----- File Replicators -----
.
c:\cygwin\bin\git.exe
c:\cygwin\lib\git-core\git-add.exe
c:\cygwin\lib\git-core\git-annotate.exe
c:\cygwin\lib\git-core\git-apply.exe
c:\cygwin\lib\git-core\git-archive.exe
c:\cygwin\lib\git-core\git-bisect--helper.exe
c:\cygwin\lib\git-core\git-blame.exe
c:\cygwin\lib\git-core\git-branch.exe
c:\cygwin\lib\git-core\git-bundle.exe
c:\cygwin\lib\git-core\git-cat-file.exe
c:\cygwin\lib\git-core\git-check-attr.exe
c:\cygwin\lib\git-core\git-check-ref-format.exe
c:\cygwin\lib\git-core\git-checkout-index.exe
c:\cygwin\lib\git-core\git-checkout.exe
c:\cygwin\lib\git-core\git-cherry-pick.exe
c:\cygwin\lib\git-core\git-cherry.exe
c:\cygwin\lib\git-core\git-clean.exe
c:\cygwin\lib\git-core\git-clone.exe
c:\cygwin\lib\git-core\git-commit-tree.exe
c:\cygwin\lib\git-core\git-commit.exe
c:\cygwin\lib\git-core\git-config.exe
c:\cygwin\lib\git-core\git-count-objects.exe
c:\cygwin\lib\git-core\git-describe.exe
c:\cygwin\lib\git-core\git-diff-files.exe
c:\cygwin\lib\git-core\git-diff-index.exe
c:\cygwin\lib\git-core\git-diff-tree.exe
c:\cygwin\lib\git-core\git-diff.exe
c:\cygwin\lib\git-core\git-fast-export.exe
c:\cygwin\lib\git-core\git-fetch-pack.exe
c:\cygwin\lib\git-core\git-fetch.exe
c:\cygwin\lib\git-core\git-fmt-merge-msg.exe
c:\cygwin\lib\git-core\git-for-each-ref.exe
c:\cygwin\lib\git-core\git-format-patch.exe
c:\cygwin\lib\git-core\git-fsck-objects.exe
c:\cygwin\lib\git-core\git-fsck.exe
c:\cygwin\lib\git-core\git-gc.exe
c:\cygwin\lib\git-core\git-get-tar-commit-id.exe
c:\cygwin\lib\git-core\git-grep.exe
c:\cygwin\lib\git-core\git-hash-object.exe
c:\cygwin\lib\git-core\git-help.exe
c:\cygwin\lib\git-core\git-index-pack.exe
c:\cygwin\lib\git-core\git-init-db.exe
c:\cygwin\lib\git-core\git-init.exe
c:\cygwin\lib\git-core\git-log.exe
c:\cygwin\lib\git-core\git-ls-files.exe
c:\cygwin\lib\git-core\git-ls-remote.exe
c:\cygwin\lib\git-core\git-ls-tree.exe
c:\cygwin\lib\git-core\git-mailinfo.exe
c:\cygwin\lib\git-core\git-mailsplit.exe
c:\cygwin\lib\git-core\git-merge-base.exe
c:\cygwin\lib\git-core\git-merge-file.exe
c:\cygwin\lib\git-core\git-merge-index.exe
c:\cygwin\lib\git-core\git-merge-ours.exe
c:\cygwin\lib\git-core\git-merge-recursive.exe
c:\cygwin\lib\git-core\git-merge-subtree.exe
c:\cygwin\lib\git-core\git-merge-tree.exe
c:\cygwin\lib\git-core\git-merge.exe
c:\cygwin\lib\git-core\git-mktag.exe
c:\cygwin\lib\git-core\git-mktree.exe
c:\cygwin\lib\git-core\git-mv.exe
c:\cygwin\lib\git-core\git-name-rev.exe
c:\cygwin\lib\git-core\git-pack-objects.exe
c:\cygwin\lib\git-core\git-pack-redundant.exe
c:\cygwin\lib\git-core\git-pack-refs.exe
c:\cygwin\lib\git-core\git-patch-id.exe
c:\cygwin\lib\git-core\git-peek-remote.exe
c:\cygwin\lib\git-core\git-prune-packed.exe
c:\cygwin\lib\git-core\git-prune.exe
c:\cygwin\lib\git-core\git-push.exe
c:\cygwin\lib\git-core\git-read-tree.exe
c:\cygwin\lib\git-core\git-receive-pack.exe
c:\cygwin\lib\git-core\git-reflog.exe
c:\cygwin\lib\git-core\git-remote.exe
c:\cygwin\lib\git-core\git-replace.exe
c:\cygwin\lib\git-core\git-repo-config.exe
c:\cygwin\lib\git-core\git-rerere.exe
c:\cygwin\lib\git-core\git-reset.exe
c:\cygwin\lib\git-core\git-rev-list.exe
c:\cygwin\lib\git-core\git-rev-parse.exe
c:\cygwin\lib\git-core\git-revert.exe
c:\cygwin\lib\git-core\git-rm.exe
c:\cygwin\lib\git-core\git-send-pack.exe
c:\cygwin\lib\git-core\git-shortlog.exe
c:\cygwin\lib\git-core\git-show-branch.exe
c:\cygwin\lib\git-core\git-show-ref.exe
c:\cygwin\lib\git-core\git-show.exe
c:\cygwin\lib\git-core\git-stage.exe
c:\cygwin\lib\git-core\git-status.exe
c:\cygwin\lib\git-core\git-stripspace.exe
c:\cygwin\lib\git-core\git-symbolic-ref.exe
c:\cygwin\lib\git-core\git-tag.exe
c:\cygwin\lib\git-core\git-tar-tree.exe
c:\cygwin\lib\git-core\git-unpack-file.exe
c:\cygwin\lib\git-core\git-unpack-objects.exe
c:\cygwin\lib\git-core\git-update-index.exe
c:\cygwin\lib\git-core\git-update-ref.exe
c:\cygwin\lib\git-core\git-update-server-info.exe
c:\cygwin\lib\git-core\git-upload-archive.exe
c:\cygwin\lib\git-core\git-var.exe
c:\cygwin\lib\git-core\git-verify-pack.exe
c:\cygwin\lib\git-core\git-verify-tag.exe
c:\cygwin\lib\git-core\git-whatchanged.exe
c:\cygwin\lib\git-core\git-write-tree.exe
c:\cygwin\lib\git-core\git.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-06-22 to 2012-07-22 )))))))))))))))))))))))))))))))
.
.
2012-07-22 01:02 . 2012-07-22 01:02 56200 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8ACFD315-1F02-4F41-B38E-0D9C8F750854}\offreg.dll
2012-07-22 01:00 . 2012-07-22 01:04 -------- d-----w- c:\users\colin\AppData\Local\temp
2012-07-22 01:00 . 2012-07-22 01:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-07-22 01:00 . 2012-07-22 01:00 -------- d-----w- c:\users\Wiz\AppData\Local\temp
2012-07-22 00:35 . 2012-07-15 16:41 6891424 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8ACFD315-1F02-4F41-B38E-0D9C8F750854}\mpengine.dll
2012-07-20 02:04 . 2012-07-20 02:04 -------- d-----w- C:\FRST
2012-07-19 02:01 . 2012-07-19 02:01 -------- d-----w- c:\windows\Microsoft Antimalware
2012-07-17 10:33 . 2012-02-09 04:17 713784 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9EE6C01A-A253-497E-9913-E9B118A81EAB}\gapaengine.dll
2012-07-17 10:32 . 2012-07-15 16:41 6891424 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-07-17 10:18 . 2012-07-17 10:18 -------- d-----w- c:\program files\Microsoft Security Client
2012-07-17 08:20 . 2012-02-29 15:09 157696 ----a-w- c:\windows\system32\imagehlp.dll
2012-07-17 08:20 . 2012-02-29 13:32 12800 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-07-17 07:53 . 2012-04-23 16:00 984064 ----a-w- c:\windows\system32\crypt32.dll
2012-07-16 10:13 . 2012-07-16 10:13 -------- d-sh--w- c:\windows\system32\%APPDATA%
2012-07-09 10:23 . 2012-07-17 10:15 -------- d-----w- C:\Downloads
2012-06-25 06:04 . 2012-06-25 06:04 1394248 ----a-w- c:\windows\system32\msxml4.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-12 09:26 . 2012-04-17 09:34 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-12 09:26 . 2011-06-07 09:27 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-13 13:40 . 2012-07-17 08:29 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-06-02 22:19 . 2012-06-21 07:18 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-21 07:18 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-21 07:17 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-21 07:17 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-21 07:18 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-06-21 07:18 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-06-21 07:17 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 08:25 . 2012-07-17 08:09 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-02 05:19 . 2012-06-21 07:17 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 05:12 . 2012-06-21 07:17 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-05-13 10:38 . 2009-08-18 01:30 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2012-05-13 10:37 . 2009-08-18 01:24 19352 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2009-10-07 09:12 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2009-10-07 09:12 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2009-10-07 09:12 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2009-10-07 09:12 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2009-10-07 09:12 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2009-10-07 09:12 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2009-10-07 09:12 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2009-10-07 09:12 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2009-10-07 09:12 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2010-12-21 1483264]
"Steam"="h:\program files\Steam\Steam.exe" [2011-10-02 1242448]
"KiesHelper"="c:\program files\Samsung\Kies\KiesHelper.exe" [2012-05-04 955792]
"KiesPDLR"="c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-05-04 21392]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-07-03 17417392]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [2012-05-14 6149120]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-04-18 159744]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-08-29 36864]
"Logitech Hardware Abstraction Layer"="c:\program files\Common Files\Logitech\khalshared\KHALMNPR.EXE" [2007-01-11 101136]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"PCMService"="c:\program files\CyberLink\PowerCinema\PCMService.exe" [2007-08-22 159744]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"VolPanel"="c:\program files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" [2006-11-26 180224]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-11 101136]
"RCApp"="c:\program files\gigabyte\RCApp\U7000RCApp.exe" [2007-04-24 625152]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-09-07 405504]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-15 13793824]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2009-06-15 92704]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-05-27 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-29 937920]
"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2012-05-04 3521424]
"PMBVolumeWatcher"="c:\program files\Sony\PMB\PMBVolumeWatcher.exe" [2010-05-31 600928]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
SetPoint.lnk - c:\program files\SetPoint\SetPoint.exe [2008-3-20 679936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-13 20:58 611712 ----a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DELL Webcam Manager]
2007-07-27 08:43 118784 ------w- c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter]
2007-05-25 06:03 17920 ----a-w- c:\dell\E-Center\EULALauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2009-11-13 11:31 247144 ----a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-17 09:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.google.com.au/
IE: Download all with Free Download Manager -
file://c:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager -
file://c:\program files\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager -
file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager -
file://c:\program files\Free Download Manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.253
DPF: Microsoft XML Parser for Java -
file:///C:/Windows/Java/classes/xmldso.cab
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-DellSupportCenter - c:\program files\Dell Support Center\bin\sprtcmd.exe
HKLM-Run-DellSupportCenter - c:\program files\Dell Support Center\bin\sprtcmd.exe
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-dscactivate - c:\program files\Dell Support Center\gs_agent\custom\dsca.exe
MSConfigStartUp-Google Desktop Search - c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
MSConfigStartUp-PC Suite Tray - c:\program files\Nokia\Nokia PC Suite 6\PCSuite.exe
AddRemove-SLABCOMM&10C4&EA60 - c:\program files\Silabs\MCU\DriverUninstall\DriverUninstaller.exe VCP CP210x Cardinal\SLABCOMM&10C4&EA60
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - c:\program files\Samsung\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - c:\program files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - c:\program files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - c:\program files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - c:\program files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-22_WiBro_WiMAX - c:\program files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe
.
.
.
**************************************************************************
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files:
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CLCapSvc]
"ImagePath"="\"c:\program files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe\"\00am Files\CyberLink\PowerCinema\Kernel\TV\CapSetup\00HLP\00\12\00½¶\06wT:¬\03"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(4480)
c:\program files\SetPoint\lgscroll.dll
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
c:\windows\system32\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\WLANExt.exe
c:\program files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
c:\program files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Dell Network Assistant\hnm_svc.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\program files\Sony\PMB\PMBDeviceInfoProvider.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\STacSV.exe
c:\program files\TomTom HOME 2\TomTomHOMEService.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
c:\windows\System32\rundll32.exe
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer.exe
c:\windows\ehome\ehmsas.exe
c:\program files\WIDCOMM\Bluetooth Software\BtStackServer.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\HidFind.exe
c:\program files\DellTPad\Apntex.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\msfeedssync.exe
.
**************************************************************************
.
Completion time: 2012-07-22 11:14:26 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-22 01:12
.
Pre-Run: 4,135,829,504 bytes free
Post-Run: 13,484,158,976 bytes free
.
- - End Of File - - 7B579C93852BE287DF62212106BAE017