ComboFix 11-07-12.09 - Laptop 13/07/2011 19:33:15.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.64.1033.18.8106.6210 [GMT 12:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\PCDr\5830\Downloads\2ee79d71-badc-46b4-b731-42b15f3cd1c3.dll c:\programdata\PCDr\5830\Downloads\3a79f062-8f3e-464f-9815-2c45840494ee.dll c:\programdata\PCDr\5830\Downloads\3e4c86d5-a5c1-4c3f-8fc7-6258992b16c5.dll c:\programdata\PCDr\5830\Downloads\493f295d-1a46-46f6-926c-63b474cedab4.dll c:\programdata\PCDr\5830\Downloads\5e1c102f-bfde-420c-87c0-64fe851888e5.dll c:\programdata\PCDr\5830\Downloads\6cf47205-6796-460b-806d-8f5f1a1f6b2e.dll c:\programdata\PCDr\5830\Downloads\7014e871-cc3b-4dec-b82b-bc70222b40ed.dll c:\programdata\PCDr\5830\Downloads\a4930af9-016c-4915-a740-a3364e7618aa.dll c:\programdata\PCDr\5830\Downloads\e9bb45d9-5a2b-47e8-9c48-168276d422cc.dll c:\users\Laptop\AppData\Roaming\ODIN c:\users\Laptop\AppData\Roaming\ODIN\ODIN.ini c:\windows\SysWow64\DXGIZ.DLL . . ((((((((((((((((((((((((( Files Created from 2011-06-13 to 2011-07-13 ))))))))))))))))))))))))))))))) . . 2011-07-13 07:47 . 2011-07-13 07:47 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-07-10 10:53 . 2003-03-21 01:45 250544 ----a-w- c:\program files (x86)\Common Files\keyhelp.ocx 2011-07-10 10:53 . 2011-07-10 10:53 -------- d-----w- c:\program files (x86)\HotPotatoes6 2011-07-08 21:21 . 2011-07-11 08:43 -------- d-----w- C:\MGADiagToolOutput 2011-07-08 21:20 . 2011-07-08 21:20 -------- d-----w- c:\programdata\Office Genuine Advantage 2011-07-07 10:48 . 2011-07-07 10:48 -------- d-----w- c:\program files (x86)\ZD Soft 2011-07-07 10:32 . 2011-07-07 10:32 -------- d-----w- c:\program files (x86)\ESCV 2011-07-07 10:31 . 2011-07-07 10:31 -------- d-----w- c:\windows\Downloaded Installations 2011-07-07 07:42 . 2011-07-07 07:42 -------- d-----w- c:\program files (x86)\TechSmith 2011-07-05 21:27 . 2011-07-05 21:27 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help 2011-07-05 07:38 . 2011-07-05 07:38 -------- d-----w- c:\program files\COMODO 2011-07-05 07:37 . 2011-07-05 07:37 1700352 ----a-w- c:\windows\SysWow64\gdiplus.dll 2011-07-03 11:38 . 2011-07-03 11:38 -------- d-----w- C:\My backups 2011-07-03 11:33 . 2011-07-03 21:13 -------- d-----w- c:\windows\SysWow64\NV 2011-07-03 11:33 . 2011-07-03 21:13 -------- d-----w- c:\windows\system32\NV 2011-07-03 11:29 . 2011-07-03 11:29 -------- d-----w- c:\users\UpdatusUser 2011-07-03 11:27 . 2011-05-21 06:01 8863336 ----a-w- c:\windows\system32\nvwgf2umx.dll 2011-07-03 11:26 . 2011-07-03 11:26 -------- d-----w- C:\NVIDIA 2011-07-03 09:34 . 2011-06-06 22:10 8873296 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-07-03 02:44 . 2011-07-03 02:44 -------- d-----w- c:\program files (x86)\Common Files\Adobe 2011-07-03 02:30 . 2011-07-03 02:30 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D4FCC5B9-D92F-43CC-8506-AD927009A334}\gapaengine.dll 2011-07-02 07:17 . 2011-07-02 07:17 -------- d-----w- c:\programdata\SUPERAntiSpyware.com 2011-07-02 07:17 . 2011-07-02 07:17 -------- d-----w- c:\programdata\!SASCORE 2011-07-02 07:17 . 2011-07-02 08:45 -------- d-----w- c:\program files\SUPERAntiSpyware 2011-07-02 00:33 . 2011-07-02 01:38 -------- d-----w- c:\programdata\Blizzard Entertainment 2011-07-02 00:33 . 2011-07-02 01:38 -------- d-----w- c:\program files (x86)\StarCraft II 2011-07-02 00:33 . 2011-07-02 00:47 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment 2011-07-02 00:03 . 2011-07-02 00:03 -------- d-----w- c:\program files (x86)\Common Files\Apple 2011-07-02 00:03 . 2011-07-02 00:03 -------- d-----w- c:\program files (x86)\Apple Software Update 2011-07-02 00:03 . 2011-07-02 00:03 -------- d-----w- c:\programdata\Apple 2011-07-01 10:27 . 2010-05-25 22:39 6144 ------w- c:\windows\system32\8EF8.tmp 2011-07-01 10:25 . 2010-05-25 22:39 6144 ------w- c:\windows\system32\344A.tmp 2011-07-01 09:53 . 2011-07-01 09:53 -------- d-----w- c:\program files (x86)\TweetDeck 2011-07-01 09:53 . 2011-07-01 09:53 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR 2011-07-01 08:54 . 2010-05-25 22:39 6144 ------w- c:\windows\system32\9AAA.tmp 2011-07-01 08:53 . 2010-05-25 22:39 6144 ------w- c:\windows\system32\DBFC.tmp 2011-07-01 08:53 . 2011-07-12 06:55 -------- d-----w- c:\program files (x86)\Sophos 2011-07-01 08:21 . 2011-07-01 08:21 -------- d-----w- c:\programdata\Malwarebytes 2011-07-01 08:21 . 2011-05-28 21:11 39984 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2011-07-01 08:21 . 2011-07-01 08:21 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-07-01 08:21 . 2011-05-28 21:11 25912 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-07-01 07:44 . 2011-07-12 20:42 -------- d-----w- c:\programdata\MFAData 2011-07-01 07:39 . 2011-07-01 07:39 -------- d-----w- c:\program files (x86)\Microsoft Security Client 2011-07-01 07:39 . 2011-07-01 07:39 -------- d-----w- c:\program files\Microsoft Security Client 2011-06-26 04:15 . 2011-06-26 04:15 2784600 ----a-w- c:\windows\system32\auto_reactivate.exe 2011-06-26 03:44 . 2011-06-26 03:52 272448 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys 2011-06-26 03:44 . 2011-06-26 03:56 -------- d-----w- c:\program files (x86)\DAEMON Tools Pro 2011-06-26 02:54 . 2011-06-26 02:56 -------- d-----w- c:\programdata\DAEMON Tools Pro 2011-06-26 01:24 . 2011-06-26 01:24 -------- d-----w- c:\program files\Dameon 2011-06-26 01:00 . 2011-06-26 01:02 -------- d-----w- c:\programdata\PCDr 2011-06-26 00:37 . 2011-06-26 00:37 -------- d-----w- c:\program files (x86)\Microsoft Games 2011-06-26 00:29 . 2011-06-26 03:35 867064 ----a-w- c:\windows\system32\drivers\sptd.sys 2011-06-26 00:25 . 2011-06-26 00:25 -------- d-----w- c:\program files (x86)\PowerISO 2011-06-26 00:25 . 2010-04-12 08:55 91568 ----a-w- c:\windows\system32\drivers\scdemu.sys 2011-06-26 00:15 . 2009-02-24 06:35 255552 ----a-w- c:\windows\system32\drivers\mcdbus.sys 2011-06-26 00:08 . 2011-06-26 00:20 -------- d-----w- c:\program files (x86)\MagicISO 2011-06-26 00:03 . 2011-06-26 00:03 -------- d-----w- c:\programdata\farstone 2011-06-26 00:00 . 2000-06-25 19:43 254224 ----a-w- c:\windows\SysWow64\drmclien.dll 2011-06-25 23:58 . 2006-12-19 07:45 81920 ----a-w- c:\windows\VPLAY801.EXE 2011-06-25 23:58 . 2007-08-15 09:32 81424 ----a-w- c:\windows\system32\drivers\FVXSCSI.SYS 2011-06-25 23:58 . 2007-03-02 01:48 21784 ----a-w- c:\windows\system32\drivers\FCDABUS.SYS 2011-06-25 23:57 . 2007-04-09 20:05 32768 ------w- c:\windows\SysWow64\inVHDDrvExe.exe 2011-06-25 23:57 . 2007-03-02 01:48 36864 ------w- c:\windows\SysWow64\unVHDDrvExe.exe 2011-06-25 02:13 . 2011-06-25 02:13 -------- d--h--w- c:\programdata\Common Files 2011-06-25 00:15 . 2011-06-25 00:15 -------- d-----w- c:\program files (x86)\Electronic Arts 2011-06-25 00:07 . 2011-06-19 20:57 8873296 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0759AC3A-AEFC-4FC4-8AF2-5B1B709BE266}\mpengine.dll 2011-06-24 13:27 . 2011-06-24 13:27 -------- d-----w- c:\windows\SysWow64\Wat 2011-06-24 13:27 . 2011-06-24 13:27 -------- d-----w- c:\windows\system32\Wat 2011-06-24 12:46 . 2011-06-24 12:46 -------- d-----w- c:\program files (x86)\Microsoft Synchronization Services 2011-06-24 12:46 . 2011-06-24 12:46 -------- d-----w- c:\program files (x86)\Microsoft Sync Framework 2011-06-24 12:45 . 2011-06-24 12:45 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8 2011-06-24 10:24 . 2011-06-24 10:24 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services 2011-06-24 10:23 . 2011-07-05 21:31 -------- d-----w- c:\programdata\Microsoft Help 2011-06-24 10:23 . 2011-06-24 10:23 -------- d-----r- C:\MSOCache 2011-06-24 09:33 . 2011-01-03 08:38 177128 ----a-w- c:\windows\system32\drivers\ssadmdm.sys 2011-06-24 09:33 . 2011-01-03 08:38 16872 ----a-w- c:\windows\system32\drivers\ssadmdfl.sys 2011-06-24 09:33 . 2011-01-03 08:38 157160 ----a-w- c:\windows\system32\drivers\ssadbus.sys 2011-06-24 09:33 . 2011-01-03 08:38 13800 ----a-w- c:\windows\system32\drivers\ssadwhnt.sys 2011-06-24 09:33 . 2011-01-03 08:38 13800 ----a-w- c:\windows\system32\drivers\ssadwh.sys 2011-06-24 09:33 . 2011-01-03 08:38 13288 ----a-w- c:\windows\system32\drivers\ssadcmnt.sys 2011-06-24 09:33 . 2011-01-03 08:38 13288 ----a-w- c:\windows\system32\drivers\ssadcm.sys 2011-06-24 09:33 . 2010-12-21 05:55 36328 ----a-w- c:\windows\system32\drivers\ssadadb.sys 2011-06-24 09:33 . 2010-12-21 05:55 1917416 ----a-w- c:\windows\system32\WdfCoInstaller01005.dll 2011-06-24 09:33 . 2010-12-21 05:55 1917416 ----a-w- c:\windows\system32\drivers\WdfCoInstaller01005.dll 2011-06-24 09:32 . 2010-12-21 05:55 15944 ----a-w- c:\windows\system32\drivers\sscdwhnt.sys 2011-06-24 09:32 . 2010-12-21 05:55 15944 ----a-w- c:\windows\system32\drivers\sscdwh.sys 2011-06-24 09:32 . 2010-12-21 05:55 19016 ----a-w- c:\windows\system32\drivers\sscdmdfl.sys 2011-06-24 09:32 . 2010-12-21 05:55 172104 ----a-w- c:\windows\system32\drivers\sscdmdm.sys 2011-06-24 09:32 . 2010-12-21 05:55 15432 ----a-w- c:\windows\system32\drivers\sscdcmnt.sys 2011-06-24 09:32 . 2010-12-21 05:55 15432 ----a-w- c:\windows\system32\drivers\sscdcm.sys 2011-06-24 09:32 . 2010-12-21 05:55 136264 ----a-w- c:\windows\system32\drivers\sscdbus.sys 2011-06-24 09:32 . 2011-06-06 23:13 4659712 ----a-w- c:\windows\SysWow64\Redemption.dll 2011-06-24 09:32 . 2011-06-24 09:32 -------- d-----w- c:\program files (x86)\MarkAny 2011-06-24 09:32 . 2011-06-06 23:13 821824 ----a-w- c:\windows\SysWow64\dgderapi.dll 2011-06-24 09:32 . 2011-06-24 09:32 -------- d-----w- c:\program files (x86)\Samsung 2011-06-24 09:32 . 2011-06-24 09:32 -------- d-----w- c:\programdata\Samsung 2011-06-24 09:17 . 2011-06-24 09:17 1263200 ----a-w- c:\windows\system32\drivers\tdrpm273.sys 2011-06-24 09:17 . 2011-06-24 09:17 970336 ----a-w- c:\windows\system32\drivers\timntr.sys 2011-06-24 09:16 . 2011-07-05 07:32 -------- d-----w- c:\program files (x86)\Common Files\Acronis 2011-06-24 07:48 . 2011-06-24 07:48 -------- d-----w- c:\program files (x86)\Common Files\doubleTwist 2011-06-24 07:48 . 2008-12-17 07:22 57344 ----a-w- c:\windows\SysWow64\ff_vfw.dll 2011-06-24 07:48 . 2011-06-24 07:48 -------- d-----w- c:\program files (x86)\ffdshow 2011-06-24 07:48 . 2008-12-11 01:26 60273 ----a-w- c:\windows\SysWow64\pthreadGC2.dll 2011-06-24 07:46 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe 2011-06-24 07:46 . 2011-04-09 05:56 123904 ----a-w- c:\windows\SysWow64\poqexec.exe 2011-06-24 07:44 . 2011-02-18 10:51 31232 ----a-w- c:\windows\system32\prevhost.exe 2011-06-24 07:44 . 2011-02-18 05:39 31232 ----a-w- c:\windows\SysWow64\prevhost.exe 2011-06-24 07:41 . 2011-02-23 04:55 90624 ----a-w- c:\windows\system32\drivers\bowser.sys 2011-06-24 07:38 . 2011-06-24 07:48 -------- d-----w- c:\program files (x86)\doubleTwist 2.0 2011-06-24 07:38 . 2011-06-24 07:58 -------- d-----w- c:\program files (x86)\gPadServer 2011-06-24 07:15 . 2011-06-24 23:24 -------- d-----w- C:\$AVG 2011-06-24 07:15 . 2011-07-01 08:11 -------- d-----w- c:\programdata\avg9 2011-06-24 07:09 . 2011-06-24 07:12 -------- d-----w- c:\programdata\WinZip 2011-06-24 07:07 . 2011-06-25 00:10 -------- d-----w- c:\program files (x86)\Google 2011-06-24 07:04 . 2011-06-24 07:04 -------- d-----w- c:\program files (x86)\VideoLAN 2011-06-24 06:58 . 2011-06-26 04:00 -------- d-----w- c:\programdata\Creative 2011-06-24 06:54 . 2011-06-24 06:54 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-06-24 06:46 . 2011-06-24 06:46 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll 2011-06-24 06:44 . 2011-07-07 07:43 -------- d-----w- c:\users\Laptop 2011-06-24 06:26 . 2011-06-24 06:26 -------- d-----w- C:\FIND_EULA_PATH 2011-06-24 06:26 . 2011-06-24 06:26 -------- d-----w- c:\program files (x86)\Dell Touch Software Suite 2011-06-24 06:23 . 2011-06-24 06:23 -------- d-----w- c:\users\Default\AppData\Local\SoftThinks . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-06-11 03:41 . 2011-06-11 03:41 800256 ----a-w- c:\windows\system32\usp10.dll 2011-06-11 03:41 . 2011-06-11 03:41 7680 ----a-w- c:\windows\system32\KBDINTAM.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7680 ----a-w- c:\windows\system32\KBDINMAL.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7680 ----a-w- c:\windows\system32\KBDINDEV.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7680 ----a-w- c:\windows\system32\KBDINBEN.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7168 ----a-w- c:\windows\SysWow64\KBDINTAM.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7168 ----a-w- c:\windows\SysWow64\KBDINORI.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7168 ----a-w- c:\windows\SysWow64\KBDINMAR.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7168 ----a-w- c:\windows\SysWow64\KBDINMAL.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7168 ----a-w- c:\windows\SysWow64\KBDINKAN.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7168 ----a-w- c:\windows\SysWow64\KBDINHIN.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7168 ----a-w- c:\windows\SysWow64\KBDINDEV.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7168 ----a-w- c:\windows\SysWow64\KBDINBEN.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7168 ----a-w- c:\windows\system32\KBDINTEL.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7168 ----a-w- c:\windows\system32\KBDINPUN.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7168 ----a-w- c:\windows\system32\KBDINORI.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7168 ----a-w- c:\windows\system32\KBDINMAR.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7168 ----a-w- c:\windows\system32\KBDINKAN.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7168 ----a-w- c:\windows\system32\KBDINHIN.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7168 ----a-w- c:\windows\system32\KBDINGUJ.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7168 ----a-w- c:\windows\system32\KBDINEN.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7168 ----a-w- c:\windows\system32\KBDINBE2.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7168 ----a-w- c:\windows\system32\KBDINBE1.DLL 2011-06-11 03:41 . 2011-06-11 03:41 7168 ----a-w- c:\windows\system32\KBDINASA.DLL 2011-06-11 03:41 . 2011-06-11 03:41 6656 ----a-w- c:\windows\SysWow64\KBDINTEL.DLL 2011-06-11 03:41 . 2011-06-11 03:41 6656 ----a-w- c:\windows\SysWow64\KBDINPUN.DLL 2011-06-11 03:41 . 2011-06-11 03:41 6656 ----a-w- c:\windows\SysWow64\KBDINGUJ.DLL 2011-06-11 03:41 . 2011-06-11 03:41 6656 ----a-w- c:\windows\SysWow64\KBDINBE2.DLL 2011-06-11 03:41 . 2011-06-11 03:41 6656 ----a-w- c:\windows\SysWow64\KBDINBE1.DLL 2011-06-11 03:41 . 2011-06-11 03:41 6656 ----a-w- c:\windows\SysWow64\KBDINASA.DLL 2011-06-11 03:41 . 2011-06-11 03:41 626176 ----a-w- c:\windows\SysWow64\usp10.dll 2011-06-11 03:41 . 2011-06-11 03:41 961024 ----a-w- c:\windows\system32\CPFilters.dll 2011-06-11 03:41 . 2011-06-11 03:41 902656 ----a-w- c:\windows\system32\d2d1.dll 2011-06-11 03:41 . 2011-06-11 03:41 850944 ----a-w- c:\windows\SysWow64\sbe.dll 2011-06-11 03:41 . 2011-06-11 03:41 739840 ----a-w- c:\windows\SysWow64\d2d1.dll 2011-06-11 03:41 . 2011-06-11 03:41 723968 ----a-w- c:\windows\system32\EncDec.dll 2011-06-11 03:41 . 2011-06-11 03:41 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll 2011-06-11 03:41 . 2011-06-11 03:41 534528 ----a-w- c:\windows\SysWow64\EncDec.dll 2011-06-11 03:41 . 2011-06-11 03:41 259072 ----a-w- c:\windows\system32\mpg2splt.ax 2011-06-11 03:41 . 2011-06-11 03:41 199680 ----a-w- c:\windows\SysWow64\mpg2splt.ax 2011-06-11 03:41 . 2011-06-11 03:41 197120 ----a-w- c:\windows\system32\d3d10_1.dll 2011-06-11 03:41 . 2011-06-11 03:41 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll 2011-06-11 03:41 . 2011-06-11 03:41 1544192 ----a-w- c:\windows\system32\DWrite.dll 2011-06-11 03:41 . 2011-06-11 03:41 1139200 ----a-w- c:\windows\system32\FntCache.dll 2011-06-11 03:41 . 2011-06-11 03:41 1118720 ----a-w- c:\windows\system32\sbe.dll 2011-06-11 03:41 . 2011-06-11 03:41 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll 2011-06-11 03:41 . 2011-06-11 03:41 99328 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2011-06-11 03:41 . 2011-06-11 03:41 951680 ----a-w- c:\windows\system32\drivers\ndis.sys 2011-06-11 03:41 . 2011-06-11 03:41 715776 ----a-w- c:\windows\system32\kerberos.dll 2011-06-11 03:41 . 2011-06-11 03:41 70656 ----a-w- c:\windows\SysWow64\fontsub.dll 2011-06-11 03:41 . 2011-06-11 03:41 542208 ----a-w- c:\windows\SysWow64\kerberos.dll 2011-06-11 03:41 . 2011-06-11 03:41 100864 ----a-w- c:\windows\system32\fontsub.dll 2011-06-11 03:29 . 2011-06-11 03:29 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2011-06-11 03:29 . 2011-06-11 03:29 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2011-06-11 03:29 . 2011-06-11 03:29 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll 2011-06-11 03:29 . 2011-06-11 03:29 85504 ----a-w- c:\windows\system32\iesetup.dll 2011-06-11 03:29 . 2011-06-11 03:29 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2011-06-11 03:29 . 2011-06-11 03:29 76800 ----a-w- c:\windows\system32\tdc.ocx 2011-06-11 03:29 . 2011-06-11 03:29 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2011-06-11 03:29 . 2011-06-11 03:29 74752 ----a-w- c:\windows\SysWow64\iesetup.dll 2011-06-11 03:29 . 2011-06-11 03:29 63488 ----a-w- c:\windows\SysWow64\tdc.ocx 2011-06-11 03:29 . 2011-06-11 03:29 603648 ----a-w- c:\windows\system32\vbscript.dll 2011-06-11 03:29 . 2011-06-11 03:29 49664 ----a-w- c:\windows\system32\imgutil.dll 2011-06-11 03:29 . 2011-06-11 03:29 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2011-06-11 03:29 . 2011-06-11 03:29 48640 ----a-w- c:\windows\system32\mshtmler.dll 2011-06-11 03:29 . 2011-06-11 03:29 448512 ----a-w- c:\windows\system32\html.iec 2011-06-11 03:29 . 2011-06-11 03:29 420864 ----a-w- c:\windows\SysWow64\vbscript.dll 2011-06-11 03:29 . 2011-06-11 03:29 367104 ----a-w- c:\windows\SysWow64\html.iec 2011-06-11 03:29 . 2011-06-11 03:29 35840 ----a-w- c:\windows\SysWow64\imgutil.dll 2011-06-11 03:29 . 2011-06-11 03:29 30720 ----a-w- c:\windows\system32\licmgr10.dll 2011-06-11 03:29 . 2011-06-11 03:29 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll 2011-06-11 03:29 . 2011-06-11 03:29 222208 ----a-w- c:\windows\system32\msls31.dll 2011-06-11 03:29 . 2011-06-11 03:29 173056 ----a-w- c:\windows\system32\ieUnatt.exe 2011-06-11 03:29 . 2011-06-11 03:29 165888 ----a-w- c:\windows\system32\iexpress.exe 2011-06-11 03:29 . 2011-06-11 03:29 161792 ----a-w- c:\windows\SysWow64\msls31.dll 2011-06-11 03:29 . 2011-06-11 03:29 160256 ----a-w- c:\windows\system32\wextract.exe 2011-06-11 03:29 . 2011-06-11 03:29 152064 ----a-w- c:\windows\SysWow64\wextract.exe 2011-06-11 03:29 . 2011-06-11 03:29 150528 ----a-w- c:\windows\SysWow64\iexpress.exe 2011-06-11 03:29 . 2011-06-11 03:29 1492992 ----a-w- c:\windows\system32\inetcpl.cpl 2011-06-11 03:29 . 2011-06-11 03:29 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2011-06-11 03:29 . 2011-06-11 03:29 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2011-06-11 03:29 . 2011-06-11 03:29 1389056 ----a-w- c:\windows\system32\wininet.dll 2011-06-11 03:29 . 2011-06-11 03:29 135168 ----a-w- c:\windows\system32\IEAdvpack.dll 2011-06-11 03:29 . 2011-06-11 03:29 12288 ----a-w- c:\windows\system32\mshta.exe 2011-06-11 03:29 . 2011-06-11 03:29 11776 ----a-w- c:\windows\SysWow64\mshta.exe 2011-06-11 03:29 . 2011-06-11 03:29 114176 ----a-w- c:\windows\system32\admparse.dll 2011-06-11 03:29 . 2011-06-11 03:29 1126912 ----a-w- c:\windows\SysWow64\wininet.dll 2011-06-11 03:29 . 2011-06-11 03:29 111616 ----a-w- c:\windows\system32\iesysprep.dll 2011-06-11 03:29 . 2011-06-11 03:29 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2011-06-11 03:29 . 2011-06-11 03:29 101888 ----a-w- c:\windows\SysWow64\admparse.dll 2011-06-11 01:53 . 2011-06-11 01:53 521448 ----a-w- c:\windows\system32\deployJava1.dll 2011-06-06 23:13 . 2011-06-06 23:13 974848 ----a-w- c:\windows\SysWow64\cis-2.4.dll 2011-06-06 23:13 . 2011-06-06 23:13 90112 ----a-w- c:\windows\MAMCityDownload.ocx 2011-06-06 23:13 . 2011-06-06 23:13 81920 ----a-w- c:\windows\SysWow64\issacapi_bs-2.3.dll 2011-06-06 23:13 . 2011-06-06 23:13 65536 ----a-w- c:\windows\SysWow64\issacapi_pe-2.3.dll 2011-06-06 23:13 . 2011-06-06 23:13 57344 ----a-w- c:\windows\SysWow64\MTXSYNCICON.dll 2011-06-06 23:13 . 2011-06-06 23:13 57344 ----a-w- c:\windows\SysWow64\issacapi_se-2.3.dll 2011-06-06 23:13 . 2011-06-06 23:13 569344 ----a-w- c:\windows\SysWow64\muzdecode.ax 2011-06-06 23:13 . 2011-06-06 23:13 491520 ----a-w- c:\windows\SysWow64\muzapp.dll 2011-06-06 23:13 . 2011-06-06 23:13 49152 ----a-w- c:\windows\SysWow64\MaJGUILib.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\users\Laptop\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\users\Laptop\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\users\Laptop\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "KiesHelper"="c:\program files (x86)\Samsung\Kies\KiesHelper.exe" [2011-06-09 940944] "KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2011-06-09 3373968] "DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2011-03-17 842048] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-07-02 2988928] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2010-12-23 491650] "RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112] "Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] . c:\users\Laptop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Laptop\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-26 24176560] gPadServer.lnk - c:\program files (x86)\gPadServer\gPadServer.exe [2011-6-24 167424] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0auto_reactivate \\?\volume{302c6c38-93dd-11e0-8059-806e6f6e6963}\bootwiz\asrm.bin . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x] R2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-24 136176] R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632] R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [x] R3 FACAP;facap, FastAccess Video Capture;c:\windows\system32\DRIVERS\facap.sys [x] R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [x] R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x] R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\8EF8.tmp [x] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-12-27 31124344] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-12-17 340240] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184] R3 reparse;reparse;c:\windows\system32\DRIVERS\cbreparse.sys [x] R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656] R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [x] R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [x] R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x] R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x] S0 bdisk;COMODO Disk Raw Access Filter;c:\windows\system32\drivers\bdisk.sys [x] S0 CBUfs;CBUfs;c:\windows\system32\drivers\CBUFS.sys [x] S0 cbvd;Comodo Encrypted Virtual Disk;c:\windows\system32\DRIVERS\cbvd.sys [x] S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-05-04 128384] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952] S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208] S2 COSService.exe;Comodo Online Storage Service;c:\program files\COMODO\COMODO BackUp\COSService.exe [2011-06-02 670000] S2 iPodDrv;iPodDrv;c:\windows\system32\drivers\iPodDrv.sys [x] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-21 2214504] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-05-20 378472] S2 SynchronizationService.exe;Comodo BackUp Service;c:\program files\COMODO\COMODO BackUp\SynchronizationService.exe [2011-06-02 1557808] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-20 2656280] S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [x] S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [x] S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [x] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x] S3 cyhid;Cypress Input Device;c:\windows\system32\DRIVERS\cyhid.sys [x] S3 cykbfltrService;Cypress Keyboard Filter Driver;c:\windows\system32\DRIVERS\cykbfltr.sys [x] S3 cymfltrService;Cypress Trackpad Filter Driver;c:\windows\system32\DRIVERS\cymfltr.sys [x] S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [x] S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x] S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [x] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x] S3 vdbus;Virtual Disk Bus Enumerator;c:\windows\system32\DRIVERS\vdbus.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2011-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-24 07:07] . 2011-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-24 07:07] . 2011-07-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2372956138-338855233-1135559829-1002Core.job - c:\users\Laptop\AppData\Local\Google\Update\GoogleUpdate.exe [2011-07-08 07:07] . 2011-07-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2372956138-338855233-1135559829-1002UA.job - c:\users\Laptop\AppData\Local\Google\Update\GoogleUpdate.exe [2011-07-08 07:07] . 2011-06-26 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job - c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09] . 2011-07-13 c:\windows\Tasks\SystemToolsDailyTest.job - c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09] . . --------- x86-64 ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\COSDriveOverlayIcon] @="{5FDACB62-6B7B-4116-9403-C5E0D3852A57}" [HKEY_CLASSES_ROOT\CLSID\{5FDACB62-6B7B-4116-9403-C5E0D3852A57}] 2011-06-02 08:04 673072 ----a-w- c:\program files\COMODO\COMODO BackUp\ShellExtension_3.0.171317.133.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 ----a-w- c:\users\Laptop\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 ----a-w- c:\users\Laptop\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 ----a-w- c:\users\Laptop\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 ----a-w- c:\users\Laptop\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CyCpIo"="c:\program files\Cypress\TrackPad\CyCpIo.exe" [2011-03-10 2364928] "CyHidWin"="c:\program files\Cypress\TrackPad\CyHidWin.exe" [2011-03-10 2351104] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-02-26 6611560] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-03-02 2189416] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-03-12 167960] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-03-12 391704] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-03-12 418840] "FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-12-17 686704] "BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-01-24 10355200] "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-12-17 1933584] "IntelTBRunOnce"="wscript.exe" [2009-07-14 168960] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736] "NVHotkey"="c:\windows\system32\nvHotkey.dll" [2011-05-21 326760] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 "AppInit_DLLs"=c:\windows\System32\nvinitx.dll . ------- Supplementary Scan ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www1.ap.dell.com/content/default.aspx?c=nz&l=en&s=gen mLocal Page = c:\windows\SysWOW64\blank.htm IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 10.0.1.1 FF - ProfilePath - c:\users\Laptop\AppData\Roaming\Mozilla\Firefox\Profiles\cblbq9yv.default\ . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Wow6432Node-HKLM-Run-FAStartup - (no file) Wow6432Node-HKLM-Run-RAMDrive - c:\program files (x86)\FarStone\VirtualDrive\VHD\RDTask.exe Toolbar-Locked - (no file) AddRemove-{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1 - c:\program files (x86)\AVG\AVG PC Tuneup 2011\unins000.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MEMSWEEP2] "ImagePath"="\??\c:\windows\system32\8EF8.tmp" . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-2372956138-338855233-1135559829-1002\Software\SecuROM\License information*] "datasecu"=hex:45,a5,b1,de,da,c9,1c,a2,6d,cd,a6,bc,2a,61,86,69,01,fb,f4,ff,33, 01,13,90,e7,de,b7,79,90,ce,02,0a,3c,75,44,fb,b0,f0,54,b0,a6,f0,ed,66,0f,57,\ "rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-07-13 19:53:07 ComboFix-quarantined-files.txt 2011-07-13 07:53 . Pre-Run: 475,355,066,368 bytes free Post-Run: 475,397,959,680 bytes free . - - End Of File - - ABDCC6BE98A49D407EEC705584D0DB43