Carsten1502 | 11.10.2013 10:10 | Hi, hier das ComboFix Logfile: Code:
ComboFix 13-10-09.01 - Administrator 11.10.2013 10:43:41.1.1 - x86
Microsoft Windows 8 Pro 6.2.9200.0.1252.49.1031.18.1535.549 [GMT 2:00]
ausgeführt von:: c:\users\Administrator\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\IsUn0407.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-09-11 bis 2013-10-11 ))))))))))))))))))))))))))))))
.
.
2013-10-11 09:02 . 2013-10-11 09:02 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-10-10 16:54 . 2013-10-10 16:54 -------- d-----w- C:\FRST
2013-10-10 16:18 . 2013-10-11 07:07 -------- d-----w- c:\users\Administrator\AppData\Local\FreePDF_XP
2013-10-10 15:41 . 2013-10-10 17:58 -------- d-----w- c:\users\Administrator\AppData\Local\CrashDumps
2013-10-10 15:41 . 2013-10-10 15:41 -------- d-----w- c:\users\Administrator\AppData\Roaming\OpenOffice
2013-10-09 17:19 . 2013-10-09 17:19 -------- d-----w- c:\users\Administrator\AppData\Local\Programs
2013-10-09 16:10 . 2013-07-09 02:50 85760 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2013-10-09 16:09 . 2013-07-01 22:15 36864 ----a-w- c:\windows\system32\drivers\usbscan.sys
2013-10-09 16:09 . 2013-07-01 22:15 18944 ----a-w- c:\windows\system32\drivers\usbprint.sys
2013-10-09 16:09 . 2013-06-29 02:32 26496 ----a-w- c:\windows\system32\drivers\hidparse.sys
2013-10-09 16:09 . 2013-06-29 02:31 61440 ----a-w- c:\windows\system32\drivers\hidclass.sys
2013-10-09 16:09 . 2013-07-19 22:13 102608 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-05 11:50 . 2013-10-05 11:50 -------- d-----w- c:\users\Carsten\AppData\Roaming\AVG
2013-10-05 11:42 . 2013-10-05 11:42 -------- d-----w- c:\users\Administrator\AppData\Roaming\AVG
2013-10-05 11:41 . 2013-10-05 11:43 -------- d-----w- c:\programdata\AVG
2013-10-05 11:41 . 2013-10-05 11:41 -------- d-sh--w- c:\programdata\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-10-05 09:22 . 2013-10-05 09:22 -------- d-----w- c:\windows\ServiceProfiles\LocalService\winhttp
2013-10-03 21:01 . 2013-10-03 21:01 -------- d-----w- c:\users\Carsten\AppData\Local\Clipboarder
2013-10-03 20:59 . 2013-10-03 21:02 -------- d-----w- c:\users\Carsten\AppData\Local\Sidebar7
2013-10-03 20:57 . 2012-05-19 04:43 1144832 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
2013-10-03 20:57 . 2012-05-19 04:41 77824 ----a-w- c:\program files\Windows Sidebar\sbdrop.dll
2013-10-03 20:57 . 2006-11-02 15:03 63488 ----a-w- c:\program files\Windows Sidebar\wlsrvc.dll
2013-10-03 20:57 . 2013-05-04 10:18 46080 ----a-w- c:\program files\Windows Sidebar\dwmapi.dll
2013-10-03 07:54 . 2013-10-03 07:54 -------- d-----w- c:\programdata\Malwarebytes
2013-10-03 07:53 . 2013-10-03 09:06 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2013-10-03 07:43 . 2013-10-10 16:04 -------- d-----w- C:\AdwCleaner
2013-09-25 07:30 . 2013-09-25 07:30 -------- d-----w- c:\users\Administrator\AppData\Roaming\FreeFLVConverter
2013-09-25 06:56 . 2013-09-25 21:27 -------- d-----w- c:\users\Carsten\AppData\Local\CrashDumps
2013-09-25 06:55 . 2013-09-25 06:55 -------- d-----w- c:\users\Carsten\AppData\Roaming\DivX
2013-09-24 19:32 . 2013-09-25 08:26 -------- d-----w- c:\program files\Common Files\DivX Shared
2013-09-21 10:24 . 2013-09-21 10:25 -------- d-----w- c:\program files\Google
2013-09-19 08:10 . 2013-09-18 23:26 78296 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-19 08:10 . 2013-09-18 23:26 694232 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-19 07:37 . 2013-08-03 04:17 3390464 ----a-w- c:\windows\system32\win32k.sys
2013-09-19 07:37 . 2013-08-21 02:05 2876928 ----a-w- c:\windows\system32\jscript9.dll
2013-09-19 07:37 . 2013-08-21 02:36 770648 ----a-w- c:\program files\Internet Explorer\iexplore.exe
2013-09-19 07:37 . 2013-08-21 02:06 1767936 ----a-w- c:\windows\system32\wininet.dll
2013-09-19 07:37 . 2013-08-21 02:06 817664 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-09-19 07:37 . 2013-08-21 02:06 661504 ----a-w- c:\windows\system32\uxtheme.dll
2013-09-19 07:37 . 2013-08-21 02:05 109056 ----a-w- c:\windows\system32\iesysprep.dll
2013-09-19 07:36 . 2013-08-21 02:06 44032 ----a-w- c:\windows\system32\UXInit.dll
2013-09-19 07:36 . 2013-08-21 02:05 108032 ----a-w- c:\program files\Internet Explorer\jsdebuggeride.dll
2013-09-19 07:36 . 2013-08-21 02:05 61440 ----a-w- c:\windows\system32\iesetup.dll
2013-09-19 07:36 . 2013-08-21 02:05 257536 ----a-w- c:\program files\Internet Explorer\ieproxy.dll
2013-09-19 07:36 . 2013-08-21 02:05 236032 ----a-w- c:\program files\Internet Explorer\IEShims.dll
2013-09-19 07:36 . 2013-08-21 01:43 2706432 ----a-w- c:\windows\system32\mshtml.tlb
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-19 08:16 . 2013-05-06 11:41 65632 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-09-19 08:16 . 2013-03-17 09:29 88840 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-09-19 08:16 . 2013-03-17 09:29 136672 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-07-18 10:14 . 2013-07-18 10:14 74703 ----a-w- c:\windows\system32\mfc45.dat
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShareOverlay]
@="{594D4122-1F87-41E2-96C7-825FB4796516}"
[HKEY_CLASSES_ROOT\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516}]
2013-06-29 08:49 594432 ----a-w- c:\program files\Classic Shell\ClassicExplorer32.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2009-04-14 604704]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-09-19 347192]
"FreePDF Assistant"="c:\program files\FreePDF_XP\fpassist.exe" [2013-03-14 373760]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2012-09-25 1163264]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"SAOB Monitor"="c:\program files\Acronis\TrueImageHome\OnlineBackupStandalone\TrueImageMonitor.exe" [2011-09-22 2571032]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2011-09-22 5587832]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2011-09-22 395344]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
c:\users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
FRITZ!DSL Internet.lnk - c:\program files\FRITZ!DSL\FritzDsl.exe [2009-7-27 987960]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\StartUp\
HotSync Manager.lnk - c:\programs~1\Palm\hotsync.exe [2013-4-21 263680]
Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2013-7-3 563416]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableCursorSuppression"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /m /P \Device\HarddiskVolume8\0autocheck autochk *
.
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-02-28 161384]
R3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
S0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);c:\windows\system32\DRIVERS\tdrpm273.sys [2013-04-21 752128]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-04-02 37352]
S1 NEOFLTR_730_22751;Juniper Networks TDI Filter Driver (NEOFLTR_730_22751);c:\windows\system32\Drivers\NEOFLTR_730_22751.SYS [2012-11-23 91824]
S2 afcdpsrv;Acronis Nonstop Backup-Dienst;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [2013-04-21 3246040]
S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2013-09-19 84024]
S2 IGDCTRL;AVM IGD CTRL Service;c:\program files\FRITZ!DSL\IGDCTRL.EXE [2009-07-28 73528]
S2 JuniperAccessService;Juniper Unified Network Service;c:\program files\Common Files\Juniper Networks\JUNS\dsAccessService.exe [2013-03-27 167464]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\PSIA.exe [2013-07-03 1228504]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files\Secunia\PSI\sua.exe [2013-07-03 660184]
S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [2013-04-21 167968]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf_x86.sys [2013-07-03 16024]
.
.
Inhalt des "geplante Tasks" Ordners
.
2013-10-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-17 18:49]
.
2013-10-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-09-21 10:24]
.
2013-10-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-09-21 10:24]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://microsoft.com/update
TCP: DhcpNameServer = 192.168.178.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM-Run-DivXMediaServer - c:\program files\DivX\DivX Media Server\DivXMediaServer.exe
HKU-Default-Run-FRITZ!protect - FwebProt.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (Administrator)
"{553891B7-A0D5-4526-BE18-D3CE461D6310}"=hex:51,66,7a,6c,4c,1d,3b,1b,a7,8e,2b,
4a,e3,f1,4a,08,a1,14,96,8e,4e,5d,2f,0e
"{449D0D6E-2412-4E61-B68F-1CB625CD9E52}"=hex:51,66,7a,6c,4c,1d,3b,1b,7e,12,8e,
5b,24,75,0d,03,a9,83,59,f6,2d,8d,d2,4c
"{EA801577-E6AD-4BD5-8F71-4BE0154331A4}"=hex:51,66,7a,6c,4c,1d,3b,1b,67,0a,93,
f5,9b,b7,b9,06,90,7d,0e,a0,1d,03,7d,ba
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,3b,1b,ab,88,07,
69,c6,87,40,0b,a9,e7,91,9a,f9,99,61,5d
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,3b,1b,54,1f,db,
c4,73,f5,37,0e,a3,78,d9,65,c9,85,c4,b7
"{AE48ED75-5A56-4C5F-BBCE-6F1AC3875F66}"=hex:51,66,7a,6c,4c,1d,3b,1b,65,f2,5b,
b1,60,0b,33,01,a4,c2,2a,5a,cb,c7,13,78
"{C728ECCB-7A57-4AFF-AB17-6434AFF18F49}"=hex:51,66,7a,6c,4c,1d,3b,1b,db,f3,3b,
d8,61,2b,93,07,b4,1b,21,74,a7,b1,c3,57
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (Administrator)
"Timestamp"=hex:39,25,67,d4,aa,a4,ce,01
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,08,76,96,85,6e,34,d1,41,91,9c,50,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,08,76,96,85,6e,34,d1,41,91,9c,50,\
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\UserChoice]
@Denied: (2) (Administrator)
"Hash"="6toF4FqZ9CI="
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\UserChoice]
@Denied: (2) (Administrator)
"Hash"="PENBi4/633I="
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2\UserChoice]
@Denied: (2) (Administrator)
"Hash"="Gbx0bTR0BVs="
"ProgId"="WMP11.AssocFile.3G2"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp\UserChoice]
@Denied: (2) (Administrator)
"Hash"="GYrmpQMOP+Y="
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac\UserChoice]
@Denied: (2) (Administrator)
"Hash"="sNfaFMPswMg="
"ProgId"="AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.adt\UserChoice]
@Denied: (2) (Administrator)
"Hash"="lOS1kV0iZc8="
"ProgId"="WMP11.AssocFile.ADTS"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.adts\UserChoice]
@Denied: (2) (Administrator)
"Hash"="tWuP4W8cuzA="
"ProgId"="WMP11.AssocFile.ADTS"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice]
@Denied: (2) (Administrator)
"Hash"="Y+GYvvzmVtg="
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
@Denied: (2) (Administrator)
"Hash"="3zw++lE9gfk="
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice]
@Denied: (2) (Administrator)
"Hash"="nNB/hESlJqA="
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice]
@Denied: (2) (Administrator)
"Hash"="Mjd93FQyJuE="
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice]
@Denied: (2) (Administrator)
"Hash"="Qsqw9+lB7+c="
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice]
@Denied: (2) (Administrator)
"Hash"="XimINgjzheE="
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice]
@Denied: (2) (Administrator)
"Hash"="jVkV5N4flkc="
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice]
@Denied: (2) (Administrator)
"Hash"="Q43d//z4GJE="
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice]
@Denied: (2) (Administrator)
"Hash"="T4kVKaqD2TY="
"ProgId"="AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\UserChoice]
@Denied: (2) (Administrator)
"Hash"="zFTOpjCdRe0="
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\UserChoice]
@Denied: (2) (Administrator)
"Hash"="ygc12GkfUyM="
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MP2\UserChoice]
@Denied: (2) (Administrator)
"Hash"="BoCc9hSnf6g="
"ProgId"="WMP11.AssocFile.MP3"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (Administrator)
"Hash"="tIs40EPTE/E="
"ProgId"="AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice]
@Denied: (2) (Administrator)
"Hash"="SAuo/NMMfkE="
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4v\UserChoice]
@Denied: (2) (Administrator)
"Hash"="E8Xf3VahEQg="
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice]
@Denied: (2) (Administrator)
"Hash"="y3Xlbm4G4A0="
"ProgId"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MPE\UserChoice]
@Denied: (2) (Administrator)
"Hash"="Z9Pg95vE0+4="
"ProgId"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice]
@Denied: (2) (Administrator)
"Hash"="ZsBXokkrRz4="
"ProgId"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice]
@Denied: (2) (Administrator)
"Hash"="aGYz+ivP88g="
"ProgId"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mts\UserChoice]
@Denied: (2) (Administrator)
"Hash"="WtXPuo2Uo8g="
"ProgId"="WMP11.AssocFile.M2TS"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.oxps\UserChoice]
@Denied: (2) (Administrator)
"Hash"="t7DSZYJcJ0g="
"ProgId"="AppX86746z2101ayy2ygv3g96e4eqdf8r99j"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\UserChoice]
@Denied: (2) (Administrator)
"Hash"="9ee2/uL+6GA="
"ProgId"="AppX86746z2101ayy2ygv3g96e4eqdf8r99j"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice]
@Denied: (2) (Administrator)
"Hash"="EKznZ39alrU="
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice]
@Denied: (2) (Administrator)
"Hash"="xh0oADlMDRk="
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice]
@Denied: (2) (Administrator)
"Hash"="K3TC5Hcup7g="
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TS\UserChoice]
@Denied: (2) (Administrator)
"Hash"="Vnjwt420kPE="
"ProgId"="WMP11.AssocFile.TTS"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TTS\UserChoice]
@Denied: (2) (Administrator)
"Hash"="PR1n3VYLG3U="
"ProgId"="WMP11.AssocFile.TTS"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\UserChoice]
@Denied: (2) (Administrator)
"Hash"="FEGYwgFYcwA="
"ProgId"="txtfile"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (Administrator)
"Hash"="bal60haK06g="
"ProgId"="AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wdp\UserChoice]
@Denied: (2) (Administrator)
"Hash"="5LWAzGMYi50="
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice]
@Denied: (2) (Administrator)
"Hash"="t+tPu5hmIvM="
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (Administrator)
"Hash"="WbCGh8AwleU="
"ProgId"="AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice]
@Denied: (2) (Administrator)
"Hash"="fc7eDj1nWBM="
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.WPL\UserChoice]
@Denied: (2) (Administrator)
"Hash"="SLtgDthwfK0="
"ProgId"="WMP11.AssocFile.WPL"
.
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xps\UserChoice]
@Denied: (2) (Administrator)
"Hash"="aw3DZsPuq5Y="
"ProgId"="AppX86746z2101ayy2ygv3g96e4eqdf8r99j"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
Zeit der Fertigstellung: 2013-10-11 11:05:24
ComboFix-quarantined-files.txt 2013-10-11 09:05
.
Vor Suchlauf: 15 Verzeichnis(se), 49.872.261.120 Bytes frei
Nach Suchlauf: 20 Verzeichnis(se), 49.847.197.696 Bytes frei
.
- - End Of File - - 2EC61E2F5F652385E37C255637136B07
72B8CE41AF0DE751C946802B3ED844B4
Gruß
Carsten |