Hi and thx for the info.
I can borrow the laptop, just thought that would have been easier, she is bringing it down tomorrow, just finding out what operating system.
Will test machine out now.
ComboFix 11-09-01.03 - FLIPP 04/09/2011 21:13:04.1.4 - x64
Running from: c:\users\FLIPP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UD56X9PS\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\windows\SysWow64\mfc100deu.dll
c:\windows\UA000071.DLL
.
.
((((((((((((((((((((((((( Files Created from 2011-08-04 to 2011-09-04 )))))))))))))))))))))))))))))))
.
.
2011-09-04 20:23 . 2011-09-04 20:23 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2011-09-04 20:23 . 2011-09-04 20:23 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-09-04 17:37 . 2011-09-04 17:37 -------- d-----w- c:\program files\Java
2011-09-01 19:11 . 2011-09-01 19:11 -------- d-----w- c:\program files (x86)\ESET
2011-08-29 23:08 . 2011-08-29 23:12 -------- d-----w- c:\programdata\ManiaPlanet
2011-08-29 23:08 . 2011-08-29 23:09 -------- d-----w- c:\program files (x86)\ManiaPlanet
2011-08-27 13:34 . 2011-08-28 23:24 -------- d-----w- c:\users\FLIPP\AppData\Roaming\Sammsoft
2011-08-27 00:48 . 2011-08-27 00:48 -------- d-----w- c:\program files (x86)\Google
2011-08-26 21:07 . 2011-08-26 21:07 -------- d-----w- C:\_OTL
2011-08-26 21:02 . 2011-08-26 21:04 -------- d-----w- c:\program files (x86)\ERUNT
2011-08-26 11:37 . 2011-08-12 04:10 8862544 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9AC299A4-512B-45F5-AC2F-3E8D757C653C}\mpengine.dll
2011-08-24 12:45 . 2011-08-24 12:45 -------- d-----w- C:\f12f1591da052aec4117
2011-08-24 11:08 . 2011-07-11 13:45 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-24 11:08 . 2011-07-11 13:25 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-08-21 16:34 . 2011-08-21 16:34 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2011-08-19 22:56 . 2011-08-19 22:56 -------- d-----w- c:\users\FLIPP\AppData\Local\Mozilla
2011-08-19 18:20 . 2011-08-19 18:20 -------- d-----w- c:\users\FLIPP\AppData\Local\Deployment
2011-08-19 18:20 . 2011-08-19 18:20 -------- d-----w- c:\users\FLIPP\AppData\Local\Apps
2011-08-13 00:23 . 2011-09-04 17:37 525544 ----a-w- c:\windows\system32\deployJava1.dll
2011-08-11 12:56 . 2011-07-04 11:32 22360 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-08-11 12:56 . 2011-07-04 11:36 288088 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-08-11 12:56 . 2011-07-04 11:35 45400 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-08-11 12:56 . 2011-07-04 11:32 31064 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-08-11 12:56 . 2011-07-04 11:36 600920 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-08-11 12:56 . 2011-07-04 11:32 64856 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-08-11 12:56 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-08-11 12:56 . 2011-07-04 11:43 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-08-11 12:56 . 2011-08-11 12:56 -------- d-----w- c:\program files\AVAST Software
2011-08-10 12:43 . 2011-08-10 12:43 -------- d--h--w- c:\programdata\Common Files
2011-08-10 12:42 . 2011-08-10 12:43 -------- d-----w- c:\programdata\MFAData
2011-08-10 11:03 . 2011-06-06 10:59 2409784 ----a-w- c:\program files (x86)\Windows Mail\OESpamFilter.dat
2011-08-10 11:03 . 2011-06-06 10:59 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-08-10 11:03 . 2011-06-17 16:16 451072 ----a-w- c:\windows\system32\winsrv.dll
2011-08-10 11:03 . 2011-07-06 15:49 275456 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-10 11:03 . 2011-06-17 20:14 1427344 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-10 11:03 . 2011-06-20 08:45 4699536 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-08-10 00:07 . 2011-08-10 00:07 -------- d-----w- c:\windows\system32\Macromed
2011-08-09 18:42 . 2011-08-09 18:42 -------- d-----w- c:\programdata\Avira
2011-08-08 20:25 . 2011-07-20 10:30 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-08-08 20:25 . 2011-07-20 10:30 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-20 01:03 . 2011-05-15 11:48 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-26 20:15 . 2010-06-11 18:31 55384 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-07-15 00:57 . 2010-03-10 13:40 7634 ----a-w- c:\windows\SysWow64\ealregsnapshot1.reg
2011-07-06 18:52 . 2009-08-23 14:37 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-06 18:52 . 2009-08-23 14:37 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-04 11:43 . 2011-02-18 16:14 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-06-11 00:58 . 2011-06-11 00:58 81744 ----a-w- c:\windows\SysWow64\mfcm100u.dll
2011-06-11 00:58 . 2011-06-11 00:58 81744 ----a-w- c:\windows\SysWow64\mfcm100.dll
2011-06-11 00:58 . 2011-06-11 00:58 773968 ----a-w- c:\windows\SysWow64\msvcr100.dll
2011-06-11 00:58 . 2011-06-11 00:58 64336 ----a-w- c:\windows\SysWow64\mfc100fra.dll
2011-06-11 00:58 . 2011-06-11 00:58 63824 ----a-w- c:\windows\SysWow64\mfc100esn.dll
2011-06-11 00:58 . 2011-06-11 00:58 62288 ----a-w- c:\windows\SysWow64\mfc100ita.dll
2011-06-11 00:58 . 2011-06-11 00:58 60752 ----a-w- c:\windows\SysWow64\mfc100rus.dll
2011-06-11 00:58 . 2011-06-11 00:58 55120 ----a-w- c:\windows\SysWow64\mfc100enu.dll
2011-06-11 00:58 . 2011-06-11 00:58 51024 ----a-w- c:\windows\SysWow64\vcomp100.dll
2011-06-11 00:58 . 2011-06-11 00:58 4422992 ----a-w- c:\windows\SysWow64\mfc100u.dll
2011-06-11 00:58 . 2011-06-11 00:58 4397384 ----a-w- c:\windows\SysWow64\mfc100.dll
2011-06-11 00:58 . 2011-06-11 00:58 43856 ----a-w- c:\windows\SysWow64\mfc100jpn.dll
2011-06-11 00:58 . 2011-06-11 00:58 43344 ----a-w- c:\windows\SysWow64\mfc100kor.dll
2011-06-11 00:58 . 2011-06-11 00:58 421200 ----a-w- c:\windows\SysWow64\msvcp100.dll
2011-06-11 00:58 . 2011-06-11 00:58 36176 ----a-w- c:\windows\SysWow64\mfc100cht.dll
2011-06-11 00:58 . 2011-06-11 00:58 36176 ----a-w- c:\windows\SysWow64\mfc100chs.dll
2011-06-11 00:58 . 2011-06-11 00:58 138056 ----a-w- c:\windows\SysWow64\atl100.dll
2011-06-11 00:15 . 2011-06-11 00:15 93008 ----a-w- c:\windows\system32\mfcm100u.dll
2011-06-11 00:15 . 2011-06-11 00:15 93008 ----a-w- c:\windows\system32\mfcm100.dll
2011-06-11 00:15 . 2011-06-11 00:15 829264 ----a-w- c:\windows\system32\msvcr100.dll
2011-06-11 00:15 . 2011-06-11 00:15 64336 ----a-w- c:\windows\system32\mfc100fra.dll
2011-06-11 00:15 . 2011-06-11 00:15 64336 ----a-w- c:\windows\system32\mfc100deu.dll
2011-06-11 00:15 . 2011-06-11 00:15 63824 ----a-w- c:\windows\system32\mfc100esn.dll
2011-06-11 00:15 . 2011-06-11 00:15 62288 ----a-w- c:\windows\system32\mfc100ita.dll
2011-06-11 00:15 . 2011-06-11 00:15 608080 ----a-w- c:\windows\system32\msvcp100.dll
2011-06-11 00:15 . 2011-06-11 00:15 60752 ----a-w- c:\windows\system32\mfc100rus.dll
2011-06-11 00:15 . 2011-06-11 00:15 57168 ----a-w- c:\windows\system32\vcomp100.dll
2011-06-11 00:15 . 2011-06-11 00:15 5601616 ----a-w- c:\windows\system32\mfc100u.dll
2011-06-11 00:15 . 2011-06-11 00:15 5574984 ----a-w- c:\windows\system32\mfc100.dll
2011-06-11 00:15 . 2011-06-11 00:15 55120 ----a-w- c:\windows\system32\mfc100enu.dll
2011-06-11 00:15 . 2011-06-11 00:15 43856 ----a-w- c:\windows\system32\mfc100jpn.dll
2011-06-11 00:15 . 2011-06-11 00:15 43344 ----a-w- c:\windows\system32\mfc100kor.dll
2011-06-11 00:15 . 2011-06-11 00:15 36176 ----a-w- c:\windows\system32\mfc100cht.dll
2011-06-11 00:15 . 2011-06-11 00:15 36176 ----a-w- c:\windows\system32\mfc100chs.dll
2011-06-11 00:15 . 2011-06-11 00:15 158536 ----a-w- c:\windows\system32\atl100.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
"ISUSPM Startup"="c:\progra~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-17 221184]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files (x86)\Common Files\Real\Update_OB\realsched.exe" [2009-12-31 198160]
"CLMLServer for HP TouchSmart"="c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [2008-10-17 189736]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD64.exe" [2007-02-15 119296]
"KBD"="c:\program files (x86)\Hewlett-Packard\KBD\KbdStub.EXE" [2008-07-21 12288]
"DVDAgent"="c:\program files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2008-09-26 1148200]
"UpdatePSTShortCut"="c:\program files (x86)\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" [2008-09-11 210216]
"UpdatePDIRShortCut"="c:\program files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]
"ISUSScheduler"="c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"EEventManager"="c:\progra~2\EPSONS~1\EVENTM~1\EEventManager.exe" [2008-05-07 591696]
"ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-07-04 3493720]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
.
R0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-27 136176]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-03-26 2218600]
R3 ATICDSDr;ATICDSDr;c:\users\FLIPP\AppData\Local\Temp\ATICDSDr.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-27 136176]
R4 hcw85cir;Hauppauge Consumer Infrared Receiver;c:\windows\system32\drivers\hcw85cir.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 {55662437-DA8C-40c0-AADA-2C816A897A49};{55662437-DA8C-40c0-AADA-2C816A897A49};c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl [2008-09-26 27632]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 27648]
S2 HPBtnSrv;HP Easy Backup Button Service;c:\program files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe [2008-09-30 192512]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-03-26 378472]
S3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\system32\drivers\HCW85BDA.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 netr28x;Ralink 802.11n Wireless Driver for Windows Vista;c:\windows\system32\DRIVERS\netr28x.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-27 00:48]
.
2011-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-27 00:48]
.
2010-12-16 c:\windows\Tasks\User_Feed_Synchronization-{2630C28E-E88E-49C7-9770-69E193BCAF2E}.job
- c:\windows\system32\msfeedssync.exe [2011-04-24 23:49]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-07-04 11:43 134384 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-10-06 182808]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uLocal Page = c:\windows\system32\blank.htm
mStart Page =
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel
TCP: DhcpNameServer = 192.168.0.1
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-SmartMenu - c:\program files (x86)\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
HKLM-Run-Windows Defender - c:\program files (x86)\Windows Defender\MSASCui.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2204173278-169951079-703970126-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:c1,4d,86,11,fe,8a,6b,d1,d2,1f,9e,94,5c,7e,0e,72,7d,4a,f1,b5,ed,f6,74,
cb,24,80,94,f0,80,10,24,18,9c,31,8f,f8,90,76,e0,03,54,7e,a5,07,f4,5b,c8,a4,\
"??"=hex:3d,38,10,60,5a,5b,7a,eb,9a,3a,3e,b8,2a,df,94,29
.
[HKEY_USERS\S-1-5-21-2204173278-169951079-703970126-1000\Software\SecuROM\License information*]
"datasecu"=hex:e3,2e,3a,d8,d1,a7,bd,e3,69,e3,26,9c,f2,a6,1b,8e,b7,02,f8,4e,b4,
f7,7b,f2,ff,1d,eb,18,ac,fa,e3,cd,da,cb,51,59,72,ef,bf,5f,ca,b5,91,f2,95,06,\
"rkeysecu"=hex:77,29,f6,d5,90,c7,a0,8d,8e,9e,e4,a5,d6,52,66,85
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11a_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11a_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11a.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11a.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11a.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11a.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe
c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
.
**************************************************************************
.
Completion time: 2011-09-04 21:32:59 - machine was rebooted
ComboFix-quarantined-files.txt 2011-09-04 20:32
.
Pre-Run: 607,950,630,912 bytes free
Post-Run: 607,718,010,880 bytes free
.
- - End Of File - - 53D816F39E06901FD8EFAF628AF0D6B1
Wayne