
ComboFix 12-01-15.01 - Elimato . 01. 2012 19:00:29.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.421.1051.18.3886.2343 [GMT 1:00]
Running from: c:\users\Elimato\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Common Files\ASPG_icon.ico
c:\windows\system32\drivers\etc\hosts.ics
.
.
((((((((((((((((((((((((( Files Created from 2011-12-15 to 2012-01-15 )))))))))))))))))))))))))))))))
.
.
2012-01-15 17:38 . 2012-01-15 17:38 69000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4A7A8104-A46F-4EC4-A133-72280F2F5563}\offreg.dll
2012-01-14 18:13 . 2011-11-21 11:40 8822856 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4A7A8104-A46F-4EC4-A133-72280F2F5563}\mpengine.dll
2012-01-11 13:58 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 13:58 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 13:58 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 13:58 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 13:58 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 13:58 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 13:58 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-11 13:58 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-11 11:27 . 2012-01-11 11:27 -------- d-----w- C:\rsit
2012-01-10 16:41 . 2012-01-10 21:16 -------- d-----w- c:\windows\SysWow64\NV
2012-01-10 16:41 . 2012-01-10 21:16 -------- d-----w- c:\windows\system32\NV
2012-01-10 16:38 . 2012-01-10 16:38 -------- d-----w- c:\programdata\NVIDIA Corporation
2012-01-08 12:51 . 2012-01-08 12:51 479232 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcm80.dll
2012-01-08 12:51 . 2012-01-08 12:51 43992 ----a-w- c:\program files (x86)\Mozilla Firefox\mozutils.dll
2012-01-08 12:51 . 2012-01-08 12:51 548864 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp80.dll
2012-01-08 12:51 . 2012-01-08 12:51 626688 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr80.dll
2011-12-19 18:38 . 2011-12-19 18:38 -------- d-----w- c:\program files\Media Player Classic - Home Cinema
2011-12-17 12:13 . 2011-12-17 15:18 -------- d-----w- c:\users\Elimato\AppData\Roaming\Hamachi
2011-12-17 12:13 . 2011-12-17 12:13 33344 ----a-w- c:\windows\system32\drivers\hamachi.sys
2011-12-17 12:13 . 2011-12-17 12:13 -------- d-----w- c:\program files (x86)\Hamachi
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-15 17:38 . 2010-12-26 15:31 45056 ----a-w- c:\windows\system32\acovcnt.exe
2011-11-28 08:57 . 2011-11-03 22:04 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-24 04:52 . 2011-12-15 11:17 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-11-21 11:40 . 2011-09-25 08:23 8822856 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-05 05:32 . 2011-12-15 11:17 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-05 04:26 . 2011-12-15 11:17 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-10-26 05:21 . 2011-12-15 11:17 43520 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-21 16:41 . 2011-10-21 16:41 510232 ----a-w- c:\windows\system32\igfxsrvc.exe
2011-10-21 16:41 . 2011-10-21 16:41 167704 ----a-w- c:\windows\system32\igfxtray.exe
2011-10-21 16:41 . 2011-10-21 16:41 416024 ----a-w- c:\windows\system32\igfxpers.exe
2011-10-21 16:41 . 2011-10-21 16:41 239896 ----a-w- c:\windows\system32\igfxext.exe
2011-10-21 16:41 . 2011-10-21 16:41 392472 ----a-w- c:\windows\system32\hkcmd.exe
2011-10-21 16:41 . 2011-10-21 16:41 4378392 ----a-w- c:\windows\system32\GfxUI.exe
2011-10-21 16:41 . 2011-10-21 16:41 184600 ----a-w- c:\windows\system32\difx64.exe
2011-10-21 16:36 . 2011-10-21 16:36 90112 ----a-w- c:\windows\system32\igfxCoIn_v2559.dll
2011-10-21 16:30 . 2011-10-21 16:30 12310112 ----a-w- c:\windows\system32\drivers\igdkmd64.sys
2011-10-21 16:30 . 2010-04-21 16:18 8313856 ----a-w- c:\windows\system32\igdumd64.dll
2011-10-21 16:25 . 2011-10-21 16:25 6323712 ----a-w- c:\windows\SysWow64\igdumd32.dll
2011-10-21 16:21 . 2011-10-21 16:21 581120 ----a-w- c:\windows\SysWow64\igdumdx32.dll
2011-10-21 16:19 . 2010-03-23 19:25 14592512 ----a-w- c:\windows\system32\igd10umd64.dll
2011-10-21 16:13 . 2011-02-11 17:04 12340224 ----a-w- c:\windows\SysWow64\igd10umd32.dll
2011-10-21 16:08 . 2011-10-21 16:08 18651648 ----a-w- c:\windows\system32\ig4icd64.dll
2011-10-21 16:03 . 2011-10-21 16:03 13903872 ----a-w- c:\windows\SysWow64\ig4icd32.dll
2011-10-21 15:59 . 2011-10-21 15:59 286720 ----a-w- c:\windows\system32\igfxrrom.lrc
2011-10-21 15:59 . 2011-10-21 15:59 286720 ----a-w- c:\windows\system32\igfxrsky.lrc
2011-10-21 15:59 . 2011-10-21 15:59 286720 ----a-w- c:\windows\system32\igfxrhrv.lrc
2011-10-21 15:59 . 2011-10-21 15:59 286208 ----a-w- c:\windows\system32\igfxrslv.lrc
2011-10-21 15:59 . 2011-10-21 15:59 286208 ----a-w- c:\windows\system32\igfxrtrk.lrc
2011-10-21 15:59 . 2011-10-21 15:59 286208 ----a-w- c:\windows\system32\igfxrsve.lrc
2011-10-21 15:59 . 2011-10-21 15:59 285696 ----a-w- c:\windows\system32\igfxrtha.lrc
2011-10-21 15:59 . 2011-10-21 15:59 287232 ----a-w- c:\windows\system32\igfxresn.lrc
2011-10-21 15:59 . 2011-10-21 15:59 286720 ----a-w- c:\windows\system32\igfxrrus.lrc
2011-10-21 15:59 . 2011-10-21 15:59 286720 ----a-w- c:\windows\system32\igfxrptg.lrc
2011-10-21 15:59 . 2011-10-21 15:59 286720 ----a-w- c:\windows\system32\igfxrplk.lrc
2011-10-21 15:59 . 2011-10-21 15:59 286208 ----a-w- c:\windows\system32\igfxrptb.lrc
2011-10-21 15:59 . 2011-10-21 15:59 286720 ----a-w- c:\windows\system32\igfxrita.lrc
2011-10-21 15:59 . 2011-10-21 15:59 286208 ----a-w- c:\windows\system32\igfxrnor.lrc
2011-10-21 15:59 . 2011-10-21 15:59 283648 ----a-w- c:\windows\system32\igfxrjpn.lrc
2011-10-21 15:59 . 2011-10-21 15:59 283136 ----a-w- c:\windows\system32\igfxrkor.lrc
2011-10-21 15:59 . 2011-10-21 15:59 287232 ----a-w- c:\windows\system32\igfxrell.lrc
2011-10-21 15:59 . 2011-10-21 15:59 286208 ----a-w- c:\windows\system32\igfxrhun.lrc
2011-10-21 15:59 . 2011-10-21 15:59 285184 ----a-w- c:\windows\system32\igfxrheb.lrc
2011-10-21 15:59 . 2011-10-21 15:59 287232 ----a-w- c:\windows\system32\igfxrfra.lrc
2011-10-21 15:59 . 2011-10-21 15:59 286720 ----a-w- c:\windows\system32\igfxrdeu.lrc
2011-10-21 15:59 . 2011-10-21 15:59 286208 ----a-w- c:\windows\system32\igfxrfin.lrc
2011-10-21 15:58 . 2011-10-21 15:58 286720 ----a-w- c:\windows\system32\igfxrnld.lrc
2011-10-21 15:58 . 2011-10-21 15:58 286720 ----a-w- c:\windows\system32\igfxrcsy.lrc
2011-10-21 15:58 . 2011-10-21 15:58 285696 ----a-w- c:\windows\system32\igfxrdan.lrc
2011-10-21 15:58 . 2011-10-21 15:58 285184 ----a-w- c:\windows\system32\igfxrara.lrc
2011-10-21 15:58 . 2011-10-21 15:58 282624 ----a-w- c:\windows\system32\igfxrcht.lrc
2011-10-21 15:58 . 2011-10-21 15:58 282624 ----a-w- c:\windows\system32\igfxrchs.lrc
2011-10-21 15:58 . 2011-10-21 15:58 126976 ----a-w- c:\windows\system32\igfxcpl.cpl
2011-10-21 15:58 . 2011-10-21 15:58 375808 ----a-w- c:\windows\system32\igfxpph.dll
2011-10-21 15:58 . 2011-10-21 15:58 378368 ----a-w- c:\windows\system32\igfxTMM.dll
2011-10-21 15:58 . 2011-10-21 15:58 28672 ----a-w- c:\windows\system32\igfxexps.dll
2011-10-21 15:57 . 2010-03-23 19:02 62464 ----a-w- c:\windows\system32\igfxsrvc.dll
2011-10-21 15:57 . 2010-03-23 19:01 110080 ----a-w- c:\windows\system32\hccutils.dll
2011-10-21 15:57 . 2011-10-21 15:57 146432 ----a-w- c:\windows\system32\gfxSrvc.dll
2011-10-21 15:57 . 2011-10-21 15:57 4096 ----a-w- c:\windows\system32\IGFXDEVLib.dll
2011-10-21 15:57 . 2011-10-21 15:57 390144 ----a-w- c:\windows\system32\igfxdev.dll
2011-10-21 15:56 . 2011-10-21 15:56 285696 ----a-w- c:\windows\system32\igfxrenu.lrc
2011-10-21 15:56 . 2011-10-21 15:56 9014784 ----a-w- c:\windows\system32\igfxress.dll
2011-10-21 15:56 . 2011-10-21 15:56 142336 ----a-w- c:\windows\system32\igfxdo.dll
2011-10-21 15:52 . 2011-10-21 15:52 24576 ----a-w- c:\windows\SysWow64\igfxexps32.dll
2011-10-21 15:52 . 2011-10-21 15:52 294400 ----a-w- c:\windows\SysWow64\igfxdv32.dll
2011-10-21 15:50 . 2011-10-21 15:50 2177536 ----a-w- c:\windows\system32\igfxcmjit64.dll
2011-10-21 15:50 . 2011-10-21 15:50 171520 ----a-w- c:\windows\SysWow64\igfxcmrt32.dll
2011-10-21 15:50 . 2011-10-21 15:50 1663488 ----a-w- c:\windows\SysWow64\igfxcmjit32.dll
2011-10-21 15:50 . 2011-10-21 15:50 148480 ----a-w- c:\windows\system32\igfxcmrt64.dll
2011-10-20 23:26 . 2011-10-20 23:26 94208 ----a-w- c:\windows\SysWow64\dpl100.dll
2009-04-08 17:31 . 2009-04-08 17:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-12 04:45 . 2008-08-12 04:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 16:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-01-13 7109248]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-01-05 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-10-21 106496]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2009-8-1 2680160]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-26 135664]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [x]
R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-26 135664]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Kontrola siete od spoločnosti Microsoft;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 nmwcdcx64;Nokia USB Generic;c:\windows\system32\drivers\nmwcdcx64.sys [x]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\nmwcdx64.sys [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2314240]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 75356418
*Deregistered* - 75356418
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-26 18:33]
.
2012-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-26 18:33]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 15:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2009-12-24 1736704]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-09-01 323584]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-09-30 621440]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-10-21 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-10-21 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-10-21 416024]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.daemon-search.com/startpage
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com/ie
mLocal Page =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
Trusted Zone: ica.cz\b
FF - ProfilePath - c:\users\Elimato\AppData\Roaming\Mozilla\Firefox\Profiles\xjs2vfrq.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.sk/
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-01-15 19:08:41
ComboFix-quarantined-files.txt 2012-01-15 18:08
.
Pre-Run: 13 420 359 680 bytes free
Post-Run: 13 013 229 568 bytes free
.
- - End Of File - - B9474776E868646F792775C91445FBF4