Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 14-09-29.02 - WIN 7 10/02/2014 10:01:42.2.4 - x86
- Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2031.936 [GMT 8:00]
- Running from: c:\users\WIN 7\Desktop\ComboFix.exe
- AV: Norton 360 Premier Edition *Disabled/Updated* {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB}
- FW: Norton 360 Premier Edition *Disabled* {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0}
- SP: Norton 360 Premier Edition *Enabled/Updated* {631E4324-D31C-783F-EC5C-35AD42B18466}
- SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- ---- Previous Run -------
- .
- c:\users\Public\sdelevURL.tmp
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\databases\chrome-extension_dhdepfaagokllfmhfbcfmocaeigmoebo_0
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\databases\chrome-extension_dhdepfaagokllfmhfbcfmocaeigmoebo_0\1
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\databases\chrome-extension_dhdepfaagokllfmhfbcfmocaeigmoebo_0\2
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\background.html
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\background.js
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\crossriderManifest.json
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\extension.js
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\icons\actions\icon1.png
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\icons\icon128.png
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\icons\icon16.png
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\icons\icon48.png
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\icons\notifications\icon1.png
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\icons\notifications\icon48.png
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\js\api\chrome.js
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\js\api\cookie.js
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\js\api\message.js
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\js\api\push.js
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\js\background.js
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\js\lib\app_api.js
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\js\lib\async_api.js
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\js\lib\bg_app_api.js
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\js\lib\cookie_store.js
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\js\lib\data_store.js
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\js\lib\faye-browser-min.js
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\js\lib\util.js
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\manifest.json
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\popup.html
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Local Storage\chrome-extension_dhdepfaagokllfmhfbcfmocaeigmoebo_0.localstorage-journal
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Local Storage\chrome-extension_dhdepfaagokllfmhfbcfmocaeigmoebo_0.localstorage
- c:\users\WIN 7\AppData\Local\Torch\User Data\Default\Preferences
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- -------\Legacy_NPF
- .
- .
- ((((((((((((((((((((((((( Files Created from 2014-09-02 to 2014-10-02 )))))))))))))))))))))))))))))))
- .
- .
- 2014-10-02 02:06 . 2014-10-02 02:06 -------- d-----w- c:\users\fbwuser\AppData\Local\temp
- 2014-10-02 02:06 . 2014-10-02 02:06 -------- d-----w- c:\users\Default\AppData\Local\temp
- 2014-10-02 01:21 . 2014-10-02 01:51 110296 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
- 2014-10-02 01:20 . 2014-10-02 01:20 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
- 2014-10-02 01:20 . 2014-05-11 23:26 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
- 2014-10-02 01:20 . 2014-05-11 23:25 74456 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
- 2014-10-02 01:20 . 2014-05-11 23:25 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
- 2014-10-01 07:03 . 2014-10-01 07:03 -------- d-----w- c:\programdata\GridinSoft
- 2014-10-01 07:03 . 2014-10-01 07:04 -------- d-----w- c:\program files\GridinSoft Trojan Killer
- 2014-10-01 01:02 . 2014-09-25 01:40 519680 ----a-w- c:\windows\system32\qdvd.dll
- 2014-09-29 02:31 . 2014-09-29 02:31 -------- d-sh--w- c:\users\WIN 7\AppData\Local\EmieUserList
- 2014-09-29 02:31 . 2014-09-29 02:31 -------- d-sh--w- c:\users\WIN 7\AppData\Local\EmieSiteList
- 2014-09-25 16:00 . 2014-09-25 16:00 16128 ----a-w- c:\windows\system32\drivers\gtkdrv.sys
- 2014-09-25 01:11 . 2014-09-25 01:11 -------- d-----w- c:\programdata\Malwarebytes
- 2014-09-24 03:01 . 2014-09-09 21:47 2048 ----a-w- c:\windows\system32\tzres.dll
- 2014-09-22 03:14 . 2014-09-22 03:14 -------- d-----w- c:\programdata\Oracle
- 2014-09-16 00:42 . 2014-09-16 00:42 -------- d-----w- c:\users\WIN 7\AppData\Roaming\Zbshareware Lab
- 2014-09-15 05:42 . 2014-09-25 05:16 -------- d-----w- c:\windows\rescache
- 2014-09-13 12:05 . 2014-09-13 12:05 3231696 ----a-w- c:\program files\Mozilla Firefox\d3dcompiler_46.dll
- 2014-09-10 04:55 . 2014-07-07 01:40 1059840 ----a-w- c:\windows\system32\lsasrv.dll
- 2014-09-10 04:55 . 2014-07-07 01:40 550912 ----a-w- c:\windows\system32\kerberos.dll
- 2014-09-10 04:55 . 2014-06-24 02:59 1987584 ----a-w- c:\windows\system32\d3d10warp.dll
- 2014-09-10 04:55 . 2014-08-01 11:35 793600 ----a-w- c:\windows\system32\TSWorkspace.dll
- .
- .
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2014-09-24 03:24 . 2012-04-22 22:53 701104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
- 2014-09-24 03:24 . 2011-10-10 02:28 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
- 2014-08-23 01:46 . 2014-09-01 00:25 305152 ----a-w- c:\windows\system32\gdi32.dll
- 2014-08-23 00:42 . 2014-09-01 00:25 2352640 ----a-w- c:\windows\system32\win32k.sys
- 2014-07-24 18:35 . 2014-07-24 18:35 875688 ----a-w- c:\windows\system32\msvcr120_clr0400.dll
- 2014-07-14 01:42 . 2014-08-13 00:33 654336 ----a-w- c:\windows\system32\rpcrt4.dll
- 2014-07-09 01:29 . 2014-08-13 00:29 6144 ----a-w- c:\windows\system32\KBDYAK.DLL
- 2014-07-09 01:29 . 2014-08-13 00:29 6144 ----a-w- c:\windows\system32\KBDBASH.DLL
- 2013-02-17 03:27 . 2013-02-17 03:27 2174976 ----a-w- c:\program files\Common Files\atimpenc.dll
- .
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
- @="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
- [HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
- 2012-11-15 23:07 21904 ----a-w- c:\program files\Internet Download Manager\IDMShellExt.dll
- .
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2013-12-15 3821136]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
- "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
- "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2014-01-17 421888]
- "HDD Regenerator"="c:\program files\HDD Regenerator\Shell.exe" [BU]
- .
- c:\users\WIN 7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
- OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2006-10-26 98632]
- .
- c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
- SpyderUtility.lnk - c:\program files\Datacolor\Spyder4Express\Utility\SpyderUtility.exe [2012-2-8 8241767]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
- "ConsentPromptBehaviorAdmin"= 0 (0x0)
- "ConsentPromptBehaviorUser"= 3 (0x3)
- "EnableUIADesktopToggle"= 0 (0x0)
- "PromptOnSecureDesktop"= 0 (0x0)
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
- 2013-11-21 16:57 959904 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
- 2013-03-20 21:10 472992 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCEPServiceManager]
- 2013-03-13 05:39 1039248 ----a-w- c:\program files\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aimersoft Helper Compact.exe]
- 2013-05-29 07:50 1734144 ----a-w- c:\program files\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
- 2007-06-01 02:21 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrowserPlugInHelper]
- c:\program files\Aimersoft\Video Converter Ultimate\BrowserPlugInHelper.exe [BU]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
- c:\program files\Samsung\Kies\KiesTrayAgent.exe [BU]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
- 2011-08-21 17:18 6276408 ----a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mobilegeni daemon]
- c:\program files\Mobogenie\DaemonProcess.exe [BU]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
- 2007-03-01 07:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
- 2013-10-02 12:28 1090912 ----a-w- c:\program files\Nokia\Nokia Suite\NokiaSuite.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RIMBBLaunchAgent.exe]
- 2013-01-17 08:08 267792 ----a-w- c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Search Protection]
- c:\program files\Yahoo!\Search Protection\SearchProtection.exe [BU]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wondershare Helper Compact.exe]
- 2013-12-18 03:43 1980416 ----a-w- c:\program files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
- .
- R2 MBAMService;MBAMService;c:\program files\Malwarebytes Anti-Malware\mbamservice.exe [2014-05-11 860472]
- R3 BprotectEx;Baidu ProtectEx;c:\windows\System32\drivers\BprotectEx.sys [x]
- R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-08-18 108032]
- R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [2014-10-02 110296]
- R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys [2014-05-11 51928]
- R3 PCFApiUtil;PCFApiUtil;c:\program files\Baidu Security\PC Faster\3.7.0.0\PCFApiUtil.sys [x]
- R3 Spyder4;Datacolor Spyder4;c:\windows\system32\DRIVERS\dccmtr.sys [2011-06-02 12288]
- R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
- R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
- R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-10-11 1343400]
- R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\drivers\WSDScan.sys [2009-07-14 20480]
- R4 Blackberry Device Manager;Blackberry Device Manager;c:\program files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [2013-01-18 577536]
- R4 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe [2013-11-27 555304]
- R4 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\nlssrv32.exe [2012-09-05 66560]
- R4 TeamViewer8;TeamViewer 8;c:\program files\TeamViewer\Version8\TeamViewer_Service.exe [2014-08-04 5095264]
- S0 Bhbase;Baidu Hook Base;c:\windows\System32\drivers\Bhbase.sys [2013-09-26 47456]
- S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\1405000.01C\SYMDS.SYS [2013-05-21 367704]
- S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\1405000.01C\SYMEFA.SYS [2013-05-23 934488]
- S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\BASHDefs\20140912.003\BHDrvx86.sys [2014-09-12 1137368]
- S1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\N360\1405000.01C\ccSetx86.sys [2013-04-16 134744]
- S1 HssDRV6;Hotspot Shield Routing Driver 6;c:\windows\system32\DRIVERS\hssdrv6.sys [2013-11-13 39624]
- S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\IPSDefs\20140930.001\IDSvix86.sys [2014-09-01 476888]
- S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\1405000.01C\Ironx86.SYS [2013-03-05 175264]
- S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\N360\1405000.01C\SYMNETS.SYS [2013-04-25 339544]
- S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-17 176128]
- S2 hshld;Hotspot Shield Service;c:\program files\Hotspot Shield\bin\cmw_srv.exe [2013-11-27 906024]
- S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [2013-11-28 108000]
- S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-05-11 1809720]
- S2 N360;Norton 360;c:\program files\Norton 360 Premier Edition\Engine\20.5.0.28\ccSvcHst.exe [2013-05-21 144368]
- S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2014-09-10 111408]
- S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2014-05-11 23256]
- S3 MEI;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECI.sys [2010-10-19 41088]
- S3 netr28;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28.sys [2012-12-06 2046560]
- S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2011-05-16 391272]
- S3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys [2013-06-21 37064]
- S3 TrojanKillerDriver;GridinSoft Trojan Killer Driver;c:\windows\system32\DRIVERS\gtkdrv.sys [2014-09-25 16128]
- .
- .
- Contents of the 'Scheduled Tasks' folder
- .
- 2014-10-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-22 03:24]
- .
- .
- ------- Supplementary Scan -------
- .
- uStart Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=N360&pvid=20.5.0.28
- IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
- IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
- IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
- IE: Locate Spot on Map by GPS - c:\program files\Opanda\IExif 2.3\IExifMap.htm
- IE: View Exif/GPS/IPTC with IExif - c:\program files\Opanda\IExif 2.3\IExifCom.htm
- TCP: Interfaces\{CD890928-BFE0-4285-B317-3F5296BFEAFA}: NameServer = 202.134.0.155
- FF - ProfilePath - c:\users\WIN 7\AppData\Roaming\Mozilla\Firefox\Profiles\azh1isgu.default-1412064827447\
- FF - prefs.js: browser.search.selectedEngine - Bing
- .
- - - - - ORPHANS REMOVED - - - -
- .
- Toolbar-10 - (no file)
- .
- .
- .
- [HKEY_LOCAL_MACHINE\system\ControlSet001\services\N360]
- "ImagePath"="\"c:\program files\Norton 360 Premier Edition\Engine\20.5.0.28\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360 Premier Edition\Engine\20.5.0.28\diMaster.dll\" /prefetch:1"
- .
- --------------------- LOCKED REGISTRY KEYS ---------------------
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.032"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abr\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.abr"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.ani"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.arw"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.bay"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
- @Denied: (2) (S-1-5-21-22482793-1858402393-37194211-1000)
- @Denied: (2) (LocalSystem)
- "Progid"="PhotoViewer.FileAssoc.Bitmap"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bw\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.bw"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.cs1"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.cur"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.dcr"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.dcx"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.dib"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.dng"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.emf"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.eps"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.erf"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.fff"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.fpx"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.gif"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.hdr"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.icl"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.icn"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice]
- @Denied: (2) (S-1-5-21-22482793-1858402393-37194211-1000)
- @Denied: (2) (LocalSystem)
- "Progid"="Winamp.File.iff"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ilbm\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.ilbm"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.int\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.int"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inta\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.inta"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.iw4"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.j2c"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.j2k"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbr\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.jbr"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.jfif"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.jif"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.jp2"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.jpc"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.jpk"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.jpx"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lbm\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.lbm"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.mef"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.mos"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.mrw"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.nef"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.orf"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.pbm"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbr\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.pbr"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.pct"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.pcx"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.pef"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.pgm"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.pic"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.pict"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pix\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.pix"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice]
- @Denied: (2) (S-1-5-21-22482793-1858402393-37194211-1000)
- @Denied: (2) (LocalSystem)
- "Progid"="PhotoViewer.FileAssoc.Png"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.ppm"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.psp"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspbrush\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.pspbrush"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.pspimage"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.raf"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.ras"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgb\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.rgb"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgba\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.rgba"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.rle"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsb\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.rsb"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.sgi"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.sr2"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.srf"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.tga"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.thm"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.tif"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.tiff"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.ttc"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.ttf"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v10o\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.v10o"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v10p\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.v10p"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v10pf\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.v10pf"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.wbm"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.wbmp"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.wmf"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.xbm"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.xif"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.xmp"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="ACDSee 10.0.xpm"
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000_Classes\CLSID\{1273c904-aaff-4d3e-a7a2-50ce315ce2d0}]
- @Denied: (Full) (Everyone)
- @Allowed: (Read) (RestrictedCode)
- "Model"=dword:00000045
- "Therad"=dword:0000001f
- "SpecVersion"=dword:00000081
- "MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
- 1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
- .
- [HKEY_USERS\S-1-5-21-22482793-1858402393-37194211-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
- @Denied: (Full) (Everyone)
- @Allowed: (Read) (RestrictedCode)
- "scansk"=hex(0):3b,97,97,be,cb,c0,fb,30,a8,9d,95,74,c9,f0,f1,4a,05,c2,17,9e,48,
- be,06,95,5f,97,d6,38,a7,a3,19,1c,ce,58,ac,77,ab,ca,0f,93,00,00,00,00,00,00,\
- .
- [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
- @Denied: (A) (Users)
- @Denied: (A) (Everyone)
- @Allowed: (B 1 2 3 4 5) (S-1-5-20)
- "BlindDial"=dword:00000000
- .
- [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
- @Denied: (A) (Users)
- @Denied: (A) (Everyone)
- @Allowed: (B 1 2 3 4 5) (S-1-5-20)
- "BlindDial"=dword:00000000
- .
- [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
- @Denied: (Full) (Everyone)
- .
- --------------------- DLLs Loaded Under Running Processes ---------------------
- .
- - - - - - - - > 'Explorer.exe'(988)
- c:\program files\Microsoft Office\Office12\1033\GrooveIntlResource.dll
- .
- ------------------------ Other Running Processes ------------------------
- .
- c:\windows\system32\atieclxx.exe
- c:\windows\system32\taskhost.exe
- c:\program files\Hard Disk Sentinel\HDSentinel.exe
- c:\program files\GridinSoft Trojan Killer\trojankiller.exe
- c:\windows\System32\WUDFHost.exe
- c:\windows\system32\conhost.exe
- c:\windows\system32\sppsvc.exe
- c:\windows\system32\taskhost.exe
- .
- **************************************************************************
- .
- Completion time: 2014-10-02 10:11:14 - machine was rebooted
- ComboFix-quarantined-files.txt 2014-10-02 02:11
- .
- Pre-Run: 24,044,769,280 bytes free
- Post-Run: 23,809,265,664 bytes free
- .
- - - End Of File - - 954AC671105817288A09AA38FE68FD18
- A36C5E4F47E84449FF07ED3517B43A31
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement