| Carsten1502 |  11.10.2013 10:10 |        Hi, hier das ComboFix Logfile:    Code:  
 ComboFix 13-10-09.01 - Administrator 11.10.2013  10:43:41.1.1 - x86 
Microsoft Windows 8 Pro  6.2.9200.0.1252.49.1031.18.1535.549 [GMT 2:00] 
ausgeführt von:: c:\users\Administrator\Desktop\ComboFix.exe 
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} 
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} 
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} 
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} 
. 
. 
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   )))))))))))))))))))))))))))))))))))))))))))))))) 
. 
. 
c:\windows\IsUn0407.exe 
. 
. 
(((((((((((((((((((((((   Dateien erstellt von 2013-09-11 bis 2013-10-11  )))))))))))))))))))))))))))))) 
. 
. 
2013-10-11 09:02 . 2013-10-11 09:02        --------        d-----w-        c:\users\UpdatusUser\AppData\Local\temp 
2013-10-10 16:54 . 2013-10-10 16:54        --------        d-----w-        C:\FRST 
2013-10-10 16:18 . 2013-10-11 07:07        --------        d-----w-        c:\users\Administrator\AppData\Local\FreePDF_XP 
2013-10-10 15:41 . 2013-10-10 17:58        --------        d-----w-        c:\users\Administrator\AppData\Local\CrashDumps 
2013-10-10 15:41 . 2013-10-10 15:41        --------        d-----w-        c:\users\Administrator\AppData\Roaming\OpenOffice 
2013-10-09 17:19 . 2013-10-09 17:19        --------        d-----w-        c:\users\Administrator\AppData\Local\Programs 
2013-10-09 16:10 . 2013-07-09 02:50        85760        ----a-w-        c:\windows\system32\drivers\USBAUDIO.sys 
2013-10-09 16:09 . 2013-07-01 22:15        36864        ----a-w-        c:\windows\system32\drivers\usbscan.sys 
2013-10-09 16:09 . 2013-07-01 22:15        18944        ----a-w-        c:\windows\system32\drivers\usbprint.sys 
2013-10-09 16:09 . 2013-06-29 02:32        26496        ----a-w-        c:\windows\system32\drivers\hidparse.sys 
2013-10-09 16:09 . 2013-06-29 02:31        61440        ----a-w-        c:\windows\system32\drivers\hidclass.sys 
2013-10-09 16:09 . 2013-07-19 22:13        102608        ----a-w-        c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll 
2013-10-05 11:50 . 2013-10-05 11:50        --------        d-----w-        c:\users\Carsten\AppData\Roaming\AVG 
2013-10-05 11:42 . 2013-10-05 11:42        --------        d-----w-        c:\users\Administrator\AppData\Roaming\AVG 
2013-10-05 11:41 . 2013-10-05 11:43        --------        d-----w-        c:\programdata\AVG 
2013-10-05 11:41 . 2013-10-05 11:41        --------        d-sh--w-        c:\programdata\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F} 
2013-10-05 09:22 . 2013-10-05 09:22        --------        d-----w-        c:\windows\ServiceProfiles\LocalService\winhttp 
2013-10-03 21:01 . 2013-10-03 21:01        --------        d-----w-        c:\users\Carsten\AppData\Local\Clipboarder 
2013-10-03 20:59 . 2013-10-03 21:02        --------        d-----w-        c:\users\Carsten\AppData\Local\Sidebar7 
2013-10-03 20:57 . 2012-05-19 04:43        1144832        ----a-w-        c:\program files\Windows Sidebar\sidebar.exe 
2013-10-03 20:57 . 2012-05-19 04:41        77824        ----a-w-        c:\program files\Windows Sidebar\sbdrop.dll 
2013-10-03 20:57 . 2006-11-02 15:03        63488        ----a-w-        c:\program files\Windows Sidebar\wlsrvc.dll 
2013-10-03 20:57 . 2013-05-04 10:18        46080        ----a-w-        c:\program files\Windows Sidebar\dwmapi.dll 
2013-10-03 07:54 . 2013-10-03 07:54        --------        d-----w-        c:\programdata\Malwarebytes 
2013-10-03 07:53 . 2013-10-03 09:06        --------        d-----w-        c:\programdata\Malwarebytes' Anti-Malware (portable) 
2013-10-03 07:43 . 2013-10-10 16:04        --------        d-----w-        C:\AdwCleaner 
2013-09-25 07:30 . 2013-09-25 07:30        --------        d-----w-        c:\users\Administrator\AppData\Roaming\FreeFLVConverter 
2013-09-25 06:56 . 2013-09-25 21:27        --------        d-----w-        c:\users\Carsten\AppData\Local\CrashDumps 
2013-09-25 06:55 . 2013-09-25 06:55        --------        d-----w-        c:\users\Carsten\AppData\Roaming\DivX 
2013-09-24 19:32 . 2013-09-25 08:26        --------        d-----w-        c:\program files\Common Files\DivX Shared 
2013-09-21 10:24 . 2013-09-21 10:25        --------        d-----w-        c:\program files\Google 
2013-09-19 08:10 . 2013-09-18 23:26        78296        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl 
2013-09-19 08:10 . 2013-09-18 23:26        694232        ----a-w-        c:\windows\system32\FlashPlayerApp.exe 
2013-09-19 07:37 . 2013-08-03 04:17        3390464        ----a-w-        c:\windows\system32\win32k.sys 
2013-09-19 07:37 . 2013-08-21 02:05        2876928        ----a-w-        c:\windows\system32\jscript9.dll 
2013-09-19 07:37 . 2013-08-21 02:36        770648        ----a-w-        c:\program files\Internet Explorer\iexplore.exe 
2013-09-19 07:37 . 2013-08-21 02:06        1767936        ----a-w-        c:\windows\system32\wininet.dll 
2013-09-19 07:37 . 2013-08-21 02:06        817664        ----a-w-        c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll 
2013-09-19 07:37 . 2013-08-21 02:06        661504        ----a-w-        c:\windows\system32\uxtheme.dll 
2013-09-19 07:37 . 2013-08-21 02:05        109056        ----a-w-        c:\windows\system32\iesysprep.dll 
2013-09-19 07:36 . 2013-08-21 02:06        44032        ----a-w-        c:\windows\system32\UXInit.dll 
2013-09-19 07:36 . 2013-08-21 02:05        108032        ----a-w-        c:\program files\Internet Explorer\jsdebuggeride.dll 
2013-09-19 07:36 . 2013-08-21 02:05        61440        ----a-w-        c:\windows\system32\iesetup.dll 
2013-09-19 07:36 . 2013-08-21 02:05        257536        ----a-w-        c:\program files\Internet Explorer\ieproxy.dll 
2013-09-19 07:36 . 2013-08-21 02:05        236032        ----a-w-        c:\program files\Internet Explorer\IEShims.dll 
2013-09-19 07:36 . 2013-08-21 01:43        2706432        ----a-w-        c:\windows\system32\mshtml.tlb 
. 
. 
. 
((((((((((((((((((((((((((((((((((((   Find3M Bericht   )))))))))))))))))))))))))))))))))))))))))))))))))))))) 
. 
2013-09-19 08:16 . 2013-05-06 11:41        65632        ----a-w-        c:\windows\system32\drivers\avnetflt.sys 
2013-09-19 08:16 . 2013-03-17 09:29        88840        ----a-w-        c:\windows\system32\drivers\avgntflt.sys 
2013-09-19 08:16 . 2013-03-17 09:29        136672        ----a-w-        c:\windows\system32\drivers\avipbb.sys 
2013-07-18 10:14 . 2013-07-18 10:14        74703        ----a-w-        c:\windows\system32\mfc45.dat 
. 
. 
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   )))))))))))))))))))))))))))))))))))))))) 
. 
. 
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.  
REGEDIT4 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShareOverlay] 
@="{594D4122-1F87-41E2-96C7-825FB4796516}" 
[HKEY_CLASSES_ROOT\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516}] 
2013-06-29 08:49        594432        ----a-w-        c:\program files\Classic Shell\ClassicExplorer32.dll 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 
"SoundMan"="SOUNDMAN.EXE" [2009-04-14 604704] 
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-09-19 347192] 
"FreePDF Assistant"="c:\program files\FreePDF_XP\fpassist.exe" [2013-03-14 373760] 
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2012-09-25 1163264] 
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688] 
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456] 
"SAOB Monitor"="c:\program files\Acronis\TrueImageHome\OnlineBackupStandalone\TrueImageMonitor.exe" [2011-09-22 2571032] 
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2011-09-22 5587832] 
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2011-09-22 395344] 
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] 
. 
c:\users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ 
FRITZ!DSL Internet.lnk - c:\program files\FRITZ!DSL\FritzDsl.exe [2009-7-27 987960] 
. 
c:\programdata\Microsoft\Windows\Start Menu\Programs\StartUp\ 
HotSync Manager.lnk - c:\programs~1\Palm\hotsync.exe [2013-4-21 263680] 
Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2013-7-3 563416] 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] 
"ConsentPromptBehaviorAdmin"= 5 (0x5) 
"EnableCursorSuppression"= 1 (0x1) 
"EnableUIADesktopToggle"= 0 (0x0) 
"ConsentPromptBehaviorUser"= 3 (0x3) 
"EnableLinkedConnections"= 1 (0x1) 
. 
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] 
BootExecute        REG_MULTI_SZ           autocheck autochk /m /P \Device\HarddiskVolume8\0autocheck autochk * 
. 
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-02-28 161384] 
R3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136] 
S0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);c:\windows\system32\DRIVERS\tdrpm273.sys [2013-04-21 752128] 
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-04-02 37352] 
S1 NEOFLTR_730_22751;Juniper Networks TDI Filter Driver (NEOFLTR_730_22751);c:\windows\system32\Drivers\NEOFLTR_730_22751.SYS [2012-11-23 91824] 
S2 afcdpsrv;Acronis Nonstop Backup-Dienst;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [2013-04-21 3246040] 
S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2013-09-19 84024] 
S2 IGDCTRL;AVM IGD CTRL Service;c:\program files\FRITZ!DSL\IGDCTRL.EXE [2009-07-28 73528] 
S2 JuniperAccessService;Juniper Unified Network Service;c:\program files\Common Files\Juniper Networks\JUNS\dsAccessService.exe [2013-03-27 167464] 
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\PSIA.exe [2013-07-03 1228504] 
S2 Secunia Update Agent;Secunia Update Agent;c:\program files\Secunia\PSI\sua.exe [2013-07-03 660184] 
S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [2013-04-21 167968] 
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf_x86.sys [2013-07-03 16024] 
. 
. 
Inhalt des "geplante Tasks" Ordners 
. 
2013-10-11 c:\windows\Tasks\Adobe Flash Player Updater.job 
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-17 18:49] 
. 
2013-10-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job 
- c:\program files\Google\Update\GoogleUpdate.exe [2013-09-21 10:24] 
. 
2013-10-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job 
- c:\program files\Google\Update\GoogleUpdate.exe [2013-09-21 10:24] 
. 
. 
------- Zusätzlicher Suchlauf ------- 
. 
uStart Page = hxxp://microsoft.com/update 
TCP: DhcpNameServer = 192.168.178.1 
. 
- - - - Entfernte verwaiste Registrierungseinträge - - - - 
. 
HKLM-Run-DivXMediaServer - c:\program files\DivX\DivX Media Server\DivXMediaServer.exe 
HKU-Default-Run-FRITZ!protect - FwebProt.exe 
. 
. 
. 
--------------------- Gesperrte Registrierungsschluessel --------------------- 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Internet Explorer\Approved Extensions] 
@Denied: (2) (Administrator) 
"{553891B7-A0D5-4526-BE18-D3CE461D6310}"=hex:51,66,7a,6c,4c,1d,3b,1b,a7,8e,2b, 
   4a,e3,f1,4a,08,a1,14,96,8e,4e,5d,2f,0e 
"{449D0D6E-2412-4E61-B68F-1CB625CD9E52}"=hex:51,66,7a,6c,4c,1d,3b,1b,7e,12,8e, 
   5b,24,75,0d,03,a9,83,59,f6,2d,8d,d2,4c 
"{EA801577-E6AD-4BD5-8F71-4BE0154331A4}"=hex:51,66,7a,6c,4c,1d,3b,1b,67,0a,93, 
   f5,9b,b7,b9,06,90,7d,0e,a0,1d,03,7d,ba 
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,3b,1b,ab,88,07, 
   69,c6,87,40,0b,a9,e7,91,9a,f9,99,61,5d 
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,3b,1b,54,1f,db, 
   c4,73,f5,37,0e,a3,78,d9,65,c9,85,c4,b7 
"{AE48ED75-5A56-4C5F-BBCE-6F1AC3875F66}"=hex:51,66,7a,6c,4c,1d,3b,1b,65,f2,5b, 
   b1,60,0b,33,01,a4,c2,2a,5a,cb,c7,13,78 
"{C728ECCB-7A57-4AFF-AB17-6434AFF18F49}"=hex:51,66,7a,6c,4c,1d,3b,1b,db,f3,3b, 
   d8,61,2b,93,07,b4,1b,21,74,a7,b1,c3,57 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration] 
@Denied: (2) (Administrator) 
"Timestamp"=hex:39,25,67,d4,aa,a4,ce,01 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Internet Explorer\User Preferences] 
@Denied: (2) (Administrator) 
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, 
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,08,76,96,85,6e,34,d1,41,91,9c,50,\ 
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, 
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,08,76,96,85,6e,34,d1,41,91,9c,50,\ 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="6toF4FqZ9CI=" 
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="PENBi4/633I=" 
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="Gbx0bTR0BVs=" 
"ProgId"="WMP11.AssocFile.3G2" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="GYrmpQMOP+Y=" 
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="sNfaFMPswMg=" 
"ProgId"="AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.adt\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="lOS1kV0iZc8=" 
"ProgId"="WMP11.AssocFile.ADTS" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.adts\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="tWuP4W8cuzA=" 
"ProgId"="WMP11.AssocFile.ADTS" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="Y+GYvvzmVtg=" 
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="3zw++lE9gfk=" 
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="nNB/hESlJqA=" 
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="Mjd93FQyJuE=" 
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="Qsqw9+lB7+c=" 
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="XimINgjzheE=" 
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="jVkV5N4flkc=" 
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="Q43d//z4GJE=" 
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="T4kVKaqD2TY=" 
"ProgId"="AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="zFTOpjCdRe0=" 
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="ygc12GkfUyM=" 
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MP2\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="BoCc9hSnf6g=" 
"ProgId"="WMP11.AssocFile.MP3" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="tIs40EPTE/E=" 
"ProgId"="AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="SAuo/NMMfkE=" 
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4v\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="E8Xf3VahEQg=" 
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="y3Xlbm4G4A0=" 
"ProgId"="WMP11.AssocFile.MPEG" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MPE\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="Z9Pg95vE0+4=" 
"ProgId"="WMP11.AssocFile.MPEG" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="ZsBXokkrRz4=" 
"ProgId"="WMP11.AssocFile.MPEG" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="aGYz+ivP88g=" 
"ProgId"="WMP11.AssocFile.MPEG" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mts\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="WtXPuo2Uo8g=" 
"ProgId"="WMP11.AssocFile.M2TS" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.oxps\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="t7DSZYJcJ0g=" 
"ProgId"="AppX86746z2101ayy2ygv3g96e4eqdf8r99j" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="9ee2/uL+6GA=" 
"ProgId"="AppX86746z2101ayy2ygv3g96e4eqdf8r99j" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="EKznZ39alrU=" 
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="xh0oADlMDRk=" 
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="K3TC5Hcup7g=" 
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TS\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="Vnjwt420kPE=" 
"ProgId"="WMP11.AssocFile.TTS" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TTS\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="PR1n3VYLG3U=" 
"ProgId"="WMP11.AssocFile.TTS" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="FEGYwgFYcwA=" 
"ProgId"="txtfile" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="bal60haK06g=" 
"ProgId"="AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wdp\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="5LWAzGMYi50=" 
"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="t+tPu5hmIvM=" 
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="WbCGh8AwleU=" 
"ProgId"="AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="fc7eDj1nWBM=" 
"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.WPL\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="SLtgDthwfK0=" 
"ProgId"="WMP11.AssocFile.WPL" 
. 
[HKEY_USERS\S-1-5-21-1161230377-839233791-2051609808-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xps\UserChoice] 
@Denied: (2) (Administrator) 
"Hash"="aw3DZsPuq5Y=" 
"ProgId"="AppX86746z2101ayy2ygv3g96e4eqdf8r99j" 
. 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] 
@Denied: (Full) (Everyone) 
@SACL=(02 0000) 
. 
Zeit der Fertigstellung: 2013-10-11  11:05:24 
ComboFix-quarantined-files.txt  2013-10-11 09:05 
. 
Vor Suchlauf: 15 Verzeichnis(se), 49.872.261.120 Bytes frei 
Nach Suchlauf: 20 Verzeichnis(se), 49.847.197.696 Bytes frei 
. 
- - End Of File - - 2EC61E2F5F652385E37C255637136B07 
72B8CE41AF0DE751C946802B3ED844B4   
Gruß 
Carsten    |