Killaklo | 19.05.2013 12:41 | Gude,
Logfile: Code:
ComboFix 13-05-18.03 - Andy 19.05.2013 13:18:05.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.6135.4332 [GMT 2:00]
ausgef¸hrt von:: L:\ComboFix.exe
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
. ADS - Windows: deleted 24 bytes in 1 streams.
.
(((((((((((((((((((((((((((((((((((( Weitere Lˆschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
D:\install.exe
d:\users\Andy\AppData\Roaming\AcroIEHelpe.txt
d:\users\Andy\AppData\Roaming\explorer
d:\users\Andy\AppData\Roaming\srvblck2.tmp
d:\users\Andy\AppData\Roaming\srvblck5.tmp
d:\users\Andy\AppData\Roaming\urhtps.tmp
d:\windows\SysWow64\DEBUG.log
d:\windows\SysWow64\frapsvid.dll
d:\windows\SysWow64\Packet.dll
d:\windows\SysWow64\pthreadVC.dll
d:\windows\SysWow64\wpcap.dll
.
.
((((((((((((((((((((((((((((((((((((((( Treiber/Dienste )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_NPF
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-04-19 bis 2013-05-19 ))))))))))))))))))))))))))))))
.
.
2013-05-19 11:24 . 2013-05-19 11:24 -------- d-----w- d:\users\Default\AppData\Local\temp
2013-05-17 16:18 . 2013-05-13 06:37 9460464 ----a-w- d:\programdata\Microsoft\Windows Defender\Definition Updates\{6920F83E-D265-48E2-AFD7-A870AA550289}\mpengine.dll
2013-05-16 20:22 . 2013-05-05 21:36 17818624 ----a-w- d:\windows\system32\mshtml.dll
2013-05-16 20:22 . 2013-05-05 21:16 2382848 ----a-w- d:\windows\system32\mshtml.tlb
2013-05-16 20:22 . 2013-05-05 19:12 2382848 ----a-w- d:\windows\SysWow64\mshtml.tlb
2013-05-16 12:45 . 2013-04-10 06:01 265064 ----a-w- d:\windows\system32\drivers\dxgmms1.sys
2013-05-16 12:45 . 2013-04-10 06:01 983400 ----a-w- d:\windows\system32\drivers\dxgkrnl.sys
2013-05-16 12:45 . 2011-02-03 11:25 144384 ----a-w- d:\windows\system32\cdd.dll
2013-05-16 12:44 . 2013-02-27 05:52 14172672 ----a-w- d:\windows\system32\shell32.dll
2013-05-16 12:44 . 2013-02-27 06:02 111448 ----a-w- d:\windows\system32\consent.exe
2013-05-16 12:44 . 2013-02-27 05:52 197120 ----a-w- d:\windows\system32\shdocvw.dll
2013-05-16 12:44 . 2013-02-27 05:48 1930752 ----a-w- d:\windows\system32\authui.dll
2013-05-16 12:44 . 2013-02-27 05:47 70144 ----a-w- d:\windows\system32\appinfo.dll
2013-05-16 12:44 . 2013-02-27 04:49 1796096 ----a-w- d:\windows\SysWow64\authui.dll
2013-05-16 12:44 . 2013-03-19 05:53 48640 ----a-w- d:\windows\system32\wwanprotdim.dll
2013-05-16 12:44 . 2013-03-19 05:53 230400 ----a-w- d:\windows\system32\wwansvc.dll
2013-05-16 12:44 . 2013-04-10 03:30 3153920 ----a-w- d:\windows\system32\win32k.sys
2013-05-13 14:12 . 2013-05-13 14:12 -------- d-----w- D:\FRST
2013-04-25 08:32 . 2013-04-12 14:45 1656680 ----a-w- d:\windows\system32\drivers\ntfs.sys
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-19 11:26 . 2011-03-28 17:36 22240 ----a-w- d:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-16 20:25 . 2011-05-02 13:23 75016696 ----a-w- d:\windows\system32\MRT.exe
2013-05-14 19:12 . 2012-04-16 14:05 692104 ----a-w- d:\windows\SysWow64\FlashPlayerApp.exe
2013-05-14 19:12 . 2012-03-07 12:14 71048 ----a-w- d:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-02 00:06 . 2011-04-25 17:09 278800 ------w- d:\windows\system32\MpSigStub.exe
2013-04-13 05:49 . 2013-05-16 12:45 135168 ----a-w- d:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49 . 2013-05-16 12:45 350208 ----a-w- d:\windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49 . 2013-05-16 12:45 308736 ----a-w- d:\windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49 . 2013-05-16 12:45 111104 ----a-w- d:\windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45 . 2013-05-16 12:45 474624 ----a-w- d:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45 . 2013-05-16 12:45 2176512 ----a-w- d:\windows\apppatch\AcGenral.dll
2013-04-11 14:18 . 2011-06-11 08:58 281768 ----a-w- d:\windows\SysWow64\PnkBstrB.xtr
2013-04-11 14:18 . 2011-06-10 23:16 281768 ----a-w- d:\windows\SysWow64\PnkBstrB.exe
2013-04-11 14:07 . 2011-06-10 23:16 271200 ----a-w- d:\windows\SysWow64\PnkBstrB.ex0
2013-03-19 06:04 . 2013-04-11 11:53 5550424 ----a-w- d:\windows\system32\ntoskrnl.exe
2013-03-19 05:46 . 2013-04-11 11:53 43520 ----a-w- d:\windows\system32\csrsrv.dll
2013-03-19 05:04 . 2013-04-11 11:53 3968856 ----a-w- d:\windows\SysWow64\ntkrnlpa.exe
2013-03-19 05:04 . 2013-04-11 11:53 3913560 ----a-w- d:\windows\SysWow64\ntoskrnl.exe
2013-03-19 04:47 . 2013-04-11 11:53 6656 ----a-w- d:\windows\SysWow64\apisetschema.dll
2013-03-19 03:06 . 2013-04-11 11:53 112640 ----a-w- d:\windows\system32\smss.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Eintr‰ge & legitime Standardeintr‰ge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="d:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"Spotify Web Helper"="d:\users\Andy\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2013-05-05 1105408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="d:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-03-04 281768]
"StartCCC"="d:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-11-16 641704]
.
d:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
NETGEAR WNDA3100v2 Setup-Assistent.lnk - d:\program files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe [2011-11-29 4577760]
SmartCopy.lnk - d:\program files (x86)\Northstar\SmartCopy\SmartCopy.exe [2011-4-25 319488]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"DivXUpdate"="d:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"TkBellExe"="d:\program files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
"QuickTime Task"="d:\program files (x86)\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="d:\program files (x86)\iTunes\iTunesHelper.exe"
"StartCCC"="d:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"CloneCDTray"="d:\program files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s
"LogMeIn Hamachi Ui"="d:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"SunJavaUpdateSched"="d:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"AMD AVT"=Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "d:\program files (x86)\AMD AVT\bin\kdbsync.exe" aml
"WinampAgent"="d:\program files (x86)\Winamp\winampa.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="1"
"UpdatesDisableNotify"="1"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;d:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 WSWNDA3100;WSWNDA3100;d:\program files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [2010-08-19 272864]
R3 dump_wmimmc;dump_wmimmc;c:\windows.old.000\program files (x86)\steam\steamapps\common\ava\Binaries\GameGuard\dump_wmimmc.sys [x]
R3 EagleX64;EagleX64;d:\windows\system32\drivers\EagleX64.sys [x]
R3 ggflt;SEMC USB Flash Driver Filter;d:\windows\system32\DRIVERS\ggflt.sys [2011-06-21 13352]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;d:\windows\system32\drivers\LGVirHid.sys [2009-11-24 16008]
R3 libusb0;libusb-win32 - Kernel Driver 04/08/2011 1.2.4.0;d:\windows\system32\DRIVERS\libusb0.sys [2011-05-17 44480]
R3 npggsvc;nProtect GameGuard Service;d:\windows\system32\GameMon.des [x]
R3 s0017bus;Sony Ericsson Device 0017 driver (WDM);d:\windows\system32\DRIVERS\s0017bus.sys [2008-10-21 113704]
R3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;d:\windows\system32\DRIVERS\s0017mdfl.sys [2008-10-21 19496]
R3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;d:\windows\system32\DRIVERS\s0017mdm.sys [2008-10-21 152616]
R3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);d:\windows\system32\DRIVERS\s0017mgmt.sys [2008-10-21 133160]
R3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);d:\windows\system32\DRIVERS\s0017nd5.sys [2008-10-21 34856]
R3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;d:\windows\system32\DRIVERS\s0017obex.sys [2008-10-21 128552]
R3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);d:\windows\system32\DRIVERS\s0017unic.sys [2008-10-21 145960]
R3 Sony PC Companion;Sony PC Companion;d:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]
R3 TsUsbFlt;TsUsbFlt;d:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R4 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;d:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-12-10 2465712]
R4 ICQ Service;ICQ Service;d:\program files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608]
S0 SCMNdisP;General NDIS Protocol Driver;d:\windows\system32\DRIVERS\scmndisp.sys [2007-01-19 25312]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;d:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-08-18 254528]
S2 Akamai;Akamai NetSession Interface;d:\windows\System32\svchost.exe [2009-07-14 27136]
S2 AMD External Events Utility;AMD External Events Utility;d:\windows\system32\atiesrxx.exe [2012-11-16 238080]
S2 AntiVirSchedulerService;Avira AntiVir Planer;d:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-04-29 136360]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;d:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2011-03-30 2026304]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;d:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
S3 BCMH43XX;Treiber f¸r Broadcom 802.11-USB-Netzwerkadapter;d:\windows\system32\DRIVERS\bcmwlhigh664.sys [2009-11-06 838136]
S3 e1yexpress;Intel(R) Gigabit-Netzwerkverbindungstreiber;d:\windows\system32\DRIVERS\e1y60x64.sys [2009-06-10 281088]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;d:\windows\system32\drivers\LGBusEnum.sys [2009-11-24 22408]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;d:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-10-07 11856]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Inhalt des "geplante Tasks" Ordners
.
2013-05-19 d:\windows\Tasks\Adobe Flash Player Updater.job
- d:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-16 19:12]
.
2013-05-17 d:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1908369367-3690954649-3213997060-1001Core.job
- d:\users\Andy\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-12 19:29]
.
2013-05-18 d:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1908369367-3690954649-3213997060-1001UA.job
- d:\users\Andy\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-12 19:29]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OEM Upgrade DVD"="d:\oem\Upgrade Kit\DVDMainStart.Launcher.exe" [2009-10-19 410968]
"Launch LCore"="d:\program files\Logitech Gaming Software\LCore.exe" [2011-12-07 5889816]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
FontCache
.
------- Zus‰tzlicher Suchlauf -------
.
uLocal Page = d:\windows\system32\blank.htm
mLocal Page = d:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = 127.0.0.1:9421;<local>
IE: Free YouTube to MP3 Converter - d:\users\Andy\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - d:\program files (x86)\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - d:\users\Andy\AppData\Roaming\Mozilla\Firefox\Profiles\g4h18ccp.default\
FF - prefs.js: network.proxy.type - 0
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - Entfernte verwaiste Registrierungseintr‰ge - - - -
.
AddRemove-Guild Wars - d:\guild wars\Gw.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="d:\program files (x86)\common files\akamai/netsession_win_ca0e279.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="d:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1908369367-3690954649-3213997060-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:0d,a0,9c,6a,a3,66,a5,4b,b8,92,e4,8f,04,a1,7b,0d,76,c8,2b,c8,4b,56,88,
4d,12,b8,11,6c,7c,b7,88,1a,4e,46,78,d7,ce,1e,54,65,9e,83,1e,8f,4a,7b,45,5d,\
"??"=hex:41,e0,42,8c,cf,55,c7,95,2b,14,4d,f8,66,7b,0c,1b
.
[HKEY_USERS\S-1-5-21-1908369367-3690954649-3213997060-1001\Software\SecuROM\License information*]
"datasecu"=hex:cc,79,35,6f,d1,1c,fb,21,5c,9f,7d,0e,52,c7,ac,f6,7c,fb,08,8f,ce,
d5,0e,0d,34,c3,51,38,67,cb,b4,f4,22,9e,c5,56,3f,88,4c,93,e3,7d,3d,3c,18,f3,\
"rkeysecu"=hex:4c,c7,46,e7,d7,01,46,1c,d6,68,23,8e,ad,a0,84,93
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@d:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="d:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@d:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="d:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="d:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="d:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="d:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="d:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
d:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
d:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
d:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-05-19 13:30:31 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2013-05-19 11:30
.
Vor Suchlauf: 76 Verzeichnis(se), 67.919.212.544 Bytes frei
Nach Suchlauf: 81 Verzeichnis(se), 67.983.659.008 Bytes frei
.
- - End Of File - - A67BAE6E5C8A25EF104AD63C4A8E0E0B Ich kann allerdings seit dem ich den ComboFix ausgeführt habe keine Anwendungen mehr starten auf meinem Pc, dazu gehört unter anderem mein Internetexplorer sowie FIrefox.
Ist das normal ?
MFG |