Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

please help...I'm new here, need some help analyzing this combo fix log


  • Please log in to reply
1 reply to this topic

#1 mathewtroutt

mathewtroutt

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:07:41 AM

Posted 05 January 2014 - 01:35 PM

Mod Edit: Moved to proper forum.. ~~ boopme


ComboFix 14-01-04.03 - Mat 01/05/2014  13:07:19.2.2 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.5119.3763 [GMT -5:00]
Running from: c:\users\Mat\Desktop\jump drive\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Mat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HpM3Util.exe
c:\users\Mat\AppData\Roaming\verison.dll
.
.
(((((((((((((((((((((((((   Files Created from 2013-12-05 to 2014-01-05  )))))))))))))))))))))))))))))))
.
.
2014-01-05 18:13 . 2014-01-05 18:13 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-01-05 18:13 . 2014-01-05 18:13 -------- d-----w- c:\users\Public\AppData\Local\temp
2014-01-05 18:13 . 2014-01-05 18:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-01-05 15:01 . 2014-01-05 15:01 86362 ----a-w- c:\programdata\Microsoft\BingDesktop\BingCore\temp\tmp31EA.exe
2014-01-05 04:47 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2FBF200A-0632-4AE8-A4C2-B79C69DBCDD9}\mpengine.dll
2013-12-26 00:58 . 2013-12-26 00:58 456704 ----a-w- c:\programdata\Microsoft\BingDesktop\BingCore\temp\tmpE144.exe
2013-12-23 10:10 . 2013-12-23 10:11 -------- d-----w- c:\users\Mat\AppData\Local\Iccsoft
2013-12-23 10:10 . 2013-12-23 10:10 90710 ----a-w- c:\programdata\Microsoft\BingDesktop\BingCore\temp\tmpEA68.exe
2013-12-20 03:18 . 2013-12-20 03:18 -------- d-----w- c:\users\Mat\AppData\Local\CrashRpt
2013-12-20 02:10 . 2013-12-20 02:12 -------- d-----w- c:\users\Mat\AppData\Roaming\StarTrekPC
2013-12-20 01:59 . 2009-02-24 23:35 255552 ----a-w- c:\windows\SysWow64\drivers\mcdbus.sys
2013-12-20 01:59 . 2009-02-24 23:35 255552 ----a-w- c:\windows\system32\drivers\mcdbus.sys
2013-12-20 01:59 . 2013-12-20 02:00 -------- d-----w- c:\program files (x86)\MagicDisc
2013-12-20 01:53 . 2013-12-20 01:53 -------- d-----w- c:\program files (x86)\Franzis
2013-12-20 01:42 . 2013-12-20 01:42 -------- d-----w- c:\program files\7-Zip
2013-12-20 01:26 . 2013-12-20 01:26 -------- d-----w- c:\users\Mat\AppData\Roaming\mysearchdial
2013-12-20 01:26 . 2013-12-20 01:26 -------- d-----w- c:\program files (x86)\Mysearchdial
2013-12-12 08:03 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2013-12-12 08:03 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2013-12-12 08:03 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
2013-12-12 08:03 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL
2013-12-12 08:03 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll
2013-12-12 05:42 . 2013-10-30 02:32 335360 ----a-w- c:\windows\system32\msieftp.dll
2013-12-10 12:16 . 2013-12-10 12:16 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2013-12-10 12:15 . 2013-12-10 12:17 -------- d-----w- c:\users\Mat\AppData\Local\Adobe
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-03 19:57 . 2013-12-03 19:57 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-12-03 19:57 . 2013-05-14 04:47 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-26 08:03 . 2013-11-26 08:03 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-11-26 08:03 . 2013-11-26 08:03 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-11-26 08:02 . 2013-11-26 08:02 942592 ----a-w- c:\windows\system32\jsIntl.dll
2013-11-26 08:02 . 2013-11-26 08:02 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-11-26 08:02 . 2013-11-26 08:02 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-11-26 08:02 . 2013-11-26 08:02 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-11-26 08:02 . 2013-11-26 08:02 84992 ----a-w- c:\windows\system32\mshtmled.dll
2013-11-26 08:02 . 2013-11-26 08:02 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-11-26 08:02 . 2013-11-26 08:02 81408 ----a-w- c:\windows\system32\icardie.dll
2013-11-26 08:02 . 2013-11-26 08:02 774144 ----a-w- c:\windows\system32\jscript.dll
2013-11-26 08:02 . 2013-11-26 08:02 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-11-26 08:02 . 2013-11-26 08:02 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-11-26 08:02 . 2013-11-26 08:02 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-11-26 08:02 . 2013-11-26 08:02 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2013-11-26 08:02 . 2013-11-26 08:02 626176 ----a-w- c:\windows\system32\msfeeds.dll
2013-11-26 08:02 . 2013-11-26 08:02 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-11-26 08:02 . 2013-11-26 08:02 62464 ----a-w- c:\windows\system32\pngfilt.dll
2013-11-26 08:02 . 2013-11-26 08:02 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2013-11-26 08:02 . 2013-11-26 08:02 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-11-26 08:02 . 2013-11-26 08:02 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2013-11-26 08:02 . 2013-11-26 08:02 548352 ----a-w- c:\windows\system32\vbscript.dll
2013-11-26 08:02 . 2013-11-26 08:02 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-11-26 08:02 . 2013-11-26 08:02 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2013-11-26 08:02 . 2013-11-26 08:02 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-11-26 08:02 . 2013-11-26 08:02 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-11-26 08:02 . 2013-11-26 08:02 48128 ----a-w- c:\windows\system32\imgutil.dll
2013-11-26 08:02 . 2013-11-26 08:02 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-11-26 08:02 . 2013-11-26 08:02 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2013-11-26 08:02 . 2013-11-26 08:02 413696 ----a-w- c:\windows\system32\html.iec
2013-11-26 08:02 . 2013-11-26 08:02 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-11-26 08:02 . 2013-11-26 08:02 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-11-26 08:02 . 2013-11-26 08:02 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-11-26 08:02 . 2013-11-26 08:02 337408 ----a-w- c:\windows\SysWow64\html.iec
2013-11-26 08:02 . 2013-11-26 08:02 30208 ----a-w- c:\windows\system32\licmgr10.dll
2013-11-26 08:02 . 2013-11-26 08:02 296960 ----a-w- c:\windows\system32\dxtrans.dll
2013-11-26 08:02 . 2013-11-26 08:02 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2013-11-26 08:02 . 2013-11-26 08:02 247808 ----a-w- c:\windows\system32\msls31.dll
2013-11-26 08:02 . 2013-11-26 08:02 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-11-26 08:02 . 2013-11-26 08:02 243200 ----a-w- c:\windows\system32\webcheck.dll
2013-11-26 08:02 . 2013-11-26 08:02 235520 ----a-w- c:\windows\system32\url.dll
2013-11-26 08:02 . 2013-11-26 08:02 235008 ----a-w- c:\windows\system32\elshyph.dll
2013-11-26 08:02 . 2013-11-26 08:02 195584 ----a-w- c:\windows\system32\msrating.dll
2013-11-26 08:02 . 2013-11-26 08:02 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2013-11-26 08:02 . 2013-11-26 08:02 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-11-26 08:02 . 2013-11-26 08:02 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-11-26 08:02 . 2013-11-26 08:02 147968 ----a-w- c:\windows\system32\occache.dll
2013-11-26 08:02 . 2013-11-26 08:02 143872 ----a-w- c:\windows\system32\wextract.exe
2013-11-26 08:02 . 2013-11-26 08:02 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2013-11-26 08:02 . 2013-11-26 08:02 13824 ----a-w- c:\windows\system32\mshta.exe
2013-11-26 08:02 . 2013-11-26 08:02 135680 ----a-w- c:\windows\system32\iepeers.dll
2013-11-26 08:02 . 2013-11-26 08:02 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2013-11-26 08:02 . 2013-11-26 08:02 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2013-11-26 08:02 . 2013-11-26 08:02 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-11-26 08:02 . 2013-11-26 08:02 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-11-26 08:02 . 2013-11-26 08:02 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-11-26 08:02 . 2013-11-26 08:02 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-11-26 08:02 . 2013-11-26 08:02 105984 ----a-w- c:\windows\system32\iesysprep.dll
2013-11-26 08:02 . 2013-11-26 08:02 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-11-26 08:02 . 2013-11-26 08:02 101376 ----a-w- c:\windows\system32\inseng.dll
2013-11-19 08:33 . 2010-11-21 03:27 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-11-09 04:09 . 2013-11-09 04:09 2179072 ----a-w- c:\programdata\Microsoft\BingDesktop\BingCore\BingDesktopCore.dll
2013-10-14 23:00 . 2013-11-26 08:05 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
2013-10-12 02:30 . 2013-11-14 03:23 830464 ----a-w- c:\windows\system32\nshwfp.dll
2013-10-12 02:29 . 2013-11-14 03:23 859648 ----a-w- c:\windows\system32\IKEEXT.DLL
2013-10-12 02:29 . 2013-11-14 03:23 324096 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2013-10-12 02:03 . 2013-11-14 03:23 656896 ----a-w- c:\windows\SysWow64\nshwfp.dll
2013-10-12 02:01 . 2013-11-14 03:23 216576 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL
2013-10-08 12:50 . 2013-11-24 22:53 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Iccsoft"="c:\users\Mat\AppData\Local\Iccsoft\Desktopserv8.dll" [2013-12-23 21504]
"crsscmgr"="c:\users\Mat\AppData\Roaming\Adobe\crsscmgr\crssc.exe" [2013-12-26 456704]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-22 59720]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-09-05 958576]
.
c:\users\Mat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files (x86)\MagicDisc\MagicDisc.exe [2013-12-19 576000]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
CodecPackTrayMenu.lnk - c:\windows\SysWOW64\C2MP\TrayMenu.exe [2013-3-19 704008]
CodecPackUpdateChecker.lnk - c:\windows\SysWOW64\C2MP\UpdateChecker.exe [2013-3-20 46848]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R1 uidlcemv;uidlcemv;c:\windows\system32\drivers\uidlcemv.sys;c:\windows\SYSNATIVE\drivers\uidlcemv.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 netr28x;Ralink 802.11n Wireless Driver for Windows Vista;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x]
R3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 WMP110v2;Linksys WMP110 RangePlus Wireless PCI Adapter Driver for Windows Vista;c:\windows\system32\DRIVERS\WMP110v2.sys;c:\windows\SYSNATIVE\DRIVERS\WMP110v2.sys [x]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{2D46B6DC-2207-486B-B523-A557E6D54B47}]
start [BU]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-06 00:15 1210320 ----a-w- c:\program files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-01-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-03-09 02:34]
.
2014-01-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-03-09 02:34]
.
2014-01-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4031965386-4186482130-2057420510-1001Core.job
- c:\users\Mat\AppData\Local\Google\Update\GoogleUpdate.exe [2013-05-14 06:39]
.
2014-01-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4031965386-4186482130-2057420510-1001UA.job
- c:\users\Mat\AppData\Local\Google\Update\GoogleUpdate.exe [2013-05-14 06:39]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1BingDesktopOverlays]
@="{B82655E9-B81D-4A97-8154-0D84A4C048E4}"
[HKEY_CLASSES_ROOT\CLSID\{B82655E9-B81D-4A97-8154-0D84A4C048E4}]
2013-11-09 04:09 2492416 ----a-w- c:\programdata\Microsoft\BingDesktop\BingCore\BingDesktopOverlays.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2013-07-15 7833120]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2013-07-15 1833504]
"FAHConsole"="c:\program files\File Association Helper\FAHConsole.exe" [2013-09-26 216248]
"Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2012-09-20 1832760]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://start.mysearchdial.com/?f=1&a=irmsd1202&cd=2XzuyEtN2Y1L1QzutDtDtBtAyCzytD0AzytByCyCtCyEyBtDtN0D0Tzu0SyBtCzytN1L2XzutN1L1CzutCyD1B1P1R&cr=997287599&ir=
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.1
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_152_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_152_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2014-01-05  13:15:09
ComboFix-quarantined-files.txt  2014-01-05 18:15
ComboFix2.txt  2013-11-16 02:50
.
Pre-Run: 126,858,489,856 bytes free
Post-Run: 126,772,748,288 bytes free
.
- - End Of File - - C7103410DDBD67F20B9D8DC21BA34EEB
A36C5E4F47E84449FF07ED3517B43A31

Edited by boopme, 05 January 2014 - 01:44 PM.


BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 38,766 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:08:41 AM

Posted 10 January 2014 - 09:23 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Nothing suspicious was found on the ComboFix log.
Run these tools and let me know what problems you are having with this computer.

Search and delete the AdWare, PUP (Potentially Unwanted Program) installed on your computer.

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the Report button and the report will open in Notepad.
IMPORTANT
  • If you click the Clean button all items listed in the report will be removed.
If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Check off the element(s) you wish to keep.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Sn].txt (n is a number).
thisisujrt.gif Please download
Junkware Removal Tool to your Desktop.
  • Please close your security software to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click it and select Run as administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete, depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
  • Please post the contents of JRT.txt into your reply.
===

Please download and run this DDS Scanning Tool. Nothing will be deleted. It will just give me some additional information about your system.

Download DDS by sUBs from one of the following links, if you no longer have it available. Save it to your desktop.

1: DDS.scr (Not recommended if you use Chrome to download this .scr file. Use the other options.)
2: DDS.pif
3: DDS.COM

Double click on the DDS icon, allow it to run.
A small box will open, with an explanation about the tool. No input is needed, the scan is running.
Notepad will open with the results.
Follow the instructions that pop up for posting the results.
Please note: You may have to disable any script protection running if the scan fails to run.

dds_scr.gif

Please just paste the contents of the DDS.txt log in your next post. DO NOT attach the log.
===

Third party programs if not up to date can be the cause of infiltration an infection.

Please restart the computer before running this security check.

Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
p.s.
If the SecurityCheck program fails to run for any reason, run it as an Administrator.
===

Please paste the logs in your next reply, DO NOT ATTACH THEM




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users