helgasee | 23.02.2015 05:08 | Iminent erscheint nicht bei den zu deinstallierenden Dateien. Ich habe Revo Uninstaller Pro 3.1.2 auf dem Rechner. Code:
ComboFix 15-02-16.01 - Helga Seemannn 22.02.2015 16:41:36.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3997.1392 [GMT 1:00]
ausgeführt von:: c:\users\Helga Seemannn\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {179979E8-273D-D14E-0543-2861940E4886}
FW: Kaspersky Internet Security *Disabled* {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
SP: IObit Malware Fighter *Enabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Kaspersky Internet Security *Disabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Probit Software\Easy Speed PC
c:\program files (x86)\Probit Software\Easy Speed PC\EasySpeedPC.exe
c:\programdata\ntuser.pol
c:\programdata\Roaming
c:\users\Helga Seemannn\AppData\Local\assembly\tmp
c:\users\Helga Seemannn\WINDOWS
c:\windows\SysWOW64mfc45.dll
c:\windows\wininit.ini
c:\windows\XSxS
.
Infizierte Kopie von c:\windows\SysWow64\userinit.exe wurde gefunden und desinfiziert
Kopie von - c:\windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe wurde wiederhergestellt
.
.
((((((((((((((((((((((( Dateien erstellt von 2015-01-22 bis 2015-02-22 ))))))))))))))))))))))))))))))
.
.
2015-02-22 16:40 . 2015-02-22 16:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-02-22 16:40 . 2015-02-22 16:40 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2015-02-20 21:13 . 2015-02-20 21:19 -------- d-----w- C:\FRST
2015-02-20 19:49 . 2015-02-20 19:49 -------- d-----w- c:\programdata\Malwarebytes
2015-02-20 18:58 . 2015-02-20 18:58 51496 ----a-w- c:\windows\system32\drivers\stflt.sys
2015-02-20 06:00 . 2015-01-29 09:07 11910896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0AB831CA-B01E-47DD-ACBF-08826E3E3CB7}\mpengine.dll
2015-02-18 21:29 . 2015-02-18 21:29 950272 ----a-w- c:\windows\system32\perftrack.dll
2015-02-18 21:29 . 2015-02-18 21:29 91136 ----a-w- c:\windows\system32\wdi.dll
2015-02-18 21:29 . 2015-02-18 21:29 76800 ----a-w- c:\windows\SysWow64\wdi.dll
2015-02-18 21:29 . 2015-02-18 21:29 29696 ----a-w- c:\windows\system32\powertracker.dll
2015-02-18 16:42 . 2015-02-18 16:43 -------- d-----w- c:\program files (x86)\DVDVideoSoft
2015-02-18 16:42 . 2015-02-18 16:42 -------- d-----w- c:\program files (x86)\Common Files\DVDVideoSoft
2015-02-18 16:42 . 2015-02-18 16:42 -------- d-----w- c:\users\Helga Seemannn\AppData\Roaming\RHEng
2015-02-18 16:40 . 2015-02-18 16:45 -------- d-----w- c:\users\Helga Seemannn\AppData\Roaming\DVDVideoSoft
2015-02-18 16:27 . 2015-02-18 16:27 -------- d-----w- c:\users\Helga Seemannn\AppData\Local\CDex
2015-02-18 16:26 . 2015-02-18 16:27 -------- d-----w- c:\program files (x86)\CDex
2015-02-12 06:25 . 2015-01-23 04:41 6041600 ----a-w- c:\windows\system32\jscript9.dll
2015-02-12 06:25 . 2015-01-23 03:43 620032 ----a-w- c:\windows\SysWow64\jscript9diag.dll
2015-02-12 06:25 . 2015-01-23 03:17 4300800 ----a-w- c:\windows\SysWow64\jscript9.dll
2015-02-12 06:25 . 2015-01-23 04:42 814080 ----a-w- c:\windows\system32\jscript9diag.dll
2015-02-11 06:05 . 2015-01-13 03:10 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2015-02-11 06:04 . 2015-01-09 02:03 3201536 ----a-w- c:\windows\system32\win32k.sys
2015-02-09 06:22 . 2015-02-09 06:22 11532704 ----a-w- c:\windows\system32\drivers\NETwsw01.sys
2015-02-09 06:21 . 2015-02-09 06:21 942080 ----a-w- c:\windows\system32\AmRdrIco.icl
2015-02-09 06:21 . 2015-02-09 06:21 21784 ----a-w- c:\windows\system32\AmUStor.dll
2015-02-09 06:21 . 2015-02-09 06:21 108312 ----a-w- c:\windows\system32\drivers\AmUStor.sys
2015-02-05 06:57 . 2014-06-04 14:17 21184 ----a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2015-01-30 17:34 . 2015-01-30 17:35 -------- d-----w- c:\program files (x86)\EZCast
2015-01-28 16:24 . 2015-01-28 16:29 -------- d-----w- c:\users\Helga Seemannn\AppData\Roaming\VoipConnect
2015-01-28 16:24 . 2015-01-28 16:24 -------- d-----w- c:\program files (x86)\VoipConnect.com
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-02-11 07:02 . 2012-01-20 17:58 116773704 ----a-w- c:\windows\system32\MRT.exe
2015-02-06 07:11 . 2012-04-04 17:46 701616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2015-02-06 07:11 . 2012-01-22 13:17 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-12-29 09:20 . 2014-12-29 09:20 26528 ----a-w- c:\windows\SysWow64\drivers\HWiNFO64A.SYS
2014-12-29 07:22 . 2014-12-29 07:22 5120 ----a-w- c:\windows\system32\drivers\subvga64.sys
2014-12-29 07:22 . 2014-12-29 07:22 15872 ----a-w- c:\windows\system32\subvgadisp64.dll
2014-12-22 23:41 . 2010-11-21 03:27 298120 ------w- c:\windows\system32\MpSigStub.exe
2014-12-19 03:06 . 2015-01-14 06:23 210432 ----a-w- c:\windows\system32\profsvc.dll
2014-12-19 01:46 . 2015-01-14 06:23 141312 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2014-12-11 17:47 . 2015-01-14 06:23 87040 ----a-w- c:\windows\system32\TSWbPrxy.exe
2014-12-06 04:17 . 2015-01-14 06:23 303616 ----a-w- c:\windows\system32\nlasvc.dll
2014-12-06 03:50 . 2015-01-14 06:23 52224 ----a-w- c:\windows\SysWow64\nlaapi.dll
2014-12-06 03:50 . 2015-01-14 06:23 156672 ----a-w- c:\windows\SysWow64\ncsi.dll
2014-12-05 06:04 . 2014-12-05 06:04 515568 ----a-w- c:\windows\system32\igfxsrvc.exe
2014-12-05 06:04 . 2014-12-05 06:04 439296 ----a-w- c:\windows\system32\igfxrrus.lrc
2014-12-05 06:04 . 2014-12-05 06:04 439296 ----a-w- c:\windows\system32\igfxrrom.lrc
2014-12-05 06:04 . 2014-12-05 06:04 438784 ----a-w- c:\windows\system32\igfxrsky.lrc
2014-12-05 06:04 . 2014-12-05 06:04 438784 ----a-w- c:\windows\system32\igfxrptg.lrc
2014-12-05 06:04 . 2014-12-05 06:04 438784 ----a-w- c:\windows\system32\igfxrplk.lrc
2014-12-05 06:04 . 2014-12-05 06:04 438784 ----a-w- c:\windows\system32\igfxrnld.lrc
2014-12-05 06:04 . 2014-12-05 06:04 437760 ----a-w- c:\windows\system32\igfxrtrk.lrc
2014-12-05 06:04 . 2014-12-05 06:04 437760 ----a-w- c:\windows\system32\igfxrsve.lrc
2014-12-05 06:04 . 2014-12-05 06:04 437760 ----a-w- c:\windows\system32\igfxrslv.lrc
2014-12-05 06:04 . 2014-12-05 06:04 437760 ----a-w- c:\windows\system32\igfxrptb.lrc
2014-12-05 06:04 . 2014-12-05 06:04 437760 ----a-w- c:\windows\system32\igfxrnor.lrc
2014-12-05 06:04 . 2014-12-05 06:04 437248 ----a-w- c:\windows\system32\igfxrtha.lrc
2014-12-05 06:04 . 2014-12-05 06:04 410624 ----a-w- c:\windows\system32\igfxTMM.dll
2014-12-05 06:04 . 2014-12-05 06:04 279024 ----a-w- c:\windows\SysWow64\IntelCpHeciSvc.exe
2014-12-05 06:04 . 2014-12-05 06:04 172016 ----a-w- c:\windows\system32\igfxtray.exe
2014-12-05 06:04 . 2014-12-05 06:04 116224 ----a-w- c:\windows\system32\igfxCoIn_v3517.dll
2014-12-05 06:04 . 2014-12-05 06:04 431104 ----a-w- c:\windows\system32\igfxrkor.lrc
2014-12-05 06:04 . 2011-08-31 20:21 64000 ----a-w- c:\windows\system32\igfxsrvc.dll
2014-12-05 06:04 . 2014-12-05 06:04 9728 ----a-w- c:\windows\system32\IGFXDEVLib.dll
2014-12-05 06:04 . 2014-12-05 06:04 442880 ----a-w- c:\windows\system32\igfxdev.dll
2014-12-05 06:04 . 2014-12-05 06:04 442352 ----a-w- c:\windows\system32\igfxpers.exe
2014-12-05 06:04 . 2014-12-05 06:04 440320 ----a-w- c:\windows\system32\igfxrell.lrc
2014-12-05 06:04 . 2014-12-05 06:04 439808 ----a-w- c:\windows\system32\igfxrfra.lrc
2014-12-05 06:04 . 2014-12-05 06:04 439808 ----a-w- c:\windows\system32\igfxresn.lrc
2014-12-05 06:04 . 2014-12-05 06:04 438784 ----a-w- c:\windows\system32\igfxrita.lrc
2014-12-05 06:04 . 2014-12-05 06:04 438784 ----a-w- c:\windows\system32\igfxrhrv.lrc
2014-12-05 06:04 . 2014-12-05 06:04 438784 ----a-w- c:\windows\system32\igfxrdeu.lrc
2014-12-05 06:04 . 2014-12-05 06:04 438272 ----a-w- c:\windows\system32\igfxrhun.lrc
2014-12-05 06:04 . 2014-12-05 06:04 438272 ----a-w- c:\windows\system32\igfxrfin.lrc
2014-12-05 06:04 . 2014-12-05 06:04 438272 ----a-w- c:\windows\system32\igfxrcsy.lrc
2014-12-05 06:04 . 2014-12-05 06:04 437248 ----a-w- c:\windows\system32\igfxrdan.lrc
2014-12-05 06:04 . 2014-12-05 06:04 435712 ----a-w- c:\windows\system32\igfxrheb.lrc
2014-12-05 06:04 . 2014-12-05 06:04 435712 ----a-w- c:\windows\system32\igfxrara.lrc
2014-12-05 06:04 . 2014-12-05 06:04 432128 ----a-w- c:\windows\system32\igfxrjpn.lrc
2014-12-05 06:04 . 2014-12-05 06:04 429056 ----a-w- c:\windows\system32\igfxrcht.lrc
2014-12-05 06:04 . 2014-12-05 06:04 428544 ----a-w- c:\windows\system32\igfxrchs.lrc
2014-12-05 06:04 . 2014-12-05 06:04 384512 ----a-w- c:\windows\system32\igfxpph.dll
2014-12-05 06:04 . 2014-12-05 06:04 330752 ----a-w- c:\windows\SysWow64\igfxdv32.dll
2014-12-05 06:04 . 2014-12-05 06:04 286208 ----a-w- c:\windows\system32\igfxrenu.lrc
2014-12-05 06:04 . 2014-12-05 06:04 254960 ----a-w- c:\windows\system32\igfxext.exe
2014-12-05 06:04 . 2014-12-05 06:04 142336 ----a-w- c:\windows\system32\igfxdo.dll
2014-12-05 06:04 . 2014-12-05 06:04 126976 ----a-w- c:\windows\system32\igfxcpl.cpl
2014-12-05 06:04 . 2014-12-05 06:04 12617728 ----a-w- c:\windows\system32\igdumd64.dll
2014-12-05 06:04 . 2013-06-27 06:07 11049984 ----a-w- c:\windows\SysWow64\igdumd32.dll
2014-12-05 06:04 . 2013-06-27 06:06 9007616 ----a-w- c:\windows\system32\igfxress.dll
2014-12-05 06:04 . 2011-08-31 20:21 28672 ----a-w- c:\windows\system32\igfxexps.dll
2014-12-05 06:04 . 2011-08-31 20:16 25088 ----a-w- c:\windows\SysWow64\igfxexps32.dll
2014-12-05 06:04 . 2014-12-05 06:04 5363520 ----a-w- c:\windows\system32\drivers\igdkmd64.sys
2014-12-05 06:04 . 2014-12-05 06:04 99328 ----a-w- c:\windows\system32\igdde64.dll
2014-12-05 06:04 . 2014-12-05 06:04 78848 ----a-w- c:\windows\SysWow64\igdde32.dll
2014-12-05 06:04 . 2014-12-05 06:04 12859392 ----a-w- c:\windows\system32\igd10umd64.dll
2014-12-05 06:04 . 2014-12-05 06:04 11176448 ----a-w- c:\windows\SysWow64\igd10umd32.dll
2014-12-05 06:04 . 2014-12-05 06:04 13031424 ----a-w- c:\windows\system32\ig4icd64.dll
2014-12-05 06:04 . 2014-12-05 06:04 10812928 ----a-w- c:\windows\SysWow64\ig4icd32.dll
2014-12-05 06:04 . 2014-12-05 06:04 5904880 ----a-w- c:\windows\system32\GfxUI.exe
2014-12-05 06:04 . 2014-12-05 06:04 399856 ----a-w- c:\windows\system32\hkcmd.exe
2014-12-05 06:04 . 2014-12-05 06:04 185840 ----a-w- c:\windows\system32\difx64.exe
2014-12-05 06:04 . 2014-12-05 06:04 175104 ----a-w- c:\windows\system32\gfxSrvc.dll
2014-12-05 06:04 . 2012-12-14 01:42 110592 ----a-w- c:\windows\system32\hccutils.dll
2014-12-05 06:04 . 2014-12-05 06:04 101888 ----a-w- c:\windows\system32\drivers\risdxc64.sys
2014-12-05 06:03 . 2014-12-05 06:03 69088 ----a-w- c:\windows\system32\drivers\iBtFltCoex.sys
2014-12-05 06:03 . 2014-12-05 06:03 1721216 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2014-12-05 06:03 . 2014-12-05 06:03 1419576 ----a-w- c:\windows\system32\drivers\btmhsf.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F}]
2014-06-11 14:20 464720 ----a-w- c:\program files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 131248 ----a-w- c:\users\Helga Seemannn\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 131248 ----a-w- c:\users\Helga Seemannn\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 131248 ----a-w- c:\users\Helga Seemannn\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Quickstart - Toolbar"="c:\launcher31b19\Launcher.exe" [2008-04-01 260096]
"Hoffnung fuer heute"="c:\program files (x86)\ComBib\Hoffnung fuer heute\Hoffnung fuer heute.exe" [2013-12-02 2568192]
"StickyPassword"="c:\program files (x86)\Sticky Password\stpass.exe" [2014-09-24 14310200]
"VoipConnect"="c:\program files (x86)\VoipConnect.com\VoipConnect\VoipConnect.exe" [2014-12-04 23048288]
"GoogleChromeAutoLaunch_E7AB2F37F5105CE78BDE76BDD71ECAE2"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2015-02-17 843592]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2015-01-20 7404312]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"TSleepSrv"="c:\program files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe" [2010-06-05 252792]
"TOSDCR"="c:\program files (x86)\TOSHIBA\PasswordUtility\TOSDCR.exe" [2007-08-28 169296]
"IObit Malware Fighter"="c:\program files (x86)\IObit\IObit Malware Fighter\IMF.exe" [2015-02-02 5768992]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 8"="c:\program files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" [2014-12-10 2427680]
.
c:\users\Helga Seemannn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
FastStone Capture.lnk - c:\program files (x86)\FastStone Capture\FSCapture.exe -Silent [2007-2-12 1111552]
Hoffnung fuer heute.LNK - c:\program files (x86)\ComBib\Hoffnung fuer heute\Hoffnung fuer heute.exe cbAutoStart [2013-12-2 2568192]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2011-5-10 2750376]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ioloSystemService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"SSBkgdUpdate"="c:\program files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
"PPort11reminder"="c:\program files (x86)\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "c:\programdata\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 KMService;KMService;c:\windows\system32\srvany.exe;c:\windows\SYSNATIVE\srvany.exe [x]
R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
R2 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x]
R3 cpuz134;cpuz134;c:\users\HELGAS~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys;c:\users\HELGAS~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 EsgScanner;EsgScanner;c:\windows\system32\DRIVERS\EsgScanner.sys;c:\windows\SYSNATIVE\DRIVERS\EsgScanner.sys [x]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys;c:\windows\SYSNATIVE\Drivers\ANDROIDUSB.sys [x]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys;c:\windows\SYSNATIVE\DRIVERS\htcnprot.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys;c:\windows\SYSNATIVE\drivers\intelaud.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf_amd64.sys;c:\windows\SYSNATIVE\DRIVERS\psi_mf_amd64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys;c:\windows\SYSNATIVE\DRIVERS\revoflt.sys [x]
R3 SWDUMon;SWDUMon;c:\windows\system32\DRIVERS\SWDUMon.sys;c:\windows\SYSNATIVE\DRIVERS\SWDUMon.sys [x]
R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [x]
R3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys;c:\program files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WSDScan;WSD-Scanunterstützung durch UMB;c:\windows\system32\drivers\WSDScan.sys;c:\windows\SYSNATIVE\drivers\WSDScan.sys [x]
R4 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x]
R4 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
R4 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
R4 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x]
R4 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
R4 NitroDriverReadSpool2;NitroPDFDriverCreatorReadSpool2;c:\program files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe;c:\program files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe [x]
R4 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [x]
R4 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe;c:\program files (x86)\Secunia\PSI\PSIA.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys;c:\windows\SYSNATIVE\DRIVERS\tos_sps64.sys [x]
S1 cnnctfy3;Connectify LightWeight Filter;c:\windows\system32\DRIVERS\cnnctfy3.sys;c:\windows\SYSNATIVE\DRIVERS\cnnctfy3.sys [x]
S1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\ElRawDsk.sys;c:\windows\SYSNATIVE\drivers\ElRawDsk.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S1 klhk;klhk;c:\windows\system32\DRIVERS\klhk.sys;c:\windows\SYSNATIVE\DRIVERS\klhk.sys [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
S1 klpd;klpd;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x]
S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x]
S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x]
S1 RawDisk3;RawDisk3;c:\windows\system32\drivers\rawdsk3.sys;c:\windows\SYSNATIVE\drivers\rawdsk3.sys [x]
S2 AdvancedSystemCareService8;Advanced SystemCare Service 8;c:\program files (x86)\IObit\Advanced SystemCare 8\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [x]
S2 AVP15.0.0;Kaspersky Anti-Virus Service 15.0.0;c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avp.exe;c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avp.exe [x]
S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [x]
S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [x]
S2 HTCMonitorService;HTCMonitorService;c:\program files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe;c:\program files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [x]
S2 IMFservice;IMF Service;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [x]
S2 ioloSystemService;iolo System Service;c:\program files (x86)\iolo\Common\Lib\ioloServiceManager.exe;c:\program files (x86)\iolo\Common\Lib\ioloServiceManager.exe [x]
S2 irstrtsv;Intel(R) Rapid Start Technology Service;c:\windows\system32\irstrtsv.exe;c:\windows\SYSNATIVE\irstrtsv.exe [x]
S2 PDFsFilter;PDFsFilter;c:\windows\system32\DRIVERS\PDFsFilter.sys;c:\windows\SYSNATIVE\DRIVERS\PDFsFilter.sys [x]
S2 risdxc;risdxc;c:\windows\system32\DRIVERS\risdxc64.sys;c:\windows\SYSNATIVE\DRIVERS\risdxc64.sys [x]
S2 serviceIEConfig;IEConfig 1und1 Edition;c:\windows\SysWOW64\ieconfig_1und1_svc.exe;c:\windows\SysWOW64\ieconfig_1und1_svc.exe [x]
S2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys;c:\windows\SYSNATIVE\DRIVERS\TVALZFL.sys [x]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x]
S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 irstrtdv;Intel(R) Rapid Start Technology Driver;c:\windows\system32\DRIVERS\irstrtdv.sys;c:\windows\SYSNATIVE\DRIVERS\irstrtdv.sys [x]
S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys;c:\windows\SYSNATIVE\DRIVERS\iwdbus.sys [x]
S3 klflt;Kaspersky Lab Kernel DLL;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x]
S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys;c:\windows\SYSNATIVE\DRIVERS\pgeffect.sys [x]
S3 subvgaproduct64;subvgaproduct64;c:\windows\system32\DRIVERS\subvga64.sys;c:\windows\SYSNATIVE\DRIVERS\subvga64.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-02-20 05:50 1084744 ----a-w- c:\program files (x86)\Google\Chrome\Application\40.0.2214.115\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2015-02-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 07:11]
.
2015-02-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-07 05:46]
.
2015-02-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-07 05:46]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
2015-02-05 06:56 2471744 ----a-w- c:\program files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 164016 ----a-w- c:\users\Helga Seemannn\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 164016 ----a-w- c:\users\Helga Seemannn\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 164016 ----a-w- c:\users\Helga Seemannn\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 164016 ----a-w- c:\users\Helga Seemannn\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2015-01-15 15:59 776520 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2015-01-15 15:59 776520 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2015-01-15 15:59 776520 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2015-01-15 15:59 776520 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2015-01-15 15:59 776520 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2011-09-23 590256]
"TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2011-08-03 981888]
"TosWaitSrv"="c:\program files\TOSHIBA\TPHM\TosWaitSrv.exe" [2011-08-10 712096]
"IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-06-01 1935120]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-24 2726728]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2000-01-01 13657304]
"RtHDVBg_Dolby"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2000-01-01 1360600]
"BatteryManager"="c:\program files\TOSHIBA\Power Saver\TBatmgrTrayIcon.EXE" [2011-09-23 285608]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2011-06-09 710560]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2014-12-05 172016]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2014-12-05 399856]
"Persistence"="c:\windows\system32\igfxpers.exe" [2014-12-05 442352]
.
------- Zusätzlicher Suchlauf -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://go.1und1.de/links/home
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com
uSearchURL,(Default) = hxxp://go.1und1.de/suchbox/1und1suche?su=%s
IE: Alles mit FDM herunterladen - file://c:\program files (x86)\Free Download Manager\dlall.htm
IE: An OneNote s&enden - c:\progra~1\MICROS~4\Office14\ONBttnIE.dll/105
IE: Auswahl mit FDM herunterladen - file://c:\program files (x86)\Free Download Manager\dlselected.htm
IE: Datei mit FDM herunterladen - file://c:\program files (x86)\Free Download Manager\dllink.htm
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~4\Office14\EXCEL.EXE/3000
IE: Translate this web page with Babylon - c:\program files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
IE: Translate with Babylon - c:\program files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
IE: Videos mit FDM herunterladen - file://c:\program files (x86)\Free Download Manager\dlfvideo.htm
IE: Zu Anti-Banner hinzufügen - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\ie_banner_deny.htm
TCP: DhcpNameServer = 192.168.178.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-*LABAL* - (no file)
SafeBoot-64517561.sys
SafeBoot-80929766.sys
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\serviceIEConfig]
"ImagePath"="c:\windows\SysWOW64\ieconfig_1und1_svc.exe /startedbyscm:016FE01B-40E31F2D-serviceIEConfig"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}"=hex:51,66,7a,6c,4c,1d,38,12,26,bd,a8,
0a,e6,f4,22,0e,f1,4c,12,2a,bb,94,a4,70
"{2E250B90-0E7A-42A3-9D65-E39F9F227FA4}"=hex:51,66,7a,6c,4c,1d,38,12,fe,08,36,
2a,48,40,cd,07,e2,73,a0,df,9a,7c,3b,b0
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93,
aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83
"{B164E929-A1B6-4A06-B104-2CD0E90A88FF}"=hex:51,66,7a,6c,4c,1d,38,12,47,ea,77,
b5,84,ef,68,0f,ce,12,6f,90,ec,54,cc,eb
"{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,38,12,5b,ab,e0,
b0,13,40,37,0c,c5,34,01,f3,05,d0,46,eb
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
"{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}"=hex:51,66,7a,6c,4c,1d,38,12,b0,b9,4d,
f6,7d,c9,e9,34,32,65,fa,b1,a8,8e,f9,ca
"{9E6D0D23-3D72-4A94-AE1F-2D167624E3D9}"=hex:51,66,7a,6c,4c,1d,38,12,1e,23,4f,
b7,75,5e,cb,37,82,24,5f,7b,46,57,96,f5
"{73455575-E40C-433C-9784-C78DC7761455}"=hex:51,66,7a,6c,4c,1d,38,12,48,7b,67,
5a,0b,87,63,3e,bb,bf,b5,e0,f7,05,61,79
"{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}"=hex:51,66,7a,6c,4c,1d,38,12,4e,e2,46,
7c,a0,8c,e0,31,bd,b1,2e,9a,cb,cc,8a,63
"{310CA7B9-D56B-499A-B786-D9648270585E}"=hex:51,66,7a,6c,4c,1d,38,12,84,89,2e,
18,6c,b6,c5,34,9b,bd,ab,09,b2,03,2d,72
"{D48FF4B4-E68F-47D1-8E25-81A0F0EEB341}"=hex:51,66,7a,6c,4c,1d,38,12,da,f7,9c,
d0,bd,a8,bf,02,f1,33,c2,e0,f5,b0,f7,55
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:06,6f,ba,aa,3b,26,cd,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d2,61,0f,cf,c8,1d,f5,4b,98,9d,b7,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d2,61,0f,cf,c8,1d,f5,4b,98,9d,b7,\
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.032"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abr\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.abr"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amr\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="VLC.amr"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.ani"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.arw"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.bay"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BMP\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.bmp"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bwf\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.bwf"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cel\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.cel"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.cr2"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.crw"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.cs1"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.cur"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.dcr"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.dcx"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.DIB\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.dib"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.djv"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.djvu"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.dng"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.emf"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.eps"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.erf"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.fff"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flc\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.flc"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fli\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.fli"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.gif"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.hdr"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.icl"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.icn"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ICO\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.ico"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.iff"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.iw4"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.j2c"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.j2k"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbr\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.jbr"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JFIF\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.jfif"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.jif"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.jp2"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.jpc"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JPE\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.jpe"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JPEG\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.jpeg"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JPG\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.jpg"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.jpk"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.jpx"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kar\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.kar"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.kdc"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m15\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.m15"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1a\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.m1a"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2a\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.m2a"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m75\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.m75"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.mef"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.mos"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.mpv"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.mrw"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.nef"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nrw\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.nrw"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.orf"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbr\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.pbr"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.pct"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.pcx"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.pef"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.pic"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pics\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.pics"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.pict"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.PNG\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.png"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.psd"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.psp"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspbrush\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.pspbrush"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.pspimage"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qcp\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="VLC.qcp"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qtpf\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.qtpf"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.raf"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.ras"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.raw"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.rle"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rw2\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.rw2"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rwl\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.rwl"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sfil\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.sfil"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smf\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.smf"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smi\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.smi"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smil\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.smil"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sml\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.sml"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.sr2"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.srf"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srw\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.srw"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.swa\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.swa"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.tga"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.thm"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TIF\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.tif"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TIFF\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.tiff"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.ttc"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.ttf"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ulw\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.ulw"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v60po\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 6.v60po"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v60pp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 6.v60pp"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v60ppf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 6.v60ppf"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vfw\UserChoice]
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 5.vfw"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.wbm"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.wbmp"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.wmf"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.xif"
.
[HKEY_USERS\S-1-5-21-4063226719-3667356119-3298405193-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-4063226719-3667356119-3298405193-1001)
"Progid"="ACDSee Pro 6.xmp"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.16"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\SysWOW64\irstrtsv.exe
c:\program files (x86)\iolo\System Mechanic\LiveBoost.exe
c:\program files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
c:\program files (x86)\TOSHIBA\widimon\widimon.exe
c:\program files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2015-02-22 17:44:51 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2015-02-22 16:44
.
Vor Suchlauf: 28 Verzeichnis(se), 17.594.920.960 Bytes frei
Nach Suchlauf: 35 Verzeichnis(se), 18.894.512.128 Bytes frei
.
- - End Of File - - 68640400299BD6F49D2BFB0C855D8586
5B5E648D12FCADC244C1EC30318E1EB9 Hallo Schrauber,
die Onlinesuche ist wieder möglich.
Aber wenn ich bei einem Shop bin, kommen immer noch diese vielen Anzeigen "Top SchnAppchen" oder mitten in der Seite kleinere Anzeigen. Ich habe mal einen Rechtsklick bei beiden gemacht und "Element untersuchen" angeklickt und habe es kopiert. Code:
<div class="fo-deals-header fo-header fo-close-xyz sgsefvhuedc" data-bind="html: strings['deals_header']">Top-Schnäppchen</div> Code:
<div id="fo-right-ribbon" data-bind="css: 'ribbonContainer' + ribbonSize, style: { 'top': ribbonPosition.top + 'px', 'left' : ribbonPosition.left + 'px', 'width' : ribbonDimensions.width + 'px', 'height' : ribbonDimensions.height + 'px' }" class="ribbonContainerMedium" style="top: 144px; left: 723.5px; width: 71px; height: 243px;">
<span class="sld-nvgt fo-close-xyz ribbonWidthMedium" id="sld-next" data-bind="click: showDisplayWindow, css: 'ribbonWidth' + ribbonSize">
<!--ko text: strings['more']-->More<!--/ko-->
</span>
<div id="optout" data-bind="with: $parent" style="height: 1px;width: 260px;">
<span id="sld-container-destroy" class="sld-cross fa fa-times-circle-o" data-bind="click: hide"></span>
<!--<span id="sld-container-settings" class="sld-cog fa fa-cog" title="Settings"></span>-->
</div>
<div id="sld-slider_wrapper" class="fo-close-xyz">
<ul id="sld-image_slider" class="fo-close-xyz">
<!-- ko foreach: { data: offersModel.offers }-->
<li class="fo-close-xyz ribbonWidthMedium ribbonHeightMedium" data-bind="css: 'ribbonWidth' + $parent.ribbonSize + ' ribbonHeight' + $parent.ribbonSize, event: { click: onClick, mouseover: zoomIntoOffer, mouseleave: zoomOutOfOffer }">
<div class="fobestprice" data-bind="visible: offer.ribbon.length">
<div class="fobestpriceinner"><!--ko text: $parent.strings['deals_header2']-->Beste<!--/ko--></div>
</div>
<div class="img fo-close-xyz ribbonImageMedium" data-bind="style: {backgroundImage: 'url(\'' + offer.thumb + '\')'}, css: 'ribbonImage' + $parent.ribbonSize" style="background-image: url(hxxp://api-img.billiger.de/a/10227/268010034_L.jpg);"></div>
<div class="sld-price fo-close-xyz ribbonPriceMedium" data-bind="css: 'ribbonPrice' + $parent.ribbonSize, html : offer.price">€10.98</div>
<div id="sld-zoom-inner" data-bind="css: 'ribbonZoom' + $parent.ribbonSize, slideVisible: zoomVisible, attr: { title: offer.title }" class="ribbonZoomMedium" style="display: none;" title="EMCUR Nasendusche und Nasenspülsalz 10 Beutel (530605)Bewährtes Hausmittel: Nasendusche bei Erkältungen und HeuschnupfenEinfach und besonders effektiv: Die Nasendusche von Emcur ist bei Schnup...">
<div class="sld-corner fo-close-xyz"></div>
<div class="sld-zoom-wrapper fo-close-xyz">
<div class="fo-close-xyz">
<img data-bind="css: 'fo-offer-img', attr: { src : offer.thumb }" class="fo-offer-img" src="hxxp://api-img.billiger.de/a/10227/268010034_L.jpg">
<div class="sld-zoom-desc fo-close-xyz">
<div class="sld-zoom-price fo-close-xyz" data-bind="html: offer.price">€10.98</div>
<div class="sld-zoom-merchant-name fo-close-xyz" data-bind="html: offer.merchantText">windeln.de</div>
<div class="sld-zoom-title fo-close-xyz" data-bind="html: offer.title">EMCUR Nasendusche und Nasenspülsalz 10 Beutel (530605)Bewährtes Hausmittel: Nasendusche bei Erkältungen und HeuschnupfenEinfach und besonders effektiv: Die Nasendusche von Emcur ist bei Schnup...</div>
<div class="sld-zoom-visit fo-close-xyz" data-bind="text: $parent.strings['visit_store']">Jetzt kaufen</div>
</div>
<i id="sld-zoom-destroy" class="sld-zoom-cross fa fa-times-circle-o" data-bind="click: hideZoom"></i>
</div>
</div>
<div id="sld-zoom-out" class="fo-close-xyz"></div>
</div>
</li>
<li class="fo-close-xyz ribbonWidthMedium ribbonHeightMedium" data-bind="css: 'ribbonWidth' + $parent.ribbonSize + ' ribbonHeight' + $parent.ribbonSize, event: { click: onClick, mouseover: zoomIntoOffer, mouseleave: zoomOutOfOffer }">
<div class="fobestprice" data-bind="visible: offer.ribbon.length" style="display: none;">
<div class="fobestpriceinner"><!--ko text: $parent.strings['deals_header2']-->Beste<!--/ko--></div>
</div>
<div class="img fo-close-xyz ribbonImageMedium" data-bind="style: {backgroundImage: 'url(\'' + offer.thumb + '\')'}, css: 'ribbonImage' + $parent.ribbonSize" style="background-image: url(hxxp://i41.twenga.com/4/tp/97/85/6127168054060559785.png);"></div>
<div class="sld-price fo-close-xyz ribbonPriceMedium" data-bind="css: 'ribbonPrice' + $parent.ribbonSize, html : offer.price">€34.78</div>
<div id="sld-zoom-inner" data-bind="css: 'ribbonZoom' + $parent.ribbonSize, slideVisible: zoomVisible, attr: { title: offer.title }" class="ribbonZoomMedium" style="display: none;" title="4BB2 Little Girl Schwimmanzug UV50+Der Little Girl Schwimmanzug bietet Ihrem Kind mit UV50+ besonders hohen Schutz vor schädlichen UVA- und UVB-Strahlen, bewahrt es vor Hautausschlag und eign...">
<div class="sld-corner fo-close-xyz"></div>
<div class="sld-zoom-wrapper fo-close-xyz">
<div class="fo-close-xyz">
<img data-bind="css: 'fo-offer-img', attr: { src : offer.thumb }" class="fo-offer-img" src="hxxp://i41.twenga.com/4/tp/97/85/6127168054060559785.png">
<div class="sld-zoom-desc fo-close-xyz">
<div class="sld-zoom-price fo-close-xyz" data-bind="html: offer.price">€34.78</div>
<div class="sld-zoom-merchant-name fo-close-xyz" data-bind="html: offer.merchantText">windeln.de</div>
<div class="sld-zoom-title fo-close-xyz" data-bind="html: offer.title">4BB2 Little Girl Schwimmanzug UV50+Der Little Girl Schwimmanzug bietet Ihrem Kind mit UV50+ besonders hohen Schutz vor schädlichen UVA- und UVB-Strahlen, bewahrt es vor Hautausschlag und eign...</div>
<div class="sld-zoom-visit fo-close-xyz" data-bind="text: $parent.strings['visit_store']">Jetzt kaufen</div>
</div>
<i id="sld-zoom-destroy" class="sld-zoom-cross fa fa-times-circle-o" data-bind="click: hideZoom"></i>
</div>
</div>
<div id="sld-zoom-out" class="fo-close-xyz"></div>
</div>
</li>
<li class="fo-close-xyz ribbonWidthMedium ribbonHeightMedium" data-bind="css: 'ribbonWidth' + $parent.ribbonSize + ' ribbonHeight' + $parent.ribbonSize, event: { click: onClick, mouseover: zoomIntoOffer, mouseleave: zoomOutOfOffer }">
<div class="fobestprice" data-bind="visible: offer.ribbon.length" style="display: none;">
<div class="fobestpriceinner"><!--ko text: $parent.strings['deals_header2']-->Beste<!--/ko--></div>
</div>
<div class="img fo-close-xyz ribbonImageMedium" data-bind="style: {backgroundImage: 'url(\'' + offer.thumb + '\')'}, css: 'ribbonImage' + $parent.ribbonSize" style="background-image: url(hxxp://i41.twenga.com/4/tp/49/53/2266790068113404953.png);"></div>
<div class="sld-price fo-close-xyz ribbonPriceMedium" data-bind="css: 'ribbonPrice' + $parent.ribbonSize, html : offer.price">€61.88</div>
<div id="sld-zoom-inner" data-bind="css: 'ribbonZoom' + $parent.ribbonSize, slideVisible: zoomVisible, attr: { title: offer.title }" class="ribbonZoomMedium" style="display: none;" title="Lässig Glam Backpack ContrastAus besonders leichtem und strapazierfähigem Polyester hergestellt, bieten die Rucksäcke im geschmackvollen Freizeitlook den bewährten Komfort einer Wickeltasche">
<div class="sld-corner fo-close-xyz"></div>
<div class="sld-zoom-wrapper fo-close-xyz">
<div class="fo-close-xyz">
<img data-bind="css: 'fo-offer-img', attr: { src : offer.thumb }" class="fo-offer-img" src="hxxp://i41.twenga.com/4/tp/49/53/2266790068113404953.png">
<div class="sld-zoom-desc fo-close-xyz">
<div class="sld-zoom-price fo-close-xyz" data-bind="html: offer.price">€61.88</div>
<div class="sld-zoom-merchant-name fo-close-xyz" data-bind="html: offer.merchantText">windeln.de</div>
<div class="sld-zoom-title fo-close-xyz" data-bind="html: offer.title">Lässig Glam Backpack ContrastAus besonders leichtem und strapazierfähigem Polyester hergestellt, bieten die Rucksäcke im geschmackvollen Freizeitlook den bewährten Komfort einer Wickeltasche</div>
<div class="sld-zoom-visit fo-close-xyz" data-bind="text: $parent.strings['visit_store']">Jetzt kaufen</div>
</div>
<i id="sld-zoom-destroy" class="sld-zoom-cross fa fa-times-circle-o" data-bind="click: hideZoom"></i>
</div>
</div>
<div id="sld-zoom-out" class="fo-close-xyz"></div>
</div>
</li>
<!-- /ko -->
</ul>
</div>
<span class="sld-name ribbonWidthMedium" data-bind="css: 'ribbonWidth' + ribbonSize"><!--ko text: strings['attribution1']-->UnterstÃŒtzt von<!--/ko--><a data-bind="text: $parent.providerName, attr: { href: $parent.providerLink }" href="hxxp://www.rollaround.net">Roll Around</a></span>
<span class="sld-brought ribbonWidthMedium" data-bind="text: $parent.extraAttribution, visible: $parent.extraAttribution, css: 'ribbonWidth' + ribbonSize" style="display: none;"></span>
</div> Wie kann ich diese blöden Anzeigen wegkriegen???
Gruß
Helga
Weiterleitung auf unerwünschte Seiten ist wieder aktiv |