ComboFix 12-09-06.02 - dandadandan 06/09/2012 21:32:41.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.8172.6577 [GMT 1:00]
Running from: c:\users\dandadandan\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\chrome.manifest
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\funmoods.css
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\funmoods.xul
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\images\pref.jpg
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\arwDwn.gif
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\ae.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\bg.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\ch.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\cn.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\cz.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\de.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\eg.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\en.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\es.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\fr.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\gr.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\he.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\il.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\it.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\ja.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\jp.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\nl.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\no.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\pl.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\pt.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\ro.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\ru.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\sa.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\se.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\sv.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\tr.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\ua.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\flgs\us.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\help_16.gif
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\home.gif
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\logo.png
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\privecy_16_hot.gif
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\imgs\tellafriend.gif
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\loader.xul
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\mtstart.js
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\preferences.xul
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\content\tmplt.js
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\install.rdf
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.rsa
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.sf
c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\extensions\
ffxtlbr@funmoods.com\META-INF\manifest.mf
.
.
((((((((((((((((((((((((( Files Created from 2012-08-06 to 2012-09-06 )))))))))))))))))))))))))))))))
.
.
2012-09-02 17:33 . 2012-09-04 01:53--------d-----w-C:\FRST
2012-09-01 15:41 . 2012-09-01 15:41--------d-----w-c:\program files\CCleaner
2012-09-01 15:40 . 2012-09-01 15:57--------d-----w-c:\programdata\Spybot - Search & Destroy
2012-09-01 15:40 . 2012-09-01 15:45--------d-----w-c:\program files (x86)\Spybot - Search & Destroy
2012-09-01 05:22 . 2012-09-01 05:22--------d-----w-c:\users\dandadandan\AppData\Roaming\Malwarebytes
2012-09-01 05:22 . 2012-09-01 05:22--------d-----w-c:\programdata\Malwarebytes
2012-09-01 05:22 . 2012-09-01 05:22--------d-----w-c:\program files (x86)\Malwarebytes' Anti-Malware
2012-09-01 05:22 . 2012-07-03 12:4624904----a-w-c:\windows\system32\drivers\mbam.sys
2012-09-01 05:22 . 2012-08-28 00:499310152----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-08-20 04:33 . 2012-08-20 04:33--------d-----w-c:\program files (x86)\GUMF6AD.tmp
2012-08-20 04:33 . 2012-08-20 04:334024320----a-w-c:\program files (x86)\GUTF6CD.tmp
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-31 19:04 . 2012-06-10 23:18426184----a-w-c:\windows\SysWow64\FlashPlayerApp.exe
2012-08-31 19:04 . 2011-07-12 21:4770344----a-w-c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-19 21:47 . 2012-07-19 21:47328704----a-w-c:\windows\system32\services.exe.680C4F959CB4C10B
2012-07-12 22:46 . 2012-07-12 22:46328704----a-w-c:\windows\system32\services.exe.29B93C8DF1B05AD5
2012-07-12 22:32 . 2012-07-12 22:32328704----a-w-c:\windows\system32\services.exe.CDC3BD3B51028232
2012-07-12 22:23 . 2012-07-12 22:2350392----a-w-c:\windows\system32\drivers\vujioxqw.sys
2012-07-12 22:23 . 2012-07-12 22:23328704----a-w-c:\windows\system32\services.exe.DBBB9B918D6D7D6C
2012-07-12 22:13 . 2012-07-12 22:13328704----a-w-c:\windows\system32\services.exe.EF4DB39E3493D087
2012-07-12 22:11 . 2012-07-12 22:11328704----a-w-c:\windows\system32\services.exe.5BB6BD836AEAA0CD
2012-07-12 22:08 . 2012-07-12 22:08328704----a-w-c:\windows\system32\services.exe.F8D168A513F5846F
2012-07-12 22:03 . 2012-07-12 22:03328704----a-w-c:\windows\system32\services.exe.AE5BF11DBD2FB70F
2012-07-12 22:00 . 2012-07-12 22:00328704----a-w-c:\windows\system32\services.exe.21EF982B30E56EED
2012-07-12 21:55 . 2012-07-12 21:55328704----a-w-c:\windows\system32\services.exe.D4EC0ACD8F8D58D0
2012-07-10 22:26 . 2011-04-06 00:1859701280----a-w-c:\windows\system32\MRT.exe
2012-07-04 18:14 . 2012-07-04 18:1413764096----a-w-c:\windows\SysWow64\aticaldd.dll
2012-07-04 18:14 . 2011-03-09 04:306203392----a-w-c:\windows\SysWow64\atiumdag.dll
2012-07-04 18:14 . 2012-07-04 18:1454784----a-w-c:\windows\system32\atimpc64.dll
2012-07-04 18:14 . 2012-07-04 18:1454784----a-w-c:\windows\system32\amdpcom64.dll
2012-07-04 18:14 . 2012-07-04 18:14120320----a-w-c:\windows\system32\atitmm64.dll
2012-07-04 18:14 . 2012-07-04 18:1451200----a-w-c:\windows\system32\aticalrt64.dll
2012-07-04 18:14 . 2012-07-04 18:14236544----a-w-c:\windows\system32\atiesrxx.exe
2012-07-04 18:14 . 2012-07-04 18:1459392----a-w-c:\windows\system32\atiedu64.dll
2012-07-04 18:14 . 2012-07-04 18:1453248----a-w-c:\windows\system32\drivers\ati2erec.dll
2012-07-04 18:14 . 2012-07-04 18:14343040----a-w-c:\windows\system32\drivers\atikmpag.sys
2012-07-04 18:14 . 2011-03-09 04:56909312----a-w-c:\windows\SysWow64\aticfx32.dll
2012-07-04 18:14 . 2012-07-04 18:1421504----a-w-c:\windows\system32\atimuixx.dll
2012-07-04 18:14 . 2012-07-04 18:1453760----a-w-c:\windows\SysWow64\atimpc32.dll
2012-07-04 18:14 . 2012-07-04 18:1453760----a-w-c:\windows\SysWow64\amdpcom32.dll
2012-07-04 18:14 . 2012-07-04 18:14514560----a-w-c:\windows\system32\atiadlxx.dll
2012-07-04 18:14 . 2011-03-09 04:1754784----a-w-c:\windows\system32\atiuxp64.dll
2012-07-04 18:13 . 2012-07-04 18:13360448----a-w-c:\windows\SysWow64\atiadlxy.dll
2012-07-04 18:13 . 2012-07-04 18:1395760----a-w-c:\windows\system32\drivers\AtihdW76.sys
2012-07-04 18:13 . 2012-07-04 18:1343520----a-w-c:\windows\SysWow64\ati2edxx.dll
2012-07-04 18:13 . 2011-03-09 04:407479296----a-w-c:\windows\system32\atidxx64.dll
2012-07-04 18:13 . 2011-03-09 04:1644544----a-w-c:\windows\system32\atiu9p64.dll
2012-07-04 18:13 . 2012-07-04 18:1317408----a-w-c:\windows\system32\atig6pxx.dll
2012-07-04 18:13 . 2012-07-04 18:131120768----a-w-c:\windows\system32\atiumd6v.dll
2012-07-04 18:13 . 2012-07-04 18:13159744----a-w-c:\windows\system32\atiapfxx.exe
2012-07-04 18:13 . 2011-03-09 04:486800896----a-w-c:\windows\SysWow64\atidxx32.dll
2012-07-04 18:12 . 2011-04-05 10:5664000----a-w-c:\windows\system32\coinst.dll
2012-07-04 18:12 . 2012-07-04 18:127431680----a-w-c:\windows\system32\atiumd64.dll
2012-07-04 18:12 . 2011-03-09 04:1632256----a-w-c:\windows\SysWow64\atiu9pag.dll
2012-07-04 18:12 . 2012-07-04 18:1214848----a-w-c:\windows\SysWow64\atiglpxx.dll
2012-07-04 18:12 . 2012-07-04 18:1214848----a-w-c:\windows\system32\atiglpxx.dll
2012-07-04 18:12 . 2012-07-04 18:1241984----a-w-c:\windows\system32\atig6txx.dll
2012-07-04 18:12 . 2011-03-09 04:1741984----a-w-c:\windows\SysWow64\atiuxpag.dll
2012-07-04 18:12 . 2012-07-04 18:12442368----a-w-c:\windows\system32\ATIDEMGX.dll
2012-07-04 18:12 . 2012-07-04 18:114731904----a-w-c:\windows\system32\atiumd6a.dll
2012-07-04 18:12 . 2011-03-09 04:551067520----a-w-c:\windows\system32\aticfx64.dll
2012-07-04 18:11 . 2012-07-04 18:1026181632----a-w-c:\windows\system32\atio6axx.dll
2012-07-04 18:11 . 2012-07-04 18:11503808----a-w-c:\windows\system32\atieclxx.exe
2012-07-04 18:11 . 2012-07-04 18:1016090624----a-w-c:\windows\system32\aticaldd64.dll
2012-07-04 18:11 . 2012-07-04 18:1144544----a-w-c:\windows\system32\aticalcl64.dll
2012-07-04 18:11 . 2012-07-04 18:111831424----a-w-c:\windows\SysWow64\atiumdmv.dll
2012-07-04 18:11 . 2011-03-09 03:344795904----a-w-c:\windows\SysWow64\atiumdva.dll
2012-07-04 18:11 . 2012-07-04 18:0919753984----a-w-c:\windows\SysWow64\atioglxx.dll
2012-07-04 18:11 . 2012-07-04 18:1033280----a-w-c:\windows\SysWow64\atigktxx.dll
2012-07-04 18:10 . 2012-07-04 18:1011174400----a-w-c:\windows\system32\drivers\atikmdag.sys
2012-07-04 18:09 . 2012-07-04 18:0946080----a-w-c:\windows\SysWow64\aticalrt.dll
2012-07-04 18:09 . 2012-07-04 18:0944032----a-w-c:\windows\SysWow64\aticalcl.dll
2012-06-25 15:04 . 2012-06-25 15:041394248----a-w-c:\windows\SysWow64\msxml4.dll
2012-06-12 03:08 . 2012-07-10 22:283148800----a-w-c:\windows\system32\win32k.sys
2012-06-09 05:43 . 2012-07-10 21:0314172672----a-w-c:\windows\system32\shell32.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}"= "c:\program files (x86)\IncrediMail_MediaBar_2\prxtbIncr.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}]
2011-05-09 09:49176936----a-w-c:\program files (x86)\IncrediMail_MediaBar_2\prxtbIncr.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}"= "c:\program files (x86)\IncrediMail_MediaBar_2\prxtbIncr.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:1994208----a-w-c:\users\dandadandan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:1994208----a-w-c:\users\dandadandan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:1994208----a-w-c:\users\dandadandan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:1994208----a-w-c:\users\dandadandan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"HydraVisionDesktopManager"="c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [2010-11-18 393216]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288]
"BCU"="c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" [2009-10-26 375000]
"SSDMonitor"="c:\program files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe" [2011-05-18 112600]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files (x86)\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-30 59280]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-06-07 421776]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-04-06 641664]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
.
c:\users\dandadandan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\dandadandan\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-8-27 26924984]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security PackagesREG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-31 250056]
R3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [2010-10-27 279152]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-11-01 33736]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2010-06-25 36928]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-28 113120]
R3 Mrvleap;MARVELL EAP Driver;c:\windows\system32\DRIVERS\mrv64drv.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-20 98688]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\rtl8187B.sys [2010-03-31 450048]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-04-07 1255736]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 mv91xx;mv91xx;c:\windows\system32\DRIVERS\mv91xx.sys [2010-08-27 297000]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-07-04 236544]
S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-10-26 223464]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-16 80896]
S2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [2011-05-18 632792]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-07-04 11174400]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-07-04 343040]
S3 ATHDFU;Atheros Valkyrie USB BootROM;c:\windows\system32\Drivers\AthDfu.sys [2010-10-27 55336]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-07-04 95760]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [2010-10-27 31080]
S3 cmudaxp;ASUS Xonar DG Audio Interface;c:\windows\system32\drivers\cmudaxp.sys [2010-07-23 1261056]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
S3 MRV6X64U;Marvell TOPDOG 802.11n WLAN Driver for Vista x64 (USB8x);c:\windows\system32\DRIVERS\WN111x.sys [2007-10-28 340480]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-09-30 80384]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-09-30 180736]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-10-26 406632]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-09-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-10 19:04]
.
2012-09-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2694974181-1940623718-3779438024-1000Core.job
- c:\users\dandadandan\AppData\Local\Google\Update\GoogleUpdate.exe [2005-01-02 00:25]
.
2012-09-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2694974181-1940623718-3779438024-1000UA.job
- c:\users\dandadandan\AppData\Local\Google\Update\GoogleUpdate.exe [2005-01-02 00:25]
.
2012-09-05 c:\windows\Tasks\RMSchedule.job
- c:\program files (x86)\Registry Mechanic\RegMech.exe [2011-05-18 03:28]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:1997792----a-w-c:\users\dandadandan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:1997792----a-w-c:\users\dandadandan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:1997792----a-w-c:\users\dandadandan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:1997792----a-w-c:\users\dandadandan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2010-10-27 613536]
"AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2010-10-27 379040]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-02 11545192]
"Cmaudio8788"="c:\windows\Syswow64\cmicnfgp.dll" [2009-12-08 8151040]
"Cmaudio8788GX"="c:\windows\syswow64\HsMgr.exe" [2008-07-11 200704]
"Cmaudio8788GX64"="c:\windows\system\HsMgr64.exe" [2008-07-11 282112]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://start.funmoods.com/?f=1&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0FyEyC0DtDyEzz0F0B0AtAyE0Czz0EyBtN0D0Tzu0StBtDtDtN1L2XzutBtFtCtFtDtFtAtDtC&cr=516689117
mStart Page = hxxp://start.funmoods.com/?f=1&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0FyEyC0DtDyEzz0F0B0AtAyE0Czz0EyBtN0D0Tzu0StBtDtDtN1L2XzutBtFtCtFtDtFtAtDtC&cr=516689117
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Add to Evernote 4.0 - c:\program files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.254 192.168.1.254
FF - ProfilePath - c:\users\dandadandan\AppData\Roaming\Mozilla\Firefox\Profiles\swkj9kyu.default\
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?affID=113480&babsrc=KW_ss&mntrId=aac8c8e700000000000000184d77e7c9&q=
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=113480
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - aac8c8e700000000000000184d77e7c9
FF - user.js: extensions.BabylonToolbar_i.hardId - aac8c8e700000000000000184d77e7c9
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15533
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1723:46
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
FF - user.js: extensions.funmoods.hmpg - true
FF - user.js: extensions.funmoods.hmpgUrl - hxxp://start.funmoods.com/?f=1&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0FyEyC0DtDyEzz0F0B0AtAyE0Czz0EyBtN0D0Tzu0StBtDtDtN1L2XzutBtFtCtFtDtFtAtDtC&cr=516689117
FF - user.js: extensions.funmoods.dfltSrch - true
FF - user.js: extensions.funmoods.srchPrvdr - Search
FF - user.js: extensions.funmoods.dnsErr - true
FF - user.js: extensions.funmoods_i.newTab - true
FF - user.js: extensions.funmoods.newTabUrl - hxxp://start.funmoods.com/?f=2&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0FyEyC0DtDyEzz0F0B0AtAyE0Czz0EyBtN0D0Tzu0StBtDtDtN1L2XzutBtFtCtFtDtFtAtDtC&cr=516689117
FF - user.js: extensions.funmoods.tlbrSrchUrl - hxxp://start.funmoods.com/?f=3&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0FyEyC0DtDyEzz0F0B0AtAyE0Czz0EyBtN0D0Tzu0StBtDtDtN1L2XzutBtFtCtFtDtFtAtDtC&cr=516689117&q=
FF - user.js: extensions.funmoods.id - F46D048FBA34C8E7
FF - user.js: extensions.funmoods.instlDay - 15541
FF - user.js: extensions.funmoods.vrsn - 1.5.23.22
FF - user.js: extensions.funmoods.vrsni - 1.5.23.22
FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.23.220:54
FF - user.js: extensions.funmoods.prtnrId - funmoods
FF - user.js: extensions.funmoods.prdct - funmoods
FF - user.js: extensions.funmoods.aflt - iron2
FF - user.js: extensions.funmoods_i.smplGrp - none
FF - user.js: extensions.funmoods.tlbrId - base
FF - user.js: extensions.funmoods.instlRef - iron2
FF - user.js: extensions.funmoods.dfltLng -
FF - user.js: extensions.funmoods.excTlbr - false
FF - user.js: extensions.funmoods.autoRvrt - false
FF - user.js: extensions.funmoods.envrmnt - production
FF - user.js: extensions.funmoods.isdcmntcmplt - true
FF - user.js: extensions.funmoods.mntrvrsn - 1.3.0
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2694974181-1940623718-3779438024-1000\Software\SecuROM\License information*]
"datasecu"=hex:0d,99,33,3c,90,88,4b,ab,2a,cf,d4,fe,05,54,c7,f3,07,c2,2f,ac,c4,
e0,fb,96,bf,bd,5f,e3,41,66,35,8e,89,03,f2,93,a5,b0,0f,6b,f0,58,85,28,ea,c6,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\ASUS Xonar DG Audio\Customapp\ASUSAUDIOCENTER.EXE
.
**************************************************************************
.
Completion time: 2012-09-06 22:52:09 - machine was rebooted
ComboFix-quarantined-files.txt 2012-09-06 21:52
.
Pre-Run: 653,690,925,056 bytes free
Post-Run: 653,295,955,968 bytes free
.
- - End Of File - - 01A1636574416529CB4142634F903CD5