Documente Academic
Documente Profesional
Documente Cultură
4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.4030.1931 [GMT 0:0
0]
Running from: c:\users\Alex\Desktop\projects\ComboFix.exe
AV: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB16E49CB52ECD9}
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765
193BCB75F}
SP: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {B5F5C120-2089-702E-0001553BB0D5A664}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D2
3E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2013-11-01 to 2013-12-01 )))))))
))))))))))))))))))))))))
.
.
2013-12-01 19:59 . 2013-12-01 19:59
-------d-----wc:\users
\Default\AppData\Local\temp
2013-12-01 19:52 . 2013-11-08 03:12
10285968
----a-wc:\progr
amdata\Microsoft\Microsoft Antimalware\Definition Updates\{2F008DBA-1DBB-4856-89
AC-044086CFEF12}\mpengine.dll
2013-11-17 16:40 . 2013-11-17 16:39
965000 ------wc:\programdata\M
icrosoft\Microsoft Antimalware\Definition Updates\{62B7C576-4CE1-486A-8A7B-F0748
175C51A}\gapaengine.dll
2013-11-17 16:40 . 2012-07-25 15:22
927800 ------wc:\programdata\M
icrosoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-11-17 16:40 . 2013-10-14 07:12
10280728
----a-wc:\progr
amdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-11-15 22:08 . 2013-11-15 22:08
-------d-----wc:\users
\Alex\AppData\Local\CrashDumps
2013-11-15 17:37 . 2013-11-15 17:35
39976 ----a-wc:\windows\syste
m32\drivers\btwl2cap.sys
2013-11-15 17:37 . 2013-11-15 17:35
21544 ----a-wc:\windows\syste
m32\drivers\btwrchid.sys
2013-11-15 17:37 . 2013-11-15 17:35
210984 ----a-wc:\windows\syste
m32\drivers\btwavdt.sys
2013-11-15 17:37 . 2013-11-15 17:35
184144 ----a-wc:\windows\syste
m32\drivers\btwaudio.sys
2013-11-13 11:18 . 2013-10-05 20:25
1474048 ----a-wc:\windows\syste
m32\crypt32.dll
2013-11-12 13:56 . 2013-11-12 13:56
-------d-----wc:\progr
amdata\Oracle
2013-11-12 13:55 . 2013-11-12 13:55
96168 ----a-wc:\windows\SysWo
w64\WindowsAccessBridge-32.dll
2013-11-09 13:28 . 2013-11-09 13:29
-------d-----wc:\progr
am files (x86)\Code Laboratories
2013-11-05 17:40 . 2013-11-11 18:08
-------d-----wc:\users
\Alex\AppData\Roaming\codeblocks
2013-11-05 16:58 . 2013-11-05 17:00
-------d-----wc:\users
\Alex\AppData\Roaming\Processing
2013-11-02 10:23 . 2012-07-11 05:26
765952 ----a-wc:\windows\SysWo
w64\xvidcore.dll
2013-11-02 10:23 . 2012-07-11 05:26
180224 ----a-wc:\windows\SysWo
w64\xvidvfw.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))
)))))))))))))))))))))))))))))))
.
2013-11-19 10:21 . 2010-11-21 03:27
267936 ------wc:\windows\syste
m32\MpSigStub.exe
2013-11-14 13:07 . 2012-07-26 10:46
82896128
----a-wc:\windo
ws\system32\MRT.exe
2013-10-28 18:02 . 2013-10-28 18:02
66264 ----a-wc:\windows\syste
m32\btwdi.dll
2013-10-28 18:02 . 2013-10-28 18:02
2255064 ----a-wc:\windows\syste
m32\BtwRSupportService.exe
2013-10-28 18:02 . 2013-10-28 18:02
166104 ----a-wc:\windows\syste
m32\drivers\btwampfl.sys
2013-10-28 18:02 . 2013-10-28 18:02
2232024 ----a-wc:\windows\syste
m32\BcmBtRSupport.dll
2013-10-28 18:02 . 2013-10-28 18:02
170712 ----a-wc:\windows\syste
m32\drivers\bcbtums.sys
2013-10-11 15:30 . 2013-10-11 15:30
568640 ----a-wc:\windows\syste
m32\drivers\iaStor.sys
2013-10-11 15:21 . 2013-10-11 15:22
96768 ----a-wc:\windows\syste
m32\drivers\AtihdW76.sys
2013-10-11 15:21 . 2013-10-11 15:22
110080 ----a-wc:\windows\syste
m32\DelayAPO.dll
2013-10-11 15:20 . 2013-10-11 15:22
76288 ----a-wc:\windows\syste
m32\OpenVideo64.dll
2013-10-11 15:20 . 2013-10-11 15:22
64000 ----a-wc:\windows\syste
m32\OVDecode64.dll
2013-10-11 15:20 . 2013-10-11 15:22
56320 ----a-wc:\windows\SysWo
w64\OVDecode.dll
2013-10-11 15:20 . 2013-10-11 15:22
65536 ----a-wc:\windows\SysWo
w64\OpenVideo.dll
2013-10-11 15:20 . 2013-10-11 15:22
78848 ----a-wc:\windows\syste
m32\coinst_12.104.2.dll
2013-10-11 15:20 . 2013-10-11 15:22
222720 ----a-wc:\windows\syste
m32\clinfo.exe
2013-10-11 15:20 . 2013-10-11 15:22
5944264 ----a-wc:\windows\SysWo
w64\atiumdag.dll
2013-10-11 15:20 . 2013-10-11 15:22
4451288 ----a-wc:\windows\SysWo
w64\atiumdva.dll
2013-10-11 15:20 . 2013-10-11 15:22
19952640
----a-wc:\windo
ws\SysWow64\atioglxx.dll
2013-10-11 15:20 . 2013-10-11 15:22
120320 ----a-wc:\windows\syste
m32\atitmm64.dll
2013-10-11 15:20 . 2013-10-11 15:22
24316928
----a-wc:\windo
ws\system32\atio6axx.dll
2013-10-11 15:20 . 2012-03-29 17:35
5001856 ----a-wc:\windows\syste
m32\atiumd6a.dll
2013-10-11 15:20 . 2012-03-29 17:20
6985624 ----a-wc:\windows\syste
m32\atiumd64.dll
2013-10-11 15:20 . 2012-03-29 17:07
139696 ----a-wc:\windows\syste
m32\atiuxp64.dll
2013-10-11 15:20 . 2012-03-29 17:07
118584 ----a-wc:\windows\SysWo
w64\atiuxpag.dll
2013-10-11 15:20 . 2012-03-29 17:07
112440 ----a-wc:\windows\syste
m32\atiu9p64.dll
2013-10-11 15:20 . 2012-03-29 17:06
92304 ----a-wc:\windows\SysWo
w64\atiu9pag.dll
2013-10-11 15:20 . 2013-10-11 15:22
78432 ----a-wc:\windows\syste
m32\atimpc64.dll
78432
----a-w-
c:\windows\syste
71704
----a-w-
c:\windows\SysWo
71704
----a-w-
c:\windows\SysWo
581120 ----a-w-
c:\windows\syste
26112
----a-w-
c:\windows\syste
59392
----a-w-
c:\windows\syste
564736 ----a-w-
c:\windows\syste
44032
----a-w-
c:\windows\syste
34816
----a-w-
c:\windows\SysWo
241152 ----a-w-
c:\windows\syste
17920
----a-w-
c:\windows\syste
14848
----a-w-
c:\windows\SysWo
14848
----a-w-
c:\windows\syste
11664896
----a-w-
c:\windo
442368 ----a-w-
c:\windows\syste
970912 ----a-w-
c:\windows\SysWo
1155264 ----a-w-
c:\windows\syste
7233336 ----a-w-
c:\windows\SysWo
8272136 ----a-w-
c:\windows\syste
51200
----a-w-
c:\windows\syste
46080
----a-w-
c:\windows\SysWo
16082944
----a-w-
c:\windo
13703168
----a-w-
c:\windo
44544
----a-w-
c:\windows\syste
44032
----a-w-
c:\windows\SysWo
430080 ----a-w-
c:\windows\SysWo
163840 ----a-w-
c:\windows\syste
638464 ----a-w-
c:\windows\syste
54784
----a-w-
c:\windows\syste
53248
----a-w-
c:\windows\syste
15:22
50176
----a-w-
c:\windows\SysWo
15:22
43520
----a-w-
c:\windows\SysWo
15:22
798734 ----a-w-
c:\windows\SysWo
15:22
1187342 ----a-w-
c:\windows\syste
15:22
1061902 ----a-w-
c:\windows\syste
15:22
995342 ----a-w-
c:\windows\SysWo
15:22
29155328
----a-w-
c:\windo
15:22
23814656
----a-w-
c:\windo
14:58
1425408 ----a-w-
c:\windows\sttra
14:57
255488 ----a-w-
c:\windows\syste
14:57
655872 ------w-
c:\windows\syste
14:57
536576 ----a-w-
c:\windows\syste
14:57
4761600 ----a-w-
c:\windows\syste
14:57
450048 ----a-w-
c:\windows\syste
14:57
38400
----a-w-
c:\windows\syste
14:57
318464 ----a-w-
c:\windows\syste
14:57
1986048 ----a-w-
c:\windows\syste
14:57
1425408 ----a-w-
c:\windows\syste
14:57
577352 ----a-w-
c:\windows\syste
14:57
295240 ----a-w-
c:\windows\syste
14:57
245576 ----a-w-
c:\windows\syste
14:57
202056 ----a-w-
c:\windows\syste
14:57
182600 ----a-w-
c:\windows\syste
14:57
177992 ----a-w-
c:\windows\syste
14:57
169800 ----a-w-
c:\windows\syste
14:57
167752 ----a-w-
c:\windows\syste
14:57
155976 ----a-w-
c:\windows\syste
14:57
140104 ----a-w-
c:\windows\syste
14:57
139592 ----a-w-
c:\windows\syste
14:57
131912 ----a-w-
c:\windows\syste
ys;c:\windows\SYSNATIVE\DRIVERS\btwdpan.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\
windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
R3 DAMDrv;DAMDrv;c:\windows\system32\DRIVERS\DAMDrv64.sys;c:\windows\SYSNATIVE\D
RIVERS\DAMDrv64.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\driver
s\dmvsc.sys [x]
R3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\SysWOW64\flcdlo
ck.exe;c:\windows\SysWOW64\flcdlock.exe [x]
R3 hpCMSrv;HP Connection Manager 4 Service;c:\program files (x86)\Hewlett-Packar
d\HP Connection Manager\hpCMSrv.exe;c:\program files (x86)\Hewlett-Packard\HP Co
nnection Manager\hpCMSrv.exe [x]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys;c:\wind
ows\SYSNATIVE\Drivers\ANDROIDUSB.sys [x]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys;c:
\windows\SYSNATIVE\DRIVERS\htcnprot.sys [x]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\j
mcr.sys [x]
R3 johci;JMicron 1394 Filter Driver;c:\windows\system32\DRIVERS\johci.sys;c:\win
dows\SYSNATIVE\DRIVERS\johci.sys [x]
R3 MAFWPROFIRE;Service for M-Audio ProFire;c:\windows\system32\DRIVERS\MAudioPro
Fire.sys;c:\windows\SYSNATIVE\DRIVERS\MAudioProFire.sys [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program
files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe;c:\program files (x86)\McA
fee Security Scan\3.0.207\McCHSvc.exe [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhc
pDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Sha
red\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe;c:\program files (x86)\Common Files\R
oxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATI
VE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD
.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\W
atAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 PdiService;Portrait Displays SDK Service;c:\program files (x86)\Common Files\
Portrait Displays\Drivers\pdisrvc.exe;c:\program files (x86)\Common Files\Portra
it Displays\Drivers\pdisrvc.exe [x]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys;c:\windows\SYSNATI
VE\DRIVERS\avgidsha.sys [x]
S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys;c:\windows
\SYSNATIVE\DRIVERS\avgloga.sys [x]
S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVE
RS\avgmfx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys;c:\
windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x]
S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\D
RIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S0 MfeEpeOpal;MfeEpeOpal; [x]
S0 MfeEpePc;MfeEpePc; [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATI
VE\Drivers\PxHlpa64.sys [x]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys;c:\wi
ndows\SYSNATIVE\DRIVERS\avgidsdrivera.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys;c:\windows\SYS
NATIVE\DRIVERS\avgtdia.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsof
tbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\System32\drivers\psd.sys;c
:\windows\SYSNATIVE\drivers\psd.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\a
tiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMPPALR3;Intel Centrino Wireless Bluetooth + High Speed Service;c:\program files
\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHS
AmpPalService.exe [x]
S2 BcmBtRSupport;Bluetooth Driver Management Service;c:\windows\system32\BtwRSup
portService.exe;c:\windows\SYSNATIVE\BtwRSupportService.exe [x]
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Secur
ity Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program fi
les\Intel\BluetoothHS\BTHSSecurityMgr.exe [x]
S2 HP Power Assistant Service;HP Power Assistant Service;c:\program files\Hewlet
t-Packard\HP Power Assistant\HPPA_Service.exe;c:\program files\Hewlett-Packard\H
P Power Assistant\HPPA_Service.exe [x]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x
86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)
\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]
S2 HPFSService;File Sanitizer for HP ProtectTools;c:\program files (x86)\Hewlett
-Packard\File Sanitizer\HPFSService.exe;c:\program files (x86)\Hewlett-Packard\F
ile Sanitizer\HPFSService.exe [x]
S2 hpHotkeyMonitor;hpHotkeyMonitor;c:\program files (x86)\Hewlett-Packard\HP Hot
key Support\HPHotkeyMonitor.exe;c:\program files (x86)\Hewlett-Packard\HP Hotkey
Support\HPHotkeyMonitor.exe [x]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpser
vice.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Int
el\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)
\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing
Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program
files\Intel\iCLS Client\HeciServer.exe [x]
S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R)
Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x
86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [
x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\pro
gram files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_serv
ice.exe [x]
S2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent;c:\program
files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe;c:\program files\H
ewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [x]
S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrv
WFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Int
ernet Pass-Through\PassThruSvr.exe;c:\program files (x86)\HTC\Internet Pass-Thro
ugh\PassThruSvr.exe [x]
S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsv
c.exe;c:\program files (x86)\PDF Complete\pdfsvc.exe [x]
S2 RoxioBurnLauncher;Roxio Burn Launcher;c:\program files (x86)\Roxio\Roxio Burn
\RoxioBurnLauncher.exe;c:\program files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher
.exe [x]
S2 thinkupApache;thinkupApache;c:\bitnami\THINKU~1.8-1\apache2\bin\httpd.exe;c:\
bitnami\THINKU~1.8-1\apache2\bin\httpd.exe [x]
S2 thinkupMySQL;thinkupMySQL;c:\bitnami\thinkup-2.0.beta.8-1\mysql\bin\mysqld.ex
e;c:\bitnami\thinkup-2.0.beta.8-1\mysql\bin\mysqld.exe [x]
S2 uArcCapture;ArcCapture;c:\windows\SysWow64\ArcVCapRender\uArcCapture.exe;c:\w
indows\SysWow64\ArcVCapRender\uArcCapture.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:
\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
WebBrowser-{687578B9-7132-4A7A-80E4-30EE31099E03} - (no file)
AddRemove-{EE202411-2C26-49E8-9784-1BC1DBF7DE96} - c:\program files (x86)\Instal
lShield Installation Information\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}\setup.ex
e
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B667
08-40E2BE4D-pdfcService"
.
--------------------- LOCKED REGISTRY KEYS --------------------.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66
}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900
_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66
}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66
}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66
}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C
9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C
9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C
9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C40800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900
_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C40800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-
0800200C9A66}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C40800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-
444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B
0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B
0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B
0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing\WinZip]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC108002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-12-01 20:02:44
ComboFix-quarantined-files.txt 2013-12-01 20:02
ComboFix2.txt 2013-11-17 17:53
.
Pre-Run: 86,806,659,072 bytes free
Post-Run: 86,335,340,544 bytes free
.
- - End Of File - - ECD4A4FB856434A282FE7293D4AF55B3