|   | Hardcore114 | 22.02.2015 11:12 |  
 Ich habe ein kleines Problem. Ich habe mein Avast ausgestellt und den Scan gestartet. Dann kam die meldung ich solle mein AVG Antivirus free ausschalten welches ich aber weder noch auf dem Rechner habe noch im Taskmanager zu finden ist. Darf ich von meinem Taskmanager und der Meldung einen Screenshot anhängen? Im Taskmanager sieht man auf dem Screenshot auch die (gestern noch cmd.exe *32 heute die cmd.3XE *32) auch zu finden ist jetzt eine "NirCmd.3XE *32" 
Edit: oh tut mir leid: "Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen." habe ich vergessen. ich werde die Meldung jetzt wegklicken und den Log posten.     Code: 
 ComboFix 15-02-16.01 - David 22.02.2015  11:21:50.1.4 - x64Microsoft Windows 7 Professional   6.1.7601.1.1252.49.1031.18.8174.6468 [GMT 1:00]
 ausgeführt von:: c:\users\David\Desktop\ComboFix.exe
 AV: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
 SP: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
 SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 .
 .
 ((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
 .
 .
 c:\windows\IsUn0407.exe
 c:\windows\msdownld.tmp
 D:\install.exe
 .
 .
 (((((((((((((((((((((((   Dateien erstellt von 2015-01-22 bis 2015-02-22  ))))))))))))))))))))))))))))))
 .
 .
 2015-02-22 10:32 . 2015-02-22 10:32        --------        d-----w-        c:\users\Default\AppData\Local\temp
 2015-02-22 10:12 . 2015-02-22 10:12        75888        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{78173DDB-4650-4B72-A94C-1D47E76E4D4A}\offreg.dll
 2015-02-21 19:57 . 2015-02-21 20:03        --------        d-----w-        C:\FRST
 2015-02-21 11:28 . 2015-02-21 11:28        --------        d-----w-        c:\users\David\AppData\Roaming\AVAST Software
 2015-02-21 11:27 . 2015-02-21 11:27        116728        ----a-w-        c:\windows\system32\drivers\aswStm.sys
 2015-02-21 11:27 . 2015-02-21 11:27        267632        ----a-w-        c:\windows\system32\drivers\aswVmm.sys
 2015-02-21 11:27 . 2015-02-21 11:27        65776        ----a-w-        c:\windows\system32\drivers\aswRvrt.sys
 2015-02-21 11:27 . 2015-02-21 11:27        436624        ----a-w-        c:\windows\system32\drivers\aswSP.sys
 2015-02-21 11:27 . 2015-02-21 11:27        87912        ----a-w-        c:\windows\system32\drivers\aswmonflt.sys
 2015-02-21 11:27 . 2015-02-21 11:27        93568        ----a-w-        c:\windows\system32\drivers\aswRdr2.sys
 2015-02-21 11:27 . 2015-02-21 11:27        29208        ----a-w-        c:\windows\system32\drivers\aswHwid.sys
 2015-02-21 11:27 . 2015-02-21 11:27        1050432        ----a-w-        c:\windows\system32\drivers\aswsnx.sys
 2015-02-21 11:27 . 2015-02-21 11:27        364512        ----a-w-        c:\windows\system32\aswBoot.exe
 2015-02-21 11:27 . 2015-02-21 11:27        43152        ----a-w-        c:\windows\avastSS.scr
 2015-02-21 11:26 . 2015-02-21 11:26        --------        d-----w-        c:\program files\AVAST Software
 2015-02-21 11:24 . 2015-02-21 11:26        --------        d-----w-        c:\programdata\AVAST Software
 2015-02-20 09:50 . 2015-01-29 09:07        11910896        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{78173DDB-4650-4B72-A94C-1D47E76E4D4A}\mpengine.dll
 2015-02-17 17:34 . 2015-01-09 03:14        91136        ----a-w-        c:\windows\system32\wdi.dll
 2015-02-17 17:34 . 2015-01-09 03:14        950272        ----a-w-        c:\windows\system32\perftrack.dll
 2015-02-17 17:34 . 2015-01-09 03:14        29696        ----a-w-        c:\windows\system32\powertracker.dll
 2015-02-17 17:34 . 2015-01-09 02:48        76800        ----a-w-        c:\windows\SysWow64\wdi.dll
 2015-02-17 16:23 . 2009-02-22 14:17        1246231        ----a-w-        C:\DUKE3D.EXE
 2015-02-17 13:23 . 2015-02-17 13:23        --------        d-----w-        c:\users\David\AppData\Roaming\Atari
 2015-02-17 12:49 . 2015-02-17 12:49        --------        d-----w-        c:\program files (x86)\Portable
 2015-02-16 00:56 . 2015-02-16 00:56        --------        d-----w-        c:\users\David\AppData\Roaming\OpenOffice
 2015-02-16 00:55 . 2015-02-16 00:55        --------        d-----w-        c:\program files (x86)\OpenOffice 4
 2015-02-13 05:46 . 2015-01-23 04:42        814080        ----a-w-        c:\windows\system32\jscript9diag.dll
 2015-02-13 05:46 . 2015-01-23 04:41        6041600        ----a-w-        c:\windows\system32\jscript9.dll
 2015-02-13 05:46 . 2015-01-23 03:43        620032        ----a-w-        c:\windows\SysWow64\jscript9diag.dll
 2015-02-13 05:46 . 2015-01-23 03:17        4300800        ----a-w-        c:\windows\SysWow64\jscript9.dll
 2015-02-12 09:47 . 2015-02-12 10:28        --------        d-----w-        C:\Keen
 2015-02-12 09:26 . 2015-02-12 09:27        --------        d-----w-        C:\frogger
 2015-02-11 10:04 . 2015-01-13 03:10        1424384        ----a-w-        c:\windows\system32\WindowsCodecs.dll
 2015-02-11 10:03 . 2015-01-09 02:03        3201536        ----a-w-        c:\windows\system32\win32k.sys
 2015-02-07 00:57 . 2015-02-07 00:57        --------        d-----w-        c:\users\David\AppData\Roaming\BANDISOFT
 2015-02-07 00:56 . 2015-02-07 00:56        --------        d-----w-        c:\program files (x86)\Bandicam
 2015-01-29 18:08 . 2015-01-29 18:08        --------        d-----w-        C:\tv
 2015-01-29 18:00 . 2002-05-21 07:37        131072        ----a-w-        c:\windows\SysWow64\eax.dll
 2015-01-29 17:57 . 2015-02-21 20:55        --------        d-----w-        C:\S2
 .
 .
 .
 ((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
 .
 2015-02-12 02:02 . 2013-11-09 15:25        116773704        ----a-w-        c:\windows\system32\MRT.exe
 2015-02-05 04:58 . 2013-06-29 11:18        71344        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
 2015-02-05 04:58 . 2013-06-29 11:18        701616        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
 2015-01-08 00:40 . 2015-01-08 00:40        4102        ----a-w-        c:\windows\SysWow64\ealregsnapshot1.reg
 2014-12-22 23:41 . 2010-11-21 03:27        298120        ------w-        c:\windows\system32\MpSigStub.exe
 2014-12-19 03:06 . 2015-01-14 20:32        210432        ----a-w-        c:\windows\system32\profsvc.dll
 2014-12-19 01:46 . 2015-01-14 20:32        141312        ----a-w-        c:\windows\system32\drivers\mrxdav.sys
 2014-12-11 17:47 . 2015-01-14 20:32        62976        ----a-w-        c:\windows\system32\TSWbPrxy.exe
 2014-12-06 04:17 . 2015-01-14 20:32        303616        ----a-w-        c:\windows\system32\nlasvc.dll
 2014-12-06 03:50 . 2015-01-14 20:32        52224        ----a-w-        c:\windows\SysWow64\nlaapi.dll
 2014-12-06 03:50 . 2015-01-14 20:32        156672        ----a-w-        c:\windows\SysWow64\ncsi.dll
 .
 .
 ((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
 .
 .
 *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
 REGEDIT4
 .
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "KPeerNexonEU"="c:\nexon\NEXON_EU_Downloader\nxEULauncher.exe" [2013-07-04 438272]
 "icq"="c:\users\David\AppData\Roaming\ICQM\icq.exe" [2013-07-07 28698984]
 "DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2012-10-23 3108480]
 "Akamai NetSession Interface"="c:\users\David\AppData\Local\Akamai\netsession_win.exe" [2014-04-17 4672920]
 "uTorrent"="c:\users\David\AppData\Roaming\uTorrent\uTorrent.exe" [2015-01-21 1374032]
 "Messenger (Yahoo!)"="c:\progra~2\Yahoo!\Messenger\YahooMessenger.exe" [2012-05-25 6595928]
 .
 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
 "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
 "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-02-21 5227112]
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
 "ConsentPromptBehaviorAdmin"= 5 (0x5)
 "ConsentPromptBehaviorUser"= 3 (0x3)
 "EnableUIADesktopToggle"= 0 (0x0)
 "SoftwareSASGeneration"= 1 (0x1)
 .
 [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
 "mixer1"=wdmaud.drv
 .
 R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
 R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
 R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
 R3 ArcService;Arc Service;c:\program files (x86)\Perfect World Entertainment\Arc\ArcService.exe;c:\program files (x86)\Perfect World Entertainment\Arc\ArcService.exe [x]
 R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
 R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
 R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
 R3 Origin Client Service;Origin Client Service;c:\program files (x86)\Origin\OriginClientService.exe;c:\program files (x86)\Origin\OriginClientService.exe [x]
 R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
 R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
 R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
 R3 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe;c:\program files (x86)\Tunngle\TnglCtrl.exe [x]
 R3 vmci;vmci;c:\windows\system32\DRIVERS\vmci.sys;c:\windows\SYSNATIVE\DRIVERS\vmci.sys [x]
 R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
 R3 xhunter1;xhunter1;c:\windows\xhunter1.sys;c:\windows\xhunter1.sys [x]
 S0 aswRvrt;avast! Revert; [x]
 S0 aswVmm;avast! VM Monitor; [x]
 S0 ESLWireAC;ESLWireAC;c:\windows\system32\drivers\ESLWireACD.sys;c:\windows\SYSNATIVE\drivers\ESLWireACD.sys [x]
 S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
 S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
 S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
 S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
 S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
 S2 EslWireHelper;ESL Wire Helper Service;c:\program files\EslWire\service\WireHelperSvc.exe;c:\program files\EslWire\service\WireHelperSvc.exe [x]
 S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [x]
 S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
 S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
 S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys;c:\windows\SYSNATIVE\DRIVERS\tap0901t.sys [x]
 .
 .
 Inhalt des "geplante Tasks" Ordners
 .
 2015-02-22 c:\windows\Tasks\Adobe Flash Player Updater.job
 - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-29 04:58]
 .
 2015-02-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
 - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-07-12 10:35]
 .
 2015-02-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
 - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-07-12 10:35]
 .
 .
 --------- X64 Entries -----------
 .
 .
 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
 @="{472083B0-C522-11CF-8763-00608CC02F24}"
 [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
 2015-02-21 11:27        860984        ----a-w-        c:\program files\AVAST Software\Avast\ashShA64.dll
 .
 ------- Zusätzlicher Suchlauf -------
 .
 uLocal Page = c:\windows\system32\blank.htm
 uStart Page = hxxp://www.google.com
 mLocal Page = c:\windows\SysWOW64\blank.htm
 uInternet Settings,ProxyOverride = <local>
 Trusted Zone: aeriagames.com
 Trusted Zone: clonewarsadventures.com
 Trusted Zone: freerealms.com
 Trusted Zone: soe.com
 Trusted Zone: sony.com
 TCP: DhcpNameServer = 192.168.0.1
 TCP: Interfaces\{FA6B3B38-2C61-41F2-9861-3594F3DD8B35}: DhcpNameServer = 192.168.0.1
 FF - ProfilePath - c:\users\David\AppData\Roaming\Mozilla\Firefox\Profiles\4to1r28p.default-1405135581555\
 .
 - - - - Entfernte verwaiste Registrierungseinträge - - - -
 .
 HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
 AddRemove-GOGPACKBEYONDGOODANDEVIL_is1 - c:\gog games\Beyond Good and Evil\unins000.exe
 AddRemove-GOGPACKSETTLERS2GOLD_is1 - c:\gog games\Settlers 2 GOLD\unins000.exe
 AddRemove-ThiefGoldDeinstallKey - c:\games\ThiefG\thiefalphaIIu.log
 AddRemove-VP3 Codec for Video for Windows - c:\windows\system32\Uninstal.exe
 .
 .
 .
 --------------------- Gesperrte Registrierungsschluessel ---------------------
 .
 [HKEY_USERS\S-1-5-21-3260951588-4144526485-2639087776-1000\Software\SecuROM\License information*]
 "datasecu"=hex:cd,6f,ff,14,be,02,60,52,fb,33,d2,45,d9,42,7c,89,76,fa,b3,a2,e3,
 99,5b,83,67,05,9c,86,40,e1,df,fe,4b,d8,bb,03,b5,12,ac,90,52,c0,09,10,49,bf,\
 "rkeysecu"=hex:b0,26,6f,c5,a1,25,3b,43,be,47,b0,95,f9,41,fe,38
 .
 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
 @Denied: (A 2) (Everyone)
 @="FlashBroker"
 "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe,-101"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
 "Enabled"=dword:00000001
 .
 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
 @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
 @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
 @Denied: (A 2) (Everyone)
 @="IFlashBroker6"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
 @="{00020424-0000-0000-C000-000000000046}"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
 @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
 "Version"="1.0"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
 @Denied: (A 2) (Everyone)
 @="FlashBroker"
 "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe,-101"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
 "Enabled"=dword:00000001
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
 @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
 @Denied: (A 2) (Everyone)
 @="Shockwave Flash Object"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx"
 "ThreadingModel"="Apartment"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
 @="0"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
 @="ShockwaveFlash.ShockwaveFlash.16"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
 @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
 @="1.0"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
 @="ShockwaveFlash.ShockwaveFlash"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
 @Denied: (A 2) (Everyone)
 @="Macromedia Flash Factory Object"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx"
 "ThreadingModel"="Apartment"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
 @="FlashFactory.FlashFactory.1"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
 @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
 @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
 @="1.0"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
 @="FlashFactory.FlashFactory"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
 @Denied: (A 2) (Everyone)
 @="IFlashBroker6"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
 @="{00020424-0000-0000-C000-000000000046}"
 .
 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
 @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
 "Version"="1.0"
 .
 [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
 @Denied: (Full) (Everyone)
 .
 Zeit der Fertigstellung: 2015-02-22  11:35:06
 ComboFix-quarantined-files.txt  2015-02-22 10:35
 .
 Vor Suchlauf: 32 Verzeichnis(se), 77.824.868.352 Bytes frei
 Nach Suchlauf: 37 Verzeichnis(se), 82.253.201.408 Bytes frei
 .
 - - End Of File - - 572269072B76F4DF472F4702BBF6F41C
 A36C5E4F47E84449FF07ED3517B43A31
 |