ComboFix Log
ComboFix 11-12-16.03 - FAG 12/16/2011 22:34:58.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3062.1577 [GMT -5:00]
Running from: c:\users\FAG\Desktop\ComboFix.exe
AV: AVG Internet Security *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
FW: AVG Firewall *Enabled* {621CC794-9486-F902-D092-0484E8EA828B}
SP: AVG Internet Security *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\FAG\AppData\Roaming\Mozilla\Firefox\Profiles\tadpvum0.default\searchplugins\bing-zugo.xml
.
.
((((((((((((((((((((((((( Files Created from 2011-11-17 to 2011-12-17 )))))))))))))))))))))))))))))))
.
.
2011-12-17 03:48 . 2011-12-17 03:48 -------- d-----w- c:\users\FAG\AppData\Local\temp
2011-12-17 03:48 . 2011-12-17 03:48 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-12-17 03:48 . 2011-12-17 03:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-12-14 22:19 . 2011-11-24 04:25 2342912 ----a-w- c:\windows\system32\win32k.sys
2011-12-14 22:19 . 2011-11-05 04:26 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-14 22:19 . 2011-10-15 05:38 534528 ----a-w- c:\windows\system32\EncDec.dll
2011-12-14 22:19 . 2011-10-26 04:28 38912 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-14 22:19 . 2011-10-26 04:47 3912560 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-12-14 22:19 . 2011-10-26 04:47 3967856 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-14 05:11 . 2011-12-14 05:11 163329 ----a-w- c:\windows\Ahriman's Prophecy Uninstaller.exe
2011-12-14 05:10 . 2011-12-14 05:11 -------- d-----w- c:\program files\Ahriman's Prophecy
2011-12-14 02:40 . 2011-12-14 02:40 -------- d-----w- c:\program files\rpg2003
2011-12-13 22:38 . 2011-12-13 22:38 -------- d-----w- c:\program files\BandiMPEG1
2011-12-08 22:37 . 2011-12-08 22:37 40960 ----a-r- c:\users\FAG\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe
2011-12-08 22:37 . 2011-12-08 22:37 40960 ----a-r- c:\users\FAG\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe
2011-12-08 22:37 . 2011-12-08 22:37 -------- d-----w- c:\program files\Project64 1.6
2011-12-08 02:58 . 2011-12-08 02:58 61440 ----a-r- c:\users\FAG\AppData\Roaming\Microsoft\Installer\{3F6D3F2C-3DBA-4D20-96D6-D5676F7DB642}\NewShortcut2_3F6D3F2C3DBA4D2096D6D5676F7DB642.exe
2011-12-08 02:58 . 2011-12-08 02:58 61440 ----a-r- c:\users\FAG\AppData\Roaming\Microsoft\Installer\{3F6D3F2C-3DBA-4D20-96D6-D5676F7DB642}\NewShortcut21_3F6D3F2C3DBA4D2096D6D5676F7DB642.exe
2011-12-08 02:58 . 2011-12-08 02:58 -------- d-----w- c:\program files\Zenosoft
2011-12-08 02:57 . 2011-12-08 02:57 -------- d-----w- c:\windows\Downloaded Installations
2011-12-08 01:23 . 2011-12-08 01:23 -------- d-----w- c:\windows\lhsp
2011-12-08 01:23 . 2011-12-08 01:23 -------- d-----w- c:\program files\CoolSpeech
2011-12-06 05:43 . 2011-02-19 06:30 805376 ----a-w- c:\windows\system32\FntCache.dll
2011-12-06 05:43 . 2011-02-19 06:30 1076736 ----a-w- c:\windows\system32\DWrite.dll
2011-12-06 05:43 . 2011-02-19 06:30 739840 ----a-w- c:\windows\system32\d2d1.dll
2011-12-01 22:47 . 2011-12-01 22:47 -------- d-----w- c:\windows\en
2011-12-01 22:46 . 2011-12-01 22:46 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-12-01 22:45 . 2011-12-01 22:45 -------- d-----w- c:\windows\PCHEALTH
2011-12-01 22:45 . 2011-12-01 22:46 -------- d-----w- c:\program files\Windows Live
2011-12-01 22:39 . 2011-12-11 02:08 -------- d-----w- c:\users\FAG\AppData\Local\Windows Live
2011-12-01 22:39 . 2011-12-01 22:39 -------- d-----w- c:\program files\Common Files\Windows Live
2011-12-01 21:52 . 2011-12-01 21:52 -------- d-----w- C:\Fraps
2011-11-30 17:45 . 2011-11-30 17:47 -------- d--h--w- c:\windows\msdownld.tmp
2011-11-27 20:12 . 2011-11-27 20:12 -------- d-----w- c:\users\FAG\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
2011-11-27 20:12 . 2011-11-27 20:12 -------- d-----w- c:\users\FAG\AppData\Roaming\Wacom
2011-11-27 20:11 . 2011-11-27 20:12 -------- d-----w- c:\programdata\Wacom
2011-11-27 20:11 . 2011-11-27 20:11 -------- d-----w- c:\program files\Common Files\Adobe AIR
2011-11-27 20:10 . 2011-11-27 20:10 -------- d-----w- c:\users\FAG\AppData\Local\Adobe
2011-11-27 20:09 . 2011-11-27 20:12 -------- d-----w- c:\program files\Bamboo Dock
2011-11-27 20:05 . 2011-11-27 20:05 -------- d-----w- c:\users\FAG\AppData\Roaming\WTablet
2011-11-27 20:05 . 2011-09-08 22:48 1107832 ----a-w- c:\windows\system32\Pen_Touch_Tablet.dll
2011-11-27 20:04 . 2011-09-08 22:49 10752 ----a-w- c:\windows\system32\drivers\wacmoumonitor.sys
2011-11-27 20:03 . 2011-09-08 22:49 11312 ----a-w- c:\windows\system32\drivers\wacommousefilter.sys
2011-11-27 20:02 . 2011-09-08 22:49 14120 ----a-w- c:\windows\system32\drivers\wacomvhid.sys
2011-11-27 20:02 . 2011-09-08 22:48 1152888 ----a-w- c:\windows\system32\WacomMT.dll
2011-11-27 20:02 . 2011-09-08 22:48 1156472 ----a-w- c:\windows\system32\Wintab32.dll
2011-11-27 20:02 . 2011-09-08 22:48 1369464 ----a-w- c:\windows\system32\Pen_Tablet.dll
2011-11-27 20:02 . 2011-11-27 20:05 -------- d-----w- c:\program files\Tablet
2011-11-27 19:50 . 2011-11-27 19:50 -------- d-----w- c:\users\FAG\AppData\Roaming\SYSTEMAX Software Development
2011-11-27 19:50 . 2011-11-27 19:50 -------- d-----w- c:\programdata\SYSTEMAX Software Development
2011-11-27 18:45 . 2011-11-27 18:45 -------- d-----w- c:\program files\WinPcap
2011-11-27 18:44 . 2011-11-27 18:46 -------- d-----w- c:\programdata\Freemake
2011-11-27 18:44 . 2011-11-27 18:44 -------- d-----w- c:\program files\Freemake
2011-11-27 09:41 . 2011-11-27 09:41 -------- d-----w- C:\found.000
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-01 22:44 . 2011-03-28 23:36 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-11-06 03:01 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-10-03 10:06 . 2010-05-25 03:25 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-09-29 16:03 . 2011-11-10 08:08 1290608 ----a-w- c:\windows\system32\drivers\tcpip.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{59c6f12b-f004-43e5-9997-08f2123119b6}]
2011-01-06 04:30 81920 ----a-w- c:\program files\oovootoolbar\oovootoolbarX.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-10-11 20:12 1244040 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-10-11 1244040]
"{59c6f12b-f004-43e5-9997-08f2123119b6}"= "c:\program files\oovootoolbar\oovootoolbarX.dll" [2011-01-06 81920]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CLASSES_ROOT\clsid\{59c6f12b-f004-43e5-9997-08f2123119b6}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-10-11 1244040]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-09-06 20:45 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-09-06 3722416]
"BambooCore"="c:\program files\Bamboo Dock\BambooCore.exe" [2011-09-27 646232]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKLM\~\startupfolder\C:^Users^FAG^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\users\FAG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2011-09-13 03:36 137536 ----atw- c:\users\FAG\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ooVoo.exe]
2011-05-18 13:25 22631608 ----a-w- c:\program files\ooVoo\ooVoo.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-10-29 18:49 249064 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2011-12-16 08:07 4616064 ----a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
2009-05-20 02:16 222504 ----a-w- c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile Device Center]
2007-05-31 14:21 648072 ----a-w- c:\windows\WindowsMobile\wmdc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YouCam Mirror Tray icon]
2009-06-11 17:14 162912 ----a-w- c:\program files\CyberLink\YouCam\YouCamTray.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 FreemakeVideoCapture;FreemakeVideoCapture;c:\program files\Freemake\CaptureLib\CaptureLibService.exe [2011-11-24 8704]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2011-08-21 4178784]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
R3 Synth3dVsc;Synth3dVsc; [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub; [x]
R3 VGPU;VGPU; [x]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2011-09-08 10752]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-11-10 1343400]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-08-11 116608]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-09-06 54616]
S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe [2009-07-14 20992]
S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2011-02-11 35088]
S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2011-09-08 5554552]
S2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2011-09-08 451960]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
S3 XDva391;XDva391;c:\windows\system32\XDva391.sys [x]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-09-28 315392]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - aswMBR
*Deregistered* - dump_wmimmc
*Deregistered* - uwldypow
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HsfXAudioService REG_MULTI_SZ HsfXAudioService
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-16 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4092775245-913444807-781344819-1000Core.job
- c:\users\FAG\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-09-13 03:36]
.
2011-12-17 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4092775245-913444807-781344819-1000UA.job
- c:\users\FAG\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-09-13 03:36]
.
2011-12-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4092775245-913444807-781344819-1000Core.job
- c:\users\FAG\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-07 17:22]
.
2011-12-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4092775245-913444807-781344819-1000UA.job
- c:\users\FAG\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-07 17:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bing.com/?pc=Z015&form=ZGAPHP
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 75.75.76.76 75.75.75.75
FF - ProfilePath - c:\users\FAG\AppData\Roaming\Mozilla\Firefox\Profiles\tadpvum0.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2405280&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/?pc=Z015&form=ZGAPHP
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z015&form=ZGAADF&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
FF - Ext: avast! WebRep:
wrc@avast.com - c:\program files\AVAST Software\Avast\WebRep\FF
FF - Ext: Softonic-Eng7 Community Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - %profile%\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
FF - Ext: LimeWire Toolbar:
toolbar@ask.com - %profile%\extensions\toolbar@ask.com
FF - Ext: ooVooToolbar: {59c6f12b-f004-43e5-9997-08f2123119b6} - %profile%\extensions\{59c6f12b-f004-43e5-9997-08f2123119b6}
FF - Ext: Conduit Engine :
engine@conduit.com - %profile%\extensions\engine@conduit.com
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-12-16 22:58:42
ComboFix-quarantined-files.txt 2011-12-17 03:58
ComboFix2.txt 2011-11-01 23:00
.
Pre-Run: 108,187,795,456 bytes free
Post-Run: 111,487,619,072 bytes free
.
- - End Of File - - CEA3FCB72322470A1BD3CF0E8E30142C