ComboFix 14-04-29.01 - NRMBC 04/29/2014 18:20:25.1.2 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4095.3101 [GMT -4:00] Running from: c:\users\NRMBC\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Enabled/Outdated* {641105E6-77ED-3F35-A304-765193BCB75F} SP: Microsoft Security Essentials *Enabled/Outdated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} . [i] ADS - Windows: deleted 128 bytes in 1 streams. [/i] . ((((((((((((((((((((((((( Files Created from 2014-03-28 to 2014-04-29 ))))))))))))))))))))))))))))))) . . 2014-04-28 21:51 . 2014-04-28 21:53 -------- d-----w- C:\FRST 2014-04-27 15:58 . 2014-04-27 15:58 -------- d-----w- c:\windows\Migration 2014-04-27 15:11 . 2014-02-04 02:35 190912 ----a-w- c:\windows\system32\drivers\storport.sys 2014-04-27 15:11 . 2014-02-04 02:35 274880 ----a-w- c:\windows\system32\drivers\msiscsi.sys 2014-04-27 15:11 . 2014-02-04 02:35 27584 ----a-w- c:\windows\system32\drivers\Diskdump.sys 2014-04-27 15:11 . 2014-02-04 02:28 2048 ----a-w- c:\windows\system32\iologmsg.dll 2014-04-27 15:11 . 2014-02-04 02:00 2048 ----a-w- c:\windows\SysWow64\iologmsg.dll 2014-04-27 15:10 . 2014-03-04 09:44 362496 ----a-w- c:\windows\system32\wow64win.dll 2014-04-27 15:10 . 2014-03-04 09:44 243712 ----a-w- c:\windows\system32\wow64.dll 2014-04-27 15:10 . 2014-03-04 09:44 13312 ----a-w- c:\windows\system32\wow64cpu.dll 2014-04-27 15:10 . 2014-03-04 09:44 16384 ----a-w- c:\windows\system32\ntvdm64.dll 2014-04-27 15:10 . 2014-03-04 09:44 1163264 ----a-w- c:\windows\system32\kernel32.dll 2014-04-27 15:10 . 2014-03-04 09:17 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll 2014-04-27 15:10 . 2014-03-04 09:16 25600 ----a-w- c:\windows\SysWow64\setup16.exe 2014-04-27 15:10 . 2014-03-04 09:16 5120 ----a-w- c:\windows\SysWow64\wow32.dll 2014-04-27 15:10 . 2014-03-04 08:09 7680 ----a-w- c:\windows\SysWow64\instnm.exe 2014-04-27 15:10 . 2014-03-04 08:09 2048 ----a-w- c:\windows\SysWow64\user.exe 2014-04-27 15:10 . 2014-01-24 02:37 1684928 ----a-w- c:\windows\system32\drivers\ntfs.sys 2014-04-27 14:46 . 2014-04-29 22:27 -------- d-----w- c:\windows\system32\wbem\repository 2014-04-27 13:51 . 2014-04-27 13:52 -------- d-----w- C:\e54ef2af26de7719e97a4afc98cf 2014-04-06 16:07 . 2014-04-06 16:07 -------- d-----w- C:\83f1bf16e23646151585178c 2014-04-06 14:50 . 2014-02-17 18:30 1031560 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{129C35F6-8A55-4449-B49C-B9844EDCBE6B}\gapaengine.dll 2014-04-06 14:50 . 2014-03-07 04:43 10521840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CB3B2618-5579-4624-A413-A40EB4A38927}\mpengine.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-04-28 22:50 . 2012-04-03 16:34 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-04-28 22:50 . 2012-02-28 00:33 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-04-27 15:55 . 2012-02-28 01:57 90655440 ----a-w- c:\windows\system32\MRT.exe 2014-03-07 04:43 . 2014-03-30 13:51 10521840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2014-03-04 09:17 . 2014-04-27 15:10 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2014-02-23 07:12 . 2014-03-16 16:17 17847808 ----a-w- c:\windows\system32\mshtml.dll 2014-02-23 06:54 . 2014-03-16 16:17 2334720 ----a-w- c:\windows\system32\jscript9.dll 2014-02-23 06:52 . 2014-03-16 16:17 10926592 ----a-w- c:\windows\system32\ieframe.dll 2014-02-23 06:48 . 2014-03-16 16:17 1347072 ----a-w- c:\windows\system32\urlmon.dll 2014-02-23 06:48 . 2014-03-16 16:17 1392128 ----a-w- c:\windows\system32\wininet.dll 2014-02-23 06:46 . 2014-03-16 16:17 1494528 ----a-w- c:\windows\system32\inetcpl.cpl 2014-02-23 06:46 . 2014-03-16 16:17 237056 ----a-w- c:\windows\system32\url.dll 2014-02-23 06:46 . 2014-03-16 16:17 86016 ----a-w- c:\windows\system32\jsproxy.dll 2014-02-23 06:45 . 2014-03-16 16:17 173056 ----a-w- c:\windows\system32\ieUnatt.exe 2014-02-23 06:45 . 2014-03-16 16:17 816640 ----a-w- c:\windows\system32\jscript.dll 2014-02-23 06:45 . 2014-03-16 16:17 599040 ----a-w- c:\windows\system32\vbscript.dll 2014-02-23 06:44 . 2014-03-16 16:17 729088 ----a-w- c:\windows\system32\msfeeds.dll 2014-02-23 06:44 . 2014-03-16 16:17 2147840 ----a-w- c:\windows\system32\iertutil.dll 2014-02-23 06:44 . 2014-03-16 16:17 96768 ----a-w- c:\windows\system32\mshtmled.dll 2014-02-23 06:44 . 2014-03-16 16:17 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2014-02-23 06:43 . 2014-03-16 16:17 248320 ----a-w- c:\windows\system32\ieui.dll 2014-02-23 05:47 . 2014-03-16 16:17 1806848 ----a-w- c:\windows\SysWow64\jscript9.dll 2014-02-23 05:40 . 2014-03-16 16:17 1129472 ----a-w- c:\windows\SysWow64\wininet.dll 2014-02-23 05:39 . 2014-03-16 16:17 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2014-02-23 05:38 . 2014-03-16 16:17 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2014-02-23 05:37 . 2014-03-16 16:17 421376 ----a-w- c:\windows\SysWow64\vbscript.dll 2014-02-23 05:36 . 2014-03-16 16:17 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb 2014-02-17 18:30 . 2012-06-17 14:03 1031560 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2014-02-07 01:23 . 2014-03-16 14:06 3156480 ----a-w- c:\windows\system32\win32k.sys 2014-02-04 02:32 . 2014-03-16 14:00 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll 2014-02-04 02:32 . 2014-03-16 14:01 624128 ----a-w- c:\windows\system32\qedit.dll 2014-02-04 02:04 . 2014-03-16 14:00 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll 2014-02-04 02:04 . 2014-03-16 14:01 509440 ----a-w- c:\windows\SysWow64\qedit.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-01-16 343168] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2014-02-13 43848] "BingDesktop"="c:\program files (x86)\Microsoft\BingDesktop\BingDesktop.exe" [2014-02-21 2357984] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2014-01-17 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2014-02-21 152392] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer7"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x] R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x] R3 PaeFireStudio;PreSonus FireStudio;c:\windows\system32\Drivers\PaeFireStudio.sys;c:\windows\SYSNATIVE\Drivers\PaeFireStudio.sys [x] R3 PaeFireStudioAudio;PreSonus FireStudio Audio;c:\windows\system32\drivers\PaeFireStudioAudio.sys;c:\windows\SYSNATIVE\drivers\PaeFireStudioAudio.sys [x] R3 PaeFireStudioMidi;PreSonus FireStudio MIDI;c:\windows\system32\drivers\PaeFireStudioMidi.sys;c:\windows\SYSNATIVE\drivers\PaeFireStudioMidi.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys;c:\windows\SYSNATIVE\DRIVERS\wdcsam64.sys [x] S0 johci;JMicron 1394 Filter Driver;c:\windows\system32\DRIVERS\johci.sys;c:\windows\SYSNATIVE\DRIVERS\johci.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 BingDesktopUpdate;Bing Desktop Update service;c:\program files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe;c:\program files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [x] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\nlssrv32.exe;c:\windows\SysWOW64\nlssrv32.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 cmudaxp;ASUS Xonar Essence STX Audio Interface;c:\windows\system32\drivers\cmudaxp.sys;c:\windows\SYSNATIVE\drivers\cmudaxp.sys [x] S3 hcw18bda;Hauppauge WinTV 418 Driver;c:\windows\system32\drivers\hcw18bda.sys;c:\windows\SYSNATIVE\drivers\hcw18bda.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . --- Other Services/Drivers In Memory --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2009-06-17 17:11 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe . Contents of the 'Scheduled Tasks' folder . 2014-04-28 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 15:51] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Cmaudio8788"="c:\windows\Syswow64\cmicnfgp.dll" [2011-05-12 8769536] "Cmaudio8788GX"="c:\windows\syswow64\HsMgr.exe" [2008-07-11 200704] "Cmaudio8788GX64"="c:\windows\system\HsMgr64.exe" [2008-07-11 282112] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-03 9642528] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072] . ------- Supplementary Scan ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\MICROS~4\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\NRMBC\AppData\Roaming\Mozilla\Firefox\Profiles\pynxcgy1.default\ FF - prefs.js: browser.startup.homepage - www.msn.com . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKCU-Run-Universal Control - (no file) . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_206_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_206_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_206_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_206_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version] "Version"=hex:fb,df,a1,e7,4e,ba,01,c8,38,ff,0f,61,15,d0,ab,01,ef,3a,c3,ef,4e, a9,ae,8b,2c,4b,19,07,49,7e,c7,63,19,79,e7,8d,2e,87,12,d9,0a,af,71,8d,06,bc,\ . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.13" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version] "Version"=hex:fb,df,a1,e7,4e,ba,01,c8,38,ff,0f,61,15,d0,ab,01,ef,3a,c3,ef,4e, a9,ae,8b,2c,4b,19,07,49,7e,c7,63,19,79,e7,8d,2e,87,12,d9,0a,af,71,8d,06,bc,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Other Running Processes ------------------------ . c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\ASUS Xonar Essence STX Audio\Customapp\ASUSAUDIOCENTER.EXE c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe . ************************************************************************** . Completion time: 2014-04-29 18:32:58 - machine was rebooted ComboFix-quarantined-files.txt 2014-04-29 22:32 . Pre-Run: 687,562,207,232 bytes free Post-Run: 687,647,223,808 bytes free . - - End Of File - - 25B080E4907838EC9847DE17008AD305 A36C5E4F47E84449FF07ED3517B43A31