Folgendes Problem ist aufgetaucht nach dem Neustarten ist der Laptop abgestürzt. Habe 25Min gewartet, aber nichts ist Geschehen.Deshalb habe ich diesen durch den Power-Button ausgeschaltet. Hier die Logfiles Code:
ComboFix 13-08-01.01 - Administrator 02.08.2013 12:40:52.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3946.2785 [GMT 2:00]
ausgeführt von:: c:\users\Administrator\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\CFLog
c:\cflog\CrashLog_20110429.txt
c:\cflog\CrashLog_20110430.txt
c:\cflog\CrashLog_20110501.txt
c:\cflog\CrashLog_20110519.txt
c:\cflog\CrashLog_20110924.txt
c:\cflog\CrashLog_20111210.txt
c:\cflog\CrashLog_20111211.txt
c:\cflog\CrashLog_20111225.txt
c:\cflog\CrashLog_20111227.txt
c:\cflog\CrashLog_20120103.txt
c:\cflog\EPLog.txt
c:\directory\CyberGate
c:\programdata\AVS
c:\programdata\AVS\account.txt
c:\programdata\AVS\avs.vbs
c:\programdata\AVS\device\avs.exe
c:\programdata\AVS\device\curllib.dll
c:\programdata\AVS\device\libeay32.dll
c:\programdata\AVS\device\libsasl.dll
c:\programdata\AVS\device\openldap.dll
c:\programdata\AVS\device\ssleay32.dll
c:\programdata\AVS\device\vsinit.dll
c:\programdata\AVS\lastsuccess.txt
c:\programdata\AVS\param.txt
c:\programdata\AVS\server.txt
c:\programdata\FullRemove.exe
c:\users\Administrator\AppData\Roaming\077A7919E8E6C4
c:\users\Ibrahim\AppData\Roaming\kernel33.dll
c:\windows\SysWow64\41DF10E9B63BB43DCE90D1795A13FC33.dll
c:\windows\SysWow64\frapsvid.dll
c:\windows\SysWow64\system.dll
c:\windows\wininit.ini
D:\install.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-07-02 bis 2013-08-02 ))))))))))))))))))))))))))))))
.
.
2013-08-02 10:54 . 2013-08-02 10:54 -------- d-----w- c:\users\Ibrahim\AppData\Local\temp
2013-08-02 04:51 . 2013-08-02 04:51 -------- d-----w- C:\FRST
2013-07-30 16:17 . 2012-07-11 15:09 64856 ----a-w- c:\windows\system32\klfphc.dll
2013-07-30 16:16 . 2013-07-30 16:16 -------- d-----w- c:\windows\ELAMBKUP
2013-07-30 16:16 . 2013-08-02 11:03 -------- d-----w- c:\programdata\Kaspersky Lab
2013-07-30 16:16 . 2013-07-30 16:16 -------- d-----w- c:\program files (x86)\Kaspersky Lab
2013-07-30 16:15 . 2013-07-30 16:24 620128 ----a-w- c:\windows\system32\drivers\klif.sys
2013-07-30 16:15 . 2013-07-30 16:24 90208 ----a-w- c:\windows\system32\drivers\klflt.sys
2013-07-30 15:45 . 2013-07-30 15:48 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2013-07-29 20:34 . 2013-05-07 14:41 524016 ----a-w- c:\windows\system32\drivers\SynTP.sys
2013-07-29 20:34 . 2013-05-07 14:41 151280 ----a-w- c:\windows\SysWow64\SynTPCom.dll
2013-07-29 20:34 . 2013-05-07 14:41 264432 ----a-w- c:\windows\system32\SynTPAPI.dll
2013-07-29 20:34 . 2013-05-07 14:41 192240 ----a-w- c:\windows\system32\SynTPCo19.dll
2013-07-29 20:34 . 2013-05-07 14:41 819440 ----a-w- c:\windows\system32\SynCOM.dll
2013-07-29 20:34 . 2013-05-07 14:41 351984 ----a-w- c:\windows\SysWow64\SynCom.dll
2013-07-29 20:34 . 2013-05-07 14:41 33008 ----a-w- c:\windows\system32\drivers\Smb_driver_Intel.sys
2013-07-29 20:32 . 2013-07-29 20:32 -------- d-----w- c:\windows\Dell
2013-07-29 20:31 . 2013-07-29 20:31 -------- d-----w- c:\program files\Apoint2K
2013-07-29 20:27 . 2013-02-28 19:29 116056 ----a-w- c:\windows\system32\Vxdif.dll
2013-07-29 20:27 . 2013-04-23 08:32 495408 ----a-w- c:\windows\system32\drivers\Apfiltr.sys
2013-07-29 20:06 . 2013-07-29 20:08 -------- d-----w- c:\programdata\FreeDriverScout
2013-07-29 20:04 . 2013-08-01 20:02 -------- d-----w- c:\users\Administrator\AppData\Roaming\Windows Net Data
2013-07-28 22:33 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2013-07-28 22:33 . 2013-04-17 06:24 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-07-28 07:57 . 2013-07-28 07:57 -------- d-----w- c:\users\Administrator\AppData\Roaming\ATI
2013-07-28 07:57 . 2013-07-28 07:57 -------- d-----w- c:\users\Administrator\AppData\Local\ATI
2013-07-28 07:57 . 2013-07-28 07:57 -------- d-----w- c:\programdata\ATI
2013-07-28 07:50 . 2013-07-28 07:50 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
2013-07-28 07:49 . 2013-07-28 07:49 -------- d-----w- c:\program files (x86)\ATI Technologies
2013-07-28 07:49 . 2013-07-28 07:49 -------- d-----w- c:\program files\ATI
2013-07-28 07:48 . 2013-07-28 07:50 -------- d-----w- c:\program files\ATI Technologies
2013-07-28 07:47 . 2013-07-28 08:04 -------- d-----w- C:\AMD
2013-07-28 05:29 . 2013-07-28 05:31 -------- d-----w- c:\program files (x86)\Driver Cleaner Pro
2013-07-28 04:52 . 2013-07-28 04:52 -------- d-----w- c:\program files\Common Files\ATI Technologies
2013-07-28 04:37 . 2013-07-29 20:03 -------- d-----w- c:\programdata\Package Cache
2013-07-28 04:02 . 2013-04-25 23:30 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2013-07-28 04:02 . 2013-03-31 22:52 1887232 ----a-w- c:\windows\system32\d3d11.dll
2013-07-28 03:41 . 2013-07-28 03:41 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-07-28 03:21 . 2013-05-10 05:49 30720 ----a-w- c:\windows\system32\cryptdlg.dll
2013-07-28 03:21 . 2013-05-10 03:20 24576 ----a-w- c:\windows\SysWow64\cryptdlg.dll
2013-07-28 02:18 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
2013-07-28 02:18 . 2013-04-02 22:51 1643520 ----a-w- c:\windows\system32\DWrite.dll
2013-07-24 11:03 . 2013-07-24 11:03 -------- d-----w- c:\program files (x86)\LOLReplay
2013-07-21 02:45 . 2013-07-21 02:45 -------- d-----w- c:\windows\de
2013-07-21 02:45 . 2013-07-21 02:45 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2013-07-21 02:44 . 2012-09-12 13:20 57856 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2013-07-21 02:44 . 2013-07-21 02:44 -------- d-----w- c:\program files\Windows Live
2013-07-21 02:44 . 2013-07-21 02:44 -------- d-----w- c:\windows\PCHEALTH
2013-07-21 02:37 . 2013-07-21 02:37 89944 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\42dc7cac1ce85bb04\DSETUP.dll
2013-07-21 02:37 . 2013-07-21 02:37 537432 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\42dc7cac1ce85bb04\DXSETUP.exe
2013-07-21 02:37 . 2013-07-21 02:37 1801048 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\42dc7cac1ce85bb04\dsetup32.dll
2013-07-21 02:37 . 2013-07-21 02:37 89944 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\41c90cd31ce85bb03\DSETUP.dll
2013-07-21 02:37 . 2013-07-21 02:37 537432 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\41c90cd31ce85bb03\DXSETUP.exe
2013-07-21 02:37 . 2013-07-21 02:37 1801048 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\41c90cd31ce85bb03\dsetup32.dll
2013-07-21 02:37 . 2013-07-21 02:37 525656 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\3f8c81f11ce85bb01\DXSETUP.exe
2013-07-21 02:37 . 2013-07-21 02:37 1691480 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\3f8c81f11ce85bb01\dsetup32.dll
2013-07-21 02:37 . 2013-07-21 02:37 94040 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\3f8c81f11ce85bb01\DSETUP.dll
2013-07-21 02:29 . 2013-08-01 20:03 -------- d-----w- C:\Fraps
2013-07-21 01:03 . 2013-07-19 04:04 262552 ----a-w- c:\program files (x86)\Mozilla Firefox\browser\components\browsercomps.dll
2013-07-21 00:58 . 2013-06-04 06:00 624128 ----a-w- c:\windows\system32\qedit.dll
2013-07-21 00:58 . 2013-06-04 04:53 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2013-07-21 00:58 . 2013-06-05 03:34 3153920 ----a-w- c:\windows\system32\win32k.sys
2013-07-21 00:58 . 2013-04-26 05:51 751104 ----a-w- c:\windows\system32\win32spl.dll
2013-07-21 00:58 . 2013-04-26 04:55 492544 ----a-w- c:\windows\SysWow64\win32spl.dll
2013-07-17 18:26 . 2013-07-17 18:26 -------- d-----w- c:\programdata\Caphyon
2013-07-17 18:25 . 2013-07-17 18:25 -------- d-----w- c:\users\Administrator\AppData\Roaming\SitenApp
2013-07-17 13:24 . 2013-07-17 13:24 -------- d-----w- c:\program files (x86)\gPotato
2013-07-15 16:30 . 2013-07-15 23:15 -------- d-----w- c:\programdata\bcb
2013-07-15 16:21 . 2013-07-15 16:21 -------- d-----w- c:\users\Administrator\avt
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-30 16:24 . 2012-08-13 14:49 178448 ----a-w- c:\windows\system32\drivers\kneps.sys
2013-07-30 16:24 . 2012-06-08 09:38 54368 ----a-w- c:\windows\system32\drivers\kltdi.sys
2013-07-21 02:43 . 2012-07-17 12:37 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-07-15 01:34 . 2013-07-30 15:26 9460976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B13A66D9-2971-4363-877B-85026DE05500}\mpengine.dll
2013-06-23 22:41 . 2011-03-05 19:25 78185248 ----a-w- c:\windows\system32\MRT.exe
2013-06-21 17:10 . 2013-06-21 17:11 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-06-21 17:10 . 2012-05-20 12:26 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-06-21 17:10 . 2011-03-06 16:56 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-06-21 17:08 . 2012-07-04 12:18 1093032 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-06-21 17:08 . 2011-03-06 17:02 972712 ----a-w- c:\windows\system32\deployJava1.dll
2013-06-17 22:04 . 2013-06-17 22:04 0 ----a-w- c:\windows\SysWow64\sho8E1A.tmp
2013-05-29 15:23 . 2013-05-29 14:55 859841624 ----a-w- C:\Crossfire_Install_1172.exe
2013-05-18 13:44 . 2013-05-18 13:44 0 ----a-w- c:\windows\SysWow64\sho2202.tmp
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-07-20 15:43 220632 ----a-w- c:\users\Administrator\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-07-20 15:43 220632 ----a-w- c:\users\Administrator\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-07-20 15:43 220632 ----a-w- c:\users\Administrator\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FileHippo.com"="c:\program files (x86)\FileHippo.com\UpdateChecker.exe" [2012-11-23 307712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-03-28 642656]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe" [2013-07-30 356376]
.
c:\users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
net.lnk - c:\users\Administrator\AppData\Roaming\Windows Net Data\net.exe [2013-7-29 709120]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
avsinit.vbs [2013-7-15 142]
bcb2init.vbs [2013-7-15 142]
LOLRecorder.lnk - c:\program files (x86)\LOLReplay\LOLRecorder.exe -minimize [2013-7-17 526336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"AMD AVT"=Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "c:\program files (x86)\AMD AVT\bin\kdbsync.exe" aml
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="1"
"UpdatesDisableNotify"="1"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 ALSysIO;ALSysIO;c:\users\Ibrahim\AppData\Local\Temp\ALSysIO64.sys;c:\users\Ibrahim\AppData\Local\Temp\ALSysIO64.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 dump_wmimmc;dump_wmimmc;c:\program files (x86)\eFusion\BlackShot\system\GameGuard\dump_wmimmc.sys;c:\program files (x86)\eFusion\BlackShot\system\GameGuard\dump_wmimmc.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 HPMo4DE3;Mouse Suite Driver_4DE3 (WDF Version);c:\windows\system32\DRIVERS\HPMo4DE3.sys;c:\windows\SYSNATIVE\DRIVERS\HPMo4DE3.sys [x]
R3 HPub4DE3;USB Mouse Low Filter Driver_4DE3 (WDF Version);c:\windows\system32\Drivers\HPub4DE3.sys;c:\windows\SYSNATIVE\Drivers\HPub4DE3.sys [x]
R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys;c:\windows\SYSNATIVE\DRIVERS\MijXfilt.sys [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
R3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [x]
R3 X6va005;X6va005;c:\users\Ibrahim\AppData\Local\Temp\0057550.tmp;c:\users\Ibrahim\AppData\Local\Temp\0057550.tmp [x]
R3 X6va006;X6va006;c:\users\Ibrahim\AppData\Local\Temp\006C507.tmp;c:\users\Ibrahim\AppData\Local\Temp\006C507.tmp [x]
R3 X6va008;X6va008;c:\windows\SysWOW64\Drivers\X6va008;c:\windows\SysWOW64\Drivers\X6va008 [x]
R3 X6va009;X6va009;c:\windows\SysWOW64\Drivers\X6va009;c:\windows\SysWOW64\Drivers\X6va009 [x]
R3 X6va010;X6va010;c:\windows\SysWOW64\Drivers\X6va010;c:\windows\SysWOW64\Drivers\X6va010 [x]
R3 X6va012;X6va012;c:\windows\SysWOW64\Drivers\X6va012;c:\windows\SysWOW64\Drivers\X6va012 [x]
R4 CoolPic - Fun Social Pictures Updater;CoolPic - Fun Social Pictures Updater;c:\program files\CoolPic - Fun Social Pictures\ExtensionUpdaterService.exe;c:\program files\CoolPic - Fun Social Pictures\ExtensionUpdaterService.exe [x]
R4 Giraffic;Veoh Giraffic Video Accelerator;c:\program files (x86)\Giraffic\Veoh_GirafficWatchdog.exe;c:\program files (x86)\Giraffic\Veoh_GirafficWatchdog.exe [x]
R4 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R4 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x]
S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x]
S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys;c:\windows\SYSNATIVE\Drivers\SABI.sys [x]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
Inhalt des "geplante Tasks" Ordners
.
2013-08-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3108295939-4095832443-2851371546-1000Core.job
- c:\users\Ibrahim\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-14 18:26]
.
2013-08-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3108295939-4095832443-2851371546-1000UA.job
- c:\users\Ibrahim\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-14 18:26]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-07-20 15:43 244696 ----a-w- c:\users\Administrator\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-07-20 15:43 244696 ----a-w- c:\users\Administrator\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-07-20 15:43 244696 ----a-w- c:\users\Administrator\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mStart Page = about:blank
TCP: Interfaces\{9ECD0294-4960-470F-BEC0-BEF96D3DCA1B}\5416379724F687D2233434034373: DhcpNameServer = 192.168.2.1
DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095} -
FF - ProfilePath - c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\zjmn65wj.default\
FF - ExtSQL: 2013-07-30 17:50; EFGLQA@78ETGYN-0W7FN789T87.COM; c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\zjmn65wj.default\extensions\EFGLQA@78ETGYN-0W7FN789T87.COM
FF - ExtSQL: 2013-07-30 18:24; content_blocker@kaspersky.com; c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\content_blocker@kaspersky.com
FF - ExtSQL: 2013-07-30 18:24; url_advisor@kaspersky.com; c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\url_advisor@kaspersky.com
FF - ExtSQL: 2013-07-30 18:24; virtual_keyboard@kaspersky.com; c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\virtual_keyboard@kaspersky.com
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{5e5ab302-7f65-44cd-8211-c1d4caaccea3} - (no file)
URLSearchHooks-{cd90bf73-20f6-44ef-993d-bb920303bd2e} - (no file)
URLSearchHooks-{c840e246-6b95-475e-9bd7-caa1c7eca9f2} - (no file)
URLSearchHooks-{64ead72b-ffd4-4e01-aa3a-4c71665d73e4} - (no file)
Toolbar-Locked - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
WebBrowser-{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - (no file)
WebBrowser-{CD90BF73-20F6-44EF-993D-BB920303BD2E} - (no file)
WebBrowser-{64EAD72B-FFD4-4E01-AA3A-4C71665D73E4} - (no file)
AddRemove-{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8} - c:\program files (x86)\InstallShield Installation Information\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\Setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\Akamai]
"ServiceDll"="c:\program files (x86)\common files\akamai/netsession_win_8fa3539.dll"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va005]
"ImagePath"="\??\c:\users\Ibrahim\AppData\Local\Temp\0057550.tmp"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va006]
"ImagePath"="\??\c:\users\Ibrahim\AppData\Local\Temp\006C507.tmp"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va008]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va008"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va009]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va009"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va010]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va010"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va012]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va012"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:9c,f5,5f,9d,4a,78,cd,01
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (Administrator)
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,3b,1b,74,c9,23,
89,3d,1d,d9,02,9b,c4,1a,24,72,4b,2f,df
"{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}"=hex:51,66,7a,6c,4c,1d,3b,1b,0e,1b,61,
e4,e1,ce,2b,00,b0,82,40,eb,45,12,86,c1
"{4D2D3B0F-69BE-477A-90F5-FDDB05357975}"=hex:51,66,7a,6c,4c,1d,3b,1b,1f,26,3e,
54,81,38,1c,0f,85,fd,b6,9b,01,76,35,6c
"{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3}"=hex:51,66,7a,6c,4c,1d,3b,1b,12,ae,49,
47,5a,2e,ab,0c,97,19,8a,94,ce,ef,82,ba
"{326E768D-4182-46FD-9C16-1449A49795F4}"=hex:51,66,7a,6c,4c,1d,3b,1b,9d,6b,7d,
2b,bd,10,9b,0e,89,1e,5f,09,a0,d4,d9,ed
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,3b,1b,ab,8a,07,
6f,cf,87,4a,0e,a3,e3,9f,9a,f5,9a,61,5a
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,3b,1b,54,1d,db,
c2,7a,f5,3d,0b,a9,7c,d7,65,c5,86,c4,b0
"{1631550F-191D-4826-B069-D9439253D926}"=hex:51,66,7a,6c,4c,1d,3b,1b,1f,48,22,
0f,22,48,40,00,a5,61,92,03,96,10,95,3f
"{11111111-1111-1111-1111-110311341134}"=hex:51,66,7a,6c,4c,1d,3b,1b,01,0c,02,
08,2e,40,77,59,04,19,5a,43,15,77,5d,2d
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (Administrator)
"Timestamp"=hex:c0,4b,be,54,9e,8c,ce,01
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,79,d1,ab,ca,53,77,cd,46,89,82,28,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,79,d1,ab,ca,53,77,cd,46,89,82,28,\
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.3g2"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.3gp"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.3gp2"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.3gpp"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AAC\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.aac"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADT\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ADTS"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADTS\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ADTS"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.aif"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.aifc"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.aiff"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.asf"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.asx"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.au"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AVI"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cdda\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.cdda"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.div\UserChoice]
@Denied: (2) (Administrator)
"Progid"="divx_div_file"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.divx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.divx"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="ChromeHTML.Administrator"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (Administrator)
"Progid"="ChromeHTML.Administrator"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ipa\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.ipa"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itl\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.itl"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.m1v"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2T\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.m2t"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2TS\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.m2ts"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2V\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.m2v"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.m3u"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u8\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m3u8"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.m4a"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4p\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m4p"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4r\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m4r"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.m4v"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.mid"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.midi"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.mkv"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MOD\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.mod"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.mov"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.mp2"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.mp2v"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.mp3"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP4"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP4"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.mpa"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.mpe"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.mpeg"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.mpg"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.mpv2"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MTS\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.mts"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qt\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.qt"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.rmi"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="ChromeHTML.Administrator"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.snd"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tix\UserChoice]
@Denied: (2) (Administrator)
"Progid"="divx_tix_file"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TS\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.ts"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TTS\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.TTS"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vob\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.vob"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.wav"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wave\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.wave"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.wax"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.wm"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.wma"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMD"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMS"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.wmv"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.wmx"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmz\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMZ"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpl\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WPL"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="goplayer.wvx"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (Administrator)
"Progid"="ChromeHTML.Administrator"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="ChromeHTML.Administrator"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.yml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\notepad++.exe"
.
[HKEY_USERS\S-1-5-21-3108295939-4095832443-2851371546-500\Software\Microsoft\Windows\CurrentVersion\Ext\Settings]
@Denied: (2) (Administrator)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_75_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_75_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_75_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_75_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\LOLReplay\LOLRecorder.exe
c:\program files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
c:\users\All Users\bcb\device\sbchost.exe
c:\program files (x86)\Internet Explorer\IEXPLORE.EXE
c:\program files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
c:\program files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-08-02 13:12:56 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2013-08-02 11:12
.
Vor Suchlauf: 16 Verzeichnis(se), 62.854.995.968 Bytes frei
Nach Suchlauf: 20 Verzeichnis(se), 62.728.753.152 Bytes frei
.
- - End Of File - - 8915860BF620949A93B0790F6667DF2C
2E5DEBB2116B3417023E0D6562D7ED07 |