| Lord Flame |  13.02.2015 14:27 |        Hier das Combofix log:   Code:  
 ComboFix 15-02-13.02 - Administrator 13.02.2015  14:12:35.1.2 - x64 
Microsoft Windows 7 Professional   6.1.7601.1.1252.49.1031.18.4095.2069 [GMT 1:00] 
ausgeführt von:: c:\users\Administrator\Desktop\ComboFix.exe 
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B} 
AV: Emsisoft Anti-Malware *Disabled/Updated* {8504DEEF-CC04-1F76-2137-F1A5F4A659DA} 
AV: Microsoft Security Essentials *Disabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A} 
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} 
SP: Emsisoft Anti-Malware *Disabled/Updated* {3E653F0B-EA3E-10F8-1B87-CAD78F211367} 
SP: Microsoft Security Essentials *Disabled/Updated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7} 
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} 
. 
. 
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   )))))))))))))))))))))))))))))))))))))))))))))))) 
. 
. 
c:\windows\IsUn0407.exe 
. 
. 
(((((((((((((((((((((((   Dateien erstellt von 2015-01-13 bis 2015-02-13  )))))))))))))))))))))))))))))) 
. 
. 
2015-02-13 13:21 . 2015-02-13 13:21        --------        d-----w-        c:\users\Default\AppData\Local\temp 
2015-02-13 13:21 . 2015-02-13 13:21        --------        d-----w-        c:\users\admin\AppData\Local\temp 
2015-02-13 12:26 . 2015-02-13 12:29        --------        d-----w-        C:\FRST 
2015-02-13 12:26 . 2015-02-13 12:26        --------        d-----w-        c:\programdata\rmbwizard 
2015-02-13 12:25 . 2015-02-13 12:25        --------        d-----w-        c:\windows\LastGood 
2015-02-13 12:18 . 2015-02-13 12:18        --------        d-----w-        c:\users\Administrator\AppData\Local\Secunia PSI 
2015-02-13 12:16 . 2015-02-13 12:16        --------        d-----w-        c:\program files (x86)\Secunia 
2015-02-13 11:46 . 2015-02-13 12:04        --------        d-----w-        c:\windows\SysWow64\vbox 
2015-02-13 11:46 . 2015-02-13 12:04        --------        d-----w-        c:\windows\system32\vbox 
2015-02-13 11:22 . 2015-02-13 11:22        --------        d-----w-        c:\program files\Paragon Software 
2015-02-13 11:19 . 2015-02-13 11:19        --------        d-----w-        c:\users\Administrator\AppData\Local\Downloaded Installations 
2015-02-13 11:18 . 2015-02-13 11:18        --------        d-----w-        c:\programdata\explauncher 
2015-02-13 11:18 . 2015-02-13 11:18        75888        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E5EE0C49-9B1B-44AC-BE78-928D2E9BB2F4}\offreg.dll 
2015-02-13 11:07 . 2015-02-13 11:07        --------        d-----w-        c:\users\Administrator\AppData\Local\Opera Software 
2015-02-13 11:07 . 2015-02-13 11:07        --------        d-----w-        c:\users\Administrator\AppData\Roaming\Opera Software 
2015-02-13 11:04 . 2015-02-13 11:04        --------        d-----w-        c:\users\Administrator\AppData\Roaming\AVAST Software 
2015-02-13 11:03 . 2015-02-13 11:03        --------        d-----w-        c:\programdata\Panda Security 
2015-02-13 11:02 . 2015-02-13 11:03        --------        d-----w-        c:\program files (x86)\Google 
2015-02-13 11:02 . 2015-02-13 11:05        --------        d-----w-        c:\users\Administrator\AppData\Local\Google 
2015-02-13 11:02 . 2015-02-13 11:02        267632        ----a-w-        c:\windows\system32\drivers\aswVmm.sys 
2015-02-13 11:02 . 2015-02-13 11:02        116728        ----a-w-        c:\windows\system32\drivers\aswStm.sys 
2015-02-13 11:02 . 2015-02-13 11:04        87912        ----a-w-        c:\windows\system32\drivers\aswmonflt.sys 
2015-02-13 11:02 . 2015-02-13 11:02        65776        ----a-w-        c:\windows\system32\drivers\aswRvrt.sys 
2015-02-13 11:02 . 2015-02-13 11:02        436624        ----a-w-        c:\windows\system32\drivers\aswSP.sys 
2015-02-13 11:02 . 2015-02-13 11:02        29208        ----a-w-        c:\windows\system32\drivers\aswHwid.sys 
2015-02-13 11:02 . 2015-02-13 11:02        93568        ----a-w-        c:\windows\system32\drivers\aswRdr2.sys 
2015-02-13 11:02 . 2015-02-13 11:04        1050432        ----a-w-        c:\windows\system32\drivers\aswsnx.sys 
2015-02-13 11:02 . 2015-02-13 11:02        364512        ----a-w-        c:\windows\system32\aswBoot.exe 
2015-02-13 11:01 . 2015-02-13 11:01        43152        ----a-w-        c:\windows\avastSS.scr 
2015-02-13 10:59 . 2015-02-13 10:59        1188440        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{847D254A-0784-42CC-96B7-3B1FA63CB13C}\gapaengine.dll 
2015-02-13 10:59 . 2014-12-02 01:26        11870360        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E5EE0C49-9B1B-44AC-BE78-928D2E9BB2F4}\mpengine.dll 
2015-02-13 10:57 . 2015-02-13 10:59        --------        d-----w-        c:\programdata\AVAST Software 
2015-02-13 10:56 . 2015-02-13 10:56        --------        d-----w-        c:\program files (x86)\Microsoft Security Client 
2015-02-13 10:56 . 2015-02-13 10:56        --------        d-----w-        c:\program files\Microsoft Security Client 
2015-02-13 10:47 . 2015-02-13 10:47        --------        d-----w-        c:\users\Sir Darkflame 
2015-02-13 10:29 . 2014-12-15 03:13        11870360        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{958AF359-E20C-4E25-9AFF-A425BE8392F8}\mpengine.dll 
2015-02-12 22:13 . 2015-01-09 03:14        91136        ----a-w-        c:\windows\system32\wdi.dll 
2015-02-12 22:13 . 2015-01-09 03:14        950272        ----a-w-        c:\windows\system32\perftrack.dll 
2015-02-12 22:13 . 2015-01-09 03:14        29696        ----a-w-        c:\windows\system32\powertracker.dll 
2015-02-12 22:13 . 2015-01-09 02:48        76800        ----a-w-        c:\windows\SysWow64\wdi.dll 
2015-02-12 13:06 . 2015-01-23 04:41        6041600        ----a-w-        c:\windows\system32\jscript9.dll 
2015-02-12 13:06 . 2015-01-23 03:43        620032        ----a-w-        c:\windows\SysWow64\jscript9diag.dll 
2015-02-12 13:06 . 2015-01-23 03:17        4300800        ----a-w-        c:\windows\SysWow64\jscript9.dll 
2015-02-12 13:06 . 2015-01-23 04:42        814080        ----a-w-        c:\windows\system32\jscript9diag.dll 
2015-02-11 18:28 . 2015-01-13 03:10        1424384        ----a-w-        c:\windows\system32\WindowsCodecs.dll 
2015-02-11 18:27 . 2015-01-09 02:03        3201536        ----a-w-        c:\windows\system32\win32k.sys 
2015-02-05 14:56 . 2015-02-05 14:57        --------        d-----w-        c:\users\Administrator\AppData\Roaming\SpaceEngineers 
2015-02-02 15:14 . 2015-02-02 15:14        --------        d-----w-        c:\program files (x86)\Common Files\Java 
2015-02-02 15:12 . 2015-02-02 15:12        8704        ----a-w-        c:\windows\system32\drivers\hidkmdf.sys 
2015-02-02 15:12 . 2015-02-02 15:12        42056        ----a-w-        c:\windows\system32\drivers\sshid.sys 
2015-02-02 15:12 . 2015-02-02 15:12        25088        ----a-w-        c:\windows\system32\drivers\ssdevfactory.sys 
2015-02-02 03:39 . 2015-02-02 03:39        --------        d-----w-        c:\program files (x86)\NVIDIA Corporation 
2015-02-02 03:39 . 2015-02-02 03:39        --------        d-----w-        c:\program files (x86)\Common Files\Wise Installation Wizard 
2015-01-30 16:33 . 2015-01-30 16:33        --------        d-----w-        c:\users\Administrator\AppData\Local\Black_Tree_Gaming 
2015-01-24 16:25 . 2015-01-24 16:25        --------        d-----w-        c:\programdata\Emsisoft 
2015-01-24 15:48 . 2015-01-24 15:48        --------        d-----w-        c:\users\Administrator\AppData\Local\Skyrim 
2015-01-24 15:28 . 2015-01-25 12:13        --------        d-----w-        c:\program files (x86)\Emsisoft Anti-Malware 
2015-01-24 15:13 . 2015-01-24 15:13        --------        d-----w-        C:\TDSSKiller_Quarantine 
2015-01-24 14:23 . 2015-01-24 14:23        119808        ----a-r-        c:\users\Administrator\AppData\Roaming\Microsoft\Installer\{CCF298AF-9CE1-4B26-B251-486E98A34789}\icons.exe 
2015-01-22 18:17 . 2015-01-22 18:17        255672        ----a-w-        c:\program files\Common Files\Microsoft Shared\OFFICE15\1031\OSFINTL.DLL 
2015-01-22 17:29 . 2015-01-14 10:32        33856        ---ha-w-        c:\windows\system32\hamachi.sys 
2015-01-22 16:46 . 2015-01-22 16:46        3009720        ----a-w-        c:\program files\Common Files\Microsoft Shared\OFFICE15\1031\MSOINTL.DLL 
2015-01-21 14:05 . 2015-01-21 14:05        81238200        ----a-w-        c:\program files (x86)\Common Files\Microsoft Shared\OFFICE15\MSORES.DLL 
2015-01-21 14:05 . 2015-01-21 14:05        5736144        ----a-w-        c:\program files (x86)\Common Files\Microsoft Shared\OFFICE15\CMigrate.exe 
2015-01-21 14:05 . 2015-01-21 14:05        5435576        ----a-w-        c:\program files (x86)\Common Files\Microsoft Shared\OFFICE15\Csi.dll 
2015-01-21 14:05 . 2015-01-21 14:05        26476728        ----a-w-        c:\program files (x86)\Common Files\Microsoft Shared\OFFICE15\MSO.DLL 
2015-01-21 14:02 . 2015-01-21 14:02        877808        ----a-w-        c:\program files\Common Files\Microsoft Shared\OFFICE15\ACEES.DLL 
2015-01-21 14:02 . 2015-01-21 14:02        532704        ----a-w-        c:\program files\Common Files\Microsoft Shared\OFFICE15\ACEEXCL.DLL 
2015-01-21 14:02 . 2015-01-21 14:02        445664        ----a-w-        c:\program files\Common Files\Microsoft Shared\OFFICE15\ACEOLEDB.DLL 
2015-01-21 14:02 . 2015-01-21 14:02        2272456        ----a-w-        c:\program files\Common Files\Microsoft Shared\OFFICE15\ACECORE.DLL 
2015-01-21 14:02 . 2015-01-21 14:02        203480        ----a-w-        c:\program files\Common Files\Microsoft Shared\OFFICE15\ACETXT.DLL 
2015-01-21 14:01 . 2015-01-21 14:01        617720        ----a-w-        c:\program files\Common Files\Microsoft Shared\OFFICE15\ACEDAO.DLL 
2015-01-21 14:01 . 2015-01-21 14:01        853200        ----a-w-        c:\program files\Common Files\Microsoft Shared\OFFICE15\WXPNSE.DLL 
2015-01-21 14:01 . 2015-01-21 14:01        81238200        ----a-w-        c:\program files\Common Files\Microsoft Shared\OFFICE15\MSORES.DLL 
2015-01-21 14:01 . 2015-01-21 14:01        7838928        ----a-w-        c:\program files\Common Files\Microsoft Shared\OFFICE15\CMigrate.exe 
2015-01-21 14:01 . 2015-01-21 14:01        7603896        ----a-w-        c:\program files\Common Files\Microsoft Shared\OFFICE15\Csi.dll 
2015-01-21 14:01 . 2015-01-21 14:01        2226848        ----a-w-        c:\program files\Common Files\Microsoft Shared\OFFICE15\RICHED20.DLL 
2015-01-21 14:01 . 2015-01-21 14:01        111848        ----a-w-        c:\program files\Common Files\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE 
2015-01-21 14:01 . 2015-01-21 14:01        654512        ----a-w-        c:\program files\Common Files\Microsoft Shared\OFFICE15\MSOSQM.EXE 
2015-01-21 14:01 . 2015-01-21 14:01        36978360        ----a-w-        c:\program files\Common Files\Microsoft Shared\OFFICE15\MSO.DLL 
2015-01-18 19:16 . 2015-01-18 19:16        --------        d-----w-        c:\users\Administrator\AppData\Roaming\OpenOffice 
2015-01-16 19:43 . 2015-01-16 19:43        --------        d-----w-        c:\program files (x86)\Microsoft Visual Studio 11.0 
2015-01-16 19:41 . 2015-01-16 19:41        --------        d-----w-        c:\program files (x86)\Windows Phone Silverlight Kits 
2015-01-16 19:41 . 2015-01-18 21:56        2382112        ----a-w-        c:\programdata\Microsoft\VisualStudio\12.0\1033\ResourceCache.dll 
2015-01-16 19:39 . 2015-01-16 19:39        --------        d-----w-        c:\program files (x86)\Microsoft XDE 
2015-01-16 19:39 . 2010-02-03 12:04        489072        ----a-w-        c:\windows\aus_ddss.scr 
2015-01-16 19:39 . 2015-01-16 19:39        --------        d-----w-        c:\program files (x86)\Auslogics 
2015-01-16 19:35 . 2015-01-16 19:35        --------        d-----w-        c:\program files (x86)\AppInsights 
2015-01-16 19:30 . 2015-01-16 19:30        --------        d-----w-        c:\program files\Microsoft SQL Server Compact Edition 
2015-01-16 19:30 . 2015-01-16 19:30        --------        d-----w-        c:\program files (x86)\Microsoft SQL Server Compact Edition 
2015-01-16 19:29 . 2015-01-16 19:29        --------        d-----w-        c:\program files\Application Verifier 
2015-01-16 19:29 . 2015-01-16 19:29        --------        d-----w-        c:\program files (x86)\Application Verifier 
2015-01-16 19:28 . 2015-01-16 19:36        --------        d-----w-        c:\programdata\Windows App Certification Kit 
2015-01-16 19:27 . 2015-01-16 19:27        --------        d-----w-        c:\program files (x86)\Common Files\Microsoft 
2015-01-16 19:26 . 2015-01-16 19:26        --------        d-----w-        c:\programdata\PreEmptive Solutions 
2015-01-16 19:25 . 2015-01-16 19:26        --------        d-----w-        c:\program files (x86)\Microsoft ASP.NET 
2015-01-16 19:24 . 2015-01-16 19:24        --------        d-----w-        c:\program files (x86)\Microsoft Web Tools 
2015-01-16 19:23 . 2015-01-16 19:35        --------        d-----w-        c:\program files\IIS Express 
2015-01-16 19:23 . 2015-01-16 19:35        --------        d-----w-        c:\program files (x86)\IIS Express 
2015-01-16 19:23 . 2015-01-16 19:23        --------        d-----w-        c:\programdata\NuGet 
2015-01-16 19:23 . 2015-01-16 19:23        --------        d-----w-        c:\program files (x86)\NuGet 
2015-01-16 19:23 . 2015-01-16 19:23        --------        d-----w-        c:\program files (x86)\Microsoft WCF Data Services 
2015-01-16 19:23 . 2015-01-16 19:23        --------        d-----w-        c:\program files\IIS 
2015-01-16 19:23 . 2015-01-16 19:23        --------        d-----w-        c:\program files (x86)\IIS 
2015-01-16 19:13 . 2015-01-16 19:16        --------        d-----w-        c:\program files (x86)\Windows Kits 
2015-01-16 19:13 . 2015-01-16 19:13        --------        d-----w-        c:\program files (x86)\Windows Phone Kits 
2015-01-16 19:13 . 2015-01-16 19:13        --------        d-----w-        c:\program files (x86)\HTML Help Workshop 
2015-01-16 19:12 . 2015-01-16 19:12        --------        d-----w-        c:\windows\symbols 
2015-01-16 19:12 . 2015-01-16 19:12        --------        d-----w-        c:\program files (x86)\Microsoft Help Viewer 
2015-01-16 19:11 . 2015-01-16 19:16        --------        d-----w-        c:\windows\SysWow64\1033 
2015-01-16 19:05 . 2015-01-16 19:44        --------        d-----w-        c:\program files (x86)\Common Files\Merge Modules 
2015-01-16 19:03 . 2015-01-16 19:12        --------        d-----w-        c:\windows\system32\1033 
2015-01-16 19:03 . 2015-01-16 19:39        --------        d-----w-        c:\program files (x86)\Microsoft SDKs 
2015-01-16 19:03 . 2015-01-16 19:03        --------        d-----w-        c:\program files\Microsoft Visual Studio 12.0 
2015-01-16 18:58 . 2015-02-11 22:23        --------        d-----w-        c:\programdata\Package Cache 
2015-01-16 16:56 . 2015-01-16 16:56        --------        d-----w-        c:\users\Administrator\AppData\Local\Gameforge4d 
2015-01-16 16:56 . 2015-01-16 16:56        --------        d-----w-        c:\program files (x86)\GameforgeLive 
2015-01-16 13:28 . 2013-04-09 23:34        1247744        ----a-w-        c:\windows\SysWow64\DWrite.dll 
2015-01-16 13:28 . 2013-04-02 22:51        1643520        ----a-w-        c:\windows\system32\DWrite.dll 
2015-01-14 18:58 . 2015-01-14 18:58        --------        d-----w-        c:\users\Administrator\.idlerc 
2015-01-14 18:24 . 2015-01-14 18:24        --------        d-----w-        c:\users\Administrator\AppData\Roaming\VSRevoGroup 
2015-01-14 17:57 . 2015-01-14 18:06        --------        d-----w-        c:\users\Administrator\.zenmap 
2015-01-14 17:48 . 2015-01-16 16:50        --------        d-----w-        c:\program files\Enigma Software Group 
2015-01-14 13:28 . 2014-12-19 03:06        210432        ----a-w-        c:\windows\system32\profsvc.dll 
2015-01-14 13:28 . 2014-12-06 04:17        303616        ----a-w-        c:\windows\system32\nlasvc.dll 
. 
. 
((((((((((((((((((((((((((((((((((((   Find3M Bericht   )))))))))))))))))))))))))))))))))))))))))))))))))))))) 
. 
2015-02-13 11:38 . 2015-01-04 15:57        71344        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl 
2015-02-13 11:38 . 2015-01-04 15:57        701616        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe 
2015-02-11 22:12 . 2015-01-04 16:07        116773704        ----a-w-        c:\windows\system32\MRT.exe 
2015-02-02 15:13 . 2015-01-08 17:01        111016        ----a-w-        c:\windows\system32\WindowsAccessBridge-64.dll 
2015-02-02 15:12 . 2015-01-04 16:25        98216        ----a-w-        c:\windows\SysWow64\WindowsAccessBridge-32.dll 
2015-01-08 08:55 . 2010-11-21 03:27        298120        ------w-        c:\windows\system32\MpSigStub.exe 
2015-01-04 17:38 . 2015-01-04 16:17        88480        ----a-w-        c:\windows\system32\drivers\atksgt.sys 
2015-01-04 17:38 . 2015-01-04 16:17        46400        ----a-w-        c:\windows\system32\drivers\lirsgt.sys 
2015-01-04 16:24 . 2015-01-04 16:24        194048        ----a-w-        c:\windows\SysWow64\elshyph.dll 
2015-01-04 16:23 . 2015-01-04 16:23        71680        ----a-w-        c:\windows\SysWow64\RegisterIEPKEYs.exe 
2015-01-04 16:23 . 2015-01-04 16:23        645120        ----a-w-        c:\windows\SysWow64\jsIntl.dll 
2015-01-04 16:23 . 2015-01-04 16:23        235008        ----a-w-        c:\windows\system32\elshyph.dll 
2015-01-04 16:23 . 2015-01-04 16:23        182272        ----a-w-        c:\windows\SysWow64\msls31.dll 
2015-01-04 16:23 . 2015-01-04 16:23        86016        ----a-w-        c:\windows\SysWow64\iesysprep.dll 
2015-01-04 16:23 . 2015-01-04 16:23        74240        ----a-w-        c:\windows\SysWow64\SetIEInstalledDate.exe 
2015-01-04 16:23 . 2015-01-04 16:23        62464        ----a-w-        c:\windows\SysWow64\tdc.ocx 
2015-01-04 16:23 . 2015-01-04 16:23        48640        ----a-w-        c:\windows\SysWow64\mshtmler.dll 
2015-01-04 16:23 . 2015-01-04 16:23        36352        ----a-w-        c:\windows\SysWow64\imgutil.dll 
2015-01-04 16:23 . 2015-01-04 16:23        337408        ----a-w-        c:\windows\SysWow64\html.iec 
2015-01-04 16:23 . 2015-01-04 16:23        24576        ----a-w-        c:\windows\SysWow64\licmgr10.dll 
2015-01-04 16:23 . 2015-01-04 16:23        151552        ----a-w-        c:\windows\SysWow64\iexpress.exe 
2015-01-04 16:23 . 2015-01-04 16:23        139264        ----a-w-        c:\windows\SysWow64\wextract.exe 
2015-01-04 16:23 . 2015-01-04 16:23        13312        ----a-w-        c:\windows\SysWow64\mshta.exe 
2015-01-04 16:23 . 2015-01-04 16:23        111616        ----a-w-        c:\windows\SysWow64\IEAdvpack.dll 
2015-01-04 16:23 . 2015-01-04 16:23        942592        ----a-w-        c:\windows\system32\jsIntl.dll 
2015-01-04 16:23 . 2015-01-04 16:23        90112        ----a-w-        c:\windows\system32\SetIEInstalledDate.exe 
2015-01-04 16:23 . 2015-01-04 16:23        86016        ----a-w-        c:\windows\system32\RegisterIEPKEYs.exe 
2015-01-04 16:23 . 2015-01-04 16:23        52224        ----a-w-        c:\windows\system32\msfeedsbs.dll 
2015-01-04 16:23 . 2015-01-04 16:23        48640        ----a-w-        c:\windows\system32\mshtmler.dll 
2015-01-04 16:23 . 2015-01-04 16:23        247808        ----a-w-        c:\windows\system32\msls31.dll 
2015-01-04 16:23 . 2015-01-04 16:23        13312        ----a-w-        c:\windows\system32\msfeedssync.exe 
2015-01-04 16:23 . 2015-01-04 16:23        131072        ----a-w-        c:\windows\system32\IEAdvpack.dll 
2015-01-04 16:23 . 2015-01-04 16:23        105984        ----a-w-        c:\windows\system32\iesysprep.dll 
2015-01-04 16:23 . 2015-01-04 16:23        81408        ----a-w-        c:\windows\system32\icardie.dll 
2015-01-04 16:23 . 2015-01-04 16:23        77312        ----a-w-        c:\windows\system32\tdc.ocx 
2015-01-04 16:23 . 2015-01-04 16:23        616104        ----a-w-        c:\windows\system32\ieapfltr.dat 
2015-01-04 16:23 . 2015-01-04 16:23        413696        ----a-w-        c:\windows\system32\html.iec 
2015-01-04 16:23 . 2015-01-04 16:23        30208        ----a-w-        c:\windows\system32\licmgr10.dll 
2015-01-04 16:23 . 2015-01-04 16:23        243200        ----a-w-        c:\windows\system32\webcheck.dll 
2015-01-04 16:23 . 2015-01-04 16:23        235520        ----a-w-        c:\windows\system32\url.dll 
2015-01-04 16:23 . 2015-01-04 16:23        167424        ----a-w-        c:\windows\system32\iexpress.exe 
2015-01-04 16:23 . 2015-01-04 16:23        143872        ----a-w-        c:\windows\system32\wextract.exe 
2015-01-04 16:23 . 2015-01-04 16:23        101376        ----a-w-        c:\windows\system32\inseng.dll 
2015-01-04 16:23 . 2015-01-04 16:23        774144        ----a-w-        c:\windows\system32\jscript.dll 
2015-01-04 16:23 . 2015-01-04 16:23        62464        ----a-w-        c:\windows\system32\pngfilt.dll 
2015-01-04 16:23 . 2015-01-04 16:23        48128        ----a-w-        c:\windows\system32\imgutil.dll 
2015-01-04 16:23 . 2015-01-04 16:23        147968        ----a-w-        c:\windows\system32\occache.dll 
2015-01-04 16:23 . 2015-01-04 16:23        13824        ----a-w-        c:\windows\system32\mshta.exe 
2015-01-04 16:23 . 2015-01-04 16:23        135680        ----a-w-        c:\windows\system32\iepeers.dll 
2015-01-04 16:19 . 2015-01-04 16:19        9728        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 
2015-01-04 16:19 . 2015-01-04 16:19        9728        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 
2015-01-04 16:19 . 2015-01-04 16:19        648192        ----a-w-        c:\windows\system32\d3d10level9.dll 
2015-01-04 16:19 . 2015-01-04 16:19        604160        ----a-w-        c:\windows\SysWow64\d3d10level9.dll 
2015-01-04 16:19 . 2015-01-04 16:19        5632        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 
2015-01-04 16:19 . 2015-01-04 16:19        5632        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll 
2015-01-04 16:19 . 2015-01-04 16:19        5632        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 
2015-01-04 16:19 . 2015-01-04 16:19        5632        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 
2015-01-04 16:19 . 2015-01-04 16:19        522752        ----a-w-        c:\windows\system32\XpsGdiConverter.dll 
2015-01-04 16:19 . 2015-01-04 16:19        4096        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll 
2015-01-04 16:19 . 2015-01-04 16:19        4096        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 
2015-01-04 16:19 . 2015-01-04 16:19        364544        ----a-w-        c:\windows\SysWow64\XpsGdiConverter.dll 
2015-01-04 16:19 . 2015-01-04 16:19        363008        ----a-w-        c:\windows\system32\dxgi.dll 
2015-01-04 16:19 . 2015-01-04 16:19        3584        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll 
2015-01-04 16:19 . 2015-01-04 16:19        3584        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 
2015-01-04 16:19 . 2015-01-04 16:19        333312        ----a-w-        c:\windows\system32\d3d10_1core.dll 
2015-01-04 16:19 . 2015-01-04 16:19        3072        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll 
2015-01-04 16:19 . 2015-01-04 16:19        3072        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll 
2015-01-04 16:19 . 2015-01-04 16:19        3072        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 
2015-01-04 16:19 . 2015-01-04 16:19        3072        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 
2015-01-04 16:19 . 2015-01-04 16:19        296960        ----a-w-        c:\windows\system32\d3d10core.dll 
2015-01-04 16:19 . 2015-01-04 16:19        293376        ----a-w-        c:\windows\SysWow64\dxgi.dll 
2015-01-04 16:19 . 2015-01-04 16:19        2560        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll 
2015-01-04 16:19 . 2015-01-04 16:19        2560        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 
2015-01-04 16:19 . 2015-01-04 16:19        249856        ----a-w-        c:\windows\SysWow64\d3d10_1core.dll 
2015-01-04 16:19 . 2015-01-04 16:19        245248        ----a-w-        c:\windows\system32\WindowsCodecsExt.dll 
2015-01-04 16:19 . 2015-01-04 16:19        221184        ----a-w-        c:\windows\system32\UIAnimation.dll 
2015-01-04 16:19 . 2015-01-04 16:19        220160        ----a-w-        c:\windows\SysWow64\d3d10core.dll 
2015-01-04 16:19 . 2015-01-04 16:19        207872        ----a-w-        c:\windows\SysWow64\WindowsCodecsExt.dll 
2015-01-04 16:19 . 2015-01-04 16:19        194560        ----a-w-        c:\windows\system32\d3d10_1.dll 
2015-01-04 16:19 . 2015-01-04 16:19        187392        ----a-w-        c:\windows\SysWow64\UIAnimation.dll 
2015-01-04 16:19 . 2015-01-04 16:19        1682432        ----a-w-        c:\windows\system32\XpsPrint.dll 
2015-01-04 16:19 . 2015-01-04 16:19        161792        ----a-w-        c:\windows\SysWow64\d3d10_1.dll 
2015-01-04 16:19 . 2015-01-04 16:19        1238528        ----a-w-        c:\windows\system32\d3d10.dll 
2015-01-04 16:19 . 2015-01-04 16:19        1175552        ----a-w-        c:\windows\system32\FntCache.dll 
2015-01-04 16:19 . 2015-01-04 16:19        1158144        ----a-w-        c:\windows\SysWow64\XpsPrint.dll 
2015-01-04 16:19 . 2015-01-04 16:19        1080832        ----a-w-        c:\windows\SysWow64\d3d10.dll 
2015-01-04 16:19 . 2015-01-04 16:19        10752        ---ha-w-        c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll 
2015-01-04 16:19 . 2015-01-04 16:19        10752        ---ha-w-        c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 
2014-12-15 10:45 . 2015-01-06 13:00        35112        ----a-w-        c:\windows\system32\drivers\teamviewervpn.sys 
2014-12-10 11:25 . 2014-12-10 11:25        2459136        ----a-w-        c:\windows\SysWow64\python27.dll 
2014-11-28 12:02 . 2014-11-28 12:02        18456        ----a-w-        c:\windows\system32\drivers\psi_mf_amd64.sys 
2014-11-20 04:42 . 2014-11-20 04:42        37008        ----a-w-        c:\windows\system32\FM20DEU.DLL 
2014-11-18 19:47 . 2014-11-18 19:47        1691816        ----a-w-        c:\windows\system32\FM20.DLL 
2014-11-15 13:46 . 2014-11-15 13:46        274696        ----a-w-        c:\windows\system32\drivers\MpFilter.sys 
2014-11-15 13:46 . 2014-11-15 13:46        124560        ----a-w-        c:\windows\system32\drivers\NisDrvWFP.sys 
. 
. 
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   )))))))))))))))))))))))))))))))))))))))) 
. 
. 
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.  
REGEDIT4 
. 
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)] 
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}" 
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}] 
2015-01-21 14:05        1729744        ----a-w-        c:\progra~2\MICROS~4\Office15\GROOVEEX.DLL 
. 
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)] 
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}" 
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}] 
2015-01-21 14:05        1729744        ----a-w-        c:\progra~2\MICROS~4\Office15\GROOVEEX.DLL 
. 
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)] 
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}" 
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}] 
2015-01-21 14:05        1729744        ----a-w-        c:\progra~2\MICROS~4\Office15\GROOVEEX.DLL 
. 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 
"HydraVisionDesktopManager"="c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [2012-11-16 393216] 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X] 
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-04-29 642304] 
"LogMeIn Hamachi Ui"="d:\hamachi\hamachi-2-ui.exe" [2015-01-20 3977576] 
"AvastUI.exe"="d:\avast\AvastUI.exe" [2015-02-13 5225064] 
. 
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ 
Allzeit Atomzeit (leise, 3 Min. verzögert).lnk - c:\allzeit atomzeit\Atomzeit.exe /leise 3 [2007-4-16 77824] 
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2014-11-28 591576] 
SteelSeries Engine 3.lnk - c:\program files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe -dataPath="c:\programdata\SteelSeries\SteelSeries Engine 3" -dbEnv=production -auto=true [2015-2-2 17833984] 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] 
"ConsentPromptBehaviorUser"= 3 (0x3) 
"EnableUIADesktopToggle"= 0 (0x0) 
"SoftwareSASGeneration"= 1 (0x1) 
. 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] 
@="Service" 
. 
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] 
R3 a2acc;a2acc;c:\program files (x86)\EMSISOFT ANTI-MALWARE\a2accx64.sys;c:\program files (x86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [x] 
R3 cleanhlp;cleanhlp;c:\program files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys;c:\program files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [x] 
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] 
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] 
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x] 
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x] 
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x] 
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] 
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] 
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] 
R3 VsEtwService120;Visual Studio ETW Event Collection Service;c:\program files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe;c:\program files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [x] 
R4 a2AntiMalware;Emsisoft Protection Service;c:\program files (x86)\Emsisoft Anti-Malware\a2service.exe;c:\program files (x86)\Emsisoft Anti-Malware\a2service.exe [x] 
R4 Origin Client Service;Origin Client Service;d:\origin\OriginClientService.exe;d:\origin\OriginClientService.exe [x] 
R4 OverwolfUpdater;Overwolf Updater Windows SCM;c:\program files (x86)\Overwolf\OverwolfUpdater.exe;c:\program files (x86)\Overwolf\OverwolfUpdater.exe [x] 
S1 A2DDA;A2 Direct Disk Access Support Driver;c:\program files (x86)\Emsisoft Anti-Malware\a2ddax64.sys;c:\program files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [x] 
S1 a2injectiondriver;a2injectiondriver;c:\program files (x86)\Emsisoft Anti-Malware\a2dix64.sys;c:\program files (x86)\Emsisoft Anti-Malware\a2dix64.sys [x] 
S1 a2util;a-squared Malware-IDS utility driver;c:\program files (x86)\Emsisoft Anti-Malware\a2util64.sys;c:\program files (x86)\Emsisoft Anti-Malware\a2util64.sys [x] 
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] 
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;d:\hamachi\hamachi-2.exe;d:\hamachi\hamachi-2.exe [x] 
S2 IpOverUsbSvc;Windows Phone IP over USB Transport (IpOverUsbSvc);c:\program files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe;c:\program files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [x] 
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] 
S3 hidkmdf;Filter Driver Service for HID-KMDF Interface layer;c:\windows\system32\DRIVERS\hidkmdf.sys;c:\windows\SYSNATIVE\DRIVERS\hidkmdf.sys [x] 
S3 RTCore64;RTCore64;d:\msi afterburner\RTCore64.sys;d:\msi afterburner\RTCore64.sys [x] 
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] 
S3 sshid;SteelSeries HID Service;c:\windows\system32\DRIVERS\sshid.sys;c:\windows\SYSNATIVE\DRIVERS\sshid.sys [x] 
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys;c:\windows\SYSNATIVE\DRIVERS\teamviewervpn.sys [x] 
. 
. 
--- Andere Dienste/Treiber im Speicher --- 
. 
*NewlyCreated* - ASWHWID 
*NewlyCreated* - ASWMONFLT 
*NewlyCreated* - ASWRDR 
*NewlyCreated* - ASWSNX 
*NewlyCreated* - ASWSTM 
*NewlyCreated* - ASWVMM 
*NewlyCreated* - KXTDIPOC 
*NewlyCreated* - MPFILTER 
*NewlyCreated* - NISDRV 
*NewlyCreated* - PSI 
*NewlyCreated* - QTBIKRXB 
*NewlyCreated* - RFUWDYBO 
*NewlyCreated* - VBOXASWDRV 
*Deregistered* - kxtdipoc 
*Deregistered* - qtbikrxb 
. 
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 
2015-02-13 11:03        1086280        ----a-w-        c:\program files (x86)\Google\Chrome\Application\40.0.2214.111\Installer\chrmstp.exe 
. 
Inhalt des "geplante Tasks" Ordners 
. 
2015-02-13 c:\windows\Tasks\Adobe Flash Player Updater.job 
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-04 11:38] 
. 
2015-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job 
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-02-13 11:02] 
. 
2015-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job 
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-02-13 11:02] 
. 
. 
--------- X64 Entries ----------- 
. 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)] 
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}" 
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}] 
2015-01-21 14:01        2334928        ----a-w-        d:\mcoffi~1\Office15\GROOVEEX.DLL 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)] 
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}" 
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}] 
2015-01-21 14:01        2334928        ----a-w-        d:\mcoffi~1\Office15\GROOVEEX.DLL 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)] 
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}" 
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}] 
2015-01-21 14:01        2334928        ----a-w-        d:\mcoffi~1\Office15\GROOVEEX.DLL 
. 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] 
@="{472083B0-C522-11CF-8763-00608CC02F24}" 
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 
2015-02-13 11:02        860984        ----a-w-        d:\avast\ashShA64.dll 
. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2014-05-09 13672152] 
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2015-01-30 1332296] 
. 
------- Zusätzlicher Suchlauf ------- 
. 
uLocal Page = c:\windows\system32\blank.htm 
uStart Page = about:Tabs 
mLocal Page = c:\windows\SysWOW64\blank.htm 
IE: An OneNote s&enden - d:\mcoffi~1\Office15\ONBttnIE.dll/105 
IE: Client auf Monitor & öffnen1 - c:\windows\web\AOpenClient.htm 
IE: Client auf Monitor & öffnen2 - c:\windows\web\AOpenClient.htm 
IE: Nach Microsoft E&xcel exportieren - d:\mcoffi~1\Office15\EXCEL.EXE/3000 
TCP: Interfaces\{3B7C1F1E-95AA-495A-881C-D64F94F61C02}: NameServer = 8.8.8.8,8.8.4.4 
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL 
. 
- - - - Entfernte verwaiste Registrierungseinträge - - - - 
. 
Toolbar-Locked - (no file) 
SafeBoot-45442217.sys 
SafeBoot-CleanHlp 
SafeBoot-CleanHlp.sys 
Toolbar-Locked - (no file) 
AddRemove-1207665503_is1 - f:\terraria\unins000.exe 
AddRemove-Adobe Acrobat 5.0 - c:\windows\ISUN0407.EXE 
. 
. 
. 
--------------------- Gesperrte Registrierungsschluessel --------------------- 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Internet Explorer\User Preferences] 
@Denied: (2) (Administrator) 
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, 
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,42,b5,b8,8e,30,86,cf,48,88,31,5d,\ 
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, 
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,42,b5,b8,8e,30,86,cf,48,88,31,5d,\ 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.3G2" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.3GP" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.3G2" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.3GP" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.8SVX\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.8SVX" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AAC\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.AAC" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADT\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.ADTS" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADTS\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.ADTS" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AFC\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.AFC" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.AIF" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.AIFC" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.AIFF" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.ASF" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.ASX" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.AU" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="Applications\\vlc.exe" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BWF\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.BWF" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CDA\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.CDA" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crx\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="OperaStable" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cue\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.CUE" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dll\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="Applications\\notepad.exe" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.doc\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="Word.Document.8" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docm\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="Word.DocumentMacroEnabled.12" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docx\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="Word.Document.12" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dot\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="Word.Template.8" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotm\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="Word.TemplateMacroEnabled.12" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotx\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="Word.Template.12" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.FLA\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.FLA" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.FLAC" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.FPL\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.FPL" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="OperaStable" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="OperaStable" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.IMG\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="Applications\\VCDMount.exe" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.MPEG" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2T\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.M2TS" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2TS\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.M2TS" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2V\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.MPEG" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.M3U" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M3U8\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.M3U8" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.M4A" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M4B\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.M4B" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M4R\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.M4R" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.MP4" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.MIDI" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.MIDI" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MKA\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.MKA" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MOD\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.MPEG" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MP+\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.MP+" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MP1\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.MP1" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.MP2" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.MPEG" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.MP3" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.MP4" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4v\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.MP4" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.MPEG" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MPC\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.MPC" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.MPEG" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.MPEG" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.MPEG" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MPP\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.MPP" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.MPEG" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MTS\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.M2TS" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nex\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="OperaStable" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.OGA\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.OGA" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.OGG\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.OGG" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.OGX\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.OGX" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.OPUS\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.OPUS" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="Applications\\SumatraPDF.exe" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.PLS\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.PLS" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.RF64\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.RF64" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.MIDI" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rtf\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="Word.RTF.8" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgf\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="Applications\\GOWrite.exe" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="OperaStable" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.SND" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.SPX\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.SPX" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.SVX\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.SVX" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TS\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="VsWinExpress.ts.12.0" 
"Hash"="m+DR1As22GY=" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TTS\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.TTS" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.W64\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.W64" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.WAV" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.WAVE\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.WAVE" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.WAX" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbk\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="Word.Backup.8" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wiz\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="Word.Wizard.8" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.ASF" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.WMA" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.WMD" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.WMS" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.WMV" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.ASX" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmz\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.WMZ" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpl\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="WMP11.AssocFile.WPL" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.WV\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.WV" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="foobar2000.WVX" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="OperaStable" 
. 
[HKEY_USERS\S-1-5-21-4198189618-3789533832-1361530959-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice] 
@Denied: (2) (Administrator) 
"Progid"="OperaStable" 
. 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] 
@Denied: (Full) (Everyone) 
. 
Zeit der Fertigstellung: 2015-02-13  14:26:08 
ComboFix-quarantined-files.txt  2015-02-13 13:26 
. 
Vor Suchlauf: 22 Verzeichnis(se), 148.067.270.656 Bytes frei 
Nach Suchlauf: 26 Verzeichnis(se), 148.022.435.840 Bytes frei 
. 
- - End Of File - - E6CC271B830CE794C00AA773DEADCF77 
A36C5E4F47E84449FF07ED3517B43A31      |