ComboFix
[CODE]
Combofix Logfile: Code:
ComboFix 13-12-13.01 - Nutzer 14.12.2013 10:48:15.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.12174.3423 [GMT 1:00]
ausgeführt von:: c:\users\Nutzer\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\1&1
c:\programdata\1&1\1&1 SmartFax\Settings.xml
c:\users\Nutzer\AppData\Roaming\1&1
c:\users\Nutzer\AppData\Roaming\1&1\1&1 SmartFax\FaxNumberHistory.xml
c:\users\Nutzer\AppData\Roaming\1&1\1&1 SmartFax\Settings.xml
c:\windows\IsUn0407.exe
c:\windows\msvcr71.dll
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-11-14 bis 2013-12-14 ))))))))))))))))))))))))))))))
.
.
2013-12-14 09:53 . 2013-12-14 09:53 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-12-14 09:53 . 2013-12-14 09:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-13 23:42 . 2013-12-13 23:42 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E8E5DC85-69F0-4B3A-B8A4-086C67C1FE98}\offreg.dll
2013-12-13 15:21 . 2013-11-08 03:12 10285968 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E8E5DC85-69F0-4B3A-B8A4-086C67C1FE98}\mpengine.dll
2013-12-13 10:16 . 2013-12-13 10:16 -------- d-----w- C:\FRST
2013-12-12 08:24 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2013-12-12 08:24 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2013-12-12 08:24 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
2013-12-12 08:24 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL
2013-12-12 08:24 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll
2013-12-12 08:22 . 2013-11-26 08:35 5769216 ----a-w- c:\windows\system32\jscript9.dll
2013-12-12 08:22 . 2013-11-26 08:16 4243968 ----a-w- c:\windows\SysWow64\jscript9.dll
2013-12-11 11:06 . 2013-10-30 02:32 335360 ----a-w- c:\windows\system32\msieftp.dll
2013-12-11 11:06 . 2013-10-30 02:19 301568 ----a-w- c:\windows\SysWow64\msieftp.dll
2013-12-11 11:06 . 2013-10-30 01:24 3155968 ----a-w- c:\windows\system32\win32k.sys
2013-12-11 11:06 . 2013-11-23 18:26 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-12-11 11:06 . 2013-11-23 17:47 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2013-12-11 11:06 . 2013-10-19 02:18 81408 ----a-w- c:\windows\system32\imagehlp.dll
2013-12-11 11:06 . 2013-10-19 01:36 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2013-12-11 11:06 . 2013-11-12 02:23 2048 ----a-w- c:\windows\system32\tzres.dll
2013-12-11 11:06 . 2013-11-12 02:07 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2013-12-11 11:05 . 2013-10-04 02:16 116736 ----a-w- c:\windows\system32\drivers\drmk.sys
2013-12-11 11:05 . 2013-10-04 01:36 230400 ----a-w- c:\windows\system32\drivers\portcls.sys
2013-12-11 11:05 . 2013-10-12 02:32 150016 ----a-w- c:\windows\system32\wshom.ocx
2013-12-11 11:05 . 2013-10-12 02:31 202752 ----a-w- c:\windows\system32\scrrun.dll
2013-12-11 11:05 . 2013-10-12 02:04 121856 ----a-w- c:\windows\SysWow64\wshom.ocx
2013-12-11 11:05 . 2013-10-12 01:33 156160 ----a-w- c:\windows\system32\cscript.exe
2013-12-11 11:05 . 2013-10-12 01:15 141824 ----a-w- c:\windows\SysWow64\wscript.exe
2013-12-11 11:05 . 2013-10-12 02:03 163840 ----a-w- c:\windows\SysWow64\scrrun.dll
2013-12-11 11:05 . 2013-10-12 01:33 168960 ----a-w- c:\windows\system32\wscript.exe
2013-12-11 11:05 . 2013-10-12 01:15 126976 ----a-w- c:\windows\SysWow64\cscript.exe
2013-12-06 20:27 . 2013-12-06 20:27 -------- d-----w- c:\users\Nutzer\AppData\Roaming\AVAST Software
2013-12-06 20:26 . 2013-12-06 20:26 92544 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-12-06 20:26 . 2013-12-06 20:26 84328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-12-06 20:26 . 2013-12-06 20:26 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-12-06 20:26 . 2013-12-06 20:26 65264 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-12-06 20:26 . 2013-12-06 20:26 409832 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-12-06 20:26 . 2013-12-06 20:26 38984 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-12-06 20:26 . 2013-12-06 20:26 205320 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-12-06 20:26 . 2013-12-06 20:26 1032416 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-12-06 20:26 . 2013-12-06 20:26 28184 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2013-12-06 20:26 . 2013-12-06 20:26 43152 ----a-w- c:\windows\avastSS.scr
2013-12-06 20:26 . 2013-12-06 20:26 334648 ----a-w- c:\windows\system32\aswBoot.exe
2013-11-29 17:58 . 2013-11-29 17:58 -------- d-----w- c:\program files (x86)\ITN Converter
2013-11-29 14:24 . 2013-11-29 14:24 -------- d-----w- c:\users\Nutzer\AppData\Local\ElevatedDiagnostics
2013-11-29 13:48 . 2013-11-29 13:48 -------- d-----w- c:\program files (x86)\RoyalTek
2013-11-27 21:10 . 2013-11-27 21:10 -------- d-----w- c:\users\Nutzer\Eigene Routen
2013-11-27 20:35 . 2013-11-27 21:08 -------- d-----w- c:\users\Nutzer\.hgt
2013-11-27 20:35 . 2013-11-27 20:35 -------- d-----w- c:\users\Nutzer\.swt
2013-11-20 13:26 . 2013-11-20 13:26 -------- d-----w- c:\windows\WindowsMobile
2013-11-19 21:20 . 2013-11-19 23:04 -------- d-----w- c:\program files (x86)\QemuManager
2013-11-19 21:18 . 2013-11-29 12:22 -------- d-----w- c:\program files (x86)\Bochs-2.6.2
2013-11-18 23:25 . 2013-11-18 23:25 -------- d-----w- c:\windows\SysWow64\tmp
2013-11-18 23:24 . 2013-11-18 23:24 -------- d-----w- c:\windows\SysWow64\log
2013-11-18 22:29 . 2013-11-18 22:29 -------- d-----w- c:\users\Nutzer\AppData\Roaming\Canneverbe Limited
2013-11-18 22:29 . 2013-11-18 22:29 -------- d-----w- c:\programdata\Canneverbe Limited
2013-11-18 22:28 . 2013-11-18 22:28 -------- d-----w- c:\program files (x86)\CDBurnerXP
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-14 09:41 . 2012-10-11 09:54 387 ----a-w- c:\users\Nutzer\AppData\Roaming\sp_data.sys
2013-11-14 02:01 . 2012-10-13 14:44 82896128 ----a-w- c:\windows\system32\MRT.exe
2013-11-13 10:56 . 2013-11-13 10:56 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-11-13 10:56 . 2013-11-13 10:56 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-11-13 10:56 . 2013-11-13 10:56 942592 ----a-w- c:\windows\system32\jsIntl.dll
2013-11-13 10:56 . 2013-11-13 10:56 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-11-13 10:56 . 2013-11-13 10:56 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-11-13 10:56 . 2013-11-13 10:56 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-11-13 10:56 . 2013-11-13 10:56 84992 ----a-w- c:\windows\system32\mshtmled.dll
2013-11-13 10:56 . 2013-11-13 10:56 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-11-13 10:56 . 2013-11-13 10:56 81408 ----a-w- c:\windows\system32\icardie.dll
2013-11-13 10:56 . 2013-11-13 10:56 774144 ----a-w- c:\windows\system32\jscript.dll
2013-11-13 10:56 . 2013-11-13 10:56 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-11-13 10:56 . 2013-11-13 10:56 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-11-13 10:56 . 2013-11-13 10:56 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-11-13 10:56 . 2013-11-13 10:56 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2013-11-13 10:56 . 2013-11-13 10:56 626176 ----a-w- c:\windows\system32\msfeeds.dll
2013-11-13 10:56 . 2013-11-13 10:56 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-11-13 10:56 . 2013-11-13 10:56 62464 ----a-w- c:\windows\system32\pngfilt.dll
2013-11-13 10:56 . 2013-11-13 10:56 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2013-11-13 10:56 . 2013-11-13 10:56 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-11-13 10:56 . 2013-11-13 10:56 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2013-11-13 10:56 . 2013-11-13 10:56 548352 ----a-w- c:\windows\system32\vbscript.dll
2013-11-13 10:56 . 2013-11-13 10:56 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-11-13 10:56 . 2013-11-13 10:56 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2013-11-13 10:56 . 2013-11-13 10:56 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-11-13 10:56 . 2013-11-13 10:56 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-11-13 10:56 . 2013-11-13 10:56 48128 ----a-w- c:\windows\system32\imgutil.dll
2013-11-13 10:56 . 2013-11-13 10:56 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-11-13 10:56 . 2013-11-13 10:56 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2013-11-13 10:56 . 2013-11-13 10:56 413696 ----a-w- c:\windows\system32\html.iec
2013-11-13 10:56 . 2013-11-13 10:56 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-11-13 10:56 . 2013-11-13 10:56 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-11-13 10:56 . 2013-11-13 10:56 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-11-13 10:56 . 2013-11-13 10:56 337408 ----a-w- c:\windows\SysWow64\html.iec
2013-11-13 10:56 . 2013-11-13 10:56 30208 ----a-w- c:\windows\system32\licmgr10.dll
2013-11-13 10:56 . 2013-11-13 10:56 296960 ----a-w- c:\windows\system32\dxtrans.dll
2013-11-13 10:56 . 2013-11-13 10:56 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2013-11-13 10:56 . 2013-11-13 10:56 247808 ----a-w- c:\windows\system32\msls31.dll
2013-11-13 10:56 . 2013-11-13 10:56 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-11-13 10:56 . 2013-11-13 10:56 243200 ----a-w- c:\windows\system32\webcheck.dll
2013-11-13 10:56 . 2013-11-13 10:56 235520 ----a-w- c:\windows\system32\url.dll
2013-11-13 10:56 . 2013-11-13 10:56 235008 ----a-w- c:\windows\system32\elshyph.dll
2013-11-13 10:56 . 2013-11-13 10:56 195584 ----a-w- c:\windows\system32\msrating.dll
2013-11-13 10:56 . 2013-11-13 10:56 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2013-11-13 10:56 . 2013-11-13 10:56 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-11-13 10:56 . 2013-11-13 10:56 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-11-13 10:56 . 2013-11-13 10:56 147968 ----a-w- c:\windows\system32\occache.dll
2013-11-13 10:56 . 2013-11-13 10:56 143872 ----a-w- c:\windows\system32\wextract.exe
2013-11-13 10:56 . 2013-11-13 10:56 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2013-11-13 10:56 . 2013-11-13 10:56 13824 ----a-w- c:\windows\system32\mshta.exe
2013-11-13 10:56 . 2013-11-13 10:56 135680 ----a-w- c:\windows\system32\iepeers.dll
2013-11-13 10:56 . 2013-11-13 10:56 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2013-11-13 10:56 . 2013-11-13 10:56 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2013-11-13 10:56 . 2013-11-13 10:56 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-11-13 10:56 . 2013-11-13 10:56 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-11-13 10:56 . 2013-11-13 10:56 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-11-13 10:56 . 2013-11-13 10:56 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-11-13 10:56 . 2013-11-13 10:56 105984 ----a-w- c:\windows\system32\iesysprep.dll
2013-11-13 10:56 . 2013-11-13 10:56 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-11-13 10:56 . 2013-11-13 10:56 101376 ----a-w- c:\windows\system32\inseng.dll
2013-11-11 04:50 . 2012-10-11 14:38 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-10-31 09:09 . 2013-10-31 09:16 8946728 ----a-w- c:\windows\system32\cdintf500_64.dll
2013-10-31 09:09 . 2013-10-31 09:16 7181352 ----a-w- c:\windows\SysWow64\cdintf500.dll
2013-10-17 11:29 . 2013-10-17 11:29 4955176 ----a-w- c:\windows\SysWow64\LxXtreme110.dll
2013-10-17 11:29 . 2013-10-17 11:29 28200 ----a-w- c:\windows\SysWow64\LxTPSW100.dll
2013-10-17 11:29 . 2013-10-17 11:29 106536 ----a-w- c:\windows\SysWow64\LxUISettingsN100.dll
2013-10-17 11:29 . 2013-10-17 11:29 65576 ----a-w- c:\windows\SysWow64\LxPXTree100.dll
2013-10-17 11:29 . 2013-10-17 11:29 1340456 ----a-w- c:\windows\SysWow64\LxTool112.dll
2013-10-17 11:29 . 2013-10-17 11:29 129576 ----a-w- c:\windows\SysWow64\LxMail100.dll
2013-10-17 11:29 . 2013-10-17 11:29 51752 ----a-w- c:\windows\SysWow64\LXCurr100.dll
2013-10-17 11:29 . 2013-10-17 11:29 70184 ----a-w- c:\windows\SysWow64\LxCI12.dll
2013-10-17 11:29 . 2013-10-17 11:29 209960 ----a-w- c:\windows\SysWow64\LxBasics100.dll
2013-10-14 17:00 . 2013-11-13 11:03 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
2013-10-12 02:30 . 2013-11-13 15:04 830464 ----a-w- c:\windows\system32\nshwfp.dll
2013-10-12 02:29 . 2013-11-13 15:04 859648 ----a-w- c:\windows\system32\IKEEXT.DLL
2013-10-12 02:29 . 2013-11-13 15:04 324096 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2013-10-12 02:03 . 2013-11-13 15:04 656896 ----a-w- c:\windows\SysWow64\nshwfp.dll
2013-10-12 02:01 . 2013-11-13 15:04 216576 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL
2013-10-11 10:36 . 2013-10-11 10:36 51752 ----a-w- c:\windows\SysWow64\FKStampPainter20.dll
2013-10-05 20:25 . 2013-11-13 15:05 1474048 ----a-w- c:\windows\system32\crypt32.dll
2013-10-05 19:57 . 2013-11-13 15:05 1168384 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-10-04 02:28 . 2013-11-13 15:04 190464 ----a-w- c:\windows\system32\SmartcardCredentialProvider.dll
2013-10-04 02:25 . 2013-11-13 15:04 197120 ----a-w- c:\windows\system32\credui.dll
2013-10-04 02:24 . 2013-11-13 15:04 1930752 ----a-w- c:\windows\system32\authui.dll
2013-10-04 01:58 . 2013-11-13 15:04 152576 ----a-w- c:\windows\SysWow64\SmartcardCredentialProvider.dll
2013-10-04 01:56 . 2013-11-13 15:04 168960 ----a-w- c:\windows\SysWow64\credui.dll
2013-10-04 01:56 . 2013-11-13 15:04 1796096 ----a-w- c:\windows\SysWow64\authui.dll
2013-10-03 02:23 . 2013-11-13 15:05 404480 ----a-w- c:\windows\system32\gdi32.dll
2013-10-03 02:00 . 2013-11-13 15:05 311808 ----a-w- c:\windows\SysWow64\gdi32.dll
2013-09-28 01:09 . 2013-11-13 15:05 497152 ----a-w- c:\windows\system32\drivers\afd.sys
2013-09-26 13:27 . 2013-09-26 13:27 76840 ----a-w- c:\windows\SysWow64\LxDNTvm100.dll
2013-09-26 13:27 . 2013-09-26 13:27 321576 ----a-w- c:\windows\SysWow64\LxDNT100.dll
2013-09-26 13:27 . 2013-09-26 13:27 140840 ----a-w- c:\windows\SysWow64\LxDNTvmc100.dll
2013-09-25 02:26 . 2013-11-13 15:05 95680 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2013-09-25 02:26 . 2013-11-13 15:05 154560 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2013-09-25 02:23 . 2013-11-13 15:05 135680 ----a-w- c:\windows\system32\sspicli.dll
2013-09-25 02:23 . 2013-11-13 15:05 28672 ----a-w- c:\windows\system32\sspisrv.dll
2013-09-25 02:23 . 2013-11-13 15:05 28160 ----a-w- c:\windows\system32\secur32.dll
2013-09-25 02:22 . 2013-11-13 15:05 340992 ----a-w- c:\windows\system32\schannel.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"F.lux"="c:\users\Nutzer\AppData\Local\FluxSoftware\Flux\flux.exe" [2013-10-15 1016712]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2012-02-24 3331312]
"ASUSWebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe" [2011-07-29 737104]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-02-27 291608]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2012-02-16 322176]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2011-10-25 174720]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2012-02-02 2321072]
"RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2011-03-30 87336]
"BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2011-09-28 75048]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"AllShareAgent"="c:\program files (x86)\Samsung\AllShare\AllShareAgent.exe" [2012-03-01 285072]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2013-12-06 3568312]
.
c:\users\Nutzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.4.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2012-8-13 1199104]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AsusVibeLauncher.lnk - c:\program files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe /start [2012-2-24 549040]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"midi2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 CLKMSVC10_38F51D56;CyberLink Product - 2012/05/19 01:57;c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe;c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys;c:\windows\SYSNATIVE\Drivers\ssadadb.sys [x]
R3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
R3 btath_avdt;Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys;c:\windows\SYSNATIVE\drivers\btath_avdt.sys [x]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x]
R3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
R3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x]
R3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
R3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys;c:\windows\SYSNATIVE\drivers\Mkd2Nadr.sys [x]
R3 Mkd3kfNt;Mkd3kfNt;c:\windows\system32\drivers\Mkd3kfNt.sys;c:\windows\SYSNATIVE\drivers\Mkd3kfNt.sys [x]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x]
R3 SimpleSlideShowServer;SimpleSlideShowServer;c:\program files (x86)\Samsung\AllShare\AllShareSlideShowService.exe;c:\program files (x86)\Samsung\AllShare\AllShareSlideShowService.exe [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdm.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 VBoxUSB;VirtualBox USB;c:\windows\system32\Drivers\VBoxUSB.sys;c:\windows\SYSNATIVE\Drivers\VBoxUSB.sys [x]
R4 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys;c:\windows\SYSNATIVE\drivers\aswKbd.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxDrv.sys [x]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxUSBMon.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x]
S2 ASUS InstantOn;ASUS InstantOn Service;c:\program files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe;c:\program files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [x]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys;c:\windows\SYSNATIVE\drivers\aswFsBlk.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 SamsungAllShareV2.0;Samsung AllShare PC;c:\program files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe;c:\program files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 ZAtheros Bt&Wlan Coex Agent;ZAtheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x]
S3 AiCharger;ASUS Charger Driver;c:\windows\system32\DRIVERS\AiCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AiCharger.sys [x]
S3 AsusVBus;AsusVBus;c:\windows\system32\DRIVERS\AsusVBus.sys;c:\windows\SYSNATIVE\DRIVERS\AsusVBus.sys [x]
S3 AsusVTouch;AsusVTouch;c:\windows\system32\DRIVERS\AsusVTouch.sys;c:\windows\SYSNATIVE\DRIVERS\AsusVTouch.sys [x]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - CLKMDRV10_38F51D56
.
Inhalt des "geplante Tasks" Ordners
.
2013-12-13 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
- c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 20:41]
.
2013-12-13 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
- c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 20:41]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-12-06 20:26 326944 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2011-05-25 07:09 227840 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2011-05-25 07:09 227840 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-03-06 170264]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-03-06 398616]
"AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-12-29 1014432]
"AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-12-29 800416]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=71461f0a-823a-4a87-8ad6-a9d5a5f931ea&searchtype=hp&installDate={installDate}
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=71461f0a-823a-4a87-8ad6-a9d5a5f931ea&searchtype=ds&q={searchTerms}&installDate={installDate}
TCP: Interfaces\{952061AE-52BE-43CD-A0C4-ED203E4903FF}: NameServer = 192.168.178.1
FF - ProfilePath - c:\users\Nutzer\AppData\Roaming\Mozilla\Firefox\Profiles\u8rgr50n.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - google.de
FF - prefs.js: keyword.URL - hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=b5407523-9d30-4afa-ade6-2dcf8cf63eec&affid=111583&searchtype=ds&babsrc=lnkry&q=
FF - ExtSQL: 2013-10-22 20:24; {b9db16a4-6edc-47ec-a1f4-b86292ed211d}; c:\users\Nutzer\AppData\Roaming\Mozilla\Firefox\Profiles\u8rgr50n.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - ExtSQL: 2013-11-08 22:39; YoutubeDownloader@PeterOlayev.com; c:\users\Nutzer\AppData\Roaming\Mozilla\Firefox\Profiles\u8rgr50n.default\extensions\YoutubeDownloader@PeterOlayev.com.xpi
FF - ExtSQL: 2013-12-06 21:26; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKLM-Run-20131121 - c:\program files\AVAST Software\Avast\setup\emupdate\bd8b5be3-5c9e-458d-9149-36c4c4f4f270.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
HKLM-Run-ETDCtrl - c:\program files (x86)\Elantech\ETDCtrl.exe
AddRemove-Bochs 2.6.2 - c:\program files (x86)\Bochs-2.6.2\Uninstall.exe
AddRemove-Kain 2 - c:\windows\IsUn0407.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2803969532-3586009099-3580304194-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:cc,7d,3f,ec,0f,a9,5f,68,80,19,3d,17,33,70,61,39,64,06,cd,27,e2,b2,25,
f4,5e,fe,eb,0b,5e,8b,ac,a2,89,8d,65,d6,1c,42,c0,0c,47,04,be,cc,27,67,a3,73,\
"??"=hex:32,b2,0a,ee,2f,91,27,a2,29,9c,60,2f,22,1b,e9,c3
.
[HKEY_USERS\S-1-5-21-2803969532-3586009099-3580304194-1001\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:16,f3,a4,4f,70,ac,4d,76,28,d9,17,87,82,f6,db,d0,51,38,2f,22,e4,
95,dd,d4,13,2f,1f,7c,b2,f9,10,d8,ee,44,64,70,65,6d,c8,02,44,87,ca,54,21,58,\
"rkeysecu"=hex:de,b6,88,f1,4a,ef,9e,a7,7b,a7,e0,ef,c4,ac,6c,b4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-12-14 10:55:09
ComboFix-quarantined-files.txt 2013-12-14 09:55
.
Vor Suchlauf: 15 Verzeichnis(se), 150.258.970.624 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 150.607.466.496 Bytes frei
.
- - End Of File - - DEDA196114F2933FD87D3472B5632621 --- --- ---
lg |