| PotatoeJesus |  29.08.2014 14:15 |        Das hat sich zur Combofix.txt Datei noch eine log.txt Datei geöffnet. Ich poste mal beide: 
Combofix:   Code:  
 ComboFix 14-08-29.03 - Burak 29.08.2014  14:57:11.1.4 - x64 
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.8141.5957 [GMT 2:00] 
ausgeführt von:: c:\users\Burak\Desktop\ComboFix.exe 
AV: Bitdefender Antivirus *Disabled/Updated* {9A0813D8-CED6-F86B-072E-28D2AF25A83D} 
FW: Bitdefender Firewall *Disabled* {A23392FD-84B9-F933-2C71-81E751F6EF46} 
SP: Bitdefender Antispyware *Disabled/Updated* {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280} 
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} 
 * Neuer Wiederherstellungspunkt wurde erstellt 
. 
. 
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   )))))))))))))))))))))))))))))))))))))))))))))))) 
. 
. 
C:\END 
c:\programdata\1365794204.bdinstall.bin 
c:\programdata\1365794320.1228.bin 
c:\programdata\1365794320.3748.bin 
c:\programdata\1365794535.bdinstall.bin 
c:\programdata\1365794992.bdinstall.bin 
c:\programdata\1366579226.6192.bin 
c:\programdata\1366579226.6724.bin 
c:\programdata\1366579226.6924.bin 
c:\programdata\1366579226.6960.bin 
c:\programdata\1366579226.bdinstall.bin 
c:\programdata\1369239762.bdinstall.bin 
c:\programdata\1369239773.bdinstall.bin 
c:\programdata\1390129995.bdinstall.bin 
c:\programdata\1390130092.bdinstall.bin 
c:\programdata\1390130137.bdinstall.bin 
c:\programdata\1390130457.bdinstall.bin 
c:\programdata\1392463864.bdinstall.bin 
c:\programdata\1392464729.bdinstall.bin 
c:\programdata\1392465026.bdinstall.bin 
c:\programdata\1401796698.bdinstall.bin 
c:\programdata\1401796707.bdinstall.bin 
c:\programdata\1401797311.bdinstall.bin 
c:\programdata\1401800683.bdinstall.bin 
c:\users\Burak\AppData\Local\Savings Explorer 
c:\users\Burak\AppData\Local\Savings Explorer\Chrome\Installer.log 
c:\users\Burak\AppData\Roaming\Mozilla\Firefox\Profiles\0g8s9jjg.default-1362844820888\searchplugins\trovi-search.xml 
c:\windows\iun6002.exe 
c:\windows\SysWow64\redist.txt 
. 
. 
(((((((((((((((((((((((   Dateien erstellt von 2014-07-28 bis 2014-08-29  )))))))))))))))))))))))))))))) 
. 
. 
2014-08-29 13:04 . 2014-08-29 13:04        --------        d-----w-        c:\users\hedev\AppData\Local\temp 
2014-08-29 13:04 . 2014-08-29 13:04        --------        d-----w-        c:\users\Gast\AppData\Local\temp 
2014-08-29 13:04 . 2014-08-29 13:04        --------        d-----w-        c:\users\Default\AppData\Local\temp 
2014-08-29 12:40 . 2014-08-29 12:40        94656        ----a-w-        c:\windows\system32\WPRO_41_2001woem.tmp 
2014-08-27 17:44 . 2014-08-23 02:07        404480        ----a-w-        c:\windows\system32\gdi32.dll 
2014-08-27 17:44 . 2014-08-23 01:45        311808        ----a-w-        c:\windows\SysWow64\gdi32.dll 
2014-08-27 17:44 . 2014-08-23 00:59        3163648        ----a-w-        c:\windows\system32\win32k.sys 
2014-08-24 19:40 . 2014-08-24 19:40        --------        d-----w-        c:\program files\Defraggler 
2014-08-24 15:56 . 2014-08-24 16:01        --------        d-----w-        c:\program files (x86)\Terror Engine 
2014-08-23 20:47 . 2014-08-23 20:48        --------        d-----w-        c:\users\Gast\Steuer2013 
2014-08-23 16:36 . 2014-08-23 16:36        --------        d-----w-        c:\users\Gast\AppData\Roaming\elsterformular 
2014-08-22 10:46 . 2014-08-22 10:46        --------        d-----w-        c:\program files (x86)\Common Files\Java 
2014-08-19 17:08 . 2014-08-19 17:08        --------        d-----w-        c:\users\Burak\AppData\Local\Adobe 
2014-08-14 17:23 . 2014-03-09 21:48        171160        ----a-w-        c:\windows\system32\infocardapi.dll 
2014-08-14 17:23 . 2014-03-09 21:48        1389208        ----a-w-        c:\windows\system32\icardagt.exe 
2014-08-14 17:23 . 2014-03-09 21:47        99480        ----a-w-        c:\windows\SysWow64\infocardapi.dll 
2014-08-14 17:23 . 2014-03-09 21:47        619672        ----a-w-        c:\windows\SysWow64\icardagt.exe 
2014-08-14 17:23 . 2014-06-30 22:24        8856        ----a-w-        c:\windows\system32\icardres.dll 
2014-08-14 17:23 . 2014-06-30 22:14        8856        ----a-w-        c:\windows\SysWow64\icardres.dll 
2014-08-14 17:22 . 2014-06-06 06:16        35480        ----a-w-        c:\windows\SysWow64\TsWpfWrp.exe 
2014-08-14 17:22 . 2014-06-06 06:12        35480        ----a-w-        c:\windows\system32\TsWpfWrp.exe 
2014-08-14 16:48 . 2014-08-14 16:48        --------        d-----w-        c:\program files (x86)\Five Nights at Freddy's DEMO 
2014-08-14 16:46 . 2014-08-14 16:46        --------        d-----w-        c:\users\Burak\AppData\Roaming\MMFApplications 
2014-08-14 16:44 . 2014-08-14 16:45        --------        d-----w-        c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 
2014-08-14 16:44 . 2014-08-14 16:45        --------        d-----w-        c:\program files\iTunes 
2014-08-14 16:44 . 2014-08-14 16:45        --------        d-----w-        c:\program files (x86)\iTunes 
2014-08-14 16:44 . 2014-08-14 16:44        --------        d-----w-        c:\program files\iPod 
2014-08-14 16:07 . 2014-07-25 13:28        548352        ----a-w-        c:\windows\system32\vbscript.dll 
2014-08-11 21:32 . 2014-08-11 21:32        --------        d-----w-        c:\users\Gast\AppData\Local\Apple 
2014-08-11 21:28 . 2014-08-11 21:36        --------        d-----w-        c:\users\Gast\AppData\Roaming\DVDVideoSoft 
2014-08-05 17:20 . 2014-08-05 17:20        227728        ----a-w-        c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll 
2014-08-04 17:37 . 2014-08-04 17:37        --------        d-----w-        c:\programdata\elsterformular 
2014-08-04 17:36 . 2014-08-04 17:36        --------        d-----w-        c:\program files (x86)\ElsterFormular 
2014-08-03 10:30 . 2014-08-03 10:30        --------        d-----w-        c:\users\Gast\AppData\Local\Google 
2014-08-02 16:11 . 2014-05-14 16:23        44512        ----a-w-        c:\windows\system32\wups2.dll 
2014-08-02 16:11 . 2014-05-14 16:23        58336        ----a-w-        c:\windows\system32\wuauclt.exe 
2014-08-02 16:11 . 2014-05-14 16:23        2477536        ----a-w-        c:\windows\system32\wuaueng.dll 
2014-08-02 16:11 . 2014-05-14 16:21        2620928        ----a-w-        c:\windows\system32\wucltux.dll 
2014-08-02 16:10 . 2014-05-14 16:23        38880        ----a-w-        c:\windows\system32\wups.dll 
2014-08-02 16:10 . 2014-05-14 16:20        97792        ----a-w-        c:\windows\system32\wudriver.dll 
2014-08-02 16:10 . 2014-05-14 16:23        36320        ----a-w-        c:\windows\SysWow64\wups.dll 
2014-08-02 16:10 . 2014-05-14 16:23        700384        ----a-w-        c:\windows\system32\wuapi.dll 
2014-08-02 16:10 . 2014-05-14 16:23        581600        ----a-w-        c:\windows\SysWow64\wuapi.dll 
2014-08-02 16:10 . 2014-05-14 16:17        92672        ----a-w-        c:\windows\SysWow64\wudriver.dll 
2014-08-02 16:10 . 2014-05-14 07:23        198600        ----a-w-        c:\windows\system32\wuwebv.dll 
2014-08-02 16:10 . 2014-05-14 07:23        179656        ----a-w-        c:\windows\SysWow64\wuwebv.dll 
2014-08-02 16:10 . 2014-05-14 07:20        36864        ----a-w-        c:\windows\system32\wuapp.exe 
2014-08-02 16:10 . 2014-05-14 07:17        33792        ----a-w-        c:\windows\SysWow64\wuapp.exe 
. 
. 
. 
((((((((((((((((((((((((((((((((((((   Find3M Bericht   )))))))))))))))))))))))))))))))))))))))))))))))))))))) 
. 
2014-08-29 12:40 . 2009-08-18 10:24        23256        ----a-w-        c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 
2014-08-29 12:40 . 2013-02-10 15:32        34752        ----a-w-        c:\windows\system32\drivers\WPRO_41_2001.sys 
2014-08-22 10:44 . 2014-04-19 16:51        98216        ----a-w-        c:\windows\SysWow64\WindowsAccessBridge-32.dll 
2014-08-15 21:12 . 2013-02-10 18:03        71344        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl 
2014-08-15 21:12 . 2013-02-10 18:03        699568        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe 
2014-08-14 17:26 . 2013-02-10 16:31        99218768        ----a-w-        c:\windows\system32\MRT.exe 
2014-08-14 17:14 . 2014-06-28 17:26        297088        ----a-w-        c:\windows\SysWow64\PnkBstrB.xtr 
2014-08-14 17:14 . 2014-06-03 10:32        297088        ----a-w-        c:\windows\SysWow64\PnkBstrB.exe 
2014-08-14 17:14 . 2013-09-27 11:12        280904        ----a-w-        c:\windows\SysWow64\PnkBstrB.ex0 
2014-08-14 16:24 . 2014-06-03 13:08        647752        ----a-w-        c:\windows\system32\drivers\avckf.sys 
2014-08-14 16:24 . 2014-06-03 13:08        1260120        ----a-w-        c:\windows\system32\drivers\avc3.sys 
2014-08-14 16:24 . 2014-01-19 11:15        84848        ----a-w-        c:\windows\system32\bdsandboxuiskin.dll 
2014-08-14 16:24 . 2014-01-19 11:15        34384        ----a-w-        c:\windows\system32\bdsandboxuh.dll 
2014-08-14 16:24 . 2014-06-03 13:04        419616        ----a-w-        c:\windows\system32\drivers\trufos.sys 
2014-08-14 16:24 . 2014-01-19 11:57        74512        ----a-w-        c:\windows\system32\bdsandboxuiskin32.dll 
2014-08-03 17:05 . 2013-02-10 15:59        32320        ----a-w-        c:\windows\system32\drivers\FNETTBOH_305.SYS 
2014-06-28 18:11 . 2014-06-03 10:32        76152        ----a-w-        c:\windows\SysWow64\PnkBstrA.exe 
2014-06-18 02:18 . 2014-07-10 16:26        692736        ----a-w-        c:\windows\system32\osk.exe 
2014-06-18 01:51 . 2014-07-10 16:26        646144        ----a-w-        c:\windows\SysWow64\osk.exe 
2014-06-06 14:01 . 2014-06-06 14:01        283064        ----a-w-        c:\windows\system32\drivers\dtsoftbus01.sys 
2014-06-06 10:10 . 2014-07-10 16:26        624128        ----a-w-        c:\windows\system32\qedit.dll 
2014-06-06 09:44 . 2014-07-10 16:26        509440        ----a-w-        c:\windows\SysWow64\qedit.dll 
2014-06-05 14:45 . 2014-07-10 16:25        1460736        ----a-w-        c:\windows\system32\lsasrv.dll 
2014-06-05 14:26 . 2014-07-10 16:25        22016        ----a-w-        c:\windows\SysWow64\secur32.dll 
2014-06-05 14:25 . 2014-07-10 16:25        96768        ----a-w-        c:\windows\SysWow64\sspicli.dll 
2014-06-03 11:42 . 2014-06-03 11:45        1198049        ----a-w-        c:\windows\unins000.exe 
2014-06-03 11:33 . 2013-02-12 14:34        111016        ----a-w-        c:\windows\system32\WindowsAccessBridge-64.dll 
2014-01-05 21:09 . 2014-01-05 21:09        2759168        ----a-w-        c:\program files (x86)\GS_x64.Enabler 
. 
. 
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   )))))))))))))))))))))))))))))))))))))))) 
. 
. 
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.  
REGEDIT4 
. 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 
"AppleIEDAV"="c:\program files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe" [2013-11-15 1326408] 
"iCloudServices"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" [2013-11-20 59720] 
"Bitdefender Wallet Agent"="c:\program files\Bitdefender\Bitdefender\pmbxag.exe" [2014-08-14 568400] 
"Bitdefender Wallet Application Agent"="c:\program files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" [2014-08-14 615256] 
"Akamai NetSession Interface"="c:\users\Burak\AppData\Local\Akamai\netsession_win.exe" [2014-04-17 4672920] 
"Spotify Web Helper"="c:\users\Burak\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2014-08-21 1245752] 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-11-29 284440] 
"IMSS"="c:\program files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [2012-02-07 133400] 
"XFastUSB"="c:\program files (x86)\XFastUSB\XFastUsb.exe" [2013-02-10 5019360] 
"THX TruStudio NB Settings"="c:\program files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" [2011-05-19 909824] 
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] 
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-06-11 641704] 
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904] 
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2014-08-01 152392] 
. 
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] 
"Bitdefender Wallet Agent"="c:\program files\Bitdefender\Bitdefender\pmbxag.exe" [2014-08-14 568400] 
"Bitdefender Wallet"="c:\program files\Bitdefender\Bitdefender\pwdmanui.exe" [2014-08-14 1002048] 
"Bitdefender Wallet Application Agent"="c:\program files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" [2014-08-14 615256] 
. 
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ 
Sitecom Wireless Utility.lnk - c:\program files (x86)\Sitecom\Common\WLANUtil.exe -s [2013-7-29 1626112] 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] 
"ConsentPromptBehaviorAdmin"= 0 (0x0) 
"ConsentPromptBehaviorUser"= 3 (0x3) 
"EnableLUA"= 0 (0x0) 
"EnableUIADesktopToggle"= 0 (0x0) 
"PromptOnSecureDesktop"= 0 (0x0) 
. 
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] 
"LoadAppInit_DLLs"=1 (0x1) 
. 
R2 1a34a8e0;GS.Supporter;c:\windows\system32\rundll32.exe;c:\windows\SYSNATIVE\rundll32.exe [x] 
R2 ASGT;ASGT;c:\windows\SysWOW64\ASGT.exe;c:\windows\SysWOW64\ASGT.exe [x] 
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] 
R3 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys;c:\windows\SYSNATIVE\DRIVERS\avckf.sys [x] 
R3 bdfwfpf_pc;bdfwfpf_pc;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [x] 
R3 BDSandBox;BDSandBox;c:\windows\system32\drivers\bdsandbox.sys;c:\windows\SYSNATIVE\drivers\bdsandbox.sys [x] 
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x] 
R3 BRDriver64;BRDriver64;c:\programdata\BitRaider\BRDriver64.sys;c:\programdata\BitRaider\BRDriver64.sys [x] 
R3 BRSptSvc;BitRaider Mini-Support Service;c:\programdata\BitRaider\BRSptSvc.exe;c:\programdata\BitRaider\BRSptSvc.exe [x] 
R3 cpuz136;cpuz136;c:\windows\TEMP\cpuz136\cpuz136_x64.sys;c:\windows\TEMP\cpuz136\cpuz136_x64.sys [x] 
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] 
R3 DrvAgent64;DrvAgent64;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS [x] 
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x] 
R3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS;c:\windows\SYSNATIVE\drivers\FNETTBOH_305.SYS [x] 
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] 
R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys;c:\windows\SYSNATIVE\DRIVERS\MijXfilt.sys [x] 
R3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x] 
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x] 
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] 
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] 
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] 
R3 USBTINSP;TI-Nspire(TM) Handheld or TI Network Bridge Device Driver;c:\windows\system32\DRIVERS\tinspusb.sys;c:\windows\SYSNATIVE\DRIVERS\tinspusb.sys [x] 
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x] 
R3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x] 
R3 VBoxUSB;VirtualBox USB;c:\windows\system32\Drivers\VBoxUSB.sys;c:\windows\SYSNATIVE\Drivers\VBoxUSB.sys [x] 
R3 xhunter1;xhunter1;c:\windows\xhunter1.sys;c:\windows\xhunter1.sys [x] 
R4 BdDesktopParental;Bitdefender Desktop Parental Control;c:\program files\Bitdefender\Bitdefender\bdparentalservice.exe;c:\program files\Bitdefender\Bitdefender\bdparentalservice.exe [x] 
S0 asahci64;asahci64;c:\windows\system32\DRIVERS\asahci64.sys;c:\windows\SYSNATIVE\DRIVERS\asahci64.sys [x] 
S0 AsrRamDisk;AsrRamDisk;c:\windows\system32\DRIVERS\AsrRamDisk.sys;c:\windows\SYSNATIVE\DRIVERS\AsrRamDisk.sys [x] 
S0 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys;c:\windows\SYSNATIVE\DRIVERS\avc3.sys [x] 
S0 gzflt;gzflt;c:\windows\system32\DRIVERS\gzflt.sys;c:\windows\SYSNATIVE\DRIVERS\gzflt.sys [x] 
S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x] 
S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AsrAppCharger.sys [x] 
S1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [x] 
S1 bdfwfpf;bdfwfpf;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [x] 
S1 BDVEDISK;BDVEDISK;c:\windows\system32\DRIVERS\bdvedisk.sys;c:\windows\SYSNATIVE\DRIVERS\bdvedisk.sys [x] 
S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS;c:\windows\SYSNATIVE\drivers\FNETURPX.SYS [x] 
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] 
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x] 
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] 
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] 
S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x] 
S2 ISCTAgent;ISCT Always Updated Agent;c:\program files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe;c:\program files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [x] 
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] 
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x] 
S2 RalinkRegistryWriter64;RalinkRegistryWriter64;c:\program files (x86)\Sitecom\Common\RaRegistry64.exe;c:\program files (x86)\Sitecom\Common\RaRegistry64.exe [x] 
S2 SafeBox;SafeBox;c:\program files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe;c:\program files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [x] 
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x] 
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] 
S2 UPDATESRV;Bitdefender Desktop Update Service;c:\program files\Bitdefender\Bitdefender\updatesrv.exe;c:\program files\Bitdefender\Bitdefender\updatesrv.exe [x] 
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] 
S3 avchv;avchv Function Driver;c:\windows\system32\DRIVERS\avchv.sys;c:\windows\SYSNATIVE\DRIVERS\avchv.sys [x] 
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] 
S3 ikbevent;Intel Upper keyboard Class Filter Driver;c:\windows\system32\DRIVERS\ikbevent.sys;c:\windows\SYSNATIVE\DRIVERS\ikbevent.sys [x] 
S3 imsevent;Intel Upper Mouse Class Filter Driver;c:\windows\system32\DRIVERS\imsevent.sys;c:\windows\SYSNATIVE\DRIVERS\imsevent.sys [x] 
S3 ISCT;Intel(R) Smart Connect Technology Device Driver;c:\windows\system32\DRIVERS\ISCTD64.sys;c:\windows\SYSNATIVE\DRIVERS\ISCTD64.sys [x] 
S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x] 
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x] 
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x] 
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] 
S3 ScpVBus;Scp Virtual Bus Driver;c:\windows\system32\DRIVERS\ScpVBus.sys;c:\windows\SYSNATIVE\DRIVERS\ScpVBus.sys [x] 
S3 WPRO_41_2001;WinPcap Packet Driver (WPRO_41_2001);c:\windows\system32\drivers\WPRO_41_2001.sys;c:\windows\SYSNATIVE\drivers\WPRO_41_2001.sys [x] 
. 
. 
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 
2014-08-26 16:38        1096520        ----a-w-        c:\program files (x86)\Google\Chrome\Application\37.0.2062.94\Installer\chrmstp.exe 
. 
Inhalt des "geplante Tasks" Ordners 
. 
2014-08-28 c:\windows\Tasks\Adobe Flash Player Updater.job 
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-10 21:12] 
. 
2014-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job 
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-28 20:37] 
. 
2014-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job 
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-28 20:37] 
. 
. 
--------- X64 Entries ----------- 
. 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox1] 
@="{152C96EB-288E-4EDC-B7C6-D21F8250ADF3}" 
[HKEY_CLASSES_ROOT\CLSID\{152C96EB-288E-4EDC-B7C6-D21F8250ADF3}] 
2013-07-08 13:59        206352        ----a-w-        c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox2] 
@="{342DAA0B-D796-460D-8566-901E08A1CCAD}" 
[HKEY_CLASSES_ROOT\CLSID\{342DAA0B-D796-460D-8566-901E08A1CCAD}] 
2013-07-08 13:59        206352        ----a-w-        c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox3] 
@="{57595DAE-1AE1-4D97-A49E-67CBB53B52DF}" 
[HKEY_CLASSES_ROOT\CLSID\{57595DAE-1AE1-4D97-A49E-67CBB53B52DF}] 
2013-07-08 13:59        206352        ----a-w-        c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox4] 
@="{33816773-98AE-4723-ADE0-EBE54C8B5A67}" 
[HKEY_CLASSES_ROOT\CLSID\{33816773-98AE-4723-ADE0-EBE54C8B5A67}] 
2013-07-08 13:59        206352        ----a-w-        c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-10-17 13307496] 
"THXCfg64"="c:\windows\system32\THXCfg64.dll" [2011-05-13 26624] 
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184] 
"Bdagent"="c:\program files\Bitdefender\Bitdefender\bdagent.exe" [2014-08-14 1743088] 
. 
------- Zusätzlicher Suchlauf ------- 
. 
uLocal Page = c:\windows\system32\blank.htm 
uStart Page = about:blank 
mStart Page = about:blank 
mLocal Page = c:\windows\SysWOW64\blank.htm 
uInternet Settings,ProxyOverride = *.local;<local> 
IE: An OneNote s&enden - c:\progra~1\MICROS~4\Office15\ONBttnIE.dll/105 
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000 
IE: Free YouTube to MP3 Converter - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm 
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~4\Office15\EXCEL.EXE/3000 
IE: Se&nd to OneNote - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105 
IE: {{c0e8ae32-0758-4c8d-ab71-23b361fe8964} - c:\users\Burak\AppData\Local\Temp\ie_script.htm 
IE: {{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - 
Trusted Zone: aeriagames.com 
Trusted Zone: qq.com\cache.tv 
Trusted Zone: qq.com\qqlivecaption 
Trusted Zone: qq.com\qqlivehabit 
Trusted Zone: qq.com\qqlivesearch 
Trusted Zone: qq.com\video_1 
FF - ProfilePath - c:\users\Burak\AppData\Roaming\Mozilla\Firefox\Profiles\0g8s9jjg.default-1362844820888\ 
FF - prefs.js: browser.search.selectedEngine - Google 
FF - prefs.js: browser.startup.homepage - google.de 
FF - prefs.js: keyword.URL -  
FF - prefs.js: network.proxy.ftp - 37.187.101.139 
FF - prefs.js: network.proxy.ftp_port - 8118 
FF - prefs.js: network.proxy.gopher - 37.187.101.139 
FF - prefs.js: network.proxy.gopher_port - 8118 
FF - prefs.js: network.proxy.http - 37.187.101.139 
FF - prefs.js: network.proxy.http_port - 8118 
FF - prefs.js: network.proxy.socks - 37.187.101.139 
FF - prefs.js: network.proxy.socks_port - 8118 
FF - prefs.js: network.proxy.ssl - 37.187.101.139 
FF - prefs.js: network.proxy.ssl_port - 8118 
FF - prefs.js: network.proxy.type - 0 
FF - user.js: extensions.mysearchdial.hmpg - true 
FF - user.js: extensions.mysearchdial.hmpgUrl - hxxp://start.mysearchdial.com/?f=1&a=irmsd1103&cd=2XzuyEtN2Y1L1Qzu0B0CyD0F0FyEyCtDtA0EtByEyByCzy0FtN0D0Tzu0SyCzzzztN1L2XzutBtFtBtFtCtAtFtCtAtAzztN1L1CzutCtD1B1P1R&cr=1977847028&ir= 
FF - user.js: extensions.mysearchdial.dfltSrch - true 
FF - user.js: extensions.mysearchdial.srchPrvdr - Mysearchdial 
FF - user.js: extensions.mysearchdial.dnsErr - true 
FF - user.js: extensions.mysearchdial_i.newTab - false 
FF - user.js: extensions.mysearchdial.newTabUrl - hxxp://start.mysearchdial.com/?f=2&a=irmsd1103&cd=2XzuyEtN2Y1L1Qzu0B0CyD0F0FyEyCtDtA0EtByEyByCzy0FtN0D0Tzu0SyCzzzztN1L2XzutBtFtBtFtCtAtFtCtAtAzztN1L1CzutCtD1B1P1R&cr=1977847028&ir= 
FF - user.js: extensions.mysearchdial.tlbrSrchUrl - hxxp://start.mysearchdial.com/?f=3&a=irmsd1103&cd=2XzuyEtN2Y1L1Qzu0B0CyD0F0FyEyCtDtA0EtByEyByCzy0FtN0D0Tzu0SyCzzzztN1L2XzutBtFtBtFtCtAtFtCtAtAzztN1L1CzutCtD1B1P1R&cr=1977847028&ir=&q= 
FF - user.js: extensions.mysearchdial.id - BC5FF4603E24769F 
FF - user.js: extensions.mysearchdial.instlDay - 16028 
FF - user.js: extensions.mysearchdial.vrsn - 1.8.21.0 
FF - user.js: extensions.mysearchdial.vrsni - 1.8.21.0 
FF - user.js: extensions.mysearchdial_i.vrsnTs - 1.8.21.00:23 
FF - user.js: extensions.mysearchdial.prtnrId - mysearchdial 
FF - user.js: extensions.mysearchdial.prdct - mysearchdial 
FF - user.js: extensions.mysearchdial.aflt - irmsd1103 
FF - user.js: extensions.mysearchdial_i.smplGrp - none 
FF - user.js: extensions.mysearchdial.tlbrId - base 
FF - user.js: extensions.mysearchdial.instlRef -  
FF - user.js: extensions.mysearchdial.dfltLng -  
FF - user.js: extensions.mysearchdial.appId - {CA5CAA63-B27C-4963-9BEC-CB16A36D56F8} 
FF - user.js: extensions.mysearchdial.excTlbr - false 
FF - user.js: extensions.mysearchdial_i.hmpg - true 
FF - user.js: extensions.mysearchdial.cr - 1977847028 
FF - user.js: extensions.mysearchdial.cd - 2XzuyEtN2Y1L1Qzu0B0CyD0F0FyEyCtDtA0EtByEyByCzy0FtN0D0Tzu0SyCzzzztN1L2XzutBtFtBtFtCtAtFtCtAtAzztN1L1CzutCtD1B1P1R 
FF - user.js: extensions.irmysearch.aflt - irmsd1103 
FF - user.js: extensions.irmysearch.instlRef -  
FF - user.js: extensions.irmysearch.cr - 1977847028 
FF - user.js: extensions.irmysearch.cd - 2XzuyEtN2Y1L1Qzu0B0CyD0F0FyEyCtDtA0EtByEyByCzy0FtN0D0Tzu0SyCzzzztN1L2XzutBtFtBtFtCtAtFtCtAtAzztN1L1CzutCtD1B1P1R 
. 
- - - - Entfernte verwaiste Registrierungseinträge - - - - 
. 
BHO-{31ad400d-1b06-4e33-a59a-90c2c140cba0} - (no file) 
Wow6432Node-HKCU-Run-ASRockXTU - (no file) 
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start 
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file) 
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file) 
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file) 
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file) 
. 
. 
. 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc] 
"ImagePath"="c:\windows\system32\GameMon.des -service" 
. 
--------------------- Gesperrte Registrierungsschluessel --------------------- 
. 
[HKEY_USERS\S-1-5-21-1145914912-1038568159-3068141755-1000_Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}] 
@Denied: (Full) (Everyone) 
@Allowed: (Read) (RestrictedCode) 
"scansk"=hex(0):96,20,0c,4f,dc,d4,e0,8a,2e,bf,4e,a8,c3,41,14,15,d1,8d,6c,72,4d, 
   b4,fa,99,38,d9,89,4f,21,b6,26,62,69,99,86,fc,70,b9,4f,1c,00,00,00,00,00,00,\ 
. 
[HKEY_USERS\S-1-5-21-1145914912-1038568159-3068141755-1000_Classes\Wow6432Node\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}] 
@Denied: (Full) (Everyone) 
@Allowed: (Read) (RestrictedCode) 
"scansk"=hex(0):51,e9,5f,c2,9c,db,51,fa,39,b0,57,b0,11,23,d7,05,dc,bc,e3,05,35, 
   f4,32,fe,99,da,a2,4c,71,f9,6d,ab,00,cd,bc,d1,c0,2c,b7,16,00,00,00,00,00,00,\ 
. 
[HKEY_USERS\S-1-5-21-1145914912-1038568159-3068141755-1000_Classes\Wow6432Node\CLSID\{c42f1377-85b1-4fc0-b5f0-ed18f2b1b367}] 
@Denied: (Full) (Everyone) 
@Allowed: (Read) (RestrictedCode) 
"Model"=dword:000000c3 
"Therad"=dword:0000001a 
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a, 
   1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\ 
. 
[HKEY_USERS\S-1-5-21-1145914912-1038568159-3068141755-1000_Classes\Wow6432Node\CLSID\{c4e1e99d-4d5c-4d78-a218-dd0ff12571a4}] 
@Denied: (Full) (Everyone) 
@Allowed: (Read) (RestrictedCode) 
"Model"=dword:00000046 
"Therad"=dword:0000001e 
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26, 
   38,95,44,bc,f4,23,4f,c9,2a,f3,ff,44,0b,f3,8c,70,4a,af,68,3b,8f,70,42,b6,14,\ 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] 
@Denied: (A 2) (Everyone) 
@="FlashBroker" 
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe,-101" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] 
"Enabled"=dword:00000001 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] 
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] 
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] 
@Denied: (A 2) (Everyone) 
@="IFlashBroker5" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] 
@="{00020424-0000-0000-C000-000000000046}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] 
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" 
"Version"="1.0" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] 
@Denied: (A 2) (Everyone) 
@="FlashBroker" 
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe,-101" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] 
"Enabled"=dword:00000001 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] 
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] 
@Denied: (A 2) (Everyone) 
@="Shockwave Flash Object" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx" 
"ThreadingModel"="Apartment" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] 
@="0" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] 
@="ShockwaveFlash.ShockwaveFlash.14" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx, 1" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] 
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] 
@="1.0" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] 
@="ShockwaveFlash.ShockwaveFlash" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] 
@Denied: (A 2) (Everyone) 
@="Macromedia Flash Factory Object" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx" 
"ThreadingModel"="Apartment" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] 
@="FlashFactory.FlashFactory.1" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx, 1" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] 
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] 
@="1.0" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] 
@="FlashFactory.FlashFactory" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] 
@Denied: (A 2) (Everyone) 
@="IFlashBroker5" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] 
@="{00020424-0000-0000-C000-000000000046}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] 
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" 
"Version"="1.0" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] 
@Denied: (A) (Everyone) 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] 
@Denied: (A) (Everyone) 
. 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] 
@Denied: (Full) (Everyone) 
. 
Zeit der Fertigstellung: 2014-08-29  15:06:37 
ComboFix-quarantined-files.txt  2014-08-29 13:06 
. 
Vor Suchlauf: 17 Verzeichnis(se), 484.848.562.176 Bytes frei 
Nach Suchlauf: 21 Verzeichnis(se), 484.349.448.192 Bytes frei 
. 
- - End Of File - - 5B07EC3C95C02FFBEF24DAB0ECB7ADA2 
A36C5E4F47E84449FF07ED3517B43A31    Code:  
 ComboFix 14-08-29.03 - Burak 29.08.2014  14:57:11.1.4 - x64 
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.8141.5957 [GMT 2:00] 
ausgeführt von:: c:\users\Burak\Desktop\ComboFix.exe 
AV: Bitdefender Antivirus *Disabled/Updated* {9A0813D8-CED6-F86B-072E-28D2AF25A83D} 
FW: Bitdefender Firewall *Disabled* {A23392FD-84B9-F933-2C71-81E751F6EF46} 
SP: Bitdefender Antispyware *Disabled/Updated* {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280} 
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} 
 * Neuer Wiederherstellungspunkt wurde erstellt 
. 
. 
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   )))))))))))))))))))))))))))))))))))))))))))))))) 
. 
. 
C:\END 
c:\programdata\1365794204.bdinstall.bin 
c:\programdata\1365794320.1228.bin 
c:\programdata\1365794320.3748.bin 
c:\programdata\1365794535.bdinstall.bin 
c:\programdata\1365794992.bdinstall.bin 
c:\programdata\1366579226.6192.bin 
c:\programdata\1366579226.6724.bin 
c:\programdata\1366579226.6924.bin 
c:\programdata\1366579226.6960.bin 
c:\programdata\1366579226.bdinstall.bin 
c:\programdata\1369239762.bdinstall.bin 
c:\programdata\1369239773.bdinstall.bin 
c:\programdata\1390129995.bdinstall.bin 
c:\programdata\1390130092.bdinstall.bin 
c:\programdata\1390130137.bdinstall.bin 
c:\programdata\1390130457.bdinstall.bin 
c:\programdata\1392463864.bdinstall.bin 
c:\programdata\1392464729.bdinstall.bin 
c:\programdata\1392465026.bdinstall.bin 
c:\programdata\1401796698.bdinstall.bin 
c:\programdata\1401796707.bdinstall.bin 
c:\programdata\1401797311.bdinstall.bin 
c:\programdata\1401800683.bdinstall.bin 
c:\users\Burak\AppData\Local\Savings Explorer 
c:\users\Burak\AppData\Local\Savings Explorer\Chrome\Installer.log 
c:\users\Burak\AppData\Roaming\Mozilla\Firefox\Profiles\0g8s9jjg.default-1362844820888\searchplugins\trovi-search.xml 
c:\windows\iun6002.exe 
c:\windows\SysWow64\redist.txt 
. 
. 
(((((((((((((((((((((((   Dateien erstellt von 2014-07-28 bis 2014-08-29  )))))))))))))))))))))))))))))) 
. 
. 
2014-08-29 13:04 . 2014-08-29 13:04        --------        d-----w-        c:\users\hedev\AppData\Local\temp 
2014-08-29 13:04 . 2014-08-29 13:04        --------        d-----w-        c:\users\Gast\AppData\Local\temp 
2014-08-29 13:04 . 2014-08-29 13:04        --------        d-----w-        c:\users\Default\AppData\Local\temp 
2014-08-29 12:40 . 2014-08-29 12:40        94656        ----a-w-        c:\windows\system32\WPRO_41_2001woem.tmp 
2014-08-27 17:44 . 2014-08-23 02:07        404480        ----a-w-        c:\windows\system32\gdi32.dll 
2014-08-27 17:44 . 2014-08-23 01:45        311808        ----a-w-        c:\windows\SysWow64\gdi32.dll 
2014-08-27 17:44 . 2014-08-23 00:59        3163648        ----a-w-        c:\windows\system32\win32k.sys 
2014-08-24 19:40 . 2014-08-24 19:40        --------        d-----w-        c:\program files\Defraggler 
2014-08-24 15:56 . 2014-08-24 16:01        --------        d-----w-        c:\program files (x86)\Terror Engine 
2014-08-23 20:47 . 2014-08-23 20:48        --------        d-----w-        c:\users\Gast\Steuer2013 
2014-08-23 16:36 . 2014-08-23 16:36        --------        d-----w-        c:\users\Gast\AppData\Roaming\elsterformular 
2014-08-22 10:46 . 2014-08-22 10:46        --------        d-----w-        c:\program files (x86)\Common Files\Java 
2014-08-19 17:08 . 2014-08-19 17:08        --------        d-----w-        c:\users\Burak\AppData\Local\Adobe 
2014-08-14 17:23 . 2014-03-09 21:48        171160        ----a-w-        c:\windows\system32\infocardapi.dll 
2014-08-14 17:23 . 2014-03-09 21:48        1389208        ----a-w-        c:\windows\system32\icardagt.exe 
2014-08-14 17:23 . 2014-03-09 21:47        99480        ----a-w-        c:\windows\SysWow64\infocardapi.dll 
2014-08-14 17:23 . 2014-03-09 21:47        619672        ----a-w-        c:\windows\SysWow64\icardagt.exe 
2014-08-14 17:23 . 2014-06-30 22:24        8856        ----a-w-        c:\windows\system32\icardres.dll 
2014-08-14 17:23 . 2014-06-30 22:14        8856        ----a-w-        c:\windows\SysWow64\icardres.dll 
2014-08-14 17:22 . 2014-06-06 06:16        35480        ----a-w-        c:\windows\SysWow64\TsWpfWrp.exe 
2014-08-14 17:22 . 2014-06-06 06:12        35480        ----a-w-        c:\windows\system32\TsWpfWrp.exe 
2014-08-14 16:48 . 2014-08-14 16:48        --------        d-----w-        c:\program files (x86)\Five Nights at Freddy's DEMO 
2014-08-14 16:46 . 2014-08-14 16:46        --------        d-----w-        c:\users\Burak\AppData\Roaming\MMFApplications 
2014-08-14 16:44 . 2014-08-14 16:45        --------        d-----w-        c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 
2014-08-14 16:44 . 2014-08-14 16:45        --------        d-----w-        c:\program files\iTunes 
2014-08-14 16:44 . 2014-08-14 16:45        --------        d-----w-        c:\program files (x86)\iTunes 
2014-08-14 16:44 . 2014-08-14 16:44        --------        d-----w-        c:\program files\iPod 
2014-08-14 16:07 . 2014-07-25 13:28        548352        ----a-w-        c:\windows\system32\vbscript.dll 
2014-08-11 21:32 . 2014-08-11 21:32        --------        d-----w-        c:\users\Gast\AppData\Local\Apple 
2014-08-11 21:28 . 2014-08-11 21:36        --------        d-----w-        c:\users\Gast\AppData\Roaming\DVDVideoSoft 
2014-08-05 17:20 . 2014-08-05 17:20        227728        ----a-w-        c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll 
2014-08-04 17:37 . 2014-08-04 17:37        --------        d-----w-        c:\programdata\elsterformular 
2014-08-04 17:36 . 2014-08-04 17:36        --------        d-----w-        c:\program files (x86)\ElsterFormular 
2014-08-03 10:30 . 2014-08-03 10:30        --------        d-----w-        c:\users\Gast\AppData\Local\Google 
2014-08-02 16:11 . 2014-05-14 16:23        44512        ----a-w-        c:\windows\system32\wups2.dll 
2014-08-02 16:11 . 2014-05-14 16:23        58336        ----a-w-        c:\windows\system32\wuauclt.exe 
2014-08-02 16:11 . 2014-05-14 16:23        2477536        ----a-w-        c:\windows\system32\wuaueng.dll 
2014-08-02 16:11 . 2014-05-14 16:21        2620928        ----a-w-        c:\windows\system32\wucltux.dll 
2014-08-02 16:10 . 2014-05-14 16:23        38880        ----a-w-        c:\windows\system32\wups.dll 
2014-08-02 16:10 . 2014-05-14 16:20        97792        ----a-w-        c:\windows\system32\wudriver.dll 
2014-08-02 16:10 . 2014-05-14 16:23        36320        ----a-w-        c:\windows\SysWow64\wups.dll 
2014-08-02 16:10 . 2014-05-14 16:23        700384        ----a-w-        c:\windows\system32\wuapi.dll 
2014-08-02 16:10 . 2014-05-14 16:23        581600        ----a-w-        c:\windows\SysWow64\wuapi.dll 
2014-08-02 16:10 . 2014-05-14 16:17        92672        ----a-w-        c:\windows\SysWow64\wudriver.dll 
2014-08-02 16:10 . 2014-05-14 07:23        198600        ----a-w-        c:\windows\system32\wuwebv.dll 
2014-08-02 16:10 . 2014-05-14 07:23        179656        ----a-w-        c:\windows\SysWow64\wuwebv.dll 
2014-08-02 16:10 . 2014-05-14 07:20        36864        ----a-w-        c:\windows\system32\wuapp.exe 
2014-08-02 16:10 . 2014-05-14 07:17        33792        ----a-w-        c:\windows\SysWow64\wuapp.exe 
. 
. 
. 
((((((((((((((((((((((((((((((((((((   Find3M Bericht   )))))))))))))))))))))))))))))))))))))))))))))))))))))) 
. 
2014-08-29 12:40 . 2009-08-18 10:24        23256        ----a-w-        c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 
2014-08-29 12:40 . 2013-02-10 15:32        34752        ----a-w-        c:\windows\system32\drivers\WPRO_41_2001.sys 
2014-08-22 10:44 . 2014-04-19 16:51        98216        ----a-w-        c:\windows\SysWow64\WindowsAccessBridge-32.dll 
2014-08-15 21:12 . 2013-02-10 18:03        71344        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl 
2014-08-15 21:12 . 2013-02-10 18:03        699568        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe 
2014-08-14 17:26 . 2013-02-10 16:31        99218768        ----a-w-        c:\windows\system32\MRT.exe 
2014-08-14 17:14 . 2014-06-28 17:26        297088        ----a-w-        c:\windows\SysWow64\PnkBstrB.xtr 
2014-08-14 17:14 . 2014-06-03 10:32        297088        ----a-w-        c:\windows\SysWow64\PnkBstrB.exe 
2014-08-14 17:14 . 2013-09-27 11:12        280904        ----a-w-        c:\windows\SysWow64\PnkBstrB.ex0 
2014-08-14 16:24 . 2014-06-03 13:08        647752        ----a-w-        c:\windows\system32\drivers\avckf.sys 
2014-08-14 16:24 . 2014-06-03 13:08        1260120        ----a-w-        c:\windows\system32\drivers\avc3.sys 
2014-08-14 16:24 . 2014-01-19 11:15        84848        ----a-w-        c:\windows\system32\bdsandboxuiskin.dll 
2014-08-14 16:24 . 2014-01-19 11:15        34384        ----a-w-        c:\windows\system32\bdsandboxuh.dll 
2014-08-14 16:24 . 2014-06-03 13:04        419616        ----a-w-        c:\windows\system32\drivers\trufos.sys 
2014-08-14 16:24 . 2014-01-19 11:57        74512        ----a-w-        c:\windows\system32\bdsandboxuiskin32.dll 
2014-08-03 17:05 . 2013-02-10 15:59        32320        ----a-w-        c:\windows\system32\drivers\FNETTBOH_305.SYS 
2014-06-28 18:11 . 2014-06-03 10:32        76152        ----a-w-        c:\windows\SysWow64\PnkBstrA.exe 
2014-06-18 02:18 . 2014-07-10 16:26        692736        ----a-w-        c:\windows\system32\osk.exe 
2014-06-18 01:51 . 2014-07-10 16:26        646144        ----a-w-        c:\windows\SysWow64\osk.exe 
2014-06-06 14:01 . 2014-06-06 14:01        283064        ----a-w-        c:\windows\system32\drivers\dtsoftbus01.sys 
2014-06-06 10:10 . 2014-07-10 16:26        624128        ----a-w-        c:\windows\system32\qedit.dll 
2014-06-06 09:44 . 2014-07-10 16:26        509440        ----a-w-        c:\windows\SysWow64\qedit.dll 
2014-06-05 14:45 . 2014-07-10 16:25        1460736        ----a-w-        c:\windows\system32\lsasrv.dll 
2014-06-05 14:26 . 2014-07-10 16:25        22016        ----a-w-        c:\windows\SysWow64\secur32.dll 
2014-06-05 14:25 . 2014-07-10 16:25        96768        ----a-w-        c:\windows\SysWow64\sspicli.dll 
2014-06-03 11:42 . 2014-06-03 11:45        1198049        ----a-w-        c:\windows\unins000.exe 
2014-06-03 11:33 . 2013-02-12 14:34        111016        ----a-w-        c:\windows\system32\WindowsAccessBridge-64.dll 
2014-01-05 21:09 . 2014-01-05 21:09        2759168        ----a-w-        c:\program files (x86)\GS_x64.Enabler 
. 
. 
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   )))))))))))))))))))))))))))))))))))))))) 
. 
. 
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.  
REGEDIT4 
. 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 
"AppleIEDAV"="c:\program files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe" [2013-11-15 1326408] 
"iCloudServices"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" [2013-11-20 59720] 
"Bitdefender Wallet Agent"="c:\program files\Bitdefender\Bitdefender\pmbxag.exe" [2014-08-14 568400] 
"Bitdefender Wallet Application Agent"="c:\program files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" [2014-08-14 615256] 
"Akamai NetSession Interface"="c:\users\Burak\AppData\Local\Akamai\netsession_win.exe" [2014-04-17 4672920] 
"Spotify Web Helper"="c:\users\Burak\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2014-08-21 1245752] 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-11-29 284440] 
"IMSS"="c:\program files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [2012-02-07 133400] 
"XFastUSB"="c:\program files (x86)\XFastUSB\XFastUsb.exe" [2013-02-10 5019360] 
"THX TruStudio NB Settings"="c:\program files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" [2011-05-19 909824] 
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] 
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-06-11 641704] 
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904] 
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2014-08-01 152392] 
. 
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] 
"Bitdefender Wallet Agent"="c:\program files\Bitdefender\Bitdefender\pmbxag.exe" [2014-08-14 568400] 
"Bitdefender Wallet"="c:\program files\Bitdefender\Bitdefender\pwdmanui.exe" [2014-08-14 1002048] 
"Bitdefender Wallet Application Agent"="c:\program files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" [2014-08-14 615256] 
. 
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ 
Sitecom Wireless Utility.lnk - c:\program files (x86)\Sitecom\Common\WLANUtil.exe -s [2013-7-29 1626112] 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] 
"ConsentPromptBehaviorAdmin"= 0 (0x0) 
"ConsentPromptBehaviorUser"= 3 (0x3) 
"EnableLUA"= 0 (0x0) 
"EnableUIADesktopToggle"= 0 (0x0) 
"PromptOnSecureDesktop"= 0 (0x0) 
. 
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] 
"LoadAppInit_DLLs"=1 (0x1) 
. 
R2 1a34a8e0;GS.Supporter;c:\windows\system32\rundll32.exe;c:\windows\SYSNATIVE\rundll32.exe [x] 
R2 ASGT;ASGT;c:\windows\SysWOW64\ASGT.exe;c:\windows\SysWOW64\ASGT.exe [x] 
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] 
R3 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys;c:\windows\SYSNATIVE\DRIVERS\avckf.sys [x] 
R3 bdfwfpf_pc;bdfwfpf_pc;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [x] 
R3 BDSandBox;BDSandBox;c:\windows\system32\drivers\bdsandbox.sys;c:\windows\SYSNATIVE\drivers\bdsandbox.sys [x] 
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x] 
R3 BRDriver64;BRDriver64;c:\programdata\BitRaider\BRDriver64.sys;c:\programdata\BitRaider\BRDriver64.sys [x] 
R3 BRSptSvc;BitRaider Mini-Support Service;c:\programdata\BitRaider\BRSptSvc.exe;c:\programdata\BitRaider\BRSptSvc.exe [x] 
R3 cpuz136;cpuz136;c:\windows\TEMP\cpuz136\cpuz136_x64.sys;c:\windows\TEMP\cpuz136\cpuz136_x64.sys [x] 
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] 
R3 DrvAgent64;DrvAgent64;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS [x] 
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x] 
R3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS;c:\windows\SYSNATIVE\drivers\FNETTBOH_305.SYS [x] 
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] 
R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys;c:\windows\SYSNATIVE\DRIVERS\MijXfilt.sys [x] 
R3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x] 
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x] 
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] 
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] 
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] 
R3 USBTINSP;TI-Nspire(TM) Handheld or TI Network Bridge Device Driver;c:\windows\system32\DRIVERS\tinspusb.sys;c:\windows\SYSNATIVE\DRIVERS\tinspusb.sys [x] 
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x] 
R3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x] 
R3 VBoxUSB;VirtualBox USB;c:\windows\system32\Drivers\VBoxUSB.sys;c:\windows\SYSNATIVE\Drivers\VBoxUSB.sys [x] 
R3 xhunter1;xhunter1;c:\windows\xhunter1.sys;c:\windows\xhunter1.sys [x] 
R4 BdDesktopParental;Bitdefender Desktop Parental Control;c:\program files\Bitdefender\Bitdefender\bdparentalservice.exe;c:\program files\Bitdefender\Bitdefender\bdparentalservice.exe [x] 
S0 asahci64;asahci64;c:\windows\system32\DRIVERS\asahci64.sys;c:\windows\SYSNATIVE\DRIVERS\asahci64.sys [x] 
S0 AsrRamDisk;AsrRamDisk;c:\windows\system32\DRIVERS\AsrRamDisk.sys;c:\windows\SYSNATIVE\DRIVERS\AsrRamDisk.sys [x] 
S0 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys;c:\windows\SYSNATIVE\DRIVERS\avc3.sys [x] 
S0 gzflt;gzflt;c:\windows\system32\DRIVERS\gzflt.sys;c:\windows\SYSNATIVE\DRIVERS\gzflt.sys [x] 
S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x] 
S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AsrAppCharger.sys [x] 
S1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [x] 
S1 bdfwfpf;bdfwfpf;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [x] 
S1 BDVEDISK;BDVEDISK;c:\windows\system32\DRIVERS\bdvedisk.sys;c:\windows\SYSNATIVE\DRIVERS\bdvedisk.sys [x] 
S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS;c:\windows\SYSNATIVE\drivers\FNETURPX.SYS [x] 
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] 
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x] 
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] 
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] 
S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x] 
S2 ISCTAgent;ISCT Always Updated Agent;c:\program files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe;c:\program files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [x] 
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] 
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x] 
S2 RalinkRegistryWriter64;RalinkRegistryWriter64;c:\program files (x86)\Sitecom\Common\RaRegistry64.exe;c:\program files (x86)\Sitecom\Common\RaRegistry64.exe [x] 
S2 SafeBox;SafeBox;c:\program files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe;c:\program files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [x] 
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x] 
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] 
S2 UPDATESRV;Bitdefender Desktop Update Service;c:\program files\Bitdefender\Bitdefender\updatesrv.exe;c:\program files\Bitdefender\Bitdefender\updatesrv.exe [x] 
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] 
S3 avchv;avchv Function Driver;c:\windows\system32\DRIVERS\avchv.sys;c:\windows\SYSNATIVE\DRIVERS\avchv.sys [x] 
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] 
S3 ikbevent;Intel Upper keyboard Class Filter Driver;c:\windows\system32\DRIVERS\ikbevent.sys;c:\windows\SYSNATIVE\DRIVERS\ikbevent.sys [x] 
S3 imsevent;Intel Upper Mouse Class Filter Driver;c:\windows\system32\DRIVERS\imsevent.sys;c:\windows\SYSNATIVE\DRIVERS\imsevent.sys [x] 
S3 ISCT;Intel(R) Smart Connect Technology Device Driver;c:\windows\system32\DRIVERS\ISCTD64.sys;c:\windows\SYSNATIVE\DRIVERS\ISCTD64.sys [x] 
S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x] 
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x] 
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x] 
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] 
S3 ScpVBus;Scp Virtual Bus Driver;c:\windows\system32\DRIVERS\ScpVBus.sys;c:\windows\SYSNATIVE\DRIVERS\ScpVBus.sys [x] 
S3 WPRO_41_2001;WinPcap Packet Driver (WPRO_41_2001);c:\windows\system32\drivers\WPRO_41_2001.sys;c:\windows\SYSNATIVE\drivers\WPRO_41_2001.sys [x] 
. 
. 
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 
2014-08-26 16:38        1096520        ----a-w-        c:\program files (x86)\Google\Chrome\Application\37.0.2062.94\Installer\chrmstp.exe 
. 
Inhalt des "geplante Tasks" Ordners 
. 
2014-08-28 c:\windows\Tasks\Adobe Flash Player Updater.job 
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-10 21:12] 
. 
2014-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job 
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-28 20:37] 
. 
2014-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job 
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-28 20:37] 
. 
. 
--------- X64 Entries ----------- 
. 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox1] 
@="{152C96EB-288E-4EDC-B7C6-D21F8250ADF3}" 
[HKEY_CLASSES_ROOT\CLSID\{152C96EB-288E-4EDC-B7C6-D21F8250ADF3}] 
2013-07-08 13:59        206352        ----a-w-        c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox2] 
@="{342DAA0B-D796-460D-8566-901E08A1CCAD}" 
[HKEY_CLASSES_ROOT\CLSID\{342DAA0B-D796-460D-8566-901E08A1CCAD}] 
2013-07-08 13:59        206352        ----a-w-        c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox3] 
@="{57595DAE-1AE1-4D97-A49E-67CBB53B52DF}" 
[HKEY_CLASSES_ROOT\CLSID\{57595DAE-1AE1-4D97-A49E-67CBB53B52DF}] 
2013-07-08 13:59        206352        ----a-w-        c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox4] 
@="{33816773-98AE-4723-ADE0-EBE54C8B5A67}" 
[HKEY_CLASSES_ROOT\CLSID\{33816773-98AE-4723-ADE0-EBE54C8B5A67}] 
2013-07-08 13:59        206352        ----a-w-        c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-10-17 13307496] 
"THXCfg64"="c:\windows\system32\THXCfg64.dll" [2011-05-13 26624] 
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184] 
"Bdagent"="c:\program files\Bitdefender\Bitdefender\bdagent.exe" [2014-08-14 1743088] 
. 
------- Zusätzlicher Suchlauf ------- 
. 
uLocal Page = c:\windows\system32\blank.htm 
uStart Page = about:blank 
mStart Page = about:blank 
mLocal Page = c:\windows\SysWOW64\blank.htm 
uInternet Settings,ProxyOverride = *.local;<local> 
IE: An OneNote s&enden - c:\progra~1\MICROS~4\Office15\ONBttnIE.dll/105 
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000 
IE: Free YouTube to MP3 Converter - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm 
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~4\Office15\EXCEL.EXE/3000 
IE: Se&nd to OneNote - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105 
IE: {{c0e8ae32-0758-4c8d-ab71-23b361fe8964} - c:\users\Burak\AppData\Local\Temp\ie_script.htm 
IE: {{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - 
Trusted Zone: aeriagames.com 
Trusted Zone: qq.com\cache.tv 
Trusted Zone: qq.com\qqlivecaption 
Trusted Zone: qq.com\qqlivehabit 
Trusted Zone: qq.com\qqlivesearch 
Trusted Zone: qq.com\video_1 
FF - ProfilePath - c:\users\Burak\AppData\Roaming\Mozilla\Firefox\Profiles\0g8s9jjg.default-1362844820888\ 
FF - prefs.js: browser.search.selectedEngine - Google 
FF - prefs.js: browser.startup.homepage - google.de 
FF - prefs.js: keyword.URL -  
FF - prefs.js: network.proxy.ftp - 37.187.101.139 
FF - prefs.js: network.proxy.ftp_port - 8118 
FF - prefs.js: network.proxy.gopher - 37.187.101.139 
FF - prefs.js: network.proxy.gopher_port - 8118 
FF - prefs.js: network.proxy.http - 37.187.101.139 
FF - prefs.js: network.proxy.http_port - 8118 
FF - prefs.js: network.proxy.socks - 37.187.101.139 
FF - prefs.js: network.proxy.socks_port - 8118 
FF - prefs.js: network.proxy.ssl - 37.187.101.139 
FF - prefs.js: network.proxy.ssl_port - 8118 
FF - prefs.js: network.proxy.type - 0 
FF - user.js: extensions.mysearchdial.hmpg - true 
FF - user.js: extensions.mysearchdial.hmpgUrl - hxxp://start.mysearchdial.com/?f=1&a=irmsd1103&cd=2XzuyEtN2Y1L1Qzu0B0CyD0F0FyEyCtDtA0EtByEyByCzy0FtN0D0Tzu0SyCzzzztN1L2XzutBtFtBtFtCtAtFtCtAtAzztN1L1CzutCtD1B1P1R&cr=1977847028&ir= 
FF - user.js: extensions.mysearchdial.dfltSrch - true 
FF - user.js: extensions.mysearchdial.srchPrvdr - Mysearchdial 
FF - user.js: extensions.mysearchdial.dnsErr - true 
FF - user.js: extensions.mysearchdial_i.newTab - false 
FF - user.js: extensions.mysearchdial.newTabUrl - hxxp://start.mysearchdial.com/?f=2&a=irmsd1103&cd=2XzuyEtN2Y1L1Qzu0B0CyD0F0FyEyCtDtA0EtByEyByCzy0FtN0D0Tzu0SyCzzzztN1L2XzutBtFtBtFtCtAtFtCtAtAzztN1L1CzutCtD1B1P1R&cr=1977847028&ir= 
FF - user.js: extensions.mysearchdial.tlbrSrchUrl - hxxp://start.mysearchdial.com/?f=3&a=irmsd1103&cd=2XzuyEtN2Y1L1Qzu0B0CyD0F0FyEyCtDtA0EtByEyByCzy0FtN0D0Tzu0SyCzzzztN1L2XzutBtFtBtFtCtAtFtCtAtAzztN1L1CzutCtD1B1P1R&cr=1977847028&ir=&q= 
FF - user.js: extensions.mysearchdial.id - BC5FF4603E24769F 
FF - user.js: extensions.mysearchdial.instlDay - 16028 
FF - user.js: extensions.mysearchdial.vrsn - 1.8.21.0 
FF - user.js: extensions.mysearchdial.vrsni - 1.8.21.0 
FF - user.js: extensions.mysearchdial_i.vrsnTs - 1.8.21.00:23 
FF - user.js: extensions.mysearchdial.prtnrId - mysearchdial 
FF - user.js: extensions.mysearchdial.prdct - mysearchdial 
FF - user.js: extensions.mysearchdial.aflt - irmsd1103 
FF - user.js: extensions.mysearchdial_i.smplGrp - none 
FF - user.js: extensions.mysearchdial.tlbrId - base 
FF - user.js: extensions.mysearchdial.instlRef -  
FF - user.js: extensions.mysearchdial.dfltLng -  
FF - user.js: extensions.mysearchdial.appId - {CA5CAA63-B27C-4963-9BEC-CB16A36D56F8} 
FF - user.js: extensions.mysearchdial.excTlbr - false 
FF - user.js: extensions.mysearchdial_i.hmpg - true 
FF - user.js: extensions.mysearchdial.cr - 1977847028 
FF - user.js: extensions.mysearchdial.cd - 2XzuyEtN2Y1L1Qzu0B0CyD0F0FyEyCtDtA0EtByEyByCzy0FtN0D0Tzu0SyCzzzztN1L2XzutBtFtBtFtCtAtFtCtAtAzztN1L1CzutCtD1B1P1R 
FF - user.js: extensions.irmysearch.aflt - irmsd1103 
FF - user.js: extensions.irmysearch.instlRef -  
FF - user.js: extensions.irmysearch.cr - 1977847028 
FF - user.js: extensions.irmysearch.cd - 2XzuyEtN2Y1L1Qzu0B0CyD0F0FyEyCtDtA0EtByEyByCzy0FtN0D0Tzu0SyCzzzztN1L2XzutBtFtBtFtCtAtFtCtAtAzztN1L1CzutCtD1B1P1R 
. 
- - - - Entfernte verwaiste Registrierungseinträge - - - - 
. 
BHO-{31ad400d-1b06-4e33-a59a-90c2c140cba0} - (no file) 
Wow6432Node-HKCU-Run-ASRockXTU - (no file) 
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start 
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file) 
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file) 
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file) 
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file) 
. 
. 
. 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc] 
"ImagePath"="c:\windows\system32\GameMon.des -service" 
. 
--------------------- Gesperrte Registrierungsschluessel --------------------- 
. 
[HKEY_USERS\S-1-5-21-1145914912-1038568159-3068141755-1000_Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}] 
@Denied: (Full) (Everyone) 
@Allowed: (Read) (RestrictedCode) 
"scansk"=hex(0):96,20,0c,4f,dc,d4,e0,8a,2e,bf,4e,a8,c3,41,14,15,d1,8d,6c,72,4d, 
   b4,fa,99,38,d9,89,4f,21,b6,26,62,69,99,86,fc,70,b9,4f,1c,00,00,00,00,00,00,\ 
. 
[HKEY_USERS\S-1-5-21-1145914912-1038568159-3068141755-1000_Classes\Wow6432Node\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}] 
@Denied: (Full) (Everyone) 
@Allowed: (Read) (RestrictedCode) 
"scansk"=hex(0):51,e9,5f,c2,9c,db,51,fa,39,b0,57,b0,11,23,d7,05,dc,bc,e3,05,35, 
   f4,32,fe,99,da,a2,4c,71,f9,6d,ab,00,cd,bc,d1,c0,2c,b7,16,00,00,00,00,00,00,\ 
. 
[HKEY_USERS\S-1-5-21-1145914912-1038568159-3068141755-1000_Classes\Wow6432Node\CLSID\{c42f1377-85b1-4fc0-b5f0-ed18f2b1b367}] 
@Denied: (Full) (Everyone) 
@Allowed: (Read) (RestrictedCode) 
"Model"=dword:000000c3 
"Therad"=dword:0000001a 
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a, 
   1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\ 
. 
[HKEY_USERS\S-1-5-21-1145914912-1038568159-3068141755-1000_Classes\Wow6432Node\CLSID\{c4e1e99d-4d5c-4d78-a218-dd0ff12571a4}] 
@Denied: (Full) (Everyone) 
@Allowed: (Read) (RestrictedCode) 
"Model"=dword:00000046 
"Therad"=dword:0000001e 
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26, 
   38,95,44,bc,f4,23,4f,c9,2a,f3,ff,44,0b,f3,8c,70,4a,af,68,3b,8f,70,42,b6,14,\ 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] 
@Denied: (A 2) (Everyone) 
@="FlashBroker" 
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe,-101" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] 
"Enabled"=dword:00000001 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] 
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] 
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] 
@Denied: (A 2) (Everyone) 
@="IFlashBroker5" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] 
@="{00020424-0000-0000-C000-000000000046}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] 
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" 
"Version"="1.0" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] 
@Denied: (A 2) (Everyone) 
@="FlashBroker" 
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe,-101" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] 
"Enabled"=dword:00000001 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] 
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] 
@Denied: (A 2) (Everyone) 
@="Shockwave Flash Object" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx" 
"ThreadingModel"="Apartment" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] 
@="0" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] 
@="ShockwaveFlash.ShockwaveFlash.14" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx, 1" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] 
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] 
@="1.0" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] 
@="ShockwaveFlash.ShockwaveFlash" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] 
@Denied: (A 2) (Everyone) 
@="Macromedia Flash Factory Object" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx" 
"ThreadingModel"="Apartment" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] 
@="FlashFactory.FlashFactory.1" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] 
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx, 1" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] 
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] 
@="1.0" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] 
@="FlashFactory.FlashFactory" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] 
@Denied: (A 2) (Everyone) 
@="IFlashBroker5" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] 
@="{00020424-0000-0000-C000-000000000046}" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] 
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" 
"Version"="1.0" 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] 
@Denied: (A) (Everyone) 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] 
@Denied: (A) (Everyone) 
. 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] 
@Denied: (Full) (Everyone) 
. 
Zeit der Fertigstellung: 2014-08-29  15:06:37 
ComboFix-quarantined-files.txt  2014-08-29 13:06 
. 
Vor Suchlauf: 17 Verzeichnis(se), 484.848.562.176 Bytes frei 
Nach Suchlauf: 21 Verzeichnis(se), 484.349.448.192 Bytes frei 
. 
- - End Of File - - 5B07EC3C95C02FFBEF24DAB0ECB7ADA2 
A36C5E4F47E84449FF07ED3517B43A31      |