ComboFix 11-04-06.03 - Anthony 07/04/2011 9:54.1.4 - x86 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.3071.2269 [GMT 1:00] Running from: c:\users\Anthony\Desktop\ComboFix.exe AV: Kaspersky Internet Security *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06} FW: Kaspersky Internet Security *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D} SP: Kaspersky Internet Security *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Install.exe c:\program files\Mozilla Firefox\extensions\{1CE11043-9A15-4207-A565-0C94C42D590D} c:\programdata\Microsoft\Network\Downloader\qmgr0.dat c:\programdata\Microsoft\Network\Downloader\qmgr1.dat c:\users\Anthony\AppData\Local\{19375093-FDA9-4759-98DD-C504E8F59F61} c:\users\Anthony\AppData\Local\{19375093-FDA9-4759-98DD-C504E8F59F61}\chrome.manifest c:\users\Anthony\AppData\Local\{19375093-FDA9-4759-98DD-C504E8F59F61}\chrome\content\_cfg.js c:\users\Anthony\AppData\Local\{19375093-FDA9-4759-98DD-C504E8F59F61}\chrome\content\overlay.xul c:\users\Anthony\AppData\Local\{19375093-FDA9-4759-98DD-C504E8F59F61}\install.rdf c:\users\Anthony\AppData\Local\uyuyesog.dll c:\users\Anthony\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Antimalware Doctor.lnk c:\users\Anthony\AppData\Roaming\Microsoft\Windows\Start Menu\Antimalware Doctor.lnk c:\users\Anthony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antimalware Doctor c:\users\Anthony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antimalware Doctor\Antimalware Doctor.lnk c:\users\Anthony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antimalware Doctor\Uninstall.lnk c:\users\Anthony\AppData\Roaming\SystemProc c:\windows\system32\null0.19709441460635302.exe . ----- BITS: Possible infected sites ----- . hxxp://wlxindex . ((((((((((((((((((((((((( Files Created from 2011-03-07 to 2011-04-07 ))))))))))))))))))))))))))))))) . . 2011-04-07 08:52 . 2011-04-07 08:52 -------- d-----w- C:\32788R22FWJFW 2011-04-07 08:42 . 2011-04-07 08:42 -------- d-----w- c:\program files\Common Files\Java 2011-04-07 08:41 . 2011-02-02 20:40 472808 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll 2011-04-07 08:41 . 2011-02-02 20:40 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-04-07 08:26 . 2011-04-07 08:26 -------- d-----w- c:\users\Anthony\AppData\Local\{418FA485-90D7-4CA6-A5F9-C0B1D6CE5E9B} 2011-04-05 18:53 . 2011-04-05 18:54 -------- d-----w- c:\users\Anthony\AppData\Local\{E8A8E643-EE12-4EBE-A745-58B0DEC555E9} 2011-04-05 06:53 . 2011-04-05 06:53 -------- d-----w- c:\users\Anthony\AppData\Local\{471CCED3-7F4B-45E0-92FB-ACE09B8084C9} 2011-04-04 13:15 . 2011-04-04 13:15 -------- d-----w- c:\users\Anthony\AppData\Local\{27903436-12EE-494C-9D5D-29EAA02C776A} 2011-04-04 12:01 . 2011-04-06 23:00 0 ----a-w- c:\users\Anthony\AppData\Local\Fzuzo.bin 2011-04-04 01:14 . 2011-04-04 01:15 -------- d-----w- c:\users\Anthony\AppData\Local\{09E6019A-BFA0-4886-B62B-0D904FFF8678} 2011-04-03 13:14 . 2011-04-03 13:14 -------- d-----w- c:\users\Anthony\AppData\Local\{28CCD898-745D-463D-976F-7CEA842EAF01} 2011-04-03 01:13 . 2011-04-03 01:14 -------- d-----w- c:\users\Anthony\AppData\Local\{7228278D-210C-41F0-845C-6A8AA1A20C34} 2011-04-01 18:51 . 2011-04-01 18:51 -------- d-----w- c:\users\Anthony\AppData\Local\{BCFCD2E6-BAB7-4DE2-BC59-EC27148B989B} 2011-04-01 05:52 . 2011-03-15 04:05 6792528 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{83C456C7-C434-4BD7-8D56-D08E3C766FE7}\mpengine.dll 2011-03-31 10:02 . 2011-03-31 10:02 -------- d-----w- c:\users\Anthony\AppData\Local\{B89DE561-07CD-42EC-B790-D27FD880C33D} 2011-03-27 12:27 . 2011-03-27 12:28 -------- d-----w- c:\users\Anthony\AppData\Local\{7B2C7994-FB0E-4DF9-82A9-5D83F1967F87} 2011-03-27 12:24 . 2011-03-27 12:24 -------- d-----w- c:\users\Anthony\AppData\Local\{59C8D8EE-5826-428C-82CE-9224BEEB1D4B} 2011-03-26 21:40 . 2011-03-26 21:40 -------- d-----w- c:\users\Anthony\AppData\Local\{651778BA-08F6-44FB-B250-8E8C6C0AD485} 2011-03-26 09:06 . 2011-03-26 09:06 -------- d-----w- c:\users\Anthony\AppData\Local\{358E1883-935D-40F4-95B3-345F09C69FF6} 2011-03-25 15:24 . 2011-03-25 15:25 -------- d-----w- c:\users\Anthony\AppData\Local\{F00D4288-2790-4AB7-AB35-D2DBB7A29707} 2011-03-24 19:32 . 2011-03-24 19:32 -------- d-----w- c:\users\Anthony\AppData\Local\{7DAA3ADA-53C7-493E-A8D2-0DEDA61D0172} 2011-03-23 19:59 . 2011-03-23 19:59 -------- d-----w- c:\users\Anthony\AppData\Local\{612D8E73-CAAD-4CD7-B5B3-B4CF93E8A628} 2011-03-23 07:58 . 2011-03-23 07:59 -------- d-----w- c:\users\Anthony\AppData\Local\{E68E64C0-226A-4970-A2EB-0AD16CDB7C8D} 2011-03-22 16:19 . 2011-03-22 16:19 -------- d-----w- c:\users\Anthony\AppData\Local\{9335C91F-A78D-414C-A41D-E856A97FCE86} 2011-03-21 23:24 . 2011-03-21 23:24 -------- d-----w- c:\users\Anthony\AppData\Local\{F867818A-FC5D-4F78-8264-942AF62A5580} 2011-03-21 11:24 . 2011-03-21 11:24 -------- d-----w- c:\users\Anthony\AppData\Local\{38774B89-5070-403B-87A6-3B58CBA862B2} 2011-03-20 23:24 . 2011-03-21 18:35 -------- d-----w- c:\users\Anthony\AppData\Roaming\Spotify 2011-03-20 23:24 . 2011-03-21 18:33 -------- d-----w- c:\users\Anthony\AppData\Local\Spotify 2011-03-20 23:24 . 2011-03-20 23:24 -------- d-----w- c:\program files\Spotify 2011-03-20 23:24 . 2011-03-20 23:24 -------- d-----w- c:\users\Anthony\AppData\Local\{BF124FEA-0A56-45E7-8A65-02BE8CA4C3C0} 2011-03-20 11:23 . 2011-03-20 11:24 -------- d-----w- c:\users\Anthony\AppData\Local\{C8583049-798E-4826-8179-79ADCD1E698C} 2011-03-19 22:07 . 2011-03-19 22:08 -------- d-----w- c:\users\Anthony\AppData\Local\{E7386A9F-D88D-4093-9D4E-585F0FEA174C} 2011-03-19 10:07 . 2011-03-19 10:07 -------- d-----w- c:\users\Anthony\AppData\Local\{3F63444F-E51D-465E-9EAB-2A2A00FCE8F6} 2011-03-18 12:38 . 2011-03-18 12:39 -------- d-----w- c:\users\Anthony\AppData\Local\{DBE3002F-64C7-49E3-8EA1-9FFDC455DA6D} 2011-03-17 23:23 . 2011-03-17 23:24 -------- d-----w- c:\users\Anthony\AppData\Local\{7E32E558-C130-4C26-9641-F69A0B35B64A} 2011-03-17 18:43 . 2010-02-04 10:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll 2011-03-17 18:43 . 2010-02-04 10:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll 2011-03-17 11:23 . 2011-03-17 11:23 -------- d-----w- c:\users\Anthony\AppData\Local\{BEF3C44A-12DB-494B-8C1A-E4679CC975B8} 2011-03-16 23:23 . 2011-03-16 23:23 -------- d-----w- c:\users\Anthony\AppData\Local\{163E507C-9566-4084-9711-644DF15B1E28} 2011-03-16 09:54 . 2011-03-16 09:54 -------- d-----w- c:\users\Anthony\AppData\Local\{7A8187F0-2A4E-43BD-A58A-12B49F1EAC03} 2011-03-15 17:24 . 2011-03-15 17:25 -------- d-----w- c:\users\Anthony\AppData\Local\{02CE091F-E2A8-40B6-B445-BE25E3CA14D2} 2011-03-14 23:28 . 2011-03-14 23:28 -------- d-----w- c:\users\Anthony\AppData\Local\{7DA83D33-202E-43E5-84B6-315F6B5F34D9} 2011-03-13 18:08 . 2011-03-13 18:08 -------- d-----w- c:\users\Anthony\AppData\Local\{71CBF977-1E56-4D2F-97BF-887B08322BDB} 2011-03-12 09:35 . 2011-03-12 09:36 -------- d-----w- c:\users\Anthony\AppData\Local\{BBA3F14E-65B2-4CF4-A5A0-A8599A527E84} 2011-03-11 18:55 . 2011-03-11 19:00 -------- d-----w- c:\program files\zbattle.net 2011-03-11 14:08 . 2011-03-11 14:08 -------- d-----w- c:\users\Anthony\AppData\Local\{325F9CA4-EC45-4625-8924-E4004BD161C0} 2011-03-10 21:04 . 2011-03-10 21:04 -------- d-----w- c:\users\Anthony\AppData\Local\{885FA540-59D3-4659-A717-783313ADC332} 2011-03-10 00:12 . 2011-03-12 14:10 -------- d-----w- c:\program files\blueMSX 2011-03-09 23:25 . 2011-03-09 23:25 -------- d-----w- c:\users\Anthony\AppData\Local\{1EA2D52F-71FC-4FB9-91A7-BA5F2DBA2DCE} 2011-03-09 08:05 . 2011-02-19 05:33 802304 ----a-w- c:\windows\system32\FntCache.dll 2011-03-09 08:05 . 2011-02-19 05:32 1074176 ----a-w- c:\windows\system32\DWrite.dll 2011-03-09 08:05 . 2011-02-19 05:32 739840 ----a-w- c:\windows\system32\d2d1.dll 2011-03-09 08:05 . 2010-12-23 05:28 850432 ----a-w- c:\windows\system32\sbe.dll 2011-03-09 08:05 . 2010-12-23 05:28 642048 ----a-w- c:\windows\system32\CPFilters.dll 2011-03-09 08:05 . 2010-12-23 05:28 534528 ----a-w- c:\windows\system32\EncDec.dll 2011-03-09 08:05 . 2010-12-23 05:24 199680 ----a-w- c:\windows\system32\mpg2splt.ax 2011-03-09 08:05 . 2010-12-18 05:30 2690560 ----a-w- c:\windows\system32\mstscax.dll 2011-03-09 08:05 . 2010-12-18 05:26 1034240 ----a-w- c:\windows\system32\mstsc.exe 2011-03-08 13:47 . 2011-03-08 13:48 -------- d-----w- c:\users\Anthony\AppData\Local\{68DE9C70-7165-4596-93A2-CE854EB8A25A} . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-04-04 17:28 . 2009-07-13 23:11 57424 ----a-w- c:\windows\system32\drivers\disk.sys 2011-03-27 23:09 . 2010-06-24 10:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-02-03 05:45 . 2011-02-09 12:27 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys 2011-02-02 18:11 . 2009-11-10 14:26 222080 ------w- c:\windows\system32\MpSigStub.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}] 2008-11-18 12:58 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192] . [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192] . [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2010-10-06 23:36 94208 ----a-w- c:\users\Anthony\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2010-10-06 23:36 94208 ----a-w- c:\users\Anthony\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2010-10-06 23:36 94208 ----a-w- c:\users\Anthony\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2010-10-06 23:36 94208 ----a-w- c:\users\Anthony\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504] "Steam"="c:\program files\Steam\steam.exe" [2010-11-17 1242448] "DisplayFusion"="c:\program files\DisplayFusion\DisplayFusion.exe" [2010-03-14 813744] "uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-12-29 395640] "Google Update"="c:\users\Anthony\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-09-29 136176] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2009-06-03 103720] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-20 7625248] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2010-08-18 340520] "Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-07-12 74752] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-08-10 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160] "HTC Sync Loader"="c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2010-08-18 249856] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064] . c:\users\Anthony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Anthony\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-3-31 23360040] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-2-8 113664] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux3"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2010-09-01 07:32 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2010-08-10 04:15 421888 ----a-w- c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-10-26 25088] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-24 1343400] S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-14 36880] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2009-11-03 21520] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-10-02 19472] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2009-08-21 66592] . . Contents of the 'Scheduled Tasks' folder . 2011-04-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-485591569-2650029946-3558758453-1000Core.job - c:\users\Anthony\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-29 21:50] . 2011-04-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-485591569-2650029946-3558758453-1000UA.job - c:\users\Anthony\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-29 21:50] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.aldi.com uInternet Settings,ProxyOverride = *.local IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000 IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/710-72741-17534-1/4 IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\users\Anthony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk FF - ProfilePath - c:\users\Anthony\AppData\Roaming\Mozilla\Firefox\Profiles\35yasoe8.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: Dawn of the Dragons Community Toolbar: {cac9d76b-2b7f-4f42-918f-3470a847f562} - %profile%\extensions\{cac9d76b-2b7f-4f42-918f-3470a847f562} FF - Ext: FireFTP: {a7c6cf7f-112c-4500-a7ea-39801a327e5f} - %profile%\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f} . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) HKLM-Run-Mhesasomizi - c:\users\Anthony\AppData\Local\uyuyesog.dll AddRemove-UnityWebPlayer - c:\users\Anthony\AppData\Local\Unity\WebPlayer\Uninstall.exe . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-04-07 10:02:15 ComboFix-quarantined-files.txt 2011-04-07 09:02 . Pre-Run: 580,737,855,488 bytes free Post-Run: 583,937,404,928 bytes free . - - End Of File - - 9D27E2308DB0CC55DE233B6314B01DB2