ComboFix 11-01-20.04 - mmm . 01. 2011 18:14:14.1.2 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3839.2802 [GMT 1:00]
Running from: c:\users\mmm\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Install.exe
c:\progra~2\MYWEBS~1\bar\1.bin\mwsoemon.exe
c:\program files (x86)\FunWebProducts
c:\program files (x86)\MyWebSearch
c:\program files (x86)\MyWebSearch\bar\1.bin\F3BKGERR.JPG
c:\program files (x86)\MyWebSearch\bar\1.bin\F3CJpeg.dll
c:\program files (x86)\MyWebSearch\bar\1.bin\F3DTactl.dll
c:\program files (x86)\MyWebSearch\bar\1.bin\F3HISTSW.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\F3HKSTUB.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\F3HTtpct.dll
c:\program files (x86)\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\F3POPSWT.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
c:\program files (x86)\MyWebSearch\bar\1.bin\F3REGHK.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\F3REPROX.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\F3RESTUB.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\F3SCrctr.dll
c:\program files (x86)\MyWebSearch\bar\1.bin\F3SCHMON.EXE
c:\program files (x86)\MyWebSearch\bar\1.bin\F3SPACER.WMV
c:\program files (x86)\MyWebSearch\bar\1.bin\F3WALLPP.DAT
c:\program files (x86)\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\FWPBUDDY.PNG
c:\program files (x86)\MyWebSearch\bar\1.bin\CHROME.MANIFEST
c:\program files (x86)\MyWebSearch\bar\1.bin\chrome\M3FFXTBR.JAR
c:\program files (x86)\MyWebSearch\bar\1.bin\INSTALL.RDF
c:\program files (x86)\MyWebSearch\bar\1.bin\M3AUXSTB.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\M3DLGHK.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\M3HIGHIN.EXE
c:\program files (x86)\MyWebSearch\bar\1.bin\M3HTml.dll
c:\program files (x86)\MyWebSearch\bar\1.bin\M3IDLE.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
c:\program files (x86)\MyWebSearch\bar\1.bin\M3MEDINT.EXE
c:\program files (x86)\MyWebSearch\bar\1.bin\M3MSG.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\M3SKIN.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
c:\program files (x86)\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
c:\program files (x86)\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
c:\program files (x86)\MyWebSearch\bar\1.bin\M3TPINST.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\MWSMLBTN.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE
c:\program files (x86)\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\MWSOESTB.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE
c:\program files (x86)\MyWebSearch\bar\1.bin\MWSUABTN.DLL
c:\program files (x86)\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
c:\program files (x86)\MyWebSearch\bar\Avatar\COMMON.F3S
c:\program files (x86)\MyWebSearch\bar\Game\CHECKERS.F3S
c:\program files (x86)\MyWebSearch\bar\Game\CHESS.F3S
c:\program files (x86)\MyWebSearch\bar\Game\REVERSI.F3S
c:\program files (x86)\MyWebSearch\bar\icons\CM.ICO
c:\program files (x86)\MyWebSearch\bar\icons\MFC.ICO
c:\program files (x86)\MyWebSearch\bar\icons\PSS.ICO
c:\program files (x86)\MyWebSearch\bar\icons\SMILEY.ICO
c:\program files (x86)\MyWebSearch\bar\icons\WB.ICO
c:\program files (x86)\MyWebSearch\bar\icons\ZWINKY.ICO
c:\program files (x86)\MyWebSearch\bar\Message\COMMON.F3S
c:\program files (x86)\MyWebSearch\bar\Notifier\COMMON.F3S
c:\program files (x86)\MyWebSearch\bar\Notifier\DOG.F3S
c:\program files (x86)\MyWebSearch\bar\Notifier\FISH.F3S
c:\program files (x86)\MyWebSearch\bar\Notifier\KUNGFU.F3S
c:\program files (x86)\MyWebSearch\bar\Notifier\LIFEGARD.F3S
c:\program files (x86)\MyWebSearch\bar\Notifier\MAID.F3S
c:\program files (x86)\MyWebSearch\bar\Notifier\MAILBOX.F3S
c:\program files (x86)\MyWebSearch\bar\Notifier\OPERA.F3S
c:\program files (x86)\MyWebSearch\bar\Notifier\ROBOT.F3S
c:\program files (x86)\MyWebSearch\bar\Notifier\SEDUCT.F3S
c:\program files (x86)\MyWebSearch\bar\Notifier\SURFER.F3S
c:\program files (x86)\MyWebSearch\bar\Overlay\COMMON.F3S
c:\program files (x86)\MyWebSearch\bar\Settings\s_pid.dat
c:\windows\system32\f3PSSavr.scr
c:\windows\SysWow64\f3PSSavr.scr
c:\windows\SysWow64\lsprst7.dll
c:\windows\SysWow64\prsgrc.dll
c:\windows\SysWow64\system32
c:\windows\SysWow64\system32\cis-2.4.dll
c:\windows\SysWow64\system32\issacapi_bs-2.3.dll
c:\windows\SysWow64\system32\issacapi_pe-2.3.dll
c:\windows\SysWow64\system32\issacapi_se-2.3.dll
c:\windows\SysWow64\system32\MACXMLProto.dll
c:\windows\SysWow64\system32\MaDRM.dll
c:\windows\SysWow64\system32\MaJGUILib.dll
c:\windows\SysWow64\system32\MaJUtilLib.dll
c:\windows\SysWow64\system32\MAMACExtract.dll
c:\windows\SysWow64\system32\MASetupCaller.dll
c:\windows\SysWow64\system32\MASetupCleaner.exe
c:\windows\SysWow64\system32\MaXMLProto.dll
c:\windows\SysWow64\system32\MetaStore2.dll
c:\windows\SysWow64\system32\Microsoft.Synchronization.dll
c:\windows\SysWow64\system32\MK_Lyric.dll
c:\windows\SysWow64\system32\MSCLib.dll
c:\windows\SysWow64\system32\MSFLib.dll
c:\windows\SysWow64\system32\MSLUR71.dll
c:\windows\SysWow64\system32\msvcp60.dll
c:\windows\SysWow64\system32\MTTELECHIP.dll
c:\windows\SysWow64\system32\MTXSYNCICON.dll
c:\windows\SysWow64\system32\muzaf1.dll
c:\windows\SysWow64\system32\muzapp.dll
c:\windows\SysWow64\system32\muzapp.exe
c:\windows\SysWow64\system32\muzdecode.ax
c:\windows\SysWow64\system32\muzeffect.ax
c:\windows\SysWow64\system32\muzmp4sp.ax
c:\windows\SysWow64\system32\muzmpgsp.ax
c:\windows\SysWow64\system32\muzoggsp.ax
c:\windows\SysWow64\system32\muzwmts.dll
c:\windows\SysWow64\system32\psapi.dll
c:\windows\SysWow64\system32\Synchronization2.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_MyWebSearchService
((((((((((((((((((((((((( Files Created from 2010-12-21 to 2011-01-21 )))))))))))))))))))))))))))))))
.
2011-01-21 17:18 . 2011-01-21 17:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-21 17:11 . 2011-01-21 17:12 -------- d-----w- C:\32788R22FWJFW
2011-01-20 12:47 . 2011-01-21 13:59 -------- d-----w- c:\program files\trend micro
2011-01-20 12:47 . 2011-01-20 12:47 -------- d-----w- C:\rsit
2010-12-23 15:42 . 2010-12-23 15:42 -------- d-----w- c:\windows\SysWow64\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-15 17:23 . 2010-12-15 14:51 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2010-12-17 06:56 . 2010-12-22 07:58 545 ----a-w- c:\windows\UC.PIF
2010-12-17 06:56 . 2010-12-22 07:58 545 ----a-w- c:\windows\RAR.PIF
2010-12-17 06:56 . 2010-12-22 07:58 545 ----a-w- c:\windows\PKZIP.PIF
2010-12-17 06:56 . 2010-12-22 07:58 545 ----a-w- c:\windows\PKUNZIP.PIF
2010-12-17 06:56 . 2010-12-22 07:58 545 ----a-w- c:\windows\NOCLOSE.PIF
2010-12-17 06:56 . 2010-12-22 07:58 545 ----a-w- c:\windows\LHA.PIF
2010-12-17 06:56 . 2010-12-22 07:58 545 ----a-w- c:\windows\ARJ.PIF
2010-12-15 14:51 . 2010-12-15 14:51 53248 ----a-r- c:\users\mmm\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2010-12-13 10:24 . 2010-12-13 10:24 3024 ----a-w- c:\windows\SysWow64\ealregsnapshot1.reg
2010-12-11 10:45 . 2010-12-11 10:07 2829 ----a-w- c:\windows\War3Unin.pif
2010-12-11 10:45 . 2010-12-11 10:07 139264 ----a-w- c:\windows\War3Unin.exe
2010-11-15 17:26 . 2010-11-15 17:26 5222 ----a-w- c:\programdata\xml5A7E.tmp
2010-11-15 17:26 . 2010-11-15 17:26 2263 ----a-w- c:\programdata\xml5B8A.tmp
2010-11-15 17:26 . 2010-11-15 17:26 13489 ----a-w- c:\programdata\xml5B3B.tmp
2010-11-15 14:26 . 2010-11-15 14:27 2601816 ----a-w- c:\windows\system32\WavesGUILib.dll
2010-11-15 14:26 . 2010-11-15 14:27 518896 ----a-w- c:\windows\system32\SRSTSX64.dll
2010-11-15 14:26 . 2010-11-15 14:27 211184 ----a-w- c:\windows\system32\SRSTSH64.dll
2010-11-15 14:26 . 2010-11-15 14:27 198896 ----a-w- c:\windows\system32\SRSHP64.dll
2010-11-15 14:26 . 2010-11-15 14:27 155888 ----a-w- c:\windows\system32\SRSWOW64.dll
2010-11-15 14:26 . 2010-11-15 14:27 120208 ----a-w- c:\windows\system32\SFSS_APO.dll
2010-11-15 14:26 . 2010-11-15 14:27 81232 ----a-w- c:\windows\system32\SFCOM64.dll
2010-11-15 14:26 . 2010-11-15 14:27 78160 ----a-w- c:\windows\system32\SFAPO64.dll
2010-11-15 14:26 . 2010-11-15 14:27 74064 ----a-w- c:\windows\SysWow64\SFCOM.dll
2010-11-15 14:26 . 2010-11-15 14:27 220496 ----a-w- c:\windows\system32\SFNHK64.dll
2010-11-15 14:26 . 2010-11-15 14:27 1146984 ----a-w- c:\windows\system32\RTSnMg64.cpl
2010-11-15 14:26 . 2010-11-15 14:27 332392 ----a-w- c:\windows\system32\RtlCPAPI64.dll
2010-11-15 14:26 . 2010-11-15 14:27 2048104 ----a-w- c:\windows\system32\RtPgEx64.dll
2010-11-15 14:26 . 2010-11-15 14:27 2511464 ----a-w- c:\windows\system32\drivers\RTKVHD64.sys
2010-11-15 14:26 . 2010-11-15 14:27 2625640 ----a-w- c:\windows\system32\RtkAPO64.dll
2010-11-15 14:26 . 2010-11-15 14:27 149608 ----a-w- c:\windows\system32\RtkCfg64.dll
2010-11-15 14:26 . 2010-11-15 14:27 99016 ----a-w- c:\windows\system32\RTEEL64A.dll
2010-11-15 14:26 . 2010-11-15 14:27 76488 ----a-w- c:\windows\system32\RTEEG64A.dll
2010-11-15 14:26 . 2010-11-15 14:27 601704 ----a-w- c:\windows\system32\RtkApi64.dll
2010-11-15 14:26 . 2010-11-15 14:27 372936 ----a-w- c:\windows\system32\RTEEP64A.dll
2010-11-15 14:26 . 2010-11-15 14:27 201928 ----a-w- c:\windows\system32\RTEED64A.dll
2010-11-15 14:26 . 2010-11-15 14:27 1215592 ----a-w- c:\windows\system32\RTCOM64.dll
2010-11-15 14:26 . 2010-11-15 14:27 79976 ----a-w- c:\windows\system32\RCoInst64.dll
2010-11-15 14:26 . 2010-11-15 14:27 477800 ----a-w- c:\windows\system32\RCoRes64.dat
2010-11-15 14:26 . 2010-11-15 14:27 307920 ----a-w- c:\windows\system32\RP3DHT64.dll
2010-11-15 14:26 . 2010-11-15 14:27 307920 ----a-w- c:\windows\system32\RP3DAA64.dll
2010-11-15 14:26 . 2010-11-15 14:27 334680 ----a-w- c:\windows\system32\MaxxVolumeSDAPO.dll
2010-11-15 14:26 . 2010-11-15 14:27 2197264 ----a-w- c:\windows\system32\MaxxAudioEQ.dll
2010-11-15 14:26 . 2010-11-15 14:27 1756160 ----a-w- c:\windows\system32\MaxxAudioRealtek.dll
2010-11-15 14:26 . 2010-11-15 14:27 334848 ----a-w- c:\windows\system32\MaxxAudioAPO30.dll
2010-11-15 14:26 . 2010-11-15 14:27 318808 ----a-w- c:\windows\system32\MaxxAudioAPO20.dll
2010-11-15 14:26 . 2010-11-15 14:27 474336 ----a-w- c:\windows\system32\DTSVoiceClarityDLL64.dll
2010-11-15 14:26 . 2010-11-15 14:27 338336 ----a-w- c:\windows\system32\FMAPO64.dll
2010-11-15 14:26 . 2010-11-15 14:27 489696 ----a-w- c:\windows\system32\DTSSymmetryDLL64.dll
2010-11-15 14:26 . 2010-11-15 14:27 315616 ----a-w- c:\windows\system32\DTSNeoPCDLL64.dll
2010-11-15 14:26 . 2010-11-15 14:27 268512 ----a-w- c:\windows\system32\DTSLimiterDLL64.dll
2010-11-15 14:26 . 2010-11-15 14:27 265440 ----a-w- c:\windows\system32\DTSGainCompensatorDLL64.dll
2010-11-15 14:26 . 2010-11-15 14:27 1325792 ----a-w- c:\windows\system32\DTSS2SpeakerDLL64.dll
2010-11-15 14:26 . 2010-11-15 14:27 124640 ----a-w- c:\windows\system32\DTSLFXAPO64.dll
2010-11-15 14:26 . 2010-11-15 14:27 124128 ----a-w- c:\windows\system32\DTSGFXAPO64.dll
2010-11-15 14:26 . 2010-11-15 14:27 123616 ----a-w- c:\windows\system32\DTSGFXAPONS64.dll
2010-11-15 14:26 . 2010-11-15 14:27 1178336 ----a-w- c:\windows\system32\DTSS2HeadphoneDLL64.dll
2010-11-15 14:26 . 2010-11-15 14:27 503520 ----a-w- c:\windows\system32\DTSBassEnhancementDLL64.dll
2010-11-15 14:26 . 2010-11-15 14:27 1110240 ----a-w- c:\windows\system32\DTSBoostDLL64.dll
2010-11-15 14:26 . 2010-11-15 14:27 200800 ----a-w- c:\windows\system32\AERTAC64.dll
2010-11-15 14:26 . 2010-11-15 14:27 108960 ----a-w- c:\windows\system32\AERTAR64.dll
2010-11-15 14:26 . 2010-11-15 14:27 1251944 ----a-w- c:\windows\RtlExUpd.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2010-07-26 20568]
R3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2011\RpcAgentSrv.exe [2009-08-17 93848]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [2010-07-26 16392]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-11-15 834544]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-09-07 61008]
.
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF10700.cfxxe" [X]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-15 11474024]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1680976]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://
www.google.sk/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do programu Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\mmm\AppData\Roaming\Mozilla\Firefox\Profiles\wlg53pct.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
- - - - ORPHANS REMOVED - - - -
Wow6432Node-HKLM-Run-NPSStartup - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
.
**************************************************************************
.
Completion time: 2011-01-21 18:26:09 - machine was rebooted
ComboFix-quarantined-files.txt 2011-01-21 17:26
Pre-Run: 29 391 650 816 bytes free
Post-Run: 30 348 955 648 bytes free
- - End Of File - - 4E851566BD457297EF8FA24EC5C697DE