Combofix log
ComboFix 13-01-03.02 - arthur1934 01/03/2013 16:34:08.1.4 - x64
Running from: c:\users\arthur1934\Downloads\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\AddLyrics\AdDLyrics.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_DefaultTabSearch
.
.
((((((((((((((((((((((((( Files Created from 2012-12-03 to 2013-01-03 )))))))))))))))))))))))))))))))
.
.
2013-01-03 08:44 . 2013-01-03 08:44 -------- d-----w- c:\users\Kboe\AppData\Local\temp
2013-01-03 08:44 . 2013-01-03 08:44 -------- d-----w- c:\users\Joshua\AppData\Local\temp
2013-01-03 08:44 . 2013-01-03 08:44 -------- d-----w- c:\users\Gwendu\AppData\Local\temp
2013-01-03 08:44 . 2013-01-03 08:44 -------- d-----w- c:\users\Guest\AppData\Local\temp
2013-01-03 08:44 . 2013-01-03 08:44 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-01-03 07:52 . 2012-11-19 01:01 9125352 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8438F54C-0DF8-4FE3-A23E-F0A105A527CE}\mpengine.dll
2013-01-01 16:36 . 2013-01-01 16:39 -------- d-----w- c:\users\arthur1934\AppData\Local\Windows Live
2013-01-01 16:35 . 2013-01-03 07:41 -------- d-----w- c:\users\arthur1934\Tracing
2013-01-01 11:35 . 2013-01-01 11:35 388096 ----a-r- c:\users\arthur1934\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-01-01 11:35 . 2013-01-01 11:35 -------- d-----w- c:\program files (x86)\Trend Micro
2013-01-01 11:32 . 2013-01-01 11:32 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-01-01 11:32 . 2012-12-14 08:49 24176 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-01-01 00:58 . 2012-11-19 01:01 9125352 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-12-31 10:24 . 2012-12-31 10:24 -------- d-----w- c:\program files (x86)\Applian Technologies
2012-12-30 03:40 . 2012-12-30 03:40 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-12-30 03:40 . 2012-12-30 03:40 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-12-30 03:40 . 2012-12-30 03:40 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-12-30 03:40 . 2012-12-30 03:40 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-12-30 03:40 . 2012-12-30 03:40 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-12-30 03:40 . 2012-12-30 03:40 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-12-30 03:40 . 2012-12-30 03:40 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-12-30 03:40 . 2012-12-30 03:40 -------- d-----w- c:\program files (x86)\QuickTime
2012-12-29 21:30 . 2012-12-29 21:30 -------- d-----w- c:\users\arthur1934\AppData\Local\RezzieSoft
2012-12-29 15:53 . 2012-12-29 15:53 -------- d-----w- c:\programdata\BrowserProtect
2012-12-29 15:52 . 2012-12-29 15:52 -------- d-----w- c:\users\arthur1934\AppData\Roaming\BabSolution
2012-12-29 15:52 . 2012-12-29 15:52 -------- d-----w- c:\program files (x86)\BabylonToolbar
2012-12-29 15:47 . 2012-12-29 15:48 -------- d-----w- c:\users\arthur1934\AppData\Local\Smartbar
2012-12-29 15:47 . 2012-12-29 15:47 -------- d-----w- c:\users\Joshua\AppData\Local\RezzieSoft
2012-12-29 15:47 . 2013-01-03 08:42 -------- d-----w- c:\program files (x86)\AddLyrics
2012-12-29 15:47 . 2012-12-29 15:47 -------- d-----w- c:\program files (x86)\Text Twist
2012-12-28 16:50 . 2012-12-28 16:50 -------- d-----w- c:\users\arthur1934\AppData\Local\Halfbrick
2012-12-28 16:49 . 2012-12-28 16:49 -------- d-----w- c:\users\arthur1934\AppData\Local\Intel
2012-12-28 16:47 . 2012-12-28 16:47 -------- d-----w- c:\program files (x86)\Halfbrick Studios
2012-12-28 16:34 . 2012-12-28 16:34 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR
2012-12-28 01:05 . 2012-12-28 01:05 -------- d-----w- c:\users\arthur1934\AppData\Local\Macroplant_LLC
2012-12-27 14:18 . 2012-12-31 16:07 -------- d-----w- c:\users\arthur1934\AppData\Roaming\redsn0w
2012-12-27 13:58 . 2012-12-27 13:58 -------- d-----w- c:\users\Joshua\AppData\Local\Macroplant_LLC
2012-12-27 13:56 . 2012-04-09 16:27 190480 ----a-w- c:\windows\system32\CbFsMntNtf3.dll
2012-12-27 13:56 . 2012-04-09 16:27 223760 ----a-w- c:\windows\SysWow64\CbFsNetRdr3.dll
2012-12-27 13:56 . 2012-04-09 16:27 158224 ----a-w- c:\windows\SysWow64\CbFsMntNtf3.dll
2012-12-27 13:56 . 2012-04-09 16:27 141328 ----a-w- c:\windows\system32\CbFsNetRdr3.dll
2012-12-27 13:55 . 2012-04-09 16:27 352144 ----a-w- c:\windows\system32\drivers\cbfs3.sys
2012-12-27 13:55 . 2012-12-29 22:22 -------- d-----w- c:\program files (x86)\iExplorer
2012-12-27 13:50 . 2012-12-27 13:50 -------- d-----w- c:\users\arthur1934\AppData\Local\Programs
2012-12-25 20:47 . 2012-12-25 20:47 -------- d-----w- c:\users\Joshua\AppData\Local\Windows Live
2012-12-25 01:42 . 2012-12-25 01:42 -------- d-----w- c:\users\Joshua\AppData\Local\Macromedia
2012-12-24 23:19 . 2012-12-16 17:11 46080 ----a-w- c:\windows\system32\atmlib.dll
2012-12-24 23:19 . 2012-12-16 14:13 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2012-12-24 23:19 . 2012-12-16 14:45 367616 ----a-w- c:\windows\system32\atmfd.dll
2012-12-24 23:19 . 2012-12-16 14:13 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2012-12-23 09:27 . 2012-12-29 17:29 -------- d-----w- c:\users\Joshua\AppData\Roaming\redsn0w
2012-12-22 09:07 . 2012-12-22 09:07 -------- d-----w- c:\program files\iPod
2012-12-22 09:07 . 2012-12-22 09:08 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-12-22 09:07 . 2012-12-22 09:08 -------- d-----w- c:\program files\iTunes
2012-12-22 09:07 . 2012-12-22 09:08 -------- d-----w- c:\program files (x86)\iTunes
2012-12-22 02:09 . 2012-12-22 02:09 -------- d-----w- c:\users\arthur1934\AppData\Roaming\ConsumerSoft
2012-12-15 02:09 . 2012-12-25 06:53 -------- d-----w- c:\users\arthur1934\AppData\Roaming\vlc
2012-12-15 02:04 . 2012-12-15 02:04 -------- d-----w- c:\program files (x86)\VideoLAN
2012-12-14 17:58 . 2012-11-22 03:26 3149824 ----a-w- c:\windows\system32\win32k.sys
2012-12-13 10:39 . 2012-11-09 05:45 2048 ----a-w- c:\windows\system32\tzres.dll
2012-12-13 10:39 . 2012-11-09 04:42 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-12-13 10:39 . 2012-11-02 05:59 478208 ----a-w- c:\windows\system32\dpnet.dll
2012-12-13 10:39 . 2012-11-02 05:11 376832 ----a-w- c:\windows\SysWow64\dpnet.dll
2012-12-13 10:25 . 2012-12-13 10:25 -------- d-----w- c:\windows\Migration
2012-12-13 10:25 . 2012-12-25 06:54 -------- d-----w- c:\windows\Help
2012-12-12 22:23 . 2012-12-12 22:23 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2012-12-12 22:06 . 2012-12-12 22:06 -------- d-----w- c:\program files (x86)\IObit
2012-12-10 00:03 . 2012-12-10 00:03 -------- d-----w- C:\perflogs
2012-12-09 12:20 . 2012-12-09 12:20 -------- d-----w- c:\users\arthur1934\AppData\Roaming\InstallShield
2012-12-07 09:00 . 2012-12-07 09:00 -------- d-----w- c:\users\Joshua\AppData\Roaming\TuneUp Software
2012-12-04 12:25 . 2012-12-04 12:25 -------- d-----w- c:\users\Joshua\AppData\Local\Apple
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-14 18:23 . 2012-05-11 18:47 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-12-14 18:23 . 2012-05-11 18:47 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-12-13 02:12 . 2012-10-04 17:18 67413224 ----a-w- c:\windows\system32\MRT.exe
2012-12-12 22:23 . 2012-12-12 22:23 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2012-12-12 20:53 . 2012-10-06 16:37 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2012-12-11 20:49 . 2012-10-07 16:09 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2012-11-21 01:07 . 2012-11-21 01:08 72192 ----a-w- c:\windows\system32\drivers\ew_jucdcecm.sys
2012-11-21 01:07 . 2012-11-21 01:08 28672 ----a-w- c:\windows\system32\drivers\ew_juextctrl.sys
2012-11-21 01:07 . 2012-11-21 01:08 223744 ----a-w- c:\windows\system32\drivers\ew_juwwanecm.sys
2012-11-21 01:07 . 2012-11-21 01:08 13952 ----a-w- c:\windows\system32\drivers\ew_usbenumfilter.sys
2012-11-21 01:07 . 2012-11-21 01:08 1001472 ----a-w- c:\windows\system32\drivers\mod7700.sys
2012-11-21 01:07 . 2012-11-21 01:08 98304 ----a-w- c:\windows\system32\drivers\ew_jucdcacm.sys
2012-11-21 01:07 . 2012-11-21 01:08 87040 ----a-w- c:\windows\system32\drivers\ew_jubusenum.sys
2012-11-21 01:07 . 2012-11-21 01:08 421888 ----a-w- c:\windows\system32\drivers\ewusbwwan.sys
2012-11-21 01:07 . 2012-11-21 01:08 32768 ----a-w- c:\windows\system32\drivers\ewdcsc.sys
2012-11-21 01:07 . 2012-11-21 01:08 223232 ----a-w- c:\windows\system32\drivers\ewusbmdm.sys
2012-11-21 01:07 . 2012-11-21 01:08 22016 ----a-w- c:\windows\system32\drivers\ew_hwupgrade.sys
2012-11-21 01:07 . 2012-11-21 01:08 117248 ----a-w- c:\windows\system32\drivers\ew_hwusbdev.sys
2012-11-21 01:06 . 2012-10-02 19:18 1490656 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2012-11-21 01:06 . 2012-10-02 19:18 1490656 ----a-w- c:\windows\system32\drivers\WdfCoInstaller01007.dll
2012-11-20 13:53 . 2012-11-20 13:53 62744 ----a-w- c:\windows\SysWow64\xinput1_2.dll
2012-10-29 11:07 . 2012-12-02 02:25 83 ----a-w- c:\program files (x86)\update-NFSMW2012.bat
2012-10-29 11:07 . 2012-12-01 20:28 83 ----a-w- c:\users\arthur1934\update-NFSMW2012.bat
2012-10-27 13:07 . 2012-10-27 13:08 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-10-27 13:07 . 2012-10-22 03:52 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-10-27 13:07 . 2012-05-11 18:18 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-10-27 12:08 . 2012-10-27 12:08 106496 ----a-w- c:\windows\SysWow64\ATL71.DLL
2012-10-27 12:00 . 2012-10-27 12:00 57344 ----a-r- c:\users\arthur1934\AppData\Roaming\Microsoft\Installer\{87441A59-5E64-4096-A170-14EFE67200C3}\ARPPRODUCTICON.exe
2012-10-24 19:12 . 2012-10-24 19:12 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2012-10-24 19:12 . 2012-10-24 19:12 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
2012-10-23 06:04 . 2012-11-28 22:07 972264 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3C314D97-27CA-43D1-B88C-7330C3E453AC}\gapaengine.dll
2012-10-17 16:41 . 2012-10-17 16:42 109256 ----a-w- c:\windows\SysWow64\EasyHook64.dll
2012-10-17 16:41 . 2012-10-17 16:42 90824 ----a-w- c:\windows\SysWow64\EasyHook32.dll
2012-10-16 08:38 . 2012-11-28 18:55 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38 . 2012-11-28 18:55 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39 . 2012-11-28 18:55 561664 ----a-w- c:\windows\apppatch\AcLayers.dll
2012-10-13 14:09 . 2011-03-29 01:36 19720 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-10-12 19:09 . 2012-11-21 00:35 25472 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-10-09 18:17 . 2012-11-21 13:31 55296 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2012-10-09 18:17 . 2012-11-21 13:31 226816 ----a-w- c:\windows\system32\dhcpcore6.dll
2012-10-09 17:40 . 2012-11-21 13:31 193536 ----a-w- c:\windows\SysWow64\dhcpcore6.dll
2012-10-09 17:40 . 2012-11-21 13:31 44032 ----a-w- c:\windows\SysWow64\dhcpcsvc6.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll" [2012-06-11 1524056]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0}]
2010-11-21 03:24 297808 ----a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}]
2012-02-27 08:42 88976 ----a-w- c:\progra~2\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{EB5CEE80-030A-4ED8-8E20-454E9C68380F}]
2012-09-19 07:09 2465720 ----a-w- c:\program files (x86)\Bandoo\Plugins\IE\ieplugin.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{99079a25-328f-4bd4-be04-00955acaa0a7}"= "c:\progra~2\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll" [2012-02-27 88976]
.
[HKEY_CLASSES_ROOT\clsid\{99079a25-328f-4bd4-be04-00955acaa0a7}]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EldosIconOverlay]
@="{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}"
[HKEY_CLASSES_ROOT\CLSID\{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}]
2012-04-09 16:27 158224 ----a-w- c:\windows\SysWOW64\CbFsMntNtf3.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\progra~2\Yahoo!\Messenger\YahooMessenger.exe" [2012-05-25 6595928]
"Advanced SystemCare 6"="c:\program files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe" [2012-09-24 490880]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-05-11 39408]
"Facebook Update"="c:\users\arthur1934\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-10-20 138096]
"TOPI.EXE"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2011-05-16 846936]
"
[email protected]"="c:\program files (x86)\AddLyrics\YTLUpdater.exe" [2012-12-05 101888]
"Browser Infrastructure Helper"="c:\users\arthur1934\AppData\Local\Smartbar\Application\QuickShare.exe" [2012-12-10 13824]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"NBAgent"="c:\program files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe" [2011-11-18 1492264]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-01-05 291608]
"Nikon Message Center 2"="c:\program files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe" [2010-05-25 619008]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2011-07-12 1298816]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544]
"Intel AppUp(SM) center"="c:\program files (x86)\Intel\IntelAppStore\bin\ismagent.exe" [2012-08-01 155456]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-24 421888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOPI.EXE"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2011-05-16 846936]
"Norton Download Manager{NSME22-B22-4abb-B07C-C084B04B4F12}"="c:\program files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe" [2012-10-10 143928]
"Norton Download Manager{N360202019-SHPD-FSD31014}"="c:\program files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe" [2012-10-10 143928]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~3\browse~2\251005~1.80\{c16c1~1\browse~1.dll c:\progra~3\browse~2\251005~1.80\{c16c1~1\browserprotect.dll c:\progra~2\bandoo\bndhook.dll
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 Globe Tattoo Broadband. RunOuc;Globe Tattoo Broadband. OUC;c:\program files (x86)\Globe Tattoo Broadband\UpdateDog\ouc.exe [2012-11-21 655712]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]
R3 BtFilter;Bluetooth LowerFilter Class Filter Driver;c:\windows\system32\DRIVERS\btfilter.sys [2011-08-09 45168]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [2012-11-21 117248]
R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2011-07-12 57216]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2011-11-26 138152]
R3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2011-12-14 833976]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-09-28 53760]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-10-03 1255736]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys [2012-01-05 16152]
S0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\DRIVERS\NBVol.sys [2011-12-01 72240]
S0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\DRIVERS\NBVolUp.sys [2011-12-01 15920]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\0604000.009\SYMDS64.SYS [2011-08-16 451192]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\0604000.009\SYMEFA64.SYS [2012-05-22 1129120]
S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [2009-06-24 482384]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\BASHDefs\20121130.005\BHDrvx64.sys [2012-10-23 1384608]
S1 ccSet_MCLIENT;Norton Management Settings Manager;c:\windows\system32\drivers\MCLIENTx64\0302000.013\ccSetx64.sys [2012-10-03 168096]
S1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\N360x64\0604000.009\ccSetx64.sys [2012-06-07 167072]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\IPSDefs\20130102.001\IDSvia64.sys [2012-09-29 513184]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\0604000.009\Ironx64.SYS [2011-11-17 190072]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\N360x64\0604000.009\SYMNETS.SYS [2011-11-17 405624]
S2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe [2012-10-31 464256]
S2 BrowserProtect;BrowserProtect;c:\programdata\BrowserProtect\2.5.1005.80\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [2012-12-14 2469992]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 GFNEXSrv;GFNEX Service;c:\windows\System32\GFNEXSrv.exe [2010-09-10 162824]
S2 HWDeviceService64.exe;HWDeviceService64.exe;c:\programdata\DatacardService\HWDeviceService64.exe [2011-03-14 346976]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-02-03 628448]
S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-02-21 128280]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-02-21 161560]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344]
S2 MCLIENT;Norton Management;c:\program files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe [2012-10-10 143928]
S2 N360;Norton 360;c:\program files (x86)\Norton 360\Engine\6.4.0.9\ccSvcHst.exe [2012-06-16 138272]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-11-04 687400]
S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-08-30 128456]
S2 ScrybeUpdater;Scrybe Updater;c:\program files (x86)\Synaptics\Scrybe\Service\ScrybeUpdater.exe [2011-05-27 1300264]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-08-13 3064000]
S2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [2011-02-10 112080]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2011-11-24 294848]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [2009-06-20 14472]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-02-29 363800]
S3 cbfs3;EldoS Callback File System driver v3;c:\windows\system32\DRIVERS\cbfs3.sys [2012-04-09 352144]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-12-29 138912]
S3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\DRIVERS\ew_usbenumfilter.sys [2012-11-21 13952]
S3 huawei_cdcacm;huawei_cdcacm;c:\windows\system32\DRIVERS\ew_jucdcacm.sys [2012-11-21 98304]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [2012-11-21 87040]
S3 huawei_ext_ctrl;huawei_ext_ctrl;c:\windows\system32\DRIVERS\ew_juextctrl.sys [2012-11-21 28672]
S3 huawei_wwanecm;huawei_wwanecm;c:\windows\system32\DRIVERS\ew_juwwanecm.sys [2012-11-21 223744]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2011-12-06 331264]
S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys [2012-01-05 355096]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys [2012-01-05 786200]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176]
S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-09-12 368896]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [2011-02-09 38096]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2011-08-17 251496]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-08-24 565352]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2013-01-03 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-11 18:24]
.
2013-01-01 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1610491612-2308874447-2798531541-1000Core.job
- c:\users\arthur1934\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-10-20 23:26]
.
2013-01-03 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1610491612-2308874447-2798531541-1000UA.job
- c:\users\arthur1934\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-10-20 23:26]
.
2013-01-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-11 18:52]
.
2013-01-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-11 18:52]
.
2013-01-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1610491612-2308874447-2798531541-1000Core.job
- c:\users\arthur1934\AppData\Local\Google\Update\GoogleUpdate.exe [2012-12-24 00:31]
.
2013-01-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1610491612-2308874447-2798531541-1000UA.job
- c:\users\arthur1934\AppData\Local\Google\Update\GoogleUpdate.exe [2012-12-24 00:31]
.
2013-01-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1610491612-2308874447-2798531541-1001Core.job
- c:\users\Joshua\AppData\Local\Google\Update\GoogleUpdate.exe [2012-12-25 00:31]
.
2013-01-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1610491612-2308874447-2798531541-1001UA.job
- c:\users\Joshua\AppData\Local\Google\Update\GoogleUpdate.exe [2012-12-25 00:31]
.
2013-01-03 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
- c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 20:41]
.
2012-12-31 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
- c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 20:41]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EldosIconOverlay]
@="{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}"
[HKEY_CLASSES_ROOT\CLSID\{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}]
2012-04-09 16:27 190480 ----a-w- c:\windows\System32\CbFsMntNtf3.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2011-11-26 710560]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-05-10 398616]
"SRS Premium Sound HD"="c:\program files\SRS Labs\SRS Control Panel\SRSPanel_64.exe" [2012-03-22 2165120]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-05-10 170264]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-03-16 12459112]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2011-02-10 1546720]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 1289704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-05-10 440088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\progra~2\SEARCH~1\Datamngr\x64\datamngr.dll c:\progra~2\SEARCH~1\Datamngr\x64\IEBHO.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.babylon.com/?affID=116987&tt=5212_4&babsrc=HP_ss&mntrId=d06c3eb90000000000001cc63ca8ccf8
mDefault_Search_URL = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/
mDefault_Page_URL = hxxp://isearch.glarysoft.com/?src=iehome
mStart Page = hxxp://isearch.glarysoft.com/?src=iehome
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/
uSearchAssistant = hxxp://www.searchamong.com/searchview.php?source=6987e315b363f4b09672a1cda71caea8&query={searchTerms}&cat=webs&bar=true
IE: &Google Search - c:\program files (x86)\Google\googletoolbar.dll/cmsearch.html
IE: Backward &Links - c:\program files (x86)\Google\googletoolbar.dll/cmbacklinks.html
IE: Cac&hed Snapshot of Page - c:\program files (x86)\Google\googletoolbar.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: Si&milar Pages - c:\program files (x86)\Google\googletoolbar.dll/cmsimilar.html
IE: Translate into English - c:\program files (x86)\Google\googletoolbar.dll/cmtrans.html
Trusted Zone: facebook.com\www
TCP: Interfaces\{8B458FE7-67D4-4694-9E5B-B5F611B65225}: NameServer = 10.198.220.124 202.126.40.5
FF - ProfilePath - c:\users\arthur1934\AppData\Roaming\Mozilla\Firefox\Profiles\i6s2czgc.default\
FF - prefs.js: browser.search.defaulturl - hxxp://home.speedbit.com/search.aspx?site=shdefault&pid=%s&aid=%s&shr=%d&q=
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?affID=116987&tt=5212_4&babsrc=HP_ss&mntrId=d06c3eb90000000000001cc63ca8ccf8
FF - ExtSQL: 2012-11-22 04:25;
[email protected]; c:\users\arthur1934\AppData\Roaming\Mozilla\Firefox\Profiles\i6s2czgc.default\extensions\
[email protected]
FF - ExtSQL: 2012-11-25 10:41; {62d40876-df18-411f-9d34-a9dd7a197bc5}; c:\users\arthur1934\AppData\Roaming\Mozilla\Firefox\Profiles\i6s2czgc.default\extensions\{62d40876-df18-411f-9d34-a9dd7a197bc5}
FF - ExtSQL: 2012-12-03 00:14; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\arthur1934\AppData\Roaming\Mozilla\Firefox\Profiles\i6s2czgc.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - user.js: extensions.autoDisableScopes - 0
FF - user.js: extensions.shownSelectionUI - true
FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=d06c3eb90000000000001cc63ca8ccf8&q=
FF - user.js: extensions.BabylonToolbar.id - d06c3eb90000000000001cc63ca8ccf8
FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}
FF - user.js: extensions.BabylonToolbar.instlDay - 15703
FF - user.js: extensions.BabylonToolbar.vrsn - 1.8.7.2
FF - user.js: extensions.BabylonToolbar.vrsni - 1.8.7.2
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.8.7.215:52
FF - user.js: extensions.BabylonToolbar.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar.tlbrId - base
FF - user.js: extensions.BabylonToolbar.instlRef - sst
FF - user.js: extensions.BabylonToolbar.dfltLng - en
FF - user.js: extensions.BabylonToolbar_i.excTlbr - false
FF - user.js: extensions.BabylonToolbar.excTlbr - false
FF - user.js: extensions.BabylonToolbar.admin - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=116987&tt=5212_4
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar.autoRvrt - false
FF - user.js: extensions.BabylonToolbar.rvrt - false
FF - user.js: extensions.BabylonToolbar_i.newTab - false
.
.
------- File Associations -------
.
vbefile\shell\open2\command="%SystemRoot%\System32\CScript.exe" "%1" %*
vbsfile\shell\open2\command="%SystemRoot%\System32\CScript.exe" "%1" %*
jsefile\shell\open2\command=c:\windows\System32\CScript.exe "%1" %*
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{B40720CF-4DDD-40DC-86EA-26404E77C1E8} - c:\program files (x86)\AddLyrics\AddLyrics.dll
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
Toolbar-{D0F4A166-B8D4-48b8-9D63-80849FE137CB} - (no file)
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
WebBrowser-{7473B6BD-4691-4744-A82B-7854EB3D70B6} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe
HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe
HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe
AddRemove-Freecorder extension for Chrome - c:\program files (x86)\Freecorder extension\UninstallChromeToolbar.exe
AddRemove-Freecorder extension for Firefox - c:\program files (x86)\Freecorder extension\UninstallFirefoxToolbar.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\MCLIENT]
"ImagePath"="\"c:\program files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe\" /s \"MCLIENT\" /m \"c:\program files (x86)\Norton Management\Engine\3.2.0.19\diMaster.dll\" /prefetch:1"
--
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\N360]
"ImagePath"="\"c:\program files (x86)\Norton 360\Engine\6.4.0.9\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton 360\Engine\6.4.0.9\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1610491612-2308874447-2798531541-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E29597E7-E8D5-608B-05CF-E00C861C5FE6}*]
"jagadfpgicjcfjgjellm"=hex:63,61,66,67,69,6a,00,00
"paoofgnmbfgnklmkbialdhcaekkgiabc"=hex:64,61,62,66,6c,65,67,65,00,00
"hagadfpgicjcfjgj"=hex:61,61,00,73
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\SysWOW64\schtasks.exe
c:\programdata\Globe Tattoo Broadband\OnlineUpdate\ouc.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files (x86)\Bandoo\Bandoo.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Completion time: 2013-01-03 16:54:12 - machine was rebooted
ComboFix-quarantined-files.txt 2013-01-03 08:54
.
Pre-Run: 526,826,745,856 bytes free
Post-Run: 527,347,138,560 bytes free
.
- - End Of File - - 2187127B41E4223531A9FB207BB26DC2