|   | dennisfcb | 02.02.2013 00:52 |  
 Fixlog  Code: 
 Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-02-2013 03Ran by SYSTEM at 2013-02-01 23:47:39 Run:1
 Running from I:\
 
 ==============================================
 
 HKEY_USERS\Dennis\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell Value deleted successfully.
 C:\Users\Dennis\AppData\Roaming\skype.dat moved successfully.
 C:\Users\Dennis\AppData\Roaming\skype.ini moved successfully.
 
 ==== End of Fixlog ====
 
Combofix-Log    Code: 
 ComboFix 13-02-01.04 - Dennis 02.02.2013   0:00.1.2 - x64Microsoft Windows 7 Ultimate   6.1.7601.1.1252.49.1031.18.4094.2800 [GMT 1:00]
 ausgeführt von:: c:\users\Dennis\Desktop\ComboFix.exe
 AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
 SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
 SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 .
 .
 ((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
 .
 .
 c:\users\Dennis\4.0
 D:\Autorun.inf
 .
 .
 (((((((((((((((((((((((   Dateien erstellt von 2013-01-01 bis 2013-02-01  ))))))))))))))))))))))))))))))
 .
 .
 2013-02-01 12:28 . 2013-02-01 12:28        --------        d-----w-        C:\FRST
 2013-01-30 15:22 . 2013-01-30 15:22        --------        d-----w-        c:\programdata\Kaspersky Lab
 2013-01-30 15:22 . 2013-01-30 15:22        --------        d-----w-        c:\program files (x86)\Kaspersky Lab
 2013-01-29 16:41 . 2013-01-29 16:41        --------        d-----w-        c:\users\Dennis\.tfo4
 2013-01-29 16:23 . 2013-01-08 05:32        9161176        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{7E82550F-24B9-4E20-B0D6-EBF10F9FA257}\mpengine.dll
 2013-01-26 17:50 . 2013-01-26 17:50        --------        d-----w-        c:\program files (x86)\Common Files\Skype
 2013-01-26 17:50 . 2013-01-26 17:50        --------        d-----r-        c:\program files (x86)\Skype
 2013-01-25 05:23 . 2013-01-25 05:23        42880        ----a-w-        c:\windows\SysWow64\xfcodec.dll
 2013-01-25 05:23 . 2013-01-25 05:23        28544        ----a-w-        c:\windows\system32\xfcodec64.dll
 2013-01-19 15:38 . 2013-01-19 15:39        --------        d-----w-        c:\users\Dennis\AppData\Local\Mozilla Firefox
 2013-01-15 16:42 . 2013-01-04 15:53        9060864        ----a-w-        c:\windows\system32\mshtml.dll
 2013-01-11 15:54 . 2010-06-02 03:55        74072        ----a-w-        c:\windows\SysWow64\XAPOFX1_5.dll
 2013-01-11 15:54 . 2010-06-02 03:55        527192        ----a-w-        c:\windows\SysWow64\XAudio2_7.dll
 2013-01-11 15:54 . 2010-06-02 03:55        239960        ----a-w-        c:\windows\SysWow64\xactengine3_7.dll
 2013-01-11 15:54 . 2010-05-26 10:41        2106216        ----a-w-        c:\windows\SysWow64\D3DCompiler_43.dll
 2013-01-11 15:54 . 2010-05-26 10:41        1868128        ----a-w-        c:\windows\SysWow64\d3dcsx_43.dll
 2013-01-11 15:54 . 2010-05-26 10:41        470880        ----a-w-        c:\windows\SysWow64\d3dx10_43.dll
 2013-01-11 15:54 . 2010-05-26 10:41        248672        ----a-w-        c:\windows\SysWow64\d3dx11_43.dll
 2013-01-11 15:54 . 2010-05-26 10:41        1998168        ----a-w-        c:\windows\SysWow64\D3DX9_43.dll
 2013-01-11 15:42 . 2013-01-11 15:42        --------        d-----w-        c:\program files (x86)\hulumuluch
 2013-01-10 16:26 . 2012-12-07 11:20        23552        ----a-w-        c:\windows\system32\oflc.rs
 .
 .
 .
 ((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
 .
 2013-01-27 14:06 . 2010-10-23 12:29        281768        ----a-w-        c:\windows\SysWow64\PnkBstrB.xtr
 2013-01-27 14:06 . 2010-10-23 12:29        281768        ----a-w-        c:\windows\SysWow64\PnkBstrB.exe
 2013-01-27 14:05 . 2010-10-23 12:29        269288        ----a-w-        c:\windows\SysWow64\PnkBstrB.ex0
 2013-01-10 21:09 . 2010-11-17 10:27        67599240        ----a-w-        c:\windows\system32\MRT.exe
 2013-01-10 16:47 . 2012-04-11 13:34        697864        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
 2013-01-10 16:47 . 2011-05-18 20:43        74248        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
 2012-12-16 17:11 . 2012-12-22 00:29        46080        ----a-w-        c:\windows\system32\atmlib.dll
 2012-12-16 14:45 . 2012-12-22 00:29        367616        ----a-w-        c:\windows\system32\atmfd.dll
 2012-12-16 14:13 . 2012-12-22 00:29        295424        ----a-w-        c:\windows\SysWow64\atmfd.dll
 2012-12-16 14:13 . 2012-12-22 00:29        34304        ----a-w-        c:\windows\SysWow64\atmlib.dll
 2012-11-30 04:45 . 2013-01-10 16:26        44032        ----a-w-        c:\windows\apppatch\acwow64.dll
 2012-11-12 12:28 . 2012-12-12 16:55        1638912        ----a-w-        c:\windows\system32\mshtml.tlb
 2012-11-12 11:52 . 2012-12-12 16:55        1638912        ----a-w-        c:\windows\SysWow64\mshtml.tlb
 2012-11-09 05:45 . 2012-12-12 16:56        2048        ----a-w-        c:\windows\system32\tzres.dll
 2012-11-09 04:42 . 2012-12-12 16:56        2048        ----a-w-        c:\windows\SysWow64\tzres.dll
 .
 .
 ((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
 .
 .
 *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
 REGEDIT4
 .
 [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1EldosIconOverlay]
 @="{646F8197-A414-4F44-8736-5AC840D93AA1}"
 [HKEY_CLASSES_ROOT\CLSID\{646F8197-A414-4F44-8736-5AC840D93AA1}]
 2012-04-09 14:27        158224        ----a-w-        c:\windows\SysWOW64\CbFsMntNtf3.dll
 .
 [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EldosIconOverlay]
 @="{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}"
 [HKEY_CLASSES_ROOT\CLSID\{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}]
 2012-04-09 14:27        158224        ----a-w-        c:\windows\SysWOW64\CbFsMntNtf3.dll
 .
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "KSS"="c:\program files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe" [2012-04-25 202296]
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
 "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-09-30 98304]
 "ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]
 "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-08-08 348664]
 "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
 "AVMWlanClient"="c:\program files (x86)\avmwlanstick\wlangui.exe" [2010-10-22 2105344]
 "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-18 946352]
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
 "ConsentPromptBehaviorAdmin"= 5 (0x5)
 "ConsentPromptBehaviorUser"= 3 (0x3)
 "EnableUIADesktopToggle"= 0 (0x0)
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
 "DisableMonitoring"=dword:00000001
 .
 R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
 R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-01-08 161536]
 R3 ALSysIO;ALSysIO;c:\users\Dennis\AppData\Local\Temp\ALSysIO64.sys [x]
 R3 avmeject;AVM Eject;c:\windows\system32\drivers\avmeject.sys [2010-10-22 14120]
 R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [2011-04-01 341856]
 R3 LVUVC64;Logitech HD Webcam C270(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [2011-04-01 4184672]
 R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys [2010-12-02 171008]
 R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992]
 R3 SilvrLnk;SilverLink (USB GraphLink) Cable;c:\windows\system32\DRIVERS\silvrlnk.sys [2009-09-10 129536]
 R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
 R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
 R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
 R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-02-18 51712]
 R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
 S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-22 834544]
 S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-10-19 27760]
 S1 cbfs3;cbfs3;c:\windows\system32\drivers\cbfs3.sys [2012-04-09 352144]
 S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-09-29 203264]
 S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-09 86224]
 S2 AntiVirWebService;Avira Browser Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [2012-05-09 465360]
 S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-02-28 2343816]
 S2 KSS;Kaspersky Security Scan Service;c:\program files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [2012-04-25 202296]
 S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2011-04-01 428640]
 S2 wDokan;wDokan;c:\windows\system32\drivers\wdokan.sys [2010-08-11 86392]
 S2 wDokanMounter;wDokanMounter;c:\program files (x86)\Wuala Dokan\mounter.exe [2010-08-11 11776]
 S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2010-08-16 116240]
 S3 FWLANUSB;AVM FRITZ!WLAN;c:\windows\system32\DRIVERS\fwlanusb.sys [2009-03-20 460800]
 S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-06-23 344680]
 .
 .
 Inhalt des "geplante Tasks" Ordners
 .
 2013-01-30 c:\windows\Tasks\Adobe Flash Player Updater.job
 - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-11 16:47]
 .
 2013-01-30 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1027476448-1133028917-2562891829-1001Core.job
 - c:\users\Dennis\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-09-05 16:52]
 .
 2013-01-30 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1027476448-1133028917-2562891829-1001UA.job
 - c:\users\Dennis\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-09-05 16:52]
 .
 .
 --------- X64 Entries -----------
 .
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\0WualaOverlayIcon1]
 @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
 [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
 2012-05-02 12:10        1721856        ----a-w-        c:\program files (x86)\Wuala OverlayIcons\OverlayIcon.dll
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\0WualaOverlayIcon2]
 @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
 [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
 2012-05-02 12:10        1721856        ----a-w-        c:\program files (x86)\Wuala OverlayIcons\OverlayIcon.dll
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\0WualaOverlayIcon3]
 @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
 [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
 2012-05-02 12:10        1721856        ----a-w-        c:\program files (x86)\Wuala OverlayIcons\OverlayIcon.dll
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\0WualaOverlayIcon4]
 @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
 [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
 2012-05-02 12:10        1721856        ----a-w-        c:\program files (x86)\Wuala OverlayIcons\OverlayIcon.dll
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1EldosIconOverlay]
 @="{646F8197-A414-4F44-8736-5AC840D93AA1}"
 [HKEY_CLASSES_ROOT\CLSID\{646F8197-A414-4F44-8736-5AC840D93AA1}]
 2012-04-09 14:27        190480        ----a-w-        c:\windows\System32\CbFsMntNtf3.dll
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EldosIconOverlay]
 @="{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}"
 [HKEY_CLASSES_ROOT\CLSID\{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}]
 2012-04-09 14:27        190480        ----a-w-        c:\windows\System32\CbFsMntNtf3.dll
 .
 ------- Zusätzlicher Suchlauf -------
 .
 uLocal Page = c:\windows\system32\blank.htm
 uStart Page = hxxp://de.ask.com/?l=dis&o=APN10023&gct=hp
 mLocal Page = c:\windows\SysWOW64\blank.htm
 IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
 IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
 LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll
 Trusted Zone: samsungsetup.com\www
 TCP: DhcpNameServer = 192.168.1.1
 DPF: {271A3CF5-5A54-447B-A08F-BE805F0DA60B} - hxxps://www.olb.de/olb_fb3_1857/plugin/AXFOAM.CAB
 DPF: {2AD0C02D-3A2E-4192-BD8A-19C89BD0DFF1} - file:///C:/ProgramData/Skype/Plugins/Plugins/263AF18BA8E6473194D1E386FDADB7DE/4USclub.cab
 FF - ProfilePath - c:\users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\j5f1fzae.default\
 FF - prefs.js: browser.search.selectedEngine - Google
 FF - prefs.js: browser.startup.homepage - hxxp://www.spiegel.de/
 FF - prefs.js: network.proxy.type - 4
 .
 - - - - Entfernte verwaiste Registrierungseinträge - - - -
 .
 BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files (x86)\Ask.com\GenericAskToolbar.dll
 Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files (x86)\Ask.com\GenericAskToolbar.dll
 Wow6432Node-HKLM-Run-<NO NAME> - (no file)
 AddRemove-Call of Duty Black Ops GERMAN Uncut 1.00 - i:\spiele\Call of Duty Black Ops\Call of Duty Black Ops GERMAN Uncut\Uninstall.exe
 AddRemove-Company of Heroes - j:\spiele\Company of Heroes\Uninstall_German.exe
 AddRemove-PokerStars.net - i:\spiele\Pokerstars\PokerStarsUninstall.exe
 AddRemove-{3854605E-9D82-446C-8FFA-79FF0471C8C3} - i:\spiele\Need for Speed Underground 2\Nfs 2\Uninstall.exe
 AddRemove-{A716BE0A-331D-4603-9E70-319153D1943F}_is1 - i:\spiele\Mafia 2\MAFIA 2\unins000.exe
 .
 .
 .
 --------------------- Gesperrte Registrierungsschluessel ---------------------
 .
 [HKEY_USERS\S-1-5-21-1027476448-1133028917-2562891829-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C78157EA-CF51-C61D-AD7E-F85A1A49BA62}*]
 "haiolgkfhobgjkpo"=hex:69,61,6d,6c,63,6a,6d,66,64,6e,6a,66,70,69,66,69,6f,62,
 00,00
 "iacpbgapnckmicjinn"=hex:69,61,66,6d,70,69,6c,6b,64,6b,64,6f,6f,69,62,6d,65,6a,
 00,00
 .
 [HKEY_USERS\S-1-5-21-1027476448-1133028917-2562891829-1001\Software\SecuROM\License information*]
 "datasecu"=hex:29,de,5c,eb,9e,c8,8b,83,f1,65,d4,6a,fc,47,5c,94,e0,94,2d,0d,3d,
 be,a9,bb,3a,2a,65,c5,50,7a,d3,45,7b,70,b1,ad,2c,6a,f2,f0,9e,4b,c6,e6,28,81,\
 "rkeysecu"=hex:d4,2c,e8,1d,32,03,d5,43,3e,ac,b4,54,36,7c,55,78
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
 @Denied: (A 2) (Everyone)
 @="FlashBroker"
 "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
 "Enabled"=dword:00000001
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
 @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
 @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
 @Denied: (A 2) (Everyone)
 @="IFlashBroker5"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
 @="{00020424-0000-0000-C000-000000000046}"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
 @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
 "Version"="1.0"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
 @Denied: (A 2) (Everyone)
 @="FlashBroker"
 "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
 "Enabled"=dword:00000001
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
 @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
 @Denied: (A 2) (Everyone)
 @="Shockwave Flash Object"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"
 "ThreadingModel"="Apartment"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
 @="0"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
 @="ShockwaveFlash.ShockwaveFlash.11"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
 @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
 @="1.0"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
 @="ShockwaveFlash.ShockwaveFlash"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
 @Denied: (A 2) (Everyone)
 @="Macromedia Flash Factory Object"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"
 "ThreadingModel"="Apartment"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
 @="FlashFactory.FlashFactory.1"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
 @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
 @="1.0"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
 @="FlashFactory.FlashFactory"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
 @Denied: (A 2) (Everyone)
 @="IFlashBroker5"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
 @="{00020424-0000-0000-C000-000000000046}"
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
 @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
 "Version"="1.0"
 .
 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
 @Denied: (A) (Users)
 @Denied: (A) (Everyone)
 @Allowed: (B 1 2 3 4 5) (S-1-5-20)
 "BlindDial"=dword:00000000
 .
 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
 @Denied: (Full) (Everyone)
 .
 ------------------------ Weitere laufende Prozesse ------------------------
 .
 c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
 c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
 c:\program files (x86)\avmwlanstick\WlanNetService.exe
 c:\program files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
 c:\windows\SysWOW64\PnkBstrA.exe
 .
 **************************************************************************
 .
 Zeit der Fertigstellung: 2013-02-02  00:45:34 - PC wurde neu gestartet
 ComboFix-quarantined-files.txt  2013-02-01 23:45
 .
 Vor Suchlauf: 12 Verzeichnis(se), 349.654.802.432 Bytes frei
 Nach Suchlauf: 18 Verzeichnis(se), 349.555.478.528 Bytes frei
 .
 - - End Of File - - 13D21BD311ADC4C065CD1B87E7CF9155
 |