Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 14-02-14.01 - ASUS 15.02.2014 16:49:34.2.8 - x64
- Microsoft Windows 7 Ultimate 6.1.7601.1.1254.90.1055.18.8077.5349 [GMT 2:00]
- Running from: c:\users\ASUS\Downloads\ComboFix.exe
- AV: COMODO Antivirus *Disabled/Updated* {B74CC7D2-B407-E1DC-1033-DD315BCDC8C8}
- FW: COMODO Firewall *Disabled* {8F7746F7-FE68-E084-3B6C-7404A51E8FB3}
- SP: COMODO Antivirus *Disabled/Updated* {0C2D2636-923D-EE52-2A83-E643204A8275}
- SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- c:\windows\PFRO.log
- .
- .
- ((((((((((((((((((((((((( Files Created from 2014-01-15 to 2014-02-15 )))))))))))))))))))))))))))))))
- .
- .
- 2014-02-15 15:05 . 2014-02-15 15:05 -------- d-----w- c:\users\Public\AppData\Local\temp
- 2014-02-15 15:05 . 2014-02-15 15:05 -------- d-----w- c:\users\Default\AppData\Local\temp
- 2014-02-14 21:08 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL
- 2014-02-14 21:08 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
- 2014-02-14 21:08 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
- 2014-02-14 21:08 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL
- 2014-02-14 21:08 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll
- 2014-02-14 20:56 . 2014-02-14 20:56 -------- d-----w- c:\windows\Migration
- 2014-02-14 20:55 . 2013-10-14 16:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
- 2014-02-14 20:37 . 2014-02-14 20:37 -------- d-----w- c:\program files (x86)\SkypeWebPlugin
- 2014-02-14 20:28 . 2013-10-19 02:18 81408 ----a-w- c:\windows\system32\imagehlp.dll
- 2014-02-14 20:23 . 2013-10-12 02:32 150016 ----a-w- c:\windows\system32\wshom.ocx
- 2014-02-14 20:23 . 2013-10-12 02:31 202752 ----a-w- c:\windows\system32\scrrun.dll
- 2014-02-14 20:23 . 2013-10-12 02:04 121856 ----a-w- c:\windows\SysWow64\wshom.ocx
- 2014-02-14 20:23 . 2013-10-12 02:03 163840 ----a-w- c:\windows\SysWow64\scrrun.dll
- 2014-02-14 20:23 . 2013-10-12 01:33 156160 ----a-w- c:\windows\system32\cscript.exe
- 2014-02-14 20:23 . 2013-10-12 01:33 168960 ----a-w- c:\windows\system32\wscript.exe
- 2014-02-14 20:23 . 2013-10-12 01:15 141824 ----a-w- c:\windows\SysWow64\wscript.exe
- 2014-02-14 20:23 . 2013-10-12 01:15 126976 ----a-w- c:\windows\SysWow64\cscript.exe
- 2014-02-14 15:46 . 2014-02-14 17:05 -------- d-----w- c:\users\ASUS\MPLABXProjects
- 2014-02-13 23:36 . 2011-09-21 06:09 453632 ----a-w- c:\windows\system32\wbem\repdrvfs.dll
- 2014-02-10 20:23 . 2014-02-10 20:23 830648 ----a-w- c:\windows\system32\drivers\vdbus.sys
- 2014-02-10 20:23 . 2014-02-10 20:23 682888 ----a-w- c:\windows\system32\drivers\cbvd.sys
- 2014-02-10 20:23 . 2014-02-10 20:23 236320 ----a-w- c:\windows\system32\drivers\CBUFS.sys
- 2014-02-10 20:23 . 2014-02-10 20:23 87512 ----a-w- c:\windows\system32\drivers\bdisk.sys
- 2014-02-10 20:23 . 2014-02-10 20:23 679792 ----a-w- c:\windows\system32\drivers\CBreparse.sys
- 2014-02-07 01:40 . 2014-02-07 01:40 -------- d-----w- c:\users\ASUS\AppData\Local\WpfApplication1
- 2014-02-06 00:20 . 2008-05-15 01:28 26624 ----a-w- c:\windows\system32\drivers\jswpslwfx.sys
- 2014-02-06 00:19 . 2014-02-06 00:20 -------- d-----w- c:\program files (x86)\Jumpstart
- 2014-02-06 00:19 . 2014-02-06 00:20 -------- d-----w- c:\programdata\Atheros
- 2014-02-05 23:34 . 2014-02-05 23:34 -------- d-----w- c:\users\ASUS\AppData\Local\Line
- 2014-02-05 23:34 . 2014-02-05 23:34 -------- d-----w- c:\program files (x86)\Naver
- 2014-02-05 17:43 . 2014-02-05 17:43 -------- d-----w- c:\users\ASUS\AppData\Local\SkypeWebPlugin
- 2014-02-04 22:17 . 2014-02-04 22:44 -------- d-----w- c:\users\ASUS\Heaven
- 2014-02-04 21:44 . 2014-02-04 21:44 -------- d-----w- c:\program files (x86)\Unigine
- 2014-02-04 16:37 . 2014-02-04 16:37 -------- d-----w- c:\users\ASUS\AppData\Roaming\ProductData
- 2014-01-30 20:54 . 2014-01-30 20:54 57096 ----a-w- c:\windows\system32\certsentry.dll
- 2014-01-30 15:38 . 2014-02-04 16:18 119000 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
- 2014-01-28 00:10 . 2013-08-13 13:00 1002728 ----a-w- c:\windows\system32\WinUSBCoInstaller2.dll
- 2014-01-20 13:16 . 2014-01-20 13:16 -------- d-----w- c:\users\ASUS\AppData\Local\CrystalDiskMark
- 2014-01-16 15:20 . 2014-01-21 20:21 -------- d-----w- c:\users\ASUS\Cloud@Mail.Ru
- 2014-01-16 15:20 . 2014-01-16 15:20 -------- d-----w- c:\users\ASUS\AppData\Local\Mail.Ru
- .
- .
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2014-02-04 17:09 . 2013-02-08 11:47 88567024 ----a-w- c:\windows\system32\MRT.exe
- 2014-01-30 20:54 . 2013-03-28 19:17 48392 ----a-w- c:\windows\SysWow64\certsentry.dll
- 2014-01-15 17:22 . 2013-06-20 16:48 3897568 ----a-w- c:\programdata\Microsoft\VisualStudio\11.0\1033\ResourceCache.dll
- 2014-01-07 12:36 . 2014-01-07 12:36 1720192 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
- 2013-12-16 12:05 . 2013-02-08 09:58 387 ----a-w- c:\users\ASUS\AppData\Roaming\sp_data.sys
- 2013-11-29 16:56 . 2013-10-29 19:15 1096480 ----a-w- c:\windows\system32\nvspcap64.dll
- 2013-11-29 16:56 . 2013-10-29 19:15 979744 ----a-w- c:\windows\SysWow64\nvspcap.dll
- 2013-11-21 15:17 . 2013-11-03 08:08 239616 ----a-w- c:\windows\system32\USBAccessLink.dll
- 2013-11-21 15:17 . 2013-11-03 08:08 196608 ----a-w- c:\windows\SysWow64\USBAccessLink.dll
- .
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
- @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
- 2013-09-10 23:54 131248 ----a-w- c:\users\ASUS\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
- @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
- 2013-09-10 23:54 131248 ----a-w- c:\users\ASUS\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
- @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
- 2013-09-10 23:54 131248 ----a-w- c:\users\ASUS\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
- @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
- 2013-09-10 23:54 131248 ----a-w- c:\users\ASUS\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
- .
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "AdobeBridge"="" [BU]
- "cis.exe"="c:\program files\COMODO\COMODO Internet Security\cis.exe" [2013-11-20 8788696]
- "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-04-17 3671872]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
- "ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2012-06-25 322208]
- "ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2012-06-19 174752]
- "HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
- "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
- "jswtrayutil"="c:\program files (x86)\Jumpstart\jswtrayutil.exe" [2008-09-26 528384]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
- "ConsentPromptBehaviorAdmin"= 5 (0x5)
- "ConsentPromptBehaviorUser"= 3 (0x3)
- "EnableUIADesktopToggle"= 0 (0x0)
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
- "LoadAppInit_DLLs"=1 (0x1)
- "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
- .
- R1 AntiLog32;AntiLog32;c:\windows\system32\drivers\AntiLog64.sys;c:\windows\SYSNATIVE\drivers\AntiLog64.sys [x]
- R1 CFRMD;CFRMD;c:\windows\system32\DRIVERS\CFRMD.sys;c:\windows\SYSNATIVE\DRIVERS\CFRMD.sys [x]
- R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
- R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
- R2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x]
- R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protokolü;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x]
- R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x]
- R3 ASUSProcObsrv;ASUS Process Creation/Termination Observer;e:\i386\AsPrOb64.sys;e:\i386\AsPrOb64.sys [x]
- R3 cmdvirth;COMODO Virtual Service Manager;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe [x]
- R3 DIRECTIO;DIRECTIO;c:\program files\PerformanceTest\DirectIo64.sys;c:\program files\PerformanceTest\DirectIo64.sys [x]
- R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
- R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [x]
- R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
- R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys;c:\windows\SYSNATIVE\drivers\intelaud.sys [x]
- R3 jswpsapi;JumpStart Wi-Fi Protected Setup;c:\program files (x86)\Jumpstart\jswpsapi.exe;c:\program files (x86)\Jumpstart\jswpsapi.exe [x]
- R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
- R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
- R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
- R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
- R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [x]
- R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
- R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
- R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
- R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
- R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
- R3 WatAdminSvc;Windows Etkinleştirme Teknolojileri Hizmeti;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
- S0 bdisk;Comodo Disk Raw Access Filter;c:\windows\system32\drivers\bdisk.sys;c:\windows\SYSNATIVE\drivers\bdisk.sys [x]
- S0 CBUfs;CBUfs;c:\windows\system32\drivers\CBUFS.sys;c:\windows\SYSNATIVE\drivers\CBUFS.sys [x]
- S0 cbvd;Comodo Backup Virtual Disk;c:\windows\system32\DRIVERS\cbvd.sys;c:\windows\SYSNATIVE\DRIVERS\cbvd.sys [x]
- S0 iusb3hcs;Intel(R) USB 3.0 Ana Bilgisayar Denetleyici Değiştirici Sürücüsü;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
- S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
- S0 reparse;reparse;c:\windows\system32\DRIVERS\cbreparse.sys;c:\windows\SYSNATIVE\DRIVERS\cbreparse.sys [x]
- S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x]
- S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys;c:\windows\SYSNATIVE\DRIVERS\cmderd.sys [x]
- S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys;c:\windows\SYSNATIVE\DRIVERS\cmdguard.sys [x]
- S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys;c:\windows\SYSNATIVE\DRIVERS\cmdhlp.sys [x]
- S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
- S1 JSWPSLWF;JumpStart Wireless Filter Driver;c:\windows\system32\DRIVERS\jswpslwfx.sys;c:\windows\SYSNATIVE\DRIVERS\jswpslwfx.sys [x]
- S1 nvkflt;nvkflt;c:\windows\system32\DRIVERS\nvkflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvkflt.sys [x]
- S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x]
- S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x]
- S2 ASUS InstantOn;ASUS InstantOn Service;c:\program files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe;c:\program files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [x]
- S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x]
- S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x]
- S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x]
- S2 CLPSLauncher;COMODO LPS Launcher;c:\program files (x86)\Common Files\COMODO\launcher_service.exe;c:\program files (x86)\Common Files\COMODO\launcher_service.exe [x]
- S2 COSService.exe;COMODO Online Storage Service;c:\program files\COMODO\COMMON\COSService.exe;c:\program files\COMODO\COMMON\COSService.exe [x]
- S2 DragonUpdater;COMODO Dragon Update Service;c:\program files (x86)\Comodo\Dragon\dragon_updater.exe;c:\program files (x86)\Comodo\Dragon\dragon_updater.exe [x]
- S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [x]
- S2 GeekBuddyRSP;GeekBuddyRSP Service;c:\program files (x86)\Common Files\COMODO\GeekBuddyRSP.exe;c:\program files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [x]
- S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
- S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
- S2 jswpbapi;JumpStart Push-Button Service;c:\program files (x86)\Jumpstart\jswpbapi.exe;c:\program files (x86)\Jumpstart\jswpbapi.exe [x]
- S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
- S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
- S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
- S2 SynchronizationService.exe;COMODO BackUp Service;c:\program files\COMODO\COMMON\SynchronizationService.exe;c:\program files\COMODO\COMMON\SynchronizationService.exe [x]
- S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
- S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
- S2 WTGService;WTGService;c:\program files (x86)\AveaConnectionManager\WTGService.exe;c:\program files (x86)\AveaConnectionManager\WTGService.exe [x]
- S3 AiCharger;ASUS Charger Driver;c:\windows\system32\DRIVERS\AiCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AiCharger.sys [x]
- S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Sanal Bağdaştırıcısı;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x]
- S3 AsusVBus;AsusVBus;c:\windows\system32\DRIVERS\AsusVBus.sys;c:\windows\SYSNATIVE\DRIVERS\AsusVBus.sys [x]
- S3 AsusVTouch;AsusVTouch;c:\windows\system32\DRIVERS\AsusVTouch.sys;c:\windows\SYSNATIVE\DRIVERS\AsusVTouch.sys [x]
- S3 ATP;ASUS PS/2 Port Input Device;c:\windows\system32\DRIVERS\AsusTP.sys;c:\windows\SYSNATIVE\DRIVERS\AsusTP.sys [x]
- S3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [x]
- S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x]
- S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x]
- S3 ibtfltcoex;ibtfltcoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x]
- S3 iusb3hub;Intel(R) USB 3.0 Hub Sürücüsü;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
- S3 iusb3xhc;Intel(R) USB 3.0 Genişletilebilir Ana Bilgisayar Denetleyici Sürücüsü;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
- S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys;c:\windows\SYSNATIVE\DRIVERS\iwdbus.sys [x]
- S3 L1C;NDIS Miniport Driver for Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
- S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
- S3 vdbus;Virtual Disk Bus Enumerator;c:\windows\system32\DRIVERS\vdbus.sys;c:\windows\SYSNATIVE\DRIVERS\vdbus.sys [x]
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{2D46B6DC-2207-486B-B523-A557E6D54B47}]
- start [BU]
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
- 2014-02-04 02:05 1211720 ----a-w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.107\Installer\chrmstp.exe
- .
- Contents of the 'Scheduled Tasks' folder
- .
- 2014-02-12 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3536734130-3265028361-2442345767-1000Core.job
- - c:\users\ASUS\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-02-08 02:23]
- .
- 2014-02-15 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3536734130-3265028361-2442345767-1000UA.job
- - c:\users\ASUS\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-02-08 02:23]
- .
- 2014-02-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-08 10:44]
- .
- 2014-02-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-08 10:44]
- .
- 2013-11-04 c:\windows\Tasks\User_Feed_Synchronization-{31FB8002-5FED-42D9-990C-5F8A50982F94}.job
- - c:\windows\system32\msfeedssync.exe [2014-02-14 20:46]
- .
- .
- --------- X64 Entries -----------
- .
- .
- [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
- 2014-02-04 16:36 2471744 ----a-w- c:\program files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\COSDriveIconOverlay]
- @="{5FDACB62-6B7B-4116-9403-C5E0D3852A57}"
- [HKEY_CLASSES_ROOT\CLSID\{5FDACB62-6B7B-4116-9403-C5E0D3852A57}]
- 2014-02-10 20:23 7202496 ----a-w- c:\program files\COMODO\COMMON\ShellExtension.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\COSSyncItemInSyncIconOverlay]
- @="{68F287EF-DA6D-4595-AF52-90FF6CE52AFE}"
- [HKEY_CLASSES_ROOT\CLSID\{68F287EF-DA6D-4595-AF52-90FF6CE52AFE}]
- 2014-02-10 20:23 7202496 ----a-w- c:\program files\COMODO\COMMON\ShellExtension.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\COSSyncItemModifiedIconOverlay]
- @="{AE67D273-7253-4236-B55E-D40055B305D6}"
- [HKEY_CLASSES_ROOT\CLSID\{AE67D273-7253-4236-B55E-D40055B305D6}]
- 2014-02-10 20:23 7202496 ----a-w- c:\program files\COMODO\COMMON\ShellExtension.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\COSSyncItemNewIconOverlay]
- @="{022F23E9-DA0F-4A86-A728-CAF6150C0B63}"
- [HKEY_CLASSES_ROOT\CLSID\{022F23E9-DA0F-4A86-A728-CAF6150C0B63}]
- 2014-02-10 20:23 7202496 ----a-w- c:\program files\COMODO\COMMON\ShellExtension.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\COSSyncItemUnsynchronizedIconOverlay]
- @="{4D7EE7CF-E7A1-45FE-8F80-3A37574918D7}"
- [HKEY_CLASSES_ROOT\CLSID\{4D7EE7CF-E7A1-45FE-8F80-3A37574918D7}]
- 2014-02-10 20:23 7202496 ----a-w- c:\program files\COMODO\COMMON\ShellExtension.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
- @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
- 2013-09-10 23:54 164016 ----a-w- c:\users\ASUS\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
- @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
- 2013-09-10 23:54 164016 ----a-w- c:\users\ASUS\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
- @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
- 2013-09-10 23:54 164016 ----a-w- c:\users\ASUS\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
- @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
- 2013-09-10 23:54 164016 ----a-w- c:\users\ASUS\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2012-03-27 11407120]
- "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-04-02 170264]
- "ASUS Quick Gesture (x86)"="c:\program files (x86)\asus\asus smart gesture\quickgesture\x86\quickgesture.exe" [2012-07-13 17376]
- "ASUS TP Center (x64)"="c:\program files (x86)\asus\asus smart gesture\astpcenter\x64\asustpcenter.exe" [2012-07-13 235488]
- "ASUS Quick Gesture (x64)"="c:\program files (x86)\asus\asus smart gesture\quickgesture\x64\quickgesture64.exe" [2012-07-13 19424]
- "Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-11-08 1028384]
- "ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2013-11-29 1096480]
- "USB3MON"="c:\program files (x86)\intel\intel(r) usb 3.0 extensible host controller driver\application\iusb3mon.exe" [2012-03-26 291608]
- "RTHDVCPL"="c:\program files\realtek\audio\hda\ravcpl64.exe" [2012-07-02 12921488]
- "RtHDVBg"="c:\program files\realtek\audio\hda\ravbg64.exe" [2012-07-10 1214608]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
- "AppInit_DLLs"=c:\windows\System32\nvinitx.dll c:\windows\System32\nvinitx.dll
- .
- ------- Supplementary Scan -------
- .
- uLocal Page = c:\windows\system32\blank.htm
- uStart Page = hxxp://www.bing.com/
- mStart Page = hxxp://www.google.com
- mLocal Page = c:\windows\SysWOW64\blank.htm
- IE: Download all links with IDM - c:\users\ASUS\Desktop\Programlar\IEGetAll.htm
- IE: Download with IDM - c:\users\ASUS\Desktop\Programlar\IEExt.htm
- IE: Microsoft Excel'e &Ver - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
- Trusted Zone: alipay.com
- Trusted Zone: alisoft.com
- Trusted Zone: taobao.com
- TCP: DhcpNameServer = 192.168.1.1
- TCP: Interfaces\{DA65CE73-B608-40A1-86CA-C8BF5E51DCDF}: NameServer = 160.75.100.20,160.75.2.20
- .
- - - - - ORPHANS REMOVED - - - -
- .
- BHO-{081524f7-7ed8-43ff-b01e-915c410a9cbe} - (no file)
- .
- .
- .
- --------------------- LOCKED REGISTRY KEYS ---------------------
- .
- [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.alb\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="PhotoManagerDeluxe.8.alb"
- .
- [HKEY_USERS\S-1-5-21-3536734130-3265028361-2442345767-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F478FB47-8B4E-C975-1444-CD7EDC04C553}*]
- "jafkblmlhodmgamefane"=hex:64,62,70,6f,62,66,67,70,65,66,65,68,66,61,68,68,6e,
- 70,6f,61,67,66,62,6d,6b,6a,6d,64,6d,64,6b,70,62,6a,69,69,67,6c,6d,69,00,3e
- .
- [HKEY_USERS\S-1-5-21-3536734130-3265028361-2442345767-1000_Classes\Wow6432Node\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
- @Denied: (Full) (Everyone)
- @Allowed: (Read) (RestrictedCode)
- "scansk"=hex(0):0e,c1,25,2b,65,0d,a9,af,9a,1b,33,10,56,aa,f7,e1,92,f8,80,94,e6,
- 70,be,94,35,c8,9c,9a,fb,5e,16,2c,01,2a,64,7a,51,1c,59,15,00,00,00,00,00,00,\
- .
- [HKEY_USERS\S-1-5-21-3536734130-3265028361-2442345767-1000_Classes\Wow6432Node\CLSID\{d1250aa6-3005-4431-a0c8-3945cc4632f0}]
- @Denied: (Full) (Everyone)
- @Allowed: (Read) (RestrictedCode)
- "Model"=dword:00000075
- "Therad"=dword:0000000f
- "SpecVersion"=dword:00000068
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
- @Denied: (A 2) (Everyone)
- @="FlashBroker"
- "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
- "Enabled"=dword:00000001
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
- @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
- @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
- @Denied: (A 2) (Everyone)
- @="IFlashBroker5"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
- @="{00020424-0000-0000-C000-000000000046}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
- @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
- "Version"="1.0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
- @Denied: (A 2) (Everyone)
- @="FlashBroker"
- "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
- "Enabled"=dword:00000001
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
- @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
- @Denied: (A 2) (Everyone)
- @="Shockwave Flash Object"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"
- "ThreadingModel"="Apartment"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
- @="0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
- @="ShockwaveFlash.ShockwaveFlash.11"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
- @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
- @="1.0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
- @="ShockwaveFlash.ShockwaveFlash"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
- @Denied: (A 2) (Everyone)
- @="Macromedia Flash Factory Object"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"
- "ThreadingModel"="Apartment"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
- @="FlashFactory.FlashFactory.1"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
- @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
- @="1.0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
- @="FlashFactory.FlashFactory"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
- @Denied: (A 2) (Everyone)
- @="IFlashBroker3"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
- @="{00020424-0000-0000-C000-000000000046}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
- @="{6EF568F4-D437-4466-AA63-A3645136D93E}"
- "Version"="1.0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}]
- @Denied: (A 2) (Everyone)
- @="IFlashBroker"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32]
- @="{00020424-0000-0000-C000-000000000046}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib]
- @="{6EF568F4-D437-4466-AA63-A3645136D93E}"
- "Version"="1.0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
- @Denied: (A 2) (Everyone)
- @="IFlashBroker5"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
- @="{00020424-0000-0000-C000-000000000046}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
- @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
- "Version"="1.0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]
- @Denied: (A 2) (Everyone)
- @="IFlashBroker2"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]
- @="{00020424-0000-0000-C000-000000000046}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]
- @="{6EF568F4-D437-4466-AA63-A3645136D93E}"
- "Version"="1.0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
- @="?????????????????? v1"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
- @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
- @="?????????????????? v2"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
- @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
- @Denied: (A) (Users)
- @Denied: (A) (Everyone)
- @Allowed: (B 1 2 3 4 5) (S-1-5-20)
- "BlindDial"=dword:00000000
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
- @Denied: (A) (Users)
- @Denied: (A) (Everyone)
- @Allowed: (B 1 2 3 4 5) (S-1-5-20)
- "BlindDial"=dword:00000000
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
- @Denied: (Full) (Everyone)
- .
- Completion time: 2014-02-15 17:09:59
- ComboFix-quarantined-files.txt 2014-02-15 15:09
- ComboFix2.txt 2013-10-04 18:07
- .
- Pre-Run: 10.026.962.944 bayt boş
- Post-Run: 10.159.820.800 bayt boş
- .
- - - End Of File - - BA64903539CCB61756D1BD452282C49A
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement