To answer your question as to what makes me think I have this virus - MSE is still finding it, but it cannot clean it. Here are the two logs:
Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.orgDatabase version: v2012.01.21.02
Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
Chuck :: LAPTOP [administrator]
1/21/2012 3:11:29 PM
mbam-log-2012-01-21 (15-11-29).txt
Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 379601
Time elapsed: 1 hour(s), 2 minute(s), 15 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
ComboFix 12-01-21.02 - Chuck 01/21/2012 16:27:42.1.2 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4085.1976 [GMT -6:00]
Running from: c:\users\Chuck\Desktop\PCHelpForum.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\KBL.LOG
.
.
((((((((((((((((((((((((( Files Created from 2011-12-21 to 2012-01-21 )))))))))))))))))))))))))))))))
.
.
2012-01-21 23:01 . 2012-01-21 23:01 69000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7A8FA8FA-0F83-4AF9-BECE-620A0A7F1C19}\offreg.dll
2012-01-21 22:35 . 2012-01-21 22:35 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-21 21:11 . 2012-01-06 05:15 8602168 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7A8FA8FA-0F83-4AF9-BECE-620A0A7F1C19}\mpengine.dll
2012-01-21 21:04 . 2012-01-21 21:04 -------- d-----w- c:\programdata\Malwarebytes
2012-01-21 21:04 . 2012-01-21 21:08 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-01-21 21:04 . 2011-12-10 21:24 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-17 12:20 . 2011-03-12 22:52 1653760 ----a-w- c:\windows\system32\XpsPrint.dll
2012-01-17 12:20 . 2011-03-12 21:55 876032 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2012-01-15 22:38 . 2012-01-15 22:37 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-01-15 12:22 . 2012-01-15 12:22 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2012-01-15 12:09 . 2011-11-16 16:42 347136 ----a-w- c:\windows\system32\schannel.dll
2012-01-15 12:09 . 2011-11-17 06:53 515968 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-15 12:09 . 2011-11-16 16:43 442368 ----a-w- c:\windows\system32\winhttp.dll
2012-01-15 12:09 . 2011-11-16 16:42 94720 ----a-w- c:\windows\system32\secur32.dll
2012-01-15 12:09 . 2011-11-16 16:41 1689600 ----a-w- c:\windows\system32\lsasrv.dll
2012-01-15 12:09 . 2011-11-16 16:24 77312 ----a-w- c:\windows\SysWow64\secur32.dll
2012-01-15 12:09 . 2011-11-16 16:23 377344 ----a-w- c:\windows\SysWow64\winhttp.dll
2012-01-15 12:09 . 2011-11-16 16:23 278528 ----a-w- c:\windows\SysWow64\schannel.dll
2012-01-15 12:09 . 2011-11-16 14:34 11264 ----a-w- c:\windows\system32\lsass.exe
2012-01-15 11:57 . 2012-01-15 11:57 -------- d-----w- c:\program files (x86)\Windows Portable Devices
2012-01-15 11:57 . 2012-01-15 11:57 -------- d-----w- c:\program files\Windows Portable Devices
2012-01-15 11:57 . 2012-01-15 11:57 -------- d-----w- c:\windows\SysWow64\spool
2012-01-15 04:36 . 2009-09-10 02:05 103424 ----a-w- c:\windows\system32\UIAnimation.dll
2012-01-15 04:36 . 2009-09-10 02:00 92672 ----a-w- c:\windows\SysWow64\UIAnimation.dll
2012-01-15 04:36 . 2009-09-10 02:07 3815424 ----a-w- c:\windows\system32\UIRibbon.dll
2012-01-15 04:36 . 2009-09-10 02:06 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2012-01-15 04:36 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\SysWow64\UIRibbonRes.dll
2012-01-15 04:35 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\SysWow64\UIRibbon.dll
2012-01-15 04:15 . 2012-01-15 04:15 979456 ----a-w- c:\windows\SysWow64\MFH264Dec.dll
2012-01-15 04:14 . 2012-01-15 04:14 3584 ----a-w- c:\windows\system32\drivers\en-US\dxgkrnl.sys.mui
2012-01-15 04:01 . 2011-10-14 17:30 559616 ----a-w- c:\windows\system32\EncDec.dll
2012-01-15 04:01 . 2011-10-14 16:02 429056 ----a-w- c:\windows\SysWow64\EncDec.dll
2012-01-15 04:01 . 2011-09-20 21:06 1423744 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-01-15 04:01 . 2011-09-20 14:04 40448 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2012-01-15 03:59 . 2011-12-01 15:29 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-01-15 03:58 . 2011-08-13 05:11 6144 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2012-01-15 03:58 . 2011-08-13 04:43 6144 ----a-w- c:\program files (x86)\Internet Explorer\iecompat.dll
2012-01-15 03:58 . 2011-11-18 18:07 76800 ----a-w- c:\windows\system32\packager.dll
2012-01-15 03:58 . 2011-11-18 17:47 66560 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-15 03:57 . 2011-07-29 16:08 375808 ----a-w- c:\windows\system32\psisdecd.dll
2012-01-15 03:57 . 2011-07-29 16:08 289792 ----a-w- c:\windows\system32\psisrndr.ax
2012-01-15 03:57 . 2011-07-29 16:06 100352 ----a-w- c:\windows\system32\Mpeg2Data.ax
2012-01-15 03:57 . 2011-07-29 16:01 293376 ----a-w- c:\windows\SysWow64\psisdecd.dll
2012-01-15 03:57 . 2011-07-29 16:01 217088 ----a-w- c:\windows\SysWow64\psisrndr.ax
2012-01-15 03:57 . 2011-07-29 16:00 69632 ----a-w- c:\windows\SysWow64\Mpeg2Data.ax
2012-01-15 03:57 . 2011-07-29 16:06 73216 ----a-w- c:\windows\system32\MSDvbNP.ax
2012-01-15 03:57 . 2011-07-29 16:00 57856 ----a-w- c:\windows\SysWow64\MSDvbNP.ax
2012-01-15 03:32 . 2012-01-15 03:32 -------- d-----w- c:\windows\SysWow64\ca-ES
2012-01-15 03:32 . 2012-01-15 03:32 -------- d-----w- c:\windows\SysWow64\eu-ES
2012-01-15 03:32 . 2012-01-15 03:32 -------- d-----w- c:\windows\SysWow64\vi-VN
2012-01-15 03:32 . 2012-01-15 03:32 -------- d-----w- c:\windows\system32\ca-ES
2012-01-15 03:32 . 2012-01-15 03:32 -------- d-----w- c:\windows\system32\eu-ES
2012-01-15 03:32 . 2012-01-15 03:32 -------- d-----w- c:\windows\system32\vi-VN
2012-01-14 22:33 . 2012-01-14 22:33 -------- d-----w- c:\windows\system32\EventProviders
2012-01-14 21:48 . 2012-01-14 21:48 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2012-01-14 21:16 . 2009-04-11 07:11 397312 ----a-w- c:\windows\system32\WscEapPr.dll
2012-01-14 21:15 . 2009-04-11 07:15 380392 ----a-w- c:\windows\system32\ci.dll
2012-01-14 21:14 . 2009-04-11 07:11 74752 ----a-w- c:\windows\system32\wscsvc.dll
2012-01-14 21:13 . 2009-04-11 07:11 43520 ----a-w- c:\windows\system32\wbem\wbemprox.dll
2012-01-14 21:13 . 2009-04-11 07:11 1172992 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2012-01-14 21:13 . 2009-04-11 07:11 936448 ----a-w- c:\windows\system32\SmiEngine.dll
2012-01-14 21:13 . 2009-04-11 07:11 891392 ----a-w- c:\windows\system32\wbem\fastprox.dll
2012-01-14 21:13 . 2009-04-11 07:11 293888 ----a-w- c:\windows\system32\wdscore.dll
2012-01-14 21:13 . 2009-04-11 07:10 138752 ----a-w- c:\windows\system32\PkgMgr.exe
2012-01-14 21:13 . 2009-04-11 07:11 315904 ----a-w- c:\windows\system32\drvstore.dll
2012-01-14 20:57 . 2009-11-03 22:07 28160 ----a-w- c:\windows\system32\drivers\en-US\http.sys.mui
2012-01-14 20:56 . 2010-09-06 18:28 179712 ----a-w- c:\windows\system32\srvsvc.dll
2012-01-14 20:56 . 2010-09-06 18:28 12288 ----a-w- c:\windows\system32\sscore.dll
2012-01-14 20:56 . 2010-09-06 18:27 17920 ----a-w- c:\windows\system32\netevent.dll
2012-01-14 20:56 . 2010-09-06 16:20 9728 ----a-w- c:\windows\SysWow64\sscore.dll
2012-01-14 20:56 . 2010-09-06 16:19 17920 ----a-w- c:\windows\SysWow64\netevent.dll
2012-01-14 11:08 . 2012-01-06 05:15 8602168 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-01-14 05:22 . 2012-01-14 05:22 917840 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7EACE238-0330-41E6-A3F5-D43512314BE4}\gapaengine.dll
2012-01-14 05:19 . 2012-01-14 05:19 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BC103DC5-E9C0-4A37-8DF1-E54967BE9F5C}\offreg.dll
2012-01-14 05:05 . 2012-01-14 05:05 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2012-01-14 05:05 . 2012-01-14 05:06 -------- d-----w- c:\program files\Microsoft Security Client
2012-01-14 05:02 . 2010-04-06 08:34 345984 ----a-w- c:\windows\system32\drivers\netio.sys
2012-01-14 04:55 . 2012-01-14 04:55 -------- d-----w- c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP
2012-01-14 04:36 . 2009-11-08 16:55 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2012-01-14 04:36 . 2009-11-08 16:55 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2012-01-14 04:36 . 2009-11-08 16:55 48960 ----a-w- c:\windows\system32\netfxperf.dll
2012-01-14 04:36 . 2009-11-08 16:55 444752 ----a-w- c:\windows\system32\mscoree.dll
2012-01-14 04:36 . 2009-11-08 16:55 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2012-01-14 04:36 . 2009-11-08 16:55 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2012-01-14 04:36 . 2009-11-08 16:55 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2012-01-14 04:36 . 2009-11-08 16:55 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2012-01-14 04:36 . 2009-11-08 16:55 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-01-14 04:36 . 2009-11-08 16:55 1942856 ----a-w- c:\windows\system32\dfshim.dll
2012-01-14 04:26 . 2011-03-03 15:59 32256 ----a-w- c:\windows\system32\Apphlpdm.dll
2012-01-14 04:26 . 2011-03-03 15:40 28672 ----a-w- c:\windows\SysWow64\Apphlpdm.dll
2012-01-14 04:26 . 2011-03-03 14:00 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2012-01-14 04:26 . 2011-03-03 13:35 4240384 ----a-w- c:\windows\SysWow64\GameUXLegacyGDFs.dll
2012-01-14 04:12 . 2012-01-14 04:12 -------- d-----w- c:\program files (x86)\MSXML 4.0
2012-01-14 04:11 . 2009-07-14 18:31 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2012-01-14 04:11 . 2009-07-14 18:18 654928 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2012-01-14 04:11 . 2009-07-14 18:18 42064 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2012-01-14 03:42 . 2008-05-27 04:59 18904 ----a-w- c:\windows\SysWow64\StructuredQuerySchemaTrivial.bin
2012-01-14 03:42 . 2008-05-27 04:59 18904 ----a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin
2012-01-14 02:52 . 2009-01-08 01:20 537088 ----a-w- c:\program files\Internet Explorer\pdm.dll
2012-01-14 02:52 . 2009-01-08 01:20 358904 ----a-w- c:\program files\Internet Explorer\msdbg2.dll
2012-01-14 02:52 . 2009-01-08 01:20 355832 ----a-w- c:\program files (x86)\Internet Explorer\pdm.dll
2012-01-14 02:52 . 2009-01-08 01:20 265720 ----a-w- c:\program files (x86)\Internet Explorer\msdbg2.dll
2012-01-14 02:29 . 2006-11-10 22:25 525792 ----a-w- c:\windows\system32\difxapi.dll
2012-01-14 01:44 . 2010-02-20 23:15 32768 ----a-w- c:\windows\system32\nshhttp.dll
2012-01-14 01:44 . 2010-02-20 23:06 24064 ----a-w- c:\windows\SysWow64\nshhttp.dll
2012-01-14 01:44 . 2010-02-20 23:14 33792 ----a-w- c:\windows\system32\httpapi.dll
2012-01-14 01:44 . 2010-02-20 23:05 30720 ----a-w- c:\windows\SysWow64\httpapi.dll
2012-01-14 01:44 . 2010-02-20 21:30 620032 ----a-w- c:\windows\system32\drivers\http.sys
2012-01-14 01:18 . 2009-09-10 15:27 1486848 ----a-w- c:\program files\Windows Media Player\setup_wm.exe
2012-01-14 01:18 . 2009-09-10 15:27 372736 ----a-w- c:\windows\system32\unregmp2.exe
2012-01-14 01:18 . 2009-09-10 14:58 1418752 ----a-w- c:\program files (x86)\Windows Media Player\setup_wm.exe
2012-01-14 01:18 . 2009-09-10 14:58 310784 ----a-w- c:\windows\SysWow64\unregmp2.exe
2012-01-14 01:17 . 2009-08-14 16:04 143360 ----a-w- c:\windows\system32\netiohlp.dll
2012-01-14 01:17 . 2009-08-14 14:10 12800 ----a-w- c:\windows\system32\MRINFO.EXE
2012-01-14 01:17 . 2009-08-14 14:10 32256 ----a-w- c:\windows\system32\NETSTAT.EXE
2012-01-14 01:17 . 2009-08-14 14:10 23040 ----a-w- c:\windows\system32\ARP.EXE
2012-01-14 01:17 . 2009-08-14 13:49 27136 ----a-w- c:\windows\SysWow64\NETSTAT.EXE
2012-01-14 01:17 . 2009-08-14 13:48 105984 ----a-w- c:\windows\SysWow64\netiohlp.dll
2012-01-14 01:16 . 2009-08-14 14:10 10752 ----a-w- c:\windows\system32\TCPSVCS.EXE
2012-01-14 01:16 . 2009-08-14 14:10 21504 ----a-w- c:\windows\system32\ROUTE.EXE
2012-01-14 01:16 . 2009-08-14 14:10 11264 ----a-w- c:\windows\system32\finger.exe
2012-01-14 01:16 . 2009-08-14 14:10 10240 ----a-w- c:\windows\system32\HOSTNAME.EXE
2012-01-14 01:16 . 2009-08-14 13:49 9728 ----a-w- c:\windows\SysWow64\TCPSVCS.EXE
2012-01-14 01:16 . 2009-08-14 13:49 17920 ----a-w- c:\windows\SysWow64\ROUTE.EXE
2012-01-14 01:16 . 2009-08-14 13:49 11264 ----a-w- c:\windows\SysWow64\MRINFO.EXE
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1555968]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QPService"="c:\program files (x86)\HP\QuickPlay\QPService.exe" [2007-12-20 468264]
"UCam_Menu"="c:\program files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-17 218408]
"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 23:34 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-10-26 1702400]
"RtHDVCpl"="RAVCpl64.exe" [2007-10-09 5429760]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-10-24 178712]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 701440]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 138264]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 203800]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 168472]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://my.yahoo.com/uLocal Page = c:\windows\system32\blank.htm
mStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptopmLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKLM-Run-QlbCtrl - %ProgramFiles(x86)%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
Wow6432Node-HKLM-Run-SunJavaUpdateSched - c:\program files (x86)\Java\jre6\bin\jusched.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-Windows Defender - c:\program files (x86)\Windows Defender\MSASCui.exe
HKLM-Run-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}]
@Denied: (A 2) (Everyone)
@SACL=
@="FlashProp Class"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}\InprocServer32]
@SACL=
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}\Programmable]
@SACL=
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@SACL=
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Control]
@SACL=
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\EnableFullPage]
@SACL=
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Implemented Categories]
@SACL=
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@SACL=
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@SACL=
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@SACL=
@="ShockwaveFlash.ShockwaveFlash.9"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Programmable]
@SACL=
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@SACL=
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@SACL=
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@SACL=
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@SACL=
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@SACL=
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Control]
@SACL=
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@SACL=
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@SACL=
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Programmable]
@SACL=
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@SACL=
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@SACL=
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@SACL=
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@SACL=
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}]
@Denied: (A 2) (Everyone)
@SACL=
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil9d.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\Elevation]
@SACL=
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\LocalServer32]
@SACL=
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil9d.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\TypeLib]
@SACL=
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}]
@Denied: (A 2) (Everyone)
@SACL=
@="IFlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32]
@SACL=
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib]
@SACL=
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@SACL=
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@SACL=
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@SACL=
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@SACL=
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\program files (x86)\CyberLink\Shared Files\RichVideo.exe
c:\program files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
c:\program files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe
.
**************************************************************************
.
Completion time: 2012-01-21 17:13:06 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-21 23:13
.
Pre-Run: 149,891,264,512 bytes free
Post-Run: 150,183,657,472 bytes free
.
- - End Of File - - 04060A7F1E33A7E8815211B58BB04773