combofix
ComboFix 11-07-12.09 - Billie Watspm 07/15/2011 21:14:58.2.2 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4090.2008 [GMT -4:00]
Running from: c:\users\Billie Watspm\Downloads\ComboFix.exe
Command switches used :: c:\users\Billie Watspm\Desktop\cfscript.txt
AV: Norton 360 *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
FW: Norton 360 *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
SP: Norton 360 *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-06-16 to 2011-07-16 )))))))))))))))))))))))))))))))
.
.
2011-07-16 01:26 . 2011-07-16 01:29 -------- d-----w- c:\users\Billie Watspm\AppData\Local\temp
2011-07-16 01:26 . 2011-07-16 01:26 -------- d-----w- c:\users\Mcx1\AppData\Local\temp
2011-07-16 01:26 . 2011-07-16 01:26 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-16 01:02 . 2011-07-16 01:02 -------- d-----w- C:\_OTM
2011-07-13 22:06 . 2011-04-20 16:03 451072 ----a-w- c:\windows\system32\winsrv.dll
2011-07-13 22:06 . 2011-04-20 15:58 85504 ----a-w- c:\windows\system32\csrsrv.dll
2011-07-13 22:06 . 2011-06-02 13:50 2764288 ----a-w- c:\windows\system32\win32k.sys
2011-07-13 02:58 . 2011-07-13 02:58 -------- d-----w- c:\program files (x86)\ESET
2011-07-07 03:02 . 2011-07-07 03:02 -------- d-----w- c:\users\Billie Watspm\AppData\Roaming\Malwarebytes
2011-07-07 03:02 . 2011-07-07 03:02 -------- d-----w- c:\programdata\Malwarebytes
2011-07-07 03:02 . 2011-05-29 13:11 39984 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-07 03:02 . 2011-07-07 03:02 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-07 03:02 . 2011-05-29 13:11 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-28 22:13 . 2011-04-29 16:15 344576 ----a-w- c:\windows\system32\schannel.dll
2011-06-28 22:13 . 2011-04-29 15:59 276992 ----a-w- c:\windows\SysWow64\schannel.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-04 18:52 . 2011-06-04 18:52 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-06-04 18:52 . 2011-06-04 18:52 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
2011-06-04 18:52 . 2011-06-04 18:52 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-06-04 18:52 . 2011-06-04 18:52 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-06-04 18:52 . 2011-06-04 18:52 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-06-04 18:52 . 2011-06-04 18:52 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-06-04 18:52 . 2011-06-04 18:52 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-06-04 18:52 . 2011-06-04 18:52 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-06-04 18:52 . 2011-06-04 18:52 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-06-04 18:52 . 2011-06-04 18:52 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-06-04 18:52 . 2011-06-04 18:52 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-06-04 18:52 . 2011-06-04 18:52 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-06-04 18:52 . 2011-06-04 18:52 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-06-04 18:52 . 2011-06-04 18:52 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-06-04 18:52 . 2011-06-04 18:52 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-06-04 18:52 . 2011-06-04 18:52 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-06-04 18:52 . 2011-06-04 18:52 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-06-04 18:52 . 2011-06-04 18:52 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-06-04 18:52 . 2011-06-04 18:52 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-06-04 18:52 . 2011-06-04 18:52 222208 ----a-w- c:\windows\system32\msls31.dll
2011-06-04 18:52 . 2011-06-04 18:52 1389056 ----a-w- c:\windows\system32\wininet.dll
2011-06-04 18:52 . 2011-06-04 18:52 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-06-04 18:52 . 2011-06-04 18:52 12288 ----a-w- c:\windows\system32\mshta.exe
2011-06-04 18:52 . 2011-06-04 18:52 114176 ----a-w- c:\windows\system32\admparse.dll
2011-06-04 18:52 . 2011-06-04 18:52 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-06-04 18:52 . 2011-06-04 18:52 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-06-04 18:52 . 2011-06-04 18:52 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-06-04 18:52 . 2011-06-04 18:52 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-06-04 18:52 . 2011-06-04 18:52 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-06-04 18:52 . 2011-06-04 18:52 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-06-04 18:52 . 2011-06-04 18:52 448512 ----a-w- c:\windows\system32\html.iec
2011-06-04 18:51 . 2011-06-04 18:51 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-06-04 18:51 . 2011-06-04 18:51 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-04 18:51 . 2011-06-04 18:51 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-06-04 18:51 . 2011-06-04 18:51 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-06-04 18:51 . 2011-06-04 18:51 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-06-04 18:51 . 2011-06-04 18:51 160256 ----a-w- c:\windows\system32\wextract.exe
2011-06-04 18:51 . 2011-06-04 18:51 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-21 20:59 . 2011-05-21 20:10 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--- c:\windows\system32\iesetup.dll ---
Company: Microsoft Corporation
File Description: IOD Version Map
File Version: 9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
Product Name: Windows® Internet Explorer
Copyright: © Microsoft Corporation. All rights reserved.
Original Filename: iesetup.dll.mui
File size: 85504
Created time: 2011-06-04 18:51
Modified time: 2011-06-04 18:51
MD5: 93202ED0B473A8FEDFD9F5E668BE72ED
SHA1: B176086CE516E177DE3C2DDAC8E67D7DF79B9F7C
.
.
((((((((((((((((((((((((((((( SnapShot@2011-07-13_05.21.14 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-21 03:20 . 2011-07-13 05:01 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-01-21 03:20 . 2011-07-16 00:51 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-01-21 03:20 . 2011-07-16 00:51 65536 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-01-21 03:20 . 2011-07-13 05:01 65536 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-01-21 03:20 . 2011-07-16 00:51 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-01-21 03:20 . 2011-07-13 05:01 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-01-21 02:23 . 2011-07-16 01:31 59848 c:\windows\system32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 15:45 . 2011-07-16 01:31 83710 c:\windows\system32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-05-07 10:29 . 2011-07-16 01:31 14514 c:\windows\system32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3158143292-209350120-1254742864-1000_UserData.bin
+ 2011-07-13 22:06 . 2009-06-17 10:37 35328 c:\windows\system32\DriverStore\FileRepository\bth.inf_204106c4\BTHUSB.SYS
+ 2009-09-23 23:11 . 2009-04-11 05:39 26112 c:\windows\system32\DriverStore\FileRepository\bth.inf_204106c4\bthenum.sys
- 2006-11-02 12:40 . 2011-07-02 13:36 86016 c:\windows\inf\infstor.dat
+ 2006-11-02 12:40 . 2011-07-14 07:19 86016 c:\windows\inf\infstor.dat
+ 2006-11-02 12:40 . 2011-07-14 07:19 51200 c:\windows\inf\infpub.dat
- 2006-11-02 12:40 . 2011-07-02 13:36 51200 c:\windows\inf\infpub.dat
+ 2009-07-30 07:06 . 2011-07-14 07:19 3440 c:\windows\system32\WDI\ERCQueuedResolutions.dat
- 2009-07-30 07:06 . 2011-06-28 01:39 3440 c:\windows\system32\WDI\ERCQueuedResolutions.dat
+ 2011-07-16 01:27 . 2011-07-16 01:27 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-07-13 05:19 . 2011-07-13 05:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-16 01:27 . 2011-07-16 01:27 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-07-13 05:19 . 2011-07-13 05:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-07-13 22:06 . 2011-04-12 16:11 859648 c:\windows\SysWOW64\kernel32.dll
+ 2006-11-02 15:21 . 2011-07-14 07:22 363776 c:\windows\system32\FNTCACHE.DAT
- 2006-11-02 15:21 . 2011-06-29 07:38 363776 c:\windows\system32\FNTCACHE.DAT
+ 2009-09-23 23:12 . 2009-04-11 07:10 204288 c:\windows\system32\DriverStore\FileRepository\bth.inf_204106c4\fsquirt.exe
+ 2011-07-13 22:06 . 2011-04-21 14:17 695296 c:\windows\system32\DriverStore\FileRepository\bth.inf_204106c4\bthport.sys
- 2011-02-20 07:41 . 2011-07-13 05:18 371436 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-02-20 07:41 . 2011-07-16 01:26 371436 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2006-11-02 12:40 . 2011-07-02 13:36 143360 c:\windows\inf\infstrng.dat
+ 2006-11-02 12:40 . 2011-07-14 07:19 143360 c:\windows\inf\infstrng.dat
+ 2006-11-02 12:40 . 2011-07-14 07:19 665600 c:\windows\inf\drvindex.dat
- 2006-11-02 12:40 . 2009-12-25 06:39 665600 c:\windows\inf\drvindex.dat
+ 2011-07-13 22:06 . 2011-04-12 16:15 1210880 c:\windows\system32\kernel32.dll
- 2011-06-17 07:29 . 2011-07-13 05:18 6729356 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3158143292-209350120-1254742864-1000-8192.dat
+ 2011-06-17 07:29 . 2011-07-16 01:26 6729356 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3158143292-209350120-1254742864-1000-8192.dat
- 2011-06-17 07:29 . 2011-07-08 02:08 1744656 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3158143292-209350120-1254742864-1000-4096.dat
+ 2011-06-17 07:29 . 2011-07-14 07:19 1744656 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3158143292-209350120-1254742864-1000-4096.dat
+ 2006-11-02 12:33 . 2011-07-16 01:26 11272192 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
- 2006-11-02 12:33 . 2011-06-29 07:36 11272192 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2006-11-02 12:35 . 2011-07-14 07:01 50867144 c:\windows\system32\mrt.exe
+ 2011-07-16 01:14 . 2011-07-16 01:14 11026432 c:\windows\ERDNT\Hiv-backup\SCHEMA.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-07 68856]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
"ISUSPM"="c:\program files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"MyWGU Messenger"="c:\program files (x86)\MyWGU Messenger\MyWGU-Messenger.exe" [2007-11-30 172544]
"Aim"="c:\program files (x86)\AIM\aim.exe" [2011-01-05 4321112]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files (x86)\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files (x86)\Norton 360\osCheck.exe" [2008-02-25 988512]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Gateway\traybar.exe" [2008-03-29 638976]
"RemoteControl"="c:\program files (x86)\CyberLink\PowerDVD\PDVDServ.exe" [2008-07-22 87336]
"LanguageShortcut"="c:\program files (x86)\CyberLink\PowerDVD\Language\Language.exe" [2008-05-14 62760]
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-09-22 47904]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-04-14 421160]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 lxdqCATSCustConnectService;lxdqCATSCustConnectService;c:\windows\system32\spool\DRIVERS\x64\3\\lxdqserv.exe [2009-04-28 29184]
R3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WisINT15;WisINT15;c:\windows\System32\OEM\factory\WisINT15.SYS [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
S1 IDSvia64;Symantec Intrusion Prevention Driver;c:\progra~3\Symantec\DEFINI~1\SymcData\ipsdefs\20110714.001\IDSvia64.sys [2010-09-15 392752]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 27648]
S2 ETService;Empowering Technology Service;c:\program files\GATEWAY\Gateway Recovery Management\Service\ETService.exe [2008-07-16 24576]
S2 LiveUpdate Notice;LiveUpdate Notice;c:\program files (x86)\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
S2 lxdq_device;lxdq_device;c:\windows\system32\lxdqcoms.exe [2008-02-27 1044648]
S2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx64coinst,serviceStartProc [x]
S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXHWAZL.sys [x]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-05-09 136824]
S3 NETw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\NETw5v64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2mdx64.sys [x]
S3 O2SDRDR;O2SDRDR;c:\windows\system32\DRIVERS\o2sdx64.sys [x]
S3 SYMNDISV;SYMNDISV;c:\windows\System32\Drivers\SYMNDISV.SYS [x]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [x]
S3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk60x64.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - COMHOST
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1220392]
"lxdqmon.exe"="c:\program files (x86)\Lexmark Z2400 Series\lxdqmon.exe" [2008-03-27 656040]
"EzPrint"="c:\program files (x86)\Lexmark Z2400 Series\ezprint.exe" [2008-03-27 107176]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-03 16330272]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://www.yahoo.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*
http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 68.87.74.166 68.87.68.166
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
FF - ProfilePath - c:\users\Billie Watspm\AppData\Roaming\Mozilla\Firefox\Profiles\4n2vsu55.default\
FF - prefs.js: browser.startup.homepage - hxxp://startskins.com/5124071740/
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 53475
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Move Media Player:
moveplayer@movenetworks.com - c:\users\Billie Watspm\AppData\Roaming\Move Networks
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: printpdf:
printpdf@pavlov.net - %profile%\extensions\printpdf@pavlov.net
FF - Ext: Zynga Community Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{013EE055-89EF-4DC1-AE98-F4884ABDEBBf} - c:\windows\SysWow64\atl32.dll
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10b.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]
@Denied: (A 2) (Everyone)
@="IFlashBroker2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@SACL=
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@SACL=
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@SACL=
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@SACL=
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files (x86)\O2Micro Flash Memory Card Driver\o2flash.exe
c:\program files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Camera Assistant Software for Gateway\CEC_MAIN.exe
.
**************************************************************************
.
Completion time: 2011-07-15 21:35:08 - machine was rebooted
ComboFix-quarantined-files.txt 2011-07-16 01:35
ComboFix2.txt 2011-07-13 05:27
.
Pre-Run: 69,558,116,352 bytes free
Post-Run: 69,328,359,424 bytes free
.
- - End Of File - - 14DA8791588392328A31F0A3568DE969