I have followed your instructions and both logs are located below. I must add that a small issue happened when running ComboFix. I shut off real-time protection for windows defender and disabled Avast shields for 1 hour as I thought it would stay off for an hour. When it rebooted Avast was re-enabled and a popup came telling me that ComboFix was seeking permission at which point I meant to click "allow it" but inadvertently clicked "not to allow it" and in the ComboFix window it stated log not created...Access Denied. I hope I didn't screw up the process as I permanently disabled all shields and reran ComboFix and it completed with a log which is below.
========== OTL ==========
========== COMMANDS ==========
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
HOSTS file reset successfully
OTL by OldTimer - Version 3.2.29.1 log created on 10092011_214250
Files\Folders moved on Reboot...
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
Registry entries deleted on Reboot...
ComboFix 11-10-09.01 - Kyle 09/10/2011 22:11:01.2.4 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.4029.2278 [GMT -4:00]
Running from: c:\users\Kyle\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\users\Kyle\AppData\Roaming\inst.exe
c:\windows\SysWow64\Dump\MiniDump.dmp
.
.
((((((((((((((((((((((((( Files Created from 2011-09-10 to 2011-10-10 )))))))))))))))))))))))))))))))
.
.
2011-10-10 02:21 . 2011-10-10 02:21 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{64C4F38B-E2B6-49B5-A6E2-E8E83ABD46A8}\offreg.dll
2011-10-10 02:19 . 2011-10-10 02:22 -------- d-----w- c:\users\Kyle\AppData\Local\temp
2011-10-10 02:19 . 2011-10-10 02:19 -------- d-----w- c:\users\Mcx1\AppData\Local\temp
2011-10-10 02:19 . 2011-10-10 02:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-10-10 01:42 . 2011-10-10 01:42 -------- d-----w- C:\_OTL
2011-10-09 15:59 . 2011-10-09 15:59 -------- d-----w- c:\users\Kyle\AppData\Local\VS Revo Group
2011-10-09 15:59 . 2009-12-30 15:21 31800 ----a-w- c:\windows\system32\drivers\revoflt.sys
2011-10-09 15:59 . 2011-10-09 15:59 -------- d-----w- c:\program files\VS Revo Group
2011-10-08 12:08 . 2011-10-08 12:08 -------- d-----w- c:\users\Kyle\AppData\Roaming\go
2011-10-08 01:39 . 2011-10-08 01:39 388096 ----a-r- c:\users\Kyle\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-10-08 01:39 . 2011-10-08 01:39 -------- d-----w- c:\program files (x86)\Trend Micro
2011-10-08 01:30 . 2011-10-08 12:09 -------- d-----w- c:\programdata\Easybits GO
2011-10-08 01:27 . 2011-10-08 01:27 25160 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-10-08 01:26 . 2011-10-08 01:26 -------- d-----w- c:\programdata\Hitman Pro
2011-10-07 12:15 . 2011-10-07 12:15 -------- d-----w- c:\program files (x86)\Common Files\xing shared
2011-10-07 12:03 . 2011-10-07 12:03 -------- d-----w- c:\users\Kyle\AppData\Local\Secunia PSI
2011-10-07 12:03 . 2011-10-07 12:03 -------- d-----w- c:\program files (x86)\Secunia
2011-10-07 05:51 . 2011-09-21 13:00 9049936 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{64C4F38B-E2B6-49B5-A6E2-E8E83ABD46A8}\mpengine.dll
2011-10-06 19:30 . 2011-10-06 19:30 -------- d-----w- c:\users\Kyle\AppData\Roaming\SUPERAntiSpyware.com
2011-10-06 19:29 . 2011-10-06 19:29 -------- d-----w- c:\programdata\!SASCORE
2011-10-06 18:14 . 2011-10-06 18:21 -------- d-----w- c:\users\Kyle\AppData\Roaming\Wise Registry Cleaner
2011-10-06 18:13 . 2011-10-06 18:13 -------- d-----w- c:\program files (x86)\Wise Registry Cleaner
2011-10-06 18:13 . 2011-10-07 17:58 -------- d-----w- c:\program files\MyDefrag v4.3.1
2011-10-06 18:13 . 2010-05-21 16:11 485376 ----a-w- c:\windows\system32\MyDefragScreenSaver_v4.3.1.scr
2011-10-06 18:13 . 2010-05-21 16:11 1147392 ----a-w- c:\windows\system32\MyDefragScreenSaver_v4.3.1.exe
2011-10-06 18:01 . 2011-10-06 18:01 -------- d-----w- C:\NVIDIA
2011-10-06 17:59 . 2011-10-06 17:59 -------- d-----w- c:\windows\en
2011-10-06 17:53 . 2011-10-06 17:53 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-10-06 17:28 . 2011-10-06 18:06 -------- d-----w- c:\users\UpdatusUser
2011-10-06 17:28 . 2011-10-06 18:07 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2011-10-06 17:00 . 2011-10-06 17:00 -------- d-----w- c:\users\Kyle\AppData\Local\LogMeIn
2011-10-06 17:00 . 2011-09-26 22:16 59776 ----a-w- c:\windows\system32\Spool\prtprocs\x64\LMIproc.dll
2011-10-06 16:59 . 2011-09-26 22:16 34688 ----a-w- c:\windows\system32\LMIport.dll
2011-10-06 16:59 . 2011-09-26 22:17 87456 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-10-06 16:59 . 2011-09-16 19:10 72216 ----a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2011-10-06 16:59 . 2011-09-26 22:16 80768 ----a-w- c:\windows\system32\LMIinit.dll
2011-10-06 16:59 . 2011-10-09 15:19 -------- d-----w- c:\programdata\LogMeIn
2011-10-06 16:59 . 2011-10-06 16:59 -------- d-----w- c:\program files (x86)\LogMeIn
2011-10-06 16:32 . 2011-10-06 16:32 -------- d-----w- c:\program files\CCleaner
2011-10-06 16:25 . 2011-07-11 13:45 2048 ----a-w- c:\windows\system32\tzres.dll
2011-10-06 16:25 . 2011-07-11 13:25 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-10-06 16:25 . 2011-06-17 16:16 451072 ----a-w- c:\windows\system32\winsrv.dll
2011-10-06 16:25 . 2011-08-10 12:14 2409784 ----a-w- c:\program files (x86)\Windows Mail\OESpamFilter.dat
2011-10-06 16:25 . 2011-08-10 12:14 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-10-06 16:25 . 2011-07-06 15:49 275456 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-10-06 16:25 . 2011-06-17 20:14 1427344 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-10-06 16:25 . 2011-06-20 08:45 4699536 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-09-16 19:10 . 2011-09-16 19:10 35616 ----a-w- c:\windows\system32\lmimirr.dll
2011-09-16 19:10 . 2011-09-16 19:10 14624 ----a-w- c:\windows\system32\lmimirr2.dll
2011-09-16 19:10 . 2011-09-16 19:10 11552 ----a-w- c:\windows\system32\drivers\lmimirr.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-07 12:14 . 2008-10-28 12:53 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
2011-10-07 12:13 . 2011-05-20 03:32 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-31 21:00 . 2010-12-08 21:59 25416 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-03 11:50 . 2011-02-23 05:39 836200 ----a-w- c:\windows\system32\easyupdatusapiu64.dll
2011-08-03 11:50 . 2011-02-23 05:39 6136936 ----a-w- c:\windows\system32\nvcpl.dll
2011-08-03 11:50 . 2011-02-23 05:39 3021416 ----a-w- c:\windows\system32\nvsvc64.dll
2011-08-03 11:50 . 2011-02-23 05:38 980072 ----a-w- c:\windows\system32\nvvsvc.exe
2011-08-03 11:50 . 2011-02-23 05:38 117864 ----a-w- c:\windows\system32\nvmctray.dll
2011-08-03 11:50 . 2010-07-09 20:27 61544 ----a-w- c:\windows\system32\nvshext.dll
2011-08-03 11:50 . 2009-06-30 01:08 2758760 ----a-w- c:\windows\system32\nvapi64.dll
2011-08-03 07:31 . 2011-08-03 07:31 311912 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2011-07-19 09:05 . 2010-04-17 17:30 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{a0b91230-b76e-4022-a900-e567a6fafbf5}"= "c:\program files (x86)\Element_Search\prxtbEle2.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{a0b91230-b76e-4022-a900-e567a6fafbf5}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 ----a-w- c:\program files (x86)\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{a0b91230-b76e-4022-a900-e567a6fafbf5}]
2011-01-17 14:54 175912 ----a-w- c:\program files (x86)\Element_Search\prxtbEle2.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{a0b91230-b76e-4022-a900-e567a6fafbf5}"= "c:\program files (x86)\Element_Search\prxtbEle2.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{a0b91230-b76e-4022-a900-e567a6fafbf5}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"ContentTransferWMDetector.exe"="c:\program files (x86)\Sony\Content Transfer\ContentTransferWMDetector.exe" [2009-11-19 583016]
"avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-05-10 3459712]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"B Register c:\program files (x86)\DivX\DivX Plus Player\DSEPlugins\DivXPlaybackModule.dll"="c:\windows\system32\rundll32.exe" [2006-11-02 44544]
"B Register c:\program files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXBannerAdPlugin.dll"="c:\windows\system32\rundll32.exe" [2006-11-02 44544]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2011-4-19 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 arusb_lhx;TP-LINK TL-WN821N 11N Wireless device driver;c:\windows\system32\DRIVERS\arusb_lhx.sys
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys
R3 ITEIO.SYS;ITEIO.SYS;c:\windows\System32\drivers\ITEIO.sys
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
R3 X6va001;X6va001;c:\users\Kyle\AppData\Local\Temp\001590.tmp
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S1 aswSnx;aswSnx;
S1 aswSP;aswSP;
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-10-06 140672]
S2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/04/17 18:09];c:\program files (x86)\CyberLink\PowerDVD9\000.fcl [2009-05-08 01:05 146928]
S2 aswFsBlk;aswFsBlk;
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys
S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-06-02 24576]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2011-09-26 375176]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2011-09-16 15928]
S2 ME Services Manager;ME Services Manager;c:\program files\intel\inteldh\msm\MSM.exe [2008-07-16 2476432]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2011-04-19 993848]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2011-04-19 399416]
S2 Software Services Manager;Software Services Manager;c:\program files\intel\inteldh\common\IntelDHSvcMgr.exe [2008-07-16 68496]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-08-03 379496]
S3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3249588682-3175115880-603202803-1000Core.job
- c:\users\Kyle\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-07 16:02]
.
2011-10-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3249588682-3175115880-603202803-1000UA.job
- c:\users\Kyle\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-07 16:02]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-05-10 12:10 134384 ----a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelSWUpdateClient"="c:\program files\intel\inteldh\common\SWUpdateClient.exe" [2008-07-16 179600]
"RtHDVCpl"="RAVCpl64.exe" [2008-08-04 6455840]
"Skytel"="Skytel.exe" [2008-08-04 1833504]
"Acer Empowering Technology Monitor"="c:\program files\Acer\Empowering Technology\SysMonitor.exe" [2008-06-02 319488]
"EmpoweringTechnology"="c:\program files\Acer\Empowering Technology\Framework.Launcher.exe" [2008-06-02 319488]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-08-25 153624]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-08-25 225816]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-08-25 199704]
"LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2011-09-16 57928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ehshell.exe]
"Debugger"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" -MceShellRedirect
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2382351
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=1009&s=1&o=vp64&d=0310&m=aspire_m5700
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
FF - ProfilePath - c:\users\Kyle\AppData\Roaming\Mozilla\Firefox\Profiles\uu03jf4n.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.intellicast.com/National/Radar/Current.aspx?animate=true
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKLM-Run-eRecoveryService - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{A0B91230-B76E-4022-A900-E567A6FAFBF5} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
HKLM-Run-Windows Defender - c:\program files (x86)\Windows Defender\MSASCui.exe
AddRemove-Coke - Pemberton - c:\windows\system32\Coke - Pemberton.scr
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\X6va001]
"ImagePath"="\??\c:\users\Kyle\AppData\Local\Temp\001590.tmp"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{B154377D-700F-42cc-9474-23858FBDF4BD}]
"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD9\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10x_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10x_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files\Intel\AMT\LMS.exe
c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
.
**************************************************************************
.
Completion time: 2011-10-09 22:28:06 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-10 02:28
.
Pre-Run: 475,717,967,872 bytes free
Post-Run: 475,498,745,856 bytes free
.
- - End Of File - - 3D1BA65A08ACABD3162ADDEB6E1D5721