Combo fix text
ComboFix 11-03-06.01 - Mike 03/06/2011 17:41:18.1.2 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.4092.2198 [GMT -6:00]
Running from: c:\users\Mike\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\ClickPotatoLite
c:\program files (x86)\ClickPotatoLite\bin\10.0.659.0\firefox\extensions\install.rdf
c:\program files (x86)\ClickPotatoLite\bin\10.0.659.0\LaunchHelp.dll
c:\programdata\ClickPotatoLiteSA
c:\programdata\ClickPotatoLiteSA\ClickPotatoLiteSA.dat
c:\programdata\ClickPotatoLiteSA\ClickPotatoLiteSAAbout.mht
c:\programdata\ClickPotatoLiteSA\ClickPotatoLiteSAEULA.mht
c:\programdata\Microsoft\Windows\Start Menu\Programs\ClickPotato
c:\programdata\Microsoft\Windows\Start Menu\Programs\ClickPotato\About Us.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\ClickPotato\ClickPotato Customer Support.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\ClickPotato\ClickPotato Uninstall Instructions.lnk
c:\users\Mike\AppData\Roaming\ClickPotatoLite
F:\autorun.inf
.
.
((((((((((((((((((((((((( Files Created from 2011-02-06 to 2011-03-06 )))))))))))))))))))))))))))))))
.
.
2011-03-06 23:47 . 2011-03-06 23:47 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-03-04 17:32 . 2011-02-11 07:30 7947600 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{73BC8CF1-5AE7-45BD-BA7F-13EECA30A3FA}\mpengine.dll
2011-03-04 06:55 . 2011-03-04 06:55 -------- d-----w- c:\program files (x86)\Wide Angle Software
2011-03-03 17:05 . 2008-04-17 18:12 126312 ----a-w- c:\windows\system32\GEARAspi64.dll
2011-03-03 17:05 . 2008-04-17 18:12 107368 ----a-w- c:\windows\SysWow64\GEARAspi.dll
2011-03-03 17:05 . 2011-03-03 17:05 -------- dc----w- c:\windows\system32\DRVSTORE
2011-03-03 17:05 . 2009-05-18 19:17 34152 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-03-03 17:04 . 2011-03-03 17:04 -------- d-----w- c:\program files\iPod
2011-03-03 17:03 . 2011-03-03 17:05 -------- d-----w- c:\programdata\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2011-03-03 17:03 . 2011-03-03 17:05 -------- d-----w- c:\program files\iTunes
2011-03-03 17:03 . 2011-03-03 17:05 -------- d-----w- c:\program files (x86)\iTunes
2011-03-03 17:03 . 2011-03-03 17:03 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2011-03-03 17:03 . 2011-03-03 17:03 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2011-03-03 17:03 . 2011-03-03 17:03 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2011-03-03 17:03 . 2011-03-03 17:03 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2011-03-03 17:03 . 2011-03-03 17:03 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2011-03-03 17:03 . 2011-03-03 17:03 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2011-03-03 17:03 . 2011-03-03 17:03 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2011-03-03 17:02 . 2011-03-03 17:03 -------- d-----w- c:\program files (x86)\QuickTime
2011-03-03 17:02 . 2011-03-03 17:03 -------- d-----w- c:\programdata\Apple Computer
2011-03-03 17:02 . 2011-03-03 17:02 -------- d-----w- c:\program files (x86)\Apple Software Update
2011-03-03 16:59 . 2011-03-03 16:59 -------- d-----w- c:\program files\Common Files\Apple
2011-03-03 16:59 . 2011-03-03 16:59 -------- d-----w- c:\program files\Bonjour
2011-03-03 16:59 . 2011-03-03 16:59 -------- d-----w- c:\program files (x86)\Bonjour
2011-03-03 16:59 . 2011-03-03 17:04 -------- d-----w- c:\program files (x86)\Common Files\Apple
2011-03-03 16:59 . 2011-03-03 16:59 -------- d-----w- c:\programdata\Apple
2011-03-03 05:39 . 2011-03-03 05:39 -------- d-----w- c:\program files (x86)\Common Files\NSV
2011-02-27 09:45 . 2011-02-27 09:45 -------- d-----w- c:\program files (x86)\uTorrent
2011-02-27 04:50 . 2011-02-27 04:50 -------- d-----w- c:\windows\system32\SRSLabs
2011-02-27 04:46 . 2011-02-27 04:46 -------- d-----w- c:\windows\system32\EventProviders
2011-02-25 15:24 . 2011-02-25 15:24 -------- d-----w- c:\program files (x86)\Common Files\DivX Shared
2011-02-25 15:23 . 2011-02-25 15:24 -------- d-----w- c:\program files (x86)\DivX
2011-02-25 15:22 . 2011-02-25 15:24 -------- d-----w- c:\programdata\DivX
2011-02-25 09:11 . 2010-09-20 12:14 316416 ----a-w- c:\windows\system32\msshsq.dll
2011-02-25 09:11 . 2010-09-20 09:25 231936 ----a-w- c:\windows\SysWow64\msshsq.dll
2011-02-25 09:05 . 2009-11-08 16:55 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2011-02-25 09:05 . 2009-11-08 16:55 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2011-02-25 09:05 . 2009-11-08 16:55 444752 ----a-w- c:\windows\system32\mscoree.dll
2011-02-25 09:05 . 2009-11-08 16:55 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2011-02-25 09:05 . 2009-11-08 16:55 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2011-02-25 09:05 . 2009-11-08 16:55 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2011-02-25 09:05 . 2009-11-08 16:55 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2011-02-25 09:05 . 2009-11-08 16:55 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-02-25 09:05 . 2009-11-08 16:55 48960 ----a-w- c:\windows\system32\netfxperf.dll
2011-02-25 09:05 . 2009-11-08 16:55 1942856 ----a-w- c:\windows\system32\dfshim.dll
2011-02-25 07:43 . 2011-02-25 07:44 -------- d-----w- c:\program files (x86)\GameSpy Arcade
2011-02-25 05:18 . 2011-02-25 07:46 -------- d-----w- c:\program files (x86)\GOG.com
2011-02-25 05:03 . 2011-02-25 05:03 -------- d-----w- c:\program files (x86)\GOG.com Downloader
2011-02-25 05:03 . 2011-02-25 05:03 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR
2011-02-25 04:37 . 2011-02-25 04:37 -------- d-----w- c:\program files (x86)\VideoLAN
2011-02-25 04:11 . 2011-02-25 04:50 -------- d-----w- C:\Youcam
2011-02-24 09:34 . 2008-06-20 01:16 49160 ----a-w- c:\windows\system32\infocardcpl.cpl
2011-02-24 09:34 . 2008-06-20 01:14 37384 ----a-w- c:\windows\SysWow64\infocardcpl.cpl
2011-02-24 09:34 . 2008-06-20 01:16 11264 ----a-w- c:\windows\system32\icardres.dll
2011-02-24 09:34 . 2008-06-20 01:14 11264 ----a-w- c:\windows\SysWow64\icardres.dll
2011-02-24 09:34 . 2008-06-20 01:14 781344 ----a-w- c:\windows\SysWow64\PresentationNative_v0300.dll
2011-02-24 09:34 . 2008-06-20 01:17 1168928 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2011-02-24 09:34 . 2008-06-20 01:16 167432 ----a-w- c:\windows\system32\infocardapi.dll
2011-02-24 09:34 . 2008-06-20 01:16 1383936 ----a-w- c:\windows\system32\icardagt.exe
2011-02-24 09:34 . 2008-06-20 01:14 97800 ----a-w- c:\windows\SysWow64\infocardapi.dll
2011-02-24 09:34 . 2008-06-20 01:14 622080 ----a-w- c:\windows\SysWow64\icardagt.exe
2011-02-24 09:34 . 2008-06-20 01:17 126520 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2011-02-24 09:34 . 2008-06-20 01:14 105016 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2011-02-24 09:27 . 2008-07-27 18:03 158720 ----a-w- c:\windows\SysWow64\mscorier.dll
2011-02-24 09:27 . 2008-07-27 18:01 158208 ----a-w- c:\windows\system32\mscorier.dll
2011-02-24 09:27 . 2008-07-27 18:01 76288 ----a-w- c:\windows\system32\mscories.dll
2011-02-24 09:27 . 2008-07-27 18:03 83968 ----a-w- c:\windows\SysWow64\mscories.dll
2011-02-24 09:14 . 2009-08-01 06:27 201184 ----a-w- c:\windows\SysWow64\winrm.vbs
2011-02-24 05:05 . 2011-02-24 05:05 -------- d--h--w- c:\program files (x86)\InstallJammer Registry
2011-02-23 21:08 . 2011-02-23 21:08 -------- d-----w- c:\programdata\IObit
2011-02-23 21:08 . 2011-02-23 21:08 -------- d-----w- c:\program files (x86)\IObit
2011-02-23 17:47 . 2011-02-23 17:47 -------- d-----w- c:\program files (x86)\MSECache
2011-02-23 17:15 . 2008-06-26 02:25 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2011-02-23 17:15 . 2008-06-26 01:45 12240896 ----a-w- c:\windows\SysWow64\NlsLexicons0007.dll
2011-02-23 17:15 . 2008-06-26 02:25 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2011-02-23 17:15 . 2008-06-26 01:45 2644480 ----a-w- c:\windows\SysWow64\NlsLexicons0009.dll
2011-02-23 17:15 . 2008-06-26 03:56 1361920 ----a-w- c:\windows\system32\NaturalLanguage6.dll
2011-02-23 17:15 . 2008-06-26 03:29 801280 ----a-w- c:\windows\SysWow64\NaturalLanguage6.dll
2011-02-23 17:07 . 2011-01-06 10:52 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-02-23 17:05 . 2009-06-04 12:59 2423296 ----a-w- c:\windows\system32\mstscax.dll
2011-02-23 17:04 . 2009-03-03 04:57 718336 ----a-w- c:\windows\system32\rpcss.dll
2011-02-23 17:02 . 2008-06-23 02:14 1245184 ----a-w- c:\windows\system32\WMNetMgr.dll
2011-02-23 17:01 . 2009-06-10 12:25 202752 ----a-w- c:\windows\system32\wkssvc.dll
2011-02-23 17:00 . 2010-01-21 16:34 72192 ----a-w- c:\windows\system32\l3codeca.acm
2011-02-23 17:00 . 2010-01-21 15:59 62464 ----a-w- c:\windows\SysWow64\l3codeca.acm
2011-02-23 17:00 . 2010-04-16 16:41 622080 ----a-w- c:\windows\system32\usp10.dll
2011-02-23 17:00 . 2010-04-16 16:10 501760 ----a-w- c:\windows\SysWow64\usp10.dll
2011-02-23 16:58 . 2008-09-18 04:56 147456 ----a-w- c:\windows\SysWow64\Faultrep.dll
2011-02-23 16:58 . 2008-09-18 04:47 120832 ----a-w- c:\windows\system32\wersvc.dll
2011-02-23 16:58 . 2008-09-18 04:47 176640 ----a-w- c:\windows\system32\Faultrep.dll
2011-02-23 16:58 . 2010-11-06 04:35 854528 ----a-w- c:\windows\system32\schedsvc.dll
2011-02-23 16:58 . 2010-11-06 11:10 357376 ----a-w- c:\windows\SysWow64\taskschd.dll
2011-02-23 16:58 . 2010-11-06 04:35 499712 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-02-23 16:58 . 2010-11-06 04:35 655872 ----a-w- c:\windows\system32\taskschd.dll
2011-02-23 16:58 . 2010-11-04 21:16 267776 ----a-w- c:\windows\system32\taskeng.exe
2011-02-23 16:58 . 2010-11-06 11:10 270336 ----a-w- c:\windows\SysWow64\taskcomp.dll
2011-02-23 16:58 . 2010-11-06 04:35 410112 ----a-w- c:\windows\system32\taskcomp.dll
2011-02-23 16:58 . 2010-11-05 00:53 171520 ----a-w- c:\windows\SysWow64\taskeng.exe
2011-02-23 16:45 . 2011-02-23 16:45 -------- d-----w- c:\program files (x86)\MSXML 4.0
2011-02-23 16:44 . 2010-02-20 23:44 32768 ----a-w- c:\windows\system32\nshhttp.dll
2011-02-23 16:44 . 2010-02-20 23:39 24064 ----a-w- c:\windows\SysWow64\nshhttp.dll
2011-02-23 16:44 . 2010-02-20 21:40 610304 ----a-w- c:\windows\system32\drivers\http.sys
2011-02-23 16:44 . 2010-02-20 23:42 33792 ----a-w- c:\windows\system32\httpapi.dll
2011-02-23 16:44 . 2010-02-20 23:37 31232 ----a-w- c:\windows\SysWow64\httpapi.dll
2011-02-23 16:43 . 2010-04-14 18:33 101376 ----a-w- c:\windows\system32\MSNP.ax
2011-02-23 16:43 . 2010-04-14 18:33 227328 ----a-w- c:\windows\system32\mpg2splt.ax
2011-02-23 16:43 . 2010-04-14 17:46 80896 ----a-w- c:\windows\SysWow64\MSNP.ax
2011-02-23 16:43 . 2010-04-14 17:45 177664 ----a-w- c:\windows\SysWow64\mpg2splt.ax
2011-02-23 16:43 . 2008-04-23 05:05 73216 ----a-w- c:\windows\system32\MSDvbNP.ax
2011-02-23 16:43 . 2008-04-23 04:41 57856 ----a-w- c:\windows\SysWow64\MSDvbNP.ax
2011-02-23 16:43 . 2010-04-14 18:35 375808 ----a-w- c:\windows\system32\psisdecd.dll
2011-02-23 16:43 . 2010-04-14 17:47 293376 ----a-w- c:\windows\SysWow64\psisdecd.dll
2011-02-23 16:43 . 2010-04-14 17:47 217088 ----a-w- c:\windows\SysWow64\psisrndr.ax
2011-02-23 16:43 . 2010-04-14 18:35 289792 ----a-w- c:\windows\system32\psisrndr.ax
2011-02-23 16:43 . 2010-04-14 18:35 558592 ----a-w- c:\windows\system32\EncDec.dll
2011-02-23 16:43 . 2010-04-14 17:46 428544 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-02-23 16:42 . 2008-04-30 05:56 589824 ----a-w- c:\program files\Common Files\System\msadc\msadce.dll
2011-02-23 16:42 . 2008-04-30 05:36 454656 ----a-w- c:\program files (x86)\Common Files\System\msadc\msadce.dll
2011-02-23 08:07 . 2011-02-25 15:24 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird
2011-02-23 07:45 . 2011-02-23 07:45 5236 ----a-w- c:\windows\SysWow64\PerfStringBackup.TMP
2011-02-23 07:25 . 2011-02-23 07:25 -------- d-----w- c:\program files (x86)\ActivIdentity
2011-02-23 07:25 . 2011-02-23 07:33 -------- d-----w- c:\program files\ActivIdentity
2011-02-23 07:25 . 2011-02-23 07:25 -------- d-----w- c:\program files\Common Files\ActivIdentity
2011-02-23 07:24 . 2011-02-23 07:24 -------- d-sh--w- c:\windows\ftpcache
2011-02-23 07:21 . 2009-12-23 12:43 171520 ----a-w- c:\windows\SysWow64\wintrust.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1555968]
"Google Update"="c:\users\Mike\AppData\Local\Google\Update\GoogleUpdate.exe" [2011-02-23 136176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UCam_Menu"="c:\program files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"QPService"="c:\program files (x86)\HP\QuickPlay\QPService.exe" [2008-04-24 468264]
"QlbCtrl.exe"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"HP Health Check Scheduler"="c:\program files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752]
"SunJavaUpdateSched"="c:\program files (x86)\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"IObit Security 360"="c:\program files (x86)\IObit\IObit Security 360\IS360tray.exe" [2010-06-12 1280344]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-02-15 1230704]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-03-02 421160]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
ActivClient Agent.lnk - c:\program files\ActivIdentity\ActivClient\acsagent.exe [2009-6-3 164904]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 40832]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-25 72064]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
R3 S3XXx64;SCR3xx USB SmartCardReader64;c:\windows\system32\DRIVERS\S3XXx64.sys [2010-01-07 68224]
S2 ac.sharedstore;ActivIdentity Shared Store Service;c:\program files\Common Files\ActivIdentity\ac.sharedstore.exe [2009-06-03 277032]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_48fbb870\AESTSr64.exe [2008-02-12 86016]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2008-03-19 23040]
S2 IS360service;IS360service;c:\program files (x86)\IObit\IObit Security 360\IS360srv.exe [2010-06-12 312152]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-03-26 341328]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files (x86)\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-02-07 193840]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2008-01-24 60928]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-04-01 120720]
S3 NETw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\NETw5v64.sys [2008-11-17 4751360]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2008-05-23 54816]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-497396581-4044696950-189682976-1000Core.job
- c:\users\Mike\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-23 06:19]
.
2011-03-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-497396581-4044696950-189682976-1000UA.job
- c:\users\Mike\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-23 06:19]
.
2011-03-06 c:\windows\Tasks\User_Feed_Synchronization-{2DC63420-943A-4D79-95FB-5E63EA1FB9C8}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:50]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="%ProgramFiles%\Windows Defender\MSASCui.exe -hide" [X]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1220392]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2008-01-24 685568]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 1436224]
"acevents"="c:\program files\ActivIdentity\ActivClient\acevents.exe" [2009-06-03 196648]
"accrdsub"="c:\program files\ActivIdentity\ActivClient\accrdsub.exe" [2009-06-03 483880]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-07-22 450048]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-10-03 16395880]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uStart Page =
https://ecampus.phoenix.edu/portal/portal/public/login.aspx
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb
mLocal Page = %SystemRoot%\system32\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\d37vehjj.default\
FF - prefs.js: browser.startup.homepage - hxxps://ecampus.phoenix.edu/portal/portal/public/login.aspx
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files (x86)\DivX\DivX Plus Web Player\firefox\html5video
FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - c:\program files (x86)\DivX\DivX Plus Web Player\firefox\wpa
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-(Default) - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@SACL=
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Control]
@SACL=
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\EnableFullPage]
@SACL=
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Implemented Categories]
@SACL=
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@SACL=
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@SACL=
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@SACL=
@="ShockwaveFlash.ShockwaveFlash.9"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Programmable]
@SACL=
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@SACL=
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@SACL=
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@SACL=
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@SACL=
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@SACL=
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Control]
@SACL=
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@SACL=
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@SACL=
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Programmable]
@SACL=
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@SACL=
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@SACL=
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@SACL=
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@SACL=
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}]
@Denied: (A 2) (Everyone)
@SACL=
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil9e.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\Elevation]
@SACL=
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\LocalServer32]
@SACL=
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil9e.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\TypeLib]
@SACL=
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}]
@Denied: (A 2) (Everyone)
@SACL=
@="IFlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32]
@SACL=
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib]
@SACL=
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@SACL=
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@SACL=
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@SACL=
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@SACL=
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\program files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
c:\program files (x86)\CyberLink\Shared Files\RichVideo.exe
c:\program files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
.
**************************************************************************
.
Completion time: 2011-03-06 17:54:41 - machine was rebooted
ComboFix-quarantined-files.txt 2011-03-06 23:54
.
Pre-Run: 208,647,507,968 bytes free
Post-Run: 209,312,182,272 bytes free
.
- - End Of File - - 37C10366B55957D78F460CF0A0133C7A
Edited by gringo_pr, 08 March 2011 - 02:57 PM.