ComboFix 12-10-08.03 - Family 10/08/2012 17:41:22.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2663.1318 [GMT -7:00]
Running from: c:\users\Family\Desktop\ComboFix.exe
AV: Norton Internet Security *Disabled/Outdated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Disabled/Outdated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\c052e1523d8c5aff82c3c9b0b31d8616_c
c:\users\Public\DynamicInstaller.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-09-09 to 2012-10-09 )))))))))))))))))))))))))))))))
.
.
2012-10-09 01:00 . 2012-10-09 01:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-10-09 01:00 . 2012-10-09 01:00 -------- d-----w- c:\users\Guest.FamilyLaptop\AppData\Local\temp
2012-10-09 01:00 . 2012-10-09 01:00 -------- d-----w- c:\users\Guest\AppData\Local\temp
2012-10-08 22:32 . 2012-10-08 22:32 -------- d-----w- c:\users\Family\AppData\Roaming\Malwarebytes
2012-10-08 22:32 . 2012-10-08 22:32 -------- d-----w- c:\programdata\Malwarebytes
2012-10-08 22:32 . 2012-10-08 22:32 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-10-08 22:32 . 2012-09-08 00:04 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-10-08 18:20 . 2012-10-08 18:20 -------- d-----w- c:\program files (x86)\Siber Systems
2012-10-08 18:19 . 2012-08-21 09:13 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-10-08 18:19 . 2012-08-21 09:13 359464 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-10-08 18:19 . 2012-08-21 09:13 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-10-08 18:19 . 2012-08-21 09:13 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-10-08 18:19 . 2012-08-21 09:13 969200 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-10-08 18:18 . 2012-08-21 09:13 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-10-08 18:18 . 2012-08-21 09:12 41224 ----a-w- c:\windows\avastSS.scr
2012-10-08 18:18 . 2012-08-21 09:12 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe
2012-10-08 17:50 . 2012-10-08 17:51 -------- d-----w- c:\windows\system32\drivers\NISx64\1309000.009
2012-10-08 17:24 . 2012-10-08 17:24 -------- d-----w- C:\TDSSKiller_Quarantine
2012-10-08 04:52 . 2012-10-08 04:52 -------- d-----w- C:\FRST
2012-09-30 19:01 . 2012-09-30 19:01 -------- d-----w- c:\windows\system32\%LOCALAPPDATA%
2012-09-26 15:55 . 2012-09-26 15:55 -------- d-----w- c:\users\Guest.FamilyLaptop\AppData\Roaming\WindSolutions
2012-09-25 12:07 . 2012-09-25 12:07 -------- d-----w- c:\users\Family\AppData\Roaming\Unity
2012-09-20 13:45 . 2012-09-30 14:18 -------- d-----w- c:\users\Family\AppData\Local\Unity
2012-09-20 13:45 . 2012-09-20 13:45 -------- d-----w- c:\users\Family\AppData\Local\Apps
2012-09-20 13:45 . 2012-09-20 13:45 -------- d-----w- c:\users\Family\AppData\Local\Deployment
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-27 20:34 . 2012-08-27 20:34 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-08-27 20:33 . 2012-08-27 20:35 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-08-22 01:48 . 2012-08-22 01:48 0 ----a-w- c:\windows\SysWow64\sho8353.tmp
2012-08-21 09:12 . 2012-06-30 21:33 285328 ----a-w- c:\windows\system32\aswBoot.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{553318DA-D010-469E-84B1-496563CAE1BF}]
2012-02-02 01:18 136192 ----a-w- c:\program files (x86)\HTTO Group, Ltd\FBDownloader IE Add-on\FBDownloader.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-06-08 336384]
"ITSecMng"="c:\program files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2011-04-02 80840]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2011-07-12 1298816]
"NortonOnlineBackupReminder"="c:\program files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe" [2011-06-22 3218864]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-01-17 421736]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728]
.
c:\users\Guest.FamilyLaptop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
IMVU.lnk - c:\users\Family\AppData\Roaming\IMVUClient\IMVUQualityAgent.exe [N/A]
.
c:\users\Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
fliptoast.lnk - c:\program files (x86)\fliptoast\fliptoast.exe [N/A]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.1.121\SSScheduler.exe [2010-9-2 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
SetupExecute REG_MULTI_SZ c:\windows\System32\poqexec.exe /display_progress \SystemRoot\WinSxS\pending.xml
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp