Okay I downloaded Combofix to the Downloads folder then put it on the desktop, renamed it svchost.exe and then ran it. I had disabled my AV Bitdefender Internet Security 2011 as much as possible before running ComboFix. Although it said it would take about 10-20 minutes only, the process was very slow. Though I have a snappy computer, It took 11 hours to reach Completed stage 48 and it was stuck there so I decided to run it in safe mode. I have tried pressing F8 key in the past for going into safe mode but it somehow doesn't work for me due to my mobo probably so I use msconfig to get into safe mode by changing boot settings to Safe boot - minimal. After my pc booted into safe mode, I ran ComboFix and it took almost just 10-12 minutes to complete all the stages. Then it rebooted the computer itself. When it rebooted into safe mode again, the log appeared. Then I tried to go to msconfig again to change the boot settings to normal but it said something like msconfig is set for deletion and I wasn't able to open it. So I did a restart after which I was able to get into msconfig and able to select normal boot again. After restarting again, there was no network so I restarted my pc once again and after this restart I got back my internet(atleast the icon showed). I pulled the power plug on my modem thinking I would change the homepage that would still be there so that after connecting to the internet I wouldn't be taken to that malicious page apype dot com and starwebsearch dot com again. So I changed the homepage to google.com and closed the browser. Then I reconnected the modem's power and when it showed I had network access, I started firefox. But it still opened the horror page. When the infection was new, it used to give me wrong suggestions everywhere and do many other things but now only my homepage is reversed to that site again and again. Even my searchbar engine does not change like it used to get changed just like my homepage. It stays on google These good changes happened when I used PC Tools. So would just a fresh install of firefox be enough for deleting this virus? The logs of the ComboFix scan are as follows. Thanks again for helping.
ComboFix 12-09-18.07 - Vicky 20-Sep-12 10:48:26.2.2 - x86 MINIMAL
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3071.2341 [GMT 5.5:30]
Running from: c:\users\Vicky\Desktop\svchost.exe.exe
AV: BitDefender Antivirus *Disabled/Updated* {50909708-FF80-02AF-F814-B28405891E92}
FW: BitDefender Firewall *Disabled* {68AB162D-B5EF-03F7-D34B-1BB1FB5A59E9}
SP: BitDefender AntiSpyware *Disabled/Updated* {EBF176EC-D9BA-0D21-C2A4-89F67E0E542F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
ADS - Windows: deleted 192 bytes in 1 streams.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\mazuki.dll
c:\users\Vicky\AppData\Local\assembly\tmp
c:\users\Vicky\AppData\Roaming\FFSJ
c:\users\Vicky\AppData\Roaming\FFSJ\FFSJ.cfg
c:\windows\system32\Config.cfg
c:\windows\system32\DreamScene.dll.2086
c:\windows\system32\netjr32.dll
c:\windows\system32\roboot.exe
c:\windows\system32\wpcap.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_VCS
-------\Service_Vcs
.
.
((((((((((((((((((((((((( Files Created from 2012-08-20 to 2012-09-20 )))))))))))))))))))))))))))))))
.
.
2012-09-20 05:28 . 2012-09-20 05:30 -------- d-----w- c:\users\Vicky\AppData\Local\temp
2012-09-20 05:28 . 2012-09-20 05:28 -------- d-----w- c:\users\UpdatusUser.Vicky-PC\AppData\Local\temp
2012-09-19 17:33 . 2012-09-19 17:33 9310 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXTBOX.JS
2012-09-19 17:33 . 2012-09-19 17:33 8646 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TILEBOX.JS
2012-09-19 17:33 . 2012-09-19 17:33 8613 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\SAVEDUSER.JS
2012-09-19 17:33 . 2012-09-19 17:33 6429 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS
2012-09-19 17:33 . 2012-09-19 17:33 63115 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS
2012-09-19 17:33 . 2012-09-19 17:33 5927 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXT.JS
2012-09-19 17:33 . 2012-09-19 17:33 4599 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UIRESOURCE.JS
2012-09-19 17:33 . 2012-09-19 17:33 6910 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\NEWUSERCOMM.JS
2012-09-19 17:33 . 2012-09-19 17:33 6208 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LINK.JS
2012-09-19 17:33 . 2012-09-19 17:33 18541 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LOCALIZATION.JS
2012-09-19 17:33 . 2012-09-19 17:33 1651 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\QUERYSTRING.JS
2012-09-19 17:32 . 2012-09-19 17:32 8288 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\IMAGE.JS
2012-09-19 17:32 . 2012-09-19 17:32 51852 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\EXTERNALWRAPPER.JS
2012-09-19 17:32 . 2012-09-19 17:32 8782 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS
2012-09-19 17:32 . 2012-09-19 17:32 7271 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS
2012-09-19 17:32 . 2012-09-19 17:32 23327 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS
2012-09-19 17:32 . 2012-09-19 17:32 20719 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS
2012-09-18 16:51 . 2012-09-18 16:51 -------- d-----w- c:\users\Vicky\AppData\Roaming\PC Tools
2012-09-18 14:33 . 2012-09-18 14:33 -------- d-----w- c:\users\Vicky\AppData\Local\Threat Expert
2012-09-18 07:51 . 2012-06-22 06:08 767960 ----a-w- c:\windows\BDTSupport.dll0947.old
2012-09-18 07:51 . 2012-06-22 06:09 149464 ----a-w- c:\windows\SGDetectionTool.dll0947.old
2012-09-18 07:51 . 2012-06-22 06:09 2267096 ----a-w- c:\windows\PCTBDCore.dll0947.old
2012-09-18 07:50 . 2012-06-22 10:03 17880 ----a-w- c:\windows\system32\drivers\pctBTFix.sys
2012-09-18 07:49 . 2012-09-18 07:49 -------- d-----w- c:\program files\PC Tools
2012-09-18 07:15 . 2012-09-18 21:17 -------- d-----w- c:\program files\Common Files\PC Tools
2012-09-18 07:15 . 2012-06-22 10:04 203120 ----a-w- c:\windows\system32\drivers\PCTSD.sys
2012-09-18 07:14 . 2012-09-18 21:15 -------- d-----w- c:\programdata\PC Tools
2012-09-18 07:14 . 2012-09-18 07:14 -------- d-----w- c:\users\Vicky\AppData\Roaming\TestApp
2012-09-18 05:43 . 2012-09-18 05:43 -------- d-----w- c:\program files\Mindjet
2012-09-17 17:58 . 2012-09-17 17:58 -------- d-----w- c:\program files\TeamViewer
2012-09-17 17:58 . 2012-08-07 10:36 25088 ----a-w- c:\windows\system32\drivers\teamviewervpn.sys
2012-09-17 17:55 . 2012-09-17 17:56 -------- d-----w- c:\users\Vicky\AppData\Roaming\calibre
2012-09-17 17:55 . 2012-09-17 17:55 -------- d-----w- c:\program files\Calibre2
2012-09-17 17:52 . 2012-09-17 17:53 -------- d-----w- c:\program files\FrostWire 5
2012-09-17 17:43 . 2012-09-17 17:43 -------- d-----w- c:\users\Vicky\AppData\Local\Usmania_Code
2012-09-17 17:43 . 2012-09-17 17:43 -------- d-----w- c:\programdata\Usmania Code
2012-09-17 17:43 . 2012-09-17 17:43 -------- d-----w- c:\program files\Usmania Code
2012-09-17 17:43 . 2012-09-17 17:43 -------- d-----r- C:\AHCache
2012-09-17 17:42 . 2012-09-17 17:42 -------- d-----w- c:\program files\Throttle
2012-09-17 17:26 . 2012-09-17 17:36 -------- d-----w- c:\users\Vicky\AppData\Roaming\SurfAnonymousFree
2012-09-17 17:26 . 2012-09-17 17:36 -------- d-----w- c:\programdata\SurfAnonymousFree
2012-09-17 17:25 . 2012-09-17 17:25 -------- d-----w- c:\program files\CalcTape
2012-09-17 17:22 . 2012-09-17 17:36 -------- d-----w- c:\users\Vicky\AppData\Local\DeskShare
2012-09-17 17:22 . 2012-09-17 17:25 -------- d-----w- c:\programdata\firebird
2012-09-17 17:22 . 2012-09-17 17:22 -------- d-----w- c:\users\Vicky\AppData\Local\DeskShare Data
2012-09-17 17:22 . 2012-09-17 17:22 -------- d-----w- c:\programdata\Deskshare
2012-09-17 17:22 . 2012-09-17 17:22 -------- d-----w- c:\users\Vicky\AppData\Local\Spoon
2012-09-17 17:22 . 2012-09-17 17:22 -------- d-----w- c:\program files\Deskshare
2012-09-17 17:19 . 2009-06-16 06:06 1226672 ----a-w- c:\windows\system32\Codejock.ReportControl.v13.1.0.ocx
2012-09-17 17:19 . 2009-06-16 05:05 1791920 ----a-w- c:\windows\system32\Codejock.Controls.v13.1.0.ocx
2012-09-17 17:19 . 2008-08-22 02:05 538544 ----a-w- c:\windows\system32\Codejock.SkinFramework.Unicode.v12.0.2.ocx
2012-09-17 17:19 . 2009-06-16 05:05 2320304 ----a-w- c:\windows\system32\Codejock.CommandBars.v13.1.0.ocx
2012-09-17 17:19 . 2004-03-08 18:30 662288 ----a-w- c:\windows\system32\MSCOMCT2.OCX
2012-09-17 17:19 . 1998-06-17 19:30 89360 ----a-w- c:\windows\system32\VB5DB.DLL
2012-09-17 17:19 . 2012-09-17 17:19 -------- d-----w- c:\program files\Reminder Commander
2012-09-17 17:17 . 2012-06-24 09:08 158144 ----a-w- c:\windows\system32\drivers\fancyrd.sys
2012-09-17 17:17 . 2012-04-18 11:42 19392 ----a-w- c:\windows\system32\drivers\rxbsknl.sys
2012-09-17 17:17 . 2012-09-17 21:34 -------- d-----w- c:\program files\Primo Ramdisk Ultimate Edition
2012-09-17 17:15 . 2012-09-17 17:15 -------- d-----w- c:\program files\Photo Stamp Remover
2012-09-17 17:10 . 2012-09-17 17:10 -------- d-----w- C:\mbc
2012-09-17 17:09 . 2012-09-17 17:09 -------- d-----w- c:\program files\RobotSoft
2012-09-17 17:08 . 2012-09-17 17:08 -------- d-----w- c:\program files\mirabyte
2012-09-17 17:07 . 2006-01-30 03:02 5632 ----a-w- c:\windows\system32\pxc25pm.dll
2012-09-17 17:06 . 2012-09-17 17:06 -------- d-----w- c:\programdata\Mindjet
2012-09-17 17:05 . 2012-09-17 17:05 -------- d-----w- c:\users\Vicky\AppData\Local\{9D53112B-37A1-4DBB-8E9C-CDC5FFF46604}
2012-09-17 17:02 . 2012-09-17 17:02 -------- d-----w- c:\users\Vicky\AppData\Roaming\Maxprog
2012-09-17 17:02 . 2012-09-17 17:02 -------- d-----w- c:\program files\eMail Extractor
2012-09-17 17:01 . 2012-09-17 17:01 -------- d-----w- c:\users\Vicky\AppData\Roaming\CommonDataMSI
2012-09-17 17:01 . 2012-09-17 17:01 -------- d-----w- c:\users\Vicky\AppData\Roaming\Iconico
2012-09-17 17:01 . 2012-09-17 17:01 -------- d-----w- c:\program files\LineReader
2012-09-17 17:00 . 2012-09-17 17:00 -------- d-----w- c:\users\Vicky\AppData\Roaming\MyPhoneExplorer
2012-09-17 17:00 . 2012-09-17 17:57 -------- d-----w- c:\program files\MyPhoneExplorer
2012-09-17 16:52 . 2012-09-17 16:52 -------- d-----w- c:\program files\GtkSharp
2012-09-17 16:52 . 2012-09-17 16:52 -------- d-----w- c:\program files\Kepard
2012-09-17 16:50 . 2012-09-17 16:50 -------- d-----w- c:\program files\ChordWizard
2012-09-17 16:00 . 2012-08-13 20:07 381608 ------w- c:\windows\system32\MC17.exe
2012-09-17 15:59 . 2012-08-13 16:00 585728 ------w- c:\windows\system32\AReadyLB.dll
2012-09-17 15:59 . 2012-08-13 16:00 229376 ------w- c:\windows\system32\AudDevicePlugin.dll
2012-09-17 15:59 . 2012-09-17 15:59 -------- d-----w- c:\program files\J River
2012-09-17 15:59 . 2012-09-17 15:59 -------- d-----w- c:\users\Vicky\AppData\Roaming\J River
2012-09-17 15:55 . 2012-09-17 15:57 -------- d-----w- c:\programdata\Mirolit
2012-09-17 15:55 . 2012-09-17 15:55 -------- d-----w- c:\program files\Mirolit
2012-09-17 15:53 . 2012-09-17 15:53 -------- d-----w- c:\program files\Geometry Expressions v3.0
2012-09-17 15:51 . 2012-09-17 15:51 -------- d-----w- c:\program files\Common Files\System-G
2012-09-17 15:51 . 2012-09-17 16:44 -------- d-----w- c:\program files\Gammadyne Mailer
2012-09-17 15:49 . 2012-09-17 15:49 -------- d-----w- c:\program files\ThunderSoft
2012-09-17 15:47 . 2012-09-17 15:48 -------- d-----w- c:\program files\DreamCalc DC4P
2012-09-17 15:46 . 2012-09-17 15:46 -------- d-----w- c:\users\Vicky\AppData\Roaming\DiskSpaceFan
2012-09-17 15:46 . 2012-09-17 15:46 -------- d-----w- c:\program files\Cookapp
2012-09-17 15:44 . 2012-09-17 15:45 -------- d-----w- c:\users\Vicky\AppData\Roaming\Direct Folders
2012-09-17 15:44 . 2012-09-17 15:44 -------- d-----w- c:\program files\Direct Folders
2012-09-17 15:37 . 2012-09-17 15:38 -------- d-----w- c:\program files\BitTorrent Ultra Accelerator
2012-09-17 15:35 . 2012-09-17 15:35 -------- d-----w- c:\program files\Tint Guide
2012-09-17 15:35 . 2012-09-17 15:35 -------- d-----w- c:\program files\Beauty Guide
2012-09-17 15:31 . 2012-09-17 15:31 -------- d-----w- c:\users\Vicky\AppData\Roaming\Scooter Software
2012-09-17 15:31 . 2012-09-17 15:31 -------- d-----w- c:\program files\Beyond Compare 3
2012-09-17 15:21 . 2009-08-24 16:38 28160 ----a-w- c:\windows\system32\DfSdkBt.exe
2012-09-17 15:21 . 2012-09-17 15:21 -------- d-----w- c:\program files\Ashampoo
2012-09-17 15:19 . 2012-09-17 15:19 -------- d-----w- c:\users\Vicky\AppData\Roaming\Writer's Cafe 2
2012-09-17 15:18 . 2012-09-17 15:20 -------- d-----w- c:\program files\Writer's Cafe 2
2012-09-17 15:16 . 2012-09-17 15:16 -------- d-----w- c:\program files\Acmework
2012-09-14 20:59 . 2012-09-14 20:59 -------- d-----w- c:\users\Vicky\AppData\Roaming\dvdcss
2012-09-13 12:02 . 2012-09-13 12:02 -------- d-----w- c:\program files\Office 2010 Trial Extender
2012-09-05 11:10 . 2012-09-05 11:10 446464 ----a-w- c:\windows\system32\YuoTubeDownloader.dll
2012-09-05 08:33 . 2012-09-05 08:33 -------- d-----w- c:\users\House\AppData\Roaming\Design Science
2012-09-04 22:59 . 2012-09-05 18:52 -------- d-----w- c:\users\Vicky\AppData\Local\Apple Computer
2012-09-03 08:13 . 2012-09-03 08:13 -------- d-----w- c:\program files\RocketDock
2012-09-03 06:51 . 2009-07-14 01:14 3405312 ----a-w- c:\windows\system32\xpsrchvw.exe
2012-09-03 06:51 . 2010-11-20 12:17 4247040 ----a-w- c:\program files\Windows NT\Accessories\wordpad.exe
2012-09-03 06:51 . 2010-11-20 12:17 164864 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2012-09-02 06:21 . 2012-09-02 06:21 -------- d-----w- c:\users\Vicky\AppData\Roaming\Rovio
2012-09-01 08:05 . 2012-09-01 08:05 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-08-30 07:46 . 2012-08-30 07:46 -------- d-----w- c:\programdata\ProcessLasso
2012-08-30 07:45 . 2012-08-30 07:47 -------- d-----w- c:\users\Vicky\AppData\Roaming\ProcessLasso
2012-08-30 07:45 . 2012-08-30 07:53 -------- d-----w- c:\program files\Process Lasso
2012-08-30 07:05 . 2012-08-30 07:06 -------- d-----w- c:\users\Vicky\AppData\Roaming\Wise Disk Cleaner
2012-08-23 13:07 . 2012-08-23 13:07 -------- d-----w- c:\users\House\AppData\Roaming\Comodo
2012-08-23 13:07 . 2012-08-23 13:07 -------- d-----w- c:\users\House\AppData\Local\Comodo
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-01 08:05 . 2012-01-01 17:17 821736 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-09-01 08:05 . 2011-12-16 09:46 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-22 18:01 . 2012-04-10 16:22 696520 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-22 18:01 . 2011-12-15 11:14 73416 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-17 19:20 . 2012-08-12 15:11 45320 ----a-w- c:\windows\system32\certsentry.dll
2012-07-20 06:37 . 2012-07-20 06:37 34308 ----a-w- c:\windows\system32\LB603.dll
2012-07-20 06:36 . 2012-07-20 06:36 157696 ----a-w- c:\windows\system32\asxtract.dll
2012-07-20 06:36 . 2012-07-20 06:36 136008 ----a-w- c:\windows\system32\MSINET.Ocx
2012-07-14 07:30 . 2012-07-14 07:30 4024320 ----a-w- c:\program files\GUT1A06.tmp
2012-07-13 14:34 . 2012-07-13 14:34 53248 ----a-r- c:\users\Vicky\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2012-07-13 12:17 . 2012-01-20 12:06 499712 ----a-w- c:\windows\system32\msvcp71.dll
2012-07-13 12:17 . 2012-01-20 12:06 348160 ----a-w- c:\windows\system32\msvcr71.dll
2012-07-12 09:28 . 2012-07-12 08:45 233888 ----a-w- c:\windows\system32\DreamScene.dll
2012-07-03 08:16 . 2011-12-26 16:55 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-27 10:53 . 2011-12-26 14:34 2755072 ----a-w- c:\windows\system32\themeui.dll
2012-06-27 10:53 . 2009-07-13 23:39 37376 ----a-w- c:\windows\system32\themeservice.dll
2012-06-27 10:53 . 2009-07-13 23:40 249856 ----a-w- c:\windows\system32\uxtheme.dll
2010-07-08 05:07 . 2010-07-08 05:07 101544 ----a-w- c:\program files\Common Files\LinkInstaller.exe
2012-09-08 07:08 . 2012-09-08 07:08 266720 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{3d175337-41e3-48eb-a754-493577f658b9}"= "c:\windows\system32\YuoTubeDownloader.dll" [2012-09-05 446464]
.
[HKEY_CLASSES_ROOT\clsid\{3d175337-41e3-48eb-a754-493577f658b9}]
[HKEY_CLASSES_ROOT\ToolBarMFC.DeskBandImplD.1]
[HKEY_CLASSES_ROOT\TypeLib\{942926A2-CC3B-4970-9AD6-D9056D197CE6}]
[HKEY_CLASSES_ROOT\ToolBarMFC.DeskBandImplD]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3d175337-41e3-48eb-a754-493577f658b9}]
2012-09-05 11:10 446464 ----a-w- c:\windows\System32\YuoTubeDownloader.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3d175337-41e3-48eb-a754-493577f658b9}"= "c:\windows\system32\YuoTubeDownloader.dll" [2012-09-05 446464]
.
[HKEY_CLASSES_ROOT\clsid\{3d175337-41e3-48eb-a754-493577f658b9}]
[HKEY_CLASSES_ROOT\ToolBarMFC.DeskBandImplD.1]
[HKEY_CLASSES_ROOT\TypeLib\{942926A2-CC3B-4970-9AD6-D9056D197CE6}]
[HKEY_CLASSES_ROOT\ToolBarMFC.DeskBandImplD]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2010-03-15 718208]
"Chameleon Folder"="c:\program files\Chameleon Folder 2\chfolder.exe" [2012-03-09 2906112]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2011\ieshow.exe" [2011-12-26 92352]
"BDAgent"="c:\program files\BitDefender\BitDefender 2011\bdagent.exe" [2011-12-26 1451928]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2011-11-11 205336]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\users\House\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2010-3-29 227712]
.
c:\users\Vicky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Mouse Button Control.lnk - c:\program files\ElectraSoft\mbc\MBC.EXE [2012-9-17 458752]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^BitTorrent Ultra Accelerator.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\BitTorrent Ultra Accelerator.lnk
backup=c:\windows\pss\BitTorrent Ultra Accelerator.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^DFX.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\DFX.lnk
backup=c:\windows\pss\DFX.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^MobileGo Service.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\MobileGo Service.lnk
backup=c:\windows\pss\MobileGo Service.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^RocketDock.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\RocketDock.lnk
backup=c:\windows\pss\RocketDock.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SkinPackMenu.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\SkinPackMenu.lnk
backup=c:\windows\pss\SkinPackMenu.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^UberIcon.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\UberIcon.lnk
backup=c:\windows\pss\UberIcon.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^YzShadow.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\YzShadow.lnk
backup=c:\windows\pss\YzShadow.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Vicky^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Direct Folders.lnk]
path=c:\users\Vicky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Direct Folders.lnk
backup=c:\windows\pss\Direct Folders.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Vicky^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk]
path=c:\users\Vicky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Vicky^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^PersonalBrain.lnk]
path=c:\users\Vicky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PersonalBrain.lnk
backup=c:\windows\pss\PersonalBrain.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power2GoExpress]
NA [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-07-27 20:51 919008 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2012-02-20 15:58 59240 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenuEx]
2010-04-02 04:48 1185112 ----a-w- c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
2010-08-20 04:27 107816 ----a-w- c:\program files\CyberLink\Power2Go\CLMLSvc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
2012-04-11 23:08 1163072 ----a-w- c:\program files\DAEMON Tools Pro\DTAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2012-01-01 14:32 136176 ----atw- c:\users\Vicky\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTurbo]
2012-04-16 08:44 177152 ----a-w- c:\program files\iNTERNET Turbo\ITTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LearnWords Launcher]
2012-03-26 23:18 792576 ----a-w- c:\program files\LearnWords\LearnWords.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMReminderService]
2012-07-02 22:55 38288 ----a-w- e:\vicky\Installed\Mindjet MindManager\MmReminderService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2012-04-18 15:26 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2012-07-13 12:17 296096 ----a-w- c:\program files\Real\RealPlayer\Update\realsched.exe
.
R1 Bdfndisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [x]
R1 bdfwfpf;bdfwfpf;c:\program files\Common Files\BitDefender\BitDefender Firewall\bdfwfpf.sys [x]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
R2 AHDDC2;Ashampoo HDD Control 2 Service;c:\program files\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe [x]
R2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe [x]
R2 IceDragonUpdater;COMODO IceDragon Update Service;c:\program files\Comodo\IceDragon\icedragon_updater.exe [x]
R2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\nlssrv32.exe [x]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [x]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
R2 TeamViewer7;TeamViewer 7;c:\program files\TeamViewer\Version7\TeamViewer_Service.exe [x]
R2 Updatesrv;BitDefender Desktop Update Service;c:\program files\BitDefender\BitDefender 2011\updatesrv.exe [x]
R2 VBoxDrv;VBox Support Driver;c:\program files\YouWave_Android\vb\VBoxDrv.sys [x]
R2 WCMVCAM;WebcamMax, WDM Video Capture;c:\windows\system32\DRIVERS\wcmvcam.sys [x]
R3 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys [x]
R3 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys [x]
R3 bdfm;bdfm;c:\windows\system32\DRIVERS\bdfm.sys [x]
R3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo HDD Control 2\DfSdkS.exe [x]
R3 ExpressAccountsService;Express Accounts;c:\program files\NCH Software\ExpressAccounts\expressaccounts.exe [x]
R3 GSService;GSService;c:\windows\system32\GSService.exe [x]
R3 LTXMD_VAC;Litex Media Virtual Audio Cable (WDM);c:\windows\system32\drivers\lmvac.sys [x]
R3 Media Center 17 Service;Media Center 17 Service;c:\program files\J River\Media Center 17\JRService.exe [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]
R3 Nbdrv;NetBalancer Service;c:\windows\system32\DRIVERS\nbdrv.sys [x]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
R3 REN2CAP_DRIVER;Hear;c:\windows\system32\drivers\ren2cap.sys [x]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys [x]
R3 RRNetCap;RRNetCap Service;c:\windows\system32\DRIVERS\rrnetcap.sys [x]
R3 RRNetCapMP;RRNetCapMP;c:\windows\system32\DRIVERS\rrnetcap.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
R3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 Update Server;BitDefender Update Server v2;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [x]
R3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [x]
R3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [x]
R3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [x]
R3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [x]
R3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [x]
R4 DragonSvc;Dragon Service;c:\program files\Common Files\Nuance\dgnsvc.exe [x]
S0 FancyRd;Primo Ramdisk Controller;c:\windows\system32\DRIVERS\fancyrd.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{90EF4A5E-85DB-4825-96F5-1AB93C2A8EEB}]
2012-07-02 22:52 1409 ----a-r- e:\vicky\Installed\Mindjet MindManager\sys\MmInternetExplorerActiveSetup.vbs
.
Contents of the 'Scheduled Tasks' folder
.
2012-09-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-499340394-4099650204-2415665824-1000Core.job
- c:\users\Vicky\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-01 14:32]
.
2012-09-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-499340394-4099650204-2415665824-1000UA.job
- c:\users\Vicky\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-01 14:32]
.
2012-09-19 c:\windows\Tasks\RegClean Pro_DEFAULT.job
- c:\program files\RegClean Pro\RegCleanPro.exe [2012-01-01 07:56]
.
2012-09-19 c:\windows\Tasks\RegClean Pro_UPDATES.job
- c:\program files\RegClean Pro\RegCleanPro.exe [2012-01-01 07:56]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.google.co.in/
mStart Page = hxxp://in.yahoo.com/?fr=fp-spt_gen
IE:
IE: Add to Link Commander collection
IE: Download with Mipony - file://c:\program files\MiPony\Browser\IEContext.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~4\Office14\ONBttnIE.dll/105
IE: Send Image To MindManager - e:\vicky\Installed\Mindjet MindManager\Mm8InternetExplorer.dll/201
IE: Send Link To MindManager - e:\vicky\Installed\Mindjet MindManager\Mm8InternetExplorer.dll/203
IE: Send Page To MindManager - e:\vicky\Installed\Mindjet MindManager\Mm8InternetExplorer.dll/204
IE: Send Text To MindManager - e:\vicky\Installed\Mindjet MindManager\Mm8InternetExplorer.dll/202
TCP: Interfaces\{05C55753-A390-4370-BD93-BBB2EAB7A44D}: NameServer = 59.185.0.23,59.185.0.50
FF - ProfilePath - c:\users\Vicky\AppData\Roaming\Mozilla\Firefox\Profiles\fhijf7ns.default\
FF - prefs.js: browser.search.defaulturl - hxxp://
www.gigabase.ru/search?clid=1&q=
FF - prefs.js: browser.search.selectedEngine - Custom search
FF - prefs.js: browser.startup.homepage - hxxp://apype.com
FF - prefs.js: keyword.URL - hxxp://apype.com/results.php?q=
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
BHO-{0E7B5242-346E-652E-0A16-3BF61F895702} - (no file)
HKU-Default-Run-Reasonable NoClone - (no file)
MSConfigStartUp-Babylon Client - c:\program files\Babylon\Babylon-Pro\Babylon.exe
MSConfigStartUp-campaper - c:\program files\campaper\campaper.exe
MSConfigStartUp-RockMelt Update - c:\users\Vicky\AppData\Local\RockMelt\Update\RockMeltUpdate.exe
MSConfigStartUp-SearchSettings - c:\program files\Common Files\Spigot\Search Settings\SearchSettings.exe
MSConfigStartUp-TAForOE Loader - c:\program files\TextAloud\TAForOELoader.exe
MSConfigStartUp-Video Library - c:\users\Vicky\AppData\Local\Temp\Rpcqt.dll
MSConfigStartUp-YuoTubeDownloader_Helper - c:\program files\YuoTubeDownloader\YuoTubeDownloader_Helper.exe
AddRemove-Key Reminder Commander 4.00 - c:\users\Vicky\Desktop\Uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{381FFDE8-2394-4F90-B10D-FC6124A40F8C}"=hex:51,66,7a,6c,4c,1d,38,12,86,fe,0c,
3c,a6,6d,fe,0a,ce,1b,bf,21,21,fa,4b,98
"{EE5D279F-081B-4404-994D-C6B60AAEBA6D}"=hex:51,66,7a,6c,4c,1d,38,12,f1,24,4e,
ea,29,46,6a,01,e6,5b,85,f6,0f,f0,fe,79
"{0FB6A909-6086-458F-BD92-1F8EE10042A0}"=hex:51,66,7a,6c,4c,1d,38,12,67,aa,a5,
0b,b4,2e,e1,00,c2,84,5c,ce,e4,5e,06,b4
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}"=hex:51,66,7a,6c,4c,1d,38,12,d8,cf,e9,
98,0d,61,19,04,eb,fc,4e,6b,77,8d,c0,d5
"{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,38,12,5b,ab,e0,
b0,13,40,37,0c,c5,34,01,f3,05,d0,46,eb
"{C08DF07A-3E49-4E25-9AB0-D3882835F153}"=hex:51,66,7a,6c,4c,1d,38,12,14,f3,9e,
c4,7b,70,4b,0b,e5,a6,90,c8,2d,6b,b5,47
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}"=hex:51,66,7a,6c,4c,1d,38,12,95,22,87,
ed,ef,26,9e,05,cb,ba,f4,42,79,f0,6b,0e
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:cc,40,94,66,28,f9,cc,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fc,9e,eb,b9,6a,e6,93,4d,9a,1e,5c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fc,9e,eb,b9,6a,e6,93,4d,9a,1e,5c,\
.
[HKEY_USERS\.Default\Software\SetId\Internal]
@Denied: (A 2) (LocalSystem)
"DEVICE2"="vrfIyq7KygA="
"DATA2"="<settings accountStatus=\"4\" oldDevice=\"\" timeDiff=\"1106312873\" expireTime=\"1309830893\" productStatus=\"1\" obSize=\"0\" InstallIS=\"1289332796\" isSubsc=\"0\" authStat_is=\"0\" version=\"14.1\" keyType=\"194\" prodId=\"2\" moduleId1=\"8\" moduleId2=\"0\" relType=\"1\" />"
.
[HKEY_USERS\S-1-5-21-499340394-4099650204-2415665824-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8B9462F1-CA22-C48C-8A89-885E3BB03B97}*]
"bbbhmnpdoafdfgaaoflnafbkcbfofhnpegfk"=hex:69,61,66,6d,6f,6a,69,6b,65,6a,6f,6e,
6c,6a,66,6a,6c,70,00,00
"ablhknooeaogpfiemgonfiaghlejoigfed"=hex:6a,61,69,6d,64,6a,6e,6f,6f,67,63,64,
69,62,6e,6b,69,62,6c,6a,00,00
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\conhost.exe
.
**************************************************************************
.
Completion time: 2012-09-20 11:04:41 - machine was rebooted
ComboFix-quarantined-files.txt 2012-09-20 05:34
.
Pre-Run: 9,461,977,088 bytes free
Post-Run: 9,934,626,816 bytes free
.
- - End Of File - - 90C0275EEF1C15816758A3E7F2045FA8