littlesheep | 29.04.2014 22:29 | Ich bin auf jeden Fall schon mal beeindruckt... :crazy:
Das hat jetzt funktioniert, hat auch nicht gemeckert (apropos gemeckert, meine Virensoftware hat heute beim Starten - weiß nicht genau, ob er den gestern und die Tage vorher auch schon namentlich erwähnt hatte - die Datei Genesis.exe zwei oder drei Mal als "im Arbeitsspeicher..." benannt und gelöscht) - hier das Log: Code:
ComboFix 14-04-29.01 - Claudia 29.04.2014 23:09:48.1.6 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8191.5814 [GMT 2:00]
ausgeführt von:: c:\users\Claudia\Desktop\ComboFix.exe
AV: ESET Smart Security 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET Personal Firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\END
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\smartbar_3312014.exe.lnk
c:\users\Claudia\AppData\Local\AnyProtectScannerSetup.exe
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome.manifest
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\api.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\api\asyncDB.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\api\background.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\api\browserAction.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\api\contextMenu.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\api\dbManager.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\api\dom_bg.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\api\fileManager.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\api\firefox.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\api\firefoxNotifications.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\api\firefoxOmnibox.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\api\message.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\api\pageAction.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\api\request.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\api\tabs.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\api\webRequest.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\api\windowsMessagingHandler.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\background.html
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\baseObject.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\browser.xul
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\addressBarChangeObserver.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\console.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\consts.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\delegate.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\extensionDataStore.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\folderIOWrapper.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\httpObserver.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\IDBWrapper.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\installer.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\logFile.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\prefs.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\progressListenerObserver.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\registry.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\reloadObserver.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\reports.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\requestObject.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\searchSettings.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\uninstallObserver.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\updateManager.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\utils.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\core\xhr.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\dialog.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\ffCoreFilesIndex.txt
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\main.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\options.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\options.xul
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\platformVersion.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\chrome\content\search_dialog.xul
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\defaults\preferences\prefs.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\manifest.xml
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins.json
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\1.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\102.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\103.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\104.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\13.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\14.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\155.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\16.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\17.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\177.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\182.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\183.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\184.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\190.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\191.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\195.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\207.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\21.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\211.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\22.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\220.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\226.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\233.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\242.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\244.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\246.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\28.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\4.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\47.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\64.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\7.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\72.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\78.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\9.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\91.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\93.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\plugins\98.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\userCode\background.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\extensionData\userCode\extension.js
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\install.rdf
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\locale\en-US\translations.dtd
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\skin\button1.png
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\skin\button2.png
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\skin\button3.png
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\skin\button4.png
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\skin\button5.png
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\skin\crossrider_statusbar.png
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\skin\icon128.png
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\skin\icon16.png
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\skin\icon24.png
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\skin\icon48.png
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\skin\panelarrow-up.png
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\skin\popup.html
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\skin\skin.css
c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com\skin\update.css
c:\windows\SysWow64\AVSredirect.dll
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-03-28 bis 2014-04-29 ))))))))))))))))))))))))))))))
.
.
2014-04-29 21:18 . 2014-04-29 21:18 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-04-29 21:18 . 2014-04-29 21:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-04-29 19:27 . 2014-04-29 19:27 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3DF22FEA-40D0-460F-81D0-132D380CF371}\offreg.dll
2014-04-29 18:31 . 2014-04-17 03:31 10651704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3DF22FEA-40D0-460F-81D0-132D380CF371}\mpengine.dll
2014-04-28 21:22 . 2014-04-28 21:22 -------- d-s---w- c:\windows\system32\CompatTel
2014-04-28 21:21 . 2014-04-14 02:24 465408 ----a-w- c:\windows\system32\aepdu.dll
2014-04-28 21:21 . 2014-04-14 02:19 424448 ----a-w- c:\windows\system32\aeinv.dll
2014-04-28 21:04 . 2014-04-28 21:05 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-04-28 21:03 . 2014-04-28 21:03 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-04-28 21:03 . 2014-04-28 21:03 -------- d-----w- c:\programdata\Malwarebytes
2014-04-28 21:03 . 2014-04-03 07:51 63192 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-04-28 21:03 . 2014-04-03 07:51 88280 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-04-28 21:03 . 2014-04-03 07:50 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-04-28 20:54 . 2014-04-28 20:54 -------- d-----w- c:\program files (x86)\Uninstaller
2014-04-28 20:52 . 2014-04-28 20:52 -------- d-----w- c:\users\Claudia\AppData\Local\com
2014-04-28 20:50 . 2014-04-29 18:27 -------- d-----w- c:\program files (x86)\MyPC Backup
2014-04-28 20:49 . 2014-04-28 20:53 -------- d-----w- c:\program files (x86)\MediaPlayerplus
2014-04-28 20:49 . 2014-04-28 20:49 -------- d-----w- c:\users\Claudia\AppData\Roaming\VOPackage
2014-04-28 20:49 . 2014-04-28 20:52 -------- d-----w- c:\program files (x86)\Freeven pro 1.2
2014-04-28 20:49 . 2014-04-29 21:06 -------- d-----w- c:\users\Claudia\AppData\Local\Genesis
2014-04-28 20:48 . 2014-04-28 20:48 -------- d-----w- c:\users\Claudia\AppData\Local\SearchProtect
2014-04-28 20:39 . 2014-04-28 20:39 -------- d-----w- c:\program files\V-bates
2014-04-28 20:39 . 2014-04-28 20:39 -------- d-----w- c:\users\Claudia\AppData\Local\LPT
2014-04-28 20:39 . 2014-04-28 20:39 -------- d-----w- c:\users\Claudia\AppData\Local\Smartbar
2014-04-19 00:08 . 2014-04-19 00:08 -------- d-----w- c:\users\Claudia\AppData\Roaming\Bigasoft Total Video Converter 4
2014-04-19 00:07 . 2014-04-19 00:07 -------- d-----w- c:\program files (x86)\Bigasoft
2014-04-18 22:31 . 2014-04-19 00:29 -------- d-----w- c:\program files\rrsavings
2014-04-18 22:30 . 2014-04-18 22:30 -------- d-----w- c:\program files\002
2014-04-18 22:10 . 2014-04-18 22:10 -------- d-----w- c:\users\Claudia\AppData\Roaming\DivX
2014-04-18 22:10 . 2014-04-18 22:31 -------- d-----w- c:\program files\DivX
2014-04-18 22:10 . 2014-04-18 22:31 -------- d-----w- c:\program files (x86)\Common Files\DivX Shared
2014-04-18 22:08 . 2014-04-18 22:31 -------- d-----w- c:\programdata\DivX
2014-04-18 22:06 . 2014-04-18 22:06 -------- d-----w- c:\users\Claudia\.drdivx2
2014-04-18 20:55 . 2014-04-18 20:55 -------- d-----w- c:\users\Claudia\AppData\Roaming\SupTab
2014-04-18 20:55 . 2014-04-18 20:59 -------- d-----w- c:\program files (x86)\SupTab
2014-04-18 20:55 . 2014-04-18 20:55 -------- d-----w- c:\programdata\IePluginService
2014-04-18 20:55 . 2014-04-18 21:04 -------- d-----w- c:\programdata\WPM
2014-04-18 20:55 . 2014-04-18 20:55 -------- d-----w- c:\users\Claudia\AppData\Local\WinRST
2014-04-18 20:55 . 2014-04-18 20:55 -------- d-----w- c:\program files (x86)\WinRST
2014-04-18 20:55 . 2014-04-18 20:55 -------- d-----w- c:\users\Claudia\AppData\Local\PirritSuggestor
2014-04-18 20:55 . 2014-04-18 20:55 -------- d-----w- c:\users\Claudia\AppData\Roaming\Pirrit
2014-04-18 20:55 . 2014-04-18 20:55 -------- d-----w- c:\program files (x86)\Pirrit
2014-04-18 20:54 . 2014-04-18 20:59 -------- d-----w- c:\users\Claudia\AppData\Roaming\sweet-page
2014-04-18 20:42 . 2014-03-06 08:11 5784064 ----a-w- c:\windows\system32\jscript9.dll
2014-04-18 20:42 . 2014-03-06 07:46 4254720 ----a-w- c:\windows\SysWow64\jscript9.dll
2014-04-18 20:34 . 2014-01-24 02:37 1684928 ----a-w- c:\windows\system32\drivers\ntfs.sys
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-04-28 21:59 . 2012-03-29 17:10 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-04-28 21:59 . 2011-05-15 17:53 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-04-18 20:38 . 2010-12-16 13:08 90655440 ----a-w- c:\windows\system32\MRT.exe
2014-03-31 07:35 . 2010-12-10 10:11 270496 ------w- c:\windows\system32\MpSigStub.exe
2014-03-20 21:03 . 2013-10-27 08:12 15783992 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2014-03-20 21:03 . 2013-02-25 22:32 18302384 ----a-w- c:\windows\system32\nvwgf2umx.dll
2014-03-20 21:03 . 2014-03-20 21:03 832936 ----a-w- c:\windows\SysWow64\nvumdshim.dll
2014-03-20 21:03 . 2013-02-25 22:32 947808 ----a-w- c:\windows\system32\nvumdshimx.dll
2014-03-20 21:03 . 2014-03-20 21:03 9690424 ----a-w- c:\windows\SysWow64\nvopencl.dll
2014-03-20 21:03 . 2014-03-20 21:03 11589272 ----a-w- c:\windows\system32\nvopencl.dll
2014-03-20 21:02 . 2014-03-20 21:02 31474976 ----a-w- c:\windows\system32\nvoglv64.dll
2014-03-20 21:02 . 2014-03-20 21:02 353504 ----a-w- c:\windows\system32\nvoglshim64.dll
2014-03-20 21:02 . 2014-03-20 21:02 305600 ----a-w- c:\windows\SysWow64\nvoglshim32.dll
2014-03-20 21:02 . 2014-03-20 21:02 23716640 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2014-03-20 21:02 . 2014-03-20 21:02 12708128 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2014-03-20 21:02 . 2014-03-20 21:02 892704 ----a-w- c:\windows\system32\NvIFR64.dll
2014-03-20 21:02 . 2014-03-20 21:02 863064 ----a-w- c:\windows\SysWow64\NvIFR.dll
2014-03-20 21:02 . 2014-03-20 21:02 174296 ----a-w- c:\windows\system32\nvinitx.dll
2014-03-20 21:02 . 2014-03-20 21:02 148016 ----a-w- c:\windows\SysWow64\nvinit.dll
2014-03-20 21:02 . 2014-03-20 21:02 877856 ----a-w- c:\windows\system32\NvFBC64.dll
2014-03-20 21:02 . 2014-03-20 21:02 846168 ----a-w- c:\windows\SysWow64\NvFBC.dll
2014-03-20 21:02 . 2014-03-20 21:02 1885472 ----a-w- c:\windows\system32\nvdispco6433523.dll
2014-03-20 21:02 . 2014-03-20 21:02 1516488 ----a-w- c:\windows\system32\nvdispgenco6433523.dll
2014-03-20 21:02 . 2014-03-20 21:02 3143456 ----a-w- c:\windows\system32\nvcuvid.dll
2014-03-20 21:02 . 2014-03-20 21:02 17755424 ----a-w- c:\windows\system32\nvd3dumx.dll
2014-03-20 21:02 . 2013-09-17 20:22 14709720 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2014-03-20 21:02 . 2014-03-20 21:02 9728064 ----a-w- c:\windows\SysWow64\nvcuda.dll
2014-03-20 21:02 . 2014-03-20 21:02 2958792 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2014-03-20 21:02 . 2014-03-20 21:02 2783008 ----a-w- c:\windows\system32\nvcuvenc.dll
2014-03-20 21:02 . 2014-03-20 21:02 2411976 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2014-03-20 21:02 . 2014-03-20 21:02 11636176 ----a-w- c:\windows\system32\nvcuda.dll
2014-03-20 21:02 . 2014-03-20 21:02 17561544 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2014-03-20 21:02 . 2014-03-20 21:02 25255256 ----a-w- c:\windows\system32\nvcompiler.dll
2014-03-20 21:02 . 2013-02-25 22:32 3093280 ----a-w- c:\windows\system32\nvapi64.dll
2014-03-20 21:02 . 2013-02-25 22:32 2715264 ----a-w- c:\windows\SysWow64\nvapi.dll
2014-03-19 13:27 . 2014-03-19 13:27 76496 ----a-w- c:\windows\system32\drivers\dc3d.sys
2014-03-19 13:23 . 2014-03-19 13:23 862664 ----a-w- c:\windows\SysWow64\msvcr110.dll
2014-03-19 13:23 . 2014-03-19 13:23 828872 ----a-w- c:\windows\system32\msvcr110.dll
2014-03-19 13:23 . 2014-03-19 13:23 661448 ----a-w- c:\windows\system32\msvcp110.dll
2014-03-19 13:23 . 2014-03-19 13:23 534480 ----a-w- c:\windows\SysWow64\msvcp110.dll
2014-03-19 13:23 . 2014-03-19 13:23 50896 ----a-w- c:\windows\system32\drivers\point64.sys
2014-03-19 13:23 . 2014-03-19 13:23 354264 ----a-w- c:\windows\system32\vccorlib110.dll
2014-03-19 13:23 . 2014-03-19 13:23 251864 ----a-w- c:\windows\SysWow64\vccorlib110.dll
2014-03-11 20:07 . 2014-03-11 20:07 4550656 ----a-w- c:\windows\SysWow64\GPhotos.scr
2014-03-04 13:06 . 2010-08-08 22:12 6714312 ----a-w- c:\windows\system32\nvcpl.dll
2014-03-04 13:06 . 2010-08-08 22:12 3497816 ----a-w- c:\windows\system32\nvsvc64.dll
2014-03-04 13:05 . 2010-08-08 22:12 922968 ----a-w- c:\windows\system32\nvvsvc.exe
2014-03-04 13:05 . 2010-08-08 22:12 64968 ----a-w- c:\windows\system32\nvshext.dll
2014-03-04 13:05 . 2010-08-08 22:12 2558808 ----a-w- c:\windows\system32\nvsvcr.dll
2014-03-04 13:05 . 2010-08-08 22:12 386336 ----a-w- c:\windows\system32\nvmctray.dll
2014-03-04 13:05 . 2012-11-15 21:11 3649185 ----a-w- c:\windows\system32\nvcoproc.bin
2014-03-04 11:32 . 2014-03-30 11:42 599840 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2014-03-04 09:17 . 2014-04-18 20:35 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2014-02-07 01:23 . 2014-03-30 11:32 3156480 ----a-w- c:\windows\system32\win32k.sys
2014-02-04 02:32 . 2014-03-30 11:31 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-02-04 02:32 . 2014-03-30 11:31 624128 ----a-w- c:\windows\system32\qedit.dll
2014-02-04 02:04 . 2014-03-30 11:31 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2014-02-04 02:04 . 2014-03-30 11:31 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2010-12-11 21:21 . 2010-02-14 14:35 4411392 ----a-w- c:\program files (x86)\mplayerc.exe
2010-12-11 19:01 . 2004-02-18 18:36 245760 ----a-w- c:\program files (x86)\PvrDiskUtil.exe
2006-05-02 23:00 163328 --sh--r- c:\windows\SysWOW64\flvDX.dll
2007-02-20 23:00 31232 --sh--r- c:\windows\SysWOW64\msfDX.dll
2008-03-15 23:00 216064 --sh--r- c:\windows\SysWOW64\nbDX.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{11111111-1111-1111-1111-110511421146}]
2014-04-28 20:52 500072 ----a-w- c:\program files (x86)\MediaPlayerplus\MediaPlayerplus-bho.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{11111111-1111-1111-1111-110511421153}]
2014-04-28 20:51 500072 ----a-w- c:\program files (x86)\Freeven pro 1.2\Freeven pro 1.2-bho.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}]
2014-04-07 13:38 195872 ----a-w- c:\program files\V-bates\Extension32.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0}]
2010-11-05 01:58 297808 ----a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-28 21:44 1400712 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{d40c654d-7c51-4eb3-95b2-1e23905c2a2d}]
2010-11-05 01:58 297808 ----a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShareOverlay]
@="{594D4122-1F87-41E2-96C7-825FB4796516}"
[HKEY_CLASSES_ROOT\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516}]
2010-10-30 11:09 478208 ----a-w- c:\program files\Classic Shell\ClassicExplorer32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TBPanel"="c:\program files (x86)\Vtune\TBPanel.exe" [2010-09-02 2158592]
"GMX SMS-Manager"="c:\program files (x86)\GMX\GMX SMS-Manager\SMSMngr.exe" [2007-07-19 3539968]
"CTSyncU.exe"="c:\program files (x86)\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-07-17 868352]
"TomTomHOME.exe"="c:\program files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" [2013-03-22 248208]
"iCloudServices"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" [2012-12-17 59872]
"ApplePhotoStreams"="c:\program files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2012-12-17 59872]
"com.apple.dav.bookmarks.daemon"="c:\program files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe" [2012-12-17 59872]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2013-09-04 1564528]
"Browser Infrastructure Helper"="c:\users\Claudia\AppData\Local\Smartbar\Application\Smartbar.exe" [2014-03-25 26904]
"genesis"="c:\users\claudia\appdata\local\genesis\genesis.exe" [2014-04-28 2887680]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"TrueImageMonitor.exe"="c:\program files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" [2010-03-27 5141512]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-05-07 1073312]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2013-09-04 311152]
"BingDesktop"="c:\program files (x86)\Microsoft\BingDesktop\BingDesktop.exe" [2013-06-20 2249352]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
c:\users\Claudia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MyPC Backup.lnk - c:\program files (x86)\MyPC Backup\MyPC Backup.exe [2014-3-14 2901032]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer9"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0auto_reactivate \\?\Volume{a12df864-0442-11e0-8560-806e6f6e6963}\bootwiz\asrm.bin
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 IePluginService;IePlugin Service;c:\programdata\IePluginService\PluginService.exe;c:\programdata\IePluginService\PluginService.exe [x]
R2 PirritDesktop;PirritDesktop;c:\users\Claudia\AppData\Local\PirritSuggestor\PirritService.exe;c:\users\Claudia\AppData\Local\PirritSuggestor\PirritService.exe [x]
R2 PirritUpdater;PirritUpdater;c:\program files (x86)\Pirrit\AutoUpdater.exe;c:\program files (x86)\Pirrit\AutoUpdater.exe [x]
R2 WinRST;WinRST;c:\program files (x86)\WinRST\WinRST.exe;c:\program files (x86)\WinRST\WinRST.exe [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\SysWOW64\FsUsbExDisk.SYS;c:\windows\SysWOW64\FsUsbExDisk.SYS [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\DRIVERS\tdrpm258.sys;c:\windows\SYSNATIVE\DRIVERS\tdrpm258.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S2 afcdpsrv;Acronis Nonstop Backup service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [x]
S2 BackupStack;Computer Backup (MyPC Backup);c:\program files (x86)\MyPC Backup\BackupStack.exe;c:\program files (x86)\MyPC Backup\BackupStack.exe [x]
S2 BingDesktopUpdate;Bing Desktop Update service;c:\program files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe;c:\program files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [x]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfp.sys [x]
S2 Mext Guard;Mext Guard;c:\program files\V-bates\guardsvc.exe;c:\program files\V-bates\guardsvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [x]
S2 V-bates Updater;V-bates Updater;c:\program files\V-bates\ExtensionUpdaterService.exe;c:\program files\V-bates\ExtensionUpdaterService.exe [x]
S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys;c:\windows\SYSNATIVE\DRIVERS\afcdp.sys [x]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys;c:\windows\SYSNATIVE\DRIVERS\dc3d.sys [x]
S3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2014-04-29 c:\windows\Tasks\14ecb001-f416-4a5e-b100-cc6e315349af-1.job
- c:\program files (x86)\Freeven pro 1.2\Freeven pro 1.2-codedownloader.exe [2014-04-28 20:50]
.
2014-04-29 c:\windows\Tasks\14ecb001-f416-4a5e-b100-cc6e315349af-2.job
- c:\program files (x86)\Freeven pro 1.2\14ecb001-f416-4a5e-b100-cc6e315349af-2.exe [2014-04-28 20:51]
.
2014-04-29 c:\windows\Tasks\14ecb001-f416-4a5e-b100-cc6e315349af-3.job
- c:\program files (x86)\Freeven pro 1.2\14ecb001-f416-4a5e-b100-cc6e315349af-3.exe [2014-04-28 20:49]
.
2014-04-29 c:\windows\Tasks\14ecb001-f416-4a5e-b100-cc6e315349af-4.job
- c:\program files (x86)\Freeven pro 1.2\14ecb001-f416-4a5e-b100-cc6e315349af-4.exe [2014-04-28 20:49]
.
2014-04-29 c:\windows\Tasks\14ecb001-f416-4a5e-b100-cc6e315349af-5.job
- c:\program files (x86)\Freeven pro 1.2\14ecb001-f416-4a5e-b100-cc6e315349af-5.exe [2014-04-28 20:52]
.
2014-04-29 c:\windows\Tasks\923e656c-7931-4c44-9b19-6d3c00ebfbd9-1.job
- c:\program files (x86)\MediaPlayerplus\MediaPlayerplus-codedownloader.exe [2014-04-28 20:51]
.
2014-04-29 c:\windows\Tasks\923e656c-7931-4c44-9b19-6d3c00ebfbd9-2.job
- c:\program files (x86)\MediaPlayerplus\923e656c-7931-4c44-9b19-6d3c00ebfbd9-2.exe [2014-04-28 20:52]
.
2014-04-29 c:\windows\Tasks\923e656c-7931-4c44-9b19-6d3c00ebfbd9-3.job
- c:\program files (x86)\MediaPlayerplus\923e656c-7931-4c44-9b19-6d3c00ebfbd9-3.exe [2014-04-28 20:50]
.
2014-04-29 c:\windows\Tasks\923e656c-7931-4c44-9b19-6d3c00ebfbd9-4.job
- c:\program files (x86)\MediaPlayerplus\923e656c-7931-4c44-9b19-6d3c00ebfbd9-4.exe [2014-04-28 20:50]
.
2014-04-29 c:\windows\Tasks\923e656c-7931-4c44-9b19-6d3c00ebfbd9-5.job
- c:\program files (x86)\MediaPlayerplus\923e656c-7931-4c44-9b19-6d3c00ebfbd9-5.exe [2014-04-28 20:53]
.
2014-04-29 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 21:59]
.
2014-04-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-04 17:06]
.
2014-04-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-04 17:06]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShareOverlay]
@="{594D4122-1F87-41E2-96C7-825FB4796516}"
[HKEY_CLASSES_ROOT\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516}]
2010-10-30 11:09 594432 ----a-w- c:\program files\Classic Shell\ClassicExplorer64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CmPCIaudio"="c:\windows\Syswow64\CMICNFG3.dll" [2009-05-11 8126464]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-11-04 2919168]
"CTCheck"="c:\program files\Creative\ZEN Media Explorer\CTCheck.exe" [2007-11-06 397312]
"Acronis Scheduler2 Service"="c:\program files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" [2010-03-27 362952]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-09-20 444904]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-03-20 1797064]
"V-bates"="c:\program files\V-bates\notifier.exe" [2014-04-07 375584]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK2q0U14moCf-ET1EM4uw4GigvFB13oDfsPU-0fo0C6mk4NKg1XjLo_bCzP1bfvbysSYTBYA_U1YbhW2x6q0gXxM7tERQ8Gdx2kZO8xvaIbTYAWEkOd-HzZ7JuY961T4qLXebIQcdfkMCWrpg7jUY5xm3hpwWAsuY4AU9-YMrgx8ShU87ZCsvC6AaVDgG-BjeFZfQoPi1TwU31A,,
mDefault_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1397854450&from=cor&uid=395049983_1052576_AC757C6F&q={searchTerms}
mDefault_Page_URL = hxxp://www.sweet-page.com/?type=hp&ts=1397854450&from=cor&uid=395049983_1052576_AC757C6F
mStart Page = hxxp://www.sweet-page.com/?type=hp&ts=1397854450&from=cor&uid=395049983_1052576_AC757C6F
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1397854450&from=cor&uid=395049983_1052576_AC757C6F&q={searchTerms}
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=hxxp://127.0.0.1:9880
uSearchAssistant = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK2q0U14moCf-ET1EM4uw4GigvFB13oDfsPU-0fo0C6mk4NKg1XjLo_bCzP1bfvbysSYTBYA_U1YbhW2x6q0gXxM7tERQ8Gdx2kZO8xvaIbTYDZSU_pU1Qp4xx5ARpaXJhwu6BFFYCb7JyQI0Rz9vgpMRIbm9ocagIUeGDcQaXEQ8CREucr5wX27GOoIo2gWHHOYNdqcUJfEtBQ,,&q={searchTerms}
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Claudia\AppData\Roaming\Mozilla\Firefox\Profiles\ift3z7in.default\
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: keyword.URL - hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK2q0U14moCf-ET1EM4uw4GigvFB13oDfsPU-0fo0C6mk4NKg1XjLo_bCzP1bfvbysSYTBYA_U1YbhW2x6q0gXxM7tERQ8Gdx2kZO8xvaIbTYDZSU_pU1Qp4xx5ARpaXJhwu6BFFYCb7JyQI0Rz9vgpMRIbm9ocagIUeGDcQaXEQ8CREucr5wX27GOoIo2gWHHOYNdqcUJfEtBQ,,&q=
FF - user.js: extensions.autoDisableScopes - 0
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKCU-Run-KiesAirMessage - c:\program files (x86)\Samsung\Kies\KiesAirMessage.exe
Wow6432Node-HKLM-Run-mobilegeni daemon - c:\program files (x86)\Mobogenie\DaemonProcess.exe
Wow6432Node-HKLM-Run-DivXMediaServer - c:\program files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-dBpoweramp Dalet Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp DirectShow Decoder - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp DSP Effects - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp FLAC Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Monkeys Audio Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Mp2 and BwfMp2 codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp mp3 (Fraunhofer IIS) Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Music Converter - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Ogg Vorbis Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Real Audio (Helix) Encoder - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBPoweramp tooLame MP2 codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Wave64 Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp WavPack Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp [Calculate Audio CRC] Codec - c:\windows\system32\SpoonUninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1277317880-2460927560-2137772949-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\pspimage*ÿÿÿE¥cuE¥cu¾Z«e¸´T]
"0"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00,
00,1a,00,ee,bb,fe,23,00,00,10,00,30,81,e2,33,1e,4e,76,46,83,5a,98,39,5c,3b,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-1277317880-2460927560-2137772949-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*pspimage*ÿÿÿE¥cuE¥cu¾Z«e¸´T]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1277317880-2460927560-2137772949-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*pspimage*ÿÿÿE¥cuE¥cu¾Z«e¸´T\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1277317880-2460927560-2137772949-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.*pspimage*ÿÿÿE¥cuE¥cu¾Z«e¸´T]
"0"=hex:51,00,75,00,69,00,6e,00,63,00,79,00,2e,00,70,73,70,69,6d,61,67,65,00,
ff,ff,ff,45,a5,63,75,45,a5,63,75,be,5a,ab,65,01,b8,b4,54,10,01,00,00,a6,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-1277317880-2460927560-2137772949-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A7683762-250E-1153-8024-4B2E4BD01261}*]
"oadgidkllokdlihcbncfkifajgffgm"=hex:69,61,62,61,6c,6c,61,70,62,6b,70,65,6f,6b,
63,61,61,61,00,00
"nafggahdoojdcjickaifmfoaianf"=hex:6a,61,70,63,68,6f,6a,63,70,68,63,61,65,66,
6a,6f,66,69,61,6a,00,ff
"oapiaamakhgeobpljakhoedhflkggc"=hex:64,61,69,70,66,6f,61,65,00,fc
.
[HKEY_USERS\S-1-5-21-1277317880-2460927560-2137772949-1001_Classes\Wow6432Node\CLSID\{22ffb237-803b-4efd-bc84-2d3a41480e10}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:0000002a
"Therad"=dword:0000001f
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,c3,4d,9e,47,61,a7,8f,c3,5d,5c,e7,10,32,dc,92,66,f1,78,db,23,e0,fc,\
.
[HKEY_USERS\S-1-5-21-1277317880-2460927560-2137772949-1001_Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):56,36,7c,21,a5,29,13,2c,4b,95,2b,36,9a,43,ed,57,fe,4c,65,4d,cf,
b7,69,c0,d7,42,9f,f0,09,91,14,08,75,0f,10,c1,7f,d0,80,46,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_206_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_206_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_206_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_206_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.13"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-04-29 23:21:05
ComboFix-quarantined-files.txt 2014-04-29 21:21
.
Vor Suchlauf: 9 Verzeichnis(se), 398.623.420.416 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 431.000.928.256 Bytes frei
.
- - End Of File - - BBBF9DFBE60FAED714D90212181EBF93
10FA4DEA160749C165DB2CD2762E9FEE |