dieFackel | 30.11.2011 16:00 | Da ist er auch schon: Code:
ComboFix 11-11-30.01 - Laner 30.11.2011 15:49:03.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.49.1031.18.4093.2728 [GMT 1:00]
ausgeführt von:: c:\users\Laner\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Funload.de
c:\program files (x86)\Funload.de\Funload.deToolbarHelper.exe
c:\program files (x86)\Funload.de\Funload.deToolbarHelper1.exe
c:\program files (x86)\Funload.de\GottenAppsContextMenu.xml
c:\program files (x86)\Funload.de\INSTALL.LOG
c:\program files (x86)\Funload.de\OtherAppsContextMenu.xml
c:\program files (x86)\Funload.de\SharedAppsContextMenu.xml
c:\program files (x86)\Funload.de\tbFun0.dll
c:\program files (x86)\Funload.de\tbFun1.dll
c:\program files (x86)\Funload.de\tbFunl.dll
c:\program files (x86)\Funload.de\toolbar.cfg
c:\program files (x86)\Funload.de\ToolbarContextMenu.xml
c:\program files (x86)\Funload.de\uninstall.exe
c:\program files (x86)\Funload.de\UNWISE.EXE
c:\program files (x86)\Funload.de\UNWISE.INI
c:\users\Laner\AppData\Roaming\Microsoft\Windows\Recent\Total War SHOGUN 2 (2).url
c:\users\Laner\AppData\Roaming\Microsoft\Windows\Recent\Total War SHOGUN 2.url
c:\users\Laner\Documents\Downloads\Integrated_CT2629906.exe
D:\install.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2011-10-28 bis 2011-11-30 ))))))))))))))))))))))))))))))
.
.
2011-11-30 14:53 . 2011-11-30 14:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-11-29 18:25 . 2011-11-29 18:25 -------- d-----w- C:\_OTL
2011-11-29 13:18 . 2011-10-18 00:27 8570192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FDC35495-4AF9-4C9E-8646-A0F4D15E437A}\mpengine.dll
2011-11-27 23:57 . 2011-11-28 00:26 -------- d-----w- c:\program files (x86)\Simple Port Forwarding
2011-11-27 23:57 . 2011-11-27 23:57 -------- d-----w- c:\windows\Simple Port Forwarding
2011-11-25 18:41 . 2011-11-25 18:41 -------- d-----w- c:\users\Laner\AppData\Roaming\Avira
2011-11-25 18:20 . 2011-10-19 15:56 97312 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-11-25 18:20 . 2011-10-19 15:56 27760 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2011-11-25 18:20 . 2011-10-19 15:56 130760 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-11-25 18:20 . 2011-11-25 18:20 -------- d-----w- c:\programdata\Avira
2011-11-25 18:20 . 2011-11-25 18:20 -------- d-----w- c:\program files (x86)\Avira
2011-11-24 17:50 . 2011-11-24 17:50 -------- d-----w- c:\program files (x86)\ESET
2011-11-24 17:43 . 2011-11-25 18:18 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-11-24 17:43 . 2011-11-25 18:18 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2011-11-24 17:16 . 2011-11-24 17:16 -------- d-----w- c:\users\Laner\AppData\Roaming\Malwarebytes
2011-11-24 17:16 . 2011-11-24 17:16 -------- d-----w- c:\programdata\Malwarebytes
2011-11-24 17:16 . 2011-11-24 17:16 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-11-24 17:16 . 2011-08-31 16:00 25416 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-20 13:23 . 2011-11-20 18:29 -------- d-----w- c:\users\Laner\AppData\Local\ESN Sonar
2011-11-19 21:29 . 2011-11-20 13:15 -------- d-----w- c:\users\UpdatusUser
2011-11-19 21:28 . 2011-10-15 08:53 837952 ----a-w- c:\windows\system32\easyupdatusapiu64.dll
2011-11-19 19:29 . 2011-11-29 22:34 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2011-11-19 19:29 . 2011-11-19 19:29 -------- d-----w- c:\users\Laner\AppData\Local\PunkBuster
2011-11-19 19:27 . 2011-11-19 19:27 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins
2011-11-19 18:50 . 2011-11-19 18:50 -------- d--h--w- c:\program files (x86)\Common Files\EAInstaller
2011-11-19 18:50 . 2011-11-29 22:34 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-11-19 18:50 . 2011-11-29 20:39 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2011-11-19 18:50 . 2011-11-19 19:02 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-11-19 17:38 . 2011-11-19 17:46 -------- d-----w- c:\users\Laner\AppData\Roaming\Origin
2011-11-19 17:37 . 2011-11-19 17:37 -------- d-----w- c:\users\Laner\AppData\Local\Origin
2011-11-19 17:37 . 2011-11-19 19:25 -------- d-----w- c:\programdata\Origin
2011-11-19 17:37 . 2011-11-19 18:18 -------- d-----w- c:\program files (x86)\Origin Games
2011-11-19 17:37 . 2011-11-19 17:41 -------- d-----w- c:\program files (x86)\Origin
2011-11-17 18:09 . 2011-11-28 23:05 -------- d-----w- c:\users\Laner\AppData\Local\CrashDumps
2011-11-17 17:22 . 2011-11-18 01:19 -------- d-----w- c:\users\Laner\AppData\Local\NPE
2011-11-17 17:22 . 2011-11-17 17:23 -------- d-----w- c:\programdata\Norton
2011-11-12 00:04 . 2011-11-12 00:04 -------- d-----w- c:\users\Laner\AppData\Local\Skyrim
2011-11-11 20:08 . 2011-10-01 05:28 886784 ----a-w- c:\program files\Common Files\System\wab32.dll
2011-11-11 20:08 . 2011-10-01 04:43 708608 ----a-w- c:\program files (x86)\Common Files\System\wab32.dll
2011-11-11 19:52 . 2011-09-29 04:09 3141120 ----a-w- c:\windows\system32\win32k.sys
2011-11-11 19:49 . 2011-08-17 05:32 613888 ----a-w- c:\windows\system32\psisdecd.dll
2011-11-11 19:49 . 2011-08-17 05:27 75776 ----a-w- c:\windows\system32\MSDvbNP.ax
2011-11-11 19:49 . 2011-08-17 05:27 288256 ----a-w- c:\windows\system32\MSNP.ax
2011-11-11 19:49 . 2011-08-17 05:27 108032 ----a-w- c:\windows\system32\psisrndr.ax
2011-11-11 19:49 . 2011-08-17 05:27 104960 ----a-w- c:\windows\system32\Mpeg2Data.ax
2011-11-11 19:49 . 2011-08-17 04:26 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll
2011-11-11 19:49 . 2011-08-17 04:22 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2011-11-11 19:49 . 2011-08-17 04:22 72704 ----a-w- c:\windows\SysWow64\Mpeg2Data.ax
2011-11-11 19:49 . 2011-08-17 04:22 59904 ----a-w- c:\windows\SysWow64\MSDvbNP.ax
2011-11-11 19:49 . 2011-08-17 04:22 204288 ----a-w- c:\windows\SysWow64\MSNP.ax
2011-11-11 19:47 . 2011-08-15 05:08 6144 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2011-11-11 19:47 . 2011-08-15 04:25 6144 ----a-w- c:\program files (x86)\Internet Explorer\iecompat.dll
2011-11-11 19:42 . 2011-08-27 05:40 861184 ----a-w- c:\windows\system32\oleaut32.dll
2011-11-11 19:42 . 2011-08-27 05:40 331776 ----a-w- c:\windows\system32\oleacc.dll
2011-11-11 19:42 . 2011-08-27 04:43 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-11-11 19:42 . 2011-08-27 04:43 233472 ----a-w- c:\windows\SysWow64\oleacc.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-30 14:54 . 2010-12-28 10:27 25640 ----a-w- c:\windows\gdrv.sys
2011-10-15 08:53 . 2010-12-28 10:24 8791360 ----a-w- c:\windows\system32\nvwgf2umx.dll
2011-10-15 08:53 . 2010-12-28 10:24 7041856 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2011-10-15 08:53 . 2010-12-28 10:24 2808128 ----a-w- c:\windows\system32\nvapi64.dll
2011-10-15 08:53 . 2010-12-28 10:24 2458432 ----a-w- c:\windows\SysWow64\nvapi.dll
2011-10-15 08:53 . 2010-12-28 10:24 13205312 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2011-10-15 08:53 . 2010-10-16 12:13 10406208 ----a-w- c:\windows\system32\nvcpl.dll
2011-10-15 08:53 . 2010-10-16 12:13 5067584 ----a-w- c:\windows\system32\nvsvc64.dll
2011-10-15 08:53 . 2010-10-16 12:13 222528 ----a-w- c:\windows\system32\nvmctray.dll
2011-10-15 08:53 . 2010-10-16 12:13 3074368 ----a-w- c:\windows\system32\nvsvcr.dll
2011-10-15 08:53 . 2010-10-16 12:13 1640768 ----a-w- c:\windows\system32\nvvsvc.exe
2011-10-15 08:53 . 2010-10-16 12:13 137536 ----a-w- c:\windows\system32\nvshext.dll
2011-10-14 23:54 . 2011-10-14 23:54 321856 ----a-w- c:\windows\SysWow64\nvStreaming.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-08-04 1242448]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"BitTorrent"="c:\program files (x86)\BitTorrent\BitTorrent.exe" [2010-12-29 397688]
"ManyCam"="c:\program files (x86)\ManyCam\Bin\ManyCam.exe" [2011-03-21 1752136]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"EADM"="c:\program files (x86)\Origin\Origin.exe" [2011-11-07 28846216]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BCU"="c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" [2009-10-15 375000]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-01-19 43632]
"NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-11-20 106496]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-10-19 258512]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\drivers\x64\3\EKIJ5000MUI.exe" [2010-09-02 2045440]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-12-31 1196048]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-01-26 136176]
R2 ICQ Service;ICQ Service;c:\program files (x86)\ICQ6Toolbar\ICQ Service.exe [x]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-01-26 136176]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 hotcore3;hc3ServiceName;c:\windows\system32\DRIVERS\hotcore3.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-10-19 86224]
S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-10-15 223464]
S2 ES lite Service;ES lite Service for program management.;c:\program files (x86)\Gigabyte\EasySaver\ESSVR.EXE [2009-08-24 68136]
S2 JMB36X;JMB36X;c:\windows\SysWOW64\XSrvSetup.exe [2010-01-19 72304]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2011-11-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-01-26 09:31]
.
2011-11-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-01-26 09:31]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-06 10144288]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 242192]
"EKIJ5000StatusMonitor"="c:\windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe" [2010-09-02 2045440]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page =
mLocal Page =
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files (x86)\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Laner\AppData\Roaming\Mozilla\Firefox\Profiles\mq82ssea.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Google
pref('extensions.shownSelectionUI',true); pref('extensions.autoDisableScopes',0);
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-Funload.de Toolbar - c:\program files (x86)\Funload.de\uninstall.exe
AddRemove-ICQToolbar - c:\program files (x86)\ICQ6Toolbar\ICQUnToolbar.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-128432448-2284216070-1018584416-1000\Software\SecuROM\License information*]
"datasecu"=hex:d3,af,df,c7,41,bb,30,8f,b0,c4,91,d6,e2,92,ba,44,08,39,7a,99,29,
63,18,7e,ad,89,2d,d4,50,63,7b,2b,0c,73,13,bf,d0,42,be,52,4c,4d,d7,ca,b3,8e,\
"rkeysecu"=hex:35,1c,4f,ee,99,72,0d,b8,74,7a,68,8b,8e,ae,85,49
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{6EF568F4-D437-4466-AA63-A3645136D93E}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}]
@Denied: (A 2) (Everyone)
@="IFlashBroker"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib]
@="{6EF568F4-D437-4466-AA63-A3645136D93E}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]
@Denied: (A 2) (Everyone)
@="IFlashBroker2"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]
@="{6EF568F4-D437-4466-AA63-A3645136D93E}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files\Logitech\SetPoint\x86\SetPoint32.exe
c:\program files (x86)\Common Files\Steam\SteamService.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2011-11-30 15:59:18 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2011-11-30 14:59
.
Vor Suchlauf: 11 Verzeichnis(se), 20.602.621.952 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 20.487.979.008 Bytes frei
.
- - End Of File - - 5AE2FA5B3C4E5AD550E6AFD03D8B3556 LG dieFackel |