ahoernchen | 17.03.2016 17:13 | Hallo,
habe Combofix durchlaufen lassen. Avast war allerdings nicht offen, auch wenn es angezeigt wurde - ein Neustart wurde auch nicht durchgeführt. Hier die Logdatei Code:
ComboFix 16-03-14.01 - Philip 17.03.2016 16:52:01.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3070.1571 [GMT 1:00]
ausgeführt von:: c:\users\Philip\Desktop\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
/wow section - STAGE 3
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\psfBEEB.tmp
.
.
((((((((((((((((((((((( Dateien erstellt von 2016-02-17 bis 2016-03-17 ))))))))))))))))))))))))))))))
.
.
2016-03-17 16:02 . 2016-03-17 16:02 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-03-17 15:51 . 2016-03-17 15:51 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FDD43209-B2E1-4E96-BFE0-6F53BC1C317B}\offreg.2828.dll
2016-03-16 08:09 . 2016-03-16 16:26 -------- d-----w- C:\FRST
2016-03-15 17:37 . 2016-03-15 17:37 -------- d-----w- C:\quarantäne
2016-03-15 16:26 . 2016-03-16 15:39 -------- d-----w- c:\program files (x86)\AdwCleaner
2016-03-15 15:13 . 2016-03-02 14:59 11249080 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FDD43209-B2E1-4E96-BFE0-6F53BC1C317B}\mpengine.dll
2016-03-11 14:43 . 2016-03-11 14:43 -------- d-----w- c:\users\Philip\AppData\Roaming\MCorp
2016-03-11 13:42 . 2016-03-11 14:03 -------- d-----w- c:\users\Philip\AppData\Local\app
2016-03-11 13:40 . 2016-03-16 16:12 -------- d-----w- c:\program files (x86)\MPC Cleaner
2016-03-11 10:49 . 2016-03-16 16:13 -------- d-----w- c:\users\Philip\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-03-11 10:49 . 2016-03-11 10:49 -------- d-----w- C:\extensions
2016-03-10 08:59 . 2016-02-08 20:51 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2016-03-10 08:58 . 2016-02-11 18:44 3938240 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2016-03-10 08:57 . 2016-02-05 01:19 381440 ----a-w- c:\windows\system32\mfds.dll
2016-02-17 16:54 . 2016-02-17 16:54 -------- d-----w- c:\users\Philip\AppData\Roaming\Xilisoft
2016-02-17 16:48 . 2016-02-17 16:48 -------- d-----w- c:\program files (x86)\Xilisoft
2016-02-17 12:00 . 2016-02-18 08:58 -------- d-----w- c:\users\Philip\AppData\Roaming\Windows Live Writer
2016-02-17 12:00 . 2016-02-17 12:00 -------- d-----w- c:\users\Philip\AppData\Local\Windows Live Writer
2016-02-17 11:56 . 2016-02-17 11:56 -------- d-----w- c:\windows\de
2016-02-17 11:55 . 2016-02-17 11:55 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2016-02-17 11:53 . 2016-02-17 11:53 -------- d-----w- c:\program files\Windows Live
2016-02-17 11:53 . 2016-02-17 11:55 -------- d-----w- c:\program files (x86)\Windows Live
2016-02-17 11:51 . 2010-06-02 03:55 77656 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2016-02-17 11:51 . 2010-06-02 03:55 74072 ----a-w- c:\windows\SysWow64\XAPOFX1_5.dll
2016-02-17 11:51 . 2010-06-02 03:55 527192 ----a-w- c:\windows\SysWow64\XAudio2_7.dll
2016-02-17 11:51 . 2010-06-02 03:55 518488 ----a-w- c:\windows\system32\XAudio2_7.dll
2016-02-17 11:51 . 2010-05-26 10:41 2526056 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2016-02-17 11:51 . 2010-05-26 10:41 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll
2016-02-17 11:51 . 2010-05-26 10:41 276832 ----a-w- c:\windows\system32\d3dx11_43.dll
2016-02-17 11:51 . 2010-05-26 10:41 248672 ----a-w- c:\windows\SysWow64\d3dx11_43.dll
2016-02-17 11:51 . 2009-09-04 16:29 453456 ----a-w- c:\windows\SysWow64\d3dx10_42.dll
2016-02-17 11:51 . 2009-09-04 16:29 523088 ----a-w- c:\windows\system32\d3dx10_42.dll
2016-02-17 11:48 . 2016-02-17 11:48 94040 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\17a464981d1697903\DSETUP.dll
2016-02-17 11:48 . 2016-02-17 11:48 525656 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\17a464981d1697903\DXSETUP.exe
2016-02-17 11:48 . 2016-02-17 11:48 1691480 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\17a464981d1697903\dsetup32.dll
2016-02-17 11:48 . 2016-02-17 11:48 89944 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\1450f38a1d1697902\DSETUP.dll
2016-02-17 11:48 . 2016-02-17 11:48 537432 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\1450f38a1d1697902\DXSETUP.exe
2016-02-17 11:48 . 2016-02-17 11:48 1801048 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\1450f38a1d1697902\dsetup32.dll
2016-02-17 11:48 . 2016-02-17 11:48 89944 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\120e7d5f1d1697901\DSETUP.dll
2016-02-17 11:48 . 2016-02-17 11:48 537432 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\120e7d5f1d1697901\DXSETUP.exe
2016-02-17 11:48 . 2016-02-17 11:48 1801048 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\120e7d5f1d1697901\dsetup32.dll
2016-02-17 11:48 . 2016-02-25 17:14 -------- d-----w- c:\users\Philip\AppData\Local\Windows Live
2016-02-17 10:54 . 2016-02-17 16:54 -------- d-----w- c:\users\Philip\AppData\Roaming\EssentialPIM
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-03-16 15:50 . 2015-01-29 12:39 192216 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2016-03-10 08:54 . 2009-10-31 09:27 143659408 ----a-w- c:\windows\system32\MRT.exe
2016-03-10 07:56 . 2013-03-13 13:58 1070904 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2016-03-10 07:56 . 2013-03-13 13:58 107792 ----a-w- c:\windows\system32\drivers\aswmonflt.sys
2016-02-23 16:52 . 2013-03-13 13:58 463744 ----a-w- c:\windows\system32\drivers\aswsp.sys
2016-02-17 11:53 . 2012-07-17 13:37 24288 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2016-02-11 18:30 . 2016-03-10 08:58 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2016-02-10 10:57 . 2013-03-13 13:58 287016 ----a-w- c:\windows\system32\drivers\aswvmm.sys
2016-02-06 19:57 . 2014-01-09 10:20 165344 ----a-w- c:\windows\system32\drivers\aswStm.sys
2016-02-06 19:57 . 2016-02-06 19:58 398152 ----a-w- c:\windows\system32\aswBoot.exe
2016-02-06 19:57 . 2014-05-11 16:27 37656 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2016-02-06 19:57 . 2013-03-13 13:58 74544 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2016-02-06 19:57 . 2013-03-13 13:58 103064 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2016-02-06 19:57 . 2016-02-06 19:57 52184 ----a-w- c:\windows\avastSS.scr
2016-02-06 19:57 . 2016-02-06 19:58 37144 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2016-02-04 22:13 . 2016-02-04 22:13 875720 ----a-w- c:\windows\SysWow64\msvcr120_clr0400.dll
2016-02-04 22:13 . 2016-02-04 22:13 536776 ----a-w- c:\windows\SysWow64\msvcp120_clr0400.dll
2016-02-04 22:03 . 2016-02-04 22:03 869568 ----a-w- c:\windows\system32\msvcr120_clr0400.dll
2016-02-04 22:03 . 2016-02-04 22:03 678600 ----a-w- c:\windows\system32\msvcp120_clr0400.dll
2016-01-22 06:19 . 2016-02-10 08:22 14179840 ----a-w- c:\windows\system32\shell32.dll
2016-01-22 06:18 . 2016-02-10 08:23 961024 ----a-w- c:\windows\system32\CPFilters.dll
2016-01-22 06:18 . 2016-02-10 08:23 723968 ----a-w- c:\windows\system32\EncDec.dll
2016-01-22 06:17 . 2016-02-10 08:23 159744 ----a-w- c:\windows\system32\mtxoci.dll
2016-01-22 06:15 . 2016-02-10 08:21 1866752 ----a-w- c:\windows\system32\ExplorerFrame.dll
2016-01-22 06:12 . 2016-02-10 08:21 1940992 ----a-w- c:\windows\system32\authui.dll
2016-01-22 06:04 . 2016-02-10 08:23 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll
2016-01-22 06:04 . 2016-02-10 08:23 535040 ----a-w- c:\windows\SysWow64\EncDec.dll
2016-01-22 06:02 . 2016-02-10 08:23 114176 ----a-w- c:\windows\SysWow64\mtxoci.dll
2016-01-22 06:02 . 2016-02-10 08:23 176128 ----a-w- c:\windows\SysWow64\msorcl32.dll
2016-01-22 06:00 . 2016-02-10 08:21 1498624 ----a-w- c:\windows\SysWow64\ExplorerFrame.dll
2016-01-22 05:59 . 2016-02-10 08:21 1805824 ----a-w- c:\windows\SysWow64\authui.dll
2016-01-22 05:19 . 2016-02-10 08:21 3231232 ----a-w- c:\windows\explorer.exe
2016-01-22 05:12 . 2016-02-10 08:21 2973184 ----a-w- c:\windows\SysWow64\explorer.exe
2016-01-16 19:01 . 2016-02-10 08:27 2085888 ----a-w- c:\windows\system32\ole32.dll
2016-01-16 18:36 . 2016-02-10 08:27 1413632 ----a-w- c:\windows\SysWow64\ole32.dll
2016-01-07 17:42 . 2016-02-10 08:28 141312 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2016-01-06 19:02 . 2016-02-10 08:30 24576 ----a-w- c:\windows\system32\jnwmon.dll
2016-01-06 19:02 . 2016-02-10 08:30 275456 ----a-w- c:\windows\system32\InkEd.dll
2016-01-06 18:41 . 2016-02-10 08:30 216064 ----a-w- c:\windows\SysWow64\InkEd.dll
2015-03-26 11:48 . 2015-03-26 11:48 2174976 ----a-w- c:\program files (x86)\Common Files\atimpenc.dll
2013-05-10 14:58 . 2013-09-09 09:39 6583664 ----a-w- c:\program files\AVAST So
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2014-12-12 7394584]
"GoogleChromeAutoLaunch_79E03DDA57221DD184735CE95D8488A3"="c:\users\Philip\AppData\Local\Google\Chrome\Application\chrome.exe" [2016-03-08 874136]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2016-03-10 7137664]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2014-09-26 271744]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe /firstrun [2009-6-30 1316192]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Dell DataSafe Online"="c:\program files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;MBAMService;c:\users\Philip\Desktop\Malwarebytes Anti-Malware\mbamservice.exe;c:\users\Philip\Desktop\Malwarebytes Anti-Malware\mbamservice.exe [x]
R2 MPCProtectService;MPC Core Protect Service;c:\program files (x86)\MPC Cleaner\MPCProtectService.exe;c:\program files (x86)\MPC Cleaner\MPCProtectService.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys;c:\windows\SYSNATIVE\drivers\aswKbd.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe;c:\program files\Dell\DellDock\DockLogin.exe [x]
S2 GfK-NetworkMeter;GfK-NetworkMeter;c:\program files (x86)\GfK-NetworkMeter\GfK-NetworkMeter64.exe;c:\program files (x86)\GfK-NetworkMeter\GfK-NetworkMeter64.exe [x]
S2 GfK-Reporting-Service;GfK-Reporting-Service;c:\program files (x86)\GfK Internet-Monitor\GfK-Reporting.exe;c:\program files (x86)\GfK Internet-Monitor\GfK-Reporting.exe [x]
S2 GfK-Update-Service;GfK-Update-Service;c:\program files (x86)\GfK Internet-Monitor\GfK-Updater.exe;c:\program files (x86)\GfK Internet-Monitor\GfK-Updater.exe [x]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - NetworkMeterDriver
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Inhalt des "geplante Tasks" Ordners
.
2016-03-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1019215699-1292833561-829163427-1000Core.job
- c:\users\Philip\AppData\Local\Google\Update\GoogleUpdate.exe [2013-03-13 05:41]
.
2016-03-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1019215699-1292833561-829163427-1000UA.job
- c:\users\Philip\AppData\Local\Google\Update\GoogleUpdate.exe [2013-03-13 05:41]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2016-02-06 19:57 905248 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-06-03 7834656]
"CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 767312]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 363544]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.google.com
mSearch Bar = https://www.google.com/?trackid=sp-006
mDefault_Search_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
IE: Free YouTube Download - c:\users\Philip\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\Philip\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
SafeBoot-mcmscsvc
SafeBoot-MCODS
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
AddRemove-Free Studio_is1 - c:\program files (x86)\Common Files\DVDVideoSoft\Uninstall.exe
AddRemove-Uninstall_is1 - c:\program files (x86)\Common Files\DVDVideoSoft\unins000.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1019215699-1292833561-829163427-1000\Software\Microsoft\Internet Explorer\Approved Extensions]
@DACL=(02 0000)
"{855F3B16-6D32-4FE6-8A56-BBB695989046}"=hex:51,66,7a,6c,4c,1d,3b,1b,06,24,4d,
9d,0c,3c,88,07,90,54,f0,f6,94,d9,dc,58
"{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3}"=hex:51,66,7a,6c,4c,1d,3b,1b,12,ac,48,
46,5b,2e,a3,0c,98,13,8a,94,cb,ed,82,bd
"{21347690-EC41-4F9A-8887-1F4AEE672439}"=hex:51,66,7a,6c,4c,1d,3b,1b,80,69,26,
39,7f,bd,f4,07,92,85,54,0a,ef,26,68,27
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,3b,1b,21,81,17,
e7,64,9d,40,06,a5,39,dd,a9,28,97,19,1d
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,3b,1b,6f,c1,f8,
a5,5b,93,be,59,a6,ef,4b,e0,c8,4b,f9,11
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,3b,1b,0c,17,cd,
00,93,b9,ed,0a,bf,94,b1,17,8d,6f,f1,dd
"{6EBF7485-159F-4BFF-A14F-B9E3AAC4465B}"=hex:51,66,7a,6c,4c,1d,3b,1b,95,6b,ad,
76,a1,44,91,03,bb,4d,f2,a3,ab,85,0a,45
"{74F475FA-6C75-43BD-AAB9-ECDA6184F600}"=hex:51,66,7a,6c,4c,1d,3b,1b,ea,6a,e6,
6c,4b,3d,d3,0b,b0,bb,a7,9a,60,c5,ba,1e
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,3b,1b,54,1f,da,
c3,7b,f5,35,0b,a6,76,d7,65,c0,84,c4,b7
"{8E5E2654-AD2D-48BF-AC2D-D17F00898D06}"=hex:51,66,7a,6c,4c,1d,3b,1b,44,39,4c,
96,13,fc,d1,00,b6,2f,9a,3f,01,c8,c1,18
"{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}"=hex:51,66,7a,6c,4c,1d,3b,1b,6b,3d,98,
29,a1,0f,d3,0d,93,9b,34,cf,11,8b,00,eb
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,3b,1b,ab,88,06,
6e,ce,87,42,0e,ac,e9,9f,9a,f0,98,61,5d
"{4D2D3B0F-69BE-477A-90F5-FDDB05357975}"=hex:51,66,7a,6c,4c,1d,3b,1b,1f,24,3f,
55,80,38,14,0f,8a,f7,b6,9b,04,74,35,6b
"{98889811-442D-49DD-99D7-DC866BE87DBC}"=hex:51,66,7a,6c,4c,1d,3b,1b,01,87,9a,
80,13,15,b3,01,83,d5,97,c6,6a,a9,31,a2
.
[HKEY_USERS\S-1-5-21-1019215699-1292833561-829163427-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:5b,cd,9d,16,bb,b2,fa,ef,e3,eb,d0,e1,4c,81,a6,8f,32,5e,1d,a9,d2,c2,25,
2f,0c,2f,3b,f8,4c,2b,f2,53,ce,2e,9d,9a,cc,60,ce,c6,1d,77,df,ec,f2,2c,da,27,\
"??"=hex:ca,a1,67,65,e9,91,f0,ff,ba,7f,40,03,16,72,91,cf
.
[HKEY_USERS\S-1-5-21-1019215699-1292833561-829163427-1000\Software\SecuROM\License information*]
"datasecu"=hex:af,72,fc,00,81,65,76,2b,bc,ee,36,06,66,71,73,4b,ca,e0,0e,89,31,
6a,12,e3,08,4b,8f,0b,b5,dd,81,df,0d,3f,3f,c7,b6,e6,84,2c,54,e7,72,25,1f,6a,\
"rkeysecu"=hex:c1,07,03,19,6a,ac,78,cd,4d,43,34,59,ae,4f,bc,f8
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2016-03-17 17:07:06
ComboFix-quarantined-files.txt 2016-03-17 16:07
.
Vor Suchlauf: 19 Verzeichnis(se), 323.598.659.584 Bytes frei
Nach Suchlauf: 24 Verzeichnis(se), 323.623.161.856 Bytes frei
.
- - End Of File - - 37366C31E3888862070897ECB7E96EB6
A36C5E4F47E84449FF07ED3517B43A31 |