My computer has a boot-up issue. I think there is an issue with the RAM.
Also, I do video editing with Sony's Vegas Video Pro. It has been crashing a lot with simple tasks - this also might have to do with an issue with the RAM.
Right now, the computer is running smooth. I can tell when there is a virus issue because the motherboard fan starts running high and won't settle back down.
Lastly, I have three external drives that I work with a lot (video, music & web sites). Are the tests being running also scanning them for infestations and issues?
Here is the ComboFix report:
ComboFix 14-06-30.01 - Greg 06/30/2014 8:07.1.8 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.10231.7755 [GMT -7:00]
Running from: c:\users\Greg\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Java\jre7\bin\jp2ssv.dll
c:\users\Greg\AppData\Local\cwbimxoe.exe
c:\users\Greg\AppData\Local\jiitdnvr.exe
c:\users\Greg\Documents\FAP196.tmp
c:\users\Greg\Documents\FAP27F7.tmp
c:\users\Greg\Documents\FAP300F.tmp
c:\users\Greg\Documents\FAP4EFE.tmp
c:\users\Greg\Documents\FAP803D.tmp
c:\users\Greg\Documents\FAP9D0C.tmp
c:\users\Greg\Documents\FAPB294.tmp
c:\users\Greg\Documents\FAPB4EC.tmp
c:\users\Greg\Documents\FAPB7B7.tmp
c:\users\Greg\Documents\FAPB8B3.tmp
c:\users\Greg\Documents\FAPDDD4.tmp
c:\users\Greg\Documents\FAPE729.tmp
c:\users\Greg\Documents\FAPE94F.tmp
c:\users\Greg\Documents\FAPEA89.tmp
c:\users\Greg\Documents\FAPEABA.tmp
c:\users\Greg\Documents\FAPF494.tmp
c:\users\Greg\Documents\FAPFB31.tmp
c:\users\Greg\g2mdlhlpx.exe
c:\users\Greg\GoToAssistDownloadHelper.exe
c:\users\Greg\ncftp
c:\users\Greg\ncftp\firewall.txt
.
.
((((((((((((((((((((((((( Files Created from 2014-05-28 to 2014-06-30 )))))))))))))))))))))))))))))))
.
.
2014-06-30 15:14 . 2014-06-30 15:14 -------- d-----w- c:\users\Test\AppData\Local\temp
2014-06-30 15:14 . 2014-06-30 15:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-06-30 14:24 . 2014-06-30 14:55 -------- d-----w- c:\users\Greg\AppData\Roaming\Acyzegos
2014-06-30 01:28 . 2014-06-05 10:54 10779000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6F0924D3-B859-4B03-9C4C-CB1917E543A9}\mpengine.dll
2014-06-27 16:03 . 2014-06-27 17:00 -------- d-----w- c:\users\Greg\AppData\Roaming\Paihemem
2014-06-26 21:56 . 2014-06-05 10:54 10779000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-06-25 20:45 . 2014-06-25 21:45 -------- d-----w- c:\users\Greg\AppData\Roaming\Baygilox
2014-06-25 16:58 . 2014-05-02 05:01 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5B597A98-3B3E-4EC6-AA19-CDAF4F10FE0E}\gapaengine.dll
2014-06-24 16:50 . 2014-06-24 16:50 -------- d-----w- c:\users\Test\AppData\Roaming\FLEXnet
2014-06-23 20:48 . 2014-06-23 20:48 55104 ----a-w- c:\windows\system32\drivers\zhrklagu.sys
2014-06-23 19:45 . 2014-06-23 21:38 -------- d-----w- c:\users\Greg\AppData\Roaming\Vydicii
2014-06-21 22:05 . 2014-06-30 14:26 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-06-21 22:05 . 2014-06-23 22:20 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-06-21 22:05 . 2014-06-21 22:05 -------- d-----w- c:\programdata\Malwarebytes
2014-06-21 22:05 . 2014-05-12 14:26 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-06-21 22:05 . 2014-05-12 14:26 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-06-21 22:05 . 2014-05-12 14:25 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-06-21 21:17 . 2014-06-21 21:17 -------- d-----w- C:\_OTL
2014-06-21 19:56 . 2014-06-22 22:35 -------- d-----w- c:\users\Greg\AppData\Roaming\Atbeacaq
2014-06-18 16:38 . 2014-06-18 17:06 -------- d-----w- c:\users\Greg\AppData\Local\Audible
2014-06-18 00:52 . 2014-06-18 00:52 -------- d-----w- c:\users\Test\AppData\Roaming\Sony Creative Software Inc
2014-06-18 00:16 . 2014-06-18 00:16 255352 ----a-w- c:\windows\SysWow64\awrdscdc.ax
2014-06-18 00:16 . 2001-08-18 05:43 24576 ------w- c:\windows\SysWow64\msxml3a.dll
2014-06-18 00:16 . 2014-06-18 00:16 -------- d-----w- c:\program files (x86)\Audible
2014-06-15 19:59 . 2014-06-15 19:59 -------- d-----w- c:\users\Greg\AppData\Roaming\com.adobe.DC3Module.AdobeADC
2014-06-14 04:11 . 2014-06-14 04:11 -------- d-----w- c:\users\Test\AppData\Roaming\Publish Providers
2014-06-14 04:11 . 2014-06-14 04:11 -------- d-----w- c:\users\Test\AppData\Roaming\NVIDIA
2014-06-14 04:11 . 2014-06-14 04:11 -------- d-----w- c:\users\Test\AppData\Roaming\Titler
2014-06-14 04:11 . 2014-06-14 04:11 -------- d-----w- c:\users\Test\AppData\Local\BorisFX
2014-06-14 04:11 . 2014-06-14 04:11 -------- d-----w- c:\users\Test\AppData\Roaming\Sony
2014-06-14 04:11 . 2014-06-14 04:11 -------- d-----w- c:\users\Test\AppData\Local\Sony
2014-06-12 06:45 . 2014-06-12 06:45 -------- d-----w- c:\program files (x86)\Common Files\Steam
2014-06-12 06:45 . 2014-06-24 07:08 -------- d-----w- c:\program files (x86)\Steam
2014-06-12 03:54 . 2014-06-08 09:13 506368 ----a-w- c:\windows\system32\aepdu.dll
2014-06-03 03:06 . 2014-06-03 03:06 -------- d-----w- c:\program files\iPod
2014-06-03 03:06 . 2014-06-03 03:07 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-06-03 03:06 . 2014-06-03 03:07 -------- d-----w- c:\program files\iTunes
2014-06-03 03:06 . 2014-06-03 03:07 -------- d-----w- c:\program files (x86)\iTunes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-06-16 23:29 . 2014-04-19 04:04 699056 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-06-16 23:29 . 2014-04-19 04:04 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-06-12 06:55 . 2014-04-15 04:53 95414520 ----a-w- c:\windows\system32\MRT.exe
2014-05-27 23:36 . 2014-05-27 23:36 210216 ----a-w- c:\windows\SysWow64\atsckernel.exe
2014-05-27 23:36 . 2014-05-27 23:36 118056 ----a-w- c:\windows\SysWow64\atashost.exe
2014-05-19 17:42 . 2014-05-19 17:42 53248 ----a-r- c:\users\Greg\AppData\Roaming\Microsoft\Installer\{632DCE79-2711-4B07-BB89-DA763E96840C}\ARPPRODUCTICON.exe
2014-05-19 17:42 . 2014-05-19 17:42 53248 ----a-r- c:\users\Greg\AppData\Roaming\Microsoft\Installer\{3A9527CF-4E91-4683-A03F-F1AD022126E5}\ARPPRODUCTICON.exe
2014-05-12 03:31 . 2014-05-12 03:31 736952 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2014-05-12 03:31 . 2014-05-12 03:31 2876528 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2014-05-12 03:30 . 2014-05-12 03:30 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2014-05-12 03:30 . 2014-05-12 03:30 539984 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2014-05-02 05:01 . 2014-04-19 23:52 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-04-24 21:01 . 2014-04-24 21:01 34587232 ----a-w- c:\windows\system32\BCC8_OFX_Float.dll
2014-04-24 21:01 . 2014-04-24 21:01 1151072 ----a-w- c:\windows\system32\BCC8_Common_OFX.dll
2014-04-17 12:31 . 2014-04-18 21:34 10651704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F8EFE198-6533-447D-A00C-28908CC09B85}\mpengine.dll
2014-04-17 02:07 . 2014-04-17 02:07 313256 ----a-w- c:\windows\system32\javaws.exe
2014-04-17 02:07 . 2014-04-17 02:07 189352 ----a-w- c:\windows\system32\javaw.exe
2014-04-17 02:07 . 2014-04-17 02:07 189352 ----a-w- c:\windows\system32\java.exe
2014-04-17 02:07 . 2014-04-17 02:07 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2014-04-17 02:07 . 2014-04-17 02:07 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-04-16 03:30 . 2014-04-16 03:30 113629 ----a-w- c:\windows\SysWow64\slmgr.vbs
2014-04-16 03:30 . 2014-04-16 03:30 113629 ----a-w- c:\windows\system32\slmgr.vbs
2014-04-15 09:34 . 2014-04-15 09:34 1070232 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2014-04-15 05:14 . 2014-04-15 05:14 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-04-15 05:14 . 2014-04-15 05:14 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll
2014-04-15 05:14 . 2014-04-15 05:14 81408 ----a-w- c:\windows\system32\icardie.dll
2014-04-15 05:14 . 2014-04-15 05:14 77312 ----a-w- c:\windows\system32\tdc.ocx
2014-04-15 05:14 . 2014-04-15 05:14 762368 ----a-w- c:\windows\system32\ieapfltr.dll
2014-04-15 05:14 . 2014-04-15 05:14 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2014-04-15 05:14 . 2014-04-15 05:14 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2014-04-15 05:14 . 2014-04-15 05:14 62976 ----a-w- c:\windows\system32\pngfilt.dll
2014-04-15 05:14 . 2014-04-15 05:14 61952 ----a-w- c:\windows\SysWow64\tdc.ocx
2014-04-15 05:14 . 2014-04-15 05:14 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2014-04-15 05:14 . 2014-04-15 05:14 51200 ----a-w- c:\windows\system32\imgutil.dll
2014-04-15 05:14 . 2014-04-15 05:14 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2014-04-15 05:14 . 2014-04-15 05:14 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-04-15 05:14 . 2014-04-15 05:14 441856 ----a-w- c:\windows\system32\html.iec
2014-04-15 05:14 . 2014-04-15 05:14 38400 ----a-w- c:\windows\SysWow64\imgutil.dll
2014-04-15 05:14 . 2014-04-15 05:14 361984 ----a-w- c:\windows\SysWow64\html.iec
2014-04-15 05:14 . 2014-04-15 05:14 27648 ----a-w- c:\windows\system32\licmgr10.dll
2014-04-15 05:14 . 2014-04-15 05:14 270848 ----a-w- c:\windows\system32\iedkcs32.dll
2014-04-15 05:14 . 2014-04-15 05:14 247296 ----a-w- c:\windows\system32\webcheck.dll
2014-04-15 05:14 . 2014-04-15 05:14 235008 ----a-w- c:\windows\system32\url.dll
2014-04-15 05:14 . 2014-04-15 05:14 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll
2014-04-15 05:14 . 2014-04-15 05:14 226304 ----a-w- c:\windows\system32\elshyph.dll
2014-04-15 05:14 . 2014-04-15 05:14 216064 ----a-w- c:\windows\system32\msls31.dll
2014-04-15 05:14 . 2014-04-15 05:14 185344 ----a-w- c:\windows\SysWow64\elshyph.dll
2014-04-15 05:14 . 2014-04-15 05:14 173568 ----a-w- c:\windows\system32\ieUnatt.exe
2014-04-15 05:14 . 2014-04-15 05:14 167424 ----a-w- c:\windows\system32\iexpress.exe
2014-04-15 05:14 . 2014-04-15 05:14 158720 ----a-w- c:\windows\SysWow64\msls31.dll
2014-04-15 05:14 . 2014-04-15 05:14 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2014-04-15 05:14 . 2014-04-15 05:14 149504 ----a-w- c:\windows\system32\occache.dll
2014-04-15 05:14 . 2014-04-15 05:14 144896 ----a-w- c:\windows\system32\wextract.exe
2014-04-15 05:14 . 2014-04-15 05:14 1400416 ----a-w- c:\windows\system32\ieapfltr.dat
2014-04-15 05:14 . 2014-04-15 05:14 138752 ----a-w- c:\windows\SysWow64\wextract.exe
2014-04-15 05:14 . 2014-04-15 05:14 13824 ----a-w- c:\windows\system32\mshta.exe
2014-04-15 05:14 . 2014-04-15 05:14 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2014-04-15 05:14 . 2014-04-15 05:14 136192 ----a-w- c:\windows\system32\iepeers.dll
2014-04-15 05:14 . 2014-04-15 05:14 135680 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-04-15 05:14 . 2014-04-15 05:14 12800 ----a-w- c:\windows\SysWow64\mshta.exe
2014-04-15 05:14 . 2014-04-15 05:14 12800 ----a-w- c:\windows\system32\msfeedssync.exe
2014-04-15 05:14 . 2014-04-15 05:14 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2014-04-15 05:14 . 2014-04-15 05:14 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-04-15 05:14 . 2014-04-15 05:14 102912 ----a-w- c:\windows\system32\inseng.dll
2014-04-12 02:22 . 2014-05-14 14:47 155072 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2014-04-12 02:22 . 2014-05-14 14:47 95680 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2014-04-12 02:19 . 2014-05-14 14:47 29184 ----a-w- c:\windows\system32\sspisrv.dll
2014-04-12 02:19 . 2014-05-14 14:47 136192 ----a-w- c:\windows\system32\sspicli.dll
2014-04-12 02:19 . 2014-05-14 14:47 28160 ----a-w- c:\windows\system32\secur32.dll
2014-04-12 02:19 . 2014-05-14 14:47 1460736 ----a-w- c:\windows\system32\lsasrv.dll
2014-04-12 02:19 . 2014-05-14 14:47 31232 ----a-w- c:\windows\system32\lsass.exe
2014-04-12 02:12 . 2014-05-14 14:47 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2014-04-12 02:10 . 2014-05-14 14:47 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00001YSISyncComplete]
@="{89B5F9CC-C4A2-462C-BD27-29CEAC972135}"
[HKEY_CLASSES_ROOT\CLSID\{89B5F9CC-C4A2-462C-BD27-29CEAC972135}]
2014-02-25 14:32 2852920 ----a-w- c:\program files (x86)\Hightail Desktop App\YSINSE.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00002YSISyncActive]
@="{84B7BDFB-C50A-4335-B7C2-8AEC454F9E25}"
[HKEY_CLASSES_ROOT\CLSID\{84B7BDFB-C50A-4335-B7C2-8AEC454F9E25}]
2014-02-25 14:32 2852920 ----a-w- c:\program files (x86)\Hightail Desktop App\YSINSE.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00003YSISyncError]
@="{306A9CDE-AC70-453A-8008-B5F9962B8F88}"
[HKEY_CLASSES_ROOT\CLSID\{306A9CDE-AC70-453A-8008-B5F9962B8F88}]
2014-02-25 14:32 2852920 ----a-w- c:\program files (x86)\Hightail Desktop App\YSINSE.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00004YSILocalOnly]
@="{23A7D2DC-F395-4E33-876C-84A2DFAB0EBB}"
[HKEY_CLASSES_ROOT\CLSID\{23A7D2DC-F395-4E33-876C-84A2DFAB0EBB}]
2014-02-25 14:32 2852920 ----a-w- c:\program files (x86)\Hightail Desktop App\YSINSE.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2014-04-19 02:05 1020424 ----a-r- c:\program files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2014-04-19 02:05 1020424 ----a-r- c:\program files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2014-04-19 02:05 1020424 ----a-r- c:\program files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 131248 ----a-w- c:\users\Greg\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 131248 ----a-w- c:\users\Greg\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 131248 ----a-w- c:\users\Greg\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 131248 ----a-w- c:\users\Greg\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadwin PrintScreen (64-bit)"="c:\program files\Gadwin\Gadwin PrintScreen\PrintScreen64.exe" [2014-02-21 14082208]
"TomTomHOME.exe"="c:\program files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" [2014-06-05 248176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-12-21 959904]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2014-02-13 43848]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2014-01-17 421888]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-23 402432]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS4ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Intuit SyncManager"="c:\program files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2014-02-27 3775800]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-12 640376]
"Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2014-05-26 2688920]
"Carbonite Backup"="c:\program files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe" [2014-04-19 1056264]
"ISUSPM"="c:\programdata\FLEXnet\Connect\11\\isuspm.exe" [2010-05-21 324976]
"RoxWatchTray"="c:\program files (x86)\Roxio Easy CD & DVD Burning\Common\RoxWatchTray14.exe" [2012-11-29 294032]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2014-05-27 152392]
.
c:\users\Greg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Greg\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-5-19 33322312]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Intuit Data Protect.lnk - c:\program files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe /Startup [2014-2-27 6296888]
QuickBooks Update Agent.lnk - c:\program files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2014-2-27 1129288]
QuickBooks_Standard_21.lnk - c:\program files (x86)\Intuit\QuickBooks 2014\QBW32.EXE -silent [2014-2-27 1215816]
Transfer Utility Camera Monitor.lnk - c:\program files (x86)\PIXELA\Transfer Utility\CameraMonitor.exe [2014-4-29 376176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 Carbonite-Mirror-Image-Svc;Carbonite Mirror Image Service;c:\program files\Carbonite\Carbonite Mirror Image\CarboniteMirrorImage.exe;c:\program files\Carbonite\Carbonite Mirror Image\CarboniteMirrorImage.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 RoxWatch14;Roxio Hard Drive Watcher 14;c:\program files (x86)\Roxio Easy CD & DVD Burning\Common\RoxWatch14.exe;c:\program files (x86)\Roxio Easy CD & DVD Burning\Common\RoxWatch14.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RoxMediaDB14;RoxMediaDB14;c:\program files (x86)\Roxio Easy CD & DVD Burning\Common\RoxMediaDB14.exe;c:\program files (x86)\Roxio Easy CD & DVD Burning\Common\RoxMediaDB14.exe [x]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S0 Sahdad64;HDD Filter Driver;c:\windows\System32\Drivers\Sahdad64.sys;c:\windows\SYSNATIVE\Drivers\Sahdad64.sys [x]
S0 Saibad64;Volume Filter Driver;c:\windows\System32\Drivers\Saibad64.sys;c:\windows\SYSNATIVE\Drivers\Saibad64.sys [x]
S1 SaibVdAd64;Virtual Disk Driver;c:\windows\system32\Drivers\SaibVdAd64.sys;c:\windows\SYSNATIVE\Drivers\SaibVdAd64.sys [x]
S2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe;c:\program files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 atashost;WebEx Service Host for Support Center;c:\windows\SysWOW64\atashost.exe;c:\windows\SysWOW64\atashost.exe [x]
S2 BOT4Service;BOT4Service;c:\program files (x86)\Roxio\BackOnTrack\App\BService.exe;c:\program files (x86)\Roxio\BackOnTrack\App\BService.exe [x]
S2 NVWMI;NVIDIA WMI Provider;c:\windows\system32\nvwmi64.exe;c:\windows\SYSNATIVE\nvwmi64.exe [x]
S2 QBVSS;QBIDPService;c:\program files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe;c:\program files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe [x]
S2 RoxioBurnLauncher;Roxio Burn Launcher;c:\program files (x86)\Roxio Easy CD & DVD Burning\Roxio Burn\RoxioBurnLauncher.exe;c:\program files (x86)\Roxio Easy CD & DVD Burning\Roxio Burn\RoxioBurnLauncher.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-06-11 20:25 1091912 ----a-w- c:\program files (x86)\Google\Chrome\Application\35.0.1916.153\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-06-30 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-19 23:29]
.
2014-06-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-04-17 02:06]
.
2014-06-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-04-17 02:06]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1]
@="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}"
[HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}]
2014-05-23 09:10 671904 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2]
@="{853B7E05-C47D-4985-909A-D0DC5C6D7303}"
[HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}]
2014-05-23 09:10 671904 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3]
@="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}"
[HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}]
2014-05-23 09:10 671904 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00001YSISyncComplete]
@="{89B5F9CC-C4A2-462C-BD27-29CEAC972135}"
[HKEY_CLASSES_ROOT\CLSID\{89B5F9CC-C4A2-462C-BD27-29CEAC972135}]
2014-02-25 14:32 2994232 ----a-w- c:\program files\Hightail Desktop App\YSINSE64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00002YSISyncActive]
@="{84B7BDFB-C50A-4335-B7C2-8AEC454F9E25}"
[HKEY_CLASSES_ROOT\CLSID\{84B7BDFB-C50A-4335-B7C2-8AEC454F9E25}]
2014-02-25 14:32 2994232 ----a-w- c:\program files\Hightail Desktop App\YSINSE64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00003YSISyncError]
@="{306A9CDE-AC70-453A-8008-B5F9962B8F88}"
[HKEY_CLASSES_ROOT\CLSID\{306A9CDE-AC70-453A-8008-B5F9962B8F88}]
2014-02-25 14:32 2994232 ----a-w- c:\program files\Hightail Desktop App\YSINSE64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00004YSILocalOnly]
@="{23A7D2DC-F395-4E33-876C-84A2DFAB0EBB}"
[HKEY_CLASSES_ROOT\CLSID\{23A7D2DC-F395-4E33-876C-84A2DFAB0EBB}]
2014-02-25 14:32 2994232 ----a-w- c:\program files\Hightail Desktop App\YSINSE64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2014-04-19 01:53 1293320 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2014-04-19 01:53 1293320 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2014-04-19 01:53 1293320 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 164016 ----a-w- c:\users\Greg\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 164016 ----a-w- c:\users\Greg\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 164016 ----a-w- c:\users\Greg\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 164016 ----a-w- c:\users\Greg\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2014-03-21 2728736]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2014-02-28 558496]
"Hightail Sync Agent"="c:\program files (x86)\Hightail Desktop App\Hightail.exe" [2014-02-25 7107640]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
Trusted Zone: dell.com
Trusted Zone: hearthsidefoods.com\myapps
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
Handler: intu-help-qb7 - {5A03BD9D-766D-47A6-8E87-CD90F60BE245} - c:\program files (x86)\Intuit\QuickBooks 2014\HelpAsyncPluggableProtocol.dll
FF - ProfilePath - c:\users\Greg\AppData\Roaming\Mozilla\Firefox\Profiles\qgeebwvf.default\
FF - prefs.js: browser.startup.homepage - hxxps://my.yahoo.com/
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKCU-Run-Labaol - c:\users\Greg\AppData\Roaming\Atbeacaq\lyoxerd.exe
Wow6432Node-HKCU-Run-wsqlhrut - c:\users\Greg\AppData\Local\cwbimxoe.exe
Wow6432Node-HKCU-Run-jkewvust - c:\users\Greg\AppData\Local\jiitdnvr.exe
Wow6432Node-HKLM-Run-Labaol - c:\users\Greg\AppData\Roaming\Atbeacaq\lyoxerd.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-Labaol - c:\users\Greg\AppData\Roaming\Atbeacaq\lyoxerd.exe
AddRemove-InstallShield_{20DFF861-31EE-41F6-98D5-0A992AE7D116} - c:\program files\InstallShield Installation Information\{20DFF861-31EE-41F6-98D5-0A992AE7D116}\setup.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:3a,ac,d8,57,db,a9,b4,00,d2,25,f4,bd,79,c7,bf,23,e1,c7,41,2c,b8,
2b,4f,48,30,a2,c8,70,4d,f7,62,c0,ff,d4,60,1c,d2,f9,f0,1b,7f,4a,9b,da,09,1b,\
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.13"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2014-06-30 08:17:34
ComboFix-quarantined-files.txt 2014-06-30 15:17
.
Pre-Run: 647,304,056,832 bytes free
Post-Run: 647,265,669,120 bytes free
.
- - End Of File - - 1980216D384715F80F71D1E0C41626DA
A36C5E4F47E84449FF07ED3517B43A31