SkorPlays | 30.08.2015 16:22 | Ah ok danke. hier ist die txt: Code:
ComboFix 15-08-27.01 - SkorPlays 30.08.2015 15:03:52.2.6 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8157.5165 [GMT 2:00]
ausgeführt von:: c:\users\SkorPlays\Desktop\ComboFix.exe
AV: McAfee Anti-Virus und Anti-Spyware *Disabled/Updated* {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
FW: McAfee Firewall *Disabled* {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}
SP: McAfee Anti-Virus und Anti-Spyware *Disabled/Updated* {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\SearchProtect
c:\program files (x86)\SearchProtect\Main\bin\CltMngSvc.exe
c:\program files (x86)\SearchProtect\Main\bin\SPtool.dll
c:\program files (x86)\SearchProtect\Main\bin\uninstall.exe
c:\program files (x86)\SearchProtect\Main\bin\uninstall.pun
c:\program files (x86)\SearchProtect\Main\rep\cfi.bin
c:\program files (x86)\SearchProtect\Main\rep\edk.bin
c:\program files (x86)\SearchProtect\Main\rep\pni.bin
c:\program files (x86)\SearchProtect\Main\rep\SystemRepository.dat
c:\program files (x86)\SearchProtect\Main\rep\trn.bin
c:\program files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe
c:\program files (x86)\SearchProtect\SearchProtect\bin\RN32.dll
c:\program files (x86)\SearchProtect\SearchProtect\bin\SPtool64.exe
c:\program files (x86)\SearchProtect\SearchProtect\bin\VC32.dll
c:\program files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll
c:\program files (x86)\SearchProtect\SearchProtect\bin\VC64.dll
c:\program files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll
c:\program files (x86)\SearchProtect\UI\bin\cltmngui.exe
c:\program files (x86)\SearchProtect\UI\dialogs\Consent\consent.css
c:\program files (x86)\SearchProtect\UI\dialogs\Consent\consent.html
c:\program files (x86)\SearchProtect\UI\dialogs\Consent\consent.js
c:\program files (x86)\SearchProtect\UI\dialogs\Consent\defaults.js
c:\program files (x86)\SearchProtect\UI\dialogs\Images\Apply-default.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\Apply-onclick.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\Apply-Rollover.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\bg-dia.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\bg-uninstall.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\bg-with-logo.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\bg.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\bgNotif.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\bgSettings.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\bgSettingsDS.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\bgUninstall.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\btnBlue.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\btnClose.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\btnSilver.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\button-bg.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\checkbox.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\checkbox_checked.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\checkbox_def.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\close-win-def.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\close-win-over-click.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\gray-bg.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\hez-def-grey.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\hez-def.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\hez-selected.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\hez.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\icon-win.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\info-icon.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\menu-rollover.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\menu-selected.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\radio-button-def.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\radio-button-selected.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\radio-button.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\radio-button2.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\Settings-icon.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\SP_DialogBG.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\text-field.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\v.png
c:\program files (x86)\SearchProtect\UI\dialogs\Images\x.png
c:\program files (x86)\SearchProtect\UI\dialogs\libs\defaults.js
c:\program files (x86)\SearchProtect\UI\dialogs\libs\DialogAPI.js
c:\program files (x86)\SearchProtect\UI\dialogs\libs\dialogUtils.js
c:\program files (x86)\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js
c:\program files (x86)\SearchProtect\UI\dialogs\libs\json2.min.js
c:\program files (x86)\SearchProtect\UI\dialogs\libs\main.js
c:\program files (x86)\SearchProtect\UI\dialogs\protection\defaults.js
c:\program files (x86)\SearchProtect\UI\dialogs\protection\protection.css
c:\program files (x86)\SearchProtect\UI\dialogs\protection\protection.html
c:\program files (x86)\SearchProtect\UI\dialogs\protection\protection.js
c:\program files (x86)\SearchProtect\UI\dialogs\protectionDS\defaults.js
c:\program files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.css
c:\program files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.html
c:\program files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.js
c:\program files (x86)\SearchProtect\UI\dialogs\settings.html
c:\program files (x86)\SearchProtect\UI\dialogs\settings\defaults.js
c:\program files (x86)\SearchProtect\UI\dialogs\settings\settings.css
c:\program files (x86)\SearchProtect\UI\dialogs\settings\settings.html
c:\program files (x86)\SearchProtect\UI\dialogs\settings\settings.js
c:\program files (x86)\SearchProtect\UI\dialogs\style.css
c:\program files (x86)\SearchProtect\UI\dialogs\uninstall\defaults.js
c:\program files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.css
c:\program files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.html
c:\program files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.js
c:\program files (x86)\XTab\SupTab.dll
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\_ctypes.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\_elementtree.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\_hashlib.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\_multiprocessing.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\_socket.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\_ssl.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\pyexpat.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\pysqlite2._sqlite.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\python27.dll
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\pythoncom27.dll
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\PyWinTypes27.dll
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\select.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\unicodedata.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\win32api.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\win32com.shell.shell.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\win32crypt.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\win32event.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\win32file.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\win32inet.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\win32pdh.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\win32pipe.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\win32process.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\win32profile.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\win32security.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\win32ts.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\windows._lib_cacheinvalidation.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\wx._controls_.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\wx._core_.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\wx._gdi_.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\wx._html2.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\wx._misc_.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\wx._windows_.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\wx._wizard.pyd
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\wxbase294u_net_vc90.dll
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\wxbase294u_vc90.dll
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\wxmsw294u_adv_vc90.dll
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\wxmsw294u_core_vc90.dll
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\wxmsw294u_html_vc90.dll
c:\users\SKORPL~1\AppData\Local\Temp\_MEI41282\wxmsw294u_webview_vc90.dll
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\_ctypes.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\_elementtree.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\_hashlib.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\_multiprocessing.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\_socket.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\_ssl.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\pyexpat.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\pysqlite2._sqlite.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\python27.dll
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\pythoncom27.dll
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\PyWinTypes27.dll
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\select.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\unicodedata.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\win32api.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\win32com.shell.shell.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\win32crypt.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\win32event.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\win32file.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\win32inet.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\win32pdh.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\win32pipe.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\win32process.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\win32profile.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\win32security.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\win32ts.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\windows._lib_cacheinvalidation.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\wx._controls_.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\wx._core_.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\wx._gdi_.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\wx._html2.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\wx._misc_.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\wx._windows_.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\wx._wizard.pyd
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\wxbase294u_net_vc90.dll
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\wxbase294u_vc90.dll
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\wxmsw294u_adv_vc90.dll
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\wxmsw294u_core_vc90.dll
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\wxmsw294u_html_vc90.dll
c:\users\SkorPlays\AppData\Local\Temp\_MEI41282\wxmsw294u_webview_vc90.dll
.
---- Vorheriger Suchlauf -------
.
C:\END
c:\program files (x86)\SearchProtect\CRASH_DUMP_P9312_T8432_D2015_08_29_T15_25_44.dmp
c:\program files (x86)\SearchProtect\CRASH_REPORT_P9312_T8432_D2015_08_29_T15_25_44.txt
c:\program files (x86)\SearchProtect\EULA.txt
c:\program files (x86)\XTab\SupTab.dll
c:\programdata\97771893c780bafa
c:\programdata\97771893c780bafa\15a1758beb4d95da6f8d8cdd74ed151b.ini
c:\programdata\97771893c780bafa\3ed03cfb568002832d87d62c8895086e.ini
c:\programdata\97771893c780bafa\5563f418483f31116f8d8cdd74ed151b.ini
c:\programdata\97771893c780bafa\c6fe71eb0df193216f8d8cdd74ed151b.ini
c:\users\SkorPlays\AppData\Local\Adobe\downloader.dll
c:\users\SkorPlays\AppData\Local\Adobe\gccheck.exe
c:\users\SkorPlays\AppData\Local\Adobe\gtbcheck.exe
c:\users\SkorPlays\AppData\Local\lollipop
c:\users\SkorPlays\xobglu32.dll
c:\windows\wininit.ini
.
-- Vorheriger Suchlauf --
.
Infizierte Kopie von c:\windows\SysWow64\user32.dll wurde gefunden und desinfiziert
Kopie von - c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll wurde wiederhergestellt
.
--------
.
Infizierte Kopie von c:\windows\SysWow64\userinit.exe wurde gefunden und desinfiziert
Kopie von - c:\windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe wurde wiederhergestellt
.
.
((((((((((((((((((((((((((((((((((((((( Treiber/Dienste )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_AdobeUpdateService
-------\Service_CltMngSvc
-------\Service_AdobeUpdateService
-------\Service_CltMngSvc
.
.
((((((((((((((((((((((( Dateien erstellt von 2015-07-28 bis 2015-08-30 ))))))))))))))))))))))))))))))
.
.
2015-08-30 13:51 . 2015-08-30 13:51 -------- d-----w- C:\$RECYCLE.BIN
2015-08-30 13:15 . 2015-08-30 13:15 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-08-30 12:07 . 2015-08-30 12:07 22512 ----a-w- c:\windows\system32\drivers\SPPD.sys
2015-08-29 13:12 . 2015-08-29 13:12 -------- d-----w- c:\users\SkorPlays\AppData\Local\bvxvbxvd
2015-08-29 13:06 . 2015-08-29 13:06 -------- d-----w- c:\users\SkorPlays\AppData\Local\SearchProtect
2015-08-29 12:27 . 2015-08-30 11:18 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2015-08-29 12:27 . 2015-08-29 13:43 192216 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-08-29 12:24 . 2015-08-29 13:42 109272 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-08-29 11:57 . 2015-08-29 11:57 -------- d-----w- c:\program files (x86)\VS Revo Group
2015-08-28 13:42 . 2015-08-28 15:58 -------- d-----w- C:\FRST
2015-08-27 08:36 . 2015-08-11 04:52 69416 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2015-08-27 08:36 . 2015-08-11 04:52 50472 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2015-08-25 01:00 . 2015-08-11 01:20 25191936 ----a-w- c:\windows\system32\mshtml.dll
2015-08-25 01:00 . 2015-08-11 01:14 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2015-08-25 01:00 . 2015-08-11 00:33 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2015-08-24 06:38 . 2015-08-24 06:38 -------- d-----w- c:\program files (x86)\Common Files\Skype
2015-08-24 06:38 . 2015-08-24 06:38 -------- d-----r- c:\program files (x86)\Skype
2015-08-24 01:10 . 2015-07-30 13:13 103120 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-08-24 01:10 . 2015-07-30 13:13 124624 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-23 18:57 . 2015-08-23 18:57 -------- d-----w- c:\program files\iPod
2015-08-23 18:57 . 2015-08-23 18:57 -------- d-----w- c:\program files (x86)\iTunes
2015-08-23 18:57 . 2015-08-23 18:57 -------- d-----w- c:\program files\iTunes
2015-08-23 11:28 . 2015-07-01 20:49 260096 ----a-w- c:\windows\system32\WebClnt.dll
2015-08-23 10:59 . 2015-08-24 16:08 -------- d-----w- c:\users\SkorPlays\AppData\Local\bvxvyxvec
2015-08-07 15:49 . 2015-08-23 23:24 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10145.bin
2015-08-02 16:05 . 2015-08-02 16:06 63488 ----a-w- c:\users\SkorPlays\xobglu16.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-08-24 06:54 . 2013-11-22 14:19 778440 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2015-08-24 06:54 . 2013-11-22 14:19 142536 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-08-24 01:01 . 2013-12-06 14:28 132483416 ----a-w- c:\windows\system32\MRT.exe
2015-08-17 23:30 . 2014-07-29 19:05 1316184 ----a-w- c:\windows\SysWow64\nvspbridge.dll
2015-08-17 23:30 . 2014-01-18 10:14 1423120 ----a-w- c:\windows\SysWow64\nvspcap.dll
2015-08-17 23:29 . 2014-07-29 19:05 1756608 ----a-w- c:\windows\system32\nvspbridge64.dll
2015-08-17 23:29 . 2014-01-18 10:14 1710568 ----a-w- c:\windows\system32\nvspcap64.dll
2015-08-13 02:44 . 2015-01-16 13:27 631504 ----a-w- c:\programdata\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe
2015-08-11 04:52 . 2014-01-18 10:11 72504 ----a-w- c:\windows\system32\nvaudcap64v.dll
2015-08-03 10:12 . 2014-04-22 07:09 33856 ---ha-w- c:\windows\system32\hamachi.sys
2015-07-24 05:57 . 2014-09-25 21:00 97888 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2015-07-18 14:13 . 2014-08-07 22:17 226168 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2015-07-18 14:10 . 2014-08-07 22:17 226168 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2015-07-15 17:54 . 2015-08-23 11:29 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2015-07-04 18:07 . 2015-07-15 11:37 2087424 ----a-w- c:\windows\system32\ole32.dll
2015-07-04 17:48 . 2015-07-15 11:37 1414656 ----a-w- c:\windows\SysWow64\ole32.dll
2015-07-02 13:33 . 2015-04-08 05:44 412440 ----a-w- c:\windows\system32\drivers\mfeaack.sys
2015-07-02 13:33 . 2013-11-04 15:51 77536 ----a-w- c:\windows\system32\drivers\cfwids.sys
2015-07-02 13:33 . 2013-11-04 15:46 344704 ----a-w- c:\windows\system32\drivers\mfewfpk.sys
2015-07-02 13:33 . 2013-11-04 15:41 496888 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2015-07-02 13:33 . 2013-11-04 15:40 347800 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2015-07-02 13:33 . 2013-09-24 19:22 875928 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2015-06-29 08:03 . 2014-01-04 16:51 254792 ----a-w- c:\windows\system32\mfevtps.exe
2015-06-28 20:37 . 2015-06-28 20:37 529080 ----a-w- c:\windows\system32\drivers\mfencbdc.sys
2015-06-28 20:37 . 2015-06-28 20:37 20480 ----a-w- c:\windows\system32\drivers\mfeclnrk.sys
2015-06-28 20:37 . 2015-06-28 20:37 109728 ----a-w- c:\windows\system32\drivers\mfencrk.sys
2015-06-17 17:47 . 2015-07-15 11:41 404992 ----a-w- c:\windows\system32\gdi32.dll
2015-06-17 17:37 . 2015-07-15 11:41 312320 ----a-w- c:\windows\SysWow64\gdi32.dll
2015-06-17 09:10 . 2015-07-14 14:54 938752 ----a-w- c:\windows\SysWow64\nvumdshim.dll
2015-06-17 09:10 . 2015-07-14 14:54 40280 ----a-w- c:\windows\system32\nvhdap64.dll
2015-06-17 09:10 . 2015-07-14 14:54 204648 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
2015-06-17 09:10 . 2015-07-14 14:54 1099992 ----a-w- c:\windows\system32\nvumdshimx.dll
2015-06-17 09:10 . 2015-07-14 14:54 982672 ----a-w- c:\windows\SysWow64\NvIFR.dll
2015-06-17 09:10 . 2015-07-14 14:54 975176 ----a-w- c:\windows\SysWow64\NvFBC.dll
2015-06-17 09:10 . 2015-07-14 14:54 503408 ----a-w- c:\windows\system32\nvEncodeAPI64.dll
2015-06-17 09:10 . 2015-07-14 14:54 42729104 ----a-w- c:\windows\system32\nvcompiler.dll
2015-06-17 09:10 . 2015-07-14 14:54 408392 ----a-w- c:\windows\system32\NvIFROpenGL.dll
2015-06-17 09:10 . 2015-07-14 14:54 407296 ----a-w- c:\windows\SysWow64\nvEncodeAPI.dll
2015-06-17 09:10 . 2015-07-14 14:54 37748880 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2015-06-17 09:10 . 2015-07-14 14:54 364176 ----a-w- c:\windows\SysWow64\NvIFROpenGL.dll
2015-06-17 09:10 . 2015-07-14 14:54 30481552 ----a-w- c:\windows\system32\nvoglv64.dll
2015-06-17 09:10 . 2015-07-14 14:54 2932368 ----a-w- c:\windows\system32\nvcuvid.dll
2015-06-17 09:10 . 2015-07-14 14:54 2599752 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2015-06-17 09:10 . 2015-07-14 14:54 1898128 ----a-w- c:\windows\system32\nvdispco6435330.dll
2015-06-17 09:10 . 2015-07-14 14:54 176904 ----a-w- c:\windows\system32\nvinitx.dll
2015-06-17 09:10 . 2015-07-14 14:54 16145200 ----a-w- c:\windows\system32\nvopencl.dll
2015-06-17 09:10 . 2015-07-14 14:54 1557832 ----a-w- c:\windows\system32\nvdispgenco6435330.dll
2015-06-17 09:10 . 2015-07-14 14:54 155280 ----a-w- c:\windows\SysWow64\nvinit.dll
2015-06-17 09:10 . 2015-07-14 14:54 150832 ----a-w- c:\windows\system32\nvoglshim64.dll
2015-06-17 09:10 . 2015-07-14 14:54 14497520 ----a-w- c:\windows\system32\nvcuda.dll
2015-06-17 09:10 . 2015-07-14 14:54 13263056 ----a-w- c:\windows\SysWow64\nvopencl.dll
2015-06-17 09:10 . 2015-07-14 14:54 128696 ----a-w- c:\windows\SysWow64\nvoglshim32.dll
2015-06-17 09:10 . 2015-07-14 14:54 11831856 ----a-w- c:\windows\SysWow64\nvcuda.dll
2015-06-17 09:10 . 2015-07-14 14:54 11011216 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2015-06-17 09:10 . 2015-07-14 14:54 1060168 ----a-w- c:\windows\system32\NvIFR64.dll
2015-06-17 09:10 . 2015-07-14 14:54 1050768 ----a-w- c:\windows\system32\NvFBC64.dll
2015-06-17 09:10 . 2015-01-24 10:42 22947144 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2015-06-17 09:10 . 2014-01-18 10:11 1567576 ----a-w- c:\windows\system32\nvhdagenco6420103.dll
2015-06-17 09:10 . 2013-11-21 08:44 112784 ----a-w- c:\windows\system32\OpenCL.dll
2015-06-17 09:10 . 2013-11-21 08:44 105288 ----a-w- c:\windows\SysWow64\OpenCL.dll
2015-06-17 09:10 . 2013-11-12 07:41 17724600 ----a-w- c:\windows\system32\nvwgf2umx.dll
2015-06-17 09:10 . 2013-11-12 07:41 15224784 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2015-06-17 09:10 . 2013-11-12 07:41 15866992 ----a-w- c:\windows\system32\nvd3dumx.dll
2015-06-17 09:10 . 2013-11-12 07:41 12855416 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2015-06-17 09:10 . 2013-11-12 07:41 3395648 ----a-w- c:\windows\system32\nvapi64.dll
2015-06-17 09:10 . 2013-11-12 07:41 2997544 ----a-w- c:\windows\SysWow64\nvapi.dll
2015-06-17 06:48 . 2013-11-21 08:45 937616 ----a-w- c:\windows\system32\nvvsvc.exe
2015-06-17 06:48 . 2013-11-21 08:45 62792 ----a-w- c:\windows\system32\nvshext.dll
2015-06-17 06:48 . 2013-11-21 08:45 385168 ----a-w- c:\windows\system32\nvmctray.dll
2015-06-17 06:48 . 2013-11-21 08:45 2558792 ----a-w- c:\windows\system32\nvsvcr.dll
2015-06-17 06:48 . 2013-11-21 08:45 6873232 ----a-w- c:\windows\system32\nvcpl.dll
2015-06-17 06:48 . 2013-11-21 08:45 3492168 ----a-w- c:\windows\system32\nvsvc64.dll
2015-06-17 06:03 . 2015-07-14 14:58 571024 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2015-06-15 21:50 . 2015-07-15 11:37 112064 ----a-w- c:\windows\system32\consent.exe
2015-06-15 21:45 . 2015-07-15 11:37 3242496 ----a-w- c:\windows\system32\msi.dll
2015-06-15 21:45 . 2015-07-15 11:37 504320 ----a-w- c:\windows\system32\msihnd.dll
2015-06-15 21:45 . 2015-07-15 11:37 70656 ----a-w- c:\windows\system32\appinfo.dll
2015-06-15 21:45 . 2015-07-15 11:37 1941504 ----a-w- c:\windows\system32\authui.dll
2015-06-15 21:44 . 2015-07-15 11:37 128000 ----a-w- c:\windows\system32\msiexec.exe
2015-06-15 21:43 . 2015-07-15 11:37 337408 ----a-w- c:\windows\SysWow64\msihnd.dll
2015-06-15 21:43 . 2015-07-15 11:37 2364416 ----a-w- c:\windows\SysWow64\msi.dll
2015-06-15 21:43 . 2015-07-15 11:37 1805824 ----a-w- c:\windows\SysWow64\authui.dll
2015-06-15 21:42 . 2015-07-15 11:37 73216 ----a-w- c:\windows\SysWow64\msiexec.exe
2015-06-15 21:42 . 2015-07-15 11:37 25088 ----a-w- c:\windows\system32\msimsg.dll
2015-06-15 21:37 . 2015-07-15 11:37 25088 ----a-w- c:\windows\SysWow64\msimsg.dll
2015-06-10 21:08 . 2015-06-10 21:08 6112072 ----a-w- c:\windows\system32\usbaaplrc.dll
2015-06-10 21:08 . 2015-06-10 21:08 54784 ----a-w- c:\windows\system32\drivers\usbaapl64.sys
2015-06-10 16:59 . 2015-06-10 16:59 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2015-06-10 16:59 . 2015-06-10 16:59 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2015-06-10 16:59 . 2015-06-10 16:59 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2015-06-10 16:59 . 2015-06-10 16:59 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2015-06-09 18:03 . 2015-07-15 11:41 3180544 ----a-w- c:\windows\system32\rdpcorets.dll
2015-06-09 18:03 . 2015-07-15 11:41 16384 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2015-06-02 14:11 . 2013-11-21 08:45 4421614 ----a-w- c:\windows\system32\nvcoproc.bin
2015-06-02 00:07 . 2015-07-15 11:41 254976 ----a-w- c:\windows\system32\cewmdm.dll
2015-06-01 23:47 . 2015-07-15 11:41 210432 ----a-w- c:\windows\SysWow64\cewmdm.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}]
2013-12-30 20:28 294456 ----a-w- c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2015-05-15 07:38 1605832 ----a-w- c:\users\SkorPlays\AppData\Local\Microsoft\OneDrive\17.3.5849.0427\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2015-05-15 07:38 1605832 ----a-w- c:\users\SkorPlays\AppData\Local\Microsoft\OneDrive\17.3.5849.0427\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2015-05-15 07:38 1605832 ----a-w- c:\users\SkorPlays\AppData\Local\Microsoft\OneDrive\17.3.5849.0427\FileSyncShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EADM"="d:\neuer ordner\Origin\Origin.exe" [2015-07-27 3632112]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"GoogleDriveSync"="c:\program files (x86)\Google\Drive\googledrivesync.exe" [2014-01-30 21822128]
"CAHeadless"="c:\program files (x86)\Adobe\Elements 11 Organizer\CAHeadless\ElementsAutoAnalyzer.exe" [2012-09-17 840784]
"TeamSpeak 3 Client"="c:\users\SkorPlays\AppData\Local\TeamSpeak 3 Client\ts3client_win64.exe" [2015-08-04 11715560]
"Steam"="d:\neuer ordner\Steam\steam.exe" [2015-08-19 2899136]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2015-08-07 53735968]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BambooCore"="c:\program files (x86)\Bamboo Dock\BambooCore.exe" [2012-10-16 646744]
"Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2015-04-20 2584240]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2015-06-08 334896]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.11.149\SSScheduler.exe [2015-6-26 330456]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]
@=""
.
R1 {c5e48979-bd7f-4cf7-9b73-2482a67a4f37}w64;{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}w64;c:\windows\system32\drivers\{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}w64.sys;c:\windows\SYSNATIVE\drivers\{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}w64.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
R3 BRDriver64_1_3_3_E02B25FC;BRDriver64_1_3_3_E02B25FC;c:\programdata\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys;c:\programdata\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [x]
R3 BRSptStub;BitRaider Mini-Support Service Stub Loader;c:\programdata\BitRaider\BRSptStub.exe;c:\programdata\BitRaider\BRSptStub.exe [x]
R3 EasyAntiCheat;EasyAntiCheat;c:\windows\system32\EasyAntiCheat.exe;c:\windows\SYSNATIVE\EasyAntiCheat.exe [x]
R3 FlexNet Licensing Service 64;FlexNet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 hidkmdf;KMDF Driver;c:\windows\system32\DRIVERS\hidkmdf.sys;c:\windows\SYSNATIVE\DRIVERS\hidkmdf.sys [x]
R3 HipShieldK;McAfee Inc. HipShieldK;c:\windows\system32\drivers\HipShieldK.sys;c:\windows\SYSNATIVE\drivers\HipShieldK.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
R3 LVUVC64;Logitech HD Webcam C310(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
R3 mfencrk;McAfee Inc. mfencrk;c:\windows\system32\DRIVERS\mfencrk.sys;c:\windows\SYSNATIVE\DRIVERS\mfencrk.sys [x]
R3 mfesapsn;McAfee Process Start Notification Service;c:\program files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys;c:\program files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [x]
R3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\drivers\nvstusb.sys;c:\windows\SYSNATIVE\drivers\nvstusb.sys [x]
R3 Origin Client Service;Origin Client Service;d:\neuer ordner\Origin\OriginClientService.exe;d:\neuer ordner\Origin\OriginClientService.exe [x]
R3 ptun0901;TAP Adapter V9 for Private Tunnel;c:\windows\system32\DRIVERS\ptun0901.sys;c:\windows\SYSNATIVE\DRIVERS\ptun0901.sys [x]
R3 PVUSB;CESG502 64bit USB Driver;c:\windows\system32\DRIVERS\CESG64.sys;c:\windows\SYSNATIVE\DRIVERS\CESG64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SPPD;SPPD;c:\windows\system32\drivers\SPPD.sys;c:\windows\SYSNATIVE\drivers\SPPD.sys [x]
R3 Survarium Update Service;Survarium Update Service;d:\neuer ordner\Survarium\game\binaries\x86\survarium_service.exe Survarium;d:\neuer ordner\Survarium\game\binaries\x86\survarium_service.exe Survarium [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WacHidRouter;Wacom Hid Router;c:\windows\system32\DRIVERS\wachidrouter.sys;c:\windows\SYSNATIVE\DRIVERS\wachidrouter.sys [x]
R3 wacomrouterfilter;Wacom Router Filter Driver;c:\windows\system32\DRIVERS\wacomrouterfilter.sys;c:\windows\SYSNATIVE\DRIVERS\wacomrouterfilter.sys [x]
R3 XSplit_Dummy;XSplit Stream Audio Renderer;c:\windows\system32\drivers\xspltspk.sys;c:\windows\SYSNATIVE\drivers\xspltspk.sys [x]
R4 HomeNetSvc;McAfee Home Network;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [x]
R4 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files (x86)\McAfee\SiteAdvisor\McSACore.exe;c:\program files (x86)\McAfee\SiteAdvisor\McSACore.exe [x]
R4 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.11.149\McCHSvc.exe;c:\program files\McAfee Security Scan\3.11.149\McCHSvc.exe [x]
R4 mccspsvc;McAfee CSP Service;c:\program files\Common Files\McAfee\CSP\1.6.1008.0\McCSPServiceHost.exe;c:\program files\Common Files\McAfee\CSP\1.6.1008.0\McCSPServiceHost.exe [x]
R4 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [x]
R4 mcpltsvc;McAfee Platform Services;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [x]
S0 amd_sata;amd_sata;c:\windows\system32\drivers\amd_sata.sys;c:\windows\SYSNATIVE\drivers\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\drivers\amd_xata.sys;c:\windows\SYSNATIVE\drivers\amd_xata.sys [x]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys;c:\windows\SYSNATIVE\drivers\mfewfpk.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S2 AdobeActiveFileMonitor11.0;Adobe Active File Monitor V11;c:\program files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe;c:\program files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [x]
S2 Apple Mobile Device Service;Apple Mobile Device Service;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [x]
S2 ClickToRunSvc;Microsoft Office-Klick-und-Los-Dienst;c:\program files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe;c:\program files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
S2 IHProtect Service;IHProtect Service;c:\program files (x86)\XTab\ProtectService.exe;c:\program files (x86)\XTab\ProtectService.exe [x]
S2 McAPExe;McAfee AP Service;c:\program files\McAfee\MSC\McAPExe.exe;c:\program files\McAfee\MSC\McAPExe.exe [x]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [x]
S2 McPvDrv;McPvDrv Driver;c:\windows\system32\drivers\McPvDrv.sys;c:\windows\SYSNATIVE\drivers\McPvDrv.sys [x]
S2 mfemms;McAfee Service Controller;c:\program files\Common Files\McAfee\SystemCore\\mfemms.exe;c:\program files\Common Files\McAfee\SystemCore\\mfemms.exe [x]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe;c:\windows\SYSNATIVE\mfevtps.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x]
S2 WindowsMangerProtect;WindowsMangerProtect Service;c:\programdata\WindowsMangerProtect\ProtectWindowsManager.exe;c:\programdata\WindowsMangerProtect\ProtectWindowsManager.exe [x]
S2 WTabletServiceCon;Wacom Consumer Service;c:\program files\Tablet\Pen\WTabletServiceCon.exe;c:\program files\Tablet\Pen\WTabletServiceCon.exe [x]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys;c:\windows\SYSNATIVE\drivers\cfwids.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x]
S3 mfeaack;McAfee Inc. mfeaack;c:\windows\system32\drivers\mfeaack.sys;c:\windows\SYSNATIVE\drivers\mfeaack.sys [x]
S3 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [x]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys;c:\windows\SYSNATIVE\drivers\mfefirek.sys [x]
S3 mfencbdc;McAfee Inc. mfencbdc;c:\windows\system32\DRIVERS\mfencbdc.sys;c:\windows\SYSNATIVE\DRIVERS\mfencbdc.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
S3 VUSB3HUB;VIA USB 3 Root Hub Service;c:\windows\system32\drivers\ViaHub3.sys;c:\windows\SYSNATIVE\drivers\ViaHub3.sys [x]
S3 xhcdrv;VIA USB eXtensible Host Controller Service;c:\windows\system32\drivers\xhcdrv.sys;c:\windows\SYSNATIVE\drivers\xhcdrv.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-03-04 07:47 1150280 ----a-w- c:\program files (x86)\Google\Chrome\Application\33.0.1750.146\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2015-08-30 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-22 06:54]
.
2015-08-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-03-02 10:42]
.
2015-08-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-03-02 10:42]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}]
2013-12-30 20:28 357432 ----a-w- c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1]
@="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}"
[HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}]
2015-04-16 15:42 997536 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2]
@="{853B7E05-C47D-4985-909A-D0DC5C6D7303}"
[HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}]
2015-04-16 15:42 997536 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3]
@="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}"
[HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}]
2015-04-16 15:42 997536 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2015-05-15 07:38 1645256 ----a-w- c:\users\SkorPlays\AppData\Local\Microsoft\OneDrive\17.3.5849.0427\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2015-05-15 07:38 1645256 ----a-w- c:\users\SkorPlays\AppData\Local\Microsoft\OneDrive\17.3.5849.0427\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2015-05-15 07:38 1645256 ----a-w- c:\users\SkorPlays\AppData\Local\Microsoft\OneDrive\17.3.5849.0427\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2015-07-14 10:32 2335960 ----a-w- c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2015-07-14 10:32 2335960 ----a-w- c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2015-07-14 10:32 2335960 ----a-w- c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-01-30 13:05 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-01-30 13:05 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-01-30 13:05 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-01-30 13:05 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-01-30 13:05 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2013-09-13 13653208]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-10-01 825184]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2015-03-30 500936]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2015-08-17 2634872]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2015-08-17 1710568]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2014-10-14 12697368]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2015-08-13 170256]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mDefault_Search_URL = hxxp://search.delta-homes.com/web/?type=ds&ts=1432159444&z=7d9bb244af014a8d825a900g9z4c9oagcw9tczfceb&from=wpm05203&uid=ST1000DM003-1CH162_Z1D7TDEZXXXXZ1D7TDEZ&q={searchTerms}
mDefault_Page_URL = hxxp://www.delta-homes.com/?type=hp&ts=1432159444&z=7d9bb244af014a8d825a900g9z4c9oagcw9tczfceb&from=wpm05203&uid=ST1000DM003-1CH162_Z1D7TDEZXXXXZ1D7TDEZ
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://search.delta-homes.com/web/?type=ds&ts=1432159444&z=7d9bb244af014a8d825a900g9z4c9oagcw9tczfceb&from=wpm05203&uid=ST1000DM003-1CH162_Z1D7TDEZXXXXZ1D7TDEZ&q={searchTerms}
uInternet Settings,ProxyOverride = <-loopback>
uSearchAssistant = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=39fd456c-30f7-a095-92b0-3b0634ced7c4&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=12/01/2014&type=hp1000
IE: Free YouTube Download - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm
IE: {{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{8A7190DC-F334-43F4-B352-D40785F3098D}: NameServer = 8.8.8.8,8.8.4.4
FF - ProfilePath - c:\users\SkorPlays\AppData\Roaming\Mozilla\Firefox\Profiles\ozj3zv8p.default-1432180219096\
FF - prefs.js: browser.startup.homepage - hxxps://www.youtube.com/feed/subscriptions
FF - prefs.js: network.proxy.type - 0
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - c:\program files (x86)\XTab\SupTab.dll
BHO-{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} - c:\program files (x86)\XTab\SupTab.dll
BHO-{93DBF2BB-A2B3-4683-A92E-57E60751F346} - c:\program files (x86)\Conduit\ValueApps\IE\ValueAppsLoader.dll
BHO-{E3F1CA13-EA0E-4617-8D03-3EAA6A94A7E0} - c:\program files (x86)\Flowsurf\FlowSurf.dll
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-Akamai NetSession Interface - c:\users\SkorPlays\AppData\Local\Akamai\netsession_win.exe
Wow6432Node-HKCU-Run-mapdisk - c:\users\SkorPlays\Documents\ArmAWork\mapdisk.bat
Wow6432Node-HKCU-Run-Battle.net - c:\program files (x86)\Battle.net\Battle.net
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
AddRemove-BI's Tools drive - c:\users\SkorPlays\Documents\ArmAWork\UnInstall.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-SearchProtect - c:\program files (x86)\SearchProtect\Main\bin\uninstall.exe
AddRemove-Steam - d:\neuer ordner\Steam\uninstall.exe
AddRemove-SOE-DC Universe Online Live - d:\neuer ordner\Steam\steamapps\common\DC Universe Online\Uninstaller.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-779221656-3612620493-2744903148-1001\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:6d,2e,2b,47,69,bc,1c,35,73,3b,ef,12,17,68,ee,7c,f0,1f,e8,d4,dd,
4b,f9,a9,a5,d8,7d,29,4d,55,56,b8,b4,3c,1d,52,a5,8d,89,23,b9,9c,2e,d3,c2,41,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_18_0_0_232_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_18_0_0_232_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_18_0_0_232_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_18_0_0_232_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_232.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.18"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_232.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_232.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_232.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files\Tablet\Pen\WacomHost.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2015-08-30 15:54:57 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2015-08-30 13:54
.
Vor Suchlauf: 5.174.874.112 Bytes frei
Nach Suchlauf: 5.492.850.688 Bytes frei
.
- - End Of File - - BBA7181245370C8E2F2BD5CEB6E8B4D7
A36C5E4F47E84449FF07ED3517B43A31 |