Music.Junky | 05.02.2012 21:19 | Soweit sogut. :)
Combofix Logfile: Code:
ComboFix 12-02-05.02 - Celii 05.02.2012 21:10:05.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4095.2999 [GMT 1:00]
ausgeführt von:: c:\users\Celii\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Common Files\packardbell.ico
c:\users\Celii\AppData\Roaming\.#
c:\windows\IsUn0407.exe
D:\install.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-01-05 bis 2012-02-05 ))))))))))))))))))))))))))))))
.
.
2012-02-03 16:09 . 2012-01-06 05:15 8602168 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2973EC5F-3963-4682-879B-CE65817CA918}\mpengine.dll
2012-02-02 18:07 . 2012-02-02 18:07 -------- d-----w- C:\_OTL
2012-01-31 17:53 . 2012-01-31 17:53 -------- d-----w- c:\program files (x86)\ESET
2012-01-22 22:56 . 2012-01-22 22:56 -------- d-----w- c:\users\Celii\AppData\Local\adaware
2012-01-22 22:56 . 2012-02-02 18:09 -------- d-----w- c:\programdata\Ad-Aware Browsing Protection
2012-01-22 22:56 . 2012-01-22 22:56 -------- d-----w- c:\program files (x86)\Toolbar Cleaner
2012-01-22 22:56 . 2012-01-22 22:56 -------- d-----w- c:\program files (x86)\adawaretb
2012-01-22 22:56 . 2011-12-23 06:12 69376 ----a-w- c:\windows\system32\drivers\Lbd.sys
2012-01-22 22:56 . 2012-01-22 22:56 -------- d-----w- c:\program files (x86)\Lavasoft
2012-01-22 21:52 . 2012-01-22 21:52 -------- d-----w- c:\program files (x86)\7-Zip
2012-01-22 21:23 . 2012-01-22 21:23 -------- d-----w- c:\users\Celii\AppData\Roaming\Malwarebytes
2012-01-22 21:23 . 2012-01-22 21:23 -------- d-----w- c:\programdata\Malwarebytes
2012-01-22 21:23 . 2012-01-31 16:21 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-01-22 21:23 . 2011-12-10 14:24 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-22 21:01 . 2012-01-22 21:01 388096 begin_of_the_skype_highlighting**************01 388096******end_of_the_skype_highlighting ----a-r- c:\users\Celii\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-01-22 21:01 . 2012-01-22 21:01 -------- d-----w- c:\program files (x86)\Trend Micro
2012-01-18 14:32 . 2012-01-18 14:32 -------- d-----w- c:\program files (x86)\Jasc Software Inc
2012-01-18 14:22 . 2012-01-18 14:22 -------- d-----w- c:\users\Celii\AppData\Roaming\Jasc
2012-01-11 16:15 . 2012-01-11 16:15 719832 ----a-w- c:\program files (x86)\Mozilla Firefox\mozcpp19.dll
2012-01-11 16:15 . 2012-01-11 16:15 16856 ----a-w- c:\program files (x86)\Mozilla Firefox\plugin-container.exe
2012-01-10 22:27 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-10 22:27 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-10 22:27 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-10 22:27 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-10 22:27 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-10 22:27 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-10 22:27 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-10 22:27 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-26 23:52 . 2010-05-01 11:43 279656 ------w- c:\windows\system32\MpSigStub.exe
2011-12-25 19:25 . 2011-12-25 19:25 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-24 04:52 . 2011-12-24 17:50 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-11-09 13:54 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-11-09 13:54 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-11-09 12:24 . 2011-11-09 12:24 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-11-09 12:24 . 2011-11-09 12:24 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-11-09 12:24 . 2011-11-09 12:24 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-11-09 12:24 . 2011-11-09 12:24 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-11-09 12:24 . 2011-11-09 12:24 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-11-09 12:24 . 2011-11-09 12:24 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-11-09 12:24 . 2011-11-09 12:24 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-11-09 12:24 . 2011-11-09 12:24 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-11-09 12:24 . 2011-11-09 12:24 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-11-09 12:24 . 2011-11-09 12:24 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-11-09 12:24 . 2011-11-09 12:24 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-11-09 12:24 . 2011-11-09 12:24 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-11-09 12:24 . 2011-11-09 12:24 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-11-09 12:24 . 2011-11-09 12:24 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-11-09 12:24 . 2011-11-09 12:24 222208 ----a-w- c:\windows\system32\msls31.dll
2011-11-09 12:24 . 2011-11-09 12:24 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-11-09 12:24 . 2011-11-09 12:24 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-11-09 12:24 . 2011-11-09 12:24 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-11-09 12:24 . 2011-11-09 12:24 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-11-09 12:24 . 2011-11-09 12:24 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-11-09 12:24 . 2011-11-09 12:24 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-11-09 12:24 . 2011-11-09 12:24 12288 ----a-w- c:\windows\system32\mshta.exe
2011-11-09 12:24 . 2011-11-09 12:24 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-11-09 12:24 . 2011-11-09 12:24 114176 ----a-w- c:\windows\system32\admparse.dll
2011-11-09 12:24 . 2011-11-09 12:24 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-11-09 12:24 . 2011-11-09 12:24 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-11-09 12:24 . 2011-11-09 12:24 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-11-09 12:24 . 2011-11-09 12:24 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-11-09 12:24 . 2011-11-09 12:24 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-11-09 12:24 . 2011-11-09 12:24 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-11-09 12:24 . 2011-11-09 12:24 448512 ----a-w- c:\windows\system32\html.iec
2011-11-09 12:24 . 2011-11-09 12:24 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-09 12:24 . 2011-11-09 12:24 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-11-09 12:24 . 2011-11-09 12:24 160256 ----a-w- c:\windows\system32\wextract.exe
2011-11-08 11:15 . 2010-05-01 11:18 88288 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-11-08 11:15 . 2010-05-01 11:18 123784 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-11-08 11:14 . 2010-11-18 19:15 55384 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
2011-12-21 15:44 87440 ----a-w- c:\program files (x86)\adawaretb\adawareDx.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{6c97a91e-4524-4019-86af-2aa2d567bf5c}"= "c:\program files (x86)\adawaretb\adawareDx.dll" [2011-12-21 87440]
.
[HKEY_CLASSES_ROOT\clsid\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-25 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"CherryKeyMan"="c:\program files (x86)\Cherry\KeyMan\KeyMan.exe" [2007-11-28 237620]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2010-11-05 281768]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"setc"="c:\program files (x86)\MySecurityCenter\Programs\setc.exe" [2010-10-20 389488]
"regist"="c:\program files (x86)\MySecurityCenter\Programs\RegistrationPopup.exe" [2010-10-20 385392]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2011-11-14 197288]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"adaware"="reg.exe delete HKCU\Software\AppDataLow\Software\adaware" [X]
"adaware_XP"="reg.exe delete HKCU\Software\adaware" [X]
.
c:\users\Celii\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
OpenOffice.org 3.2.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2009-12-15 384000]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files (x86)\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 135664]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 135664]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x]
S0 nvamacpi;NVIDIA Away Mode System;c:\windows\system32\DRIVERS\NVAMACPI.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-12-08 169312]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-11-08 136360]
S2 Greg_Service;GRegService;c:\program files (x86)\Packard Bell\Registration\GregHSRW.exe [2009-06-04 1150496]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2012-01-22 2152152]
S2 MySecurityCenter License Service;MySecurityCenter License Service;c:\program files (x86)\MySecurityCenter\Programs\service.exe [2010-10-20 78192]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-21 2214504]
S2 Updater Service;Updater Service;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe [2009-07-04 240160]
S3 Ch64PS2;Cherry PS/2 Tastatur Treiber (CDI);c:\windows\system32\DRIVERS\Ch64PS2.sys [x]
S3 CH64PS2M;Cherry PS/2 Maus Treiber (CDI);c:\windows\system32\DRIVERS\CH64PS2M.sys [x]
S3 Cherry Device Interface;Cherry Device Interface;c:\program files (x86)\Cherry\CDI\cdi.exe [2007-12-04 585774]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [2012-01-22 17152]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 29071298
*NewlyCreated* - LAVASOFT_KERNEXPLORER
*Deregistered* - 29071298
.
Inhalt des "geplante Tasks" Ordners
.
2012-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 01:26]
.
2012-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 01:26]
.
2012-02-05 c:\windows\Tasks\MYPCTuneUp64-Celii-Notification.job
- c:\program files\MYPCTuneUp\MYPCTuneUp\Sync.exe [2011-10-06 10:59]
.
2012-02-02 c:\windows\Tasks\MYPCTuneUp64-Celii-Startup.job
- c:\program files\MYPCTuneUp\MYPCTuneUp\MYPCTuneUp64.exe [2011-10-06 10:59]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-20 7981088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&m=imedia_m3710&r=173605108106p03d5v1k5y47m28206
mStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&m=imedia_m3710&r=173605108106p03d5v1k5y47m28206
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
LSP: c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\Celii\AppData\Roaming\Mozilla\Firefox\Profiles\u9qtrp20.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension for Firefox: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: Ad-Aware Security Toolbar: {87934c42-161d-45bc-8cef-ef18abe2a30c} - %profile%\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,
27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,
ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3
"{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93,
aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-02-05 21:16:30
ComboFix-quarantined-files.txt 2012-02-05 20:16
.
Vor Suchlauf: 9 Verzeichnis(se), 311.845.433.344 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 311.707.131.904 Bytes frei
.
- - End Of File - - 69CCA346A15A942EA1B3BDA83B99EF57 --- --- --- |