I edited it a little and I'm posting it so I can see it better.
ComboFix 12-06-12.03 - Adam 06/12/2012 20:53:41.2.4 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4094.2283 [GMT -4:00]
Running from: c:\users\Adam\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\1320091276.bdinstall.bin
c:\users\Adam\AppData\Roaming\Love
c:\users\Adam\AppData\Roaming\Love\mari0\options.txt
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
c:\windows\PFRO.log
c:\windows\SysWow64\avisynth.dll
c:\windows\SysWow64\devil.dll
c:\windows\SysWow64\server.log
.
---- Previous Run -------
.
c:\windows\Installer\{407c2ae1-b9e3-f1ae-d184-4c81afaf026a}\@
c:\windows\Installer\{407c2ae1-b9e3-f1ae-d184-4c81afaf026a}\L\00000004.@
c:\windows\Installer\{407c2ae1-b9e3-f1ae-d184-4c81afaf026a}\L\201d3dde
c:\windows\Installer\{407c2ae1-b9e3-f1ae-d184-4c81afaf026a}\U\00000004.@
c:\windows\Installer\{407c2ae1-b9e3-f1ae-d184-4c81afaf026a}\U\00000008.@
c:\windows\Installer\{407c2ae1-b9e3-f1ae-d184-4c81afaf026a}\U\000000cb.@
c:\windows\Installer\{407c2ae1-b9e3-f1ae-d184-4c81afaf026a}\U\80000000.@
c:\windows\Installer\{407c2ae1-b9e3-f1ae-d184-4c81afaf026a}\U\80000032.@
c:\windows\Installer\{407c2ae1-b9e3-f1ae-d184-4c81afaf026a}\U\80000064.@
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_{79007602-0CDB-4405-9DBF-1257BB3226EE}
.
.
((((((((((((((((((((((((( Files Created from 2012-05-13 to 2012-06-13 )))))))))))))))))))))))))))))))
.
.
2012-06-13 01:10 . 2012-06-13 01:10 -------- d-----w- c:\users\UpdatusUser.Adam-PC\AppData\Local\temp
2012-06-13 01:10 . 2012-06-13 01:10 -------- d-----w- c:\users\Public\AppData\Local\temp
2012-06-13 01:10 . 2012-06-13 01:10 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-13 01:10 . 2012-06-13 01:10 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-06-13 01:10 . 2012-06-13 01:10 -------- d-----w- c:\users\Mcx1\AppData\Local\temp
2012-06-10 14:57 . 2012-06-11 05:02 -------- d-----w- c:\program files (x86)\Black_Box
2012-06-09 16:13 . 2012-06-09 16:13 388096 ----a-r- c:\users\Adam\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-06-09 16:13 . 2012-06-09 16:13 -------- d-----w- c:\program files (x86)\Trend Micro
2012-06-09 15:08 . 2012-06-09 15:08 -------- d-----w- c:\users\Adam\AppData\Roaming\SUPERAntiSpyware.com
2012-06-09 15:08 . 2012-06-09 15:08 -------- d-----w- c:\program files\SUPERAntiSpyware
2012-06-09 15:08 . 2012-06-09 15:08 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2012-06-08 17:39 . 2012-06-08 17:39 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-06-08 15:15 . 2012-06-08 15:15 -------- d-----w- c:\windows\SysWow64\drivers\AVG
2012-06-08 15:14 . 2012-06-12 21:52 -------- d-----w- c:\windows\system32\drivers\AVG
2012-06-08 15:14 . 2012-06-08 15:14 -------- d-----w- C:\$AVG
2012-06-08 15:12 . 2012-06-08 15:12 -------- d-----w- c:\program files (x86)\AVG
2012-06-08 01:54 . 2012-06-08 01:54 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%
2012-06-05 19:20 . 2012-05-08 17:02 8955792 ------w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{73D38E1E-10DE-4BCC-B14E-D96D751CA046}\mpengine.dll
2012-06-05 00:14 . 2012-06-05 00:14 -------- d-----w- c:\program files (x86)\Photo Story 3 for Windows
2012-06-03 03:24 . 2012-06-09 16:17 -------- d-----w- c:\program files (x86)\TightVNC
2012-06-03 03:23 . 2012-06-03 03:23 -------- d-----w- c:\users\Adam\AppData\Local\Downloaded Installations
2012-05-29 02:00 . 2012-05-29 02:00 -------- d-----w- c:\users\Adam\AppData\Local\Cranium
2012-05-29 01:42 . 2012-05-29 01:42 -------- d-----w- c:\program files (x86)\iPhoneBrowser
2012-05-26 11:45 . 2012-05-26 11:45 -------- d-----w- c:\users\Adam\AppData\Local\libimobiledevice
2012-05-25 23:11 . 2012-05-26 20:12 -------- d-----w- c:\program files (x86)\Paradox Interactive
2012-05-25 22:56 . 2012-05-25 22:56 -------- d-----w- c:\users\Adam\AppData\Roaming\Atari
2012-05-25 22:45 . 2012-05-25 23:33 -------- d-----w- c:\program files (x86)\Roller Coaster Tycoon 3 Platinum - CarlesNeo !
2012-05-25 18:59 . 2012-05-25 18:59 -------- d-----w- c:\program files (x86)\Microsoft Chart Controls
2012-05-25 18:59 . 2012-05-25 18:59 -------- d-----w- c:\users\Adam\AppData\Local\CrashRpt
2012-05-24 00:30 . 2012-05-24 00:30 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2012-05-21 23:30 . 2012-05-21 23:46 -------- d-----w- c:\program files (x86)\Landwirtschafts Simulator 2011
2012-05-19 19:48 . 2012-05-19 19:48 -------- d-----w- c:\users\Adam\AppData\Roaming\.minecraft_xray
2012-05-19 19:33 . 2012-05-19 19:33 -------- d-----w- c:\program files\7-Zip
2012-05-18 00:29 . 2012-05-18 00:51 -------- d-----w- C:\multiAVCHD
2012-05-15 06:21 . 2012-05-15 06:21 423744 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2012-05-14 18:58 . 2012-05-14 18:59 -------- d-----w- c:\users\Adam\AppData\Local\SniperV2
2012-05-14 18:32 . 2012-05-14 18:32 -------- d-----w- c:\program files (x86)\Rebellion
2012-05-14 03:50 . 2012-05-14 03:50 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2012-05-14 03:50 . 2012-05-14 03:50 157352 ----a-w- c:\program files (x86)\Mozilla Firefox\maintenanceservice_installer.exe
2012-05-14 03:50 . 2012-05-14 03:50 129976 ----a-w- c:\program files (x86)\Mozilla Firefox\maintenanceservice.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-26 16:49 . 2011-06-23 01:47 281032 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-05-26 16:49 . 2011-06-21 00:55 281032 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-05-26 00:42 . 2011-06-21 00:55 281032 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-05-25 18:57 . 2011-06-21 00:55 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-05-19 19:11 . 2011-12-06 20:35 839112 ----a-w- c:\windows\system32\deployJava1.dll
2012-05-15 10:48 . 2012-02-22 23:01 68928 ----a-w- c:\windows\system32\OpenCL.dll
2012-05-15 10:48 . 2012-02-22 23:01 61248 ----a-w- c:\windows\SysWow64\OpenCL.dll
2012-05-15 10:48 . 2011-08-16 01:07 1738048 ----a-w- c:\windows\system32\nvdispco64.dll
2012-05-15 10:48 . 2011-08-16 01:07 1468224 ----a-w- c:\windows\system32\nvgenco64.dll
2012-05-15 10:48 . 2011-06-18 17:38 18044224 ----a-w- c:\windows\system32\nvd3dumx.dll
2012-05-15 10:48 . 2011-06-18 17:38 15322432 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2012-05-15 10:48 . 2011-06-18 17:38 2741568 ----a-w- c:\windows\system32\nvapi64.dll
2012-05-15 09:29 . 2011-06-18 17:40 889664 ----a-w- c:\windows\system32\nvvsvc.exe
2012-05-15 09:29 . 2011-06-18 17:40 63296 ----a-w- c:\windows\system32\nvshext.dll
2012-05-15 09:29 . 2011-06-18 17:40 118080 ----a-w- c:\windows\system32\nvmctray.dll
2012-05-15 09:29 . 2011-06-18 17:40 3149632 ----a-w- c:\windows\system32\nvsvc64.dll
2012-05-15 09:28 . 2011-06-18 17:40 6151488 ----a-w- c:\windows\system32\nvcpl.dll
2012-05-06 01:29 . 2012-05-06 00:02 3658157137 ----a-w- c:\program files (x86)\VindictusSetupV152.exe
2012-05-04 21:31 . 2012-04-08 14:07 419488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-05-04 21:31 . 2011-06-17 03:43 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-04 21:31 . 2012-04-08 14:31 8744608 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-21 18:11 . 2012-04-21 18:08 21840 ----atw- c:\windows\SysWow64\SIntfNT.dll
2012-04-21 18:11 . 2012-04-21 18:08 17212 ----atw- c:\windows\SysWow64\SIntf32.dll
2012-04-21 18:11 . 2012-04-21 18:08 12067 ----atw- c:\windows\SysWow64\SIntf16.dll
2012-04-21 17:20 . 2012-04-21 17:20 94208 ----a-w- c:\windows\DIIUnin.exe
2012-04-21 17:20 . 2012-04-21 17:20 2829 ----a-w- c:\windows\DIIUnin.pif
2012-04-19 08:50 . 2012-04-19 08:50 28480 ----a-w- c:\windows\system32\drivers\avgidsha.sys
2012-04-19 00:56 . 2012-04-19 00:56 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2012-04-19 00:56 . 2012-04-19 00:56 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
2012-04-18 17:08 . 2012-02-22 23:01 1451840 ----a-w- c:\windows\system32\nvhdagenco6420103.dll
2012-04-04 22:47 . 2011-06-18 20:51 687504 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-04-04 19:56 . 2011-10-30 19:27 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-03 08:22 . 2012-05-11 20:17 4699520 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-02 13:59 . 2012-05-11 20:17 2766848 ----a-w- c:\windows\system32\win32k.sys
2012-03-30 12:45 . 2012-05-11 20:18 1423744 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-03-20 23:34 . 2012-05-11 20:18 72576 ----a-w- c:\windows\system32\drivers\partmgr.sys
2012-03-19 09:17 . 2012-03-19 09:17 383808 ----a-w- c:\windows\system32\drivers\avgtdia.sys
2006-05-03 17:06 163328 --sha-r- c:\windows\SysWOW64\flvDX.dll
2007-02-21 18:47 31232 --sha-r- c:\windows\SysWOW64\msfDX.dll
2008-03-16 20:30 216064 --sha-r- c:\windows\SysWOW64\nbDX.dll
2010-01-07 05:00 107520 --sha-r- c:\windows\SysWOW64\TAKDSDecoder.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-10_22.40.46 )))))))))))))))))))))))))))))))))))))))))
.
[snapshot omitted]
+ 2011-10-16 19:38 . 2011-10-16 19:38 100966912 c:\windows\Installer\1a9557e.msp
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-08-15 1242448]
"DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2011-03-17 842048]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
"MobileDocuments"="c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-02-29 17148552]
"Spotify Web Helper"="c:\users\Adam\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-05-03 932528]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2012-05-11 880496]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-05-21 4786048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SoundTray"="c:\program files (x86)\Analog Devices\SoundMAX\SoundTray.exe" [2008-03-26 143360]
"SoundMAXPnP"="c:\program files (x86)\Analog Devices\Core\smax4pnp.exe" [2008-03-16 1302528]
"LifeCam"="c:\program files (x86)\Microsoft LifeCam\LifeExp.exe" [2010-12-13 135536]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2011-09-05 36760]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2011-09-05 2904984]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-02-28 1987976]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888]
"AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2012-04-05 2587008]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
.
c:\users\Adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
fliptoast.lnk - c:\program files (x86)\fliptoast\fliptoast.exe [N/A]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2011-7-24 102912]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-04 257696]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-06-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-08 21:31]
.
2012-06-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-22 20:35]
.
2012-06-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-22 20:35]
.
2012-06-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-593570071-605911810-3574683811-1000Core.job
- c:\users\Adam\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-18 19:09]
.
2012-06-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-593570071-605911810-3574683811-1000UA.job
- c:\users\Adam\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-18 19:09]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-09-16 497648]
"combofix"="c:\combofix\CF5328.3XE" [2008-01-21 363008]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = %SystemRoot%\system32\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105
LSP: %SYSTEMROOT%\system32\nvLsp.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
FF - ProfilePath - c:\users\Adam\AppData\Roaming\Mozilla\Firefox\Profiles\3gp9yy3b.default\
FF - prefs.js: browser.startup.homepage -
www.google.com
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-WMPNSCFG - c:\program files (x86)\Windows Media Player\WMPNSCFG.exe
HKLM-Run-PocketCloud Location - c:\program files (x86)\Wyse\PocketCloud Windows Companion\WyseBrowser.exe
AddRemove-BattlEye for A2 - c:\program files (x86)\steam\steamapps\common\arma 2BattlEye\UnInstallBE.exe
AddRemove-BattlEye for OA - c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowheadExpansion\BattlEye\UnInstallBE.exe
AddRemove-CraftBukkit - c:\users\Adam\Desktop\Bukkit\Uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-593570071-605911810-3574683811-1000\Software\SecuROM\License information*]
"datasecu"=hex:19,80,9f,79,ee,d4,bf,9e,03,64,7a,0b,e4,9c,a9,48,33,a1,d0,61,1e,
2b,a3,48,19,a7,c1,b1,45,f4,ad,3d,35,5b,ed,33,5b,3f,b6,1e,b1,31,ac,71,a3,f1,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*]
"value"="?\06\01\14\11&2?"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\AVG\AVG2012\avgidsagent.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Completion time: 2012-06-12 21:21:58 - machine was rebooted
ComboFix-quarantined-files.txt 2012-06-13 01:21
.
Pre-Run: 417,874,452,480 bytes free
Post-Run: 418,292,916,224 bytes free
.
- - End Of File - - 7F7F38405D1F5ACBB30A9754346062E3