New
#11
The results
ThanksCode:Microsoft Windows [Version 6.1.7601] Copyright (c) 2009 Microsoft Corporation. All rights reserved. C:\Windows\system32>SC QUERYEX CRYPTSVC SERVICE_NAME: CRYPTSVC TYPE : 20 WIN32_SHARE_PROCESS STATE : 4 RUNNING (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN) WIN32_EXIT_CODE : 0 (0x0) SERVICE_EXIT_CODE : 0 (0x0) CHECKPOINT : 0x0 WAIT_HINT : 0x0 PID : 1288 FLAGS : C:\Windows\system32>SC QUERYEX CRYPTSVC SERVICE_NAME: CRYPTSVC TYPE : 20 WIN32_SHARE_PROCESS STATE : 4 RUNNING (STOPPABLE, NOT_PAUSABLE, ACCEPTS_SHUTDOWN) WIN32_EXIT_CODE : 0 (0x0) SERVICE_EXIT_CODE : 0 (0x0) CHECKPOINT : 0x0 WAIT_HINT : 0x0 PID : 1288 FLAGS : C:\Windows\system32>SC SDSHOW CRYPTSVC D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCR RC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) C:\Windows\system32>ICACLS C:\Windows\System32\sppc.dll C:\Windows\System32\sppc.dll NT SERVICE\TrustedInstaller:(F) BUILTIN\Administrators:(RX) NT AUTHORITY\SYSTEM:(RX) BUILTIN\Users:(RX) Successfully processed 1 files; Failed processing 0 files C:\Windows\system32>ICACLS C:\Windows\System32\slc.dll C:\Windows\System32\slc.dll NT SERVICE\TrustedInstaller:(F) BUILTIN\Administrators:(RX) NT AUTHORITY\SYSTEM:(RX) BUILTIN\Users:(RX) Successfully processed 1 files; Failed processing 0 files C:\Windows\system32>ICACLS C:\Windows\System32\slcext.dll C:\Windows\System32\slcext.dll NT SERVICE\TrustedInstaller:(F) BUILTIN\Administrators:(RX) NT AUTHORITY\SYSTEM:(RX) BUILTIN\Users:(RX) Successfully processed 1 files; Failed processing 0 files C:\Windows\system32>ICACLS C:\Windows\System32\sppcomapi.dll C:\Windows\System32\sppcomapi.dll NT SERVICE\TrustedInstaller:(F) BUILTIN\Administrators:(RX) NT AUTHORITY\SYSTEM:(RX) BUILTIN\Users:(RX) Successfully processed 1 files; Failed processing 0 files C:\Windows\system32>ICACLS C:\Windows\System32\sppsvc.exe C:\Windows\System32\sppsvc.exe NT SERVICE\TrustedInstaller:(F) BUILTIN\Administrators:(RX) NT AUTHORITY\SYSTEM:(RX) BUILTIN\Users:(RX) Successfully processed 1 files; Failed processing 0 files C:\Windows\system32>ICACLS C:\Windows\System32\SPPWMI.DLL C:\Windows\System32\SPPWMI.DLL NT SERVICE\TrustedInstaller:(F) BUILTIN\Administrators:(RX) NT AUTHORITY\SYSTEM:(RX) BUILTIN\Users:(RX) Successfully processed 1 files; Failed processing 0 files C:\Windows\system32>ICACLS C:\Windows\System32\SPP.DLL C:\Windows\System32\SPP.DLL NT SERVICE\TrustedInstaller:(F) BUILTIN\Administrators:(RX) NT AUTHORITY\SYSTEM:(RX) BUILTIN\Users:(RX) Successfully processed 1 files; Failed processing 0 files C:\Windows\system32>ICACLS C:\Windows\System32\SLWGA.DLL C:\Windows\System32\SLWGA.DLL NT SERVICE\TrustedInstaller:(F) BUILTIN\Administrators:(RX) NT AUTHORITY\SYSTEM:(RX) BUILTIN\Users:(RX) Successfully processed 1 files; Failed processing 0 files C:\Windows\system32>REG QUERY HKU HKEY_USERS\.DEFAULT HKEY_USERS\S-1-5-19 HKEY_USERS\S-1-5-20 HKEY_USERS\S-1-5-21-2252157477-423583748-1435103908-1001 HKEY_USERS\S-1-5-21-2252157477-423583748-1435103908-1001_Classes HKEY_USERS\S-1-5-18 C:\Windows\system32>REG QUERY HKU\S-1-5-20 HKEY_USERS\S-1-5-20\AppEvents HKEY_USERS\S-1-5-20\Console HKEY_USERS\S-1-5-20\Control Panel HKEY_USERS\S-1-5-20\Environment HKEY_USERS\S-1-5-20\EUDC HKEY_USERS\S-1-5-20\Keyboard Layout HKEY_USERS\S-1-5-20\Network HKEY_USERS\S-1-5-20\Printers HKEY_USERS\S-1-5-20\Software HKEY_USERS\S-1-5-20\System C:\Windows\system32>REG QUERY HKU\S-1-5-20\Environment HKEY_USERS\S-1-5-20\Environment TEMP REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Temp TMP REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Temp C:\Windows\system32>REG QUERY HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ ProfileList\S-1-5-20 C:\Windows\system32>