Thank you so much that worked

i did the combo fix and here is the log:
ComboFix 11-01-20.04 - Ian Young 01/21/2011 15:02:44.1.4 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.8190.6495 [GMT -6:00]
Running from: c:\users\Ian Young\Saved Games\Desktop\ComboFix.exe
Command switches used :: c:\users\Ian Young\Saved Games\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\32788R22FWJFW
c:\32788r22fwjfw\EN-US\cmd.cfxxe.mui
c:\hp\KBD\KbdStub.EXE
c:\program files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
c:\program files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe
c:\program files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe
c:\program files (x86)\iTunes\iTunesHelper.exe
c:\program files (x86)\Java\jre1.6.0_03\bin\jusched.exe
c:\program files (x86)\QuickTime\QTTask.exe
c:\program files (x86)\Search Toolbar
c:\program files (x86)\Search Toolbar\icon.ico
c:\program files (x86)\Search Toolbar\SearchToolbarUninstall.exe
c:\program files (x86)\Search Toolbar\SearchToolbarUpdater.exe
c:\program files (x86)\whitesmoketoolbar
c:\program files (x86)\whitesmoketoolbar\chrome\content\lib\external.js
c:\program files (x86)\whitesmoketoolbar\chrome\content\lib\vmncode.js
c:\program files (x86)\whitesmoketoolbar\chrome\content\vmncode.js
c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.
www.Facebook\skin\scripts\defscript.js
c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.
www.Twitter\js\jquery.js
c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.
www.Twitter\js\scripts.js
c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.
www.Twitter\skin\scripts\defscript.js
c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.
www.WebTV\skin\scripts\defscript.js
c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.
www.YouTube\js\jquery-1.3.2.min.js
c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.
www.YouTube\js\jquery.autocomplete.min.js
c:\program files (x86)\whitesmoketoolbar\chrome\content\widgets\net.vmn.
www.YouTube\skin\scripts\defscript.js
c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\default\scripts\defscript.js
c:\program files (x86)\whitesmoketoolbar\chrome\skin\lib\panels\gameData.js
c:\program files (x86)\whitesmoketoolbar\components\windowmediator.js
c:\program files (x86)\whitesmoketoolbar\uninstall.exe
c:\program files (x86)\whitesmoketoolbar\whitesmoketoolbar.dll
c:\programdata\Microsoft\Windows\Start Menu\Programs\System Tool
c:\programdata\Microsoft\Windows\Start Menu\Programs\System Tool\System Tool 2011.lnk
c:\programdata\V7IFM37E.exe
c:\programdata\vlc-1.0.0-win32.exe
c:\programdata\vlc-1.0.1-win32.exe
c:\programdata\vlc-1.0.3-win32.exe
c:\users\Ian Young\AppData\Roaming\Adobe\AdobeUpdate .exe
c:\users\Ian Young\AppData\Roaming\sdhkryu.bat
C:\whtsmk.exe
c:\windows\system32\FastUv32.dll
c:\windows\system32\jusched.exe
c:\windows\SysWow64\audition.dll
c:\windows\SysWow64\FastUv32.dll
c:\windows\SysWow64\jusched.exe
c:\windows\Tasks\At1.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At14.job
c:\windows\Tasks\At15.job
c:\windows\Tasks\At16.job
c:\windows\Tasks\At17.job
Code:
<pre>
c:\hp\KBD\KbdStub .exe --->c:\hp\KBD\KbdStub.exe
c:\program files (x86)\Adobe\Reader 8.0\Reader\Reader_sl .exe --->c:\program files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier .exe --->c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
c:\program files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth .exe --->c:\program files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe
c:\program files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler .exe --->c:\program files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
</pre>
.
.
((((((((((((((((((((((((( Files Created from 2010-12-21 to 2011-01-21 )))))))))))))))))))))))))))))))
.
2011-01-21 21:12 . 2011-01-21 21:12 -------- d-----w- c:\users\Ian Young\AppData\Local\temp
2011-01-21 21:12 . 2011-01-21 21:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-21 15:44 . 2011-01-21 16:27 -------- d-----w- c:\users\Ian Young\AppData\Local\Temp(21)
2011-01-20 22:10 . 2011-01-20 22:10 -------- d-----w- C:\_OTL
2011-01-17 14:47 . 2011-01-17 14:53 34560 ----a-w- c:\windows\SysWow64\drivers\Normandy.sys
2011-01-02 05:23 . 2011-01-02 05:23 -------- d-----w- c:\program files (x86)\ERUNT
2011-01-02 05:02 . 2010-11-02 06:29 660760 ----a-w- c:\program files\Internet Explorer\iexplore.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-23 22:13 . 2010-11-11 15:15 0 ----a-w- c:\users\Ian Young\AppData\Local\Cmetuxeg.bin
2009-03-16 19:36 . 2009-03-16 19:36 1691464 ----a-w- c:\program files\dsetup32.dll
2009-03-16 19:35 . 2009-03-16 19:35 525128 ----a-w- c:\program files\DXSETUP.exe
2009-03-16 19:35 . 2009-03-16 19:35 94024 ----a-w- c:\program files\DSETUP.dll
.
Code:
<pre>
c:\program files (x86)\HP\HP Software Update\HPWuSchd2 .exe
c:\program files (x86)\iTunes\iTunesHelper .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{f999a48b-1950-4d81-9971-79018f807b4b}]
2010-10-18 10:26 3908192 ----a-w- c:\program files (x86)\FreeOnlineRadioPlayerRecorder\tbFre0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{f999a48b-1950-4d81-9971-79018f807b4b}"= "c:\program files (x86)\FreeOnlineRadioPlayerRecorder\tbFre0.dll" [2010-10-18 3908192]
[HKEY_CLASSES_ROOT\clsid\{f999a48b-1950-4d81-9971-79018f807b4b}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1555968]
"Weather"="c:\program files (x86)\AWS\WeatherBug\Weather.exe" [2007-08-29 1347584]
"AROReminder"="c:\program files (x86)\Advanced Registry Optimizer\ARO.exe" [2008-08-22 2084480]
"Steam"="c:\program files (x86)\steam\steam.exe" [2010-11-20 1242448]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask .exe -atboottime" [X]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"HP Health Check Scheduler"="c:\program files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-02 75008]
"SunJavaUpdateSched"="c:\program files (x86)\Java\jre1.6.0_03\bin\jusched.exe" [N/A]
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-04-13 47392]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [N/A]
"nmctxth"="c:\program files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-12 642856]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [N/A]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe" [2010-06-30 231888]
c:\users\Ian Young\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files (x86)\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-12 136176]
R2 LinksysUpdater;Linksys Updater;c:\program files (x86)\Linksys\Linksys Updater\bin\LinksysUpdater.exe [2008-11-13 204800]
R3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;c:\windows\system32\drivers\BVRPMPR5a64.SYS [2009-06-11 35840]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800]
R3 Normandy;Normandy SR2; [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2010-04-20 50688]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2010-04-29 335288]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-08-27 1253376]
S2 HPBtnSrv;HP Chasis Button Service;c:\hp\HPEZBTN\HPBtnSrv.exe [2007-05-29 198240]
S2 McciCMService64;McciCMService64;c:\program files\Common Files\Motive\McciCMService.exe [2009-08-14 517632]
S3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\system32\drivers\HCW85BDA.sys [2008-12-04 1686528]
S3 netr28x;Ralink 802.11n Wireless Driver for Windows Vista;c:\windows\system32\DRIVERS\netr28x.sys [2008-06-09 459776]
.
Contents of the 'Scheduled Tasks' folder
2011-01-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-12 19:55]
2011-01-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-12 19:55]
2011-01-21 c:\windows\Tasks\User_Feed_Synchronization-{2B569909-EA70-4117-81A1-F0AA99D8121D}.job
- c:\windows\system32\msfeedssync.exe [2011-01-02 04:25]
.
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-01 138264]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-01 203288]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-01 167448]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-06-11 178712]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-28 16141344]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-28 82464]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Pavilion&pf=cndt
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {4ECE056F-E50F-4F9D-B069-EB342D21F26A} - hxxp://photos1.walmart.com/WalmartActivia3.cab
FF - ProfilePath - c:\users\Ian Young\AppData\Roaming\Mozilla\Firefox\Profiles\ocaw0gfp.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2737658&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://forums.spybot.info/showthread.php?t=288
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: FreeOnlineRadioPlayerRecorder Toolbar: {f999a48b-1950-4d81-9971-79018f807b4b} - %profile%\extensions\{f999a48b-1950-4d81-9971-79018f807b4b}
FF - Ext: Search Toolbar:
searchtoolbar@zugo.com - %profile%\extensions\searchtoolbar@zugo.com
FF - Ext: MediaBar: {E84D42CA-64EB-11DE-A65F-8C3656D89593} - %profile%\extensions\{E84D42CA-64EB-11DE-A65F-8C3656D89593}
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{F999A48B-1950-4D81-9971-79018F807B4B} - (no file)
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b1,ce,b1,6b,19,6e,d1,49,9c,38,11,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b1,ce,b1,6b,19,6e,d1,49,9c,38,11,\
[HKEY_USERS\S-1-5-21-2015652920-1189781164-2704344669-1000\¬ î**]
@Allowed: (Read) (RestrictedCode)
"MachineID"=hex:f2,29,d3,52,f6,70,cc,00
DUMPHIVE0.003 (REGF)
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
Completion time: 2011-01-21 15:14:09
ComboFix-quarantined-files.txt 2011-01-21 21:14
ComboFix2.txt 2011-01-21 15:44
Pre-Run: 379,807,338,496 bytes free
Post-Run: 379,759,349,760 bytes free
- - End Of File - - 2FF361540F76C7FFC8B1A169E24795C1