Rheingold | 21.12.2011 08:46 | : Code:
ComboFix 11-12-20.04 - Administrator 21.12.2011 8:27.2.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3990.2146 [GMT 1:00]
ausgeführt von:: c:\users\Administrator\Desktop\ComboFix.exe
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\LP
c:\program files (x86)\LP\A7CB\6FA5.tmp
c:\program files (x86)\LP\A7CB\897.tmp
c:\program files (x86)\LP\A7CB\A7A3.tmp
c:\program files (x86)\LP\A7CB\DE11.tmp
c:\program files (x86)\LP\A7CB\ED79.tmp
c:\program files (x86)\mbam-setup-1.51.2.1300.exe
c:\program files (x86)\PSISetup2003.exe
c:\program files (x86)\RealPlayer_1406666_de.exe
c:\program files (x86)\Setup.exe
c:\users\ADMINI~1\AppData\Local\Temp\SASF93E.tmp
c:\users\Administrator\AppData\Local\Temp\SASF93E.tmp
c:\users\Jasmina\FacebookVideoCallSetup_v1.2.203.0.exe
c:\users\Jasmina\fbookbot.exe
c:\users\Jasmina\mp3DC213.exe
c:\windows\assembly\tmp\U
c:\windows\SysWow64\SWCTL.DLL
.
.
((((((((((((((((((((((( Dateien erstellt von 2011-11-21 bis 2011-12-21 ))))))))))))))))))))))))))))))
.
.
2011-12-21 07:33 . 2011-12-21 07:33 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2011-12-21 07:33 . 2011-12-21 07:33 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-12-21 07:33 . 2011-12-21 07:33 -------- d-----w- c:\users\Nico.dell-PC.000\AppData\Local\temp
2011-12-19 12:21 . 2011-12-19 12:21 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-12-19 09:30 . 2011-12-19 09:30 -------- d-----w- c:\windows\SysWow64\wbem\en-US
2011-12-19 09:30 . 2011-12-19 09:30 -------- d-----w- c:\windows\system32\wbem\en-US
2011-12-19 09:13 . 2011-12-19 09:13 -------- d-----w- c:\program files\Microsoft Silverlight
2011-12-19 09:12 . 2011-12-19 09:12 13072536 ----a-w- c:\windows\Silverlight_x64.exe
2011-12-19 08:00 . 2011-12-19 08:50 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2011-12-19 08:00 . 2011-12-19 08:50 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-12-18 12:56 . 2011-12-18 12:56 -------- d-----w- c:\program files (x86)\ESET
2011-12-18 07:06 . 2011-12-18 07:06 -------- d-----w- C:\_OTL
2011-12-16 08:08 . 2011-12-16 08:08 -------- d-----w- c:\users\Administrator\AppData\Roaming\RealNetworks
2011-12-15 10:50 . 2011-12-15 10:50 -------- d-----w- c:\users\Administrator\AppData\Local\SoftGrid Client
2011-12-15 10:50 . 2011-12-19 09:19 -------- d-----w- c:\users\Administrator\AppData\Roaming\SoftGrid Client
2011-12-15 10:34 . 2011-12-15 10:34 -------- d-----w- c:\program files\iPod
2011-12-15 10:34 . 2011-12-15 10:35 -------- d-----w- c:\program files\iTunes
2011-12-15 10:34 . 2011-12-15 10:35 -------- d-----w- c:\program files (x86)\iTunes
2011-12-15 10:29 . 2011-12-15 10:29 11776 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nprjplug.dll
2011-12-15 10:29 . 2011-12-15 10:29 -------- d-----w- c:\program files (x86)\Common Files\xing shared
2011-12-15 10:29 . 2011-12-15 10:29 150696 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppl3260.dll
2011-12-15 10:28 . 2011-12-15 10:28 108544 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nprpjplug.dll
2011-12-15 10:28 . 2011-12-15 10:28 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
2011-12-15 10:28 . 2011-12-15 10:28 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
2011-12-15 10:25 . 2011-12-15 10:25 713472 ----a-w- c:\program files (x86)\RealPlayer.exe
2011-12-15 10:22 . 2011-12-15 10:25 -------- d-sh--w- c:\users\Administrator\AppData\Local\4d0d2e25
2011-12-15 09:41 . 2011-12-15 09:41 -------- d-----w- c:\program files\CCleaner
2011-12-15 09:39 . 2011-12-15 09:39 3552208 ----a-w- c:\program files (x86)\ccsetup313.exe
2011-12-14 22:09 . 2011-10-15 06:31 723456 ----a-w- c:\windows\system32\EncDec.dll
2011-12-14 22:09 . 2011-10-15 05:38 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-12-14 22:09 . 2011-10-26 05:21 43520 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-14 22:09 . 2011-11-24 04:52 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-12-14 21:58 . 2011-11-05 05:32 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-14 21:58 . 2011-11-05 04:26 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-12-14 18:58 . 2011-12-14 18:58 163 ----a-w- c:\users\Nico.dell-PC.000\AppData\Roaming\Microsoft\A7CB\bl593131_64.bat
2011-12-14 07:38 . 2011-12-14 07:38 -------- d-sh--w- c:\users\Jasmina\AppData\Local\4d0d2e25
2011-12-14 07:35 . 2011-12-15 20:45 -------- d-----w- c:\users\Jasmina\AppData\Roaming\57168
2011-12-14 07:34 . 2011-12-15 20:45 -------- d-----w- c:\users\Jasmina\AppData\Roaming\B8457
2011-12-13 19:19 . 2011-12-13 19:19 181 ----a-w- c:\users\Nico.dell-PC.000\AppData\Roaming\Microsoft\A7CB\bl1265152_64.bat
2011-12-13 19:18 . 2011-12-13 19:18 163 ----a-w- c:\users\Nico.dell-PC.000\AppData\Roaming\Microsoft\A7CB\bl1246260_64.bat
2011-12-13 19:18 . 2011-12-13 19:18 163 ----a-w- c:\users\Nico.dell-PC.000\AppData\Roaming\Microsoft\A7CB\bl1208336_64.bat
2011-12-13 19:17 . 2011-12-16 08:57 -------- d-sh--w- c:\users\Nico.dell-PC.000\AppData\Local\4d0d2e25
2011-12-13 19:17 . 2011-12-13 19:17 165 ----a-w- c:\users\Nico.dell-PC.000\AppData\Roaming\Microsoft\A7CB\bl1172004_64.bat
2011-12-13 19:14 . 2011-12-15 20:45 -------- d-----w- c:\users\Nico.dell-PC.000\AppData\Roaming\57168
2011-12-13 19:14 . 2011-12-15 07:04 -------- d-----w- c:\users\Nico.dell-PC.000\AppData\Roaming\B8457
2011-12-08 18:59 . 2011-12-08 18:59 -------- d-----w- c:\users\Nico.dell-PC.000\AppData\Local\Apple
2011-12-02 15:28 . 2011-12-02 15:28 -------- d-----w- c:\programdata\Nexon
2011-12-02 14:45 . 2011-12-02 15:22 -------- d-----w- C:\Download
2011-12-02 14:45 . 2011-12-02 15:22 -------- d-----w- C:\Nexon
2011-12-02 14:45 . 2011-12-02 14:45 235 ----a-w- c:\windows\SysWow64\nxEuUninstall.bat
2011-12-02 14:45 . 2011-12-02 14:45 446464 ----a-w- c:\windows\NEXON_EU_DownloaderUpdater.exe
2011-11-28 19:37 . 2011-11-29 08:07 -------- d-----w- c:\users\Nico.dell-PC.000\AppData\Local\Windows Live
2011-11-24 08:40 . 2011-06-16 16:53 232960 ----a-w- c:\windows\system32\Spool\prtprocs\x64\EKIJ5000PPR.dll
2011-11-24 08:36 . 2011-11-24 08:36 -------- d-----w- c:\windows\SysWow64\spool
2011-11-24 08:23 . 2011-11-24 08:23 12713136 ----a-w- c:\program files (x86)\aio_install.exe
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-19 08:53 . 2011-05-23 11:19 2300696 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2011-12-19 08:53 . 2011-05-23 11:19 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2011-12-17 08:14 . 2011-05-21 18:35 2300696 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2011-12-17 08:14 . 2011-05-21 18:35 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2011-12-14 07:38 . 2011-05-19 13:13 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-29 10:50 . 2011-10-29 10:49 39401336 ----a-w- c:\program files (x86)\QuickTimeInstaller.exe
2011-10-29 09:21 . 2011-05-15 03:21 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-10-29 09:17 . 2011-10-29 09:10 910624 ----a-w- c:\program files (x86)\jxpiinstall.exe
2011-10-29 08:54 . 2011-10-29 08:54 1019816 ----a-w- c:\program files\DELL_DELL-DIGITAL-DELIVERY_A05_R313622.exe
2011-10-25 11:17 . 2011-10-25 11:17 9756672 ----a-w- c:\program files\L502X_A__06.exe
2011-10-24 12:29 . 2011-10-24 12:29 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2011-10-24 12:29 . 2011-10-24 12:29 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
2011-10-17 07:05 . 2011-10-17 07:05 13885360 ----a-w- c:\program files (x86)\Firefox Setup 7.0.1.exe
2011-10-17 06:07 . 2011-10-17 06:07 1739400 ----a-w- c:\users\Jasmina\PSISetup2003.exe
2011-10-13 06:08 . 2011-10-13 06:08 292184 ----a-w- c:\users\Jasmina\dxwebsetup.exe
2011-10-07 15:06 . 2011-10-07 14:58 384512408 ----a-w- c:\users\Jasmina\Nero-11.0.10700_trial.exe
2011-10-04 18:36 . 2011-10-04 18:36 10308272 ----a-w- c:\users\Jasmina\Opera_1151_int_Setup.exe
2011-10-03 12:40 . 2011-10-03 12:41 247053 ----a-w- c:\program files (x86)\mp3DC213.exe
2011-10-01 07:43 . 2011-10-01 07:43 6727840 ----a-w- c:\users\Jasmina\SkypeClicktoCall.exe
2011-09-29 16:29 . 2011-11-09 07:00 1923952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-09-29 06:55 . 2011-09-29 06:55 3103511 ----a-w- c:\program files (x86)\kcsetup8.exe
2011-09-24 16:12 . 2011-09-24 16:12 1291624 ----a-w- c:\program files\wlsetup-web__1_.exe
2011-09-23 13:20 . 2011-05-15 03:22 525544 ----a-w- c:\windows\system32\deployJava1.dll
2011-09-23 13:06 . 2011-09-23 13:05 21073936 ----a-w- c:\program files (x86)\vlc-1.1.11-win32.exe
2011-09-23 11:41 . 2011-09-23 11:40 23773184 ----a-w- c:\program files (x86)\PXCViewer98_x64.msi
2011-09-23 11:31 . 2011-09-22 09:34 3089056 ----a-w- c:\program files (x86)\install_flash_player.exe
2011-09-23 11:27 . 2011-09-23 11:27 1376768 ----a-w- c:\program files (x86)\7z920-x64.msi
2011-09-16 05:47 . 2011-09-16 05:44 168166968 ----a-w- c:\program files (x86)\OOo_3.3.0_Win_x86_install-wJRE_de.exe
2011-08-30 14:06 . 2011-05-28 12:11 14563768 ----a-w- c:\program files (x86)\FreeYouTubeToMP3Converter.exe
2011-08-30 14:04 . 2011-05-28 12:13 14212584 ----a-w- c:\program files (x86)\FreeYouTubeToiPodConverter.exe
2011-08-28 10:12 . 2011-08-28 10:11 51975388 ----a-w- c:\program files (x86)\VSX4_Pro_TBYB.exe.part
2011-08-28 08:56 . 2011-08-28 08:55 2466704 ----a-w- c:\program files (x86)\AdobeDownloadAssistant.exe
2011-08-27 10:56 . 2011-08-27 10:56 1228384 ----a-w- c:\program files (x86)\PremiereElements_9_LS15.exe
2011-08-27 10:23 . 2011-08-27 10:23 8353800 ----a-w- c:\program files (x86)\Adobe_Premiere_Elements_9-AkamaiDLM.exe
2011-08-25 16:58 . 2011-08-25 16:58 6716353 ----a-w- c:\program files (x86)\Sunbird_Setup_1.0_Beta_1.exe
2011-07-18 14:59 . 2011-07-18 14:59 13522064 ----a-w- c:\program files (x86)\Firefox Setup 5.0.1.exe
2011-05-22 08:35 . 2011-05-22 08:35 21255560 ----a-w- c:\program files (x86)\SkypeSetupFull.exe
2011-05-19 13:44 . 2011-05-19 13:44 1663693 ----a-w- c:\program files (x86)\winrar-x64-400d.exe
2011-05-19 13:39 . 2011-05-19 13:37 81797928 ----a-w- c:\program files (x86)\iTunes64Setup.exe
2011-05-19 13:18 . 2011-05-19 13:17 20240744 ----a-w- c:\program files (x86)\gimp-2.6.11-i686-setup.exe
2011-05-19 13:17 . 2011-05-19 13:17 19735256 ----a-w- c:\program files (x86)\gimp-2.6.8-x64-setup.exe
2011-05-19 13:10 . 2011-05-19 13:10 14166016 ----a-w- c:\program files (x86)\wz150gev.msi
2011-05-19 13:06 . 2011-05-19 13:06 767064 ----a-w- c:\program files (x86)\wpsetup4.57.exe
2011-05-19 11:34 . 2011-05-19 11:34 568648 ----a-w- c:\program files (x86)\GoogleEarthSetup.exe
2011-05-19 11:28 . 2011-05-19 11:28 52718176 ----a-w- c:\program files (x86)\avira_antivir_personal_de.exe
2011-05-19 11:26 . 2011-05-19 11:26 9326056 ----a-w- c:\program files (x86)\Thunderbird Setup 3.1.10.exe
2011-05-19 11:25 . 2011-05-19 11:25 12362480 ----a-w- c:\program files (x86)\Firefox Setup 4.0.1.exe
2011-01-19 11:34 . 2011-01-19 11:34 3003392 ----a-w- c:\program files (x86)\openofficeorg33.msi
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 17351304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2010-08-19 487562]
"Dell DataSafe Online"="c:\program files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe" [2010-08-26 1117528]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112]
"Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544]
"SMSTray"="c:\program files (x86)\Samsung\EmoDio\SMSTray.exe" [2009-04-16 479232]
"NBAgent"="c:\program files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe" [2011-09-20 1493288]
"ChicoSys"="c:\windows\SysWOW64\cc32\webtmr.exe" [2009-07-13 5635736]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2011-12-15 296056]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-12-08 421736]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\drivers\x64\3\EKIJ5000MUI.exe" [2011-06-16 2922496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe" [2010-08-11 163040]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CCWinTray"="c:\windows\tray\wintmr.exe" [2009-07-13 5975704]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"KodakHomeCenter"="c:\program files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe" [2011-09-05 2232752]
.
c:\users\Nico.dell-PC.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\users\Jasmina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2011-4-19 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"HideFastUserSwitching"= 1 (0x1)
"EnableLinkedConnections"= 1 (0x1)
"EnableLUA"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableClock"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideSCAHealth"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ksupmgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2011-01-24 991296]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-19 136176]
R2 ksupmgr;File-/Update Service;c:\windows\SysWOW64\ksupmgr.exe [2010-08-25 765592]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2011-01-24 1298496]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-19 136176]
R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-12-17 340240]
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\DRIVERS\nvstusb.sys [x]
R3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys [x]
R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
S0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\DRIVERS\NBVol.sys [x]
S0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\DRIVERS\NBVolUp.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [x]
S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-01-24 901184]
S2 DBService;DATA BECKER Update Service;c:\program files (x86)\Common Files\DATA BECKER Shared\DBService.exe [2010-05-28 2650112]
S2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files (x86)\Kodak\AiO\Center\EKAiOHostService.exe [2011-09-05 393648]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-09-23 641832]
S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2010-11-30 1997416]
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [x]
S3 AVer7231_x64;AVerMedia 7231 capture service;c:\windows\system32\DRIVERS\AVer7231_x64.sys [x]
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [x]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [x]
S3 HPMo4DE3;Mouse Suite Driver_4DE3 (WDF Version);c:\windows\system32\DRIVERS\HPMo4DE3.sys [x]
S3 HPub4DE3;USB Mouse Low Filter Driver_4DE3 (WDF Version);c:\windows\system32\Drivers\HPub4DE3.sys [x]
S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [x]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NETwNs64;___ Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows 7 64-Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - avipbb
*Deregistered* - Chico
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Inhalt des "geplante Tasks" Ordners
.
2011-12-21 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3230886925-126132133-2629391164-1025UA.job
- c:\users\Nico.dell-PC.000\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-10 19:23]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2010-12-14 6561384]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-12-11 2186856]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2010-11-29 312936]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-12 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-12 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-12 418328]
"FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-12-17 686704]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-01-24 10355200]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-12-17 1933584]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2011-05-30 2055816]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-07-28 497648]
"EKIJ5000StatusMonitor"="c:\windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe" [2011-06-16 2922496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Free YouTube to iPod Converter - c:\users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm
IE: Free YouTube to MP3 Converter - c:\users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\3cers2zs.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - www.google.de
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKLM-Run-Conime - c:\windows\system32\conime.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\Akamai]
"ServiceDll"="c:\program files (x86)\common files\akamai/netsession_win_b427739.dll"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ce,9e,47,77,90,b8,f8,4f,8e,46,72,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ce,9e,47,77,90,b8,f8,4f,8e,46,72,\
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.123\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.csv\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dbf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dif\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.doc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dot\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="ThunderbirdEML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hwp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.log\UserChoice]
@Denied: (2) (Administrator)
"Progid"="txtfile"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Opera.HTML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Opera.HTML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarMathDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpdp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="NCH.MixPad.mpdp"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odb\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.DatabaseDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.MathDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.DrawDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.WriterDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.ImpressDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ods\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.CalcDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odt\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.WriterDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.otg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.DrawDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.oth\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.WriterDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.otp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.ImpressDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ott\UserChoice]
@Denied: (2) (Administrator)
"Progid"="opendocument.WriterDocument.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.oxt\UserChoice]
@Denied: (2) (Administrator)
"Progid"="office.Extension.1"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pot\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pps\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppt\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rtf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.slk\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.stc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.std\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarDrawTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sti\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.stw\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sxc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sxd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarDrawDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sxi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarImpressDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sxm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarMathDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sxw\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.URL"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wdseml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="ThunderbirdEML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wk1\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wks\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="NCH.WavePad.wpp"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Opera.HTML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xls\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsb\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlt\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xltm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xltx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcTemplate.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlw\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarCalcDocument.6"
.
[HKEY_USERS\S-1-5-21-3230886925-126132133-2629391164-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="soffice.StarWriterDocument.6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2011-12-21 08:36:50
ComboFix-quarantined-files.txt 2011-12-21 07:36
.
Vor Suchlauf: 17 Verzeichnis(se), 118.534.037.504 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 118.229.495.808 Bytes frei
.
- - End Of File - - 349A187C0E2F5F539931BA904FBE7AB5: |