Heistmer | 11.10.2012 10:03 | Das hab ich nun auch geschafft,
Probleme gab es dabei Combofix zu starten. Das System ist immer bei ca der Hälfte bei verzeichniss C:/32788R22FWJFW hängen geblieben.
Nach mehrfachen versuchen, und zwischenzeitlichen Löschens des Ordners hat es dann geklappt.
Leider bekahm ich dann die Meldung das Avira noch im Hintergrund läuft. Über den Taskmanager habe ich es dann auch gefunden konnte aber auf Grund der Gruppenrichtlinie es nicht deaktivieren. Ich habe dann mittels AutoRuns es deaktiviert bekommen, und dann sogar deinstaliren können.
Danach konte ich Kombofix wieder starten und es gab keine Fehlermeldung
Hier nun das Kombofix Log. Code:
ComboFix 12-10-11.01 - Heistmer 11.10.2012 10:17:58.1.4 - x64
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.49.1031.18.3325.1856 [GMT 2:00]
ausgeführt von:: c:\users\Heistmer\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\index.htm
c:\program files (x86)\PluginDL
c:\program files (x86)\PluginDL\axdlplug.inf
c:\program files (x86)\PluginDL\PluginDL.url
c:\program files (x86)\xp-AntiSpy
c:\program files (x86)\xp-AntiSpy\Uninstall.exe
c:\program files (x86)\xp-AntiSpy\xp-AntiSpy.chm
c:\program files (x86)\xp-AntiSpy\xp-AntiSpy.exe
c:\program files (x86)\xp-AntiSpy\xp-AntiSpy.url
c:\programdata\568DE542ED.sys
c:\programdata\dsgsdgdsgdsgw.pad
c:\users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PluginDL
c:\users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PluginDL\HomePage.lnk
c:\windows\Installer\$PatchCache$\Managed\6D79387323DF29048A45A657BCE7AD64\1.5.2060\pst.ini2
c:\windows\IsUn0407.exe
c:\windows\UA000107.DLL
.
.
((((((((((((((((((((((( Dateien erstellt von 2012-09-11 bis 2012-10-11 ))))))))))))))))))))))))))))))
.
.
2012-10-11 08:29 . 2012-10-11 08:29 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-10-11 08:29 . 2012-10-11 08:29 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-10-11 06:06 . 2012-09-13 13:45 2048 ----a-w- c:\windows\system32\tzres.dll
2012-10-11 06:06 . 2012-09-13 13:28 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-10-11 06:06 . 2012-08-24 16:07 218624 ----a-w- c:\windows\system32\wintrust.dll
2012-10-11 06:06 . 2012-08-24 15:53 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-10-11 06:06 . 2012-06-02 00:20 1268736 ----a-w- c:\windows\system32\crypt32.dll
2012-10-11 06:06 . 2012-06-02 00:20 174592 ----a-w- c:\windows\system32\cryptsvc.dll
2012-10-11 06:06 . 2012-06-02 00:20 132096 ----a-w- c:\windows\system32\cryptnet.dll
2012-10-11 06:06 . 2012-06-02 00:02 985088 ----a-w- c:\windows\SysWow64\crypt32.dll
2012-10-11 06:06 . 2012-06-02 00:02 98304 ----a-w- c:\windows\SysWow64\cryptnet.dll
2012-10-11 06:06 . 2012-06-02 00:02 133120 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2012-10-11 06:05 . 2012-08-29 11:40 4699520 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-10-09 11:58 . 2012-08-30 07:27 9308616 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D5E27317-FF4E-48ED-B38E-F479CE507871}\mpengine.dll
2012-10-09 11:30 . 2012-10-09 20:43 -------- d-----w- C:\_OTL
2012-10-04 15:06 . 2012-10-04 15:06 -------- d-----w- c:\program files (x86)\ESET
2012-10-02 18:51 . 2012-10-02 18:51 -------- d-----w- c:\users\Heistmer\AppData\Roaming\Malwarebytes
2012-10-02 18:51 . 2012-10-02 18:51 -------- d-----w- c:\programdata\Malwarebytes
2012-10-02 18:51 . 2012-10-02 18:51 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-10-02 18:51 . 2012-09-07 15:04 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-22 21:57 . 2012-09-22 21:57 -------- d-----w- c:\users\Heistmer\AppData\Local\NOS
2012-09-11 18:53 . 2012-09-11 18:53 -------- d-----w- c:\users\Heistmer\AppData\Roaming\MAGIX
2012-09-11 18:53 . 2012-09-11 18:53 -------- d-----w- c:\users\Heistmer\AppData\Local\Xara
2012-09-11 18:51 . 2012-09-11 18:53 -------- d-----w- c:\programdata\MAGIX
2012-09-11 18:51 . 2012-09-11 18:51 -------- d-----w- c:\program files (x86)\MAGIX
2012-09-11 18:50 . 2012-10-02 21:42 -------- d-----w- c:\programdata\Yahoo!
2012-09-11 18:50 . 2012-09-11 18:50 -------- d-----w- c:\users\Heistmer\AppData\Roaming\Yahoo!
2012-09-11 18:50 . 2012-09-11 18:50 -------- d-----w- c:\program files (x86)\Yahoo!
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-08 20:10 . 2012-08-08 20:10 73416 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-08 20:10 . 2012-08-08 20:10 696520 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AutoStart-Manager"="c:\program files (x86)\Tools&More\Autostart-Manager\AutoStart-Manager.exe" [2012-02-29 401408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AVMFBoxMonitor"="c:\program files (x86)\FRITZ!Box Monitor\FRITZBoxMonitor.exe" [2008-06-03 1508656]
.
c:\users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
FRITZ!DSL Protect.lnk - c:\program files (x86)\FRITZ!DSL\FwebProt.exe [2007-9-7 1070384]
Trillian.lnk - c:\program files (x86)\Trillian\trillian.exe [2012-7-2 2298320]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FRITZ!DSL Startcenter.lnk - c:\windows\Installer\{2457326B-C110-40C3-89B0-889CC913871A}\Icon2457326B4.exe [2008-6-14 29184]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-7-19 1196048]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\acrord32.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\afterfx.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\exprwd.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\filezilla.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\flashplayer11-2_p2_install_win_ax64_112211.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\flashplayer11-2_p2_uninstall_win_64_112211.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\flipshare.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\magictune.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\mml.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\mmlupdate.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\msoxmled.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\mstore.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\presentationhost.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\switchboard.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\uninstall.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe"
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" --preload
.
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [x]
S2 acedrv10;acedrv10;c:\windows\system32\drivers\acedrv10.sys [2009-08-18 277904]
S2 acehlp10;acehlp10;c:\windows\system32\drivers\acehlp10.sys [2009-08-18 228000]
S3 3xHybr64;Philips SAA713x PCI Card;c:\windows\system32\DRIVERS\3xHybr64.sys [2008-03-13 1607392]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Themes
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 242192]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-20 7981088]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local;192.168.*.*
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchAssistant = hxxp://www.google.com/ie
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
LSP: c:\program files (x86)\FRITZ!DSL\\sarah.dll
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
Trusted Zone: com.tw\www.msi
TCP: DhcpNameServer = 192.168.178.1
DPF: {615A1925-0E5B-4767-A65E-3165AEAC32A3}
FF - ProfilePath - c:\users\Heistmer\AppData\Roaming\Mozilla\Firefox\Profiles\7ew9dmkc.default\
FF - prefs.js: browser.search.selectedEngine - FireSearch
FF - prefs.js: browser.startup.homepage - hxxp://www2.firesearch.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Ext: Firebug: firebug@software.joehewitt.com - %profile%\extensions\firebug@software.joehewitt.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-TAPI - c:\windows\IsUn0407.exe
AddRemove-xp-AntiSpy - c:\program files (x86)\xp-AntiSpy\Uninstall.exe
AddRemove-bleh eggs link - c:\progra~4\PROXYM~1\AntiPlus.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*êÖtêÖt¾Z¾Zuw&]
@Allowed: (Read) (RestrictedCode)
"0"=hex:56,00,31,00,00,00,00,00,3b,41,58,98,10,00,48,45,49,53,54,4d,7e,31,00,
00,3e,00,07,00,04,00,ef,be,2f,41,e6,8e,3b,41,58,98,26,00,00,00,48,a3,07,00,\
"MRUListEx"=hex:01,00,00,00,00,00,00,00,ff,ff,ff,ff
"1"=hex:56,00,31,00,00,00,00,00,3b,41,e0,9b,10,00,48,45,49,53,54,4d,7e,31,00,
00,3e,00,07,00,04,00,ef,be,2f,41,e6,8e,3b,41,e0,9b,26,00,00,00,48,a3,07,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*ê
v¾ZƒZbÙžYš7*\À7*Е7*]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,fd,40,bc,6b,10,00,44,45,52,54,4f,49,7e,31,00,
00,4e,00,07,00,04,00,ef,be,f5,40,62,99,fd,40,bc,6b,26,00,00,00,f1,45,00,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*ê1vê1v¾Zž`£Ä"]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,c6,40,f6,9a,10,00,54,4f,57,45,52,2d,7e,31,00,
00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,c6,40,f6,9a,26,00,00,00,23,72,07,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*ê8vê8v¾ZF_Ú¬kÃ]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,b9,40,20,8e,10,00,54,4f,57,45,52,2d,7e,31,00,
00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,b9,40,20,8e,26,00,00,00,23,72,07,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png êpvêpv¾ZX_
°rC]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,b6,40,0f,a0,10,00,54,4f,57,45,52,2d,7e,31,00,
00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,b6,40,0f,a0,26,00,00,00,23,72,07,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*ê›vê›v¾Zæa Äâ]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,ef,40,56,43,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,ef,40,56,43,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*êœvêœv¾Zbén¢]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,3f,40,1b,ad,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,3f,40,1b,ad,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:01,00,00,00,00,00,00,00,ff,ff,ff,ff
"1"=hex:52,00,31,00,00,00,00,00,41,40,07,a8,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,41,40,07,a8,26,00,00,00,fe,a1,03,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*êžv¾ZÈf*œÁ*X”+*œº+*+*]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,9a,40,d7,a5,10,00,54,4f,57,45,52,2d,7e,31,00,
00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,9a,40,d7,a5,26,00,00,00,23,72,07,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*êñvêñv¾ZOW늌û]
@Allowed: (Read) (RestrictedCode)
"0"=hex:56,00,31,00,00,00,00,00,2f,41,29,93,10,00,48,45,49,53,54,4d,7e,31,00,
00,3e,00,07,00,04,00,ef,be,2f,41,e6,8e,2f,41,29,93,26,00,00,00,48,a3,07,00,\
"MRUListEx"=hex:01,00,00,00,00,00,00,00,ff,ff,ff,ff
"1"=hex:56,00,31,00,00,00,00,00,2f,41,47,93,10,00,48,45,49,53,54,4d,7e,31,00,
00,3e,00,07,00,04,00,ef,be,2f,41,e6,8e,2f,41,47,93,26,00,00,00,48,a3,07,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*êwêw¾Z[?àó1]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,a2,40,cb,9e,10,00,54,4f,57,45,52,2d,7e,31,00,
00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,a2,40,cb,9e,26,00,00,00,23,72,07,00,\
"MRUListEx"=hex:02,00,00,00,01,00,00,00,00,00,00,00,ff,ff,ff,ff
"1"=hex:66,00,31,00,00,00,00,00,a2,40,2b,9f,10,00,54,4f,57,45,52,2d,7e,31,00,
00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,a2,40,2b,9f,26,00,00,00,23,72,07,00,\
"2"=hex:66,00,31,00,00,00,00,00,a2,40,83,a0,10,00,54,4f,57,45,52,2d,7e,31,00,
00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,a2,40,83,a0,26,00,00,00,23,72,07,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*¾ZƒZÞÅžY]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,fd,40,e1,54,10,00,44,45,52,54,4f,49,7e,31,00,
00,4e,00,07,00,04,00,ef,be,f5,40,62,99,fd,40,e1,54,26,00,00,00,f1,45,00,00,\
"MRUListEx"=hex:01,00,00,00,00,00,00,00,ff,ff,ff,ff
"1"=hex:66,00,31,00,00,00,00,00,fd,40,ac,76,10,00,44,45,52,54,4f,49,7e,31,00,
00,4e,00,07,00,04,00,ef,be,f5,40,62,99,fd,40,ac,76,26,00,00,00,f1,45,00,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*¾Z]’*Æ]
@Allowed: (Read) (RestrictedCode)
"0"=hex:56,00,31,00,00,00,00,00,30,41,dd,4a,10,00,48,45,49,53,54,4d,7e,31,00,
00,3e,00,07,00,04,00,ef,be,2f,41,e6,8e,30,41,dd,4a,26,00,00,00,48,a3,07,00,\
"MRUListEx"=hex:01,00,00,00,00,00,00,00,ff,ff,ff,ff
"1"=hex:56,00,31,00,00,00,00,00,32,41,43,a2,10,00,48,45,49,53,54,4d,7e,31,00,
00,3e,00,07,00,04,00,ef,be,2f,41,e6,8e,32,41,43,a2,26,00,00,00,48,a3,07,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*¾Z…cKù&¢]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,bf,40,46,87,10,00,54,4f,57,45,52,2d,7e,31,00,
00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,bf,40,46,87,26,00,00,00,23,72,07,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*¾ZÈfÁ*]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,9a,40,14,a3,10,00,54,4f,57,45,52,2d,7e,31,00,
00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,9a,40,14,a3,26,00,00,00,23,72,07,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*êÌuêÌu¾Z2_2î£]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,ba,40,1a,a2,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,ba,40,1a,a2,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:04,00,00,00,03,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,ff,
ff,ff,ff
"1"=hex:52,00,31,00,00,00,00,00,ba,40,1a,a2,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,ba,40,1a,a2,26,00,00,00,fe,a1,03,00,\
"2"=hex:52,00,31,00,00,00,00,00,ba,40,1a,a2,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,ba,40,1a,a2,26,00,00,00,fe,a1,03,00,\
"3"=hex:52,00,31,00,00,00,00,00,ba,40,1a,a2,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,ba,40,1a,a2,26,00,00,00,fe,a1,03,00,\
"4"=hex:52,00,31,00,00,00,00,00,ba,40,1a,a2,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,ba,40,1a,a2,26,00,00,00,fe,a1,03,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*ê*vê*v¾Zò^ÓŽù>]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,35,40,80,a6,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,35,40,80,a6,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:02,00,00,00,01,00,00,00,00,00,00,00,ff,ff,ff,ff
"1"=hex:52,00,31,00,00,00,00,00,35,40,47,ac,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,35,40,47,ac,26,00,00,00,fe,a1,03,00,\
"2"=hex:52,00,31,00,00,00,00,00,35,40,64,af,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,35,40,64,af,26,00,00,00,fe,a1,03,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*¾Zú`ÚÄ;]
@Allowed: (Read) (RestrictedCode)
"0"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00,
00,1a,00,ee,bb,fe,23,00,00,10,00,30,81,e2,33,1e,4e,76,46,83,5a,98,39,5c,3b,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*¾Za[2bF]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,47,40,e1,ae,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,47,40,e1,ae,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*¾Z”j>{ßb]
@Allowed: (Read) (RestrictedCode)
"0"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00,
00,1a,00,ee,bb,fe,23,00,00,10,00,30,81,e2,33,1e,4e,76,46,83,5a,98,39,5c,3b,\
"MRUListEx"=hex:02,00,00,00,01,00,00,00,00,00,00,00,ff,ff,ff,ff
"1"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00,
00,1a,00,ee,bb,fe,23,00,00,10,00,30,81,e2,33,1e,4e,76,46,83,5a,98,39,5c,3b,\
"2"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00,
00,1a,00,ee,bb,fe,23,00,00,10,00,30,81,e2,33,1e,4e,76,46,83,5a,98,39,5c,3b,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*¾Z·pR\³]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,ec,40,f2,9e,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,ec,40,f2,9e,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\pspimage*›vê›v¾ZæaªÄâ`š]*¤À]*–]*]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,ef,40,56,43,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,ef,40,56,43,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\pspimage*}-Bþÿÿÿêžvêžv¾ZÈf*œÁ*X”+*œº+*+*]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,9a,40,8a,a3,10,00,54,4f,57,45,52,2d,7e,31,00,
00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,9a,40,8a,a3,26,00,00,00,23,72,07,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\pspimage*ø¯uÀõþÿÿÿê¥uê¥u¾ZDaa—Ê]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,51,40,cd,b0,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,51,40,cd,b0,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:0e,00,00,00,0d,00,00,00,0c,00,00,00,0b,00,00,00,0a,00,00,00,09,
00,00,00,08,00,00,00,07,00,00,00,06,00,00,00,05,00,00,00,04,00,00,00,03,00,\
"1"=hex:52,00,31,00,00,00,00,00,54,40,4e,98,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,4e,98,26,00,00,00,fe,a1,03,00,\
"2"=hex:52,00,31,00,00,00,00,00,54,40,73,98,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,73,98,26,00,00,00,fe,a1,03,00,\
"3"=hex:52,00,31,00,00,00,00,00,54,40,92,98,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,92,98,26,00,00,00,fe,a1,03,00,\
"4"=hex:52,00,31,00,00,00,00,00,54,40,ac,98,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,ac,98,26,00,00,00,fe,a1,03,00,\
"5"=hex:52,00,31,00,00,00,00,00,54,40,ca,98,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,ca,98,26,00,00,00,fe,a1,03,00,\
"6"=hex:52,00,31,00,00,00,00,00,54,40,e5,98,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,e5,98,26,00,00,00,fe,a1,03,00,\
"7"=hex:52,00,31,00,00,00,00,00,54,40,02,99,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,02,99,26,00,00,00,fe,a1,03,00,\
"8"=hex:52,00,31,00,00,00,00,00,54,40,19,99,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,19,99,26,00,00,00,fe,a1,03,00,\
"9"=hex:52,00,31,00,00,00,00,00,54,40,36,99,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,36,99,26,00,00,00,fe,a1,03,00,\
"10"=hex:52,00,31,00,00,00,00,00,54,40,74,99,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,74,99,26,00,00,00,fe,a1,03,00,\
"11"=hex:52,00,31,00,00,00,00,00,54,40,b9,99,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,b9,99,26,00,00,00,fe,a1,03,00,\
"12"=hex:52,00,31,00,00,00,00,00,54,40,80,9a,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,80,9a,26,00,00,00,fe,a1,03,00,\
"13"=hex:52,00,31,00,00,00,00,00,54,40,ca,9a,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,ca,9a,26,00,00,00,fe,a1,03,00,\
"14"=hex:52,00,31,00,00,00,00,00,54,40,eb,9a,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,eb,9a,26,00,00,00,fe,a1,03,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\pspimage ø¯uÀõþÿÿÿê¥uê¥u¾ZDaá
—Ê]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,54,40,0b,9b,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,0b,9b,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:0a,00,00,00,09,00,00,00,08,00,00,00,07,00,00,00,06,00,00,00,05,
00,00,00,04,00,00,00,03,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,ff,ff,\
"1"=hex:52,00,31,00,00,00,00,00,54,40,b8,9d,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,b8,9d,26,00,00,00,fe,a1,03,00,\
"2"=hex:52,00,31,00,00,00,00,00,54,40,8c,a6,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,8c,a6,26,00,00,00,fe,a1,03,00,\
"3"=hex:52,00,31,00,00,00,00,00,54,40,d8,a6,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,d8,a6,26,00,00,00,fe,a1,03,00,\
"4"=hex:52,00,31,00,00,00,00,00,54,40,46,a7,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,46,a7,26,00,00,00,fe,a1,03,00,\
"5"=hex:52,00,31,00,00,00,00,00,54,40,4a,a7,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,4a,a7,26,00,00,00,fe,a1,03,00,\
"6"=hex:52,00,31,00,00,00,00,00,54,40,5d,a7,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,5d,a7,26,00,00,00,fe,a1,03,00,\
"7"=hex:52,00,31,00,00,00,00,00,54,40,0f,a8,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,0f,a8,26,00,00,00,fe,a1,03,00,\
"8"=hex:52,00,31,00,00,00,00,00,54,40,21,a8,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,21,a8,26,00,00,00,fe,a1,03,00,\
"9"=hex:52,00,31,00,00,00,00,00,54,40,37,a8,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,37,a8,26,00,00,00,fe,a1,03,00,\
"10"=hex:52,00,31,00,00,00,00,00,54,40,49,a8,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,49,a8,26,00,00,00,fe,a1,03,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\pspimage ø
v,ßPTþÿÿÿê vê v¾Zò^ÓŽù>]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,35,40,e3,bc,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,35,40,e3,bc,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:01,00,00,00,00,00,00,00,ff,ff,ff,ff
"1"=hex:52,00,31,00,00,00,00,00,35,40,7a,be,10,00,68,6f,63,68,7a,65,69,74,00,
00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,35,40,7a,be,26,00,00,00,fe,a1,03,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_400_252_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_400_252_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:b5,58,57,e5,b4,98,13,5e,68,e9,00,b7,64,94,bb,28,9f,7f,e7,a7,f3,
09,ab,5a,37,76,eb,9d,e0,6e,51,aa,0b,a7,21,cc,f1,30,44,f7,c5,c7,8a,40,6c,d7,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_400_252_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_400_252_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_400_252.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_400_252.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_400_252.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_400_252.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\0\win32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_400_252.ocx"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\FLAGS]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\HELPDIR]
@="c:\\Windows\\system32\\Macromed\\Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0\FLAGS]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0\HELPDIR]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_400_252_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
"RasTimeoutResponseWait"=dword:00000032
"RasTimeoutPause"=dword:00000005
"ConnectTypesAllowed"=dword:0000000a
"CheckPasswordTimeoutSeconds"=dword:00000014
"WaitV2TimeoutSeconds"=dword:00000004
"SerialPort"="Bluetooth"
"HasUsbDevice"=dword:00000000
"SerialBaudRate"=dword:0001c200
"DeviceType"=""
"DeviceOemInfo"=""
"DeviceVersion"=dword:04401504
"DeviceProcessorType"=dword:00000000
"DeviceProcessor"=""
"DTPTNetworkType"="{0}"
"DisableIr"=dword:00000000
"GuestOnly"=dword:00000000
"MajorVersion"=dword:00000006
"MinorVersion"=dword:00000000
"InstalledDir"=expand:"%windir%\\WindowsMobile"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:b5,58,57,e5,b4,98,13,5e,68,e9,00,b7,64,94,bb,28,9f,7f,e7,a7,f3,
09,ab,5a,37,76,eb,9d,e0,6e,51,aa,0b,a7,21,cc,f1,30,44,f7,c5,c7,8a,40,6c,d7,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Zeit der Fertigstellung: 2012-10-11 10:34:27
ComboFix-quarantined-files.txt 2012-10-11 08:34
.
Vor Suchlauf: 16 Verzeichnis(se), 29.150.113.792 Bytes frei
Nach Suchlauf: 21 Verzeichnis(se), 28.972.433.408 Bytes frei
.
- - End Of File - - FAC62B0F29F3CB50D64FEB2D16B49A6A |