Você está na página 1de 16

ComboFix 10-08-07.01 - Administrator 08/08/2010 9:53.1.

2 - x86
Microsoft® Windows Vista Home Premium 6.0.6001.1.1252.1.1033.18.2812.1301 [GMT 1:
00]
Running from: c:\users\Administrator\Downloads\ComboFix.exe
AV: Symantec AntiVirus *On-access scanning disabled* (Updated) {FB06448E-52B8-49
3A-90F3-E43226D3305C}
SP: Symantec AntiVirus *disabled* (Updated) {6C85A515-B91D-4D2B-AF18-40984A4A849
3}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))
)))))))))))))))))))))))))))))
.
c:\users\Administrator\AppData\Roaming\Hoihy
c:\users\Administrator\AppData\Roaming\Hoihy\ywum.exe
.
((((((((((((((((((((((((( Files Created from 2010-07-08 to 2010-08-08 )))))))
))))))))))))))))))))))))
.
2010-08-08 09:01 . 2010-08-08 09:01 -------- d-----w- c:\users
\Default\AppData\Local\temp
2010-08-08 08:51 . 2010-08-08 08:52 -------- d-----w- C:\32788
R22FWJFW
2010-08-08 07:50 . 2010-08-08 07:50 0 ----a-w- c:\windows\nsreg
.dat
2010-08-08 07:50 . 2010-08-08 07:50 -------- d-----w- c:\users
\Administrator\AppData\Local\Mozilla
2010-08-08 02:45 . 2010-08-08 02:45 -------- d-----w- c:\progr
am files\Microsoft CAPICOM 2.1.0.2
2010-08-08 02:35 . 2010-02-12 10:48 293376 ----a-w- c:\windows\syste
m32\browserchoice.exe
2010-08-08 02:33 . 2010-08-08 02:33 -------- d-----w- c:\users
\Default\AppData\Local\Microsoft Help
2010-08-08 02:18 . 2008-06-20 01:14 105016 ----a-w- c:\windows\syste
m32\PresentationCFFRasterizerNative_v0300.dll
2010-08-08 02:18 . 2008-06-20 01:14 97800 ----a-w- c:\windows\syste
m32\infocardapi.dll
2010-08-08 02:18 . 2008-06-20 01:14 43544 ----a-w- c:\windows\syste
m32\PresentationHostProxy.dll
2010-08-08 02:18 . 2008-06-20 01:14 11264 ----a-w- c:\windows\syste
m32\icardres.dll
2010-08-08 02:18 . 2008-06-20 01:14 622080 ----a-w- c:\windows\syste
m32\icardagt.exe
2010-08-08 02:18 . 2008-06-20 01:14 781344 ----a-w- c:\windows\syste
m32\PresentationNative_v0300.dll
2010-08-08 02:18 . 2008-06-20 01:14 326160 ----a-w- c:\windows\syste
m32\PresentationHost.exe
2010-08-08 02:08 . 2008-07-27 18:03 96760 ----a-w- c:\windows\syste
m32\dfshim.dll
2010-08-08 02:08 . 2008-07-27 18:03 282112 ----a-w- c:\windows\syste
m32\mscoree.dll
2010-08-08 02:08 . 2008-07-27 18:03 41984 ----a-w- c:\windows\syste
m32\netfxperf.dll
2010-08-08 02:08 . 2008-07-27 18:03 158720 ----a-w- c:\windows\syste
m32\mscorier.dll
2010-08-08 02:08 . 2008-07-27 18:03 83968 ----a-w- c:\windows\syste
m32\mscories.dll
2010-08-08 02:04 . 2010-02-20 23:39 24064 ----a-w- c:\windows\syste
m32\nshhttp.dll
2010-08-08 02:04 . 2010-02-20 23:37 31232 ----a-w- c:\windows\syste
m32\httpapi.dll
2010-08-08 02:04 . 2010-02-20 21:18 411136 ----a-w- c:\windows\syste
m32\drivers\http.sys
2010-08-08 02:03 . 2010-08-08 02:03 -------- d-----w- c:\progr
am files\MSXML 4.0
2010-08-07 07:05 . 2009-12-28 12:35 11776 ----a-w- c:\windows\syste
m32\tsbyuv.dll
2010-08-07 07:05 . 2009-12-28 12:32 22528 ----a-w- c:\windows\syste
m32\msyuv.dll
2010-08-07 07:05 . 2009-12-28 12:32 31744 ----a-w- c:\windows\syste
m32\msvidc32.dll
2010-08-07 07:05 . 2009-12-28 12:32 13312 ----a-w- c:\windows\syste
m32\msrle32.dll
2010-08-07 07:05 . 2009-12-28 12:31 50176 ----a-w- c:\windows\syste
m32\iyuv_32.dll
2010-08-07 07:05 . 2009-12-28 12:32 123904 ----a-w- c:\windows\syste
m32\msvfw32.dll
2010-08-07 07:05 . 2009-12-28 12:31 82944 ----a-w- c:\windows\syste
m32\mciavi32.dll
2010-08-07 07:05 . 2009-12-28 12:28 91136 ----a-w- c:\windows\syste
m32\avifil32.dll
2010-08-07 07:05 . 2009-12-28 12:28 65024 ----a-w- c:\windows\syste
m32\avicap32.dll
2010-08-07 07:03 . 2008-09-10 03:40 1334272 ----a-w- c:\windows\syste
m32\msxml6.dll
2010-08-07 07:03 . 2009-08-10 13:05 351232 ----a-w- c:\windows\syste
m32\WSDApi.dll
2010-08-07 07:02 . 2009-10-19 14:27 156672 ----a-w- c:\windows\syste
m32\t2embed.dll
2010-08-07 07:02 . 2009-12-11 12:07 301568 ----a-w- c:\windows\syste
m32\drivers\srv.sys
2010-08-07 07:02 . 2009-12-11 12:07 98304 ----a-w- c:\windows\syste
m32\drivers\srvnet.sys
2010-08-07 07:01 . 2008-10-22 03:57 241152 ----a-w- c:\windows\syste
m32\PortableDeviceApi.dll
2010-08-07 07:01 . 2009-08-14 16:29 104960 ----a-w- c:\windows\syste
m32\netiohlp.dll
2010-08-07 07:01 . 2009-08-14 14:16 9728 ----a-w- c:\windows\syste
m32\TCPSVCS.EXE
2010-08-07 07:01 . 2009-08-14 14:16 17920 ----a-w- c:\windows\syste
m32\ROUTE.EXE
2010-08-07 07:01 . 2009-08-14 14:16 11264 ----a-w- c:\windows\syste
m32\MRINFO.EXE
2010-08-07 07:01 . 2009-08-14 14:16 27136 ----a-w- c:\windows\syste
m32\NETSTAT.EXE
2010-08-07 07:01 . 2009-08-14 14:16 19968 ----a-w- c:\windows\syste
m32\ARP.EXE
2010-08-07 07:01 . 2009-08-14 14:16 8704 ----a-w- c:\windows\syste
m32\HOSTNAME.EXE
2010-08-07 07:01 . 2009-08-14 14:16 10240 ----a-w- c:\windows\syste
m32\finger.exe
2010-08-07 07:01 . 2009-08-14 16:29 17920 ----a-w- c:\windows\syste
m32\netevent.dll
2010-08-07 07:00 . 2009-07-11 19:32 513024 ----a-w- c:\windows\syste
m32\wlansvc.dll
2010-08-07 07:00 . 2009-07-11 19:32 302592 ----a-w- c:\windows\syste
m32\wlansec.dll
2010-08-07 07:00 . 2009-07-11 19:32 293376 ----a-w- c:\windows\syste
m32\wlanmsm.dll
2010-08-07 07:00 . 2009-07-11 19:29 127488 ----a-w- c:\windows\syste
m32\L2SecHC.dll
2010-08-07 06:59 . 2009-09-10 17:30 213504 ----a-w- c:\windows\syste
m32\msv1_0.dll
2010-08-07 06:58 . 2010-01-29 16:21 738304 ----a-w- c:\windows\syste
m32\inetcomm.dll
2010-08-07 06:58 . 2010-02-23 11:32 212992 ----a-w- c:\windows\syste
m32\drivers\mrxsmb10.sys
2010-08-07 06:58 . 2010-02-23 11:32 78848 ----a-w- c:\windows\syste
m32\drivers\mrxsmb20.sys
2010-08-07 06:58 . 2010-02-23 11:32 105984 ----a-w- c:\windows\syste
m32\drivers\mrxsmb.sys
2010-08-07 06:57 . 2009-06-10 12:11 2868224 ----a-w- c:\windows\syste
m32\mf.dll
2010-08-07 06:57 . 2010-02-18 14:49 3598216 ----a-w- c:\windows\syste
m32\ntkrnlpa.exe
2010-08-07 06:57 . 2010-02-18 14:49 3545992 ----a-w- c:\windows\syste
m32\ntoskrnl.exe
2010-08-07 06:55 . 2008-12-06 04:42 376832 ----a-w- c:\windows\syste
m32\winhttp.dll
2010-08-07 06:55 . 2010-04-05 16:07 67072 ----a-w- c:\windows\syste
m32\asycfilt.dll
2010-08-07 06:54 . 2010-03-04 18:54 430080 ----a-w- c:\windows\syste
m32\vbscript.dll
2010-08-07 06:54 . 2009-07-17 14:35 71680 ----a-w- c:\windows\syste
m32\atl.dll
2010-08-07 06:53 . 2008-10-21 05:25 296960 ----a-w- c:\windows\syste
m32\gdi32.dll
2010-08-07 06:53 . 2010-04-16 16:05 28672 ----a-w- c:\windows\syste
m32\Apphlpdm.dll
2010-08-07 06:53 . 2010-04-16 14:17 4240384 ----a-w- c:\windows\syste
m32\GameUXLegacyGDFs.dll
2010-08-07 06:52 . 2010-04-23 13:55 2048 ----a-w- c:\windows\syste
m32\tzres.dll
2010-08-07 06:51 . 2008-06-06 03:27 562176 ----a-w- c:\windows\syste
m32\msdtcprx.dll
2010-08-07 06:51 . 2008-06-06 03:27 38912 ----a-w- c:\windows\syste
m32\xolehlp.dll
2010-08-07 06:51 . 2009-06-10 12:12 160256 ----a-w- c:\windows\syste
m32\wkssvc.dll
2010-08-07 06:50 . 2009-06-04 12:34 2066432 ----a-w- c:\windows\syste
m32\mstscax.dll
2010-08-07 06:50 . 2008-09-05 05:14 1191936 ----a-w- c:\windows\syste
m32\msxml3.dll
2010-08-07 06:48 . 2010-05-26 16:16 34304 ----a-w- c:\windows\syste
m32\atmlib.dll
2010-08-07 06:48 . 2010-05-26 14:25 289792 ----a-w- c:\windows\syste
m32\atmfd.dll
2010-08-07 06:48 . 2009-10-19 14:24 72704 ----a-w- c:\windows\syste
m32\fontsub.dll
2010-08-07 06:48 . 2009-06-15 15:20 10240 ----a-w- c:\windows\syste
m32\dciman32.dll
2010-08-07 06:46 . 2009-04-23 12:42 636928 ----a-w- c:\windows\syste
m32\localspl.dll
2010-08-07 06:46 . 2008-10-29 06:29 2927104 ----a-w- c:\windows\explo
rer.exe
2010-08-07 06:45 . 2009-06-15 15:24 175104 ----a-w- c:\windows\syste
m32\wdigest.dll
2010-08-07 06:45 . 2009-06-15 15:24 270848 ----a-w- c:\windows\syste
m32\schannel.dll
2010-08-07 06:45 . 2009-06-15 15:23 1256448 ----a-w- c:\windows\syste
m32\lsasrv.dll
2010-08-07 06:45 . 2009-06-15 15:21 499712 ----a-w- c:\windows\syste
m32\kerberos.dll
2010-08-07 06:45 . 2009-06-15 18:20 439896 ----a-w- c:\windows\syste
m32\drivers\ksecdd.sys
2010-08-07 06:45 . 2009-06-15 15:24 72704 ----a-w- c:\windows\syste
m32\secur32.dll
2010-08-07 06:45 . 2009-06-15 12:57 9728 ----a-w- c:\windows\syste
m32\lsass.exe
2010-08-07 06:44 . 2009-03-03 04:40 499200 ----a-w- c:\windows\syste
m32\wbem\WmiPrvSD.dll
2010-08-07 06:44 . 2009-03-03 04:39 551424 ----a-w- c:\windows\syste
m32\rpcss.dll
2010-08-07 06:44 . 2009-03-03 04:36 615424 ----a-w- c:\windows\syste
m32\wbem\fastprox.dll
2010-08-07 06:44 . 2009-03-03 02:16 247296 ----a-w- c:\windows\syste
m32\wbem\WmiPrvSE.exe
2010-08-07 06:44 . 2009-03-03 04:40 129024 ----a-w- c:\windows\syste
m32\wbem\WmiDcPrv.dll
2010-08-07 06:44 . 2009-03-03 04:39 26112 ----a-w- c:\windows\syste
m32\printfilterpipelineprxy.dll
2010-08-07 06:44 . 2009-03-03 03:04 666624 ----a-w- c:\windows\syste
m32\printfilterpipelinesvc.exe
2010-08-07 06:44 . 2009-03-03 04:39 183296 ----a-w- c:\windows\syste
m32\sdohlp.dll
2010-08-07 06:44 . 2009-03-03 04:37 98304 ----a-w- c:\windows\syste
m32\iasrecst.dll
2010-08-07 06:44 . 2009-03-03 04:37 54784 ----a-w- c:\windows\syste
m32\iasads.dll
2010-08-07 06:44 . 2009-03-03 04:37 44032 ----a-w- c:\windows\syste
m32\iasdatastore.dll
2010-08-07 06:44 . 2009-03-03 02:38 17408 ----a-w- c:\windows\syste
m32\iashost.exe
2010-08-07 06:43 . 2010-02-18 14:49 898952 ----a-w- c:\windows\syste
m32\drivers\tcpip.sys
2010-08-07 06:43 . 2010-02-18 14:11 190464 ----a-w- c:\windows\syste
m32\iphlpsvc.dll
2010-08-07 06:43 . 2010-02-18 11:52 25088 ----a-w- c:\windows\syste
m32\drivers\tunnel.sys
2010-08-07 06:41 . 2010-04-16 16:10 1314816 ----a-w- c:\windows\syste
m32\quartz.dll
2010-08-07 06:41 . 2009-03-17 03:38 13824 ----a-w- c:\windows\syste
m32\apilogen.dll
2010-08-07 06:41 . 2009-03-17 03:38 24064 ----a-w- c:\windows\syste
m32\amxread.dll
2010-08-07 06:40 . 2008-08-28 03:40 425472 ----a-w- c:\windows\syste
m32\PhotoMetadataHandler.dll
2010-08-07 06:40 . 2008-08-28 03:40 712704 ----a-w- c:\windows\syste
m32\WindowsCodecs.dll
2010-08-07 06:40 . 2008-08-28 03:40 347136 ----a-w- c:\windows\syste
m32\WindowsCodecsExt.dll
2010-08-07 06:40 . 2008-09-18 04:56 125952 ----a-w- c:\windows\syste
m32\wersvc.dll
2010-08-07 06:40 . 2008-09-18 04:56 147456 ----a-w- c:\windows\syste
m32\Faultrep.dll
2010-08-07 06:39 . 2008-08-12 03:39 443392 ----a-w- c:\windows\syste
m32\win32spl.dll
2010-08-07 06:39 . 2009-07-14 13:00 313344 ----a-w- c:\windows\syste
m32\wmpdxm.dll
2010-08-07 06:38 . 2010-01-25 08:35 523776 ----a-w- c:\windows\syste
m32\RMActivate_isv.exe
2010-08-07 06:38 . 2010-01-25 08:34 511488 ----a-w- c:\windows\syste
m32\RMActivate.exe
2010-08-07 06:38 . 2010-01-25 12:48 472576 ----a-w- c:\windows\syste
m32\secproc_isv.dll
2010-08-07 06:38 . 2010-01-25 12:48 472064 ----a-w- c:\windows\syste
m32\secproc.dll
2010-08-07 06:38 . 2010-01-25 08:35 346624 ----a-w- c:\windows\syste
m32\RMActivate_ssp_isv.exe
2010-08-07 06:38 . 2010-01-25 08:34 347136 ----a-w- c:\windows\syste
m32\RMActivate_ssp.exe
2010-08-07 06:38 . 2010-01-25 12:48 151040 ----a-w- c:\windows\syste
m32\secproc_ssp_isv.dll
2010-08-07 06:38 . 2010-01-25 12:48 151040 ----a-w- c:\windows\syste
m32\secproc_ssp.dll
2010-08-07 06:38 . 2010-01-25 12:45 329216 ----a-w- c:\windows\syste
m32\msdrm.dll
2010-08-07 06:37 . 2008-06-23 01:59 996352 ----a-w- c:\windows\syste
m32\WMNetMgr.dll
2010-08-07 06:37 . 2008-06-23 01:58 94720 ----a-w- c:\windows\syste
m32\logagent.exe
2010-08-07 06:36 . 2009-09-04 12:24 61440 ----a-w- c:\windows\syste
m32\msasn1.dll
2010-08-07 06:36 . 2009-04-02 12:37 604672 ----a-w- c:\windows\syste
m32\WMSPDMOD.DLL
2010-08-07 06:35 . 2009-09-10 15:21 310784 ----a-w- c:\windows\syste
m32\unregmp2.exe
2010-08-07 06:35 . 2009-07-14 12:59 4096 ----a-w- c:\windows\syste
m32\dxmasf.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))
)))))))))))))))))))))))))))))))
.
2010-08-08 07:57 . 2009-01-28 06:34 -------- d-----w- c:\users
\Administrator\AppData\Roaming\Pyqa
2010-08-08 03:38 . 2008-11-03 17:18 75832 ----a-w- c:\users\Adminis
trator\AppData\Local\GDIPFONTCACHEV1.DAT
2010-08-08 03:32 . 2010-06-22 01:01 12 ----a-w- c:\windows\bthse
rvsdp.dat
2010-08-08 03:31 . 2006-11-02 11:18 -------- d-----w- c:\progr
am files\Windows Mail
2010-08-08 03:11 . 2008-11-03 18:25 -------- d-----w- c:\progr
amdata\Microsoft Help
2010-08-08 03:06 . 2008-11-03 18:13 -------- d-----w- c:\progr
am files\Microsoft Works
2010-07-27 17:44 . 2008-11-03 18:46 588472 ----a-w- c:\windows\syste
m32\ezsvc7x.dll
2010-07-18 20:10 . 2008-11-03 17:54 -------- d-----w- c:\progr
amdata\WildTangent
2010-07-02 21:48 . 2008-11-03 17:37 -------- d-----w- c:\progr
amdata\Symantec
2010-07-02 21:47 . 2010-07-02 21:45 -------- d-----w- c:\progr
am files\Common Files\Symantec Shared
2010-07-02 21:47 . 2010-07-02 21:45 -------- d-----w- c:\progr
am files\Symantec
2010-07-02 21:47 . 2010-07-02 21:47 805 ----a-w- c:\windows\syste
m32\drivers\SYMEVENT.INF
2010-07-02 21:47 . 2010-07-02 21:47 8014 ----a-w- c:\windows\syste
m32\drivers\SYMEVENT.CAT
2010-07-02 21:47 . 2010-07-02 21:47 109744 ----a-w- c:\windows\syste
m32\drivers\SYMEVENT.SYS
2010-07-02 21:45 . 2010-07-02 21:45 -------- d-----w- c:\progr
am files\Symantec AntiVirus
2010-07-02 21:38 . 2008-11-03 17:37 -------- d-----w- c:\progr
amdata\Norton
2010-07-02 01:14 . 2010-07-02 01:07 -------- d-----w- c:\users
\Administrator\AppData\Roaming\vlc
2010-07-02 01:00 . 2010-07-02 01:00 -------- d-----w- c:\progr
am files\VideoLAN
2010-07-02 00:59 . 2010-07-02 00:59 -------- d-----w- c:\users
\Administrator\AppData\Roaming\Leadertech
2010-06-22 17:07 . 2010-06-22 15:28 -------- d-----w- c:\users
\Administrator\AppData\Roaming\CyberLink
2010-06-22 15:15 . 2010-06-22 15:14 -------- d-----w- c:\users
\Administrator\AppData\Roaming\hewlett-packard
2010-06-22 15:14 . 2008-11-03 18:55 -------- d-----w- c:\progr
am files\SMINST
2010-06-22 15:07 . 2010-06-22 15:07 -------- d-----w- c:\users
\Administrator\AppData\Roaming\HP TCS
2010-06-22 15:07 . 2006-11-02 12:37 -------- d-----w- c:\progr
am files\Windows Sidebar
2010-06-22 15:05 . 2010-06-22 15:05 0 --sha-r- c:\windows\syste
m32\drivers\103C_HP_cNB_TouchSmart tx2 Notebook PC_Y5335KV_0U_QCNF9111LC5_E50354
3-032_4A_I3045_SQuanta_V16.16_F.26_T091211_WV3-1_L409_M2813_J320_7AMD_8F31_92.20
_#100621_N10EC8168;14E4432B_(NJ430EA#ABU)_XMOBILE_CN10_Z_2Rev 1.MRK
2010-06-22 01:59 . 2010-06-22 01:59 -------- d-----w- c:\users
\Administrator\AppData\Roaming\ATI
2010-06-22 01:59 . 2010-06-22 01:59 -------- d-----w- c:\progr
amdata\ATI
2010-06-22 01:59 . 2010-06-22 01:59 -------- d-----w- c:\users
\Administrator\AppData\Roaming\DigitalPersona
2010-06-22 01:54 . 2008-11-03 17:35 -------- d-----w- c:\progr
amdata\Hewlett-Packard
2010-06-22 01:54 . 2010-06-22 01:54 -------- d-----w- c:\users
\Administrator\AppData\Roaming\Macrovision
2010-06-22 01:54 . 2010-06-22 01:54 -------- d-----w- c:\progr
am files\DigitalPersona
2010-06-22 01:54 . 2010-06-22 01:54 -------- d-----w- c:\progr
amdata\Macrovision
2010-06-22 01:54 . 2008-11-03 17:19 -------- d-----w- c:\progr
am files\Hewlett-Packard
2010-06-22 01:53 . 2010-06-22 01:53 -------- d-----w- c:\progr
am files\Common Files\muvee Technologies
2010-06-22 01:53 . 2010-06-22 01:53 -------- d-----w- c:\progr
am files\muvee Technologies
2010-06-22 01:52 . 2010-06-22 01:52 53319 ----a-w- c:\programdata\T
emp\{D36DD326-7280-11D8-97C8-000129760CBE}\PostBuild.exe
2010-06-22 01:52 . 2008-11-03 17:34 -------- d--h--w- c:\progr
am files\InstallShield Installation Information
2010-06-22 01:52 . 2010-06-22 01:52 53319 ----a-w- c:\programdata\T
emp\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}\PostBuild.exe
2010-06-22 01:51 . 2010-06-22 01:51 36864 ----a-w- c:\programdata\T
emp\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}\PostBuild.exe
2010-06-22 01:50 . 2010-06-22 01:50 36864 ----a-w- c:\programdata\T
emp\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}\PostBuild.exe
2010-06-22 01:50 . 2010-06-22 01:50 53319 ----a-w- c:\programdata\T
emp\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}\PostBuild.exe
2010-06-22 01:49 . 2008-11-03 18:35 -------- d-----w- c:\progr
amdata\CyberLink
2010-06-22 01:49 . 2008-11-03 18:35 36864 ----a-w- c:\programdata\T
emp\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\PostBuild.exe
2010-06-22 01:48 . 2010-06-22 01:48 36864 ----a-w- c:\programdata\T
emp\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\PostBuild.exe
2010-06-22 01:46 . 2010-06-22 01:46 36864 ----a-w- c:\programdata\T
emp\{67626E09-5366-4480-8F1E-93FADF50CA15}\PostBuild.exe
2010-06-22 01:44 . 2010-06-22 01:44 36864 ----a-w- c:\programdata\T
emp\{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}\PostBuild.exe
2010-06-22 01:42 . 2010-06-22 01:43 36864 ----a-w- c:\programdata\T
emp\{DCCAD079-F92C-44DA-B258-624FC6517A5A}\PostBuild.exe
2010-06-22 01:42 . 2010-06-22 01:42 -------- d-----w- c:\progr
am files\Common Files\LightScribe
2010-06-22 01:41 . 2010-06-22 01:41 0 ----a-w- c:\windows\ativp
srm.bin
2010-06-22 01:16 . 2010-06-22 01:16 -------- d-----w- c:\progr
am files\WIDCOMM
2010-06-22 01:15 . 2010-06-22 01:15 -------- d-----w- c:\progr
am files\N-trig
2010-06-22 01:15 . 2010-06-22 01:15 0 ---ha-w- c:\windows\syste
m32\drivers\Msft_User_NtrigDigitizerUSB_01_05_00.Wdf
2010-06-22 01:15 . 2010-06-22 01:15 0 ---ha-w- c:\windows\syste
m32\drivers\Msft_Kernel_WinUSB_01007.Wdf
2010-06-22 01:14 . 2010-06-22 01:14 -------- d-----w- c:\progr
am files\AMD
2010-06-22 01:13 . 2010-06-22 01:13 -------- d-----w- c:\progr
am files\Broadcom
2010-06-22 01:13 . 2010-06-22 01:13 6656 ----a-w- c:\windows\syste
m32\bcmwlrc.dll
2010-06-22 01:13 . 2010-06-22 01:13 87328 ----a-w- c:\windows\syste
m32\bcmwlcoi.dll
2010-06-22 01:13 . 2010-06-22 01:13 3813376 ----a-w- c:\windows\syste
m32\bcmihvsrv.dll
2010-06-22 01:13 . 2010-06-22 01:13 3506176 ----a-w- c:\windows\syste
m32\bcmihvui.dll
2010-06-22 01:13 . 2010-06-22 01:13 1326584 ----a-w- c:\windows\syste
m32\drivers\BCMWL6.SYS
2010-06-22 01:12 . 2010-06-22 01:11 -------- d-----w- c:\progr
am files\Realtek
2010-06-22 01:11 . 2010-06-22 01:11 319456 ----a-w- c:\windows\DIFxA
PI.dll
2010-06-22 01:11 . 2010-06-22 01:11 -------- d--h--w- c:\progr
am files\Temp
2010-06-22 01:10 . 2010-06-22 01:10 -------- d-----w- c:\progr
am files\DIFX
2010-06-22 01:10 . 2010-06-22 01:10 -------- d-----w- c:\progr
am files\Fingerprint Sensor
2010-06-22 01:10 . 2010-06-22 01:10 -------- d-----w- c:\progr
am files\Motorola
2010-06-22 01:09 . 2010-06-22 01:09 0 ---ha-w- c:\windows\syste
m32\drivers\Msft_Kernel_SynTP_01000.Wdf
2010-06-22 01:09 . 2010-06-22 01:09 -------- d-----w- c:\progr
am files\Synaptics
2010-06-22 01:08 . 2010-06-22 01:06 -------- d-----w- c:\progr
am files\ATI Technologies
2010-06-22 01:06 . 2010-06-22 01:06 -------- d-----w- c:\progr
am files\ATI
2010-06-22 01:06 . 2010-06-22 01:06 10134 ----a-r- c:\users\Adminis
trator\AppData\Roaming\Microsoft\Installer\{AD8777EC-B62C-A010-76D2-27C1BF4239BA
}\ARPPRODUCTICON.exe
2010-06-22 01:04 . 2008-11-03 17:16 680 ----a-w- c:\users\Adminis
trator\AppData\Local\d3d9caps.dat
2008-11-03 18:55 . 2008-11-03 18:41 8192 --sha-w- c:\windows\Users
\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))
)))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\programdata\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-07-12 2
26904]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScri
beControlPanel.exe" [2008-06-09 2363392]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2008-10
-01 972080]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872
080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
[2008-08-01 61440]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-06-20 1316136]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2008-09-23 1208320
]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2008-09-24 6335008
]
"NtrigApplet"="c:\program files\N-trig\N-trig Software Bundle\NtrigApplet.exe" [
2008-10-04 2256896]
"DVDAgent"="c:\program files\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2008-09-26
1148200]
"TSMAgent"="c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [200
8-10-30 1160488]
"CLMLServer for HP TouchSmart"="c:\program files\Hewlett-Packard\TouchSmart\Medi
a\Kernel\CLML\CLMLSvc.exe" [2008-10-30 189736]
"TVAgent"="c:\program files\Hewlett-Packard\Media\TV\TVAgent.exe" [2008-09-25 20
6120]
"UCam_Menu"="c:\program files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartM
enu.exe" [2008-06-14 210216]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2008
-10-21 914224]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartM
enu.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMe
nu.exe" [2008-10-07 210216]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-07-15 814144]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1
008184]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.
exe" [2008-09-05 206128]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_s
l.exe" [2008-06-12 34672]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMe
nu.exe" [2008-06-14 210216]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUISt
artMenu.exe" [2008-06-14 210216]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-0
6-10 144784]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HP
HC_Scheduler.exe" [2008-06-16 75008]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [200
7-05-09 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HP
WAMain.exe" [2008-04-15 488752]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-11-22 10
7112]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-11-28 134808]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-6-1
9 727592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.s
ys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVi
rus]
"DisableMonitoring"=dword:00000001
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Int
ernet Security\Engine\16.0.0.125\ccSvcHst.exe [x]
R3 DIRECTIO;DIRECTIO;z:\burnintestpro\DirectIo.sys [x]
R3 EraserUtilDrv10631;EraserUtilDrv10631;c:\program files\Common Files\Symantec
Shared\EENGINE\EraserUtilDrv10631.sys [x]
R3 EraserUtilDrv11010;EraserUtilDrv11010;c:\program files\Common Files\Symantec
Shared\EENGINE\EraserUtilDrv11010.sys [x]
R3 SavRoam;SavRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2006-11-28 1
22008]
S2 {55662437-DA8C-40c0-AADA-2C816A897A49};{55662437-DA8C-40c0-AADA-2C816A897A49}
;c:\program files\Hewlett-Packard\Media\DVD\000.fcl [2008-09-26 59376]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERT
Srv.exe [2008-07-15 81920]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.
exe [2008-01-21 21504]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SM
INST\BLService.exe [2008-10-06 365952]
S2 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files\Hewlett-Packa
rd\Media\TV\Kernel\TV\TVCapSvc.exe [2008-09-25 296320]
S2 TVSched;TV Task Scheduler (TVTS);c:\program files\Hewlett-Packard\Media\TV\Ke
rnel\TV\TVSched.exe [2008-09-25 116096]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\
Com4QLBEx.exe [2008-09-08 193840]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2008-09-04 54
784]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symante
c Shared\EENGINE\EraserUtilRebootDrv.sys [2010-06-17 102448]
S3 NtrigDigitizerUSBLowerFilter;N-trig HID Tablet Digitizer KMDF Filter Driver;c
:\windows\system32\DRIVERS\NtrigDigitizerUSBLowerFilter.sys [2008-07-27 5632]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [20
08-05-29 22072]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSv
cs
ezSharedSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D
85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 17:14 451872 ----a-w- c:\program files\Common Files\Li
ghtScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-08-01 c:\windows\Tasks\HPCeeScheduleForAdministrator.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-11-03 19:34]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=
91&bd=Pavilion&pf=cnnb
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Soft
ware\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Softw
are\btsendto_ie.htm
FF - ProfilePath - c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profil
es\97i67bie.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - prefs.js: network.proxy.type - 0
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors",
true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.l
u", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.n
u", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.n
z", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.x
n--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.x
n--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.x
n--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.x
n--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.t
el", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-gene
ric-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type",
5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.co
unt", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.si
ze", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeout
Secs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", fals
e);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled",
true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl
.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl
.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl
.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl
.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{97
2ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.prop
erties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{97
2ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/brows
er.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update
.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugin
s.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugin
s.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugin
s.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugin
s.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugin
s.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-{A923347E-9C51-6689-3785-A08575E71E91} - c:\users\Administrator\AppData
\Roaming\Hoihy\ywum.exe

**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http:/
/www.gmer.net
Rootkit scan 2010-08-08 10:02
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.0.0.125\ccSvc
Hst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet
Security\Engine\16.0.0.125\diMaster.dll\" /prefetch:1"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816
A897A49}]
"ImagePath"="\??\c:\program files\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.asf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASF"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.asx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASX"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AU"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.avi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.avi"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.cda\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.CDA"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.m1v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.M2V\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.M3U"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.MOD\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.mp2v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP3"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.mpe\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.mpv2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.rmi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AU"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WAV"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.wax\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WAX"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.wm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASF"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMA"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.wmd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMD"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.wms\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMS"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMV"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.wmx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASX"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.wmz\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMZ"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.wpl\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WPL"
[HKEY_USERS\S-1-5-21-2166689169-3893746836-3979649406-500\Software\Microsoft\Win
dows\CurrentVersion\Explorer\FileExts\.wvx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WVX"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E
}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX
.exe,-101"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E
}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E
}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E
}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6A
F30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6A
F30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6A
F30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-
08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(748)
c:\windows\system32\DPPWDFLT.dll
- - - - - - - > 'Explorer.exe'(5604)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
c:\windows\system32\btmmhook.dll
c:\program files\DigitalPersona\Bin\DpoSet.dll
.
Completion time: 2010-08-08 10:07:53
ComboFix-quarantined-files.txt 2010-08-08 09:07
Pre-Run: 257,767,477,248 bytes free
Post-Run: 257,770,754,048 bytes free
- - End Of File - - 7D4F217E417DD5702BF2D59E39CDA910

Você também pode gostar