OK, took a while to get through stage 5, but finished finally. Here is the report….
ComboFix 13-09-28.02 - dogonit23 09/29/2013 14:22:44.5.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3835.2850 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\Extras\Fix\ComboFix.exe
AV: Lavasoft Ad-Aware *Disabled/Updated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}
SP: IObit Malware Fighter *Enabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Lavasoft Ad-Aware *Disabled/Updated* {5BB89C30-6480-BC7C-9F17-199BD76F557A}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2013-08-28 to 2013-09-29 )))))))))))))))))))))))))))))))
.
.
2013-09-29 22:01 . 2013-09-29 22:01 ——– d—–w- c:\users\Public\AppData\Local\temp
2013-09-29 22:01 . 2013-09-29 22:01 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-09-29 22:01 . 2013-09-29 22:01 ——– d—–w- c:\users\Administrator\AppData\Local\temp
2013-09-29 19:01 . 2013-09-29 19:01 ——– d—–w- c:\users\dogonit23\AppData\Roaming\com.aligmarketing.slf
2013-09-29 19:01 . 2013-09-29 19:01 ——– d—–w- c:\program files (x86)\slf
2013-09-29 17:07 . 2013-09-05 05:32 9694160 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{92BBE67E-BEF1-446E-813E-B21B1496B4F3}\mpengine.dll
2013-09-29 02:01 . 2013-09-29 02:01 ——– d—–w- c:\windows\ERUNT
2013-09-28 07:02 . 2013-09-05 05:32 9694160 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-09-26 06:19 . 2013-09-26 06:19 ——– d—–w- C:\FRST
2013-09-24 22:37 . 2013-09-24 22:39 ——– d—–w- c:\users\dogonit23\AppData\Local\FreeScreenSharing
2013-09-24 03:09 . 2013-09-24 03:11 ——– d—–w- c:\users\dogonit23\AppData\Roaming\VDownloader
2013-09-24 03:01 . 2013-09-24 07:41 ——– d—–w- c:\users\dogonit23\AppData\Local\VDownloader
2013-09-24 03:01 . 2010-01-26 18:11 444283 —-a-w- c:\program files\Common Files\WinPcapNmap.exe
2013-09-24 03:00 . 2013-09-29 04:58 ——– d—–w- c:\program files\VDownloader
2013-09-21 03:46 . 2013-09-24 18:16 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2013-09-21 03:44 . 2013-09-25 12:17 ——– d—–w- c:\program files (x86)\Spybot - Search & Destroy 2
2013-09-20 19:10 . 2013-09-29 01:25 ——– d—–w- c:\programdata\Uniblue
2013-09-20 06:08 . 2013-09-20 06:08 ——– d—–w- c:\users\dogonit23\AppData\Roaming\IsolatedStorage
2013-09-20 06:08 . 2013-09-20 06:08 ——– d—–w- c:\programdata\IsolatedStorage
2013-09-20 06:06 . 2013-09-20 06:06 ——– d—–w- c:\users\dogonit23\AppData\Roaming\EasyEmailSender
2013-09-20 06:06 . 2013-09-20 06:06 ——– d—–w- C:\temp
2013-09-20 06:06 . 2013-09-20 06:06 ——– d—–w- c:\program files (x86)\EasyEmailSender
2013-09-20 05:58 . 2013-09-20 05:58 ——– d—–w- c:\users\dogonit23\AppData\Local\Downloaded Installations
2013-09-19 05:06 . 2013-09-19 05:06 ——– d-sh–w- c:\windows\ftpcache
2013-09-19 05:05 . 2013-09-19 05:06 ——– d—–w- c:\program files (x86)\FLV-Media Player
2013-09-18 10:02 . 2013-09-18 10:02 ——– d—–w- c:\program files (x86)\Microsoft CAPICOM 2.1.0.2
2013-09-17 09:04 . 2013-05-23 01:49 17720 —-a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2013-09-16 19:03 . 2013-09-16 19:03 ——– d—–w- c:\program files (x86)\AdminSystem.NET
2013-09-15 09:33 . 2013-09-15 09:33 ——– d—–w- c:\programdata\RegInOut
2013-09-15 09:12 . 2013-09-15 09:12 ——– d—–w- c:\programdata\GlarySoft
2013-09-15 00:19 . 2013-04-18 03:20 26432 —-a-w- c:\windows\system32\RegistryDefragBootTime.exe
2013-09-14 23:58 . 2013-09-02 09:09 117024 —-a-w- c:\windows\system32\BootDefrag.exe
2013-09-14 23:58 . 2013-09-14 23:58 ——– d—–w- c:\users\dogonit23\AppData\Roaming\GlarySoft
2013-09-14 23:58 . 2013-09-19 23:45 ——– d—–w- c:\program files (x86)\Glary Utilities 3
2013-09-14 23:44 . 2013-09-15 09:33 ——– d—–w- c:\program files (x86)\RegInOut System Utilities
2013-09-14 23:08 . 2013-08-16 00:31 268968 —-a-w- c:\windows\SysWow64\sqlite3.dll
2013-09-14 23:07 . 2013-09-14 23:07 ——– d—–w- c:\programdata\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
2013-09-14 23:07 . 2013-09-14 23:08 ——– d—–w- c:\programdata\IObit
2013-09-14 23:06 . 2013-09-17 09:04 ——– d—–w- c:\users\dogonit23\AppData\Roaming\IObit
2013-09-14 23:06 . 2013-09-17 09:04 ——– d—–w- c:\program files (x86)\IObit
2013-09-13 19:14 . 2013-09-29 01:26 ——– d—–w- C:\AdwCleaner
2013-09-13 08:31 . 2013-08-10 05:22 1084928 —-a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-09-13 08:31 . 2013-08-10 03:59 817664 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2013-09-13 08:31 . 2013-08-10 05:21 53248 —-a-w- c:\windows\system32\jsproxy.dll
2013-09-13 08:31 . 2013-08-10 03:59 1767936 —-a-w- c:\windows\SysWow64\wininet.dll
2013-09-13 08:31 . 2013-08-10 05:22 2241024 —-a-w- c:\windows\system32\wininet.dll
2013-09-13 08:31 . 2013-08-10 05:20 15404544 —-a-w- c:\windows\system32\ieframe.dll
2013-09-13 08:31 . 2013-08-10 05:21 19246592 —-a-w- c:\windows\system32\mshtml.dll
2013-09-12 01:14 . 2013-08-05 02:25 155584 —-a-w- c:\windows\system32\drivers\ataport.sys
2013-09-12 01:14 . 2013-08-02 01:59 3968960 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-09-12 01:14 . 2013-08-02 01:59 3913664 —-a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-09-12 01:14 . 2013-08-02 02:23 5550528 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-09-12 01:14 . 2013-08-02 02:15 1732032 —-a-w- c:\windows\system32\ntdll.dll
2013-09-12 01:14 . 2013-08-02 02:13 424448 —-a-w- c:\windows\system32\KernelBase.dll
2013-09-12 01:14 . 2013-08-02 01:51 1292192 —-a-w- c:\windows\SysWow64\ntdll.dll
2013-09-12 01:06 . 2013-08-08 01:20 3155456 —-a-w- c:\windows\system32\win32k.sys
2013-09-12 01:06 . 2013-07-26 02:24 14172672 —-a-w- c:\windows\system32\shell32.dll
2013-09-12 01:06 . 2013-07-26 02:24 197120 —-a-w- c:\windows\system32\shdocvw.dll
2013-09-09 06:55 . 2013-09-09 06:55 ——– d—–w- c:\users\dogonit23\AppData\Local\Geckofx
2013-09-06 18:46 . 2013-09-06 17:21 965008 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6C1C8E88-806D-40E1-A05F-836CF1B04488}\gapaengine.dll
2013-09-04 01:40 . 2013-09-13 20:43 ——– d—–w- c:\users\dogonit23\7 Minute Research
2013-09-02 21:03 . 2013-09-02 22:10 ——– d—–w- c:\users\dogonit23\AppData\Local\xheader-data
2013-09-02 21:03 . 2013-09-02 21:03 205717 —-a-w- c:\windows\XHeader Uninstaller.exe
2013-09-02 21:02 . 2013-09-02 21:02 ——– d—–w- c:\program files (x86)\XHeader
2013-09-02 21:02 . 2013-09-02 21:02 ——– d—–w- c:\program files (x86)\Common Files\Thraex Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-23 17:13 . 2013-05-07 21:30 692616 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-09-23 17:13 . 2013-05-07 21:30 71048 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-13 08:25 . 2013-05-07 19:01 79143768 —-a-w- c:\windows\system32\MRT.exe
2013-08-30 20:37 . 2013-08-30 20:37 163273 —-a-w- c:\windows\Nexus Toolbar Uninstaller.exe
2013-08-23 17:59 . 2013-05-21 18:09 941720 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-08-06 19:39 . 2013-08-06 19:39 47496 —-a-w- c:\windows\system32\sbbd.exe
2013-08-06 19:39 . 2013-08-06 19:39 14456 —-a-w- c:\windows\system32\drivers\gfibto.sys
2013-08-02 01:48 . 2013-09-12 01:13 44032 —-a-w- c:\windows\apppatch\acwow64.dll
2013-07-25 09:25 . 2013-08-14 17:39 1888768 —-a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-25 08:57 . 2013-08-14 17:39 1620992 —-a-w- c:\windows\SysWow64\WMVDECOD.DLL
2013-07-19 01:58 . 2013-08-14 17:39 2048 —-a-w- c:\windows\system32\tzres.dll
2013-07-19 01:41 . 2013-08-14 17:39 2048 —-a-w- c:\windows\SysWow64\tzres.dll
2013-07-09 05:52 . 2013-08-14 17:39 224256 —-a-w- c:\windows\system32\wintrust.dll
2013-07-09 05:51 . 2013-08-14 17:40 1217024 —-a-w- c:\windows\system32\rpcrt4.dll
2013-07-09 05:46 . 2013-08-14 17:40 1472512 —-a-w- c:\windows\system32\crypt32.dll
2013-07-09 05:46 . 2013-08-14 17:39 184320 —-a-w- c:\windows\system32\cryptsvc.dll
2013-07-09 05:46 . 2013-08-14 17:39 139776 —-a-w- c:\windows\system32\cryptnet.dll
2013-07-09 04:52 . 2013-08-14 17:40 663552 —-a-w- c:\windows\SysWow64\rpcrt4.dll
2013-07-09 04:52 . 2013-08-14 17:39 175104 —-a-w- c:\windows\SysWow64\wintrust.dll
2013-07-09 04:46 . 2013-08-14 17:40 1166848 —-a-w- c:\windows\SysWow64\crypt32.dll
2013-07-09 04:46 . 2013-08-14 17:39 140288 —-a-w- c:\windows\SysWow64\cryptsvc.dll
2013-07-09 04:46 . 2013-08-14 17:39 103936 —-a-w- c:\windows\SysWow64\cryptnet.dll
2013-07-06 06:03 . 2013-08-14 17:36 1910208 —-a-w- c:\windows\system32\drivers\tcpip.sys
2013-07-03 17:34 . 2013-07-03 17:34 1054720 —-a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-07-03 17:33 . 2013-07-03 17:33 226304 —-a-w- c:\windows\system32\elshyph.dll
2013-07-03 17:33 . 2013-07-03 17:33 185344 —-a-w- c:\windows\SysWow64\elshyph.dll
2013-07-03 17:33 . 2013-07-03 17:33 158720 —-a-w- c:\windows\SysWow64\msls31.dll
2013-07-03 17:33 . 2013-07-03 17:33 719360 —-a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-07-03 17:33 . 2013-07-03 17:33 150528 —-a-w- c:\windows\SysWow64\iexpress.exe
2013-07-03 17:33 . 2013-07-03 17:33 138752 —-a-w- c:\windows\SysWow64\wextract.exe
2013-07-03 17:33 . 2013-07-03 17:33 523264 —-a-w- c:\windows\SysWow64\vbscript.dll
2013-07-03 17:33 . 2013-07-03 17:33 137216 —-a-w- c:\windows\SysWow64\ieUnatt.exe
2013-07-03 17:33 . 2013-07-03 17:33 73728 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-07-03 17:33 . 2013-07-03 17:33 61952 —-a-w- c:\windows\SysWow64\tdc.ocx
2013-07-03 17:33 . 2013-07-03 17:33 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll
2013-07-03 17:33 . 2013-07-03 17:33 38400 —-a-w- c:\windows\SysWow64\imgutil.dll
2013-07-03 17:33 . 2013-07-03 17:33 361984 —-a-w- c:\windows\SysWow64\html.iec
2013-07-03 17:33 . 2013-07-03 17:33 12800 —-a-w- c:\windows\SysWow64\mshta.exe
2013-07-03 17:33 . 2013-07-03 17:33 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-07-03 17:33 . 2013-07-03 17:33 23040 —-a-w- c:\windows\SysWow64\licmgr10.dll
2013-07-03 17:33 . 2013-07-03 17:33 1441280 —-a-w- c:\windows\SysWow64\inetcpl.cpl
2013-07-03 17:33 . 2013-07-03 17:33 81408 —-a-w- c:\windows\system32\icardie.dll
2013-07-03 17:33 . 2013-07-03 17:33 762368 —-a-w- c:\windows\system32\ieapfltr.dll
2013-07-03 17:33 . 2013-07-03 17:33 452096 —-a-w- c:\windows\system32\dxtmsft.dll
2013-07-03 17:33 . 2013-07-03 17:33 441856 —-a-w- c:\windows\system32\html.iec
2013-07-03 17:33 . 2013-07-03 17:33 281600 —-a-w- c:\windows\system32\dxtrans.dll
2013-07-03 17:33 . 2013-07-03 17:33 216064 —-a-w- c:\windows\system32\msls31.dll
2013-07-03 17:33 . 2013-07-03 17:33 197120 —-a-w- c:\windows\system32\msrating.dll
2013-07-03 17:33 . 2013-07-03 17:33 1400416 —-a-w- c:\windows\system32\ieapfltr.dat
2013-07-03 17:33 . 2013-07-03 17:33 905728 —-a-w- c:\windows\system32\mshtmlmedia.dll
2013-07-03 17:33 . 2013-07-03 17:33 27648 —-a-w- c:\windows\system32\licmgr10.dll
2013-07-03 17:33 . 2013-07-03 17:33 270848 —-a-w- c:\windows\system32\iedkcs32.dll
2013-07-03 17:33 . 2013-07-03 17:33 247296 —-a-w- c:\windows\system32\webcheck.dll
2013-07-03 17:33 . 2013-07-03 17:33 235008 —-a-w- c:\windows\system32\url.dll
2013-07-03 17:33 . 2013-07-03 17:33 1509376 —-a-w- c:\windows\system32\inetcpl.cpl
2013-07-03 17:33 . 2013-07-03 17:33 102912 —-a-w- c:\windows\system32\inseng.dll
2013-07-03 17:33 . 2013-07-03 17:33 97280 —-a-w- c:\windows\system32\mshtmled.dll
2013-07-03 17:33 . 2013-07-03 17:33 599552 —-a-w- c:\windows\system32\vbscript.dll
2013-07-03 17:33 . 2013-07-03 17:33 173568 —-a-w- c:\windows\system32\ieUnatt.exe
2013-07-03 17:33 . 2013-07-03 17:33 167424 —-a-w- c:\windows\system32\iexpress.exe
2013-07-03 17:33 . 2013-07-03 17:33 144896 —-a-w- c:\windows\system32\wextract.exe
2013-07-03 17:33 . 2013-07-03 17:33 149504 —-a-w- c:\windows\system32\occache.dll
2013-07-03 17:33 . 2013-07-03 17:33 62976 —-a-w- c:\windows\system32\pngfilt.dll
2013-07-03 17:33 . 2013-07-03 17:33 52224 —-a-w- c:\windows\system32\msfeedsbs.dll
2013-07-03 17:33 . 2013-07-03 17:33 51200 —-a-w- c:\windows\system32\imgutil.dll
2013-07-03 17:33 . 2013-07-03 17:33 13824 —-a-w- c:\windows\system32\mshta.exe
2013-07-03 17:33 . 2013-07-03 17:33 136192 —-a-w- c:\windows\system32\iepeers.dll
2013-07-03 17:33 . 2013-07-03 17:33 12800 —-a-w- c:\windows\system32\msfeedssync.exe
2013-07-03 17:33 . 2013-07-03 17:33 135680 —-a-w- c:\windows\system32\IEAdvpack.dll
2013-07-03 17:33 . 2013-07-03 17:33 92160 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-07-03 17:33 . 2013-07-03 17:33 77312 —-a-w- c:\windows\system32\tdc.ocx
2013-07-03 17:33 . 2013-07-03 17:33 48640 —-a-w- c:\windows\system32\mshtmler.dll
2013-07-01 22:43 . 2013-07-01 22:43 49152 —-a-r- c:\windows\SysWow64\inetwh32.dll
2013-07-01 22:43 . 2013-07-01 22:43 1044480 —-a-r- c:\windows\SysWow64\roboex32.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2013-05-05 160328]
"IDMan"="c:\program files (x86)\Internet Download Manager\IDMan.exe" [2012-11-24 3540416]
"FreeScreenSharing"="c:\users\dogonit23\AppData\Local\FreeScreenSharing\FreeScreenSharing.exe" [2013-06-26 2266104]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-09-30 98304]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2013-05-08 41056]
"IObit Malware Fighter"="c:\program files (x86)\IObit\IObit Malware Fighter\IMF.exe" [2013-08-17 1549120]
.
c:\users\dogonit23\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Nexus Toolbar.lnk - c:\nexustoolbar\NexusToolbar.exe [2012-5-16 937984]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk * \0BootDefrag.exe\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service]
@="Ad-Aware Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
.
R0 BootDefragDriver;BootDefragDriver;c:\windows\System32\drivers\BootDefragDriver.sys;c:\windows\SYSNATIVE\drivers\BootDefragDriver.sys [x]
R2 CLKMSVC10_C6F09094;CyberLink Product - 2011/01/03 00:55;c:\program files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe;c:\program files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 IMFservice;IMF Service;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [x]
R2 SBAMSvc;Ad-Aware;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [x]
R2 SecureUpdateSvc;SecureUpdate;c:\program files (x86)\Secure Speed Dial\IE\SecureUpdate.exe;c:\program files (x86)\Secure Speed Dial\IE\SecureUpdate.exe [x]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 EsgScanner;EsgScanner;c:\windows\system32\DRIVERS\EsgScanner.sys;c:\windows\SYSNATIVE\DRIVERS\EsgScanner.sys [x]
R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x]
R3 SystemExplorerHelpService;System Explorer Service;c:\program files (x86)\System Explorer\service\SystemExplorerService64.exe;c:\program files (x86)\System Explorer\service\SystemExplorerService64.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 UrlFilter;UrlFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
R4 FileMonitor;FileMonitor;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [x]
S0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys;c:\windows\SYSNATIVE\drivers\gfibto.sys [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [x]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [x]
S2 Ad-Aware Service;Ad-Aware Service;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe [x]
S2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare 6\ASCService.exe [x]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe;c:\program files\IDT\WDM\AESTSr64.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]
S2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [x]
S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [x]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]
S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [x]
S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys;c:\windows\SYSNATIVE\DRIVERS\idmwfp.sys [x]
S2 NitroReaderDriverReadSpool3;NitroPDFReaderDriverCreatorReadSpool3;c:\program files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe;c:\program files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe [x]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 RoxioNow Service;RoxioNow Service;c:\program files (x86)\Roxio\RoxioNow Player\RNowSvc.exe;c:\program files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S2 SpyHunter 4 Service;SpyHunter 4 Service;c:\progra~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE;c:\progra~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [x]
S3 clwvd;HP Webcam Splitter;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x]
S3 RegFilter;RegFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
— Other Services/Drivers In Memory —
.
*Deregistered* - CLKMDRV10_C6F09094
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-09-21 09:56 1177552 —-a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-09-20 c:\windows\Tasks\GlaryInitialize 3.job
- c:\program files (x86)\Glary Utilities 3\Initialize.exe [2013-09-02 09:06]
.
2013-09-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-11 21:45]
.
2013-09-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-11 21:45]
.
2013-09-02 c:\windows\Tasks\HPCeeScheduleForDOGONIT23-HP$.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15]
.
2013-09-28 c:\windows\Tasks\HPCeeScheduleFordogonit23.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00Zecter]
@="{D25B32FE-CB96-491A-98FF-AD59DA382D69}"
[HKEY_CLASSES_ROOT\CLSID\{D25B32FE-CB96-491A-98FF-AD59DA382D69}]
2010-09-23 04:53 2210304 —-a-w- c:\program files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\01Zecter]
@="{EB24CA6D-F315-4A81-AC1A-C79CFD77F3F5}"
[HKEY_CLASSES_ROOT\CLSID\{EB24CA6D-F315-4A81-AC1A-C79CFD77F3F5}]
2010-09-23 04:53 2210304 —-a-w- c:\program files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\02Zecter]
@="{B3C78E40-6B64-47C3-AE34-60B770881EB8}"
[HKEY_CLASSES_ROOT\CLSID\{B3C78E40-6B64-47C3-AE34-60B770881EB8}]
2010-09-23 04:53 2210304 —-a-w- c:\program files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\03Zecter]
@="{622AFE52-33F6-4D9F-9966-E0BC52D7D69D}"
[HKEY_CLASSES_ROOT\CLSID\{622AFE52-33F6-4D9F-9966-E0BC52D7D69D}]
2010-09-23 04:53 2210304 —-a-w- c:\program files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\04Zecter]
@="{855156F0-2A0F-11DE-8C30-0800200C9A66}"
[HKEY_CLASSES_ROOT\CLSID\{855156F0-2A0F-11DE-8C30-0800200C9A66}]
2010-09-23 04:53 2210304 —-a-w- c:\program files (x86)\Hewlett-Packard\HP CloudDrive\ShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2012-11-15 23:07 23496 —-a-w- c:\program files (x86)\Internet Download Manager\IDMShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-09-14 487424]
"HPWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe" [2010-07-21 8192]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-06-21 1356240]
"VDownloader"="c:\program files\VDownloader\VDownloader.exe" [2013-09-20 880640]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences Pro\FencesMenu64.dll" [2010-09-16 464744]
.
——- Supplementary Scan ——-
.
uStart Page =
https://www.google.com/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Customize Menu - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Download all links with IDM - c:\program files (x86)\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - c:\program files (x86)\Internet Download Manager\IEExt.htm
IE: Fill Forms - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Save Page As PDF … - file://c:\program files (x86)\Nitro PDF\PDF Download\nitroweb.htm
Trusted Zone: blackhatteam.com\www
Trusted Zone: samsungsetup.com\www
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\dogonit23\AppData\Roaming\Mozilla\Firefox\Profiles\qfgmkrbu.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.com/
FF - prefs.js: network.proxy.gopher -
FF - prefs.js: network.proxy.gopher_port - 0
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2013-09-14 09:07; [removed]; c:\users\dogonit23\AppData\Roaming\Mozilla\Firefox\Profiles\qfgmkrbu.default\extensions\[removed]
FF - ExtSQL: 2013-09-16 00:42; [removed]; c:\users\dogonit23\AppData\Roaming\Mozilla\Firefox\Profiles\qfgmkrbu.default\extensions\[removed]
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-AccelerateTab_is1 - c:\program files (x86)\Secure Speed Dial\unins000.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-2034785586-1586066431-309787569-1001_Classes\Wow6432Node\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):e1,fa,26,9e,16,71,f9,40,fb,15,d5,77,ea,07,30,a7,39,d2,1c,7a,28,
fd,86,24,4d,fb,97,24,cb,1f,d2,c7,f2,4f,81,c0,31,5f,7c,c0,00,00,00,00,00,00,\
.
[HKEY_USERS\S-1-5-21-2034785586-1586066431-309787569-1001_Classes\Wow6432Node\CLSID\{ecad5a90-57d9-4d3e-aa6b-72489e80ca18}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:000000bf
"Therad"=dword:00000009
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-09-29 15:06:20
ComboFix-quarantined-files.txt 2013-09-29 22:06
ComboFix2.txt 2013-09-20 23:13
ComboFix3.txt 2013-09-16 11:22
.
Pre-Run: 250,883,309,568 bytes free
Post-Run: 251,110,576,128 bytes free
.
- - End Of File - - B1FDCFEA8C11AFD18F7BEE4CFEB055A0
0BA2A85985CC2D6245F7E3F7BC450923