ComboFix 12-07-29.02 - sid 30-Jul-12 7:58.2.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3990.2177 [GMT 5.5:30]
Running from: c:\users\sid\Desktop\ComboFix.exe
Command switches used :: c:\users\sid\Desktop\CFscript.txt
AV: Microsoft Security Essentials Prerelease *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials Prerelease *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2012-06-28 to 2012-07-30 )))))))))))))))))))))))))))))))
.
.
2012-07-30 02:32 . 2012-07-30 02:32--------d-----w-c:\users\UpdatusUser\AppData\Local\temp
2012-07-30 02:32 . 2012-07-30 02:32--------d-----w-c:\users\Default\AppData\Local\temp
2012-07-30 02:08 . 2012-07-30 02:0869000----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CB8A4904-90A9-4133-87EB-B294DE915203}\offreg.dll
2012-07-29 04:02 . 2012-07-29 04:02--------d-----w-c:\program files (x86)\ESET
2012-07-29 03:51 . 2012-07-15 21:109133488----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CB8A4904-90A9-4133-87EB-B294DE915203}\mpengine.dll
2012-07-28 11:41 . 2012-07-28 11:419821896----a-w-c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-07-27 04:13 . 2012-07-27 04:14--------d-----w-C:\FRST
2012-07-26 04:58 . 2012-02-09 08:47927800----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{41CC4F44-05B1-4C1B-B47F-852CC81C82FD}\gapaengine.dll
2012-07-26 04:57 . 2012-02-09 08:47927800----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2012-07-26 04:39 . 2012-07-26 04:39--------d-----w-c:\program files (x86)\Microsoft Security Client
2012-07-26 04:39 . 2012-07-26 04:39--------d-----w-c:\program files\Microsoft Security Client
2012-07-12 05:10 . 2012-07-12 05:10--------d-----w-c:\program files (x86)\Gophoto.it
2012-07-12 05:08 . 2012-07-29 04:35--------d-----w-c:\program files (x86)\1ClickDownload
2012-07-12 03:24 . 2012-07-12 03:24--------d-sh--w-c:\windows\system32\%APPDATA%
2012-07-11 16:34 . 2012-07-11 16:34--------d-----w-c:\programdata\Intel
2012-07-11 16:33 . 2012-07-11 16:33--------d-----w-c:\program files (x86)\Cisco
2012-07-11 16:32 . 2012-07-11 16:32--------d--h--w-c:\windows\system32\WLANProfiles
2012-07-11 16:11 . 2012-07-11 16:11--------d-----w-c:\users\sid\AppData\Roaming\SystemRequirementsLab
2012-07-11 15:25 . 2012-06-12 03:083148800----a-w-c:\windows\system32\win32k.sys
2012-07-11 05:50 . 2012-07-11 05:51--------d-----w-c:\users\sid\AppData\Local\NVIDIA Corporation
2012-07-11 03:47 . 2012-06-06 06:062004480----a-w-c:\windows\system32\msxml6.dll
2012-07-11 03:47 . 2012-06-06 06:061881600----a-w-c:\windows\system32\msxml3.dll
2012-07-11 03:47 . 2012-06-06 05:051390080----a-w-c:\windows\SysWow64\msxml6.dll
2012-07-11 03:47 . 2012-06-06 05:051236992----a-w-c:\windows\SysWow64\msxml3.dll
2012-07-11 03:47 . 2010-06-26 03:552048----a-w-c:\windows\system32\msxml3r.dll
2012-07-11 03:47 . 2010-06-26 03:242048----a-w-c:\windows\SysWow64\msxml3r.dll
2012-07-11 03:47 . 2012-06-09 05:4314172672----a-w-c:\windows\system32\shell32.dll
2012-07-11 03:46 . 2012-06-02 05:50458704----a-w-c:\windows\system32\drivers\cng.sys
2012-07-11 03:46 . 2012-06-02 05:4895600----a-w-c:\windows\system32\drivers\ksecdd.sys
2012-07-11 03:46 . 2012-06-02 05:48151920----a-w-c:\windows\system32\drivers\ksecpkg.sys
2012-07-11 03:46 . 2012-06-02 05:45340992----a-w-c:\windows\system32\schannel.dll
2012-07-11 03:46 . 2012-06-02 05:44307200----a-w-c:\windows\system32\ncrypt.dll
2012-07-11 03:46 . 2012-06-02 04:40225280----a-w-c:\windows\SysWow64\schannel.dll
2012-07-11 03:46 . 2012-06-02 04:39219136----a-w-c:\windows\SysWow64\ncrypt.dll
2012-07-11 03:46 . 2012-06-02 04:4022016----a-w-c:\windows\SysWow64\secur32.dll
2012-07-11 03:46 . 2012-06-02 04:3496768----a-w-c:\windows\SysWow64\sspicli.dll
2012-07-11 03:41 . 2012-06-06 06:05495616----a-w-c:\program files\Common Files\System\ado\msadox.dll
2012-07-11 03:41 . 2012-06-06 06:0561440----a-w-c:\program files\Common Files\System\ado\msador15.dll
2012-07-11 03:41 . 2012-06-06 06:05466944----a-w-c:\program files\Common Files\System\ado\msadomd.dll
2012-07-11 03:41 . 2012-06-06 06:051499136----a-w-c:\program files\Common Files\System\ado\msado15.dll
2012-07-11 03:41 . 2012-06-06 06:05258048----a-w-c:\program files\Common Files\System\msadc\msadco.dll
2012-07-11 03:41 . 2012-06-06 05:05143360----a-w-c:\program files (x86)\Common Files\System\ado\msjro.dll
2012-07-11 03:41 . 2012-06-06 05:05372736----a-w-c:\program files (x86)\Common Files\System\ado\msadox.dll
2012-07-11 03:41 . 2012-06-06 05:0557344----a-w-c:\program files (x86)\Common Files\System\ado\msador15.dll
2012-07-11 03:41 . 2012-06-06 05:05352256----a-w-c:\program files (x86)\Common Files\System\ado\msadomd.dll
2012-07-11 03:41 . 2012-06-06 05:05212992----a-w-c:\program files (x86)\Common Files\System\msadc\msadco.dll
2012-07-11 03:41 . 2012-06-06 05:051019904----a-w-c:\program files (x86)\Common Files\System\ado\msado15.dll
2012-07-11 03:41 . 2012-06-06 05:03805376----a-w-c:\windows\SysWow64\cdosys.dll
2012-07-11 03:40 . 2012-06-06 06:021133568----a-w-c:\windows\system32\cdosys.dll
2012-07-07 04:26 . 1998-10-29 11:15306688----a-w-c:\windows\IsUninst.exe
2012-07-06 04:06 . 2012-07-06 04:06--------d-----w-c:\users\sid\AppData\Local\NeoSmart_Technologies
2012-07-06 04:04 . 2012-07-06 04:04--------d-----w-C:\NST
2012-07-06 04:03 . 2012-07-06 04:03--------d-----w-c:\program files (x86)\NeoSmart Technologies
2012-07-04 09:13 . 2012-07-04 09:13--------d-----w-C:\DriveKey
2012-07-04 09:13 . 2001-09-04 22:48225280----a-w-c:\program files (x86)\Common Files\InstallShield\IScript\iscript.dll
2012-07-04 09:13 . 2001-09-04 22:4877824----a-w-c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
2012-07-04 09:13 . 2001-09-04 22:44176128----a-w-c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
2012-07-04 09:13 . 2001-09-04 22:4332768----a-w-c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2012-07-04 09:13 . 2001-09-04 21:54610436----a-w-c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe
2012-07-02 08:57 . 2012-07-02 08:57--------d-----w-c:\users\sid\AppData\Local\NokiaAccount
2012-07-02 07:44 . 2012-07-02 07:44--------d-----w-c:\users\sid\AppData\Roaming\Nokia Suite
2012-07-02 07:44 . 2012-07-02 09:14--------d-----w-c:\users\sid\AppData\Roaming\Nokia
2012-06-30 03:29 . 2012-06-30 03:44--------d-----w-C:\Recovered Files
2012-06-30 03:25 . 2012-06-30 03:26--------d-----w-c:\program files (x86)\Data Recover-Center
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-28 11:41 . 2012-04-08 13:13426184----a-w-c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-28 11:41 . 2011-12-02 08:1870344----a-w-c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-11 14:58 . 2011-12-02 08:5059701280----a-w-c:\windows\system32\MRT.exe
2012-06-20 06:36 . 2012-06-20 06:36722782----a-w-c:\windows\unins000.exe
2012-06-02 22:19 . 2012-06-21 07:0838424----a-w-c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-21 07:082428952----a-w-c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-21 07:0844056----a-w-c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-21 07:0857880----a-w-c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-21 07:08701976----a-w-c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-21 07:082622464----a-w-c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-21 07:0899840----a-w-c:\windows\system32\wudriver.dll
2012-06-02 09:49 . 2012-06-21 07:08186752----a-w-c:\windows\system32\wuwebv.dll
2012-06-02 09:45 . 2012-06-21 07:0836864----a-w-c:\windows\system32\wuapp.exe
2012-05-24 11:38 . 2012-01-19 03:22737072----a-w-c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll
2012-05-24 11:38 . 2012-01-19 03:224283672----a-w-c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2012-05-24 10:56 . 2012-01-19 03:1142776----a-w-c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2012-05-24 10:56 . 2012-01-19 03:11539984----a-w-c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2012-05-15 10:48 . 2012-05-28 12:118105280----a-w-c:\windows\SysWow64\nvwgf2um.dll
2012-05-15 10:48 . 2012-05-28 12:11364352----a-w-c:\windows\system32\nvdecodemft.dll
2012-05-15 10:48 . 2012-05-28 12:11301376----a-w-c:\windows\SysWow64\nvdecodemft.dll
2012-05-15 10:48 . 2012-05-28 12:1128992----a-w-c:\windows\system32\drivers\nvpciflt.sys
2012-05-15 10:48 . 2012-05-28 12:1125743168----a-w-c:\windows\system32\nvoglv64.dll
2012-05-15 10:48 . 2012-05-28 12:11249152----a-w-c:\windows\system32\drivers\nvkflt.sys
2012-05-15 10:48 . 2012-05-28 12:1119607872----a-w-c:\windows\SysWow64\nvoglv32.dll
2012-05-15 10:48 . 2012-05-28 12:1114298944----a-w-c:\windows\system32\drivers\nvlddmkm.sys
2012-05-15 10:48 . 2012-05-28 12:1110194752----a-w-c:\windows\system32\nvwgf2umx.dll
2012-05-15 10:48 . 2012-05-28 12:118139072----a-w-c:\windows\system32\nvcuda.dll
2012-05-15 10:48 . 2012-05-28 12:115982528----a-w-c:\windows\SysWow64\nvcuda.dll
2012-05-15 10:48 . 2012-05-28 12:112881856----a-w-c:\windows\system32\nvcuvenc.dll
2012-05-15 10:48 . 2012-05-28 12:112681664----a-w-c:\windows\system32\nvcuvid.dll
2012-05-15 10:48 . 2012-05-28 12:112524992----a-w-c:\windows\SysWow64\nvcuvid.dll
2012-05-15 10:48 . 2012-05-28 12:1125248064----a-w-c:\windows\system32\nvcompiler.dll
2012-05-15 10:48 . 2012-05-28 12:112445120----a-w-c:\windows\SysWow64\nvcuvenc.dll
2012-05-15 10:48 . 2012-05-28 12:1117551680----a-w-c:\windows\SysWow64\nvcompiler.dll
2012-05-15 10:48 . 2012-02-23 03:3768928----a-w-c:\windows\system32\OpenCL.dll
2012-05-15 10:48 . 2012-02-23 03:3761248----a-w-c:\windows\SysWow64\OpenCL.dll
2012-05-15 10:48 . 2012-02-23 03:3718044224----a-w-c:\windows\system32\nvd3dumx.dll
2012-05-15 10:48 . 2012-02-23 03:3715322432----a-w-c:\windows\SysWow64\nvd3dum.dll
2012-05-15 10:48 . 2011-12-02 14:32818496----a-w-c:\windows\SysWow64\nvumdshim.dll
2012-05-15 10:48 . 2011-12-02 14:322368832----a-w-c:\windows\SysWow64\nvapi.dll
2012-05-15 10:48 . 2011-12-02 14:321738048----a-w-c:\windows\system32\nvdispco64.dll
2012-05-15 10:48 . 2011-12-02 14:321468224----a-w-c:\windows\system32\nvgenco64.dll
2012-05-15 10:48 . 2011-12-01 16:01949056----a-w-c:\windows\system32\nvumdshimx.dll
2012-05-15 10:48 . 2011-12-01 16:01246592----a-w-c:\windows\system32\nvinitx.dll
2012-05-15 10:48 . 2011-12-01 16:01202048----a-w-c:\windows\SysWow64\nvinit.dll
2012-05-15 10:48 . 2011-12-01 16:012741568----a-w-c:\windows\system32\nvapi64.dll
2012-05-15 09:29 . 2011-04-21 15:05889664----a-w-c:\windows\system32\nvvsvc.exe
2012-05-15 09:29 . 2011-04-21 15:05858944----a-w-c:\windows\system32\nv3dappshext.dll
2012-05-15 09:29 . 2011-04-21 15:0563296----a-w-c:\windows\system32\nvshext.dll
2012-05-15 09:29 . 2011-04-21 15:0555616----a-w-c:\windows\system32\nv3dappshextr.dll
2012-05-15 09:29 . 2011-04-21 15:052561856----a-w-c:\windows\system32\nvsvcr.dll
2012-05-15 09:29 . 2011-04-21 15:05118080----a-w-c:\windows\system32\nvmctray.dll
2012-05-15 09:29 . 2011-04-21 15:052621723----a-w-c:\windows\system32\nvcoproc.bin
2012-05-15 09:29 . 2011-04-21 15:053149632----a-w-c:\windows\system32\nvsvc64.dll
2012-05-15 09:28 . 2011-04-21 15:056151488----a-w-c:\windows\system32\nvcpl.dll
2012-05-14 20:51 . 2012-05-14 20:51423744----a-w-c:\windows\SysWow64\nvStreaming.exe
2012-05-04 11:06 . 2012-06-13 09:445559664----a-w-c:\windows\system32\ntoskrnl.exe
2012-05-04 10:03 . 2012-06-13 09:443968368----a-w-c:\windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03 . 2012-06-13 09:443913072----a-w-c:\windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40 . 2012-06-13 09:44209920----a-w-c:\windows\system32\profsvc.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-07-27_15.43.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:54 . 2012-07-30 02:0816384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-07-27 15:4216384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-07-27 15:4232768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-07-30 02:0832768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-07-27 15:4216384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2012-07-30 02:0816384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-11-21 03:09 . 2012-07-30 02:1065306 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-07-30 02:1038754 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2011-12-01 11:14 . 2012-07-27 15:1516944 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-644134914-3384040744-1973889131-1000_UserData.bin
+ 2011-12-01 11:14 . 2012-07-30 02:1016944 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-644134914-3384040744-1973889131-1000_UserData.bin
+ 2011-12-01 16:03 . 2012-07-28 12:5212928 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Bluetooth\bthservsdp.dat
- 2011-12-01 16:03 . 2012-07-27 05:2912928 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Bluetooth\bthservsdp.dat
- 2012-07-27 15:42 . 2012-07-27 15:422048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-07-30 02:07 . 2012-07-30 02:072048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-07-30 02:07 . 2012-07-30 02:072048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-07-27 15:42 . 2012-07-27 15:422048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-07-28 11:41 . 2012-07-28 11:41686792 c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_268_Plugin.exe
+ 2012-07-28 10:37 . 2012-07-28 10:37686792 c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_268_ActiveX.exe
+ 2012-07-28 10:37 . 2012-07-28 10:37466632 c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_268_ActiveX.dll
+ 2012-04-08 13:13 . 2012-07-28 11:41250056 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
- 2012-04-08 13:13 . 2012-07-12 04:56250056 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2011-12-02 17:03 . 2012-07-29 04:19432144 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin
- 2009-07-14 02:36 . 2012-07-26 16:30662532 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-07-29 11:53662532 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-07-29 11:53122328 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2012-07-26 16:30122328 c:\windows\system32\perfc009.dat
+ 2012-07-28 11:41 . 2012-07-28 11:41417992 c:\windows\system32\Macromed\Flash\FlashUtil64_11_3_300_268_Plugin.exe
+ 2012-07-28 10:37 . 2012-07-28 10:37417992 c:\windows\system32\Macromed\Flash\FlashUtil64_11_3_300_268_ActiveX.exe
+ 2012-07-28 10:37 . 2012-07-28 10:37513224 c:\windows\system32\Macromed\Flash\FlashUtil64_11_3_300_268_ActiveX.dll
- 2011-12-02 00:28 . 2012-07-26 04:57180224 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-12-02 00:28 . 2012-07-28 11:41180224 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 05:01 . 2012-07-27 15:41587776 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-07-29 18:01587776 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2012-07-28 11:41 . 2012-07-28 11:419465032 c:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll
+ 2012-07-28 11:41 . 2012-07-28 11:411536712 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_268.exe
- 2011-12-02 00:28 . 2012-07-26 04:572146304 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2011-12-02 00:28 . 2012-07-28 11:412146304 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-07-28 11:412899968 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-07-26 04:572899968 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-12-04 13:10 . 2012-07-29 08:168179540 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-644134914-3384040744-1973889131-1000-8192.dat
- 2011-12-04 13:10 . 2012-07-26 04:358179540 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-644134914-3384040744-1973889131-1000-8192.dat
+ 2012-07-28 11:41 . 2012-07-28 11:4112315336 c:\windows\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaSuite.exe"="c:\program files (x86)\Nokia\Nokia Suite\NokiaSuite.exe" [2012-05-16 1084840]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-01-12 283160]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2011-09-16 115048]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security PackagesREG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-02 136176]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-28 250056]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys [2012-03-01 195584]
R3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [2011-11-14 327168]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2011-07-29 16776]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2011-07-29 9096]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-02-18 1431888]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-02 136176]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-10-12 114304]
R3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [2011-12-09 60416]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2010-12-15 174168]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2012-04-17 273168]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-20 98688]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2011-08-01 45416]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-12-11 1255736]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2008-05-06 14464]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2012-05-15 28992]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2011-03-04 55856]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-12-02 272448]
S1 nvkflt;nvkflt;c:\windows\system32\DRIVERS\nvkflt.sys [2012-05-15 249152]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-17 98208]
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2012-03-01 659976]
S2 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2011-02-02 18656]
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-03-08 135952]
S2 hshld;Hotspot Shield Service;c:\program files (x86)\Hotspot Shield\bin\openvpnas.exe [2012-04-10 542552]
S2 HssWd;Hotspot Shield Monitoring Service;c:\program files (x86)\Hotspot Shield\bin\hsswd.exe [2012-04-02 329544]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-12 13336]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-05-14 382272]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-20 2656280]
S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [2012-04-17 2671376]
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2012-03-01 195584]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2010-06-07 174848]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
S3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\Netwsw00.sys [2012-03-12 11471872]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2011-09-13 95744]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2011-09-13 212992]
S3 nvoclk64;NVIDIA Enthusiasts Platform KDM;c:\windows\system32\DRIVERS\nvoclk64.sys [2009-09-15 42088]
S3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys [2010-07-02 29288]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-29 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-08 11:41]
.
2012-07-29 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-644134914-3384040744-1973889131-1000Core.job
- c:\users\sid\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-06-20 05:01]
.
2012-07-29 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-644134914-3384040744-1973889131-1000UA.job
- c:\users\sid\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-06-20 05:01]
.
2012-07-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-02 09:35]
.
2012-07-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-02 09:35]
.
2012-07-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-644134914-3384040744-1973889131-1000Core.job
- c:\users\sid\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-02 09:48]
.
2012-07-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-644134914-3384040744-1973889131-1000UA.job
- c:\users\sid\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-02 09:48]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-03-30 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-03-30 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-03-30 418840]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2010-12-14 6561384]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-12-10 2186856]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://
www.google.co.in/
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
LSP: c:\program files (x86)\TrafficCompressor\TCompLsp.dll
TCP: DhcpNameServer = 192.168.1.1
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-644134914-3384040744-1973889131-1000\Software\SecuROM\License information*]
"datasecu"=hex:cb,55,f3,07,1a,7d,79,82,19,72,d7,cf,56,05,6f,31,6b,1a,5a,6f,06,
01,19,5e,2d,6f,c5,c7,81,a7,fd,d5,f1,6b,01,11,41,99,f1,ff,7e,31,ff,11,7a,ae,\
"rkeysecu"=hex:88,ac,ab,d8,81,ea,b8,a1,98,8d,51,8e,e9,95,88,3a
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_268_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_268_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\07A7D4FBD98D1D111AD7000A9CA05BF0\7D2F387510089040102000060BECB6AB]
@DACL=(02 0000)
"PatchGUID"=""
"MediaCabinet"=""
"File"="Global_Vba_VbRuntime_f0.1E64E430_36E0_11D2_A794_0060089A724B"
"ComponentVersion"="6.0.89.64"
"ProductVersion"="18.0.55"
"PatchSize"="0"
"PatchAttributes"="0"
"PatchSequence"="0"
"SharedComponent"="0"
"IsFullFile"="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\1B1D70235E082D119BD50006794CED42\7D2F387510089040102000060BECB6AB]
@DACL=(02 0000)
"PatchGUID"=""
"MediaCabinet"=""
"File"="Global_Controls_COMCATDLL_f0.3207D1B0_80E5_11D2_B95D_006097C4DE24"
"ComponentVersion"="4.71.1460.1"
"ProductVersion"="18.0.55"
"PatchSize"="0"
"PatchAttributes"="0"
"PatchSequence"="0"
"SharedComponent"="0"
"IsFullFile"="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\1F16F47424372D111A99000A9CA05BF0\7D2F387510089040102000060BECB6AB]
@DACL=(02 0000)
"PatchGUID"=""
"MediaCabinet"=""
"File"="Global_System_STDOLE_f1.8C0C59A0_7DC8_11D2_B95D_006097C4DE24"
"ComponentVersion"="2.40.4275.1"
"ProductVersion"="18.0.55"
"PatchSize"="0"
"PatchAttributes"="0"
"PatchSequence"="0"
"SharedComponent"="0"
"IsFullFile"="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\269AF799760E1D113969000A9CF0729F\7D2F387510089040102000060BECB6AB]
@DACL=(02 0000)
"PatchGUID"=""
"MediaCabinet"=""
"File"="Global_System_OLEAUT32_f3.8C0C59A0_7DC8_11D2_B95D_006097C4DE24"
"ComponentVersion"="2.40.4275.1"
"ProductVersion"="18.0.55"
"PatchSize"="0"
"PatchAttributes"="0"
"PatchSequence"="0"
"SharedComponent"="0"
"IsFullFile"="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\3178400169C22D11A9790006794C4E25\7D2F387510089040102000060BECB6AB]
@DACL=(02 0000)
"PatchGUID"=""
"MediaCabinet"=""
"File"="Global_System_OLEPRO32_f0.8C0C59A0_7DC8_11D2_B95D_006097C4DE24"
"ComponentVersion"="5.0.4275.1"
"ProductVersion"="18.0.55"
"PatchSize"="0"
"PatchAttributes"="0"
"PatchSequence"="0"
"SharedComponent"="0"
"IsFullFile"="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\5B94A7F282EE3DFAB59EA0B25C612AAD\7D2F387510089040112000060BECB6AB]
@DACL=(02 0000)
"PatchGUID"=""
"MediaCabinet"=""
"File"="_F5A31E7BBC774475A49CF363C6C05AB6.D5955B9CA4DD4C1197BDAB88FAFFCD9E"
"ComponentVersion"="2.2.0.0"
"ProductVersion"="18.0.55"
"PatchSize"="0"
"PatchAttributes"="0"
"PatchSequence"="0"
"SharedComponent"="0"
"IsFullFile"="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\DEE1EA864502FF1657156D9CE8722FBE\7D2F387510089040112000060BECB6AB]
@DACL=(02 0000)
"PatchGUID"=""
"MediaCabinet"=""
"File"="_52A6679D04554A008411F937A937C447.D5955B9CA4DD4C1197BDAB88FAFFCD9E"
"ComponentVersion"="2.2.0.0"
"ProductVersion"="18.0.55"
"PatchSize"="0"
"PatchAttributes"="0"
"PatchSequence"="0"
"SharedComponent"="0"
"IsFullFile"="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-07-30 08:04:00
ComboFix-quarantined-files.txt 2012-07-30 02:34
ComboFix2.txt 2012-07-27 15:45
.
Pre-Run: 38,078,590,976 bytes free
Post-Run: 38,107,848,704 bytes free
.
- - End Of File - - 1A00F7BB7711EE1CE74B8B901BF7A354