Here is the combofix log
++++++++++++++++++++++++++++
ComboFix 12-08-30.05 - fgcue 08/31/2012 0:42.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2811.1340 [GMT -4:00]
Running from: c:\users\fgcue\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
c:\windows\SysWow64\FlashPlayerInstaller.exe
c:\windows\SysWow64\muzapp.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-07-28 to 2012-08-31 )))))))))))))))))))))))))))))))
.
.
2012-08-31 04:54 . 2012-08-31 04:54 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-31 04:03 . 2012-08-31 04:03 -------- d-----w- c:\users\fgcue\AppData\Local\Google
2012-08-31 04:03 . 2012-08-31 04:03 -------- d-----w- c:\program files (x86)\Google
2012-08-31 04:03 . 2012-08-21 09:13 359464 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-08-31 04:03 . 2012-08-21 09:13 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-08-31 04:03 . 2012-08-21 09:13 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-08-31 04:03 . 2012-08-21 09:13 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-08-31 04:03 . 2012-08-21 09:13 969200 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-31 04:03 . 2012-08-21 09:13 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-08-31 04:03 . 2012-08-21 09:12 285328 ----a-w- c:\windows\system32\aswBoot.exe
2012-08-31 04:03 . 2012-08-21 09:12 41224 ----a-w- c:\windows\avastSS.scr
2012-08-31 04:03 . 2012-08-21 09:12 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe
2012-08-31 04:02 . 2012-08-31 04:02 -------- d-----w- c:\programdata\AVAST Software
2012-08-31 04:02 . 2012-08-31 04:02 -------- d-----w- c:\program files\AVAST Software
2012-08-31 02:54 . 2012-08-31 02:54 -------- d-----w- c:\users\fgcue\AppData\Roaming\Malwarebytes
2012-08-31 02:54 . 2012-08-31 02:54 -------- d-----w- c:\programdata\Malwarebytes
2012-08-31 02:54 . 2012-08-31 02:54 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-08-31 02:54 . 2012-07-03 17:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-30 21:23 . 2012-08-28 05:49 9310152 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BC46D4C1-B995-43DC-A422-2253A9EC2899}\mpengine.dll
2012-08-30 04:51 . 2012-08-30 04:51 -------- d-----w- c:\program files (x86)\ESET
2012-08-30 04:03 . 2012-08-30 08:13 -------- d-----w- c:\users\fgcue\AppData\Local\{986322B5-F257-11E1-8270-B8AC6F996F26}
2012-08-29 05:31 . 2012-08-29 05:31 -------- d-----w- c:\program files\Common Files\CANON
2012-08-29 05:28 . 2012-08-29 05:28 -------- d-----w- c:\program files\Canon
2012-08-29 05:27 . 2012-08-29 05:27 -------- d--h--w- c:\programdata\CanonBJ
2012-08-29 05:26 . 2012-08-29 05:26 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
2012-08-29 05:21 . 2012-08-30 08:13 -------- d-----w- c:\program files (x86)\Canon
2012-08-29 05:08 . 2012-08-30 08:13 -------- d-----w- c:\program files (x86)\Coupons
2012-08-29 02:27 . 2012-08-30 22:30 -------- d-----w- c:\users\fgcue\AppData\Local\Cyberlink
2012-08-27 20:17 . 2012-08-29 02:27 -------- d-----w- c:\users\fgcue\AppData\Roaming\CyberLink
2012-08-16 07:05 . 2012-06-29 03:49 1392128 ----a-w- c:\windows\system32\wininet.dll
2012-08-15 23:43 . 2012-05-05 08:36 503808 ----a-w- c:\windows\system32\srcore.dll
2012-08-15 23:43 . 2012-05-05 07:46 43008 ----a-w- c:\windows\SysWow64\srclient.dll
2012-08-15 23:43 . 2012-02-11 06:43 751104 ----a-w- c:\windows\system32\win32spl.dll
2012-08-15 23:43 . 2012-02-11 06:36 559104 ----a-w- c:\windows\system32\spoolsv.exe
2012-08-15 23:43 . 2012-02-11 06:36 67072 ----a-w- c:\windows\splwow64.exe
2012-08-15 23:43 . 2012-02-11 05:43 492032 ----a-w- c:\windows\SysWow64\win32spl.dll
2012-08-15 23:43 . 2012-07-04 22:13 59392 ----a-w- c:\windows\system32\browcli.dll
2012-08-15 23:43 . 2012-07-04 22:13 136704 ----a-w- c:\windows\system32\browser.dll
2012-08-15 23:43 . 2012-07-04 22:16 73216 ----a-w- c:\windows\system32\netapi32.dll
2012-08-15 23:43 . 2012-07-04 21:14 41984 ----a-w- c:\windows\SysWow64\browcli.dll
2012-08-15 23:43 . 2012-07-18 18:15 3148800 ----a-w- c:\windows\system32\win32k.sys
2012-08-15 23:43 . 2012-05-14 05:26 956928 ----a-w- c:\windows\system32\localspl.dll
2012-08-09 21:09 . 2012-08-09 21:09 -------- d-----w- c:\users\fgcue\AppData\Roaming\WinBatch
2012-08-06 22:09 . 2012-08-06 22:09 -------- d-----w- C:\Temp
2012-08-06 22:04 . 2011-04-28 09:09 88520 ----a-w- c:\windows\system32\drivers\ssudbus.sys
2012-08-06 22:04 . 2011-04-28 09:09 203080 ----a-w- c:\windows\system32\drivers\ssudmdm.sys
2012-08-06 21:44 . 2012-08-06 21:44 -------- d-----w- c:\users\fgcue\AppData\Local\Samsung
2012-08-06 21:44 . 2012-08-06 21:44 -------- d-----w- c:\users\fgcue\AppData\Roaming\Samsung
2012-08-06 21:29 . 2012-06-26 20:03 4659712 ----a-w- c:\windows\SysWow64\Redemption.dll
2012-08-06 21:28 . 2012-08-06 21:28 -------- d-----w- c:\program files (x86)\MarkAny
2012-08-06 21:28 . 2012-06-26 20:02 821824 ----a-w- c:\windows\SysWow64\dgderapi.dll
2012-08-06 21:28 . 2012-08-06 22:04 -------- d-----w- c:\program files (x86)\Samsung
2012-08-06 21:13 . 2012-08-06 21:13 -------- d-----w- c:\users\fgcue\AppData\Local\Downloaded Installations
2012-08-06 03:52 . 2012-08-06 03:52 -------- d-----w- c:\program files\SAMSUNG
2012-08-06 03:49 . 2012-08-06 21:28 -------- d-----w- c:\programdata\Samsung
2012-08-06 02:20 . 2012-08-06 02:20 -------- d-----w- c:\users\fgcue\AppData\Local\DDMSettings
2012-08-02 17:19 . 2012-08-06 02:16 -------- d-----w- c:\programdata\VirtualizedApplications
2012-08-02 15:08 . 2012-08-03 20:45 -------- d-----w- c:\users\fgcue\AppData\Roaming\SoftGrid Client
2012-08-02 15:08 . 2012-08-02 15:08 -------- d-----w- c:\users\fgcue\AppData\Local\SoftGrid Client
2012-08-02 15:07 . 2012-08-02 15:07 -------- d-----w- c:\program files\Microsoft Office
2012-08-02 15:07 . 2012-08-03 01:50 -------- d-----w- c:\program files (x86)\Microsoft Application Virtualization Client
2012-08-02 15:07 . 2012-08-02 15:08 -------- d-----w- c:\users\fgcue\AppData\Roaming\TP
2012-08-01 11:18 . 2012-08-01 11:18 -------- d-----w- c:\users\Public\Recorded TV
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-16 07:00 . 2012-07-26 15:10 62134624 ----a-w- c:\windows\system32\MRT.exe
2012-08-16 01:17 . 2012-07-26 16:37 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-16 01:17 . 2012-07-26 16:37 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-28 21:26 . 2012-07-28 21:28 2048104 ----a-w- c:\windows\system32\RtPgEx64.dll
2012-07-28 21:26 . 2012-07-28 21:28 1146984 ----a-w- c:\windows\system32\RTSnMg64.cpl
2012-07-28 21:26 . 2012-07-28 21:28 332392 ----a-w- c:\windows\system32\RtlCPAPI64.dll
2012-07-28 21:26 . 2012-07-28 21:28 2625640 ----a-w- c:\windows\system32\RtkAPO64.dll
2012-07-28 21:26 . 2012-07-28 21:28 2494056 ----a-w- c:\windows\system32\drivers\RTKVHD64.sys
2012-07-28 21:26 . 2012-07-28 21:28 149608 ----a-w- c:\windows\system32\RtkCfg64.dll
2012-07-28 21:26 . 2012-07-28 21:28 569960 ----a-w- c:\windows\system32\RtkApi64.dll
2012-07-28 21:26 . 2012-07-28 21:28 80488 ----a-w- c:\windows\system32\RCoInst64.dll
2012-07-28 21:26 . 2012-07-28 21:28 1215592 ----a-w- c:\windows\system32\RTCOM64.dll
2012-07-28 21:26 . 2012-07-28 21:28 200800 ----a-w- c:\windows\system32\AERTAC64.dll
2012-07-28 21:26 . 2012-07-26 07:38 1251944 ----a-w- c:\windows\RtlExUpd.dll
2012-07-27 01:37 . 2012-07-27 01:37 955888 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-07-27 01:37 . 2012-07-27 01:37 268784 ----a-w- c:\windows\system32\javaws.exe
2012-07-27 01:37 . 2012-07-27 01:37 189424 ----a-w- c:\windows\system32\javaw.exe
2012-07-27 01:37 . 2012-07-27 01:37 188912 ----a-w- c:\windows\system32\java.exe
2012-07-27 01:37 . 2010-07-11 05:29 839152 ----a-w- c:\windows\system32\deployJava1.dll
2012-07-27 01:35 . 2012-07-26 17:07 772592 ----a-w- c:\windows\SysWow64\npdeployJava1.dll
2012-07-27 01:35 . 2010-07-11 05:29 687600 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-07-27 01:02 . 2012-07-27 01:02 737072 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2012-07-27 01:01 . 2012-07-27 01:01 4283672 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2012-07-27 01:01 . 2012-07-27 01:01 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2012-07-27 01:01 . 2012-07-27 01:01 539984 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2012-07-26 18:05 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-07-26 18:05 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-07-26 15:15 . 2012-07-26 15:15 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-07-26 15:15 . 2012-07-26 15:15 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-07-26 15:15 . 2012-07-26 15:15 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-07-26 15:15 . 2012-07-26 15:15 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-07-26 15:15 . 2012-07-26 15:15 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-07-26 15:15 . 2012-07-26 15:15 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-07-26 15:15 . 2012-07-26 15:15 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-07-26 15:15 . 2012-07-26 15:15 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-07-26 15:15 . 2012-07-26 15:15 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2012-07-26 15:15 . 2012-07-26 15:15 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-07-26 15:15 . 2012-07-26 15:15 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-07-26 15:15 . 2012-07-26 15:15 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-07-26 15:15 . 2012-07-26 15:15 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-07-26 15:15 . 2012-07-26 15:15 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-07-26 15:15 . 2012-07-26 15:15 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-07-26 15:15 . 2012-07-26 15:15 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-07-26 15:15 . 2012-07-26 15:15 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-07-26 15:15 . 2012-07-26 15:15 222208 ----a-w- c:\windows\system32\msls31.dll
2012-07-26 15:15 . 2012-07-26 15:15 197120 ----a-w- c:\windows\system32\msrating.dll
2012-07-26 15:15 . 2012-07-26 15:15 149504 ----a-w- c:\windows\system32\occache.dll
2012-07-26 15:15 . 2012-07-26 15:15 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-07-26 15:15 . 2012-07-26 15:15 89088 ----a-w- c:\windows\system32\ie4uinit.exe
2012-07-26 15:15 . 2012-07-26 15:15 82432 ----a-w- c:\windows\system32\icardie.dll
2012-07-26 15:15 . 2012-07-26 15:15 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-07-26 15:15 . 2012-07-26 15:15 65024 ----a-w- c:\windows\system32\pngfilt.dll
2012-07-26 15:15 . 2012-07-26 15:15 55296 ----a-w- c:\windows\system32\msfeedsbs.dll
2012-07-26 15:15 . 2012-07-26 15:15 534528 ----a-w- c:\windows\system32\ieapfltr.dll
2012-07-26 15:15 . 2012-07-26 15:15 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-07-26 15:15 . 2012-07-26 15:15 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-07-26 15:15 . 2012-07-26 15:15 452608 ----a-w- c:\windows\system32\dxtmsft.dll
2012-07-26 15:15 . 2012-07-26 15:15 448512 ----a-w- c:\windows\system32\html.iec
2012-07-26 15:15 . 2012-07-26 15:15 39936 ----a-w- c:\windows\system32\iernonce.dll
2012-07-26 15:15 . 2012-07-26 15:15 3695416 ----a-w- c:\windows\system32\ieapfltr.dat
2012-07-26 15:15 . 2012-07-26 15:15 282112 ----a-w- c:\windows\system32\dxtrans.dll
2012-07-26 15:15 . 2012-07-26 15:15 267776 ----a-w- c:\windows\system32\ieaksie.dll
2012-07-26 15:15 . 2012-07-26 15:15 163840 ----a-w- c:\windows\system32\ieakui.dll
2012-07-26 15:15 . 2012-07-26 15:15 160256 ----a-w- c:\windows\system32\ieakeng.dll
2012-07-26 15:15 . 2012-07-26 15:15 145920 ----a-w- c:\windows\system32\iepeers.dll
2012-07-26 15:15 . 2012-07-26 15:15 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-07-26 15:15 . 2012-07-26 15:15 12288 ----a-w- c:\windows\system32\mshta.exe
2012-07-26 15:15 . 2012-07-26 15:15 114176 ----a-w- c:\windows\system32\admparse.dll
2012-07-26 15:15 . 2012-07-26 15:15 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-07-26 15:15 . 2012-07-26 15:15 10752 ----a-w- c:\windows\system32\msfeedssync.exe
2012-07-26 15:15 . 2012-07-26 15:15 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-07-26 15:15 . 2012-07-26 15:15 697344 ----a-w- c:\windows\system32\msfeeds.dll
2012-07-26 15:15 . 2012-07-26 15:15 603648 ----a-w- c:\windows\system32\vbscript.dll
2012-07-26 15:15 . 2012-07-26 15:15 403248 ----a-w- c:\windows\system32\iedkcs32.dll
2012-07-26 15:15 . 2012-07-26 15:15 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-07-26 15:15 . 2012-07-26 15:15 249344 ----a-w- c:\windows\system32\webcheck.dll
2012-07-26 15:15 . 2012-07-26 15:15 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-07-26 15:15 . 2012-07-26 15:15 160256 ----a-w- c:\windows\system32\wextract.exe
2012-07-26 15:15 . 2012-07-26 15:15 103936 ----a-w- c:\windows\system32\inseng.dll
2012-07-26 07:51 . 2012-07-26 07:51 29480 ----a-w- c:\windows\SysWow64\msxml3a.dll
2012-07-26 07:51 . 2003-03-19 03:14 505128 ----a-w- c:\windows\SysWow64\msvcp71.dll
2012-07-26 07:51 . 2003-02-21 11:42 353576 ----a-w- c:\windows\SysWow64\msvcr71.dll
2012-06-26 20:02 . 2012-06-26 20:02 90112 ----a-w- c:\windows\MAMCityDownload.ocx
2012-06-26 20:02 . 2012-06-26 20:02 330240 ----a-w- c:\windows\MASetupCaller.dll
2012-06-26 20:02 . 2012-06-26 20:02 30568 ----a-w- c:\windows\MusiccityDownload.exe
2012-06-26 20:02 . 2012-06-26 20:02 974848 ----a-w- c:\windows\SysWow64\cis-2.4.dll
2012-06-26 20:02 . 2012-06-26 20:02 81920 ----a-w- c:\windows\SysWow64\issacapi_bs-2.3.dll
2012-06-26 20:02 . 2012-06-26 20:02 65536 ----a-w- c:\windows\SysWow64\issacapi_pe-2.3.dll
2012-06-26 20:02 . 2012-06-26 20:02 57344 ----a-w- c:\windows\SysWow64\MTXSYNCICON.dll
2012-06-26 20:02 . 2012-06-26 20:02 57344 ----a-w- c:\windows\SysWow64\MK_Lyric.dll
2012-06-26 20:02 . 2012-06-26 20:02 57344 ----a-w- c:\windows\SysWow64\issacapi_se-2.3.dll
2012-06-26 20:02 . 2012-06-26 20:02 569344 ----a-w- c:\windows\SysWow64\muzdecode.ax
2012-06-26 20:02 . 2012-06-26 20:02 491520 ----a-w- c:\windows\SysWow64\muzapp.dll
2012-06-26 20:02 . 2012-06-26 20:02 49152 ----a-w- c:\windows\SysWow64\MaJGUILib.dll
2012-06-26 20:02 . 2012-06-26 20:02 45320 ----a-w- c:\windows\SysWow64\MAMACExtract.dll
2012-06-26 20:02 . 2012-06-26 20:02 45056 ----a-w- c:\windows\SysWow64\MaXMLProto.dll
2012-06-26 20:02 . 2012-06-26 20:02 45056 ----a-w- c:\windows\SysWow64\MACXMLProto.dll
2012-06-26 20:02 . 2012-06-26 20:02 40960 ----a-w- c:\windows\SysWow64\MTTELECHIP.dll
2012-06-26 20:02 . 2012-06-26 20:02 352256 ----a-w- c:\windows\SysWow64\MSLUR71.dll
2012-06-26 20:02 . 2012-06-26 20:02 258048 ----a-w- c:\windows\SysWow64\muzoggsp.ax
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2010-05-19 2736128]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-07-16 975800]
"KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-07-16 21432]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-06-17 98304]
"BingDesktop"="c:\program files (x86)\Microsoft\BingDesktop\BingDesktop.exe" [2012-03-30 1858152]
"Sprint SmartView"="c:\program files (x86)\Sprint\Sprint SmartView\SprintSV.exe" [2010-05-25 75072]
"RDVCHG"="c:\program files (x86)\Sprint\Sprint SmartView\RDVCHG.exe" [2010-05-25 316736]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2010-11-09 586296]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-07-16 3524536]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-31 136176]
R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-09 86072]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-06-18 103992]
R2 RtVOsdService;RtVOsdService Installer;c:\program files\Realtek\RtVOsd\RtVOsdService.exe [2010-06-24 315392]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-16 250056]
R3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe [2012-02-10 240408]
R3 CASprint;Sprint Con App Svc;c:\program files (x86)\Sprint\Sprint SmartView\ConAppsSvc.exe [2010-05-25 124224]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2011-04-28 88520]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-31 136176]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-14 113120]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 PCTINDIS5X64;PCTINDIS5X64 NDIS Protocol Driver;c:\windows\system32\PCTINDIS5X64.SYS [2010-05-25 43032]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-05-07 245792]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2011-04-28 203080]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-07-26 1255736]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-06-10 389120]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-09-20 203264]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-08-21 71600]
S2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe [2012-02-10 193816]
S2 BingDesktopUpdate;Bing Desktop Update service;c:\program files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [2012-03-30 151656]
S2 CinemaNow Service;CinemaNow Service;c:\program files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe [2010-05-21 140272]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-28 94264]
S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-11-09 26680]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
S2 NvtlService;NovaCore SDK Service;c:\program files (x86)\Novatel Wireless\Novacore\Server\NvtlSrvr.exe [2010-01-11 82944]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-09-20 7767552]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-09-20 279040]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - ASWSNX
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-05-19 17:36 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-26 01:17]
.
2012-08-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-31 04:03]
.
2012-08-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-31 04:03]
.
2012-08-30 c:\windows\Tasks\HPCeeScheduleForfgcue.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 02:15]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-08-21 09:11 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-07-28 6489704]
"HPWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe" [2010-06-18 8192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
FF - ProfilePath - c:\users\fgcue\AppData\Roaming\Mozilla\Firefox\Profiles\j85m6kuf.default\
FF - prefs.js: browser.startup.homepage - about:home|hxxp://
www.tvguide.com/ipad/new-tonight/80001/|http://www.eatdrinkdeals.com/|http://slickdeals.net/
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-KiesAirMessage - c:\program files (x86)\Samsung\Kies\KiesAirMessage.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-{6F44AF95-3CDE-4513-AD3F-6D45F17BF324} - c:\program files (x86)\InstallShield Installation Information\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}\setup.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\atibtmon.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
.
**************************************************************************
.
Completion time: 2012-08-31 01:02:35 - machine was rebooted
ComboFix-quarantined-files.txt 2012-08-31 05:02
.
Pre-Run: 219,973,509,120 bytes free
Post-Run: 219,687,137,280 bytes free
.
- - End Of File - - 28DD14E1C0216F5EDE2AC9BCC1B373FF