Was hat combofix denn gegen antispy?^^
[code]
Combofix Logfile: Code:
ComboFix 12-03-06.01 - TimR 06.03.2012 21:40:24.1.4 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.4094.2470 [GMT 1:00]
ausgeführt von:: c:\users\TimR\Desktop\ComboFix.exe
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\xp-AntiSpy
c:\program files (x86)\xp-AntiSpy\Uninstall.exe
c:\program files (x86)\xp-AntiSpy\xp-AntiSpy.chm
c:\program files (x86)\xp-AntiSpy\xp-AntiSpy.exe
c:\program files (x86)\xp-AntiSpy\xp-AntiSpy.url
c:\windows\SysWow64\muzapp.exe
c:\windows\SysWow64\system32
c:\windows\SysWow64\system32\3DAudio.ax
c:\windows\SysWow64\system32\avrt.dll
c:\windows\SysWow64\system32\cis-2.4.dll
c:\windows\SysWow64\system32\issacapi_bs-2.3.dll
c:\windows\SysWow64\system32\issacapi_pe-2.3.dll
c:\windows\SysWow64\system32\issacapi_se-2.3.dll
c:\windows\SysWow64\system32\MACXMLProto.dll
c:\windows\SysWow64\system32\MaDRM.dll
c:\windows\SysWow64\system32\MaJGUILib.dll
c:\windows\SysWow64\system32\MAMACExtract.dll
c:\windows\SysWow64\system32\MASetupCleaner.exe
c:\windows\SysWow64\system32\MaXMLProto.dll
c:\windows\SysWow64\system32\mfplat.dll
c:\windows\SysWow64\system32\MK_Lyric.dll
c:\windows\SysWow64\system32\MSCLib.dll
c:\windows\SysWow64\system32\MSFLib.dll
c:\windows\SysWow64\system32\MSLUR71.dll
c:\windows\SysWow64\system32\msvcp60.dll
c:\windows\SysWow64\system32\MTTELECHIP.dll
c:\windows\SysWow64\system32\MTXSYNCICON.dll
c:\windows\SysWow64\system32\muzaf1.dll
c:\windows\SysWow64\system32\muzapp.dll
c:\windows\SysWow64\system32\muzapp.exe
c:\windows\SysWow64\system32\muzdecode.ax
c:\windows\SysWow64\system32\muzeffect.ax
c:\windows\SysWow64\system32\muzmp4sp.ax
c:\windows\SysWow64\system32\muzmpgsp.ax
c:\windows\SysWow64\system32\muzoggsp.ax
c:\windows\SysWow64\system32\muzwmts.dll
c:\windows\SysWow64\system32\psapi.dll
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-02-06 bis 2012-03-06 ))))))))))))))))))))))))))))))
.
.
2012-03-06 20:23 . 2012-03-06 20:23 -------- d-----w- C:\_OTL
2012-03-02 23:45 . 2012-03-02 23:45 -------- d-----w- c:\programdata\YouTube Downloader
2012-03-02 23:45 . 2012-03-02 23:45 -------- d-----w- c:\program files (x86)\YouTube Downloader
2012-03-01 21:22 . 2012-03-01 21:24 -------- d-----w- c:\users\TimR\AppData\Roaming\Trillian
2012-03-01 16:13 . 2012-03-06 06:40 -------- d-----w- c:\users\TimR\AppData\Roaming\vlc
2012-03-01 16:11 . 2012-03-01 16:12 -------- d-----w- c:\program files (x86)\VLC
2012-03-01 16:01 . 2012-03-01 16:01 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-03-01 16:00 . 2012-03-01 16:00 -------- d-----w- c:\program files (x86)\Java
2012-03-01 15:33 . 2012-03-01 15:33 8756384 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-03-01 15:24 . 2012-03-01 15:24 -------- d-----w- c:\program files (x86)\Common Files\Skype
2012-03-01 15:19 . 2012-03-01 15:19 -------- d-----w- c:\users\TimR\AppData\Local\Secunia PSI
2012-03-01 15:19 . 2012-03-01 15:19 -------- d-----w- c:\program files (x86)\Secunia
2012-03-01 15:15 . 2012-03-01 15:33 417440 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-03-01 15:12 . 2012-03-01 15:12 -------- d-----w- c:\program files (x86)\FileHippo.com
2012-03-01 15:09 . 2012-03-01 15:09 750488 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-03-01 15:09 . 2012-03-01 15:09 660368 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-01 10:07 . 2012-03-01 10:41 -------- d-----w- c:\program files (x86)\SAS
2012-03-01 03:45 . 2012-03-01 03:45 -------- d-----w- c:\users\TimR\AppData\Roaming\SUPERAntiSpyware.com
2012-03-01 03:44 . 2012-03-01 03:44 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2012-03-01 03:44 . 2012-03-01 03:45 -------- d-----w- c:\program files (x86)\SuperAntiSpyware
2012-02-17 19:18 . 2012-02-17 19:18 -------- d-----w- c:\programdata\Logitech
2012-02-17 14:17 . 2012-02-17 14:17 -------- d-----w- c:\users\TimR\AppData\Local\LogiShrd
2012-02-17 14:17 . 2012-02-17 14:17 53248 ----a-r- c:\users\TimR\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2012-02-17 14:17 . 2012-02-17 14:17 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2012-02-17 14:13 . 2012-02-17 14:17 -------- d-----w- c:\users\TimR\AppData\Roaming\Logitech
2012-02-17 14:13 . 2012-02-17 14:13 -------- d-----w- c:\users\TimR\AppData\Roaming\Logishrd
2012-02-17 07:53 . 2012-02-29 17:34 -------- d-----w- c:\programdata\EA Logs
2012-02-17 07:53 . 2012-03-01 09:56 -------- d--h--w- c:\program files (x86)\Common Files\EAInstaller
2012-02-17 07:52 . 2012-02-17 07:52 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2012-02-17 06:55 . 2012-03-01 21:25 -------- d-----w- c:\program files\CCleaner
2012-02-17 06:49 . 2012-02-17 06:49 -------- d-----w- c:\users\TimR\AppData\Roaming\Origin
2012-02-17 06:49 . 2012-02-17 06:49 -------- d-----w- c:\program files (x86)\Origin Games
2012-02-17 06:49 . 2012-02-17 06:49 -------- d-----w- c:\users\TimR\AppData\Local\Origin
2012-02-17 06:49 . 2012-02-17 07:53 -------- d-----w- c:\programdata\Origin
2012-02-16 05:29 . 2011-12-14 16:38 621056 ----a-w- c:\windows\system32\msvcrt.dll
2012-02-16 05:29 . 2011-12-14 16:17 680448 ----a-w- c:\windows\SysWow64\msvcrt.dll
2012-02-16 05:29 . 2012-01-12 20:16 2765824 ----a-w- c:\windows\system32\win32k.sys
2012-02-16 05:29 . 2012-01-03 14:25 404992 ----a-w- c:\windows\system32\drivers\afd.sys
2012-02-16 05:29 . 2011-12-20 10:56 2409784 ----a-w- c:\program files (x86)\Windows Mail\OESpamFilter.dat
2012-02-16 05:29 . 2011-12-20 10:56 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-01 16:00 . 2010-06-27 10:08 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-03-01 15:33 . 2011-05-16 04:43 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-12-16 14:20 . 2011-12-16 14:20 17976 ----a-w- c:\windows\system32\drivers\psi_mf.sys
2011-12-10 14:24 . 2010-05-24 19:42 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-08 04:22 . 2012-02-05 16:45 98616 ----a-w- c:\windows\system32\drivers\ssudbus.sys
2011-12-08 04:22 . 2012-02-05 16:45 203320 ----a-w- c:\windows\system32\drivers\ssudserd.sys
2011-12-08 04:22 . 2012-02-05 16:45 203320 ----a-w- c:\windows\system32\drivers\ssudmdm.sys
2011-12-08 04:22 . 2012-02-05 16:39 1917416 ----a-w- c:\windows\system32\drivers\WdfCoInstaller01005.dll
2011-12-08 04:22 . 2012-02-05 16:39 13800 ----a-w- c:\windows\system32\drivers\ssadwhnt.sys
2011-12-08 04:22 . 2012-02-05 16:39 13800 ----a-w- c:\windows\system32\drivers\ssadwh.sys
2011-12-08 04:22 . 2012-02-05 16:39 36328 ----a-w- c:\windows\system32\drivers\ssadadb.sys
2011-12-08 04:22 . 2012-02-05 16:39 177640 ----a-w- c:\windows\system32\drivers\ssadmdm.sys
2011-12-08 04:22 . 2012-02-05 16:39 16872 ----a-w- c:\windows\system32\drivers\ssadmdfl.sys
2011-12-08 04:22 . 2012-02-05 16:39 157672 ----a-w- c:\windows\system32\drivers\ssadbus.sys
2011-12-08 04:22 . 2012-02-05 16:39 146920 ----a-w- c:\windows\system32\drivers\ssadserd.sys
2011-12-08 04:22 . 2012-02-05 16:39 13288 ----a-w- c:\windows\system32\drivers\ssadcmnt.sys
2011-12-08 04:22 . 2012-02-05 16:39 13288 ----a-w- c:\windows\system32\drivers\ssadcm.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\TimR\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\TimR\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\TimR\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1555968]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2010-11-08 281768]
"CTxfiHlp"="CTXFIHLP.EXE" [2010-07-07 24576]
"StartCCC"="c:\program files (x86)\ATI\11-12\ATI.ACE\Core-Static\CLIStart.exe" [2011-11-09 343168]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"ConsentPromptBehaviorAdmin"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-01 253600]
S2 !SASCORE;SAS Core Service;c:\program files (x86)\SAS\SASCORE64.EXE [2011-08-11 140672]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - ALSYSIO
*Deregistered* - GPU-Z
.
Inhalt des "geplante Tasks" Ordners
.
2012-03-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-01 15:33]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\TimR\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\TimR\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\TimR\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\TimR\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2010-08-03 415816]
"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2010-08-03 2412616]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2010-08-03 4725320]
"EvtMgr6"="c:\program files (x86)\Logitech\SetPoint\SetPointP\SetPoint.exe" [2011-10-07 1744152]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Free YouTube Download - c:\users\TimR\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to MP3 Converter - c:\users\TimR\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 195.50.140.116 195.50.140.180
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-xp-AntiSpy - c:\program files (x86)\xp-AntiSpy\Uninstall.exe
AddRemove-BioLayout Express 3D Web Start Version - c:\windows\system32\javaws.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-4223294054-2252070966-736884885-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{55DA2683-E261-A796-7A1D-2B0E16E7F8CF}*]
"hacdojmcnacndiaf"=hex:6a,61,69,6b,64,6b,63,68,6f,63,66,68,69,6e,69,65,6d,6f,
6f,6f,00,ee
"iaidihpchodlbcjdnf"=hex:6a,61,6a,6a,6f,6a,6e,67,65,64,6a,6d,6f,68,66,6c,65,6a,
65,6d,00,9e
.
[HKEY_USERS\S-1-5-21-4223294054-2252070966-736884885-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:75,b7,0f,31,0b,ba,a3,b8,85,dd,50,1c,a9,8c,38,db,de,48,2a,c9,8d,e7,65,
4d,24,2e,6f,63,8b,e5,3a,67,bc,6d,cf,91,83,ea,66,26,73,f0,16,1e,5f,20,f2,93,\
"??"=hex:65,34,23,f1,ac,3e,ae,99,14,20,f8,2a,53,ca,02,2f
.
[HKEY_USERS\S-1-5-21-4223294054-2252070966-736884885-1000\Software\SecuROM\License information*]
"datasecu"=hex:15,ec,20,27,2c,bf,3f,28,7b,58,9e,a0,74,56,0d,96,be,51,fa,a8,17,
4f,82,4e,e8,9c,33,58,cf,1b,d9,a1,1c,4a,db,1f,e6,b1,23,ce,58,6e,4b,48,4f,d7,\
"rkeysecu"=hex:99,15,3a,ee,9a,b0,d2,2d,05,34,33,85,d4,87,3c,a3
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_160_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_160_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_160.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_160.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_160.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_160.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Zeit der Fertigstellung: 2012-03-06 21:49:22
ComboFix-quarantined-files.txt 2012-03-06 20:49
.
Vor Suchlauf: 12 Verzeichnis(se), 357.204.037.632 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 357.085.655.040 Bytes frei
.
- - End Of File - - F1F64AB4BEC3DB5C49676A273EEB5F39 --- --- --- |