ComboFix 12-07-04.04 - Spencer 07/04/2012 22:29:12.4.6 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.8191.6249 [GMT -4:00]
Running from: c:\users\Spencer\Desktop\ComboFix.exe
Command switches used :: c:\users\Spencer\Desktop\CFScript.txt
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
--------------- FCopy ---------------
.
c:\windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16937_none_34154fcd77f3bbda\afd.sys --> c:\windows\System32\drivers\afd.sys
c:\windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16986_none_0f140fa780164fde\tcpip.sys --> c:\windows\System32\Drivers\tcpip.sys
c:\windows\winsxs\amd64_networking-mpssvc-svc_31bf3856ad364e35_6.1.7600.16385_none_f6092d1fe18dc440\MPSSVC.dll --> c:\windows\System32\mpssvc.dll
c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7600.17008_none_d24deecfb43ce339\cryptsvc.dll --> c:\windows\System32\cryptsvc.dll
.
((((((((((((((((((((((((( Files Created from 2012-06-05 to 2012-07-05 )))))))))))))))))))))))))))))))
.
.
2012-07-05 02:32 . 2012-07-05 02:32--------d-----w-c:\users\Default\AppData\Local\temp
2012-07-05 02:29 . 2012-03-30 11:091895280----a-w-c:\windows\SysWow64\drivers\tcpip.sys
2012-07-05 02:29 . 2011-12-28 03:59499200----a-w-c:\windows\SysWow64\drivers\afd.sys
2012-07-05 02:29 . 2009-07-14 01:41824832----a-w-c:\windows\SysWow64\mpssvc.dll
2012-07-04 20:38 . 2012-07-04 20:38--------d-----w-c:\programdata\Nexon
2012-07-03 22:07 . 2012-07-03 22:07--------d-----w-c:\users\Spencer\AppData\Local\Movie_Fone
2012-07-03 01:40 . 2012-07-03 01:40--------d-----w-c:\program files (x86)\ESET
2012-07-02 10:25 . 2012-07-02 10:26--------d-----w-C:\FRST
2012-07-02 09:41 . 2009-07-14 01:39328704----a-w-c:\windows\SysWow64\services.exe
2012-07-02 07:57 . 2012-07-02 07:57--------d-----w-c:\users\Spencer\AppData\Local\Futuremark_Corporation
2012-07-02 07:54 . 2012-07-02 07:54--------d-----w-c:\program files (x86)\Common Files\Futuremark Shared
2012-06-29 22:05 . 2012-06-29 22:05--------d-----w-c:\users\Spencer\AppData\Local\PreEmptive Solutions
2012-06-29 22:01 . 2012-06-29 22:15--------d-----w-c:\users\Spencer\AppData\Local\Gapotchenko
2012-06-29 05:32 . 2012-06-29 05:32--------d-----w-c:\users\Spencer\AppData\Roaming\Awesomium
2012-06-29 01:38 . 2012-06-29 01:38--------d-----w-c:\users\Spencer\AppData\Local\SCE
2012-06-29 01:38 . 2012-06-29 01:38--------d-----w-C:\Crash
2012-06-23 03:57 . 2007-03-20 16:3343520----a-w-c:\windows\SysWow64\libusb0.dll
2012-06-21 21:01 . 2012-06-02 22:192428952----a-w-c:\windows\system32\wuaueng.dll
2012-06-21 21:01 . 2012-06-02 22:1957880----a-w-c:\windows\system32\wuauclt.exe
2012-06-21 21:01 . 2012-06-02 22:1944056----a-w-c:\windows\system32\wups2.dll
2012-06-21 21:01 . 2012-06-02 22:152622464----a-w-c:\windows\system32\wucltux.dll
2012-06-21 21:01 . 2012-06-02 22:1938424----a-w-c:\windows\system32\wups.dll
2012-06-21 21:01 . 2012-06-02 22:19701976----a-w-c:\windows\system32\wuapi.dll
2012-06-21 21:01 . 2012-06-02 22:1599840----a-w-c:\windows\system32\wudriver.dll
2012-06-21 21:01 . 2012-06-02 19:19186752----a-w-c:\windows\system32\wuwebv.dll
2012-06-21 21:01 . 2012-06-02 19:1536864----a-w-c:\windows\system32\wuapp.exe
2012-06-20 05:33 . 2012-06-20 05:33--------d-----w-c:\users\Spencer\AppData\Local\NuGet
2012-06-20 05:32 . 2012-06-20 05:32--------d-----w-c:\users\Spencer\AppData\Roaming\NuGet
2012-06-19 07:51 . 2012-06-19 07:51--------d--h--w-c:\programdata\Common Files
2012-06-19 07:43 . 2012-06-19 07:43--------d-----w-c:\users\Spencer\AppData\Local\Macromedia
2012-06-18 22:44 . 2012-06-18 22:44--------d-----w-c:\users\Spencer\AppData\Local\Funcom
2012-06-18 20:40 . 2012-06-18 20:40275360----a-w-c:\windows\system32\DreamScene.dll
2012-06-18 20:40 . 2012-06-18 20:40--------d-----w-c:\windows\system32\WDSA
2012-06-15 07:55 . 2012-06-15 07:55--------d-----w-c:\programdata\NVIDIA
2012-06-13 22:04 . 2012-04-26 05:3476288----a-w-c:\windows\system32\rdpwsx.dll
2012-06-13 22:04 . 2012-04-26 05:34149504----a-w-c:\windows\system32\rdpcorekmts.dll
2012-06-13 22:04 . 2012-04-26 05:289216----a-w-c:\windows\system32\rdrmemptylst.exe
2012-06-13 22:04 . 2012-05-02 05:32208896----a-w-c:\windows\system32\profsvc.dll
2012-06-13 22:04 . 2012-05-04 10:525505392----a-w-c:\windows\system32\ntoskrnl.exe
2012-06-13 22:04 . 2012-05-04 10:083958128----a-w-c:\windows\SysWow64\ntkrnlpa.exe
2012-06-13 22:04 . 2012-05-04 10:083902320----a-w-c:\windows\SysWow64\ntoskrnl.exe
2012-06-13 22:04 . 2012-05-15 01:323144192----a-w-c:\windows\system32\win32k.sys
2012-06-13 22:04 . 2012-04-28 03:50204800----a-w-c:\windows\system32\drivers\rdpwd.sys
2012-06-13 22:03 . 2012-04-07 12:183213824----a-w-c:\windows\system32\msi.dll
2012-06-13 22:03 . 2012-04-07 11:342342400----a-w-c:\windows\SysWow64\msi.dll
2012-06-13 22:03 . 2012-04-24 05:591460224----a-w-c:\windows\system32\crypt32.dll
2012-06-13 22:03 . 2012-04-24 05:59182272----a-w-c:\windows\system32\cryptsvc.dll
2012-06-13 22:03 . 2012-04-24 05:59140288----a-w-c:\windows\system32\cryptnet.dll
2012-06-13 22:03 . 2012-04-24 04:471156608----a-w-c:\windows\SysWow64\crypt32.dll
2012-06-13 22:03 . 2012-04-24 05:59182272----a-w-c:\windows\SysWow64\cryptsvc.dll
2012-06-13 22:03 . 2012-04-24 04:47103936----a-w-c:\windows\SysWow64\cryptnet.dll
2012-06-08 02:03 . 2012-06-08 02:03--------d-----w-c:\users\Spencer\AppData\Local\ESN Sonar
2012-06-06 07:00 . 2012-06-06 07:00--------d-----w-c:\program files (x86)\Common Files\PX Storage Engine
2012-06-06 06:40 . 2011-03-30 20:2698304----a-w-c:\program files (x86)\Windows Media Player\wmp.dll
2012-06-06 06:40 . 2012-06-06 06:40--------d-----w-c:\program files (x86)\Windows Media Player Plus!
2012-06-05 06:27 . 2012-06-05 06:27--------d-----w-c:\programdata\ATI
2012-06-05 06:26 . 2012-06-05 06:26--------d-----w-c:\program files (x86)\AMD AVT
2012-06-05 06:26 . 2012-06-05 06:26--------d-----w-c:\program files (x86)\AMD APP
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-29 05:32 . 2012-01-20 22:45283312----a-w-c:\windows\SysWow64\PnkBstrB.xtr
2012-06-29 05:32 . 2012-01-20 22:40283312----a-w-c:\windows\SysWow64\PnkBstrB.exe
2012-06-29 01:40 . 2012-01-20 22:40282512----a-w-c:\windows\SysWow64\PnkBstrB.ex0
2012-06-29 01:39 . 2012-01-20 22:4076888----a-w-c:\windows\SysWow64\PnkBstrA.exe
2012-06-24 23:10 . 2012-04-06 01:11276504----a-w-c:\windows\SysWow64\atiglpxx.dll
2012-06-24 23:10 . 2012-04-06 01:11359960----a-w-c:\windows\system32\atig6pxx.dll
2012-06-24 23:10 . 2012-02-15 03:18197656----a-w-c:\windows\SysWow64\aticfx32.dll
2012-06-24 23:10 . 2011-12-06 03:16344088----a-w-c:\windows\system32\aticfx64.dll
2012-06-12 19:59 . 2012-04-04 00:26426184----a-w-c:\windows\SysWow64\FlashPlayerApp.exe
2012-06-12 19:59 . 2012-01-21 06:1470344----a-w-c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-09 19:49 . 2012-02-05 06:05314392----a-w-c:\windows\system32\EvoDisplayHelper.dll
2012-06-09 19:49 . 2012-02-05 06:05197144----a-w-c:\windows\SysWow64\EvoDisplayHelper.dll
2012-05-29 02:06 . 2012-02-13 04:33466456----a-w-c:\windows\system32\wrap_oal.dll
2012-05-29 02:06 . 2012-02-13 04:33444952----a-w-c:\windows\SysWow64\wrap_oal.dll
2012-05-29 02:06 . 2012-02-13 04:33122904----a-w-c:\windows\system32\OpenAL32.dll
2012-05-29 02:06 . 2012-02-13 04:33109080----a-w-c:\windows\SysWow64\OpenAL32.dll
2012-05-02 04:49 . 2012-05-02 04:492337865----a-w-c:\windows\SysWow64\pbsvc.exe
2012-04-22 21:54 . 2012-04-22 21:54374792----a-w-c:\windows\system32\drivers\UMDF\lgSSQVGA.dll
2012-04-22 21:54 . 2012-04-22 21:54157704----a-w-c:\windows\system32\drivers\UMDF\lgSSBW.dll
2012-04-14 07:38 . 2012-04-04 00:368741536----a-w-c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-06 05:22 . 2012-04-06 05:2211174400----a-w-c:\windows\system32\drivers\atikmdag.sys
2012-04-06 02:34 . 2012-04-06 02:34187392----a-w-c:\windows\system32\clinfo.exe
2012-04-06 02:34 . 2012-04-06 02:3474752----a-w-c:\windows\system32\OpenVideo64.dll
2012-04-06 02:34 . 2012-04-06 02:3464512----a-w-c:\windows\SysWow64\OpenVideo.dll
2012-04-06 02:33 . 2012-04-06 02:3363488----a-w-c:\windows\system32\OVDecode64.dll
2012-04-06 02:33 . 2012-04-06 02:3356320----a-w-c:\windows\SysWow64\OVDecode.dll
2012-04-06 02:33 . 2012-04-06 02:3316457216----a-w-c:\windows\system32\amdocl64.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-07-03_01.31.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-01-20 21:52 . 2012-07-04 17:2557968 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-07-04 17:4528110 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:30 . 2012-06-09 05:4986016 c:\windows\system32\DriverStore\infpub.dat
+ 2009-07-14 05:30 . 2012-07-05 00:4486016 c:\windows\system32\DriverStore\infpub.dat
+ 2012-01-20 23:15 . 2012-07-04 20:2932768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-01-20 23:15 . 2012-07-03 01:1732768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-01-20 23:15 . 2012-07-04 20:2932768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2012-01-20 23:15 . 2012-07-03 01:1732768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-07-03 01:1716384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2012-07-04 20:2916384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-20 21:22 . 2012-07-04 17:457498 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-297926242-239688007-3628787549-1000_UserData.bin
- 2012-07-03 01:31 . 2012-07-03 01:312048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-07-05 02:33 . 2012-07-05 02:332048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:36 . 2012-07-04 17:49275554 c:\windows\system32\perfc009.dat
+ 2009-07-14 05:30 . 2012-07-05 00:44143360 c:\windows\system32\DriverStore\infstrng.dat
- 2009-07-14 05:30 . 2012-06-09 05:49143360 c:\windows\system32\DriverStore\infstrng.dat
- 2009-07-14 05:01 . 2012-07-03 01:30273332 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-07-05 02:32273332 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 02:36 . 2012-07-04 17:491109902 c:\windows\system32\perfh009.dat
- 2012-02-10 05:00 . 2012-07-03 01:301274720 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2012-02-10 05:00 . 2012-07-04 17:431274720 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2012-02-05 09:20 . 2012-07-05 02:322846880 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-297926242-239688007-3628787549-1000-12288.dat
- 2009-07-14 02:34 . 2012-07-02 17:5910485760 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2012-07-04 17:3610485760 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2012-01-20 21:19 . 2012-07-05 02:3220426639 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-297926242-239688007-3628787549-1000-8192.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:5894208----a-w-c:\users\Spencer\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:5894208----a-w-c:\users\Spencer\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:5894208----a-w-c:\users\Spencer\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EvolveClient"="d:\program files\Echobit\Evolve\EvolveClient.exe" [2012-06-24 2466840]
"Steam"="d:\program files (x86)\Steam\steam.exe" [2012-05-04 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"Six Engine"="c:\program files (x86)\ASUS\EPU\EPU.exe" [2010-06-14 5309056]
"Razer Mamba Elite Driver"="c:\program files (x86)\Razer\Mamba\RazerMambaSysTray.exe" [2011-11-25 973720]
"QFan Help"="c:\program files (x86)\ASUS\AI Suite\QFan4\FanHelp.exe" [2010-03-25 888960]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-22 1675160]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-04-06 641664]
"amd_dc_opt"="d:\program files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
.
c:\users\Spencer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Spencer\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security PackagesREG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-03-05 53888]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 MBAMService;MBAMService;d:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 EvoSvc;Evolve Service;d:\program files\Echobit\Evolve\EvoSvc.exe [2012-06-24 1511448]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2010-12-14 128928]
R3 IDVistaService;Input Director Vista Service;d:\program files (x86)\Input Director\IDVistaService.exe [2009-02-08 13824]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-04-04 24904]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-02-22 100912]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\Drivers\nx6000.sys [2010-12-13 36720]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-08-02 51712]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-22 1255736]
R4 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
R4 AdvancedSystemCareService5;Advanced SystemCare Service 5;d:\program files (x86)\IObit\Advanced SystemCare 5\ASCService.exe [2011-12-30 497496]
R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-04-06 236544]
R4 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-04-06 361984]
R4 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-12-28 96896]
R4 HiPatchService;Hi-Rez Studios Authenticate and Update Service;d:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [x]
R4 hshld;Hotspot Shield Service;d:\program files (x86)\Hotspot Shield\bin\openvpnas.exe [2012-03-26 542040]
R4 HssWd;Hotspot Shield Monitoring Service;d:\program files (x86)\Hotspot Shield\bin\hsswd.exe [2012-03-26 329544]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]
R4 NETGEARGenieDaemon;NETGEARGenieDaemon;d:\program files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [2011-10-24 1370400]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656]
R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-01-31 158856]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
R4 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-03-19 2666880]
S0 McPvDrv;McPvDrv Driver;c:\windows\system32\drivers\McPvDrv.sys [2011-04-11 71800]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-02-22 289664]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2012-02-22 75936]
S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-03-05 53888]
S2 InputDirector;Input Director Service;d:\program files (x86)\Input Director\IDWinService.exe [2010-02-01 36864]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-03-20 210584]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-03-20 162192]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-04-06 11174400]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-04-06 343040]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2012-02-22 65264]
S3 EvoKbFilter;Evolve Keyboard Filter Driver;c:\windows\system32\Drivers\EvoKbFilter.sys [2012-02-05 27800]
S3 EvolveVirtualAdapter;Evolve Virtual Miniport Driver;c:\windows\system32\DRIVERS\evolve.sys [2012-02-05 21656]
S3 EvoMouFilter;Evolve Mouse Filter Driver;c:\windows\system32\Drivers\EvoMouFilter.sys [2012-02-05 24216]
S3 LADF_CaptureOnly;LADF Capture Filter Driver;c:\windows\system32\DRIVERS\ladfGSCamd64.sys [2011-04-11 410184]
S3 LADF_RenderOnly;LADF Render Filter Driver;c:\windows\system32\DRIVERS\ladfGSRamd64.sys [2011-04-11 341832]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-23 22408]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-23 16008]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2012-02-22 487296]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-04-27 83080]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-04-27 184968]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-06-23 344680]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2008-05-06 14464]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-05 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-297926242-239688007-3628787549-1000Core.job
- c:\users\Spencer\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-22 00:02]
.
2012-07-05 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-297926242-239688007-3628787549-1000UA.job
- c:\users\Spencer\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-22 00:02]
.
2012-07-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-297926242-239688007-3628787549-1000Core.job
- c:\users\Spencer\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-20 20:25]
.
2012-07-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-297926242-239688007-3628787549-1000UA.job
- c:\users\Spencer\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-20 20:25]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:5897792----a-w-c:\users\Spencer\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:5897792----a-w-c:\users\Spencer\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:5897792----a-w-c:\users\Spencer\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:5897792----a-w-c:\users\Spencer\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-12-07 5889816]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-06 11057768]
"McPvTray_exe"="c:\program files\McAfee\MAT\McPvTray.exe" [2011-04-08 436384]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.babylon.com/?AF=110788&tt=290312_bexdll&babsrc=HP_ss&mntrId=da23b6450000000000000000b6bb57a8
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 10.0.0.1
FF - ProfilePath - c:\users\Spencer\AppData\Roaming\Mozilla\Firefox\Profiles\n580dgpp.default\
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=110788
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - da23b6450000000000000000b6bb57a8
FF - user.js: extensions.BabylonToolbar_i.hardId - da23b6450000000000000000b6bb57a8
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15431
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1723:01
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
d:\program files (x86)\Input Director\InputDirectorSessionHelper.exe
c:\windows\SysWOW64\rundll32.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\ASUS\GPU Boost Driver\GpuBoostServer.exe
.
**************************************************************************
.
Completion time: 2012-07-04 22:34:55 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-05 02:34
ComboFix2.txt 2012-07-02 09:49
.
Pre-Run: 12,711,514,112 bytes free
Post-Run: 13,405,831,168 bytes free
.
- - End Of File - - A85AB5BEC3F2B467E1B1335AA9DFF197
I could not find the file
"c:\combofix\CF32693.3XE" [2009-07-14 344576]v\
that you mentioned, or even a combofix directory.