Related:
- Flash player not working
- Adobe flash player download - Download - Other
- Snapchat flash not working - Guide
- Mumu player 12 - Download - Android emulators
- Msi app player - Download - Android emulators
- Flash drive/card tester - Download - Backup and recovery
5 responses
Anonymous User
Oct 13, 2011 at 10:02 AM
Oct 13, 2011 at 10:02 AM
Try this
Open IE 9
Go to Tools-internet options
Click on Advanced tab
then browse to the Accelerated graphics section.(first one on top)
Click to select the Use software rendering instead of GPU rendering check box.
Click Apply, and then click OK.
Restart IE 9 and let me know how it works.
If this doesnt then say me what specific error you receive
Open IE 9
Go to Tools-internet options
Click on Advanced tab
then browse to the Accelerated graphics section.(first one on top)
Click to select the Use software rendering instead of GPU rendering check box.
Click Apply, and then click OK.
Restart IE 9 and let me know how it works.
If this doesnt then say me what specific error you receive
Anonymous User
Oct 15, 2011 at 03:17 AM
Oct 15, 2011 at 03:17 AM
Ok if everything looks ok,we can shift our focus on malwares especially exploits which can cause issues with video sites
First step, boot your system in safe mode with networking
1. Download Combofix to your desktop.
http://www.combofix.org/download.php
2.Close all open Windows including this one.
Close or disable all running Antivirus, Antispyware, and Firewall programs as they may interfere with the proper running of ComboFix.
3. Double click on the ComboFix icon.
Windows is issuing this prompt because ComboFix does not have a digital signature. This is perfectly normal and safe and you can click on the Run button to continue.
4. Accept the disclaimer and the recovery
5.You should now press the Yes button to continue. If at any time during the Recovery Console installation you receive a message stating that it failed to install, please allow ComboFix to continue with the scan of your computer.
ComboFix will disconnect your computer from the Internet, so do not be surprised or concerned if you receive any warnings stating that you are no longer on the Internet. When ComboFix has finished it will automatically restore your Internet connection.
If you see your Windows desktop disappear, do not worry. This is normal and ComboFix will restore your desktop before it is finished. Eventually you will see a new screen that states the program is almost finished and telling you the programs log file, or report, will be located at C:\ComboFix.txt.
During the process, please do not mouse click nor must you tap on the keyboard. Let the tool run.
Let me know how it works after the scan,upload the log
First step, boot your system in safe mode with networking
1. Download Combofix to your desktop.
http://www.combofix.org/download.php
2.Close all open Windows including this one.
Close or disable all running Antivirus, Antispyware, and Firewall programs as they may interfere with the proper running of ComboFix.
3. Double click on the ComboFix icon.
Windows is issuing this prompt because ComboFix does not have a digital signature. This is perfectly normal and safe and you can click on the Run button to continue.
4. Accept the disclaimer and the recovery
5.You should now press the Yes button to continue. If at any time during the Recovery Console installation you receive a message stating that it failed to install, please allow ComboFix to continue with the scan of your computer.
ComboFix will disconnect your computer from the Internet, so do not be surprised or concerned if you receive any warnings stating that you are no longer on the Internet. When ComboFix has finished it will automatically restore your Internet connection.
If you see your Windows desktop disappear, do not worry. This is normal and ComboFix will restore your desktop before it is finished. Eventually you will see a new screen that states the program is almost finished and telling you the programs log file, or report, will be located at C:\ComboFix.txt.
During the process, please do not mouse click nor must you tap on the keyboard. Let the tool run.
Let me know how it works after the scan,upload the log
Here is the log.Hope the problem is somewhere in there.
Thanks
ComboFix 11-10-16.03 - zyleissvort 17/10/2011 13:09:35.2.4 - x64 NETWORK
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.3959.3281 [GMT 2:00]
Running from: c:\users\zyleissvort\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\zyleissvort\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
.
.
((((((((((((((((((((((((( Files Created from 2011-09-17 to 2011-10-17 )))))))))))))))))))))))))))))))
.
.
2011-10-17 11:18 . 2011-10-17 11:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-10-17 10:52 . 2011-09-12 15:26 9049936 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-17 10:52 . 2011-10-17 11:00 69000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A1E6C2F4-2D0D-4128-8836-E1A41F35C46F}\offreg.dll
2011-10-17 10:52 . 2011-09-12 15:26 9049936 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A1E6C2F4-2D0D-4128-8836-E1A41F35C46F}\mpengine.dll
2011-10-17 10:52 . 2011-10-17 10:52 917840 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{74E69B40-D7A2-4C6E-82E9-ABE0934F5CA3}\gapaengine.dll
2011-10-17 10:45 . 2011-10-17 10:45 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2011-10-17 10:45 . 2011-10-17 10:45 -------- d-----w- c:\program files\Microsoft Security Client
2011-10-17 10:31 . 2011-10-17 10:31 -------- d-----w- c:\windows\en
2011-10-17 10:22 . 2011-09-21 07:00 9049936 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D6ABF6E7-2981-4E31-A5C7-2272633087F5}\mpengine.dll
2011-10-17 10:22 . 2010-10-19 20:51 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-10-17 10:22 . 2011-10-17 10:22 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-10-17 10:21 . 2011-10-17 10:21 15712 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\7e1d72f31cc8cb601\MeshBetaRemover.exe
2011-10-16 16:38 . 2011-10-16 16:38 -------- d-----w- c:\users\zyleissvort\AppData\Local\ElevatedDiagnostics
2011-10-12 23:32 . 2011-09-01 05:12 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-10-12 23:32 . 2011-09-01 02:22 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-10-12 09:26 . 2011-09-06 03:03 3138048 ----a-w- c:\windows\system32\win32k.sys
2011-10-12 09:26 . 2011-08-17 05:26 613888 ----a-w- c:\windows\system32\psisdecd.dll
2011-10-12 09:26 . 2011-08-17 05:25 108032 ----a-w- c:\windows\system32\psisrndr.ax
2011-10-12 09:26 . 2011-08-17 04:24 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll
2011-10-12 09:26 . 2011-08-17 04:19 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2011-10-12 09:25 . 2011-08-27 05:37 861696 ----a-w- c:\windows\system32\oleaut32.dll
2011-10-12 09:25 . 2011-08-27 05:37 331776 ----a-w- c:\windows\system32\oleacc.dll
2011-10-12 09:25 . 2011-08-27 04:26 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-10-12 09:25 . 2011-08-27 04:26 233472 ----a-w- c:\windows\SysWow64\oleacc.dll
2011-09-27 14:20 . 2011-09-27 14:20 -------- d-----w- c:\users\zyleissvort\AppData\Local\DDMSettings
2011-09-24 08:29 . 2011-09-24 08:29 -------- d-----w- c:\users\zyleissvort\AppData\Local\WinZip
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-13 07:43 . 2011-08-14 18:46 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-08 21:35 . 2010-09-11 14:43 2301208 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2011-10-08 21:34 . 2010-10-06 21:09 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2011-10-08 21:34 . 2010-10-06 21:09 710976 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-07-22 20:51 . 2011-07-22 20:51 94208 ----a-w- c:\windows\SysWow64\dpl100.dll
2008-04-14 12:00 . 2010-10-21 06:06 94208 ----a-w- c:\program files\iphlpapi.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-10-17_10.01.52 )))))))))))))))))))))))))))))))))))))))))
.
- 2010-11-10 00:54 . 2010-11-10 00:54 49016 c:\windows\SysWOW64\sirenacm.dll
+ 2011-05-13 14:03 . 2011-05-13 14:03 49016 c:\windows\SysWOW64\sirenacm.dll
- 2011-10-17 09:22 . 2011-10-17 09:22 13378 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
+ 2011-10-17 11:00 . 2011-10-17 11:00 13378 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
+ 2009-07-14 04:54 . 2011-10-17 10:17 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-10-17 09:20 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-10-17 10:17 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-10-17 09:20 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-10-17 10:17 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-10-17 09:20 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-04-29 12:31 . 2011-10-17 10:16 55480 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-10-17 10:16 34338 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2011-10-17 09:19 34338 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-09-09 17:38 . 2011-10-17 10:16 11670 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3620401426-851611152-3603892462-1000_UserData.bin
+ 2011-04-27 13:25 . 2011-04-27 13:25 84864 c:\windows\system32\drivers\NisDrvWFP.sys
+ 2011-04-18 11:18 . 2011-04-18 11:18 40832 c:\windows\system32\drivers\MpNWMon.sys
+ 2009-07-14 04:46 . 2011-10-17 10:35 96656 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2011-10-17 10:32 . 2011-10-17 10:32 24576 c:\windows\Installer\7399d.msp
+ 2011-10-17 10:32 . 2011-10-17 10:32 56832 c:\windows\Installer\73997.msi
+ 2011-10-17 10:32 . 2011-10-17 10:32 30720 c:\windows\Installer\73993.msp
+ 2011-10-17 10:32 . 2011-10-17 10:32 74240 c:\windows\Installer\7398e.msi
+ 2011-10-17 10:32 . 2011-10-17 10:32 23552 c:\windows\Installer\73986.msp
+ 2010-10-29 16:44 . 2010-10-29 16:44 29696 c:\windows\Installer\73981.msi
+ 2011-10-17 10:31 . 2011-10-17 10:31 60416 c:\windows\Installer\7397b.msp
+ 2011-10-17 10:29 . 2011-10-17 10:29 29184 c:\windows\Installer\73920.msp
+ 2011-10-17 10:29 . 2011-10-17 10:29 67072 c:\windows\Installer\73916.msi
+ 2011-10-17 10:23 . 2011-10-17 10:23 37888 c:\windows\Installer\73774.msi
+ 2011-10-17 10:22 . 2011-10-17 10:22 53248 c:\windows\Installer\73770.msi
+ 2011-10-17 10:22 . 2011-10-17 10:22 39936 c:\windows\Installer\73768.msp
+ 2010-10-29 16:44 . 2010-10-29 16:44 74240 c:\windows\Installer\73763.msi
+ 2011-10-17 10:22 . 2011-10-17 10:22 26112 c:\windows\Installer\7375a.msi
+ 2011-10-17 10:26 . 2011-10-17 10:26 80395 c:\windows\Installer\{E5B21F11-6933-4E0B-A25C-7963E3C07D11}\MsblIco.Exe
+ 2011-10-17 10:33 . 2011-10-17 10:33 89440 c:\windows\Installer\{95140000-007A-0409-0000-0000000FF1CE}\OLCIcon.exe
+ 2010-09-22 14:33 . 2010-09-22 14:33 55136 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\utilclasses.dll
+ 2010-09-22 14:33 . 2010-09-22 14:33 91488 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\TesClient.dll
+ 2010-09-22 14:33 . 2010-09-22 14:33 34144 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\SqmWrapper.dll
+ 2010-09-22 14:33 . 2010-09-22 14:33 71520 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\MOE.exe
+ 2010-09-22 14:32 . 2010-09-22 14:32 40800 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\logging.dll
+ 2010-09-22 14:32 . 2010-09-22 14:32 77152 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\lkrhwlc.dll
+ 2010-09-22 14:33 . 2010-09-22 14:33 97120 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\esestore.dll
+ 2011-10-17 11:00 . 2011-10-17 11:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-10-17 09:23 . 2011-10-17 09:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-10-17 11:00 . 2011-10-17 11:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-10-17 09:23 . 2011-10-17 09:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-05-13 13:42 . 2011-05-13 13:42 302448 c:\windows\WLXPGSS.SCR
+ 2011-03-28 18:31 . 2011-03-28 18:31 209280 c:\windows\SysWOW64\LIVESSP.DLL
+ 2009-07-14 02:36 . 2011-10-17 10:45 618626 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-10-17 10:45 107648 c:\windows\system32\perfc009.dat
+ 2011-03-28 19:11 . 2011-03-28 19:11 252800 c:\windows\system32\LIVESSP.DLL
- 2010-09-21 12:49 . 2010-09-21 12:49 252800 c:\windows\system32\LIVESSP.DLL
+ 2011-04-18 11:18 . 2011-04-18 11:18 189440 c:\windows\system32\drivers\MpFilter.sys
- 2009-07-14 05:01 . 2011-10-17 09:22 434732 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-10-17 11:00 434732 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2010-10-29 16:44 . 2010-10-29 16:44 153600 c:\windows\Installer\73976.msi
+ 2011-10-17 10:31 . 2011-10-17 10:31 509952 c:\windows\Installer\7395f.msp
+ 2011-10-17 10:31 . 2011-10-17 10:31 636416 c:\windows\Installer\73955.msp
+ 2011-10-17 10:30 . 2011-10-17 10:30 468480 c:\windows\Installer\7393d.msp
+ 2011-10-17 10:30 . 2011-10-17 10:30 626688 c:\windows\Installer\7392e.msp
+ 2011-10-17 10:28 . 2011-10-17 10:28 113664 c:\windows\Installer\738f4.msp
+ 2011-10-17 10:27 . 2011-10-17 10:27 205824 c:\windows\Installer\738b3.msp
+ 2010-10-29 16:44 . 2010-10-29 16:44 775168 c:\windows\Installer\738aa.msi
+ 2011-10-17 10:24 . 2011-10-17 10:24 715264 c:\windows\Installer\737d5.msp
+ 2011-10-17 10:23 . 2011-10-17 10:23 136704 c:\windows\Installer\737ab.msp
+ 2010-10-29 16:43 . 2010-10-29 16:43 429056 c:\windows\Installer\737a6.msi
+ 2010-09-22 14:31 . 2010-09-22 14:31 108384 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\Microsoft.Web.dll
+ 2010-09-22 14:33 . 2010-09-22 14:33 953696 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\MeshSessions.dll
+ 2010-09-22 14:33 . 2010-09-22 14:33 117600 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\encoders.dll
+ 2010-09-22 14:32 . 2010-09-22 14:32 160608 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\commengine.dll
+ 2010-09-22 14:32 . 2010-09-22 14:32 438112 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\bitswarm.dll
+ 2010-11-19 17:45 . 2011-10-17 11:00 5263132 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3620401426-851611152-3603892462-1000-8192.dat
- 2010-11-19 17:45 . 2011-10-17 09:22 5263132 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3620401426-851611152-3603892462-1000-8192.dat
+ 2011-10-17 10:33 . 2011-10-17 10:33 3095552 c:\windows\Installer\739a1.msi
+ 2011-10-17 10:32 . 2011-10-17 10:32 2631168 c:\windows\Installer\7398a.msi
+ 2011-10-17 10:31 . 2011-10-17 10:31 2146816 c:\windows\Installer\73970.msp
+ 2010-10-29 16:44 . 2010-10-29 16:44 4250112 c:\windows\Installer\73965.msi
+ 2010-10-29 16:44 . 2010-10-29 16:44 4175360 c:\windows\Installer\7395a.msi
+ 2010-10-29 16:44 . 2010-10-29 16:44 3410944 c:\windows\Installer\7394f.msi
+ 2011-10-17 10:31 . 2011-10-17 10:31 6661632 c:\windows\Installer\7394a.msi
+ 2010-10-29 16:44 . 2010-10-29 16:44 1070592 c:\windows\Installer\73933.msi
+ 2010-10-29 16:43 . 2010-10-29 16:43 1492992 c:\windows\Installer\73925.msi
+ 2011-10-17 10:29 . 2011-10-17 10:29 1828864 c:\windows\Installer\73910.msp
+ 2011-10-17 10:29 . 2011-10-17 10:29 3454976 c:\windows\Installer\73907.msi
+ 2011-10-17 10:29 . 2011-10-17 10:29 3103744 c:\windows\Installer\73903.msp
+ 2011-10-17 10:28 . 2011-10-17 10:28 6195200 c:\windows\Installer\738f8.msi
+ 2011-10-17 10:28 . 2011-10-17 10:28 6363136 c:\windows\Installer\738b7.msi
+ 2011-10-17 10:27 . 2011-10-17 10:27 3731968 c:\windows\Installer\738a1.msp
+ 2011-10-17 10:26 . 2011-10-17 10:26 2956288 c:\windows\Installer\73859.msp
+ 2010-10-29 16:44 . 2010-10-29 16:44 8313856 c:\windows\Installer\7383f.msi
+ 2011-10-17 10:25 . 2011-10-17 10:25 5872128 c:\windows\Installer\7383a.msp
+ 2011-10-17 10:24 . 2011-10-17 10:24 3313152 c:\windows\Installer\737f9.msp
+ 2010-10-29 16:43 . 2010-10-29 16:43 8332288 c:\windows\Installer\737dd.msi
+ 2011-10-17 10:24 . 2011-10-17 10:24 2310656 c:\windows\Installer\737c4.msi
+ 2011-10-17 10:24 . 2011-10-17 10:24 1139200 c:\windows\Installer\737bc.msp
+ 2010-10-29 16:43 . 2010-10-29 16:43 4004864 c:\windows\Installer\737b0.msi
+ 2011-10-17 10:23 . 2011-10-17 10:23 2933248 c:\windows\Installer\737a1.msp
+ 2010-10-29 16:43 . 2010-10-29 16:43 7710720 c:\windows\Installer\7378d.msi
+ 2011-10-17 10:23 . 2011-10-17 10:23 4425728 c:\windows\Installer\73788.msp
+ 2010-10-29 16:43 . 2010-10-29 16:43 9433088 c:\windows\Installer\73779.msi
+ 2011-10-17 10:22 . 2011-10-17 10:22 2856448 c:\windows\Installer\7376c.msi
+ 2011-10-17 10:22 . 2011-10-17 10:22 4227072 c:\windows\Installer\73756.msi
+ 2011-10-17 10:21 . 2011-10-17 10:21 8822784 c:\windows\Installer\73752.msi
+ 2011-05-19 15:23 . 2011-05-19 15:23 2708992 c:\windows\Installer\1c64a8.msi
+ 2011-06-15 12:51 . 2011-06-15 12:51 1911808 c:\windows\Installer\1c64a1.msi
+ 2010-09-22 22:17 . 2010-09-22 22:17 1204584 c:\windows\Installer\$PatchCache$\Managed\032440EF5AC97F34B985A55C2AA8F133\15.4.3502\wlarp.exe
+ 2010-10-29 16:44 . 2010-10-29 16:44 11846656 c:\windows\Installer\73898.msi
+ 2011-10-17 10:27 . 2011-10-17 10:27 14623744 c:\windows\Installer\73890.msp
+ 2010-10-29 16:44 . 2010-10-29 16:44 34193408 c:\windows\Installer\73864.msi
+ 2010-10-29 16:44 . 2010-10-29 16:44 13850624 c:\windows\Installer\73823.msi
+ 2011-10-17 10:25 . 2011-10-17 10:25 22647296 c:\windows\Installer\7380c.msi
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-10-18 3908192]
"{cd90bf73-20f6-44ef-993d-bb920303bd2e}"= "c:\program files (x86)\Veoh_Web_Player\prxtbVeoh.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{cd90bf73-20f6-44ef-993d-bb920303bd2e}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 11:26 3908192 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2010-10-18 11:26 3908192 ----a-w- c:\program files (x86)\uTorrentBar\tbuTor.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{cd90bf73-20f6-44ef-993d-bb920303bd2e}]
2011-01-17 14:54 175912 ----a-w- c:\program files (x86)\Veoh_Web_Player\prxtbVeoh.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-10-18 3908192]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-10-18 3908192]
"{cd90bf73-20f6-44ef-993d-bb920303bd2e}"= "c:\program files (x86)\Veoh_Web_Player\prxtbVeoh.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CLASSES_ROOT\clsid\{cd90bf73-20f6-44ef-993d-bb920303bd2e}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"NokiaOviSuite2"="c:\program files (x86)\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2010-09-02 672632]
"AutoStartNPSAgent"="c:\program files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe" [2009-06-03 102400]
"VeohPlugin"="c:\program files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2011-06-30 2648184]
"googletalk"="c:\users\zyleissvort\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files (x86)\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-12-23 284696]
"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2009-06-24 409744]
"Desktop Disc Tool"="c:\program files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2010-08-19 522736]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-03-24 102400]
"DellSupportCenter"="c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2011-06-13 273544]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"="c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [2011-10-05 559616]
"Launcher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe" [2010-07-21 165184]
"DSUpdateLauncher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" [2010-07-21 18240]
"STToasterLauncher"="c:\program files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe" [2010-07-21 122176]
.
c:\users\zyleissvort\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-9-15 113664]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-2 1079584]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-16 1324384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 0293581318845081mcinstcleanup;McAfee Application Installer Cleanup (0293581318845081);c:\users\ZYLEISSVORT~1\AppData\Local\Temp\029358~1.EXE [x]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_58afa5ca50c7b5e7\AESTSr64.exe [2010-03-17 89600]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664]
R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
R2 Giraffic;Veoh Giraffic Video Accelerator;c:\program files (x86)\Giraffic\Veoh_GirafficWatchdog.exe [2011-09-19 2221200]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-26 136176]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-12-23 13336]
R2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-09-14 508264]
R2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2010-08-20 689472]
R2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x]
R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-17 2320920]
R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-26 136176]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 nmwcdcx64;Nokia USB Generic;c:\windows\system32\drivers\ccdcmbox64.sys [x]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\ccdcmbx64.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
R3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
R3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
R3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
R3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
R3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-09-14 219496]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [2009-05-18 16392]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe [2009-11-02 126352]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S3 BcmVWL;Broadcom Virtual Wireless;c:\windows\system32\DRIVERS\bcmvwl64.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-26 21:33]
.
2011-10-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-26 21:33]
.
2011-10-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3620401426-851611152-3603892462-1000Core.job
- c:\users\zyleissvort\AppData\Local\Google\Update\GoogleUpdate.exe [2010-10-18 17:10]
.
2011-10-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3620401426-851611152-3603892462-1000UA.job
- c:\users\zyleissvort\AppData\Local\Google\Update\GoogleUpdate.exe [2010-10-18 17:10]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-03-17 487424]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"Broadcom Wireless Manager UI"="c:\program files\Dell\DW WLAN Card\WLTRAY.exe" [2010-02-03 5712896]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\zyleissvort\AppData\Roaming\Mozilla\Firefox\Profiles\7mlvtf39.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ncr
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-10-17 13:20:43
ComboFix-quarantined-files.txt 2011-10-17 11:20
ComboFix2.txt 2011-10-17 10:04
.
Pre-Run: 399,779,237,888 bytes free
Post-Run: 399,338,688,512 bytes free
.
- - End Of File - - 0ED2D732F615A1DB1401050DBCDDC39D
Thanks
ComboFix 11-10-16.03 - zyleissvort 17/10/2011 13:09:35.2.4 - x64 NETWORK
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.3959.3281 [GMT 2:00]
Running from: c:\users\zyleissvort\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\zyleissvort\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
.
.
((((((((((((((((((((((((( Files Created from 2011-09-17 to 2011-10-17 )))))))))))))))))))))))))))))))
.
.
2011-10-17 11:18 . 2011-10-17 11:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-10-17 10:52 . 2011-09-12 15:26 9049936 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-17 10:52 . 2011-10-17 11:00 69000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A1E6C2F4-2D0D-4128-8836-E1A41F35C46F}\offreg.dll
2011-10-17 10:52 . 2011-09-12 15:26 9049936 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A1E6C2F4-2D0D-4128-8836-E1A41F35C46F}\mpengine.dll
2011-10-17 10:52 . 2011-10-17 10:52 917840 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{74E69B40-D7A2-4C6E-82E9-ABE0934F5CA3}\gapaengine.dll
2011-10-17 10:45 . 2011-10-17 10:45 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2011-10-17 10:45 . 2011-10-17 10:45 -------- d-----w- c:\program files\Microsoft Security Client
2011-10-17 10:31 . 2011-10-17 10:31 -------- d-----w- c:\windows\en
2011-10-17 10:22 . 2011-09-21 07:00 9049936 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D6ABF6E7-2981-4E31-A5C7-2272633087F5}\mpengine.dll
2011-10-17 10:22 . 2010-10-19 20:51 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-10-17 10:22 . 2011-10-17 10:22 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-10-17 10:21 . 2011-10-17 10:21 15712 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\7e1d72f31cc8cb601\MeshBetaRemover.exe
2011-10-16 16:38 . 2011-10-16 16:38 -------- d-----w- c:\users\zyleissvort\AppData\Local\ElevatedDiagnostics
2011-10-12 23:32 . 2011-09-01 05:12 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-10-12 23:32 . 2011-09-01 02:22 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-10-12 09:26 . 2011-09-06 03:03 3138048 ----a-w- c:\windows\system32\win32k.sys
2011-10-12 09:26 . 2011-08-17 05:26 613888 ----a-w- c:\windows\system32\psisdecd.dll
2011-10-12 09:26 . 2011-08-17 05:25 108032 ----a-w- c:\windows\system32\psisrndr.ax
2011-10-12 09:26 . 2011-08-17 04:24 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll
2011-10-12 09:26 . 2011-08-17 04:19 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2011-10-12 09:25 . 2011-08-27 05:37 861696 ----a-w- c:\windows\system32\oleaut32.dll
2011-10-12 09:25 . 2011-08-27 05:37 331776 ----a-w- c:\windows\system32\oleacc.dll
2011-10-12 09:25 . 2011-08-27 04:26 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-10-12 09:25 . 2011-08-27 04:26 233472 ----a-w- c:\windows\SysWow64\oleacc.dll
2011-09-27 14:20 . 2011-09-27 14:20 -------- d-----w- c:\users\zyleissvort\AppData\Local\DDMSettings
2011-09-24 08:29 . 2011-09-24 08:29 -------- d-----w- c:\users\zyleissvort\AppData\Local\WinZip
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-13 07:43 . 2011-08-14 18:46 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-08 21:35 . 2010-09-11 14:43 2301208 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2011-10-08 21:34 . 2010-10-06 21:09 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2011-10-08 21:34 . 2010-10-06 21:09 710976 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-07-22 20:51 . 2011-07-22 20:51 94208 ----a-w- c:\windows\SysWow64\dpl100.dll
2008-04-14 12:00 . 2010-10-21 06:06 94208 ----a-w- c:\program files\iphlpapi.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-10-17_10.01.52 )))))))))))))))))))))))))))))))))))))))))
.
- 2010-11-10 00:54 . 2010-11-10 00:54 49016 c:\windows\SysWOW64\sirenacm.dll
+ 2011-05-13 14:03 . 2011-05-13 14:03 49016 c:\windows\SysWOW64\sirenacm.dll
- 2011-10-17 09:22 . 2011-10-17 09:22 13378 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
+ 2011-10-17 11:00 . 2011-10-17 11:00 13378 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
+ 2009-07-14 04:54 . 2011-10-17 10:17 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-10-17 09:20 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-10-17 10:17 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-10-17 09:20 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-10-17 10:17 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-10-17 09:20 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-04-29 12:31 . 2011-10-17 10:16 55480 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-10-17 10:16 34338 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2011-10-17 09:19 34338 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-09-09 17:38 . 2011-10-17 10:16 11670 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3620401426-851611152-3603892462-1000_UserData.bin
+ 2011-04-27 13:25 . 2011-04-27 13:25 84864 c:\windows\system32\drivers\NisDrvWFP.sys
+ 2011-04-18 11:18 . 2011-04-18 11:18 40832 c:\windows\system32\drivers\MpNWMon.sys
+ 2009-07-14 04:46 . 2011-10-17 10:35 96656 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2011-10-17 10:32 . 2011-10-17 10:32 24576 c:\windows\Installer\7399d.msp
+ 2011-10-17 10:32 . 2011-10-17 10:32 56832 c:\windows\Installer\73997.msi
+ 2011-10-17 10:32 . 2011-10-17 10:32 30720 c:\windows\Installer\73993.msp
+ 2011-10-17 10:32 . 2011-10-17 10:32 74240 c:\windows\Installer\7398e.msi
+ 2011-10-17 10:32 . 2011-10-17 10:32 23552 c:\windows\Installer\73986.msp
+ 2010-10-29 16:44 . 2010-10-29 16:44 29696 c:\windows\Installer\73981.msi
+ 2011-10-17 10:31 . 2011-10-17 10:31 60416 c:\windows\Installer\7397b.msp
+ 2011-10-17 10:29 . 2011-10-17 10:29 29184 c:\windows\Installer\73920.msp
+ 2011-10-17 10:29 . 2011-10-17 10:29 67072 c:\windows\Installer\73916.msi
+ 2011-10-17 10:23 . 2011-10-17 10:23 37888 c:\windows\Installer\73774.msi
+ 2011-10-17 10:22 . 2011-10-17 10:22 53248 c:\windows\Installer\73770.msi
+ 2011-10-17 10:22 . 2011-10-17 10:22 39936 c:\windows\Installer\73768.msp
+ 2010-10-29 16:44 . 2010-10-29 16:44 74240 c:\windows\Installer\73763.msi
+ 2011-10-17 10:22 . 2011-10-17 10:22 26112 c:\windows\Installer\7375a.msi
+ 2011-10-17 10:26 . 2011-10-17 10:26 80395 c:\windows\Installer\{E5B21F11-6933-4E0B-A25C-7963E3C07D11}\MsblIco.Exe
+ 2011-10-17 10:33 . 2011-10-17 10:33 89440 c:\windows\Installer\{95140000-007A-0409-0000-0000000FF1CE}\OLCIcon.exe
+ 2010-09-22 14:33 . 2010-09-22 14:33 55136 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\utilclasses.dll
+ 2010-09-22 14:33 . 2010-09-22 14:33 91488 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\TesClient.dll
+ 2010-09-22 14:33 . 2010-09-22 14:33 34144 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\SqmWrapper.dll
+ 2010-09-22 14:33 . 2010-09-22 14:33 71520 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\MOE.exe
+ 2010-09-22 14:32 . 2010-09-22 14:32 40800 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\logging.dll
+ 2010-09-22 14:32 . 2010-09-22 14:32 77152 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\lkrhwlc.dll
+ 2010-09-22 14:33 . 2010-09-22 14:33 97120 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\esestore.dll
+ 2011-10-17 11:00 . 2011-10-17 11:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-10-17 09:23 . 2011-10-17 09:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-10-17 11:00 . 2011-10-17 11:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-10-17 09:23 . 2011-10-17 09:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-05-13 13:42 . 2011-05-13 13:42 302448 c:\windows\WLXPGSS.SCR
+ 2011-03-28 18:31 . 2011-03-28 18:31 209280 c:\windows\SysWOW64\LIVESSP.DLL
+ 2009-07-14 02:36 . 2011-10-17 10:45 618626 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-10-17 10:45 107648 c:\windows\system32\perfc009.dat
+ 2011-03-28 19:11 . 2011-03-28 19:11 252800 c:\windows\system32\LIVESSP.DLL
- 2010-09-21 12:49 . 2010-09-21 12:49 252800 c:\windows\system32\LIVESSP.DLL
+ 2011-04-18 11:18 . 2011-04-18 11:18 189440 c:\windows\system32\drivers\MpFilter.sys
- 2009-07-14 05:01 . 2011-10-17 09:22 434732 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-10-17 11:00 434732 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2010-10-29 16:44 . 2010-10-29 16:44 153600 c:\windows\Installer\73976.msi
+ 2011-10-17 10:31 . 2011-10-17 10:31 509952 c:\windows\Installer\7395f.msp
+ 2011-10-17 10:31 . 2011-10-17 10:31 636416 c:\windows\Installer\73955.msp
+ 2011-10-17 10:30 . 2011-10-17 10:30 468480 c:\windows\Installer\7393d.msp
+ 2011-10-17 10:30 . 2011-10-17 10:30 626688 c:\windows\Installer\7392e.msp
+ 2011-10-17 10:28 . 2011-10-17 10:28 113664 c:\windows\Installer\738f4.msp
+ 2011-10-17 10:27 . 2011-10-17 10:27 205824 c:\windows\Installer\738b3.msp
+ 2010-10-29 16:44 . 2010-10-29 16:44 775168 c:\windows\Installer\738aa.msi
+ 2011-10-17 10:24 . 2011-10-17 10:24 715264 c:\windows\Installer\737d5.msp
+ 2011-10-17 10:23 . 2011-10-17 10:23 136704 c:\windows\Installer\737ab.msp
+ 2010-10-29 16:43 . 2010-10-29 16:43 429056 c:\windows\Installer\737a6.msi
+ 2010-09-22 14:31 . 2010-09-22 14:31 108384 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\Microsoft.Web.dll
+ 2010-09-22 14:33 . 2010-09-22 14:33 953696 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\MeshSessions.dll
+ 2010-09-22 14:33 . 2010-09-22 14:33 117600 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\encoders.dll
+ 2010-09-22 14:32 . 2010-09-22 14:32 160608 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\commengine.dll
+ 2010-09-22 14:32 . 2010-09-22 14:32 438112 c:\windows\Installer\$PatchCache$\Managed\6116D6C8427B0184F8D20D746E7B6DE8\15.4.5722\bitswarm.dll
+ 2010-11-19 17:45 . 2011-10-17 11:00 5263132 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3620401426-851611152-3603892462-1000-8192.dat
- 2010-11-19 17:45 . 2011-10-17 09:22 5263132 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3620401426-851611152-3603892462-1000-8192.dat
+ 2011-10-17 10:33 . 2011-10-17 10:33 3095552 c:\windows\Installer\739a1.msi
+ 2011-10-17 10:32 . 2011-10-17 10:32 2631168 c:\windows\Installer\7398a.msi
+ 2011-10-17 10:31 . 2011-10-17 10:31 2146816 c:\windows\Installer\73970.msp
+ 2010-10-29 16:44 . 2010-10-29 16:44 4250112 c:\windows\Installer\73965.msi
+ 2010-10-29 16:44 . 2010-10-29 16:44 4175360 c:\windows\Installer\7395a.msi
+ 2010-10-29 16:44 . 2010-10-29 16:44 3410944 c:\windows\Installer\7394f.msi
+ 2011-10-17 10:31 . 2011-10-17 10:31 6661632 c:\windows\Installer\7394a.msi
+ 2010-10-29 16:44 . 2010-10-29 16:44 1070592 c:\windows\Installer\73933.msi
+ 2010-10-29 16:43 . 2010-10-29 16:43 1492992 c:\windows\Installer\73925.msi
+ 2011-10-17 10:29 . 2011-10-17 10:29 1828864 c:\windows\Installer\73910.msp
+ 2011-10-17 10:29 . 2011-10-17 10:29 3454976 c:\windows\Installer\73907.msi
+ 2011-10-17 10:29 . 2011-10-17 10:29 3103744 c:\windows\Installer\73903.msp
+ 2011-10-17 10:28 . 2011-10-17 10:28 6195200 c:\windows\Installer\738f8.msi
+ 2011-10-17 10:28 . 2011-10-17 10:28 6363136 c:\windows\Installer\738b7.msi
+ 2011-10-17 10:27 . 2011-10-17 10:27 3731968 c:\windows\Installer\738a1.msp
+ 2011-10-17 10:26 . 2011-10-17 10:26 2956288 c:\windows\Installer\73859.msp
+ 2010-10-29 16:44 . 2010-10-29 16:44 8313856 c:\windows\Installer\7383f.msi
+ 2011-10-17 10:25 . 2011-10-17 10:25 5872128 c:\windows\Installer\7383a.msp
+ 2011-10-17 10:24 . 2011-10-17 10:24 3313152 c:\windows\Installer\737f9.msp
+ 2010-10-29 16:43 . 2010-10-29 16:43 8332288 c:\windows\Installer\737dd.msi
+ 2011-10-17 10:24 . 2011-10-17 10:24 2310656 c:\windows\Installer\737c4.msi
+ 2011-10-17 10:24 . 2011-10-17 10:24 1139200 c:\windows\Installer\737bc.msp
+ 2010-10-29 16:43 . 2010-10-29 16:43 4004864 c:\windows\Installer\737b0.msi
+ 2011-10-17 10:23 . 2011-10-17 10:23 2933248 c:\windows\Installer\737a1.msp
+ 2010-10-29 16:43 . 2010-10-29 16:43 7710720 c:\windows\Installer\7378d.msi
+ 2011-10-17 10:23 . 2011-10-17 10:23 4425728 c:\windows\Installer\73788.msp
+ 2010-10-29 16:43 . 2010-10-29 16:43 9433088 c:\windows\Installer\73779.msi
+ 2011-10-17 10:22 . 2011-10-17 10:22 2856448 c:\windows\Installer\7376c.msi
+ 2011-10-17 10:22 . 2011-10-17 10:22 4227072 c:\windows\Installer\73756.msi
+ 2011-10-17 10:21 . 2011-10-17 10:21 8822784 c:\windows\Installer\73752.msi
+ 2011-05-19 15:23 . 2011-05-19 15:23 2708992 c:\windows\Installer\1c64a8.msi
+ 2011-06-15 12:51 . 2011-06-15 12:51 1911808 c:\windows\Installer\1c64a1.msi
+ 2010-09-22 22:17 . 2010-09-22 22:17 1204584 c:\windows\Installer\$PatchCache$\Managed\032440EF5AC97F34B985A55C2AA8F133\15.4.3502\wlarp.exe
+ 2010-10-29 16:44 . 2010-10-29 16:44 11846656 c:\windows\Installer\73898.msi
+ 2011-10-17 10:27 . 2011-10-17 10:27 14623744 c:\windows\Installer\73890.msp
+ 2010-10-29 16:44 . 2010-10-29 16:44 34193408 c:\windows\Installer\73864.msi
+ 2010-10-29 16:44 . 2010-10-29 16:44 13850624 c:\windows\Installer\73823.msi
+ 2011-10-17 10:25 . 2011-10-17 10:25 22647296 c:\windows\Installer\7380c.msi
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-10-18 3908192]
"{cd90bf73-20f6-44ef-993d-bb920303bd2e}"= "c:\program files (x86)\Veoh_Web_Player\prxtbVeoh.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{cd90bf73-20f6-44ef-993d-bb920303bd2e}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 11:26 3908192 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2010-10-18 11:26 3908192 ----a-w- c:\program files (x86)\uTorrentBar\tbuTor.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{cd90bf73-20f6-44ef-993d-bb920303bd2e}]
2011-01-17 14:54 175912 ----a-w- c:\program files (x86)\Veoh_Web_Player\prxtbVeoh.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-10-18 3908192]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-10-18 3908192]
"{cd90bf73-20f6-44ef-993d-bb920303bd2e}"= "c:\program files (x86)\Veoh_Web_Player\prxtbVeoh.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CLASSES_ROOT\clsid\{cd90bf73-20f6-44ef-993d-bb920303bd2e}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"NokiaOviSuite2"="c:\program files (x86)\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2010-09-02 672632]
"AutoStartNPSAgent"="c:\program files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe" [2009-06-03 102400]
"VeohPlugin"="c:\program files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2011-06-30 2648184]
"googletalk"="c:\users\zyleissvort\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files (x86)\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-12-23 284696]
"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2009-06-24 409744]
"Desktop Disc Tool"="c:\program files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2010-08-19 522736]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-03-24 102400]
"DellSupportCenter"="c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2011-06-13 273544]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"="c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [2011-10-05 559616]
"Launcher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe" [2010-07-21 165184]
"DSUpdateLauncher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" [2010-07-21 18240]
"STToasterLauncher"="c:\program files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe" [2010-07-21 122176]
.
c:\users\zyleissvort\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-9-15 113664]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-2 1079584]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-16 1324384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 0293581318845081mcinstcleanup;McAfee Application Installer Cleanup (0293581318845081);c:\users\ZYLEISSVORT~1\AppData\Local\Temp\029358~1.EXE [x]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_58afa5ca50c7b5e7\AESTSr64.exe [2010-03-17 89600]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664]
R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
R2 Giraffic;Veoh Giraffic Video Accelerator;c:\program files (x86)\Giraffic\Veoh_GirafficWatchdog.exe [2011-09-19 2221200]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-26 136176]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-12-23 13336]
R2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-09-14 508264]
R2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2010-08-20 689472]
R2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x]
R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-17 2320920]
R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-26 136176]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 nmwcdcx64;Nokia USB Generic;c:\windows\system32\drivers\ccdcmbox64.sys [x]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\ccdcmbx64.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
R3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
R3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
R3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
R3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
R3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-09-14 219496]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [2009-05-18 16392]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe [2009-11-02 126352]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S3 BcmVWL;Broadcom Virtual Wireless;c:\windows\system32\DRIVERS\bcmvwl64.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-26 21:33]
.
2011-10-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-26 21:33]
.
2011-10-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3620401426-851611152-3603892462-1000Core.job
- c:\users\zyleissvort\AppData\Local\Google\Update\GoogleUpdate.exe [2010-10-18 17:10]
.
2011-10-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3620401426-851611152-3603892462-1000UA.job
- c:\users\zyleissvort\AppData\Local\Google\Update\GoogleUpdate.exe [2010-10-18 17:10]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-03-17 487424]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"Broadcom Wireless Manager UI"="c:\program files\Dell\DW WLAN Card\WLTRAY.exe" [2010-02-03 5712896]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\zyleissvort\AppData\Roaming\Mozilla\Firefox\Profiles\7mlvtf39.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ncr
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-10-17 13:20:43
ComboFix-quarantined-files.txt 2011-10-17 11:20
ComboFix2.txt 2011-10-17 10:04
.
Pre-Run: 399,779,237,888 bytes free
Post-Run: 399,338,688,512 bytes free
.
- - End Of File - - 0ED2D732F615A1DB1401050DBCDDC39D
Anonymous User
Oct 18, 2011 at 04:16 AM
Oct 18, 2011 at 04:16 AM
Now download this
https://ccm.net/downloads/security-and-maintenance/4621-malwarebytes-anti-malware/
Run a scan and remove infections
''Giraffe video accelerator '' >>> uninstall it
Now run flash player uninstaller
http://download.macromedia.com/pub/flashplayer/current/uninstall_flash_player_64bit.exe
Browse this path
%userprofile%\AppData\Roaming\Adobe\Flash Player
and remove all folders
Now download the flash playerfrom here
https://www.adobe.com/products/flashplayer/distribution.html
Install it and check if videos work now
Also try to disable your antivirus and check
https://ccm.net/downloads/security-and-maintenance/4621-malwarebytes-anti-malware/
Run a scan and remove infections
''Giraffe video accelerator '' >>> uninstall it
Now run flash player uninstaller
http://download.macromedia.com/pub/flashplayer/current/uninstall_flash_player_64bit.exe
Browse this path
%userprofile%\AppData\Roaming\Adobe\Flash Player
and remove all folders
Now download the flash playerfrom here
https://www.adobe.com/products/flashplayer/distribution.html
Install it and check if videos work now
Also try to disable your antivirus and check
Hi, I did as you told. unfortunately it is not working.
this is the log for the malware program.
Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org
Database version: 6705
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
18/10/2011 16:53:42
mbam-log-2011-10-18 (16-53-42).txt
Scan type: Full scan (C:\|D:\|Q:\|)
Objects scanned: 476544
Time elapsed: 1 hour(s), 5 minute(s), 29 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Users\zyleissvort\documents\setup files\mywebfacesetup2.3.70.1.grman000.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
I tried uninstalling , deleting the Flash player files and then reinstalling, but it didnt work.
I also checked whether there was any problem with my ISP service or from dailymotion/Metacafe/Myspacevideo itself, but I checked with other users here, and for them it works. Its quite weird.
Thanks again.
this is the log for the malware program.
Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org
Database version: 6705
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
18/10/2011 16:53:42
mbam-log-2011-10-18 (16-53-42).txt
Scan type: Full scan (C:\|D:\|Q:\|)
Objects scanned: 476544
Time elapsed: 1 hour(s), 5 minute(s), 29 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Users\zyleissvort\documents\setup files\mywebfacesetup2.3.70.1.grman000.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
I tried uninstalling , deleting the Flash player files and then reinstalling, but it didnt work.
I also checked whether there was any problem with my ISP service or from dailymotion/Metacafe/Myspacevideo itself, but I checked with other users here, and for them it works. Its quite weird.
Thanks again.
Anonymous User
Oct 19, 2011 at 01:59 AM
Oct 19, 2011 at 01:59 AM
It is quite wierd.
Let us try this
I hope you uninstalled giraffe video accelerator
I just want you to disable your antivirus (microsoft security essentials) and try watching videos
Open security essentials>>>settings>>Realtime protection>> uncheck ''turn on realtime protection '' option
Does it work now?
If that doesnt work,Create a temporary user profile and try to browse videos using it
Try to reinstall your firefox browser and check
Let me know
Let us try this
I hope you uninstalled giraffe video accelerator
I just want you to disable your antivirus (microsoft security essentials) and try watching videos
Open security essentials>>>settings>>Realtime protection>> uncheck ''turn on realtime protection '' option
Does it work now?
If that doesnt work,Create a temporary user profile and try to browse videos using it
Try to reinstall your firefox browser and check
Let me know
Didn't find the answer you are looking for?
Ask a question
Anonymous User
Oct 20, 2011 at 12:18 AM
Oct 20, 2011 at 12:18 AM
I dont think windows firewall blocks streaming videos especially being our home computer.
You also made it sure to check your ISP too
Do you remember when this issue started?
You also made it sure to check your ISP too
Do you remember when this issue started?
Oct 14, 2011 at 03:35 AM
I tried what u said but it didnt work.
My flash player doesnt work for specific sites as i told, the video part of the screen just comes blank ( or black for that matter ) , but for other sites it works. It is quite weird.
I have not seen any other problem with other flash based apps/plug ins.
I dont get any warning/ error box from the PC.
I use IE9/Safari/Chrome/Firefox, all up to date, including my flash player.
thanks