ComboFix 09-08-09.03 - BURAQ 08/09/2009 23:10.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1256.966.1033.18.1014.330 [GMT 3:00]
Running from: c:\users\BURAQ\Downloads\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\users\BURAQ\AppData\Roaming\.#
c:\windows\system32\videocore.dll
c:\windows\system32\videoformat.dll
.
((((((((((((((((((((((((( Files Created from 2009-07-09 to 2009-08-09 )))))))))))))))))))))))))))))))
.
2009-08-09 20:20 . 2009-08-09 20:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-08-09 18:20 . 2009-08-09 18:20 -------- d-----w- C:\Hotspot Shield
2009-08-04 16:53 . 1997-07-19 13:55 1347344 ----a-w- c:\windows\system32\Msvbvm50.dll
2009-07-30 12:00 . 2009-07-30 12:00 -------- d-----w- c:\programdata\WindowsSearch
2009-07-22 19:13 . 2009-07-22 19:13 28592 ----a-w- c:\windows\system32\drivers\tap0901.sys
2009-07-21 14:02 . 2009-07-21 14:02 12816 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\wmifw.exe
2009-07-21 14:02 . 2009-07-21 14:02 12816 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\wmiav.exe
2009-07-21 14:02 . 2009-07-21 14:02 12816 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\wmias.exe
2009-07-18 14:44 . 2009-06-15 14:53 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-07-18 14:44 . 2009-06-15 14:52 23552 ----a-w- c:\windows\system32\lpk.dll
2009-07-18 14:44 . 2009-06-15 14:52 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-07-18 14:44 . 2009-06-15 14:51 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-07-18 14:44 . 2009-06-15 12:42 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-07-13 07:15 . 2009-07-13 07:16 -------- d-----w- c:\program files\Error Repair Professional
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-09 19:49 . 2008-12-24 16:34 3992608 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-08-09 19:48 . 2008-12-24 16:34 37512 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-08-09 18:20 . 2009-07-09 02:39 -------- d-----w- c:\program files\Hotspot Shield
2009-08-09 07:17 . 2008-12-24 16:34 -------- d-----w- c:\programdata\Kaspersky Lab
2009-08-08 22:29 . 2008-12-24 16:34 811040 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-08-08 22:29 . 2008-12-24 16:34 5864 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-08-08 22:28 . 2008-12-24 05:10 8524 ----a-w- c:\windows\bthservsdp.dat
2009-08-04 10:31 . 2008-12-24 05:18 159040 ----a-w- c:\users\BURAQ\AppData\Local\GDIPFONTCACHEV1.DAT
2009-08-03 06:54 . 2008-12-24 19:07 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-31 14:56 . 2009-03-21 19:18 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-29 22:22 . 2009-01-21 20:19 -------- d-----w- c:\program files\Messenger Plus! Live
2009-07-21 21:52 . 2009-07-28 19:41 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-28 19:41 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-28 19:41 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-28 19:41 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-21 14:02 . 2009-02-05 14:16 208616 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\avp.exe
2009-07-18 14:49 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-07-18 14:48 . 2008-12-24 18:37 -------- d-----w- c:\programdata\Microsoft Help
2009-07-02 02:34 . 2009-07-02 02:34 33840 ----a-w- c:\windows\system32\drivers\HssDrv.sys
2009-07-01 19:05 . 2009-05-12 21:37 163840 ----a-w- c:\users\BURAQ\AppData\Roaming\GRETECH\GomPlayer\GrLauncherTempSetup.exe
2009-06-27 17:05 . 2008-12-24 19:03 -------- d-----w- c:\program files\Common Files\Real
2009-06-27 17:04 . 2009-06-27 17:04 -------- d-----w- c:\program files\Common Files\xing shared
2009-06-27 17:04 . 2009-04-20 18:15 -------- d-----w- c:\program files\Real
2009-06-25 20:50 . 2009-06-25 20:36 -------- d-----w- c:\program files\Video GIF Converter
2009-06-16 07:09 . 2009-02-25 12:21 -------- d-----w- c:\users\BURAQ\AppData\Roaming\Wildfire
2009-06-15 08:37 . 2009-05-20 19:47 -------- d-----w- c:\programdata\DriverScanner
2009-06-14 18:13 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-06-14 18:13 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-06-14 18:13 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-06-14 18:13 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-06-14 18:13 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-06-14 18:13 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-06-14 18:12 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-06-14 17:59 . 2006-11-02 12:37 37665 ----a-w- c:\windows\Fonts\GlobalUserInterface.CompositeFont
2009-06-12 00:20 . 2009-02-21 15:37 680 ----a-w- c:\users\BURAQ\AppData\Local\d3d9caps.dat
2009-06-02 20:48 . 2009-06-02 20:48 153600 ----a-w- c:\windows\system32\TLBINF32.DLL
2009-05-28 13:15 . 2009-02-25 07:41 604416 ----a-w- c:\windows\system32\TUProgSt.exe
2009-05-20 12:32 . 2008-12-24 16:36 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-05-20 12:32 . 2008-12-24 16:36 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2008-12-26 13:42 . 2008-12-26 10:13 1004 --sha-w- c:\windows\System32\sys_drv.dat
2009-03-25 06:59 . 2007-02-21 19:49 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2009-08-09 18:19 218160 ----a-w- c:\program files\Hotspot Shield\hssie\HssIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-16 815104]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-07-21 208616]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-12-12 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-12-12 106496]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-12-12 81920]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-27 198160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SigmatelSysTrayApp"="sttray.exe" - c:\windows\sttray.exe [2009-03-25 303104]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-2-27 113664]
QuickSet.lnk - c:\windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2008-12-24 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd.dll c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~1\KASPER~1\KASPER~1\adialhk.dll c:\progra~1\KASPER~1\KASPER~1\kloehk.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):5e,1c,d0,f7,1c,ed,c9,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2579951557-3660409174-3374248726-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{36F4FA8B-8B7D-493F-B281-52C40C843F88}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{C2A2CD92-2032-495E-ABF8-8B5FDFA11AF3}c:\\program files\\macromedia\\flash mx\\flash.exe"= UDP:c:\program files\macromedia\flash mx\flash.exe:Flash 6.0 r25
"UDP Query User{89E0BFA3-1640-4B65-9192-01DBCF2DB13F}c:\\program files\\macromedia\\flash mx\\flash.exe"= TCP:c:\program files\macromedia\flash mx\flash.exe:Flash 6.0 r25
"TCP Query User{4B440E8B-4189-458B-8118-3A4421816750}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{3A5491E2-2038-4D43-A045-FFED768C4C77}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{2E5BE3E8-9599-4F0B-AABF-56853221F314}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{39A5254F-29C1-4B0C-A52E-723611FDB441}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{B8F97E61-BE4D-45CD-A010-AC9F4AE8D4A0}c:\\program files\\macromedia\\flash mx\\flash.exe"= UDP:c:\program files\macromedia\flash mx\flash.exe:Flash 6.0 r25
"UDP Query User{FB98AF57-8B2A-4CA7-AF12-A9DED5659530}c:\\program files\\macromedia\\flash mx\\flash.exe"= TCP:c:\program files\macromedia\flash mx\flash.exe:Flash 6.0 r25
"{FB09559E-0CA0-46B5-ACF7-6095B14FD3E7}"= UDP:e:\sthiwv\STSetup.exe:SpeedTouch Home Install Wizard
"{C25A389D-AE69-4ABC-8D85-2AAEA089D075}"= TCP:e:\sthiwv\STSetup.exe:SpeedTouch Home Install Wizard
"{F37C73F4-9DC4-4025-B41C-61EF75D1E397}"= UDP:e:\sthiwv\STSetup.exe:SpeedTouch Home Install Wizard
"{0E1C68C6-522B-4455-A789-7202F8B933B9}"= TCP:e:\sthiwv\STSetup.exe:SpeedTouch Home Install Wizard
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [30/01/08 05:29 ص 33808]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [10/07/08 05:28 ص 20496]
R1 pelmouse;Mouse Suite Driver;c:\windows\System32\drivers\PELMouse.SYS [20/05/09 11:24 م 18944]
R2 HssSrv;Hotspot Shield Routing Service;c:\program files\Hotspot Shield\HssWPR\hsssrv.exe [16/06/09 12:21 ص 331312]
R3 HssDrv;Hotspot Shield Helper Miniport;c:\windows\System32\drivers\HssDrv.sys [02/07/09 05:34 ص 33840]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\System32\drivers\klfltdev.sys [14/03/08 06:02 ص 26640]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [17/11/08 07:40 ص 3668480]
R3 pelps2m;PS/2 Mouse Filter Driver;c:\windows\System32\drivers\pelps2m.sys [20/05/09 11:24 م 40448]
R3 tap0901;TAP-Win32 Adapter V9;c:\windows\System32\drivers\tap0901.sys [22/07/09 10:13 م 28592]
S3 HssTrayService;Hotspot Shield Tray Service;c:\program files\Hotspot Shield\bin\HssTrayService.exe [22/07/09 10:14 م 57640]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-09 c:\windows\Tasks\User_Feed_Synchronization-{F2DE6055-D188-4299-968C-E86E71525E07}.job
- c:\windows\system32\msfeedssync.exe [2009-07-28 20:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.hotspotshield.com/g/?c=h
mStart Page = about:blank
uInternet Settings,ProxyOverride = local
uInternet Settings,ProxyServer = 127.0.0.1:9666
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
.
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.abr"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.ani"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.bmp"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.cur"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.dcr"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.dib"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.emf"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.eps"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.gif"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.icl"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.iff"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jbr"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jfif"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jpe"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jpeg"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jpg"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.kdc"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pbr"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pct"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pic"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pict"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.png"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.psd"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.psp"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspbrush\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pspbrush"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.raw"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.rle"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rw2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.rw2"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.srf"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.tga"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.tif"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.tiff"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.ttc"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.ttf"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.wbm"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.wbmp"
[HKEY_USERS\S-1-5-21-2579951557-3660409174-3374248726-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.wmf"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-08-09 23:23
ComboFix-quarantined-files.txt 2009-08-09 20:23
Pre-Run: 29,782,192,128 bytes free
Post-Run: 29,608,132,608 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=45 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45
294 --- E O F --- 2009-08-06 22:53