Hey Will;
First I just want to appoligize, for getting so antzy, and bombarding you with all the logs...N-E-Way things went a lot more smoothly this time, and it appears with almost no corruption at all, as a matter of fact the log only took about 15 minutes to finish, hopefully thats a good sign...Tell me what you think of the GMER Log and your findings on the ComboFix Log that I'm attaching, that is when you have a chance, and again, sorry if i've seemed pushy, dont mean to be, just yesterday took it's toll on me...Will be really looking foward to getting this rootkit out of the computer...Will be waiting for your further instructions....Thanks again...Bobster52
----
Edit for log:
ComboFix 13-01-17.04 - Bobby 01/20/2013 11:24:51.1.2 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4095.2485 [GMT -5:00]
Running from: c:\users\Bobby\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 6.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 6.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2012-12-20 to 2013-01-20 )))))))))))))))))))))))))))))))
.
.
2013-01-20 16:30 . 2013-01-20 16:30 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-01-20 16:30 . 2013-01-20 16:30 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-01-20 16:30 . 2013-01-20 16:30 -------- d-----w- c:\users\Bobby\AppData\Local\temp
2013-01-20 00:38 . 2013-01-20 00:38 308640 ----a-w- c:\windows\system32\javaws.exe
2013-01-20 00:38 . 2013-01-20 00:38 108448 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-01-20 00:38 . 2013-01-20 00:38 188832 ----a-w- c:\windows\system32\javaw.exe
2013-01-20 00:38 . 2013-01-20 00:38 188832 ----a-w- c:\windows\system32\java.exe
2013-01-19 21:06 . 2013-01-19 21:06 -------- d-----w- c:\program files\Java
2013-01-19 21:05 . 2013-01-19 21:05 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-01-19 21:04 . 2013-01-19 21:04 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-01-19 21:04 . 2013-01-19 21:04 -------- d-----w- c:\program files (x86)\Java
2013-01-19 19:39 . 2013-01-19 19:39 -------- d-----w- c:\program files\ESET
2013-01-18 11:55 . 2013-01-08 05:32 9161176 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3C615380-80EA-4ECA-AD2C-6271ABBBC435}\mpengine.dll
2013-01-08 18:12 . 2012-11-20 04:22 204288 ----a-w- c:\windows\SysWow64\ncrypt.dll
2013-01-08 18:12 . 2012-11-20 04:21 253952 ----a-w- c:\windows\system32\ncrypt.dll
2013-01-08 18:11 . 2012-11-23 01:54 2770432 ----a-w- c:\windows\system32\win32k.sys
2013-01-08 18:11 . 2012-11-02 10:47 1869824 ----a-w- c:\windows\system32\msxml3.dll
2013-01-08 18:11 . 2012-11-02 10:47 1794560 ----a-w- c:\windows\system32\msxml6.dll
2013-01-08 18:11 . 2012-11-02 10:19 1400832 ----a-w- c:\windows\SysWow64\msxml6.dll
2013-01-08 18:11 . 2012-11-02 10:19 1248768 ----a-w- c:\windows\SysWow64\msxml3.dll
2013-01-08 18:11 . 2012-11-22 04:22 456192 ----a-w- c:\windows\system32\shlwapi.dll
2013-01-07 08:12 . 2013-01-17 15:25 -------- d-----w- c:\programdata\MSNDynFiles
2013-01-03 12:59 . 2013-01-03 12:59 -------- d-----w- c:\users\Bobby\AppData\Roaming\Malwarebytes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-20 00:38 . 2012-11-03 14:29 1081760 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-01-20 00:38 . 2012-03-13 03:59 960416 ----a-w- c:\windows\system32\deployJava1.dll
2013-01-19 21:04 . 2012-04-26 21:39 859552 ----a-w- c:\windows\SysWow64\npdeployJava1.dll
2013-01-19 21:04 . 2012-03-13 03:56 780192 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-01-09 20:00 . 2012-04-05 21:04 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-01-09 20:00 . 2012-03-13 20:19 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-08 18:13 . 2006-11-02 12:35 67599240 ----a-w- c:\windows\system32\mrt.exe
2012-12-16 13:31 . 2012-12-20 20:50 48128 ----a-w- c:\windows\system32\atmlib.dll
2012-12-16 13:12 . 2012-12-20 20:50 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2012-12-16 11:08 . 2012-12-20 20:50 368128 ----a-w- c:\windows\system32\atmfd.dll
2012-12-16 10:50 . 2012-12-20 20:50 293376 ----a-w- c:\windows\SysWow64\atmfd.dll
2012-12-13 04:50 . 2012-12-13 04:50 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-12-13 04:50 . 2012-12-13 04:50 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-12-13 04:50 . 2012-12-13 04:50 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-12-13 04:50 . 2012-12-13 04:50 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-12-13 04:50 . 2012-12-13 04:50 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-12-13 04:50 . 2012-12-13 04:50 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-12-13 04:50 . 2012-12-13 04:50 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-12-13 04:50 . 2012-12-13 04:50 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2012-12-13 04:50 . 2012-12-13 04:50 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-12-13 04:50 . 2012-12-13 04:50 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2012-12-13 04:50 . 2012-12-13 04:50 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-12-13 04:50 . 2012-12-13 04:50 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2012-12-13 04:50 . 2012-12-13 04:50 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-12-13 04:50 . 2012-12-13 04:50 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll
2012-12-13 04:50 . 2012-12-13 04:50 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-12-13 04:50 . 2012-12-13 04:50 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-12-13 04:50 . 2012-12-13 04:50 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2012-12-13 04:50 . 2012-12-13 04:50 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2012-12-13 04:50 . 2012-12-13 04:50 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-12-13 04:50 . 2012-12-13 04:50 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-12-13 04:50 . 2012-12-13 04:50 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-12-13 04:50 . 2012-12-13 04:50 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-12-13 04:50 . 2012-12-13 04:50 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-12-13 04:50 . 2012-12-13 04:50 85504 ----a-w- c:\windows\system32\jsproxy.dll
2012-12-13 04:50 . 2012-12-13 04:50 816640 ----a-w- c:\windows\system32\jscript.dll
2012-12-13 04:50 . 2012-12-13 04:50 55296 ----a-w- c:\windows\system32\msfeedsbs.dll
2012-12-13 04:50 . 2012-12-13 04:50 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-12-13 04:50 . 2012-12-13 04:50 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-12-13 04:50 . 2012-12-13 04:50 267776 ----a-w- c:\windows\system32\ieaksie.dll
2012-12-13 04:50 . 2012-12-13 04:50 248320 ----a-w- c:\windows\system32\ieui.dll
2012-12-13 04:50 . 2012-12-13 04:50 2312704 ----a-w- c:\windows\system32\jscript9.dll
2012-12-13 04:50 . 2012-12-13 04:50 222208 ----a-w- c:\windows\system32\msls31.dll
2012-12-13 04:50 . 2012-12-13 04:50 2144768 ----a-w- c:\windows\system32\iertutil.dll
2012-12-13 04:50 . 2012-12-13 04:50 197120 ----a-w- c:\windows\system32\msrating.dll
2012-12-13 04:50 . 2012-12-13 04:50 163840 ----a-w- c:\windows\system32\ieakui.dll
2012-12-13 04:50 . 2012-12-13 04:50 160256 ----a-w- c:\windows\system32\ieakeng.dll
2012-12-13 04:50 . 2012-12-13 04:50 145920 ----a-w- c:\windows\system32\iepeers.dll
2012-12-13 04:50 . 2012-12-13 04:50 1392128 ----a-w- c:\windows\system32\wininet.dll
2012-12-13 04:50 . 2012-12-13 04:50 136192 ----a-w- c:\windows\system32\advpack.dll
2012-12-13 04:50 . 2012-12-13 04:50 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-12-13 04:50 . 2012-12-13 04:50 1346048 ----a-w- c:\windows\system32\urlmon.dll
2012-12-13 04:50 . 2012-12-13 04:50 12288 ----a-w- c:\windows\system32\mshta.exe
2012-12-13 04:50 . 2012-12-13 04:50 114176 ----a-w- c:\windows\system32\admparse.dll
2012-12-13 04:50 . 2012-12-13 04:50 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-12-13 04:50 . 2012-12-13 04:50 10752 ----a-w- c:\windows\system32\msfeedssync.exe
2012-12-13 04:50 . 2012-12-13 04:50 96768 ----a-w- c:\windows\system32\mshtmled.dll
2012-12-13 04:50 . 2012-12-13 04:50 89088 ----a-w- c:\windows\system32\ie4uinit.exe
2012-12-13 04:50 . 2012-12-13 04:50 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-12-13 04:50 . 2012-12-13 04:50 82432 ----a-w- c:\windows\system32\icardie.dll
2012-12-13 04:50 . 2012-12-13 04:50 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-12-13 04:50 . 2012-12-13 04:50 729088 ----a-w- c:\windows\system32\msfeeds.dll
2012-12-13 04:50 . 2012-12-13 04:50 65024 ----a-w- c:\windows\system32\pngfilt.dll
2012-12-13 04:50 . 2012-12-13 04:50 599040 ----a-w- c:\windows\system32\vbscript.dll
2012-12-13 04:50 . 2012-12-13 04:50 534528 ----a-w- c:\windows\system32\ieapfltr.dll
2012-12-13 04:50 . 2012-12-13 04:50 452608 ----a-w- c:\windows\system32\dxtmsft.dll
2012-12-13 04:50 . 2012-12-13 04:50 448512 ----a-w- c:\windows\system32\html.iec
2012-12-13 04:50 . 2012-12-13 04:50 403248 ----a-w- c:\windows\system32\iedkcs32.dll
2012-12-13 04:50 . 2012-12-13 04:50 39936 ----a-w- c:\windows\system32\iernonce.dll
2012-12-13 04:50 . 2012-12-13 04:50 3695416 ----a-w- c:\windows\system32\ieapfltr.dat
2012-12-13 04:50 . 2012-12-13 04:50 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-12-13 04:50 . 2012-12-13 04:50 282112 ----a-w- c:\windows\system32\dxtrans.dll
2012-12-13 04:50 . 2012-12-13 04:50 249344 ----a-w- c:\windows\system32\webcheck.dll
2012-12-13 04:50 . 2012-12-13 04:50 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-12-13 04:50 . 2012-12-13 04:50 237056 ----a-w- c:\windows\system32\url.dll
2012-12-13 04:50 . 2012-12-13 04:50 17811968 ----a-w- c:\windows\system32\mshtml.dll
2012-12-13 04:50 . 2012-12-13 04:50 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2012-12-13 04:50 . 2012-12-13 04:50 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-12-13 04:50 . 2012-12-13 04:50 160256 ----a-w- c:\windows\system32\wextract.exe
2012-12-13 04:50 . 2012-12-13 04:50 149504 ----a-w- c:\windows\system32\occache.dll
2012-12-13 04:50 . 2012-12-13 04:50 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
2012-12-13 04:50 . 2012-12-13 04:50 10925568 ----a-w- c:\windows\system32\ieframe.dll
2012-12-13 04:50 . 2012-12-13 04:50 103936 ----a-w- c:\windows\system32\inseng.dll
2012-11-13 01:45 . 2012-12-11 20:39 2048 ----a-w- c:\windows\system32\tzres.dll
2012-11-13 01:29 . 2012-12-11 20:39 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-11-04 23:03 . 2012-10-29 14:18 319488 ----a-w- c:\windows\HideWin.exe
2012-11-02 10:45 . 2012-12-11 20:39 477696 ----a-w- c:\windows\system32\dpnet.dll
2012-11-02 10:45 . 2012-12-11 20:39 68096 ----a-w- c:\windows\system32\dpnathlp.dll
2012-11-02 10:18 . 2012-12-11 20:39 376320 ----a-w- c:\windows\SysWow64\dpnet.dll
2012-11-02 08:59 . 2012-12-11 20:39 26112 ----a-w- c:\windows\system32\dpnsvr.exe
2012-11-02 08:26 . 2012-12-11 20:39 23040 ----a-w- c:\windows\SysWow64\dpnsvr.exe
2012-10-30 23:10 . 2012-10-30 22:45 29480 ----a-w- c:\windows\SysWow64\msxml3a.dll
2012-10-30 23:10 . 2006-12-11 01:39 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
2012-10-30 23:10 . 2006-12-11 01:39 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
2012-10-29 15:14 . 2012-10-29 14:57 60416 ----a-w- c:\windows\ALCFDRTM.VER
2012-10-29 14:57 . 2012-10-29 14:57 60416 ----a-w- c:\windows\ALCFDRTM.EXE
2012-10-23 12:24 . 2012-10-23 12:24 138744 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
2012-10-23 12:24 . 2012-10-23 12:24 211344 ----a-w- c:\windows\system32\drivers\eamonm.sys
2012-10-23 12:24 . 2012-10-23 12:24 149592 ----a-w- c:\windows\system32\drivers\ehdrv.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LCDC"="c:\program files (x86)\LCDC\LCDC.exe" [2006-11-07 1691648]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1555968]
"PowerPanel Personal Edition User Interaction"="c:\program files (x86)\CyberPower PowerPanel Personal Edition\pppeuser.exe" [2005-10-24 262144]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 138240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"B9864E2C-516D-4587-A290-189473179455"="start" [X]
.
c:\users\Bobby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote Table Of Contents.onetoc2 [2012-10-30 3656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 02485070
*NewlyCreated* - 65559996
*NewlyCreated* - 98465247
*Deregistered* - 02485070
*Deregistered* - 65559996
*Deregistered* - 98465247
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Themes
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2012-07-02 19:40 453736 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2011-08-10 1873256]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]
"SoundMan"="SOUNDMAN.EXE" [2009-04-14 604704]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2012-11-26 6325936]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1 192.168.0.1
DPF: vzTCPConfig - hxxp://my.verizon.com/micro/speedoptimizer/fios/vzTCPConfig.CAB
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-WMPNSCFG - c:\program files (x86)\Windows Media Player\WMPNSCFG.exe
Wow6432Node-HKLM-Run-NWEReboot - (no file)
SafeBoot-65559996.sys
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2013-01-20 11:31:47
ComboFix-quarantined-files.txt 2013-01-20 16:31
.
Pre-Run: 245,630,492,672 bytes free
Post-Run: 245,526,945,792 bytes free
.
- - End Of File - - F511E0C3C3DEF9F75E14C635B579936F