| 
 Die Log-Datei ist nun da. 
CoboFix.txt:    Code: 
 ..
 ((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
 .
 .
 c:\program files (x86)\Common Files\Acer GameZone online.ico
 c:\programdata\dsgsdgdsgdsgw.pad
 c:\programdata\ism_0_llatsni.pad
 c:\users\dhushan\AppData\Roaming\Chrome.exe
 c:\users\dhushan\AppData\Roaming\dhushanlog.dat
 c:\users\dhushan\AppData\Roaming\Log
 c:\users\dhushan\AppData\Roaming\WinUpd65432.exe
 c:\users\dhushan\Documents\Windows\miner.dll
 c:\users\dhushan\Documents\Windows\phatk.cl
 c:\users\dhushan\Documents\Windows\phatk.ptx
 c:\users\dhushan\Documents\Windows\tmp.txt
 c:\users\dhushan\Documents\Windows\usft_ext.dll
 c:\windows\Install
 c:\windows\Installer\{b522f2dd-e2eb-b5e4-d4b7-50bbc394d728}
 c:\windows\Installer\{b522f2dd-e2eb-b5e4-d4b7-50bbc394d728}\@
 c:\windows\Installer\{b522f2dd-e2eb-b5e4-d4b7-50bbc394d728}\U\00000001.@
 c:\windows\Installer\{b522f2dd-e2eb-b5e4-d4b7-50bbc394d728}\U\00000002.@
 c:\windows\Installer\{b522f2dd-e2eb-b5e4-d4b7-50bbc394d728}\U\80000000.@
 c:\windows\Installer\{b522f2dd-e2eb-b5e4-d4b7-50bbc394d728}\U\80000001.@
 c:\windows\Installer\{b522f2dd-e2eb-b5e4-d4b7-50bbc394d728}\U\800000cb.@
 c:\windows\wininit.ini
 c:\windows\TEMP\logishrd\LVPrcInj01.dll . . . . Nicht in der Lage zu löschen
 c:\windows\TEMP\logishrd\LVPrcInj02.dll . . . . Nicht in der Lage zu löschen
 .
 Infizierte Kopie von c:\windows\system32\services.exe wurde gefunden und desinfiziert
 Kopie von - c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe wurde wiederhergestellt
 .
 .
 (((((((((((((((((((((((   Dateien erstellt von 2013-09-02 bis 2013-10-02  ))))))))))))))))))))))))))))))
 .
 .
 2013-10-02 10:53 . 2013-10-02 10:53        --------        d-----w-        c:\users\Default\AppData\Local\temp
 2013-10-02 10:30 . 2013-10-02 10:30        --------        d-----w-        c:\users\dhushan\AppData\Local\Programs
 2013-10-02 10:28 . 2013-10-02 10:28        --------        d-----w-        c:\users\dhushan\AppData\Local\Macromedia
 2013-10-02 10:23 . 2013-09-15 22:50        9694160        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{D7086FCD-52E0-4BFC-8B63-1E256330804D}\mpengine.dll
 2013-10-02 10:05 . 2013-10-02 10:16        --------        d-----w-        c:\windows\Logs
 2013-10-02 09:47 . 2013-10-02 09:48        --------        d-----w-        C:\AdwCleaner
 2013-10-02 08:13 . 2013-10-02 08:13        --------        d-----w-        C:\FRST
 2013-09-14 15:43 . 2013-09-14 15:43        --------        d-----w-        c:\program files (x86)\Video Download Converter
 .
 .
 .
 ((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
 .
 2013-10-02 10:26 . 2013-02-25 09:20        692616        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
 2013-10-02 10:26 . 2011-08-29 09:32        71048        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
 2013-09-04 11:40 . 2013-05-06 11:22        81112        ----a-w-        c:\windows\system32\drivers\avnetflt.sys
 2013-09-04 11:40 . 2013-03-30 13:17        132088        ----a-w-        c:\windows\system32\drivers\avipbb.sys
 2013-09-04 11:40 . 2013-03-30 13:17        105344        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
 2013-08-07 02:22 . 2010-02-24 20:04        278800        ------w-        c:\windows\system32\MpSigStub.exe
 .
 .
 ((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
 .
 .
 *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
 REGEDIT4
 .
 [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
 @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
 [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
 2009-09-10 13:41        120104        ----a-w-        c:\program files (x86)\EgisTec\MyWinLocker 3\x86\PSDProtect.dll
 .
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-10-12 39408]
 "phonostarTimer"="d:\programme\phonostar-Player\phonostarTimer.exe" [2010-04-01 39936]
 "dradio-RecorderTimer"="c:\program files (x86)\dradio-Recorder\phonostarTimer.exe" [2011-06-20 40960]
 "FileHippo.com"="d:\programme\FileHippo.com\UpdateChecker.exe" [2012-11-23 307712]
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
 "JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
 "BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2009-08-12 261888]
 "Hotkey Utility"="c:\program files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe" [2009-08-18 629280]
 "EgisTecLiveUpdate"="c:\program files (x86)\EgisTec Egis Software Update\EgisUpdate.exe" [2009-08-04 199464]
 "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2013-05-08 41056]
 "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-09-25 98304]
 "ArcadeDeluxeAgent"="c:\program files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2009-09-29 128296]
 "PlayMovie"="c:\program files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe" [2009-09-29 181480]
 "GrooveMonitor"="d:\programme\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
 "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
 "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-08-10 421888]
 "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-09-01 421160]
 "LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-05-08 2780432]
 "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-09-04 347192]
 .
 c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
 Nikon Monitor.lnk - c:\program files (x86)\Common Files\Nikon\Monitor\NkMonitor.exe [2008-6-5 479232]
 SmartCopy.lnk - c:\program files (x86)\Northstar\SmartCopy\SmartCopy.exe [2009-12-17 319488]
 SmartLauncher.lnk - c:\program files (x86)\Northstar\SmartLauncher\SmartLauncher.exe [2009-12-17 339968]
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
 "ConsentPromptBehaviorAdmin"= 5 (0x5)
 "ConsentPromptBehaviorUser"= 3 (0x3)
 "EnableUIADesktopToggle"= 0 (0x0)
 .
 R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
 R3 LVUVC64;Logitech Webcam Pro 9000(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
 R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe;c:\program files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [x]
 R3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x]
 R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
 R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
 S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
 S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x]
 S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x]
 S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x]
 S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
 S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
 S2 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe;c:\program files (x86)\Acer\Registration\GregHSRW.exe [x]
 S2 LVPrcS64;Process Monitor;c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe;c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [x]
 S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [x]
 S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x]
 S3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k62x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1k62x64.sys [x]
 S3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys;c:\windows\SYSNATIVE\DRIVERS\LVPr2M64.sys [x]
 .
 .
 Inhalt des "geplante Tasks" Ordners
 .
 2013-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
 - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-22 22:20]
 .
 2013-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
 - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-22 22:20]
 .
 .
 --------- X64 Entries -----------
 .
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
 @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
 [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
 2009-09-10 13:44        137512        ----a-w-        c:\program files (x86)\EgisTec\MyWinLocker 3\x64\PSDProtect.dll
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]
 "mwlDaemon"="c:\program files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2009-09-10 349480]
 "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-06-16 7883296]
 "Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-06-16 1833504]
 .
 ------- Zusätzlicher Suchlauf -------
 .
 uStart Page = hxxp://www.spiegel.de/
 uLocal Page = c:\windows\system32\blank.htm
 mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_m7810&r=17360210qn06973154u15yh9l3cl3q
 mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_m7810&r=17360210qn06973154u15yh9l3cl3q
 mLocal Page = c:\windows\SysWOW64\blank.htm
 uInternet Settings,ProxyOverride = *.local
 IE: Free YouTube to Mp3 Converter - c:\users\dhushan\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
 IE: Nach Microsoft E&xel exportieren - d:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
 TCP: DhcpNameServer = 192.168.2.1 192.168.2.1
 FF - ProfilePath - c:\users\dhushan\AppData\Roaming\Mozilla\Firefox\Profiles\m9z85dj0.default\
 FF - prefs.js: browser.startup.homepage - hxxp://www.spiegel.de/
 .
 - - - - Entfernte verwaiste Registrierungseinträge - - - -
 .
 URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - c:\program files (x86)\Ask.com\GenericAskToolbar.dll
 Toolbar-Locked - (no file)
 Toolbar-{48586425-6bb7-4f51-8dc6-38c88e3ebb58} - c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
 SafeBoot-mcmscsvc
 SafeBoot-MCODS
 Toolbar-Locked - (no file)
 HKLM-Run-VideoDownloadConverter Home Page Guard 64 bit - c:\progra~2\VIDEOD~2\bar\1.bin\AppIntegrator64.exe
 .
 .
 .
 --------------------- Gesperrte Registrierungsschluessel ---------------------
 .
 [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
 @Denied: (2) (LocalSystem)
 "{98889811-442D-49DD-99D7-DC866BE87DBC}"=hex:51,66,7a,6c,4c,1d,38,12,7f,9b,9b,
 9c,1f,0a,b3,0c,e6,c1,9f,c6,6e,b6,39,a8
 "{D4027C7F-154A-4066-A1AD-4243D8127440}"=hex:51,66,7a,6c,4c,1d,38,12,11,7f,11,
 d0,78,5b,08,05,de,bb,01,03,dd,4c,30,54
 "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,
 27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b
 "{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
 1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
 "{2EECD738-5844-4A99-B4B6-146BF802613B}"=hex:51,66,7a,6c,4c,1d,38,12,56,d4,ff,
 2a,76,16,f7,0f,cb,a0,57,2b,fd,5c,25,2f
 "{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
 76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
 "{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
 94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
 "{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}"=hex:51,66,7a,6c,4c,1d,38,12,d8,cf,e9,
 98,0d,61,19,04,eb,fc,4e,6b,77,8d,c0,d5
 "{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,
 ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3
 "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
 df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
 "{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
 2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
 "{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}"=hex:51,66,7a,6c,4c,1d,38,12,35,fc,e1,
 93,3e,68,a1,09,fc,5c,6e,9a,4b,77,a7,8a
 "{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
 fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
 "{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
 b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
 .
 [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
 @Denied: (2) (LocalSystem)
 "Timestamp"=hex:4b,a4,b7,3f,93,48,cd,01
 .
 [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
 @Denied: (2) (LocalSystem)
 "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
 d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,00,21,4d,18,bf,72,6a,49,9c,2a,19,\
 "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
 d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,00,21,4d,18,bf,72,6a,49,9c,2a,19,\
 .
 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
 @Denied: (A 2) (Everyone)
 @="FlashBroker"
 "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe,-101"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
 "Enabled"=dword:00000001
 .
 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
 @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
 @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
 @Denied: (A 2) (Everyone)
 @="IFlashBroker5"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
 @="{00020424-0000-0000-C000-000000000046}"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
 @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
 "Version"="1.0"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
 @Denied: (A 2) (Everyone)
 @="FlashBroker"
 "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe,-101"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
 "Enabled"=dword:00000001
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
 @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
 @Denied: (A 2) (Everyone)
 @="Shockwave Flash Object"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"
 "ThreadingModel"="Apartment"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
 @="0"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
 @="ShockwaveFlash.ShockwaveFlash.11"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
 @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
 @="1.0"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
 @="ShockwaveFlash.ShockwaveFlash"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
 @Denied: (A 2) (Everyone)
 @="Macromedia Flash Factory Object"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"
 "ThreadingModel"="Apartment"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
 @="FlashFactory.FlashFactory.1"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
 @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
 @="1.0"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
 @="FlashFactory.FlashFactory"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
 @Denied: (A 2) (Everyone)
 @="IFlashBroker5"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
 @="{00020424-0000-0000-C000-000000000046}"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
 @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
 "Version"="1.0"
 .
 [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
 @Denied: (Full) (Everyone)
 .
 ------------------------ Weitere laufende Prozesse ------------------------
 .
 c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
 c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
 c:\program files (x86)\Bonjour\mDNSResponder.exe
 c:\program files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
 c:\program files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
 c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
 .
 **************************************************************************
 .
 Zeit der Fertigstellung: 2013-10-02  13:00:34 - PC wurde neu gestartet
 ComboFix-quarantined-files.txt  2013-10-02 11:00
 .
 Vor Suchlauf: 12 Verzeichnis(se), 24.442.474.496 Bytes frei
 Nach Suchlauf: 17 Verzeichnis(se), 24.316.456.960 Bytes frei
 .
 - - End Of File - - 026838272D740EC93F35FE0D1FB9E757
 A36C5E4F47E84449FF07ED3517B43A31
 |