Daigochiban | 26.05.2014 22:17 | So hier der Log vom ComboFix. Code:
ComboFix 14-05-26.02 - Admin 26.05.2014 20:35:06.1.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.8191.6478 [GMT 2:00]
ausgeführt von:: c:\users\Winni\Desktop\ComboFix.exe
AV: Bitdefender Antivirus *Disabled/Updated* {9A0813D8-CED6-F86B-072E-28D2AF25A83D}
SP: Bitdefender Spyware-Schutz *Disabled/Updated* {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\1382709695.bdinstall.bin
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-04-26 bis 2014-05-26 ))))))))))))))))))))))))))))))
.
.
2014-05-26 18:41 . 2014-05-26 18:41 -------- d-----w- c:\users\hedev\AppData\Local\temp
2014-05-26 18:41 . 2014-05-26 18:41 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-05-26 18:41 . 2014-05-26 18:41 -------- d-----w- c:\users\Admin\AppData\Local\temp
2014-05-25 17:37 . 2014-05-25 17:37 -------- d-----w- c:\users\Winni\AppData\Local\THQ
2014-05-25 12:51 . 2014-05-25 12:52 -------- d-----w- C:\FRST
2014-05-25 12:24 . 2014-05-25 13:45 -------- d-----w- C:\AdwCleaner
2014-05-22 17:03 . 2014-05-22 17:03 -------- d-----w- c:\program files\iPod
2014-05-22 17:03 . 2014-05-22 17:04 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-05-22 17:03 . 2014-05-22 17:04 -------- d-----w- c:\program files\iTunes
2014-05-22 17:03 . 2014-05-22 17:04 -------- d-----w- c:\program files (x86)\iTunes
2014-05-20 21:14 . 2014-05-20 21:14 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2014-05-15 12:12 . 2014-05-15 12:12 389240 ----a-w- c:\windows\system32\drivers\trufos.sys
2014-05-14 15:53 . 2014-05-06 00:21 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2014-05-14 15:53 . 2014-05-05 23:14 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2014-05-14 15:53 . 2014-05-06 00:46 17847808 ----a-w- c:\windows\system32\mshtml.dll
2014-05-14 15:53 . 2014-05-06 00:21 96768 ----a-w- c:\windows\system32\mshtmled.dll
2014-05-13 13:24 . 2014-05-13 13:24 -------- d-----w- c:\users\Winni\AppData\Roaming\Lavasoft
2014-05-13 13:02 . 2014-05-13 13:02 -------- d-----w- c:\users\Admin\AppData\Roaming\LavasoftStatistics
2014-05-13 12:42 . 2014-05-13 12:42 -------- d-----w- c:\programdata\Lavasoft
2014-05-12 19:58 . 2014-05-12 20:08 -------- d-----w- c:\users\Admin\AppData\Local\ManyCam
2014-05-12 19:55 . 2014-05-12 19:55 -------- d-----w- c:\users\Admin\AppData\Roaming\ManyCam
2014-05-12 19:55 . 2014-05-12 19:57 -------- d-----w- c:\program files (x86)\ManyCam
2014-05-12 19:26 . 2014-05-12 19:26 -------- d-----w- c:\users\Admin\AppData\Roaming\dlg
2014-05-12 19:25 . 2014-05-12 19:25 120832 ----a-w- c:\windows\system32\xljveinstall.exe
2014-05-12 19:25 . 2014-05-12 19:25 124928 ----a-w- c:\windows\system32\DlProtectSvc.exe
2014-05-12 19:24 . 2014-05-13 13:29 -------- d-----w- c:\program files (x86)\globalUpdate
2014-05-12 19:24 . 2014-05-12 19:24 -------- d-----w- c:\users\Admin\AppData\Local\globalUpdate
2014-05-11 22:20 . 2014-05-11 22:22 -------- d-----w- c:\users\Admin\AppData\Roaming\Fantasy Grounds
2014-05-11 22:20 . 2014-05-11 22:21 -------- d-----w- c:\program files (x86)\Fantasy Grounds
2014-05-11 14:23 . 2014-05-11 17:06 -------- d-----w- c:\programdata\boost_interprocess
2014-05-11 14:23 . 2014-05-11 14:35 -------- d-----w- c:\users\Winni\AppData\Local\Plex Media Server
2014-05-11 14:21 . 2014-05-11 14:21 -------- d-----w- c:\program files (x86)\Plex
2014-05-05 22:35 . 2014-05-05 22:43 -------- d-----w- c:\users\Winni\AppData\Roaming\HandBrake
2014-05-05 20:38 . 2014-05-05 20:41 -------- d-----w- c:\users\Winni\AppData\Local\Google
2014-04-28 20:13 . 2014-04-28 20:17 -------- d-----w- c:\program files\NetBeans 8.0
2014-04-28 20:13 . 2014-04-28 20:13 -------- d-----w- c:\program files (x86)\Common Files\Java
2014-04-28 20:13 . 2014-04-28 20:12 313256 ----a-w- c:\windows\system32\javaws.exe
2014-04-28 20:12 . 2014-04-28 20:12 191400 ----a-w- c:\windows\system32\javaw.exe
2014-04-28 20:12 . 2014-04-28 20:12 190888 ----a-w- c:\windows\system32\java.exe
2014-04-28 20:12 . 2014-04-28 20:12 111016 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2014-04-28 20:11 . 2014-04-28 20:12 -------- d-----w- c:\program files\Java
2014-04-28 20:11 . 2014-04-28 20:47 -------- d-----w- c:\users\Admin\.nbi
2014-04-28 19:48 . 2014-04-28 19:48 -------- d-----w- c:\users\Winni\AppData\Roaming\.neurophstudio
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-14 15:46 . 2012-10-21 18:48 93223848 ----a-w- c:\windows\system32\MRT.exe
2014-05-13 20:18 . 2012-10-22 19:13 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-05-13 20:18 . 2012-10-22 19:13 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-04-14 18:13 . 2014-04-19 19:00 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-03-31 20:46 . 2014-03-31 20:46 130712 ----a-w- c:\windows\SysWow64\MSSTDFMT.DLL
2014-03-31 20:46 . 2014-03-31 20:46 1070232 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2014-03-08 04:06 . 2014-04-08 20:14 10926592 ----a-w- c:\windows\system32\ieframe.dll
2014-03-08 03:49 . 2014-04-08 20:14 2334720 ----a-w- c:\windows\system32\jscript9.dll
2014-03-08 03:41 . 2014-04-08 20:14 1347072 ----a-w- c:\windows\system32\urlmon.dll
2014-03-08 03:40 . 2014-04-08 20:14 1392128 ----a-w- c:\windows\system32\wininet.dll
2014-03-08 03:39 . 2014-04-08 20:14 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
2014-03-08 03:38 . 2014-04-08 20:14 237056 ----a-w- c:\windows\system32\url.dll
2014-03-08 03:37 . 2014-04-08 20:14 85504 ----a-w- c:\windows\system32\jsproxy.dll
2014-03-08 03:34 . 2014-04-08 20:14 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2014-03-08 03:34 . 2014-04-08 20:14 816640 ----a-w- c:\windows\system32\jscript.dll
2014-03-08 03:33 . 2014-04-08 20:14 599040 ----a-w- c:\windows\system32\vbscript.dll
2014-03-08 03:32 . 2014-04-08 20:14 729088 ----a-w- c:\windows\system32\msfeeds.dll
2014-03-08 03:32 . 2014-04-08 20:14 2147840 ----a-w- c:\windows\system32\iertutil.dll
2014-03-08 03:24 . 2014-04-08 20:14 248320 ----a-w- c:\windows\system32\ieui.dll
2014-03-07 23:12 . 2014-04-08 20:14 1806848 ----a-w- c:\windows\SysWow64\jscript9.dll
2014-03-07 23:02 . 2014-04-08 20:14 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2014-03-07 23:02 . 2014-04-08 20:14 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2014-03-07 22:57 . 2014-04-08 20:14 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2014-03-07 22:56 . 2014-04-08 20:14 421376 ----a-w- c:\windows\SysWow64\vbscript.dll
2014-03-04 09:44 . 2014-04-08 20:12 362496 ----a-w- c:\windows\system32\wow64win.dll
2014-03-04 09:44 . 2014-04-08 20:12 243712 ----a-w- c:\windows\system32\wow64.dll
2014-03-04 09:44 . 2014-04-08 20:12 13312 ----a-w- c:\windows\system32\wow64cpu.dll
2014-03-04 09:44 . 2014-04-08 20:12 16384 ----a-w- c:\windows\system32\ntvdm64.dll
2014-03-04 09:44 . 2014-04-08 20:12 1163264 ----a-w- c:\windows\system32\kernel32.dll
2014-03-04 09:17 . 2014-04-08 20:12 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2014-03-04 09:17 . 2014-04-08 20:12 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2014-03-04 09:16 . 2014-04-08 20:12 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2014-03-04 09:16 . 2014-04-08 20:12 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2014-03-04 08:09 . 2014-04-08 20:12 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2014-03-04 08:09 . 2014-04-08 20:12 2048 ----a-w- c:\windows\SysWow64\user.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2014-02-12 43848]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-04-24 642304]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2014-03-17 224128]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2014-05-15 152392]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Bitdefender-Geldbörse-Agent"="c:\program files\Bitdefender\Bitdefender\pmbxag.exe" [2014-03-31 567888]
"Bitdefender-Geldbörse"="c:\program files\Bitdefender\Bitdefender\pwdmanui.exe" [2014-03-31 1001536]
"Bitdefender-Geldbörse-Anwendungs-Agent"="c:\program files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" [2014-03-31 614232]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 Freemake Improver;Freemake Improver;c:\programdata\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe;c:\programdata\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 ALSysIO;ALSysIO;c:\users\Admin\AppData\Local\Temp\ALSysIO64.sys;c:\users\Admin\AppData\Local\Temp\ALSysIO64.sys [x]
R3 Apowersoft_AudioDevice;Apowersoft_AudioDevice;c:\windows\system32\drivers\Apowersoft_AudioDevice.sys;c:\windows\SYSNATIVE\drivers\Apowersoft_AudioDevice.sys [x]
R3 athrusb;Atheros Wireless LAN USB device driver;c:\windows\system32\DRIVERS\athrxusb.sys;c:\windows\SYSNATIVE\DRIVERS\athrxusb.sys [x]
R3 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys;c:\windows\SYSNATIVE\DRIVERS\avckf.sys [x]
R3 BDSandBox;BDSandBox;c:\windows\system32\drivers\bdsandbox.sys;c:\windows\SYSNATIVE\drivers\bdsandbox.sys [x]
R3 BRDriver64;BRDriver64;c:\programdata\BitRaider\BRDriver64.sys;c:\programdata\BitRaider\BRDriver64.sys [x]
R3 BRSptSvc;BitRaider Mini-Support Service;c:\programdata\BitRaider\BRSptSvc.exe;c:\programdata\BitRaider\BRSptSvc.exe [x]
R3 BthAvrcp;Bluetooth-AVRCP-Profil;c:\windows\system32\DRIVERS\BthAvrcp.sys;c:\windows\SYSNATIVE\DRIVERS\BthAvrcp.sys [x]
R3 csr_a2dp;Bluetooth-AV-Profil;c:\windows\system32\drivers\bthav.sys;c:\windows\SYSNATIVE\drivers\bthav.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R4 DlProtectSvc;Download Protect Service;c:\windows\System32\DlProtectSvc.exe;c:\windows\SYSNATIVE\DlProtectSvc.exe [x]
S0 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys;c:\windows\SYSNATIVE\DRIVERS\avc3.sys [x]
S0 gzflt;gzflt;c:\windows\system32\DRIVERS\gzflt.sys;c:\windows\SYSNATIVE\DRIVERS\gzflt.sys [x]
S1 bdfwfpf;bdfwfpf;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 UPDATESRV;Bitdefender Desktop Update Service;c:\program files\Bitdefender\Bitdefender\updatesrv.exe;c:\program files\Bitdefender\Bitdefender\updatesrv.exe [x]
S2 WesFaultSecure;Remotezugriff-PPPOE-Treiber Desktop AGP;c:\windows\system32\xljveinstall.exe;c:\windows\SYSNATIVE\xljveinstall.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 avchv;avchv Function Driver;c:\windows\system32\DRIVERS\avchv.sys;c:\windows\SYSNATIVE\DRIVERS\avchv.sys [x]
S3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\DRIVERS\mcvidrv.sys;c:\windows\SYSNATIVE\DRIVERS\mcvidrv.sys [x]
S3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv_x64.sys;c:\windows\SYSNATIVE\drivers\mcaudrv_x64.sys [x]
S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2014-05-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-22 20:18]
.
2014-05-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1143599331-371919559-3494116047-1003Core.job
- c:\users\Winni\AppData\Local\Google\Update\GoogleUpdate.exe [2014-05-05 20:38]
.
2014-05-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1143599331-371919559-3494116047-1003UA.job
- c:\users\Winni\AppData\Local\Google\Update\GoogleUpdate.exe [2014-05-05 20:38]
.
2014-05-25 c:\windows\Tasks\update-S-1-5-21-1143599331-371919559-3494116047-1003.job
- c:\program files (x86)\Skillbrains\Updater\Updater.exe [2012-10-22 11:37]
.
2014-05-25 c:\windows\Tasks\update-sys.job
- c:\program files (x86)\Skillbrains\Updater\Updater.exe [2012-10-22 11:37]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Bdagent"="c:\program files\Bitdefender\Bitdefender\bdagent.exe" [2014-03-31 1742064]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: Interfaces\{C0163090-193E-4CA1-9498-4D4C049B3E7A}: NameServer = 192.168.2.1
FF - ProfilePath - c:\users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\mk1wz4pq.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1143599331-371919559-3494116047-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-1143599331-371919559-3494116047-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_USERS\S-1-5-21-1143599331-371919559-3494116047-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B3D9E068-DE3E-E628-5947-78929B5C6C7B}*]
"hajncfacooeedfoh"=hex:6b,61,66,63,6e,6a,70,62,63,62,6e,6f,62,69,64,67,69,6b,
61,68,67,66,00,c0
"gacifmeamonjbh"=hex:61,63,63,6c,68,70,69,6c,6a,68,62,62,6d,64,6c,6b,6c,65,6c,
69,62,69,62,63,62,61,61,63,70,68,6c,69,6e,63,65,69,64,67,70,67,66,61,64,6a,\
.
[HKEY_USERS\S-1-5-21-1143599331-371919559-3494116047-1001\Software\SecuROM\License information*]
"datasecu"=hex:2d,70,90,02,79,97,3a,74,b2,68,48,af,ec,12,b1,02,fb,ae,c1,26,83,
78,b1,2e,80,d4,57,6d,d8,29,23,02,c9,ec,ed,95,9c,08,11,bf,93,27,bf,4e,66,74,\
"rkeysecu"=hex:ee,52,0d,19,6e,70,16,0d,a0,f1,8f,f6,30,a2,9a,b6
.
[HKEY_USERS\S-1-5-21-1143599331-371919559-3494116047-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B3D9E068-DE3E-E628-5947-78929B5C6C7B}*]
"hajncfacooeedfoh"=hex:6b,61,66,63,6e,6a,70,62,63,62,6e,6f,62,69,64,67,69,6b,
61,68,67,66,00,c0
"gacifmeamonjbh"=hex:61,63,6f,63,6b,63,6c,64,62,6a,70,61,65,6f,69,67,6f,6e,70,
6e,64,6d,65,66,65,69,69,66,67,6f,69,66,6c,6d,70,62,66,6b,66,67,68,69,66,67,\
"ialimabkbfocbioonm"=hex:6b,61,66,63,6e,6a,70,62,63,62,6e,6f,62,69,64,67,69,6b,
61,68,67,66,00,c0
.
[HKEY_USERS\S-1-5-21-1143599331-371919559-3494116047-1003\Software\SecuROM\License information*]
"datasecu"=hex:47,15,b4,d6,7b,2e,fe,27,35,49,67,49,41,2e,68,31,2b,59,08,b5,b6,
8c,fe,e3,4f,9b,20,44,7c,92,66,31,50,86,3c,01,1e,bf,cb,1e,60,96,6d,83,a1,29,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_USERS\S-1-5-21-1143599331-371919559-3494116047-1003_Classes\CLSID]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1143599331-371919559-3494116047-1003_Classes\CLSID\{699A646B-C61E-4C36-A253-620E4EBD294C}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1143599331-371919559-3494116047-1003_Classes\CLSID\{97D17A04-4438-4C8E-BAC7-BC21B8B9E999}]
@DACL=(02 0000)
@="GPUStatusReader.GPUMonitor"
.
[HKEY_USERS\S-1-5-21-1143599331-371919559-3494116047-1003_Classes\CLSID\{d0f19d12-f0c9-434b-a9a8-35a6c5cd0530}]
@DACL=(02 0000)
@="Shell Icon Handler For Curse Client Install Package"
"AppId"="CurseClient.application, Culture=neutral, PublicKeyToken=9e9e83ddf3ed3ead, processorArchitecture=msil"
"DeploymentProviderUrl"="hxxp://clientupdate-v5.curse.com/CurseClient.application"
"IconFile"="ClientIcons\\CCIP.ico"
.
[HKEY_USERS\S-1-5-21-1143599331-371919559-3494116047-1003_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1143599331-371919559-3494116047-1003_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}]
@Class="REG_SZ"
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.13"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-05-26 20:44:58
ComboFix-quarantined-files.txt 2014-05-26 18:44
.
Vor Suchlauf: 17 Verzeichnis(se), 38.102.671.360 Bytes frei
Nach Suchlauf: 21 Verzeichnis(se), 37.972.160.512 Bytes frei
.
- - End Of File - - 0B01DB512AFA0A4CC3CA2A9587FC2FB4
A36C5E4F47E84449FF07ED3517B43A31 Mir ist grad beim ausschalten von Bitdefender aufgefallen, dass dieser am 22.5. einen und am 12.5 eine ganze Reihe Funde hatte. Allerdings hat es mich gar nicht darüber informiert....:wtf:
Leider kann ich keine Logdatei von Bitdefender finden sonst würd ich die ja auch posten :(
Und noch etwas hab ich gerade bemerkt: Wenn ich mich als Administrator einlogge, ist DownloadProtect in der Programm und Funktionen Liste von Windows zu finden. Soll ich das dort deinstallieren? |