evilsmeagol
Posts: 29 +0
:wave: Greetings and salutations! I thought my computer had gone bonkers, It was such a relief to discover there was a rational explanation! At least the problem led to my finding this site, which is awesome! I followed the six steps advised, it all went smoothly. I await further instructions. I feel quite exposed posting this log, like I'm letting someone read my diary! Please be gentle! Thank you so much!
:monkey: ~nicole ^_^
ComboFix 11-10-12.04 - Nicole 10/12/2011 23:05:16.1.2 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.2038.1151 [GMT -6:00]
Running from: c:\users\Nicole\Downloads\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\program files (x86)\FLV Direct Player
c:\program files (x86)\FLV Direct Player\downloading.swf
c:\program files (x86)\FLV Direct Player\FLVPlayer.exe
c:\program files (x86)\FLV Direct Player\player.swf
c:\program files (x86)\FLV Direct Player\preload.swf
c:\program files (x86)\FLV Direct Player\Skin\DirectFLV\Button.bmp
c:\program files (x86)\FLV Direct Player\Skin\DirectFLV\Logo.bmp
c:\program files (x86)\FLV Direct Player\Skin\DirectFLV\skin.xml
c:\program files (x86)\FLV Direct Player\Skin\DirectFLV\SysCloseButton.bmp
c:\program files (x86)\FLV Direct Player\Skin\DirectFLV\SysMaxButton.bmp
c:\program files (x86)\FLV Direct Player\Skin\DirectFLV\SysMinButton.bmp
c:\program files (x86)\FLV Direct Player\Skin\DirectFLV\Window.bmp
c:\program files (x86)\FLV Direct Player\uninstall.exe
c:\program files (x86)\QuestScan
c:\program files (x86)\QuestScan\questscan.dll
c:\program files (x86)\QuestScan\questscan.exe
c:\programdata\JavaUpdateBackup.dll
c:\programdata\Tarma Installer
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico
c:\users\Nicole\AppData\Local\{1299E484-F0A3-4D0A-AE5D-8A33A6892182}
c:\users\Nicole\AppData\Local\{1299E484-F0A3-4D0A-AE5D-8A33A6892182}\chrome.manifest
c:\users\Nicole\AppData\Local\{1299E484-F0A3-4D0A-AE5D-8A33A6892182}\chrome\content\_cfg.js
c:\users\Nicole\AppData\Local\{1299E484-F0A3-4D0A-AE5D-8A33A6892182}\chrome\content\overlay.xul
c:\users\Nicole\AppData\Local\{1299E484-F0A3-4D0A-AE5D-8A33A6892182}\install.rdf
c:\users\Nicole\AppData\Local\Adobe\AdobeUpdate\Adobeupdt32.dll
c:\users\Nicole\AppData\Local\Adobe\AdobeUpdate\Adobeupdt32.exe
c:\users\Nicole\AppData\Local\ajc.dll
c:\users\Nicole\AppData\Local\ajc.exe
c:\users\Nicole\AppData\Local\Apple Computer\AppleUpdate\Appleupdt32.dll
c:\users\Nicole\AppData\Local\Apple Computer\AppleUpdate\Appleupdt32.exe
c:\users\Nicole\AppData\Local\Apps\AppsUpdate\Appsupdt32.dll
c:\users\Nicole\AppData\Local\Apps\AppsUpdate\Appsupdt32.exe
c:\users\Nicole\AppData\Local\DDMSettings\DDMSettingsUpdate\DDMSettingsupdt32.dll
c:\users\Nicole\AppData\Local\DDMSettings\DDMSettingsUpdate\DDMSettingsupdt32.exe
c:\users\Nicole\AppData\Local\Diagnostics\DiagnosticsUpdate\Diagnosticsupdt32.dll
c:\users\Nicole\AppData\Local\Diagnostics\DiagnosticsUpdate\Diagnosticsupdt32.exe
c:\users\Nicole\AppData\Local\Google\GoogleUpdate\Googleupdt32.dll
c:\users\Nicole\AppData\Local\Google\GoogleUpdate\Googleupdt32.exe
c:\users\Nicole\AppData\Local\Graboid\GraboidUpdate\Graboidupdt32.dll
c:\users\Nicole\AppData\Local\Graboid\GraboidUpdate\Graboidupdt32.exe
c:\users\Nicole\AppData\Local\Ilivid Player\IlividUpdate\Ilividupdt32.dll
c:\users\Nicole\AppData\Local\Ilivid Player\IlividUpdate\Ilividupdt32.exe
c:\users\Nicole\AppData\Local\Microsoft\MicrosoftUpdate\Microsoftupdt32.dll
c:\users\Nicole\AppData\Local\microsoft\microsoftupdate\Microsoftupdt32.exe
c:\users\Nicole\AppData\Local\ServiceAdmin.dll
c:\users\Nicole\AppData\Local\ServicePTR.dll
c:\users\Nicole\AppData\Local\Servicex86_x64.dll
c:\users\Nicole\AppData\Local\TCPIPAdmin.dll
c:\users\Nicole\AppData\Local\Trayx86_x64.dll
c:\users\Nicole\AppData\Local\wbu.exe
c:\users\Nicole\AppData\Roaming\0bdfar.exe
c:\users\Nicole\AppData\Roaming\24i25el0.exe
c:\users\Nicole\AppData\Roaming\3pvvuynj.exe
c:\users\Nicole\AppData\Roaming\7eigo00f.exe
c:\users\Nicole\AppData\Roaming\8eed.log
c:\users\Nicole\AppData\Roaming\9b5mxsh46.exe
c:\users\Nicole\AppData\Roaming\9xxofydmw.exe
c:\users\Nicole\AppData\Roaming\dynkcqkdn.exe
c:\users\Nicole\AppData\Roaming\ez87ilnhy.exe
c:\users\Nicole\AppData\Roaming\lssas.exe
c:\users\Nicole\AppData\Roaming\manager.exe
c:\users\Nicole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\santa.bat
c:\users\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\urwbwi1t.default\extensions\{bdaa08bb-3011-4150-b901-fbcef2426e39}
c:\users\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\urwbwi1t.default\extensions\{bdaa08bb-3011-4150-b901-fbcef2426e39}\chrome.manifest
c:\users\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\urwbwi1t.default\extensions\{bdaa08bb-3011-4150-b901-fbcef2426e39}\chrome\xulcache.jar
c:\users\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\urwbwi1t.default\extensions\{bdaa08bb-3011-4150-b901-fbcef2426e39}\defaults\preferences\xulcache.js
c:\users\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\urwbwi1t.default\extensions\{bdaa08bb-3011-4150-b901-fbcef2426e39}\install.rdf
c:\users\Nicole\AppData\Roaming\nsxirq246.exe
c:\users\Nicole\AppData\Roaming\qbkjuxzt.exe
c:\users\Nicole\AppData\Roaming\svlgl6pfq.exe
c:\users\Public\Desktop\FLV Direct Player.lnk
c:\windows\SysWow64\downloader.txt
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_QuestScan Service
.
.
((((((((((((((((((((((((( Files Created from 2011-09-13 to 2011-10-13 )))))))))))))))))))))))))))))))
.
.
2011-10-13 05:12 . 2011-10-13 05:12 -------- d-----w- c:\users\LogMeInRemoteUser\AppData\Local\temp
2011-10-13 05:12 . 2011-10-13 05:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-10-11 16:30 . 2011-10-11 16:32 -------- d-----w- c:\users\Nicole\AppData\Local\ElevatedDiagnostics
2011-10-11 16:23 . 2007-02-02 17:26 224768 ----a-w- c:\windows\system32\Spool\prtprocs\x64\hpzpp4v2.dll
2011-10-11 16:23 . 2007-02-02 17:28 130048 ----a-w- c:\windows\system32\hpz3l4v2.dll
2011-10-10 03:36 . 2011-10-10 03:36 -------- d-----w- c:\program files (x86)\Apple Software Update
2011-09-27 22:32 . 2011-09-27 22:32 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-09-19 19:29 . 2011-09-24 04:59 98304 ----a-w- c:\windows\SysWow64\srrstr.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-25 00:18 . 2011-08-14 00:04 0 ----a-w- c:\users\Nicole\AppData\Local\Nkitodafuveliko.bin
2011-08-14 00:02 . 2011-08-14 00:02 148 ----a-w- c:\users\Nicole\AppData\Roaming\rjxrku1pp.bat
2011-08-14 00:02 . 2011-08-14 00:02 148 ----a-w- c:\users\Nicole\AppData\Roaming\6yd609g44.bat
2011-08-12 04:10 . 2011-08-26 08:42 8862544 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A2651948-AEB0-488A-8123-C318A472D1A1}\mpengine.dll
2011-07-21 02:43 . 2010-03-02 23:11 87456 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-07-21 02:43 . 2010-03-02 23:11 33152 ----a-w- c:\windows\system32\LMIport.dll
2011-07-21 02:43 . 2010-03-02 23:11 80768 ----a-w- c:\windows\system32\LMIinit.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTo1.dll" [2011-06-25 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{26A7CA19-7D58-411D-B2DA-F1B0324CBFFC}]
2010-09-12 14:07 1499136 ----a-w- c:\program files (x86)\Gamers Unite! Snag Bar\Toolbar.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2011-06-25 02:58 3911776 ----a-w- c:\program files (x86)\uTorrentBar\tbuTo1.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-02-28 22:11 191488 ------w- c:\program files (x86)\Yontoo Layers Client\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{25515A79-C1C7-4B97-97F8-31A711694487}"= "c:\program files (x86)\Gamers Unite! Snag Bar\Toolbar.dll" [2010-09-12 1499136]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTo1.dll" [2011-06-25 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{25515a79-c1c7-4b97-97f8-31a711694487}]
[HKEY_CLASSES_ROOT\FCTB000062781.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{017D1380-106D-43D5-97DC-81E8A527FD73}]
[HKEY_CLASSES_ROOT\FCTB000062781.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AnyDVD"="c:\program files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe" [2010-04-01 3369920]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2011-04-15 399736]
"cdloader"="c:\users\Nicole\AppData\Roaming\mjusbsp\cdloader2.exe" [2010-12-03 50592]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"CloneCDTray"="c:\program files (x86)\SlySoft\CloneCD\CloneCDTray.exe" [2009-01-29 57344]
"ElbyCheckAnyDVD"="c:\program files (x86)\SlySoft\AnyDVD\ElbyCheck.exe" [2003-09-20 45056]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-30 421888]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\Update\realsched.exe" [2011-03-14 273544]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-06-07 421160]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBBAFYARgBSAEUARQAtAFYATgBKADMAMgAtAEcAMwBMAEEAQQAtAEEANAA4ADkAUgAtADkAVQBKAEsARgAtAEUASwBLADMAWAA&inst=NwA3AC0ANAAyADQANwAxADMAOQA4ADYALQBUAEIAOQArADIALQBGAEwAKwA5AC0AWABPADMANgArADEALQBGADkATQA3AEMAKwA1AC0ARgA5AE0AMQAwAEIAKwAyAC0AWABPADkAKwAxAC0ARgA5AE0AMgArADEALQBEAEQAVAArADAA&prod=90&ver=9.0.894" [?]
.
c:\users\Nicole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Canon IJ Status Monitor Canon Inkjet MX300 series.lnk - c:\windows\system32\rundll32.exe [2009-7-13 45568]
OpenOffice.org 3.2.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2009-12-15 384000]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R1 hlcrtria;hlcrtria;c:\windows\system32\drivers\hlcrtria.sys [x]
R1 ibhgsnqb;ibhgsnqb;c:\windows\system32\drivers\ibhgsnqb.sys [x]
R1 jtnpzsry;jtnpzsry;c:\windows\system32\drivers\jtnpzsry.sys [x]
R1 lanhqums;lanhqums;c:\windows\system32\drivers\lanhqums.sys [x]
R1 mgeimbnh;mgeimbnh;c:\windows\system32\drivers\mgeimbnh.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-20 136176]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-20 136176]
R3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys [x]
R3 LVUVC64;Logitech Webcam 120(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2011-07-21 375176]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2008-08-11 15928]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-04-24 483688]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-04-24 209768]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-20 06:34]
.
2011-10-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-20 06:34]
.
2011-10-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-486493133-1455968607-1562069686-1001Core.job
- c:\users\Nicole\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-17 02:46]
.
2011-10-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-486493133-1455968607-1562069686-1001UA.job
- c:\users\Nicole\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-17 02:46]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2008-08-11 57928]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-24 165912]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-24 385560]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-24 363544]
"combofix"="c:\combofix\CF23823.3XE" [2009-07-14 344576]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://mp3tubetoolbar.com/?tmp=toolbar_Mp3Tube_homepage&prt=pinballtbfour04ie&clid=7e5964b4ce2a49648f23c672d9a9f119
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 68.87.85.102 68.87.69.150
FF - ProfilePath - c:\users\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\urwbwi1t.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=ConduitEngine&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Yahoo-Mp3Tube
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: LoudMo Contextual Ad Assistant: {c402222d-edf1-7871-7250-2c8915d1f628} - c:\program files (x86)\Mozilla Firefox\extensions\{c402222d-edf1-7871-7250-2c8915d1f628}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: QuestScan: {F0E1168A-B4B5-484C-B77E-0D28E6B64096} - c:\program files (x86)\Mozilla Firefox\extensions\{F0E1168A-B4B5-484C-B77E-0D28E6B64096}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: Facebook Toolbar: firefox@facebook.com - %profile%\extensions\firefox@facebook.com
FF - Ext: Zynga Community Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF - Ext: LogMeIn, Inc. Remote Access Plugin: LogMeInClient@logmein.com - %profile%\extensions\LogMeInClient@logmein.com
FF - Ext: Gamers Unite! Snag Bar: {afe43e80-0abc-4df2-81a0-3fe44b74abe8} - %profile%\extensions\{afe43e80-0abc-4df2-81a0-3fe44b74abe8}
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
FF - Ext: Yontoo Layers: plugin@yontoo.com - %profile%\extensions\plugin@yontoo.com
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF - user.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - user.js: keyword.enabled - 1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-{0C8413C1-FAD1-446C-8584-BE50576F863E} - (no file)
Wow6432Node-HKCU-Run-DW6 - c:\program files (x86)\The Weather Channel FW\Desktop\DesktopWeather.exe
Wow6432Node-HKCU-Run-616r - c:\users\Nicole\AppData\Roaming\0bdfar.exe
Wow6432Node-HKCU-Run-Local Account Service - c:\users\Nicole\AppData\Roaming\lssas.exe
Wow6432Node-HKCU-Run-Plug Manager - c:\users\Nicole\AppData\Roaming\manager.exe
Wow6432Node-HKCU-Run-DDMSettings Update - c:\users\Nicole\AppData\Local\DDMSettings\DDMSettingsUpdate\DDMSettingsupdt32.exe
Wow6432Node-HKCU-Run-JavaUpdateBackup - c:\programdata\JavaUpdateBackup.dll
Wow6432Node-HKCU-Run-Apps Update - c:\users\Nicole\AppData\Local\Apps\AppsUpdate\Appsupdt32.exe
Wow6432Node-HKCU-Run-Ilivid Player Update - c:\users\Nicole\AppData\Local\Ilivid Player\IlividUpdate\Ilividupdt32.exe
Wow6432Node-HKCU-Run-Graboid Update - c:\users\Nicole\AppData\Local\Graboid\GraboidUpdate\Graboidupdt32.exe
Wow6432Node-HKCU-Run-Diagnostics Update - c:\users\Nicole\AppData\Local\Diagnostics\DiagnosticsUpdate\Diagnosticsupdt32.exe
Wow6432Node-HKCU-Run-Adobe Update - c:\users\Nicole\AppData\Local\Adobe\AdobeUpdate\Adobeupdt32.exe
Wow6432Node-HKCU-Run-Apple Computer Update - c:\users\Nicole\AppData\Local\Apple Computer\AppleUpdate\Appleupdt32.exe
Wow6432Node-HKU-Default-Run-Microsoft Update - c:\users\Nicole\AppData\Local\Microsoft\MicrosoftUpdate\Microsoftupdt32.exe
Wow6432Node-HKU-Default-Run-Ilivid Player Update - c:\users\Nicole\AppData\Local\Ilivid Player\IlividUpdate\Ilividupdt32.exe
Wow6432Node-HKU-Default-Run-Graboid Update - c:\users\Nicole\AppData\Local\Graboid\GraboidUpdate\Graboidupdt32.exe
Wow6432Node-HKU-Default-Run-DDMSettings Update - c:\users\Nicole\AppData\Local\DDMSettings\DDMSettingsUpdate\DDMSettingsupdt32.exe
Wow6432Node-HKU-Default-Run-Apple Computer Update - c:\users\Nicole\AppData\Local\Apple Computer\AppleUpdate\Appleupdt32.exe
Toolbar-Locked - (no file)
WebBrowser-{0C8413C1-FAD1-446C-8584-BE50576F863E} - (no file)
WebBrowser-{25515A79-C1C7-4B97-97F8-31A711694487} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\OpenOffice.org 3\program\soffice.exe
c:\program files (x86)\OpenOffice.org 3\program\soffice.bin
.
**************************************************************************
.
Completion time: 2011-10-12 23:32:47 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-13 05:32
.
Pre-Run: 1,774,178,304 bytes free
Post-Run: 2,410,188,800 bytes free
.
- - End Of File - - 4B0D581E4ECADFBA7B97B254577A3845
:monkey: ~nicole ^_^
ComboFix 11-10-12.04 - Nicole 10/12/2011 23:05:16.1.2 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.2038.1151 [GMT -6:00]
Running from: c:\users\Nicole\Downloads\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\program files (x86)\FLV Direct Player
c:\program files (x86)\FLV Direct Player\downloading.swf
c:\program files (x86)\FLV Direct Player\FLVPlayer.exe
c:\program files (x86)\FLV Direct Player\player.swf
c:\program files (x86)\FLV Direct Player\preload.swf
c:\program files (x86)\FLV Direct Player\Skin\DirectFLV\Button.bmp
c:\program files (x86)\FLV Direct Player\Skin\DirectFLV\Logo.bmp
c:\program files (x86)\FLV Direct Player\Skin\DirectFLV\skin.xml
c:\program files (x86)\FLV Direct Player\Skin\DirectFLV\SysCloseButton.bmp
c:\program files (x86)\FLV Direct Player\Skin\DirectFLV\SysMaxButton.bmp
c:\program files (x86)\FLV Direct Player\Skin\DirectFLV\SysMinButton.bmp
c:\program files (x86)\FLV Direct Player\Skin\DirectFLV\Window.bmp
c:\program files (x86)\FLV Direct Player\uninstall.exe
c:\program files (x86)\QuestScan
c:\program files (x86)\QuestScan\questscan.dll
c:\program files (x86)\QuestScan\questscan.exe
c:\programdata\JavaUpdateBackup.dll
c:\programdata\Tarma Installer
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico
c:\users\Nicole\AppData\Local\{1299E484-F0A3-4D0A-AE5D-8A33A6892182}
c:\users\Nicole\AppData\Local\{1299E484-F0A3-4D0A-AE5D-8A33A6892182}\chrome.manifest
c:\users\Nicole\AppData\Local\{1299E484-F0A3-4D0A-AE5D-8A33A6892182}\chrome\content\_cfg.js
c:\users\Nicole\AppData\Local\{1299E484-F0A3-4D0A-AE5D-8A33A6892182}\chrome\content\overlay.xul
c:\users\Nicole\AppData\Local\{1299E484-F0A3-4D0A-AE5D-8A33A6892182}\install.rdf
c:\users\Nicole\AppData\Local\Adobe\AdobeUpdate\Adobeupdt32.dll
c:\users\Nicole\AppData\Local\Adobe\AdobeUpdate\Adobeupdt32.exe
c:\users\Nicole\AppData\Local\ajc.dll
c:\users\Nicole\AppData\Local\ajc.exe
c:\users\Nicole\AppData\Local\Apple Computer\AppleUpdate\Appleupdt32.dll
c:\users\Nicole\AppData\Local\Apple Computer\AppleUpdate\Appleupdt32.exe
c:\users\Nicole\AppData\Local\Apps\AppsUpdate\Appsupdt32.dll
c:\users\Nicole\AppData\Local\Apps\AppsUpdate\Appsupdt32.exe
c:\users\Nicole\AppData\Local\DDMSettings\DDMSettingsUpdate\DDMSettingsupdt32.dll
c:\users\Nicole\AppData\Local\DDMSettings\DDMSettingsUpdate\DDMSettingsupdt32.exe
c:\users\Nicole\AppData\Local\Diagnostics\DiagnosticsUpdate\Diagnosticsupdt32.dll
c:\users\Nicole\AppData\Local\Diagnostics\DiagnosticsUpdate\Diagnosticsupdt32.exe
c:\users\Nicole\AppData\Local\Google\GoogleUpdate\Googleupdt32.dll
c:\users\Nicole\AppData\Local\Google\GoogleUpdate\Googleupdt32.exe
c:\users\Nicole\AppData\Local\Graboid\GraboidUpdate\Graboidupdt32.dll
c:\users\Nicole\AppData\Local\Graboid\GraboidUpdate\Graboidupdt32.exe
c:\users\Nicole\AppData\Local\Ilivid Player\IlividUpdate\Ilividupdt32.dll
c:\users\Nicole\AppData\Local\Ilivid Player\IlividUpdate\Ilividupdt32.exe
c:\users\Nicole\AppData\Local\Microsoft\MicrosoftUpdate\Microsoftupdt32.dll
c:\users\Nicole\AppData\Local\microsoft\microsoftupdate\Microsoftupdt32.exe
c:\users\Nicole\AppData\Local\ServiceAdmin.dll
c:\users\Nicole\AppData\Local\ServicePTR.dll
c:\users\Nicole\AppData\Local\Servicex86_x64.dll
c:\users\Nicole\AppData\Local\TCPIPAdmin.dll
c:\users\Nicole\AppData\Local\Trayx86_x64.dll
c:\users\Nicole\AppData\Local\wbu.exe
c:\users\Nicole\AppData\Roaming\0bdfar.exe
c:\users\Nicole\AppData\Roaming\24i25el0.exe
c:\users\Nicole\AppData\Roaming\3pvvuynj.exe
c:\users\Nicole\AppData\Roaming\7eigo00f.exe
c:\users\Nicole\AppData\Roaming\8eed.log
c:\users\Nicole\AppData\Roaming\9b5mxsh46.exe
c:\users\Nicole\AppData\Roaming\9xxofydmw.exe
c:\users\Nicole\AppData\Roaming\dynkcqkdn.exe
c:\users\Nicole\AppData\Roaming\ez87ilnhy.exe
c:\users\Nicole\AppData\Roaming\lssas.exe
c:\users\Nicole\AppData\Roaming\manager.exe
c:\users\Nicole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\santa.bat
c:\users\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\urwbwi1t.default\extensions\{bdaa08bb-3011-4150-b901-fbcef2426e39}
c:\users\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\urwbwi1t.default\extensions\{bdaa08bb-3011-4150-b901-fbcef2426e39}\chrome.manifest
c:\users\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\urwbwi1t.default\extensions\{bdaa08bb-3011-4150-b901-fbcef2426e39}\chrome\xulcache.jar
c:\users\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\urwbwi1t.default\extensions\{bdaa08bb-3011-4150-b901-fbcef2426e39}\defaults\preferences\xulcache.js
c:\users\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\urwbwi1t.default\extensions\{bdaa08bb-3011-4150-b901-fbcef2426e39}\install.rdf
c:\users\Nicole\AppData\Roaming\nsxirq246.exe
c:\users\Nicole\AppData\Roaming\qbkjuxzt.exe
c:\users\Nicole\AppData\Roaming\svlgl6pfq.exe
c:\users\Public\Desktop\FLV Direct Player.lnk
c:\windows\SysWow64\downloader.txt
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_QuestScan Service
.
.
((((((((((((((((((((((((( Files Created from 2011-09-13 to 2011-10-13 )))))))))))))))))))))))))))))))
.
.
2011-10-13 05:12 . 2011-10-13 05:12 -------- d-----w- c:\users\LogMeInRemoteUser\AppData\Local\temp
2011-10-13 05:12 . 2011-10-13 05:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-10-11 16:30 . 2011-10-11 16:32 -------- d-----w- c:\users\Nicole\AppData\Local\ElevatedDiagnostics
2011-10-11 16:23 . 2007-02-02 17:26 224768 ----a-w- c:\windows\system32\Spool\prtprocs\x64\hpzpp4v2.dll
2011-10-11 16:23 . 2007-02-02 17:28 130048 ----a-w- c:\windows\system32\hpz3l4v2.dll
2011-10-10 03:36 . 2011-10-10 03:36 -------- d-----w- c:\program files (x86)\Apple Software Update
2011-09-27 22:32 . 2011-09-27 22:32 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-09-19 19:29 . 2011-09-24 04:59 98304 ----a-w- c:\windows\SysWow64\srrstr.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-25 00:18 . 2011-08-14 00:04 0 ----a-w- c:\users\Nicole\AppData\Local\Nkitodafuveliko.bin
2011-08-14 00:02 . 2011-08-14 00:02 148 ----a-w- c:\users\Nicole\AppData\Roaming\rjxrku1pp.bat
2011-08-14 00:02 . 2011-08-14 00:02 148 ----a-w- c:\users\Nicole\AppData\Roaming\6yd609g44.bat
2011-08-12 04:10 . 2011-08-26 08:42 8862544 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A2651948-AEB0-488A-8123-C318A472D1A1}\mpengine.dll
2011-07-21 02:43 . 2010-03-02 23:11 87456 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-07-21 02:43 . 2010-03-02 23:11 33152 ----a-w- c:\windows\system32\LMIport.dll
2011-07-21 02:43 . 2010-03-02 23:11 80768 ----a-w- c:\windows\system32\LMIinit.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTo1.dll" [2011-06-25 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{26A7CA19-7D58-411D-B2DA-F1B0324CBFFC}]
2010-09-12 14:07 1499136 ----a-w- c:\program files (x86)\Gamers Unite! Snag Bar\Toolbar.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2011-06-25 02:58 3911776 ----a-w- c:\program files (x86)\uTorrentBar\tbuTo1.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-02-28 22:11 191488 ------w- c:\program files (x86)\Yontoo Layers Client\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{25515A79-C1C7-4B97-97F8-31A711694487}"= "c:\program files (x86)\Gamers Unite! Snag Bar\Toolbar.dll" [2010-09-12 1499136]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTo1.dll" [2011-06-25 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{25515a79-c1c7-4b97-97f8-31a711694487}]
[HKEY_CLASSES_ROOT\FCTB000062781.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{017D1380-106D-43D5-97DC-81E8A527FD73}]
[HKEY_CLASSES_ROOT\FCTB000062781.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AnyDVD"="c:\program files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe" [2010-04-01 3369920]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2011-04-15 399736]
"cdloader"="c:\users\Nicole\AppData\Roaming\mjusbsp\cdloader2.exe" [2010-12-03 50592]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"CloneCDTray"="c:\program files (x86)\SlySoft\CloneCD\CloneCDTray.exe" [2009-01-29 57344]
"ElbyCheckAnyDVD"="c:\program files (x86)\SlySoft\AnyDVD\ElbyCheck.exe" [2003-09-20 45056]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-30 421888]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\Update\realsched.exe" [2011-03-14 273544]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-06-07 421160]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBBAFYARgBSAEUARQAtAFYATgBKADMAMgAtAEcAMwBMAEEAQQAtAEEANAA4ADkAUgAtADkAVQBKAEsARgAtAEUASwBLADMAWAA&inst=NwA3AC0ANAAyADQANwAxADMAOQA4ADYALQBUAEIAOQArADIALQBGAEwAKwA5AC0AWABPADMANgArADEALQBGADkATQA3AEMAKwA1AC0ARgA5AE0AMQAwAEIAKwAyAC0AWABPADkAKwAxAC0ARgA5AE0AMgArADEALQBEAEQAVAArADAA&prod=90&ver=9.0.894" [?]
.
c:\users\Nicole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Canon IJ Status Monitor Canon Inkjet MX300 series.lnk - c:\windows\system32\rundll32.exe [2009-7-13 45568]
OpenOffice.org 3.2.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2009-12-15 384000]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R1 hlcrtria;hlcrtria;c:\windows\system32\drivers\hlcrtria.sys [x]
R1 ibhgsnqb;ibhgsnqb;c:\windows\system32\drivers\ibhgsnqb.sys [x]
R1 jtnpzsry;jtnpzsry;c:\windows\system32\drivers\jtnpzsry.sys [x]
R1 lanhqums;lanhqums;c:\windows\system32\drivers\lanhqums.sys [x]
R1 mgeimbnh;mgeimbnh;c:\windows\system32\drivers\mgeimbnh.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-20 136176]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-20 136176]
R3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys [x]
R3 LVUVC64;Logitech Webcam 120(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2011-07-21 375176]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2008-08-11 15928]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-04-24 483688]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-04-24 209768]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-20 06:34]
.
2011-10-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-20 06:34]
.
2011-10-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-486493133-1455968607-1562069686-1001Core.job
- c:\users\Nicole\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-17 02:46]
.
2011-10-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-486493133-1455968607-1562069686-1001UA.job
- c:\users\Nicole\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-17 02:46]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2008-08-11 57928]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-24 165912]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-24 385560]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-24 363544]
"combofix"="c:\combofix\CF23823.3XE" [2009-07-14 344576]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://mp3tubetoolbar.com/?tmp=toolbar_Mp3Tube_homepage&prt=pinballtbfour04ie&clid=7e5964b4ce2a49648f23c672d9a9f119
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 68.87.85.102 68.87.69.150
FF - ProfilePath - c:\users\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\urwbwi1t.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=ConduitEngine&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Yahoo-Mp3Tube
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: LoudMo Contextual Ad Assistant: {c402222d-edf1-7871-7250-2c8915d1f628} - c:\program files (x86)\Mozilla Firefox\extensions\{c402222d-edf1-7871-7250-2c8915d1f628}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: QuestScan: {F0E1168A-B4B5-484C-B77E-0D28E6B64096} - c:\program files (x86)\Mozilla Firefox\extensions\{F0E1168A-B4B5-484C-B77E-0D28E6B64096}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: Facebook Toolbar: firefox@facebook.com - %profile%\extensions\firefox@facebook.com
FF - Ext: Zynga Community Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF - Ext: LogMeIn, Inc. Remote Access Plugin: LogMeInClient@logmein.com - %profile%\extensions\LogMeInClient@logmein.com
FF - Ext: Gamers Unite! Snag Bar: {afe43e80-0abc-4df2-81a0-3fe44b74abe8} - %profile%\extensions\{afe43e80-0abc-4df2-81a0-3fe44b74abe8}
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
FF - Ext: Yontoo Layers: plugin@yontoo.com - %profile%\extensions\plugin@yontoo.com
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF - user.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - user.js: keyword.enabled - 1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-{0C8413C1-FAD1-446C-8584-BE50576F863E} - (no file)
Wow6432Node-HKCU-Run-DW6 - c:\program files (x86)\The Weather Channel FW\Desktop\DesktopWeather.exe
Wow6432Node-HKCU-Run-616r - c:\users\Nicole\AppData\Roaming\0bdfar.exe
Wow6432Node-HKCU-Run-Local Account Service - c:\users\Nicole\AppData\Roaming\lssas.exe
Wow6432Node-HKCU-Run-Plug Manager - c:\users\Nicole\AppData\Roaming\manager.exe
Wow6432Node-HKCU-Run-DDMSettings Update - c:\users\Nicole\AppData\Local\DDMSettings\DDMSettingsUpdate\DDMSettingsupdt32.exe
Wow6432Node-HKCU-Run-JavaUpdateBackup - c:\programdata\JavaUpdateBackup.dll
Wow6432Node-HKCU-Run-Apps Update - c:\users\Nicole\AppData\Local\Apps\AppsUpdate\Appsupdt32.exe
Wow6432Node-HKCU-Run-Ilivid Player Update - c:\users\Nicole\AppData\Local\Ilivid Player\IlividUpdate\Ilividupdt32.exe
Wow6432Node-HKCU-Run-Graboid Update - c:\users\Nicole\AppData\Local\Graboid\GraboidUpdate\Graboidupdt32.exe
Wow6432Node-HKCU-Run-Diagnostics Update - c:\users\Nicole\AppData\Local\Diagnostics\DiagnosticsUpdate\Diagnosticsupdt32.exe
Wow6432Node-HKCU-Run-Adobe Update - c:\users\Nicole\AppData\Local\Adobe\AdobeUpdate\Adobeupdt32.exe
Wow6432Node-HKCU-Run-Apple Computer Update - c:\users\Nicole\AppData\Local\Apple Computer\AppleUpdate\Appleupdt32.exe
Wow6432Node-HKU-Default-Run-Microsoft Update - c:\users\Nicole\AppData\Local\Microsoft\MicrosoftUpdate\Microsoftupdt32.exe
Wow6432Node-HKU-Default-Run-Ilivid Player Update - c:\users\Nicole\AppData\Local\Ilivid Player\IlividUpdate\Ilividupdt32.exe
Wow6432Node-HKU-Default-Run-Graboid Update - c:\users\Nicole\AppData\Local\Graboid\GraboidUpdate\Graboidupdt32.exe
Wow6432Node-HKU-Default-Run-DDMSettings Update - c:\users\Nicole\AppData\Local\DDMSettings\DDMSettingsUpdate\DDMSettingsupdt32.exe
Wow6432Node-HKU-Default-Run-Apple Computer Update - c:\users\Nicole\AppData\Local\Apple Computer\AppleUpdate\Appleupdt32.exe
Toolbar-Locked - (no file)
WebBrowser-{0C8413C1-FAD1-446C-8584-BE50576F863E} - (no file)
WebBrowser-{25515A79-C1C7-4B97-97F8-31A711694487} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\OpenOffice.org 3\program\soffice.exe
c:\program files (x86)\OpenOffice.org 3\program\soffice.bin
.
**************************************************************************
.
Completion time: 2011-10-12 23:32:47 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-13 05:32
.
Pre-Run: 1,774,178,304 bytes free
Post-Run: 2,410,188,800 bytes free
.
- - End Of File - - 4B0D581E4ECADFBA7B97B254577A3845