offline
- Pridružio: 15 Sep 2008
- Poruke: 74
|
Combofix log:
ComboFix 09-04-27.02 - Korisnik 27.04.2009 22:47.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.385.1033.18.1023.678 [GMT 2:00]
Running from: c:\documents and settings\Korisnik\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Korisnik\Desktop\CFScript.txt
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated)
FW: ESET Personal firewall *enabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-05-27 to 2009-4-27 )))))))))))))))))))))))))))))))
.
2009-04-27 18:02 . 2009-04-27 18:02 -------- d-----w c:\documents and settings\Korisnik\Application Data\Malwarebytes
2009-04-27 18:02 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-27 18:02 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-27 18:02 . 2009-04-27 18:02 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-27 18:02 . 2009-04-27 18:02 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-25 20:03 . 2009-04-25 20:03 -------- d-----w c:\documents and settings\Korisnik\Application Data\DriverCure
2009-04-25 20:03 . 2009-04-25 20:03 -------- d-----w c:\program files\Common Files\ParetoLogic
2009-04-25 20:03 . 2009-04-27 08:12 -------- d-----w c:\documents and settings\All Users\Application Data\DriverCure
2009-04-25 20:03 . 2009-04-25 20:03 -------- d-----w c:\documents and settings\All Users\Application Data\ParetoLogic
2009-04-24 17:18 . 2009-04-24 17:18 -------- d-s---w c:\documents and settings\Korisnik\UserData
2009-04-21 17:18 . 2009-04-27 16:49 -------- d-----w c:\program files\KaraFun
2009-04-19 20:50 . 2009-04-19 20:50 -------- d-----w c:\program files\mp3DirectCut
2009-04-14 02:19 . 2009-04-14 02:19 41808 ----a-w c:\windows\system32\xfcodec.dll
2009-04-12 19:34 . 2009-04-25 23:41 -------- d-----w c:\documents and settings\Korisnik\Application Data\Skype
2009-04-12 19:34 . 2009-04-12 19:34 -------- d-----r c:\program files\Skype
2009-04-12 19:34 . 2009-04-12 19:34 -------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-04-12 16:47 . 2009-04-12 16:47 -------- d-----w c:\documents and settings\Korisnik\Application Data\Xfire Plus
2009-04-12 16:46 . 2009-04-12 16:46 -------- d-----w c:\program files\Xfire Plus
2009-04-11 18:20 . 2009-04-11 18:34 -------- d-----w c:\documents and settings\Korisnik\Application Data\BitTorrent
2009-04-11 18:20 . 2009-04-11 18:20 -------- d-----w c:\documents and settings\Korisnik\Local Settings\Application Data\DNA
2009-04-11 18:20 . 2009-04-15 17:27 -------- d-----w c:\program files\DNA
2009-04-11 18:20 . 2009-04-15 17:35 -------- d-----w c:\documents and settings\Korisnik\Application Data\DNA
2009-04-11 18:20 . 2009-04-11 18:20 -------- d-----w c:\program files\BitTorrent
2009-04-11 18:20 . 2009-04-11 18:20 -------- d-----w c:\program files\AskSearch
2009-04-11 18:20 . 2009-04-13 12:32 -------- d-----w c:\program files\AskBarDis
2009-04-09 12:12 . 2009-04-09 12:12 -------- d-----w c:\program files\Orban
2009-04-01 18:27 . 2009-04-01 18:27 -------- d-----w c:\documents and settings\Korisnik\Application Data\TeamViewer
2009-04-01 18:27 . 2009-04-01 18:27 -------- d-----w c:\program files\TeamViewer
2009-04-01 18:26 . 2009-04-01 18:26 -------- d-----w c:\documents and settings\Korisnik\temp
2009-03-30 14:54 . 2009-03-30 14:54 -------- d-----w c:\documents and settings\Korisnik\Application Data\Yahoo!
2009-03-30 14:54 . 2009-03-30 14:54 -------- d-----w c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-03-30 10:42 . 2009-03-30 10:42 -------- d-----w c:\documents and settings\Korisnik\Local Settings\Application Data\Google
2009-03-30 10:42 . 2009-04-04 10:28 -------- d-----w c:\program files\Google
2009-03-30 10:36 . 2009-03-30 10:36 -------- d-----w c:\program files\Common Files\SWF Studio
2009-03-30 10:34 . 2009-03-30 10:34 -------- d-----w c:\program files\Yahoo!
2009-03-30 10:33 . 2009-03-30 10:33 -------- d-----w c:\program files\The Weather Channel FW
2009-03-29 22:05 . 2009-04-04 10:50 -------- d-----w c:\program files\SpeedFan
2009-03-28 21:58 . 2009-03-28 22:07 -------- d-----w c:\windows\NV26002748.TMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-26 22:50 . 2009-03-10 16:22 189072 ----a-w c:\windows\system32\PnkBstrB.exe
2009-04-26 21:48 . 2009-03-10 16:22 138920 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-04-25 10:04 . 2009-02-27 22:40 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-24 11:03 . 2009-02-28 10:46 -------- d-----w c:\program files\Xfire
2009-04-20 11:19 . 2009-02-27 16:32 15800 ----a-w c:\documents and settings\Korisnik\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-15 17:27 . 2009-03-07 15:11 163712 ----a-w c:\windows\system32\drivers\vidstub.sys
2009-04-06 17:16 . 2009-03-21 00:52 -------- d-----w c:\program files\Java
2009-03-31 11:52 . 2009-02-28 10:48 -------- d-----w c:\program files\Winamp
2009-03-29 19:03 . 2009-02-27 16:26 86627 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-26 19:39 . 2009-03-26 19:39 -------- d-----w c:\program files\IrfanView
2009-03-25 22:51 . 2009-03-25 22:51 -------- d-----w c:\program files\Common Files\Adobe AIR
2009-03-25 22:51 . 2009-02-28 10:54 -------- d-----w c:\program files\Common Files\Adobe
2009-03-23 23:41 . 2009-03-23 23:41 -------- d-----w c:\program files\Opera
2009-03-12 19:36 . 2009-03-12 19:35 -------- d-----w c:\program files\Hamachi
2009-03-12 19:35 . 2009-03-12 19:35 25280 ----a-w c:\windows\system32\drivers\hamachi.sys
2009-03-11 09:33 . 2009-03-11 09:29 122771 ----a-w c:\windows\hpoins14.dat
2009-03-11 09:33 . 2009-03-11 09:33 -------- d-----w c:\program files\Hewlett-Packard
2009-03-11 09:33 . 2009-03-11 09:33 -------- d-----w c:\program files\Common Files\Hewlett-Packard
2009-03-11 09:31 . 2009-03-11 09:31 -------- d-----w c:\program files\HP
2009-03-10 16:22 . 2009-03-10 16:22 75064 ----a-w c:\windows\system32\PnkBstrA.exe
2009-03-10 16:18 . 2009-03-10 16:18 2999 ----a-w c:\program files\Common Files\unins000.dat
2009-03-10 16:18 . 2009-03-10 16:18 728858 ----a-w c:\program files\Common Files\unins000.exe
2009-03-10 15:13 . 2009-02-27 16:58 -------- d-----w c:\program files\ESET
2009-03-09 03:19 . 2009-03-21 00:52 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-09 00:26 . 2009-03-09 00:25 -------- d-----w c:\program files\Windows Live
2009-03-09 00:25 . 2009-03-09 00:25 -------- d-----w c:\program files\Microsoft
2009-03-09 00:25 . 2009-03-09 00:25 -------- d-----w c:\program files\Windows Live SkyDrive
2009-03-09 00:24 . 2009-03-09 00:24 -------- d-----w c:\program files\Common Files\Windows Live
2009-03-07 15:11 . 2009-03-07 15:11 -------- d-----w c:\program files\Common Files\Stardock
2009-03-07 15:11 . 2009-03-07 15:11 -------- d-----w c:\program files\Stardock
2009-03-07 15:02 . 2009-03-07 15:02 -------- d-----w c:\program files\FileSubmit
2009-03-06 23:45 . 2009-03-06 23:45 98304 ----a-w c:\windows\system32\CmdLineExt.dll
2009-03-03 18:43 . 2009-03-03 18:36 -------- d-----w c:\program files\Ahead
2009-03-03 18:42 . 2009-03-03 18:42 -------- d-----w c:\program files\Common Files\LightScribe
2009-03-03 18:39 . 2009-03-03 18:39 -------- d-----w c:\program files\Common Files\Nero
2009-03-03 18:36 . 2009-03-03 18:36 -------- d-----w c:\program files\Common Files\Ahead
2009-03-03 14:27 . 2009-03-03 14:27 -------- d-----w c:\program files\Common Files\Adobe Systems Shared
2009-02-28 17:04 . 2009-02-28 16:40 -------- d-----w c:\program files\Counter-Strike 1.6
2009-02-28 10:19 . 2009-02-28 10:19 -------- d-----w c:\program files\Opera 10 Preview
2009-02-28 09:57 . 2009-02-28 09:57 -------- d-----w c:\program files\Marvell
2009-02-27 23:03 . 2009-02-27 22:36 -------- d-----w c:\program files\Common Files\InstallShield
2009-02-27 22:40 . 2009-02-27 22:40 -------- d-----w c:\program files\Realtek
2009-02-27 22:37 . 2009-02-27 22:37 -------- d-----w c:\program files\Multimedia Combo Set
2009-02-27 22:36 . 2009-02-27 22:36 2466816 ----a-w c:\program files\Multimedia Combo Set.msi
2009-02-27 22:36 . 2009-02-27 22:36 4632 ----a-w c:\program files\0x0409.ini
2009-02-27 16:33 . 2009-02-27 16:33 664 -c--a-w c:\windows\system32\d3d9caps.dat
2009-02-27 16:33 . 2009-02-27 16:33 552 -c--a-w c:\windows\system32\d3d8caps.dat
2009-02-27 16:27 . 2009-02-27 16:27 -------- d-----w c:\program files\microsoft frontpage
2009-02-27 16:27 . 2001-08-23 10:00 67 --sha-w c:\windows\Fonts\desktop.ini
2009-02-27 16:24 . 2009-02-27 16:24 21640 -c--a-w c:\windows\system32\emptyregdb.dat
2009-02-16 22:17 . 2009-02-27 23:03 453152 ----a-w c:\windows\system32\NVUNINST.EXE
2009-02-06 17:52 . 2009-02-06 17:52 49504 ----a-w c:\windows\system32\sirenacm.dll
.
------- Sigcheck -------
[-] 2006-05-02 08:55 1580544 6E266AAF4168B3569A330C61AB01F6B4 c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( [Link mogu videti samo ulogovani korisnici] )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-27 20:42 . 2009-04-27 20:42 16384 c:\windows\Temp\Perflib_Perfdata_46c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-09-29 15:24 325000 ----a-w c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-29 325000]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-29 325000]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nodenable"="c:\program files\eset\nodenable.exe" [2008-09-23 326823]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-06-10 1447168]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" - c:\windows\system32\hdashcut.exe [2005-10-13 61952]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-02-18 1657376]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-09-21 86016]
"AlcWzrd"="ALCWZRD.EXE" - c:\windows\ALCWZRD.EXE [2005-09-21 2807808]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^Korisnik^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Korisnik\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\Counter-Strike 1.6\\hl.exe"=
"d:\\Program Files\\Counter-Strike 1.6\\hl.exe"=
"c:\\Program Files\\Opera 10 Preview\\opera.exe"=
"d:\\Program Files\\Nova mapa\\kucni_server\\samp-server.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-04-06 38496]
R3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\DRIVERS\s115bus.sys [2007-04-23 83208]
R3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s115mgmt.sys [2007-04-23 100488]
R3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s115obex.sys [2007-04-23 98568]
S0 BootScreen;BootScreen; [x]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
Contents of the 'Scheduled Tasks' folder
2009-04-26 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2009-01-13 14:59]
2009-04-26 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2009-01-13 14:59]
.
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
uSearchURL,(Default) = [Link mogu videti samo ulogovani korisnici]
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-04-27 22:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ìê*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\œEÆ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\t§*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\T¯*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\d¯*•‘|\Comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\<´*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\¸*•‘|\Comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\*º*•‘|\Comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ º*•‘|\Comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\üº*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\€¼*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ô¾*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\¬Á*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ŒÃ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\èÃ*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Æ*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\(È*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\,È*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ÈÈ*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\üÈ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\°É*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Ì*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\,Î*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\4Î*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\HÎ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\HÏ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Ð*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\xÐ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\€Ð*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ Ñ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\XÑ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\lÒ*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ÄÓ*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\„Ô*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Ô*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\TÕ*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\lÕ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\pÕ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\dÖ*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\€×*•‘|\COMCTL32.DLL]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\×*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\À×*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ü×*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ Ø*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\<Ø*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ÜØ*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Ù*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\”Ù*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\¬Ù*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ÈÙ*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Ú*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Û*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\(Û*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\HÛ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\„Û*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ØÛ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\|Ü*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\„Ü*•‘|\Comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Ü*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ØÝ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\àÝ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\dÞ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Œß*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Ðà*•‘|\COMCTL32.DLL]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ã*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ã*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\$ã*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\(ã*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\¤ã*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\°ã*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ÜäÉ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Hå*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\*è*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Lè*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Àè*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\*é*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\$ê*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Lë*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\àë*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\øì*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Dí*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\|í*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\XîÆ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Äï*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\,ðò*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\,ðý*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\,ðþ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Ìðâ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Ìðë*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Ìðò*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Ìðý*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Ìðþ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Ðð*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ðñ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\lô*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\œô*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\$õ*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\üõþ*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ö*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ö*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\œöý*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Øö*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\÷*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Ü÷*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ù*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\tù*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\ú*•‘|\COMCTL32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\MUILanguages\FileVersions\Xû*•‘|\comctl32.dll]
"MUIVer"=hex(b):84,08,54,0b,00,00,06,00
"000600000b540a59"=dword:00000000
[HKEY_USERS\S-1-5-21-1935655697-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{CBC127BB-A410-B7B7-77EB-CB684F63E03A}*]
"hakcgobphbebbjka"=hex:6a,61,70,62,62,6b,70,6e,62,6d,69,6e,64,6a,61,64,6f,6b,
61,63,00,22
"iaaimddlihgipgeigh"=hex:63,61,67,63,64,69,00,00
"iaecipekjimdlcnmmo"=hex:6a,61,61,63,6d,6a,6d,6e,67,70,68,6d,66,6d,61,64,68,6c,
70,61,00,22
.
Completion time: 2009-04-27 22:49
ComboFix-quarantined-files.txt 2009-04-27 20:48
ComboFix2.txt 2009-04-27 20:43
ComboFix3.txt 2009-04-27 19:58
Pre-Run: 31.455.813.632 bytes free
Post-Run: 31.452.549.120 bytes free
526
-----------------------------------------------------------------------------------------------------------------------------
Sada idem i ovo sa USB
|