Associate
- Joined
- 20 Aug 2012
- Posts
- 269
- Location
- Greater London
ok, so i did a combofix scan, because i think i have the dopewars virus, that's buried itself in the registry so i can't find it, and i got some results (obviously), and i was wondering whether someone could decipher them and tell me what to do about it:
ComboFix 12-10-04.02 - Adam 04/10/2012 19:35:50.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.44.1033.18.8191.5704 [GMT 1:00]
Running from: c:\users\Adam\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: AVG Anti-Virus Free Edition 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2012-09-04 to 2012-10-04 )))))))))))))))))))))))))))))))
.
.
2012-10-04 18:12 . 2011-02-17 17:26 81920 ----a-w- c:\windows\eSellerateControl350.dll
2012-10-04 18:12 . 2011-02-17 17:26 356352 ----a-w- c:\windows\eSellerateEngine.dll
2012-10-04 18:12 . 2012-10-04 18:20 -------- d-----w- c:\program files (x86)\Dope Wars Removal Tool
2012-10-03 18:23 . 2012-10-03 18:23 20992 ----a-w- c:\windows\bw-uninstall.exe
2012-10-01 16:04 . 2012-10-01 16:04 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-10-01 06:08 . 2012-10-01 06:08 -------- d-----w- c:\users\Adam\AppData\Roaming\AVG2013
2012-10-01 05:48 . 2012-07-23 14:59 24960 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-10-01 05:42 . 2012-10-01 05:42 -------- d-----w- c:\programdata\IObit
2012-09-30 21:28 . 2012-09-30 21:28 -------- d-----w- c:\users\Adam\AppData\Roaming\TuneUp Software
2012-09-30 21:28 . 2012-09-30 21:53 -------- d-----w- c:\programdata\AVG2013
2012-09-30 21:28 . 2012-09-30 21:28 -------- d-----w- C:\$AVG
2012-09-30 21:27 . 2012-09-30 21:27 -------- d-----w- c:\program files (x86)\AVG
2012-09-30 21:22 . 2012-10-04 17:07 -------- d-----w- c:\programdata\MFAData
2012-09-30 21:22 . 2012-09-30 21:30 -------- d-----w- c:\users\Adam\AppData\Local\Avg2013
2012-09-30 21:22 . 2012-09-30 21:22 -------- d--h--w- c:\programdata\Common Files
2012-09-30 21:22 . 2012-09-30 21:22 -------- d-----w- c:\users\Adam\AppData\Local\MFAData
2012-09-30 21:01 . 2012-10-04 17:49 -------- d-----w- c:\users\Adam\AppData\Roaming\IObit
2012-09-30 21:01 . 2012-09-30 21:01 -------- d-----w- c:\program files (x86)\IObit
2012-09-30 13:46 . 2012-09-30 13:46 -------- d-----w- c:\windows\PCHEALTH
2012-09-30 13:46 . 2012-09-30 13:46 -------- d-----w- c:\program files\Microsoft Sync Framework
2012-09-30 13:46 . 2012-09-30 13:46 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2012-09-30 13:44 . 2012-10-01 05:32 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2012-09-30 13:43 . 2012-09-30 13:43 -------- d-----w- c:\program files\Microsoft Analysis Services
2012-09-30 13:43 . 2012-09-30 13:43 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2012-09-30 13:37 . 2012-09-30 13:37 -------- d-----w- c:\windows\system32\appmgmt
2012-09-25 18:20 . 2012-09-25 18:20 11264 ----a-r- c:\users\Adam\AppData\Roaming\Microsoft\Installer\{98613C99-1399-416C-A07C-1EE1C585D872}\Icon98613C992.exe
2012-09-25 18:20 . 2012-10-01 05:25 -------- d-----w- c:\program files (x86)\Seagate
2012-09-25 18:19 . 2012-09-25 18:19 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-09-23 10:21 . 2012-09-23 10:21 -------- d-----w- c:\users\Adam\AppData\Local\ElevatedDiagnostics
2012-09-23 09:37 . 2012-10-01 05:26 -------- d-----w- c:\users\Adam\AppData\Roaming\Malwarebytes
2012-09-23 09:37 . 2012-10-01 05:35 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-09-23 09:37 . 2012-10-01 05:26 -------- d-----w- c:\programdata\Malwarebytes
2012-09-23 09:37 . 2012-09-07 16:04 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-21 18:41 . 2012-08-30 07:27 9308616 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C0D89985-0EE5-4C37-B807-8BF85E63C789}\mpengine.dll
2012-09-17 18:19 . 2012-09-17 18:19 -------- d-----w- c:\users\Adam\AppData\Roaming\PACE Anti-Piracy
2012-09-17 18:19 . 2012-09-17 18:19 -------- d-----w- c:\users\Adam\AppData\Local\PACE Anti-Piracy
2012-09-17 18:19 . 2012-09-17 18:19 -------- d-----w- c:\programdata\PACE Anti-Piracy
2012-09-17 17:59 . 2012-09-17 17:59 -------- d-----w- c:\users\Adam\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2012-09-17 17:59 . 2012-09-17 17:59 -------- d-----w- c:\users\Adam\AppData\Roaming\Adobe Mini Bridge CS5
2012-09-17 17:58 . 2012-09-17 17:58 56672 ----a-w- c:\windows\system32\drivers\avgidsha.sys
2012-09-15 09:07 . 2012-08-21 12:01 33240 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-09-15 09:06 . 2012-10-01 05:26 -------- d-----w- c:\program files\iTunes
2012-09-15 09:06 . 2012-10-01 05:26 -------- d-----w- c:\program files\iPod
2012-09-15 09:06 . 2012-10-01 05:25 -------- d-----w- c:\program files (x86)\iTunes
2012-09-14 04:34 . 2012-09-14 04:34 105312 ----a-w- c:\windows\system32\drivers\avgmfx64.sys
2012-09-13 19:09 . 2012-09-13 19:11 -------- d--h--w- c:\windows\msdownld.tmp
2012-09-12 18:53 . 2012-09-12 18:53 -------- d-----w- c:\users\Adam\AppData\Local\NVIDIA Corporation
2012-09-12 16:14 . 2012-10-01 05:26 -------- d-----w- c:\programdata\NVIDIA
2012-09-12 16:14 . 2012-10-01 05:58 -------- d-----w- c:\users\UpdatusUser
2012-09-12 16:14 . 2012-05-15 09:29 889664 ----a-w- c:\windows\system32\nvvsvc.exe
2012-09-12 16:14 . 2012-05-15 09:29 63296 ----a-w- c:\windows\system32\nvshext.dll
2012-09-12 16:14 . 2012-05-15 09:29 2561856 ----a-w- c:\windows\system32\nvsvcr.dll
2012-09-12 16:14 . 2012-05-15 09:29 118080 ----a-w- c:\windows\system32\nvmctray.dll
2012-09-12 16:14 . 2012-05-15 09:29 3149632 ----a-w- c:\windows\system32\nvsvc64.dll
2012-09-12 16:14 . 2012-05-15 09:28 6151488 ----a-w- c:\windows\system32\nvcpl.dll
2012-09-12 16:13 . 2012-05-15 10:48 68928 ----a-w- c:\windows\system32\OpenCL.dll
2012-09-12 16:13 . 2012-05-15 10:48 61248 ----a-w- c:\windows\SysWow64\OpenCL.dll
2012-09-12 16:13 . 2012-09-12 16:13 -------- d-----w- c:\programdata\NVIDIA Corporation
2012-09-12 10:47 . 2012-09-12 10:47 199520 ----a-w- c:\windows\system32\drivers\avgtdia.sys
2012-09-12 10:47 . 2012-09-12 10:47 175968 ----a-w- c:\windows\system32\drivers\avgldx64.sys
2012-09-10 19:19 . 2012-10-01 05:25 -------- d-----w- c:\program files (x86)\MSI Kombustor 2.3
2012-09-10 19:19 . 2012-10-01 05:25 -------- d-----w- c:\program files (x86)\MSI Afterburner
2012-09-08 09:15 . 2011-09-21 09:25 21992 ----a-w- c:\windows\system32\drivers\cpuz135_x64.sys
2012-09-07 21:45 . 2012-10-01 05:26 -------- d-----w- c:\program files\CPUID
2012-09-07 19:56 . 2012-10-01 05:26 -------- d-----w- c:\users\Adam\AppData\Local\Autodesk
2012-09-04 19:15 . 2012-09-04 19:15 -------- d-----w- c:\programdata\regid.1986-12.com.adobe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-21 12:01 . 2012-09-03 18:30 125872 ----a-w- c:\windows\system32\GEARAspi64.dll
2012-08-21 12:01 . 2012-09-03 18:30 106928 ----a-w- c:\windows\SysWow64\GEARAspi.dll
2012-08-13 15:40 . 2012-08-13 15:40 150880 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys
2012-08-10 03:52 . 2012-08-10 03:52 40288 ----a-w- c:\windows\system32\drivers\avgrkx64.sys
2012-08-09 12:56 . 2012-08-09 12:56 230240 ----a-w- c:\windows\system32\drivers\avgloga.sys
2012-07-09 12:42 . 2012-07-09 12:42 4547984 ----a-w- c:\windows\system32\usbaaplrc.dll
2012-07-09 12:42 . 2012-07-09 12:42 52736 ----a-w- c:\windows\system32\drivers\usbaapl64.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AVG_UI"="c:\program files (x86)\AVG\AVG2013\avgui.exe" [2012-09-14 3039352]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2013\avgrsa.exe /sync /restart
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-07 676936]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-09-03 1431888]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-07-09 52736]
R3 VST64_DPV;VST64_DPV;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
R3 VST64HWBS2;VST64HWBS2;c:\windows\system32\DRIVERS\VSTBS26.SYS [2009-06-10 411136]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys [2012-09-17 56672]
S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys [2012-08-09 230240]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2012-08-10 40288]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys [2012-08-13 150880]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2012-09-12 175968]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2012-09-14 105312]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2012-09-12 199520]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
S2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files (x86)\IObit\Advanced SystemCare 5\ASCService.exe [2012-05-26 913792]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2013\avgidsagent.exe [2012-08-20 5751928]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-08-20 184304]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [2011-09-21 21992]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-07 399432]
S2 mi-raysat_3dsmax2012_64;mental ray 3.9 Satellite for Autodesk 3ds Max 2012 64-bit - English 64-bit;c:\program files\Autodesk\3ds Max 2012\mentalimages\satellite\raysat_3dsmax2012_64server.exe [2011-02-22 86016]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-07 25928]
S3 nvoclk64;NVIDIA Enthusiasts Platform KDM;c:\windows\system32\DRIVERS\nvoclk64.sys [2009-09-15 42088]
S3 RTL8187B;NETGEAR WG111v3 Wireless-G USB Adapter Win7 Driver;c:\windows\system32\DRIVERS\wg111v3.sys [2009-11-18 446976]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-219815611-1869838397-937281674-1000Core.job
- c:\users\Adam\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-03 18:08]
.
2012-10-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-219815611-1869838397-937281674-1000UA.job
- c:\users\Adam\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-03 18:08]
.
.
--------- X64 Entries -----------
.
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10g_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10g_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10g.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10g.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10g.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10g.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
.
**************************************************************************
.
Completion time: 2012-10-04 19:43:39 - machine was rebooted
ComboFix-quarantined-files.txt 2012-10-04 18:43
.
Pre-Run: 172,490,903,552 bytes free
Post-Run: 172,401,983,488 bytes free
.
- - End Of File - - 72AE53C940A40FC630BF6317D882B586
ComboFix 12-10-04.02 - Adam 04/10/2012 19:35:50.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.44.1033.18.8191.5704 [GMT 1:00]
Running from: c:\users\Adam\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: AVG Anti-Virus Free Edition 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2012-09-04 to 2012-10-04 )))))))))))))))))))))))))))))))
.
.
2012-10-04 18:12 . 2011-02-17 17:26 81920 ----a-w- c:\windows\eSellerateControl350.dll
2012-10-04 18:12 . 2011-02-17 17:26 356352 ----a-w- c:\windows\eSellerateEngine.dll
2012-10-04 18:12 . 2012-10-04 18:20 -------- d-----w- c:\program files (x86)\Dope Wars Removal Tool
2012-10-03 18:23 . 2012-10-03 18:23 20992 ----a-w- c:\windows\bw-uninstall.exe
2012-10-01 16:04 . 2012-10-01 16:04 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-10-01 06:08 . 2012-10-01 06:08 -------- d-----w- c:\users\Adam\AppData\Roaming\AVG2013
2012-10-01 05:48 . 2012-07-23 14:59 24960 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-10-01 05:42 . 2012-10-01 05:42 -------- d-----w- c:\programdata\IObit
2012-09-30 21:28 . 2012-09-30 21:28 -------- d-----w- c:\users\Adam\AppData\Roaming\TuneUp Software
2012-09-30 21:28 . 2012-09-30 21:53 -------- d-----w- c:\programdata\AVG2013
2012-09-30 21:28 . 2012-09-30 21:28 -------- d-----w- C:\$AVG
2012-09-30 21:27 . 2012-09-30 21:27 -------- d-----w- c:\program files (x86)\AVG
2012-09-30 21:22 . 2012-10-04 17:07 -------- d-----w- c:\programdata\MFAData
2012-09-30 21:22 . 2012-09-30 21:30 -------- d-----w- c:\users\Adam\AppData\Local\Avg2013
2012-09-30 21:22 . 2012-09-30 21:22 -------- d--h--w- c:\programdata\Common Files
2012-09-30 21:22 . 2012-09-30 21:22 -------- d-----w- c:\users\Adam\AppData\Local\MFAData
2012-09-30 21:01 . 2012-10-04 17:49 -------- d-----w- c:\users\Adam\AppData\Roaming\IObit
2012-09-30 21:01 . 2012-09-30 21:01 -------- d-----w- c:\program files (x86)\IObit
2012-09-30 13:46 . 2012-09-30 13:46 -------- d-----w- c:\windows\PCHEALTH
2012-09-30 13:46 . 2012-09-30 13:46 -------- d-----w- c:\program files\Microsoft Sync Framework
2012-09-30 13:46 . 2012-09-30 13:46 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2012-09-30 13:44 . 2012-10-01 05:32 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2012-09-30 13:43 . 2012-09-30 13:43 -------- d-----w- c:\program files\Microsoft Analysis Services
2012-09-30 13:43 . 2012-09-30 13:43 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2012-09-30 13:37 . 2012-09-30 13:37 -------- d-----w- c:\windows\system32\appmgmt
2012-09-25 18:20 . 2012-09-25 18:20 11264 ----a-r- c:\users\Adam\AppData\Roaming\Microsoft\Installer\{98613C99-1399-416C-A07C-1EE1C585D872}\Icon98613C992.exe
2012-09-25 18:20 . 2012-10-01 05:25 -------- d-----w- c:\program files (x86)\Seagate
2012-09-25 18:19 . 2012-09-25 18:19 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-09-23 10:21 . 2012-09-23 10:21 -------- d-----w- c:\users\Adam\AppData\Local\ElevatedDiagnostics
2012-09-23 09:37 . 2012-10-01 05:26 -------- d-----w- c:\users\Adam\AppData\Roaming\Malwarebytes
2012-09-23 09:37 . 2012-10-01 05:35 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-09-23 09:37 . 2012-10-01 05:26 -------- d-----w- c:\programdata\Malwarebytes
2012-09-23 09:37 . 2012-09-07 16:04 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-21 18:41 . 2012-08-30 07:27 9308616 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C0D89985-0EE5-4C37-B807-8BF85E63C789}\mpengine.dll
2012-09-17 18:19 . 2012-09-17 18:19 -------- d-----w- c:\users\Adam\AppData\Roaming\PACE Anti-Piracy
2012-09-17 18:19 . 2012-09-17 18:19 -------- d-----w- c:\users\Adam\AppData\Local\PACE Anti-Piracy
2012-09-17 18:19 . 2012-09-17 18:19 -------- d-----w- c:\programdata\PACE Anti-Piracy
2012-09-17 17:59 . 2012-09-17 17:59 -------- d-----w- c:\users\Adam\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2012-09-17 17:59 . 2012-09-17 17:59 -------- d-----w- c:\users\Adam\AppData\Roaming\Adobe Mini Bridge CS5
2012-09-17 17:58 . 2012-09-17 17:58 56672 ----a-w- c:\windows\system32\drivers\avgidsha.sys
2012-09-15 09:07 . 2012-08-21 12:01 33240 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-09-15 09:06 . 2012-10-01 05:26 -------- d-----w- c:\program files\iTunes
2012-09-15 09:06 . 2012-10-01 05:26 -------- d-----w- c:\program files\iPod
2012-09-15 09:06 . 2012-10-01 05:25 -------- d-----w- c:\program files (x86)\iTunes
2012-09-14 04:34 . 2012-09-14 04:34 105312 ----a-w- c:\windows\system32\drivers\avgmfx64.sys
2012-09-13 19:09 . 2012-09-13 19:11 -------- d--h--w- c:\windows\msdownld.tmp
2012-09-12 18:53 . 2012-09-12 18:53 -------- d-----w- c:\users\Adam\AppData\Local\NVIDIA Corporation
2012-09-12 16:14 . 2012-10-01 05:26 -------- d-----w- c:\programdata\NVIDIA
2012-09-12 16:14 . 2012-10-01 05:58 -------- d-----w- c:\users\UpdatusUser
2012-09-12 16:14 . 2012-05-15 09:29 889664 ----a-w- c:\windows\system32\nvvsvc.exe
2012-09-12 16:14 . 2012-05-15 09:29 63296 ----a-w- c:\windows\system32\nvshext.dll
2012-09-12 16:14 . 2012-05-15 09:29 2561856 ----a-w- c:\windows\system32\nvsvcr.dll
2012-09-12 16:14 . 2012-05-15 09:29 118080 ----a-w- c:\windows\system32\nvmctray.dll
2012-09-12 16:14 . 2012-05-15 09:29 3149632 ----a-w- c:\windows\system32\nvsvc64.dll
2012-09-12 16:14 . 2012-05-15 09:28 6151488 ----a-w- c:\windows\system32\nvcpl.dll
2012-09-12 16:13 . 2012-05-15 10:48 68928 ----a-w- c:\windows\system32\OpenCL.dll
2012-09-12 16:13 . 2012-05-15 10:48 61248 ----a-w- c:\windows\SysWow64\OpenCL.dll
2012-09-12 16:13 . 2012-09-12 16:13 -------- d-----w- c:\programdata\NVIDIA Corporation
2012-09-12 10:47 . 2012-09-12 10:47 199520 ----a-w- c:\windows\system32\drivers\avgtdia.sys
2012-09-12 10:47 . 2012-09-12 10:47 175968 ----a-w- c:\windows\system32\drivers\avgldx64.sys
2012-09-10 19:19 . 2012-10-01 05:25 -------- d-----w- c:\program files (x86)\MSI Kombustor 2.3
2012-09-10 19:19 . 2012-10-01 05:25 -------- d-----w- c:\program files (x86)\MSI Afterburner
2012-09-08 09:15 . 2011-09-21 09:25 21992 ----a-w- c:\windows\system32\drivers\cpuz135_x64.sys
2012-09-07 21:45 . 2012-10-01 05:26 -------- d-----w- c:\program files\CPUID
2012-09-07 19:56 . 2012-10-01 05:26 -------- d-----w- c:\users\Adam\AppData\Local\Autodesk
2012-09-04 19:15 . 2012-09-04 19:15 -------- d-----w- c:\programdata\regid.1986-12.com.adobe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-21 12:01 . 2012-09-03 18:30 125872 ----a-w- c:\windows\system32\GEARAspi64.dll
2012-08-21 12:01 . 2012-09-03 18:30 106928 ----a-w- c:\windows\SysWow64\GEARAspi.dll
2012-08-13 15:40 . 2012-08-13 15:40 150880 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys
2012-08-10 03:52 . 2012-08-10 03:52 40288 ----a-w- c:\windows\system32\drivers\avgrkx64.sys
2012-08-09 12:56 . 2012-08-09 12:56 230240 ----a-w- c:\windows\system32\drivers\avgloga.sys
2012-07-09 12:42 . 2012-07-09 12:42 4547984 ----a-w- c:\windows\system32\usbaaplrc.dll
2012-07-09 12:42 . 2012-07-09 12:42 52736 ----a-w- c:\windows\system32\drivers\usbaapl64.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AVG_UI"="c:\program files (x86)\AVG\AVG2013\avgui.exe" [2012-09-14 3039352]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2013\avgrsa.exe /sync /restart
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-07 676936]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-09-03 1431888]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-07-09 52736]
R3 VST64_DPV;VST64_DPV;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
R3 VST64HWBS2;VST64HWBS2;c:\windows\system32\DRIVERS\VSTBS26.SYS [2009-06-10 411136]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys [2012-09-17 56672]
S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys [2012-08-09 230240]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2012-08-10 40288]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys [2012-08-13 150880]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2012-09-12 175968]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2012-09-14 105312]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2012-09-12 199520]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
S2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files (x86)\IObit\Advanced SystemCare 5\ASCService.exe [2012-05-26 913792]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2013\avgidsagent.exe [2012-08-20 5751928]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-08-20 184304]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [2011-09-21 21992]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-07 399432]
S2 mi-raysat_3dsmax2012_64;mental ray 3.9 Satellite for Autodesk 3ds Max 2012 64-bit - English 64-bit;c:\program files\Autodesk\3ds Max 2012\mentalimages\satellite\raysat_3dsmax2012_64server.exe [2011-02-22 86016]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-07 25928]
S3 nvoclk64;NVIDIA Enthusiasts Platform KDM;c:\windows\system32\DRIVERS\nvoclk64.sys [2009-09-15 42088]
S3 RTL8187B;NETGEAR WG111v3 Wireless-G USB Adapter Win7 Driver;c:\windows\system32\DRIVERS\wg111v3.sys [2009-11-18 446976]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-219815611-1869838397-937281674-1000Core.job
- c:\users\Adam\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-03 18:08]
.
2012-10-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-219815611-1869838397-937281674-1000UA.job
- c:\users\Adam\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-03 18:08]
.
.
--------- X64 Entries -----------
.
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10g_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10g_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10g.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10g.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10g.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10g.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
.
**************************************************************************
.
Completion time: 2012-10-04 19:43:39 - machine was rebooted
ComboFix-quarantined-files.txt 2012-10-04 18:43
.
Pre-Run: 172,490,903,552 bytes free
Post-Run: 172,401,983,488 bytes free
.
- - End Of File - - 72AE53C940A40FC630BF6317D882B586