Ok durchgeführt!
Es gab während des Prozesses keine Meldungen etc.. Alles in einem rutsch durchgelaufen!
Bemerkung 1 zu den Startseiten im Firefox:
Ich habe beide Startseiten unkenntlich gemacht da ich in diesem Verein aktiv mitarbeite und mit privatem Namen aufgeführt werde. Beide Seiten stehen ohne kryptische Zeichen in ihrer normalen URL drinnen. Obwohl mich in der log das "hxxp" der ersten Startseite irretiert. Kenne mich da allerdings nicht so aus!?
Bemerkung 2 zu den Startseiten im Firefox:
In der Log steht die zweite Startseite mit http drinnen. Kopiere ich es hier rein steht hxxp drinnen!?
Wenn es für dich unbedingt von nöten ist kann ich es angeben, würde es aber wenn möglich vermeiden wollen. Code:
ComboFix 14-05-19.01 - *** 24.05.2014 20:29:22.1.8 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.8169.6120 [GMT 2:00]
ausgeführt von:: c:\users\***\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\YoutubeAdblocker
c:\windows\SysWow64\tmp8555.tmp
c:\windows\SysWow64\tmp8565.tmp
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-04-24 bis 2014-05-24 ))))))))))))))))))))))))))))))
.
.
2014-05-24 18:35 . 2014-05-24 18:35 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-05-23 22:18 . 2014-05-23 22:18 -------- d-----w- c:\program files (x86)\ESET
2014-05-23 16:43 . 2014-04-30 23:20 10702536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4A9D3415-1C50-4BD6-B4F0-5F5F8737808B}\mpengine.dll
2014-05-21 05:49 . 2014-05-23 22:17 -------- d-----w- C:\FRST
2014-05-20 22:12 . 2014-05-24 18:14 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-05-20 22:12 . 2014-05-12 05:26 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-05-20 22:12 . 2014-05-12 05:26 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-05-20 22:12 . 2014-05-12 05:25 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-05-20 20:27 . 2014-05-20 21:37 -------- d-----w- c:\programdata\NeeXtuCouep
2014-05-20 20:27 . 2014-05-20 20:27 -------- d-----w- c:\users\UpdatusUser\AppData\Local\Chromatic Browser
2014-05-20 20:27 . 2014-05-20 20:27 -------- d-----w- c:\users\***\AppData\Local\Chromatic Browser
2014-05-20 20:27 . 2014-05-20 20:27 -------- d-----w- c:\program files (x86)\NeeXtuCouep
2014-05-20 20:26 . 2014-05-20 20:26 2118880 ----a-w- c:\windows\SysWow64\setup.exe
2014-05-18 15:46 . 2008-07-12 06:18 540688 ----a-w- c:\windows\system32\d3dx10_39.dll
2014-05-18 15:46 . 2008-07-12 06:18 1942552 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2014-05-18 15:46 . 2008-07-12 06:18 4992520 ----a-w- c:\windows\system32\D3DX9_39.dll
2014-05-18 11:39 . 2014-05-18 11:39 -------- d-----w- c:\users\***\AppData\Local\Broadcom
2014-05-18 11:39 . 2010-01-15 11:23 98344 ----a-w- c:\windows\system32\drivers\btwaudio.sys
2014-05-18 11:39 . 2010-01-15 11:23 132648 ----a-w- c:\windows\system32\drivers\btwavdt.sys
2014-05-18 11:39 . 2010-01-15 11:23 21288 ----a-w- c:\windows\system32\drivers\btwrchid.sys
2014-05-18 11:39 . 2009-04-07 12:33 35104 ----a-w- c:\windows\system32\drivers\btwl2cap.sys
2014-05-18 11:38 . 2014-05-18 11:38 -------- d-----w- c:\program files\WIDCOMM
2014-05-18 00:12 . 2014-05-18 00:12 -------- d-----w- c:\programdata\AllaboutApp
2014-05-18 00:11 . 2014-05-18 00:11 -------- d-----w- c:\users\***\AppData\Roaming\SendSpace
2014-05-18 00:10 . 2014-05-22 17:38 -------- d-----w- c:\programdata\YoutubeAdblocker
2014-05-18 00:09 . 2014-05-20 20:28 -------- d-----w- c:\programdata\savee nneT
2014-05-18 00:09 . 2014-05-18 00:09 -------- d-----w- c:\program files (x86)\savee nneT
2014-05-18 00:09 . 2014-05-22 17:34 -------- d-----w- c:\programdata\8dae8828e4a957ff
2014-05-18 00:09 . 2014-05-18 00:09 -------- d-----w- c:\users\UpdatusUser\AppData\Local\Torch
2014-05-18 00:09 . 2014-05-18 00:09 -------- d-----w- c:\users\UpdatusUser\AppData\Local\Google
2014-05-18 00:09 . 2014-05-18 00:09 -------- d-----w- c:\users\UpdatusUser\AppData\Local\Comodo
2014-05-18 00:09 . 2014-05-18 00:09 -------- d-----w- c:\users\***\AppData\Local\Torch
2014-05-18 00:09 . 2014-05-18 00:09 -------- d-----w- c:\users\***\AppData\Local\Comodo
2014-05-18 00:09 . 2014-05-18 00:09 -------- d-----w- c:\users\HomeGroupUser$
2014-05-18 00:09 . 2014-05-18 00:09 -------- d-----w- c:\users\Gast
2014-05-18 00:09 . 2014-05-18 00:09 -------- d-----w- c:\users\Administrator
2014-05-18 00:07 . 2014-05-18 00:12 -------- d-----w- c:\programdata\InstallMate
2014-05-17 23:55 . 2014-05-17 23:55 -------- d-----w- c:\windows\8A809006C25A4A3A9DAB94659BCDB107.TMP
2014-05-17 23:55 . 2014-05-17 23:55 -------- d-----w- c:\windows\SysWow64\xlive
2014-05-17 23:55 . 2014-05-17 23:55 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2014-05-17 00:50 . 2014-05-17 00:58 -------- d--h--w- c:\program files (x86)\Temp
2014-05-16 23:41 . 2014-05-16 23:41 -------- d-sh--w- c:\windows\ftpcache
2014-05-13 20:10 . 2014-05-06 04:40 23544320 ----a-w- c:\windows\system32\mshtml.dll
2014-05-13 20:10 . 2014-05-06 03:00 84992 ----a-w- c:\windows\system32\mshtmled.dll
2014-05-13 20:09 . 2014-05-06 04:17 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-05-13 20:09 . 2014-05-06 03:07 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2014-05-06 22:44 . 2014-05-06 22:44 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-05-06 22:44 . 2014-05-06 22:44 43152 ----a-w- c:\windows\avastSS.scr
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-18 20:17 . 2013-02-02 12:46 311968 ----a-w- c:\windows\system32\drivers\atksgt.sys
2014-05-18 18:52 . 2013-02-02 12:46 43168 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2014-05-15 10:44 . 2011-12-26 14:24 423240 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-05-15 10:44 . 2011-12-26 14:24 1039096 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-05-15 10:44 . 2014-01-02 17:18 85328 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-05-14 21:02 . 2012-04-01 08:29 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-05-14 21:02 . 2011-12-26 14:55 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-05-13 20:06 . 2011-12-26 13:56 93223848 ----a-w- c:\windows\system32\MRT.exe
2014-05-11 08:10 . 2014-03-15 09:15 65536 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\NewShortcut2_42CBAC89E210433F82D8B5BE80F2AEF2.exe
2014-05-11 08:10 . 2014-03-15 09:15 65536 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\NewShortcut1_D441B457DF544BDE9AF24CD3A5A86089.exe
2014-05-11 08:10 . 2014-03-15 09:12 98304 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\StartCenter2014_W8_5B46E5977D754E089659BE6AD1F9B759.exe
2014-05-11 08:10 . 2014-03-15 09:12 98304 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\StartCenter2014_C881D8C379EF459FB5826AE7A330CFFB.exe
2014-05-11 08:10 . 2014-03-15 09:12 98304 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\DesktopIcon_12315F4CBF744E98897D372E486C466A.exe
2014-05-11 08:10 . 2014-03-15 09:12 81920 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\ARPPRODUCTICON.exe
2014-05-11 08:10 . 2014-03-15 09:12 65536 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\Support_W8_F8B35F136AE646FD99DF1ED970BFF17C.exe
2014-05-11 08:10 . 2014-03-15 09:12 65536 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\Support_9CA870DD2DE842D9AA34F7B64DCA491C.exe
2014-05-11 08:10 . 2014-03-15 09:12 65536 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\SSEvorweg_W8_7048A26ED1D94694AD78722A8C26F1D9.exe
2014-05-11 08:10 . 2014-03-15 09:12 65536 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\SSEvorweg_D88EC50776204E11A45F4BA56D9E9F9A.exe
2014-05-11 08:10 . 2014-03-15 09:12 65536 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\SSEnormal_W8_490717E7771547F490F75B8D5E3FFB21.exe
2014-05-11 08:10 . 2014-03-15 09:12 65536 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\SSEnormal_E816849259B145008D96169BDA2F9A1C.exe
2014-05-11 08:10 . 2014-03-15 09:12 65536 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\SSEfest_W8_EF7BE7BF193D4A62B73F4CAA41CA972C.exe
2014-05-11 08:10 . 2014-03-15 09:12 65536 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\SSEfest_85F8D7EED43B44D48769FCEF89564CC5.exe
2014-05-11 08:10 . 2014-03-15 09:12 65536 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\SSEermaess_W8_DF471FAEB8BD4DC8AE3F38951BA12FF7.exe
2014-05-11 08:10 . 2014-03-15 09:12 65536 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\SSEermaess_AC738017BDBE4A75BD9BC236CF03BAD5.exe
2014-05-11 08:10 . 2014-03-15 09:12 65536 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\SSEeinurvor_W8_B5D6E2477DF849E89ED9C51876F8D4A7.exe
2014-05-11 08:10 . 2014-03-15 09:12 65536 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\SSEeinurvor_6111E232E85449F19ACDA70D15D6D8A7.exe
2014-05-11 08:10 . 2014-03-15 09:12 65536 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\SSEeinur_W8_007A0C27C9A3442C9CEAEEC2C7B82AE5.exe
2014-05-11 08:10 . 2014-03-15 09:12 65536 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\SSEeinur_345636AACDA04899B531EC803D3963FE.exe
2014-05-11 08:10 . 2014-03-15 09:12 49152 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\Uninstall_W8_03A9248590D14BFDBC7EF4783648E0D8.exe
2014-05-11 08:10 . 2014-03-15 09:12 49152 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\Uninstall_AA2D99EAB10D464EACD1AB33FE89209E.exe
2014-05-11 08:10 . 2014-03-15 09:12 40960 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\Report_W8_91584FFDDEF841FEB2A02531A2DC5A69.exe
2014-05-11 08:10 . 2014-03-15 09:12 40960 ----a-r- c:\users\***\AppData\Roaming\Microsoft\Installer\{A463EB06-22A6-47F5-9593-E52B291EF13E}\Report_E3BBAB5C9F584EC58992AA7E7A58C919.exe
2014-05-06 22:44 . 2013-03-16 12:15 208416 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-05-06 22:44 . 2013-03-16 12:15 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-05-06 22:44 . 2012-02-25 11:43 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-05-06 22:44 . 2011-12-26 14:24 79184 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-05-06 22:44 . 2011-12-26 14:24 334648 ----a-w- c:\windows\system32\aswBoot.exe
2014-04-14 16:12 . 2014-04-14 16:12 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2014-04-14 16:12 . 2014-04-14 16:12 312744 ----a-w- c:\windows\system32\javaws.exe
2014-04-14 16:12 . 2014-04-14 16:12 189352 ----a-w- c:\windows\system32\javaw.exe
2014-04-14 16:12 . 2014-04-14 16:12 189352 ----a-w- c:\windows\system32\java.exe
2014-03-31 20:46 . 2014-03-31 20:46 130712 ----a-w- c:\windows\SysWow64\MSSTDFMT.DLL
2014-03-31 20:46 . 2014-03-31 20:46 1070232 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2014-03-31 07:35 . 2010-11-21 03:27 270496 ------w- c:\windows\system32\MpSigStub.exe
2014-03-06 09:31 . 2014-04-08 23:35 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2014-03-06 08:59 . 2014-04-08 23:35 66048 ----a-w- c:\windows\system32\iesetup.dll
2014-03-06 08:57 . 2014-04-08 23:35 548352 ----a-w- c:\windows\system32\vbscript.dll
2014-03-06 08:57 . 2014-04-08 23:35 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll
2014-03-06 08:53 . 2014-04-08 23:34 2767360 ----a-w- c:\windows\system32\iertutil.dll
2014-03-06 08:40 . 2014-04-08 23:35 51200 ----a-w- c:\windows\system32\jsproxy.dll
2014-03-06 08:39 . 2014-04-08 23:35 33792 ----a-w- c:\windows\system32\iernonce.dll
2014-03-06 08:32 . 2014-04-08 23:35 574976 ----a-w- c:\windows\system32\ieui.dll
2014-03-06 08:29 . 2014-04-08 23:35 139264 ----a-w- c:\windows\system32\ieUnatt.exe
2014-03-06 08:29 . 2014-04-08 23:35 111616 ----a-w- c:\windows\system32\ieetwcollector.exe
2014-03-06 08:28 . 2014-04-08 23:35 752640 ----a-w- c:\windows\system32\jscript9diag.dll
2014-03-06 08:15 . 2014-04-08 23:35 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-03-06 08:11 . 2014-04-08 23:34 5784064 ----a-w- c:\windows\system32\jscript9.dll
2014-03-06 08:09 . 2014-04-08 23:35 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2014-03-06 08:03 . 2014-04-08 23:35 586240 ----a-w- c:\windows\system32\ie4uinit.exe
2014-03-06 08:02 . 2014-04-08 23:35 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2014-03-06 08:02 . 2014-04-08 23:35 455168 ----a-w- c:\windows\SysWow64\vbscript.dll
2014-03-06 08:01 . 2014-04-08 23:35 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2014-03-06 07:56 . 2014-04-08 23:35 38400 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2014-03-06 07:48 . 2014-04-08 23:35 195584 ----a-w- c:\windows\system32\msrating.dll
2014-03-06 07:46 . 2014-04-08 23:34 4254720 ----a-w- c:\windows\SysWow64\jscript9.dll
2014-03-06 07:42 . 2014-04-08 23:35 296960 ----a-w- c:\windows\system32\dxtrans.dll
2014-03-06 07:38 . 2014-04-08 23:35 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2014-03-06 07:36 . 2014-04-08 23:35 592896 ----a-w- c:\windows\SysWow64\jscript9diag.dll
2014-03-06 07:21 . 2014-04-08 23:35 628736 ----a-w- c:\windows\system32\msfeeds.dll
2014-03-06 07:13 . 2014-04-08 23:35 32256 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2014-03-06 07:11 . 2014-04-08 23:34 2043904 ----a-w- c:\windows\system32\inetcpl.cpl
2014-03-06 06:53 . 2014-04-08 23:34 13551104 ----a-w- c:\windows\system32\ieframe.dll
2014-03-06 06:40 . 2014-04-08 23:34 1967104 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2014-03-06 06:22 . 2014-04-08 23:34 2260480 ----a-w- c:\windows\system32\wininet.dll
2014-03-06 05:58 . 2014-04-08 23:34 1400832 ----a-w- c:\windows\system32\urlmon.dll
2014-03-06 05:50 . 2014-04-08 23:35 846336 ----a-w- c:\windows\system32\ieapfltr.dll
2014-03-06 05:41 . 2014-04-08 23:34 1789440 ----a-w- c:\windows\SysWow64\wininet.dll
2014-03-04 09:44 . 2014-04-08 23:31 362496 ----a-w- c:\windows\system32\wow64win.dll
2014-03-04 09:44 . 2014-04-08 23:31 243712 ----a-w- c:\windows\system32\wow64.dll
2014-03-04 09:44 . 2014-04-08 23:31 13312 ----a-w- c:\windows\system32\wow64cpu.dll
2014-03-04 09:44 . 2014-04-08 23:31 16384 ----a-w- c:\windows\system32\ntvdm64.dll
2014-03-04 09:44 . 2014-04-08 23:31 1163264 ----a-w- c:\windows\system32\kernel32.dll
2014-03-04 09:17 . 2014-04-08 23:31 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2014-03-04 09:17 . 2014-04-08 23:31 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2014-03-04 09:16 . 2014-04-08 23:31 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2014-03-04 09:16 . 2014-04-08 23:31 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2014-03-04 08:09 . 2014-04-08 23:31 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2014-03-04 08:09 . 2014-04-08 23:31 2048 ----a-w- c:\windows\SysWow64\user.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"iCloudServices"="d:\apple\Internet Services\iCloudServices.exe" [2013-11-20 59720]
"ApplePhotoStreams"="d:\apple\Internet Services\ApplePhotoStreams.exe" [2013-11-20 59720]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"FLxHCIm"="c:\program files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe" [2011-01-21 40448]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-08-17 5732992]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-09-23 1601536]
"THX TruStudio NB Settings"="c:\program files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" [2011-01-28 907776]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"TrueImageMonitor.exe"="c:\program files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" [2012-06-28 5993216]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2014-02-05 43848]
"AcronisTimounterMonitor"="c:\program files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe" [2012-06-28 1173712]
"AvastUI.exe"="d:\avast\AvastUI.exe" [2014-05-06 3873704]
"ControlCenter4"="c:\program files (x86)\ControlCenter4\BrCcBoot.exe" [2013-12-05 139776]
"BrStsMon00"="c:\program files (x86)\Browny02\Brother\BrStMonW.exe" [2012-12-27 4522496]
"BrHelp"="c:\program files (x86)\Brother\Brother Help\BrotherHelp.exe" [2013-01-18 2009088]
"iTunesHelper"="d:\itunes\iTunesHelper.exe" [2014-02-21 152392]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-3-11 1083680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMScheduler;MBAMScheduler;d:\malwarebytes anti-malware\mbamscheduler.exe;d:\malwarebytes anti-malware\mbamscheduler.exe [x]
R2 MBAMService;MBAMService;d:\malwarebytes anti-malware\mbamservice.exe;d:\malwarebytes anti-malware\mbamservice.exe [x]
R2 SkypeUpdate;Skype Updater;d:\skype\Updater\Updater.exe;d:\skype\Updater\Updater.exe [x]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys;c:\windows\SYSNATIVE\drivers\btusbflt.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
R3 cleanhlp;cleanhlp;c:\program files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys;c:\program files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [x]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [x]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x]
R3 CYDTV_SRV;cydtv Driver;c:\windows\system32\drivers\cydtv.sys;c:\windows\SYSNATIVE\drivers\cydtv.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 hcw17bda;Hauppauge SMS1000-based;c:\windows\system32\drivers\hcw17bda.sys;c:\windows\SYSNATIVE\drivers\hcw17bda.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys;c:\windows\SYSNATIVE\drivers\massfilter.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Rockey_USB;Feitian ROCKEY4 USB Service;c:\windows\system32\DRIVERS\Rockey4USB.sys;c:\windows\SYSNATIVE\DRIVERS\Rockey4USB.sys [x]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x]
R3 SaiH5F0D;SaiH5F0D;c:\windows\system32\DRIVERS\SaiH5F0D.sys;c:\windows\SYSNATIVE\DRIVERS\SaiH5F0D.sys [x]
R3 SaiU5F0D;SaiU5F0D;c:\windows\system32\DRIVERS\SaiU5F0D.sys;c:\windows\SYSNATIVE\DRIVERS\SaiU5F0D.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 TTUSB2BDA_NTAMD64;TTUSB2BDA USB 2.0 Driver AMD64;c:\windows\system32\DRIVERS\ttusb2bda_amd64.sys;c:\windows\SYSNATIVE\DRIVERS\ttusb2bda_amd64.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 fltsrv;Acronis Storage Filter Management;c:\windows\system32\DRIVERS\fltsrv.sys;c:\windows\SYSNATIVE\DRIVERS\fltsrv.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S0 vididr;Acronis Virtual Disk;c:\windows\system32\DRIVERS\vididr.sys;c:\windows\SYSNATIVE\DRIVERS\vididr.sys [x]
S0 vidsflt67;Acronis Disk Storage Filter (67);c:\windows\system32\DRIVERS\vsflt67.sys;c:\windows\SYSNATIVE\DRIVERS\vsflt67.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 {09F57980-3432-4AFC-957D-27AC45FAE1F5};Power Control [2013/12/15 16:40];d:\powerdvd13\PowerDVD13\Common\NavFilter\000.fcl;d:\powerdvd13\PowerDVD13\Common\NavFilter\000.fcl [x]
S2 AAV UpdateService;AAV UpdateService;c:\program files (x86)\AAVUpdateManager\aavus.exe;c:\program files (x86)\AAVUpdateManager\aavus.exe [x]
S2 afcdpsrv;Acronis Nonstop Backup Service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 CyberLink PowerDVD 13 Media Server Monitor Service;CyberLink PowerDVD 13 Media Server Monitor Service;d:\powerdvd13\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe;d:\powerdvd13\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe [x]
S2 CyberLink PowerDVD 13 Media Server Service;CyberLink PowerDVD 13 Media Server Service;d:\powerdvd13\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe;d:\powerdvd13\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe [x]
S2 DVBLinkServer2;DVBLink Server;d:\dvblogic\DVBLink2\DVBLinkServer.exe;d:\dvblogic\DVBLink2\DVBLinkServer.exe [x]
S2 HauppaugeTVServer;HauppaugeTVServer;d:\wintv\TVServer\HauppaugeTVServer.exe;d:\wintv\TVServer\HauppaugeTVServer.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 syncagentsrv;Acronis Sync Agent Service;c:\program files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe;c:\program files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [x]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x]
S2 TurboBoost;Intel(R) Turbo Boost Technology Monitor;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x]
S2 UI Assistant Service;UI Assistant Service;d:\1&1 surf-stick\AssistantServices.exe;d:\1&1 surf-stick\AssistantServices.exe [x]
S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys;c:\windows\SYSNATIVE\DRIVERS\afcdp.sys [x]
S3 BrYNSvc;BrYNSvc;c:\program files (x86)\Browny02\BrYNSvc.exe;c:\program files (x86)\Browny02\BrYNSvc.exe [x]
S3 dvblinkcap;DVBLink Capture #1;c:\windows\system32\DRIVERS\dvblinkcap.sys;c:\windows\SYSNATIVE\DRIVERS\dvblinkcap.sys [x]
S3 dvblinkcap2;DVBLink Capture #2;c:\windows\system32\DRIVERS\dvblinkcap2.sys;c:\windows\SYSNATIVE\DRIVERS\dvblinkcap2.sys [x]
S3 dvblinkcap3;DVBLink Capture #3;c:\windows\system32\DRIVERS\dvblinkcap3.sys;c:\windows\SYSNATIVE\DRIVERS\dvblinkcap3.sys [x]
S3 dvblinkcap4;DVBLink Capture #4;c:\windows\system32\DRIVERS\dvblinkcap4.sys;c:\windows\SYSNATIVE\DRIVERS\dvblinkcap4.sys [x]
S3 dvblinktun;DVBLink Tuner #1;c:\windows\system32\DRIVERS\dvblinktun.sys;c:\windows\SYSNATIVE\DRIVERS\dvblinktun.sys [x]
S3 dvblinktun2;DVBLink Tuner #2;c:\windows\system32\DRIVERS\dvblinktun2.sys;c:\windows\SYSNATIVE\DRIVERS\dvblinktun2.sys [x]
S3 dvblinktun3;DVBLink Tuner #3;c:\windows\system32\DRIVERS\dvblinktun3.sys;c:\windows\SYSNATIVE\DRIVERS\dvblinktun3.sys [x]
S3 dvblinktun4;DVBLink Tuner #4;c:\windows\system32\DRIVERS\dvblinktun4.sys;c:\windows\SYSNATIVE\DRIVERS\dvblinktun4.sys [x]
S3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver;c:\windows\system32\DRIVERS\FLxHCIc.sys;c:\windows\SYSNATIVE\DRIVERS\FLxHCIc.sys [x]
S3 FLxHCIh;Fresco Logic xHCI (USB3) Hub Device Driver;c:\windows\system32\DRIVERS\FLxHCIh.sys;c:\windows\SYSNATIVE\DRIVERS\FLxHCIh.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-05-06 22:44 290888 ----a-w- d:\avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelTBRunOnce"="wscript.exe" [2013-10-12 168960]
"THXCfg64"="c:\windows\system32\THXCfg64.dll" [2009-10-15 17920]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2013-11-14 8292120]
"Acronis Scheduler2 Service"="c:\program files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" [2012-06-28 403688]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-22 11075176]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: An vorhandene PDF-Datei anfügen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: In Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Linkziel in Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Nach Microsoft E&xel exportieren - d:\micros~1\Office12\EXCEL.EXE/3000
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\
FF - prefs.js: browser.startup.homepage - hxxp://***/|hxxp://***
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
SafeBoot-CleanHlp
SafeBoot-CleanHlp.sys
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
ShellIconOverlayIdentifiers- - (no file)
ShellIconOverlayIdentifiers- - (no file)
ShellIconOverlayIdentifiers- - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-SynAsusAcpi - c:\program files (x86)\Synaptics\SynTP\SynAsusAcpi.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-{7353BAE6-5E49-46C4-A9B5-8A269A313789} - c:\users\***\AppData\Local\{0691F710-1ECA-4B5A-9727-25554F1BFDC6}\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{09F57980-3432-4AFC-957D-27AC45FAE1F5}]
"ImagePath"="\??\d:\powerdvd13\PowerDVD13\Common\NavFilter\000.fcl"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-461601121-2454032722-3572995621-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:3a,cf,53,18,0e,9a,85,7c,62,c9,16,cf,aa,68,73,5a,de,ff,42,dc,10,30,70,
ba,18,f9,e1,91,2f,ff,1e,1d,f8,54,60,1f,67,3d,5f,e3,3a,32,a8,f4,07,9b,fb,55,\
"??"=hex:46,e3,4d,3a,22,cc,5a,fb,6a,9a,3d,ab,8f,cb,0e,51
.
[HKEY_USERS\S-1-5-21-461601121-2454032722-3572995621-1000\Software\SecuROM\License information*]
"datasecu"=hex:8c,22,38,27,cb,66,01,8a,6f,75,a2,b7,ac,37,ae,04,c0,bf,b7,04,77,
1d,50,6f,4d,5d,b0,0a,b5,9d,6a,19,ec,b9,4c,cc,7b,be,6a,d3,95,19,40,ad,5f,b5,\
"rkeysecu"=hex:95,d4,32,79,72,4b,dd,84,6d,49,5d,d4,4a,8c,49,36
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_182_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_182_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_182_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_182_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_182.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.13"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_182.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_182.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_182.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-05-24 20:37:09
ComboFix-quarantined-files.txt 2014-05-24 18:37
.
Vor Suchlauf: 13 Verzeichnis(se), 24.682.729.472 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 24.462.536.704 Bytes frei
.
- - End Of File - - AD5412006B0FF805738BBBD256A5C0C5 |