|
Plagegeister aller Art und deren Bekämpfung: Cross Scripting Verdacht und TrojanerfundeWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
28.07.2014, 17:55 | #1 |
| Cross Scripting Verdacht und Trojanerfunde Hallo Zusammen, habe heute bei einem Login in ein e-mail Postfach einen großen Schreck bekommen. NoScript zeigte mir an, dass es einen Verdacht auf Cross Site Scripting blockiert habe(verdächtigt wurde navigator.gmx.net). Da es nur ein Spamaccount war (den ich tatsächlich ohnehin löschen wollte und entsprechend auch gelöscht habe) ist das natürlich erstmal nicht so wild. Allerdings bin ich nun nachträglich doch etwas besorgt, dass sich etwas in mein System eingeschlichen haben könnte bzw. mein System bereits infiziert war o.Ä.. Habe Firefox mal neuinstalliert und zuvor mein System mit Malewarebytes gescannt, ohne Ergebnis und auch ein Scan mit dem Avast Browser Cleanup ergab keine Treffer. Verwende NoScript, Addblock Plus sowie Ghostery. Malewarebytes/Avast hatten zudem vor einiger Zeit schon ein paar Funde, die ich damals aber als Fehlalarm abgetan habe, weil es sich dabei um Dateien gehandelt hat, die schon ausgesprochen alt waren und auch nicht kürzlich geändert wurden (ich vermute sie waren bei der Erstinstallation von Windows dabei). Vor einiger Zeit hatte ich auch einige Funde zu Pup.optional.conduit.A. Allerdings waren dies auch schon sehr alte Dateien und ich hatte mit meinem Browser nie Probleme. Anbei die betreffende Logfile von Malwarebytes und die Details die ich bei Avast zur Datei noch rauslesen kann (leider gibt es dazu keine Logfile mehr) Malwarebytes Logfile: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.05.07.05 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 *** :: PAOLO [Administrator] 07.05.2014 17:33:58 MBAM-log-2014-05-07 (19-47-39).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 410156 Laufzeit: 2 Stunde(n), 9 Minute(n), 43 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 4 C:\Program Files\InstallShield Installation Information\{60DE4033-9503-48D1-A483-7846BD217CA9}\setup.exe (Trojan.Dropper) -> Keine Aktion durchgeführt. C:\Program Files\InstallShield Installation Information\{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}\ICQ7.exe (Trojan.Dropper) -> Keine Aktion durchgeführt. C:\Program Files\InstallShield Installation Information\{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}\setup.exe (Trojan.Dropper) -> Keine Aktion durchgeführt. C:\Toshiba\Drivers\Motorola Modem MOH\setup.exe (Trojan.Dropper) -> Keine Aktion durchgeführt. (Ende)" Code:
ATTFilter Ursprünglicher Dateiname: TCrdMain.exe Ursprünglicher Ordner: C:\Program Files\Toshiba\FlashCards Dateigröße: 716800 Letzte Änderung: 19:03.2008, 11:35:42 Transferzeit 15.11.2013 16:55:10 Kategorie: Infizierte Dateien Beschreibung: --kein Virus— Datei-ID: 1 Viele Grüße |
28.07.2014, 18:17 | #2 |
/// the machine /// TB-Ausbilder | Cross Scripting Verdacht und Trojanerfunde hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
28.07.2014, 20:02 | #3 |
| Cross Scripting Verdacht und Trojanerfunde Vielen lieben Dank für die schnelle Antwort.
__________________Anbei die Logfiles. Der Text für Addition war leider zu groß für den Post und ist deswegen angehängt. FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:25-07-2014 Ran by *** (administrator) on PAOLO on 28-07-2014 19:58:38 Running from C:\Users\***\Desktop Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (TOSHIBA CORPORATION) C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe (Toshiba Europe GmbH) C:\Program Files\Toshiba TEMPRO\TemproSvc.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\SMARTLogService\TosIPCSrv.exe (Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Safer Networking Ltd.) D:\Programm\Spybot - Search & Destroy\SDWinSec.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Toshiba) C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (TOSHIBA CORPORATION) C:\Program Files\Toshiba\ConfigFree\NDSTray.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\SmoothView\SmoothView.exe (Toshiba Europe GmbH) C:\Program Files\Toshiba TEMPRO\TemproTray.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (Elaborate Bytes AG) D:\Programm\VirtualCloneDrive\VCDDaemon.exe (TOSHIBA) C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Safer-Networking Ltd.) D:\Programm\Spybot - Search & Destroy\TeaTimer.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (TOSHIBA CORPORATION) C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation) C:\Windows\System32\conime.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) Winlogon\Notify\igfxcui: igfxdev.dll [X] HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\Run: [TOSCDSPD] => TOSCDSPD.EXE HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\Run: [SpybotSD TeaTimer] => D:\Programm\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\MountPoints2: {4763afb9-43cd-11df-b2c2-001e338ab817} - G:\autorun.exe HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\MountPoints2: {c10936aa-532f-11e1-bdfa-001e338ab817} - I:\Menu.exe HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\MountPoints2: {fe1c3ae9-ff78-11dd-b909-806e6f6e6963} - E:\Autorun.exe HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\MountPoints2: {fff61ac0-033e-11e1-863a-806e6f6e6963} - H:\Autorun.exe Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) GroupPolicyUsers\S-1-5-21-3147029616-3348592130-1442432417-1049\User: Group Policy restriction detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA; HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA; URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} URLSearchHook: HKLM - (No Name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - No File SearchScopes: HKLM - DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050 SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050 SearchScopes: HKLM - {E5F4146A-5E91-4B00-A1AB-A498D2FBB078} URL = hxxp://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA; SearchScopes: HKCU - DefaultScope {E5F4146A-5E91-4B00-A1AB-A498D2FBB078} URL = hxxp://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA_de SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050 SearchScopes: HKCU - {E5F4146A-5E91-4B00-A1AB-A498D2FBB078} URL = hxxp://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA_de BHO: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> D:\Programm\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Winsock: Catalog9 01 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 02 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 03 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 04 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 05 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 06 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 07 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 08 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Winsock: Catalog9 19 C:\Windows\system32\wpclsp.dll [72192] (Microsoft Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\9fyl39vc.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_43.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - D:\Programm\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 - D:\Programm\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Ghostery - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\9fyl39vc.default\Extensions\firefox@ghostery.com.xpi [2014-07-28] FF Extension: NoScript - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\9fyl39vc.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-07-28] FF Extension: Adblock Plus - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\9fyl39vc.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-07-28] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-04-27] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-08-10] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software) R2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [40960 2008-04-17] (TOSHIBA CORPORATION) [File not signed] S3 FirebirdServerMAGIXInstance; C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) [File not signed] S2 gupdate1c9c76df710d1a6; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-04-27] (Google Inc.) S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed] S3 jswpsapi; C:\Program Files\Jumpstart\jswpsapi.exe [937984 2007-10-30] (Atheros Communications, Inc.) [File not signed] S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [36352 2009-12-12] () [File not signed] R2 SBSDWSCService; D:\Programm\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) R3 SmartFaceVWatchSrv; C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe [73728 2008-04-24] (Toshiba) [File not signed] R2 TemproMonitoringService; C:\Program Files\Toshiba TEMPRO\TemproSvc.exe [116104 2009-07-21] (Toshiba Europe GmbH) R2 TOSHIBA SMART Log Service; C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [126976 2007-12-03] (TOSHIBA Corporation) [File not signed] R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-08-23] (Ulead Systems, Inc.) [File not signed] S2 TOSHIBA Bluetooth Service; c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 AFS; C:\Windows\system32\Drivers\AFS.sys [77004 2010-11-02] (Oak Technology Inc.) [File not signed] R2 aswFsBlk; C:\Windows\system32\Drivers\aswFsBlk.sys [29816 2013-08-30] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [66336 2013-08-30] (AVAST Software) R1 AswRdr; C:\Windows\system32\Drivers\AswRdr.sys [49760 2013-08-30] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49376 2013-08-30] () R1 aswSnx; C:\Windows\system32\Drivers\aswSnx.sys [770344 2013-08-30] (AVAST Software) R1 aswSP; C:\Windows\system32\Drivers\aswSP.sys [369584 2013-08-30] (AVAST Software) R1 aswTdi; C:\Windows\system32\Drivers\aswTdi.sys [56080 2013-08-30] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [177864 2013-08-30] () R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [30616 2013-03-04] (Elaborate Bytes AG) R0 Lbd; C:\Windows\System32\DRIVERS\Lbd.sys [64288 2010-12-03] (Lavasoft AB) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [320120 2014-06-29] (Duplex Secure Ltd.) R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [25984 2009-12-12] (The OpenVPN Project) R3 UVCFTR; C:\Windows\System32\Drivers\UVCFTR_S.SYS [18432 2007-12-17] (Chicony Electronics Co., Ltd.) R3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [22792 2009-09-11] (Logitech Inc.) R3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [35592 2009-09-11] (Logitech Inc.) R3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [14984 2009-09-11] (Logitech Inc.) R3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [66056 2009-09-11] (Logitech Inc.) S3 igfx; system32\DRIVERS\igdkmd32.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 Lavasoft Kernexplorer; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [X] S3 massfilter; system32\drivers\massfilter.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 Tosrfcom; No ImagePath S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-07-28 19:57 - 2014-07-28 19:57 - 00000000 ____D () C:\Users\***\Desktop\Neuer Ordner 2014-07-28 19:56 - 2014-07-28 19:56 - 00170734 _____ () C:\Users\***\Desktop\Addition1.txt 2014-07-28 19:56 - 2014-07-28 19:56 - 00028447 _____ () C:\Users\***\Desktop\FRST1.txt 2014-07-28 19:46 - 2014-07-28 19:47 - 00170734 _____ () C:\Users\***\Desktop\Addition.txt 2014-07-28 19:45 - 2014-07-28 19:58 - 00018664 _____ () C:\Users\***\Desktop\FRST.txt 2014-07-28 19:45 - 2014-07-28 19:58 - 00000000 ____D () C:\FRST 2014-07-28 19:44 - 2014-07-28 19:44 - 01084416 _____ (Farbar) C:\Users\***\Desktop\FRST.exe 2014-07-28 17:25 - 2014-07-28 17:25 - 00000851 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-07-28 17:13 - 2014-07-28 17:13 - 00000574 _____ () C:\Windows\PFRO.log 2014-07-28 16:50 - 2014-07-28 16:51 - 32047680 _____ () C:\Users\***\Downloads\Firefox Setup 31.0.exe 2014-07-28 16:33 - 2014-07-28 16:35 - 32047680 _____ () C:\Users\***\Downloads\Firefox_Setup_de31.0(1).exe 2014-07-28 16:32 - 2014-07-28 16:36 - 32047680 _____ () C:\Users\***\Downloads\Firefox_Setup_de31.0.exe 2014-07-19 18:39 - 2014-07-19 18:40 - 29677544 _____ (Mozilla) C:\Users\***\Downloads\Firefox Setup 30.0.exe 2014-07-19 01:30 - 2014-07-19 01:31 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\***\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-19 01:28 - 2014-07-19 01:28 - 00512784 _____ (AVAST Software) C:\Users\***\Downloads\avastclear_9.0.2013.exe.part 2014-07-19 01:24 - 2014-07-19 01:29 - 91906368 _____ (AVAST Software) C:\Users\***\Downloads\avast_free_antivirus_setup_9.0.2021.exe 2014-07-17 19:38 - 2014-07-17 19:40 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\***\Downloads\spybot-2.4.exe 2014-07-17 19:31 - 2014-07-17 19:31 - 01348263 _____ () C:\Users\***\Downloads\adwcleaner_3.215.exe 2014-07-17 19:23 - 2014-07-17 19:23 - 02953520 _____ (AVAST Software) C:\Users\***\Downloads\avast-browser-cleanup_9.0.0.224.exe 2014-07-17 17:08 - 2014-07-17 17:08 - 00131095 _____ () C:\Users\***\Downloads\***.de - Rücksendezentrum.htm 2014-06-29 21:10 - 2014-06-29 21:10 - 00000000 ____D () C:\Users\***\Documents\TecmoKoei 2014-06-29 20:13 - 2014-06-29 20:13 - 00000654 _____ () C:\Users\Public\Desktop\Virtual CloneDrive.lnk 2014-06-29 20:10 - 2014-06-29 20:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes 2014-06-29 18:23 - 2014-06-29 18:23 - 00000000 ____D () C:\Users\***\{f61e8412-1a9e-4215-926c-e70b7baf2ccd} 2014-06-29 17:53 - 2014-06-29 17:54 - 01640984 _____ () C:\Users\***\Downloads\SetupVirtualCloneDrive547.exe 2014-06-29 16:42 - 2014-06-29 16:42 - 00025169 _____ () C:\Users\***\Desktop\20140629.txt 2014-06-29 16:32 - 2014-06-29 16:32 - 00000000 ____D () C:\Users\***\AppData\Roaming\toshiba 2014-06-29 01:20 - 2014-06-29 01:20 - 00001268 _____ () C:\Users\***\Desktop\dsgfsdf.txt 2014-06-29 00:40 - 2014-07-28 14:42 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-29 00:40 - 2014-06-29 00:40 - 00000911 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-29 00:40 - 2014-06-29 00:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-29 00:39 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-06-29 00:39 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-07-28 19:58 - 2014-07-28 19:45 - 00018664 _____ () C:\Users\***\Desktop\FRST.txt 2014-07-28 19:58 - 2014-07-28 19:45 - 00000000 ____D () C:\FRST 2014-07-28 19:57 - 2014-07-28 19:57 - 00000000 ____D () C:\Users\***\Desktop\Neuer Ordner 2014-07-28 19:56 - 2014-07-28 19:56 - 00170734 _____ () C:\Users\***\Desktop\Addition1.txt 2014-07-28 19:56 - 2014-07-28 19:56 - 00028447 _____ () C:\Users\***\Desktop\FRST1.txt 2014-07-28 19:47 - 2014-07-28 19:46 - 00170734 _____ () C:\Users\***\Desktop\Addition.txt 2014-07-28 19:44 - 2014-07-28 19:44 - 01084416 _____ (Farbar) C:\Users\***\Desktop\FRST.exe 2014-07-28 19:13 - 2006-11-02 14:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-28 19:13 - 2006-11-02 14:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-28 19:05 - 2009-06-30 14:08 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-28 19:02 - 2009-02-20 19:59 - 01251258 _____ () C:\Windows\WindowsUpdate.log 2014-07-28 17:25 - 2014-07-28 17:25 - 00000851 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-07-28 17:25 - 2013-07-04 01:23 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-07-28 17:25 - 2009-04-14 19:10 - 00000000 ____D () C:\Users\***\AppData\Roaming\Mozilla 2014-07-28 17:16 - 2009-06-30 14:08 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-28 17:13 - 2014-07-28 17:13 - 00000574 _____ () C:\Windows\PFRO.log 2014-07-28 17:13 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-28 17:12 - 2006-11-02 15:01 - 00032606 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-28 16:51 - 2014-07-28 16:50 - 32047680 _____ () C:\Users\***\Downloads\Firefox Setup 31.0.exe 2014-07-28 16:36 - 2014-07-28 16:32 - 32047680 _____ () C:\Users\***\Downloads\Firefox_Setup_de31.0.exe 2014-07-28 16:35 - 2014-07-28 16:33 - 32047680 _____ () C:\Users\***\Downloads\Firefox_Setup_de31.0(1).exe 2014-07-28 15:49 - 2009-06-29 20:24 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-07-28 14:42 - 2014-06-29 00:40 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-28 12:31 - 2014-02-09 16:18 - 00000000 ____D () C:\Users\***\AppData\Roaming\vlc 2014-07-27 22:01 - 2009-02-23 03:59 - 00198656 _____ () C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-07-19 18:40 - 2014-07-19 18:39 - 29677544 _____ (Mozilla) C:\Users\***\Downloads\Firefox Setup 30.0.exe 2014-07-19 01:31 - 2014-07-19 01:30 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\***\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-19 01:29 - 2014-07-19 01:24 - 91906368 _____ (AVAST Software) C:\Users\***\Downloads\avast_free_antivirus_setup_9.0.2021.exe 2014-07-19 01:28 - 2014-07-19 01:28 - 00512784 _____ (AVAST Software) C:\Users\***\Downloads\avastclear_9.0.2013.exe.part 2014-07-17 19:40 - 2014-07-17 19:38 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\***\Downloads\spybot-2.4.exe 2014-07-17 19:31 - 2014-07-17 19:31 - 01348263 _____ () C:\Users\***\Downloads\adwcleaner_3.215.exe 2014-07-17 19:23 - 2014-07-17 19:23 - 02953520 _____ (AVAST Software) C:\Users\***\Downloads\avast-browser-cleanup_9.0.0.224.exe 2014-07-17 17:08 - 2014-07-17 17:08 - 00131095 _____ () C:\Users\***\Downloads\***.de - Rücksendezentrum.htm 2014-07-02 13:31 - 2009-03-01 23:53 - 00007728 _____ () C:\Users\***\AppData\Local\d3d9caps.dat 2014-06-29 21:10 - 2014-06-29 21:10 - 00000000 ____D () C:\Users\***\Documents\TecmoKoei 2014-06-29 20:29 - 2008-01-21 09:16 - 01600466 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-29 20:13 - 2014-06-29 20:13 - 00000654 _____ () C:\Users\Public\Desktop\Virtual CloneDrive.lnk 2014-06-29 20:13 - 2009-02-20 22:15 - 00000000 ____D () C:\Users\*** 2014-06-29 20:10 - 2014-06-29 20:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes 2014-06-29 18:23 - 2014-06-29 18:23 - 00000000 ____D () C:\Users\***\{f61e8412-1a9e-4215-926c-e70b7baf2ccd} 2014-06-29 18:17 - 2010-04-09 13:40 - 00320120 _____ (Duplex Secure Ltd.) C:\Windows\system32\Drivers\sptd.sys 2014-06-29 17:59 - 2012-08-10 19:33 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-06-29 17:54 - 2014-06-29 17:53 - 01640984 _____ () C:\Users\***\Downloads\SetupVirtualCloneDrive547.exe 2014-06-29 16:45 - 2008-07-03 10:50 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2014-06-29 16:42 - 2014-06-29 16:42 - 00025169 _____ () C:\Users\***\Desktop\20140629.txt 2014-06-29 16:32 - 2014-06-29 16:32 - 00000000 ____D () C:\Users\***\AppData\Roaming\toshiba 2014-06-29 12:15 - 2006-11-02 12:23 - 00450844 ____R () C:\Windows\system32\Drivers\etc\hosts.20140629-122231.backup 2014-06-29 01:20 - 2014-06-29 01:20 - 00001268 _____ () C:\Users\***\Desktop\dsgfsdf.txt 2014-06-29 00:40 - 2014-06-29 00:40 - 00000911 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-29 00:40 - 2014-06-29 00:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-29 00:40 - 2012-08-10 19:33 - 00000000 ____D () C:\Users\***\AppData\Roaming\Malwarebytes 2014-06-29 00:39 - 2012-08-10 19:33 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-29 00:24 - 2010-04-09 13:38 - 00000000 ____D () C:\Users\***\AppData\Roaming\DAEMON Tools Lite ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-28 17:20 ==================== End Of Log ============================ --- --- --- |
28.07.2014, 22:22 | #4 |
| Cross Scripting Verdacht und Trojanerfunde Da ich grad gelesen hab, dass die Logs zur Not in mehreren Posts stehen sollen, hier nochmal das Addition Logfile (musste es nochmals teilen): Addition Part 1: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version:25-07-2014 Ran by *** at 2014-07-28 19:46:40 Running from C:\Users\***\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C} AS: avast! Antivirus (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden Adobe Flash Player 12 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 12.0.0.43 - Adobe Systems Incorporated) Adobe Reader X (10.1.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated) Atheros Driver Installation Program (HKLM\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 5.0 - Atheros) Atheros Wi-Fi Protected Setup Library (HKLM\...\{B0BCDCBD-863D-4CAB-BF68-8D1F6B1BDC13}) (Version: - Atheros) ATI Catalyst Install Manager (HKLM\...\{E257B0A7-3B49-4943-7455-F2E7B09137C8}) (Version: 3.0.664.0 - ATI Technologies, Inc.) Audacity 1.2.6 (HKLM\...\Audacity_is1) (Version: - ) avast! Free Antivirus (HKLM\...\avast) (Version: 8.0.1497.0 - AVAST Software) Bluetooth Stack for Windows by Toshiba (HKLM\...\{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}) (Version: v6.10.07.2(T) - TOSHIBA CORPORATION) BulletStorm (Version: 1.0.0001.130 - EA) Hidden Camera Assistant Software for Toshiba (HKLM\...\{37C866E4-AA67-4725-9E95-A39968DD7960}) (Version: 1.7.193.0508L - Chicony Electronics Co.,Ltd.) Catalyst Control Center - Branding (HKLM\...\{69E5255D-9D43-4CFF-8984-843ABD7753B7}) (Version: 1.00.0000 - ATI) Catalyst Control Center Core Implementation (Version: 2008.0407.2139.36897 - ATI) Hidden Catalyst Control Center Graphics Full Existing (Version: 2008.0407.2139.36897 - ATI) Hidden Catalyst Control Center Graphics Full New (Version: 2008.0407.2139.36897 - ATI) Hidden Catalyst Control Center Graphics Light (Version: 2008.0407.2139.36897 - ATI) Hidden Catalyst Control Center Graphics Previews Vista (Version: 2008.0407.2139.36897 - ATI) Hidden Catalyst Control Center Localization Chinese Standard (Version: 2008.0407.2139.36897 - ATI) Hidden Catalyst Control Center Localization Chinese Traditional (Version: 2008.0407.2139.36897 - ATI) Hidden Catalyst Control Center Localization Dutch (Version: 2008.0407.2139.36897 - ATI) Hidden Catalyst Control Center Localization French (Version: 2008.0407.2139.36897 - ATI) Hidden Catalyst Control Center Localization German (Version: 2008.0407.2139.36897 - ATI) Hidden Catalyst Control Center Localization Italian (Version: 2008.0407.2139.36897 - ATI) Hidden Catalyst Control Center Localization Japanese (Version: 2008.0407.2139.36897 - ATI) Hidden Catalyst Control Center Localization Korean (Version: 2008.0407.2139.36897 - ATI) Hidden Catalyst Control Center Localization Portuguese (Version: 2008.0407.2139.36897 - ATI) Hidden Catalyst Control Center Localization Spanish (Version: 2008.0407.2139.36897 - ATI) Hidden Catalyst Control Center Localization Swedish (Version: 2008.0407.2139.36897 - ATI) Hidden CCC Help Chinese Standard (Version: 2008.0407.2138.36897 - ATI) Hidden CCC Help Chinese Traditional (Version: 2008.0407.2138.36897 - ATI) Hidden CCC Help Dutch (Version: 2008.0407.2138.36897 - ATI) Hidden CCC Help English (Version: 2008.0407.2138.36897 - ATI) Hidden CCC Help French (Version: 2008.0407.2138.36897 - ATI) Hidden CCC Help German (Version: 2008.0407.2138.36897 - ATI) Hidden CCC Help Italian (Version: 2008.0407.2138.36897 - ATI) Hidden CCC Help Japanese (Version: 2008.0407.2138.36897 - ATI) Hidden CCC Help Korean (Version: 2008.0407.2138.36897 - ATI) Hidden CCC Help Portuguese (Version: 2008.0407.2138.36897 - ATI) Hidden CCC Help Spanish (Version: 2008.0407.2138.36897 - ATI) Hidden CCC Help Swedish (Version: 2008.0407.2138.36897 - ATI) Hidden ccc-core-static (Version: 2008.0407.2139.36897 - Ihr Firmenname) Hidden ccc-utility (Version: 2008.0407.2139.36897 - ATI) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.03 - Piriform) CD/DVD Drive Acoustic Silencer (HKLM\...\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}) (Version: 2.02.03 - TOSHIBA) Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) DivX-Setup (HKLM\...\DivX Setup) (Version: 2.6.1.90 - DivX, LLC) DVD MovieFactory for TOSHIBA (HKLM\...\{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}) (Version: 5.51 - Ulead Systems, Inc.) Dynasty Warriors 8 Xtreme Legends (HKLM\...\Dynasty Warriors 8 Xtreme Legends_is1) (Version: - ) Firebird SQL Server - MAGIX Edition 2.0.0.1 (D) (HKLM\...\Firebird SQL Server D) (Version: 2.0.0.1 - MAGIX AG) Free M4a to MP3 Converter 7.1 (HKLM\...\Free M4a to MP3 Converter_is1) (Version: - ManiacTools.com) Free YouTube to MP3 Converter version 3.12.9.725 (HKLM\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.9.725 - DVDVideoSoft Ltd.) Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) Jade Empire Special Edition (HKLM\...\GOGPACKJADEEMPIRE_is1) (Version: 2.0.0.4 - GOG.com) Java 7 Update 51 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217040FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 20 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83216013FF}) (Version: 6.0.200 - Sun Microsystems, Inc.) Java(TM) 6 Update 6 (HKLM\...\{3248F0A8-6813-11D6-A77B-00B0D0160060}) (Version: 1.6.0.60 - Sun Microsystems, Inc.) JDownloader 0.9 (HKLM\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) Logitech Gaming Software 5.08 (HKLM\...\{33BC9D7E-E790-495E-A4EA-CFB160C17A91}) (Version: 5.08.146 - Logitech) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Memories Disc Creator 2.0 (HKLM\...\{2E132061-C78A-48D4-A899-1D13B9D189FA}) (Version: 2.0.470.1598 - Memories Disc Creator 2.0) Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden Microsoft .NET Framework 1.1 German Language Pack (HKLM\...\{E78BFA60-5393-4C38-82AB-E8019E464EB4}) (Version: 1.1.4322 - Microsoft) Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version: - ) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Games for Windows - LIVE Redistributable (HKLM\...\{F2508213-9989-4E85-A078-72BE483917EF}) (Version: 3.5.88.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2007 (HKLM\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint Viewer 2007 (German) (HKLM\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs (HKLM\...\{90120000-00B2-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (HKLM\...\{39D0E034-1042-4905-BECB-5502909FCB7C}) (Version: 9.7.0621 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Microsoft XML Parser (Version: 8.0.7820.0 - Microsoft Corporation) Hidden Microsoft XML Parser (Version: 8.20.8730.4 - Microsoft Corporation) Hidden Microsoft_VC80_ATL_x86 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC90_ATL_x86 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFCLOC_x86 (Version: 1.00.0000 - Adobe) Hidden Moorhuhnjagd (HKLM\...\Moorhuhnjagd) (Version: - ) Mozilla Firefox 31.0 (x86 de) (HKLM\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla) MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) myphotobook 3.5 (HKLM\...\myphotobook) (Version: 3.5 - myphotobook) NVIDIA PhysX (HKLM\...\{9530AE42-DAE1-4619-9594-B23487285D17}) (Version: 9.11.1107 - NVIDIA Corporation) OpenVPN 2.1.1 (HKLM\...\OpenVPN) (Version: 2.1.1 - ) Picasa 2 (HKLM\...\Picasa2) (Version: 2.0 - Google, Inc.) Prince of Persia T2T (HKLM\...\{DFFE2B1F-07E0-45A9-8801-CD8514CAA876}) (Version: - ) PxMergeModule (Version: 1.00.0000 - Your Company Name) Hidden Realtek 8169 8168 8101E 8102E Ethernet Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0000 - Realtek) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5599 - Realtek Semiconductor Corp.) RICOH R5C83x/84x Flash Media Controller Driver Ver.3.54.02 (HKLM\...\{59F6A514-9813-47A3-948C-8A155460CC2A}) (Version: 3.54.02 - ) Skins (Version: 2008.0407.2139.36897 - ATI) Hidden SPSS 15.0 für Windows [Auswertung Version] (HKLM\...\{6D9B9CF3-1E9C-45B6-B41E-5CF568605556}) (Version: 15.0.1 - SPSS Inc.) Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 10.1.8.0 - Synaptics) TOSHIBA Assist (HKLM\...\{12B3A009-A080-4619-9A2A-C6DB151D8D67}) (Version: 2.01.04 - TOSHIBA) TOSHIBA Benutzerhandbücher (HKLM\...\{1C971EE3-B4C4-4367-9676-57549919C6CE}) (Version: 7.40 - TOSHIBA) TOSHIBA ConfigFree (HKLM\...\{0D5D0BEE-FBA9-4928-A50D-6CDFAB827755}) (Version: 7.2.13 - TOSHIBA Corporation) TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.0.1.3 - TOSHIBA Corporation) TOSHIBA DVD PLAYER (HKLM\...\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}) (Version: 1.31.14 - TOSHIBA Corporation) TOSHIBA Extended Tiles for Windows Mobility Center (HKLM\...\InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}) (Version: 1.01.00 - Toshiba) TOSHIBA Extended Tiles for Windows Mobility Center (Version: 1.01.00 - Toshiba) Hidden TOSHIBA Face Recognition (HKLM\...\InstallShield_{C730E42C-935A-45BB-A0C5-37E5234D111B}) (Version: 2.0.2.32 - TOSHIBA Corporation) TOSHIBA Face Recognition (Version: 2.0.2.32 - TOSHIBA Corporation) Hidden TOSHIBA Hardware Setup (HKLM\...\{2883F6F5-0509-43F3-868C-D50330DD9DD3}) (Version: 2.00.08 - ) Toshiba Online Product Information (HKLM\...\{2290A680-4083-410A-ADCC-7092C67FC052}) (Version: 1.00.0012 - TOSHIBA) TOSHIBA Recovery Disc Creator (HKLM\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.0.0.1b - TOSHIBA) TOSHIBA SD Memory Utilities (HKLM\...\{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}) (Version: 1.8.1.3 - TOSHIBA) TOSHIBA Supervisor Password (HKLM\...\{4B1E87C3-00DE-4898-8E39-E390AAEF2391}) (Version: 2.00.04 - ) Toshiba TEMPRO (HKLM\...\{42CB94C5-66F6-4F63-8D31-7FA3A86490A8}) (Version: 2.0 - Toshiba Europe GmbH) TOSHIBA Value Added Package (HKLM\...\InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}) (Version: 1.1.19 - TOSHIBA Corporation) TOSHIBA Value Added Package (Version: 1.1.19 - TOSHIBA Corporation) Hidden TRDCReminder (HKLM\...\InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}) (Version: 1.00.0015 - TOSHIBA) TRDCReminder (Version: 1.00.0015 - TOSHIBA) Hidden TRORDCLauncher (HKLM\...\InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}) (Version: 1.0.0.1 - TOSHIBA) TRORDCLauncher (Version: 1.0.0.1 - TOSHIBA) Hidden Uninstall 1.0.0.1 (HKLM\...\Uninstall_is1) (Version: - ) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden VirtualCloneDrive (HKLM\...\VirtualCloneDrive) (Version: 5.4.7.0 - Elaborate Bytes) Visual C++ 2008 x86 Runtime - (v9.0.30729) (Version: 9.0.30729 - Microsoft Corporation) Hidden Visual C++ 2008 x86 Runtime - v9.0.30729.01 (HKLM\...\{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01) (Version: 9.0.30729.01 - Microsoft Corporation) VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN) Windows Live ID Sign-in Assistant (HKLM\...\{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}) (Version: 6.500.3165.0 - Microsoft Corporation) Windows Media Encoder 9-Reihe (HKLM\...\Windows Media Encoder 9) (Version: - ) Windows Media Encoder 9-Reihe (Version: 9.00.3374 - Microsoft Corporation) Hidden WinRAR 5.00 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{693566bc-21f8-401e-8d42-e2c5ce50dacc}\localserver32 -> C:\Users\***\AppData\Local\Temp\{d5641912-e47a-429c-879e-cfe13eac7a13}\IDriver.NonElevated.exe No (the data entry has 4 more characters). CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () |
28.07.2014, 22:28 | #5 |
| Cross Scripting Verdacht und Trojanerfunde Addition Part 2: Code:
ATTFilter CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre6\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre6\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre6\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre6\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre6\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre6\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre6\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre6\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre6\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre6\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre6\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre6\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre6\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre6\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre6\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre6\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre6\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre6\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0031-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0031-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0032-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0032-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0033-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0033-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0034-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0034-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0035-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0035-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0036-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0036-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0037-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0037-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0038-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0038-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0039-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0039-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0040-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0040-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0041-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0041-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0042-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0042-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0043-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-0043-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0031-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0031-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0031-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0032-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0032-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0032-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0033-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0033-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0033-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0034-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0034-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0034-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0035-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0035-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0035-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0036-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0036-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0036-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0037-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0037-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0037-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0038-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0038-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0038-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0039-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0039-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0039-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0040-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0040-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0040-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0041-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0041-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0041-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0042-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0042-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0042-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0043-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0043-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0043-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0044-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0044-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0044-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0045-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0045-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0045-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0046-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0046-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0046-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0047-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0047-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0047-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0048-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0048-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0048-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0049-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0049-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0049-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0050-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0050-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0050-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0051-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0051-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0051-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0052-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0052-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0052-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0053-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0053-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0053-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0054-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0054-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0054-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0055-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0055-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0055-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0056-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0056-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0056-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0057-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0057-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0057-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0058-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0058-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0058-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0059-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0059-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0059-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0060-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0060-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0060-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0061-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0061-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-0061-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0028-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0028-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0028-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0036-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0036-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0036-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0040-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0040-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0040-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0041-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0041-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0041-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0042-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0042-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0042-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0044-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0044-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0044-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0046-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0046-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0046-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0047-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0047-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0047-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0048-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0048-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0048-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0049-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0049-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0049-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0050-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0050-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0050-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0051-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0051-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0051-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0052-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0052-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0052-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0053-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0053-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0053-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0054-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0054-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0054-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0055-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0055-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0055-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0056-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0056-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0056-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0057-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0057-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0057-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0058-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0058-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0058-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0059-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0059-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0059-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0060-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0060-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0060-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0061-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0061-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0061-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0062-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0062-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0062-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0063-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0063-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0063-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0064-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0064-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0064-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0065-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0065-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0065-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0066-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0066-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0066-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0067-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0067-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0067-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0068-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0068-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0068-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0069-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0069-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0069-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0070-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0070-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0070-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0071-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0071-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-0071-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0016-0000-FFFF-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0002-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0002-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0003-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0003-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0004-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0004-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0004-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0005-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0005-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0006-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0006-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0006-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0007-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0007-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0008-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0008-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0008-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0009-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0009-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0010-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0010-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0010-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0011-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0011-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0011-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0012-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0012-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0012-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0013-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0014-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0014-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0014-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0015-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0015-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0015-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0016-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0016-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0016-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0017-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0017-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0018-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0018-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0018-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0019-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0019-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0019-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0020-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0020-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0020-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0021-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0021-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0022-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0022-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0022-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0023-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0023-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0023-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0024-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0024-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0024-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0026-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0026-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0026-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0027-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0027-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0027-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0028-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0028-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0028-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0029-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0029-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0029-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0030-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0030-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0030-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0031-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0031-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0031-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0032-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0032-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0032-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0033-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0033-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0033-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0034-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0034-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0034-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0035-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0035-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0035-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0036-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0036-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0036-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () |
28.07.2014, 22:29 | #6 |
| Cross Scripting Verdacht und Trojanerfunde Addition Part 3 Code:
ATTFilter CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0037-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0037-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0037-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0038-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0038-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0038-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0039-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0039-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0039-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0040-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0040-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0040-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0041-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0041-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0041-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0042-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0042-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0042-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0043-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0043-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0043-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0044-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0044-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0044-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0045-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll ()CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0045-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0046-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0046-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0046-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0047-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0047-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0047-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0048-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0048-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0048-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0049-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0049-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0049-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0050-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0050-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0050-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0051-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0051-ABCDEFFEDCBB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-0051-ABCDEFFEDCBC}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () CustomCLSID: HKU\S-1-5-21-3147029616-3348592130-1442432417-1000_Classes\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}\InprocServer32 -> C:\Program Files\Java\jre7\bin\jp2iexp.dll () ==================== Restore Points ========================= 25-07-2014 14:30:18 Geplanter Prüfpunkt 26-07-2014 23:42:30 Windows Update 28-07-2014 17:38:02 Geplanter Prüfpunkt ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2006-11-02 12:23 - 2014-06-29 12:22 - 00450844 ____R C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 im.adtech.de 127.0.0.1 adserver.adtech.de 127.0.0.1 adtech.de 127.0.0.1 atwola.com 127.0.0.1 adserver.71i.de 127.0.0.1 adicqserver.71i.de 127.0.0.1 71i.de 127.0.0.1 www.2009-version.info 127.0.0.1 2011-kilos-verlieren.eu 127.0.0.1 www.2011-kilos-verlieren.eu 127.0.0.1 2020search.com 127.0.0.1 www.2020search.com 127.0.0.1 20x2p.com 127.0.0.1 www.21dice.net 127.0.0.1 21dice.net 127.0.0.1 2-2005-search.com 127.0.0.1 www.2-2005-search.com 127.0.0.1 24.365soft.info 127.0.0.1 www.24.365soft.info 127.0.0.1 247fxxx.info 127.0.0.1 www.247fxxx.info 127.0.0.1 24-7pharmacy.info 127.0.0.1 www.24-7pharmacy.info 127.0.0.1 24-7searching-and-more.com 127.0.0.1 www.24-7searching-and-more.com 127.0.0.1 www.24teen.com 127.0.0.1 24teen.com 127.0.0.1 2777f1.makemegood24.com There are 1000 more lines. ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {15970730-2DE9-45F1-BEFD-D662E72049AD} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation) Task: {18D59FA1-2CE9-42D6-BB71-758445568AC5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2009-04-27] (Google Inc.) Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {5DB17485-21AD-4FC3-B636-2F9AEEF004D3} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: {892F076A-6EC8-4644-8123-057683C0BE36} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2009-04-27] (Google Inc.) Task: {92B41678-ABBF-4701-BD57-8D6143DB6D3C} - System32\Tasks\Ad-Aware Scan (Zeitplan 1) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: {B955DEAB-D6B9-403F-9879-B6CF800EB8EE} - System32\Tasks\Ad-Aware Scan (Zeitplan 2) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: {C0A87B85-EDD4-4B6B-990F-D0E8DA132BA6} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-08-30] (AVAST Software) Task: {DFF94C62-8D99-445A-93CD-6B1927CCBF51} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-07-28 16:35 - 2014-07-28 13:54 - 02822144 _____ () C:\Program Files\AVAST Software\Avast\defs\14072801\algo.dll 2008-04-24 19:25 - 2008-04-24 19:25 - 00126976 _____ () C:\Windows\system32\SmartFaceVCtrl.dll 2008-04-24 19:25 - 2008-04-24 19:25 - 06701056 _____ () C:\Windows\system32\FaceHI.dll 2008-04-24 19:25 - 2008-04-24 19:25 - 00995328 _____ () C:\Windows\system32\FaceRec.dll 2008-02-04 14:29 - 2008-02-04 14:29 - 00688128 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll 2008-07-03 10:48 - 2008-04-07 21:59 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll 2013-11-15 02:48 - 2013-11-15 02:48 - 01861968 _____ () C:\Program Files\DivX\DivX Update\DivXUpdate.exe 2013-11-15 02:49 - 2013-11-15 02:49 - 00100688 _____ () C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll 2014-07-28 17:25 - 2014-07-17 07:42 - 03800688 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2013-07-10 18:07 - 2013-07-10 18:07 - 00756888 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: Acrobat Assistant 8.0 => "D:\Programm\Acrobat 10.0\Acrobat\Acrotray.exe" MSCONFIG\startupreg: Adobe Acrobat Speed Launcher => "D:\Programm\Acrobat 10.0\Acrobat\Acrobat_sl.exe" MSCONFIG\startupreg: Adobe Acrobat Synchronizer => "D:\Programm\Acrobat 10.0\Acrobat\AdobeCollabSync.exe" MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" MSCONFIG\startupreg: AdobeCS5.5ServiceManager => "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin MSCONFIG\startupreg: AdobeUpdater => "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" MSCONFIG\startupreg: Camera Assistant Software => "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start MSCONFIG\startupreg: DAEMON Tools Lite => "D:\Programm\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: DaemonTools_WhenUSave_Installer => C:\Program Files\DaemonTools_WhenUSave_Installer\DaemonTools_WhenUSave_Installer.exe MSCONFIG\startupreg: DXDllRegExe => dxdllreg.exe MSCONFIG\startupreg: Google Desktop Search => "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup MSCONFIG\startupreg: Google EULA Launcher => c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe IE PA MSCONFIG\startupreg: ICQ => "C:\Program Files\ICQ7.2\ICQ.exe" silent loginmode=4 MSCONFIG\startupreg: ITSecMng => %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START MSCONFIG\startupreg: jswtrayutil => "C:\Program Files\Jumpstart\jswtrayutil.exe" MSCONFIG\startupreg: swg => "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" MSCONFIG\startupreg: SwitchBoard => C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe MSCONFIG\startupreg: Toshiba TEMPO => C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe ==================== Faulty Device Manager Devices ============= Name: isatap.Speedport_W_503V_Typ_C Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver ==================== Event log errors: ========================= Application errors: ================== Error: (07/28/2014 05:14:16 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/28/2014 04:47:15 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm firefox.exe, Version 30.0.0.5269 arbeitet nicht mehr mit Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem zu suchen. Prozess-ID: 1370 Anfangszeit: 01cfaa728efd1ca0 Zeitpunkt der Beendigung: 40 Error: (07/28/2014 08:04:57 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/27/2014 00:18:11 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/27/2014 08:45:05 AM) (Source: EventSystem) (EventID: 4621) (User: ) Description: 80070005EventSystem.EventSubscription{CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000} Error: (07/26/2014 01:51:02 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/25/2014 11:58:34 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/25/2014 05:00:07 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/25/2014 00:54:15 AM) (Source: EventSystem) (EventID: 4621) (User: ) Description: 80070005EventSystem.EventSubscription{CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000} Error: (07/24/2014 01:55:33 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm Launch.exe, Version 1.0.0.1 arbeitet nicht mehr mit Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem zu suchen. Prozess-ID: 1754 Anfangszeit: 01cfa73598685e22 Zeitpunkt der Beendigung: 120 System errors: ============= Error: (07/28/2014 05:17:17 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Windows Media Player-Netzwerkfreigabedienst%%1053 Error: (07/28/2014 05:17:17 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: 30000Windows Media Player-Netzwerkfreigabedienst Error: (07/28/2014 05:14:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: TOSHIBA Bluetooth Service%%2 Error: (07/28/2014 08:04:57 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: TOSHIBA Bluetooth Service%%2 Error: (07/27/2014 00:18:11 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: TOSHIBA Bluetooth Service%%2 Error: (07/26/2014 01:52:17 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Windows Media Player-Netzwerkfreigabedienst%%1053 Error: (07/26/2014 01:52:17 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: 30000Windows Media Player-Netzwerkfreigabedienst Error: (07/26/2014 01:51:02 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: TOSHIBA Bluetooth Service%%2 Error: (07/26/2014 01:50:43 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 26.07.2014 um 01:49:18 unerwartet heruntergefahren. Error: (07/25/2014 11:58:34 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: TOSHIBA Bluetooth Service%%2 Microsoft Office Sessions: ========================= Error: (03/08/2012 08:06:16 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 506 seconds with 180 seconds of active time. This session ended with a crash. Error: (03/08/2012 04:32:12 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 143 seconds with 60 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-07-28 19:46:32.636 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-07-28 19:46:31.763 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-07-28 19:46:30.905 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-07-28 19:46:30.031 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-07-28 19:46:29.002 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-07-28 19:46:28.128 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-07-28 19:46:27.223 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-07-28 19:46:26.303 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-07-28 16:23:05.700 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-07-28 16:23:04.507 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22713_none_b39feb737f8937a0\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 55% Total physical RAM: 3069.06 MB Available physical RAM: 1369.43 MB Total Pagefile: 6352.35 MB Available Pagefile: 4594.42 MB Total Virtual: 2047.88 MB Available Virtual: 1885.6 MB ==================== Drives ================================ Drive c: (Vista) (Fixed) (Total:116.29 GB) (Free:43.14 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Data) (Fixed) (Total:115.13 GB) (Free:36.17 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 233 GB) (Disk ID: D39222F7) Partition 1: (Not Active) - (Size=1 GB) - (Type=27) Partition 2: (Active) - (Size=116 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=115 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
29.07.2014, 11:20 | #7 |
/// the machine /// TB-Ausbilder | Cross Scripting Verdacht und Trojanerfunde hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.07.2014, 16:35 | #8 |
| Cross Scripting Verdacht und Trojanerfunde erledigt, hier das log: Code:
ATTFilter ComboFix 14-07-29.01 - *** 29.07.2014 17:06:28.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3069.1631 [GMT 2:00] ausgeführt von:: c:\users\***\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\DaemonTools_WhenUSave_Installer c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\mxfilerelatedcache.mxc2 c:\users\***\Favorites\mxfilerelatedcache.mxc2 c:\windows\IsUn0407.exe c:\windows\system32\pt c:\windows\system32\pt\smartfacevcp.dll.mui c:\windows\system32\pt\toscdspd.cpl.mui . . ((((((((((((((((((((((( Dateien erstellt von 2014-06-28 bis 2014-07-29 )))))))))))))))))))))))))))))) . . 2014-07-28 18:38 . 2014-07-28 18:39 -------- d-----w- c:\users\Mama 2014-07-28 17:45 . 2014-07-28 17:59 -------- d-----w- C:\FRST 2014-07-26 23:45 . 2014-07-02 03:11 8217224 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4A4D2967-350B-4DEC-B399-2DA464398FC4}\mpengine.dll 2014-06-29 16:23 . 2014-06-29 16:23 -------- d-----w- c:\users\***\{f61e8412-1a9e-4215-926c-e70b7baf2ccd} . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-07-29 14:55 . 2014-06-28 22:40 110296 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2014-06-29 16:17 . 2010-04-09 11:40 320120 ----a-w- c:\windows\system32\drivers\sptd.sys 2014-05-28 16:39 . 2014-06-15 23:58 1810432 ----a-w- c:\windows\system32\jscript9.dll 2014-05-28 16:32 . 2014-06-15 23:58 1129472 ----a-w- c:\windows\system32\wininet.dll 2014-05-28 16:32 . 2014-06-15 23:58 1427968 ----a-w- c:\windows\system32\inetcpl.cpl 2014-05-28 16:30 . 2014-06-15 23:58 142848 ----a-w- c:\windows\system32\ieUnatt.exe 2014-05-28 16:30 . 2014-06-15 23:58 421376 ----a-w- c:\windows\system32\vbscript.dll 2014-05-28 16:29 . 2014-06-15 23:58 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2014-05-28 16:29 . 2014-06-15 23:58 11776 ----a-w- c:\windows\system32\mshta.exe 2014-05-12 05:26 . 2014-06-28 22:39 51928 ----a-w- c:\windows\system32\drivers\mwac.sys 2014-05-12 05:25 . 2014-06-28 22:39 74456 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2014-05-12 05:25 . 2012-08-10 17:33 23256 ----a-w- c:\windows\system32\drivers\mbam.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-08-30 07:47 121968 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "SpybotSD TeaTimer"="d:\programm\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1029416] "NDSTray.exe"="NDSTray.exe" [BU] "topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440] "RtHDVCpl"="RtHDVCpl.exe" [2008-04-08 6037504] "Skytel"="Skytel.exe" [2007-11-20 1826816] "TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-01-17 431456] "SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2008-01-25 509816] "Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaRegistration.exe" [2008-01-11 574864] "Toshiba TEMPRO"="c:\program files\Toshiba TEMPRO\TemproTray.exe" [2009-07-21 1045904] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-08-30 4858968] "Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2009-09-17 153608] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] "DivXMediaServer"="d:\programm\DivX\DivX Media Server\DivXMediaServer.exe" [2013-12-23 450560] "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2013-11-15 1861968] "VirtualCloneDrive"="d:\programm\VirtualCloneDrive\VCDDaemon.exe" [2013-03-10 88984] . c:\users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ TRDCReminder.lnk - c:\program files\Toshiba\TRDCReminder\TRDCReminder.exe [2008-3-5 393216] . c:\users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ TRDCReminder.lnk - c:\program files\Toshiba\TRDCReminder\TRDCReminder.exe [2008-3-5 393216] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ TRDCReminder.lnk - c:\program files\Toshiba\TRDCReminder\TRDCReminder.exe [2008-3-5 393216] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2013-11-21 16:57 959904 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0] 2011-03-30 07:46 499608 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Camera Assistant Software] 2008-04-29 09:33 417792 ----a-w- c:\program files\Camera Assistant Software for Toshiba\traybar.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google EULA Launcher] 2008-05-28 11:40 20480 ----a-w- c:\program files\Google\Google EULA\GoogleEULALauncher.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Inhalt des "geplante Tasks" Ordners . 2014-07-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-27 19:24] . 2014-07-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-27 19:24] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.bing.com mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA IE: An vorhandene PDF-Datei anfügen - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: Free YouTube to Mp3 Converter - c:\users\***\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html IE: In Adobe PDF konvertieren - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Linkziel in Adobe PDF konvertieren - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 LSP: c:\windows\system32\wpclsp.dll TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\***\AppData\Roaming\Mozilla\Firefox\Profiles\9fyl39vc.default\ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . HKCU-Run-TOSCDSPD - TOSCDSPD.EXE HKCU-Run-AdobeBridge - (no file) HKLM-Run-cfFncEnabler.exe - cfFncEnabler.exe SafeBoot-WudfPf SafeBoot-WudfRd MSConfigStartUp-Acrobat Assistant 8 - d:\programm\Acrobat 10.0\Acrobat\Acrotray.exe MSConfigStartUp-Adobe Acrobat Speed Launcher - d:\programm\Acrobat 10.0\Acrobat\Acrobat_sl.exe MSConfigStartUp-Adobe Acrobat Synchronizer - d:\programm\Acrobat 10.0\Acrobat\AdobeCollabSync.exe MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe MSConfigStartUp-AdobeCS5 - c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe MSConfigStartUp-AdobeUpdater - c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe MSConfigStartUp-DAEMON Tools Lite - d:\programm\DAEMON Tools Lite\DTLite.exe MSConfigStartUp-DaemonTools_WhenUSave_Installer - c:\program files\DaemonTools_WhenUSave_Installer\DaemonTools_WhenUSave_Installer.exe MSConfigStartUp-DXDllRegExe - dxdllreg.exe MSConfigStartUp-Google Desktop Search - c:\program files\Google\Google Desktop Search\GoogleDesktop.exe MSConfigStartUp-ICQ - c:\program files\ICQ7.2\ICQ.exe MSConfigStartUp-ITSecMng - c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe MSConfigStartUp-jswtrayutil - c:\program files\Jumpstart\jswtrayutil.exe MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe MSConfigStartUp-SwitchBoard - c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe MSConfigStartUp-Toshiba TEMPO - c:\program files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe AddRemove-Moorhuhnjagd - c:\windows\IsUn0407.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2014-07-29 17:14 Windows 6.0.6002 Service Pack 2 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . Zeit der Fertigstellung: 2014-07-29 17:17:31 ComboFix-quarantined-files.txt 2014-07-29 15:17 . Vor Suchlauf: 9 Verzeichnis(se), 42.454.786.048 Bytes frei Nach Suchlauf: 13 Verzeichnis(se), 42.341.597.184 Bytes frei . - - End Of File - - 55FB21B792F9102C3D4479CC47096C3B 5C616939100B85E558DA92B899A0FC36 |
30.07.2014, 11:51 | #9 |
/// the machine /// TB-Ausbilder | Cross Scripting Verdacht und Trojanerfunde Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
30.07.2014, 16:40 | #10 |
| Cross Scripting Verdacht und Trojanerfunde Hi, Malewarebytes habe ich bereits installiert. Sollte ich das neu installieren oder reicht es mit der bereits installieren Version zu scannen? |
31.07.2014, 18:47 | #11 |
/// the machine /// TB-Ausbilder | Cross Scripting Verdacht und Trojanerfunde Reicht, mach nur ein Update
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
31.07.2014, 20:20 | #12 |
| Cross Scripting Verdacht und Trojanerfunde okay hier sind die Logs: Malwarebytes: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 30.07.2014 Suchlauf-Zeit: 17:42:54 Logdatei: MBAM Log.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.07.30.04 Rootkit Datenbank: v2014.07.17.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows Vista Service Pack 2 CPU: x86 Dateisystem: NTFS Benutzer: *** Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 353266 Verstrichene Zeit: 11 Min, 33 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Warnen PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.301 - Bericht erstellt am 31/07/2014 um 19:56:48 # Aktualisiert 28/07/2014 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzername : *** - PAOLO # Gestartet von : C:\Users\***\Downloads\adwcleaner_3.301.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\ICQ\ICQToolbar Ordner Gelöscht : C:\Program Files\Conduit Ordner Gelöscht : C:\Users\***\AppData\LocalLow\Conduit Ordner Gelöscht : C:\Users\***\AppData\Roaming\dvdvideosoftiehelpers ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2269050 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}] Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKLM\Software\DivX\Install\Setup\WizardLayout\ConduitToolbar Schlüssel Gelöscht : HKLM\Software\dt soft\daemon tools toolbar Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar ***** [ Browser ] ***** -\\ Internet Explorer v9.0.8112.16555 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search] -\\ Mozilla Firefox v31.0 (x86 de) [ Datei : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\9fyl39vc.default\prefs.js ] ************************* AdwCleaner[R0].txt - [2415 octets] - [31/07/2014 19:54:14] AdwCleaner[S0].txt - [2276 octets] - [31/07/2014 19:56:48] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2336 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows Vista (TM) Home Premium x86 Ran by *** on 31.07.2014 at 20:05:04,57 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 31.07.2014 at 20:09:39,74 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:31-07-2014 01 Ran by *** (administrator) on PAOLO on 31-07-2014 21:05:46 Running from C:\Users\***\Desktop Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (TOSHIBA CORPORATION) C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe (Toshiba Europe GmbH) C:\Program Files\Toshiba TEMPRO\TemproSvc.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\SMARTLogService\TosIPCSrv.exe (Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Safer Networking Ltd.) D:\Programm\Spybot - Search & Destroy\SDWinSec.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Toshiba) C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\SmoothView\SmoothView.exe (Toshiba Europe GmbH) C:\Program Files\Toshiba TEMPRO\TemproTray.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (Elaborate Bytes AG) D:\Programm\VirtualCloneDrive\VCDDaemon.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Safer-Networking Ltd.) D:\Programm\Spybot - Search & Destroy\TeaTimer.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) Winlogon\Notify\igfxcui: igfxdev.dll [X] HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\Run: [SpybotSD TeaTimer] => D:\Programm\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) GroupPolicyUsers\S-1-5-21-3147029616-3348592130-1442432417-1049\User: Group Policy restriction detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} SearchScopes: HKLM - {E5F4146A-5E91-4B00-A1AB-A498D2FBB078} URL = hxxp://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA; SearchScopes: HKCU - {E5F4146A-5E91-4B00-A1AB-A498D2FBB078} URL = hxxp://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA_de BHO: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> D:\Programm\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\9fyl39vc.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_43.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - D:\Programm\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 - D:\Programm\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Ghostery - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\9fyl39vc.default\Extensions\firefox@ghostery.com.xpi [2014-07-28] FF Extension: NoScript - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\9fyl39vc.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-07-28] FF Extension: Adblock Plus - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\9fyl39vc.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-07-28] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-04-27] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-08-10] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software) R2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [40960 2008-04-17] (TOSHIBA CORPORATION) [File not signed] S3 FirebirdServerMAGIXInstance; C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) [File not signed] S2 gupdate1c9c76df710d1a6; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-04-27] (Google Inc.) S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed] S3 jswpsapi; C:\Program Files\Jumpstart\jswpsapi.exe [937984 2007-10-30] (Atheros Communications, Inc.) [File not signed] S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [36352 2009-12-12] () [File not signed] R2 SBSDWSCService; D:\Programm\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) R3 SmartFaceVWatchSrv; C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe [73728 2008-04-24] (Toshiba) [File not signed] R2 TemproMonitoringService; C:\Program Files\Toshiba TEMPRO\TemproSvc.exe [116104 2009-07-21] (Toshiba Europe GmbH) R2 TOSHIBA SMART Log Service; C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [126976 2007-12-03] (TOSHIBA Corporation) [File not signed] R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-08-23] (Ulead Systems, Inc.) [File not signed] S2 TOSHIBA Bluetooth Service; c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 AFS; C:\Windows\system32\Drivers\AFS.sys [77004 2010-11-02] (Oak Technology Inc.) [File not signed] R2 aswFsBlk; C:\Windows\system32\Drivers\aswFsBlk.sys [29816 2013-08-30] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [66336 2013-08-30] (AVAST Software) R1 AswRdr; C:\Windows\system32\Drivers\AswRdr.sys [49760 2013-08-30] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49376 2013-08-30] () R1 aswSnx; C:\Windows\system32\Drivers\aswSnx.sys [770344 2013-08-30] (AVAST Software) R1 aswSP; C:\Windows\system32\Drivers\aswSP.sys [369584 2013-08-30] (AVAST Software) R1 aswTdi; C:\Windows\system32\Drivers\aswTdi.sys [56080 2013-08-30] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [177864 2013-08-30] () R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [30616 2013-03-04] (Elaborate Bytes AG) R0 Lbd; C:\Windows\System32\DRIVERS\Lbd.sys [64288 2010-12-03] (Lavasoft AB) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [320120 2014-06-29] (Duplex Secure Ltd.) R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [25984 2009-12-12] (The OpenVPN Project) R3 UVCFTR; C:\Windows\System32\Drivers\UVCFTR_S.SYS [18432 2007-12-17] (Chicony Electronics Co., Ltd.) R3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [22792 2009-09-11] (Logitech Inc.) S3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [35592 2009-09-11] (Logitech Inc.) R3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [14984 2009-09-11] (Logitech Inc.) R3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [66056 2009-09-11] (Logitech Inc.) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S3 catchme; \??\C:\Users\***\AppData\Local\Temp\catchme.sys [X] S3 igfx; system32\DRIVERS\igdkmd32.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 Lavasoft Kernexplorer; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [X] S3 massfilter; system32\drivers\massfilter.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 Tosrfcom; No ImagePath S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-07-31 21:05 - 2014-07-31 21:05 - 00000000 ____D () C:\Users\***\Desktop\FRST-OlderVersion 2014-07-31 20:09 - 2014-07-31 20:13 - 00000632 _____ () C:\Users\***\Desktop\JRT.txt 2014-07-31 20:04 - 2014-07-31 20:04 - 00002406 _____ () C:\Users\***\Desktop\AdwCleaner[S0].txt 2014-07-31 20:04 - 2014-07-31 20:04 - 00000000 ____D () C:\Windows\ERUNT 2014-07-31 19:54 - 2014-07-31 19:56 - 00000000 ____D () C:\AdwCleaner 2014-07-30 17:45 - 2014-07-30 17:46 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\***\Downloads\mbam-setup-2.0.2.1012(1).exe 2014-07-30 17:38 - 2014-07-30 17:39 - 01016261 _____ (Thisisu) C:\Users\***\Downloads\JRT.exe 2014-07-30 17:38 - 2014-07-30 17:38 - 01365525 _____ () C:\Users\***\Downloads\adwcleaner_3.301.exe 2014-07-29 17:17 - 2014-07-29 17:17 - 00010860 _____ () C:\ComboFix.txt 2014-07-29 17:03 - 2014-07-29 17:17 - 00000000 ____D () C:\Qoobox 2014-07-29 17:03 - 2014-07-29 17:17 - 00000000 ____D () C:\ComboFix 2014-07-29 17:03 - 2014-07-29 17:15 - 00000000 ____D () C:\Windows\erdnt 2014-07-29 17:03 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-07-29 17:03 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-07-29 17:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-07-29 17:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-07-29 17:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-07-29 17:03 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-07-29 17:03 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-07-29 17:03 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-07-29 16:56 - 2014-07-29 16:57 - 05563986 ____R (Swearware) C:\Users\***\Desktop\ComboFix.exe 2014-07-28 20:48 - 2014-07-28 20:49 - 00000000 ____D () C:\Users\***\Desktop\FRST 2014-07-28 20:40 - 2014-07-28 20:40 - 00000000 ____D () C:\Users\Mama\AppData\Roaming\ATI 2014-07-28 20:40 - 2014-07-28 20:40 - 00000000 ____D () C:\Users\Mama\AppData\Local\ATI 2014-07-28 20:39 - 2014-07-28 20:39 - 00086424 _____ () C:\Users\Mama\AppData\Local\GDIPFONTCACHEV1.DAT 2014-07-28 20:39 - 2014-07-28 20:39 - 00000954 _____ () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-07-28 20:39 - 2014-07-28 20:39 - 00000949 _____ () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2014-07-28 20:38 - 2014-07-28 20:39 - 00000000 ____D () C:\Users\Mama 2014-07-28 20:38 - 2014-07-28 20:38 - 00000998 __RSH () C:\Users\Mama\ntuser.pol 2014-07-28 20:38 - 2014-07-28 20:38 - 00000920 _____ () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk 2014-07-28 20:38 - 2014-07-28 20:38 - 00000020 ___SH () C:\Users\Mama\ntuser.ini 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Startmenü 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Netzwerkumgebung 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Druckumgebung 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Documents\Eigene Musik 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Documents\Eigene Bilder 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\AppData\Local\Verlauf 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 ____D () C:\Users\Mama\AppData\Local\VirtualStore 2014-07-28 20:38 - 2012-10-03 16:32 - 00000000 ____D () C:\Users\Mama\AppData\Local\Microsoft Help 2014-07-28 20:38 - 2008-01-21 04:42 - 00000000 ___RD () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-07-28 20:38 - 2008-01-21 04:42 - 00000000 ___RD () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-07-28 19:57 - 2014-07-28 19:57 - 00000000 ____D () C:\Users\***\Desktop\Neuer Ordner 2014-07-28 19:56 - 2014-07-28 19:56 - 00170734 _____ () C:\Users\***\Desktop\Addition1.txt 2014-07-28 19:56 - 2014-07-28 19:56 - 00028447 _____ () C:\Users\***\Desktop\FRST1.txt 2014-07-28 19:46 - 2014-07-28 20:16 - 00170728 _____ () C:\Users\***\Desktop\Addition.txt 2014-07-28 19:45 - 2014-07-31 21:05 - 00015582 _____ () C:\Users\***\Desktop\FRST.txt 2014-07-28 19:45 - 2014-07-31 21:05 - 00000000 ____D () C:\FRST 2014-07-28 19:44 - 2014-07-31 21:05 - 01084928 _____ (Farbar) C:\Users\***\Desktop\FRST.exe 2014-07-28 17:25 - 2014-07-28 17:25 - 00000851 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-07-28 17:13 - 2014-07-31 19:58 - 00001436 _____ () C:\Windows\PFRO.log 2014-07-28 16:50 - 2014-07-28 16:51 - 32047680 _____ () C:\Users\***\Downloads\Firefox Setup 31.0.exe 2014-07-28 16:33 - 2014-07-28 16:35 - 32047680 _____ () C:\Users\***\Downloads\Firefox_Setup_de31.0(1).exe 2014-07-28 16:32 - 2014-07-28 16:36 - 32047680 _____ () C:\Users\***\Downloads\Firefox_Setup_de31.0.exe 2014-07-28 06:12 - 2014-07-28 06:26 - 00010134 ____H () C:\Users\***\Desktop\~WRL0006.tmp 2014-07-19 18:39 - 2014-07-19 18:40 - 29677544 _____ (Mozilla) C:\Users\***\Downloads\Firefox Setup 30.0.exe 2014-07-19 01:30 - 2014-07-19 01:31 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\***\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-19 01:28 - 2014-07-19 01:28 - 00512784 _____ (AVAST Software) C:\Users\***\Downloads\avastclear_9.0.2013.exe.part 2014-07-19 01:24 - 2014-07-19 01:29 - 91906368 _____ (AVAST Software) C:\Users\***\Downloads\avast_free_antivirus_setup_9.0.2021.exe 2014-07-17 19:38 - 2014-07-17 19:40 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\***\Downloads\spybot-2.4.exe 2014-07-17 19:31 - 2014-07-17 19:31 - 01348263 _____ () C:\Users\***\Downloads\adwcleaner_3.215.exe 2014-07-17 19:23 - 2014-07-17 19:23 - 02953520 _____ (AVAST Software) C:\Users\***\Downloads\avast-browser-cleanup_9.0.0.224.exe 2014-07-17 17:08 - 2014-07-17 17:08 - 00131095 _____ () C:\Users\***\Downloads\***.de - Rücksendezentrum.htm ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-07-31 21:05 - 2014-07-31 21:05 - 00000000 ____D () C:\Users\***\Desktop\FRST-OlderVersion 2014-07-31 21:05 - 2014-07-28 19:45 - 00015582 _____ () C:\Users\***\Desktop\FRST.txt 2014-07-31 21:05 - 2014-07-28 19:45 - 00000000 ____D () C:\FRST 2014-07-31 21:05 - 2014-07-28 19:44 - 01084928 _____ (Farbar) C:\Users\***\Desktop\FRST.exe 2014-07-31 21:05 - 2009-06-30 14:08 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-31 20:13 - 2014-07-31 20:09 - 00000632 _____ () C:\Users\***\Desktop\JRT.txt 2014-07-31 20:04 - 2014-07-31 20:04 - 00002406 _____ () C:\Users\***\Desktop\AdwCleaner[S0].txt 2014-07-31 20:04 - 2014-07-31 20:04 - 00000000 ____D () C:\Windows\ERUNT 2014-07-31 20:02 - 2009-02-20 19:59 - 01349946 _____ () C:\Windows\WindowsUpdate.log 2014-07-31 20:01 - 2009-06-30 14:08 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-31 19:58 - 2014-07-28 17:13 - 00001436 _____ () C:\Windows\PFRO.log 2014-07-31 19:58 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-31 19:58 - 2006-11-02 14:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-31 19:58 - 2006-11-02 14:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-31 19:57 - 2006-11-02 15:01 - 00032606 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-31 19:56 - 2014-07-31 19:54 - 00000000 ____D () C:\AdwCleaner 2014-07-31 19:56 - 2009-04-14 19:10 - 00000000 ____D () C:\ProgramData\ICQ 2014-07-30 17:46 - 2014-07-30 17:45 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\***\Downloads\mbam-setup-2.0.2.1012(1).exe 2014-07-30 17:42 - 2014-06-29 00:40 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-30 17:39 - 2014-07-30 17:38 - 01016261 _____ (Thisisu) C:\Users\***\Downloads\JRT.exe 2014-07-30 17:38 - 2014-07-30 17:38 - 01365525 _____ () C:\Users\***\Downloads\adwcleaner_3.301.exe 2014-07-30 00:20 - 2014-02-09 16:18 - 00000000 ____D () C:\Users\***\AppData\Roaming\vlc 2014-07-29 17:17 - 2014-07-29 17:17 - 00010860 _____ () C:\ComboFix.txt 2014-07-29 17:17 - 2014-07-29 17:03 - 00000000 ____D () C:\Qoobox 2014-07-29 17:17 - 2014-07-29 17:03 - 00000000 ____D () C:\ComboFix 2014-07-29 17:17 - 2006-11-02 13:18 - 00000000 __RHD () C:\Users\Default 2014-07-29 17:17 - 2006-11-02 13:18 - 00000000 ___RD () C:\Users\Public 2014-07-29 17:15 - 2014-07-29 17:03 - 00000000 ____D () C:\Windows\erdnt 2014-07-29 17:14 - 2006-11-02 12:23 - 00000215 _____ () C:\Windows\system.ini 2014-07-29 16:57 - 2014-07-29 16:56 - 05563986 ____R (Swearware) C:\Users\****\Desktop\ComboFix.exe 2014-07-29 11:15 - 2009-02-23 03:59 - 00200704 _____ () C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-07-28 20:49 - 2014-07-28 20:48 - 00000000 ____D () C:\Users\***\Desktop\FRST 2014-07-28 20:40 - 2014-07-28 20:40 - 00000000 ____D () C:\Users\Mama\AppData\Roaming\ATI 2014-07-28 20:40 - 2014-07-28 20:40 - 00000000 ____D () C:\Users\Mama\AppData\Local\ATI 2014-07-28 20:39 - 2014-07-28 20:39 - 00086424 _____ () C:\Users\Mama\AppData\Local\GDIPFONTCACHEV1.DAT 2014-07-28 20:39 - 2014-07-28 20:39 - 00000954 _____ () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-07-28 20:39 - 2014-07-28 20:39 - 00000949 _____ () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2014-07-28 20:39 - 2014-07-28 20:38 - 00000000 ____D () C:\Users\Mama 2014-07-28 20:38 - 2014-07-28 20:38 - 00000998 __RSH () C:\Users\Mama\ntuser.pol 2014-07-28 20:38 - 2014-07-28 20:38 - 00000920 _____ () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk 2014-07-28 20:38 - 2014-07-28 20:38 - 00000020 ___SH () C:\Users\Mama\ntuser.ini 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Startmenü 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Netzwerkumgebung 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Druckumgebung 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Documents\Eigene Musik 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Documents\Eigene Bilder 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\AppData\Local\Verlauf 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 ____D () C:\Users\Mama\AppData\Local\VirtualStore 2014-07-28 20:16 - 2014-07-28 19:46 - 00170728 _____ () C:\Users\***\Desktop\Addition.txt 2014-07-28 19:57 - 2014-07-28 19:57 - 00000000 ____D () C:\Users\***\Desktop\Neuer Ordner 2014-07-28 19:56 - 2014-07-28 19:56 - 00170734 _____ () C:\Users\***\Desktop\Addition1.txt 2014-07-28 19:56 - 2014-07-28 19:56 - 00028447 _____ () C:\Users\***\Desktop\FRST1.txt 2014-07-28 17:25 - 2014-07-28 17:25 - 00000851 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-07-28 17:25 - 2013-07-04 01:23 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-07-28 17:25 - 2009-04-14 19:10 - 00000000 ____D () C:\Users\***\AppData\Roaming\Mozilla 2014-07-28 16:51 - 2014-07-28 16:50 - 32047680 _____ () C:\Users\***\Downloads\Firefox Setup 31.0.exe 2014-07-28 16:36 - 2014-07-28 16:32 - 32047680 _____ () C:\Users\***\Downloads\Firefox_Setup_de31.0.exe 2014-07-28 16:35 - 2014-07-28 16:33 - 32047680 _____ () C:\Users\***\Downloads\Firefox_Setup_de31.0(1).exe 2014-07-28 15:49 - 2009-06-29 20:24 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-07-28 06:26 - 2014-07-28 06:12 - 00010134 ____H () C:\Users\***\Desktop\~WRL0006.tmp 2014-07-19 18:40 - 2014-07-19 18:39 - 29677544 _____ (Mozilla) C:\Users\***\Downloads\Firefox Setup 30.0.exe 2014-07-19 01:31 - 2014-07-19 01:30 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\***\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-19 01:29 - 2014-07-19 01:24 - 91906368 _____ (AVAST Software) C:\Users\***\Downloads\avast_free_antivirus_setup_9.0.2021.exe 2014-07-19 01:28 - 2014-07-19 01:28 - 00512784 _____ (AVAST Software) C:\Users\***\Downloads\avastclear_9.0.2013.exe.part 2014-07-17 19:40 - 2014-07-17 19:38 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\***\Downloads\spybot-2.4.exe 2014-07-17 19:31 - 2014-07-17 19:31 - 01348263 _____ () C:\Users\***\Downloads\adwcleaner_3.215.exe 2014-07-17 19:23 - 2014-07-17 19:23 - 02953520 _____ (AVAST Software) C:\Users\***\Downloads\avast-browser-cleanup_9.0.0.224.exe 2014-07-17 17:08 - 2014-07-17 17:08 - 00131095 _____ () C:\Users\***\Downloads\***.de - Rücksendezentrum.htm 2014-07-02 13:31 - 2009-03-01 23:53 - 00007728 _____ () C:\Users\***\AppData\Local\d3d9caps.dat Some content of TEMP: ==================== C:\Users\***\AppData\Local\temp\catchme.dll C:\Users\***\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-31 20:06 ==================== End Of Log ============================ --- --- --- |
01.08.2014, 17:49 | #13 |
/// the machine /// TB-Ausbilder | Cross Scripting Verdacht und TrojanerfundeESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
02.08.2014, 16:42 | #14 |
| Cross Scripting Verdacht und Trojanerfunde Hier die Ergebnisse: Eset: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=375dc94da1bef640b74f24b951cc5533 # engine=19458 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-08-01 08:07:50 # local_time=2014-08-01 10:07:50 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode_1='avast! Antivirus' # compatibility_mode=777 16777213 100 100 26355968 183633541 0 0 # compatibility_mode_1='' # compatibility_mode=5892 16776574 100 100 336540 244456397 0 0 # scanned=188629 # found=1 # cleaned=0 # scan_time=7641 sh=EDCF4EA293DD0C7475D73797276FBE9E45EBBC29 ft=1 fh=51c8894478037c3d vn="Win32/Somoto.E evtl. unerwünschte Anwendung" ac=I fn="C:\Users\***\Downloads\m4a-to80-mp3-converter.exe" Code:
ATTFilter Results of screen317's Security Check version 0.99.85 Windows Vista Service Pack 2 x86 (UAC is enabled) Internet Explorer 9 Internet Explorer 8 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Spybot - Search & Destroy CCleaner Java(TM) 6 Update 20 Java 7 Update 51 Java(TM) 6 Update 6 Java version out of Date! Adobe Flash Player 12.0.0.43 Flash Player out of Date! Adobe Reader 10.1.10 Adobe Reader out of Date! Mozilla Firefox (31.0) ````````Process Check: objlist.exe by Laurent```````` system32 FirewallControlPanel.exe AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:31-07-2014 01 Ran by *** (administrator) on PAOLO on 02-08-2014 16:09:09 Running from C:\Users\***\Desktop Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (TOSHIBA CORPORATION) C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe (Toshiba Europe GmbH) C:\Program Files\Toshiba TEMPRO\TemproSvc.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\SMARTLogService\TosIPCSrv.exe (Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Safer Networking Ltd.) D:\Programm\Spybot - Search & Destroy\SDWinSec.exe (Toshiba) C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (TOSHIBA CORPORATION) C:\Program Files\Toshiba\ConfigFree\NDSTray.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\SmoothView\SmoothView.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Toshiba Europe GmbH) C:\Program Files\Toshiba TEMPRO\TemproTray.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (Elaborate Bytes AG) D:\Programm\VirtualCloneDrive\VCDDaemon.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (TOSHIBA CORPORATION) C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) Winlogon\Notify\igfxcui: igfxdev.dll [X] HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\Run: [SpybotSD TeaTimer] => D:\Programm\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-3147029616-3348592130-1442432417-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) GroupPolicyUsers\S-1-5-21-3147029616-3348592130-1442432417-1049\User: Group Policy restriction detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} SearchScopes: HKLM - {E5F4146A-5E91-4B00-A1AB-A498D2FBB078} URL = hxxp://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA; SearchScopes: HKCU - {E5F4146A-5E91-4B00-A1AB-A498D2FBB078} URL = hxxp://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA_de BHO: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> D:\Programm\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\+**\AppData\Roaming\Mozilla\Firefox\Profiles\9fyl39vc.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_43.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - D:\Programm\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 - D:\Programm\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Ghostery - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\9fyl39vc.default\Extensions\firefox@ghostery.com.xpi [2014-07-28] FF Extension: NoScript - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\9fyl39vc.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-07-28] FF Extension: Adblock Plus - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\9fyl39vc.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-07-28] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-04-27] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-08-10] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software) R2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [40960 2008-04-17] (TOSHIBA CORPORATION) [File not signed] S3 FirebirdServerMAGIXInstance; C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) [File not signed] S2 gupdate1c9c76df710d1a6; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-04-27] (Google Inc.) S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed] S3 jswpsapi; C:\Program Files\Jumpstart\jswpsapi.exe [937984 2007-10-30] (Atheros Communications, Inc.) [File not signed] S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [36352 2009-12-12] () [File not signed] R2 SBSDWSCService; D:\Programm\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) R3 SmartFaceVWatchSrv; C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe [73728 2008-04-24] (Toshiba) [File not signed] R2 TemproMonitoringService; C:\Program Files\Toshiba TEMPRO\TemproSvc.exe [116104 2009-07-21] (Toshiba Europe GmbH) R2 TOSHIBA SMART Log Service; C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [126976 2007-12-03] (TOSHIBA Corporation) [File not signed] R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-08-23] (Ulead Systems, Inc.) [File not signed] S2 TOSHIBA Bluetooth Service; c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 AFS; C:\Windows\system32\Drivers\AFS.sys [77004 2010-11-02] (Oak Technology Inc.) [File not signed] R2 aswFsBlk; C:\Windows\system32\Drivers\aswFsBlk.sys [29816 2013-08-30] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [66336 2013-08-30] (AVAST Software) R1 AswRdr; C:\Windows\system32\Drivers\AswRdr.sys [49760 2013-08-30] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49376 2013-08-30] () R1 aswSnx; C:\Windows\system32\Drivers\aswSnx.sys [770344 2013-08-30] (AVAST Software) R1 aswSP; C:\Windows\system32\Drivers\aswSP.sys [369584 2013-08-30] (AVAST Software) R1 aswTdi; C:\Windows\system32\Drivers\aswTdi.sys [56080 2013-08-30] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [177864 2013-08-30] () R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [30616 2013-03-04] (Elaborate Bytes AG) R0 Lbd; C:\Windows\System32\DRIVERS\Lbd.sys [64288 2010-12-03] (Lavasoft AB) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [320120 2014-06-29] (Duplex Secure Ltd.) R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [25984 2009-12-12] (The OpenVPN Project) R3 UVCFTR; C:\Windows\System32\Drivers\UVCFTR_S.SYS [18432 2007-12-17] (Chicony Electronics Co., Ltd.) R3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [22792 2009-09-11] (Logitech Inc.) S3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [35592 2009-09-11] (Logitech Inc.) R3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [14984 2009-09-11] (Logitech Inc.) R3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [66056 2009-09-11] (Logitech Inc.) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S3 catchme; \??\C:\Users\***\AppData\Local\Temp\catchme.sys [X] S3 igfx; system32\DRIVERS\igdkmd32.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 Lavasoft Kernexplorer; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [X] S3 massfilter; system32\drivers\massfilter.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 Tosrfcom; No ImagePath S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-01 22:14 - 2014-08-01 22:14 - 00001070 _____ () C:\Users\***\Desktop\checkup.txt 2014-08-01 19:54 - 2014-08-01 19:54 - 00000000 ____D () C:\Program Files\ESET 2014-08-01 19:33 - 2014-08-01 19:34 - 00854390 _____ () C:\Users\***\Desktop\SecurityCheck.exe 2014-08-01 19:33 - 2014-08-01 19:33 - 02347384 _____ (ESET) C:\Users\***\Downloads\esetsmartinstaller_deu.exe 2014-07-31 21:06 - 2014-07-31 21:15 - 00029782 _____ () C:\Users\***\Desktop\FRST2.txt 2014-07-31 21:05 - 2014-07-31 21:05 - 00000000 ____D () C:\Users\***\Desktop\FRST-OlderVersion 2014-07-31 20:09 - 2014-07-31 20:13 - 00000632 _____ () C:\Users\***\Desktop\JRT.txt 2014-07-31 20:04 - 2014-07-31 20:04 - 00002406 _____ () C:\Users\***\Desktop\AdwCleaner[S0].txt 2014-07-31 20:04 - 2014-07-31 20:04 - 00000000 ____D () C:\Windows\ERUNT 2014-07-31 19:54 - 2014-07-31 19:56 - 00000000 ____D () C:\AdwCleaner 2014-07-30 17:45 - 2014-07-30 17:46 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\***\Downloads\mbam-setup-2.0.2.1012(1).exe 2014-07-30 17:38 - 2014-07-30 17:39 - 01016261 _____ (Thisisu) C:\Users\***\Downloads\JRT.exe 2014-07-30 17:38 - 2014-07-30 17:38 - 01365525 _____ () C:\Users\***\Downloads\adwcleaner_3.301.exe 2014-07-29 17:17 - 2014-07-29 17:17 - 00010860 _____ () C:\ComboFix.txt 2014-07-29 17:03 - 2014-07-29 17:17 - 00000000 ____D () C:\Qoobox 2014-07-29 17:03 - 2014-07-29 17:17 - 00000000 ____D () C:\ComboFix 2014-07-29 17:03 - 2014-07-29 17:15 - 00000000 ____D () C:\Windows\erdnt 2014-07-29 17:03 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-07-29 17:03 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-07-29 17:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-07-29 17:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-07-29 17:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-07-29 17:03 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-07-29 17:03 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-07-29 17:03 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-07-29 16:56 - 2014-07-29 16:57 - 05563986 ____R (Swearware) C:\Users\***\Desktop\ComboFix.exe 2014-07-28 20:48 - 2014-07-28 20:49 - 00000000 ____D () C:\Users\***\Desktop\FRST 2014-07-28 20:40 - 2014-07-28 20:40 - 00000000 ____D () C:\Users\Mama\AppData\Roaming\ATI 2014-07-28 20:40 - 2014-07-28 20:40 - 00000000 ____D () C:\Users\Mama\AppData\Local\ATI 2014-07-28 20:39 - 2014-07-28 20:39 - 00086424 _____ () C:\Users\Mama\AppData\Local\GDIPFONTCACHEV1.DAT 2014-07-28 20:39 - 2014-07-28 20:39 - 00000954 _____ () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-07-28 20:39 - 2014-07-28 20:39 - 00000949 _____ () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2014-07-28 20:38 - 2014-07-28 20:39 - 00000000 ____D () C:\Users\Mama 2014-07-28 20:38 - 2014-07-28 20:38 - 00000998 __RSH () C:\Users\Mama\ntuser.pol 2014-07-28 20:38 - 2014-07-28 20:38 - 00000920 _____ () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk 2014-07-28 20:38 - 2014-07-28 20:38 - 00000020 ___SH () C:\Users\Mama\ntuser.ini 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Startmenü 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Netzwerkumgebung 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Druckumgebung 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Documents\Eigene Musik 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Documents\Eigene Bilder 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\AppData\Local\Verlauf 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 ____D () C:\Users\Mama\AppData\Local\VirtualStore 2014-07-28 20:38 - 2012-10-03 16:32 - 00000000 ____D () C:\Users\Mama\AppData\Local\Microsoft Help 2014-07-28 20:38 - 2008-01-21 04:42 - 00000000 ___RD () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-07-28 20:38 - 2008-01-21 04:42 - 00000000 ___RD () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-07-28 19:57 - 2014-07-28 19:57 - 00000000 ____D () C:\Users\***\Desktop\Neuer Ordner 2014-07-28 19:56 - 2014-07-28 19:56 - 00170734 _____ () C:\Users\***\Desktop\Addition1.txt 2014-07-28 19:56 - 2014-07-28 19:56 - 00028447 _____ () C:\Users\***\Desktop\FRST1.txt 2014-07-28 19:46 - 2014-07-28 20:16 - 00170728 _____ () C:\Users\***\Desktop\Addition.txt 2014-07-28 19:45 - 2014-08-02 16:09 - 00015762 _____ () C:\Users\***\Desktop\FRST.txt 2014-07-28 19:45 - 2014-08-02 16:09 - 00000000 ____D () C:\FRST 2014-07-28 19:44 - 2014-07-31 21:05 - 01084928 _____ (Farbar) C:\Users\***\Desktop\FRST.exe 2014-07-28 17:25 - 2014-07-28 17:25 - 00000851 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-07-28 17:13 - 2014-07-31 19:58 - 00001436 _____ () C:\Windows\PFRO.log 2014-07-28 16:50 - 2014-07-28 16:51 - 32047680 _____ () C:\Users\***\Downloads\Firefox Setup 31.0.exe 2014-07-28 16:33 - 2014-07-28 16:35 - 32047680 _____ () C:\Users\***\Downloads\Firefox_Setup_de31.0(1).exe 2014-07-28 16:32 - 2014-07-28 16:36 - 32047680 _____ () C:\Users\***\Downloads\Firefox_Setup_de31.0.exe 2014-07-28 06:12 - 2014-07-28 06:26 - 00010134 ____H () C:\Users\***\Desktop\~WRL0006.tmp 2014-07-19 18:39 - 2014-07-19 18:40 - 29677544 _____ (Mozilla) C:\Users\***\Downloads\Firefox Setup 30.0.exe 2014-07-19 01:30 - 2014-07-19 01:31 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\***\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-19 01:28 - 2014-07-19 01:28 - 00512784 _____ (AVAST Software) C:\Users\***\Downloads\avastclear_9.0.2013.exe.part 2014-07-19 01:24 - 2014-07-19 01:29 - 91906368 _____ (AVAST Software) C:\Users\***\Downloads\avast_free_antivirus_setup_9.0.2021.exe 2014-07-17 19:38 - 2014-07-17 19:40 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\***\Downloads\spybot-2.4.exe 2014-07-17 19:31 - 2014-07-17 19:31 - 01348263 _____ () C:\Users\***\Downloads\adwcleaner_3.215.exe 2014-07-17 19:23 - 2014-07-17 19:23 - 02953520 _____ (AVAST Software) C:\Users\***\Downloads\avast-browser-cleanup_9.0.0.224.exe 2014-07-17 17:08 - 2014-07-17 17:08 - 00131095 _____ () C:\Users\***\Downloads\***.de - Rücksendezentrum.htm ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-02 16:09 - 2014-07-28 19:45 - 00015762 _____ () C:\Users\***\Desktop\FRST.txt 2014-08-02 16:09 - 2014-07-28 19:45 - 00000000 ____D () C:\FRST 2014-08-02 16:06 - 2009-06-30 14:08 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-08-02 15:30 - 2006-11-02 14:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-02 15:30 - 2006-11-02 14:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-02 12:12 - 2009-02-20 19:59 - 01387845 _____ () C:\Windows\WindowsUpdate.log 2014-08-02 09:44 - 2014-06-29 00:40 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-02 02:05 - 2009-06-30 14:08 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-08-01 22:14 - 2014-08-01 22:14 - 00001070 _____ () C:\Users\***\Desktop\checkup.txt 2014-08-01 19:54 - 2014-08-01 19:54 - 00000000 ____D () C:\Program Files\ESET 2014-08-01 19:47 - 2008-01-21 09:16 - 01600466 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-08-01 19:34 - 2014-08-01 19:33 - 00854390 _____ () C:\Users\***\Desktop\SecurityCheck.exe 2014-08-01 19:33 - 2014-08-01 19:33 - 02347384 _____ (ESET) C:\Users\***\Downloads\esetsmartinstaller_deu.exe 2014-08-01 19:30 - 2009-03-01 23:53 - 00007728 _____ () C:\Users\***\AppData\Local\d3d9caps.dat 2014-08-01 14:59 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-31 23:15 - 2006-11-02 15:01 - 00032606 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-31 21:15 - 2014-07-31 21:06 - 00029782 _____ () C:\Users\***\Desktop\FRST2.txt 2014-07-31 21:05 - 2014-07-31 21:05 - 00000000 ____D () C:\Users\***\Desktop\FRST-OlderVersion 2014-07-31 21:05 - 2014-07-28 19:44 - 01084928 _____ (Farbar) C:\Users\***\Desktop\FRST.exe 2014-07-31 20:13 - 2014-07-31 20:09 - 00000632 _____ () C:\Users\***\Desktop\JRT.txt 2014-07-31 20:04 - 2014-07-31 20:04 - 00002406 _____ () C:\Users\***\Desktop\AdwCleaner[S0].txt 2014-07-31 20:04 - 2014-07-31 20:04 - 00000000 ____D () C:\Windows\ERUNT 2014-07-31 19:58 - 2014-07-28 17:13 - 00001436 _____ () C:\Windows\PFRO.log 2014-07-31 19:56 - 2014-07-31 19:54 - 00000000 ____D () C:\AdwCleaner 2014-07-31 19:56 - 2009-04-14 19:10 - 00000000 ____D () C:\ProgramData\ICQ 2014-07-30 17:46 - 2014-07-30 17:45 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\***\Downloads\mbam-setup-2.0.2.1012(1).exe 2014-07-30 17:39 - 2014-07-30 17:38 - 01016261 _____ (Thisisu) C:\Users\***\Downloads\JRT.exe 2014-07-30 17:38 - 2014-07-30 17:38 - 01365525 _____ () C:\Users\***\Downloads\adwcleaner_3.301.exe 2014-07-30 00:20 - 2014-02-09 16:18 - 00000000 ____D () C:\Users\***\AppData\Roaming\vlc 2014-07-29 17:17 - 2014-07-29 17:17 - 00010860 _____ () C:\ComboFix.txt 2014-07-29 17:17 - 2014-07-29 17:03 - 00000000 ____D () C:\Qoobox 2014-07-29 17:17 - 2014-07-29 17:03 - 00000000 ____D () C:\ComboFix 2014-07-29 17:17 - 2006-11-02 13:18 - 00000000 __RHD () C:\Users\Default 2014-07-29 17:17 - 2006-11-02 13:18 - 00000000 ___RD () C:\Users\Public 2014-07-29 17:15 - 2014-07-29 17:03 - 00000000 ____D () C:\Windows\erdnt 2014-07-29 17:14 - 2006-11-02 12:23 - 00000215 _____ () C:\Windows\system.ini 2014-07-29 16:57 - 2014-07-29 16:56 - 05563986 ____R (Swearware) C:\Users\***\Desktop\ComboFix.exe 2014-07-29 11:15 - 2009-02-23 03:59 - 00200704 _____ () C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-07-28 20:49 - 2014-07-28 20:48 - 00000000 ____D () C:\Users\***\Desktop\FRST 2014-07-28 20:40 - 2014-07-28 20:40 - 00000000 ____D () C:\Users\Mama\AppData\Roaming\ATI 2014-07-28 20:40 - 2014-07-28 20:40 - 00000000 ____D () C:\Users\Mama\AppData\Local\ATI 2014-07-28 20:39 - 2014-07-28 20:39 - 00086424 _____ () C:\Users\Mama\AppData\Local\GDIPFONTCACHEV1.DAT 2014-07-28 20:39 - 2014-07-28 20:39 - 00000954 _____ () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-07-28 20:39 - 2014-07-28 20:39 - 00000949 _____ () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2014-07-28 20:39 - 2014-07-28 20:38 - 00000000 ____D () C:\Users\Mama 2014-07-28 20:38 - 2014-07-28 20:38 - 00000998 __RSH () C:\Users\Mama\ntuser.pol 2014-07-28 20:38 - 2014-07-28 20:38 - 00000920 _____ () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk 2014-07-28 20:38 - 2014-07-28 20:38 - 00000020 ___SH () C:\Users\Mama\ntuser.ini 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Startmenü 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Netzwerkumgebung 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Druckumgebung 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Documents\Eigene Musik 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\Documents\Eigene Bilder 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 _SHDL () C:\Users\Mama\AppData\Local\Verlauf 2014-07-28 20:38 - 2014-07-28 20:38 - 00000000 ____D () C:\Users\Mama\AppData\Local\VirtualStore 2014-07-28 20:16 - 2014-07-28 19:46 - 00170728 _____ () C:\Users\***\Desktop\Addition.txt 2014-07-28 19:57 - 2014-07-28 19:57 - 00000000 ____D () C:\Users\***\Desktop\Neuer Ordner 2014-07-28 19:56 - 2014-07-28 19:56 - 00170734 _____ () C:\Users\***\Desktop\Addition1.txt 2014-07-28 19:56 - 2014-07-28 19:56 - 00028447 _____ () C:\Users\***\Desktop\FRST1.txt 2014-07-28 17:25 - 2014-07-28 17:25 - 00000851 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-07-28 17:25 - 2013-07-04 01:23 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-07-28 17:25 - 2009-04-14 19:10 - 00000000 ____D () C:\Users\***\AppData\Roaming\Mozilla 2014-07-28 16:51 - 2014-07-28 16:50 - 32047680 _____ () C:\Users\***\Downloads\Firefox Setup 31.0.exe 2014-07-28 16:36 - 2014-07-28 16:32 - 32047680 _____ () C:\Users\***\Downloads\Firefox_Setup_de31.0.exe 2014-07-28 16:35 - 2014-07-28 16:33 - 32047680 _____ () C:\Users\***\Downloads\Firefox_Setup_de31.0(1).exe 2014-07-28 15:49 - 2009-06-29 20:24 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-07-28 06:26 - 2014-07-28 06:12 - 00010134 ____H () C:\Users\***\Desktop\~WRL0006.tmp 2014-07-19 18:40 - 2014-07-19 18:39 - 29677544 _____ (Mozilla) C:\Users\***\Downloads\Firefox Setup 30.0.exe 2014-07-19 01:31 - 2014-07-19 01:30 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\***\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-19 01:29 - 2014-07-19 01:24 - 91906368 _____ (AVAST Software) C:\Users\***\Downloads\avast_free_antivirus_setup_9.0.2021.exe 2014-07-19 01:28 - 2014-07-19 01:28 - 00512784 _____ (AVAST Software) C:\Users\***\Downloads\avastclear_9.0.2013.exe.part 2014-07-17 19:40 - 2014-07-17 19:38 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\***\Downloads\spybot-2.4.exe 2014-07-17 19:31 - 2014-07-17 19:31 - 01348263 _____ () C:\Users\***\Downloads\adwcleaner_3.215.exe 2014-07-17 19:23 - 2014-07-17 19:23 - 02953520 _____ (AVAST Software) C:\Users\***\Downloads\avast-browser-cleanup_9.0.0.224.exe 2014-07-17 17:08 - 2014-07-17 17:08 - 00131095 _____ () C:\Users\***\Downloads\***de - Rücksendezentrum.htm Some content of TEMP: ==================== C:\Users\***\AppData\Local\temp\catchme.dll C:\Users\***\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-02 15:11 ==================== End Of Log ============================ Probleme kann ich jetzt direkt keine erkennen, vom Eset-Fund mal abgesehen. Ist allerdings schwer zu sagen, weil sich der PC auch vorher nicht besonders auffällig verhalten hat, wenn man von der Cross Scripting Sache mal absieht. Da hatte ich jedenfalls keine Meldung mehr. Ein paar Fragen hätte ich aber noch die ich frecherweise einfach mal stelle : Ich habe gestern festgestellt, dass unter Sicherheit bei beinahe allen Verknüpfungen (abgesehen von dreien die relativ alt sind) auf meinem Desktop ein unbekanntes Benutzerkonto aufgeführt wird (mit der Endung -500 also wohl ein Admin Konto). Wollte fragen ob das mit der Bereinigung zusammenhängen kann oder ob da irgendwas im argen ist/war? Dass das über eine Systemwiederherstellung von meiner Seite oder einen gelöschten Benutzer kam, kann ich auschließen. Einige von den Veknüpfungen sind nämlich noch relativ neu und in letzter Zeit hab ich nichts dergleichen gemacht. Seit wann das Benutzerkonto da drin ist kann ich leider nicht sagen, hab das eh mehr durch Zufall gesehen . Was genau war/ist auf meinem PC denn nun eigentlich los? Hatte sich da schon länger irgendwas eingenistet ohne, dass ichs bemerkt habe bzw. wie dramatisch war das nun eigentlich? Dann noch eine grundsätzliche Frage für die zukünftige Sicherheit: Ist es auch möglich, dass sich irgendwelche Sachen über einen gemeinsamen Internetanschluss einschleichen ?(wenn der Router auf einem anderen PC eingerichtet ist). So das wars erstmal mit dummen Fragen Danke soweit für die Hilfe und Geduld und Schöne Grüße |
03.08.2014, 06:58 | #15 |
/// the machine /// TB-Ausbilder | Cross Scripting Verdacht und Trojanerfunde Java, Flash und Adobe updaten. Zeig mir mal bitte einen Screenshot von dem Konto.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Cross Scripting Verdacht und Trojanerfunde |
administrator, anti-malware, autostart, avast, blockiert, browser, dateien, e-mail, ergebnis, explorer, fehlalarm, firefox, gelöscht, icq, infiziert, installation, logfile, löschen, malwarebytes, modem, nicht mehr, ordner, system, vista, windows |