Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 11-02-09.05 - V 02/10/2011 14:00:50.1.4 - x64
- Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.8191.6524 [GMT -5:00]
- Running from: c:\users\V\Desktop\lolkitties.exe
- AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
- SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B}
- SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
- SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- c:\users\V\AppData\Roaming\Local
- .
- ((((((((((((((((((((((((( Files Created from 2011-01-10 to 2011-02-10 )))))))))))))))))))))))))))))))
- .
- 2011-02-10 19:04 . 2011-02-10 19:04 -------- d-----w- c:\users\Default\AppData\Local\temp
- 2011-02-09 17:34 . 2011-01-13 07:20 7844688 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A54B7CC7-6C2B-4C1A-917F-ACBDAA5E4856}\mpengine.dll
- 2011-02-06 00:50 . 2011-02-06 00:50 -------- d-----w- c:\program files (x86)\Taksi
- 2011-02-05 23:47 . 2011-02-10 19:06 -------- d-----w- c:\users\V\AppData\Roaming\Dropbox
- 2011-02-05 23:45 . 2011-02-05 23:45 -------- d-----w- c:\program files\Taksi
- 2011-02-05 23:42 . 2011-02-09 20:58 -------- d-----w- C:\Tmp
- 2011-02-05 23:31 . 2011-02-08 17:41 -------- d-----w- c:\users\V\AppData\Roaming\DivX
- 2011-02-05 23:31 . 2011-02-05 23:31 -------- d-----w- c:\program files\DivX
- 2011-02-05 23:30 . 2011-02-05 23:31 -------- d-----w- c:\program files (x86)\Common Files\DivX Shared
- 2011-02-05 23:18 . 2011-02-05 23:31 -------- d-----w- c:\program files (x86)\DivX
- 2011-02-05 23:15 . 2011-02-05 23:31 -------- d-----w- c:\programdata\DivX
- 2011-02-05 02:51 . 2011-02-05 02:51 -------- d-----w- C:\WoWExperiment
- 2011-01-25 18:23 . 2011-01-25 18:23 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{55A788AA-18A2-44A0-BFCD-4A6F709C9002}\gapaengine.dll
- 2011-01-25 18:09 . 2011-01-25 18:09 -------- d-----w- c:\program files (x86)\Microsoft Security Client
- 2011-01-25 18:09 . 2011-01-25 18:09 -------- d-----w- c:\windows\Temp4D648810-78BF-1CE2-CCC5-ED67D860D83F-Signatures
- 2011-01-25 18:08 . 2011-01-25 18:09 -------- d-----w- c:\program files\Microsoft Security Client
- 2011-01-25 18:08 . 2010-04-09 11:06 374664 ----a-w- c:\windows\system32\drivers\netio.sys
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2011-01-13 07:20 . 2009-11-22 19:45 7844688 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
- 2011-01-08 03:27 . 2010-11-17 00:14 12859496 ----a-w- c:\windows\system32\nvd3dumx.dll
- 2011-01-08 03:27 . 2010-11-17 00:14 10078312 ----a-w- c:\windows\SysWow64\nvd3dum.dll
- 2011-01-08 03:27 . 2010-11-17 00:14 2200680 ----a-w- c:\windows\system32\nvapi64.dll
- 2011-01-08 03:27 . 2010-11-17 00:14 1965672 ----a-w- c:\windows\SysWow64\nvapi.dll
- 2011-01-08 01:49 . 2011-01-08 01:49 795752 ----a-w- c:\windows\system32\easyUpdatusAPIU64.dll
- 2011-01-08 01:49 . 2011-01-08 01:49 6143080 ----a-w- c:\windows\system32\nvcpl.dll
- 2011-01-08 01:49 . 2011-01-08 01:49 3156072 ----a-w- c:\windows\system32\nvsvc64.dll
- 2011-01-08 01:48 . 2011-01-08 01:48 117864 ----a-w- c:\windows\system32\nvmctray.dll
- 2011-01-08 01:48 . 2011-01-08 01:48 1005160 ----a-w- c:\windows\system32\nvvsvc.exe
- 2010-11-29 22:38 . 2010-11-29 22:38 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
- 2010-11-29 22:38 . 2010-11-29 22:38 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
- @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
- 2009-12-09 01:19 94208 ----a-w- c:\users\V\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
- @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
- 2009-12-09 01:19 94208 ----a-w- c:\users\V\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
- @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
- 2009-12-09 01:19 94208 ----a-w- c:\users\V\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
- "WinampAgent"="d:\winamp\winampa.exe" [2009-07-01 37888]
- "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
- "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
- "VMware hqtray"="c:\program files (x86)\VMware\VMware Player\hqtray.exe" [2010-01-23 64048]
- "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
- "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-12-25 421888]
- "iTunesHelper"="d:\itunes\iTunesHelper.exe" [2010-12-13 421160]
- "DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-01-10 1230704]
- "DivX Download Manager"="c:\program files (x86)\DivX\DivX Plus Web Player\DDmService.exe" [2010-12-08 63360]
- c:\users\V\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
- Dropbox.lnk - c:\users\V\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
- c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
- Taksi.lnk - c:\program files\Taksi\Taksi.exe [2010-7-11 73728]
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
- "ConsentPromptBehaviorAdmin"= 0 (0x0)
- "ConsentPromptBehaviorUser"= 3 (0x3)
- "EnableLUA"= 0 (0x0)
- "EnableUIADesktopToggle"= 0 (0x0)
- "PromptOnSecureDesktop"= 0 (0x0)
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
- @="Service"
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
- @="Service"
- R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
- R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
- R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 40832]
- R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-25 72064]
- R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
- R3 SysInfo;SysInfo;c:\windows\system32\drivers\SysInfo.sys [x]
- R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2010-09-28 51712]
- R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-04-20 1255736]
- S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-06-10 69152]
- S0 nvamacpi;NVIDIA Away Mode System;c:\windows\system32\DRIVERS\NVAMACPI.sys [2009-07-17 28192]
- S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-05 834544]
- S2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x64.sys [2010-07-09 21480]
- S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2010-06-30 1352832]
- S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-08 378984]
- S2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [2010-01-23 80944]
- S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe [2010-01-23 563760]
- S3 AVer88xHD;AVerMedia 23888 AvStream Video Capture;c:\windows\system32\drivers\AVer88xHD64.sys [2009-06-25 508672]
- S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2010-11-11 155752]
- S3 nvoclk64;NVIDIA Enthusiasts Platform KDM;c:\windows\system32\DRIVERS\nvoclk64.sys [2009-09-15 42088]
- .
- --------- x86-64 -----------
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
- @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
- 2009-12-09 01:19 97792 ----a-w- c:\users\V\AppData\Roaming\Dropbox\bin\DropboxExt64.13.dll
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
- @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
- 2009-12-09 01:19 97792 ----a-w- c:\users\V\AppData\Roaming\Dropbox\bin\DropboxExt64.13.dll
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
- @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
- 2009-12-09 01:19 97792 ----a-w- c:\users\V\AppData\Roaming\Dropbox\bin\DropboxExt64.13.dll
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-03-24 2184520]
- "CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 767312]
- "NVRaidService"="c:\windows\system32\nvraidservice.exe" [2009-06-30 291872]
- "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 1436224]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
- "LoadAppInit_DLLs"=0x1
- .
- ------- Supplementary Scan -------
- .
- uLocal Page = c:\windows\system32\blank.htm
- uStart Page = about:blank
- mLocal Page = c:\windows\SysWOW64\blank.htm
- uInternet Settings,ProxyOverride = *.local
- IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
- IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000
- IE: Se&nd to OneNote - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105
- LSP: c:\program files (x86)\VMware\VMware Player\vsocklib.dll
- FF - ProfilePath - c:\users\V\AppData\Roaming\Mozilla\Firefox\Profiles\v1foasc7.default\
- FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
- FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
- FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
- FF - Ext: Gmail Notifier: {44d0a1b4-9c90-4f86-ac92-8680b5d6549e} - %profile%\extensions\{44d0a1b4-9c90-4f86-ac92-8680b5d6549e}
- FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
- FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
- FF - Ext: RAMBack: ramback@pavlov.net - %profile%\extensions\ramback@pavlov.net
- FF - Ext: Photobucket Uploader em:version=1.3>: pbupload@photobucket.com - %profile%\extensions\pbupload@photobucket.com
- FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files (x86)\DivX\DivX Plus Web Player\firefox\html5video
- FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - c:\program files (x86)\DivX\DivX Plus Web Player\firefox\wpa
- FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(yahoo.ytff.general.dontshowhpoffer, true
- .
- .
- --------------------- LOCKED REGISTRY KEYS ---------------------
- [HKEY_USERS\S-1-5-21-784655873-2852724448-1511412404-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
- "??"=hex:d2,81,a9,f8,45,54,5c,81,6f,e3,dc,c4,1a,1a,d7,eb,a5,46,4d,bd,9e,e9,c8,
- ad,3b,52,dc,87,6d,80,03,f2,8e,84,95,93,d0,6b,c1,89,8a,b4,92,ae,9c,ef,7b,87,\
- "??"=hex:cf,55,c7,95,2b,14,4d,f8,66,7b,0c,1b,19,52,fe,22
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
- @Denied: (A 2) (Everyone)
- @="FlashBroker"
- "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
- "Enabled"=dword:00000001
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
- @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
- @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
- @Denied: (A 2) (Everyone)
- @="Shockwave Flash Object"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
- @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
- "ThreadingModel"="Apartment"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
- @="0"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
- @="ShockwaveFlash.ShockwaveFlash.10"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
- @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
- @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
- @="1.0"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
- @="ShockwaveFlash.ShockwaveFlash"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
- @Denied: (A 2) (Everyone)
- @="Macromedia Flash Factory Object"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
- @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
- "ThreadingModel"="Apartment"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
- @="FlashFactory.FlashFactory.1"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
- @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
- @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
- @="1.0"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
- @="FlashFactory.FlashFactory"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
- @Denied: (A 2) (Everyone)
- @="IFlashBroker3"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
- @="{00020424-0000-0000-C000-000000000046}"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
- @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
- "Version"="1.0"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
- @Denied: (A) (Users)
- @Denied: (A) (Everyone)
- @Allowed: (B 1 2 3 4 5) (S-1-5-20)
- "BlindDial"=dword:00000000
- "MSCurrentCountry"=dword:000000b5
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
- @Denied: (Full) (Everyone)
- .
- ------------------------ Other Running Processes ------------------------
- .
- c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
- c:\program files (x86)\Bonjour\mDNSResponder.exe
- c:\program files (x86)\TVersity\Media Server\MediaServer.exe
- c:\windows\SysWOW64\vmnat.exe
- c:\windows\SysWOW64\vmnetdhcp.exe
- c:\program files (x86)\VMware\VMware Player\vmware-authd.exe
- .
- **************************************************************************
- .
- Completion time: 2011-02-10 14:11:03 - machine was rebooted
- ComboFix-quarantined-files.txt 2011-02-10 19:11
- Pre-Run: 38,805,721,088 bytes free
- Post-Run: 38,705,721,344 bytes free
- - - End Of File - - 66FA38F4439D3641B34395AEF2AF6D06
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement