FaceTheTrace | 05.01.2015 22:35 | Code:
.
.
((((((((((((((((((((((((((((((((((((((( Treiber/Dienste )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_IO.SYS
-------\Legacy_NPF
-------\Service_io.sys
-------\Service_NPF
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-12-05 bis 2015-01-05 ))))))))))))))))))))))))))))))
.
.
2015-01-05 15:22 . 2015-01-05 20:16 -------- d-----w- C:\FRST
2015-01-05 00:22 . 2015-01-05 00:29 -------- d-----w- C:\$AVG
2015-01-05 00:18 . 2015-01-05 00:27 -------- d-----w- c:\programdata\AVG2015
2014-12-19 11:21 . 2014-12-13 03:33 115712 ----a-w- c:\windows\system32\ieUnatt.exe
2014-12-13 23:28 . 2014-10-18 01:33 3209728 ----a-w- c:\windows\system32\mf.dll
2014-12-13 23:28 . 2014-07-07 01:40 103424 ----a-w- c:\windows\system32\mfps.dll
2014-12-13 23:28 . 2014-07-07 01:39 50176 ----a-w- c:\windows\system32\rrinstaller.exe
2014-12-13 23:28 . 2014-07-07 01:39 23040 ----a-w- c:\windows\system32\mfpmp.exe
2014-12-13 23:28 . 2014-07-07 01:37 2048 ----a-w- c:\windows\system32\mferror.dll
2014-12-13 20:47 . 2014-10-30 01:45 155136 ----a-w- c:\windows\system32\charmap.exe
2014-12-08 20:25 . 2014-12-08 20:25 208152 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-12-13 20:41 . 2012-03-29 19:01 701104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-12-13 20:41 . 2011-06-07 09:14 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-11-22 02:07 . 2014-12-13 20:48 501248 ----a-w- c:\windows\system32\vbscript.dll
2014-11-22 01:00 . 2014-12-13 20:48 1888256 ----a-w- c:\windows\system32\wininet.dll
2014-11-18 20:41 . 2014-11-18 20:41 154904 ----a-w- c:\windows\system32\drivers\avgidshx.sys
2014-11-18 13:56 . 2014-11-18 13:56 1202848 ----a-w- c:\windows\system32\FM20.DLL
2014-11-11 02:44 . 2014-12-13 20:48 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-11-11 02:44 . 2014-11-22 07:13 186880 ----a-w- c:\windows\system32\pku2u.dll
2014-11-11 02:44 . 2014-11-22 07:13 550912 ----a-w- c:\windows\system32\kerberos.dll
2014-11-08 02:45 . 2014-12-13 20:47 2048 ----a-w- c:\windows\system32\tzres.dll
2014-10-27 17:18 . 2010-03-25 17:51 60416 ----a-w- c:\windows\ALCFDRTM.VER
2014-10-25 01:32 . 2014-11-15 08:39 67584 ----a-w- c:\windows\system32\packager.dll
2014-10-18 01:33 . 2014-11-15 08:40 571904 ----a-w- c:\windows\system32\oleaut32.dll
2014-10-14 01:56 . 2014-11-15 08:39 136632 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2014-10-14 01:50 . 2014-11-15 08:39 523776 ----a-w- c:\windows\system32\termsrv.dll
2014-10-14 01:50 . 2014-11-15 08:39 2363904 ----a-w- c:\windows\system32\msi.dll
2014-10-14 01:50 . 2014-11-15 08:39 1059840 ----a-w- c:\windows\system32\lsasrv.dll
2014-10-14 01:47 . 2014-11-15 08:39 146432 ----a-w- c:\windows\system32\msaudite.dll
2014-10-14 01:46 . 2014-11-15 08:39 681984 ----a-w- c:\windows\system32\adtschema.dll
2014-10-10 14:13 . 2014-10-10 14:13 200984 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2014-10-10 00:45 . 2014-11-15 08:39 2379264 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Eintrдge & legitime Standardeintrдge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG-Secure-Search-Update_0814av"="c:\users\Aaieieno?aoi?\AppData\Roaming\Avg_Update_0814av\AVG-Secure-Search-Update_0814av.exe" [?]
"AVG-Secure-Search-Update_1114av"="c:\users\Aaieieno?aoi?\AppData\Roaming\Avg_Update_1114av\AVG-Secure-Search-Update_1114av.exe" [?]
"AVG-Secure-Search-Update_1214av"="c:\users\Aaieieno?aoi?\AppData\Roaming\Avg_Update_1214av\AVG-Secure-Search-Update_1214av.exe" [?]
"KiesPreload"="c:\program files\Samsung\Kies\Kies.exe" [2014-02-07 1564992]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmiboot"="c:\windows\cmiboot.exe" [2007-02-07 65536]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2009-06-14 307200]
"BigDog303"="c:\windows\VM303_STI.EXE" [2006-01-24 61440]
"VMSnap3"="c:\windows\VMSnap3.exe" [2006-07-18 49152]
"Domino"="c:\windows\Domino.exe" [2006-07-04 49152]
"SoundMan"="SOUNDMAN.EXE" [2009-04-14 604704]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-02-22 500208]
"snp2std"="c:\windows\vsnp2std.exe" [2005-10-20 339968]
"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2014-02-07 311616]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 648072]
"CanonQuickMenu"="c:\program files\Canon\Quick Menu\CNQMMAIN.EXE" [2012-04-03 1273448]
"IJNetworkScannerSelectorEX"="c:\program files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe" [2012-03-26 449168]
"AVG_UI"="c:\program files\AVG\AVG2015\avgui.exe" [2014-12-18 3667472]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2013-10-03 280576]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-3-7 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-988684571-2984960038-3111619490-1000]
"EnableNotificationsRef"=dword:00000001
.
R0 johci;JMicron 1394 Filter Driver;c:\windows\system32\DRIVERS\johci.sys [2008-10-09 15200]
R1 NtFsLdf20;NtFsLdf20; [x]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2015\avgidsagent.exe [2014-12-18 3432976]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 BthAudioHF;?????? BthAudioHF;c:\windows\system32\DRIVERS\BthAudioHF.sys [2009-12-21 43008]
R3 BthAvrcp;??????? Bluetooth AVRCP;c:\windows\system32\DRIVERS\BthAvrcp.sys [2009-08-13 22528]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-03-31 29472]
R3 CMISTOR;CMIUCR.SYS CM320/CM220 Card Reader Driver;c:\windows\system32\DRIVERS\cmiucr.SYS [2007-01-12 93056]
R3 csr_a2dp;??????? Bluetooth AV;c:\windows\system32\drivers\bthav.sys [2009-12-21 61952]
R3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 2013\DfsdkS.exe [2009-08-24 406016]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2014-01-23 88576]
R3 EWSASERV;EWSA Control Service;c:\program files\Elcomsoft Password Recovery\Elcomsoft Wireless Security Auditor\ewsaserv.exe [x]
R3 hcw99rc;Hauppauge Nova-DT IR Driver;c:\windows\System32\Drivers\hcw99rc.sys [2007-03-23 10368]
R3 hptmv;hptmv;c:\windows\system32\DRIVERS\hptmv.sys [2006-09-27 71968]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-11-22 102912]
R3 ioatdma;Intel(R) QuickData Technology device;c:\windows\System32\Drivers\qd26032.sys [2008-01-18 37504]
R3 ioatdma1;ioatdma1;c:\windows\System32\Drivers\qd16032.sys [2008-01-18 36480]
R3 iSSetup;iSSetup;c:\windows\system32\DRIVERS\iSSetup.sys [2007-06-19 75672]
R3 m5287;m5287;c:\windows\system32\DRIVERS\m5287.sys [2006-07-20 104320]
R3 m5288;m5288;c:\windows\system32\DRIVERS\m5288.sys [2006-07-19 211072]
R3 m5289;m5289;c:\windows\system32\DRIVERS\m5289.sys [2005-07-04 52480]
R3 MegaSR1;MegaSR1;c:\windows\system32\DRIVERS\MegaSR1.sys [2008-06-26 397632]
R3 MODRC;WinFast TV Dongle With Infrared Receiver;c:\windows\system32\DRIVERS\modrc.sys [2006-11-14 13056]
R3 mv61xx;mv61xx;c:\windows\system32\DRIVERS\mv61xx.sys [2007-05-25 137728]
R3 NBv834x;Killer NIC Gaming Adapter Service;c:\windows\system32\DRIVERS\nbv834x.sys [2008-10-19 104992]
R3 netr28u;RT2870 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr28u.sys [x]
R3 OverwolfUpdater;Overwolf Updater Windows SCM;c:\program files\Overwolf\OverwolfUpdater.exe [2014-12-20 997664]
R3 PciIsaSerial;PCI-ISA Communication Port;c:\windows\system32\DRIVERS\PciIsaSerial.sys [2008-12-19 65536]
R3 PciPPorts;PCI ECP Parallel Port;c:\windows\system32\DRIVERS\PciPPorts.sys [2009-07-23 82944]
R3 PciSPorts;High-Speed PCI Serial Port;c:\windows\system32\DRIVERS\PciSPorts.sys [2008-12-19 115200]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 rr172x;rr172x;c:\windows\system32\DRIVERS\rr172x.sys [2007-06-12 90400]
R3 rr2522;rr2522;c:\windows\system32\DRIVERS\rr2522.sys [2007-07-02 112160]
R3 rt70x86;Belkin Wireless G USB Network Adapter Driver for Vista;c:\windows\system32\DRIVERS\netr70.sys [2006-12-27 245248]
R3 SI3112r;SI3112r;c:\windows\system32\DRIVERS\SI3112r.sys [2007-02-01 110128]
R3 SI3114;SI3114;c:\windows\system32\DRIVERS\SI3114.sys [2006-11-10 68912]
R3 SI3124;SI3124;c:\windows\system32\DRIVERS\SI3124.sys [2006-11-02 76208]
R3 Si3124r5;Si3124r5;c:\windows\system32\DRIVERS\Si3124r5.sys [2006-09-20 207152]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2014-01-23 184192]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
R3 tsusbhub;tsusbhub; [x]
R4 CamProExpress64;CamProExpress64;c:\program files\AirLive\CamPro Express 64\CamProExpress64.exe [x]
S0 AVGIDSHX;AVGIDSHX;c:\windows\system32\DRIVERS\avgidshx.sys [2014-11-18 154904]
S0 Avglogx;AVG Logging Driver;c:\windows\system32\DRIVERS\avglogx.sys [2014-07-18 230680]
S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2014-06-18 27416]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-21 445936]
S1 Avgdiskx;AVG Disk Driver;c:\windows\system32\DRIVERS\avgdiskx.sys [2014-06-18 121624]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdriverx.sys [2014-12-08 208152]
S1 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\avgidsshimx.sys [2014-06-18 21272]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2014-08-28 192792]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2014-10-10 200984]
S2 AAV UpdateService;AAV UpdateService;c:\program files\AAVUpdateManager\aavus.exe [2008-10-24 128296]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-05-21 176128]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-04-19 294400]
S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2015\avgwdsvc.exe [2014-12-18 298080]
S2 avmike;AVM FRITZ!Fernzugang IKE Service;c:\program files\FRITZ!Fernzugang\avmike.exe [2010-03-30 254328]
S2 certsrv;AVM FRITZ!Fernzugang Cert Service;c:\program files\FRITZ!Fernzugang\certsrv.exe [2010-03-30 121720]
S2 FoxitCloudUpdateService;Foxit Cloud Safe Update Service;c:\program files\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [2014-03-25 241704]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2013-04-18 233472]
S2 HFGService;Handsfree Headset Service;c:\windows\system32\svchost.exe [2009-07-14 20992]
S2 nwtsrv;AVM FRITZ!Fernzugang Client;c:\program files\FRITZ!Fernzugang\nwtsrv.exe [2010-03-30 153464]
S2 STM Parallel Driver;STM Parallel Driver;c:\windows\system32\drivers\parstm.sys [2003-07-09 43776]
S2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2009-12-16 185640]
S3 amdiox86;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox86.sys [2010-02-18 37944]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2011-05-21 101392]
S3 NmPar;PCI Parallel Port;c:\windows\system32\DRIVERS\NmPar.sys [2010-01-19 81920]
S3 nmserial;PCI Serial Port;c:\windows\system32\DRIVERS\nmserial.sys [2012-01-12 70656]
S3 NWIM;AVM VPN Miniport;c:\windows\system32\DRIVERS\avmnwim.sys [2010-03-30 335224]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bthaudiosvc REG_MULTI_SZ HFGService
.
Inhalt des "geplante Tasks" Ordners
.
2015-01-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 20:41]
.
.
------- Zusдtzlicher Suchlauf -------
.
mStart Page = about:blank
uSearchAssistant = hxxp://www.bing.com/search?q={searchTerms}
IE: &Экспорт в Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Закачать ВСЕ при помощи Download Master
IE: Закачать при помощи Download Master
IE: Отправить изображение на &устройство Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Отправить страницу на &устройство Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Передать на удаленную закачку DM
Trusted Zone: arbeitsagentur.de\www
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Администратор\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\
.
- - - - Entfernte verwaiste Registrierungseintrдge - - - -
.
Toolbar-Locked - (no file)
HKLM-Run-APSDaemon - c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
AddRemove-ElsterFormular - c:\programdata\elsterformular\setup\uninstall.exe
AddRemove-Origin - c:\program files\Origin\OriginUninstall.exe
AddRemove-Steam - c:\program files\Steam\uninstall.exe
AddRemove-WinPcapInst - c:\program files\WinPcap\uninstall.exe
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe
AddRemove-TeamSpeak 3 Client - c:\users\Администратор\AppData\Local\TeamSpeak 3 Client\uninstall.exe
AddRemove-UnityWebPlayer - c:\users\Администратор\AppData\Local\Unity\WebPlayer\Uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\DataMngr_Toolbar]
@Denied: (2) (Administrator)
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (Administrator)
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,3b,1b,f1,06,4f,
37,c1,00,0b,0c,b1,a1,85,e9,66,64,04,8c
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,3b,1b,21,82,1e,
e2,6d,97,40,04,a6,39,dc,a9,28,9c,13,1e
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,3b,1b,6f,c2,f1,
a0,52,99,be,5b,a5,ef,4a,e0,c8,40,f3,12
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,3b,1b,71,2d,9e,
6f,f2,6b,4c,07,ae,fb,41,fc,1c,72,e5,63
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,3b,1b,54,1c,d3,
c6,72,ff,35,09,a5,76,d6,65,c0,8f,ce,b4
"{4D2D3B0F-69BE-477A-90F5-FDDB05357975}"=hex:51,66,7a,6c,4c,1d,3b,1b,1f,27,36,
50,89,32,14,0d,89,f7,b7,9b,04,7f,3f,68
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,3b,1b,ab,8b,0f,
6b,c7,8d,42,0c,af,e9,9e,9a,f0,93,6b,5e
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,3b,1b,0c,14,c4,
05,9a,b3,ed,08,bc,94,b0,17,8d,64,fb,de
"{5790335A-A3FA-414E-BC02-37EE05DDDAC6}"=hex:51,66,7a,6c,4c,1d,3b,1b,4a,2f,8b,
4a,cd,f8,20,0b,a5,00,7d,ae,04,97,9c,db
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,84,f0,9d,a1,f4,fe,26,41,91,c9,c0,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,84,f0,9d,a1,f4,fe,26,41,91,c9,c0,\
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.3G2"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.3GP"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.3G2"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.3GP"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AAC\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ADTS"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADT\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ADTS"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADTS\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ADTS"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASF"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASX"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AU"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AVI"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WindowsLive.PhotoGallery.bmp.16.4"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.brd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\eagle.exe"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.CDA"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WindowsLive.PhotoGallery.bmp.16.4"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fb2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="fb2_auto_file"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice]
@Denied: (2) (Administrator)
"Progid"="PhotoViewer.FileAssoc.Gif"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.HTM"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.HTM"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ico\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WindowsLive.PhotoGallery.ico.16.4"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="inffile"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WindowsLive.PhotoGallery.jpg.16.4"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WindowsLive.PhotoGallery.jpg.16.4"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WindowsLive.PhotoGallery.jpg.16.4"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="jpegfile"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lck\UserChoice]
@Denied: (2) (Administrator)
"Progid"="lck_auto_file"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2t\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.M2TS"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2ts\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.M2TS"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.m3u"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.M4A"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP4"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Opera.HTML"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Opera.HTML"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\wmplayer.exe"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mod\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MOV"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP3"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP3"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP4"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP4"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mts\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.M2TS"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.PNG\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WindowsLive.PhotoGallery.png.16.4"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.properties\UserChoice]
@Denied: (2) (Administrator)
"Progid"="properties_auto_file"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\Portable Photoshop CS5 Multi.exe"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\photoviewer.dll"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.settings\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\winword.exe"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AU"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sys\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\NOTEPAD.EXE"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WindowsLive.PhotoGallery.tif.16.4"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WindowsLive.PhotoGallery.tif.16.4"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ts\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.TTS"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tts\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.TTS"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.URL"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vob\UserChoice]
@Denied: (2) (Administrator)
"Progid"="VLC.vob"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WAV"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WAX"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wdp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WindowsLive.PhotoGallery.wdp.16.4"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASF"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMA"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMD"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMS"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMV"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASX"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmz\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMZ"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpl\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WPL"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WVX"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Opera.HTML"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Opera.HTML"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Opera.HTML"
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Ext\Settings]
@Denied: (2) (Administrator)
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1AB09615-17FB-A427-01A2-B62BE546BAE6}*]
"jakogebdpcfdnanhlbgo"=hex:62,61,6b,61,00,00
"iakncffpodjneoohek"=hex:6b,61,68,61,6d,66,6a,61,61,6a,65,65,64,6a,62,6d,69,66,
66,6c,69,70,00,00
"jakogebdpcfdnanhlbci"=hex:62,61,67,61,00,00
"haaniiadmjecdghm"=hex:6b,61,68,61,6d,66,65,70,6b,67,6d,66,65,68,67,6b,63,69,
6c,62,6e,61,00,00
"hagocjcbhfjomllg"=hex:61,62,68,6e,67,67,6f,65,6b,67,64,70,6e,6a,6c,63,70,68,
6c,63,61,6c,69,67,64,62,69,6c,62,6d,6c,68,65,6c,00,00
"jaboddognfmomfileicb"=hex:64,62,6c,6e,6a,6f,6c,6b,66,62,6e,61,67,65,70,61,69,
68,65,67,6c,67,65,6b,6d,67,70,62,65,70,68,64,64,61,66,64,69,68,6f,63,00,00
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{40C79638-E613-2EEE-D790-2D2CD74E5E01}*]
"haondgppagdaepaf"=hex:62,63,65,64,66,6f,70,66,65,66,67,6c,6c,6c,64,62,61,67,
6a,63,6f,6e,6e,70,6d,6c,62,6d,70,68,6f,70,6f,63,62,6f,6f,65,69,6f,6a,6d,69,\
"haondgppgbjaiebc"=hex:64,62,64,6c,6f,62,6e,63,69,62,65,6c,67,6a,66,68,6e,68,
69,61,6b,64,65,68,6e,6c,63,6b,6f,62,6c,67,69,69,62,6c,6d,62,63,61,00,6d
"iaclhddidbpgpkjiij"=hex:6a,61,6f,6a,63,62,70,62,6d,6a,6a,69,6f,61,6d,6e,68,63,
6f,68,00,fb
"hamkbdccdpfellpc"=hex:6b,61,6f,6a,62,62,6d,70,6f,6c,62,62,65,69,63,61,64,63,
69,63,67,6f,00,00
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{733BD2A7-1F77-A0DB-81E7-33B0E4CDB860}*]
"haofomdogjhoibcm"=hex:6e,62,62,69,6e,63,64,63,6c,6d,61,67,6a,62,67,62,64,6b,
61,64,62,64,64,63,6d,68,67,6e,6b,6b,64,62,6e,65,6a,6c,6c,62,69,6b,62,61,6a,\
"jaofomdogjhoibcmnboi"=hex:66,61,62,69,70,63,63,69,68,67,68,6f,00,00
"paggncpfamofmogcklmnfoaaeodobjfk"=hex:65,61,62,69,6e,63,61,66,63,69,00,6f
.
[HKEY_USERS\S-1-5-21-2940817598-1931161818-2907281725-500\Software\SecuROM\License information*]
"datasecu"=hex:0b,75,dd,31,d1,3c,42,3f,c0,05,bb,d1,d7,fe,3d,fd,d3,d8,a8,7c,16,
fe,41,59,c0,b4,22,32,a8,f8,6b,40,a2,7f,0a,7b,bd,90,77,f5,41,75,65,a5,5d,e0,\
"rkeysecu"=hex:9f,b6,9b,e5,c9,c7,00,29,e3,06,db,15,eb,ce,26,89
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1AB09615-17FB-A427-01A2-B62BE546BAE6}\InProcServer32*]
"kaenepbnnjgiafkloaikid"=hex:62,61,65,61,00,61
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{40C79638-E613-2EEE-D790-2D2CD74E5E01}\InProcServer32*]
"iaalpobgjgcpoemadf"=hex:62,63,65,64,66,6f,70,66,65,66,67,6c,6c,6c,64,62,61,67,
6a,63,6f,6e,6e,70,6d,6c,62,6d,70,68,6f,70,6f,63,62,6f,6f,65,69,6f,6a,6d,69,\
"iaalpobgjgaoifadfo"=hex:64,62,64,6c,6f,62,6e,63,69,62,65,6c,67,6a,66,68,6e,68,
69,61,6b,64,65,68,6e,6c,63,6b,6f,62,6c,67,69,69,62,6c,6d,62,63,61,00,6d
"jaallllaphfpofofchak"=hex:6a,61,6f,6a,63,62,70,62,6d,6a,6a,69,6f,61,6d,6e,68,
63,6f,68,00,fb
"iaalbnbgbicbincpig"=hex:6a,61,6f,6a,67,62,6c,6f,6d,61,6c,6e,6a,70,70,66,68,6c,
6e,68,00,fb
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(4424)
c:\program files\WIDCOMM\Bluetooth Software\btmmhook.dll
c:\program files\WIDCOMM\Bluetooth Software\btncopy.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\atieclxx.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\WIDCOMM\Bluetooth Software\btwdins.exe
c:\programdata\EPSON\EPW!3 SSRP\E_S40RP7.EXE
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\system32\drivers\WDelMgr20.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\TeamViewer\Version5\TeamViewer.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\windows\SOUNDMAN.EXE
c:\windows\CmUCReye.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Canon\Quick Menu\CNQMUPDT.EXE
c:\program files\Canon\Quick Menu\CNQMSWCS.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2015-01-05 22:11:39 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2015-01-05 21:11
.
Vor Suchlauf: 35.152.080.896 bytes free
Nach Suchlauf: 34.357.010.432 bytes free
.
- - End Of File - - 3443A26C4113C71108DE99B88828A526
A36C5E4F47E84449FF07ED3517B43A31 Ich habe die Log in zwei Teilen gepostet |