03 . 2013-12-02 02:03 83968 ----a-w- c:\windows\system32\MshtmlDac.dll 2013-12-02 02:03 . 2013-12-02 02:03 81408 ----a-w- c:\windows\system32\icardie.dll 2013-12-02 02:03 . 2013-12-02 02:03 774144 ----a-w- c:\windows\system32\jscript.dll 2013-12-02 02:03 . 2013-12-02 02:03 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-12-02 02:03 . 2013-12-02 02:03 626176 ----a-w- c:\windows\system32\msfeeds.dll 2013-12-02 02:03 . 2013-12-02 02:03 62464 ----a-w- c:\windows\system32\pngfilt.dll 2013-12-02 02:03 . 2013-12-02 02:03 616104 ----a-w- c:\windows\system32\ieapfltr.dat 2013-12-02 02:03 . 2013-12-02 02:03 548352 ----a-w- c:\windows\system32\vbscript.dll 2013-12-02 02:03 . 2013-12-02 02:03 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-12-02 02:03 . 2013-12-02 02:03 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-12-02 02:03 . 2013-12-02 02:03 48128 ----a-w- c:\windows\system32\imgutil.dll 2013-12-02 02:03 . 2013-12-02 02:03 453120 ----a-w- c:\windows\system32\dxtmsft.dll 2013-12-02 02:03 . 2013-12-02 02:03 413696 ----a-w- c:\windows\system32\html.iec 2013-12-02 02:03 . 2013-12-02 02:03 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2013-12-02 02:03 . 2013-12-02 02:03 30208 ----a-w- c:\windows\system32\licmgr10.dll 2013-12-02 02:03 . 2013-12-02 02:03 296960 ----a-w- c:\windows\system32\dxtrans.dll 2013-12-02 02:03 . 2013-12-02 02:03 263376 ----a-w- c:\windows\system32\iedkcs32.dll 2013-12-02 02:03 . 2013-12-02 02:03 247808 ----a-w- c:\windows\system32\msls31.dll 2013-12-02 02:03 . 2013-12-02 02:03 243200 ----a-w- c:\windows\system32\webcheck.dll 2013-12-02 02:03 . 2013-12-02 02:03 235520 ----a-w- c:\windows\system32\url.dll 2013-12-02 02:03 . 2013-12-02 02:03 195584 ----a-w- c:\windows\system32\msrating.dll 2013-12-02 02:03 . 2013-12-02 02:03 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-12-02 02:03 . 2013-12-02 02:03 147968 ----a-w- c:\windows\system32\occache.dll 2013-12-02 02:03 . 2013-12-02 02:03 143872 ----a-w- c:\windows\system32\wextract.exe 2013-12-02 02:03 . 2013-12-02 02:03 13824 ----a-w- c:\windows\system32\mshta.exe 2013-12-02 02:03 . 2013-12-02 02:03 135680 ----a-w- c:\windows\system32\iepeers.dll 2013-12-02 02:03 . 2013-12-02 02:03 13312 ----a-w- c:\windows\system32\msfeedssync.exe 2013-12-02 02:03 . 2013-12-02 02:03 131072 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-12-02 02:03 . 2013-12-02 02:03 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-12-02 02:03 . 2013-12-02 02:03 105984 ----a-w- c:\windows\system32\iesysprep.dll 2013-12-02 02:03 . 2013-12-02 02:03 101376 ----a-w- c:\windows\system32\inseng.dll 2013-11-26 11:54 . 2013-12-12 16:46 23183360 ----a-w- c:\windows\system32\mshtml.dll 2013-11-26 10:19 . 2013-12-12 16:46 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2013-11-26 10:18 . 2013-12-12 16:46 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2013-11-26 09:48 . 2013-12-12 16:46 66048 ----a-w- c:\windows\system32\iesetup.dll 2013-11-26 09:46 . 2013-12-12 16:46 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll 2013-11-26 09:41 . 2013-12-12 16:46 2764288 ----a-w- c:\windows\system32\iertutil.dll 2013-11-26 09:29 . 2013-12-12 16:46 53760 ----a-w- c:\windows\system32\jsproxy.dll 2013-11-26 09:27 . 2013-12-12 16:46 33792 ----a-w- c:\windows\system32\iernonce.dll 2013-11-26 09:23 . 2013-12-12 16:46 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb 2013-11-26 09:21 . 2013-12-12 16:46 574976 ----a-w- c:\windows\system32\ieui.dll 2013-11-26 09:18 . 2013-12-12 16:46 139264 ----a-w- c:\windows\system32\ieUnatt.exe 2013-11-26 09:18 . 2013-12-12 16:46 111616 ----a-w- c:\windows\system32\ieetwcollector.exe 2013-11-26 09:16 . 2013-12-12 16:46 708608 ----a-w- c:\windows\system32\jscript9diag.dll 2013-11-26 08:57 . 2013-12-12 16:46 218624 ----a-w- c:\windows\system32\ie4uinit.exe 2013-11-26 08:35 . 2013-12-12 16:46 5769216 ----a-w- c:\windows\system32\jscript9.dll 2013-11-26 08:28 . 2013-12-12 16:46 553472 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2013-11-26 08:16 . 2013-12-12 16:46 4243968 ----a-w- c:\windows\SysWow64\jscript9.dll 2013-11-26 08:02 . 2013-12-12 16:46 1995264 ----a-w- c:\windows\system32\inetcpl.cpl 2013-11-26 07:48 . 2013-12-12 16:46 12996608 ----a-w- c:\windows\system32\ieframe.dll 2013-11-26 07:32 . 2013-12-12 16:46 1928192 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2013-11-26 07:07 . 2013-12-12 16:46 2334208 ----a-w- c:\windows\system32\wininet.dll 2013-11-26 06:40 . 2013-12-12 16:46 1395200 ----a-w- c:\windows\system32\urlmon.dll 2013-11-26 06:34 . 2013-12-12 16:46 817664 ----a-w- c:\windows\system32\ieapfltr.dll 2013-11-26 06:33 . 2013-12-12 16:46 1820160 ----a-w- c:\windows\SysWow64\wininet.dll 2013-11-23 18:26 . 2013-12-11 17:39 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2013-11-23 17:47 . 2013-12-11 17:39 465920 ----a-w- c:\windows\system32\WMPhoto.dll 2013-11-13 16:06 . 2013-10-05 15:56 92544 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2013-11-13 16:06 . 2013-10-05 15:56 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-11-12 02:23 . 2013-12-11 17:36 2048 ----a-w- c:\windows\system32\tzres.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2011-09-13 2317312] "SonicMasterTray"="c:\program files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe" [2010-07-10 984400] "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-01-23 3767096] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "EnableSecureUIAPath"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" "Nuance PDF Reader-reminder"="c:\program files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "c:\programdata\Nuance\PDF Reader\Ereg\Ereg.ini" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x] R3 athur;Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x] R3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;c:\windows\system32\drivers\BVRPMPR5a64.SYS;c:\windows\SYSNATIVE\drivers\BVRPMPR5a64.SYS [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 EsgScanner;EsgScanner;c:\windows\system32\DRIVERS\EsgScanner.sys;c:\windows\SYSNATIVE\DRIVERS\EsgScanner.sys [x] R3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys;c:\windows\SYSNATIVE\DRIVERS\vrtaucbl.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] R3 OverwolfUpdaterService;Overwolf Updater Service;c:\program files (x86)\Overwolf\OverwolfUpdater.exe;c:\program files (x86)\Overwolf\OverwolfUpdater.exe [x] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 usbrndis6;USB-RNDIS6-Adapter;c:\windows\system32\DRIVERS\usb80236.sys;c:\windows\SYSNATIVE\DRIVERS\usb80236.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x] R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] R4 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x] R4 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x] R4 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [x] R4 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x] R4 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x] R4 MSSQLServerADHelper100;SQL Server Hilfsdienst für Active Directory;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [x] R4 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x] R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys;c:\windows\SYSNATIVE\DRIVERS\RsFx0103.sys [x] R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R4 SQLAgent$SQLEXPRESS;SQL Server-Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE;c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [x] R4 SXDS10;soft Xpansion Dispatch Service;c:\program files (x86)\Common Files\soft Xpansion\sxds10.exe \Service;c:\program files (x86)\Common Files\soft Xpansion\sxds10.exe \Service [x] R4 vToolbarUpdater15.5.0;vToolbarUpdater15.5.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] R4 ZAtheros Bt&Wlan Coex Agent;ZAtheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x] S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x] S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x] S0 aswRvrt;avast! Revert; [x] S0 aswVmm;avast! VM Monitor; [x] S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys;c:\windows\SYSNATIVE\DRIVERS\vmci.sys [x] S0 vsock;vSockets Driver;c:\windows\system32\drivers\vsock.sys;c:\windows\SYSNATIVE\drivers\vsock.sys [x] S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x] S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x] S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x] S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys;c:\windows\SYSNATIVE\drivers\avgtpx64.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S1 dvdfabio;dvdfabio;c:\windows\system32\drivers\dvdfabio.sys;c:\windows\SYSNATIVE\drivers\dvdfabio.sys [x] S1 JSWPSLWF;JumpStart Wireless Filter Driver;c:\windows\system32\DRIVERS\jswpslwfx.sys;c:\windows\SYSNATIVE\DRIVERS\jswpslwfx.sys [x] S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x] S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [x] S3 AiCharger;ASUS Charger Driver;c:\windows\system32\DRIVERS\AiCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AiCharger.sys [x] S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys;c:\windows\SYSNATIVE\DRIVERS\amdhub30.sys [x] S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x] S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys;c:\windows\SYSNATIVE\DRIVERS\amdxhc.sys [x] S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x] S3 btath_avdt;Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys;c:\windows\SYSNATIVE\drivers\btath_avdt.sys [x] S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x] S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x] S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x] S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x] S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x] S3 vdrive;vdrive;c:\windows\system32\DRIVERS\vdrive.sys;c:\windows\SYSNATIVE\DRIVERS\vdrive.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *Deregistered* - PROCEXP152 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\AutorunsDisabled\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-02-04 19:44 1211720 ----a-w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.107\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-02-05 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-31 21:08] . 2014-02-03 c:\windows\Tasks\ASUS SmartLogon Console Sensor.job - c:\program files (x86)\ASUS\FaceLogon\sensorsrv.exe [2011-10-03 19:45] . 2014-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-20 21:30] . 2014-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-20 21:30] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2014-01-23 20:47 287280 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B] @="{6D4133E5-0742-4ADC-8A8C-9303440F7190}" [HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}] 2011-05-25 07:09 227840 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O] @="{64174815-8D98-4CE6-8646-4C039977D808}" [HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}] 2011-05-25 07:09 227840 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-10-14 2278504] "AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-10-01 981664] "AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-10-01 799904] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.aon.at mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: An OneNote s&enden - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 LSP: %windir%\system32\vsocklib.dll Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com TCP: DhcpNameServer = 10.0.0.138 FF - ProfilePath - c:\users\system_ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\bp9g4ldi.default\ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . BHO-{814664b0-d93b-4da6-9216-722c56179397} - c:\program files (x86)\WebEnhance\webenhance.dll Toolbar-Locked - (no file) Toolbar-Locked - (no file) AddRemove-ASUS_Screensaver - c:\windows\system32\ASUS_Screensaver.scr AddRemove-Uplay - c:\program files (x86)\Ubisoft\Ubisoft Game Launcher\Uninstall.exe AddRemove-xampp - J:\uninstall.exe AddRemove-{1ED31028-6D65-4CFD-AD03-8E484A052FE7} - c:\programdata\{E8A874E7-129E-4647-B8C1-46227F252D4F}\Setup.exe AddRemove-{6B7FB3C4-E71B-478D-9E15-5AE97EAD67B8} - c:\programdata\{E16513F0-65F3-4AB4-86DD-35C7C409A265}\Setup.exe AddRemove-{7E4FBD52-148F-49EE-AFCC-96FB498F4D7D} - c:\programdata\{7DC6FEB5-CDCF-4348-BDA7-46EEE9021D96}\Setup.exe AddRemove-{904B64C4-49D8-4941-A2B6-D13D06C5CD8B} - c:\programdata\{D6B1976C-D59B-4881-8378-7F29FE0A2822}\Setup.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.0_03" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.0_04" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.0_05" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_01" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_01" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_02" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_02" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_03" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_03" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_04" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_04" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_05" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_05" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_06" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_06" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_07" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_07" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_08" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_08" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_09" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_09" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_10" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_10" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_11" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_11" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_12" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_12" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_13" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_13" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_14" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_14" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_15" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_15" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_16" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_16" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_17" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_17" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_18" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_18" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_19" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_19" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_20" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_20" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.3.1_21" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.3.1_21" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_01" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_01" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_02" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_02" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_03" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_03" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.0_04" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.0_04" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_01" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_01" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_02" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_02" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_03" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_03" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_04" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_04" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_05" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_05" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_06" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_06" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.1_07" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.1_07" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_01" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_01" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_02" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_02" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_03" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_03" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_04" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_04" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_05" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_05" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_06" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_06" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_07" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_07" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_08" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_08" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_09" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_09" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_10" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_10" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_11" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_11" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_12" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_12" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_13" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_13" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_14" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_14" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_15" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_15" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_16" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_16" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_17" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_17" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_18" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_18" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_19" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_19" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_20" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_20" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_21" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_21" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_22" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_22" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_23" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_23" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_24" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_24" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_25" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_25" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_26" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_26" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_27" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_27" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_28" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_28" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_29" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_29" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_30" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_30" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_31" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_31" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_32" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_32" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_33" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_33" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_34" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_34" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_35" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_35" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_36" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_36" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_37" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_37" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_38" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_38" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_39" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_39" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_40" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_40" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0041-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_41" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0041-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_41" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0042-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_42" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0042-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_42" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0043-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2_43" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-0043-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.4.2_43" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.4.2" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_01" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_01" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_01" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_02" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_02" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_02" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_03" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_03" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_03" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_04" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_04" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_04" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_05" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_05" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_05" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_06" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_06" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_06" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_07" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_07" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_07" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_08" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_08" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_08" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_09" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_09" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_09" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_10" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_10" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_10" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_11" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_11" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_11" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_12" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_12" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_12" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_13" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_13" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_13" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_14" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_14" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_14" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_15" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_15" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_15" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_16" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_16" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_16" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_17" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_17" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_17" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_18" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_18" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_18" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_19" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_19" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_19" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_20" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_20" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_20" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_21" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_21" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_21" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_22" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_22" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_22" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_23" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_23" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_23" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_24" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_24" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_24" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_25" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_25" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_25" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_26" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_26" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_26" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_27" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_27" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_27" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_28" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_28" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_28" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_29" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_29" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_29" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_30" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_30" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_30" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_31" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_31" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0031-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_31" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_32" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_32" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0032-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_32" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_33" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_33" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0033-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_33" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_34" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_34" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0034-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_34" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_35" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_35" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0035-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_35" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_36" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_36" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0036-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_36" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_37" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_37" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0037-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_37" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_38" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_38" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0038-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_38" . |
06.02.2014, 19:36 | #9 |
| Windows 7 Verdach auf Virus/MalwareCode:
ATTFilter [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_39" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_39" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0039-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_39" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_40" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_40" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0040-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_40" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0041-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_41" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0041-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_41" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0041-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_41" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0042-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_42" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0042-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_42" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0042-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_42" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0043-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_43" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0043-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_43" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0043-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_43" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0044-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_44" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0044-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_44" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0044-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_44" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0045-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_45" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0045-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_45" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0045-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_45" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0046-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_46" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0046-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_46" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0046-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_46" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0047-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_47" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0047-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_47" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0047-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_47" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0048-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_48" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0048-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_48" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0048-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_48" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0049-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_49" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0049-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_49" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0049-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_49" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0050-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_50" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0050-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_50" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0050-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_50" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0051-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0_51" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0051-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.5.0_51" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-0051-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.5.0_51" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.5.0" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_01" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_01" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_01" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_02" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_02" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_02" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_03" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_03" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_03" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_04" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_04" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_04" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_05" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_05" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_05" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_06" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_06" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_06" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_07" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_07" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_07" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_08" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_08" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_08" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_09" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_09" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_09" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_10" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_10" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_10" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_11" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_11" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_11" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_12" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_12" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_12" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_13" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_13" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_13" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_14" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_14" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_14" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_15" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_15" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_15" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_16" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_16" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_16" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_17" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_17" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_17" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_18" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_18" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_18" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_19" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_19" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_19" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_20" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_20" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_20" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_21" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_21" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_21" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_22" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_22" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_22" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_23" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_23" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_23" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_24" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_24" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_24" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_25" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_25" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_25" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_26" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_26" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_26" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_27" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_27" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_27" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_28" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_28" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0028-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_28" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_29" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_29" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_29" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_30" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_30" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_30" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_31" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_31" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_31" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_32" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_32" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_32" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_33" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_33" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_33" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_34" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_34" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_34" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_35" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_35" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_35" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_36" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_36" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0036-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_36" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_37" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_37" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_37" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_38" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_38" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_38" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_39" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_39" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_39" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_40" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_40" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0040-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_40" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0041-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_41" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0041-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_41" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0041-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_41" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0042-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_42" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0042-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_42" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0042-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_42" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_43" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_43" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_43" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0044-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_44" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0044-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_44" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0044-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_44" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_45" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_45" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_45" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0046-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_46" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0046-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_46" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0046-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_46" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0047-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_47" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0047-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_47" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0047-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_47" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0048-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_48" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0048-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_48" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0048-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_48" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0049-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_49" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0049-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_49" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0049-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_49" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0050-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_50" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0050-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_50" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0050-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_50" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0051-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0_51" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0051-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.6.0_51" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-0051-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.6.0_51" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0016-0000-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.6.0" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_01" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_01" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_01" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_02" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0002-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_02" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0002-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_02" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_03" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0003-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_03" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0003-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_03" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0004-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_04" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0004-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_04" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0004-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_04" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_05" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0005-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_05" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0005-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_05" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0006-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_06" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0006-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_06" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0006-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_06" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_07" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0007-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_07" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0007-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_07" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0008-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_08" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0008-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_08" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0008-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_08" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_09" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0009-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_09" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0009-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_09" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0010-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_10" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0010-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_10" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0010-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_10" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0011-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_11" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0011-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_11" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0011-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_11" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0012-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_12" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0012-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_12" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0012-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_12" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_13" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_13" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_13" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0014-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_14" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0014-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_14" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0014-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_14" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0015-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_15" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0015-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_15" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0015-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_15" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0016-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_16" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0016-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_16" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0016-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_16" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_17" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0017-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_17" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0017-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_17" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0018-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_18" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0018-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_18" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0018-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_18" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0019-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_19" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0019-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_19" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0019-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_19" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0020-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_20" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0020-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_20" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0020-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_20" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_21" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0021-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_21" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0021-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_21" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0022-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_22" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0022-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_22" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0022-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_22" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0023-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_23" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0023-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_23" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0023-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_23" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0024-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_24" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0024-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_24" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0024-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_24" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_25" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_25" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_25" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0026-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_26" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0026-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_26" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0026-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_26" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0027-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_27" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0027-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_27" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0027-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_27" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0028-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_28" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0028-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_28" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0028-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_28" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0029-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_29" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0029-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_29" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0029-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_29" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0030-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_30" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0030-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_30" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0030-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_30" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0031-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_31" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0031-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_31" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0031-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_31" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0032-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_32" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0032-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_32" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0032-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_32" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0033-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_33" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0033-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_33" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0033-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_33" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0034-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_34" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0034-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_34" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0034-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_34" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0035-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_35" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0035-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_35" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0035-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_35" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0036-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_36" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0036-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_36" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0036-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_36" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0037-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_37" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0037-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_37" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0037-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_37" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0038-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_38" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0038-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_38" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0038-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_38" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0039-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_39" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0039-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_39" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0039-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_39" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0040-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0_40" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0040-ABCDEFFEDCBB}] @DACL=(02 0000) @="Java Plug-in 1.7.0_40" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-0040-ABCDEFFEDCBC}] @DACL=(02 0000) @="Java Plug-in 1.7.0_40" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA}] @DACL=(02 0000) @="Java Plug-in 1.7.0" . [HKEY_USERS\S-1-5-21-1604131726-2387010455-2909821853-1016_Classes\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}] @DACL=(02 0000) @="Java Plug-in 1.3.0_02" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-02-06 00:48:19 ComboFix-quarantined-files.txt 2014-02-05 23:48 . Vor Suchlauf: 20 Verzeichnis(se), 134.289.321.984 Bytes frei Nach Suchlauf: 27 Verzeichnis(se), 134.880.366.592 Bytes frei . - - End Of File - - C06DE64B0936212203BA25D17B13C62A A36C5E4F47E84449FF07ED3517B43A31 |
06.02.2014, 22:43 | #10 |
/// Malwareteam | Windows 7 Verdach auf Virus/Malware Schritt 1 Starte noch einmal FRST.
Poste folgende Logfiles in deiner nächsten Antwort:
__________________ Gruß, Jonas |
06.02.2014, 23:40 | #11 |
| Windows 7 Verdach auf Virus/MalwareFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-02-2014 Ran by system_ADMIN (administrator) on DOMINIK-PC on 06-02-2014 23:38:46 Running from C:\Users\system_ADMIN\Desktop\Neuer Ordner (8) Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe (ASUS) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Microsoft Corporation) C:\Windows\System32\alg.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (VMware, Inc.) F:\vmware\vmware-authd.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Windows\System32\prevhost.exe (Microsoft Corporation) C:\Windows\System32\calc.exe () C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe () C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.199\deploy\LoLLauncher.exe () C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.69\deploy\LolClient.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2278504 2011-10-14] (Realtek Semiconductor) HKLM\...\Run: [AtherosBtStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [981664 2011-10-01] (Atheros Communications) HKLM\...\Run: [AthBtTray] - C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [799904 2011-10-01] (Atheros Commnucations) HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2317312 2011-09-13] (ASUS) HKLM-x32\...\Run: [SonicMasterTray] - C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-01-23] (AVAST Software) Startup: C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled () Startup: C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk ShortcutTarget: Facebook Messenger.lnk -> C:\Users\Dominik\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe (Facebook) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.aon.at StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {55AFFF2A-7AB3-5413-8C22-511A1448E47F} URL = SearchScopes: HKCU - {55AFFF2A-7AB3-5413-8C22-511A1448E47F} URL = BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: avast! Ad Blocker - {FFCB3198-32F3-4E8B-9539-4324694ED663} - C:\Program Files (x86)\AVAST Software\avast! Ad Blocker IE\Adblocker64.dll (AVAST Software) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft Web Test Recorder 10.0 Helper - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation) BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: avast! Ad Blocker - {FFCB3198-32F3-4E8B-9539-4324694ED663} - C:\Program Files (x86)\AVAST Software\avast! Ad Blocker IE\Adblocker32.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 10.0.0.138 FireFox: ======== FF ProfilePath: C:\Users\system_ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\bp9g4ldi.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @Nero.com/KM - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: ZEON/PDF,version=2.0 - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation) FF Plugin HKCU: @eximion.com/KalydoPlayer - C:\Users\system_ADMIN\AppData\Roaming\Kalydo\KalydoPlayer\bin2\npkalydo.dll (Eximion B.V.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Surrf and keaep - C:\Users\system_ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\bp9g4ldi.default\Extensions\lj7arl@qvsfyuoi-.net [2013-12-02] FF Extension: NoScript - C:\Users\system_ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\bp9g4ldi.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-10-05] FF Extension: Adblock Plus - C:\Users\system_ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\bp9g4ldi.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-10-05] FF Extension: avast! Ad Blocker - C:\Program Files (x86)\Mozilla Firefox\extensions\adblocker@avast.com.xpi [2013-11-18] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-05] FF HKLM-x32\...\Firefox\Extensions: [{38e9e285-5266-4fe2-b5b5-c14c29b0cd45}] - C:\Program Files (x86)\WebEnhance\webenhance.xpi FF Extension: No Name - C:\Program Files (x86)\WebEnhance\webenhance.xpi [2013-08-27] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR Extension: (Google Docs) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-01] CHR Extension: (Google Drive) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-01] CHR Extension: (YouTube) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-01] CHR Extension: (Google-Suche) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-01] CHR Extension: (avast! Ad Blocker) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\fplhdcjmbpfkejbhngmlngaecbjmoimd [2013-12-01] CHR Extension: (avast! Online Security) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-12-01] CHR Extension: (Google Wallet) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-01] CHR Extension: (Google Mail) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-01] CHR HKCU\...\Chrome\Extension: [kdfbddbdpnahdahmamlolacimfdbeckk] - C:\Users\system_ADMIN\AppData\Local\CRE\kdfbddbdpnahdahmamlolacimfdbeckk.crx [2013-07-17] CHR HKLM-x32\...\Chrome\Extension: [ejnmnhkgiphcaeefbaooconkceehicfi] - C:\Program Files (x86)\DealPly\DealPly.crx [2013-07-17] CHR HKLM-x32\...\Chrome\Extension: [fplhdcjmbpfkejbhngmlngaecbjmoimd] - C:\Program Files\AVAST Software\Avast\AdBlocker\Chrome\avast-adblocker-chrome.crx [2013-10-05] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2013-11-13] CHR HKLM-x32\...\Chrome\Extension: [kdfbddbdpnahdahmamlolacimfdbeckk] - C:\Users\system_ADMIN\AppData\Local\CRE\kdfbddbdpnahdahmamlolacimfdbeckk.crx [2013-07-17] CHR HKLM-x32\...\Chrome\Extension: [mbegnhpbhfjiaelealfpieodkembdgbj] - C:\Program Files (x86)\WebEnhance\webenhance.crx [2013-08-27] CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= S4 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2011-11-02] (Advanced Micro Devices, Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-23] (AVAST Software) S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) R2 HPSLPSVC; C:\Users\Dominik\AppData\Local\Temp\7zS1DE4\hpslpsvc64.dll [1039360 2011-11-14] (Hewlett-Packard Co.) S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S4 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation) S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [96184 2013-12-09] (Overwolf) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2012-06-24] () R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [186056 2013-10-16] (Sandboxie Holdings, LLC) S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation) S4 SXDS10; C:\Program Files (x86)\Common Files\soft Xpansion\sxds10.exe [234096 2013-10-13] (soft Xpansion) S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) R2 VMAuthdService; F:\vmware\vmware-authd.exe [86096 2013-10-18] (VMware, Inc.) S4 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [158880 2011-10-01] (Atheros) S4 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [X] S4 vToolbarUpdater15.5.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [X] ==================== Drivers (Whitelisted) ==================== R3 AiCharger; C:\Windows\SysWOW64\DRIVERS\AiCharger.sys [17152 2011-10-15] (ASUSTek Computer Inc.) R1 Amfilter; C:\Windows\System32\DRIVERS\Amfltx64.sys [12288 2007-10-15] ((Standard mouse types)) R3 Amusbprt; C:\Windows\System32\DRIVERS\Amusbx64.sys [17920 2008-02-13] (A4Tech Co.,Ltd.) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-01-23] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-11-13] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-13] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-01-23] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-01-23] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-01-23] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-22] () R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [45856 2013-08-16] (AVG Technologies) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-11-01] (DT Soft Ltd) R1 dvdfabio; C:\Windows\system32\drivers\dvdfabio.sys [12776 2012-11-13] (Fengtao Software Inc.) S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2012-06-22] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [200552 2013-10-16] (Sandboxie Holdings, LLC) S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2013-02-12] (Microsoft Corporation) R3 vdrive; C:\Windows\System32\DRIVERS\vdrive.sys [45544 2012-11-13] (Fengtao Software Inc.) R0 vsock; C:\Windows\System32\drivers\vsock.sys [73296 2013-10-08] (VMware, Inc.) S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-26] (Microsoft Corporation) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) U4 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-06 19:38 - 2014-02-06 19:38 - 00005936 _____ () C:\Users\system_ADMIN\Downloads\Mini012214-02.zip 2014-02-06 00:48 - 2014-02-06 00:48 - 00131089 _____ () C:\ComboFix.txt 2014-02-06 00:24 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-02-06 00:24 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-02-06 00:24 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-02-06 00:24 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-02-06 00:24 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-02-06 00:24 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-02-06 00:24 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-02-06 00:24 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-02-06 00:15 - 2014-02-06 00:16 - 05180173 _____ (Swearware) C:\Users\system_ADMIN\Downloads\ComboFix (1).exe 2014-02-06 00:10 - 2014-02-06 00:16 - 00001209 _____ () C:\Users\system_ADMIN\Desktop\ComboFix - Verknüpfung.lnk 2014-02-06 00:08 - 2014-02-06 00:48 - 00000000 ____D () C:\Qoobox 2014-02-06 00:07 - 2014-02-06 00:46 - 00000000 ____D () C:\Windows\erdnt 2014-02-06 00:04 - 2014-02-06 00:06 - 05180173 ____R (Swearware) C:\Users\system_ADMIN\Downloads\ComboFix.exe 2014-02-05 22:20 - 2014-02-05 22:20 - 00448512 _____ (OldTimer Tools) C:\Users\system_ADMIN\Downloads\TFC.exe 2014-02-05 21:55 - 2014-02-05 21:55 - 00550371 _____ () C:\Users\system_ADMIN\Desktop\Autoruns.zip 2014-02-05 21:55 - 2013-07-31 13:08 - 00661184 _____ (Sysinternals - www.sysinternals.com) C:\Users\system_ADMIN\Desktop\autoruns.exe 2014-02-05 18:57 - 2014-02-06 23:38 - 00000000 ____D () C:\FRST 2014-02-05 18:43 - 2014-02-05 18:43 - 00000000 _____ () C:\Users\system_ADMIN\defogger_reenable 2014-02-05 18:42 - 2014-02-06 23:38 - 00000000 ____D () C:\Users\system_ADMIN\Desktop\Neuer Ordner (8) 2014-02-03 17:20 - 2014-02-03 17:20 - 00000000 ____D () C:\ProgramData\Overwolf 2014-02-03 17:17 - 2014-02-03 17:17 - 00000272 _____ () C:\Windows\Tasks\ASUS SmartLogon Console Sensor.job 2014-02-03 10:13 - 2014-02-03 10:13 - 00000849 _____ () C:\Users\system_ADMIN\AppData\Local\recently-used.xbel 2014-01-28 17:08 - 2014-01-28 17:08 - 00000000 ____D () C:\Users\system_ADMIN\Desktop\Neuer Ordner (7) 2014-01-28 12:43 - 2014-01-28 12:48 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Local\Temporary Projects 2014-01-26 20:28 - 2014-01-26 20:29 - 00275224 _____ () C:\Windows\Minidump\012614-97438-01.dmp 2014-01-19 18:56 - 2014-02-04 12:21 - 00003117 _____ () C:\Users\system_ADMIN\AppData\Roaming\PData.MMM 2014-01-19 18:56 - 2014-02-04 12:21 - 00003117 _____ () C:\Users\system_ADMIN\AppData\Roaming\PData.MM1 2014-01-18 13:03 - 2013-02-11 08:06 - 00001114 _____ () C:\Users\system_ADMIN\Desktop\redprobe 2014-01-15 19:41 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 19:41 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 19:41 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 19:41 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 19:41 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 19:41 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 19:41 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 19:41 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-15 19:41 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-09 23:08 - 2014-01-09 23:08 - 01349598 _____ () C:\Users\system_ADMIN\Documents\Logs-2014-01-09T23-06-47.gz 2014-01-09 15:56 - 2014-01-09 15:57 - 00275112 _____ () C:\Windows\Minidump\010914-37253-01.dmp 2014-01-08 17:07 - 2014-02-05 09:32 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\.technic 2014-01-08 16:06 - 2014-01-08 17:07 - 00000000 ____D () C:\Users\system_ADMIN\Ekahau Site Survey 2014-01-08 16:04 - 2014-01-08 16:04 - 00000000 ____D () C:\Program Files\Ekahau ==================== One Month Modified Files and Folders ======= 2014-02-06 23:38 - 2014-02-05 18:57 - 00000000 ____D () C:\FRST 2014-02-06 23:38 - 2014-02-05 18:42 - 00000000 ____D () C:\Users\system_ADMIN\Desktop\Neuer Ordner (8) 2014-02-06 23:38 - 2012-05-31 12:18 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-06 22:43 - 2013-01-20 22:30 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-06 20:51 - 2013-05-20 02:39 - 00000000 ____D () C:\Users\system_ADMIN\Documents\Bluetooth Folder 2014-02-06 19:42 - 2012-02-05 01:17 - 01897629 _____ () C:\Windows\WindowsUpdate.log 2014-02-06 19:39 - 2013-08-23 06:17 - 00000000 ____D () C:\Users\system_ADMIN\Documents\Visual Studio 2012 2014-02-06 19:38 - 2014-02-06 19:38 - 00005936 _____ () C:\Users\system_ADMIN\Downloads\Mini012214-02.zip 2014-02-06 18:53 - 2013-01-20 22:30 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-06 00:48 - 2014-02-06 00:48 - 00131089 _____ () C:\ComboFix.txt 2014-02-06 00:48 - 2014-02-06 00:08 - 00000000 ____D () C:\Qoobox 2014-02-06 00:48 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default 2014-02-06 00:46 - 2014-02-06 00:07 - 00000000 ____D () C:\Windows\erdnt 2014-02-06 00:44 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2014-02-06 00:43 - 2013-10-13 13:05 - 00000000 ____D () C:\Program Files (x86)\WebEnhance 2014-02-06 00:16 - 2014-02-06 00:15 - 05180173 _____ (Swearware) C:\Users\system_ADMIN\Downloads\ComboFix (1).exe 2014-02-06 00:16 - 2014-02-06 00:10 - 00001209 _____ () C:\Users\system_ADMIN\Desktop\ComboFix - Verknüpfung.lnk 2014-02-06 00:06 - 2014-02-06 00:04 - 05180173 ____R (Swearware) C:\Users\system_ADMIN\Downloads\ComboFix.exe 2014-02-05 22:44 - 2009-07-14 05:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-05 22:44 - 2009-07-14 05:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-05 22:37 - 2013-03-18 22:40 - 00000000 ____D () C:\ProgramData\VMware 2014-02-05 22:37 - 2012-04-02 15:47 - 00045056 _____ () C:\Windows\SysWOW64\acovcnt.exe 2014-02-05 22:37 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-05 22:37 - 2009-07-14 05:51 - 00147766 _____ () C:\Windows\setupact.log 2014-02-05 22:36 - 2011-10-19 04:20 - 00752898 _____ () C:\Windows\PFRO.log 2014-02-05 22:20 - 2014-02-05 22:20 - 00448512 _____ (OldTimer Tools) C:\Users\system_ADMIN\Downloads\TFC.exe 2014-02-05 21:56 - 2013-04-17 20:02 - 00000000 ___RD () C:\Users\system_ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-05 21:55 - 2014-02-05 21:55 - 00550371 _____ () C:\Users\system_ADMIN\Desktop\Autoruns.zip 2014-02-05 19:08 - 2013-05-02 16:07 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Local\CrashDumps 2014-02-05 18:43 - 2014-02-05 18:43 - 00000000 _____ () C:\Users\system_ADMIN\defogger_reenable 2014-02-05 18:43 - 2013-04-17 20:02 - 00000000 ____D () C:\Users\system_ADMIN 2014-02-05 18:25 - 2013-12-21 12:21 - 00001968 _____ () C:\Windows\Sandboxie.ini 2014-02-05 10:45 - 2013-06-01 17:06 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\TeamViewer 2014-02-05 09:32 - 2014-01-08 17:07 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\.technic 2014-02-04 20:47 - 2013-01-20 22:33 - 00002177 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-02-04 12:21 - 2014-01-19 18:56 - 00003117 _____ () C:\Users\system_ADMIN\AppData\Roaming\PData.MMM 2014-02-04 12:21 - 2014-01-19 18:56 - 00003117 _____ () C:\Users\system_ADMIN\AppData\Roaming\PData.MM1 2014-02-04 10:19 - 2013-12-15 15:49 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Local\Purplizer 2014-02-03 17:20 - 2014-02-03 17:20 - 00000000 ____D () C:\ProgramData\Overwolf 2014-02-03 17:17 - 2014-02-03 17:17 - 00000272 _____ () C:\Windows\Tasks\ASUS SmartLogon Console Sensor.job 2014-02-03 17:17 - 2013-11-29 16:55 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Local\Overwolf 2014-02-03 17:16 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-02-03 11:14 - 2013-04-21 08:24 - 00000000 ____D () C:\Users\system_ADMIN\.gimp-2.6 2014-02-03 10:13 - 2014-02-03 10:13 - 00000849 _____ () C:\Users\system_ADMIN\AppData\Local\recently-used.xbel 2014-02-03 10:09 - 2013-10-05 16:56 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-02-02 20:39 - 2013-12-16 17:17 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\AUTOSICH 2014-02-02 20:34 - 2013-04-21 00:08 - 00007595 _____ () C:\Users\system_ADMIN\AppData\Local\resmon.resmoncfg 2014-01-29 20:28 - 2013-12-26 16:50 - 00000000 ____D () C:\Users\system_ADMIN\Desktop\Server 2014-01-29 18:23 - 2013-08-23 05:29 - 00000262 _____ () C:\Users\system_ADMIN\Desktop\sad.txt 2014-01-28 17:08 - 2014-01-28 17:08 - 00000000 ____D () C:\Users\system_ADMIN\Desktop\Neuer Ordner (7) 2014-01-28 17:05 - 2011-02-19 05:24 - 00780892 _____ () C:\Windows\system32\perfh007.dat 2014-01-28 17:05 - 2011-02-19 05:24 - 00180408 _____ () C:\Windows\system32\perfc007.dat 2014-01-28 17:05 - 2009-07-14 06:13 - 01849474 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-01-28 12:48 - 2014-01-28 12:43 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Local\Temporary Projects 2014-01-26 20:41 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-01-26 20:29 - 2014-01-26 20:28 - 00275224 _____ () C:\Windows\Minidump\012614-97438-01.dmp 2014-01-26 20:28 - 2012-06-14 06:09 - 601211795 _____ () C:\Windows\MEMORY.DMP 2014-01-26 20:28 - 2012-06-14 06:09 - 00000000 ____D () C:\Windows\Minidump 2014-01-23 21:47 - 2013-12-22 13:19 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-01-23 21:47 - 2013-10-05 16:56 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-01-23 21:47 - 2013-10-05 16:56 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-01-23 21:47 - 2013-10-05 16:56 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-01-23 21:47 - 2013-10-05 16:56 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-01-23 21:47 - 2013-10-05 16:56 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-01-23 21:47 - 2013-10-05 16:56 - 00001968 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-01-16 18:28 - 2009-07-14 05:45 - 00522792 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-15 23:19 - 2014-01-04 17:52 - 00000000 ____D () C:\Users\system_ADMIN\Desktop\ideas1040 2014-01-14 22:22 - 2013-11-29 16:54 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\TS3Client 2014-01-14 22:22 - 2013-11-11 21:19 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\Skype 2014-01-12 19:45 - 2013-11-28 13:01 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\.minecraft 2014-01-09 23:08 - 2014-01-09 23:08 - 01349598 _____ () C:\Users\system_ADMIN\Documents\Logs-2014-01-09T23-06-47.gz 2014-01-09 16:15 - 2013-12-21 12:21 - 00001336 _____ () C:\Users\system_ADMIN\Desktop\Sandboxed Web Browser.lnk 2014-01-09 15:57 - 2014-01-09 15:56 - 00275112 _____ () C:\Windows\Minidump\010914-37253-01.dmp 2014-01-09 15:54 - 2014-01-02 23:51 - 00000000 ____D () C:\Users\system_ADMIN\Desktop\Neuer Ordner (4) 2014-01-09 15:54 - 2013-04-21 00:11 - 00000000 ____D () C:\Users\Administrator 2014-01-09 15:54 - 2012-05-20 05:24 - 00000000 ____D () C:\Users\Gast 2014-01-09 15:54 - 2012-02-05 01:36 - 00000000 ____D () C:\ProgramData\P4G 2014-01-09 15:53 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration 2014-01-08 17:07 - 2014-01-08 16:06 - 00000000 ____D () C:\Users\system_ADMIN\Ekahau Site Survey 2014-01-08 16:04 - 2014-01-08 16:04 - 00000000 ____D () C:\Program Files\Ekahau ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-31 21:55 ==================== End Of Log ============================ |
07.02.2014, 13:18 | #12 |
/// Malwareteam | Windows 7 Verdach auf Virus/Malware Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Windows\System32\MSDCSC C:\Users\system_ADMIN\AppData\Roaming\dclogs SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {55AFFF2A-7AB3-5413-8C22-511A1448E47F} URL = SearchScopes: HKCU - {55AFFF2A-7AB3-5413-8C22-511A1448E47F} URL = FF Extension: Surrf and keaep - C:\Users\system_ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\bp9g4ldi.default\Extensions\lj7arl@qvsfyuoi-.net [2013-12-02] FF HKLM-x32\...\Firefox\Extensions: [{38e9e285-5266-4fe2-b5b5-c14c29b0cd45}] - C:\Program Files (x86)\WebEnhance\webenhance.xpi FF Extension: No Name - C:\Program Files (x86)\WebEnhance\webenhance.xpi C:\Program Files (x86)\WebEnhance C:\Program Files (x86)\DealPly Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Bitte setze die Browsereinstellungen von Chrome nach folgender Anleitung zurück: https://support.google.com/chrome/answer/3296214?hl=de Schritt 3
Schritt 4 ESET Online Scanner
Schritt 5 Starte noch einmal FRST.
Gibt es noch weitere Probleme mit dem Rechner? Poste folgende Logfiles in deiner nächsten Antwort:
__________________ Gruß, Jonas |
08.02.2014, 02:11 | #13 |
| Windows 7 Verdach auf Virus/MalwareCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 06-02-2014 Ran by system_ADMIN at 2014-02-07 13:40:34 Run:1 Running from C:\Users\system_ADMIN\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Windows\System32\MSDCSC C:\Users\system_ADMIN\AppData\Roaming\dclogs SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {55AFFF2A-7AB3-5413-8C22-511A1448E47F} URL = SearchScopes: HKCU - {55AFFF2A-7AB3-5413-8C22-511A1448E47F} URL = FF Extension: Surrf and keaep - C:\Users\system_ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\bp9g4ldi.default\Extensions\lj7arl@qvsfyuoi-.net [2013-12-02] FF HKLM-x32\...\Firefox\Extensions: [{38e9e285-5266-4fe2-b5b5-c14c29b0cd45}] - C:\Program Files (x86)\WebEnhance\webenhance.xpi FF Extension: No Name - C:\Program Files (x86)\WebEnhance\webenhance.xpi C:\Program Files (x86)\WebEnhance C:\Program Files (x86)\DealPly ***************** "C:\Windows\System32\MSDCSC" => File/Directory not found. "C:\Users\system_ADMIN\AppData\Roaming\dclogs" => File/Directory not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{55AFFF2A-7AB3-5413-8C22-511A1448E47F} => Key deleted successfully. HKCR\CLSID\{55AFFF2A-7AB3-5413-8C22-511A1448E47F} => Key not found. C:\Users\system_ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\bp9g4ldi.default\Extensions\lj7arl@qvsfyuoi-.net => Moved successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{38e9e285-5266-4fe2-b5b5-c14c29b0cd45} => Value deleted successfully. FF Extension: No Name - C:\Program Files (x86)\WebEnhance\webenhance.xpi not found. C:\Program Files (x86)\WebEnhance => Moved successfully. "C:\Program Files (x86)\DealPly" => File/Directory not found. ==== End of Fixlog ==== Code:
ATTFilter Malwarebytes Anti-Malware (PRO) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.02.05.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16476 system_ADMIN :: DOMINIK-PC [Administrator] Schutz: Deaktiviert 07.02.2014 13:42:57 mbam-log-2014-02-07 (13-42-57).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 315918 Laufzeit: 11 Minute(n), 33 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=5064856776155d4aa211df785225377d # engine=16985 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-02-07 10:58:37 # local_time=2014-02-07 11:58:37 (+0100, Mitteleuropäische Zeit) # country="Austria" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 85 74 1226275 1307490 0 0 # compatibility_mode=5893 16776573 100 94 36725 143443767 0 0 # scanned=411509 # found=7 # cleaned=0 # scan_time=26453 sh=0FC145D539EF7A2D88FA76DE573B25AB9EB2A317 ft=1 fh=0484962387c0b26c vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\ubiorbitapi_r2.dll" sh=E7374DC3E12F3ADF245437736D4FE311BBC1FBEE ft=1 fh=cab52340ccc66711 vn="a variant of Win32/Packed.VMProtect.ABD trojan" ac=I fn="C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\uplay_r1_loader.dll" sh=3F020537095F61255C5D074CBAE131FF49AFAC36 ft=1 fh=e1f4a658de9f8fda vn="Win32/Fynloski.AA trojan" ac=I fn="C:\Qoobox\Quarantine\C\Windows\SysWOW64\MSDCSC\wYMgrs8BJouL\msdcsc.exe.vir" sh=3F020537095F61255C5D074CBAE131FF49AFAC36 ft=1 fh=e1f4a658de9f8fda vn="Win32/Fynloski.AA trojan" ac=I fn="C:\Sandbox\system_ADMIN\DefaultBox\drive\C\Windows\SysWOW64\MSDCSC\msdcsc.exe" sh=3F020537095F61255C5D074CBAE131FF49AFAC36 ft=1 fh=e1f4a658de9f8fda vn="Win32/Fynloski.AA trojan" ac=I fn="C:\Sandbox\system_ADMIN\DefaultBox\drive\C\Windows\SysWOW64\MSDCSC\wYMgrs8BJouL\msdcsc.exe" sh=3F020537095F61255C5D074CBAE131FF49AFAC36 ft=1 fh=e1f4a658de9f8fda vn="Win32/Fynloski.AA trojan" ac=I fn="C:\Sandbox\system_ADMIN\DefaultBox\drive\C\Windows\SysWOW64\MSDCSC\wYMgrs8BJouL\wYMgrs8BJouL\msdcsc.exe" sh=3F020537095F61255C5D074CBAE131FF49AFAC36 ft=1 fh=e1f4a658de9f8fda vn="Win32/Fynloski.AA trojan" ac=I fn="C:\Sandbox\system_ADMIN\DefaultBox\user\current\AppData\Roaming\Microsoft\update.exe" FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-02-2014 Ran by system_ADMIN (administrator) on DOMINIK-PC on 08-02-2014 02:07:40 Running from C:\Users\system_ADMIN\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (ASUS) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (ASUS) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Microsoft Corporation) C:\Windows\System32\alg.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\javaw.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (VMware, Inc.) F:\vmware\vmware-authd.exe (Microsoft Corporation) C:\Windows\System32\prevhost.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\javaw.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2278504 2011-10-14] (Realtek Semiconductor) HKLM\...\Run: [AtherosBtStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [981664 2011-10-01] (Atheros Communications) HKLM\...\Run: [AthBtTray] - C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [799904 2011-10-01] (Atheros Commnucations) HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2317312 2011-09-13] (ASUS) HKLM-x32\...\Run: [SonicMasterTray] - C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-01-23] (AVAST Software) Startup: C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled () Startup: C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk ShortcutTarget: Facebook Messenger.lnk -> C:\Users\Dominik\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe (Facebook) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.aon.at StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: avast! Ad Blocker - {FFCB3198-32F3-4E8B-9539-4324694ED663} - C:\Program Files (x86)\AVAST Software\avast! Ad Blocker IE\Adblocker64.dll (AVAST Software) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft Web Test Recorder 10.0 Helper - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation) BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: avast! Ad Blocker - {FFCB3198-32F3-4E8B-9539-4324694ED663} - C:\Program Files (x86)\AVAST Software\avast! Ad Blocker IE\Adblocker32.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 10.0.0.138 FireFox: ======== FF ProfilePath: C:\Users\system_ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\bp9g4ldi.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @Nero.com/KM - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: ZEON/PDF,version=2.0 - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation) FF Plugin HKCU: @eximion.com/KalydoPlayer - C:\Users\system_ADMIN\AppData\Roaming\Kalydo\KalydoPlayer\bin2\npkalydo.dll (Eximion B.V.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: NoScript - C:\Users\system_ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\bp9g4ldi.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-10-05] FF Extension: Adblock Plus - C:\Users\system_ADMIN\AppData\Roaming\Mozilla\Firefox\Profiles\bp9g4ldi.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-10-05] FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\extensions\adblocker@avast.com.xpi [2013-11-18] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-05] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR Extension: (Google Docs) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-01] CHR Extension: (Google Drive) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-01] CHR Extension: (YouTube) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-01] CHR Extension: (Google-Suche) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-01] CHR Extension: (avast! Ad Blocker) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\fplhdcjmbpfkejbhngmlngaecbjmoimd [2013-12-01] CHR Extension: (avast! Online Security) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-12-01] CHR Extension: (Google Wallet) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-01] CHR Extension: (Google Mail) - C:\Users\system_ADMIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-01] CHR HKCU\...\Chrome\Extension: [kdfbddbdpnahdahmamlolacimfdbeckk] - C:\Users\system_ADMIN\AppData\Local\CRE\kdfbddbdpnahdahmamlolacimfdbeckk.crx [2013-07-17] CHR HKLM-x32\...\Chrome\Extension: [ejnmnhkgiphcaeefbaooconkceehicfi] - C:\Program Files (x86)\DealPly\DealPly.crx [2013-07-17] CHR HKLM-x32\...\Chrome\Extension: [fplhdcjmbpfkejbhngmlngaecbjmoimd] - C:\Program Files\AVAST Software\Avast\AdBlocker\Chrome\avast-adblocker-chrome.crx [2013-10-05] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2013-11-13] CHR HKLM-x32\...\Chrome\Extension: [kdfbddbdpnahdahmamlolacimfdbeckk] - C:\Users\system_ADMIN\AppData\Local\CRE\kdfbddbdpnahdahmamlolacimfdbeckk.crx [2013-07-17] CHR HKLM-x32\...\Chrome\Extension: [mbegnhpbhfjiaelealfpieodkembdgbj] - C:\Program Files (x86)\WebEnhance\webenhance.crx [2013-07-17] CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= S4 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2011-11-02] (Advanced Micro Devices, Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-23] (AVAST Software) S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) R2 HPSLPSVC; C:\Users\Dominik\AppData\Local\Temp\7zS1DE4\hpslpsvc64.dll [1039360 2011-11-14] (Hewlett-Packard Co.) S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S4 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation) S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [96184 2013-12-09] (Overwolf) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2012-06-24] () R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [186056 2013-10-16] (Sandboxie Holdings, LLC) S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation) S4 SXDS10; C:\Program Files (x86)\Common Files\soft Xpansion\sxds10.exe [234096 2013-10-13] (soft Xpansion) S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) R2 VMAuthdService; F:\vmware\vmware-authd.exe [86096 2013-10-18] (VMware, Inc.) S4 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [158880 2011-10-01] (Atheros) S4 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [X] S4 vToolbarUpdater15.5.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [X] ==================== Drivers (Whitelisted) ==================== R3 AiCharger; C:\Windows\SysWOW64\DRIVERS\AiCharger.sys [17152 2011-10-15] (ASUSTek Computer Inc.) R1 Amfilter; C:\Windows\System32\DRIVERS\Amfltx64.sys [12288 2007-10-15] ((Standard mouse types)) R3 Amusbprt; C:\Windows\System32\DRIVERS\Amusbx64.sys [17920 2008-02-13] (A4Tech Co.,Ltd.) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-01-23] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-11-13] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-13] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-01-23] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-01-23] (AVAST Software) S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-01-23] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-22] () R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [45856 2013-08-16] (AVG Technologies) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-11-01] (DT Soft Ltd) R1 dvdfabio; C:\Windows\system32\drivers\dvdfabio.sys [12776 2012-11-13] (Fengtao Software Inc.) S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2012-06-22] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [200552 2013-10-16] (Sandboxie Holdings, LLC) S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2013-02-12] (Microsoft Corporation) R3 vdrive; C:\Windows\System32\DRIVERS\vdrive.sys [45544 2012-11-13] (Fengtao Software Inc.) R0 vsock; C:\Windows\System32\drivers\vsock.sys [73296 2013-10-08] (VMware, Inc.) S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-26] (Microsoft Corporation) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S4 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-08 02:07 - 2014-02-08 02:07 - 00019431 _____ () C:\Users\system_ADMIN\Desktop\FRST.txt 2014-02-07 16:32 - 2014-02-07 16:32 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-02-07 13:43 - 2014-02-07 13:43 - 02347384 _____ (ESET) C:\Users\system_ADMIN\Downloads\esetsmartinstaller_enu.exe 2014-02-07 13:43 - 2014-02-07 13:43 - 02347384 _____ (ESET) C:\Users\system_ADMIN\Desktop\esetsmartinstaller_enu.exe 2014-02-07 10:03 - 2014-02-07 10:07 - 20827501 _____ () C:\Users\system_ADMIN\Downloads\Tekkit_Lite_Server_0.6.5.zip 2014-02-07 10:02 - 2014-02-07 10:02 - 02332590 _____ () C:\Users\system_ADMIN\Downloads\TechnicLauncher.exe 2014-02-06 19:38 - 2014-02-06 19:38 - 00005936 _____ () C:\Users\system_ADMIN\Downloads\Mini012214-02.zip 2014-02-06 00:48 - 2014-02-06 00:48 - 00131089 _____ () C:\ComboFix.txt 2014-02-06 00:24 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-02-06 00:24 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-02-06 00:24 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-02-06 00:24 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-02-06 00:24 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-02-06 00:24 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-02-06 00:24 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-02-06 00:24 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-02-06 00:15 - 2014-02-06 00:16 - 05180173 _____ (Swearware) C:\Users\system_ADMIN\Downloads\ComboFix (1).exe 2014-02-06 00:08 - 2014-02-06 00:48 - 00000000 ____D () C:\Qoobox 2014-02-06 00:07 - 2014-02-06 00:46 - 00000000 ____D () C:\Windows\erdnt 2014-02-06 00:06 - 2014-02-06 00:06 - 05180173 ____R (Swearware) C:\Users\system_ADMIN\Desktop\ComboFix.exe 2014-02-06 00:04 - 2014-02-06 00:06 - 05180173 ____R (Swearware) C:\Users\system_ADMIN\Downloads\ComboFix.exe 2014-02-05 22:20 - 2014-02-05 22:20 - 00448512 _____ (OldTimer Tools) C:\Users\system_ADMIN\Downloads\TFC.exe 2014-02-05 19:02 - 2014-02-05 19:02 - 00380416 _____ () C:\Users\system_ADMIN\Desktop\Gmer-19357.exe 2014-02-05 18:57 - 2014-02-08 02:07 - 00000000 ____D () C:\FRST 2014-02-05 18:56 - 2014-02-06 23:38 - 02079744 _____ (Farbar) C:\Users\system_ADMIN\Desktop\FRST64.exe 2014-02-05 18:43 - 2014-02-05 18:43 - 00050477 _____ () C:\Users\system_ADMIN\Desktop\Defogger.exe 2014-02-05 18:43 - 2014-02-05 18:43 - 00000000 _____ () C:\Users\system_ADMIN\defogger_reenable 2014-02-05 18:42 - 2014-02-07 13:39 - 00000000 ____D () C:\Users\system_ADMIN\Desktop\Neuer Ordner (8) 2014-02-03 17:20 - 2014-02-03 17:20 - 00000000 ____D () C:\ProgramData\Overwolf 2014-02-03 17:17 - 2014-02-03 17:17 - 00000272 _____ () C:\Windows\Tasks\ASUS SmartLogon Console Sensor.job 2014-02-03 10:13 - 2014-02-03 10:13 - 00000849 _____ () C:\Users\system_ADMIN\AppData\Local\recently-used.xbel 2014-01-28 12:43 - 2014-01-28 12:48 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Local\Temporary Projects 2014-01-26 20:28 - 2014-01-26 20:29 - 00275224 _____ () C:\Windows\Minidump\012614-97438-01.dmp 2014-01-19 18:56 - 2014-02-04 12:21 - 00003117 _____ () C:\Users\system_ADMIN\AppData\Roaming\PData.MMM 2014-01-19 18:56 - 2014-02-04 12:21 - 00003117 _____ () C:\Users\system_ADMIN\AppData\Roaming\PData.MM1 2014-01-15 19:41 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 19:41 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 19:41 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 19:41 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 19:41 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 19:41 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 19:41 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 19:41 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-15 19:41 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-09 23:08 - 2014-01-09 23:08 - 01349598 _____ () C:\Users\system_ADMIN\Documents\Logs-2014-01-09T23-06-47.gz 2014-01-09 15:56 - 2014-01-09 15:57 - 00275112 _____ () C:\Windows\Minidump\010914-37253-01.dmp ==================== One Month Modified Files and Folders ======= 2014-02-08 02:08 - 2014-02-08 02:07 - 00019431 _____ () C:\Users\system_ADMIN\Desktop\FRST.txt 2014-02-08 02:07 - 2014-02-05 18:57 - 00000000 ____D () C:\FRST 2014-02-08 01:43 - 2013-01-20 22:30 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-08 01:38 - 2012-05-31 12:18 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-07 22:33 - 2012-02-05 01:17 - 01143247 _____ () C:\Windows\WindowsUpdate.log 2014-02-07 16:32 - 2014-02-07 16:32 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-02-07 15:43 - 2013-01-20 22:30 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-07 13:43 - 2014-02-07 13:43 - 02347384 _____ (ESET) C:\Users\system_ADMIN\Downloads\esetsmartinstaller_enu.exe 2014-02-07 13:43 - 2014-02-07 13:43 - 02347384 _____ (ESET) C:\Users\system_ADMIN\Desktop\esetsmartinstaller_enu.exe 2014-02-07 13:39 - 2014-02-05 18:42 - 00000000 ____D () C:\Users\system_ADMIN\Desktop\Neuer Ordner (8) 2014-02-07 13:38 - 2009-07-14 05:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-07 13:38 - 2009-07-14 05:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-07 13:30 - 2013-10-05 16:56 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-02-07 13:30 - 2013-03-18 22:40 - 00000000 ____D () C:\ProgramData\VMware 2014-02-07 13:30 - 2012-04-02 15:47 - 00045056 _____ () C:\Windows\SysWOW64\acovcnt.exe 2014-02-07 13:30 - 2009-07-14 05:45 - 00522792 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-02-07 13:29 - 2011-10-19 04:20 - 00753438 _____ () C:\Windows\PFRO.log 2014-02-07 13:29 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-07 13:29 - 2009-07-14 05:51 - 00147822 _____ () C:\Windows\setupact.log 2014-02-07 10:07 - 2014-02-07 10:03 - 20827501 _____ () C:\Users\system_ADMIN\Downloads\Tekkit_Lite_Server_0.6.5.zip 2014-02-07 10:05 - 2014-01-08 17:07 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\.technic 2014-02-07 10:02 - 2014-02-07 10:02 - 02332590 _____ () C:\Users\system_ADMIN\Downloads\TechnicLauncher.exe 2014-02-07 09:56 - 2013-05-20 02:39 - 00000000 ____D () C:\Users\system_ADMIN\Documents\Bluetooth Folder 2014-02-06 23:38 - 2014-02-05 18:56 - 02079744 _____ (Farbar) C:\Users\system_ADMIN\Desktop\FRST64.exe 2014-02-06 19:39 - 2013-08-23 06:17 - 00000000 ____D () C:\Users\system_ADMIN\Documents\Visual Studio 2012 2014-02-06 19:38 - 2014-02-06 19:38 - 00005936 _____ () C:\Users\system_ADMIN\Downloads\Mini012214-02.zip 2014-02-06 00:48 - 2014-02-06 00:48 - 00131089 _____ () C:\ComboFix.txt 2014-02-06 00:48 - 2014-02-06 00:08 - 00000000 ____D () C:\Qoobox 2014-02-06 00:48 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default 2014-02-06 00:46 - 2014-02-06 00:07 - 00000000 ____D () C:\Windows\erdnt 2014-02-06 00:44 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2014-02-06 00:16 - 2014-02-06 00:15 - 05180173 _____ (Swearware) C:\Users\system_ADMIN\Downloads\ComboFix (1).exe 2014-02-06 00:06 - 2014-02-06 00:06 - 05180173 ____R (Swearware) C:\Users\system_ADMIN\Desktop\ComboFix.exe 2014-02-06 00:06 - 2014-02-06 00:04 - 05180173 ____R (Swearware) C:\Users\system_ADMIN\Downloads\ComboFix.exe 2014-02-05 22:20 - 2014-02-05 22:20 - 00448512 _____ (OldTimer Tools) C:\Users\system_ADMIN\Downloads\TFC.exe 2014-02-05 21:56 - 2013-04-17 20:02 - 00000000 ___RD () C:\Users\system_ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-05 19:08 - 2013-05-02 16:07 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Local\CrashDumps 2014-02-05 19:02 - 2014-02-05 19:02 - 00380416 _____ () C:\Users\system_ADMIN\Desktop\Gmer-19357.exe 2014-02-05 18:43 - 2014-02-05 18:43 - 00050477 _____ () C:\Users\system_ADMIN\Desktop\Defogger.exe 2014-02-05 18:43 - 2014-02-05 18:43 - 00000000 _____ () C:\Users\system_ADMIN\defogger_reenable 2014-02-05 18:43 - 2013-04-17 20:02 - 00000000 ____D () C:\Users\system_ADMIN 2014-02-05 18:25 - 2013-12-21 12:21 - 00001968 _____ () C:\Windows\Sandboxie.ini 2014-02-05 10:45 - 2013-06-01 17:06 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\TeamViewer 2014-02-04 12:21 - 2014-01-19 18:56 - 00003117 _____ () C:\Users\system_ADMIN\AppData\Roaming\PData.MMM 2014-02-04 12:21 - 2014-01-19 18:56 - 00003117 _____ () C:\Users\system_ADMIN\AppData\Roaming\PData.MM1 2014-02-04 10:19 - 2013-12-15 15:49 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Local\Purplizer 2014-02-03 17:20 - 2014-02-03 17:20 - 00000000 ____D () C:\ProgramData\Overwolf 2014-02-03 17:17 - 2014-02-03 17:17 - 00000272 _____ () C:\Windows\Tasks\ASUS SmartLogon Console Sensor.job 2014-02-03 17:17 - 2013-11-29 16:55 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Local\Overwolf 2014-02-03 17:16 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-02-03 11:14 - 2013-04-21 08:24 - 00000000 ____D () C:\Users\system_ADMIN\.gimp-2.6 2014-02-03 10:13 - 2014-02-03 10:13 - 00000849 _____ () C:\Users\system_ADMIN\AppData\Local\recently-used.xbel 2014-02-02 20:39 - 2013-12-16 17:17 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\AUTOSICH 2014-02-02 20:34 - 2013-04-21 00:08 - 00007595 _____ () C:\Users\system_ADMIN\AppData\Local\resmon.resmoncfg 2014-01-28 17:05 - 2011-02-19 05:24 - 00780892 _____ () C:\Windows\system32\perfh007.dat 2014-01-28 17:05 - 2011-02-19 05:24 - 00180408 _____ () C:\Windows\system32\perfc007.dat 2014-01-28 17:05 - 2009-07-14 06:13 - 01849474 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-01-28 12:48 - 2014-01-28 12:43 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Local\Temporary Projects 2014-01-26 20:41 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-01-26 20:29 - 2014-01-26 20:28 - 00275224 _____ () C:\Windows\Minidump\012614-97438-01.dmp 2014-01-26 20:28 - 2012-06-14 06:09 - 601211795 _____ () C:\Windows\MEMORY.DMP 2014-01-26 20:28 - 2012-06-14 06:09 - 00000000 ____D () C:\Windows\Minidump 2014-01-23 21:47 - 2013-12-22 13:19 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-01-23 21:47 - 2013-10-05 16:56 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-01-23 21:47 - 2013-10-05 16:56 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-01-23 21:47 - 2013-10-05 16:56 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-01-23 21:47 - 2013-10-05 16:56 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-01-23 21:47 - 2013-10-05 16:56 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-01-14 22:22 - 2013-11-29 16:54 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\TS3Client 2014-01-14 22:22 - 2013-11-11 21:19 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\Skype 2014-01-12 19:45 - 2013-11-28 13:01 - 00000000 ____D () C:\Users\system_ADMIN\AppData\Roaming\.minecraft 2014-01-09 23:08 - 2014-01-09 23:08 - 01349598 _____ () C:\Users\system_ADMIN\Documents\Logs-2014-01-09T23-06-47.gz 2014-01-09 15:57 - 2014-01-09 15:56 - 00275112 _____ () C:\Windows\Minidump\010914-37253-01.dmp 2014-01-09 15:54 - 2013-04-21 00:11 - 00000000 ____D () C:\Users\Administrator 2014-01-09 15:54 - 2012-05-20 05:24 - 00000000 ____D () C:\Users\Gast 2014-01-09 15:54 - 2012-02-05 01:36 - 00000000 ____D () C:\ProgramData\P4G 2014-01-09 15:53 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-31 21:55 ==================== End Of Log ============================ sonnst Keine Probleme |
09.02.2014, 01:11 | #14 | ||||||||
/// Malwareteam | Windows 7 Verdach auf Virus/Malware Du solltest auf jeden Fall deine Sandbox zurücksetzen/leeren. Dort existieren die gleiche schädlichen Dateien nochmal. Außerdem ändere unbedingt alle Passwörter. Du hattest Malware auf dem Rechner, die Passwörter und Informationen sammelt (auch Bankdaten). Updates Java 7 Update 51 Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Cleanup Falls du Malwarebytes Anti-Malware und den ESET Online Scanner nicht mehr behalten möchtest, kannst du diese über die Systemsteuerung deinstallieren. Ich empfehle dir, mindestens ein Programm zu behalten (näheres in den Tipps). Windows XP: Start --> Systemsteuerung --> Kategorieansicht auswählen (falls nicht voreingestellt) --> SoftwareDie Reihenfolge ist hier entscheidend.
In deinen Logfiles sehe ich keine schädlichen Einträge mehr, du bist in meinen Augen Clean. Für die Zukunft habe ich dir Tipps aufgeschrieben, damit du uns in nächster Zeit nicht mehr brauchst . Tipps - Frequently Asked Questions (FAQ)/Häufig gestellte Fragen Welcher Antivirenscanner ist der Beste?
Aber Updates muss ich immer installieren, oder?
Ok, muss ich auf etwas achten, wenn ich im Internet surfe?
Welche Programme sollte ich nicht verwenden?
Gibt es noch weitere Tipps, um mich zu schützen?
Wenn du die Arbeit des Trojaner-Boards unterstützen möchtest, kannst du gerne spenden . Ich wünsche dir eine schöne und malwarefreie Zeit .
__________________ Gruß, Jonas |
09.02.2014, 19:00 | #15 |
| Windows 7 Verdach auf Virus/Malware Großes Danke nochmal |