Skalli F | 16.10.2016 21:54 | Alles nach Plan gemacht :)
Rkill log: Code:
Rkill 2.8.4 by Lawrence Abrams (Grinler)
hxxp://www.bleepingcomputer.com/
Copyright 2008-2016 BleepingComputer.com
More Information about Rkill can be found at this link:
hxxp://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 10/16/2016 10:18:48 PM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\Users\Lizenznehmer\Downloads\BaronReplays\BaronReplays\BaronReplays.exe (PID: 1916) [UP-HEUR]
* C:\Users\Lizenznehmer\Downloads\BaronReplays\BaronReplays\CefSharp.BrowserSubprocess.exe (PID: 5196) [UP-HEUR]
* C:\Users\Lizenznehmer\Downloads\BaronReplays\BaronReplays\CefSharp.BrowserSubprocess.exe (PID: 5268) [UP-HEUR]
3 proccesses terminated!
Checking Registry for malware related settings:
* apvxdwin.exe debugger. [IFEO Debugger Deleted]
* avastSvc.exe debugger. [IFEO Debugger Deleted]
* avastUI.exe debugger. [IFEO Debugger Deleted]
* avkservice.exe debugger. [IFEO Debugger Deleted]
* avp.exe debugger. [IFEO Debugger Deleted]
* blackd.exe debugger. [IFEO Debugger Deleted]
* blackice.exe debugger. [IFEO Debugger Deleted]
* cmdagent.exe debugger. [IFEO Debugger Deleted]
* cmgrdian.exe debugger. [IFEO Debugger Deleted]
* cpd.exe debugger. [IFEO Debugger Deleted]
* cv.exe debugger. [IFEO Debugger Deleted]
* espwatch.exe debugger. [IFEO Debugger Deleted]
* ethereal.exe debugger. [IFEO Debugger Deleted]
* fameh32.exe debugger. [IFEO Debugger Deleted]
* firewall.exe debugger. [IFEO Debugger Deleted]
* fsgk32.exe debugger. [IFEO Debugger Deleted]
* fsm32.exe debugger. [IFEO Debugger Deleted]
* fsma32.exe debugger. [IFEO Debugger Deleted]
* iface.exe debugger. [IFEO Debugger Deleted]
* lookout.exe debugger. [IFEO Debugger Deleted]
* mbam.exe debugger. [IFEO Debugger Deleted]
* mbamscheduler.exe debugger. [IFEO Debugger Deleted]
* mbamservice.exe debugger. [IFEO Debugger Deleted]
* MpCmdRun.exe debugger. [IFEO Debugger Deleted]
* MSASCui.exe debugger. [IFEO Debugger Deleted]
* MsMpEng.exe debugger. [IFEO Debugger Deleted]
* msseces.exe debugger. [IFEO Debugger Deleted]
* navapsvc.exe debugger. [IFEO Debugger Deleted]
* netmon.exe debugger. [IFEO Debugger Deleted]
* nod32.exe debugger. [IFEO Debugger Deleted]
* outpost.exe debugger. [IFEO Debugger Deleted]
* persfw.exe debugger. [IFEO Debugger Deleted]
* PSANHost.exe debugger. [IFEO Debugger Deleted]
* regedit.exe debugger. [IFEO Debugger Deleted]
* spybotsd.exe debugger. [IFEO Debugger Deleted]
* taskmgr.exe debugger. [IFEO Debugger Deleted]
* virusutilities.exe debugger. [IFEO Debugger Deleted]
* wireshark.exe debugger. [IFEO Debugger Deleted]
Backup Registry file created at:
C:\Users\Lizenznehmer\Desktop\rkill\rkill-10-16-2016-10-18-55.reg
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* TBS [Missing Service]
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* Cannot edit the HOSTS file.
* Permissions could not be fixed. Use Hosts-perm.bat to fix permissions: hxxp://www.bleepingcomputer.com/download/hosts-permbat/
Program finished at: 10/16/2016 10:19:45 PM
Execution time: 0 hours(s), 0 minute(s), and 57 seconds(s) Und Combofix: Code:
ComboFix 16-09-28.01 - Lizenznehmer 16.10.2016 22:32:17.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8102.4599 [GMT 2:00]
ausgeführt von:: c:\users\Lizenznehmer\Desktop\ComboFix.exe
AV: Avira Antivirus *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Antivirus *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\END
c:\program files (x86)\Searchqu Toolbar\Datamngr
c:\program files (x86)\Searchqu Toolbar\Datamngr\x64\BrowserConnection.dll
c:\programdata\374311380
c:\users\Lizenznehmer\AppData\Local\assembly\tmp
c:\users\Lizenznehmer\AppData\Local\lollipop
c:\users\Lizenznehmer\AppData\Roaming\convert\convert.exe
c:\users\Lizenznehmer\AppData\Roaming\dclogs
c:\users\Lizenznehmer\AppData\Roaming\dclogs\2014-10-26-1.dc
c:\users\Lizenznehmer\AppData\Roaming\loadtbs
c:\users\Lizenznehmer\AppData\Roaming\loadtbs\config.txt
c:\users\Lizenznehmer\AppData\Roaming\loadtbs\domHash.txt
c:\users\Lizenznehmer\AppData\Roaming\loadtbs\evHash.txt
c:\users\Lizenznehmer\AppData\Roaming\loadtbs\html\dimensions.ini
c:\users\Lizenznehmer\AppData\Roaming\loadtbs\html\install.html
c:\users\Lizenznehmer\AppData\Roaming\loadtbs\html\license.txt
c:\users\Lizenznehmer\AppData\Roaming\loadtbs\html\uninstall.html
c:\users\Lizenznehmer\AppData\Roaming\loadtbs\html\uninstallComplete.html
c:\users\Lizenznehmer\AppData\Roaming\loadtbs\keyHash.txt
c:\users\Lizenznehmer\AppData\Roaming\loadtbs\uninstall.exe
c:\users\Lizenznehmer\AppData\Roaming\loadtbs\updateHash.txt
c:\users\Lizenznehmer\AppData\Roaming\WTouch
c:\users\Lizenznehmer\AppData\Roaming\WTouch\WTouch.xml
c:\users\Lizenznehmer\Documents\~WRL0003.tmp
c:\users\Lizenznehmer\Documents\MSDCSC\msdcsc.exe
c:\windows\SysWow64\logs
c:\windows\SysWow64\logs\2016-03-17T11-13-00Log.txt
c:\windows\SysWow64\tmp2B34.tmp
c:\windows\SysWow64\tmp5C81.tmp
c:\windows\SysWow64\tmp68A2.tmp
c:\windows\SysWow64\tmp68C2.tmp
c:\windows\SysWow64\tmp7B28.tmp
c:\windows\SysWow64\tmpE761.tmp
.
.
((((((((((((((((((((((( Dateien erstellt von 2016-09-16 bis 2016-10-16 ))))))))))))))))))))))))))))))
.
.
2016-10-16 20:46 . 2016-10-16 20:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-10-16 20:39 . 2016-10-16 20:39 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{196462BD-13D9-4B17-A4A9-16B22B58724B}\offreg.2772.dll
2016-10-16 16:12 . 2016-10-16 16:21 -------- d-----w- c:\program files\TrueKey
2016-10-16 16:12 . 2016-10-16 17:43 -------- d-----w- c:\program files (x86)\McAfee Security Scan
2016-10-16 16:11 . 2016-10-16 16:11 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2016-10-16 12:43 . 2016-10-16 12:43 -------- d-----w- C:\avrescue
2016-10-15 19:02 . 2016-10-15 19:13 -------- d-----w- C:\FRST
2016-10-15 12:11 . 2016-10-15 12:11 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{196462BD-13D9-4B17-A4A9-16B22B58724B}\offreg.5432.dll
2016-10-15 11:10 . 2016-10-15 11:10 -------- d-----w- c:\program files\CCleaner
2016-10-15 09:25 . 2016-10-15 09:25 -------- d-----w- c:\users\Lizenznehmer\AppData\Roaming\GlarySoft
2016-10-15 09:24 . 2016-10-15 09:24 -------- d-----w- c:\program files (x86)\Glarysoft
2016-10-14 14:18 . 2016-10-16 15:35 -------- d-----w- c:\programdata\SecTaskMan
2016-10-14 14:18 . 2016-10-14 14:18 -------- d-----w- c:\program files (x86)\Security Task Manager
2016-10-14 12:36 . 2016-10-14 12:36 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{196462BD-13D9-4B17-A4A9-16B22B58724B}\offreg.6584.dll
2016-10-14 11:45 . 2016-09-15 01:18 12030488 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{196462BD-13D9-4B17-A4A9-16B22B58724B}\mpengine.dll
2016-10-12 09:12 . 2016-09-12 21:17 77032 ----a-w- c:\windows\system32\CompatTelRunner.exe
2016-10-12 09:12 . 2016-09-12 21:08 1226752 ----a-w- c:\windows\system32\aeinv.dll
2016-10-12 09:12 . 2016-09-09 15:54 586752 ----a-w- c:\windows\system32\generaltel.dll
2016-10-12 09:12 . 2016-09-09 15:54 314368 ----a-w- c:\windows\system32\invagent.dll
2016-10-12 09:12 . 2016-09-09 15:54 575488 ----a-w- c:\windows\system32\devinv.dll
2016-10-12 09:12 . 2016-09-09 15:54 273408 ----a-w- c:\windows\system32\centel.dll
2016-10-12 09:12 . 2016-09-09 15:54 224256 ----a-w- c:\windows\system32\aepic.dll
2016-10-12 09:12 . 2016-09-09 15:54 1629184 ----a-w- c:\windows\system32\appraiser.dll
2016-10-12 09:12 . 2016-09-09 15:54 129024 ----a-w- c:\windows\system32\acmigration.dll
2016-10-08 10:59 . 2016-10-01 19:24 133056 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2016-10-08 10:59 . 2016-09-09 18:25 269600 ----a-w- c:\windows\SysWow64\vulkan-1.dll
2016-10-08 10:59 . 2016-09-09 18:25 110880 ----a-w- c:\windows\SysWow64\vulkaninfo.exe
2016-10-08 10:59 . 2016-09-09 18:25 261920 ----a-w- c:\windows\system32\vulkan-1.dll
2016-10-08 10:59 . 2016-09-09 18:24 125216 ----a-w- c:\windows\system32\vulkaninfo.exe
2016-10-06 08:13 . 2016-10-06 08:10 31720 ----a-w- c:\windows\system32\drivers\avusbflt.sys
2016-10-03 16:57 . 2016-10-03 16:57 -------- d-----w- c:\program files (x86)\VirtualDJ
2016-10-03 14:34 . 2016-10-01 21:15 19856296 ----a-w- c:\windows\system32\nvwgf2umx.dll
2016-10-03 14:34 . 2016-10-01 21:15 17272008 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2016-10-03 14:34 . 2016-09-19 23:09 54728 ----a-w- c:\windows\system32\nvhdap64.dll
2016-10-03 14:34 . 2016-09-19 23:09 223304 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
2016-10-03 14:34 . 2016-10-01 21:15 3919048 ----a-w- c:\windows\system32\nvapi64.dll
2016-10-03 14:34 . 2016-10-01 21:15 3459448 ----a-w- c:\windows\SysWow64\nvapi.dll
2016-10-03 14:34 . 2016-10-01 21:15 14353328 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2016-10-03 14:34 . 2016-09-17 00:46 1922616 ----a-w- c:\windows\system32\nvdispco6437290.dll
2016-10-03 14:34 . 2016-09-17 00:46 1585088 ----a-w- c:\windows\system32\nvdispgenco6437290.dll
2016-09-24 21:19 . 2016-09-24 21:19 -------- d-----w- c:\program files\iPod
2016-09-24 21:19 . 2016-09-24 21:19 -------- d-----w- c:\program files\iTunes
2016-09-24 21:17 . 2016-09-24 21:17 -------- d-----w- c:\program files (x86)\Apple Software Update
2016-09-24 16:21 . 2016-09-24 16:21 -------- d-----w- c:\program files\Bonjour
2016-09-24 16:21 . 2016-09-24 16:21 -------- d-----w- c:\program files (x86)\Bonjour
2016-09-24 16:20 . 2016-09-24 21:19 -------- d-----w- c:\program files\Common Files\Apple
2016-09-24 12:09 . 2016-09-24 12:09 -------- d-----w- c:\program files (x86)\Lame For Audacity
2016-09-24 12:03 . 2016-09-24 12:03 -------- d-----w- c:\program files (x86)\Chip Digital GmbH
2016-09-24 12:03 . 2016-09-24 12:03 -------- d-----w- c:\users\Lizenznehmer\AppData\Local\Downloaded Installations
2016-09-23 21:16 . 2016-09-24 09:57 -------- d-----w- c:\programdata\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2016-09-21 09:40 . 2016-08-05 15:30 2048 ----a-w- c:\windows\system32\tzres.dll
2016-09-21 09:40 . 2016-08-05 15:13 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2016-09-18 18:03 . 2016-08-12 16:26 464896 ----a-w- c:\windows\system32\drivers\srv.sys
2016-09-18 18:03 . 2016-08-12 16:26 405504 ----a-w- c:\windows\system32\drivers\srv2.sys
2016-09-18 18:03 . 2016-08-12 16:26 168960 ----a-w- c:\windows\system32\drivers\srvnet.sys
2016-09-18 18:01 . 2016-08-16 17:36 1009152 ----a-w- c:\windows\system32\user32.dll
2016-09-18 18:01 . 2016-08-16 02:48 833024 ----a-w- c:\windows\SysWow64\user32.dll
2016-09-18 17:54 . 2016-07-07 15:36 1896168 ----a-w- c:\windows\system32\drivers\tcpip.sys
2016-09-18 17:54 . 2016-07-07 15:36 377576 ----a-w- c:\windows\system32\drivers\netio.sys
2016-09-18 17:54 . 2016-07-07 15:36 287976 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2016-09-18 17:54 . 2016-07-07 15:08 46080 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2016-09-18 17:54 . 2016-08-06 15:31 877056 ----a-w- c:\windows\system32\oleaut32.dll
2016-09-18 17:54 . 2016-08-06 15:15 581632 ----a-w- c:\windows\SysWow64\oleaut32.dll
2016-09-17 14:01 . 2016-09-17 01:42 1842744 ----a-w- c:\windows\system32\nvspcap64.dll
2016-09-17 14:01 . 2016-09-17 01:42 1756728 ----a-w- c:\windows\system32\nvspbridge64.dll
2016-09-17 14:01 . 2016-09-17 01:42 1450040 ----a-w- c:\windows\SysWow64\nvspcap.dll
2016-09-17 14:01 . 2016-09-17 01:42 1318968 ----a-w- c:\windows\SysWow64\nvspbridge.dll
2016-09-17 14:01 . 2016-09-17 01:42 121912 ----a-w- c:\windows\system32\NvRtmpStreamer64.dll
2016-09-17 14:01 . 2016-09-16 22:40 1951 ----a-w- c:\windows\NvContainerRecovery.bat
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-10-16 19:49 . 2012-06-12 13:33 796352 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2016-10-16 19:49 . 2011-11-21 08:46 142528 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2016-10-12 22:01 . 2011-11-21 09:57 143495576 -c--a-w- c:\windows\system32\MRT.exe
2016-10-06 08:10 . 2013-09-09 15:56 145536 ----a-w- c:\windows\system32\drivers\avipbb.sys
2016-10-06 08:10 . 2013-09-09 15:56 177432 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2016-10-01 19:44 . 2014-10-25 11:24 2473408 ----a-w- c:\windows\system32\nvsvc64.dll
2016-10-01 19:44 . 2014-10-25 11:24 6384064 ----a-w- c:\windows\system32\nvcpl.dll
2016-10-01 19:44 . 2015-12-21 17:40 83512 ----a-w- c:\windows\system32\nv3dappshextr.dll
2016-10-01 19:44 . 2015-12-21 17:40 546752 ----a-w- c:\windows\system32\nv3dappshext.dll
2016-10-01 19:44 . 2014-10-25 11:24 69568 ----a-w- c:\windows\system32\nvshext.dll
2016-10-01 19:44 . 2014-10-25 11:24 393784 ----a-w- c:\windows\system32\nvmctray.dll
2016-10-01 19:44 . 2014-10-25 11:24 1764408 ----a-w- c:\windows\system32\nvsvcr.dll
2016-10-01 19:44 . 2014-10-25 11:24 1362368 ----a-w- c:\windows\system32\nvvsvc.exe
2016-10-01 00:26 . 2014-10-25 11:24 7422645 ----a-w- c:\windows\system32\nvcoproc.bin
2016-09-19 23:09 . 2016-07-08 16:43 1588688 ----a-w- c:\windows\system32\nvhdagenco6420103.dll
2016-09-09 18:25 . 2016-09-09 18:25 269600 ----a-w- c:\windows\SysWow64\vulkan-1-1-0-26-0.dll
2016-09-09 18:25 . 2016-09-09 18:25 110880 ----a-w- c:\windows\SysWow64\vulkaninfo-1-1-0-26-0.exe
2016-09-09 18:25 . 2016-09-09 18:25 261920 ----a-w- c:\windows\system32\vulkan-1-1-0-26-0.dll
2016-09-09 18:24 . 2016-09-09 18:24 125216 ----a-w- c:\windows\system32\vulkaninfo-1-1-0-26-0.exe
2016-09-09 17:59 . 2016-10-12 10:10 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2016-09-02 11:13 . 2016-05-13 17:10 94144 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2016-09-02 11:13 . 2016-05-13 17:10 46016 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2016-09-02 11:13 . 2016-05-13 17:10 104384 ----a-w- c:\windows\system32\nvaudcap64v.dll
2016-08-28 10:58 . 2016-08-28 10:58 0 ---ha-w- c:\users\Lizenznehmer\AppData\Local\BITD605.tmp
2016-08-25 23:28 . 2016-08-31 13:23 1920960 ----a-w- c:\windows\system32\nvdispco6437270.dll
2016-08-25 23:28 . 2016-08-31 13:23 1586744 ----a-w- c:\windows\system32\nvdispgenco6437270.dll
2016-08-12 16:46 . 2016-10-12 10:10 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2016-08-11 14:31 . 2016-08-17 10:26 1922616 ----a-w- c:\windows\system32\nvdispco6437254.dll
2016-08-11 14:31 . 2016-08-17 10:26 1586744 ----a-w- c:\windows\system32\nvdispgenco6437254.dll
2016-07-26 12:24 . 2011-11-18 09:58 504488 ------w- c:\windows\system32\MpSigStub.exe
2014-03-07 08:03 3109520 --sha-r- c:\windows\SysWOW64\avcodec-lav-55.dll
2014-03-07 08:03 98960 --sha-r- c:\windows\SysWOW64\avfilter-lav-4.dll
2014-03-07 08:03 550032 --sha-r- c:\windows\SysWOW64\avformat-lav-55.dll
2009-09-27 07:39 415744 --sh--w- c:\windows\SysWOW64\avisynth.dll
2014-03-07 08:03 59536 --sha-r- c:\windows\SysWOW64\avresample-lav-1.dll
2005-07-14 10:31 32256 --sh--w- c:\windows\SysWOW64\AVSredirect.dll
2014-03-07 08:03 181392 --sha-r- c:\windows\SysWOW64\avutil-lav-52.dll
2004-02-22 08:11 764416 --sh--w- c:\windows\SysWOW64\devil.dll
2014-03-07 08:03 122512 --sha-r- c:\windows\SysWOW64\HLaudio.dll
2014-03-07 08:03 203408 --sha-r- c:\windows\SysWOW64\HLsplit.dll
2014-03-07 08:03 313520 --sha-r- c:\windows\SysWOW64\HLvideo.dll
2004-01-24 22:00 70656 --sh--w- c:\windows\SysWOW64\i420vfw.dll
2014-03-07 08:03 166544 --sha-r- c:\windows\SysWOW64\IntelQuickSyncDecoder.dll
2014-03-07 08:03 109712 --sha-r- c:\windows\SysWOW64\libbluray.dll
2011-02-11 07:26 112128 --sha-r- c:\windows\SysWOW64\OptimFROG.dll
2014-03-07 08:03 118416 --sha-r- c:\windows\SysWOW64\swscale-lav-2.dll
2010-01-06 21:00 107520 --sha-r- c:\windows\SysWOW64\TAKDSDecoder.dll
2012-10-05 16:54 188416 --sha-r- c:\windows\SysWOW64\winDCE32.dll
2004-01-24 22:00 70656 --sh--w- c:\windows\SysWOW64\yv12vfw.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BingSvc"="c:\users\Lizenznehmer\AppData\Local\Microsoft\BingSvc\BingSvc.exe" [2016-01-13 144008]
"BlueStacks Agent"="c:\program files (x86)\Bluestacks\HD-Agent.exe" [2016-08-03 978456]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2016-08-26 8912088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2016-10-06 917584]
"Corsair Utility Engine"="c:\program files (x86)\Corsair\Corsair Utility Engine\CorsairHID.exe" [2016-03-23 14885552]
"Avira SystrayStartTrigger"="c:\program files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe" [2016-08-19 60136]
"Wondershare Helper Compact.exe"="c:\program files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe" [2016-06-20 2131344]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
.
R2 AntiVirMailService;Avira Email-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avmailc7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avmailc7.exe [x]
R2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x]
R2 Apple Mobile Device Service;Apple Mobile Device Service;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
R2 tor;Tor Win32 Service;c:\program files (x86)\Tor\tor.exe;c:\program files (x86)\Tor\tor.exe [x]
R3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\DRIVERS\lgandnetdiag64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetdiag64.sys [x]
R3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\DRIVERS\lgandnetmodem64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetmodem64.sys [x]
R3 andnetndis;LGE AndroidNet NDIS Ethernet Adapter;c:\windows\system32\DRIVERS\lgandnetndis64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetndis64.sys [x]
R3 ArcService;Arc Service;d:\prograaame\Arc\ArcService.exe;d:\prograaame\Arc\ArcService.exe [x]
R3 BstHdPlusAndroidSvc;BlueStacks Plus Android Service ;c:\program files (x86)\BlueStacks\HD-Plus-Service.exe BstHdPlusAndroidSvc Android;c:\program files (x86)\BlueStacks\HD-Plus-Service.exe BstHdPlusAndroidSvc Android [x]
R3 BstkDrv;BlueStacks Plus Hypervisor;c:\program files (x86)\BlueStacks\BstkDrv.sys;c:\program files (x86)\BlueStacks\BstkDrv.sys [x]
R3 dtscsibus;DAEMON Tools Virtual SCSI Bus;c:\windows\system32\DRIVERS\dtscsibus.sys;c:\windows\SYSNATIVE\DRIVERS\dtscsibus.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 EasyAntiCheat;EasyAntiCheat;c:\windows\system32\EasyAntiCheat.exe;c:\windows\SYSNATIVE\EasyAntiCheat.exe [x]
R3 hidkmdf;KMDF Driver;c:\windows\system32\DRIVERS\hidkmdf.sys;c:\windows\SYSNATIVE\DRIVERS\hidkmdf.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 LGPBTDD;LGPBTDD.sys Display Driver;c:\windows\system32\Drivers\LGPBTDD.sys;c:\windows\SYSNATIVE\Drivers\LGPBTDD.sys [x]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys;c:\windows\SYSNATIVE\DRIVERS\netaapl64.sys [x]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys;c:\windows\SYSNATIVE\drivers\npf.sys [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x]
R3 NvContainerNetworkService;NVIDIA NetworkService Container;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe [x]
R3 NvStreamKms;NVIDIA KMS;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WacHidRouter;Wacom Hid Router;c:\windows\system32\DRIVERS\wachidrouter.sys;c:\windows\SYSNATIVE\DRIVERS\wachidrouter.sys [x]
R3 wacomrouterfilter;Wacom Router Filter Driver;c:\windows\system32\DRIVERS\wacomrouterfilter.sys;c:\windows\SYSNATIVE\DRIVERS\wacomrouterfilter.sys [x]
R4 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
R4 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [x]
S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AsrAppCharger.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 Avira.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\Launcher\Avira.ServiceHost.exe;c:\program files (x86)\Avira\Launcher\Avira.ServiceHost.exe [x]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x]
S2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [x]
S2 chip1click;chip 1-click download service;c:\program files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe;c:\program files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;d:\prograaame\HiPatchService.exe;d:\prograaame\HiPatchService.exe [x]
S2 InstallerService;Service Installer TrueKey;c:\program files\TrueKey\Mcafee.TrueKey.InstallerService.exe;c:\program files\TrueKey\Mcafee.TrueKey.InstallerService.exe [x]
S2 LGCoreTemp;Logitech CPU Core Tempurature;c:\program files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys;c:\program files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [x]
S2 LogiRegistryService;Logitech Gaming Registry Service;c:\program files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe;c:\program files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [x]
S2 LolScreenSaverService;League-Bildschirmschoner;c:\riot games\LolScreenSaver\service\service.exe;c:\riot games\LolScreenSaver\service\service.exe [x]
S2 NvContainerLocalSystem;NVIDIA LocalSystem Container;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe [x]
S2 NVIDIA Wireless Controller Service;NVIDIA Wireless Controller Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe [x]
S2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe;c:\windows\SYSNATIVE\Pen_Tablet.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 WTouchService;WTouch Service;c:\program files\WTouch\WTouchService.exe;c:\program files\WTouch\WTouchService.exe [x]
S3 CorsairVBusDriver;Corsair Bus;c:\windows\system32\DRIVERS\CorsairVBusDriver.sys;c:\windows\SYSNATIVE\DRIVERS\CorsairVBusDriver.sys [x]
S3 CorsairVHidDriver;Corsair virtual device;c:\windows\system32\DRIVERS\CorsairVHidDriver.sys;c:\windows\SYSNATIVE\DRIVERS\CorsairVHidDriver.sys [x]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
S3 LGBusEnum;Logitech Gaming Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGJoyXlCore;Logitech Translation Layer Driver (LGS);c:\windows\system32\drivers\LGJoyXlCore.sys;c:\windows\SYSNATIVE\drivers\LGJoyXlCore.sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 VirtuWDDM;VirtuWDDM;c:\windows\system32\DRIVERS\VirtuWDDM.sys;c:\windows\SYSNATIVE\DRIVERS\VirtuWDDM.sys [x]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys;c:\windows\SYSNATIVE\DRIVERS\wacmoumonitor.sys [x]
S4 InstallerWrapperService;Service Installer Wrapper TrueKey;c:\program files\TrueKey\InstallerWrapperService.exe;c:\program files\TrueKey\InstallerWrapperService.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2016-09-30 11:51 1266792 ----a-w- c:\program files (x86)\Google\Chrome\Application\53.0.2785.143\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2016-10-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-16 19:49]
.
2014-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cf8ea01eb8a709.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-06-04 10:21]
.
2016-10-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cfede160f58db0.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-06-04 10:21]
.
2016-10-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-06-04 10:21]
.
2016-10-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3006522507-4162188302-2506447229-1000Core.job
- c:\users\Lizenznehmer\AppData\Local\Google\Update\GoogleUpdate.exe [2015-07-12 10:36]
.
2016-10-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3006522507-4162188302-2506447229-1000UA.job
- c:\users\Lizenznehmer\AppData\Local\Google\Update\GoogleUpdate.exe [2015-07-12 10:36]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-06-09 11860072]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2016-02-17 15120504]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2016-09-09 176440]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mDefault_Search_URL = hxxp://www.luckysearches.com/web/?type=ds&ts=1429074380&from=fsf&uid=WDCXWD10EARX-00N0YB0_WD-WCC0T016841968419&q={searchTerms}
mDefault_Page_URL = about:blank
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.luckysearches.com/web/?type=ds&ts=1429074380&from=fsf&uid=WDCXWD10EARX-00N0YB0_WD-WCC0T016841968419&q={searchTerms}
uSearchAssistant = hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=Tuguu&co=DE&userid=3a96577b-d1c7-4b6b-ad01-9aa3cab0a6ba&searchtype=ds&q={searchTerms}&installDate=28/06/2013
IE: An OneNote s&enden - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Lizenznehmer\AppData\Roaming\Mozilla\Firefox\Profiles\g6ao6thf.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxps://www.youtube.com/
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M&q=
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{D8278076-BC68-4484-9233-6E7F1628B56C} - (no file)
Toolbar-{99079a25-328f-4bd4-be04-00955acaa0a7} - (no file)
Toolbar-10 - (no file)
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ImageBrowser EX Agent.lnk - c:\program files (x86)\Canon\ImageBrowser EX\MFManager.exe
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\LOLRecorder.lnk - c:\program files (x86)\LOLReplay\LOLRecorder.exe -minimize
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
BHO-{9D717F81-9148-4f12-8568-69135F087DB0} - c:\progra~2\SEARCH~1\Datamngr\x64\BROWSE~1.DLL
Toolbar-10 - (no file)
WebBrowser-{40C3CC16-7269-4B32-9531-17F2950FB06F} - (no file)
AddRemove-{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} - c:\users\Lizenznehmer\AppData\Local\3973\Updater.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3006522507-4162188302-2506447229-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:82,29,49,f7,47,dd,4d,c7,86,47,ab,4e,fa,f2,2e,b4,fb,fd,fe,b0,37,
10,12,d1,f7,06,85,61,c5,6a,b3,89,77,51,99,f5,b6,0e,92,fa,02,1f,75,59,cf,86,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\software\BlueStacks]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_23_0_0_185_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_23_0_0_185_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_23_0_0_185_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_23_0_0_185_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_23_0_0_185.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.23"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_23_0_0_185.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_23_0_0_185.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_23_0_0_185.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2016-10-16 22:48:23
ComboFix-quarantined-files.txt 2016-10-16 20:48
.
Vor Suchlauf: 9.344.630.784 Bytes frei
Nach Suchlauf: 8.093.450.240 Bytes frei
.
- - End Of File - - 372403856F0B40060A76B1386BE580A0
A36C5E4F47E84449FF07ED3517B43A31 |