Here is the Combofix log. After you look at these logs, is there anything else that needs addressing?
ComboFix 14-02-16.01 - Petra's Stuff 02/16/2014 20:46:38.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1406.631 [GMT -5:00]
Running from: c:\documents and settings\Petra's Stuff\My Documents\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\DragToDiscUserNameD.txt
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Start Menu\HP Image Zone .lnk
c:\documents and settings\Petra's Stuff\WINDOWS
C:\install.exe
c:\program files\Internet Explorer\SET10.tmp
c:\program files\Internet Explorer\SET11.tmp
c:\program files\Internet Explorer\SET12.tmp
c:\program files\Internet Explorer\SET13.tmp
c:\program files\Internet Explorer\SET14.tmp
c:\program files\Internet Explorer\SET15.tmp
c:\program files\Internet Explorer\SET16.tmp
c:\program files\Internet Explorer\SET169.tmp
c:\program files\Internet Explorer\SET16A.tmp
c:\program files\Internet Explorer\SET16B.tmp
c:\program files\Internet Explorer\SET17.tmp
c:\program files\Internet Explorer\SET17C.tmp
c:\program files\Internet Explorer\SET17D.tmp
c:\program files\Internet Explorer\SET17E.tmp
c:\program files\Internet Explorer\SET18.tmp
c:\program files\Internet Explorer\SET19.tmp
c:\program files\Internet Explorer\SET1A.tmp
c:\program files\Internet Explorer\SET1B.tmp
c:\program files\Internet Explorer\SET1C.tmp
c:\program files\Internet Explorer\SET1D.tmp
c:\program files\Internet Explorer\SET1E.tmp
c:\program files\Internet Explorer\SET1F.tmp
c:\program files\Internet Explorer\SET2.tmp
c:\program files\Internet Explorer\SET20.tmp
c:\program files\Internet Explorer\SET21.tmp
c:\program files\Internet Explorer\SET22.tmp
c:\program files\Internet Explorer\SET23.tmp
c:\program files\Internet Explorer\SET24.tmp
c:\program files\Internet Explorer\SET25.tmp
c:\program files\Internet Explorer\SET254.tmp
c:\program files\Internet Explorer\SET255.tmp
c:\program files\Internet Explorer\SET256.tmp
c:\program files\Internet Explorer\SET26.tmp
c:\program files\Internet Explorer\SET27.tmp
c:\program files\Internet Explorer\SET277.tmp
c:\program files\Internet Explorer\SET278.tmp
c:\program files\Internet Explorer\SET279.tmp
c:\program files\Internet Explorer\SET28.tmp
c:\program files\Internet Explorer\SET29.tmp
c:\program files\Internet Explorer\SET2A.tmp
c:\program files\Internet Explorer\SET2B.tmp
c:\program files\Internet Explorer\SET2B8.tmp
c:\program files\Internet Explorer\SET2B9.tmp
c:\program files\Internet Explorer\SET2BA.tmp
c:\program files\Internet Explorer\SET2C.tmp
c:\program files\Internet Explorer\SET2C0.tmp
c:\program files\Internet Explorer\SET2C1.tmp
c:\program files\Internet Explorer\SET2C2.tmp
c:\program files\Internet Explorer\SET2D.tmp
c:\program files\Internet Explorer\SET2E.tmp
c:\program files\Internet Explorer\SET2F.tmp
c:\program files\Internet Explorer\SET3.tmp
c:\program files\Internet Explorer\SET30.tmp
c:\program files\Internet Explorer\SET31.tmp
c:\program files\Internet Explorer\SET317.tmp
c:\program files\Internet Explorer\SET318.tmp
c:\program files\Internet Explorer\SET319.tmp
c:\program files\Internet Explorer\SET32.tmp
c:\program files\Internet Explorer\SET33.tmp
c:\program files\Internet Explorer\SET34.tmp
c:\program files\Internet Explorer\SET344.tmp
c:\program files\Internet Explorer\SET345.tmp
c:\program files\Internet Explorer\SET346.tmp
c:\program files\Internet Explorer\SET35.tmp
c:\program files\Internet Explorer\SET36.tmp
c:\program files\Internet Explorer\SET37.tmp
c:\program files\Internet Explorer\SET38.tmp
c:\program files\Internet Explorer\SET39.tmp
c:\program files\Internet Explorer\SET3A.tmp
c:\program files\Internet Explorer\SET3B.tmp
c:\program files\Internet Explorer\SET3C.tmp
c:\program files\Internet Explorer\SET3CF.tmp
c:\program files\Internet Explorer\SET3D.tmp
c:\program files\Internet Explorer\SET3D0.tmp
c:\program files\Internet Explorer\SET3D1.tmp
c:\program files\Internet Explorer\SET3E.tmp
c:\program files\Internet Explorer\SET3F.tmp
c:\program files\Internet Explorer\SET3FA.tmp
c:\program files\Internet Explorer\SET3FB.tmp
c:\program files\Internet Explorer\SET3FC.tmp
c:\program files\Internet Explorer\SET4.tmp
c:\program files\Internet Explorer\SET40.tmp
c:\program files\Internet Explorer\SET41.tmp
c:\program files\Internet Explorer\SET42.tmp
c:\program files\Internet Explorer\SET42E.tmp
c:\program files\Internet Explorer\SET42F.tmp
c:\program files\Internet Explorer\SET43.tmp
c:\program files\Internet Explorer\SET430.tmp
c:\program files\Internet Explorer\SET44.tmp
c:\program files\Internet Explorer\SET45.tmp
c:\program files\Internet Explorer\SET46.tmp
c:\program files\Internet Explorer\SET48D.tmp
c:\program files\Internet Explorer\SET48E.tmp
c:\program files\Internet Explorer\SET48F.tmp
c:\program files\Internet Explorer\SET4A.tmp
c:\program files\Internet Explorer\SET4B.tmp
c:\program files\Internet Explorer\SET4C.tmp
c:\program files\Internet Explorer\SET4EC.tmp
c:\program files\Internet Explorer\SET4ED.tmp
c:\program files\Internet Explorer\SET4EE.tmp
c:\program files\Internet Explorer\SET5.tmp
c:\program files\Internet Explorer\SET53.tmp
c:\program files\Internet Explorer\SET54.tmp
c:\program files\Internet Explorer\SET54B.tmp
c:\program files\Internet Explorer\SET54C.tmp
c:\program files\Internet Explorer\SET54D.tmp
c:\program files\Internet Explorer\SET55.tmp
c:\program files\Internet Explorer\SET576.tmp
c:\program files\Internet Explorer\SET577.tmp
c:\program files\Internet Explorer\SET578.tmp
c:\program files\Internet Explorer\SET5AB.tmp
c:\program files\Internet Explorer\SET5AC.tmp
c:\program files\Internet Explorer\SET5AD.tmp
c:\program files\Internet Explorer\SET5D8.tmp
c:\program files\Internet Explorer\SET5D9.tmp
c:\program files\Internet Explorer\SET5DA.tmp
c:\program files\Internet Explorer\SET6.tmp
c:\program files\Internet Explorer\SET60A.tmp
c:\program files\Internet Explorer\SET60B.tmp
c:\program files\Internet Explorer\SET60C.tmp
c:\program files\Internet Explorer\SET63.tmp
c:\program files\Internet Explorer\SET64.tmp
c:\program files\Internet Explorer\SET65.tmp
c:\program files\Internet Explorer\SET6D0.tmp
c:\program files\Internet Explorer\SET6D1.tmp
c:\program files\Internet Explorer\SET6D2.tmp
c:\program files\Internet Explorer\SET7.tmp
c:\program files\Internet Explorer\SET8.tmp
c:\program files\Internet Explorer\SET9.tmp
c:\program files\Internet Explorer\SETA.tmp
c:\program files\Internet Explorer\SETB.tmp
c:\program files\Internet Explorer\SETC.tmp
c:\program files\Internet Explorer\SETC0.tmp
c:\program files\Internet Explorer\SETC1.tmp
c:\program files\Internet Explorer\SETC2.tmp
c:\program files\Internet Explorer\SETD.tmp
c:\program files\Internet Explorer\SETE.tmp
c:\program files\Internet Explorer\SETF.tmp
c:\windows\explorer(2).exe
c:\windows\system32\SET10.tmp
c:\windows\system32\SET100.tmp
c:\windows\system32\SET101.tmp
c:\windows\system32\SET102.tmp
c:\windows\system32\SET103.tmp
c:\windows\system32\SET104.tmp
c:\windows\system32\SET105.tmp
c:\windows\system32\SET106.tmp
c:\windows\system32\SET107.tmp
c:\windows\system32\SET108.tmp
c:\windows\system32\SET109.tmp
c:\windows\system32\SET10A.tmp
c:\windows\system32\SET10B.tmp
c:\windows\system32\SET10C.tmp
c:\windows\system32\SET10D.tmp
c:\windows\system32\SET10E.tmp
c:\windows\system32\SET10F.tmp
c:\windows\system32\SET11.tmp
c:\windows\system32\SET110.tmp
c:\windows\system32\SET111.tmp
c:\windows\system32\SET112.tmp
c:\windows\system32\SET113.tmp
c:\windows\system32\SET114.tmp
c:\windows\system32\SET115.tmp
c:\windows\system32\SET116.tmp
c:\windows\system32\SET117.tmp
c:\windows\system32\SET118.tmp
c:\windows\system32\SET119.tmp
c:\windows\system32\SET11A.tmp
c:\windows\system32\SET11B.tmp
c:\windows\system32\SET11C.tmp
c:\windows\system32\SET11D.tmp
c:\windows\system32\SET11E.tmp
c:\windows\system32\SET11F.tmp
c:\windows\system32\SET12.tmp
c:\windows\system32\SET120.tmp
c:\windows\system32\SET121.tmp
c:\windows\system32\SET122.tmp
c:\windows\system32\SET123.tmp
c:\windows\system32\SET124.tmp
c:\windows\system32\SET125.tmp
c:\windows\system32\SET126.tmp
c:\windows\system32\SET127.tmp
c:\windows\system32\SET128.tmp
c:\windows\system32\SET12A.tmp
c:\windows\system32\SET12B.tmp
c:\windows\system32\SET12C.tmp
c:\windows\system32\SET12D.tmp
c:\windows\system32\SET12E.tmp
c:\windows\system32\SET12F.tmp
c:\windows\system32\SET13.tmp
c:\windows\system32\SET130.tmp
c:\windows\system32\SET131.tmp
c:\windows\system32\SET132.tmp
c:\windows\system32\SET133.tmp
c:\windows\system32\SET134.tmp
c:\windows\system32\SET135.tmp
c:\windows\system32\SET136.tmp
c:\windows\system32\SET137.tmp
c:\windows\system32\SET138.tmp
c:\windows\system32\SET139.tmp
c:\windows\system32\SET13A.tmp
c:\windows\system32\SET13B.tmp
c:\windows\system32\SET13C.tmp
c:\windows\system32\SET13D.tmp
c:\windows\system32\SET13E.tmp
c:\windows\system32\SET13F.tmp
c:\windows\system32\SET14.tmp
c:\windows\system32\SET140.tmp
c:\windows\system32\SET141.tmp
c:\windows\system32\SET142.tmp
c:\windows\system32\SET143.tmp
c:\windows\system32\SET144.tmp
c:\windows\system32\SET145.tmp
c:\windows\system32\SET146.tmp
c:\windows\system32\SET147.tmp
c:\windows\system32\SET148.tmp
c:\windows\system32\SET149.tmp
c:\windows\system32\SET14A.tmp
c:\windows\system32\SET14B.tmp
c:\windows\system32\SET14C.tmp
c:\windows\system32\SET14D.tmp
c:\windows\system32\SET14E.tmp
c:\windows\system32\SET14F.tmp
c:\windows\system32\SET15.tmp
c:\windows\system32\SET150.tmp
c:\windows\system32\SET151.tmp
c:\windows\system32\SET152.tmp
c:\windows\system32\SET153.tmp
c:\windows\system32\SET154.tmp
c:\windows\system32\SET155.tmp
c:\windows\system32\SET157.tmp
c:\windows\system32\SET158.tmp
c:\windows\system32\SET159.tmp
c:\windows\system32\SET15A.tmp
c:\windows\system32\SET15B.tmp
c:\windows\system32\SET15C.tmp
c:\windows\system32\SET15D.tmp
c:\windows\system32\SET15E.tmp
c:\windows\system32\SET15F.tmp
c:\windows\system32\SET16.tmp
c:\windows\system32\SET160.tmp
c:\windows\system32\SET161.tmp
c:\windows\system32\SET162.tmp
c:\windows\system32\SET163.tmp
c:\windows\system32\SET164.tmp
c:\windows\system32\SET165.tmp
c:\windows\system32\SET166.tmp
c:\windows\system32\SET167.tmp
c:\windows\system32\SET168.tmp
c:\windows\system32\SET169.tmp
c:\windows\system32\SET16A.tmp
c:\windows\system32\SET16B.tmp
c:\windows\system32\SET16C.tmp
c:\windows\system32\SET16D.tmp
c:\windows\system32\SET16E.tmp
c:\windows\system32\SET16F.tmp
c:\windows\system32\SET17.tmp
c:\windows\system32\SET170.tmp
c:\windows\system32\SET171.tmp
c:\windows\system32\SET172.tmp
c:\windows\system32\SET173.tmp
c:\windows\system32\SET174.tmp
c:\windows\system32\SET175.tmp
c:\windows\system32\SET176.tmp
c:\windows\system32\SET177.tmp
c:\windows\system32\SET178.tmp
c:\windows\system32\SET179.tmp
c:\windows\system32\SET17A.tmp
c:\windows\system32\SET17B.tmp
c:\windows\system32\SET17C.tmp
c:\windows\system32\SET17D.tmp
c:\windows\system32\SET17E.tmp
c:\windows\system32\SET17F.tmp
c:\windows\system32\SET18.tmp
c:\windows\system32\SET180.tmp
c:\windows\system32\SET182.tmp
c:\windows\system32\SET183.tmp
c:\windows\system32\SET184.tmp
c:\windows\system32\SET185.tmp
c:\windows\system32\SET186.tmp
c:\windows\system32\SET187.tmp
c:\windows\system32\SET188.tmp
c:\windows\system32\SET189.tmp
c:\windows\system32\SET18A.tmp
c:\windows\system32\SET18B.tmp
c:\windows\system32\SET18C.tmp
c:\windows\system32\SET18D.tmp
c:\windows\system32\SET18E.tmp
c:\windows\system32\SET18F.tmp
c:\windows\system32\SET19.tmp
c:\windows\system32\SET190.tmp
c:\windows\system32\SET191.tmp
c:\windows\system32\SET192.tmp
c:\windows\system32\SET193.tmp
c:\windows\system32\SET194.tmp
c:\windows\system32\SET195.tmp
c:\windows\system32\SET196.tmp
c:\windows\system32\SET197.tmp
c:\windows\system32\SET198.tmp
c:\windows\system32\SET199.tmp
c:\windows\system32\SET19A.tmp
c:\windows\system32\SET19B.tmp
c:\windows\system32\SET19C.tmp
c:\windows\system32\SET19D.tmp
c:\windows\system32\SET19E.tmp
c:\windows\system32\SET19F.tmp
c:\windows\system32\SET1A0.tmp
c:\windows\system32\SET1A1.tmp
c:\windows\system32\SET1A2.tmp
c:\windows\system32\SET1A3.tmp
c:\windows\system32\SET1A4.tmp
c:\windows\system32\SET1A5.tmp
c:\windows\system32\SET1A6.tmp
c:\windows\system32\SET1A7.tmp
c:\windows\system32\SET1A8.tmp
c:\windows\system32\SET1A9.tmp
c:\windows\system32\SET1AA.tmp
c:\windows\system32\SET1AB.tmp
c:\windows\system32\SET1AC.tmp
c:\windows\system32\SET1AD.tmp
c:\windows\system32\SET1AE.tmp
c:\windows\system32\SET1B.tmp
c:\windows\system32\SET1B0.tmp
c:\windows\system32\SET1B1.tmp
c:\windows\system32\SET1B2.tmp
c:\windows\system32\SET1B3.tmp
c:\windows\system32\SET1B4.tmp
c:\windows\system32\SET1B5.tmp
c:\windows\system32\SET1B6.tmp
c:\windows\system32\SET1B7.tmp
c:\windows\system32\SET1B8.tmp
c:\windows\system32\SET1B9.tmp
c:\windows\system32\SET1BA.tmp
c:\windows\system32\SET1BB.tmp
c:\windows\system32\SET1BC.tmp
c:\windows\system32\SET1BD.tmp
c:\windows\system32\SET1BE.tmp
c:\windows\system32\SET1BF.tmp
c:\windows\system32\SET1C.tmp
c:\windows\system32\SET1C0.tmp
c:\windows\system32\SET1C1.tmp
c:\windows\system32\SET1C2.tmp
c:\windows\system32\SET1C3.tmp
c:\windows\system32\SET1C4.tmp
c:\windows\system32\SET1C5.tmp
c:\windows\system32\SET1C6.tmp
c:\windows\system32\SET1C7.tmp
c:\windows\system32\SET1C8.tmp
c:\windows\system32\SET1C9.tmp
c:\windows\system32\SET1CA.tmp
c:\windows\system32\SET1CB.tmp
c:\windows\system32\SET1CC.tmp
c:\windows\system32\SET1CD.tmp
c:\windows\system32\SET1CE.tmp
c:\windows\system32\SET1CF.tmp
c:\windows\system32\SET1D.tmp
c:\windows\system32\SET1D0.tmp
c:\windows\system32\SET1D1.tmp
c:\windows\system32\SET1D2.tmp
c:\windows\system32\SET1D3.tmp
c:\windows\system32\SET1D4.tmp
c:\windows\system32\SET1D5.tmp
c:\windows\system32\SET1D6.tmp
c:\windows\system32\SET1D7.tmp
c:\windows\system32\SET1D8.tmp
c:\windows\system32\SET1D9.tmp
c:\windows\system32\SET1DA.tmp
c:\windows\system32\SET1DB.tmp
c:\windows\system32\SET1DC.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_MYWEBSEARCHSERVICE
.
.
((((((((((((((((((((((((( Files Created from 2014-01-17 to 2014-02-17 )))))))))))))))))))))))))))))))
.
.
2014-02-16 15:40 . 2014-02-16 15:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2014-02-16 15:40 . 2013-04-04 19:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-02-16 15:05 . 2014-02-16 15:05 -------- d-----w- c:\windows\ERUNT
2014-02-16 14:53 . 2014-02-16 14:57 -------- d-----w- C:\AdwCleaner
2014-02-15 02:13 . 2013-09-20 14:49 18968 ----a-w- c:\windows\system32\sdnclean.exe
2014-02-15 02:13 . 2014-02-15 03:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2014-02-15 02:13 . 2014-02-15 02:15 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2014-02-14 23:25 . 2014-02-14 23:25 -------- d-----w- c:\program files\Trend Micro
2014-02-14 11:02 . 2014-02-14 11:02 -------- d-----w- c:\program files\Mozilla Maintenance Service
2014-02-14 00:23 . 2014-02-14 11:02 -------- d-----w- c:\program files\Common Files\Java
2014-02-14 00:22 . 2014-02-14 00:22 145408 ----a-w- c:\windows\system32\javacpl.cpl
2014-02-14 00:22 . 2014-02-14 00:22 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2014-02-12 01:09 . 2014-02-12 01:09 -------- d-----w- c:\documents and settings\Petra's Stuff\Application Data\AVAST Software
2014-02-12 01:08 . 2014-02-12 01:08 57672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2014-02-12 01:08 . 2014-02-12 01:08 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-02-12 01:08 . 2014-02-12 01:08 180248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-02-12 01:08 . 2014-02-12 01:08 67824 ----a-w- c:\windows\system32\drivers\aswmonflt.sys
2014-02-12 01:08 . 2014-02-12 01:08 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-02-12 01:08 . 2014-02-12 01:08 410784 ----a-w- c:\windows\system32\drivers\aswSP.sys
2014-02-12 01:08 . 2014-02-12 01:08 54832 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2014-02-12 01:08 . 2014-02-12 01:08 270240 ----a-w- c:\windows\system32\aswBoot.exe
2014-02-12 01:08 . 2014-02-12 01:08 43152 ----a-w- c:\windows\avastSS.scr
2014-02-12 01:07 . 2014-02-12 01:07 -------- d-----w- c:\program files\AVAST Software
2014-02-12 01:06 . 2014-02-12 01:06 -------- d-----w- c:\documents and settings\All Users\Application Data\AVAST Software
2014-02-11 01:24 . 2014-02-11 01:24 -------- d-----w- c:\documents and settings\Petra's Stuff\Application Data\ElevatedDiagnostics
2014-02-08 12:43 . 2014-02-15 00:31 -------- d-----w- c:\program files\CCleaner
2014-02-08 02:21 . 2014-02-13 23:31 -------- d-----w- C:\BOOT
2014-02-08 02:21 . 2014-02-08 02:21 -------- d-----w- C:\My Backups
2014-02-08 02:21 . 2013-09-04 16:22 185800 ----a-w- c:\windows\system32\drivers\EuFdDisk.sys
2014-02-08 02:21 . 2013-09-04 16:22 14920 ----a-w- c:\windows\system32\drivers\eudskacs.sys
2014-02-08 02:21 . 2013-09-04 16:22 52040 ----a-w- c:\windows\system32\drivers\eubakup.sys
2014-02-08 02:21 . 2013-09-04 16:22 40776 ----a-w- c:\windows\system32\drivers\EUBKMON.sys
2014-02-08 02:14 . 2014-02-14 11:02 -------- d-----w- c:\program files\******
2014-02-08 01:25 . 2013-09-30 21:26 2881848 ----a-w- c:\windows\system32\pwNative.exe
2014-02-08 01:25 . 2013-09-30 21:26 15688 ------w- c:\windows\system32\pwdrvio.sys
2014-02-08 01:25 . 2013-09-30 21:26 10320 ------w- c:\windows\system32\pwdspio.sys
2014-02-07 23:52 . 2014-02-07 23:52 -------- d-----w- c:\program files\VS Revo Group
2014-02-07 23:19 . 2014-02-12 01:18 -------- d-----w- c:\program files\Belarc
2014-02-02 13:34 . 2014-02-02 13:34 -------- d-----w- c:\program files\iPod
2014-02-02 13:34 . 2014-02-02 13:35 -------- d-----w- c:\documents and settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-02-08 10:47 . 2012-04-19 18:47 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-02-08 10:47 . 2011-05-25 19:49 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-12-05 11:26 . 2004-08-10 18:51 1172992 ----a-w- c:\windows\system32\msxml3.dll
2013-11-27 20:21 . 2004-08-10 18:51 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2012-10-13 18:03 . 2012-10-13 18:03 4096000 -c--a-w- c:\program files\GUT6D.tmp
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-02-12 01:08 259464 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-04-05 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2014-01-20 43848]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2013-05-01 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2014-01-20 152392]
"SigmatelSysTrayApp"="stsystra.exe" [2006-09-22 282624]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-02-12 3767096]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"SDTray"="c:\program files\Spybot - Search & Destroy 2\SDTray.exe" [2013-12-19 5580752]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe /startup [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
backup=c:\windows\pss\McAfee Security Scan Plus.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
backup=c:\windows\pss\Service Manager.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EarthLink Installer]
/C [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 05:04 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2014-01-20 18:16 43848 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
2010-10-28 00:17 207424 ----a-w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
2006-05-10 17:12 90112 ----a-w- c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
2006-11-02 00:48 1392640 ----a-w- c:\windows\system32\WLTRAY.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]
2007-02-06 17:20 478800 ----a-w- c:\program files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPMonitor]
2009-04-20 15:10 84464 ----a-w- c:\program files\Roxio Creator 2009\5.0\CPMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
2006-08-23 22:14 1032192 ----a-w- c:\program files\Dell\QuickSet\quickset.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2006-08-29 03:57 395776 ----a-w- c:\program files\Dell Support\DSAgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2005-12-10 02:29 49152 -c----w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GarminExpressTrayApp]
2013-03-27 20:18 1098072 ----a-w- c:\program files\Garmin\Express Tray\ExpressTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 21:24 54840 -c--a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
2008-10-24 13:14 206112 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2008-10-24 13:14 206112 ----a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2008-10-24 13:14 79136 -c--a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2014-01-20 21:32 152392 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
2004-10-08 16:52 221184 ----a-w- c:\windows\system32\LVCOMSX.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2013-05-01 07:59 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2006-09-22 17:06 282624 ----a-w- c:\windows\stsystra.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2013-07-02 14:16 254336 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2012-04-05 00:33 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2006-09-22 17:47 761947 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"YahooAUService"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"wltrysvc"=2 (0x2)
"wlidsvc"=2 (0x2)
"SQLAgent$MICROSOFTSMLBIZ"=3 (0x3)
"RoxWatch11"=2 (0x2)
"RoxMediaDB11"=3 (0x3)
"RoxLiveShare11"=2 (0x2)
"Roxio Upnp Server 11"=2 (0x2)
"Roxio UPnP Renderer 11"=3 (0x3)
"ProtexisLicensing"=2 (0x2)
"Pml Driver HPZ12"=2 (0x2)
"ose"=3 (0x3)
"OneTouch 4.0 Monitor"=2 (0x2)
"odserv"=3 (0x3)
"NgVpnMgr"=2 (0x2)
"MSSQLServerADHelper"=3 (0x3)
"MSSQL$MICROSOFTSMLBIZ"=2 (0x2)
"mfevtp"=2 (0x2)
"mfefire"=2 (0x2)
"MDM"=2 (0x2)
"McShield"=2 (0x2)
"McProxy"=2 (0x2)
"McODS"=3 (0x3)
"McNASvc"=2 (0x2)
"McNaiAnn"=2 (0x2)
"mcmscsvc"=2 (0x2)
"McMPFSvc"=2 (0x2)
"McComponentHostService"=3 (0x3)
"McAfee SiteAdvisor Service"=2 (0x2)
"LiveUpdate"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"iPod Service"=3 (0x3)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"hnmsvc"=2 (0x2)
"gusvc"=3 (0x3)
"gupdatem"=3 (0x3)
"gupdate"=2 (0x2)
"Garmin Core Update Service"=2 (0x2)
"GamesAppService"=3 (0x3)
"fsssvc"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Automatic LiveUpdate Scheduler"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"AOL ACS"=2 (0x2)
"AdobeFlashPlayerUpdateSvc"=2 (0x2)
"ACDaemon"=2 (0x2)
"!SASCORE"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDTray.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDFSSvc.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdate.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdSvc.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
"5985:TCP"= 5985:TCP:Windows Remote Management
.
R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [2/11/2014 8:08 PM 49944]
R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [2/11/2014 8:08 PM 180248]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2/11/2014 8:08 PM 775952]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2/11/2014 8:08 PM 410784]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswmonflt.sys [2/11/2014 8:08 PM 67824]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2/16/2014 10:40 AM 418376]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2/14/2014 9:13 PM 2729432]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2/16/2014 10:40 AM 22856]
R3 NgVpn;Aventail VPN Adapter;c:\windows\system32\drivers\ngvpn.sys [2/2/2010 6:38 AM 79944]
R3 whmice2k;Advanced Wheel Mouse Upper Filter Driver;c:\windows\system32\drivers\whmice2k.sys [4/25/2004 7:38 PM 6885]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2/16/2014 10:40 AM 701512]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [2/14/2014 9:13 PM 3666392]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2/14/2014 9:13 PM 171928]
S3 NgFilter;Aventail VPN Filter;c:\windows\system32\drivers\ngfilter.sys [2/2/2010 6:39 AM 22600]
S3 NgLog;Aventail VPN Logging;c:\windows\system32\drivers\nglog.sys [2/2/2010 6:38 AM 27208]
S3 NgWfp;Aventail VPN Callout;c:\windows\system32\drivers\ngwfp.sys [2/2/2010 6:39 AM 25160]
S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2/7/2014 8:25 PM 15688]
S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2/7/2014 8:25 PM 10320]
S3 whfltr2k;WheelMouse USB Lower Filter Driver;c:\windows\system32\drivers\whfltr2k.sys [1/25/2007 10:45 AM 6784]
S4 GamesAppService;GamesAppService;c:\program files\WildTangent Games\App\GamesAppService.exe [10/12/2010 12:59 PM 206072]
S4 Garmin Core Update Service;Garmin Core Update Service;c:\program files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [3/27/2013 3:17 PM 185688]
S4 NgVpnMgr;Aventail VPN Client;c:\windows\system32\ngvpnmgr.exe [2/2/2010 6:39 AM 240816]
S4 Roxio UPnP Renderer 11;Roxio UPnP Renderer 11;c:\program files\Roxio Creator 2009\Digital Home 11\RoxioUPnPRenderer11.exe [8/13/2008 11:25 PM 313840]
S4 Roxio Upnp Server 11;Roxio Upnp Server 11;c:\program files\Roxio Creator 2009\Digital Home 11\RoxioUpnpService11.exe [8/13/2008 11:25 PM 367088]
S4 RoxLiveShare11;LiveShare P2P Server 11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxLiveShare11.exe [8/13/2008 11:24 PM 309744]
S4 RoxMediaDB11;RoxMediaDB11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxMediaDB11.exe [3/3/2009 9:58 PM 1122304]
S4 RoxWatch11;Roxio Hard Drive Watcher 11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatch11.exe [8/13/2008 11:24 PM 170480]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MBAMPROTECTOR
*NewlyCreated* - MBAMSCHEDULER
*NewlyCreated* - MBAMSERVICE
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-02-07 23:17 1211720 ----a-w- c:\program files\Google\Chrome\Application\32.0.1700.107\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-02-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-19 10:47]
.
2014-02-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2014-02-17 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2014-02-12 01:08]
.
2014-02-17 c:\windows\Tasks\Check for updates (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDUpdate.exe [2014-02-15 19:37]
.
2014-02-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cda93c1e5284ce.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-04-05 00:32]
.
2014-02-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-04-05 00:32]
.
2014-02-15 c:\windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDImmunize.exe [2014-02-15 19:33]
.
2014-02-15 c:\windows\Tasks\Scan the system (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDScan.exe [2014-02-15 19:34]
.
2014-02-17 c:\windows\Tasks\WebReg Deskjet 5900 series.job
- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2005-05-12 21:45]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultUrl = hxxp://www.google.com
uStart Page =
www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <-loopback>
TCP: DhcpNameServer = 75.76.84.102 75.76.84.103
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/4.0.4.0/GarminAxControl_32.CAB
DPF: {575AC44B-C254-48B4-8102-20F29D72A60E} - hxxp://dashboard.smshealthconx.net/dsh/02020300/html/SMSDSHSETFOREGROUND.CAB
DPF: {5B727CF6-427F-4F23-8CC1-A8A4E80D97D1} - hxxp://10.189.19.10/hrs/download/Setup.cab
DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} - hxxp://games.bellsouth.net/Gh/Tumblebugs/axhost.cab
DPF: {D7967FA2-F1F9-420D-A49E-9249309056A2} - hxxp://10.189.19.10/hrs/download/Setup.cab
DPF: {FD0ECA0C-6403-48CB-91C0-6C73EF7771AA} - hxxp://dashboard.smshealthconx.net/dsh/02020300/html/SMSDSHDOWNLOAD.CAB
FF - ProfilePath - c:\documents and settings\Petra's Stuff\Application Data\Mozilla\Firefox\Profiles\ecjwbyf1.default\
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Notify-SDWinLogon - SDWinLogon.dll
MSConfigStartUp-DriverCure - c:\program files\ParetoLogic\DriverCure\DriverCure.exe
MSConfigStartUp-mcui_exe - c:\program files\McAfee.com\Agent\mcagent.exe
MSConfigStartUp-RoxWatchTray - c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
MSConfigStartUp-SUPERAntiSpyware - c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
MSConfigStartUp-Yahoo! Pager - c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
AddRemove-Eyewitness World Atlas DVD - c:\windows\UNINST.EXE -rDK Multimedia\Eyewitness World Atlas DVD\1.0.0.0
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2014-02-16 21:04
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_44_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_44_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(876)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
.
- - - - - - - > 'explorer.exe'(3644)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\program files\ArcSoft\Scrapbook Suite\PhotoImpression 5\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\windows\system32\wscntfy.exe
c:\program files\Windows Desktop Search\WindowsSearch.exe
c:\windows\system32\SearchIndexer.exe
.
**************************************************************************
.
Completion time: 2014-02-16 21:11:32 - machine was rebooted
ComboFix-quarantined-files.txt 2014-02-17 02:11
.
Pre-Run: 201,479,999,488 bytes free
Post-Run: 201,362,382,848 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Home" /fastdetect
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - C1792A3E86EDFAAED676F789F255AD85
5CB90281D1A59B251F6603134774EEC3