ComboFix 13-01-17.04 - Kate 19/01/2013 1:37.1.2 - x86 MINIMAL
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.2942.2451 [GMT 0:00]
Running from: F:\ComboFix.exe
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
D:\install.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-12-19 to 2013-01-19 )))))))))))))))))))))))))))))))
.
.
2013-01-19 06:27 . 2013-01-19 06:27--------d-----w-C:\FRST
2013-01-19 00:46 . 2008-05-08 05:03303616----a-w-C:\SetACL.exe
2013-01-19 00:29 . 2004-06-11 23:33290304----a-w-C:\subinacl.exe
2013-01-19 00:03 . 2013-01-19 00:57--------d-----w-C:\Tweaking.com_Windows_Repair_Logs
2013-01-19 00:03 . 2013-01-19 00:03--------d-----w-c:\program files\Tweaking.com
2013-01-18 21:23 . 2013-01-18 21:23--------d-----w-c:\users\Kate\AppData\Roaming\Malwarebytes
2013-01-18 21:23 . 2013-01-18 21:23--------d-----w-c:\programdata\Malwarebytes
2013-01-18 21:23 . 2012-12-14 16:4921104----a-w-c:\windows\system32\drivers\mbam.sys
2013-01-18 21:23 . 2013-01-18 21:23--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2013-01-18 21:23 . 2013-01-18 21:23--------d-----w-c:\users\Kate\AppData\Local\Programs
2013-01-09 17:53 . 2013-01-09 17:59--------d-----w-c:\users\Kate\AppData\Local\Microsoft Games
2012-12-21 16:39 . 2012-12-16 14:13295424----a-w-c:\windows\system32\atmfd.dll
2012-12-21 16:39 . 2012-12-16 14:1334304----a-w-c:\windows\system32\atmlib.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-14 19:50 . 2012-05-04 07:04697272----a-w-c:\windows\system32\FlashPlayerApp.exe
2012-12-14 19:50 . 2011-09-15 17:5773656----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
2012-11-22 02:56 . 2012-12-12 19:382345984----a-w-c:\windows\system32\win32k.sys
2012-11-12 11:52 . 2012-12-12 19:361638912----a-w-c:\windows\system32\mshtml.tlb
2012-11-09 06:56 . 2011-06-09 17:3960480----a-w-c:\windows\system32\drivers\cfwids.sys
2012-11-09 06:53 . 2011-06-09 17:39210136----a-w-c:\windows\system32\drivers\mfewfpk.sys
2012-11-09 06:53 . 2011-06-09 17:29167344----a-w-c:\windows\system32\mfevtps.exe
2012-11-09 06:52 . 2011-06-09 17:409648----a-w-c:\windows\system32\drivers\mfeclnk.sys
2012-11-09 06:52 . 2011-06-09 17:3992192----a-w-c:\windows\system32\drivers\mferkdet.sys
2012-11-09 06:51 . 2011-03-13 10:20565352----a-w-c:\windows\system32\drivers\mfehidk.sys
2012-11-09 06:50 . 2011-06-09 17:39362640----a-w-c:\windows\system32\drivers\mfefirek.sys
2012-11-09 06:50 . 2011-06-09 17:3965488----a-w-c:\windows\system32\drivers\mfebopk.sys
2012-11-09 06:49 . 2011-06-09 17:39234824----a-w-c:\windows\system32\drivers\mfeavfk.sys
2012-11-09 06:49 . 2011-03-13 10:20132912----a-w-c:\windows\system32\drivers\mfeapfk.sys
2012-11-09 04:42 . 2012-12-12 19:362048----a-w-c:\windows\system32\tzres.dll
2012-11-02 05:11 . 2012-12-12 19:37376832----a-w-c:\windows\system32\dpnet.dll
2012-10-27 06:26 . 2012-12-12 19:36981504----a-w-c:\windows\system32\wininet.dll
2012-10-22 16:30 . 2012-10-22 16:30163056----a-w-c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10142.bin
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{7473b6bd-4691-4744-a82b-7854eb3d70b6}"= "c:\program files\uTorrentControl_v2\prxtbuTor.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7473b6bd-4691-4744-a82b-7854eb3d70b6}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4DB74D06-491C-440D-305E-012400990F3E}]
2009-07-14 01:1573728----a-w-c:\windows\System32\coomcat.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7473b6bd-4691-4744-a82b-7854eb3d70b6}]
2011-05-09 09:49176936----a-w-c:\program files\uTorrentControl_v2\prxtbuTor.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7473b6bd-4691-4744-a82b-7854eb3d70b6}"= "c:\program files\uTorrentControl_v2\prxtbuTor.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7473b6bd-4691-4744-a82b-7854eb3d70b6}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{7473B6BD-4691-4744-A82B-7854EB3D70B6}"= "c:\program files\uTorrentControl_v2\prxtbuTor.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7473b6bd-4691-4744-a82b-7854eb3d70b6}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MobileDocuments"="c:\program files\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="OLOGIES\ATI.ACE\CORE-STATIC\CLISTART.EXE MSRUN" [X]
"TWebCamera"="\TWEBCAMERA.EXE AUTORUN" [X]
"mcui_exe"="KEY" [X]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Toshiba TEMPRO"="c:\program files\Toshiba TEMPRO\TemproTray.exe" [2009-08-06 1050000]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2009-07-09 352256]
"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2009-06-02 425984]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2009-08-13 521528]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-28 7625248]
"SmartFaceVWatcher"="c:\program files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [2009-07-29 163840]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-03 611672]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-12-14 512360]
"Z1"="c:\users\Kate\Desktop\mbar\mbar.exe" [2013-01-09 1356360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2009-08-12 6203296]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [x]
R2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [x]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [x]
R2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [x]
R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [x]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [x]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [x]
R2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files\Toshiba TEMPRO\TemproSvc.exe [x]
R3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\DRIVERS\BthAvrcp.sys [x]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x]
R3 HipShieldK;McAfee Inc. HipShieldK;c:\windows\system32\drivers\HipShieldK.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x]
R3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-01-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-04 19:50]
.
2013-01-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-29 11:31]
.
2013-01-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-29 11:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.wp.pl/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.254
DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D} - hxxp://assets.photobox.com/assets/v/ra3RgI_VSoCPalw7aL2ig_0fSS8.cab
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-TosNC - CCORE.EXE
HKLM-Run-TosReelTimeMonitor - ITOR.EXE
HKLM-Run-KeNotify - OTIFY.EXE
HKLM-Run-TPwrMain - .EXE
HKLM-Run-00TCrdMain - .EXE
HKLM-Run-SynTPEnh - H.EXE
HKLM-Run-ToshibaServiceStation - .EXE
HKLM-Run-Toshiba Registration - DER.EXE
HKLM-Run-AppleSyncNotifier - OTIFIER.EXE
HKLM-Run-WinampAgent - AMPA.EXE
HKLM-Run-APSDaemon - .EXE
HKLM-Run-iTunesHelper - ESHELPER.EXE
HKLM-RunOnce-Malwarebytes Anti-Malware (cleanup) - c:\users\Kate\AppData\Local\Temp\Rar$EX00.703\mbar\Data\cleanup.dll
AddRemove-Bloxxit - d:\gry\Bloxit\uninstal.exe
.
.
.
Completion time: 2013-01-19 01:46:46
ComboFix-quarantined-files.txt 2013-01-19 01:46
.
Pre-Run: 120,858,779,648 bytes free
Post-Run: 121,645,056,000 bytes free
.
- - End Of File - - E1FC386E1E7AC62A97C389E2E8F93DDC