Guten Abend Schrauber
Hier wären die Ergebnisse: Code:
ComboFix 14-02-24.02 - XXX 24.02.2014 19:33:51.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.41.1031.18.4092.2401 [GMT 1:00]
ausgeführt von:: c:\users\XXX\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-01-24 bis 2014-02-24 ))))))))))))))))))))))))))))))
.
.
2014-02-24 18:44 . 2014-02-24 18:44 -------- d-----w- c:\users\Public\AppData\Local\temp
2014-02-24 18:44 . 2014-02-24 18:44 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-02-24 18:44 . 2014-02-24 18:44 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2014-02-23 11:04 . 2014-02-23 11:06 -------- d-----w- C:\FRST
2014-02-13 20:55 . 2013-12-21 09:53 548864 ----a-w- c:\windows\system32\vbscript.dll
2014-02-13 20:55 . 2013-12-21 08:56 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2014-02-13 17:39 . 2013-12-06 02:30 1882112 ----a-w- c:\windows\system32\msxml3.dll
2014-02-13 17:39 . 2013-12-06 02:02 1237504 ----a-w- c:\windows\SysWow64\msxml3.dll
2014-02-13 17:39 . 2013-12-06 02:30 2048 ----a-w- c:\windows\system32\msxml3r.dll
2014-02-13 17:39 . 2013-12-06 02:02 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
2014-02-11 15:18 . 2013-09-01 10:59 1103872 ----a-w- c:\windows\SysWow64\CBLCtlsU.ocx
2014-02-11 15:18 . 2013-07-13 10:15 805376 ----a-w- c:\windows\SysWow64\EditCtlsU.ocx
2014-02-11 15:18 . 2013-07-12 20:57 539648 ----a-w- c:\windows\SysWow64\LblCtlsU.ocx
2014-02-11 15:18 . 2013-04-05 11:55 476160 ----a-w- c:\windows\SysWow64\TabStripCtlU.ocx
2014-02-11 15:18 . 2013-03-28 21:13 645632 ----a-w- c:\windows\SysWow64\BtnCtlsU.ocx
2014-02-11 15:18 . 2013-03-03 12:37 1061888 ----a-w- c:\windows\SysWow64\ExLvwU.ocx
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-02-16 22:00 . 2010-09-06 16:36 88567024 ----a-w- c:\windows\system32\MRT.exe
2014-02-13 17:27 . 2012-04-02 16:44 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-02-13 17:27 . 2011-05-19 21:08 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-01-09 08:37 . 2011-11-21 17:21 147456 ----a-w- c:\windows\SysWow64\bzpdfc.dll
2013-12-25 16:07 . 2009-08-18 10:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2013-12-25 16:07 . 2009-08-18 09:24 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-12-18 20:23 . 2013-10-13 06:52 84720 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-12-18 20:23 . 2013-10-13 06:50 131576 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-12-18 20:23 . 2013-10-13 06:50 108440 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-12-06 20:36 . 2013-12-06 20:36 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-12-06 20:36 . 2013-12-06 20:36 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-12-06 20:36 . 2013-12-06 20:36 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-12-06 20:36 . 2013-12-06 20:36 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2013-12-06 20:36 . 2013-12-06 20:36 235008 ----a-w- c:\windows\system32\elshyph.dll
2013-12-06 20:36 . 2013-12-06 20:36 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2013-12-06 20:36 . 2013-12-06 20:36 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-12-06 20:36 . 2013-12-06 20:36 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2013-12-06 20:36 . 2013-12-06 20:36 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-12-06 20:36 . 2013-12-06 20:36 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-12-06 20:36 . 2013-12-06 20:36 337408 ----a-w- c:\windows\SysWow64\html.iec
2013-12-06 20:36 . 2013-12-06 20:36 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-12-06 20:36 . 2013-12-06 20:36 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-12-06 20:36 . 2013-12-06 20:36 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2013-12-06 20:36 . 2013-12-06 20:36 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2013-12-06 20:36 . 2013-12-06 20:36 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-12-06 20:36 . 2013-12-06 20:36 942592 ----a-w- c:\windows\system32\jsIntl.dll
2013-12-06 20:36 . 2013-12-06 20:36 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-12-06 20:36 . 2013-12-06 20:36 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-12-06 20:36 . 2013-12-06 20:36 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-12-06 20:36 . 2013-12-06 20:36 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-12-06 20:36 . 2013-12-06 20:36 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-12-06 20:36 . 2013-12-06 20:36 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-12-06 20:36 . 2013-12-06 20:36 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-12-06 20:36 . 2013-12-06 20:36 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-12-06 20:36 . 2013-12-06 20:36 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-12-06 20:36 . 2013-12-06 20:36 247808 ----a-w- c:\windows\system32\msls31.dll
2013-12-06 20:36 . 2013-12-06 20:36 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2013-12-06 20:36 . 2013-12-06 20:36 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-12-06 20:36 . 2013-12-06 20:36 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-12-06 20:36 . 2013-12-06 20:36 105984 ----a-w- c:\windows\system32\iesysprep.dll
2013-12-06 20:36 . 2013-12-06 20:36 84992 ----a-w- c:\windows\system32\mshtmled.dll
2013-12-06 20:36 . 2013-12-06 20:36 81408 ----a-w- c:\windows\system32\icardie.dll
2013-12-06 20:36 . 2013-12-06 20:36 62464 ----a-w- c:\windows\system32\pngfilt.dll
2013-12-06 20:36 . 2013-12-06 20:36 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2013-12-06 20:36 . 2013-12-06 20:36 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2013-12-06 20:36 . 2013-12-06 20:36 413696 ----a-w- c:\windows\system32\html.iec
2013-12-06 20:36 . 2013-12-06 20:36 30208 ----a-w- c:\windows\system32\licmgr10.dll
2013-12-06 20:36 . 2013-12-06 20:36 296960 ----a-w- c:\windows\system32\dxtrans.dll
2013-12-06 20:36 . 2013-12-06 20:36 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2013-12-06 20:36 . 2013-12-06 20:36 243200 ----a-w- c:\windows\system32\webcheck.dll
2013-12-06 20:36 . 2013-12-06 20:36 235520 ----a-w- c:\windows\system32\url.dll
2013-12-06 20:36 . 2013-12-06 20:36 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-12-06 20:36 . 2013-12-06 20:36 147968 ----a-w- c:\windows\system32\occache.dll
2013-12-06 20:36 . 2013-12-06 20:36 143872 ----a-w- c:\windows\system32\wextract.exe
2013-12-06 20:36 . 2013-12-06 20:36 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-12-06 20:36 . 2013-12-06 20:36 101376 ----a-w- c:\windows\system32\inseng.dll
2013-12-06 20:36 . 2013-12-06 20:36 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-12-06 20:36 . 2013-12-06 20:36 774144 ----a-w- c:\windows\system32\jscript.dll
2013-12-06 20:36 . 2013-12-06 20:36 48128 ----a-w- c:\windows\system32\imgutil.dll
2013-12-06 20:36 . 2013-12-06 20:36 13824 ----a-w- c:\windows\system32\mshta.exe
2013-12-06 20:36 . 2013-12-06 20:36 135680 ----a-w- c:\windows\system32\iepeers.dll
2013-11-27 01:41 . 2014-01-15 18:45 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-11-27 01:41 . 2014-01-15 18:45 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-11-27 01:41 . 2014-01-15 18:45 53248 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-11-27 01:41 . 2014-01-15 18:45 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-11-27 01:41 . 2014-01-15 18:45 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-11-27 01:41 . 2014-01-15 18:45 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-11-27 01:41 . 2014-01-15 18:45 7808 ----a-w- c:\windows\system32\drivers\usbd.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2013-03-28 1511792]
"Steam"="c:\program files (x86)\Steam\Steam.exe" [2014-02-19 1822400]
"TomTomHOME.exe"="c:\program files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" [2013-08-27 248208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-03-15 98304]
"KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2009-12-25 34160]
"TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-02-23 2454840]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2013-03-28 310640]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-02-20 689744]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
CodecPackTrayMenu.lnk - c:\windows\SysWOW64\C2MP\TrayMenu.exe [2013-3-19 704008]
CodecPackUpdateChecker.lnk - c:\windows\SysWOW64\C2MP\UpdateChecker.exe [2013-3-23 38792]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableSecureUIAPath"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 npkcft64;npkcft64;c:\windows\SysWOW64\npkcft64.sys;c:\windows\SysWOW64\npkcft64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe;c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [x]
R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [x]
S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [x]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [x]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [x]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe;c:\program files\TOSHIBA\TECO\TecoService.exe [x]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys;c:\windows\SYSNATIVE\DRIVERS\TVALZFL.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys;c:\windows\SYSNATIVE\DRIVERS\pgeffect.sys [x]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys;c:\windows\SYSNATIVE\DRIVERS\rtl8192se.sys [x]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [x]
S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2014-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-18 17:43]
.
2014-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-18 17:43]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2010-02-11 1050072]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-03-22 10134560]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-03-22 896032]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-05 709976]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.bing.com/
uDefault_Search_URL = hxxp://www.google.com
uLocal Page = c:\windows\system32\blank.htm
IE: Free YouTube to MP3 Converter
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MIF5BA~1\Office14\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren
LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 192.168.192.1
DPF: {20BBA18F-5BC8-47B5-8FC9-5DFCA8E56A4B} - hxxp://mpi.dacom.net/XMPI/js/LGUplus_XMPI_20110503.cab
DPF: {48ECCD73-123C-4C25-A64C-76E8E8A30CAF} - hxxp://mpi.dacom.net/XPayMPI/XPayMPI.cab
DPF: {5547DED5-E6A9-469A-90F0-5BFE5CD33FF1} - hxxps://pay.kcp.co.kr/plugin_new/file/KCPPaymentUX.cab
DPF: {A0E7D0C1-9854-497E-8645-38C19AA00724} - hxxp://www.myasset.com/myasset/login/install/IssacWebSE_3_3_3_3.cab
DPF: {E78928A6-3D2A-4BF7-A100-F3FBAA351B49} - hxxps://www.vpay.co.kr/kvpfiles_new/KVPISPCTLD_VISTA64.cab
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
ShellIconOverlayIdentifiers-{1EC23CFF-4C58-458f-924C-8519AEF61B32} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-SmartFaceVWatcher - c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe
HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2538932297-768016801-4142167647-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd]
@DACL=(02 0000)
@SACL=
.
[HKEY_USERS\S-1-5-21-2538932297-768016801-4142167647-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms]
@DACL=(02 0000)
@SACL=
.
[HKEY_USERS\S-1-5-21-2538932297-768016801-4142167647-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmz]
@DACL=(02 0000)
@SACL=
.
[HKEY_USERS\S-1-5-21-2538932297-768016801-4142167647-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3B779C6C-8ABF-99EA-AE98-C61776E7A791}*]
"nabahdiblcopckfjchglgpjhgpbl"=hex:62,61,6d,66,00,9a
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_44_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_44_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_44_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_44_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_44.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_44.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_44.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_44.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-02-24 19:49:23
ComboFix-quarantined-files.txt 2014-02-24 18:49
.
Vor Suchlauf: 12 Verzeichnis(se), 85'074'460'672 Bytes frei
Nach Suchlauf: 13 Verzeichnis(se), 85'446'705'152 Bytes frei
.
- - End Of File - - 06102086B4E0ED331F76DD9B8CC853ED Gruss & danke
samu_b |