ComboFix 14-04-30.01 - lee 05/02/2014 20:35:12.1.4 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.8190.6099 [GMT -4:00]
Running from: c:\users\lee\Desktop\ComboFix.exe
AV: Emsisoft Anti-Malware *Disabled/Updated* {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Emsisoft Anti-Malware *Disabled/Updated* {3E653F0B-EA3E-10F8-1B87-CAD78F211367}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\programdata\ZeoBIT
c:\programdata\ZeoBIT\PCKeeper\history.xml
c:\users\lee\AppData\Roaming\Adobe\plugs
c:\users\lee\AppData\Roaming\Adobe\shed
c:\users\lee\AppData\Roaming\chrtmp
c:\users\lee\AppData\Roaming\inst.exe
c:\users\lee\AppData\Roaming\Microsoft\AdjMmsVista.dll
c:\users\lee\AppData\Roaming\vso_ts_preview.xml
c:\users\lee\GoToAssistDownloadHelper.exe
c:\windows\MICROSOFT
c:\windows\MICROSOFT\System Update kb70007\Installer.dll
c:\windows\MICROSOFT\System Update kb70007\InstallerLibrary.dll
c:\windows\MICROSOFT\System Update kb70007\win32.reg
c:\windows\MICROSOFT\System Update kb70007\WindowsUpdater.exe
c:\windows\SysWow64\drivers\npf.sys
c:\windows\SysWow64\Packet.dll
c:\windows\SysWow64\pthreadVC.dll
c:\windows\SysWow64\wpcap.dll
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_NPF
-------\Service_System Update kb70007
-------\Service_System Update kb70007
.
.
((((((((((((((((((((((((( Files Created from 2014-04-03 to 2014-05-03 )))))))))))))))))))))))))))))))
.
.
2014-05-03 00:46 . 2014-05-03 00:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-05-03 00:46 . 2014-05-03 00:46 -------- d-----w- c:\users\AppData\AppData\Local\temp
2014-05-03 00:20 . 2014-04-16 07:22 10651704 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5F130446-1135-48B0-8234-0EAA74776B09}\mpengine.dll
2014-05-02 19:25 . 2014-05-02 19:28 -------- d-----w- C:\ANTIVIRUS NEW JUNKWARE REMOVE TOOL
2014-05-02 13:51 . 2014-04-16 07:22 10651704 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-05-02 01:58 . 2014-05-02 02:39 -------- d-----w- C:\AdwCleaner
2014-05-02 01:42 . 2014-05-02 01:42 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{29A5DB2B-E07B-4ECC-BD4F-C0D183236427}\gapaengine.dll
2014-05-02 01:39 . 2014-05-02 01:39 -------- d-----w- c:\windows\ERUNT
2014-05-02 01:30 . 2014-05-02 01:30 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2014-05-02 01:18 . 2014-05-02 01:18 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2014-05-02 01:18 . 2014-05-02 01:18 -------- d-----w- c:\program files\Microsoft Security Client
2014-05-02 00:47 . 2014-05-02 00:45 313256 ----a-w- c:\windows\system32\javaws.exe
2014-05-02 00:46 . 2014-05-02 00:46 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2014-05-02 00:46 . 2014-05-02 00:45 189352 ----a-w- c:\windows\system32\javaw.exe
2014-05-02 00:46 . 2014-05-02 00:45 189352 ----a-w- c:\windows\system32\java.exe
2014-05-02 00:45 . 2014-05-02 00:45 -------- d-----w- c:\program files\Java
2014-05-02 00:01 . 2014-05-02 00:01 0 ----a-w- c:\windows\SysWow64\RENBC87.tmp
2014-05-02 00:01 . 2014-05-02 00:01 0 ----a-w- c:\windows\SysWow64\RENBC86.tmp
2014-05-02 00:01 . 2014-05-02 00:01 0 ----a-w- c:\windows\SysWow64\RENBC85.tmp
2014-05-01 23:50 . 2014-05-01 23:50 -------- d-----w- c:\users\lee\AppData\Local\Avg2013
2014-05-01 15:59 . 2014-05-01 15:59 -------- d-----w- c:\programdata\Immunet
2014-05-01 15:58 . 2014-05-02 01:04 -------- d-----w- c:\program files\Immunet
2014-05-01 15:48 . 2013-09-02 07:58 175528 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2014-05-01 15:24 . 2014-05-01 15:24 -------- d-----w- c:\program files\Pale Moon
2014-05-01 15:17 . 2014-05-02 02:16 -------- d-----w- C:\download 5
2014-04-30 19:13 . 2014-04-30 19:13 -------- d-----w- c:\users\lee\AppData\Roaming\MiniGet
2014-04-30 19:13 . 2014-04-30 23:02 -------- d-----w- c:\program files (x86)\MiniGet
2014-04-30 19:12 . 2014-04-30 19:12 -------- d-----w- c:\program files (x86)\Worldwide Web Research
2014-04-30 19:12 . 2014-04-30 19:12 -------- d-----w- c:\program files (x86)\MSR
2014-04-28 02:55 . 2014-04-28 02:55 -------- d-----w- c:\windows\system32\SRSLabs
2014-04-28 02:53 . 2014-04-28 02:53 154840 ----a-w- c:\windows\system32\RCoInstII64.dll
2014-04-28 02:53 . 2014-04-28 02:53 2770976 ----a-w- c:\windows\system32\FMAPO64.dll
2014-04-28 02:53 . 2014-04-28 02:53 113576 ----a-w- c:\windows\system32\CONEQMSAPOGUILibrary.dll
2014-04-28 02:53 . 2014-04-28 02:53 209096 ----a-w- c:\windows\system32\AERTAC64.dll
2014-04-28 02:53 . 2014-04-28 02:53 108640 ----a-w- c:\windows\system32\AERTAR64.dll
2014-04-28 01:28 . 2014-04-28 01:28 -------- d-----w- C:\found.000
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-02 18:51 . 2012-04-06 19:03 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-05-02 18:51 . 2011-05-27 22:28 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-04-28 22:17 . 2009-08-20 03:15 281288 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-04-28 22:17 . 2009-08-20 03:15 281288 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-04-28 02:54 . 2009-08-18 04:28 2787032 ----a-w- c:\windows\system32\RtkAPO64.dll
2014-04-26 01:05 . 2009-08-20 03:15 290776 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-03-11 13:52 . 2014-03-11 13:52 133928 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2014-03-10 22:17 . 2013-12-23 21:40 128288 ----a-w- c:\windows\system32\IObitSmartDefragExtension.dll
2014-02-03 21:14 . 2014-02-03 21:14 12872 ----a-w- c:\windows\system32\bootdelete.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="c:\program files (x86)\Common Files\AOL\1250564758\ee\AOLSoftware.exe" [2010-03-08 41800]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files (x86)\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files (x86)\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R3 7ByteIo;7ByteIo;c:\program files (x86)\Hot CPU Tester Pro 4 LE\SysInfoX64.sys;c:\program files (x86)\Hot CPU Tester Pro 4 LE\SysInfoX64.sys [x]
R3 a2acc;a2acc;c:\program files (x86)\EMSISOFT ANTI-MALWARE\a2accx64.sys;c:\program files (x86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [x]
R4 a2AntiMalware;Emsisoft Anti-Malware 8.0 - Service;c:\program files (x86)\Emsisoft Anti-Malware\a2service.exe;c:\program files (x86)\Emsisoft Anti-Malware\a2service.exe [x]
S1 A2DDA;A2 Direct Disk Access Support Driver;c:\program files (x86)\Emsisoft Anti-Malware\a2ddax64.sys;c:\program files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [x]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Themes
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-06-20 20:05 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-12-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-09-28 11:03]
.
2013-12-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-09-28 11:03]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2013-12-10 2279712]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = http=127.0.0.1:8118;https=127.0.0.1:8118
uSearchAssistant = Google
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\lee\AppData\Roaming\Mozilla\Firefox\Profiles\g84aw4dt.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.sysnative.com/forums/security-arena/9693-corrine-help-please.html#post72139
FF - prefs.js: network.proxy.http - 119.110.73.23
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKLM-Run-EfficientReminderFree - (no file)
SafeBoot-CleanHlp
SafeBoot-CleanHlp.sys
AddRemove-Coupon Printer for Windows5.0.0.1 - c:\program files (x86)\Coupons\uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4d,53,f2,a0,d0,d2,6e,4c,aa,e6,2c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4d,53,f2,a0,d0,d2,6e,4c,aa,e6,2c,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4d,53,f2,a0,d0,d2,6e,4c,aa,e6,2c,\
.
[HKEY_USERS\S-1-5-21-4147492450-2785938924-1459033839-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:80,59,9b,da,d1,bc,68,a2,1a,39,bb,61,34,61,83,89,5a,4c,2c,54,23,
10,19,f0,a8,42,bb,26,56,f6,23,58,43,49,b8,ea,28,68,82,47,aa,8f,da,c9,da,54,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_206_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_206_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_206_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_206_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.13"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG12.00.00.01PROFESSIONAL"="70DD9C885D1A5FDA04FC1F07BC0AFC74BC2C4A216464E0B4E7DDABEAD7E40FF2C7F888212866B26CFA9D8C2A073CAC86367D3F1927077823C9BE57CE67A86502FD75D21E5A4194B2BB29E58B123C539700EA36944372BC7A297CE98D33562F288D8700077B308D2EE4E1FECC197159927F66F06E499012AB505BB35AC1766F03C3E40E8829FE5D44E91121B26D8759C36CEBA623E18C910F5BA4F68BADD6DA0FC1C7EB7112BC753B10800B26F5EFA2DCD1F47FFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6171C11EC38DE3D5D575E7D6A3B9808A6171C11EC38DE3D58C5257B1FFE081C09E16DE1DFB9C751CD2A07AF752D45DBF6EACA075BAF3026D09286424281C1129BBBCC7ED58892ED1913CF878BD802472483500C088FAC835D381F1A8EF272CAE5EFAA7E07F68DCD289899628E79B743324100411765E2D4A4E0162EA393FD3DA6D98E69FB084DCF736A6F400E77CBBE764D034845A0A9367446565D04F6CD51C26D45F923956ACC19CF9DDC038F281A66E0C876B1825C393ABA0EB81B804AE3C4AD5EA1CCC9018EDCA2B4A247D3BAAF1DCB0357DE2158E00CA0320AB36E66C65835AE82AFA4B2D123D28A3318277448D972A7A6B46601A4217278C77E4E133E4EAFCD74637A2449F4E038639943CBA4FE4AF0D6FE0F3C71543BDBA38F024A039C60188367F2FC1B82E49ABAD035397693E05C8CEB2DF526271B9DFDDF4186C2DA1BAE6E1B896A619B075276295C3B65C253ADA190279B19BCC63E6E4B96461F464AF3A8C58D1D2AB78646076FEF538B5BD5E823E2372110DC0706BF136190AB406A115B10244AF66F359E10587607F850305AD3BFE97C48F3B601705AD3E872CD8DF1DE86C3AABD81FAC76CF8CD60B0383D8EA8E421A7F091C7FDB22A74DE701858C6C69A3878694FCFF3A5CBA66C29CEEA584A7713A22F693D0FEBEF1EFD966A8383D2A3A2F7575FC3977E2F053ECDF1BECE18FCCAEE1953308BB8F9005E4A37DCE07D59F56B5ADA78EC6AE54369FDA5CE4A226223933DCB4C8FE67E1D14E29246D970D9799CB710246F13168C898B0FC6E9ADF5D01B9A7351F97794CB3CAF3635308C2749D629F19061D2C9E23ABE7BE58F366CD794A40C95EC23B93676F07DB16763A4D56BDC141EC7BCEF1A1F525700E167DB1213C37E7F51544E5D67D96B59473E9C62B0F5B23CEB93DB5C5C74377A4A23BF2E2C53D70CD0A71611B416A3DDDC98BC06FB89A9F2DAD041249CC952D1777FF82DF9A4C54B5BF0B9F90B416E8476A1972E2D21FC5BE520BCC38DE702955CC5C9E51D7B9EE123B644121A6DBA262A3C2019233C50A5A162CCE0DF5A46692DF25901378ED887A0B3A829959E97314F80325BC2CB6F12672D52F1CA9FC183E5B8B3"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\system32\hasplms.exe
c:\hp\HPEZBTN\HPBtnSrv.exe
c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\windows\SysWOW64\nlssrv32.exe
c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe
c:\program files (x86)\IObit\Driver Booster\DriverBooster.exe
.
**************************************************************************
.
Completion time: 2014-05-02 20:58:51 - machine was rebooted
ComboFix-quarantined-files.txt 2014-05-03 00:58
.
Pre-Run: 310,281,203,712 bytes free
Post-Run: 309,710,282,752 bytes free
.
- - End Of File - - E78C41D4C612124BBCB1DA37F9753C7A
03BA8F890B47C0BE359A4D5A636D214D
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.8190.6099 [GMT -4:00]
Running from: c:\users\lee\Desktop\ComboFix.exe
AV: Emsisoft Anti-Malware *Disabled/Updated* {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Emsisoft Anti-Malware *Disabled/Updated* {3E653F0B-EA3E-10F8-1B87-CAD78F211367}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\programdata\ZeoBIT
c:\programdata\ZeoBIT\PCKeeper\history.xml
c:\users\lee\AppData\Roaming\Adobe\plugs
c:\users\lee\AppData\Roaming\Adobe\shed
c:\users\lee\AppData\Roaming\chrtmp
c:\users\lee\AppData\Roaming\inst.exe
c:\users\lee\AppData\Roaming\Microsoft\AdjMmsVista.dll
c:\users\lee\AppData\Roaming\vso_ts_preview.xml
c:\users\lee\GoToAssistDownloadHelper.exe
c:\windows\MICROSOFT
c:\windows\MICROSOFT\System Update kb70007\Installer.dll
c:\windows\MICROSOFT\System Update kb70007\InstallerLibrary.dll
c:\windows\MICROSOFT\System Update kb70007\win32.reg
c:\windows\MICROSOFT\System Update kb70007\WindowsUpdater.exe
c:\windows\SysWow64\drivers\npf.sys
c:\windows\SysWow64\Packet.dll
c:\windows\SysWow64\pthreadVC.dll
c:\windows\SysWow64\wpcap.dll
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_NPF
-------\Service_System Update kb70007
-------\Service_System Update kb70007
.
.
((((((((((((((((((((((((( Files Created from 2014-04-03 to 2014-05-03 )))))))))))))))))))))))))))))))
.
.
2014-05-03 00:46 . 2014-05-03 00:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-05-03 00:46 . 2014-05-03 00:46 -------- d-----w- c:\users\AppData\AppData\Local\temp
2014-05-03 00:20 . 2014-04-16 07:22 10651704 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5F130446-1135-48B0-8234-0EAA74776B09}\mpengine.dll
2014-05-02 19:25 . 2014-05-02 19:28 -------- d-----w- C:\ANTIVIRUS NEW JUNKWARE REMOVE TOOL
2014-05-02 13:51 . 2014-04-16 07:22 10651704 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-05-02 01:58 . 2014-05-02 02:39 -------- d-----w- C:\AdwCleaner
2014-05-02 01:42 . 2014-05-02 01:42 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{29A5DB2B-E07B-4ECC-BD4F-C0D183236427}\gapaengine.dll
2014-05-02 01:39 . 2014-05-02 01:39 -------- d-----w- c:\windows\ERUNT
2014-05-02 01:30 . 2014-05-02 01:30 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2014-05-02 01:18 . 2014-05-02 01:18 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2014-05-02 01:18 . 2014-05-02 01:18 -------- d-----w- c:\program files\Microsoft Security Client
2014-05-02 00:47 . 2014-05-02 00:45 313256 ----a-w- c:\windows\system32\javaws.exe
2014-05-02 00:46 . 2014-05-02 00:46 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2014-05-02 00:46 . 2014-05-02 00:45 189352 ----a-w- c:\windows\system32\javaw.exe
2014-05-02 00:46 . 2014-05-02 00:45 189352 ----a-w- c:\windows\system32\java.exe
2014-05-02 00:45 . 2014-05-02 00:45 -------- d-----w- c:\program files\Java
2014-05-02 00:01 . 2014-05-02 00:01 0 ----a-w- c:\windows\SysWow64\RENBC87.tmp
2014-05-02 00:01 . 2014-05-02 00:01 0 ----a-w- c:\windows\SysWow64\RENBC86.tmp
2014-05-02 00:01 . 2014-05-02 00:01 0 ----a-w- c:\windows\SysWow64\RENBC85.tmp
2014-05-01 23:50 . 2014-05-01 23:50 -------- d-----w- c:\users\lee\AppData\Local\Avg2013
2014-05-01 15:59 . 2014-05-01 15:59 -------- d-----w- c:\programdata\Immunet
2014-05-01 15:58 . 2014-05-02 01:04 -------- d-----w- c:\program files\Immunet
2014-05-01 15:48 . 2013-09-02 07:58 175528 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2014-05-01 15:24 . 2014-05-01 15:24 -------- d-----w- c:\program files\Pale Moon
2014-05-01 15:17 . 2014-05-02 02:16 -------- d-----w- C:\download 5
2014-04-30 19:13 . 2014-04-30 19:13 -------- d-----w- c:\users\lee\AppData\Roaming\MiniGet
2014-04-30 19:13 . 2014-04-30 23:02 -------- d-----w- c:\program files (x86)\MiniGet
2014-04-30 19:12 . 2014-04-30 19:12 -------- d-----w- c:\program files (x86)\Worldwide Web Research
2014-04-30 19:12 . 2014-04-30 19:12 -------- d-----w- c:\program files (x86)\MSR
2014-04-28 02:55 . 2014-04-28 02:55 -------- d-----w- c:\windows\system32\SRSLabs
2014-04-28 02:53 . 2014-04-28 02:53 154840 ----a-w- c:\windows\system32\RCoInstII64.dll
2014-04-28 02:53 . 2014-04-28 02:53 2770976 ----a-w- c:\windows\system32\FMAPO64.dll
2014-04-28 02:53 . 2014-04-28 02:53 113576 ----a-w- c:\windows\system32\CONEQMSAPOGUILibrary.dll
2014-04-28 02:53 . 2014-04-28 02:53 209096 ----a-w- c:\windows\system32\AERTAC64.dll
2014-04-28 02:53 . 2014-04-28 02:53 108640 ----a-w- c:\windows\system32\AERTAR64.dll
2014-04-28 01:28 . 2014-04-28 01:28 -------- d-----w- C:\found.000
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-02 18:51 . 2012-04-06 19:03 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-05-02 18:51 . 2011-05-27 22:28 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-04-28 22:17 . 2009-08-20 03:15 281288 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-04-28 22:17 . 2009-08-20 03:15 281288 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-04-28 02:54 . 2009-08-18 04:28 2787032 ----a-w- c:\windows\system32\RtkAPO64.dll
2014-04-26 01:05 . 2009-08-20 03:15 290776 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-03-11 13:52 . 2014-03-11 13:52 133928 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2014-03-10 22:17 . 2013-12-23 21:40 128288 ----a-w- c:\windows\system32\IObitSmartDefragExtension.dll
2014-02-03 21:14 . 2014-02-03 21:14 12872 ----a-w- c:\windows\system32\bootdelete.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="c:\program files (x86)\Common Files\AOL\1250564758\ee\AOLSoftware.exe" [2010-03-08 41800]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files (x86)\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files (x86)\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R3 7ByteIo;7ByteIo;c:\program files (x86)\Hot CPU Tester Pro 4 LE\SysInfoX64.sys;c:\program files (x86)\Hot CPU Tester Pro 4 LE\SysInfoX64.sys [x]
R3 a2acc;a2acc;c:\program files (x86)\EMSISOFT ANTI-MALWARE\a2accx64.sys;c:\program files (x86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [x]
R4 a2AntiMalware;Emsisoft Anti-Malware 8.0 - Service;c:\program files (x86)\Emsisoft Anti-Malware\a2service.exe;c:\program files (x86)\Emsisoft Anti-Malware\a2service.exe [x]
S1 A2DDA;A2 Direct Disk Access Support Driver;c:\program files (x86)\Emsisoft Anti-Malware\a2ddax64.sys;c:\program files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [x]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Themes
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-06-20 20:05 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-12-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-09-28 11:03]
.
2013-12-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-09-28 11:03]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2013-12-10 2279712]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = http=127.0.0.1:8118;https=127.0.0.1:8118
uSearchAssistant = Google
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\lee\AppData\Roaming\Mozilla\Firefox\Profiles\g84aw4dt.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.sysnative.com/forums/security-arena/9693-corrine-help-please.html#post72139
FF - prefs.js: network.proxy.http - 119.110.73.23
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKLM-Run-EfficientReminderFree - (no file)
SafeBoot-CleanHlp
SafeBoot-CleanHlp.sys
AddRemove-Coupon Printer for Windows5.0.0.1 - c:\program files (x86)\Coupons\uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4d,53,f2,a0,d0,d2,6e,4c,aa,e6,2c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4d,53,f2,a0,d0,d2,6e,4c,aa,e6,2c,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4d,53,f2,a0,d0,d2,6e,4c,aa,e6,2c,\
.
[HKEY_USERS\S-1-5-21-4147492450-2785938924-1459033839-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:80,59,9b,da,d1,bc,68,a2,1a,39,bb,61,34,61,83,89,5a,4c,2c,54,23,
10,19,f0,a8,42,bb,26,56,f6,23,58,43,49,b8,ea,28,68,82,47,aa,8f,da,c9,da,54,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_206_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_206_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_206_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_206_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.13"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG12.00.00.01PROFESSIONAL"="70DD9C885D1A5FDA04FC1F07BC0AFC74BC2C4A216464E0B4E7DDABEAD7E40FF2C7F888212866B26CFA9D8C2A073CAC86367D3F1927077823C9BE57CE67A86502FD75D21E5A4194B2BB29E58B123C539700EA36944372BC7A297CE98D33562F288D8700077B308D2EE4E1FECC197159927F66F06E499012AB505BB35AC1766F03C3E40E8829FE5D44E91121B26D8759C36CEBA623E18C910F5BA4F68BADD6DA0FC1C7EB7112BC753B10800B26F5EFA2DCD1F47FFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6171C11EC38DE3D5D575E7D6A3B9808A6171C11EC38DE3D58C5257B1FFE081C09E16DE1DFB9C751CD2A07AF752D45DBF6EACA075BAF3026D09286424281C1129BBBCC7ED58892ED1913CF878BD802472483500C088FAC835D381F1A8EF272CAE5EFAA7E07F68DCD289899628E79B743324100411765E2D4A4E0162EA393FD3DA6D98E69FB084DCF736A6F400E77CBBE764D034845A0A9367446565D04F6CD51C26D45F923956ACC19CF9DDC038F281A66E0C876B1825C393ABA0EB81B804AE3C4AD5EA1CCC9018EDCA2B4A247D3BAAF1DCB0357DE2158E00CA0320AB36E66C65835AE82AFA4B2D123D28A3318277448D972A7A6B46601A4217278C77E4E133E4EAFCD74637A2449F4E038639943CBA4FE4AF0D6FE0F3C71543BDBA38F024A039C60188367F2FC1B82E49ABAD035397693E05C8CEB2DF526271B9DFDDF4186C2DA1BAE6E1B896A619B075276295C3B65C253ADA190279B19BCC63E6E4B96461F464AF3A8C58D1D2AB78646076FEF538B5BD5E823E2372110DC0706BF136190AB406A115B10244AF66F359E10587607F850305AD3BFE97C48F3B601705AD3E872CD8DF1DE86C3AABD81FAC76CF8CD60B0383D8EA8E421A7F091C7FDB22A74DE701858C6C69A3878694FCFF3A5CBA66C29CEEA584A7713A22F693D0FEBEF1EFD966A8383D2A3A2F7575FC3977E2F053ECDF1BECE18FCCAEE1953308BB8F9005E4A37DCE07D59F56B5ADA78EC6AE54369FDA5CE4A226223933DCB4C8FE67E1D14E29246D970D9799CB710246F13168C898B0FC6E9ADF5D01B9A7351F97794CB3CAF3635308C2749D629F19061D2C9E23ABE7BE58F366CD794A40C95EC23B93676F07DB16763A4D56BDC141EC7BCEF1A1F525700E167DB1213C37E7F51544E5D67D96B59473E9C62B0F5B23CEB93DB5C5C74377A4A23BF2E2C53D70CD0A71611B416A3DDDC98BC06FB89A9F2DAD041249CC952D1777FF82DF9A4C54B5BF0B9F90B416E8476A1972E2D21FC5BE520BCC38DE702955CC5C9E51D7B9EE123B644121A6DBA262A3C2019233C50A5A162CCE0DF5A46692DF25901378ED887A0B3A829959E97314F80325BC2CB6F12672D52F1CA9FC183E5B8B3"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\system32\hasplms.exe
c:\hp\HPEZBTN\HPBtnSrv.exe
c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\windows\SysWOW64\nlssrv32.exe
c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe
c:\program files (x86)\IObit\Driver Booster\DriverBooster.exe
.
**************************************************************************
.
Completion time: 2014-05-02 20:58:51 - machine was rebooted
ComboFix-quarantined-files.txt 2014-05-03 00:58
.
Pre-Run: 310,281,203,712 bytes free
Post-Run: 309,710,282,752 bytes free
.
- - End Of File - - E78C41D4C612124BBCB1DA37F9753C7A
03BA8F890B47C0BE359A4D5A636D214D