Jump to content

Change Mode

locked registry keys and...


Recommended Posts

[HKEY_USERS\S-1-5-21-3521223863-180964219-1802063814-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.oxps\UserChoice]

@Denied: (2) (Administrator)

"Hash"="ExzWmWmgmT0="

"ProgId"="AppX86746z2101ayy2ygv3g96e4eqdf8r99j"

.

[HKEY_USERS\S-1-5-21-3521223863-180964219-1802063814-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\UserChoice]

@Denied: (2) (Administrator)

"Hash"="oSGnQC1Nyds="

"ProgId"="AppX86746z2101ayy2ygv3g96e4eqdf8r99j"

.

[HKEY_USERS\S-1-5-21-3521223863-180964219-1802063814-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice]

@Denied: (2) (Administrator)

"Hash"="14T3T8TNbMA="

"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah"

.

[HKEY_USERS\S-1-5-21-3521223863-180964219-1802063814-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice]

@Denied: (2) (Administrator)

"Hash"="KfzFSSMXy6Y="

"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah"

.

[HKEY_USERS\S-1-5-21-3521223863-180964219-1802063814-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice]

@Denied: (2) (Administrator)

"Hash"="VNkc3liwKLs="

"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah"

.

[HKEY_USERS\S-1-5-21-3521223863-180964219-1802063814-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TS\UserChoice]

@Denied: (2) (Administrator)

"Hash"="h8t+ACj8Bq4="

"ProgId"="WMP11.AssocFile.TTS"

.

[HKEY_USERS\S-1-5-21-3521223863-180964219-1802063814-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TTS\UserChoice]

@Denied: (2) (Administrator)

"Hash"="pb1j2/7E4d8="

"ProgId"="WMP11.AssocFile.TTS"

.

[HKEY_USERS\S-1-5-21-3521223863-180964219-1802063814-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]

@Denied: (2) (Administrator)

"Hash"="2L7Tl8P3UKw="

"ProgId"="AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs"

.

[HKEY_USERS\S-1-5-21-3521223863-180964219-1802063814-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wdp\UserChoice]

@Denied: (2) (Administrator)

"Hash"="2qdKk4QMSPo="

"ProgId"="AppX9vdwcvrwnbettpahnt26jswq0n8hgyah"

.

[HKEY_USERS\S-1-5-21-3521223863-180964219-1802063814-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice]

@Denied: (2) (Administrator)

"Hash"="BzxBHr6bHN4="

"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt"

.

[HKEY_USERS\S-1-5-21-3521223863-180964219-1802063814-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice]

@Denied: (2) (Administrator)

"Hash"="rMi/0Kz4Xc0="

"ProgId"="AppXhjhjmgrfm2d7rd026az898dy2p1pcsyt"

.

[HKEY_USERS\S-1-5-21-3521223863-180964219-1802063814-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.WPL\UserChoice]

@Denied: (2) (Administrator)

"Hash"="QCVlxwPkuNQ="

"ProgId"="WMP11.AssocFile.WPL"

.

[HKEY_USERS\S-1-5-21-3521223863-180964219-1802063814-500CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xps\UserChoice]

@Denied: (2) (Administrator)

"Hash"="CxByOCi1ODs="

"ProgId"="AppX86746z2101ayy2ygv3g96e4eqdf8r99j"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

@SACL=(02 0000)

.

Completion time: 2017-01-15 09:59:27

ComboFix-quarantined-files.txt 2017-01-15 14:59

.

Pre-Run: 925,831,667,712 bytes free

Post-Run: 925,695,242,240 bytes free

.

- - End Of File - - EB4994E9F72EF10E87416475F592D1CE

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...