Hallo,
hier die Datei: Code:
ComboFix 13-10-12.01 - Sara 13.10.2013 13:16:46.1.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.4061.2418 [GMT 2:00]
ausgeführt von:: c:\users\Sara\Desktop\ComboFix.exe
AV: Bitdefender Virenschutz *Disabled/Updated* {9B5F5313-CAF9-DD97-C460-E778420237B4}
FW: Bitdefender Firewall *Disabled* {A364D236-8096-DCCF-EF3F-4E4DBCD170CF}
SP: Bitdefender Spyware-Schutz *Disabled/Updated* {203EB2F7-ECC3-D219-FED0-DC0A39857D09}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\program files (x86)\Google\Desktop\Install
c:\program files (x86)\Google\Desktop\Install\{75bccb62-0f3a-bb56-4f18-dbed6fca6ce8}\9519~1\A535~1\E628~1\{75bccb62-0f3a-bb56-4f18-dbed6fca6ce8}\@
c:\program files (x86)\Google\Desktop\Install\{75bccb62-0f3a-bb56-4f18-dbed6fca6ce8}\9519~1\A535~1\E628~1\{75bccb62-0f3a-bb56-4f18-dbed6fca6ce8}\L\00000004.@
c:\program files (x86)\Google\Desktop\Install\{75bccb62-0f3a-bb56-4f18-dbed6fca6ce8}\9519~1\A535~1\E628~1\{75bccb62-0f3a-bb56-4f18-dbed6fca6ce8}\L\201d3dde
c:\program files (x86)\Google\Desktop\Install\{75bccb62-0f3a-bb56-4f18-dbed6fca6ce8}\9519~1\A535~1\E628~1\{75bccb62-0f3a-bb56-4f18-dbed6fca6ce8}\L\6715e287
c:\program files (x86)\Google\Desktop\Install\{75bccb62-0f3a-bb56-4f18-dbed6fca6ce8}\9519~1\A535~1\E628~1\{75bccb62-0f3a-bb56-4f18-dbed6fca6ce8}\L\76603ac3
c:\program files (x86)\Google\Desktop\Install\{75bccb62-0f3a-bb56-4f18-dbed6fca6ce8}\9519~1\A535~1\E628~1\{75bccb62-0f3a-bb56-4f18-dbed6fca6ce8}\U\00000008.@
c:\program files (x86)\LyricsBuddy-1\LyRIcsbuddy-1-bho.dll
c:\programdata\1381222694.bdinstall.bin
c:\programdata\DSearchLink
c:\programdata\DSearchLink\DSearchLink.exe
c:\users\Sara\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\users\Sara\AppData\Local\Google\Desktop\Install
c:\users\Sara\AppData\Local\Google\Desktop\Install\{75bccb62-0f3a-bb56-4f18-dbed6fca6ce8}\2E2F~1\28F0~1\E628~1\{75bccb62-0f3a-bb56-4f18-dbed6fca6ce8}\@
c:\users\Sara\AppData\Local\Microsoft\Windows\Temporary Internet Files\{15FF4D54-B7F9-43F3-8728-47CC8B586371}.xps
c:\users\Sara\AppData\Local\Microsoft\Windows\Temporary Internet Files\{1B5AE0B1-F77F-41C1-893D-0A52DF920DA3}.xps
c:\users\Sara\AppData\Local\Microsoft\Windows\Temporary Internet Files\{A3EC51B1-8722-445A-8870-7A15DDA2D5FB}.xps
c:\users\Sara\AppData\Local\Microsoft\Windows\Temporary Internet Files\{F49E6173-F7FC-4E1C-9F3E-6734782E1F54}.xps
c:\users\Sara\AppData\Local\Microsoft\Windows\Temporary Internet Files\{FC084FE1-1739-4DA1-8150-2C6E2D330554}.xps
c:\windows\SysWow64\lsprst7.dll
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-09-13 bis 2013-10-13 ))))))))))))))))))))))))))))))
.
.
2013-10-13 11:28 . 2013-10-13 11:28 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-10-13 11:20 . 2013-10-13 11:20 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5DDE0483-CF72-4109-83F9-0065DEA86989}\offreg.dll
2013-10-12 13:58 . 2013-09-05 05:32 9694160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5DDE0483-CF72-4109-83F9-0065DEA86989}\mpengine.dll
2013-10-12 10:35 . 2013-10-12 10:35 597776 ----a-w- c:\windows\system32\drivers\avckf.sys
2013-10-12 08:56 . 2013-10-12 08:56 -------- d-----w- C:\FRST
2013-10-08 09:51 . 2013-10-08 09:51 -------- d-----w- c:\users\Sara\AppData\Roaming\Simply Super Software
2013-10-08 09:50 . 2013-10-08 16:41 -------- d-----w- c:\program files (x86)\Trojan Remover
2013-10-08 09:50 . 2013-10-08 09:50 -------- d-----w- c:\programdata\Simply Super Software
2013-10-08 09:50 . 2013-10-08 09:50 -------- d-----w- c:\users\Sara\AppData\Local\Programs
2013-10-08 09:06 . 2013-10-08 16:31 -------- d-----w- c:\programdata\BDLogging
2013-10-08 09:06 . 2012-04-17 12:34 76944 ----a-w- c:\windows\system32\drivers\bdvedisk.sys
2013-10-08 09:06 . 2013-02-22 17:46 93600 ----a-w- c:\windows\system32\drivers\BdfNdisf6.sys
2013-10-08 09:06 . 2012-11-12 16:11 82384 ----a-w- c:\windows\system32\drivers\bdsandbox.sys
2013-10-08 09:06 . 2007-04-11 09:11 511328 ----a-w- c:\windows\capicom.dll
2013-10-08 09:06 . 2012-11-02 12:17 261056 ----a-w- c:\windows\system32\drivers\avchv.sys
2013-10-08 09:06 . 2013-04-17 12:59 718840 ----a-w- c:\windows\system32\drivers\avc3.sys
2013-10-08 08:59 . 2013-10-09 06:27 -------- d-----w- c:\users\Sara\AppData\Roaming\Bitdefender
2013-10-08 08:59 . 2013-10-08 09:07 -------- d-----w- c:\programdata\Bitdefender
2013-10-08 08:55 . 2013-10-08 08:55 471821 ----a-w- c:\programdata\1381222043.bdinstall.bin
2013-10-08 08:52 . 2013-10-08 08:52 -------- d-----w- c:\users\Sara\AppData\Roaming\QuickScan
2013-10-08 08:47 . 2012-10-04 12:30 147232 ------w- c:\windows\system32\drivers\gzflt.sys
2013-10-08 08:47 . 2013-10-08 08:59 -------- d-----w- c:\program files\Bitdefender
2013-10-08 08:47 . 2013-05-28 10:12 382536 ----a-w- c:\windows\system32\drivers\trufos.sys
2013-10-08 08:41 . 2013-10-08 08:47 -------- d-----w- c:\program files\Common Files\Bitdefender
2013-10-07 19:54 . 2013-10-07 19:54 -------- d-----w- c:\windows\SysWow64\searchplugins
2013-10-07 19:54 . 2013-10-07 19:54 -------- d-----w- c:\windows\SysWow64\Extensions
2013-10-07 13:51 . 2013-10-07 13:51 -------- d-----w- c:\programdata\APN
2013-10-07 11:56 . 2012-10-30 21:50 285328 ----a-w- c:\windows\system32\aswBoot.exe
2013-10-07 11:55 . 2013-10-07 19:55 -------- d-----w- c:\programdata\AVAST Software
2013-10-07 11:55 . 2013-10-07 11:55 -------- d-----w- c:\program files\AVAST Software
2013-10-07 11:44 . 2013-10-07 11:44 -------- d-----w- c:\users\Sara\AppData\Roaming\okitspace
2013-10-07 11:43 . 2013-10-13 11:24 -------- d-----w- c:\program files (x86)\LyricsBuddy-1
2013-10-07 11:43 . 2013-10-07 11:43 -------- d-----w- c:\programdata\Babylon
2013-10-07 11:43 . 2013-10-07 11:43 -------- d-----w- c:\users\Sara\AppData\Roaming\Babylon
2013-10-06 16:32 . 2013-10-07 12:00 -------- d-----w- c:\program files (x86)\Google
2013-10-06 16:32 . 2013-10-07 13:39 -------- d-----w- c:\users\Sara\AppData\Local\Google
2013-09-23 19:31 . 2013-09-23 19:31 -------- d-----w- c:\users\Sara\.spss
2013-09-23 19:30 . 2013-09-23 19:30 -------- d-----w- c:\users\Sara\AppData\Local\javasharedresources
2013-09-23 19:24 . 2013-09-23 19:24 -------- d-----w- c:\program files\Common Files\IBM
2013-09-23 19:24 . 2013-09-23 19:24 -------- d--h--w- c:\program files (x86)\Zero G Registry
2013-09-23 19:24 . 2013-09-23 19:24 -------- d--h--w- c:\users\Sara\InstallAnywhere
2013-09-23 19:22 . 2013-09-23 19:22 -------- d-----w- c:\program files (x86)\IBM
2013-09-23 19:22 . 2013-09-23 19:22 1025 ----a-w- c:\windows\SysWow64\sysprs7.dll
2013-09-23 14:31 . 2013-09-23 14:31 -------- d-----w- c:\programdata\SafeNet Sentinel
2013-09-23 14:27 . 2013-09-23 14:27 -------- d-----w- c:\programdata\SPSS
2013-09-23 14:27 . 2013-09-23 14:27 -------- d-----w- c:\program files (x86)\IBM SPSS Statistics
2013-09-23 14:27 . 2013-09-23 14:27 -------- d-----w- c:\program files (x86)\Common Files\IBM
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-12 11:24 . 2012-05-11 19:10 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-12 11:24 . 2012-05-11 19:10 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-09-25 23:46 . 2012-05-11 20:29 80541720 ----a-w- c:\windows\system32\MRT.exe
2013-08-10 05:22 . 2013-09-12 22:33 51712 ----a-w- c:\windows\system32\ie4uinit.exe
2013-08-10 05:22 . 2013-09-12 22:33 2241024 ----a-w- c:\windows\system32\wininet.dll
2013-08-10 05:22 . 2013-09-12 22:33 1365504 ----a-w- c:\windows\system32\urlmon.dll
2013-08-10 05:21 . 2013-09-12 22:33 19246592 ----a-w- c:\windows\system32\mshtml.dll
2013-08-10 05:21 . 2013-09-12 22:33 603136 ----a-w- c:\windows\system32\msfeeds.dll
2013-08-10 05:21 . 2013-09-12 22:33 53248 ----a-w- c:\windows\system32\jsproxy.dll
2013-08-10 05:20 . 2013-09-12 22:33 855552 ----a-w- c:\windows\system32\jscript.dll
2013-08-10 05:20 . 2013-09-12 22:33 3959296 ----a-w- c:\windows\system32\jscript9.dll
2013-08-10 05:20 . 2013-09-12 22:33 526336 ----a-w- c:\windows\system32\ieui.dll
2013-08-10 05:20 . 2013-09-12 22:33 67072 ----a-w- c:\windows\system32\iesetup.dll
2013-08-10 05:20 . 2013-09-12 22:33 39936 ----a-w- c:\windows\system32\iernonce.dll
2013-08-10 05:20 . 2013-09-12 22:33 2647040 ----a-w- c:\windows\system32\iertutil.dll
2013-08-10 05:20 . 2013-09-12 22:33 136704 ----a-w- c:\windows\system32\iesysprep.dll
2013-08-10 05:20 . 2013-09-12 22:33 15404544 ----a-w- c:\windows\system32\ieframe.dll
2013-08-10 03:59 . 2013-09-12 22:33 1767936 ----a-w- c:\windows\SysWow64\wininet.dll
2013-08-10 03:58 . 2013-09-12 22:33 2876928 ----a-w- c:\windows\SysWow64\jscript9.dll
2013-08-10 03:58 . 2013-09-12 22:33 61440 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-08-10 03:58 . 2013-09-12 22:33 109056 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-08-10 03:17 . 2013-09-12 22:33 2706432 ----a-w- c:\windows\system32\mshtml.tlb
2013-08-10 03:07 . 2013-09-12 22:33 2706432 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-08-10 02:27 . 2013-09-12 22:33 89600 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-08-10 02:17 . 2013-09-12 22:33 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-08-08 01:20 . 2013-09-12 08:12 3155456 ----a-w- c:\windows\system32\win32k.sys
2013-08-07 02:22 . 2012-05-11 19:04 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-08-05 02:25 . 2013-09-12 08:12 155584 ----a-w- c:\windows\system32\drivers\ataport.sys
2013-08-02 02:23 . 2013-09-12 08:12 5550528 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-08-02 02:15 . 2013-09-12 08:12 1732032 ----a-w- c:\windows\system32\ntdll.dll
2013-08-02 02:15 . 2013-09-12 08:12 362496 ----a-w- c:\windows\system32\wow64win.dll
2013-08-02 02:15 . 2013-09-12 08:12 243712 ----a-w- c:\windows\system32\wow64.dll
2013-08-02 02:15 . 2013-09-12 08:12 13312 ----a-w- c:\windows\system32\wow64cpu.dll
2013-08-02 02:14 . 2013-09-12 08:12 215040 ----a-w- c:\windows\system32\winsrv.dll
2013-08-02 02:14 . 2013-09-12 08:12 16384 ----a-w- c:\windows\system32\ntvdm64.dll
2013-08-02 02:13 . 2013-09-12 08:12 424448 ----a-w- c:\windows\system32\KernelBase.dll
2013-08-02 02:13 . 2013-09-12 08:12 1161216 ----a-w- c:\windows\system32\kernel32.dll
2013-08-02 02:12 . 2013-09-12 08:12 43520 ----a-w- c:\windows\system32\csrsrv.dll
2013-08-02 02:12 . 2013-09-12 08:12 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 6656 ----a-w- c:\windows\system32\apisetschema.dll
2013-08-02 02:12 . 2013-09-12 08:12 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3584 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3584 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-08-02 02:12 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-08-02 01:59 . 2013-09-12 08:12 3968960 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-08-02 01:59 . 2013-09-12 08:12 3913664 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-08-02 01:51 . 2013-09-12 08:12 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll
2013-08-02 01:50 . 2013-09-12 08:12 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2013-08-02 01:50 . 2013-09-12 08:12 274944 ----a-w- c:\windows\SysWow64\KernelBase.dll
2013-08-02 01:48 . 2013-09-12 08:12 5120 ---ha-w- c:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll
2013-08-02 01:48 . 2013-09-12 08:12 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 08:12 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-08-02 01:09 . 2013-09-12 08:12 338432 ----a-w- c:\windows\system32\conhost.exe
2013-08-02 00:59 . 2013-09-12 08:12 112640 ----a-w- c:\windows\system32\smss.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2012-04-02 18:47 233288 ----a-w- c:\program files (x86)\Hotspot Shield\HssIE\HssIE.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2012-11-07 18:28 220632 ----a-w- c:\users\Sara\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2012-11-07 18:28 220632 ----a-w- c:\users\Sara\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2012-11-07 18:28 220632 ----a-w- c:\users\Sara\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-17 14:45 130736 ----a-w- c:\users\Sara\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-17 14:45 130736 ----a-w- c:\users\Sara\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-17 14:45 130736 ----a-w- c:\users\Sara\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ICQ"="c:\program files (x86)\ICQ7M\ICQ.exe" [2012-05-13 127040]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-07-25 20684656]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"FreePDF Assistant"="c:\program files (x86)\FreePDF_XP\fpassist.exe" [2011-02-23 371200]
"TrojanScanner"="c:\program files (x86)\Trojan Remover\Trjscan.exe" [2013-07-19 1655568]
.
c:\users\Sara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Sara\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-25 27776968]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0aswBoot.exe /A:* /L:1031 /KBD:2 /wow /dir:C:\Program
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 hshld;Hotspot Shield Service;c:\program files (x86)\Hotspot Shield\bin\openvpnas.exe;c:\program files (x86)\Hotspot Shield\bin\openvpnas.exe [x]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys;c:\windows\SYSNATIVE\DRIVERS\avckf.sys [x]
R3 BDSandBox;BDSandBox;c:\windows\system32\drivers\bdsandbox.sys;c:\windows\SYSNATIVE\drivers\bdsandbox.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 BdDesktopParental;Bitdefender Desktop Parental Control;c:\program files\Bitdefender\Bitdefender 2013\bdparentalservice.exe;c:\program files\Bitdefender\Bitdefender 2013\bdparentalservice.exe [x]
S0 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys;c:\windows\SYSNATIVE\DRIVERS\avc3.sys [x]
S1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [x]
S1 bdfwfpf;bdfwfpf;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [x]
S1 BDVEDISK;BDVEDISK;c:\windows\system32\DRIVERS\bdvedisk.sys;c:\windows\SYSNATIVE\DRIVERS\bdvedisk.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 HssWd;Hotspot Shield Monitoring Service;c:\program files (x86)\Hotspot Shield\bin\hsswd.exe;c:\program files (x86)\Hotspot Shield\bin\hsswd.exe [x]
S2 SafeBox;SafeBox;c:\program files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe;c:\program files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [x]
S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [x]
S2 UPDATESRV;Bitdefender Desktop Update Service;c:\program files\Bitdefender\Bitdefender 2013\updatesrv.exe;c:\program files\Bitdefender\Bitdefender 2013\updatesrv.exe [x]
S3 avchv;avchv Function Driver;c:\windows\system32\DRIVERS\avchv.sys;c:\windows\SYSNATIVE\DRIVERS\avchv.sys [x]
S3 gzflt;gzflt;c:\windows\system32\DRIVERS\gzflt.sys;c:\windows\SYSNATIVE\DRIVERS\gzflt.sys [x]
S3 k57nd60a;Broadcom NetLink (TM)-Gigabit-Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series - Adaptertreiber für Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-10-07 11:59 1185744 ----a-w- c:\program files (x86)\Google\Chrome\Application\30.0.1599.69\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-10-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-11 11:24]
.
2013-10-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-10-07 11:56]
.
2013-10-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-10-07 11:56]
.
2013-10-13 c:\windows\Tasks\LyricsBuddy-1-codedownloader.job
- c:\program files (x86)\LyricsBuddy-1\LyricsBuddy-1-codedownloader.exe [2013-10-07 11:44]
.
2013-10-13 c:\windows\Tasks\LyricsBuddy-1-enabler.job
- c:\program files (x86)\LyricsBuddy-1\LyricsBuddy-1-enabler.exe [2013-10-07 11:44]
.
2013-10-13 c:\windows\Tasks\LyricsBuddy-1-firefoxinstaller.job
- c:\program files (x86)\LyricsBuddy-1\LyricsBuddy-1-firefoxinstaller.exe [2013-10-07 11:43]
.
2013-10-13 c:\windows\Tasks\LyricsBuddy-1-updater.job
- c:\program files (x86)\LyricsBuddy-1\LyricsBuddy-1-updater.exe [2013-10-07 11:44]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2012-11-07 18:28 244696 ----a-w- c:\users\Sara\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2012-11-07 18:28 244696 ----a-w- c:\users\Sara\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2012-11-07 18:28 244696 ----a-w- c:\users\Sara\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-17 14:45 164016 ----a-w- c:\users\Sara\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-17 14:45 164016 ----a-w- c:\users\Sara\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-17 14:45 164016 ----a-w- c:\users\Sara\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-17 14:45 164016 ----a-w- c:\users\Sara\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox1]
@="{152C96EB-288E-4EDC-B7C6-D21F8250ADF3}"
[HKEY_CLASSES_ROOT\CLSID\{152C96EB-288E-4EDC-B7C6-D21F8250ADF3}]
2013-02-27 13:43 269200 ----a-w- c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox2]
@="{342DAA0B-D796-460D-8566-901E08A1CCAD}"
[HKEY_CLASSES_ROOT\CLSID\{342DAA0B-D796-460D-8566-901E08A1CCAD}]
2013-02-27 13:43 269200 ----a-w- c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox3]
@="{57595DAE-1AE1-4D97-A49E-67CBB53B52DF}"
[HKEY_CLASSES_ROOT\CLSID\{57595DAE-1AE1-4D97-A49E-67CBB53B52DF}]
2013-02-27 13:43 269200 ----a-w- c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox4]
@="{33816773-98AE-4723-ADE0-EBE54C8B5A67}"
[HKEY_CLASSES_ROOT\CLSID\{33816773-98AE-4723-ADE0-EBE54C8B5A67}]
2013-02-27 13:43 269200 ----a-w- c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Bdagent"="c:\program files\Bitdefender\Bitdefender 2013\bdagent.exe" [2013-04-24 1569536]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: An OneNote s&enden - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: Free YouTube Download - c:\users\Sara\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: {{781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - c:\program files (x86)\ICQ7M\ICQ.exe
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Sara\AppData\Roaming\Mozilla\Firefox\Profiles\w9x5qq6q.default\
FF - ExtSQL: 2013-10-07 13:44; 8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com; c:\users\Sara\AppData\Roaming\Mozilla\Firefox\Profiles\w9x5qq6q.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com
FF - ExtSQL: 2013-10-07 13:44; OKitSpace@Vittalia.es; c:\users\Sara\AppData\Roaming\okitspace\Firefox
pref('extensions.shownSelectionUI',true);
pref('extensions.autoDisableScopes',0);
FF - user.js: extensions.delta.tlbrSrchUrl -
FF - user.js: extensions.delta.id - d03c041300000000000000ff5b199d1f
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15985
FF - user.js: extensions.delta.vrsn - 1.8.24.6
FF - user.js: extensions.delta.vrsni - 1.8.24.6
FF - user.js: extensions.delta.vrsnTs - 1.8.24.613:43
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - de
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.ffxUnstlRst - true
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta_i.babTrack - affID=122123&tsp=5028
FF - user.js: extensions.delta_i.babExt -
FF - user.js: extensions.delta_i.srcExt - ss
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{11111111-1111-1111-1111-110411181168} - c:\program files (x86)\LyricsBuddy-1\LyricsBuddy-1-bho.dll
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
WebBrowser-{41564952-412D-5637-00A7-7A786E7484D7} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3801020867-2230807782-3264050191-1001\Software\SecuROM\License information*]
"datasecu"=hex:a1,0c,7e,70,f2,cb,7a,74,bd,f5,df,14,e4,d4,b8,3b,ea,c1,e4,b0,8b,
2d,f4,4e,ef,fd,8b,1d,2f,fa,d8,15,de,c4,37,ca,fe,63,09,e0,59,e1,9d,80,87,54,\
"rkeysecu"=hex:46,fc,09,05,9b,68,c3,1f,b5,22,bc,00,ea,3a,91,62
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-10-13 13:41:57
ComboFix-quarantined-files.txt 2013-10-13 11:41
.
Vor Suchlauf: 10 Verzeichnis(se), 93.950.701.568 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 95.698.513.920 Bytes frei
.
- - End Of File - - 8C6AAB59957619811C1ADE641655B755
A36C5E4F47E84449FF07ED3517B43A31 |