Malware Report - Results

This report shows all the different areas TAZER analyzes for the sample: Host, Network Activity, and Detection.

Malware Search Criteria:
  • MD5 =24b2af75eb6332db26b4139e00622e5b

  • Malware Report - Results

    File MD5SumSHA1SUMSHA256SUMFUZZY HASHFile Size
    24b2af75eb6332db26b4139e00622e5ba21213ee65d36861c3955f793ac4219bd4102b1a8951cf7d7a4a3412cf84d5a43ac2e990bff7942e2c662657ce7912d3690b606898304:rfniroN7nTLK6BCJbCSGZ4bAZ+8xWmjRFGCjt2dDDdUXbuz:LniroN7n3b0CBCbi+vOGi2RdUL4211712

    File Results

    File Name
    LSS%5Fxp.exe

    SNORT Results

    Snort ClassSnort AlertCount
    A Network Trojan was DetectedET USER_AGENTS Suspicious User Agent (TALWinInetHTTPClient)1
    A Network Trojan was DetectedET TROJAN FAKE AV HTTP CnC Post1
    Misc AttackET RBN Known Russian Business Network IP TCP (135)1

    AV Results

    AV AlertAV Vendor

    Folders (Added) - ICC Results

    PathFolder Name
    c:/Documents and Settings/All Users/Start Menu/ProgramsLive Security Suite
    c:/Documents and Settings/dmc73144/Application DataLive Security Suite
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suitedb
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Program FilesLive Security Suite
    c:/Program Files/Live Security Suitedb
    c:/Program Files/Live Security Suitelanguages
    c:/Documents and Settings/All Users/Start Menu/ProgramsLive Security Suite
    c:/Documents and Settings/dmc73144/Application DataLive Security Suite
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suitedb
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Program FilesLive Security Suite
    c:/Program Files/Live Security Suitedb
    c:/Program Files/Live Security Suitelanguages
    c:/WINDOWS/system32/driversdisdn_
    c:/Documents and Settings/All Users/Start Menu/ProgramsLive Security Suite
    c:/Documents and Settings/dmc73144/Application DataLive Security Suite
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suitedb
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Program FilesLive Security Suite
    c:/Program Files/Live Security Suitedb
    c:/Program Files/Live Security Suitelanguages
    c:/WINDOWS/system32/driversetc_
    c:/Documents and Settings/All Users/Start Menu/ProgramsLive Security Suite
    c:/Documents and Settings/dmc73144/Application DataLive Security Suite
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suitedb
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Program FilesLive Security Suite
    c:/Program Files/Live Security Suitedb
    c:/Program Files/Live Security Suitelanguages
    c:/WINDOWS/system32/MacromedCommon_
    c:/Documents and Settings/All Users/Start Menu/ProgramsLive Security Suite
    c:/Documents and Settings/dmc73144/Application DataLive Security Suite
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suitedb
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Program FilesLive Security Suite
    c:/Program Files/Live Security Suitedb
    c:/Program Files/Live Security Suitelanguages
    c:/WINDOWS/system32dhcp_
    c:/Documents and Settings/All Users/Start Menu/ProgramsLive Security Suite
    c:/Documents and Settings/dmc73144/Application DataLive Security Suite
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suitedb
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/MicrosoftWindows Media_
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windows Media_9.0
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Program FilesLive Security Suite
    c:/Program Files/Live Security Suitedb
    c:/Program Files/Live Security Suitelanguages
    c:/Documents and Settings/All Users/Start Menu/ProgramsLive Security Suite
    c:/Documents and Settings/dmc73144/Application DataLive Security Suite
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suitedb
    c:/Documents and Settings/dmc73144/Local Settings/Application DataAdobe_
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Adobe_Acrobat
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Adobe_/Acrobat8.0
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Adobe_/Acrobat/8.0Updater
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Program FilesLive Security Suite
    c:/Program Files/Live Security Suitedb
    c:/Program Files/Live Security Suitelanguages
    c:/Documents and Settings/All Users/Start Menu/ProgramsLive Security Suite
    c:/Documents and Settings/dmc73144/Application DataLive Security Suite
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suitedb
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/MicrosoftInternet Explorer_
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Program FilesLive Security Suite
    c:/Program Files/Live Security Suitedb
    c:/Program Files/Live Security Suitelanguages
    c:/Documents and Settings/All Users/Start Menu/ProgramsLive Security Suite
    c:/Documents and Settings/dmc73144/Application DataLive Security Suite
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suitedb
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/MicrosoftInternet Explorer_
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Program FilesLive Security Suite
    c:/Program Files/Live Security Suitedb
    c:/Program Files/Live Security Suitelanguages

    Files (Added) - ICC Results

    PathFile Name
    c:/DELL/VIDEO/OUTPUTnetstat_base.txt
    c:/DELL/VIDEO/OUTPUTnetstat_post.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_base.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_post.txt
    c:/DELL/VIDEO/OUTPUTtaskv_base.txt
    c:/DELL/VIDEO/OUTPUTtaskv_post.txt
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuiteLive Security Suite Home Page.lnk
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuiteLive Security Suite.lnk
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuitePurchase License.lnk
    c:/Documents and Settings/dmc73144/Application Data/Microsoft/Internet Explorer/Quick LaunchLive Security Suite.lnk
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbconfig.cfg
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbpb.dll
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbTimeout.inf
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbUrls.inf
    c:/Documents and Settings/dmc73144/Application Data/Live Security SuiteHTUninstaller.exe
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suitesettings.ini
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suiteuill.ini
    c:/Documents and Settings/dmc73144/Application Data/Live Security SuiteUninstall Live Security Suite.lnk
    c:/Documents and Settings/dmc73144/DesktopLive Security Suite.lnk
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriGSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriMSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriPSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowsofout.exe
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowspguard.ini
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowsservices.exe
    c:/Documents and Settings/dmc73144/Local Settings/Temp~Timeout.inf.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp~Urls.inf.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cinstall[1].htm
    c:/Program Files/Live Security Suiteactivate.ico
    c:/Program Files/Live Security Suite/dbDBInfo.ver
    c:/Program Files/Live Security Suite/dbga090122.db
    c:/Program Files/Live Security Suite/dbInfected.wav
    c:/Program Files/Live Security Suite/dblists.ini
    c:/Program Files/Live Security Suiteexplorer.ico
    c:/Program Files/Live Security Suite/LanguagesLSSEs.lng
    c:/Program Files/Live Security Suite/LanguagesLSSFr.lng
    c:/Program Files/Live Security Suite/LanguagesLSSGer.lng
    c:/Program Files/Live Security Suite/LanguagesLSSIt.lng
    c:/Program Files/Live Security SuiteLiveSS.exe
    c:/Program Files/Live Security Suitereg.ico
    c:/Program Files/Live Security Suiteuninstall.ico
    c:/Program Files/Live Security Suiteworking.log
    c:/Program Files/Live Security Suite~LiveSS.tmp
    c:/WINDOWS/Prefetch7Z.EXE-1A62CD19.pf
    c:/WINDOWS/PrefetchLIVESS.EXE-2474900A.pf
    c:/WINDOWS/PrefetchNET.EXE-01A53C2F.pf
    c:/WINDOWS/PrefetchNET1.EXE-029B9DB4.pf
    c:/WINDOWS/PrefetchOUTAND.EXE-23658734.pf
    c:/WINDOWS/PrefetchPING.EXE-31216D26.pf
    c:/WINDOWS/system32pb.sys
    c:/WINDOWS/system32wlsrbdffhl.dll
    c:/WINDOWS/system32wughclwicp.dll
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuiteLive Security Suite Home Page.lnk
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuiteLive Security Suite.lnk
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuitePurchase License.lnk
    c:/Documents and Settings/dmc73144/Application Data/Microsoft/Internet Explorer/Quick LaunchLive Security Suite.lnk
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbconfig.cfg
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbpb.dll
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbTimeout.inf
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbUrls.inf
    c:/Documents and Settings/dmc73144/Application Data/Live Security SuiteHTUninstaller.exe
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suitesettings.ini
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suiteuill.ini
    c:/Documents and Settings/dmc73144/Application Data/Live Security SuiteUninstall Live Security Suite.lnk
    c:/Documents and Settings/dmc73144/DesktopLive Security Suite.lnk
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriGSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriMSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriPSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowsofatby.exe
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowspguard.ini
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowsservices.exe
    c:/Documents and Settings/dmc73144/Local Settings/Temp~Timeout.inf.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp~Urls.inf.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cinstall[1].htm
    c:/Program Files/Live Security Suiteactivate.ico
    c:/Program Files/Live Security Suite/dbDBInfo.ver
    c:/Program Files/Live Security Suite/dbga090122.db
    c:/Program Files/Live Security Suite/dbInfected.wav
    c:/Program Files/Live Security Suite/dblists.ini
    c:/Program Files/Live Security Suiteexplorer.ico
    c:/Program Files/Live Security Suite/LanguagesLSSEs.lng
    c:/Program Files/Live Security Suite/LanguagesLSSFr.lng
    c:/Program Files/Live Security Suite/LanguagesLSSGer.lng
    c:/Program Files/Live Security Suite/LanguagesLSSIt.lng
    c:/Program Files/Live Security SuiteLiveSS.exe
    c:/Program Files/Live Security Suitereg.ico
    c:/Program Files/Live Security Suiteuninstall.ico
    c:/Program Files/Live Security Suiteworking.log
    c:/Program Files/Live Security Suite~LiveSS.tmp
    c:/WINDOWS/PrefetchANDOUTFORON.EXE-01AE8BBC.pf
    c:/WINDOWS/PrefetchLIVESS.EXE-2474900A.pf
    c:/WINDOWS/PrefetchPING.EXE-31216D26.pf
    c:/WINDOWS/PrefetchSANDNET.EXE-2012C478.pf
    c:/WINDOWS/system32/drivers/disdnandoutforon.exe
    c:/WINDOWS/system32anavumlwk.dll
    c:/WINDOWS/system32nvgglec.dll
    c:/WINDOWS/system32pb.sys
    c:netstat_post.txt
    c:taskv_post.txt
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuiteLive Security Suite Home Page.lnk
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuiteLive Security Suite.lnk
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuitePurchase License.lnk
    c:/Documents and Settings/dmc73144/Application Data/Microsoft/Internet Explorer/Quick LaunchLive Security Suite.lnk
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbconfig.cfg
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbpb.dll
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbTimeout.inf
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbUrls.inf
    c:/Documents and Settings/dmc73144/Application Data/Live Security SuiteHTUninstaller.exe
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suitesettings.ini
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suiteuill.ini
    c:/Documents and Settings/dmc73144/Application Data/Live Security SuiteUninstall Live Security Suite.lnk
    c:/Documents and Settings/dmc73144/DesktopLive Security Suite.lnk
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriGSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriMSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriPSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowspguard.ini
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowsservices.exe
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowstheofin.exe
    c:/Documents and Settings/dmc73144/Local Settings/Temp~Timeout.inf.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp~Urls.inf.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cinstall[1].htm
    c:/Program Files/Live Security Suiteactivate.ico
    c:/Program Files/Live Security Suite/dbDBInfo.ver
    c:/Program Files/Live Security Suite/dbga090122.db
    c:/Program Files/Live Security Suite/dbInfected.wav
    c:/Program Files/Live Security Suite/dblists.ini
    c:/Program Files/Live Security Suiteexplorer.ico
    c:/Program Files/Live Security Suite/LanguagesLSSEs.lng
    c:/Program Files/Live Security Suite/LanguagesLSSFr.lng
    c:/Program Files/Live Security Suite/LanguagesLSSGer.lng
    c:/Program Files/Live Security Suite/LanguagesLSSIt.lng
    c:/Program Files/Live Security SuiteLiveSS.exe
    c:/Program Files/Live Security Suitereg.ico
    c:/Program Files/Live Security Suiteuninstall.ico
    c:/Program Files/Live Security Suiteworking.log
    c:/Program Files/Live Security Suite~LiveSS.tmp
    c:/WINDOWS/PrefetchLIVESS.EXE-2474900A.pf
    c:/WINDOWS/PrefetchOROF.EXE-35DF9575.pf
    c:/WINDOWS/PrefetchPING.EXE-31216D26.pf
    c:/WINDOWS/system32/drivers/etcorof.exe
    c:/WINDOWS/system32/drivers/etc_hosts
    c:/WINDOWS/system32/drivers/etc_lmhosts.sam
    c:/WINDOWS/system32/drivers/etc_networks
    c:/WINDOWS/system32/drivers/etc_protocol
    c:/WINDOWS/system32/drivers/etc_services
    c:/WINDOWS/system32pb.sys
    c:/WINDOWS/system32riswtlur.dll
    c:/WINDOWS/system32tfsqfihfjl.dll
    c:netstat_post.txt
    c:tasksvc_post.txt
    c:taskv_post.txt
    c:/DELL/VIDEO/OUTPUTnetstat_base.txt
    c:/DELL/VIDEO/OUTPUTnetstat_post.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_base.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_post.txt
    c:/DELL/VIDEO/OUTPUTtaskv_base.txt
    c:/DELL/VIDEO/OUTPUTtaskv_post.txt
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuiteLive Security Suite Home Page.lnk
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuiteLive Security Suite.lnk
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuitePurchase License.lnk
    c:/Documents and Settings/dmc73144/Application Data/Microsoft/Internet Explorer/Quick LaunchLive Security Suite.lnk
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbconfig.cfg
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbpb.dll
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbTimeout.inf
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbUrls.inf
    c:/Documents and Settings/dmc73144/Application Data/Live Security SuiteHTUninstaller.exe
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suitesettings.ini
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suiteuill.ini
    c:/Documents and Settings/dmc73144/Application Data/Live Security SuiteUninstall Live Security Suite.lnk
    c:/Documents and Settings/dmc73144/DesktopLive Security Suite.lnk
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriGSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriMSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriPSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowsoutonby.exe
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowspguard.ini
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowsservices.exe
    c:/Documents and Settings/dmc73144/Local Settings/Temp~Timeout.inf.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp~Urls.inf.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cinstall[1].htm
    c:/Program Files/Live Security Suiteactivate.ico
    c:/Program Files/Live Security Suite/dbDBInfo.ver
    c:/Program Files/Live Security Suite/dbga090122.db
    c:/Program Files/Live Security Suite/dbInfected.wav
    c:/Program Files/Live Security Suite/dblists.ini
    c:/Program Files/Live Security Suiteexplorer.ico
    c:/Program Files/Live Security Suite/LanguagesLSSEs.lng
    c:/Program Files/Live Security Suite/LanguagesLSSFr.lng
    c:/Program Files/Live Security Suite/LanguagesLSSGer.lng
    c:/Program Files/Live Security Suite/LanguagesLSSIt.lng
    c:/Program Files/Live Security SuiteLiveSS.exe
    c:/Program Files/Live Security Suitereg.ico
    c:/Program Files/Live Security Suiteuninstall.ico
    c:/Program Files/Live Security Suiteworking.log
    c:/Program Files/Live Security Suite~LiveSS.tmp
    c:/WINDOWS/Prefetch7Z.EXE-1A62CD19.pf
    c:/WINDOWS/PrefetchCYGRUNSRV.EXE-01BF82AE.pf
    c:/WINDOWS/PrefetchLIVESS.EXE-2474900A.pf
    c:/WINDOWS/PrefetchNET.EXE-01A53C2F.pf
    c:/WINDOWS/PrefetchNET1.EXE-029B9DB4.pf
    c:/WINDOWS/PrefetchPING.EXE-31216D26.pf
    c:/WINDOWS/PrefetchTHEAT.EXE-18B483D6.pf
    c:/WINDOWS/system32/Macromed/Commontheat.exe
    c:/WINDOWS/system32/Macromed/Common_SwSupport.dll
    c:/WINDOWS/system32blletbjqaw.dll
    c:/WINDOWS/system32pb.sys
    c:/WINDOWS/system32wcjsmehh.dll
    c:/WINDOWS/Prefetch7Z.EXE-1A62CD19.pf
    c:/WINDOWS/PrefetchFORATTHE.EXE-022E9EFA.pf
    c:/WINDOWS/PrefetchLIVESS.EXE-2474900A.pf
    c:/WINDOWS/PrefetchPING.EXE-31216D26.pf
    c:/WINDOWS/PrefetchSANDNET.EXE-2012C478.pf
    c:/WINDOWS/system32aqurcise.dll
    c:/WINDOWS/system32ewgihvkumk.dll
    c:/WINDOWS/system32pb.sys
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuiteLive Security Suite Home Page.lnk
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuiteLive Security Suite.lnk
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuitePurchase License.lnk
    c:/Documents and Settings/dmc73144/Application Data/Microsoft/Internet Explorer/Quick LaunchLive Security Suite.lnk
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbconfig.cfg
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbpb.dll
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbTimeout.inf
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbUrls.inf
    c:/Documents and Settings/dmc73144/Application Data/Live Security SuiteHTUninstaller.exe
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suitesettings.ini
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suiteuill.ini
    c:/Documents and Settings/dmc73144/Application Data/Live Security SuiteUninstall Live Security Suite.lnk
    c:/Documents and Settings/dmc73144/DesktopLive Security Suite.lnk
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriGSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriMSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriPSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowsofbyof.exe
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowspguard.ini
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowsservices.exe
    c:/Documents and Settings/dmc73144/Local Settings/Temp~Timeout.inf.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp~Urls.inf.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cinstall[1].htm
    c:/Program Files/Live Security Suiteactivate.ico
    c:/Program Files/Live Security Suite/dbDBInfo.ver
    c:/Program Files/Live Security Suite/dbga090122.db
    c:/Program Files/Live Security Suite/dbInfected.wav
    c:/Program Files/Live Security Suite/dblists.ini
    c:/Program Files/Live Security Suiteexplorer.ico
    c:/Program Files/Live Security Suite/LanguagesLSSEs.lng
    c:/Program Files/Live Security Suite/LanguagesLSSFr.lng
    c:/Program Files/Live Security Suite/LanguagesLSSGer.lng
    c:/Program Files/Live Security Suite/LanguagesLSSIt.lng
    c:/Program Files/Live Security SuiteLiveSS.exe
    c:/Program Files/Live Security Suitereg.ico
    c:/Program Files/Live Security Suiteuninstall.ico
    c:/Program Files/Live Security Suiteworking.log
    c:/Program Files/Live Security Suite~LiveSS.tmp
    c:/WINDOWS/Prefetch7Z.EXE-1A62CD19.pf
    c:/WINDOWS/PrefetchANDBYANDAT.EXE-01618C1C.pf
    c:/WINDOWS/PrefetchLIVESS.EXE-2474900A.pf
    c:/WINDOWS/PrefetchPING.EXE-31216D26.pf
    c:/WINDOWS/system32/dhcpandbyandat.exe
    c:/WINDOWS/system32dnruefwkko.dll
    c:/WINDOWS/system32pb.sys
    c:/WINDOWS/system32titnwqjqot.dll
    c:netstat_post.txt
    c:tasksvc_post.txt
    c:taskv_post.txt
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuiteLive Security Suite Home Page.lnk
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuiteLive Security Suite.lnk
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuitePurchase License.lnk
    c:/Documents and Settings/dmc73144/Application Data/Microsoft/Internet Explorer/Quick LaunchLive Security Suite.lnk
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbconfig.cfg
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbpb.dll
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbTimeout.inf
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbUrls.inf
    c:/Documents and Settings/dmc73144/Application Data/Live Security SuiteHTUninstaller.exe
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suitesettings.ini
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suiteuill.ini
    c:/Documents and Settings/dmc73144/Application Data/Live Security SuiteUninstall Live Security Suite.lnk
    c:/Documents and Settings/dmc73144/DesktopLive Security Suite.lnk
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriGSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriMSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriPSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowsorand.exe
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowspguard.ini
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowsservices.exe
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windows Mediaforon.exe
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windows Media_/9.0WMSDKNS.DTD
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windows Media_/9.0WMSDKNS.XML
    c:/Documents and Settings/dmc73144/Local Settings/Temp~Timeout.inf.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp~Urls.inf.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cinstall[1].htm
    c:/Program Files/Live Security Suiteactivate.ico
    c:/Program Files/Live Security Suite/dbDBInfo.ver
    c:/Program Files/Live Security Suite/dbga090122.db
    c:/Program Files/Live Security Suite/dbInfected.wav
    c:/Program Files/Live Security Suite/dblists.ini
    c:/Program Files/Live Security Suiteexplorer.ico
    c:/Program Files/Live Security Suite/LanguagesLSSEs.lng
    c:/Program Files/Live Security Suite/LanguagesLSSFr.lng
    c:/Program Files/Live Security Suite/LanguagesLSSGer.lng
    c:/Program Files/Live Security Suite/LanguagesLSSIt.lng
    c:/Program Files/Live Security SuiteLiveSS.exe
    c:/Program Files/Live Security Suitereg.ico
    c:/Program Files/Live Security Suiteuninstall.ico
    c:/Program Files/Live Security Suiteworking.log
    c:/Program Files/Live Security Suite~LiveSS.tmp
    c:/WINDOWS/PrefetchFORON.EXE-18A2C406.pf
    c:/WINDOWS/PrefetchLIVESS.EXE-2474900A.pf
    c:/WINDOWS/PrefetchPING.EXE-31216D26.pf
    c:/WINDOWS/system32eeetfqdfs.dll
    c:/WINDOWS/system32erhiltpp.dll
    c:/WINDOWS/system32pb.sys
    c:netstat_post.txt
    c:tasksvc_post.txt
    c:taskv_post.txt
    c:/DELL/VIDEO/OUTPUTnetstat_base.txt
    c:/DELL/VIDEO/OUTPUTnetstat_post.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_base.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_post.txt
    c:/DELL/VIDEO/OUTPUTtaskv_base.txt
    c:/DELL/VIDEO/OUTPUTtaskv_post.txt
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuiteLive Security Suite Home Page.lnk
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuiteLive Security Suite.lnk
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuitePurchase License.lnk
    c:/Documents and Settings/dmc73144/Application Data/Microsoft/Internet Explorer/Quick LaunchLive Security Suite.lnk
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbconfig.cfg
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbpb.dll
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbTimeout.inf
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbUrls.inf
    c:/Documents and Settings/dmc73144/Application Data/Live Security SuiteHTUninstaller.exe
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suitesettings.ini
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suiteuill.ini
    c:/Documents and Settings/dmc73144/Application Data/Live Security SuiteUninstall Live Security Suite.lnk
    c:/Documents and Settings/dmc73144/DesktopLive Security Suite.lnk
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Adobeator.exe
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriGSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriMSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet ExploreriPSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowsonbyand.exe
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowspguard.ini
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowsservices.exe
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Adobe_/Acrobat/8.0/Updaterupdater.log
    c:/Documents and Settings/dmc73144/Local Settings/Temp~Timeout.inf.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp~Urls.inf.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cinstall[1].htm
    c:/Program Files/Live Security Suiteactivate.ico
    c:/Program Files/Live Security Suite/dbDBInfo.ver
    c:/Program Files/Live Security Suite/dbga090122.db
    c:/Program Files/Live Security Suite/dbInfected.wav
    c:/Program Files/Live Security Suite/dblists.ini
    c:/Program Files/Live Security Suiteexplorer.ico
    c:/Program Files/Live Security Suite/LanguagesLSSEs.lng
    c:/Program Files/Live Security Suite/LanguagesLSSFr.lng
    c:/Program Files/Live Security Suite/LanguagesLSSGer.lng
    c:/Program Files/Live Security Suite/LanguagesLSSIt.lng
    c:/Program Files/Live Security SuiteLiveSS.exe
    c:/Program Files/Live Security Suitereg.ico
    c:/Program Files/Live Security Suiteuninstall.ico
    c:/Program Files/Live Security Suiteworking.log
    c:/Program Files/Live Security Suite~LiveSS.tmp
    c:/WINDOWS/Prefetch7Z.EXE-1A62CD19.pf
    c:/WINDOWS/PrefetchATOR.EXE-24669C0B.pf
    c:/WINDOWS/PrefetchLIVESS.EXE-2474900A.pf
    c:/WINDOWS/PrefetchNET.EXE-01A53C2F.pf
    c:/WINDOWS/PrefetchNET1.EXE-029B9DB4.pf
    c:/WINDOWS/PrefetchPING.EXE-31216D26.pf
    c:/WINDOWS/system32csvlovcag.dll
    c:/WINDOWS/system32ftpuitavwp.dll
    c:/WINDOWS/system32pb.sys
    c:/DELL/VIDEO/OUTPUTnetstat_base.txt
    c:/DELL/VIDEO/OUTPUTnetstat_post.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_base.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_post.txt
    c:/DELL/VIDEO/OUTPUTtaskv_base.txt
    c:/DELL/VIDEO/OUTPUTtaskv_post.txt
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuiteLive Security Suite Home Page.lnk
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuiteLive Security Suite.lnk
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuitePurchase License.lnk
    c:/Documents and Settings/dmc73144/Application Data/Microsoft/Internet Explorer/Quick LaunchLive Security Suite.lnk
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbconfig.cfg
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbpb.dll
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbTimeout.inf
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbUrls.inf
    c:/Documents and Settings/dmc73144/Application Data/Live Security SuiteHTUninstaller.exe
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suitesettings.ini
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suiteuill.ini
    c:/Documents and Settings/dmc73144/Application Data/Live Security SuiteUninstall Live Security Suite.lnk
    c:/Documents and Settings/dmc73144/DesktopLive Security Suite.lnk
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet Explorerbyfororand.exe
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowsforby.exe
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowspguard.ini
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowsservices.exe
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet Explorer_iGSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet Explorer_iMSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet Explorer_iPSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet Explorer_MSIMGSIZ.DAT
    c:/Documents and Settings/dmc73144/Local Settings/Temp~Timeout.inf.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp~Urls.inf.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cinstall[1].htm
    c:/Program Files/Live Security Suiteactivate.ico
    c:/Program Files/Live Security Suite/dbDBInfo.ver
    c:/Program Files/Live Security Suite/dbga090122.db
    c:/Program Files/Live Security Suite/dbInfected.wav
    c:/Program Files/Live Security Suite/dblists.ini
    c:/Program Files/Live Security Suiteexplorer.ico
    c:/Program Files/Live Security Suite/LanguagesLSSEs.lng
    c:/Program Files/Live Security Suite/LanguagesLSSFr.lng
    c:/Program Files/Live Security Suite/LanguagesLSSGer.lng
    c:/Program Files/Live Security Suite/LanguagesLSSIt.lng
    c:/Program Files/Live Security SuiteLiveSS.exe
    c:/Program Files/Live Security Suitereg.ico
    c:/Program Files/Live Security Suiteuninstall.ico
    c:/Program Files/Live Security Suiteworking.log
    c:/Program Files/Live Security Suite~LiveSS.tmp
    c:/WINDOWS/Prefetch7Z.EXE-1A62CD19.pf
    c:/WINDOWS/PrefetchBYFORORAND.EXE-1D953ACD.pf
    c:/WINDOWS/PrefetchCYGRUNSRV.EXE-01BF82AE.pf
    c:/WINDOWS/PrefetchLIVESS.EXE-2474900A.pf
    c:/WINDOWS/PrefetchNET.EXE-01A53C2F.pf
    c:/WINDOWS/PrefetchNET1.EXE-029B9DB4.pf
    c:/WINDOWS/PrefetchPING.EXE-31216D26.pf
    c:/WINDOWS/system32bgwbuphd.dll
    c:/WINDOWS/system32pb.sys
    c:/WINDOWS/system32vgtetfvt.dll
    c:/DELL/VIDEO/OUTPUTnetstat_base.txt
    c:/DELL/VIDEO/OUTPUTnetstat_post.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_base.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_post.txt
    c:/DELL/VIDEO/OUTPUTtaskv_base.txt
    c:/DELL/VIDEO/OUTPUTtaskv_post.txt
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuiteLive Security Suite Home Page.lnk
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuiteLive Security Suite.lnk
    c:/Documents and Settings/All Users/Start Menu/Programs/Live Security SuitePurchase License.lnk
    c:/Documents and Settings/dmc73144/Application Data/Microsoft/Internet Explorer/Quick LaunchLive Security Suite.lnk
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbconfig.cfg
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbpb.dll
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbTimeout.inf
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suite/dbUrls.inf
    c:/Documents and Settings/dmc73144/Application Data/Live Security SuiteHTUninstaller.exe
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suitesettings.ini
    c:/Documents and Settings/dmc73144/Application Data/Live Security Suiteuill.ini
    c:/Documents and Settings/dmc73144/Application Data/Live Security SuiteUninstall Live Security Suite.lnk
    c:/Documents and Settings/dmc73144/DesktopLive Security Suite.lnk
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet Explorerandonthe.exe
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowsandofonby.exe
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowspguard.ini
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Windowsservices.exe
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet Explorer_iGSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet Explorer_iMSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet Explorer_iPSh.png
    c:/Documents and Settings/dmc73144/Local Settings/Application Data/Microsoft/Internet Explorer_MSIMGSIZ.DAT
    c:/Documents and Settings/dmc73144/Local Settings/Temp~Timeout.inf.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp~Urls.inf.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cinstall[1].htm
    c:/Program Files/Live Security Suiteactivate.ico
    c:/Program Files/Live Security Suite/dbDBInfo.ver
    c:/Program Files/Live Security Suite/dbga090122.db
    c:/Program Files/Live Security Suite/dbInfected.wav
    c:/Program Files/Live Security Suite/dblists.ini
    c:/Program Files/Live Security Suiteexplorer.ico
    c:/Program Files/Live Security Suite/LanguagesLSSEs.lng
    c:/Program Files/Live Security Suite/LanguagesLSSFr.lng
    c:/Program Files/Live Security Suite/LanguagesLSSGer.lng
    c:/Program Files/Live Security Suite/LanguagesLSSIt.lng
    c:/Program Files/Live Security SuiteLiveSS.exe
    c:/Program Files/Live Security Suitereg.ico
    c:/Program Files/Live Security Suiteuninstall.ico
    c:/Program Files/Live Security Suiteworking.log
    c:/Program Files/Live Security Suite~LiveSS.tmp
    c:/WINDOWS/Prefetch7Z.EXE-1A62CD19.pf
    c:/WINDOWS/PrefetchANDONTHE.EXE-09758669.pf
    c:/WINDOWS/PrefetchLIVESS.EXE-2474900A.pf
    c:/WINDOWS/PrefetchNET.EXE-01A53C2F.pf
    c:/WINDOWS/PrefetchNET1.EXE-029B9DB4.pf
    c:/WINDOWS/PrefetchPING.EXE-31216D26.pf
    c:/WINDOWS/system32eooshej.dll
    c:/WINDOWS/system32ofkojdh.dll
    c:/WINDOWS/system32pb.sys
    c:netstat_post.txt
    c:tasksvc_post.txt
    c:taskv_post.txt

    Files (Deleted) - ICC Results

    ActionPathFile Name

    Files (Changed) - ICC Results

    ActionPathFile Name
    modifiedc:/Documents and Settings/dmc73144/Application Data/Mozilla/Firefox/Profiles/ektregxy.defaultprefs.js
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWS/system32/configsoftware.LOG
    modifiedc:/WINDOWS/system32/configsystem.LOG
    modifiedc:/WINDOWS/system32/wbem/Logswbemess.log
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.BTR
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.DATA
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144/Application Data/Mozilla/Firefox/Profiles/ektregxy.defaultprefs.js
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/system32/configsoftware.LOG
    modifiedc:/WINDOWS/system32/configsystem.LOG
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.BTR
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.DATA
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144/Application Data/Mozilla/Firefox/Profiles/ektregxy.defaultprefs.js
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/system32/configsoftware.LOG
    modifiedc:/WINDOWS/system32/configsystem.LOG
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.BTR
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.DATA
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144/Application Data/Mozilla/Firefox/Profiles/ektregxy.defaultprefs.js
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWS/system32/configsoftware.LOG
    modifiedc:/WINDOWS/system32/configsystem.LOG
    modifiedc:/WINDOWS/system32/wbem/Logswbemess.log
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.BTR
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.DATA
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWS/system32/configsoftware.LOG
    modifiedc:/WINDOWS/system32/configsystem.LOG
    modifiedc:/WINDOWS/system32/wbem/Logswbemess.log
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.BTR
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.DATA
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144/Application Data/Mozilla/Firefox/Profiles/ektregxy.defaultprefs.js
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSANDNET.EXE-2012C478.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWS/system32/configsoftware.LOG
    modifiedc:/WINDOWS/system32/configsystem.LOG
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.BTR
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.DATA
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144/Application Data/Mozilla/Firefox/Profiles/ektregxy.defaultprefs.js
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/system32/configsoftware.LOG
    modifiedc:/WINDOWS/system32/configsystem.LOG
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.BTR
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.DATA
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144/Application Data/Mozilla/Firefox/Profiles/ektregxy.defaultprefs.js
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWS/system32/configsoftware.LOG
    modifiedc:/WINDOWS/system32/configsystem.LOG
    modifiedc:/WINDOWS/system32/wbem/Logswbemess.log
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.BTR
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.DATA
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144/Application Data/Mozilla/Firefox/Profiles/ektregxy.defaultprefs.js
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWS/system32/configsoftware.LOG
    modifiedc:/WINDOWS/system32/configsystem.LOG
    modifiedc:/WINDOWS/system32/wbem/Logswbemess.log
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.BTR
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.DATA
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144/Application Data/Mozilla/Firefox/Profiles/ektregxy.defaultprefs.js
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWS/system32/configsoftware.LOG
    modifiedc:/WINDOWS/system32/configsystem.LOG
    modifiedc:/WINDOWS/system32/wbem/Logswbemess.log
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.BTR
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.DATA
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP

    Registry Keys (Added) - ICC Results

    ActionPath

    Registry Values (Added) - ICC Results

    ActionPathVal_NameVal_Data

    Registry Values (Deleted) - ICC Results

    ActionPathVal_NameVal_TypeMod_Val_TypeVal_DataMod_Val_Data

    Registry Values (Changed) - ICC Results

    ActionPathVal_NameVal_DataMod_Val_Data
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeedD6 DC 6A 05 32 6B C1 B9 FC FC 86 C0 5B B1 71 91 8A EC A1 BA 9A CE 61 92 91 F2 09 F3 D9 68 E0 CC 64 0B 46 AD 34 58 21 E6 24 69 4B 58 4C 03 82 18 2B C1 6A 18 97 C
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirstRunDisabled0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterAntiVirusDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirewallDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterUpdatesDisableNotify0x00000001 0x00000000
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed2B D1 1D F5 99 88 2A 37 68 F5 5C 73 8C B5 5F 16 45 70 CE 2E C9 C4 E0 09 49 5B C1 FA EC 82 28 9E 6E DB EE 91 58 20 FB 19 29 C8 31 DB 1D A7 69 64 6E 35 E7 D3 17 8
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirstRunDisabled0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterAntiVirusDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirewallDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterUpdatesDisableNotify0x00000001 0x00000000
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed07 A8 FD ED 3A 48 B7 8D E0 0C 86 BE 48 A0 3A 4D C6 AF 9C 67 54 1B 42 3F DF D0 62 E1 D8 8D 9C A9 83 99 36 A5 F5 3A BD 3B D0 AA 11 4D AF AE 3D 75 25 B3 CD 51 E5 7
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirstRunDisabled0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterAntiVirusDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirewallDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterUpdatesDisableNotify0x00000001 0x00000000
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed8C 4A FB 2A 30 2E DC 4C A8 5C 82 16 57 B5 A5 8E 3C B6 05 EE F9 3D 50 A3 61 AC 70 AF AB F7 34 F5 EF 8E 98 EC 3A F2 15 8E 58 93 CB 8C 93 D6 5B 43 43 7B 3F 4A 8A C
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirstRunDisabled0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterAntiVirusDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirewallDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterUpdatesDisableNotify0x00000001 0x00000000
    modifiedHKLM/SYSTEM/CurrentControlSet/Control/ServiceCurrent0x00000009 0x0000000A
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeedE8 D4 29 D4 D8 C1 2E 3D E2 A3 52 53 4B 76 AD 7D 2D C9 AC 07 41 BC AA BE 7D C2 95 5F 95 18 1A 32 B1 5F 00 2D 19 BA 3A 27 A4 23 DC 22 34 0F FE B0 17 86 D9 7A 01 6
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirstRunDisabled0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterAntiVirusDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirewallDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterUpdatesDisableNotify0x00000001 0x00000000
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed76 09 3A 48 7C 27 33 FB 7C 9A C2 F1 D4 58 57 5A F5 23 F0 82 E8 CF 71 27 AB 7E 53 CA B0 80 C8 06 64 9B D7 90 BD D2 F6 FD 09 3B 8B 39 E8 01 A6 38 85 C3 52 9B 3E 6
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirstRunDisabled0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterAntiVirusDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirewallDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterUpdatesDisableNotify0x00000001 0x00000000
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed79 B0 19 09 31 EF 12 1E 73 72 5C 9D 59 6B 08 B2 DB 22 80 0E 34 10 88 9D B6 96 F5 E1 74 A6 3C EA 13 45 F8 80 6B 00 01 44 5F 98 9F 1E AD 23 D2 24 1C A4 33 15 ED 9
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirstRunDisabled0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterAntiVirusDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirewallDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterUpdatesDisableNotify0x00000001 0x00000000
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed3B F6 8D C3 F5 59 76 53 3A 7D CA D3 79 A9 E3 87 B0 CE E7 55 4F A2 6A C4 13 52 EB AF 73 24 E4 E9 A1 50 AB 28 59 3F DF 48 E4 55 57 1C 4C E3 B3 0C F1 5B 4C 41 9F F
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirstRunDisabled0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterAntiVirusDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirewallDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterUpdatesDisableNotify0x00000001 0x00000000
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeedCE 06 91 85 EB E7 10 3D 61 74 C7 FE CF A3 54 2C 2A 46 56 23 DD 4B 63 89 E1 F1 42 A0 E7 6E FD FA 7D 81 83 8E AA 8C 37 35 C1 B3 18 8C 97 5C 29 AE 5F 50 73 FE 72 B
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirstRunDisabled0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterAntiVirusDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirewallDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterUpdatesDisableNotify0x00000001 0x00000000
    modifiedHKLM/SYSTEM/CurrentControlSet/Control/ServiceCurrent0x00000009 0x0000000A
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeedC1 FE 1E 31 FC D0 02 C5 31 63 49 13 52 45 68 07 F1 61 92 54 DE ED 4A 50 CB EB 58 16 5A 2B B7 05 ED B9 65 55 50 0B 56 65 06 56 54 25 7D E4 0B 78 14 AF 9A 03 07 C
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirstRunDisabled0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterAntiVirusDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterFirewallDisableNotify0x00000001 0x00000000
    modifiedHKLM/SOFTWARE/Microsoft/Security CenterUpdatesDisableNotify0x00000001 0x00000000
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed77 91 40 3A DA 18 80 33 88 70 4E 8B 91 A1 7E 9D 2B 76 80 BE 7C C9 1D DD 19 97 5C E5 66 83 97 98 3D E0 7A 7E 88 29 B5 0D C4 CC D5 94 79 C3 03 43 60 38 A0 E9 D5 E
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001

    DNS Results

    DNSDNS Response
    live.comStandard query response A 65.55.206.154
    microsoft.comStandard query response A 207.46.232.182 A 207.46.197.32
    www.google.comStandard query response A 8.15.228.161 A 69.25.212.57
    livesgenpayment.comStandard query response A 208.73.210.29
    xoomer.alice.itStandard query response A 62.211.68.12
    livesecsuite.comStandard query response A 62.122.73.76
    www.livesecsuite.comStandard query response A 62.122.73.76
    www.google.comStandard query response A 69.25.212.57 A 8.15.228.161
    microsoft.comStandard query response A 207.46.197.32 A 207.46.232.182

    URL Results

    DstIPHTTP_HOSTHTTP_REQUEST_URIHTTP_USER_AGENTPROTOCOL
    65.55.206.154live.com/installMozilla/3.0 (compatible; TALWinInetHTTPClient)0x06
    239.255.255.250239.255.255.250:1900*--blank--0x11

    ARGUS PROTOCOL Results

    PROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    6412928252033
    17203500

    ARGUS DPORT Results

    DPORTPROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    806292020991487
    4436129726546
    190017203500

    ARGUS DATA Results

    TimeDateProtocolSrcIPDstIPDirFlagsSportDportPktsBytes
    00:46:422010-10-11610.10.10.765.55.206.154-> e 558806364
    00:46:422010-10-11610.10.10.78.15.228.161-> e 559807424
    00:46:422010-10-11610.10.10.7208.73.210.29-> e 5614437424
    00:47:022010-10-11610.10.10.765.55.206.154-> e 6018091162
    05:31:142010-10-11610.10.10.7208.73.210.29-> e 5574437424
    05:31:152010-10-11610.10.10.765.55.206.154-> e 558807424
    05:31:152010-10-11610.10.10.7208.73.210.29-> e 5594437424
    05:31:162010-10-11610.10.10.762.122.73.76-> e 562807424
    05:31:172010-10-11610.10.10.7207.46.232.182-> e 556807424
    05:31:352010-10-11610.10.10.765.55.206.154-> e 56380101222
    00:51:392010-10-111710.10.10.7239.255.255.250-> e 819002350
    05:36:172010-10-111710.10.10.7239.255.255.250-> e 819002350
    16:04:332010-10-11610.10.10.765.55.206.154-> e 238806364
    16:04:332010-10-11610.10.10.762.211.68.12-> e 268807424
    16:04:332010-10-11610.10.10.7208.73.210.29-> e 3934437424
    16:04:342010-10-11610.10.10.762.122.73.76-> e 444807424
    16:04:532010-10-11610.10.10.765.55.206.154-> e 388091162
    23:00:362010-10-11610.10.10.762.211.68.12-> e 526807424
    23:00:362010-10-11610.10.10.7208.73.210.29-> e 5274437424
    23:00:372010-10-11610.10.10.762.122.73.76-> e 531807424
    23:00:392010-10-11610.10.10.765.55.206.154-> e 402807424
    23:00:552010-10-11610.10.10.765.55.206.154-> e 5718091162
    16:09:412010-10-111710.10.10.7239.255.255.250-> e 819002350
    23:05:572010-10-111710.10.10.7239.255.255.250-> e 819002350
    18:09:412010-10-12610.10.10.765.55.206.154-> e 557807424
    18:09:412010-10-12610.10.10.7208.73.210.29-> e 5584437424
    18:09:422010-10-12610.10.10.762.122.73.76-> e 563807424
    18:10:012010-10-12610.10.10.765.55.206.154-> e 5708091162
    08:04:102010-10-13610.10.10.7207.46.197.32-> e 289807424
    08:04:102010-10-13610.10.10.7208.73.210.29-> e 5384437424
    08:04:112010-10-13610.10.10.762.211.68.12-> e 541807424
    08:04:312010-10-13610.10.10.765.55.206.154-> e 5808091162
    18:14:422010-10-121710.10.10.7239.255.255.250-> e 819002350
    08:09:102010-10-131710.10.10.7239.255.255.250-> e 819002350
    15:26:462010-10-13610.10.10.7207.46.232.182-> e 549807424
    15:26:462010-10-13610.10.10.7208.73.210.29-> e 5504437424
    15:26:462010-10-13610.10.10.765.55.206.154-> e 553806364
    15:27:042010-10-13610.10.10.765.55.206.154-> e 5578091162
    01:36:092010-10-14610.10.10.7207.46.232.182-> e 556807424
    01:36:092010-10-14610.10.10.7208.73.210.29-> e 5644437424
    01:36:312010-10-14610.10.10.765.55.206.154-> e 2568091162
    15:31:532010-10-131710.10.10.7239.255.255.250-> e 819002350
    01:41:082010-10-141710.10.10.7239.255.255.250-> e 819002350
    13:57:012010-10-14610.10.10.765.55.206.154-> e 344807424
    13:57:012010-10-14610.10.10.78.15.228.161-> e 346806364
    13:57:012010-10-14610.10.10.7208.73.210.29-> e 3474437424
    13:57:022010-10-14610.10.10.762.122.73.76-> e 522807424
    13:57:202010-10-14610.10.10.765.55.206.154-> e 56180101222
    14:02:242010-10-141710.10.10.7239.255.255.250-> e 819002350
    20:18:382010-10-14610.10.10.7207.46.197.32-> e 554806364
    20:18:382010-10-14610.10.10.762.122.73.76-> e 555807424
    20:18:382010-10-14610.10.10.7208.73.210.29-> e 5574436364
    20:18:382010-10-14610.10.10.7208.73.210.29-> e 5594437424
    20:18:572010-10-14610.10.10.765.55.206.154-> e 5658091162
    20:23:432010-10-141710.10.10.7239.255.255.250-> e 819002350

    Packer Results

    Packer Name

    HoneyTrap Results

    Honey Trap Log File Location

    PTFB Results

    PTFB Log File Location