ComboFix 14-06-10.01 - Phil 06/10/2014 12:01:16.1.8 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8124.5540 [GMT -4:00] Running from: c:\users\Phil\Downloads\ComboFix.exe AV: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} SP: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\Roaming c:\users\Phil\GoToAssistDownloadHelper.exe c:\windows\SysWow64\Packet.dll c:\windows\SysWow64\pthreadVC.dll c:\windows\SysWow64\wpcap.dll . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_NPF -------\Service_npf . . ((((((((((((((((((((((((( Files Created from 2014-05-10 to 2014-06-10 ))))))))))))))))))))))))))))))) . . 2014-06-10 16:05 . 2014-06-10 16:05 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-06-10 15:44 . 2014-06-10 15:44 -------- d-----w- c:\windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP 2014-06-10 14:26 . 2014-06-10 16:06 -------- d-----w- c:\users\Phil\AppData\Local\Temp 2014-06-10 14:22 . 2014-06-10 14:22 -------- d-----w- C:\NPE 2014-06-10 14:19 . 2014-06-10 14:28 -------- d-----w- c:\users\Phil\AppData\Local\NPE 2014-06-10 14:15 . 2014-06-10 15:50 -------- d-----w- c:\programdata\Norton 2014-06-09 21:17 . 2014-06-09 21:17 -------- d-----w- c:\program files\Enigma Software Group 2014-06-09 21:17 . 2014-06-09 21:17 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard 2014-06-09 20:09 . 2014-06-09 21:07 -------- d-----w- c:\programdata\RegRun 2014-06-09 20:01 . 2014-06-09 20:01 40720 ----a-w- c:\windows\system32\Partizan.exe 2014-06-09 19:57 . 2014-06-09 19:57 2 --shatr- c:\windows\winstart.bat 2014-06-09 19:56 . 2014-06-10 15:49 -------- d-----w- c:\program files (x86)\UnHackMe 2014-06-09 19:11 . 2014-06-09 19:11 423240 ----a-w- c:\windows\system32\drivers\aswsp.sys.1402341128709 2014-06-09 19:11 . 2014-06-09 19:11 1039096 ----a-w- c:\windows\system32\drivers\aswsnx.sys.1402341128709 2014-06-05 23:32 . 2014-06-10 16:06 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2014-06-05 23:32 . 2014-06-05 23:32 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware 2014-06-05 23:32 . 2014-06-05 23:32 -------- d-----w- c:\programdata\Malwarebytes 2014-06-05 23:32 . 2014-05-12 11:26 63704 ----a-w- c:\windows\system32\drivers\mwac.sys 2014-06-05 23:32 . 2014-05-12 11:26 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2014-06-05 23:32 . 2014-05-12 11:25 25816 ----a-w- c:\windows\system32\drivers\mbam.sys 2014-05-27 00:33 . 2014-05-27 00:33 -------- d-----w- c:\users\Phil\AppData\Roaming\VERIZON 2014-05-22 14:51 . 2014-06-10 15:56 -------- d-----w- c:\users\Phil\AppData\Roaming\Wise Disk Cleaner 2014-05-22 14:50 . 2014-05-22 14:50 -------- d-----w- c:\program files (x86)\Wise 2014-05-22 13:47 . 2014-05-22 13:47 -------- d-----w- c:\users\Phil\AppData\Roaming\Oracle 2014-05-22 13:47 . 2014-05-22 13:47 -------- d-----w- c:\program files (x86)\Java 2014-05-19 20:22 . 2014-05-19 20:25 -------- d-----w- c:\users\Phil\AppData\Roaming\WiseUpdate 2014-05-19 13:11 . 2014-05-19 13:11 -------- d-----w- c:\users\Default\AppData\Roaming\TuneUp Software 2014-05-17 15:32 . 2014-05-17 15:32 -------- d-----w- c:\users\Phil\AppData\Roaming\EPSON 2014-05-17 14:15 . 2014-05-17 14:15 -------- d-----w- c:\program files (x86)\Windows Sidebar 2014-05-17 13:35 . 2009-10-16 04:00 13824 ----a-w- c:\windows\system32\esxcdev.dll 2014-05-17 13:35 . 2009-10-16 04:00 132560 ----a-w- c:\windows\system32\esdevapp.exe 2014-05-17 13:35 . 2009-03-13 04:00 65793 ----a-w- c:\windows\system32\esfw7c.bin 2014-05-17 13:35 . 2009-03-13 04:00 230912 ----a-w- c:\windows\system32\esxuin7c.dll 2014-05-17 13:35 . 2009-03-13 04:00 221184 ----a-w- c:\windows\SysWow64\esint7c.dll 2014-05-17 13:35 . 2007-11-29 04:00 84992 ----a-w- c:\windows\system32\esxwia7c.dll 2014-05-17 13:35 . 2006-03-10 04:00 4608 ----a-w- c:\windows\system32\esxwiaml.dll 2014-05-17 13:35 . 2014-05-17 13:35 -------- d-----w- c:\program files (x86)\epson 2014-05-17 13:08 . 2014-02-19 05:52 159032 ----a-w- c:\windows\system32\ATL90.dll 2014-05-17 13:08 . 2014-05-17 13:10 -------- d-----w- c:\program files\Core Temp 2014-05-17 12:45 . 2014-06-10 15:44 -------- d-----w- c:\windows\system32\appmgmt 2014-05-16 20:06 . 2007-01-25 16:44 231424 ----a-w- c:\windows\system32\Spool\prtprocs\x64\hpzpp4wm.dll 2014-05-16 20:04 . 2014-06-05 23:38 -------- d-----w- C:\temp 2014-05-16 20:02 . 2009-07-14 01:41 101376 ----a-w- c:\windows\system32\Spool\prtprocs\x64\HPZPPWN7.DLL 2014-05-15 15:33 . 2014-05-15 15:33 -------- d-----w- c:\users\Phil\AppData\Roaming\AVG2014 2014-05-15 15:33 . 2014-05-15 15:33 -------- d-----w- c:\users\Phil\AppData\Roaming\TuneUp Software 2014-05-15 15:33 . 2014-05-15 15:34 -------- d-----w- c:\programdata\AVG2014 2014-05-15 15:33 . 2014-05-15 15:33 -------- d-----w- C:\$AVG 2014-05-15 15:32 . 2014-05-15 15:32 -------- d-----w- c:\program files (x86)\AVG 2014-05-15 15:25 . 2014-06-10 13:49 -------- d-----w- c:\programdata\MFAData 2014-05-15 15:25 . 2014-05-15 15:36 -------- d-----w- c:\users\Phil\AppData\Local\Avg2014 2014-05-15 15:25 . 2014-05-15 15:25 -------- d--h--w- c:\programdata\Common Files 2014-05-15 15:25 . 2014-05-15 15:25 -------- d-----w- c:\users\Phil\AppData\Local\MFAData 2014-05-15 14:57 . 2014-05-06 04:40 23544320 ----a-w- c:\windows\system32\mshtml.dll 2014-05-15 14:57 . 2014-05-06 03:00 84992 ----a-w- c:\windows\system32\mshtmled.dll 2014-05-15 14:57 . 2014-05-06 04:17 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2014-05-15 14:57 . 2014-05-06 03:07 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb 2014-05-15 14:57 . 2014-05-15 14:57 -------- d-----w- c:\program files\Common Files\DESIGNER 2014-05-15 14:19 . 2014-05-15 14:19 -------- d-----w- c:\windows\Sun 2014-05-15 14:08 . 2014-06-10 13:44 -------- d-----w- c:\users\Phil\AppData\Local\BrowserSafeguard 2014-05-15 13:53 . 2014-05-22 13:47 -------- d-----w- c:\programdata\Oracle 2014-05-15 13:53 . 2014-05-15 13:53 -------- d-----w- c:\program files (x86)\Common Files\Java 2014-05-15 13:53 . 2014-05-22 13:47 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2014-05-15 13:52 . 2014-05-15 13:52 -------- d-----w- c:\program files\003 2014-05-15 13:47 . 2014-05-15 13:47 -------- d-----w- c:\users\Phil\AppData\Local\Citrix 2014-05-15 13:46 . 2014-05-15 13:47 -------- d-----w- c:\users\Phil\AppData\Local\Deployment 2014-05-15 13:46 . 2014-05-15 13:46 -------- d-----w- c:\users\Phil\AppData\Local\Apps 2014-05-15 12:45 . 2014-05-15 12:45 -------- d-sh--w- c:\users\Phil\AppData\Local\EmieUserList 2014-05-15 12:45 . 2014-05-15 12:45 -------- d-sh--w- c:\users\Phil\AppData\Local\EmieSiteList 2014-05-15 03:40 . 2014-03-25 02:43 14175744 ----a-w- c:\windows\system32\shell32.dll 2014-05-15 03:40 . 2014-05-09 06:14 477184 ----a-w- c:\windows\system32\aepdu.dll 2014-05-15 03:40 . 2014-05-09 06:11 424448 ----a-w- c:\windows\system32\aeinv.dll 2014-05-13 18:20 . 2014-05-13 18:20 235800 ----a-w- c:\windows\system32\drivers\avgldx64.sys 2014-05-13 18:20 . 2014-05-13 18:20 273176 ----a-w- c:\windows\system32\drivers\avgtdia.sys 2014-05-13 18:06 . 2014-05-13 18:06 323352 ----a-w- c:\windows\system32\drivers\avgloga.sys 2014-05-13 18:05 . 2014-05-13 18:05 191768 ----a-w- c:\windows\system32\drivers\avgidsha.sys 2014-05-13 18:05 . 2014-05-13 18:05 152344 ----a-w- c:\windows\system32\drivers\avgdiska.sys 2014-05-13 18:05 . 2014-05-13 18:05 130328 ----a-w- c:\windows\system32\drivers\avgmfx64.sys 2014-05-13 18:04 . 2014-05-13 18:04 236312 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys 2014-05-13 18:04 . 2014-05-13 18:04 31512 ----a-w- c:\windows\system32\drivers\avgrkx64.sys 2014-05-13 17:10 . 2014-04-17 09:31 10651704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{EDE0FBFB-E71E-42D7-8F2E-D9B2AC8114CB}\mpengine.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-05-31 15:20 . 2014-02-12 19:05 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-05-31 15:20 . 2014-02-12 19:05 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-05-15 14:55 . 2014-02-12 22:50 93223848 ----a-w- c:\windows\system32\MRT.exe 2014-04-28 09:33 . 2014-04-28 09:33 370424 ----a-w- c:\windows\system32\wpcap.dll 2014-04-28 09:33 . 2014-04-28 09:33 36600 ----a-w- c:\windows\system32\drivers\npf.sys 2014-04-28 09:33 . 2014-04-28 09:33 107768 ----a-w- c:\windows\system32\Packet.dll 2014-03-31 13:35 . 2010-11-21 03:27 270496 ------w- c:\windows\system32\MpSigStub.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584] "RoboForm"="c:\program files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2014-04-19 109784] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2014-02-12 39408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IMSS"="c:\program files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [2010-05-03 112152] "NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-01-22 106496] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-12-21 959904] "Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232] "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-12 640376] "AVG_UI"="c:\program files (x86)\AVG\AVG2014\avgui.exe" [2014-05-13 5181456] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Core Temp.lnk - c:\program files\Core Temp\Core Temp.exe [2014-5-17 890016] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 0 (0x0) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "HideSCAHealth"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x] R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x] R3 rixdpcie;rixdpcie;c:\windows\system32\drivers\rixdpe64.sys;c:\windows\SYSNATIVE\drivers\rixdpe64.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 IntuitUpdateServiceV4;Intuit Update Service v4;c:\program files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe;c:\program files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [x] S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsha.sys [x] S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys;c:\windows\SYSNATIVE\DRIVERS\avgloga.sys [x] S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x] S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x] S1 Avgdiska;AVG Disk Driver;c:\windows\system32\DRIVERS\avgdiska.sys;c:\windows\SYSNATIVE\DRIVERS\avgdiska.sys [x] S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsdrivera.sys [x] S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgldx64.sys [x] S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys;c:\windows\SYSNATIVE\DRIVERS\avgtdia.sys [x] S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2014\avgidsagent.exe;c:\program files (x86)\AVG\AVG2014\avgidsagent.exe [x] S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2014\avgwdsvc.exe;c:\program files (x86)\AVG\AVG2014\avgwdsvc.exe [x] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x] S2 rimspci;rimspci;c:\windows\system32\DRIVERS\rimspe64.sys;c:\windows\SYSNATIVE\DRIVERS\rimspe64.sys [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x] S3 e1kexpress;Intel(R) Network Connections Driver K;c:\windows\system32\DRIVERS\e1k62x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1k62x64.sys [x] S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\drivers\HECIx64.sys;c:\windows\SYSNATIVE\drivers\HECIx64.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x] S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x] S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x] S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x] S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x] S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x] S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x] . . --- Other Services/Drivers In Memory --- . *NewlyCreated* - MBAMSWISSARMY *Deregistered* - ALSysIO . Contents of the 'Scheduled Tasks' folder . 2014-06-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-02-12 19:26] . 2014-06-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-02-12 19:26] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 108144] . ------- Supplementary Scan ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = https://www.google.com/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = <-loopback> IE: Append to existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert link target to existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: Customize Menu - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComCustomizeIEMenu.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Fill Forms - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComFillForms.html IE: Save Forms - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComSavePass.html IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 IE: Show RoboForm Toolbar - file://C:/Program Files (x86)/Siber Systems/AI RoboForm/RoboFormComShowToolbar.html TCP: DhcpNameServer = 192.168.1.1 DPF: {8BE5651C-D60B-4B59-B5B2-F0EB93733D17} - hxxps://www36.verizon.com/FiOSVoice/UnProtected/FiosVoiceVMUtil.CAB FF - ProfilePath - c:\users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\5fgg65mm.default-1400295701961\ FF - prefs.js: browser.startup.homepage - hxxp://www.nbcnews.com/|http://www.bloomberg.com/quickview/|https://accounts.google.com/ServiceLogin?service=mail&passive=true&rm=false&continue=https://mail.google.com/mail/&ss=1&scc=1<mpl=default<mplcache=2&emr=1|https://mightytext.net/web6/ FF - user.js: extensions.autoDisableScopes - 0 FF - user.js: extensions.shownSelectionUI - true . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKLM-Run- - (no file) HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file) . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_182_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_182_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_182_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_182_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_182.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.13" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_182.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_182.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_182.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Other Running Processes ------------------------ . c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Malwarebytes Anti-Malware\mbam.exe c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe . ************************************************************************** . Completion time: 2014-06-10 12:08:31 - machine was rebooted ComboFix-quarantined-files.txt 2014-06-10 16:08 . Pre-Run: 64,821,153,792 bytes free Post-Run: 63,873,654,784 bytes free . - - End Of File - - 9231E512960636F0DE8088AD536D88F0 A36C5E4F47E84449FF07ED3517B43A31