bodyshot174 | 12.08.2014 17:22 | Combofix: Code:
ComboFix 14-08-12.01 - Marcel 12.08.2014 17:51:53.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.8190.5190 [GMT 2:00]
ausgeführt von:: c:\users\Marcel\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\xml930B.tmp
c:\programdata\xml935A.tmp
c:\programdata\xml936A.tmp
c:\programdata\xml936B.tmp
c:\programdata\xmlE1C7.tmp
c:\programdata\xmlE2B2.tmp
c:\programdata\xmlE330.tmp
C:\Thumbs.db
c:\users\Marcel\AppData\Local\lame_enc.dll
c:\users\Marcel\AppData\Local\no23xwrapper.dll
c:\users\Marcel\AppData\Local\ogg.dll
c:\users\Marcel\AppData\Local\vorbis.dll
c:\users\Marcel\AppData\Local\vorbisenc.dll
c:\users\Marcel\AppData\Local\vorbisfile.dll
c:\users\Marcel\AppData\Roaming\AcroIEHelpe.txt
c:\users\Marcel\AppData\Roaming\inst.exe
c:\users\Marcel\AppData\Roaming\SQLite3.dll
c:\users\Marcel\AppData\Roaming\srvblck5.tmp
c:\users\Public\invokesi.exe
K:\install.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-07-12 bis 2014-08-12 ))))))))))))))))))))))))))))))
.
.
2014-08-12 16:13 . 2014-08-12 16:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-08-12 15:45 . 2014-07-02 03:09 10924376 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7C1D864E-F727-4D33-9971-62CA62880FAC}\mpengine.dll
2014-08-11 16:35 . 2014-08-11 16:38 -------- d-----w- C:\FRST
2014-08-11 16:04 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-08-11 16:03 . 2014-08-11 16:17 -------- d-----w- C:\AdwCleaner
2014-08-11 13:35 . 2014-08-11 13:35 -------- d-----w- c:\programdata\ATI
2014-08-11 13:34 . 2014-08-11 13:34 -------- d-----w- c:\users\Marcel\AppData\Roaming\library_dir
2014-08-11 13:30 . 2014-08-12 15:38 -------- d-----w- c:\users\Marcel\AppData\Roaming\Raptr
2014-08-11 13:30 . 2014-08-11 13:34 -------- d-----w- c:\program files (x86)\Raptr
2014-08-11 13:30 . 2014-08-11 13:30 -------- d-----w- c:\program files (x86)\AMD AVT
2014-08-11 13:25 . 2014-08-11 13:25 -------- d-----w- c:\program files\AMD
2014-08-11 13:21 . 2014-08-11 13:21 -------- d-----w- C:\AMD
2014-08-11 13:14 . 2014-08-11 13:14 -------- d-s---w- c:\windows\SysWow64\Microsoft
2014-08-10 23:01 . 2014-08-11 17:43 -------- d-----w- c:\users\Marcel\AppData\Roaming\GameTracker
2014-08-10 23:01 . 2014-08-10 23:01 -------- d-----w- c:\program files (x86)\GameTracker
2014-08-09 00:28 . 2014-08-09 00:28 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins
2014-08-02 15:24 . 2014-08-02 16:32 -------- d-----w- c:\users\Marcel\AppData\Local\gtk-2.0
2014-08-02 15:24 . 2014-08-02 15:24 -------- d-----w- c:\users\Marcel\.thumbnails
2014-08-02 15:19 . 2014-08-02 15:19 -------- d-----w- c:\users\Marcel\AppData\Local\fontconfig
2014-08-02 15:19 . 2014-08-02 16:35 -------- d-----w- c:\users\Marcel\.gimp-2.8
2014-08-02 15:19 . 2014-08-02 15:19 -------- d-----w- c:\users\Marcel\AppData\Local\gegl-0.2
2014-08-02 15:17 . 2014-08-02 15:18 -------- d-----w- c:\program files\GIMP 2
2014-08-02 10:11 . 2014-05-14 16:23 44512 ----a-w- c:\windows\system32\wups2.dll
2014-08-02 10:11 . 2014-05-14 16:23 58336 ----a-w- c:\windows\system32\wuauclt.exe
2014-08-02 10:11 . 2014-05-14 16:23 2477536 ----a-w- c:\windows\system32\wuaueng.dll
2014-08-02 10:11 . 2014-05-14 16:21 2620928 ----a-w- c:\windows\system32\wucltux.dll
2014-08-02 10:11 . 2014-05-14 16:23 38880 ----a-w- c:\windows\system32\wups.dll
2014-08-02 10:11 . 2014-05-14 16:23 700384 ----a-w- c:\windows\system32\wuapi.dll
2014-08-02 10:11 . 2014-05-14 16:20 97792 ----a-w- c:\windows\system32\wudriver.dll
2014-08-02 10:11 . 2014-05-14 16:17 92672 ----a-w- c:\windows\SysWow64\wudriver.dll
2014-08-02 10:10 . 2014-05-14 16:23 36320 ----a-w- c:\windows\SysWow64\wups.dll
2014-08-02 10:10 . 2014-05-14 16:23 581600 ----a-w- c:\windows\SysWow64\wuapi.dll
2014-08-02 10:10 . 2014-05-14 07:23 198600 ----a-w- c:\windows\system32\wuwebv.dll
2014-08-02 10:10 . 2014-05-14 07:23 179656 ----a-w- c:\windows\SysWow64\wuwebv.dll
2014-08-02 10:10 . 2014-05-14 07:20 36864 ----a-w- c:\windows\system32\wuapp.exe
2014-08-02 10:10 . 2014-05-14 07:17 33792 ----a-w- c:\windows\SysWow64\wuapp.exe
2014-08-01 21:31 . 2014-08-01 21:31 92008 ----a-w- c:\windows\system32\drivers\aswStm.sys
2014-08-01 21:31 . 2014-08-01 21:31 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-08-01 21:31 . 2014-08-01 21:31 43152 ----a-w- c:\windows\avastSS.scr
2014-07-31 13:35 . 2014-07-31 13:35 -------- d-----w- c:\users\Marcel\AppData\Local\Skype
2014-07-31 13:35 . 2014-07-31 13:35 -------- d-----w- c:\program files (x86)\Common Files\Skype
2014-07-30 22:48 . 2014-07-30 22:48 -------- d-----w- c:\users\Marcel\AppData\Roaming\ProtectDISC
2014-07-30 22:42 . 2014-07-30 22:42 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2014-07-30 22:41 . 2014-07-30 22:41 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2014-07-30 22:17 . 2014-07-30 22:17 -------- d-----w- c:\program files (x86)\Quadriga Games
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-08-10 11:39 . 2011-11-29 20:21 297088 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-08-10 11:39 . 2011-11-27 11:37 297088 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-08-10 11:33 . 2010-01-16 15:28 297088 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-08-09 00:42 . 2011-11-29 20:21 76152 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2014-08-01 21:31 . 2010-12-18 11:30 427360 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-08-01 21:31 . 2013-10-13 09:25 224896 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-08-01 21:31 . 2013-10-13 09:25 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-08-01 21:31 . 2012-03-27 19:03 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-08-01 21:31 . 2011-04-15 13:21 1041168 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-08-01 21:31 . 2011-01-16 14:01 307344 ----a-w- c:\windows\system32\aswBoot.exe
2014-08-01 21:31 . 2010-12-18 11:30 79184 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-07-10 13:13 . 2010-01-09 00:04 96441528 ----a-w- c:\windows\system32\MRT.exe
2014-07-09 16:29 . 2012-04-12 16:26 699056 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-07-09 16:29 . 2011-06-04 05:48 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-06-20 20:14 . 2014-07-09 15:19 266424 ----a-w- c:\windows\system32\iedkcs32.dll
2014-06-19 01:39 . 2014-07-09 15:19 23464448 ----a-w- c:\windows\system32\mshtml.dll
2014-06-19 01:06 . 2014-07-09 15:19 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-06-19 01:06 . 2014-07-09 15:19 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2014-06-19 00:48 . 2014-07-09 15:19 2768384 ----a-w- c:\windows\system32\iertutil.dll
2014-06-19 00:42 . 2014-07-09 15:19 548352 ----a-w- c:\windows\system32\vbscript.dll
2014-06-19 00:42 . 2014-07-09 15:19 66048 ----a-w- c:\windows\system32\iesetup.dll
2014-06-19 00:41 . 2014-07-09 15:19 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll
2014-06-19 00:41 . 2014-07-09 15:19 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2014-06-19 00:32 . 2014-07-09 15:19 51200 ----a-w- c:\windows\system32\jsproxy.dll
2014-06-19 00:31 . 2014-07-09 15:19 33792 ----a-w- c:\windows\system32\iernonce.dll
2014-06-19 00:26 . 2014-07-09 15:19 598016 ----a-w- c:\windows\system32\ieui.dll
2014-06-19 00:24 . 2014-07-09 15:19 139264 ----a-w- c:\windows\system32\ieUnatt.exe
2014-06-19 00:24 . 2014-07-09 15:19 111616 ----a-w- c:\windows\system32\ieetwcollector.exe
2014-06-19 00:23 . 2014-07-09 15:19 752640 ----a-w- c:\windows\system32\jscript9diag.dll
2014-06-19 00:14 . 2014-07-09 15:19 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-06-19 00:09 . 2014-07-09 15:19 452608 ----a-w- c:\windows\system32\dxtmsft.dll
2014-06-18 23:59 . 2014-07-09 15:19 38400 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2014-06-18 23:56 . 2014-07-09 15:19 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2014-06-18 23:53 . 2014-07-09 15:19 195584 ----a-w- c:\windows\system32\msrating.dll
2014-06-18 23:51 . 2014-07-09 15:19 5721088 ----a-w- c:\windows\system32\jscript9.dll
2014-06-18 23:50 . 2014-07-09 15:19 85504 ----a-w- c:\windows\system32\mshtmled.dll
2014-06-18 23:48 . 2014-07-09 15:19 292864 ----a-w- c:\windows\system32\dxtrans.dll
2014-06-18 23:39 . 2014-07-09 15:19 608768 ----a-w- c:\windows\system32\ie4uinit.exe
2014-06-18 23:38 . 2014-07-09 15:19 455168 ----a-w- c:\windows\SysWow64\vbscript.dll
2014-06-18 23:37 . 2014-07-09 15:19 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2014-06-18 23:36 . 2014-07-09 15:19 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2014-06-18 23:35 . 2014-07-09 15:19 62464 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2014-06-18 23:33 . 2014-07-09 15:19 631808 ----a-w- c:\windows\system32\msfeeds.dll
2014-06-18 23:27 . 2014-07-09 15:19 1249280 ----a-w- c:\windows\system32\mshtmlmedia.dll
2014-06-18 23:27 . 2014-07-09 15:19 2040832 ----a-w- c:\windows\system32\inetcpl.cpl
2014-06-18 23:23 . 2014-07-09 15:19 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2014-06-18 23:22 . 2014-07-09 15:19 592896 ----a-w- c:\windows\SysWow64\jscript9diag.dll
2014-06-18 23:06 . 2014-07-09 15:19 32256 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2014-06-18 22:58 . 2014-07-09 15:19 2266112 ----a-w- c:\windows\system32\wininet.dll
2014-06-18 22:52 . 2014-07-09 15:19 4254720 ----a-w- c:\windows\SysWow64\jscript9.dll
2014-06-18 22:51 . 2014-07-09 15:19 13527040 ----a-w- c:\windows\system32\ieframe.dll
2014-06-18 22:46 . 2014-07-09 15:19 1068032 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2014-06-18 22:45 . 2014-07-09 15:19 1964544 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2014-06-18 22:34 . 2014-07-09 15:19 1393664 ----a-w- c:\windows\system32\urlmon.dll
2014-06-18 22:15 . 2014-07-09 15:19 846336 ----a-w- c:\windows\system32\ieapfltr.dll
2014-06-18 22:13 . 2014-07-09 15:19 1791488 ----a-w- c:\windows\SysWow64\wininet.dll
2014-06-18 02:18 . 2014-07-09 15:08 692736 ----a-w- c:\windows\system32\osk.exe
2014-06-18 01:51 . 2014-07-09 15:08 646144 ----a-w- c:\windows\SysWow64\osk.exe
2014-06-18 01:10 . 2014-07-09 15:08 3157504 ----a-w- c:\windows\system32\win32k.sys
2014-06-06 10:10 . 2014-07-09 15:07 624128 ----a-w- c:\windows\system32\qedit.dll
2014-06-06 09:44 . 2014-07-09 15:07 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2014-06-05 14:45 . 2014-07-09 15:02 1460736 ----a-w- c:\windows\system32\lsasrv.dll
2014-06-05 14:26 . 2014-07-09 15:02 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2014-06-05 14:25 . 2014-07-09 15:02 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2014-05-30 08:08 . 2014-07-09 15:07 210944 ----a-w- c:\windows\system32\wdigest.dll
2014-05-30 08:08 . 2014-07-09 15:07 86528 ----a-w- c:\windows\system32\TSpkg.dll
2014-05-30 08:08 . 2014-07-09 15:07 340992 ----a-w- c:\windows\system32\schannel.dll
2014-05-30 08:08 . 2014-07-09 15:07 314880 ----a-w- c:\windows\system32\msv1_0.dll
2014-05-30 08:08 . 2014-07-09 15:07 307200 ----a-w- c:\windows\system32\ncrypt.dll
2014-05-30 08:08 . 2014-07-09 15:07 728064 ----a-w- c:\windows\system32\kerberos.dll
2014-05-30 08:08 . 2014-07-09 15:07 22016 ----a-w- c:\windows\system32\credssp.dll
2014-05-30 07:52 . 2014-07-09 15:07 172032 ----a-w- c:\windows\SysWow64\wdigest.dll
2014-05-30 07:52 . 2014-07-09 15:07 65536 ----a-w- c:\windows\SysWow64\TSpkg.dll
2014-05-30 07:52 . 2014-07-09 15:07 247808 ----a-w- c:\windows\SysWow64\schannel.dll
2014-05-30 07:52 . 2014-07-09 15:07 220160 ----a-w- c:\windows\SysWow64\ncrypt.dll
2014-05-30 07:52 . 2014-07-09 15:07 259584 ----a-w- c:\windows\SysWow64\msv1_0.dll
2014-05-30 07:52 . 2014-07-09 15:07 550912 ----a-w- c:\windows\SysWow64\kerberos.dll
2014-05-30 07:52 . 2014-07-09 15:07 17408 ----a-w- c:\windows\SysWow64\credssp.dll
2014-05-30 06:45 . 2014-07-09 15:07 497152 ----a-w- c:\windows\system32\drivers\afd.sys
2014-05-18 20:18 . 2014-05-18 20:18 11899396 ----a-w- c:\windows\FRIEDRIC.sCr
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"Raptr"="c:\progra~2\Raptr\raptrstub.exe" [2014-07-30 55360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2013-05-01 421888]
"AvastUI.exe"="c:\program files\Internet\Avast5\AvastUI.exe" [2014-08-01 4085896]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-04-17 767200]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Ralink Wireless Utility.lnk - c:\program files (x86)\Ralink\Common\RaUI.exe -s [2011-6-7 11474272]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
R0 CLBStor;CyberLink InstantBurn UDF Reader Help Driver; [x]
R1 EIO64;EIO Driver;c:\windows\system32\DRIVERS\EIO64.sys;c:\windows\SYSNATIVE\DRIVERS\EIO64.sys [x]
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R2 CLBUDFR;CyberLink UDF Filesystem; [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxWatch13.exe;c:\program files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxWatch13.exe [x]
R3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\DRIVERS\lgandbus64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandbus64.sys [x]
R3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\DRIVERS\lganddiag64.sys;c:\windows\SYSNATIVE\DRIVERS\lganddiag64.sys [x]
R3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\DRIVERS\lgandgps64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandgps64.sys [x]
R3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\DRIVERS\lgandmodem64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandmodem64.sys [x]
R3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\DRIVERS\lgandnetdiag64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetdiag64.sys [x]
R3 AndNetGps;LGE AndroidNet USB GPS NMEA Port;c:\windows\system32\DRIVERS\lgandnetgps64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetgps64.sys [x]
R3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\DRIVERS\lgandnetmodem64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetmodem64.sys [x]
R3 andnetndis;LGE AndroidNet NDIS Ethernet Adapter;c:\windows\system32\DRIVERS\lgandnetndis64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetndis64.sys [x]
R3 ATICDSDr;ATICDSDr;c:\users\Marcel\AppData\Local\Temp\ATICDSDr.sys;c:\users\Marcel\AppData\Local\Temp\ATICDSDr.sys [x]
R3 avmeject;AVM Eject;c:\windows\system32\drivers\avmeject.sys;c:\windows\SYSNATIVE\drivers\avmeject.sys [x]
R3 bfturboh;BUFFALO TurboUSB for HD Filter;c:\windows\system32\drivers\bfturboh.sys;c:\windows\SYSNATIVE\drivers\bfturboh.sys [x]
R3 cpuz135;cpuz135;c:\windows\TEMP\cpuz135\cpuz135_x64.sys;c:\windows\TEMP\cpuz135\cpuz135_x64.sys [x]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [x]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 DrvAgent64;DrvAgent64;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS [x]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys;c:\windows\SYSNATIVE\epmntdrv.sys [x]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys;c:\windows\SYSNATIVE\EuGdiDrv.sys [x]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [x]
R3 FWLANUSB;AVM FRITZ!WLAN;c:\windows\system32\DRIVERS\fwlanusb.sys;c:\windows\SYSNATIVE\DRIVERS\fwlanusb.sys [x]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys;c:\windows\SYSNATIVE\Drivers\ANDROIDUSB.sys [x]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys;c:\windows\SYSNATIVE\DRIVERS\htcnprot.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\DRIVERS\lgbtpt64.sys;c:\windows\SYSNATIVE\DRIVERS\lgbtpt64.sys [x]
R3 LGPBTDD;LGPBTDD.sys Display Driver;c:\windows\system32\Drivers\LGPBTDD.sys;c:\windows\SYSNATIVE\Drivers\LGPBTDD.sys [x]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\DRIVERS\lgvmdm64.sys;c:\windows\SYSNATIVE\DRIVERS\lgvmdm64.sys [x]
R3 libusb0;libusb-win32 - Kernel Driver 04/08/2011 1.2.4.0;c:\windows\system32\DRIVERS\libusb0.sys;c:\windows\SYSNATIVE\DRIVERS\libusb0.sys [x]
R3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys;c:\windows\SYSNATIVE\DRIVERS\LVPr2M64.sys [x]
R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
R3 LVUVC64;Logitech QuickCam Pro 9000(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
R3 nmwcdcx64;Nokia USB Generic;c:\windows\system32\drivers\ccdcmbox64.sys;c:\windows\SYSNATIVE\drivers\ccdcmbox64.sys [x]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\ccdcmbx64.sys;c:\windows\SYSNATIVE\drivers\ccdcmbx64.sys [x]
R3 PAC207;SoC PC-Camera;c:\windows\system32\DRIVERS\PFC027.SYS;c:\windows\SYSNATIVE\DRIVERS\PFC027.SYS [x]
R3 Ph3xIB64;Philips 713x Inbox PCI TV Card;c:\windows\system32\DRIVERS\Ph3xIB64.sys;c:\windows\SYSNATIVE\DRIVERS\Ph3xIB64.sys [x]
R3 RaMediaServer;Ralink UPnP Media Server;c:\program files (x86)\Ralink\Common\RaMediaServer.exe;c:\program files (x86)\Ralink\Common\RaMediaServer.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RoxMediaDB13;RoxMediaDB13;c:\program files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxMediaDB13.exe;c:\program files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxMediaDB13.exe [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 USBMULCD;USB Multi-Channel Audio Device Interface;c:\windows\system32\drivers\CM10664.sys;c:\windows\SYSNATIVE\drivers\CM10664.sys [x]
R3 WSDScan;WSD-Scanunterstützung durch UMB;c:\windows\system32\drivers\WSDScan.sys;c:\windows\SYSNATIVE\drivers\WSDScan.sys [x]
R3 XENfiltv;XENfiltv;c:\windows\system32\drivers\XENfiltv.sys;c:\windows\SYSNATIVE\drivers\XENfiltv.sys [x]
R3 zlportio;zlportio;g:\software\Audio - Bearbeitung\Ultrastar\Ultrastar-Deluxe-100\zlportio.sys;g:\software\Audio - Bearbeitung\Ultrastar\Ultrastar-Deluxe-100\zlportio.sys [x]
R4 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe;c:\program files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe [x]
R4 BOT4Service;BOT4Service;c:\program files (x86)\Roxio\BackOnTrack\App\BService.exe;c:\program files (x86)\Roxio\BackOnTrack\App\BService.exe [x]
R4 CyberLink PowerDVD 12 Media Server Monitor Service;CyberLink PowerDVD 12 Media Server Monitor Service;c:\program files (x86)\PowerDVD 12\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe;c:\program files (x86)\PowerDVD 12\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [x]
R4 CyberLink PowerDVD 12 Media Server Service;CyberLink PowerDVD 12 Media Server Service;c:\program files (x86)\PowerDVD 12\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe;c:\program files (x86)\PowerDVD 12\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [x]
R4 LVPrcS64;Process Monitor;c:\program files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe;c:\program files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe [x]
R4 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 OODrvled;OODrvled;c:\windows\system32\DRIVERS\OODrvled.sys;c:\windows\SYSNATIVE\DRIVERS\OODrvled.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S0 Sahdad64;HDD Filter Driver;c:\windows\System32\Drivers\Sahdad64.sys;c:\windows\SYSNATIVE\Drivers\Sahdad64.sys [x]
S0 Saibad64;Volume Filter Driver;c:\windows\System32\Drivers\Saibad64.sys;c:\windows\SYSNATIVE\Drivers\Saibad64.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S0 tclondrv;tclondrv;c:\windows\system32\DRIVERS\tclondrv.sys;c:\windows\SYSNATIVE\DRIVERS\tclondrv.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 iZ3DInjectionDriver;Driver inject our D3D and OGL wrappers;c:\program files (x86)\iZ3D Driver\Win64\S3DInjectionDriver.sys;c:\program files (x86)\iZ3D Driver\Win64\S3DInjectionDriver.sys [x]
S1 SaibVdAd64;Virtual Disk Driver;c:\windows\system32\Drivers\SaibVdAd64.sys;c:\windows\SYSNATIVE\Drivers\SaibVdAd64.sys [x]
S2 {329F96B6-DF1E-4328-BFDA-39EA953C1312};Power Control [2012/12/28 20:10];c:\program files (x86)\PowerDVD 12\PowerDVD12\Common\NavFilter\000.fcl;c:\program files (x86)\PowerDVD 12\PowerDVD12\Common\NavFilter\000.fcl [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [x]
S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [x]
S2 CLHNServiceForPowerDVD12;CLHNServiceForPowerDVD12;c:\program files (x86)\PowerDVD 12\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe;c:\program files (x86)\PowerDVD 12\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe [x]
S2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x64.sys;c:\windows\SYSNATIVE\drivers\cpuz133_x64.sys [x]
S2 GS In-Game Service;GS In-Game Service;c:\program files (x86)\GameTracker\GSInGameService.exe;c:\program files (x86)\GameTracker\GSInGameService.exe [x]
S2 HTCMonitorService;HTCMonitorService;c:\program files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe;c:\program files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [x]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
S2 ntk_PowerDVD12;ntk_PowerDVD12;c:\program files (x86)\PowerDVD 12\PowerDVD12\Kernel\DMP\CLHNServer\ntk_PowerDVD12_64.sys;c:\program files (x86)\PowerDVD 12\PowerDVD12\Kernel\DMP\CLHNServer\ntk_PowerDVD12_64.sys [x]
S2 O&O DriveLED;O&O DriveLED Service;c:\program files\System\O&O Software\DriveLED\oodlag.exe;c:\program files\System\O&O Software\DriveLED\oodlag.exe [x]
S2 OODefragAgent;O&O Defrag;c:\program files\System\O&O Software\Defrag 15\oodag.exe;c:\program files\System\O&O Software\Defrag 15\oodag.exe [x]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [x]
S2 RalinkRegistryWriter64;Ralink Registry Writer 64;c:\program files (x86)\Ralink\Common\RaRegistry64.exe;c:\program files (x86)\Ralink\Common\RaRegistry64.exe [x]
S2 S3D Service (Win32);S3D Service (Win32);c:\program files (x86)\iZ3D Driver\Win32\S3DCService.exe;c:\program files (x86)\iZ3D Driver\Win32\S3DCService.exe [x]
S2 S3D Service (Win64);S3D Service (Win64);c:\program files (x86)\iZ3D Driver\Win64\S3DCService.exe;c:\program files (x86)\iZ3D Driver\Win64\S3DCService.exe [x]
S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 lgbusenum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x]
S3 LGSUsbFilt;Logitech Gaming KMDF USB Filter Driver;c:\windows\system32\DRIVERS\LGSUsbFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSUsbFilt.Sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 SaiK0728;SaiK0728;c:\windows\system32\DRIVERS\SaiK0728.sys;c:\windows\SYSNATIVE\DRIVERS\SaiK0728.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-06-20 13:05 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-08-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-12 16:29]
.
2014-08-11 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2598369041-3088188982-4083831754-1001Core.job
- c:\users\Marcel\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-13 21:40]
.
2014-08-12 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2598369041-3088188982-4083831754-1001UA.job
- c:\users\Marcel\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-13 21:40]
.
2014-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-21 12:33]
.
2014-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-21 12:33]
.
2014-08-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2598369041-3088188982-4083831754-1001Core1cc0560e24762f0.job
- c:\users\Marcel\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-20 12:33]
.
2014-08-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2598369041-3088188982-4083831754-1001UA.job
- c:\users\Marcel\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-20 12:33]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-08-01 21:31 634872 ----a-w- c:\program files\Internet\Avast5\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-03-26 10135584]
"OODefragTray"="c:\program files\System\O&O Software\Defrag 15\oodtray.exe" [2012-06-06 3998064]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2013-02-28 7468784]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
uInternet Settings,ProxyOverride = <-loopback>
uSearchAssistant = hxxp://www.google.com
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Nach Microsoft E&xel exportieren - c:\progra~2\BRO~1\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
FF - ProfilePath - c:\users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\9fd24iea.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search
FF - prefs.js: browser.search.selectedEngine - Microsoft (Bing)
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/?pc=AV01
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search
FF - prefs.js: network.proxy.ftp - hxxp://americanproxie.info/
FF - prefs.js: network.proxy.ftp_port - 66
FF - prefs.js: network.proxy.http - hxxp://americanproxie.info/
FF - prefs.js: network.proxy.http_port - 66
FF - prefs.js: network.proxy.socks - hxxp://americanproxie.info/
FF - prefs.js: network.proxy.socks_port - 66
FF - prefs.js: network.proxy.ssl - hxxp://americanproxie.info/
FF - prefs.js: network.proxy.ssl_port - 66
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2014-07-14 18:22; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; c:\program files (x86)\Internet\Mozilla Firefox 3\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi
FF - ExtSQL: !HIDDEN! 2012-07-29 11:25; {9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}; c:\users\Marcel\AppData\Roaming\14001.006
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-Wondershare Helper Compact.exe - c:\program files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelperSetup.exe
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files (x86)\Medien\DivX\DivXCodecUninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\{329F96B6-DF1E-4328-BFDA-39EA953C1312}]
"ImagePath"="\??\c:\program files (x86)\PowerDVD 12\PowerDVD12\Common\NavFilter\000.fcl"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2598369041-3088188982-4083831754-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:d0,95,78,df,bb,a3,f3,55,e4,c6,cf,e9,38,de,23,b0,72,8b,b3,03,59,30,1d,
37,f6,1a,f2,19,0f,f2,db,51,79,91,1e,13,01,8b,e2,5b,0d,3f,84,d5,30,3c,77,22,\
"??"=hex:65,34,23,f1,ac,3e,ae,99,14,20,f8,2a,53,ca,02,2f
.
[HKEY_USERS\S-1-5-21-2598369041-3088188982-4083831754-1001\Software\SecuROM\License information*]
"datasecu"=hex:5c,8d,18,e8,6a,4e,cd,d5,67,4e,a4,91,f1,2c,fa,f5,79,c5,28,f5,2a,
b6,e5,5e,dc,48,9d,b4,50,ca,a9,8a,2c,9b,09,5e,6d,a5,ee,31,7a,81,67,23,40,d1,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.14"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG12.00.00.01PROFESSIONAL"="30223B8BD013AB3604494EEBD33C33CE0DA41BA48D976E7534D3AED067AC7CBD0B4E9FBC4FCA2F61B527BBFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6171C11EC38DE3D9DB7CE019D40AA5CA2D97226D213B55585CEE68BC67CAFC4C468A66708C7F1F7E1DE7D4D44A2A3616BB4D2313E76DE97DBBA7B3D595FFE0605CA801E4B12E3150AD6E793E1924BAB6AD216D2CB4031771B58B942082E4F0B35B1CC75CEC69CCAAA24A10816CB66AA9393033FA816F5B50B71DE00C238C9F215FE8A8E485D56861CD90B2C048862B7F962F973FE196CBC95E6ED8EDCA41CD188A6FB40D5A050275B2248B1B0DA31A2D3BCA01DDBBC5466C92A2CBC8E6DFAAF96B0AA1477305104893A428184A445ACF9B5E023334B7581DB43240D715F9C89EAB85FCA917D9CE5EA7324B6CE1F1A8A6A72669D5BE098D0A0CCA333069C3ACE58712AD4ED4F01096AB2DE203F55A9E7C7ADA2590E6E0B8B93F7BD19B01B93E3CF1C5E59B6C0CD9E1271A5C26C2675E1D636CCD5E9B81EDC550648DC36A4EBA0E9139233FD41564B95BCF155CEC7828A036EDA48F0D728E3A64FDC50C4D608CFE2C12270B693F12947367F4244BF5AE8D94C8C988AB983B3EFBE5A77692435B21A28AD543BCD7BC422934D2A0EEA87768BD9E1E4001F8C533AD3E18D99D0BFFD155C16D3C55AD39E419D2061D1781C21EF351FFB801BA53D3721DA7F2CF87AD77904831C78795FACE63180ED996D2CC980114FE39D98B4E0B7CFEDEDDA08BDDD95DC6188573C8356F7C03B0CD0A0D0485A33BED2CFD3A2A132980B304741639F56B75E2E4A0B2E7BFBCFDEAB4ABC2666C0F67EB7EEDB5C5643CC634EF3B949A0D2F76E521E9E4DE92179C06F3C434DE09849E3333B975549A9CEEC0648DAD259BF95C7F082085569B8E879AFBD876AEA6B2E8717D5BE03B9471562C88F6466B6FB1EE4B60DA8BDB036E163774EB1A72AE7B9476E46DEDDDB232D413DF8E5EE1686B08686353702EEB3B79F86CDBCAF396097C3F5F4576455E8344CBB98C5DA4F02023077D7BF23446DD492CF83F7B325C986E29B335F17C2E6DE09D266BE1DA6B7592754B420A2C44536647C17886970BED74D06B1FC7DB010734242BB5CACDA1315F79AF18B0AF93E6D806617658990FB71EF0D078EA0A47C4E86815983039AA324707D168763E1829F181DF35BCD70E44EFB3E2DC48D15E4DCA6B9E2E79F0B9D8AA5E38DEFBF6CDF849E658209FAED7EFCE7D883A3556C29243947DE9305C1D8E1EDE7AAF4B1FE456B4CB47EE1D25B729F6AD14B0510094DBA19BCB9E4B94ED155E3D79F95517348B41DB884309E7E8F6C03D12C94D33F764CE3DF410D48AD27A5E6B6862C3B15A25652D0948C2C10C7ADF134AFD342D5F0187BA82B"
"OODEFRAG15.00.00.01PROFESSIONAL"="AE293E862BBEC74AF01FDF7067DDAC1AB984B67F7A744BADEA6784B312735EABA6A26DF46F1E7DA39D753BCFC38230726F692FF30E4781729402649A9A48AFF86244C0A20181E427150E7A1243CFFE8DF0B12A58EB77EE9A70F5EAE84B05A15B02528E253A78748B56055F1571414B743F7AF3EBEF8DA0259F7D8EE3735FB5E7684195E6FA83CA98A4AF8E8760C5EA489F1338437D81C42609062526E47D9545BB3CF4A8A616A8AD8A9513ED233DD6381B000BC9F8C5ACC2D530691E787C0E31E9A231FA251B723AD2F1589ED37F2E8BFD7BE1BA4DBA51B8FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A6171C11EC38DE3DA9C6AECB7A5D1407BA7FD869164D6794F02D5450A82BFB48197F01D5B77067A90A6B1D1CD84C315EC665466680B11DB50DC7372D5503F8F871765ADFDC9BF0E08F54F0862EAEFB544507C127BB7258FA048D5AF6269D1399302165EEA633A4C50A6C0D9D801E1A66338FE7CC8C9F5005BA738200CD8B3F6739F06FBA1652D18AFE42E59841E153DCD9477936F4CD674FD9A05BE97D4D1834360A2A49B1896BF6B915588767379293C2AF9B197E06226B4C70F0AD715A5AE715442DF8835A88E5C8DC24CA6E4DE8F93CF7D679B2C4A780C272B417E31AE8FA07ACF2F917BC63467CC26D1AD4C88995DA8916B4A2FCC6C531E9FB44166E49FC8084D8507F99DA9CEAA239FC9CC04CFDF47DAB7661907089CF4F802C4DA5A58FBABF22D652D2F2FE708FF5524DC12E6026A1C9C2075B38AC9A4D5F93D1084CE9338774B82A3A5119A9CFEFCAEF4B4DFC4E7A8BF1AE29D8A5D2C41A97EF4E2E542B375B76A21642A9F8D9DC6E95526E268F3D6A2DF93AAD7C7BC71628F8A7E0AFA75FC466DEA2B385055E53154F3E7A4651D4C97309C437CD5D9D1D09C0B520EB71458230050E3712B73DCEEC346B7BD83EDEEB9706F11C4D0442DCD1A00EC7909561CA50BC7C07CBBE8C2DF7DD2A236E46AFF9C01C5FA43EBF6665ECF43B5B38E560B91934837BC10C16B48C6DBDC32B1D4C80697A9B3D7A256CAC1C9E3B808F77A14BAD9E2F1497D6560B5402DD56C738706FDFD5ADF66E8B6B0D7282007F5BA23B6487B07EF30419FE3C4B4638F68E530A1B48650E071D10B042D708EE48EE06F44972A3E262D110F637C4E1EBE362EDBA3C18E3AAC59A13B9EF089C63EBB602CA2691B5C649E1BED650E6040C82B5CBD96F9A91E13090373B991232A920B03BEE87572881B7A56A6C3DAA60A1DA9272F2B46D328CE73CE59CA95ABA863FED1B44E18E416461A49E399ADEADA818132FC2F1060E70316FCA79EB1932ACC696CE638AD1CA319DFBA8F1E62325118A690FBC6CA86FCCF48E56A093D99248D863481ABB92119FE4D99A0087EF85BFA5D8"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-08-12 18:19:37
ComboFix-quarantined-files.txt 2014-08-12 16:19
.
Vor Suchlauf: 18 Verzeichnis(se), 152.732.270.592 Bytes frei
Nach Suchlauf: 25 Verzeichnis(se), 157.257.621.504 Bytes frei
.
- - End Of File - - F5DF5EF2B661B2EEC9869E4A48B9C187
72B8CE41AF0DE751C946802B3ED844B4 |