Seitdem Combofix durchgelaufen ist funktioniert mein KeePass Programm zur Passwort-Verwaltung nicht mehr! Meine letzte externe Sicherung der Passwörter in einer verschlüsselten HTML Datei ist schon 2 Wochen alt, etwaige neue Pws sind in meinem .kdbx File...
Hab' KeePass deinstalliert & neuinstalliert, DENNOCH kommt diese Meldung:
Datei kann nicht ausgeführt werden
C:/Program Files(x86)/KeePass Password Safe 2/KeePass.exe
CreateProcess schlug fehl; Code 31.
Ein an das System angeschlossenes Gerät funktioniert nicht.
Hilfe!
Hier der Combofix Log: Code:
ComboFix 15-03-01.01 - ***** 07.03.2015 20:06:04.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8044.4865 [GMT 1:00]
ausgeführt von:: c:\users\*****\Desktop\ComboFix.exe
AV: 360 Total Security *Disabled/Updated* {2B66EE1E-E5C8-C2F7-648F-4E55AC68D37D}
SP: 360 Total Security *Disabled/Updated* {90070FFA-C3F2-CD79-5E3F-7527D7EF99C0}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\*****\AppData\Roaming\Local
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\arrow.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\context.html
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\deletelocallowlastpass.txt
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\deleteprogramfiles.txt
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\embed_cs_min.js
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\enabletoolbar.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\favicon.ico
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\find_bluetooth.exe
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\generate_min.js
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\iehome.html
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\iehome2.html
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\ielib_min.js
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\add.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\addfriend.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\addgroup.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\cog.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\collapseoff.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\collapseon.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\expandoff.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\expandon.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\lib\book_open.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\lib\creditcards.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\lib\export.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\lib\folder-blue.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\lib\help.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\lib\import.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\lib\kcontrol.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\lib\key.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\lib\note_add.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\lib\popular.gif
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\lib\popular.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\lib\remove-user-red.gif
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\logo.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\logouticon.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\lp_vault.jpg
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\lpdropdown_off.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\lpdropdown_on.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\lpwhitelogo.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\menu_x.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\poweredby.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\seccheck.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\time.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vault.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vault\add_site.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vault\cancel.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vault\create_group.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vault\delete.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vault\edit.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vault\enterprise.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vault\eye-hidden.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vault\eye-shown.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vault\folder_close.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vault\folder_open.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vault\link_account.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vault\manage_shared.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vault\search_lite.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vault\secure_note2.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vault\settings.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vault\share.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vault_button_hover.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vault_button_normal.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vaultaccept.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vaultalert.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vaultcopy.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vaultcreditmonitor.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vaultdelete.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vaultedit.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vaultff.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vaultidentity.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vaultinvite.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vaultreject.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vaultshare.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vaultshares.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\images\vaulttools.png
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\img.html
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\InTheHand.Net.Personal.dll
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\json2c.js
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\af-ZA.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\ar-EG.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\ar-SA.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\az-AZ.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\be-BY.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\bg-BG.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\bn-BD.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\bs-BA.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\ca-ES.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\cs-CZ.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\da-DK.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\de-DE.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\el-GR.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\en-AU.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\en-GB.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\en-US.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\eo-US.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\es-ES.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\es-MX.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\et-EE.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\fa-IR.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\fi-FI.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\fo-FO.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\fr-CA.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\fr-FR.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\ga-IE.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\gl-ES.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\gu-IN.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\he-IL.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\hi-IN.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\hr-HR.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\hu-HU.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\id-ID.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\is-IS.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\it-IT.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\ja-JP.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\ka-GE.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\kn-IN.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\ko-KR.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\lt-LT.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\lv-LV.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\mg-MG.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\mk-MK.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\ml-IN.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\mr-IN.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\ms-MY.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\nb-NO.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\ne-NP.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\nl-NL.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\nn-NO.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\pa-IN.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\pl-PL.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\pt-BR.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\pt-PT.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\ro-RO.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\ru-RU.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\si-LK.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\sk-SK.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\sl-SI.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\sq-AL.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\sr-RS.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\sv-SE.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\ta-IN.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\te-IN.regexp.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\th-TH.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\tl-PH.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\tr-TR.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\tzm-MA.regexp.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\uk-UA.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\ur-PK.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\ver
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\vi-VN.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\zh-CN.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lang\zh-TW.dat
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lastpass.exe
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\LastPassBroker.exe
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lp_ie.zip
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\lp_languages.zip
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\LPIEHome.ocx
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\LPIEHome64.ocx
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\LPPlugin.dll
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\LPPlugin_x64.dll
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\LPToolbar.dll
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\LPToolbar_x64.dll
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\menu.html
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\mpwchange.html
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\nplastpass.dll
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\nplastpass64.dll
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\popup_inframe_lib_min.js
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\popupcombobox.css
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\popupcombobox_min.js
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\popupfilltab.css
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\popupfilltab.frag
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\popupfilltab_common_min.js
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\popupfilltab_min.js
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\programfiles.txt
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\vaultcommonc.js
c:\users\*****\AppData\Roaming\Local\Temp\lptmp\WinBioStandalone.exe
c:\users\*****\AppData\Roaming\poclbm
c:\users\*****\AppData\Roaming\poclbm\poclbm.ini
c:\users\*****\videos\VIDEO_TS Track 1.bin
c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\IsUn0407.exe
c:\windows\msdownld.tmp
c:\windows\SysWow64\ijl11.dll
.
.
((((((((((((((((((((((( Dateien erstellt von 2015-02-07 bis 2015-03-07 ))))))))))))))))))))))))))))))
.
.
2015-03-07 19:19 . 2015-03-07 19:19 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2015-03-07 19:19 . 2015-03-07 19:19 -------- d-----w- c:\users\postgres\AppData\Local\temp
2015-03-07 19:19 . 2015-03-07 19:19 -------- d-----w- c:\users\hedev\AppData\Local\temp
2015-03-07 19:19 . 2015-03-07 19:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-03-07 18:52 . 2015-03-07 18:52 -------- d-----w- c:\program files (x86)\ESET
2015-03-07 14:21 . 2015-03-07 14:21 -------- d-sh--w- c:\windows\SysWow64\AI_RecycleBin
2015-03-07 04:44 . 2015-03-07 17:14 -------- d-----w- C:\FRST
2015-03-06 05:35 . 2015-03-06 05:35 970912 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr120.dll
2015-03-06 05:35 . 2015-03-06 05:35 455328 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp120.dll
2015-03-06 05:35 . 2015-03-06 05:35 3466856 ----a-w- c:\program files (x86)\Mozilla Firefox\d3dcompiler_47.dll
2015-03-06 05:35 . 2015-03-06 05:35 169584 ----a-w- c:\program files (x86)\Mozilla Firefox\gmp-clearkey\0.1\clearkey.dll
2015-03-06 03:00 . 2015-03-06 03:00 -------- d-----w- c:\program files (x86)\Project64 2.1
2015-03-05 17:15 . 2015-03-05 17:15 -------- d-----w- c:\users\*****\AppData\Local\Ndemic Creations
2015-03-01 18:27 . 2015-03-01 18:27 -------- d-----w- c:\users\*****\AppData\Local\CAPCOM
2015-02-26 10:57 . 2015-02-26 11:10 -------- d-----w- c:\program files (x86)\Cryptophane
2015-02-22 15:29 . 2015-02-22 15:29 -------- d-----w- c:\programdata\360TotalSecurity
2015-02-22 00:23 . 2015-02-22 00:23 -------- d-----w- c:\users\*****\AppData\Local\Steam
2015-02-17 17:41 . 2015-02-17 17:41 -------- d-----w- c:\users\*****\AppData\Roaming\XLMSoft
2015-02-17 17:32 . 2015-02-17 17:32 -------- d-----w- c:\program files (x86)\XLM Software
2015-02-13 20:37 . 2015-02-13 20:37 -------- d-----w- c:\users\*****\AppData\Roaming\Foxit Software
2015-02-13 20:36 . 2015-02-13 20:36 -------- d-----w- c:\users\Public\Foxit Software
2015-02-13 20:35 . 2015-02-13 20:35 -------- d-----w- c:\program files (x86)\Foxit Software
2015-02-06 06:24 . 2015-02-06 06:24 -------- d-----w- c:\program files (x86)\MakeMKV
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-02-12 13:35 . 2014-11-23 12:34 305736 ----a-w- c:\windows\system32\drivers\360Box64.sys
2015-02-12 13:35 . 2014-11-23 12:37 77896 ----a-w- c:\windows\system32\drivers\360AvFlt.sys
2015-02-12 13:35 . 2014-11-23 12:35 314448 ----a-w- c:\windows\system32\drivers\360fsflt.sys
2015-02-12 13:35 . 2014-11-23 12:35 180816 ----a-w- c:\windows\system32\drivers\BAPIDRV64.SYS
2015-02-06 05:23 . 2012-07-03 16:52 701616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2015-02-06 05:23 . 2011-07-22 04:47 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-01-25 19:35 . 2014-10-17 12:02 98216 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2015-01-08 00:37 . 2014-10-20 02:30 192344 ----a-w- c:\windows\system32\drivers\veracrypt.sys
2015-01-01 16:23 . 2015-01-01 16:58 175136 ----a-w- c:\windows\SysWow64\EasyAntiCheat.exe
2014-12-28 16:48 . 2014-11-01 10:20 129752 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-12-21 07:40 . 2014-12-19 15:34 18831572 ----a-w- c:\users\*****\AppData\Local\OcrMap.bin
2014-12-16 12:39 . 2014-12-16 12:39 35365 ----a-w- c:\windows\SysWow64\uninstHelixYUV.exe
2014-11-07 00:33 . 2014-11-07 00:33 14147584 ----a-w- c:\program files (x86)\Common Files\lpuninstall.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2015-02-11 01:12 152544 ----a-w- c:\users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2015-02-11 01:12 152544 ----a-w- c:\users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"]
@="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
2015-02-11 01:12 152544 ----a-w- c:\users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"]
@="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
2015-02-11 01:12 152544 ----a-w- c:\users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2015-02-11 01:12 152544 ----a-w- c:\users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"]
@="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
2015-02-11 01:12 152544 ----a-w- c:\users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2015-02-11 01:12 152544 ----a-w- c:\users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"]
@="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
2015-02-11 01:12 152544 ----a-w- c:\users\*****\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2014-11-21 7063832]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2015-02-18 785416]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Adobe Speed Launcher"="1425622892" [X]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2011-07-01 1103440]
"Dolby Advanced Audio v2"="c:\dolby pcee4\pcee4.exe" [2011-02-03 506712]
"ControlCenter3"="c:\program files (x86)\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688]
"QHSafeTray"="c:\program files (x86)\360\Total Security\safemon\QHSafeTray.exe" [2015-02-12 1208944]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Copy"="c:\users\*****\AppData\Roaming\Copy\CopyAgent.exe" [2015-02-07 15435920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"IsMyWinLockerReboot"="msiexec.exe" [2010-11-21 73216]
.
c:\users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Fences.lnk - c:\program files (x86)\Stardock\Fences\Fences.exe /startup [2012-10-29 4017368]
TimeLeft.lnk - c:\program files (x86)\TimeLeft3\TimeLeft.exe [2014-12-16 2050224]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"midi6"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 DirMngr;DirMngr;c:\program files (x86)\GNU\GnuPG\dirmngr.exe;c:\program files (x86)\GNU\GnuPG\dirmngr.exe [x]
R3 360AvFlt;360AvFlt mini-filter driver;c:\windows\system32\DRIVERS\360AvFlt.sys;c:\windows\SYSNATIVE\DRIVERS\360AvFlt.sys [x]
R3 andnetadb;ADB Interface DriverNet;c:\windows\system32\Drivers\lgandnetadb.sys;c:\windows\SYSNATIVE\Drivers\lgandnetadb.sys [x]
R3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\DRIVERS\lgandnetdiag64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetdiag64.sys [x]
R3 AndNetDiag2;LGE AndroidNet For Diagnostics Port;c:\windows\system32\DRIVERS\lgandnetdiag264.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetdiag264.sys [x]
R3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\DRIVERS\lgandnetmodem64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetmodem64.sys [x]
R3 andnetndis;LGE AndroidNet NDIS Ethernet Adapter;c:\windows\system32\DRIVERS\lgandnetndis64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetndis64.sys [x]
R3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x]
R3 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [x]
R3 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [x]
R3 Desura Install Service;Desura Install Service;c:\program files (x86)\Common Files\Desura\desura_service.exe;c:\program files (x86)\Common Files\Desura\desura_service.exe [x]
R3 EasyAntiCheat;EasyAntiCheat;c:\windows\system32\EasyAntiCheat.exe;c:\windows\SYSNATIVE\EasyAntiCheat.exe [x]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys;c:\windows\SYSNATIVE\DRIVERS\ew_hwusbdev.sys [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys;c:\windows\SYSNATIVE\DRIVERS\ggflt.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
R3 LVUVC64;Logitech Webcam Pro 9000(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 RRNetCap;RRNetCap Service;c:\windows\system32\DRIVERS\rrnetcap.sys;c:\windows\SYSNATIVE\DRIVERS\rrnetcap.sys [x]
R3 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 SynasUSB;SynasUSB;c:\windows\system32\drivers\SynUSB64.sys;c:\windows\SYSNATIVE\drivers\SynUSB64.sys [x]
R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x]
R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe;c:\program files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [x]
R3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys;c:\windows\SYSNATIVE\DRIVERS\teamviewervpn.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 VsEtwService120;Visual Studio ETW Event Collection Service;c:\program files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe;c:\program files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 CLKMSVC10_9EC60124;CyberLink Product - 2011/10/24 13:39;c:\program files (x86)\Cyberlink\PowerDVD9\NavFilter\kmsvc.exe;c:\program files (x86)\Cyberlink\PowerDVD9\NavFilter\kmsvc.exe [x]
R4 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [x]
R4 Giraffic;Veoh Giraffic Video Accelerator;c:\program files (x86)\Giraffic\Veoh_GirafficWatchdog.exe;c:\program files (x86)\Giraffic\Veoh_GirafficWatchdog.exe [x]
R4 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe;c:\program files (x86)\Acer\Registration\GREGsvc.exe [x]
R4 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x]
R4 Mobile Partner. RunOuc;Mobile Partner. OUC;c:\program files (x86)\Mobile Partner\UpdateDog\ouc.exe;c:\program files (x86)\Mobile Partner\UpdateDog\ouc.exe [x]
R4 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe;c:\program files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [x]
R4 PaceLicenseDServices;PACE License Services;c:\program files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe;c:\program files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe [x]
R4 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S0 veracrypt;veracrypt;c:\windows\System32\drivers\veracrypt.sys;c:\windows\SYSNATIVE\drivers\veracrypt.sys [x]
S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys;c:\windows\SYSNATIVE\DRIVERS\vmci.sys [x]
S0 vsock;vSockets Driver;c:\windows\system32\drivers\vsock.sys;c:\windows\SYSNATIVE\drivers\vsock.sys [x]
S1 360Box64;360Box mini-filter driver;c:\windows\system32\DRIVERS\360Box64.sys;c:\windows\SYSNATIVE\DRIVERS\360Box64.sys [x]
S1 360Camera;360Safe Camera Filter Service;c:\windows\system32\Drivers\360Camera64.sys;c:\windows\SYSNATIVE\Drivers\360Camera64.sys [x]
S1 360FsFlt;360FsFlt mini-filter driver;c:\windows\system32\DRIVERS\360FsFlt.sys;c:\windows\SYSNATIVE\DRIVERS\360FsFlt.sys [x]
S1 BAPIDRV;BAPIDRV;c:\windows\system32\DRIVERS\BAPIDRV64.sys;c:\windows\SYSNATIVE\DRIVERS\BAPIDRV64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxDrv.sys [x]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxUSBMon.sys [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x]
S2 FoxitCloudUpdateService;Foxit Cloud Safe Update Service;c:\program files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe;c:\program files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [x]
S2 HWDeviceService64.exe;HWDeviceService64.exe;c:\programdata\DatacardService\HWDeviceService64.exe;c:\programdata\DatacardService\HWDeviceService64.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 IpOverUsbSvc;Windows Phone IP over USB Transport (IpOverUsbSvc);c:\program files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe;c:\program files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 postgresql-x64-9.0;postgresql-x64-9.0 - PostgreSQL Server 9.0;C:/Program Files/PostgreSQL/9.0/bin/pg_ctl.exe runservice -N postgresql-x64-9.0 -D C:/Program Files/PostgreSQL/9.0/data -w;C:/Program Files/PostgreSQL/9.0/bin/pg_ctl.exe runservice -N postgresql-x64-9.0 -D C:/Program Files/PostgreSQL/9.0/data -w [x]
S2 QHActiveDefense;360 Total Security;c:\program files (x86)\360\Total Security\safemon\QHActiveDefense.exe;c:\program files (x86)\360\Total Security\safemon\QHActiveDefense.exe [x]
S2 Sentinel64;Sentinel64;c:\windows\System32\Drivers\Sentinel64.sys;c:\windows\SYSNATIVE\Drivers\Sentinel64.sys [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [x]
S2 VMwareHostd;VMware Workstation Server;c:\program files (x86)\VMware\VMware Workstation\vmware-hostd.exe;c:\program files (x86)\VMware\VMware Workstation\vmware-hostd.exe [x]
S2 vstor2-mntapi20-shared;Vstor2 MntApi 2.0 Driver (shared);SysWOW64\drivers\vstor2-mntapi20-shared.sys;SysWOW64\drivers\vstor2-mntapi20-shared.sys [x]
S3 360AntiHacker;360Safe Anti Hacker Service;c:\windows\system32\Drivers\360AntiHacker64.sys;c:\windows\SYSNATIVE\Drivers\360AntiHacker64.sys [x]
S3 b57xdbd;Broadcom xD Picture Bus Driver Service;c:\windows\system32\DRIVERS\b57xdbd.sys;c:\windows\SYSNATIVE\DRIVERS\b57xdbd.sys [x]
S3 b57xdmp;Broadcom xD Picture vstorp client drv;c:\windows\system32\DRIVERS\b57xdmp.sys;c:\windows\SYSNATIVE\DRIVERS\b57xdmp.sys [x]
S3 bScsiMSa;bScsiMSa;c:\windows\system32\DRIVERS\bScsiMSa.sys;c:\windows\SYSNATIVE\DRIVERS\bScsiMSa.sys [x]
S3 bScsiSDa;bScsiSDa;c:\windows\system32\DRIVERS\bScsiSDa.sys;c:\windows\SYSNATIVE\DRIVERS\bScsiSDa.sys [x]
S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys;c:\windows\SYSNATIVE\DRIVERS\vrtaucbl.sys [x]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys;c:\windows\SYSNATIVE\DRIVERS\ewusbnet.sys [x]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys;c:\windows\SYSNATIVE\DRIVERS\ew_jubusenum.sys [x]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RRNetCapMP;RRNetCapMP;c:\windows\system32\DRIVERS\rrnetcap.sys;c:\windows\SYSNATIVE\DRIVERS\rrnetcap.sys [x]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x]
S4 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S4 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S4 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S4 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - NVSTREAMKMS
*Deregistered* - truecrypt
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2015-02-11 01:12 185824 ----a-w- c:\users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2015-02-11 01:12 185824 ----a-w- c:\users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"]
@="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
2015-02-11 01:12 185824 ----a-w- c:\users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"]
@="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
2015-02-11 01:12 185824 ----a-w- c:\users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2015-02-11 01:12 185824 ----a-w- c:\users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"]
@="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
2015-02-11 01:12 185824 ----a-w- c:\users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2015-02-11 01:12 185824 ----a-w- c:\users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"]
@="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
2015-02-11 01:12 185824 ----a-w- c:\users\*****\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-06-21 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-06-21 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-06-21 416024]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-03-28 11786344]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-03-21 2207848]
"Fences"="c:\program files (x86)\Stardock\Fences\Fences.exe" [2012-10-29 4017368]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-08-01 2403104]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files (x86)\Stardock\Fences\FencesMenu64.dll" [2012-10-29 551640]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.google.com
TCP: Interfaces\{05DE8C78-3AC9-4B2C-9D85-13F5F33A6FFC}: NameServer = 193.189.244.225 193.189.244.206
TCP: Interfaces\{26141D4E-6B47-47A4-BE21-0F9864CC4ED8}: NameServer = 193.189.244.225 193.189.244.206
TCP: Interfaces\{28490DBF-A1C0-4920-AF28-50ECAEC29186}: NameServer = 193.189.244.225 193.189.244.206
TCP: Interfaces\{3B5A7CEE-5BDD-41C2-8099-5B5B5E9F3473}: NameServer = 193.189.244.225 193.189.244.206
TCP: Interfaces\{60AA6E3A-F8B7-4493-B253-ED25FEC3BE48}: NameServer = 193.189.244.206 193.189.244.225
TCP: Interfaces\{6D6AD976-9958-4895-B655-7562A517A433}: NameServer = 193.189.244.206 193.189.244.225
TCP: Interfaces\{7236F28B-4F21-47D1-BDB6-6FEF4857AD9A}: NameServer = 193.189.244.206 193.189.244.225
TCP: Interfaces\{ACFBF600-384E-4311-B0B7-79BC6ED5A56E}: NameServer = 193.189.244.206 193.189.244.225
TCP: Interfaces\{BB5550E0-672D-4085-89B5-6D45CA7386B3}: NameServer = 193.189.244.206 193.189.244.225
TCP: Interfaces\{BE6BFEF7-058C-4742-A3B9-624C3714AA79}: NameServer = 193.189.244.206 193.189.244.225
TCP: Interfaces\{D893661C-D7C1-49DF-AAC3-BCEA438691C7}: NameServer = 193.189.244.225 193.189.244.206
TCP: Interfaces\{E6B34D56-B1B1-4ACF-9922-063A5EBB478F}: NameServer = 193.189.244.225 193.189.244.206
FF - ProfilePath - c:\users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\kyd8k7f2.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{15EDBCBF-7231-4290-946E-5BB12C6AF342} - (no file)
ShellIconOverlayIdentifiers-{14A3EC74-D852-416A-9691-AC3096EE1953} - (no file)
ShellIconOverlayIdentifiers-{E9C2814C-12B8-4D74-9551-16DDEBFC8AE4} - (no file)
ShellIconOverlayIdentifiers-{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
WebBrowser-{7E111A5C-3D11-4F56-9463-5310C3C69025} - (no file)
ShellIconOverlayIdentifiers-{15EDBCBF-7231-4290-946E-5BB12C6AF342} - (no file)
ShellIconOverlayIdentifiers-{14A3EC74-D852-416A-9691-AC3096EE1953} - (no file)
ShellIconOverlayIdentifiers-{E9C2814C-12B8-4D74-9551-16DDEBFC8AE4} - (no file)
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-HelixYUVCodecs - c:\windows\system32\uninstHelixYUV.exe
AddRemove-YAMB - c:\program files (x86)\YAMB\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-x64-9.0]
"ImagePath"="C:/Program Files/PostgreSQL/9.0/bin/pg_ctl.exe runservice -N \"postgresql-x64-9.0\" -D \"C:/Program Files/PostgreSQL/9.0/data\" -w"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-x64-9.0]
"ImagePath"="C:/Program Files/PostgreSQL/9.0/bin/pg_ctl.exe runservice -N \"postgresql-x64-9.0\" -D \"C:/Program Files/PostgreSQL/9.0/data\" -w"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4d,66,3e,6f,0b,46,16,4d,86,c7,fb,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4d,66,3e,6f,0b,46,16,4d,86,c7,fb,\
.
[HKEY_USERS\S-1-5-21-1687097068-401554184-1692899982-1001\Software\SecuROM\License information*]
"datasecu"=hex:7d,b1,21,a1,cd,37,47,7f,eb,4c,b5,c7,e4,06,c5,52,b0,1a,fa,bd,e3,
8b,95,50,11,9b,8d,73,00,44,ec,30,8a,93,ea,d6,5f,fb,1a,9b,1a,9d,55,d1,57,07,\
"rkeysecu"=hex:63,02,4e,e1,f0,dd,7b,5f,af,38,e0,12,2a,49,64,9b
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:75,a2,25,0d,99,1a,54,73,69,a9,af,e5,11,69,66,5e,98,2e,db,79,1d,
10,88,a3,69,ee,82,70,00,91,51,fc,3f,a9,e7,e9,e4,67,43,e8,02,36,f2,86,89,d2,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.16"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:75,a2,25,0d,99,1a,54,73,69,a9,af,e5,11,69,66,5e,98,2e,db,79,1d,
10,88,a3,69,ee,82,70,00,91,51,fc,27,4f,f4,f1,c1,b2,ed,8d,02,36,f2,86,89,d2,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0011\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0012\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0013\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0014\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2015-03-07 20:35:55
ComboFix-quarantined-files.txt 2015-03-07 19:35
.
Vor Suchlauf: 42 Verzeichnis(se), 32.526.516.224 Bytes frei
Nach Suchlauf: 53 Verzeichnis(se), 32.773.066.752 Bytes frei
.
- - End Of File - - 37CFC9E8F0FB0FFE6729FF15FC5E1263 |