Combofix läuft nicht sauber durch
beim 1.Start kam Fehler beim Überschreiben der Datei
C:\32788R22FWJFW\hidec.3xe wiederholen klappte nicht
ignorieren läuft es weiter und geht irgendwann zu ohne ein log file zu erstellen..
hab gerad gesehen dass noch eine box kam:
ComboFix hat festgestellt das folgende Realtime Scanner aktiv sind : antivirus Norton 360
aber wie gesagt: der ist für mich nicht mehr bedienbar, wie kann ich den manuell beenden?
unterm Taskmanager sieht für mich nichts so recht nach Norton aus..
so aber nun ist es doch irgendwie fertig geworden
er hat noch gesagt: keine Widerherstellungspunkte gefunden, Download dafür ist gescheitert, aber er hat trotzdem weitergescannt Code:
ComboFix 13-07-04.01 - Henrik 05.07.2013 11:05:29.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.49.1031.18.2935.2395 [GMT 2:00]
ausgeführt von:: c:\dokumente und einstellungen\Henrik\Desktop\ComboFix.exe
AV: Norton 360 *Enabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *Enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
Achtung - Auf diesem PC ist keine Wiederherstellungskonsole installiert !!
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-06-05 bis 2013-07-05 ))))))))))))))))))))))))))))))
.
.
2013-07-05 08:39 . 2013-07-05 08:39 -------- d-----w- C:\FRST
2013-07-04 11:46 . 2013-07-04 11:46 -------- d-----w- c:\programme\ESET
2013-07-04 11:42 . 2013-07-04 11:42 -------- d-----w- c:\windows\ERUNT
2013-07-04 11:42 . 2013-07-04 11:42 -------- d-----w- C:\JRT
2013-06-26 14:05 . 2013-06-26 18:57 -------- d-----w- c:\programme\Mozilla Thunderbird
2013-06-11 06:26 . 2013-06-20 18:40 -------- d-----w- c:\windows\system32\drivers\N360\1404000.028
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-19 05:53 . 2012-11-29 22:03 142496 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2013-06-12 07:09 . 2012-04-01 16:01 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-12 07:09 . 2011-05-23 20:26 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-07 22:28 . 2008-04-14 12:00 920064 ----a-w- c:\windows\system32\wininet.dll
2013-05-07 22:28 . 2008-04-14 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2013-05-07 22:28 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-05-07 21:53 . 2008-04-14 12:00 385024 ----a-w- c:\windows\system32\html.iec
2013-05-03 05:39 . 2008-04-14 12:00 2152448 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-05-03 05:39 . 2008-04-14 07:30 2031104 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-04-12 14:00 . 2008-04-14 12:00 1876480 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-20 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-20 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-20 138008]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"TrueImageMonitor.exe"="c:\programme\Acronis\TrueImageHome\TrueImageMonitor.exe" [2008-10-13 4378000]
"AcronisTimounterMonitor"="c:\programme\Acronis\TrueImageHome\TimounterMonitor.exe" [2008-10-13 962480]
"Acronis Scheduler2 Service"="c:\programme\Gemeinsame Dateien\Acronis\Schedule2\schedhlp.exe" [2008-10-13 165144]
"FileZilla Server Interface"="c:\programme\FileZilla Server\FileZilla Server Interface.exe" [2009-12-30 1208832]
"SoundMAXPnP"="c:\programme\Analog Devices\Core\smax4pnp.exe" [2006-07-20 847872]
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"SunJavaUpdateSched"="c:\programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\dokumente und einstellungen\Administrator\Startmenü\Programme\Autostart\
BUFFALO NAS Navigator.lnk - c:\programme\BUFFALO\NASNAVI\NasNavi.exe /startup [2008-9-2 1549720]
NAS Scheduler.lnk - c:\programme\BUFFALO\NASNAVI\nassche.exe [2008-5-27 206128]
.
c:\dokumente und einstellungen\Henrik\Startmenü\Programme\Autostart\
BUFFALO NAS Navigator.lnk - c:\programme\BUFFALO\NASNAVI\NasNavi.exe /startup [2008-9-2 1549720]
NAS Scheduler.lnk - c:\programme\BUFFALO\NASNAVI\nassche.exe [2008-5-27 206128]
.
c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\
Office-Bibliothek-Direktsuche.lnk - c:\programme\Office-Bibliothek\PCLib.exe [2010-2-5 323584]
Windows Search.lnk - c:\programme\Windows Desktop Search\WindowsSearch.exe /startup [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programme\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programme\\Gemeinsame Dateien\\Nero\\Nero Web\\SetupX.exe"=
"d:\\Buffalo\\NASNavi2.11\\NASNavi2\\NasNavi2.exe"=
"c:\\Programme\\Messenger\\msmsgs.exe"=
"c:\\Programme\\Skype\\Phone\\Skype.exe"=
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\1404000.028\symds.sys [11.06.2013 08:27 367704]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\1404000.028\symefa.sys [11.06.2013 08:27 934488]
R0 tdrpman147;Acronis Try&Decide and Restore Points filter (build 147);c:\windows\system32\drivers\tdrpm147.sys [17.02.2009 19:11 971232]
R1 BHDrvx86;BHDrvx86;c:\dokumente und einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20130531.001\BHDrvx86.sys [31.05.2013 18:58 1002072]
R1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\N360\1404000.028\ccsetx86.sys [11.06.2013 08:27 134744]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\1404000.028\ironx86.sys [11.06.2013 08:27 175264]
R2 NasPmService;NAS PM Service;c:\programme\BUFFALO\NASNAVI\nassvc.exe -Service_Execute -dcyc=60 -dto=3 -dluc=0 -dmin=1 -dmax=60 -dflc=0 -apc=0 -log=0 -pm=1 -pall=1 -phttp=0 -pbc=0 -ppro=0 -pcyc=0 -pmin=1 -pmax=60 -pflc=0 --> c:\programme\BUFFALO\NASNAVI\nassvc.exe -Service_Execute -dcyc=60 -dto=3 -dluc=0 -dmin=1 -dmax=60 -dflc=0 -apc=0 -log=0 -pm=1 -pall=1 -phttp=0 -pbc=0 -ppro=0 -pcyc=0 -pmin=1 -pmax=60 -pflc=0 [?]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\programme\Gemeinsame Dateien\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [30.11.2012 00:08 106656]
R3 IDSxpx86;IDSxpx86;c:\dokumente und einstellungen\All Users\Anwendungsdaten\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20130619.001\IDSXpx86.sys [20.06.2013 21:09 373728]
S2 N360;Norton 360;c:\programme\Norton 360\Engine\20.4.0.40\ccsvchst.exe [11.06.2013 08:27 144368]
S2 Skype C2C Service;Skype C2C Service;c:\dokumente und einstellungen\All Users\Anwendungsdaten\Skype\Toolbars\Skype C2C Service\c2c_service.exe [02.10.2012 13:13 3064000]
S2 SkypeUpdate;Skype Updater;c:\programme\Skype\Updater\Updater.exe [03.07.2012 13:19 160944]
S3 FNETTHJM;Freecom Turbo USB 2.0;c:\windows\system32\drivers\fnetthjm.sys [26.07.2011 21:50 24448]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-06-25 13:25 1165776 ----a-w- c:\programme\Google\Chrome\Application\27.0.1453.116\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-07-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 07:10]
.
2013-07-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programme\Google\Update\GoogleUpdate.exe [2012-08-03 21:02]
.
2013-07-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programme\Google\Update\GoogleUpdate.exe [2012-08-03 21:02]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://cortalconsors.de/
uInternet Connection Wizard,ShellNext = hxxp://192.168.2.106/
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: danid.dk
Trusted Zone: danid.dk
TCP: DhcpNameServer = 192.168.13.13
FF - ProfilePath - c:\dokumente und einstellungen\Henrik\Anwendungsdaten\Mozilla\Firefox\Profiles\4rbl1w1z.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.cortalconsors.de/euroWebDe/-;jsessionid=DGbB4fkLXHhmy2jZLjbVXvCCp52G4swvLysQprT8pZkzXj8Rp2BK!-1768002477!1132780481786?&$euroWeb.em.msg=min
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
c:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Password.lnk - c:\windows\Temp\Password.exe /s /a
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2013-07-05 11:13
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\programme\Norton 360\Engine\20.4.0.40\ccSvcHst.exe\" /s \"N360\" /m \"c:\programme\Norton 360\Engine\20.4.0.40\diMaster.dll\" /prefetch:1"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IE UserData NT\RegBackup]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IE.HKCUZoneInfo\RegBackup]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IE40.UserAgent\RegBackup]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IEHomePageInfo\RegBackup]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\10.0]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\Monitors]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\services]
@DACL=(02 0000)
"NoServices"=dword:00000000
.
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\services\MediaGuide]
@DACL=(02 0000)
"FriendlyName"="Media Guide"
"ColorPlayer"="#0063B0"
"ImageLargeURL"="hxxp://images.metaservices.microsoft.com/svcswitch/WindowsMediaPlayer11_30x30.png"
"ImageMenuURL"="hxxp://images.metaservices.microsoft.com/svcswitch/wm_com_v_rgb_15x15.png"
"Task1ButtonText"="Media Guide"
"Task1ButtonTip"="Media Guide"
"Type"=dword:00000002
.
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\ShimInclusionList\FIREFOX.EXE]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Updates\Windows XP\SP0\ie7\Filelist]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•6~*]
"7040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Setup\ExceptionComponents\{077ACEC7-979C-40AB-9835-435BA1511E0D}]
@DACL=(02 0000)
"FriendlyName"="Windows Media Files"
"ComponentGUID"="{077ACEC7-979C-40AB-9835-435BA1511E0D}"
"Version"=dword:000a0000
"Sub-Version"=dword:00000e3e
"ExceptionInfName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{077ACEC7-979C-40AB-9835-435BA1511E0D}\\MPPRE10.inf"
"ExceptionCatalogName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{077ACEC7-979C-40AB-9835-435BA1511E0D}\\mppre10.cat"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Setup\ExceptionComponents\{30C7234B-6482-4A55-A11D-ECD9030313F2}]
@DACL=(02 0000)
"FriendlyName"="Windows Media Files"
"ComponentGUID"="{30C7234B-6482-4A55-A11D-ECD9030313F2}"
"Version"=dword:000a0000
"Sub-Version"=dword:00000e3e
"ExceptionInfName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{30C7234B-6482-4A55-A11D-ECD9030313F2}\\WMDM10.inf"
"ExceptionCatalogName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{30C7234B-6482-4A55-A11D-ECD9030313F2}\\wmdm10.cat"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Setup\ExceptionComponents\{981FB688-E76B-4246-987B-92083185B90A}]
@DACL=(02 0000)
"FriendlyName"="Windows Media Files"
"ComponentGUID"="{981FB688-E76B-4246-987B-92083185B90A}"
"Version"=dword:000a0000
"Sub-Version"=dword:00000e3e
"ExceptionInfName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{981FB688-E76B-4246-987B-92083185B90A}\\WPD10.inf"
"ExceptionCatalogName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{981FB688-E76B-4246-987B-92083185B90A}\\wpd10.cat"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Setup\ExceptionComponents\{A47B3654-48EE-48A5-B629-97D70175E58F}]
@DACL=(02 0000)
"FriendlyName"="Windows Media Files"
"ComponentGUID"="{A47B3654-48EE-48A5-B629-97D70175E58F}"
"Version"=dword:000a0000
"Sub-Version"=dword:00000e3e
"ExceptionInfName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{A47B3654-48EE-48A5-B629-97D70175E58F}\\codecs10.inf"
"ExceptionCatalogName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{A47B3654-48EE-48A5-B629-97D70175E58F}\\codecs10.cat"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Setup\ExceptionComponents\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}]
@DACL=(02 0000)
"FriendlyName"="Windows Media Files"
"ComponentGUID"="{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}"
"Version"=dword:000a0000
"Sub-Version"=dword:00000e3e
"ExceptionInfName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\\WMFSDK10.inf"
"ExceptionCatalogName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\\wmfsdk10.cat"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Setup\ExceptionComponents\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}]
@DACL=(02 0000)
"FriendlyName"="Windows Media Files"
"ComponentGUID"="{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}"
"Version"=dword:000a0000
"Sub-Version"=dword:00000e3e
"ExceptionInfName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\\DRM10.inf"
"ExceptionCatalogName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\\drm10.cat"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Setup\OOBE]
@DACL=(02 0000)
"RunWelcomeProcess"=dword:00000000
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\Codebases]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\Files]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\References]
@DACL=(02 0000)
"U_KB938464"=""
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.1.0.Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_ed83e624\Codebases]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.1.0.Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_ed83e624\Files]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.1.0.Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_ed83e624\References]
@DACL=(02 0000)
"U_KB938464"=""
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\CorAM.CorAM]
@DACL=(02 0000)
@="{BEC53FFD-6C80-4961-8211-E5B46887A5BD}"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB898461]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Update für Windows XP (KB898461)"
"Backup Dir"=""
"Fix Description"="Update für Windows XP (KB898461)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000003
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB923689]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB923689)"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB938127-v2-IE7]
@DACL=(02 0000)
"IE Service Pack"=dword:00000000
"Service Pack"=dword:00000014
"RemoveOnIE7Uninstall"=dword:00000001
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows Internet Explorer 7 (KB938127-v2)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows Internet Explorer 7 (KB938127-v2)"
"Installed By"=""
"Installed On"=""
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB938464]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB938464)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB938464)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB941569]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB941569)"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB946648]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB946648)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB946648)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB950762]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB950762)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB950762)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB950974]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB950974)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB950974)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB951066]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB951066)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB951066)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB951376-v2]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB951376-v2)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB951376-v2)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB951698]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB951698)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB951698)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB951748]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB951748)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB951748)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB951978]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Update für Windows XP (KB951978)"
"Backup Dir"=""
"Fix Description"="Update für Windows XP (KB951978)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB952069_WM9]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows Media Player (KB952069)"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB952287]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Hotfix für Windows XP (KB952287)"
"Backup Dir"=""
"Fix Description"="Hotfix für Windows XP (KB952287)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB952954]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB952954)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB952954)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB954211]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB954211)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB954211)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB954459]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB954459)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB954459)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB954600]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB954600)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB954600)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB955069]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB955069)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB955069)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB955839]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Update für Windows XP (KB955839)"
"Backup Dir"=""
"Fix Description"="Update für Windows XP (KB955839)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB956390-IE7]
@DACL=(02 0000)
"IE Service Pack"=dword:00000000
"Service Pack"=dword:00000014
"RemoveOnIE7Uninstall"=dword:00000001
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows Internet Explorer 7 (KB956390)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows Internet Explorer 7 (KB956390)"
"Installed By"=""
"Installed On"=""
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB956391]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB956391)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB956391)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB956802]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB956802)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB956802)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB956803]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB956803)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB956803)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB956841]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB956841)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB956841)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB957097]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB957097)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB957097)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB958215-IE7]
@DACL=(02 0000)
"IE Service Pack"=dword:00000000
"Service Pack"=dword:00000014
"RemoveOnIE7Uninstall"=dword:00000001
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows Internet Explorer 7 (KB958215)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows Internet Explorer 7 (KB958215)"
"Installed By"=""
"Installed On"=""
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB958644]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB958644)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB958644)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB958687]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB958687)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB958687)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB960714-IE7]
@DACL=(02 0000)
"IE Service Pack"=dword:00000000
"Service Pack"=dword:00000014
"RemoveOnIE7Uninstall"=dword:00000001
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows Internet Explorer 7 (KB960714)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows Internet Explorer 7 (KB960714)"
"Installed By"=""
"Installed On"=""
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB960715]
@DACL=(02 0000)
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows XP (KB960715)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows XP (KB960715)"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000004
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\HotFix\KB961260-IE7]
@DACL=(02 0000)
"IE Service Pack"=dword:00000000
"Service Pack"=dword:00000014
"RemoveOnIE7Uninstall"=dword:00000001
"Installed"=dword:00000001
"Comments"="Sicherheitsupdate für Windows Internet Explorer 7 (KB961260)"
"Backup Dir"=""
"Fix Description"="Sicherheitsupdate für Windows Internet Explorer 7 (KB961260)"
"Installed By"=""
"Installed On"=""
"Valid"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Irremote.ini]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\NetworkCards\10]
@DACL=(02 0000)
"ServiceName"="{8CB52801-E00B-4F28-86CE-90AB40CE3381}"
"Description"="Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\OpenGLDrivers]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Alaskan Standard Time\Dynamic DST]
@DACL=(02 0000)
"FirstEntry"=dword:000007d6
"LastEntry"=dword:000007d7
"2006"=hex:1c,02,00,00,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,05,00,02,00,
00,00,00,00,00,00,00,00,04,00,00,00,01,00,02,00,00,00,00,00,00,00
"2007"=hex:1c,02,00,00,00,00,00,00,c4,ff,ff,ff,00,00,0b,00,00,00,01,00,02,00,
00,00,00,00,00,00,00,00,03,00,00,00,02,00,02,00,00,00,00,00,00,00
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Arabic Standard Time\Dynamic DST]
@DACL=(02 0000)
"FirstEntry"=dword:000007d6
"LastEntry"=dword:000007d8
"2006"=hex:4c,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,01,00,04,00,
00,00,00,00,00,00,00,00,04,00,00,00,01,00,03,00,00,00,00,00,00,00
"2007"=hex:4c,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,01,00,01,00,04,00,
00,00,00,00,00,00,00,00,04,00,00,00,01,00,03,00,00,00,00,00,00,00
"2008"=hex:4c,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Argentina Standard Time]
@DACL=(02 0000)
"TZI"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Std"="Argentinien Normalzeit"
"Dlt"="Argentinien Sommerzeit"
"Display"="(GMT-03:00) Buenos Aires"
"Index"=dword:8000004c
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Armenian Standard Time]
@DACL=(02 0000)
"TZI"=hex:10,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,05,00,03,00,00,
00,00,00,00,00,00,00,03,00,00,00,05,00,02,00,00,00,00,00,00,00
"Std"="Armenische Normalzeit"
"Dlt"="Armenische Sommerzeit"
"Display"="(GMT+04:00) Eriwan"
"Index"=dword:8000004a
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Atlantic Standard Time\Dynamic DST]
@DACL=(02 0000)
"FirstEntry"=dword:000007d6
"LastEntry"=dword:000007d7
"2006"=hex:f0,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,05,00,02,00,
00,00,00,00,00,00,00,00,04,00,00,00,01,00,02,00,00,00,00,00,00,00
"2007"=hex:f0,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,0b,00,00,00,01,00,02,00,
00,00,00,00,00,00,00,00,03,00,00,00,02,00,02,00,00,00,00,00,00,00
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\AUS Eastern Standard Time\Dynamic DST]
@DACL=(02 0000)
"FirstEntry"=dword:000007d7
"LastEntry"=dword:000007d8
"2007"=hex:a8,fd,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,03,00,00,00,05,00,03,00,
00,00,00,00,00,00,00,00,0a,00,00,00,05,00,02,00,00,00,00,00,00,00
"2008"=hex:a8,fd,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,04,00,00,00,01,00,03,00,
00,00,00,00,00,00,00,00,0a,00,00,00,01,00,02,00,00,00,00,00,00,00
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Azerbaijan Standard Time]
@DACL=(02 0000)
"TZI"=hex:10,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,05,00,05,00,00,
00,00,00,00,00,00,00,03,00,00,00,05,00,04,00,00,00,00,00,00,00
"Std"="Aserbaidschan Normalzeit"
"Dlt"="Aserbaidschan Sommerzeit"
"Display"="(GMT+04:00) Baku"
"Index"=dword:80000040
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Cen. Australia Standard Time\Dynamic DST]
@DACL=(02 0000)
"FirstEntry"=dword:000007d7
"LastEntry"=dword:000007d8
"2007"=hex:c6,fd,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,03,00,00,00,05,00,03,00,
00,00,00,00,00,00,00,00,0a,00,00,00,05,00,02,00,00,00,00,00,00,00
"2008"=hex:c6,fd,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,04,00,00,00,01,00,03,00,
00,00,00,00,00,00,00,00,0a,00,00,00,01,00,02,00,00,00,00,00,00,00
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Brazilian Standard Time]
@DACL=(02 0000)
"TZI"=hex:f0,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,3b,
00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"Std"="Zentalbrasilianische Normalzeit"
"Dlt"="Zentalbrasilianische Sommerzeit"
"Display"="(GMT-04:00) Cuiaba"
"Index"=dword:80000048
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Standard Time\Dynamic DST]
@DACL=(02 0000)
"FirstEntry"=dword:000007d6
"LastEntry"=dword:000007d7
"2006"=hex:68,01,00,00,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,05,00,02,00,
00,00,00,00,00,00,00,00,04,00,00,00,01,00,02,00,00,00,00,00,00,00
"2007"=hex:68,01,00,00,00,00,00,00,c4,ff,ff,ff,00,00,0b,00,00,00,01,00,02,00,
00,00,00,00,00,00,00,00,03,00,00,00,02,00,02,00,00,00,00,00,00,00
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Standard Time (Mexico)]
@DACL=(02 0000)
"TZI"=hex:68,01,00,00,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,05,00,02,00,00,
00,00,00,00,00,00,00,04,00,00,00,01,00,02,00,00,00,00,00,00,00
"Std"="Central Normalzeit (Mexiko)"
"Dlt"="Central Sommerzeit (Mexiko)"
"Display"="(GMT-06:00) Guadalajara, Mexiko-Stadt, Monterrey - neu"
"Index"=dword:80000043
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\E. South America Standard Time\Dynamic DST]
@DACL=(02 0000)
"FirstEntry"=dword:000007d6
"LastEntry"=dword:000007f8
"2006"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,00,00,02,00,02,00,
00,00,00,00,00,00,00,00,0b,00,00,00,01,00,00,00,00,00,00,00,00,00
"2007"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,00,00,05,00,00,00,
00,00,00,00,00,00,00,00,0a,00,00,00,02,00,00,00,00,00,00,00,00,00
"2008"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,00,00,03,00,00,00,
00,00,00,00,00,00,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2009"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,02,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2010"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2011"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2012"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,04,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2013"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2014"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2015"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2016"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2017"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,02,00,17,00,3b,00,3b,00,e7,03
"2018"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2019"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2020"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2021"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2022"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2023"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,04,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,02,00,17,00,3b,00,3b,00,e7,03
"2024"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2025"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2026"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2027"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2028"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,02,00,17,00,3b,00,3b,00,e7,03
"2029"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2030"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2031"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2032"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,02,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2033"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2034"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,04,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,02,00,17,00,3b,00,3b,00,e7,03
"2035"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2036"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2037"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2038"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2039"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,04,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
"2040"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,02,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Eastern Standard Time\Dynamic DST]
@DACL=(02 0000)
"FirstEntry"=dword:000007d6
"LastEntry"=dword:000007d7
"2006"=hex:2c,01,00,00,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,05,00,02,00,
00,00,00,00,00,00,00,00,04,00,00,00,01,00,02,00,00,00,00,00,00,00
"2007"=hex:2c,01,00,00,00,00,00,00,c4,ff,ff,ff,00,00,0b,00,00,00,01,00,02,00,
00,00,00,00,00,00,00,00,03,00,00,00,02,00,02,00,00,00,00,00,00,00
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Egypt Standard Time\Dynamic DST]
@DACL=(02 0000)
"FirstEntry"=dword:000007d5
"LastEntry"=dword:000007da
"2005"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,09,00,04,00,05,00,17,00,
3b,00,3b,00,e7,03,00,00,04,00,05,00,05,00,00,00,00,00,00,00,00,00
"2006"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,09,00,04,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,04,00,05,00,05,00,00,00,00,00,00,00,00,00
"2007"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,09,00,04,00,01,00,17,00,
3b,00,3b,00,e7,03,00,00,04,00,04,00,05,00,17,00,3b,00,3b,00,e7,03
"2008"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,08,00,04,00,05,00,17,00,
3b,00,3b,00,e7,03,00,00,04,00,04,00,05,00,17,00,3b,00,3b,00,e7,03
"2009"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,08,00,04,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,04,00,04,00,04,00,17,00,3b,00,3b,00,e7,03
"2010"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,09,00,04,00,05,00,17,00,
3b,00,3b,00,e7,03,00,00,04,00,04,00,05,00,17,00,3b,00,3b,00,e7,03
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Georgian Standard Time]
@DACL=(02 0000)
"TZI"=hex:10,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Std"="Georgische Normalzeit"
"Dlt"="Georgische Sommerzeit"
"Display"="(GMT+04:00) Tiflis"
"Index"=dword:80000047
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Iran Standard Time\Dynamic DST]
@DACL=(02 0000)
"FirstEntry"=dword:000007d5
"LastEntry"=dword:000007d9
"2005"=hex:2e,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,09,00,02,00,04,00,02,00,
00,00,00,00,00,00,00,00,03,00,00,00,01,00,02,00,00,00,00,00,00,00
"2006"=hex:2e,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"2007"=hex:2e,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"2008"=hex:2e,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,09,00,06,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,03,00,04,00,03,00,17,00,3b,00,3b,00,e7,03
"2009"=hex:2e,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,09,00,01,00,03,00,17,00,
3b,00,3b,00,e7,03,00,00,03,00,06,00,03,00,17,00,3b,00,3b,00,e7,03
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Israel Standard Time\Dynamic DST]
@DACL=(02 0000)
"FirstEntry"=dword:000007d4
"LastEntry"=dword:000007e7
"2004"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"2005"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,02,00,02,00,
00,00,00,00,00,00,00,00,04,00,05,00,01,00,02,00,00,00,00,00,00,00
"2006"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,01,00,02,00,
00,00,00,00,00,00,00,00,03,00,05,00,05,00,02,00,00,00,00,00,00,00
"2007"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,09,00,00,00,03,00,02,00,
00,00,00,00,00,00,00,00,03,00,05,00,05,00,02,00,00,00,00,00,00,00
"2008"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,01,00,02,00,
00,00,00,00,00,00,00,00,03,00,05,00,05,00,02,00,00,00,00,00,00,00
"2009"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,09,00,00,00,05,00,02,00,
00,00,00,00,00,00,00,00,03,00,05,00,05,00,02,00,00,00,00,00,00,00
"2010"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,09,00,00,00,02,00,02,00,
00,00,00,00,00,00,00,00,03,00,05,00,05,00,02,00,00,00,00,00,00,00
"2011"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,01,00,02,00,
00,00,00,00,00,00,00,00,04,00,05,00,01,00,02,00,00,00,00,00,00,00
"2012"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,09,00,00,00,04,00,02,00,
00,00,00,00,00,00,00,00,03,00,05,00,05,00,02,00,00,00,00,00,00,00
"2013"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,09,00,00,00,02,00,02,00,
00,00,00,00,00,00,00,00,03,00,05,00,05,00,02,00,00,00,00,00,00,00
"2014"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,09,00,00,00,04,00,02,00,
00,00,00,00,00,00,00,00,03,00,05,00,05,00,02,00,00,00,00,00,00,00
"2015"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,09,00,00,00,03,00,02,00,
00,00,00,00,00,00,00,00,03,00,05,00,05,00,02,00,00,00,00,00,00,00
"2016"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,02,00,02,00,
00,00,00,00,00,00,00,00,04,00,05,00,01,00,02,00,00,00,00,00,00,00
"2017"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,09,00,00,00,04,00,02,00,
00,00,00,00,00,00,00,00,03,00,05,00,05,00,02,00,00,00,00,00,00,00
"2018"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,09,00,00,00,03,00,02,00,
00,00,00,00,00,00,00,00,03,00,05,00,05,00,02,00,00,00,00,00,00,00
"2019"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,01,00,02,00,
00,00,00,00,00,00,00,00,03,00,05,00,05,00,02,00,00,00,00,00,00,00
"2020"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,09,00,00,00,04,00,02,00,
00,00,00,00,00,00,00,00,03,00,05,00,05,00,02,00,00,00,00,00,00,00
"2021"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,09,00,00,00,02,00,02,00,
00,00,00,00,00,00,00,00,03,00,05,00,05,00,02,00,00,00,00,00,00,00
"2022"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,01,00,02,00,
00,00,00,00,00,00,00,00,04,00,05,00,01,00,02,00,00,00,00,00,00,00
"2023"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Jordan Standard Time]
@DACL=(02 0000)
"TZI"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,05,00,05,00,01,00,00,
00,00,00,00,00,00,00,03,00,04,00,05,00,17,00,3b,00,3b,00,e7,03
"Std"="Jordanien Normalzeit"
"Dlt"="Jordanien Sommerzeit"
"Display"="(GMT+02:00) Amman"
"Index"=dword:80000042
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Mauritius Standard Time]
@DACL=(02 0000)
"TZI"=hex:10,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Std"="Mauritius Normalzeit"
"Dlt"="Mauritius Sommerzeit"
"Display"="(GMT+04:00) Port Louis"
"Index"=dword:8000004f
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Middle East Standard Time]
@DACL=(02 0000)
"TZI"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,06,00,05,00,17,00,3b,
00,3b,00,e7,03,00,00,03,00,06,00,05,00,17,00,3b,00,3b,00,e7,03
"Std"="Mittlerer Osten Normalzeit"
"Dlt"="Mittlerer Osten Sommerzeit"
"Display"="(GMT+02:00) Beirut"
"Index"=dword:80000041
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Middle East Standard Time\Dynamic DST]
@DACL=(02 0000)
"2009"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,06,00,05,00,17,00,
3b,00,3b,00,e7,03,00,00,03,00,00,00,05,00,00,00,00,00,00,00,00,00
"2010"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,06,00,05,00,17,00,
3b,00,3b,00,e7,03,00,00,03,00,06,00,05,00,17,00,3b,00,3b,00,e7,03
"2011"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,06,00,05,00,17,00,
3b,00,3b,00,e7,03,00,00,03,00,06,00,05,00,17,00,3b,00,3b,00,e7,03
"2012"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,06,00,05,00,17,00,
3b,00,3b,00,e7,03,00,00,03,00,06,00,04,00,17,00,3b,00,3b,00,e7,03
"2013"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,06,00,05,00,17,00,
3b,00,3b,00,e7,03,00,00,03,00,06,00,05,00,17,00,3b,00,3b,00,e7,03
"2014"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,06,00,05,00,17,00,
3b,00,3b,00,e7,03,00,00,03,00,06,00,05,00,17,00,3b,00,3b,00,e7,03
"2015"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,06,00,04,00,17,00,
3b,00,3b,00,e7,03,00,00,03,00,06,00,05,00,17,00,3b,00,3b,00,e7,03
"2016"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,06,00,05,00,17,00,
3b,00,3b,00,e7,03,00,00,03,00,06,00,05,00,17,00,3b,00,3b,00,e7,03
"2017"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,06,00,05,00,17,00,
3b,00,3b,00,e7,03,00,00,03,00,06,00,05,00,17,00,3b,00,3b,00,e7,03
"2018"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,06,00,05,00,17,00,
3b,00,3b,00,e7,03,00,00,03,00,06,00,04,00,17,00,3b,00,3b,00,e7,03
"2019"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,06,00,05,00,17,00,
3b,00,3b,00,e7,03,00,00,03,00,06,00,05,00,17,00,3b,00,3b,00,e7,03
"2020"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,06,00,04,00,17,00,
3b,00,3b,00,e7,03,00,00,03,00,06,00,05,00,17,00,3b,00,3b,00,e7,03
"2021"=hex:88,ff,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,06,00,05,00,17,00,
3b,00,3b,00,e7,03,00,00,03,00,06,00,05,00,17,00,3b,00,3b,00,e7,03
"FirstEntry"=dword:000007d9
"LastEntry"=dword:000007e5
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Montevideo Standard Time]
@DACL=(02 0000)
"TZI"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,03,00,00,00,02,00,02,00,00,
00,00,00,00,00,00,00,0a,00,00,00,01,00,02,00,00,00,00,00,00,00
"Std"="Montevideo Normalzeit"
"Dlt"="Montevideo Sommerzeit"
"Display"="(GMT-03:00) Montevideo"
"Index"=dword:80000049
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Montevideo Standard Time\Dynamic DST]
@DACL=(02 0000)
"FirstEntry"=dword:000007d6
"LastEntry"=dword:000007d7
"2006"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,03,00,00,00,02,00,02,00,
00,00,00,00,00,00,00,00,09,00,00,00,02,00,02,00,00,00,00,00,00,00
"2007"=hex:b4,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,03,00,00,00,02,00,02,00,
00,00,00,00,00,00,00,00,0a,00,00,00,01,00,02,00,00,00,00,00,00,00
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Morocco Standard Time]
@DACL=(02 0000)
"TZI"=hex:00,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,08,00,06,00,01,00,17,00,3b,
00,3b,00,e7,03,00,00,05,00,06,00,01,00,17,00,3b,00,3b,00,e7,03
"Std"="Marokko Normalzeit"
"Dlt"="Marokko Sommerzeit"
"Display"="(GMT) Casablanca"
"Index"=dword:8000004d
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Mountain Standard Time\Dynamic DST]
@DACL=(02 0000)
"FirstEntry"=dword:000007d6
"LastEntry"=dword:000007d7
"2006"=hex:a4,01,00,00,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,05,00,02,00,
00,00,00,00,00,00,00,00,04,00,00,00,01,00,02,00,00,00,00,00,00,00
"2007"=hex:a4,01,00,00,00,00,00,00,c4,ff,ff,ff,00,00,0b,00,00,00,01,00,02,00,
00,00,00,00,00,00,00,00,03,00,00,00,02,00,02,00,00,00,00,00,00,00
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Mountain Standard Time (Mexico)]
@DACL=(02 0000)
"TZI"=hex:a4,01,00,00,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,05,00,02,00,00,
00,00,00,00,00,00,00,04,00,00,00,01,00,02,00,00,00,00,00,00,00
"Std"="Mountain Normalzeit (Mexiko)"
"Dlt"="Mountain Sommerzeit (Mexiko)"
"Display"="(GMT-07:00) Chihuahua, La Paz, Mazatlan - neu"
"Index"=dword:80000044
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Namibia Standard Time]
@DACL=(02 0000)
"TZI"=hex:88,ff,ff,ff,00,00,00,00,3c,00,00,00,00,00,09,00,00,00,01,00,02,00,00,
00,00,00,00,00,00,00,04,00,00,00,01,00,02,00,00,00,00,00,00,00
"Std"="Namibia Normalzeit"
"Dlt"="Namibia Sommerzeit"
"Display"="(GMT+01:00) Windhuk"
"Index"=dword:80000046
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\New Zealand Standard Time\Dynamic DST]
@DACL=(02 0000)
"FirstEntry"=dword:000007d6
"LastEntry"=dword:000007d8
"2006"=hex:30,fd,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,03,00,00,00,03,00,03,00,
00,00,00,00,00,00,00,00,0a,00,00,00,01,00,02,00,00,00,00,00,00,00
"2007"=hex:30,fd,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,03,00,00,00,03,00,03,00,
00,00,00,00,00,00,00,00,09,00,00,00,05,00,02,00,00,00,00,00,00,00
"2008"=hex:30,fd,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,04,00,00,00,01,00,03,00,
00,00,00,00,00,00,00,00,09,00,00,00,05,00,02,00,00,00,00,00,00,00
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Newfoundland Standard Time\Dynamic DST]
@DACL=(02 0000)
"FirstEntry"=dword:000007d6
"LastEntry"=dword:000007d7
"2006"=hex:d2,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,05,00,00,00,
01,00,00,00,00,00,00,00,04,00,00,00,01,00,00,00,01,00,00,00,00,00
"2007"=hex:d2,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,0b,00,00,00,01,00,00,00,
01,00,00,00,00,00,00,00,03,00,00,00,02,00,00,00,01,00,00,00,00,00
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific SA Standard Time\Dynamic DST]
@DACL=(02 0000)
"FirstEntry"=dword:000007d7
"LastEntry"=dword:000007db
"2007"=hex:f0,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,03,00,06,00,02,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,02,00,17,00,3b,00,3b,00,e7,03
"2008"=hex:f0,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,03,00,06,00,05,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,02,00,17,00,3b,00,3b,00,e7,03
"2009"=hex:f0,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,03,00,06,00,02,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,02,00,17,00,3b,00,3b,00,e7,03
"2010"=hex:f0,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,04,00,06,00,01,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,02,00,17,00,3b,00,3b,00,e7,03
"2011"=hex:f0,00,00,00,00,00,00,00,c4,ff,ff,ff,00,00,03,00,06,00,02,00,17,00,
3b,00,3b,00,e7,03,00,00,0a,00,06,00,02,00,17,00,3b,00,3b,00,e7,03
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST]
@DACL=(02 0000)
"FirstEntry"=dword:000007d6
"LastEntry"=dword:000007d7
"2006"=hex:e0,01,00,00,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,05,00,02,00,
00,00,00,00,00,00,00,00,04,00,00,00,01,00,02,00,00,00,00,00,00,00
"2007"=hex:e0,01,00,00,00,00,00,00,c4,ff,ff,ff,00,00,0b,00,00,00,01,00,02,00,
00,00,00,00,00,00,00,00,03,00,00,00,02,00,02,00,00,00,00,00,00,00
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time (Mexico)]
@DACL=(02 0000)
"TZI"=hex:e0,01,00,00,00,00,00,00,c4,ff,ff,ff,00,00,0a,00,00,00,05,00,02,00,00,
00,00,00,00,00,00,00,04,00,00,00,01,00,02,00,00,00,00,00,00,00
"Std"="Pacific Normalzeit (Mexiko)"
"Dlt"="Pacific Sommerzeit (Mexiko)"
"Display"="(GMT-08:00) Niederkalifornien"
"Index"=dword:80000045
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Pakistan Standard Time]
@DACL=(02 0000)
"TZI"=hex:d4,fe,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Std"="Pakistan Normalzeit"
"Dlt"="Pakistan Sommerzeit"
"Display"="(GMT+05:00) Islamabad, Karatschi"
"Index"=dword:8000004e
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Tasmania Standard Time\Dynamic DST]
@DACL=(02 0000)
"FirstEntry"=dword:000007d7
"LastEntry"=dword:000007d8
"2007"=hex:a8,fd,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,03,00,00,00,05,00,03,00,
00,00,00,00,00,00,00,00,0a,00,00,00,01,00,02,00,00,00,00,00,00,00
"2008"=hex:a8,fd,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,04,00,00,00,01,00,03,00,
00,00,00,00,00,00,00,00,0a,00,00,00,01,00,02,00,00,00,00,00,00,00
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\Venezuela Standard Time]
@DACL=(02 0000)
"TZI"=hex:0e,01,00,00,00,00,00,00,c4,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Std"="Venezuela Normalzeit"
"Dlt"="Venezuela Sommerzeit"
"Display"="(GMT-04:30) Caracas"
"Index"=dword:8000004b
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Australia Standard Time\Dynamic DST]
@DACL=(02 0000)
"FirstEntry"=dword:000007d5
"LastEntry"=dword:000007da
"2005"=hex:20,fe,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"2006"=hex:20,fe,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,01,00,00,00,01,00,00,00,
00,00,00,00,00,00,00,00,0c,00,00,00,01,00,02,00,00,00,00,00,00,00
"2007"=hex:20,fe,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,03,00,00,00,05,00,03,00,
00,00,00,00,00,00,00,00,0a,00,00,00,05,00,02,00,00,00,00,00,00,00
"2008"=hex:20,fe,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,03,00,00,00,05,00,03,00,
00,00,00,00,00,00,00,00,0a,00,00,00,05,00,02,00,00,00,00,00,00,00
"2009"=hex:20,fe,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,03,00,00,00,05,00,03,00,
00,00,00,00,00,00,00,00,01,00,04,00,01,00,00,00,00,00,00,00,00,00
"2010"=hex:20,fe,ff,ff,00,00,00,00,c4,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Tracing\CtlGuid]
@DACL=(02 0000)
"Guid"="d905ac1c-65e7-4242-99ea-fe66a8355df8"
"BitNames"=" DOT11_ASSOCIATE DOT11_ROAMING DOT11_1X DOT11_PNP DOT11_SCAN DOT11_RECEIVE DOT11_SEND DOT11_IOCTL DOT11_OID DOT11_MISC DOT11_UPCALL DOT11_KEYMGR DOT11_PEER DOT11_SOFTAP DOT11_PAM DOT11_REPEATER DOT11_APROUTER DOT11_WME DOT11_CONFIG DOT11_MSM DOT11_MSM_ADAPT DOT11_MSM_SCAN DOT11_MSM_CONNECT DOT11_MSM_SECURITY_PKT DOT11_NOTIFY_OBJECT"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Tracing\DiagL2SecCtlGuid]
@DACL=(02 0000)
"Guid"="2e8d9ec5-a712-48c4-8ce0-631eb0c1cd65"
"BitNames"=" SECHC_LOG_FLAG_ASSERT SECHC_LOG_FLAG_INIT SECHC_LOG_FLAG_DIAG SECHC_LOG_FLAG_ONEX_DIAG SECHC_LOG_FLAG_REPAIR SECHC_LOG_FLAG_STATE SECHC_LOG_FLAG_EXT SECHC_LOG_FLAG_EVENT_LOG SECHC_LOG_FLAG_FUNCTION SECHC_LOG_FLAG_MEMORY SECHC_LOG_FLAG_LOCKS"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Tracing\ServiceCtlGuid]
@DACL=(02 0000)
"Guid"="0c5a3172-2248-44fd-b9a6-8389cb1dc56a"
"BitNames"=" DOT11_AUTOCONF DOT11_AUTOCONF_CLIENT DOT11_AUTOCONF_UI DOT11_FATMSM DOT11_COMMON DOT11_WLANGPA DOT11_CLASS_COINSTALLER"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Tracing\WDF API DLL]
@DACL=(02 0000)
"LogSessionName"=expand:"stdout"
"Active"=dword:00000001
"ControlFlags"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Tracing\WDiagCoreCtlGuid]
@DACL=(02 0000)
"Guid"="637a0f36-dff5-4b2f-83dd-b106c1c725e2"
"BitNames"=" WD_LOG_FLAG_INIT WD_LOG_FLAG_RPC WD_LOG_FLAG_EVENT WD_LOG_FLAG_INTERFACE WD_LOG_FLAG_CONNECTION WD_LOG_FLAG_CONTROL WD_LOG_FLAG_LOCKS WD_LOG_FLAG_MEMORY WD_LOG_FLAG_REFERENCES WD_LOG_FLAG_FUNCTION_TRACE WD_LOG_FLAG_ASSERT"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Tracing\WLanDiagCtlGuid]
@DACL=(02 0000)
"Guid"="6da4ddca-0901-4bae-9ad4-7e6030bab531"
"BitNames"=" WLANHC_AUTOCONFIG WLANHC_RNWFMSM WLANHC_FATMSM WLANHC_DLLMAIN WLANHC_TEST"
.
[HKEY_LOCAL_MACHINE\software\TENCENT\PLATFORM_TYPE_LIST]
@Class="DEFAULT_CLASS"
@DACL=(02 0000)
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'explorer.exe'(2568)
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Zeit der Fertigstellung: 2013-07-05 11:15:21
ComboFix-quarantined-files.txt 2013-07-05 09:15
.
Vor Suchlauf: 8 Verzeichnis(se), 99.210.928.128 Bytes frei
Nach Suchlauf: 10 Verzeichnis(se), 99.371.225.088 Bytes frei
.
- - End Of File - - 50DAB3B17346A22CEB8A5A2A767C8DE7
72B8CE41AF0DE751C946802B3ED844B4 so nun muß ich erstmal Schluß machen hier
wünsche ein schönes Wochenende
vor Montag früh komme ich wohl nicht wieder dazu
bis dann
Gruß von miki60 |