trojanveli | 11.05.2015 10:58 | FRST ADDITION Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 09-05-2015
Ran by Lehrer at 2015-05-11 22:49:37
Running from C:\Users\Lehrer\Downloads
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2258613885-470133810-18836794-500 - Administrator - Enabled) => C:\Users\Administrator
Gast (S-1-5-21-2258613885-470133810-18836794-501 - Limited - Disabled)
Lehrer (S-1-5-21-2258613885-470133810-18836794-1001 - Administrator - Enabled) => C:\Users\Lehrer
Schüler (S-1-5-21-2258613885-470133810-18836794-1002 - Limited - Enabled) => C:\Users\Schüler
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Up to date) {108DAC43-C256-20B7-BB05-914135DA5160}
AS: Microsoft Security Essentials (Enabled - Up to date) {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
10 Finger BreakOut 5.5 (HKLM\...\10 Finger BreakOut_is1) (Version: - Giletech e.K.)
7-Zip 4.65 (HKLM\...\7-Zip) (Version: - )
Adobe Flash Player 11 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 11.4.402.287 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Reader X (10.1.13) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.13 - Adobe Systems Incorporated)
AKFQuiz (HKLM\...\akfquiz) (Version: 4.4.1 - AKFoerster)
Apple Application Support (HKLM\...\{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}) (Version: 2.1.7 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Audacity 1.2.6 (HKLM\...\Audacity_is1) (Version: - )
AudioCutter Cinema (HKLM\...\AudioCutter) (Version: - )
Audiograbber 1.83 SE (HKLM\...\Audiograbber) (Version: 1.83 SE - Audiograbber)
Audiograbber MP3-Plugin (HKLM\...\Audiograbber-Lame) (Version: 1.0 - AG)
Avidemux 2.5 (HKLM\...\Avidemux 2.5) (Version: 2.5.4.6714 - )
BlueJ 3.0.3 (HKLM\...\BlueJ_is1) (Version: - La Trobe University)
Browser Manager (HKLM\...\{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}) (Version: - Bit89 Inc)
CCleaner (HKLM\...\CCleaner) (Version: 3.23 - Piriform)
CLUESOFT MATHEMATIX Version 3.1 3.1.0.0 (HKLM\...\CLUESOFT MATHEMATIX Version 3.1) (Version: 3.1.0.0 - CLUESOFT, Dipl. Ing. Hubert Hutt)
CrypTool 1.4.30 (HKLM\...\CrypTool) (Version: 1.4.30 - )
DebugMode Wink (HKLM\...\DebugMode Wink) (Version: - )
Dia (nur entfernen) (HKLM\...\Dia) (Version: - )
diashapes (HKLM\...\diashapes) (Version: 0.2.2 - Steffen Macke)
DigitalSimulatorV5.57 (remove only) (HKLM\...\DigitalSimulatorV5.57) (Version: - )
DivX-Setup (HKLM\...\DivX Setup) (Version: 2.6.1.9 - DivX, LLC)
DKS Drive 5.2.503 (HKLM\...\DKS Drive) (Version: 5.2.503 - Dr. Kaiser Systemhaus GmbH)
Eraser 6.0.7.1893 (HKLM\...\{38BA2875-D7AD-4611-ABA3-C385051ADF42}) (Version: 6.7.1893 - The Eraser Project)
Express Burn Disc Burning Software (HKLM\...\ExpressBurn) (Version: - NCH Software)
Express Rip (HKLM\...\ExpressRip) (Version: - NCH Software)
Express Zip (HKLM\...\ExpressZip) (Version: - NCH Software)
FLF Services Periodensystem 1.2 (HKLM\...\FLF Services Periodensystem_is1) (Version: - )
Formelsammlung 1.1.1 (HKLM\...\{867B27ED-FA50-4446-82B7-5EB081233A23}) (Version: 1.1.1 - Frank Grießbaum)
Forte Free 2.0 (HKLM\...\Forte Free) (Version: 2.0 - Lugert Verlag)
FoxTab FLV Player (HKU\S-1-5-21-2258613885-470133810-18836794-1001\...\FoxTab FLV Player) (Version: - ) <==== ATTENTION
FreeMind (HKLM\...\B991B020-2968-11D8-AF23-444553540000_is1) (Version: 0.9.0 - )
GaitoBot AIML Editor (HKU\S-1-5-21-2258613885-470133810-18836794-1001\...\a7c51ecaabc70bd0) (Version: 2.1.0.7 - Springwald Software GmbH)
GeoGebra (HKLM\...\GeoGebra) (Version: 3.2.45.0 - International GeoGebra Institute)
GEONExT 1.73 (HKLM\...\GEONExT_is1) (Version: 1.73 - GEONExT Group)
GIMP 2.6.11 (HKLM\...\WinGimp-2.0_is1) (Version: 2.6.11 - The GIMP Team)
GlassFish Server Open Source Edition 3.1.1 (HKLM\...\nbi-glassfish-mod-3.1.1.12.0) (Version: - )
Google Earth (HKLM\...\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}) (Version: 6.1.0.5001 - Google)
Google Update Helper (Version: 1.3.21.123 - Google Inc.) Hidden
Gpg4win (2.0.4) (HKLM\...\GPG4Win) (Version: 2.0.4 - The Gpg4win Project)
HotPotatoes v 6.3.0.4 (HKLM\...\hotpot_is1) (Version: - HalfBaked)
HP Connection Manager (HKLM\...\{2B2E5A81-C31B-40AD-B3C6-C08C85755A14}) (Version: 4.3.7.1 - Hewlett-Packard Company)
HP ESU for Microsoft Windows 7 (HKLM\...\{6357258D-2BF9-49E7-A9EF-0C609D52C46D}) (Version: 2.0.6.1 - Hewlett-Packard Company)
HP HotKey Support (HKLM\...\{91265FED-244B-4DAF-A8E5-EA386209169C}) (Version: 4.0.20.1 - Hewlett-Packard Company)
HP Power Assistant (HKLM\...\{682FBA83-2CCA-4CFA-A08A-6767DAB2FC9C}) (Version: 2.5.0.16 - Hewlett-Packard Company)
HP SoftPaq Download Manager (HKLM\...\{FE465061-894A-4023-8580-56FCDD4F23F9}) (Version: 3.4.4.0 - Hewlett-Packard Company)
Inkscape 0.48.2 (HKLM\...\Inkscape) (Version: 0.48.2 - )
Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 17.2 - Intel)
IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.30 - Irfan Skiljan)
Java(TM) 6 Update 29 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83216029FF}) (Version: 6.0.290 - Oracle)
Java(TM) 7 Update 1 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217001FF}) (Version: 7.0.10 - Oracle)
Java(TM) SE Development Kit 7 Update 1 (HKLM\...\{32A3A4F4-B792-11D6-A78A-00B0D0170010}) (Version: 1.7.0.10 - Oracle)
JMicron 1394 Filter Driver (HKLM\...\{13C96625-28E4-4c58-ADE0-CDAFC64752EB}) (Version: 1.00.23.01 - JMicron Technology Corp.)
JMicron Flash Media Controller Driver (HKLM\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.0.68.0 - JMicron Technology Corp.)
Karsten Bilderschau 3.5.2 (HKLM\...\Karsten Bilderschau_is1) (Version: 3.5.2 - Karsten SlideShow Project)
LADSPA_plugins-win-0.4.15 (HKLM\...\LADSPA_plugins-win_is1) (Version: - Audacity Team)
LAME v3.98.3 for Audacity (HKLM\...\LAME for Audacity_is1) (Version: - )
LibreOffice 3.4 (HKLM\...\{7821C7B2-7E21-4CF3-925B-58B6A8BC6311}) (Version: 3.4.302 - LibreOffice)
LibreOffice 3.4 Help Pack (German) (HKLM\...\{26A10CD9-E281-4F3F-850E-F41D144B97C6}) (Version: 3.4.302 - LibreOffice)
LingoPad 2.6 Beta (Build 360) (HKLM\...\LingoPad_is1) (Version: 2.6 - Lingo4you)
LMMS 0.4.12 (HKLM\...\lmms) (Version: 0.4.12 - LMMS Developers)
Look@LAN 2.50 Build 35 (HKLM\...\Look@LAN_1.0) (Version: - )
MAGIX Foto Clinic 5.0 (D) (HKLM\...\MAGIX Foto Clinic 5.0 D) (Version: 5.0.18.0 - MAGIX AG)
MAGIX Music Maker Schulversion (D) (HKLM\...\MAGIX Music Maker Schulversion D) (Version: 11.0.1.3 - MAGIX AG)
MAGIX Music Studio Schulversion (D) (HKLM\...\MAGIX Music Studio Schulversion D) (Version: 1.0.1.0 - MAGIX AG)
MAGIX Video deluxe Schulversion (D) (HKLM\...\MAGIX Video deluxe Schulversion D) (Version: 5.5.3.3 - MAGIX AG)
Marble (remove only) (HKLM\...\Marble) (Version: - )
Maxima 5.25.0 (HKLM\...\Maxima-5.25.0_is1) (Version: 5.25.0 - The Maxima Development Team)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Mathematics (HKLM\...\{4D090F70-6F08-4B60-9357-A1DFD4458F09}) (Version: 4.0 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 2.1.1116.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.1.10329.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
MIDIView 1.1 DEMO (HKLM\...\MIDIView 1.1 DEMO) (Version: 1.1 - Loopsoft)
MixPad Audio Mixer (HKLM\...\MixPad) (Version: - NCH Software)
Mozilla Firefox 16.0 (x86 de) (HKLM\...\Mozilla Firefox 16.0 (x86 de)) (Version: 16.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 16.0 - Mozilla)
Mozilla Thunderbird (8.0) (HKLM\...\Mozilla Thunderbird (8.0)) (Version: 8.0 (de) - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero BurnLite 10 (HKLM\...\{842BEE12-CCCB-43F4-ABAF-CBA6DFE2583D}) (Version: 10.0.10500 - Nero AG)
Nero BurnLite 10 (HKLM\...\{AB627AF2-9C7E-4DBD-816B-3B2646B81E89}) (Version: 10.0.10100.1.100 - Nero AG)
Nero Update (HKLM\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.0018 - Nero AG)
NetBeans IDE 7.0.1 (HKLM\...\nbi-nb-base-7.0.1.0.0) (Version: 7.0.1 - NetBeans.org)
NetDrive (HKLM\...\NetDrive) (Version: 1.2.0.3 - MacroData Inc.)
Network Notepad 4.6.8 (HKLM\...\Netnotep_is1) (Version: - Jason Green)
Notepad++ (HKLM\...\Notepad++) (Version: 5.8.4 - )
Nvu 1.0 (HKLM\...\Nvu_is1) (Version: 1.0 - Thorsten Fritz)
Open Workbench (HKLM\...\{1E9A9E08-0366-45EE-9B66-51852F8D9812}) (Version: 1.1.6 - CA)
OpenProj (HKLM\...\{13702021-43FB-480C-912F-D9B74A538288}) (Version: 1.4.0 - Serena Software Inc.)
PDF24 Creator 3.5.3 (HKLM\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.3 - Frank Heindörfer, Philip Chinery)
PDFTK Builder 3.5.3 (HKLM\...\PDFTK Builder_is1) (Version: - )
Phase 5 HTML-Editor (HKLM\...\{20B1B020-DEAE-48D1-9960-D4C3185D758B}) (Version: 5.6.2.3 - Systemberatung Schommer)
PhotoFiltre (HKU\S-1-5-21-2258613885-470133810-18836794-1001\...\PhotoFiltre) (Version: - )
Pointofix (HKLM\...\Pointofix_is1) (Version: - Amerigomedia)
PuTTY version 0.61 (HKLM\...\PuTTY_is1) (Version: 0.61 - Simon Tatham)
QuickTime (HKLM\...\{0E64B098-8018-4256-BA23-C316A43AD9B0}) (Version: 7.72.80.56 - Apple Inc.)
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM\...\RealPlayer 15.0) (Version: - RealNetworks)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
Renesas Electronics USB 3.0 Host Controller Driver (HKLM\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden
Scribus 1.3.3.14 (HKLM\...\Scribus 1.3.3.14) (Version: 1.3.3.14 - The Scribus Team)
SDK (Version: 2.30.042 - Portrait Displays, Inc.) Hidden
Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
Stellarium 0.10.6.1 (HKLM\...\Stellarium_is1) (Version: - )
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.0.3.0 - Synaptics Incorporated)
Task Coach 1.2.30 (HKLM\...\Task Coach_is1) (Version: - Frank Niessink and Jerome Laheurte)
Teachmaster 4.3 (nur Entfernen) (HKLM\...\Teachmaster 4.3) (Version: - )
Tinypic 3.18 (HKLM\...\{E3723A04-A894-4036-A78E-282E18F43C0A}_is1) (Version: Tinypic 3.18 - E. Fiedler)
TIPP10 Version 2.1.0 (HKLM\...\TIPP10_is1) (Version: - (c) 2006-2011, Tom Thielicke IT Solutions)
TrueCrypt (HKLM\...\TrueCrypt) (Version: 7.1a - TrueCrypt Foundation)
tulox (Demoversion) (HKLM\...\tulox-Demo) (Version: - )
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden
VirtualCloneDrive (HKLM\...\VirtualCloneDrive) (Version: - Elaborate Bytes)
VLC media player 2.0.2 (HKLM\...\VLC media player) (Version: 2.0.2 - VideoLAN)
VST Bridge 1.1 (HKLM\...\VST Bridge_is1) (Version: - )
WavePad Sound Editor (HKLM\...\WavePad) (Version: - NCH Software)
WinHTTrack Website Copier 3.46-1 (HKLM\...\WinHTTrack Website Copier_is1) (Version: 3.46.1 - HTTrack)
WinSCP 4.3.5 (HKLM\...\winscp3_is1) (Version: 4.3.5 - Martin Prikryl)
XMedia Recode Version 3.1.2.8 (HKLM\...\{DDA3C325-47B2-4730-9672-BF3771C08799}_is1) (Version: 3.1.2.8 - XMedia Recode)
yEd Graph Editor 3.6 (HKLM\...\yEd Graph Editor 3.6) (Version: - yWorks GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
14-10-2013 21:12:13 Geplanter Prüfpunkt
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2015-05-09 01:33 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {1F7EBB5C-97FF-448D-BB1A-B012E9687AC6} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-05-11] (Adobe Systems Incorporated)
Task: {66A8107B-8D15-471F-93E6-66E1ACD55A44} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-09-24] (Piriform Ltd)
Task: {6A42010B-CE30-45F0-A6CD-E31872A620BC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-12-11] (Google Inc.)
Task: {9C7FF38A-7657-4D6F-844A-A9BF76115A5A} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2258613885-470133810-18836794-500 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2011-11-08] (RealNetworks, Inc.)
Task: {BEDAD3FA-9BB4-46EC-880D-39AB8F0E715A} - System32\Tasks\Microsoft\Microsoft Antimalware\MpIdleTask => C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27] (Microsoft Corporation)
Task: {C4F5D1C6-5BE8-4205-A1BD-AB1D592A02F9} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2258613885-470133810-18836794-500 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2011-11-08] (RealNetworks, Inc.)
Task: {C87113BE-B415-45E1-924A-ED40E945C315} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-12-11] (Google Inc.)
Task: {D07F574B-F925-406B-8DD5-FB2C179D6346} - System32\Tasks\ReclaimerUpdateFiles_Administrator => C:\Users\Administrator\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe [2012-10-09] (RealNetworks, Inc.)
Task: {D64028EE-3AE2-4C66-B75D-5FEB4F046043} - System32\Tasks\Browser Manager => Sc.exe start Browser Manager
Task: {EC8961BE-B311-47EB-8E07-9B676AEA7BC5} - System32\Tasks\Microsoft\Microsoft Antimalware\MP Scheduled Scan => C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27] (Microsoft Corporation)
Task: {F30449F8-362D-4B1D-A208-4D77F918292B} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {FD721CF1-C6CF-437C-AFDF-2AF9FBC2A0BB} - System32\Tasks\ReclaimerUpdateXML_Administrator => C:\Users\Administrator\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe [2012-10-09] (RealNetworks, Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\ReclaimerUpdateFiles_Administrator.job => C:\Users\Administrator\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe
Task: C:\Windows\Tasks\ReclaimerUpdateXML_Administrator.job => C:\Users\Administrator\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe
==================== Loaded Modules (whitelisted) ==============
2015-05-09 01:50 - 2001-10-28 18:42 - 00116224 _____ () C:\Windows\System32\pdfcmnnt.dll
2009-02-12 10:53 - 2009-02-12 10:53 - 00040448 _____ () C:\Program Files\MacroData Inc\NetDrive\ws_ext.dll
2015-05-09 01:56 - 2008-10-31 13:06 - 00096744 _____ () C:\Windows\system32\DKSIO.DLL
2011-07-29 01:08 - 2011-07-29 01:08 - 01259376 _____ () C:\Program Files\DivX\DivX Update\DivXUpdate.exe
2011-07-29 01:09 - 2011-07-29 01:09 - 00096112 _____ () C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
2012-03-14 14:29 - 2012-03-14 14:29 - 00892288 _____ () C:\Program Files\Hewlett-Packard\HP Power Assistant\System.Data.SQLite.dll
2012-10-10 21:18 - 2012-10-06 04:14 - 02294240 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2011-04-08 09:57 - 2011-04-08 09:57 - 00514570 _____ () C:\Program Files\Hewlett-Packard\HP Connection Manager\sqlite3.dll
2015-05-11 22:38 - 2015-05-11 22:39 - 00050477 _____ () C:\Users\Lehrer\Downloads\Defogger.exe
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Windows\system32\Drivers\gamplgqc.sys:changelist
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, the associated entry will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2258613885-470133810-18836794-1001\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 10.16.1.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\Services: Browser Manager => 2
MSCONFIG\Services: DirMngr => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: NAUpdate => 2
MSCONFIG\startupreg: Eraser => "C:\PROGRA~1\Eraser\Eraser.exe" --atRestart
==================== FirewallRules (whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{FB6F66E1-5498-4E79-8A63-9863AF862F30}] => (Allow) C:\Program Files\MacroData Inc\NetDrive\ndsvc.exe
FirewallRules: [{E9A13BDD-A5CC-4F72-876A-DB5B29B78F46}] => (Allow) C:\Program Files\MacroData Inc\NetDrive\ndsvc.exe
FirewallRules: [{B47F4EDB-0B85-48D4-9DEA-6F9F318B11A6}] => (Allow) C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{A5D70BC6-25EB-4210-9F0F-52A945852D6F}] => (Allow) C:\Program Files\MacroData Inc\NetDrive\ndsvc.exe
FirewallRules: [{1B8B9A3A-8999-48ED-BED2-F2AB1BF924AE}] => (Allow) C:\Program Files\MacroData Inc\NetDrive\ndsvc.exe
==================== Faulty Device Manager Devices =============
Name: MpKsl16967879
Description: MpKsl16967879
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: MpKsl16967879
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: Netzwerkcontroller
Description: Netzwerkcontroller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: MpKsla9af48ab
Description: MpKsla9af48ab
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: MpKsla9af48ab
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: USB (Universal Serial Bus)-Controller
Description: USB (Universal Serial Bus)-Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (05/11/2015 10:15:42 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/13/2014 11:45:48 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/13/2014 11:41:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/12/2013 05:47:40 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: DivXSetup.exe, Version: 2.6.1.87, Zeitstempel: 0x52438d09
Name des fehlerhaften Moduls: DivXSetup.exe, Version: 2.6.1.87, Zeitstempel: 0x52438d09
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00064795
ID des fehlerhaften Prozesses: 0xab8
Startzeit der fehlerhaften Anwendung: 0xDivXSetup.exe0
Pfad der fehlerhaften Anwendung: DivXSetup.exe1
Pfad des fehlerhaften Moduls: DivXSetup.exe2
Berichtskennung: DivXSetup.exe3
Error: (12/12/2013 05:36:47 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/12/2013 05:32:05 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/12/2013 05:28:56 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/12/2013 05:16:15 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (11/21/2013 07:39:46 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/30/2013 11:21:16 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (05/11/2015 10:36:07 PM) (Source: Microsoft Antimalware) (EventID: 1119) (User: )
Description: Kritischer Fehler in %TrojanDropper:Win32/Rotbrow.B60 beim Ergreifen von Maßnahmen gegen Malware oder andere möglicherweise unerwünschte Software.
Im Folgenden finden Sie weitere Informationen:
%TrojanDropper:Win32/Rotbrow.B603
Name: TrojanDropper:Win32/Rotbrow.B
ID: 2147683860
Schweregrad: %TrojanDropper:Win32/Rotbrow.B600
Kategorie: %TrojanDropper:Win32/Rotbrow.B602
Pfad: 3.0.8402.02
Erkennungsursprung: 3.0.8402.04
Erkennungstyp: 3.0.8402.08
Erkennungsquelle: %TrojanDropper:Win32/Rotbrow.B608
Benutzer: {396ABA97-4F52-423C-AF62-045B32F7CBEF}9
Prozessname: %TrojanDropper:Win32/Rotbrow.B609
Aktion: {396ABA97-4F52-423C-AF62-045B32F7CBEF}1
Aktionsstatus: {396ABA97-4F52-423C-AF62-045B32F7CBEF}8
Fehlercode: {396ABA97-4F52-423C-AF62-045B32F7CBEF}3
Fehlerbeschreibung: {396ABA97-4F52-423C-AF62-045B32F7CBEF}4
Signaturversion: 2015-05-11T20:32:23.797Z1
Modulversion: 2015-05-11T20:32:23.797Z2
Error: (05/11/2015 10:36:07 PM) (Source: Microsoft Antimalware) (EventID: 1119) (User: )
Description: Kritischer Fehler in %TrojanDropper:Win32/Rotbrow.B60 beim Ergreifen von Maßnahmen gegen Malware oder andere möglicherweise unerwünschte Software.
Im Folgenden finden Sie weitere Informationen:
%TrojanDropper:Win32/Rotbrow.B603
Name: TrojanDropper:Win32/Rotbrow.B
ID: 2147683860
Schweregrad: %TrojanDropper:Win32/Rotbrow.B600
Kategorie: %TrojanDropper:Win32/Rotbrow.B602
Pfad: 3.0.8402.02
Erkennungsursprung: 3.0.8402.04
Erkennungstyp: 3.0.8402.08
Erkennungsquelle: %TrojanDropper:Win32/Rotbrow.B608
Benutzer: {396ABA97-4F52-423C-AF62-045B32F7CBEF}9
Prozessname: %TrojanDropper:Win32/Rotbrow.B609
Aktion: {396ABA97-4F52-423C-AF62-045B32F7CBEF}1
Aktionsstatus: {396ABA97-4F52-423C-AF62-045B32F7CBEF}8
Fehlercode: {396ABA97-4F52-423C-AF62-045B32F7CBEF}3
Fehlerbeschreibung: {396ABA97-4F52-423C-AF62-045B32F7CBEF}4
Signaturversion: 2015-05-11T20:32:23.797Z1
Modulversion: 2015-05-11T20:32:23.797Z2
Error: (05/11/2015 10:27:21 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Fehler in %NT-AUTORITÄT60 beim Aktualisieren von Signaturen.
Neue Signaturversion:
Vorherige Signaturversion: 1.117.824.0
Aktualisierungsquelle: %NT-AUTORITÄT59
Aktualisierungsstufe: 3.0.8402.00
Quellpfad: 3.0.8402.01
Signaturtyp: %NT-AUTORITÄT602
Aktualisierungstyp: %NT-AUTORITÄT604
Benutzer: NT-AUTORITÄT\SYSTEM
Aktuelle Modulversion: %NT-AUTORITÄT605
Vorherige Modulversion: %NT-AUTORITÄT606
Fehlercode: %NT-AUTORITÄT607
Fehlerbeschreibung: %NT-AUTORITÄT608
Error: (05/11/2015 10:15:18 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x0000006b (0x00000000, 0x00000000, 0x00000000, 0x00000000)C:\Windows\MEMORY.DMP051115-37721-01
Error: (12/12/2013 05:46:50 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Fehler in %NT-AUTORITÄT60 beim Aktualisieren von Signaturen.
Neue Signaturversion:
Vorherige Signaturversion: 1.117.824.0
Aktualisierungsquelle: %NT-AUTORITÄT59
Aktualisierungsstufe: 3.0.8402.00
Quellpfad: 3.0.8402.01
Signaturtyp: %NT-AUTORITÄT602
Aktualisierungstyp: %NT-AUTORITÄT604
Benutzer: NT-AUTORITÄT\SYSTEM
Aktuelle Modulversion: %NT-AUTORITÄT605
Vorherige Modulversion: %NT-AUTORITÄT606
Fehlercode: %NT-AUTORITÄT607
Fehlerbeschreibung: %NT-AUTORITÄT608
Error: (12/12/2013 05:36:59 AM) (Source: Microsoft Antimalware) (EventID: 3002) (User: )
Description: Fehler in %%860-Echtzeitschutzfunktion.
Funktion: %%835
Fehlercode: 0x80004005
Fehlerbeschreibung: Unbekannter Fehler
Ursache: %%842
Error: (12/12/2013 05:26:13 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Fehler in %NT-AUTORITÄT60 beim Aktualisieren von Signaturen.
Neue Signaturversion:
Vorherige Signaturversion: 1.117.824.0
Aktualisierungsquelle: %NT-AUTORITÄT51
Aktualisierungsstufe: 3.0.8402.00
Quellpfad: 3.0.8402.01
Signaturtyp: %NT-AUTORITÄT602
Aktualisierungstyp: %NT-AUTORITÄT604
Benutzer: NT-AUTORITÄT\NETZWERKDIENST
Aktuelle Modulversion: %NT-AUTORITÄT605
Vorherige Modulversion: %NT-AUTORITÄT606
Fehlercode: %NT-AUTORITÄT607
Fehlerbeschreibung: %NT-AUTORITÄT608
Error: (12/12/2013 05:26:13 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Fehler in %NT-AUTORITÄT60 beim Aktualisieren von Signaturen.
Neue Signaturversion:
Vorherige Signaturversion: 1.117.824.0
Aktualisierungsquelle: %NT-AUTORITÄT51
Aktualisierungsstufe: 3.0.8402.00
Quellpfad: 3.0.8402.01
Signaturtyp: %NT-AUTORITÄT602
Aktualisierungstyp: %NT-AUTORITÄT604
Benutzer: NT-AUTORITÄT\NETZWERKDIENST
Aktuelle Modulversion: %NT-AUTORITÄT605
Vorherige Modulversion: %NT-AUTORITÄT606
Fehlercode: %NT-AUTORITÄT607
Fehlerbeschreibung: %NT-AUTORITÄT608
Error: (12/12/2013 05:26:13 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Fehler in %NT-AUTORITÄT60 beim Aktualisieren von Signaturen.
Neue Signaturversion:
Vorherige Signaturversion: 1.117.824.0
Aktualisierungsquelle: %NT-AUTORITÄT51
Aktualisierungsstufe: 3.0.8402.00
Quellpfad: 3.0.8402.01
Signaturtyp: %NT-AUTORITÄT602
Aktualisierungstyp: %NT-AUTORITÄT604
Benutzer: NT-AUTORITÄT\NETZWERKDIENST
Aktuelle Modulversion: %NT-AUTORITÄT605
Vorherige Modulversion: %NT-AUTORITÄT606
Fehlercode: %NT-AUTORITÄT607
Fehlerbeschreibung: %NT-AUTORITÄT608
Error: (12/12/2013 05:26:13 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Fehler in %NT-AUTORITÄT60 beim Aktualisieren von Signaturen.
Neue Signaturversion:
Vorherige Signaturversion: 1.117.824.0
Aktualisierungsquelle: %NT-AUTORITÄT51
Aktualisierungsstufe: 3.0.8402.00
Quellpfad: 3.0.8402.01
Signaturtyp: %NT-AUTORITÄT602
Aktualisierungstyp: %NT-AUTORITÄT604
Benutzer: NT-AUTORITÄT\NETZWERKDIENST
Aktuelle Modulversion: %NT-AUTORITÄT605
Vorherige Modulversion: %NT-AUTORITÄT606
Fehlercode: %NT-AUTORITÄT607
Fehlerbeschreibung: %NT-AUTORITÄT608
Microsoft Office Sessions:
=========================
Error: (05/11/2015 10:15:42 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/13/2014 11:45:48 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/13/2014 11:41:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/12/2013 05:47:40 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: DivXSetup.exe2.6.1.8752438d09DivXSetup.exe2.6.1.8752438d09c000000500064795ab801cef6ebeffa443dC:\Users\ADMINI~1\AppData\Local\Temp\nswA9B8.tmp\DivXSetup.exeC:\Users\ADMINI~1\AppData\Local\Temp\nswA9B8.tmp\DivXSetup.exe25d3066f-62e0-11e3-9cfc-10604b47d704
Error: (12/12/2013 05:36:47 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/12/2013 05:32:05 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/12/2013 05:28:56 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/12/2013 05:16:15 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (11/21/2013 07:39:46 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/30/2013 11:21:16 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-3210M CPU @ 2.50GHz
Percentage of memory in use: 36%
Total physical RAM: 2954.56 MB
Available physical RAM: 1889.92 MB
Total Pagefile: 5907.41 MB
Available Pagefile: 4833.7 MB
Total Virtual: 2047.88 MB
Available Virtual: 1884.81 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:297.97 GB) (Free:273.17 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 6133041D)
Partition 1: (Active) - (Size=126 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS)
==================== End Of Log ============================ GMER LOG Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-05-11 23:27:59
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HTS723232A7A364 rev.EC2OA60W 298,09GB
Running: Gmer-19357.exe; Driver: C:\Users\Lehrer\AppData\Local\Temp\ugdyrpog.sys
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 82C4FA49 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82C894D2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
? C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2B9FC739-D048-429E-BAB3-90DACE1E7694}\MpKsl6c391601.sys Das System kann den angegebenen Pfad nicht finden.
---- User code sections - GMER 2.1 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[3184] ntdll.dll!LdrGetProcedureAddress + 26 77422239 7 Bytes JMP 65E88FA0 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3184] kernel32.dll!K32GetDeviceDriverBaseNameW + 5D 773293D6 7 Bytes JMP 660C6C90 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3184] kernel32.dll!QueryPerformanceCounter + 13 7732C435 7 Bytes JMP 660C6CB3 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3184] kernel32.dll!LoadAppInitDlls + 355 7732F4F6 7 Bytes JMP 65E8DF1A C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3184] USER32.dll!GetWindowInfo 76D44B5E 5 Bytes JMP 65FEAB54 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3184] GDI32.dll!GetViewportOrgEx + 26C 76F2884B 7 Bytes JMP 660C6C11 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Real\RealPlayer\Update\realsched.exe[3524] kernel32.dll!SetUnhandledExceptionFilter 7732F4FB 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
---- Devices - GMER 2.1 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 dksdrv2k.sys
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 dksdrv2k.sys
---- Services - GMER 2.1 ----
Service C:\ProgramData\Browser Manager\2.3.765.24\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe (*** hidden *** ) [DISABLED] Browser Manager <-- ROOTKIT !!!
Service C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2B9FC739-D048-429E-BAB3-90DACE1E7694}\MpKsl16967879.sys (*** hidden *** ) [SYSTEM] MpKsl16967879 <-- ROOTKIT !!!
Service C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2B9FC739-D048-429E-BAB3-90DACE1E7694}\MpKsla9af48ab.sys (*** hidden *** ) [SYSTEM] MpKsla9af48ab <-- ROOTKIT !!!
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData@SystemStartTime 0xE5 0xB4 0xEC 0x1F ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData@SystemLastStartTime 0x17 0xAA 0x77 0xF9 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData@CMFStartTime 0xE5 0xB4 0xEC 0x1F ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData@CMFLastStartTime 0x17 0xAA 0x77 0xF9 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData\BootLanguages@de-DE 26
Reg HKLM\SYSTEM\CurrentControlSet\Control\Lsa@LsaPid 544
Reg HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings@StringCacheGeneration 130
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{4483DAA8-51D0-45E9-AD37-93A316C96735}\Connection@Name isatap.linuxmuster.local
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters@BootId 51
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters@BaseTime 394012216
Reg HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server@InstanceID 4dc5d9a0-a3a0-41ee-87cb-9237fd5
Reg HKLM\SYSTEM\CurrentControlSet\Control\WDI\Config@ServerName \BaseNamedObjects\WDI_{7f932cef-b432-4a9d-b42f-a12d35043e24}
Reg HKLM\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WdiContextLog@FileCounter 3
Reg HKLM\SYSTEM\CurrentControlSet\services\Browser Manager
Reg HKLM\SYSTEM\CurrentControlSet\services\Browser Manager@Type 32
Reg HKLM\SYSTEM\CurrentControlSet\services\Browser Manager@Start 4
Reg HKLM\SYSTEM\CurrentControlSet\services\Browser Manager@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\services\Browser Manager@ImagePath C:\ProgramData\Browser Manager\2.3.765.24\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
Reg HKLM\SYSTEM\CurrentControlSet\services\Browser Manager@DisplayName Browser Manager
Reg HKLM\SYSTEM\CurrentControlSet\services\Browser Manager@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\services\Browser Manager@Description Your browser protector service
Reg HKLM\SYSTEM\CurrentControlSet\services\Browser Manager@FailureActions 0xFF 0xFF 0xFF 0xFF ...
Reg HKLM\SYSTEM\CurrentControlSet\services\Browser Manager
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{4483DAA8-51D0-45E9-AD37-93A316C96735}@InterfaceName isatap.linuxmuster.local
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsl16967879
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsl16967879@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsl16967879@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsl16967879@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsl16967879@ImagePath \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2B9FC739-D048-429E-BAB3-90DACE1E7694}\MpKsl16967879.sys
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsl16967879@DeviceName MpKsl16967879
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsl16967879@AllowedProcessName \Device\HarddiskVolume2\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsl16967879
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsl6c391601
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsl6c391601@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsl6c391601@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsl6c391601@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsl6c391601@ImagePath \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2B9FC739-D048-429E-BAB3-90DACE1E7694}\MpKsl6c391601.sys
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsl6c391601@DeviceName MpKsl6c391601
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsl6c391601@AllowedProcessName \Device\HarddiskVolume2\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsl6c391601
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsla9af48ab
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsla9af48ab@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsla9af48ab@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsla9af48ab@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsla9af48ab@ImagePath \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2B9FC739-D048-429E-BAB3-90DACE1E7694}\MpKsla9af48ab.sys
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsla9af48ab@DeviceName MpKsla9af48ab
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsla9af48ab@AllowedProcessName \Device\HarddiskVolume2\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
Reg HKLM\SYSTEM\CurrentControlSet\services\MpKsla9af48ab
Reg HKLM\SYSTEM\CurrentControlSet\services\rdyboost\Parameters@LastBootPlanUserTime ?Mo?, ?Okt ?14 ?13, 08:36:17???????????????????????????????????G
Reg HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Epoch@Epoch 380
Reg HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Epoch2@Epoch 117
Reg HKLM\SYSTEM\CurrentControlSet\services\SynTP\Parameters@DetectTimeMS 837
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters@DhcpNameServer 10.16.1.1
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters@DhcpDomain linuxmuster.local
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3AFD9E72-F058-40BE-AFDB-232609CD6ACD}@DhcpIPAddress 10.16.1.163
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3AFD9E72-F058-40BE-AFDB-232609CD6ACD}@Lease 3600
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3AFD9E72-F058-40BE-AFDB-232609CD6ACD}@LeaseObtainedTime 1357551770
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3AFD9E72-F058-40BE-AFDB-232609CD6ACD}@T1 1357553570
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3AFD9E72-F058-40BE-AFDB-232609CD6ACD}@T2 1357554920
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3AFD9E72-F058-40BE-AFDB-232609CD6ACD}@LeaseTerminatesTime 1357555370
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3AFD9E72-F058-40BE-AFDB-232609CD6ACD}@DhcpDefaultGateway 10.16.1.254?
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3AFD9E72-F058-40BE-AFDB-232609CD6ACD}@DhcpDomain linuxmuster.local
Reg HKLM\SYSTEM\CurrentControlSet\services\WinDefend@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\services\WinDefend
Reg HKLM\SYSTEM\ControlSet002\Control\CMF\SqmData@SystemStartTime 0xE5 0xB4 0xEC 0x1F ...
Reg HKLM\SYSTEM\ControlSet002\Control\CMF\SqmData@SystemLastStartTime 0x17 0xAA 0x77 0xF9 ...
Reg HKLM\SYSTEM\ControlSet002\Control\CMF\SqmData@CMFStartTime 0xE5 0xB4 0xEC 0x1F ...
Reg HKLM\SYSTEM\ControlSet002\Control\CMF\SqmData@CMFLastStartTime 0x17 0xAA 0x77 0xF9 ...
Reg HKLM\SYSTEM\ControlSet002\Control\CMF\SqmData\BootLanguages@de-DE 26
Reg HKLM\SYSTEM\ControlSet002\Control\Lsa@LsaPid 544
Reg HKLM\SYSTEM\ControlSet002\Control\MUI\Settings@NextSQMCollection 0x00 0x36 0xA8 0x99 ...
Reg HKLM\SYSTEM\ControlSet002\Control\Session Manager\Memory Management\PrefetchParameters@BootId 51
Reg HKLM\SYSTEM\ControlSet002\Control\Session Manager\Memory Management\PrefetchParameters@BaseTime 394012216
Reg HKLM\SYSTEM\ControlSet002\Control\Terminal Server@InstanceID 4dc5d9a0-a3a0-41ee-87cb-9237fd5
Reg HKLM\SYSTEM\ControlSet002\Control\WDI\Config@ServerName \BaseNamedObjects\WDI_{7f932cef-b432-4a9d-b42f-a12d35043e24}
Reg HKLM\SYSTEM\ControlSet002\Control\WMI\Autologger\WdiContextLog@FileCounter 3
Reg HKLM\SYSTEM\ControlSet002\services\BITS@Start 3
Reg HKLM\SYSTEM\ControlSet002\services\rdyboost\Parameters@LastBootPlanUserTime ?Mo?, ?Okt ?14 ?13, 08:28:03???????????????????????????????????
Reg HKLM\SYSTEM\ControlSet002\services\SharedAccess\Epoch@Epoch 380
Reg HKLM\SYSTEM\ControlSet002\services\SynTP\Parameters@DetectTimeMS 837
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer@GlobalAssocChangedCounter 227
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}@NoExplorer 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}@ AcroIEHelperStub
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine\Extension-List\{00000000-0000-0000-0000-000000000000}@StartTimeLo 572558575
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine\Extension-List\{00000000-0000-0000-0000-000000000000}@StartTimeHi 30329100
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine\Extension-List\{00000000-0000-0000-0000-000000000000}@EndTimeLo 572558575
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine\Extension-List\{00000000-0000-0000-0000-000000000000}@EndTimeHi 30329100
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\S-1-5-21-2258613885-470133810-18836794-1001\Extension-List\{00000000-0000-0000-0000-000000000000}@StartTimeLo 670636731
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\S-1-5-21-2258613885-470133810-18836794-1001\Extension-List\{00000000-0000-0000-0000-000000000000}@StartTimeHi 30329100
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\S-1-5-21-2258613885-470133810-18836794-1001\Extension-List\{00000000-0000-0000-0000-000000000000}@EndTimeLo 670636731
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\S-1-5-21-2258613885-470133810-18836794-1001\Extension-List\{00000000-0000-0000-0000-000000000000}@EndTimeHi 30329100
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\101E81DEBEAC18543939D4B1989AFB7C\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\101E81DEBEAC18543939D4B1989AFB7C\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\101E81DEBEAC18543939D4B1989AFB7C\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\101E81DEBEAC18543939D4B1989AFB7C\68AB67CA7DA71301B744AA0100000010@PatchSize 1630
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\101E81DEBEAC18543939D4B1989AFB7C\68AB67CA7DA71301B744AA0100000010@PatchSequence 10028
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1DE7F110AFAA90C49809BCC45C22CCB7\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1DE7F110AFAA90C49809BCC45C22CCB7\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1DE7F110AFAA90C49809BCC45C22CCB7\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1DE7F110AFAA90C49809BCC45C22CCB7\68AB67CA7DA71301B744AA0100000010@PatchSize 1832
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F0AC60FFABAA3E40AE3F14B43F9EA06\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F0AC60FFABAA3E40AE3F14B43F9EA06\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F0AC60FFABAA3E40AE3F14B43F9EA06\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F0AC60FFABAA3E40AE3F14B43F9EA06\68AB67CA7DA71301B744AA0100000010@PatchSize 180
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F0AC60FFABAA3E40AE3F14B43F9EA06\68AB67CA7DA71301B744AA0100000010@PatchSequence 10429
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\22F4DAC0B3D560C48B6ED1CFE16DED9D\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\22F4DAC0B3D560C48B6ED1CFE16DED9D\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\22F4DAC0B3D560C48B6ED1CFE16DED9D\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\22F4DAC0B3D560C48B6ED1CFE16DED9D\68AB67CA7DA71301B744AA0100000010@PatchSize 1312
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\22F4DAC0B3D560C48B6ED1CFE16DED9D\68AB67CA7DA71301B744AA0100000010@PatchSequence 10023
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E4EB1CE0F6039A47AA5D12B8FC977CA\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E4EB1CE0F6039A47AA5D12B8FC977CA\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E4EB1CE0F6039A47AA5D12B8FC977CA\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E4EB1CE0F6039A47AA5D12B8FC977CA\68AB67CA7DA71301B744AA0100000010@PatchSize 163
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E4EB1CE0F6039A47AA5D12B8FC977CA\68AB67CA7DA71301B744AA0100000010@PatchSequence 10426
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\321519DC6CD473D47B9CB9A3D015BEA9\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\321519DC6CD473D47B9CB9A3D015BEA9\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\321519DC6CD473D47B9CB9A3D015BEA9\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\321519DC6CD473D47B9CB9A3D015BEA9\68AB67CA7DA71301B744AA0100000010@PatchSize 10975
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3441BFA836FB1C34BA6C144E93FBBA96\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3441BFA836FB1C34BA6C144E93FBBA96\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3441BFA836FB1C34BA6C144E93FBBA96\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3441BFA836FB1C34BA6C144E93FBBA96\68AB67CA7DA71301B744AA0100000010@PatchSize 23545
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3684BFA619C939645B066762586740C5\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3684BFA619C939645B066762586740C5\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3684BFA619C939645B066762586740C5\68AB67CA7DA71301B744AA0100000010@ComponentVersion 1.6.5.0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3684BFA619C939645B066762586740C5\68AB67CA7DA71301B744AA0100000010@PatchSize 5273
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\438256CEC1FA32847B45768EE56D453C\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\438256CEC1FA32847B45768EE56D453C\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\438256CEC1FA32847B45768EE56D453C\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\438256CEC1FA32847B45768EE56D453C\68AB67CA7DA71301B744AA0100000010@PatchSize 2448
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\438256CEC1FA32847B45768EE56D453C\68AB67CA7DA71301B744AA0100000010@PatchSequence 10024
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\47F704F177BAC3741AAF03FF2B4BA243\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\47F704F177BAC3741AAF03FF2B4BA243\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\47F704F177BAC3741AAF03FF2B4BA243\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\47F704F177BAC3741AAF03FF2B4BA243\68AB67CA7DA71301B744AA0100000010@PatchSize 1154
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\47F704F177BAC3741AAF03FF2B4BA243\68AB67CA7DA71301B744AA0100000010@PatchSequence 10031
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4BBDDEE59EF5395479E0F98DF8FE7B4E\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4BBDDEE59EF5395479E0F98DF8FE7B4E\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4BBDDEE59EF5395479E0F98DF8FE7B4E\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4BBDDEE59EF5395479E0F98DF8FE7B4E\68AB67CA7DA71301B744AA0100000010@PatchSize 53626
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4BBDDEE59EF5395479E0F98DF8FE7B4E\68AB67CA7DA71301B744AA0100000010@PatchSequence 10034
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5B8A5F9BB528C8A41BAFB0CD822BF716\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5B8A5F9BB528C8A41BAFB0CD822BF716\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5B8A5F9BB528C8A41BAFB0CD822BF716\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5B8A5F9BB528C8A41BAFB0CD822BF716\68AB67CA7DA71301B744AA0100000010@PatchSize 1132
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5B8A5F9BB528C8A41BAFB0CD822BF716\68AB67CA7DA71301B744AA0100000010@PatchSequence 10032
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6639F7A1600D0DD43B6C80F98BA770EC\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6639F7A1600D0DD43B6C80F98BA770EC\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6639F7A1600D0DD43B6C80F98BA770EC\68AB67CA7DA71301B744AA0100000010@ComponentVersion 1.6.5.0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7A11E946102B22241B413AE2EEBAB671\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7A11E946102B22241B413AE2EEBAB671\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7A11E946102B22241B413AE2EEBAB671\68AB67CA7DA71301B744AA0100000010@ComponentVersion 2.0.0.20884
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7A11E946102B22241B413AE2EEBAB671\68AB67CA7DA71301B744AA0100000010@PatchSize 17928
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7A11E946102B22241B413AE2EEBAB671\68AB67CA7DA71301B744AA0100000010@PatchSequence 10027
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F1AE0C9111C4CA4186FF4C932C8AB0E\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F1AE0C9111C4CA4186FF4C932C8AB0E\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F1AE0C9111C4CA4186FF4C932C8AB0E\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F1AE0C9111C4CA4186FF4C932C8AB0E\68AB67CA7DA71301B744AA0100000010@PatchSize 1444
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F1AE0C9111C4CA4186FF4C932C8AB0E\68AB67CA7DA71301B744AA0100000010@PatchSequence 10019
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A1BF16734F09DF24787B7AE363E01A86\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A1BF16734F09DF24787B7AE363E01A86\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A1BF16734F09DF24787B7AE363E01A86\68AB67CA7DA71301B744AA0100000010@ComponentVersion 1.6.5.0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A1BF16734F09DF24787B7AE363E01A86\68AB67CA7DA71301B744AA0100000010@PatchSize 175962
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A7FF64D6B8004E94DA3B543C6CD60E3F\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A7FF64D6B8004E94DA3B543C6CD60E3F\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A7FF64D6B8004E94DA3B543C6CD60E3F\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A7FF64D6B8004E94DA3B543C6CD60E3F\68AB67CA7DA71301B744AA0100000010@PatchSize 256
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A7FF64D6B8004E94DA3B543C6CD60E3F\68AB67CA7DA71301B744AA0100000010@PatchSequence 10424
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE8296B487CFCD14BB402788E8177330\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE8296B487CFCD14BB402788E8177330\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE8296B487CFCD14BB402788E8177330\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE8296B487CFCD14BB402788E8177330\68AB67CA7DA71301B744AA0100000010@PatchSize 2797
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE8296B487CFCD14BB402788E8177330\68AB67CA7DA71301B744AA0100000010@PatchSequence 10431
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B31492ABDE5EA584CA42E924A1EDC230\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B31492ABDE5EA584CA42E924A1EDC230\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B31492ABDE5EA584CA42E924A1EDC230\68AB67CA7DA71301B744AA0100000010@ComponentVersion 5.8.115.1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B31492ABDE5EA584CA42E924A1EDC230\68AB67CA7DA71301B744AA0100000010@PatchSize 242597
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B31492ABDE5EA584CA42E924A1EDC230\68AB67CA7DA71301B744AA0100000010@PatchSequence 10026
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BFBC5C8C7FF632D43BEFE50028D06EFA\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BFBC5C8C7FF632D43BEFE50028D06EFA\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BFBC5C8C7FF632D43BEFE50028D06EFA\68AB67CA7DA71301B744AA0100000010@ComponentVersion 4.21.20.1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BFBC5C8C7FF632D43BEFE50028D06EFA\68AB67CA7DA71301B744AA0100000010@PatchSize 524938
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BFBC5C8C7FF632D43BEFE50028D06EFA\68AB67CA7DA71301B744AA0100000010@PatchSequence 10025
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C37BC61A283EBF941A5A3A136A36263F\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C37BC61A283EBF941A5A3A136A36263F\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C37BC61A283EBF941A5A3A136A36263F\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C37BC61A283EBF941A5A3A136A36263F\68AB67CA7DA71301B744AA0100000010@PatchSize 10975
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C3C19C1FA44616F44BB254F47F629665\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C3C19C1FA44616F44BB254F47F629665\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C3C19C1FA44616F44BB254F47F629665\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C3C19C1FA44616F44BB254F47F629665\68AB67CA7DA71301B744AA0100000010@PatchSize 1235
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C3C19C1FA44616F44BB254F47F629665\68AB67CA7DA71301B744AA0100000010@PatchSequence 10030
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CC275594575BF0943AAEA81F6079425E\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CC275594575BF0943AAEA81F6079425E\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CC275594575BF0943AAEA81F6079425E\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CC275594575BF0943AAEA81F6079425E\68AB67CA7DA71301B744AA0100000010@PatchSize 1142
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CC275594575BF0943AAEA81F6079425E\68AB67CA7DA71301B744AA0100000010@PatchSequence 10022
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D1D233CC1E8669F49A72D1724E931D74\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D1D233CC1E8669F49A72D1724E931D74\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D1D233CC1E8669F49A72D1724E931D74\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D1D233CC1E8669F49A72D1724E931D74\68AB67CA7DA71301B744AA0100000010@PatchSize 262
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D1D233CC1E8669F49A72D1724E931D74\68AB67CA7DA71301B744AA0100000010@PatchSequence 10425
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D37F9C8794107AE4EB7242C863E97348\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D37F9C8794107AE4EB7242C863E97348\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D37F9C8794107AE4EB7242C863E97348\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D37F9C8794107AE4EB7242C863E97348\68AB67CA7DA71301B744AA0100000010@PatchSize 8896
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D456097B77E03D44A8405F20714D2FB8\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D456097B77E03D44A8405F20714D2FB8\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D456097B77E03D44A8405F20714D2FB8\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D456097B77E03D44A8405F20714D2FB8\68AB67CA7DA71301B744AA0100000010@PatchSize 439
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D456097B77E03D44A8405F20714D2FB8\68AB67CA7DA71301B744AA0100000010@PatchSequence 10430
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DE47C49379177834F98FA76A4C043F52\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DE47C49379177834F98FA76A4C043F52\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DE47C49379177834F98FA76A4C043F52\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DE47C49379177834F98FA76A4C043F52\68AB67CA7DA71301B744AA0100000010@PatchSize 59313
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DE47C49379177834F98FA76A4C043F52\68AB67CA7DA71301B744AA0100000010@PatchSequence 10021
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E186235D2ADC66D44A682BC877BA69B8\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E186235D2ADC66D44A682BC877BA69B8\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E186235D2ADC66D44A682BC877BA69B8\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E186235D2ADC66D44A682BC877BA69B8\68AB67CA7DA71301B744AA0100000010@PatchSize 17371
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E3FC65AB64CE51E4A99DF582E4B1CEAB\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E3FC65AB64CE51E4A99DF582E4B1CEAB\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E3FC65AB64CE51E4A99DF582E4B1CEAB\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E3FC65AB64CE51E4A99DF582E4B1CEAB\68AB67CA7DA71301B744AA0100000010@PatchSize 3665082
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E3FC65AB64CE51E4A99DF582E4B1CEAB\68AB67CA7DA71301B744AA0100000010@PatchSequence 10020
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E7EA0B4E57D2DD44691EF1775E71128A\68AB67CA7DA71301B744AA0100000010@PatchGUID {AC76BA86-7AD7-0000-2550-7A8C400A1014}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E7EA0B4E57D2DD44691EF1775E71128A\68AB67CA7DA71301B744AA0100000010@MediaCabinet PCW_CAB_RDR1014
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E7EA0B4E57D2DD44691EF1775E71128A\68AB67CA7DA71301B744AA0100000010@ComponentVersion 10.1.4.38
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E7EA0B4E57D2DD44691EF1775E71128A\68AB67CA7DA71301B744AA0100000010@PatchSize 3531
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68AB67CA7DA71301B744AA0100000010\Features@ReaderProgramFiles ._FU*(*_2@0slVZ*5.z_v-]SdHa@k@=nH}PCv=bB50bJl4chS@.CFU=z7XY9b=194Dy`K@s.h4d@le2hu+bKa)B~TAV?e@vJ4`k3Eo.8@gIB294`UqSc7s%$YAa5&yAgM?kGdpAb&[n^L[M_=PwF@9LFOvMX~I',fWDK6Qbnd93&(S^FJi40(,KZgi{qb?{@xnq_5XX`_QYe0sBt??CX%pr$P[^p%Dr=J5G.3@B[o!jMLkHhkqbKRaZyJ=zmC3?7^sLfI[PPih36KA!7MB!^J,R&.xeodI0a9?*PwJ9PAh$$5JiDH@eh99k.)~2E+oT*s5KOXX(Tx@O9it$PYp0%ZSFSFJ,gF=Faq]nD[DSrp5H~36!nc@e2YLT4GPl[JdnnNi-d?AjlR&UdQ%RRn=B1Z`VZ%@3r?8ZtrD7qUN,X=YFYQ?,&G1Mb?F?s*iv+yATUy8JF$5xzgV35v-JpP%J!N@1sI*A^'am)r*NNsSI]s9u&W[h.n+@?TAAcE^xSl=6]*iWU}_4Bqf1%AM?J%@XU0gul@$1X2w5jd-GZz?h}Lfo5YWDG,R@)]PIv{8Kg?Tjg3)dqD^1GS5(b99mWRS24Xr5ybfc2Q[$K^?4u?3%1C&QK8pVC=,wIs9B+Owz0mED3_69Vg1_ap=gC,$ThH]~5vhY!D,R3LA_~Q)wC.`QfH5s^n,Q~@@GK8CTMTal(?vU`0x($69AoXY,9v9LIQrs(klmNn@%=-p6cn6lYgl75uP^qD=cUtj+4]v4i]c6?skucQ?R1YF3gM`d[C?OaVN&E}8!+o8IP}@y^P}a,0_Q]FA!pRKKOv=cNu8w$9U3=]@nB*1`sW$d_+I_q9xm5l@5fj[hX8tk)0=J[O`v^9=_qKwW[nRoe-9)'z0'GX?9nMWL]C3*w)yaokOVQZ9T-Dto=@fKY*Ha*n,@RL9M&Axn4={nnTSp[-gRtTA==]p?,NP9=-X?LDM71+@qP?h+'SxpL[nIX?V7zP?.^b^v{2x_r$GtTiU[Dl@5b.-!NAFUaJDc
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68AB67CA7DA71301B744AA0100000010\InstallProperties@DisplayVersion 10.1.4
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68AB67CA7DA71301B744AA0100000010\InstallProperties@InstallDate 20121010
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68AB67CA7DA71301B744AA0100000010\InstallProperties@EstimatedSize 189588
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68AB67CA7DA71301B744AA0100000010\InstallProperties@Version 167837700
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68AB67CA7DA71301B744AA0100000010\InstallProperties@DisplayName Adobe Reader X (10.1.4) - Deutsch
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68AB67CA7DA71301B744AA0100000010\Patches@AllPatches 68AB67CA7DA700005205A7C804A00141?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68AB67CA7DA71301B744AA0100000010\Patches\68AB67CA7DA700005205A7C804A00141@State 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Reliability\Srt@Run 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce@*Restore C:\Windows\system32\rstrui.exe /RUNONCE
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ThemeManager@ServerChangeNumber 49
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX@DisplayName Adobe Flash Player 11 ActiveX
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX@DisplayVersion 11.1.102.55
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX@VersionMajor 11
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX@VersionMinor 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX@UninstallString C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe -maintain activex
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX@DisplayIcon C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1031-7B44-AA1000000001}@DisplayVersion 10.1.4
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1031-7B44-AA1000000001}@InstallDate 20121010
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1031-7B44-AA1000000001}@EstimatedSize 189588
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1031-7B44-AA1000000001}@Version 167837700
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1031-7B44-AA1000000001}@DisplayName Adobe Reader X (10.1.4) - Deutsch
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update@NextSqmReportTime 2013-10-15 18:30:16
Reg HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug@StoreLocation C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_8024402c_66c66075855619cc1111e0dd9c4f3189cbbd9c6_0bc9aa81
Reg HKLM\SOFTWARE\Microsoft\Windows Defender@DisableAntiSpyware 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2258613885-470133810-18836794-1001@RefCount 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures@Adobe Flash Player Updater.job.fp -1006338491
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1A76E1AD-720A-4467-A97D-D273B3C9AA51}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{83A0B7AD-F948-4940-ACBB-174573F57BBE}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A7ED4127-60DE-44D4-A73B-8A3C4E525FBA}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1A76E1AD-720A-4467-A97D-D273B3C9AA51}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1A76E1AD-720A-4467-A97D-D273B3C9AA51}@Path \Microsoft\Microsoft Antimalware\MpIdleTask
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1A76E1AD-720A-4467-A97D-D273B3C9AA51}@Hash 0xF6 0xA3 0xC1 0x61 ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1A76E1AD-720A-4467-A97D-D273B3C9AA51}@Triggers 0x15 0x00 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1A76E1AD-720A-4467-A97D-D273B3C9AA51}@DynamicInfo 0x03 0x00 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83A0B7AD-F948-4940-ACBB-174573F57BBE}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83A0B7AD-F948-4940-ACBB-174573F57BBE}@Path \Microsoft\Windows Defender\MP Scheduled Scan
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83A0B7AD-F948-4940-ACBB-174573F57BBE}@Hash 0xEC 0x9C 0x00 0x7E ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83A0B7AD-F948-4940-ACBB-174573F57BBE}@Triggers 0x15 0x00 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83A0B7AD-F948-4940-ACBB-174573F57BBE}@DynamicInfo 0x03 0x00 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A7ED4127-60DE-44D4-A73B-8A3C4E525FBA}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A7ED4127-60DE-44D4-A73B-8A3C4E525FBA}@Path \Microsoft\Microsoft Antimalware\MP Scheduled Scan
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A7ED4127-60DE-44D4-A73B-8A3C4E525FBA}@Hash 0x55 0x69 0x5C 0xEC ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A7ED4127-60DE-44D4-A73B-8A3C4E525FBA}@Triggers 0x15 0x00 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A7ED4127-60DE-44D4-A73B-8A3C4E525FBA}@DynamicInfo 0x03 0x00 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Microsoft Antimalware\MP Scheduled Scan
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Microsoft Antimalware\MP Scheduled Scan@Id {A7ED4127-60DE-44D4-A73B-8A3C4E525FBA}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Microsoft Antimalware\MP Scheduled Scan@Index 3
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Microsoft Antimalware\MpIdleTask@Id {1A76E1AD-720A-4467-A97D-D273B3C9AA51}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows Defender\MP Scheduled Scan
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows Defender\MP Scheduled Scan@Id {83A0B7AD-F948-4940-ACBB-174573F57BBE}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows Defender\MP Scheduled Scan@Index 3
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs c:\progra~2\browse~1\23765~1.24\{16cdf~1\browse~1.dll
Reg HKLM\SOFTWARE\Microsoft\Windows Search\CatalogNames\Windows\SystemIndex@pkm:catalog:LastCatalogCrawlId 16
Reg HKLM\SOFTWARE\Microsoft\Windows Search\CatalogNames\Windows\SystemIndex@pkm:catalog:LastCatalogCrawlModified 1
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex@NewCrawlNumber 17
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex@ElapsedRunTime 12620
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0@LastCrawlType 5
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0@LastCrawlSuccesses 123
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0@LastCrawlSeedStatus 0
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0@LastCrawlId 1
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1@LastCrawlType 1
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1@LastCrawlSuccesses 3203
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1@LastCrawlExcluded 2856
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1@LastCrawlNotFound 4
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1@LastCrawlUncategorizedErrors 16
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1@LastCrawlId 2
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2@LastCrawlSuccesses 1
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2@LastCrawlSeedStatus 0
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2@LastCrawlId 15
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StreamLog@CurrentStreamLog 8
Reg HKLM\SOFTWARE\Microsoft\Windows Search\UsnNotifier\Windows\Catalogs\SystemIndex@{8BBA84C4-3863-11E1-B50D-806E6F6E6963} 300350952
Reg HKLM\SOFTWARE\Classes\CLSID\{2781761E-28E0-4109-99FE-B9D127C57AFE}\Implemented Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}
Reg HKLM\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}
Reg HKLM\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}@ FlashBroker
Reg HKLM\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}@LocalizedString @C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe,-101
Reg HKLM\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation
Reg HKLM\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation@Enabled 1
Reg HKLM\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32@ C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe
Reg HKLM\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib
Reg HKLM\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib@ {FAB3E735-69C7-453B-A446-B6823C6DF1C9}
Reg HKLM\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32@ C:\Windows\system32\Macromed\Flash\Flash11e.ocx
Reg HKLM\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID@ ShockwaveFlash.ShockwaveFlash.10
Reg HKLM\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32@ C:\Windows\system32\Macromed\Flash\Flash11e.ocx, 1
Reg HKLM\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32@ C:\Windows\system32\Macromed\Flash\Flash11e.ocx
Reg HKLM\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32@ C:\Windows\system32\Macromed\Flash\Flash11e.ocx, 1
Reg HKLM\SOFTWARE\Classes\Installer\Products\68AB67CA7DA71301B744AA0100000010@ProductName Adobe Reader X (10.1.4) - Deutsch
Reg HKLM\SOFTWARE\Classes\Installer\Products\68AB67CA7DA71301B744AA0100000010@Version 167837700
Reg HKLM\SOFTWARE\Classes\Installer\Products\68AB67CA7DA71301B744AA0100000010\Patches@Patches 68AB67CA7DA700005205A7C804A00141?
Reg HKLM\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}
Reg HKLM\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}@ IFlashBroker4
Reg HKLM\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32
Reg HKLM\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32@ {00020424-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib
Reg HKLM\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib@ {FAB3E735-69C7-453B-A446-B6823C6DF1C9}
Reg HKLM\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib@Version 1.0
Reg HKLM\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\DefaultIcon
Reg HKLM\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\DefaultIcon@ C:\Program Files\Internet Explorer\iexplore.exe,-17
Reg HKLM\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\shell
Reg HKLM\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\shell\open
Reg HKLM\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\shell\open\command
Reg HKLM\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\shell\open\command@ "C:\Program Files\Internet Explorer\iexplore.exe" -nohome "%1"
Reg HKLM\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash\CurVer@ ShockwaveFlash.ShockwaveFlash.10
Reg HKLM\SOFTWARE\Classes\TypeLib\{57A0E746-3863-4D20-A811-950C84F1DB9B}\1.1\0\win32@ C:\Windows\system32\Macromed\Flash\Flash11e.ocx\2
Reg HKLM\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\0\win32@ C:\Windows\system32\Macromed\Flash\Flash11e.ocx
Reg HKLM\SOFTWARE\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0\0\win32@ C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe
Reg HKLM\SOFTWARE\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0\HELPDIR@ C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad@WpadLastNetwork {7A1789FF-C95C-4FD8-83EF-2AB4C9BB0225}
Reg HKCU\Software\Microsoft\Windows\Windows Error Reporting\Debug@StoreLocation C:\Users\Lehrer\AppData\Local\Microsoft\Windows\WER\ReportQueue\AppCrash_eraser.exe_6f26ac4df79ed96e49394d3bece8b89813313b5_cab_07c06ee8
---- EOF - GMER 2.1 ---- |