ComboFix 11-07-08.03 - Administrator 07/08/2011 22:51:34.3.4 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.3510.2123 [GMT -4:00]
Running from: c:\users\Administrator.DELLIMAGELT\Desktop\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AV: Vexira Antivirus Professional *Disabled/Updated* {23EEBC0C-807F-7CD1-F670-11B63CF63BB9}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{ac4107df-a5cd-4abe-95a0-acf933bdb6e1}
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{ac4107df-a5cd-4abe-95a0-acf933bdb6e1}\chrome.manifest
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{ac4107df-a5cd-4abe-95a0-acf933bdb6e1}\chrome\xulcache.jar
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{ac4107df-a5cd-4abe-95a0-acf933bdb6e1}\defaults\preferences\xulcache.js
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{ac4107df-a5cd-4abe-95a0-acf933bdb6e1}\install.rdf
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{ad467c1d-1b8a-4cfc-9044-45837f10b4f1}
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{ad467c1d-1b8a-4cfc-9044-45837f10b4f1}\chrome.manifest
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{ad467c1d-1b8a-4cfc-9044-45837f10b4f1}\chrome\xulcache.jar
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{ad467c1d-1b8a-4cfc-9044-45837f10b4f1}\defaults\preferences\xulcache.js
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{ad467c1d-1b8a-4cfc-9044-45837f10b4f1}\install.rdf
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{d9f65a27-ddaf-413e-83bf-8e4efcb37afc}
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{d9f65a27-ddaf-413e-83bf-8e4efcb37afc}\chrome.manifest
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{d9f65a27-ddaf-413e-83bf-8e4efcb37afc}\chrome\xulcache.jar
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{d9f65a27-ddaf-413e-83bf-8e4efcb37afc}\defaults\preferences\xulcache.js
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{d9f65a27-ddaf-413e-83bf-8e4efcb37afc}\install.rdf
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{e4450701-dcf3-465a-88fa-f6e970d5c345}
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{e4450701-dcf3-465a-88fa-f6e970d5c345}\chrome.manifest
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{e4450701-dcf3-465a-88fa-f6e970d5c345}\chrome\xulcache.jar
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{e4450701-dcf3-465a-88fa-f6e970d5c345}\defaults\preferences\xulcache.js
c:\users\516\AppData\Roaming\Mozilla\Firefox\Profiles\r3o80w56.default\extensions\{e4450701-dcf3-465a-88fa-f6e970d5c345}\install.rdf
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{ac4107df-a5cd-4abe-95a0-acf933bdb6e1}
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{ac4107df-a5cd-4abe-95a0-acf933bdb6e1}\chrome.manifest
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{ac4107df-a5cd-4abe-95a0-acf933bdb6e1}\chrome\xulcache.jar
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{ac4107df-a5cd-4abe-95a0-acf933bdb6e1}\defaults\preferences\xulcache.js
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{ac4107df-a5cd-4abe-95a0-acf933bdb6e1}\install.rdf
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{ad467c1d-1b8a-4cfc-9044-45837f10b4f1}
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{ad467c1d-1b8a-4cfc-9044-45837f10b4f1}\chrome.manifest
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{ad467c1d-1b8a-4cfc-9044-45837f10b4f1}\chrome\xulcache.jar
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{ad467c1d-1b8a-4cfc-9044-45837f10b4f1}\defaults\preferences\xulcache.js
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{ad467c1d-1b8a-4cfc-9044-45837f10b4f1}\install.rdf
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{d9f65a27-ddaf-413e-83bf-8e4efcb37afc}
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{d9f65a27-ddaf-413e-83bf-8e4efcb37afc}\chrome.manifest
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{d9f65a27-ddaf-413e-83bf-8e4efcb37afc}\chrome\xulcache.jar
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{d9f65a27-ddaf-413e-83bf-8e4efcb37afc}\defaults\preferences\xulcache.js
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{d9f65a27-ddaf-413e-83bf-8e4efcb37afc}\install.rdf
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{e4450701-dcf3-465a-88fa-f6e970d5c345}
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{e4450701-dcf3-465a-88fa-f6e970d5c345}\chrome.manifest
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{e4450701-dcf3-465a-88fa-f6e970d5c345}\chrome\xulcache.jar
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{e4450701-dcf3-465a-88fa-f6e970d5c345}\defaults\preferences\xulcache.js
c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\extensions\{e4450701-dcf3-465a-88fa-f6e970d5c345}\install.rdf
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{ac4107df-a5cd-4abe-95a0-acf933bdb6e1}
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{ac4107df-a5cd-4abe-95a0-acf933bdb6e1}\chrome.manifest
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{ac4107df-a5cd-4abe-95a0-acf933bdb6e1}\chrome\xulcache.jar
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{ac4107df-a5cd-4abe-95a0-acf933bdb6e1}\defaults\preferences\xulcache.js
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{ac4107df-a5cd-4abe-95a0-acf933bdb6e1}\install.rdf
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{ad467c1d-1b8a-4cfc-9044-45837f10b4f1}
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{ad467c1d-1b8a-4cfc-9044-45837f10b4f1}\chrome.manifest
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{ad467c1d-1b8a-4cfc-9044-45837f10b4f1}\chrome\xulcache.jar
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{ad467c1d-1b8a-4cfc-9044-45837f10b4f1}\defaults\preferences\xulcache.js
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{ad467c1d-1b8a-4cfc-9044-45837f10b4f1}\install.rdf
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{d9f65a27-ddaf-413e-83bf-8e4efcb37afc}
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{d9f65a27-ddaf-413e-83bf-8e4efcb37afc}\chrome.manifest
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{d9f65a27-ddaf-413e-83bf-8e4efcb37afc}\chrome\xulcache.jar
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{d9f65a27-ddaf-413e-83bf-8e4efcb37afc}\defaults\preferences\xulcache.js
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{d9f65a27-ddaf-413e-83bf-8e4efcb37afc}\install.rdf
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{e4450701-dcf3-465a-88fa-f6e970d5c345}
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{e4450701-dcf3-465a-88fa-f6e970d5c345}\chrome.manifest
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{e4450701-dcf3-465a-88fa-f6e970d5c345}\chrome\xulcache.jar
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{e4450701-dcf3-465a-88fa-f6e970d5c345}\defaults\preferences\xulcache.js
c:\users\administrator\AppData\Roaming\Mozilla\Firefox\Profiles\moahyg9w.default\extensions\{e4450701-dcf3-465a-88fa-f6e970d5c345}\install.rdf
.
.
((((((((((((((((((((((((( Files Created from 2011-06-09 to 2011-07-09 )))))))))))))))))))))))))))))))
.
.
2011-07-09 02:59 . 2011-07-09 02:59 -------- d-----w- c:\users\open\AppData\Local\temp
2011-07-09 02:59 . 2011-07-09 02:59 -------- d-----w- c:\users\mmeyer\AppData\Local\temp
2011-07-09 02:59 . 2011-07-09 02:59 -------- d-----w- c:\users\magnolia sc\AppData\Local\temp
2011-07-09 02:59 . 2011-07-09 02:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-09 02:59 . 2011-07-09 02:59 -------- d-----w- c:\users\administrator\AppData\Local\temp
2011-07-09 02:59 . 2011-07-09 02:59 -------- d-----w- c:\users\516\AppData\Local\temp
2011-07-09 02:59 . 2011-07-09 02:59 -------- d-----w- c:\users\_sjtp_tech\AppData\Local\temp
2011-06-27 21:18 . 2011-06-27 21:18 1152 ----a-w- c:\windows\system32\windrv.sys
2011-06-27 21:18 . 2011-07-08 05:59 -------- d-----w- c:\program files\SpyNoMore
2011-06-19 15:38 . 2011-04-21 21:56 16432 ----a-w- c:\windows\system32\lsdelete.exe
2011-06-19 04:52 . 2011-06-19 04:52 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-18 20:57 . 2011-06-18 20:57 -------- d-----w- c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Malwarebytes
2011-06-18 20:56 . 2011-05-29 13:11 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-18 20:56 . 2011-06-18 20:56 -------- d-----w- c:\programdata\Malwarebytes
2011-06-18 20:56 . 2011-06-18 20:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-06-18 20:56 . 2011-05-29 13:11 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-13 11:44 . 2011-06-13 11:44 365056 ----a-w- c:\windows\system32\AmRes_fi32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-09 02:13 . 2010-11-06 17:50 0 ----a-w- c:\users\Administrator.DELLIMAGELT\AppData\Local\WavXMapDrive.bat
2011-07-07 20:56 . 2010-12-27 21:42 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-05-17 18:30 . 2010-10-26 18:08 0 ----a-w- c:\users\open\AppData\Local\WavXMapDrive.bat
2011-05-17 00:00 . 2011-05-17 00:00 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{03D4E038-9A50-4F3F-9817-4140E13498A0}]
2011-06-13 11:44 365056 ----a-w- c:\windows\System32\AmRes_fi32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnabledUnlockedFDEIconOverlay]
@="{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}"
[HKEY_CLASSES_ROOT\CLSID\{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}]
2010-03-29 17:45 62832 ----a-w- c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UninitializedFdeIconOverlay]
@="{CF08DA3E-C97D-4891-A66B-E39B28DD270F}"
[HKEY_CLASSES_ROOT\CLSID\{CF08DA3E-C97D-4891-A66B-E39B28DD270F}]
2010-03-29 17:45 62832 ----a-w- c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-06-04 292208]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2010-05-25 495708]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-04-26 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-04-26 175640]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-04-26 169496]
"Broadcom Wireless Manager UI"="c:\program files\Dell\DW WLAN Card\WLTRAY.exe" [2010-02-01 5249024]
"DellControlPoint"="c:\program files\Dell\Dell ControlPoint\Dell.ControlPoint.exe" [2009-11-02 657920]
"WavXMgr"="c:\program files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe" [2010-07-21 147840]
"USCService"="c:\program files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe" [2010-06-22 34232]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-12-29 140520]
"SMART Board Service"="c:\program files\SMART Technologies\SMART Product Drivers\SMARTBoardService.exe" [2010-07-15 5350288]
"SMART SNMP Agent"="c:\program files\SMART Technologies\SMART Product Drivers\SMARTSNMPAgent.exe" [2010-07-15 1662352]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"VBSysTrayProf"="c:\program files\Vexira Antivirus\Professional\Bin\vbsystry.exe" [2010-05-26 385976]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"MeUiHelper"="c:\program files\GenevaLogic\Vision\XL\meuihlp.exe" [2007-08-21 83192]
"MeControlDL"="c:\program files\genevalogic\Vision\XL\MeSuAx.exe" [2007-08-21 328952]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2009-07-22 83336]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-27 421160]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
"SNM"="c:\program files\SpyNoMore\SNM.exe" [2010-07-12 1067984]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2009-8-26 2684256]
Dell ControlPoint System Manager.lnk - c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe [2010-2-8 1327472]
SMART Board Tools.lnk - c:\program files\SMART Technologies\SMART Product Drivers\SMARTBoardTools.exe [2010-7-15 12375952]
TdmNotify.lnk - c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmNotify.exe [2010-3-29 132456]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 DPS32;Diagnostic Policy Service ;c:\windows\system32\wdc32.exe [x]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-27 136176]
R2 InstallFilterService;FF Install Filter Service;c:\program files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe [2010-01-10 60928]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-27 136176]
R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2011-06-28 2151640]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-05-29 39984]
R3 rimspci;rimspci;c:\windows\system32\DRIVERS\rimspe86.sys [2010-03-21 48640]
R3 rixdpcie;rixdpcie;c:\windows\system32\DRIVERS\rixdpe86.sys [2010-03-21 38912]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-26 1343400]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-12-03 64288]
S0 stdflt;Disk Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdfltn.sys [2010-01-18 17072]
S0 VBRec;VBRec;c:\windows\System32\Drivers\VBRec.Sys [2010-05-18 20352]
S1 MENET;MENET;c:\windows\system32\Drivers\MENET.SYS [2007-08-21 50424]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\aestsrv.exe [2010-05-25 81920]
S2 ATService;AuthenTec Fingerprint Service;c:\program files\Fingerprint Sensor\AtService.exe [2010-05-10 1803584]
S2 BrcmMgmtAgent;Broadcom Management Agent;c:\program files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe [2009-11-04 114688]
S2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\Dell\Dell ControlPoint\DCPButtonSvc.exe [2009-11-20 278304]
S2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe [2010-02-08 386928]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640]
S2 MeSuWTS;Vision WTS Helper;c:\program files\GenevaLogic\Vision\XL\mesuwts.exe [2007-08-21 107768]
S2 risdpcie;risdpcie;c:\windows\system32\DRIVERS\risdpe86.sys [2010-03-21 59904]
S2 VAServProf;Vexira Antivirus Professional;c:\program files\Vexira Antivirus\Professional\Bin\vbcmserv.exe [2010-05-19 97592]
S2 VBShld;VBShld;c:\windows\system32\Drivers\VBShld.Sys [2010-05-18 156112]
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [2010-01-18 42672]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2010-02-26 132480]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-02-02 232960]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-05-29 22712]
S3 meddmrr;meddmrr;c:\windows\system32\DRIVERS\meddmrr.sys [2007-08-21 10488]
S3 mekbd;mekbd;c:\windows\system32\Drivers\mekbd.sys [2010-10-26 12800]
S3 memice;memice;c:\windows\system32\Drivers\memice.sys [2010-10-26 11264]
S3 SMARTMouseFilterx86;HID-compliant mouse;c:\windows\system32\DRIVERS\SMARTMouseFilterx86.sys [2010-06-15 11048]
S3 SMARTVHidMini2000x86;SMART HID Device;c:\windows\system32\DRIVERS\SMARTVHidMini2000x86.sys [2010-06-15 14120]
S3 SMARTVTabletPCx86;SMART Virtual TabletPC;c:\windows\system32\DRIVERS\SMARTVTabletPCx86.sys [2010-06-15 13440]
S3 VBEngNT;VBEngNT;c:\windows\system32\Drivers\VBEngNT.Sys [2010-05-13 237664]
S3 VBFilter;VBFilter;c:\windows\system32\Drivers\VBFilter.Sys [2010-05-18 27424]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - VBCoreNT.0
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-27 21:38]
.
2011-07-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-27 21:38]
.
2011-07-08 c:\windows\Tasks\Norton Security Scan for Administrator.job
- c:\program files\Norton Security Scan\Engine\3.0.0.103\Nss.exe [2011-02-18 07:25]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyServer = http=127.0.0.1:64404
uInternet Settings,ProxyOverride = <local>;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1 71.250.0.12
FF - ProfilePath - c:\users\Administrator.DELLIMAGELT\AppData\Roaming\Mozilla\Firefox\Profiles\erd168px.default\
FF - prefs.js: network.proxy.type - 0
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VBCoreNT.0]
"ImagePath"="\Device\HarddiskVolume3\Program Files\Vexira Antivirus\Professional\Temp\e6ab0uci.vbt"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,96,b5,e7,98,e7,6f,f1,40,a6,56,96,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,96,b5,e7,98,e7,6f,f1,40,a6,56,96,\
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.3G2"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.3GP"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.3G2"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.3GP"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AAC\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ADTS"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADT\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ADTS"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADTS\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ADTS"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASF"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASX"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AU"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AVI"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.CDA"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cdda\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.cdda"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ipa\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.ipa"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ipg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.ipg"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ipsw\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.ipsw"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itdb\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.itdb"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ite\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.ite"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itl\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.itl"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itlp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.itlp"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itls\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.itls"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itms\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.itms"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itpc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.itpc"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2t\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.M2TS"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2ts\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.M2TS"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.m3u"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u8\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m3u8"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.M4A"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4b\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m4b"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4p\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m4p"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4r\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m4r"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP4"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mod\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MOV"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP3"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP3"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP4"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP4"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mts\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.M2TS"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcast\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.pcast"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.pls"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AU"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ts\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.TTS"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tts\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.TTS"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WAV"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wave\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.wave"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WAX"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASF"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMA"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMD"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMS"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMV"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASX"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmz\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMZ"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpl\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WPL"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WVX"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-2644167271-439061571-2009282644-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.glcx\{656E6547-6176-6F4C-6769-63204C696331}* ]
"{03105F08-1C06-7704-7661-7204706F6060}"=hex:00,00,00,00,da,07,0a,00,02,00,1a,
00,12,00,04,00,1b,00,b6,03,1e,00,00,00,1f,1f,1f,1f,da,07,0a,00,02,00,1a,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-07-08 23:01:21
ComboFix-quarantined-files.txt 2011-07-09 03:01
ComboFix2.txt 2011-06-22 21:04
.
Pre-Run: 104,409,784,320 bytes free
Post-Run: 104,770,523,136 bytes free
.
- - End Of File - - 0D2FF8A69C006A387A7F3571FC0F478B