ComboFix 11-01-31.01 - mindy 01/31/2011 19:57:18.1.4 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.3839.2543 [GMT -5:00]
Running from: c:\users\mindy\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Outdated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
AV: Microsoft Security Essentials *Disabled/Updated* {BF5CEBDC-F2D3-7540-343C-F0CE11FD6E66}
FW: Kaspersky Internet Security *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D}
SP: Kaspersky Internet Security *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
SP: Microsoft Security Essentials *Disabled/Updated* {043D0A38-D4E9-7ACE-0E8C-CBBC6A7A24DB}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.dll
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.tmp
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\cid.sys
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\CLSV.dll
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\CLSV.exe
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\CLSV.tmp
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\DBOLE.exe
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\ddv.sys
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\delfile.dll
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\dudl.tmp
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\eb.sys
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\eb.tmp
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\energy.drv
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\energy.exe
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\energy.sys
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\exec.exe
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\exec.tmp
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\fix.dll
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\fix.drv
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\FW.drv
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\gid.tmp
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\hymt.exe
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\hymt.sys
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\kernel32.drv
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\pal.exe
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\PE.dll
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\PE.drv
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\PE.sys
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\PE.tmp
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\ppal.exe
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.drv
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.sys
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\sld.dll
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\sld.drv
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\SM.drv
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\snl2w.dll
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\snl2w.drv
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\std.dll
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\tjd.drv
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\tjd.exe
c:\users\mindy\AppData\Roaming\Microsoft\Windows\Recent\tjd.sys
.
((((((((((((((((((((((((( Files Created from 2011-01-01 to 2011-02-01 )))))))))))))))))))))))))))))))
.
2011-02-01 01:02 . 2011-02-01 01:02 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-30 22:04 . 2011-01-30 22:04 388096 ----a-r- c:\users\mindy\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-01-30 22:04 . 2011-01-30 22:04 -------- d-----w- c:\program files (x86)\Trend Micro
2011-01-30 16:54 . 2011-01-30 16:54 -------- d-----w- c:\users\mindy\AppData\Roaming\SUPERAntiSpyware.com
2011-01-30 16:54 . 2011-01-30 16:54 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-01-30 16:54 . 2011-01-30 16:54 -------- d-----w- c:\programdata\!SASCORE
2011-01-30 16:54 . 2011-01-30 17:59 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-01-30 16:44 . 2011-01-30 16:44 -------- d-----w- c:\program files\CCleaner
2011-01-30 07:35 . 2010-10-06 01:26 109240 ----a-w- c:\program files (x86)\Mozilla *Blocked Russian URL*\components\abhelperxpcom.dll
2011-01-30 07:35 . 2010-10-06 01:27 150200 ----a-w- c:\program files (x86)\Mozilla *Blocked Russian URL*\components\kavlinkfilter.dll
2011-01-30 07:33 . 2011-02-01 01:02 -------- d-----w- c:\programdata\Kaspersky Lab
2011-01-30 07:33 . 2011-01-30 07:33 -------- d-----w- c:\program files (x86)\Kaspersky Lab
2011-01-30 07:29 . 2011-01-30 07:29 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2011-01-28 09:34 . 2011-01-13 10:20 7844688 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{362F9319-122B-448E-BA0E-1075F677CA49}\mpengine.dll
2011-01-27 13:56 . 2011-01-27 13:56 -------- d-sh--w- c:\programdata\SIVUGHTP
2011-01-20 17:44 . 2011-01-20 17:44 -------- d-----w- c:\users\mindy\AppData\Roaming\Malwarebytes
2011-01-20 17:44 . 2011-01-20 17:44 -------- d-----w- c:\programdata\Malwarebytes
2011-01-20 17:44 . 2010-12-20 23:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-01-20 17:44 . 2011-01-30 21:33 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-01-20 17:44 . 2010-12-20 23:08 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-16 22:51 . 2011-01-16 22:51 -------- d-sh--w- c:\programdata\PIYIIXFNS
2011-01-16 22:49 . 2011-01-28 02:50 -------- d-sh--w- c:\programdata\76f0d4
2011-01-05 23:35 . 2008-05-08 00:59 99840 ----a-w- c:\windows\system32\Spool\prtprocs\x64\HPZPPLHN.DLL
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 23:53 . 2010-06-24 03:43 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2010-11-10 02:35 . 2010-12-09 13:35 8199504 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7D7E80C4-4068-4C66-8CCC-AC5FD27C62BC}\mpengine.dll
2010-11-04 06:35 . 2010-12-16 02:50 1194496 ----a-w- c:\windows\system32\wininet.dll
2010-11-04 06:31 . 2010-12-16 02:50 57856 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-04 05:52 . 2010-12-16 02:50 978944 ----a-w- c:\windows\SysWow64\wininet.dll
2010-11-04 05:48 . 2010-12-16 02:50 44544 ----a-w- c:\windows\SysWow64\licmgr10.dll
2010-11-04 05:16 . 2010-12-16 02:50 482816 ----a-w- c:\windows\system32\html.iec
2010-11-04 04:41 . 2010-12-16 02:50 386048 ----a-w- c:\windows\SysWow64\html.iec
2010-11-04 04:35 . 2010-12-16 02:50 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2010-11-04 04:08 . 2010-12-16 02:50 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
2010-02-28 04:24 . 2010-02-28 04:24 8327264 ----a-w- c:\program files (x86)\Firefox Setup 3.6.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-01-13 2988784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-03-18 421888]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [2010-11-03 365336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~2\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~2\KASPER~1\KASPER~1\sbhook.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 dump_wmimmc;dump_wmimmc;c:\program files\GALA-NET\Rappelz\GameGuard\dump_wmimmc.sys
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des
R3 UsbGps;LGE CDMA USB GPS NMEA Port;c:\windows\system32\DRIVERS\lgx64gps.sys [2008-11-11 27136]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-02-28 1255736]
S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2010-06-09 11864]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2010-04-22 27736]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-03 22544]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2009-12-02 40832]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\progra~2\KASPER~1\KASPER~1\x64\sbhook64.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Add to Anti-Banner - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
FF - ProfilePath - c:\users\mindy\AppData\Roaming\Mozilla\Firefox\Profiles\9s0gbjlr.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2536667&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Web Search...
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/?ref=hp
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2536667&q=
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Anti-Banner: *Blocked Russian URL* - c:\program files (x86)\Mozilla *Blocked Russian URL*
FF - Ext: Kaspersky URL Advisor: *Blocked Russian URL* - c:\program files (x86)\Mozilla *Blocked Russian URL*
FF - Ext: Castle Age Toolbar: {aac4043a-8832-4abe-9963-35377f30b8e6} - %profile%\extensions\{aac4043a-8832-4abe-9963-35377f30b8e6}
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Personas:
[email protected] - %profile%\extensions\
[email protected]FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: <?xmlversion=1.0?><RDF xmlns=http://www.w3.org/1999/02/22-rdf-syntax-ns# xmlns:em=http://www.mozilla.org/2004/em-rdf#><Description about=urn:mozilla:install-manifest><em:id>{cd994368-1a91-4839-acc9-f8aa8aeb550c}: {cd994368-1a91-4839-acc9-f8aa8aeb550c} - %profile%\extensions\{cd994368-1a91-4839-acc9-f8aa8aeb550c}
FF - Ext: vShare Plugin: vshare@toolbar - %profile%\extensions\vshare@toolbar
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-01-31 20:03:45
ComboFix-quarantined-files.txt 2011-02-01 01:03
Pre-Run: 43,635,773,440 bytes free
Post-Run: 43,136,581,632 bytes free
- - End Of File - - AB824D39D0E3C9E8E7C1747E1CE8164D