Big Big problem. Am sending this post from another computer.
Ran Combofix as per instructions. During process computer was rebooted and then log file created. Now no programmes will run. Get error message "Illegal operation attempted on a registary key that has been marked for deletion". Some system type programmes will run including Control Panel. Checked for restore points and am informed that none exist. After computer rebooteded as previously mentioned a quick defrag programme ran which is normal for the computer. This programme runs before the log in is requested. I have obtained the Combofix log file via a network connection and have attached it below.
Help please. Thanks.
ComboFix 13-05-10.03 - Ian 11/05/2013 11:48:17.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.8119.5668 [GMT 10:00]
Running from: c:\users\Ian\Desktop\ComboFix.exe
AV: Total Defense Anti-Virus *Enabled/Updated* {57B5C44D-AAB5-DBC9-741B-542BE5A132EA}
SP: Total Defense Anti-Virus *Enabled/Updated* {ECD425A9-8C8F-D447-4EAB-6F599E267857}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\AppleDev0\hemxccape.exe
c:\programdata\AppleDev0 . . . . Failed to delete
.
.
((((((((((((((((((((((((( Files Created from 2013-04-11 to 2013-05-11 )))))))))))))))))))))))))))))))
.
.
2013-05-11 02:01 . 2013-05-11 02:01 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-05-11 01:55 . 2013-05-11 02:04 -------- d-sh--w- c:\programdata\AppleDev0
2013-05-11 01:41 . 2013-05-11 01:41 16712 ----a-w- c:\windows\system32\drivers\PROCEXP113.SYS
2013-05-09 23:46 . 2013-05-09 23:46 -------- d-----w- c:\users\Ian\AppData\Roaming\Malwarebytes
2013-05-09 23:22 . 2013-05-09 23:22 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-05-09 23:22 . 2013-04-04 04:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-05-08 02:30 . 2013-05-08 02:30 -------- d-----w- c:\programdata\Malwarebytes
2013-04-29 01:32 . 2013-04-29 01:32 -------- d-----w- c:\program files (x86)\ERUNT
2013-04-27 12:13 . 2013-04-29 13:37 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2013-04-27 12:13 . 2009-01-25 02:14 17272 ----a-w- c:\windows\system32\sdnclean64.exe
2013-04-27 12:13 . 2013-04-27 12:13 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2
2013-04-27 12:11 . 2013-04-27 12:11 -------- d-----w- c:\users\Ian\AppData\Local\Programs
2013-04-27 08:33 . 2013-05-10 23:17 -------- d-----w- c:\users\Ian\AppData\Roaming\Mining
2013-04-25 12:33 . 2011-12-26 11:37 90608 ----a-w- c:\windows\system32\drivers\CLVirtualDrive.sys
2013-04-24 23:34 . 2013-04-24 23:34 -------- d-----w- c:\program files\WinRAR
2013-04-24 21:47 . 2013-04-27 08:45 -------- d-----w- c:\users\Ian\AppData\Roaming\.minecraft
2013-04-23 23:20 . 2013-04-12 14:45 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-23 13:05 . 2013-04-23 13:05 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-04-23 13:05 . 2013-04-03 19:35 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-04-23 13:03 . 2013-04-23 13:03 -------- d-----w- c:\programdata\McAfee
2013-04-13 07:18 . 2013-04-13 07:18 -------- d-----w- c:\program files (x86)\Common Files\Skype
2013-04-12 02:52 . 2013-04-12 02:52 -------- d-----w- c:\users\Ian\AppData\Local\Power2Go8
2013-04-12 01:52 . 2013-04-12 01:52 -------- d-----w- c:\program files (x86)\Common Files\CyberLink
2013-04-12 00:24 . 2013-04-12 00:24 26520 ----a-w- c:\program files (x86)\Mozilla Firefox\plugin-hang-ui.exe
2013-04-11 03:52 . 2013-01-24 06:01 223752 ----a-w- c:\windows\system32\drivers\fvevol.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-11 02:04 . 2011-03-29 01:36 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-11 02:04 . 2013-01-14 12:15 15712 ----a-w- c:\windows\system32\drivers\SWDUMon.sys
2013-04-16 12:28 . 2012-06-19 03:42 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-04-16 12:28 . 2012-06-19 03:42 691592 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-04-11 03:54 . 2013-01-13 00:11 72702784 ----a-w- c:\windows\system32\MRT.exe
2013-03-31 08:32 . 2013-03-31 08:32 82600 ----a-w- c:\windows\system32\drivers\amd_sata.sys
2013-03-31 08:32 . 2013-03-31 08:32 42664 ----a-w- c:\windows\system32\drivers\amd_xata.sys
2013-03-23 01:18 . 2013-03-23 01:18 6202880 ----a-w- c:\windows\SysWow64\atiumdag.dll
2013-03-23 01:18 . 2013-03-23 01:18 5005824 ----a-w- c:\windows\SysWow64\atiumdva.dll
2013-03-23 01:18 . 2013-03-23 01:18 1960448 ----a-w- c:\windows\SysWow64\atiumdmv.dll
2013-03-23 01:18 . 2013-03-23 01:18 1053184 ----a-w- c:\windows\system32\atiumd6v.dll
2013-03-23 01:18 . 2012-04-25 16:31 41984 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2013-03-23 01:18 . 2012-04-09 02:19 64000 ----a-w- c:\windows\system32\coinst.dll
2013-03-23 01:18 . 2012-04-09 01:56 4516352 ----a-w- c:\windows\system32\atiumd6a.dll
2013-03-23 01:18 . 2012-04-09 01:30 54784 ----a-w- c:\windows\system32\atiuxp64.dll
2013-03-23 01:18 . 2013-03-23 01:18 120320 ----a-w- c:\windows\system32\atitmm64.dll
2013-03-23 01:18 . 2012-04-25 16:31 32256 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2013-03-23 01:18 . 2012-04-09 01:44 7431168 ----a-w- c:\windows\system32\atiumd64.dll
2013-03-23 01:18 . 2012-04-09 01:30 44544 ----a-w- c:\windows\system32\atiu9p64.dll
2013-03-23 01:18 . 2013-03-23 01:18 56832 ----a-w- c:\windows\SysWow64\atimpc32.dll
2013-03-23 01:18 . 2013-03-23 01:18 56832 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2013-03-23 01:18 . 2013-03-23 01:18 56320 ----a-w- c:\windows\system32\atimpc64.dll
2013-03-23 01:18 . 2013-03-23 01:18 56320 ----a-w- c:\windows\system32\amdpcom64.dll
2013-03-23 01:18 . 2013-03-23 01:18 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2013-03-23 01:18 . 2013-03-23 01:18 503296 ----a-w- c:\windows\system32\atieclxx.exe
2013-03-23 01:18 . 2013-03-23 01:18 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2013-03-23 01:18 . 2013-03-23 01:18 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2013-03-23 01:18 . 2013-03-23 01:18 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2013-03-23 01:18 . 2013-03-23 01:18 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2013-03-23 01:18 . 2013-03-23 01:18 41984 ----a-w- c:\windows\system32\atig6txx.dll
2013-03-23 01:18 . 2013-03-23 01:18 339456 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2013-03-23 01:18 . 2013-03-23 01:18 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll
2013-03-23 01:18 . 2013-03-23 01:18 26181632 ----a-w- c:\windows\system32\atio6axx.dll
2013-03-23 01:18 . 2013-03-23 01:18 236544 ----a-w- c:\windows\system32\atiesrxx.exe
2013-03-23 01:18 . 2013-03-23 01:18 21504 ----a-w- c:\windows\system32\atimuixx.dll
2013-03-23 01:18 . 2013-03-23 01:18 19753472 ----a-w- c:\windows\SysWow64\atioglxx.dll
2013-03-23 01:18 . 2013-03-23 01:18 17408 ----a-w- c:\windows\system32\atig6pxx.dll
2013-03-23 01:18 . 2013-03-23 01:18 16096768 ----a-w- c:\windows\system32\aticaldd64.dll
2013-03-23 01:18 . 2013-03-23 01:18 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2013-03-23 01:18 . 2013-03-23 01:18 14848 ----a-w- c:\windows\system32\atiglpxx.dll
2013-03-23 01:18 . 2013-03-23 01:18 13770752 ----a-w- c:\windows\SysWow64\aticaldd.dll
2013-03-23 01:18 . 2013-03-23 01:18 11172864 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2013-03-23 01:18 . 2013-03-23 01:18 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2013-03-23 01:18 . 2013-03-23 01:18 514560 ----a-w- c:\windows\system32\atiadlxx.dll
2013-03-23 01:18 . 2013-03-23 01:18 360448 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2013-03-23 01:18 . 2013-03-23 01:18 159744 ----a-w- c:\windows\system32\atiapfxx.exe
2013-03-23 01:18 . 2012-04-25 17:56 909312 ----a-w- c:\windows\SysWow64\aticfx32.dll
2013-03-23 01:18 . 2012-04-25 17:47 6798848 ----a-w- c:\windows\SysWow64\atidxx32.dll
2013-03-23 01:18 . 2012-04-09 02:39 1067520 ----a-w- c:\windows\system32\aticfx64.dll
2013-03-23 01:18 . 2012-04-09 02:14 7476736 ----a-w- c:\windows\system32\atidxx64.dll
2013-03-19 06:04 . 2013-04-11 00:28 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-03-19 05:46 . 2013-04-11 00:28 43520 ----a-w- c:\windows\system32\csrsrv.dll
2013-03-19 05:04 . 2013-04-11 00:28 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-03-19 05:04 . 2013-04-11 00:28 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-03-19 04:47 . 2013-04-11 00:28 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll
2013-03-19 03:06 . 2013-04-11 00:28 112640 ----a-w- c:\windows\system32\smss.exe
2013-03-12 22:53 . 2013-01-12 12:12 861088 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-03-12 22:53 . 2013-01-12 12:12 782240 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-03-01 03:36 . 2013-04-11 00:28 3153408 ----a-w- c:\windows\system32\win32k.sys
2013-02-12 05:45 . 2013-03-23 12:00 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-02-12 05:45 . 2013-03-23 12:00 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-02-12 05:45 . 2013-03-23 12:00 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-02-12 05:45 . 2013-03-23 12:00 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-02-12 04:48 . 2013-03-23 12:00 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-02-12 04:48 . 2013-03-23 12:00 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-02-12 04:12 . 2013-03-20 22:43 19968 ----a-w- c:\windows\system32\drivers\usb8023.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress8"="c:\program files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe" [2013-03-05 1711168]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"CLVirtualDrive"="c:\program files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" [2013-03-05 492096]
.
c:\users\Ian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files (x86)\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OpenOffice.org 3.4.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2012-8-13 1199104]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideSCAHealth"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoThumbnailCache"= 1 (0x1)
"TaskbarNoNotification"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2011-02-24 03:33 79368 ----a-w- c:\windows\System32\UmxWNP.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS\0\0sdnclean64.exe
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2012-09-27 86528]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-02-28 161384]
R3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.362.0\SeaPort.exe [2012-02-14 240408]
R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 SWDUMon;SWDUMon;c:\windows\system32\DRIVERS\SWDUMon.sys [2013-05-11 15712]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2013-01-13 1255736]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 amd_sata;amd_sata;c:\windows\system32\drivers\amd_sata.sys [2013-03-31 82600]
S0 amd_xata;amd_xata;c:\windows\system32\drivers\amd_xata.sys [2013-03-31 42664]
S0 KmxAMRT;KmxAMRT;c:\windows\system32\DRIVERS\KmxAMRT.sys [2011-10-27 182352]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2008-06-15 55024]
S1 CLVirtualDrive;CLVirtualDrive;c:\windows\system32\DRIVERS\CLVirtualDrive.sys [2011-12-26 90608]
S1 KmxAgent;KmxAgent;c:\windows\system32\DRIVERS\kmxagent.sys [2011-10-26 113744]
S1 KmxCfg;KmxCfg;c:\windows\system32\DRIVERS\kmxcfg.sys [2011-09-06 365136]
S2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-09-05 169312]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2013-03-23 236544]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-09-13 361984]
S2 AODDriver4.2.0;AODDriver4.2.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-04-08 57472]
S2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.362.0\BBSvc.exe [2012-02-14 193816]
S2 CAAMSvc;CAAMSvc;c:\program files\Total Defense\Internet Security Suite\Anti-Virus\caamsvc.exe [2012-03-01 293704]
S2 CalendarSynchService;CalendarSynchService;c:\program files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe [2011-08-16 16384]
S2 ccSchedulerSVC;CA Common Scheduler Service;c:\program files\Total Defense\Internet Security Suite\ccschedulersvc.exe [2012-08-18 288336]
S2 HPAuto;HP Auto;c:\program files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-02-17 682040]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 OODefragAgent;O&O Defrag;c:\program files\OO Software\Defrag\oodag.exe [2012-11-30 3293552]
S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe [2012-04-04 1134584]
S2 RichVideo64;Cyberlink RichVideo64 Service(CRVS);c:\program files\CyberLink\Shared files\RichVideo64.exe [2012-12-21 390672]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2012-11-13 1103392]
S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2012-11-13 1369624]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2012-11-13 168384]
S2 UmxEngine;TM Engine;c:\program files\CA\SharedComponents\TMEngine\UmxEngine.exe [2011-04-04 920656]
S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys [2000-01-01 106664]
S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys [2000-01-01 226984]
S3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [2000-01-01 51712]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2000-01-01 96896]
S3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys [2000-01-01 75888]
S3 L1C;NDIS Miniport Driver for Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2012-04-12 104048]
S3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2000-01-01 50800]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2000-01-01 57512]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2013-05-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-19 12:28]
.
2013-05-11 c:\windows\Tasks\DriverUpdate Startup.job
- c:\program files (x86)\DriverUpdate\DriverUpdate.exe [2012-12-03 02:57]
.
2013-05-11 c:\windows\Tasks\HP Photo Creations Communicator.job
- c:\programdata\HP Photo Creations\Communicator.exe [2011-11-18 10:11]
.
2013-05-11 c:\windows\Tasks\HPCeeScheduleForIan.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15 11:43]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BeatsOSDApp"="c:\program files\IDT\WDM\beats64.exe" [2012-04-26 37888]
"HPSYSDRV"="c:\program files (x86)\Hewlett-Packard\HP Odometer\HPSYSDRV.EXE" [2008-11-20 62768]
"cctray"="c:\program files\Total Defense\Internet Security Suite\casc.exe" [2012-08-18 2711120]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2000-01-01 324096]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2012-04-24 1425408]
"OODefragTray"="c:\program files\OO Software\Defrag\oodtray.exe" [2012-11-30 4000112]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
FontCache
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Ian\AppData\Roaming\Mozilla\Firefox\Profiles\a7s0e0u1.default\
FF - ExtSQL: !HIDDEN! 2013-01-12 21:30;
smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-Olympus DSS - c:\programdata\AppleDev0\hemxccape.exe
Wow6432Node-HKLM-Run-NWEReboot - (no file)
Wow6432Node-HKLM-Run-Olympus DSS - c:\programdata\AppleDev0\hemxccape.exe
Notify-SDWinLogon - SDWinLogon.dll
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM_Wow6432Node-ActiveSetup-{438363A8-F486-4C37-834C-4955773CB3D3} - msiexec
AddRemove-{EE202411-2C26-49E8-9784-1BC1DBF7DE96} - c:\program files (x86)\InstallShield Installation Information\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2542283634-4230272488-366954266-1000_Classes\CLSID\{61B1A75C-BE76-5B4E-BBD7-B296509F128F}]
@Denied: (A 4) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG15.00.00.01PROFESSIONAL"="A7662F5BB48C24DCEE8CCACDC765F3AA482A0B8411667C9BF2059619FB183CC742327427C4A03AD53C409412A049D2E2CBA7781B75603048790E63CD9AE3392A3C5E9D38B77B235AD9AA486FA3CA0A81D3E43D6F6186992A655B00B820E7CA881195C8D3D6E4AC9FC4748C14E9BCBD33FEA6A6B15F58D77F16EE862FA6722C5582387797EF15C9F2BC796C8190E7BA36AEE7E9E9FDCAB01F3080F25E4EC3381C935A0D7251BA8E3049C9D409B906EF5F8AD49CEFCF4509EE98F924C2B912F1F80CC2D428D178B54B32AA19578BC56E94FBCFBCF2EB23EEECFCF860B01285FC1E79ED7B50C7E31EC70415EE672ECBEE52B0FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA9C6AECB7A5D1407FEBC9E127BECC74CA9C6AECB7A5D1407A9C6AECB7A5D140759CED4A8DF1FFD764BDB6C5C253B362EFEC26A1293609C80343EB5D457A593F36E87C6C1ED83D6421F6A73362EB6F28E12E4068027A5031EB8DCA5A9C75DBD283CDF0D49E3195FB7E1F7976E77E1CD16BF8B15954A33234BBED3F3AC5838FBACF4DBBA2F101792F8C5914FC5DC4C378955EE90820790089251A43EA2DCD68AE901E330E83357866FAEA9E1822B28B67455A847FDD6E94C3CADB3775020FD3B8DFAC627ED0456DE49B3186C6EA8CD69A4F4B85944AC8F20DA47C7E785DB967385B2B52B3CAD375877A216DFD689367D2B9D833E136975C8BEC40F288D442FAB082CC51CD4CCBFBEAEFC42808C7A01B55EECCEBEAC67B21E7F0098283FFDF5F10C1E702CBA74D9F5E8759E68E71AF1E959B448F9D871830C7908D9AAF09FC1E6CD7492E47629927262F51203BEFAED85F9797C60E0C749144B9F2A46FD390A41CD4E6E2396661C419C1A6712F2A4820863766138159F854857BC476547CA6DC850802992AA9ACD7E5DB2CCA9E1125C8378974D9AC61FE052C5895147AFC72CDADC114D3B47269FDDACC3D333F432CF21677E7A764D6329EF01E5CA7E9E1BA9E8BF3CC5F285DFB0235707736A9367539A9B028A8C02FC4BED39639E728021F0F90AF1E4658211C12C716886E12B0A813FC7AA7F73C5EEDDB3DF4818DDC3ABAD240FD4E1925D78BAE4CB084A7C2F649973E2364114F83117B8AD8FE7CE5D7E3117E63CD34E3BC823CF043BE2F394B6FD2DA6151BAD84B0D2871EE7A1A7C3537014EDB5B9414528AA83F289D4D3D3B1367911EEBC5051CC12C26EB3BE20F356846EC37EF266A82EA22BBD300C7F6CFDECF5E41CB8E24ED9F71DA30A1C436D2AA911CD0B478C946B8003C62056A95EB5705627AA089E6E9ECC6003B4F7EE3262C079B3835F58BE60DE5FB7FCE45CB0E8B462A2DA04122959FB66993278D5CB895038E04248425F847BA5FE1FD0F2EC1A50F36623EC1D77B816A235B4A480C41BFEF1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing\WinZip]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Cyberlink\MediaEspresso\DeviceDetector\DeviceDetector.exe
c:\program files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\HPTouchSmartSyncCalReminderApp.exe
.
**************************************************************************
.
Completion time: 2013-05-11 12:18:20 - machine was rebooted
ComboFix-quarantined-files.txt 2013-05-11 02:18
.
Pre-Run: 867,428,749,312 bytes free
Post-Run: 870,000,234,496 bytes free
.
- - End Of File - - C3886809C66FFAE866102E039B82D7D4