hir Code:
ComboFix 13-12-31.01 - Mesut 31.12.2013 16:26:09.2.3 - x64
Microsoft Windows 7 Enterprise 6.1.7601.1.1252.41.1033.18.2047.1018 [GMT 1:00]
ausgeführt von:: c:\users\Mesut\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\ff
c:\windows\SysWow64\ff\App\AppInfo\appicon.ico
c:\windows\SysWow64\ff\App\AppInfo\appicon_128.png
c:\windows\SysWow64\ff\App\AppInfo\appicon_16.png
c:\windows\SysWow64\ff\App\AppInfo\appicon_32.png
c:\windows\SysWow64\ff\App\AppInfo\appinfo.ini
c:\windows\SysWow64\ff\App\AppInfo\installer.ini
c:\windows\SysWow64\ff\App\Bin\sqlite3.exe
c:\windows\SysWow64\ff\App\DefaultData\plugins\plugins_readme.txt
c:\windows\SysWow64\ff\App\DefaultData\profile\bookmarks.html
c:\windows\SysWow64\ff\App\DefaultData\profile\prefs.js
c:\windows\SysWow64\ff\App\DefaultData\settings\FirefoxPortableSettings.ini
c:\windows\SysWow64\ff\App\Firefox\AccessibleMarshal.dll
c:\windows\SysWow64\ff\App\Firefox\active-update.xml
c:\windows\SysWow64\ff\App\Firefox\application.ini
c:\windows\SysWow64\ff\App\Firefox\breakpadinjector.dll
c:\windows\SysWow64\ff\App\Firefox\browser\blocklist.xml
c:\windows\SysWow64\ff\App\Firefox\browser\chrome.manifest
c:\windows\SysWow64\ff\App\Firefox\browser\components\browsercomps.dll
c:\windows\SysWow64\ff\App\Firefox\browser\components\components.manifest
c:\windows\SysWow64\ff\App\Firefox\browser\crashreporter-override.ini
c:\windows\SysWow64\ff\App\Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\icon.png
c:\windows\SysWow64\ff\App\Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\install.rdf
c:\windows\SysWow64\ff\App\Firefox\browser\omni.ja
c:\windows\SysWow64\ff\App\Firefox\browser\searchplugins\amazondotcom-de.xml
c:\windows\SysWow64\ff\App\Firefox\browser\searchplugins\bing.xml
c:\windows\SysWow64\ff\App\Firefox\browser\searchplugins\eBay-de.xml
c:\windows\SysWow64\ff\App\Firefox\browser\searchplugins\google.xml
c:\windows\SysWow64\ff\App\Firefox\browser\searchplugins\leo_ende_de.xml
c:\windows\SysWow64\ff\App\Firefox\browser\searchplugins\wikipedia-de.xml
c:\windows\SysWow64\ff\App\Firefox\browser\searchplugins\yahoo-de.xml
c:\windows\SysWow64\ff\App\Firefox\crashreporter.exe
c:\windows\SysWow64\ff\App\Firefox\crashreporter.ini
c:\windows\SysWow64\ff\App\Firefox\D3DCompiler_43.dll
c:\windows\SysWow64\ff\App\Firefox\defaults\pref\channel-prefs.js
c:\windows\SysWow64\ff\App\Firefox\dependentlibs.list
c:\windows\SysWow64\ff\App\Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\icon.png
c:\windows\SysWow64\ff\App\Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\install.rdf
c:\windows\SysWow64\ff\App\Firefox\firefox.exe
c:\windows\SysWow64\ff\App\Firefox\freebl3.chk
c:\windows\SysWow64\ff\App\Firefox\freebl3.dll
c:\windows\SysWow64\ff\App\Firefox\gkmedias.dll
c:\windows\SysWow64\ff\App\Firefox\libEGL.dll
c:\windows\SysWow64\ff\App\Firefox\libGLESv2.dll
c:\windows\SysWow64\ff\App\Firefox\maintenanceservice.exe
c:\windows\SysWow64\ff\App\Firefox\maintenanceservice_installer.exe
c:\windows\SysWow64\ff\App\Firefox\mozalloc.dll
c:\windows\SysWow64\ff\App\Firefox\mozglue.dll
c:\windows\SysWow64\ff\App\Firefox\mozjs.dll
c:\windows\SysWow64\ff\App\Firefox\msvcp100.dll
c:\windows\SysWow64\ff\App\Firefox\msvcr100.dll
c:\windows\SysWow64\ff\App\Firefox\nss3.dll
c:\windows\SysWow64\ff\App\Firefox\nssckbi.dll
c:\windows\SysWow64\ff\App\Firefox\nssdbm3.chk
c:\windows\SysWow64\ff\App\Firefox\nssdbm3.dll
c:\windows\SysWow64\ff\App\Firefox\omni.ja
c:\windows\SysWow64\ff\App\Firefox\platform.ini
c:\windows\SysWow64\ff\App\Firefox\plugin-container.exe
c:\windows\SysWow64\ff\App\Firefox\plugin-hang-ui.exe
c:\windows\SysWow64\ff\App\Firefox\precomplete
c:\windows\SysWow64\ff\App\Firefox\removed-files
c:\windows\SysWow64\ff\App\Firefox\softokn3.chk
c:\windows\SysWow64\ff\App\Firefox\softokn3.dll
c:\windows\SysWow64\ff\App\Firefox\uninstall\helper.exe
c:\windows\SysWow64\ff\App\Firefox\uninstall\uninstall.update
c:\windows\SysWow64\ff\App\Firefox\update-settings.ini
c:\windows\SysWow64\ff\App\Firefox\updater.exe
c:\windows\SysWow64\ff\App\Firefox\updater.ini
c:\windows\SysWow64\ff\App\Firefox\updates.xml
c:\windows\SysWow64\ff\App\Firefox\updates\0\update.log
c:\windows\SysWow64\ff\App\Firefox\updates\0\update.manifest
c:\windows\SysWow64\ff\App\Firefox\updates\0\update.mar
c:\windows\SysWow64\ff\App\Firefox\updates\0\update.status
c:\windows\SysWow64\ff\App\Firefox\updates\0\update.version
c:\windows\SysWow64\ff\App\Firefox\updates\0\updater.exe
c:\windows\SysWow64\ff\App\Firefox\updates\0\updater.ini
c:\windows\SysWow64\ff\App\Firefox\webapp-uninstaller.exe
c:\windows\SysWow64\ff\App\Firefox\webapprt-stub.exe
c:\windows\SysWow64\ff\App\Firefox\webapprt\omni.ja
c:\windows\SysWow64\ff\App\Firefox\webapprt\webapprt.ini
c:\windows\SysWow64\ff\App\Firefox\xul.dll
c:\windows\SysWow64\ff\App\readme.txt
c:\windows\SysWow64\ff\Data\plugins\npdsplay.dll
c:\windows\SysWow64\ff\Data\plugins\npzylomgamesplayer.dll
c:\windows\SysWow64\ff\Data\plugins\plugins_readme.txt
c:\windows\SysWow64\ff\Data\plugins_choice\list.txt
c:\windows\SysWow64\ff\Data\plugins_choice\np32dsw.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npauthz.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npAviraCallingID.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npctrl.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npdeploytk.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npdivx32.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npdrmv2.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npdsplay.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npgeplugin.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npitunes.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npjp2.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npnul32.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npNxGameeu.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npovshelper.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npPandoWebPlugin.dll
c:\windows\SysWow64\ff\Data\plugins_choice\nppdf32.dll
c:\windows\SysWow64\ff\Data\plugins_choice\nppl3260.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npqtplugin.dll
c:\windows\SysWow64\ff\Data\plugins_choice\nprpplugin.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npspwrap.dll
c:\windows\SysWow64\ff\Data\plugins_choice\NPSWF32_11_7_700_169.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npunity3d32.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npvlc.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npwinext.dll
c:\windows\SysWow64\ff\Data\plugins_choice\NPWLPG.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npwpf.dll
c:\windows\SysWow64\ff\Data\plugins_choice\npzylomgamesplayer.dll
c:\windows\SysWow64\ff\Data\profile\blocklist.xml
c:\windows\SysWow64\ff\Data\profile\bookmarkbackups\bookmarks-2013-09-08.json
c:\windows\SysWow64\ff\Data\profile\bookmarkbackups\bookmarks-2013-09-09.json
c:\windows\SysWow64\ff\Data\profile\bookmarkbackups\bookmarks-2013-09-10.json
c:\windows\SysWow64\ff\Data\profile\bookmarkbackups\bookmarks-2013-09-11.json
c:\windows\SysWow64\ff\Data\profile\bookmarkbackups\bookmarks-2013-09-16.json
c:\windows\SysWow64\ff\Data\profile\bookmarkbackups\bookmarks-2013-09-22.json
c:\windows\SysWow64\ff\Data\profile\bookmarkbackups\bookmarks-2013-09-23.json
c:\windows\SysWow64\ff\Data\profile\bookmarkbackups\bookmarks-2013-09-24.json
c:\windows\SysWow64\ff\Data\profile\bookmarkbackups\bookmarks-2013-09-25.json
c:\windows\SysWow64\ff\Data\profile\bookmarkbackups\bookmarks-2013-09-28.json
c:\windows\SysWow64\ff\Data\profile\bookmarks.html
c:\windows\SysWow64\ff\Data\profile\cert8.db
c:\windows\SysWow64\ff\Data\profile\chromeappsstore.sqlite
c:\windows\SysWow64\ff\Data\profile\compatibility.ini
c:\windows\SysWow64\ff\Data\profile\content-prefs.sqlite
c:\windows\SysWow64\ff\Data\profile\cookies.sqlite
c:\windows\SysWow64\ff\Data\profile\downloads.sqlite
c:\windows\SysWow64\ff\Data\profile\extensions.ini
c:\windows\SysWow64\ff\Data\profile\extensions.sqlite
c:\windows\SysWow64\ff\Data\profile\extensions\firebug@software.joehewitt.com.xpi
c:\windows\SysWow64\ff\Data\profile\extensions\remote-control@morch.com.xpi
c:\windows\SysWow64\ff\Data\profile\firebug\annotations.json
c:\windows\SysWow64\ff\Data\profile\firebug\breakpoints.json
c:\windows\SysWow64\ff\Data\profile\formhistory.sqlite
c:\windows\SysWow64\ff\Data\profile\healthreport.sqlite
c:\windows\SysWow64\ff\Data\profile\key3.db
c:\windows\SysWow64\ff\Data\profile\localstore-safe.rdf
c:\windows\SysWow64\ff\Data\profile\localstore.rdf
c:\windows\SysWow64\ff\Data\profile\marionette.log
c:\windows\SysWow64\ff\Data\profile\mimeTypes.rdf
c:\windows\SysWow64\ff\Data\profile\minidumps\a98c2742-fa9f-4fe8-a65d-009c3107488f.dmp
c:\windows\SysWow64\ff\Data\profile\OfflineCache\index.sqlite
c:\windows\SysWow64\ff\Data\profile\parent.lock
c:\windows\SysWow64\ff\Data\profile\permissions.sqlite
c:\windows\SysWow64\ff\Data\profile\places.sqlite
c:\windows\SysWow64\ff\Data\profile\pluginreg.dat
c:\windows\SysWow64\ff\Data\profile\prefs.js
c:\windows\SysWow64\ff\Data\profile\safebrowsing\goog-malware-shavar.cache
c:\windows\SysWow64\ff\Data\profile\safebrowsing\goog-malware-shavar.pset
c:\windows\SysWow64\ff\Data\profile\safebrowsing\goog-malware-shavar.sbstore
c:\windows\SysWow64\ff\Data\profile\safebrowsing\test-malware-simple.cache
c:\windows\SysWow64\ff\Data\profile\safebrowsing\test-malware-simple.pset
c:\windows\SysWow64\ff\Data\profile\safebrowsing\test-malware-simple.sbstore
c:\windows\SysWow64\ff\Data\profile\safebrowsing\test-phish-simple.cache
c:\windows\SysWow64\ff\Data\profile\safebrowsing\test-phish-simple.pset
c:\windows\SysWow64\ff\Data\profile\safebrowsing\test-phish-simple.sbstore
c:\windows\SysWow64\ff\Data\profile\search-metadata.json
c:\windows\SysWow64\ff\Data\profile\search.json
c:\windows\SysWow64\ff\Data\profile\search.sqlite
c:\windows\SysWow64\ff\Data\profile\secmod.db
c:\windows\SysWow64\ff\Data\profile\signons.sqlite
c:\windows\SysWow64\ff\Data\profile\start.txt
c:\windows\SysWow64\ff\Data\profile\startupCache\startupCache.4.little
c:\windows\SysWow64\ff\Data\profile\urlclassifier.pset
c:\windows\SysWow64\ff\Data\profile\urlclassifier3.sqlite
c:\windows\SysWow64\ff\Data\profile\webapps\webapps.json
c:\windows\SysWow64\ff\Data\profile\webappsstore.sqlite
c:\windows\SysWow64\ff\Data\settings\FirefoxPortableSettings.ini
c:\windows\SysWow64\ff\FirefoxPortable.exe
c:\windows\SysWow64\ff\Fonts\aaaiight.ttf
c:\windows\SysWow64\ff\Fonts\abusive pencil.ttf
c:\windows\SysWow64\ff\Fonts\Acens.ttf
c:\windows\SysWow64\ff\Fonts\Acidic.TTF
c:\windows\SysWow64\ff\Fonts\adam.ttf
c:\windows\SysWow64\ff\Fonts\adamb.ttf
c:\windows\SysWow64\ff\Fonts\adambital.ttf
c:\windows\SysWow64\ff\Fonts\Aerosol.ttf
c:\windows\SysWow64\ff\Fonts\aggstock.ttf
c:\windows\SysWow64\ff\Fonts\AIFRAGME.TTF
c:\windows\SysWow64\ff\Fonts\AIRSTREA.TTF
c:\windows\SysWow64\ff\Fonts\airstrip.ttf
c:\windows\SysWow64\ff\Fonts\aladdin.ttf
c:\windows\SysWow64\ff\Fonts\Alias.ttf
c:\windows\SysWow64\ff\Fonts\All Star Resort.ttf
c:\windows\SysWow64\ff\Fonts\AlteHaasGroteskBold.ttf
c:\windows\SysWow64\ff\Fonts\Amerdcon.ttf
c:\windows\SysWow64\ff\Fonts\Android Nation.ttf
c:\windows\SysWow64\ff\Fonts\Anime Ace.ttf
c:\windows\SysWow64\ff\Fonts\beaswfte.ttf
c:\windows\SysWow64\ff\Fonts\Blambot Custom.ttf
c:\windows\SysWow64\ff\Fonts\Blambot Pro.ttf
c:\windows\SysWow64\ff\Fonts\city_burn.ttf
c:\windows\SysWow64\ff\Fonts\CNN.ttf
c:\windows\SysWow64\ff\Fonts\Colcothar.ttf
c:\windows\SysWow64\ff\Fonts\Damn Noisy Kids.ttf
c:\windows\SysWow64\ff\Fonts\Daredevil.ttf
c:\windows\SysWow64\ff\Fonts\DENSMORE.TTF
c:\windows\SysWow64\ff\Fonts\desperado.ttf
c:\windows\SysWow64\ff\Fonts\Detectives Inc.ttf
c:\windows\SysWow64\ff\Fonts\detroitghetto.ttf
c:\windows\SysWow64\ff\Fonts\devotion.ttf
c:\windows\SysWow64\ff\Fonts\dirtyheadline.ttf
c:\windows\SysWow64\ff\Fonts\Diskoboll.ttf
c:\windows\SysWow64\ff\Fonts\EARWIGFA.TTF
c:\windows\SysWow64\ff\Fonts\EDITION_.TTF
c:\windows\SysWow64\ff\Fonts\Ellianarelle s Path.ttf
c:\windows\SysWow64\ff\Fonts\EMPIREST.TTF
c:\windows\SysWow64\ff\Fonts\EpoXY_histoRy.ttf
c:\windows\SysWow64\ff\Fonts\ERTHQAKE.TTF
c:\windows\SysWow64\ff\Fonts\esp.ttf
c:\windows\SysWow64\ff\Fonts\EUROSWH.TTF
c:\windows\SysWow64\ff\Fonts\EVITA.TTF
c:\windows\SysWow64\ff\Fonts\FAREAST.TTF
c:\windows\SysWow64\ff\Fonts\fbsbltc.ttf
c:\windows\SysWow64\ff\Fonts\FerroRosso.ttf
c:\windows\SysWow64\ff\Fonts\Fiesta.ttf
c:\windows\SysWow64\ff\Fonts\fight.TTF
c:\windows\SysWow64\ff\Fonts\Findet Nemo.ttf
c:\windows\SysWow64\ff\Fonts\Flat Earth Scribe.ttf
c:\windows\SysWow64\ff\Fonts\friends good.ttf
c:\windows\SysWow64\ff\Fonts\GameCube.ttf
c:\windows\SysWow64\ff\Fonts\Ginga.ttf
c:\windows\SysWow64\ff\Fonts\Godzilla.ttf
c:\windows\SysWow64\ff\Fonts\GothicFlames.ttf
c:\windows\SysWow64\ff\Fonts\gothikka.ttf
c:\windows\SysWow64\ff\Fonts\Graffogie.ttf
c:\windows\SysWow64\ff\Fonts\groening.ttf
c:\windows\SysWow64\ff\Fonts\gyparody.ttf
c:\windows\SysWow64\ff\Fonts\halflife.ttf
c:\windows\SysWow64\ff\Fonts\Halo.ttf
c:\windows\SysWow64\ff\Fonts\HandSean.ttf
c:\windows\SysWow64\ff\Fonts\HARD_ROCK.ttf
c:\windows\SysWow64\ff\Fonts\Hellraiser SC.ttf
c:\windows\SysWow64\ff\Fonts\Hursheys.ttf
c:\windows\SysWow64\ff\Fonts\idiot.ttf
c:\windows\SysWow64\ff\Fonts\Impossible.ttf
c:\windows\SysWow64\ff\Fonts\in_my_head.ttf
c:\windows\SysWow64\ff\Fonts\Indianhotel.ttf
c:\windows\SysWow64\ff\Fonts\jandles.ttf
c:\windows\SysWow64\ff\Fonts\JaneAust.ttf
c:\windows\SysWow64\ff\Fonts\JerseyLetters.ttf
c:\windows\SysWow64\ff\Fonts\JungleRuff.ttf
c:\windows\SysWow64\ff\Fonts\kaileenw.ttf
c:\windows\SysWow64\ff\Fonts\karabine.ttf
c:\windows\SysWow64\ff\Fonts\Karate.ttf
c:\windows\SysWow64\ff\Fonts\Kitten Meat.ttf
c:\windows\SysWow64\ff\Fonts\Kittkat.ttf
c:\windows\SysWow64\ff\Fonts\Laine.TTF
c:\windows\SysWow64\ff\Fonts\Lazy.ttf
c:\windows\SysWow64\ff\Fonts\LEDLIGHT.ttf
c:\windows\SysWow64\ff\Fonts\Legothick.ttf
c:\windows\SysWow64\ff\Fonts\linkin.ttf
c:\windows\SysWow64\ff\Fonts\LinkinPark.ttf
c:\windows\SysWow64\ff\Fonts\lottepaperfang.ttf
c:\windows\SysWow64\ff\Fonts\maksukehoitus.ttf
c:\windows\SysWow64\ff\Fonts\manga_speak.ttf
c:\windows\SysWow64\ff\Fonts\MARK.TTF
c:\windows\SysWow64\ff\Fonts\Marlboc.ttf
c:\windows\SysWow64\ff\Fonts\Marlbow.ttf
c:\windows\SysWow64\ff\Fonts\Megadeth.ttf
c:\windows\SysWow64\ff\Fonts\meresre.ttf
c:\windows\SysWow64\ff\Fonts\morgenstern.ttf
c:\windows\SysWow64\ff\Fonts\N-Gage.ttf
c:\windows\SysWow64\ff\Fonts\NASALIZA.TTF
c:\windows\SysWow64\ff\Fonts\neon2.ttf
c:\windows\SysWow64\ff\Fonts\NEUROTOX.TTF
c:\windows\SysWow64\ff\Fonts\nevis.ttf
c:\windows\SysWow64\ff\Fonts\Orange Fizz.ttf
c:\windows\SysWow64\ff\Fonts\oreos.ttf
c:\windows\SysWow64\ff\Fonts\Origami.ttf
c:\windows\SysWow64\ff\Fonts\PaisleyCaps .ttf
c:\windows\SysWow64\ff\Fonts\Patches.ttf
c:\windows\SysWow64\ff\Fonts\pdark.ttf
c:\windows\SysWow64\ff\Fonts\Phorssa.ttf
c:\windows\SysWow64\ff\Fonts\Planet of the Apes.ttf
c:\windows\SysWow64\ff\Fonts\Playtoy.ttf
c:\windows\SysWow64\ff\Fonts\Pleiades.TTF
c:\windows\SysWow64\ff\Fonts\postoffice.ttf
c:\windows\SysWow64\ff\Fonts\Pozo.ttf
c:\windows\SysWow64\ff\Fonts\Prototype.ttf
c:\windows\SysWow64\ff\Fonts\Prozak.ttf
c:\windows\SysWow64\ff\Fonts\Pyromane.ttf
c:\windows\SysWow64\ff\Fonts\quake.TTF
c:\windows\SysWow64\ff\Fonts\Requiem.ttf
c:\windows\SysWow64\ff\Fonts\Resident Evil Large.ttf
c:\windows\SysWow64\ff\Fonts\retroRockPoster.ttf
c:\windows\SysWow64\ff\Fonts\ribbon.ttf
c:\windows\SysWow64\ff\Fonts\riesling.ttf
c:\windows\SysWow64\ff\Fonts\Rockit.ttf
c:\windows\SysWow64\ff\Fonts\romeo.ttf
c:\windows\SysWow64\ff\Fonts\Rounded.ttf
c:\windows\SysWow64\ff\Fonts\rzrarti.ttf
c:\windows\SysWow64\ff\Fonts\Scream Real.ttf
c:\windows\SysWow64\ff\Fonts\se7en.ttf
c:\windows\SysWow64\ff\Fonts\Searfont.ttf
c:\windows\SysWow64\ff\Fonts\shellhead.ttf
c:\windows\SysWow64\ff\Fonts\Sickness.ttf
c:\windows\SysWow64\ff\Fonts\sidewalk.ttf
c:\windows\SysWow64\ff\Fonts\Sin City.ttf
c:\windows\SysWow64\ff\Fonts\Sliced_Juice.ttf
c:\windows\SysWow64\ff\Fonts\Smallville1.ttf
c:\windows\SysWow64\ff\Fonts\Spirit Medium.ttf
c:\windows\SysWow64\ff\Fonts\splinter2.ttf
c:\windows\SysWow64\ff\Fonts\spongefont.ttf
c:\windows\SysWow64\ff\Fonts\stentiga.ttf
c:\windows\SysWow64\ff\Fonts\TAGSTER.TTF
c:\windows\SysWow64\ff\Fonts\Taste of steel.ttf
c:\windows\SysWow64\ff\Fonts\TERMINAT.TTF
c:\windows\SysWow64\ff\Fonts\the ring.ttf
c:\windows\SysWow64\ff\Fonts\the sixth sense.ttf
c:\windows\SysWow64\ff\Fonts\the_King__26_Queen_font.ttf
c:\windows\SysWow64\ff\Fonts\the_Poison.ttf
c:\windows\SysWow64\ff\Fonts\TheGodFather.ttf
c:\windows\SysWow64\ff\Fonts\tiza.ttf
c:\windows\SysWow64\ff\Fonts\tondo.ttf
c:\windows\SysWow64\ff\Fonts\tron.ttf
c:\windows\SysWow64\ff\Fonts\Trumania.ttf
c:\windows\SysWow64\ff\Fonts\Turok.ttf
c:\windows\SysWow64\ff\Fonts\ultimate MIDNIGHT.ttf
c:\windows\SysWow64\ff\Fonts\Umberto.ttf
c:\windows\SysWow64\ff\Fonts\Unreal.ttf
c:\windows\SysWow64\ff\Fonts\Uptown__.ttf
c:\windows\SysWow64\ff\Fonts\uwch.ttf
c:\windows\SysWow64\ff\Fonts\Vampiress.ttf
c:\windows\SysWow64\ff\Fonts\Varsity.ttf
c:\windows\SysWow64\ff\Fonts\vintage.ttf
c:\windows\SysWow64\ff\Fonts\walk_plank.ttf
c:\windows\SysWow64\ff\Fonts\weezerfont.ttf
c:\windows\SysWow64\ff\Fonts\WillyWonka.ttf
c:\windows\SysWow64\ff\Fonts\Xfiles.ttf
c:\windows\SysWow64\ff\Fonts\Yoshitoshi.ttf
c:\windows\SysWow64\ff\Fonts\Yukon Gold.ttf
c:\windows\SysWow64\ff\Fonts\zerogene.ttf
c:\windows\SysWow64\ff\Other\Help\images\donation_button.png
c:\windows\SysWow64\ff\Other\Help\images\favicon.ico
c:\windows\SysWow64\ff\Other\Help\images\help_background_footer.png
c:\windows\SysWow64\ff\Other\Help\images\help_background_header.png
c:\windows\SysWow64\ff\Other\Help\images\help_logo_top.png
c:\windows\SysWow64\ff\Other\Source\AppSource.txt
c:\windows\SysWow64\ff\Other\Source\CheckForPlatformSplashDisable.nsh
c:\windows\SysWow64\ff\Other\Source\FirefoxPortable.ini
c:\windows\SysWow64\ff\Other\Source\FirefoxPortable.jpg
c:\windows\SysWow64\ff\Other\Source\FirefoxPortableU.nsi
c:\windows\SysWow64\ff\Other\Source\License.txt
c:\windows\SysWow64\ff\Other\Source\PortableApps.comLauncherLANG_DUTCH.nsh
c:\windows\SysWow64\ff\Other\Source\PortableApps.comLauncherLANG_ENGLISH.nsh
c:\windows\SysWow64\ff\Other\Source\PortableApps.comLauncherLANG_ENGLISHGB.nsh
c:\windows\SysWow64\ff\Other\Source\PortableApps.comLauncherLANG_FRENCH.nsh
c:\windows\SysWow64\ff\Other\Source\PortableApps.comLauncherLANG_GERMAN.nsh
c:\windows\SysWow64\ff\Other\Source\PortableApps.comLauncherLANG_HUNGARIAN.nsh
c:\windows\SysWow64\ff\Other\Source\PortableApps.comLauncherLANG_ITALIAN.nsh
c:\windows\SysWow64\ff\Other\Source\PortableApps.comLauncherLANG_JAPANESE.nsh
c:\windows\SysWow64\ff\Other\Source\PortableApps.comLauncherLANG_KOREAN.nsh
c:\windows\SysWow64\ff\Other\Source\PortableApps.comLauncherLANG_POLISH.nsh
c:\windows\SysWow64\ff\Other\Source\PortableApps.comLauncherLANG_PORTUGUESE.nsh
c:\windows\SysWow64\ff\Other\Source\PortableApps.comLauncherLANG_PORTUGUESEBR.nsh
c:\windows\SysWow64\ff\Other\Source\PortableApps.comLauncherLANG_RUSSIAN.nsh
c:\windows\SysWow64\ff\Other\Source\PortableApps.comLauncherLANG_SIMPCHINESE.nsh
c:\windows\SysWow64\ff\Other\Source\PortableApps.comLauncherLANG_SPANISH.nsh
c:\windows\SysWow64\ff\Other\Source\PortableApps.comLauncherLANG_SPANISHINTERNATIONAL.nsh
c:\windows\SysWow64\ff\Other\Source\PortableApps.comLauncherLANG_TRADCHINESE.nsh
c:\windows\SysWow64\ff\Other\Source\ReadINIStrWithDefault.nsh
c:\windows\SysWow64\ff\Other\Source\Readme.txt
c:\windows\SysWow64\ff\Other\Source\ReplaceInFileWithTextReplace.nsh
c:\windows\SysWow64\ff\Other\Source\SetFileAttributesDirectoryNormal.nsh
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-11-28 bis 2013-12-31 ))))))))))))))))))))))))))))))
.
.
2013-12-31 15:38 . 2013-12-31 15:38 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-12-31 15:38 . 2013-12-31 15:38 -------- d-----w- c:\users\hedev\AppData\Local\temp
2013-12-31 15:38 . 2013-12-31 15:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-25 19:27 . 2013-12-25 19:27 -------- d-----w- c:\programdata\MTA San Andreas All
2013-12-25 16:45 . 2013-12-25 16:45 -------- d-----w- c:\program files (x86)\VS Revo Group
2013-12-24 13:44 . 2013-12-24 13:44 -------- d-----w- C:\Riot Games
2013-12-24 11:16 . 2013-12-24 11:16 -------- d-----w- c:\windows\ERUNT
2013-12-24 11:05 . 2013-12-24 11:08 -------- d-----w- C:\AdwCleaner
2013-12-22 09:39 . 2013-12-28 13:35 -------- d-----w- C:\FRST
2013-12-21 19:59 . 2013-12-21 19:59 -------- d-----w- c:\users\Mesut\AppData\Roaming\Malwarebytes
2013-12-21 19:58 . 2013-12-21 19:58 -------- d-----w- c:\programdata\Malwarebytes
2013-12-21 19:58 . 2013-12-21 19:58 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-12-21 19:58 . 2013-04-04 13:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-12-18 15:46 . 2013-12-18 15:46 -------- d-----w- c:\users\Mesut\AppData\Roaming\OpenOffice
2013-12-18 15:44 . 2013-12-18 15:45 -------- d-----w- c:\program files (x86)\OpenOffice 4
2013-12-09 20:47 . 2013-12-09 20:57 -------- d--h--w- c:\windows\SysWow64\FF_BN_2019128
2013-12-08 17:31 . 2013-12-08 17:31 -------- d-----w- c:\program files (x86)\Common Files\Bitdefender
2013-12-07 15:14 . 2013-12-07 15:14 -------- d-----w- c:\programdata\regid.1995-08.com.techsmith
2013-12-07 15:14 . 2013-12-07 15:14 -------- d-----w- c:\program files (x86)\QuickTime
2013-12-07 15:02 . 2013-12-08 01:16 -------- d-----w- c:\users\Mesut\F5C9BE9A04C34A728CD0BB67C722D608.TMP
2013-12-07 14:36 . 2013-12-07 14:36 -------- d-----w- c:\users\Mesut\AppData\Roaming\BANDISOFT
2013-12-07 14:35 . 2013-12-07 14:35 -------- d-----w- c:\program files (x86)\Bandicam
2013-12-07 14:35 . 2013-12-07 14:35 -------- d-----w- c:\program files (x86)\BandiMPEG1
2013-12-05 12:23 . 2013-12-05 12:23 -------- d-----w- c:\program files (x86)\Aeria Games
2013-12-05 11:28 . 2013-12-07 14:33 -------- d-----w- C:\AeriaGames
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-28 13:05 . 2013-08-11 13:43 139264 ----a-w- c:\windows\SysWow64\r_unzip.exe
2013-11-28 21:41 . 2013-08-29 12:10 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-11-28 21:41 . 2013-08-24 21:01 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-07 10:52 . 2013-11-07 10:52 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{09326DD3-D6DC-4DFE-9AF4-BF364A099A02}\offreg.dll
2013-10-12 14:08 . 2013-07-13 16:11 291128 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-10-12 14:08 . 2013-07-13 16:02 291128 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-10-12 14:07 . 2013-07-13 16:02 281872 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-10-12 14:07 . 2013-07-13 16:02 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-10-08 05:50 . 2013-10-20 10:17 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-11-14 20584608]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2013-12-11 1823656]
"Akamai NetSession Interface"="c:\users\Mesut\AppData\Local\Akamai\netsession_win.exe" [2013-06-04 4489472]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2013-09-21 766208]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2013-11-29 3806544]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sdnclean64.exe
.
R2 AODDriver4.2.0;AODDriver4.2.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 Rent Update;Rent Update;C:/Windows/Rent/Update.exe;C:/Windows/Rent/Update.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 ArcService;Arc Service;c:\program files (x86)\Perfect World Entertainment\Arc\ArcService.exe;c:\program files (x86)\Perfect World Entertainment\Arc\ArcService.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 FairplayKD;FairplayKD;c:\programdata\MTA San Andreas All\1.3\temp\FairplayKD.sys;c:\programdata\MTA San Andreas All\1.3\temp\FairplayKD.sys [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.8.130\McCHSvc.exe;c:\program files\McAfee Security Scan\3.8.130\McCHSvc.exe [x]
R3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys;c:\windows\SYSNATIVE\drivers\Mkd2Nadr.sys [x]
R3 Mkd3kfNt;Mkd3kfNt;c:\windows\system32\drivers\Mkd3kfNt.sys;c:\windows\SYSNATIVE\drivers\Mkd3kfNt.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Microsoft Virtual 3D Video Transport Driver;c:\windows\system32\drivers\Synth3dVsc.sys;c:\windows\SYSNATIVE\drivers\Synth3dVsc.sys [x]
R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;Remote Deskotop USB Hub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [x]
R3 wolf;wolf;c:\aeriagames\WolfTeam-DE\avital\wolf64.sys;c:\aeriagames\WolfTeam-DE\avital\wolf64.sys [x]
R3 X6va012;X6va012;c:\windows\SysWOW64\Drivers\X6va012;c:\windows\SysWOW64\Drivers\X6va012 [x]
R3 X6va015;X6va015;c:\windows\SysWOW64\Drivers\X6va015;c:\windows\SysWOW64\Drivers\X6va015 [x]
R3 xhunter1;xhunter1;c:\windows\xhunter1.sys;c:\windows\xhunter1.sys [x]
R4 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S0 aswRvrt;aswRvrt; [x]
S0 aswVmm;aswVmm; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-05 10:46 1210320 ----a-w- c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-06-01 13:18]
.
2013-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-06-01 13:18]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-05-09 08:58 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"W7LXE"="c:\users\Mesut\Desktop\Windows 7 Loader eXtreme Edition v3.503\w7lxe.exe" [2010-05-22 28135936]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-07-03 1028896]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
ustart page = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = <local>
Trusted Zone: aeriagames.com
TCP: DhcpNameServer = 192.168.2.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-Adobe Flash Player ActiveX - c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_9_900_117_ActiveX.exe
AddRemove-BattlEye for A2 - c:\program files (x86)\Steam\steamapps\common\Arma 2BattlEye\UnInstallBE.exe
AddRemove-BattlEye for OA - c:\program files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\Expansion\BattlEye\UnInstallBE.exe
AddRemove-Crossfire Europe - c:\sg interactive\Crossfire Europe\uninst.exe
AddRemove-{1a413f37-ed88-4fec-9666-5c48dc4b7bb7} - c:\program files (x86)\GreenTree Applications\YTD Video Downloader\uninstall.exe
AddRemove-{3108C217-BE83-42E4-AE9E-A56A2A92E549} - c:\program files (x86)\InstallShield Installation Information\{3108C217-BE83-42E4-AE9E-A56A2A92E549}\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\Rent Update]
"ImagePath"="C:/Windows/Rent/Update.exe"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\Rent Update]
"ImagePath"="C:/Windows/Rent/Update.exe"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va012]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va012"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va015]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va015"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3476550111-2045390708-2280625213-1000\Software\SecuROM\License information*]
"datasecu"=hex:17,da,a6,e3,92,01,53,db,f8,5c,8b,3b,60,7c,08,98,ac,49,d1,b6,cc,
39,44,5b,a7,84,3b,5c,d4,6b,42,e5,15,d7,0f,29,9b,4e,1b,b3,91,40,c1,06,12,de,\
"rkeysecu"=hex:91,1c,db,6d,7a,7c,a7,7d,27,17,29,3e,4e,a0,d8,99
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-12-31 16:41:04
ComboFix-quarantined-files.txt 2013-12-31 15:41
ComboFix2.txt 2013-12-23 13:51
.
Vor Suchlauf: 88'408'162'304 bytes free
Nach Suchlauf: 20 Verzeichnis(se), 88'461'209'600 Bytes frei
.
- - End Of File - - 5E51C7E957D450F89671628403D278F3 ist es eig normal das soviele mein thema anklicken sind ja schon fast 500 klicks D:
und wünsche dir nen guten rutsch ins neue jahr :) |