hi,
Hier die Fixlog: Code:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-06-2014
Ran by Flo at 2014-06-04 16:40:32 Run:1
Running from C:\Users\Flo\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
HKLM Group Policy restriction on software: C:\Program Files\Microsoft Security Client <====== ATTENTION
HKLM Group Policy restriction on software: C:\Program Files (x86)\Microsoft Security Client <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware <====== ATTENTION
*****************
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
HKLM => Group Policy Restriction on software restored successfully.
==== End of Fixlog ==== 2 Programme konnte ich nicht löschen mit Revo.
Combofix meinte das Microsoft Security Essentials aktiviert wäre.
Der PC wurde nicht automatisch neu gestartet. Es kam der Abmeldesound aber mehr nicht.Ich habe ca 10min gewartet nachdem der Combofix.txt auf dem Bildschirm aufgetaucht ist. Dann habe ich ganz normal neugestartet. Es kam keine Fehlermeldung.
Combofix.txt : Code:
ComboFix 14-06-04.01 - Flo 04.06.2014 17:06:00.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.6143.4493 [GMT 2:00]
ausgeführt von:: c:\users\Flo\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Flo\AppData\Local\Microsoft\Windows\Temporary Internet Files\66b8d7e7-0c40-43cd-ba7b-f7364d8e3e89.jpg
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-05-04 bis 2014-06-04 ))))))))))))))))))))))))))))))
.
.
2014-06-04 15:11 . 2014-06-04 15:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-06-04 14:42 . 2014-06-04 14:42 -------- d-----w- c:\program files (x86)\VS Revo Group
2014-06-04 11:44 . 2014-06-04 14:40 -------- d-----w- C:\FRST
2014-06-03 22:44 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-06-03 22:17 . 2014-06-03 22:17 -------- d-----w- c:\windows\ERUNT
2014-06-03 22:12 . 2014-06-03 22:44 -------- d-----w- C:\AdwCleaner
2014-06-03 21:27 . 2014-06-04 12:25 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-06-03 21:27 . 2014-05-12 05:26 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-06-03 21:27 . 2014-06-03 21:27 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-06-03 21:27 . 2014-06-03 21:27 -------- d-----w- c:\programdata\Malwarebytes
2014-06-03 21:27 . 2014-05-12 05:26 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-06-03 21:27 . 2014-05-12 05:25 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-06-03 21:14 . 2014-04-30 23:20 10702536 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{03440661-6C1A-433C-AC95-7F38ADF5E978}\mpengine.dll
2014-06-03 02:13 . 2014-06-03 02:13 -------- d-----w- c:\windows\de
2014-06-03 02:12 . 2014-06-03 02:12 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2014-06-03 02:12 . 2014-06-03 02:12 -------- d-----w- c:\windows\PCHEALTH
2014-06-03 02:11 . 2014-06-03 02:12 -------- d-----w- c:\program files (x86)\Windows Live
2014-06-03 02:09 . 2014-06-03 02:13 -------- d-----w- c:\users\Flo\AppData\Local\Windows Live
2014-06-03 02:05 . 2014-06-03 02:05 -------- d-----w- c:\program files (x86)\Common Files\Windows Live
2014-06-03 02:04 . 2014-06-03 21:41 -------- d-----w- C:\temp
2014-06-03 00:48 . 2014-06-03 00:48 -------- d-----w- c:\program files (x86)\Common Files\DVDVideoSoft
2014-06-03 00:48 . 2014-06-03 00:48 -------- d-----w- c:\users\Flo\AppData\Roaming\DVDVideoSoft
2014-06-02 12:45 . 2014-04-30 23:20 10702536 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-05-27 22:37 . 2014-05-19 23:10 601432 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2014-05-27 22:36 . 2014-05-14 23:49 3774821 ----a-w- c:\windows\system32\nvcoproc.bin
2014-05-27 22:05 . 2014-03-31 16:42 40392 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2014-05-27 22:05 . 2014-03-31 16:42 34760 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2014-05-24 12:24 . 2014-05-02 14:47 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{98A73E87-1933-4BF6-82D1-2B17BCAFFF6A}\gapaengine.dll
2014-05-19 19:42 . 2014-05-19 19:44 -------- d-----w- c:\users\Flo\AppData\Roaming\GameMaker-Studio
2014-05-16 01:02 . 2014-05-06 00:21 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2014-05-16 01:02 . 2014-05-05 23:14 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2014-05-16 01:02 . 2014-05-06 00:46 17847808 ----a-w- c:\windows\system32\mshtml.dll
2014-05-16 01:02 . 2014-05-06 00:21 96768 ----a-w- c:\windows\system32\mshtmled.dll
2014-05-15 11:43 . 2014-04-12 02:22 155072 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2014-05-14 16:37 . 2014-05-14 16:37 -------- d-----w- c:\users\Flo\AppData\Roaming\Guitar Pro 6
2014-05-14 16:37 . 2014-05-14 16:37 -------- d-----w- c:\programdata\Guitar Pro 6
2014-05-07 12:28 . 2014-05-07 12:28 -------- d-----w- c:\users\Flo\AppData\Local\Diagnostics
2014-05-06 13:32 . 2014-05-16 01:47 -------- d-s---w- c:\windows\system32\CompatTel
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-06-03 02:12 . 2012-07-17 12:37 23264 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-05-20 02:44 . 2014-01-25 17:51 16003912 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2014-05-20 02:44 . 2013-07-02 20:39 2730208 ----a-w- c:\windows\SysWow64\nvapi.dll
2014-05-20 02:44 . 2013-07-02 20:39 14434704 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2014-05-20 02:44 . 2013-06-21 14:29 61216 ----a-w- c:\windows\system32\OpenCL.dll
2014-05-20 02:44 . 2013-06-21 14:29 52056 ----a-w- c:\windows\SysWow64\OpenCL.dll
2014-05-20 02:44 . 2013-06-21 14:29 3109248 ----a-w- c:\windows\system32\nvapi64.dll
2014-05-20 02:44 . 2013-02-25 22:32 17480432 ----a-w- c:\windows\system32\nvd3dumx.dll
2014-05-20 02:44 . 2009-07-13 21:59 18531568 ----a-w- c:\windows\system32\nvwgf2umx.dll
2014-05-20 01:25 . 2013-06-21 14:29 6769096 ----a-w- c:\windows\system32\nvcpl.dll
2014-05-20 01:25 . 2013-06-21 14:29 3514144 ----a-w- c:\windows\system32\nvsvc64.dll
2014-05-20 01:25 . 2013-06-21 14:29 927520 ----a-w- c:\windows\system32\nvvsvc.exe
2014-05-20 01:25 . 2013-06-21 14:29 62808 ----a-w- c:\windows\system32\nvshext.dll
2014-05-20 01:25 . 2013-06-21 14:29 387528 ----a-w- c:\windows\system32\nvmctray.dll
2014-05-20 01:25 . 2013-06-21 14:29 2560968 ----a-w- c:\windows\system32\nvsvcr.dll
2014-05-16 01:01 . 2013-06-23 00:17 93223848 ----a-w- c:\windows\system32\MRT.exe
2014-05-02 14:47 . 2013-07-18 13:35 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-04-30 18:29 . 2013-10-29 21:26 1081112 ----a-w- c:\windows\SysWow64\nvspcap.dll
2014-04-30 18:29 . 2013-10-29 21:26 1225920 ----a-w- c:\windows\system32\nvspcap64.dll
2014-03-31 19:34 . 2014-03-31 19:34 322248 ----a-w- c:\windows\WLXPGSS.SCR
2014-03-31 16:42 . 2013-10-10 13:10 37320 ----a-w- c:\windows\system32\nvaudcap64v.dll
2014-03-21 09:46 . 2014-03-21 09:46 152848 ----a-w- c:\windows\SysWow64\comdlg32.ocx
2014-03-21 09:46 . 2014-03-21 09:46 1081616 ----a-w- c:\windows\SysWow64\mscomctl.ocx
2014-03-11 07:52 . 2013-01-20 13:59 133928 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2014-03-08 04:06 . 2014-04-10 01:00 10926592 ----a-w- c:\windows\system32\ieframe.dll
2014-03-08 03:49 . 2014-04-10 01:00 2334720 ----a-w- c:\windows\system32\jscript9.dll
2014-03-08 03:41 . 2014-04-10 01:00 1347072 ----a-w- c:\windows\system32\urlmon.dll
2014-03-08 03:40 . 2014-04-10 01:00 1392128 ----a-w- c:\windows\system32\wininet.dll
2014-03-08 03:39 . 2014-04-10 01:00 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
2014-03-08 03:38 . 2014-04-10 01:00 237056 ----a-w- c:\windows\system32\url.dll
2014-03-08 03:37 . 2014-04-10 01:00 85504 ----a-w- c:\windows\system32\jsproxy.dll
2014-03-08 03:34 . 2014-04-10 01:00 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2014-03-08 03:34 . 2014-04-10 01:00 816640 ----a-w- c:\windows\system32\jscript.dll
2014-03-08 03:33 . 2014-04-10 01:00 599040 ----a-w- c:\windows\system32\vbscript.dll
2014-03-08 03:32 . 2014-04-10 01:00 729088 ----a-w- c:\windows\system32\msfeeds.dll
2014-03-08 03:32 . 2014-04-10 01:00 2147840 ----a-w- c:\windows\system32\iertutil.dll
2014-03-08 03:24 . 2014-04-10 01:00 248320 ----a-w- c:\windows\system32\ieui.dll
2014-03-07 23:12 . 2014-04-10 01:00 1806848 ----a-w- c:\windows\SysWow64\jscript9.dll
2014-03-07 23:02 . 2014-04-10 01:00 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2014-03-07 23:02 . 2014-04-10 01:00 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2014-03-07 22:57 . 2014-04-10 01:00 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2014-03-07 22:56 . 2014-04-10 01:00 421376 ----a-w- c:\windows\SysWow64\vbscript.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
R3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x]
R3 LGSUsbFilt;Logitech Gaming KMDF USB Filter Driver;c:\windows\system32\DRIVERS\LGSUsbFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSUsbFilt.Sys [x]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT-Treiber;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - UWLDYPOW
*Deregistered* - uwldypow
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-05-22 13:26 1091912 ----a-w- c:\program files (x86)\Google\Chrome\Application\35.0.1916.114\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-06-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-26 15:49]
.
2014-06-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-26 15:49]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-04-30 1225920]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-04-30 2199840]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.1.1
DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} - hxxp://www.king.com/ctl/kingcomie.cab
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-POEngine5 - (no file)
Wow6432Node-HKCU-Run-chfipqw - c:\programdata\chfipqw.dat
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM-Run-Nvtmru - c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Nico Mak Computing\WinZip]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-06-04 17:14:18
ComboFix-quarantined-files.txt 2014-06-04 15:14
.
Vor Suchlauf: 11 Verzeichnis(se), 59.770.654.720 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 61.496.172.544 Bytes frei
.
- - End Of File - - 3C0BA629582198B16DED8659D216FD7B
A36C5E4F47E84449FF07ED3517B43A31 |