seb-soft | 11.02.2015 19:31 | Code:
ComboFix 15-02-09.01 - seb 11.02.2015 18:41:12.1.2 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1033.18.4095.2429 [GMT 1:00]
ausgeführt von:: c:\unzipped\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\IsUn0407.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2015-01-11 bis 2015-02-11 ))))))))))))))))))))))))))))))
.
.
2015-02-11 18:18 . 2015-02-11 18:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-02-11 12:31 . 2015-02-11 12:45 -------- d-----w- C:\AdwCleaner
2015-02-11 12:24 . 2015-02-11 17:31 -------- d-----w- c:\program files (x86)\VS Revo Group
2015-02-11 12:17 . 2015-02-11 15:01 -------- d-----w- C:\FRST
2015-02-06 17:59 . 2015-02-06 17:59 -------- d-----w- c:\program files (x86)\Future Pinball
2015-02-06 12:06 . 2014-11-29 00:37 180648 ----a-w- c:\windows\system32\drivers\idmwfp.sys
2015-01-30 13:40 . 2015-01-30 13:41 -------- d-----w- c:\users\seb\AppData\Local\Songr
2015-01-28 12:50 . 2015-01-28 12:50 -------- d-----w- c:\users\seb\AppData\Roaming\YoutubeToMp3Converter
2015-01-28 12:50 . 2015-01-28 12:50 -------- d-----w- c:\program files (x86)\Freemake
2015-01-28 12:19 . 2015-01-28 12:19 -------- d-----w- c:\users\seb\AppData\Roaming\Mp3jam
2015-01-27 18:22 . 2015-01-27 18:22 -------- d-----w- c:\users\seb\AppData\Roaming\FreeVideoEditor
2015-01-27 18:16 . 2015-02-01 18:02 -------- d-----w- c:\program files (x86)\Common Files\DVDVideoSoft
2015-01-27 18:16 . 2015-02-01 18:02 -------- d-----w- c:\program files (x86)\DVDVideoSoft
2015-01-27 17:28 . 2015-01-27 18:02 -------- d-----w- c:\users\seb\AppData\Roaming\avidemux
2015-01-21 09:12 . 2015-01-21 09:12 -------- d-----w- c:\program files (x86)\Common Files\Java
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-02-09 14:35 . 2014-06-28 05:36 129752 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-02-05 12:29 . 2013-01-10 12:19 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-02-05 12:29 . 2013-01-10 12:19 701616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2015-01-21 09:11 . 2014-10-12 07:56 98216 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-12-31 17:56 . 2013-01-11 10:13 67072 ----a-w- c:\windows\SysWow64\ieframe.oca
2014-12-31 17:56 . 2013-01-11 10:13 241664 ----a-w- c:\windows\SysWow64\COMCTL32.oca
2014-12-31 17:56 . 2013-01-11 10:13 44032 ----a-w- c:\windows\SysWow64\TABCTL32.oca
2014-12-24 11:39 . 2013-01-05 15:40 112710672 ----a-w- c:\windows\system32\MRT.exe
2014-12-16 17:26 . 2014-12-16 17:26 16152 ----a-w- c:\windows\system32\drivers\SWDUMon.sys
2014-12-09 17:10 . 2014-01-15 07:38 1050432 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-12-09 17:09 . 2014-01-15 07:38 116728 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-12-09 17:09 . 2014-01-15 07:38 267632 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-12-09 17:09 . 2014-01-15 07:38 436624 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-12-09 17:09 . 2014-12-09 17:09 364512 ----a-w- c:\windows\system32\aswBoot.exe
2014-12-09 17:09 . 2014-12-09 17:09 43152 ----a-w- c:\windows\avastSS.scr
2014-12-09 17:09 . 2014-05-06 05:35 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-12-09 17:09 . 2014-01-15 07:38 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-12-09 17:09 . 2014-01-15 07:38 83280 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-12-09 17:09 . 2014-01-15 07:38 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-11-21 05:14 . 2014-06-28 05:35 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-11-21 05:14 . 2014-06-28 05:35 93400 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-11-21 05:14 . 2013-03-28 12:21 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-11-16 07:04 . 2013-11-16 07:03 50063360 ----a-w- c:\program files (x86)\GUT3F71.tmp
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"DiscWizardMonitor.exe"="c:\program files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe" [2009-11-10 1352480]
"AcronisTimounterMonitor"="c:\program files (x86)\Seagate\DiscWizard\TimounterMonitor.exe" [2009-11-10 906912]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-11-16 641704]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2013-05-08 41056]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-01-27 5227112]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2010-12-17 2489456]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files (x86)\Microsoft Office\Office10\OSA.EXE -b -l [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 polugive;Pt Details;c:\users\seb\AppData\Roaming\VOPackage\nsz92D6.tmpfs;c:\users\seb\AppData\Roaming\VOPackage\nsz92D6.tmpfs [x]
R3 cpuz130;cpuz130; [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SWDUMon;SWDUMon;c:\windows\system32\DRIVERS\SWDUMon.sys;c:\windows\SYSNATIVE\DRIVERS\SWDUMon.sys [x]
R3 Synth3dVsc;Synth3dVsc; [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;tsusbhub [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys;c:\windows\SYSNATIVE\DRIVERS\idmwfp.sys [x]
S2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files (x86)\Common Files\Seagate\Schedule2\schedul2.exe;c:\program files (x86)\Common Files\Seagate\Schedule2\schedul2.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 SAllBDA;TeVii DVB-S/S2 Receiver;c:\windows\system32\Drivers\TeViiS2.sys;c:\windows\SYSNATIVE\Drivers\TeViiS2.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2}]
2010-02-16 18:02 114688 ----a-w- c:\program files (x86)\PixiePack Codec Pack\InstallerHelper.exe
.
Inhalt des "geplante Tasks" Ordners
.
2015-02-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-10 12:29]
.
2015-02-06 c:\windows\Tasks\Atlantis_ab_2015_02_11.job
- c:\program files (x86)\Java\jre1.8.0_31\bin\javaw.exe [2015-01-21 09:11]
.
2015-02-06 c:\windows\Tasks\Atlantis_ab_2015_02_11_PreStarter.job
- c:\program files (x86)\Java\jre1.8.0_31\bin\javaw.exe [2015-01-21 09:11]
.
2015-02-02 c:\windows\Tasks\Die_Gaensemagd_ab_2015_02_26.job
- c:\program files (x86)\Java\jre1.8.0_31\bin\javaw.exe [2015-01-21 09:11]
.
2015-02-02 c:\windows\Tasks\Die_Gaensemagd_ab_2015_02_26_PreStarter.job
- c:\program files (x86)\Java\jre1.8.0_31\bin\javaw.exe [2015-01-21 09:11]
.
2015-02-02 c:\windows\Tasks\Dittsche_Das_wirklich_wahre_Leben_ab_2015_02_22.job
- c:\program files (x86)\Java\jre1.8.0_31\bin\javaw.exe [2015-01-21 09:11]
.
2015-02-02 c:\windows\Tasks\Dittsche_Das_wirklich_wahre_Leben_ab_2015_02_22_PreStarter.job
- c:\program files (x86)\Java\jre1.8.0_31\bin\javaw.exe [2015-01-21 09:11]
.
2015-02-02 c:\windows\Tasks\Dornroeschen_ab_2015_02_22.job
- c:\program files (x86)\Java\jre1.8.0_31\bin\javaw.exe [2015-01-21 09:11]
.
2015-02-02 c:\windows\Tasks\Dornroeschen_ab_2015_02_22_PreStarter.job
- c:\program files (x86)\Java\jre1.8.0_31\bin\javaw.exe [2015-01-21 09:11]
.
2015-01-23 c:\windows\Tasks\Ein_Herz_und_eine_Seele_Rosenmontagszug_ab_2015_02_15.job
- c:\program files (x86)\Java\jre1.8.0_31\bin\javaw.exe [2015-01-21 09:11]
.
2015-01-23 c:\windows\Tasks\Ein_Herz_und_eine_Seele_Rosenmontagszug_ab_2015_02_15_PreStarter.job
- c:\program files (x86)\Java\jre1.8.0_31\bin\javaw.exe [2015-01-21 09:11]
.
2015-02-06 c:\windows\Tasks\Tischlein_deck_dich_ab_2015_02_12.job
- c:\program files (x86)\Java\jre1.8.0_31\bin\javaw.exe [2015-01-21 09:11]
.
2015-02-06 c:\windows\Tasks\Tischlein_deck_dich_ab_2015_02_12_PreStarter.job
- c:\program files (x86)\Java\jre1.8.0_31\bin\javaw.exe [2015-01-21 09:11]
.
.
--------- X64 Entries -----------
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
NETSVCS BENÖTIGT REPARATUR - Derzeitig vorhandene Einträge:
.
Rebuilding ... You need to reboot your machine for this to take effect.
.
AeLookupSvc
AppInfo
AppMgmt
AudioSrv
BITS
browser
CertPropSvc
EapHost
FastUserSwitchingCompatibility
gpsvc
helpsvc
hkmsvc
Ias
IKEEXT
iphlpsvc
Irmon
lanmanserver
LogonHours
MMCSS
msiscsi
Nla
Ntmssvc
NWCWorkstation
Nwsapagent
PCAudit
ProfSvc
Rasauto
Rasman
Remoteaccess
schedule
SCPolicySvc
seclogon
SENS
SessionEnv
Sharedaccess
ShellHWDetection
SRService
Tapisrv
TermService
Themes
uploadmgr
wercplsupport
winmgmt
WmdmPmSp
Wmi
wuauserv
BDESVC
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = www.google.com
mDefault_Search_URL = www.google.com
mDefault_Page_URL = www.google.com
mStart Page = www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = www.google.com
IE: c:\users\seb\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloadernew.htm
IE: Alles mit FlashGet laden - c:\program files (x86)\FlashGet\jc_all.htm
IE: Download aller Links mit IDM - c:\program files (x86)\Internet Download Manager\IEGetAll.htm
IE: Download mit IDM - c:\program files (x86)\Internet Download Manager\IEExt.htm
IE: Mit FlashGet laden - c:\program files (x86)\FlashGet\jc_link.htm
IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~1\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095} -
FF - ProfilePath - c:\users\seb\AppData\Roaming\Mozilla\Firefox\Profiles\bfj3vrht.default-1421832937164\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
ShellIconOverlayIdentifiers-{CDC95B92-E27C-4745-A8C5-64A52A78855D} - (no file)
AddRemove-InstallShield für Microsoft Visual C++ 6 - c:\windows\IsUn0407.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\polugive]
"ImagePath"="c:\users\seb\AppData\Roaming\VOPackage\nsz92D6.tmpfs"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3122927800-2970940714-3403948491-1000_Classes\Wow6432Node\CLSID\{130F8154-E804-4BD5-A07B-35BE69039715}\{A730F6F3-255C-417C-8986-2C578500547E}*Hidden]
"{6D31FCD2-64F7-4E43-8E18-5A2BBA7D13C9}"="AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAc0ORMxBswkKXWNZcKG2lFAAAAAACAAAAAAAQZgAAAAEAACAAAACxs9PPh3zddPxR3ZpVbNCFlF2rb4CmTk+oRBL/dKmYdQAAAAAOgAAAAAIAACAAAAAWqjKfdCfC+WhGvNFBT2yU6/iGhcbV/L7q7Zqy0Y6zeRAAAACIV+3puV+6BE+8PVROfCDsQAAAAB+i7f5a8+zz9XApEKrtIgGKb+oTuoQY2/pBHAXT2mv9XdosiXl+bgBFAmeK6zdr2HxorFjluCf3kPsjS4jdDvI="
"{2338F5D5-2437-4FC3-9005-A01804321264}"="AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAc6B05nKe/ECw+g061BARLAAAAAACAAAAAAAQZgAAAAEAACAAAACU3n4PF0SwTDuwvudHYgok7tNhZqfN+uEg3Su9UmFPcQAAAAAOgAAAAAIAACAAAAC0nthFJWaNkxOrCU3R1Yji/amkS2yx23tXh0CXXh24RSAAAAB4CRUtjHjFEdMdADgS/cL/s773eFoZZuiSmPTAacMjCUAAAAABDUdyeQG8ByMz2VPpsEsFyVwnnTvnZazd/W+J2zemIEvAtERW6et38t0Fv9me5fliy1dzwyazVoiVf2OsG6rF"
"{FCCCD80D-2A5E-401E-B64F-D1C2E375B955}"="AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAc0ORMxBswkKXWNZcKG2lFAAAAAACAAAAAAAQZgAAAAEAACAAAABIU3minkHbvaPaoQ0bENza8u+kgKdxqYf6hV3qJtzu7gAAAAAOgAAAAAIAACAAAABZZ0qTCE62S3W9zx+MDzaNP3y5qqDACUNYzpXskZOh5BAAAAC1sYITKX1Qx2aWcxJ2OCXGQAAAAHngRneGuDnJRiSmke2OK45PKgjI6r4OVDcKzZcWnZY+HsUvwmRTI1nG74S3MczwMds1HIvqgehixmJryZg62Ig="
.
[HKEY_USERS\S-1-5-21-3122927800-2970940714-3403948491-1000_Classes\Wow6432Node\CLSID\{130F8154-E804-4BD5-A07B-35BE69039715}\{A730F6F3-255C-417C-8986-2C578500547E}*Hidden\DeltaClock]
"LastSynchronizationClock"=hex(b):80,51,ca,1e,e7,0a,d2,08
"DeltaClock"=hex(b):8c,4e,3a,f9,ff,ff,ff,ff
"LastNtpServer"="time.nist.gov"
.
[HKEY_USERS\S-1-5-21-3122927800-2970940714-3403948491-1000_Classes\Wow6432Node\CLSID\{405b8b8b-f7e1-4d0f-a16a-077a1bea3311}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000020
"Therad"=dword:00000001
"MData"=hex(0):e6,31,26,c3,aa,29,a3,3b,7d,c8,fe,6e,64,47,fe,6a,d5,25,bc,d7,6b,
54,b0,3a,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
[HKEY_USERS\S-1-5-21-3122927800-2970940714-3403948491-1000_Classes\Wow6432Node\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):aa,bb,04,f1,dc,10,8d,ba,6b,cd,f5,8a,75,4a,40,de,8a,95,58,5b,8a,
f7,a6,c8,e2,ef,9a,ab,6d,ab,a9,d6,e7,b8,97,ec,bf,64,70,ee,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.16"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2015-02-11 19:27:41 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2015-02-11 18:27
.
Vor Suchlauf: 16 Verzeichnis(se), 103.664.414.720 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 103.514.259.456 Bytes frei
.
- - End Of File - - 606601E08A39579DBE90C85E113FAE78
A36C5E4F47E84449FF07ED3517B43A31 |