ComboFix 12-08-15.01 - Rickyfk 15/08/2012 19:33:41.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.2.1033.18.8090.4318 [GMT -4:00]
Running from: C:\Users\Rickyfk\Downloads\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\ProgramData\PCDr\5907\Downloads\f0fc9c9c-10ba-435b-8365-dadb523644ff.dll
C:\Users\Rickyfk\AppData\Roaming\Rickyfklog.dat
C:\WinDir
C:\Windows\RPSETUP.EXE.LOG
((((((((((((((((((((((((( Files Created from 2012-07-15 to 2012-08-15 )))))))))))))))))))))))))))))))
2012-08-15 23:38:24 . 2012-08-15 23:38:24 -------- d-----w- C:\Users\Default\AppData\Local\temp
2012-08-15 09:34:01 . 2012-08-15 09:35:31 -------- d-----w- C:\Program Files (x86)\SpeedFan
2012-08-15 06:53:47 . 2012-08-15 06:53:47 -------- d-----w- C:\Program Files (x86)\Trend Micro
2012-08-15 06:53:23 . 2012-08-15 06:53:23 -------- d-----w- C:\ProgramData\Malwarebytes
2012-08-15 06:53:22 . 2012-07-03 17:46:44 24904 ----a-w- C:\Windows\system32\drivers\mbam.sys
2012-08-15 06:53:21 . 2012-08-15 06:53:26 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-08-15 06:28:40 . 2012-02-11 06:43:47 751104 ----a-w- C:\Windows\system32\win32spl.dll
2012-08-15 06:28:40 . 2012-02-11 06:36:02 559104 ----a-w- C:\Windows\system32\spoolsv.exe
2012-08-15 06:28:40 . 2012-02-11 06:36:01 67072 ----a-w- C:\Windows\splwow64.exe
2012-08-15 06:28:40 . 2012-02-11 05:43:49 492032 ----a-w- C:\Windows\SysWow64\win32spl.dll
2012-08-15 06:28:39 . 2012-05-05 08:36:55 503808 ----a-w- C:\Windows\system32\srcore.dll
2012-08-15 06:28:38 . 2012-07-04 22:13:27 59392 ----a-w- C:\Windows\system32\browcli.dll
2012-08-15 06:28:38 . 2012-07-04 22:13:27 136704 ----a-w- C:\Windows\system32\browser.dll
2012-08-15 06:28:38 . 2012-05-05 07:46:52 43008 ----a-w- C:\Windows\SysWow64\srclient.dll
2012-08-15 06:28:37 . 2012-07-18 18:15:06 3148800 ----a-w- C:\Windows\system32\win32k.sys
2012-08-15 06:28:37 . 2012-07-04 22:16:43 73216 ----a-w- C:\Windows\system32\netapi32.dll
2012-08-15 06:28:37 . 2012-07-04 21:14:34 41984 ----a-w- C:\Windows\SysWow64\browcli.dll
2012-08-15 06:28:36 . 2012-05-14 05:26:34 956928 ----a-w- C:\Windows\system32\localspl.dll
2012-08-15 03:55:14 . 2012-08-15 03:58:46 -------- d-----w- C:\ProgramData\TrackMania
2012-08-14 23:42:23 . 2012-08-14 23:42:23 -------- d-----w- C:\Program Files (x86)\Xiph.Org
2012-08-14 23:42:10 . 2012-08-14 23:42:10 -------- d-----w- C:\Program Files (x86)\Red 5 Studios
2012-08-14 23:16:02 . 2012-08-14 23:16:02 -------- dc----w- C:\Windows\system32\DRVSTORE
2012-08-14 23:16:02 . 2009-05-18 17:17:08 34152 ----a-w- C:\Windows\system32\drivers\GEARAspiWDM.sys
2012-08-14 23:16:02 . 2008-04-17 16:12:54 126312 ----a-w- C:\Windows\system32\GEARAspi64.dll
2012-08-14 23:16:02 . 2008-04-17 16:12:54 107368 ----a-w- C:\Windows\SysWow64\GEARAspi.dll
2012-08-14 23:15:13 . 2012-08-14 23:16:00 -------- d-----w- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2012-08-14 23:15:13 . 2012-08-14 23:15:59 -------- d-----w- C:\Program Files\iTunes
2012-08-14 23:15:13 . 2012-08-14 23:15:59 -------- d-----w- C:\Program Files (x86)\iTunes
2012-08-14 23:15:13 . 2012-08-14 23:15:13 -------- d-----w- C:\ProgramData\Apple Computer
2012-08-14 23:15:13 . 2012-08-14 23:15:13 -------- d-----w- C:\Program Files\iPod
2012-08-14 23:14:34 . 2012-08-14 23:14:35 -------- d-----w- C:\Program Files (x86)\Apple Software Update
2012-08-14 23:14:20 . 2012-08-14 23:14:20 -------- d-----w- C:\Program Files\Common Files\Apple
2012-08-14 23:14:09 . 2012-08-14 23:14:10 -------- d-----w- C:\Program Files\Bonjour
2012-08-14 23:14:09 . 2012-08-14 23:14:10 -------- d-----w- C:\Program Files (x86)\Bonjour
2012-08-14 23:14:02 . 2012-08-14 23:15:13 -------- d-----w- C:\Program Files (x86)\Common Files\Apple
2012-08-14 23:14:02 . 2012-08-14 23:14:26 -------- d-----w- C:\ProgramData\Apple
2012-08-13 00:23:36 . 2012-08-13 00:23:36 -------- d-----w- C:\ProgramData\Dell
2012-08-13 00:23:19 . 2012-08-13 00:23:36 -------- d-----w- C:\Program Files (x86)\Common Files\Nero
2012-08-13 00:23:13 . 2012-08-13 00:23:54 -------- d-----w- C:\Program Files (x86)\Nero
2012-08-13 00:23:06 . 2012-08-13 00:23:56 -------- d-----w- C:\ProgramData\Nero
2012-08-11 02:45:14 . 2009-03-18 21:35:42 33856 ---ha-w- C:\Windows\system32\hamachi.sys
2012-08-10 23:37:28 . 2012-08-10 23:37:28 -------- d-----w- C:\Windows\DEA314C409294250BC9298E4C105F28D.TMP
2012-08-10 20:59:05 . 2012-08-10 20:59:05 -------- d-sh--w- C:\ProgramData\SecuROM
2012-08-10 20:57:58 . 2012-08-10 20:57:58 178800 ----a-w- C:\Windows\SysWow64\CmdLineExt_x64.dll
2012-08-10 16:50:15 . 2012-08-10 16:50:15 -------- d-----w- C:\Windows\SysWow64\xlive
2012-08-10 16:50:11 . 2012-08-10 16:50:15 -------- d-----w- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2012-08-10 10:22:27 . 2012-08-10 10:22:27 -------- d-----w- C:\Windows\SysWow64\searchplugins
2012-08-10 10:22:27 . 2012-08-10 10:22:27 -------- d-----w- C:\Windows\SysWow64\Extensions
2012-08-10 07:00:27 . 2012-08-10 07:00:27 -------- d-----w- C:\Program Files\VS Revo Group
2012-08-10 03:34:10 . 2012-08-10 08:12:40 283312 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2012-08-10 03:27:45 . 2012-08-10 08:12:40 283312 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2012-08-10 03:27:45 . 2012-08-10 08:07:52 283312 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2012-08-10 03:27:44 . 2012-08-10 07:54:13 76888 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2012-08-10 03:27:44 . 2012-08-10 03:15:49 3360624 ----a-w- C:\Windows\SysWow64\pbsvc.exe
2012-08-10 03:14:14 . 2012-08-10 03:14:14 -------- d-----w- C:\ProgramData\Browser Manager
2012-08-10 03:14:12 . 2012-08-10 03:14:12 315 ----a-w- C:\user.js
2012-08-10 00:12:58 . 2012-08-13 05:30:46 -------- d-----w- C:\Program Files\Core Temp
2012-08-09 17:35:13 . 2012-08-09 17:35:13 -------- d-----w- C:\Program Files\Microsoft Silverlight
2012-08-09 17:35:13 . 2012-08-09 17:35:13 -------- d-----w- C:\Program Files (x86)\Microsoft Silverlight
2012-08-09 17:03:36 . 2012-08-09 17:03:36 -------- d-----w- C:\Program Files\Windows Live
2012-08-09 17:03:14 . 2012-08-09 17:04:23 -------- d-----w- C:\Program Files (x86)\Windows Live
2012-08-09 17:02:30 . 2012-08-09 17:02:30 -------- d-----w- C:\Program Files (x86)\Microsoft SkyDrive
2012-08-09 17:02:26 . 2012-08-09 17:02:26 -------- d-----w- C:\ProgramData\Microsoft SkyDrive
2012-08-09 16:59:12 . 2012-08-09 16:59:12 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2012-08-09 16:16:10 . 2012-08-09 16:18:13 -------- d-----w- C:\Program Files (x86)\mIRC
2012-08-08 21:52:18 . 2012-08-08 21:52:26 -------- d-----w- C:\ProgramData\WebcamMax
2012-08-08 21:51:27 . 2012-08-08 21:51:30 -------- d-----w- C:\Program Files (x86)\WebcamMax
2012-08-08 21:44:21 . 2012-08-08 21:44:47 -------- d-----w- C:\ProgramData\WinZip
2012-08-08 21:27:06 . 2012-08-08 21:27:06 -------- d-----w- C:\Program Files (x86)\LogMeIn Hamachi
2012-08-08 20:58:35 . 2012-08-15 19:37:11 -------- d-----w- C:\Program Files (x86)\Steam
2012-08-08 20:37:51 . 2012-08-08 20:37:51 -------- d-----w- C:\Program Files\Ventrilo
2012-08-08 19:46:17 . 2008-10-15 10:22:52 519000 ----a-w- C:\Windows\system32\d3dx10_40.dll
2012-08-08 19:46:17 . 2008-10-15 10:22:52 452440 ----a-w- C:\Windows\SysWow64\d3dx10_40.dll
2012-08-08 19:46:17 . 2008-10-15 10:22:52 2605920 ----a-w- C:\Windows\system32\D3DCompiler_40.dll
2012-08-08 19:46:17 . 2008-10-15 10:22:52 2036576 ----a-w- C:\Windows\SysWow64\D3DCompiler_40.dll
2012-08-08 19:46:16 . 2008-10-15 10:22:52 5631312 ----a-w- C:\Windows\system32\D3DX9_40.dll
2012-08-08 19:46:16 . 2008-10-15 10:22:52 4379984 ----a-w- C:\Windows\SysWow64\D3DX9_40.dll
2012-08-08 19:44:03 . 2012-08-08 19:44:03 -------- d-----w- C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP
2012-08-08 19:43:39 . 2012-08-10 23:37:15 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2012-08-08 19:04:09 . 2012-08-14 23:04:10 9232584 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2012-08-08 18:47:33 . 2012-08-08 18:47:33 -------- d-----w- C:\ProgramData\Alienware
2012-08-08 18:34:27 . 2012-08-08 18:34:29 -------- d-----w- C:\Program Files (x86)\Guild Wars 2
2012-08-08 18:01:10 . 2012-05-04 11:00:43 366592 ----a-w- C:\Windows\system32\qdvd.dll
2012-08-08 18:01:10 . 2012-05-04 09:59:54 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
2012-08-08 17:57:38 . 2012-08-08 17:57:38 -------- d-----w- C:\Windows\PCHEALTH
2012-08-08 17:56:32 . 2012-08-08 17:56:32 -------- d-----w- C:\Program Files\Microsoft Office
2012-08-08 17:56:27 . 2012-08-08 17:56:27 -------- d-----w- C:\Program Files (x86)\Microsoft Analysis Services
2012-08-08 17:56:05 . 2012-08-15 06:31:00 -------- d-----w- C:\ProgramData\Microsoft Help
2012-08-08 17:55:55 . 2012-08-08 17:55:55 -------- d-----r- C:\MSOCache
2012-08-08 17:45:36 . 2011-10-20 09:20:00 837952 ----a-w- C:\Windows\system32\easyupdatusapiu64.dll
2012-08-08 17:45:02 . 2011-07-07 20:21:32 29288 ----a-w- C:\Windows\system32\nvhdap64.dll
2012-08-08 17:45:02 . 2011-07-07 20:21:28 174184 ----a-w- C:\Windows\system32\drivers\nvhda64v.sys
2012-08-08 17:45:02 . 2011-07-07 20:21:26 1452648 ----a-w- C:\Windows\system32\nvhdagenco6420102.dll
2012-08-08 17:42:01 . 2012-08-08 17:42:01 -------- d-----w- C:\Windows\system32\2C0A
2012-08-08 17:41:58 . 2012-08-08 17:41:58 -------- d-----w- C:\Program Files (x86)\Renesas Electronics
2012-08-08 17:41:10 . 2012-08-08 17:41:10 -------- d-----w- C:\Dell
2012-08-08 17:32:05 . 2012-08-08 17:32:05 -------- d-----w- C:\Windows\SysWow64\Wat
2012-08-08 17:32:05 . 2012-08-08 17:32:05 -------- d-----w- C:\Windows\system32\Wat
2012-08-08 17:28:37 . 2012-08-08 17:28:37 -------- d-----w- C:\Program Files (x86)\Dell
2012-08-08 17:28:36 . 2012-08-08 17:28:36 -------- d-----w- C:\Windows\SysWow64\Dell
2012-08-08 17:19:40 . 2012-08-15 06:28:55 62134624 ----a-w- C:\Windows\system32\MRT.exe
2012-08-08 17:17:19 . 2012-08-08 17:17:19 -------- d-----w- C:\Program Files (x86)\Common Files\Skype
2012-08-08 17:17:19 . 2012-08-08 17:17:19 -------- d-----r- C:\Program Files (x86)\Skype
2012-08-08 17:16:24 . 2012-08-08 17:16:24 -------- d-----w- C:\Program Files (x86)\Common Files\Java
2012-08-08 17:16:03 . 2012-08-08 17:16:03 -------- d-----w- C:\Program Files (x86)\Oracle
2012-08-08 17:15:54 . 2012-08-08 17:15:43 772592 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2012-08-08 17:15:54 . 2012-07-06 02:06:20 687544 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-08-08 17:15:42 . 2012-08-08 17:15:42 -------- d-----w- C:\Program Files (x86)\Java
2012-08-08 17:13:09 . 2012-08-08 17:17:26 -------- d-----w- C:\ProgramData\Skype
2012-08-08 17:09:59 . 2012-05-01 05:40:20 209920 ----a-w- C:\Windows\system32\profsvc.dll
2012-08-08 17:08:54 . 2012-04-28 03:55:21 210944 ----a-w- C:\Windows\system32\drivers\rdpwd.sys
2012-08-08 17:08:52 . 2011-02-23 04:55:04 90624 ----a-w- C:\Windows\system32\drivers\bowser.sys
2012-08-08 17:05:59 . 2008-10-27 14:04:16 25936 ----a-w- C:\Windows\system32\X3DAudio1_5.dll
2012-08-08 17:03:30 . 2012-08-14 23:42:17 -------- d--h--w- C:\Windows\msdownld.tmp
2012-08-08 17:03:25 . 2012-08-08 17:03:25 -------- d-----w- C:\Games
2012-08-08 17:01:31 . 2012-08-08 18:39:23 -------- d-----w- C:\Program Files\AlienAutopsy
2012-08-08 17:00:34 . 2012-08-08 17:00:35 -------- d-----w- C:\Program Files (x86)\Mozilla Maintenance Service
2012-08-08 16:57:45 . 2012-08-12 23:35:43 -------- d-----w- C:\ProgramData\PCDr
2012-08-08 16:44:36 . 2012-06-02 22:19:43 2428952 ----a-w- C:\Windows\system32\wuaueng.dll
2012-08-08 16:44:36 . 2012-06-02 22:19:42 57880 ----a-w- C:\Windows\system32\wuauclt.exe
2012-08-08 16:44:36 . 2012-06-02 22:19:42 44056 ----a-w- C:\Windows\system32\wups2.dll
2012-08-08 16:44:36 . 2012-06-02 22:15:31 2622464 ----a-w- C:\Windows\system32\wucltux.dll
2012-08-08 16:44:32 . 2012-06-02 22:19:46 38424 ----a-w- C:\Windows\system32\wups.dll
2012-08-08 16:44:31 . 2012-06-02 22:19:23 701976 ----a-w- C:\Windows\system32\wuapi.dll
2012-08-08 16:44:31 . 2012-06-02 22:15:08 99840 ----a-w- C:\Windows\system32\wudriver.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2012-08-02 14:14:18 . 2012-08-02 14:14:18 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2012-08-02 14:14:16 . 2012-08-02 14:14:16 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2012-08-02 14:14:16 . 2012-08-02 14:14:16 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2012-06-18 21:07:12 . 2012-06-18 21:07:12 21360 ----a-w- C:\Windows\SysWow64\LightFXConfigurator32.dll
2012-06-18 21:07:08 . 2012-06-18 21:07:08 22384 ----a-w- C:\Windows\SysWow64\LightFX.dll
2012-06-18 21:07:00 . 2012-06-18 21:07:00 23408 ----a-w- C:\Windows\system32\LightFXConfigurator64.dll
2012-06-18 21:06:56 . 2012-06-18 21:06:56 23408 ----a-w- C:\Windows\system32\LightFX.dll
2012-06-18 20:41:38 . 2012-06-18 20:41:38 15728 ----a-w- C:\Windows\SysWow64\alienfusionapi.dll
2012-06-06 12:49:52 . 2012-06-06 12:49:52 1070152 ----a-w- C:\Windows\SysWow64\MSCOMCTL.OCX
2012-05-30 17:10:50 . 2012-05-30 17:10:50 16168 ----a-w- C:\Windows\system32\drivers\TurboB.sys
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
[-] 2012-07-04 22:13:27 . 05F5A0D14A2EE1D8255C2AA0E9E8E694 . 136704 . . [6.1.7601.17887 (win7sp1_gdr.120704-0720)] .. C:\Windows\winsxs\amd64_microsoft-windows-browserservice_31bf3856ad364e35_6.1.7601.17887_none_d6c68344b4d406bf\browser.dll
[-] 2012-07-04 22:06:49 . 156768ABAE1DAF29BA0B0C05C21FEF09 . 136704 . . [6.1.7601.22044 (win7sp1_ldr.120704-0720)] .. C:\Windows\winsxs\amd64_microsoft-windows-browserservice_31bf3856ad364e35_6.1.7601.22044_none_d7783703cdd41e02\browser.dll
[7] 2010-11-21 03:24:16 . 8EF0D5C41EC907751B8429162B1239ED . 136192 . . [6.1.7601.17514 (win7sp1_rtm.101119-1850)] .. C:\Windows\winsxs\amd64_microsoft-windows-browserservice_31bf3856ad364e35_6.1.7601.17514_none_d70f2c28b49dffae\browser.dll
[-] 2012-07-04 22:13:27 . 05F5A0D14A2EE1D8255C2AA0E9E8E694 . 136704 . . [6.1.7600.16385 (win7_rtm.090713-1255)] .. C:\Windows\system32\browser.dll
[-] 2012-02-11 06:36:02 . 85DAA09A98C9286D4EA2BA8D0E644377 . 559104 . . [6.1.7600.16385 (win7_rtm.090713-1255)] .. C:\Windows\winsxs\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.1.7601.17777_none_3433cdb2d8563d50\spoolsv.exe
[-] 2012-02-11 06:20:28 . B9D7A4858CF32A6A15D2763F1DE47E0E . 559616 . . [6.1.7600.16385 (win7_rtm.090713-1255)] .. C:\Windows\winsxs\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.1.7601.21921_none_34ed7a43f150b682\spoolsv.exe
[7] 2010-11-21 03:24:27 . B96C17B5DC1424D56EEA3A99E97428CD . 559104 . . [6.1.7600.16385 (win7_rtm.090713-1255)] .. C:\Windows\winsxs\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.1.7601.17514_none_3471a890d8284f57\spoolsv.exe
[-] 2012-02-11 06:36:02 . 85DAA09A98C9286D4EA2BA8D0E644377 . 559104 . . [6.1.7600.16385 (win7_rtm.090713-1255)] .. C:\Windows\system32\spoolsv.exe
[7] 2012-08-02 14:14:24 . D785A16A6F03F76CB862F28C9F8C9672 . 17790976 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16443_none_87cdb199f4dba857\mshtml.dll
[7] 2012-08-02 14:14:24 . 97BB8C752A400556A4FF2E1AAFA0A138 . 17790976 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20548_none_885c4fd70df4c6d4\mshtml.dll
[7] 2012-08-02 14:04:05 . 82682BA2DF50B94CD798B8315B3F7896 . 17773056 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16421_none_87e150ddf4cd3dc7\mshtml.dll
[-] 2012-06-29 04:55:23 . 8415F4792D7BC07BE328DF56FE32045A . 17809920 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16448_none_87d2b30bf4d7270a\mshtml.dll
[-] 2012-06-29 02:39:19 . C4DE0E2B31F60ACB15E6B4154E26298A . 17809920 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20554_none_884d7ec30e007d69\mshtml.dll
[7] 2012-06-02 12:49:39 . 89C4B3BF66D3C2F3D83F9DEDF1B218D6 . 17807360 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16447_none_87d1b2c1f4d80db3\mshtml.dll
[7] 2012-06-02 11:45:43 . 0C26F50D6C347CE294C84347E6FAEAA8 . 17807360 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20553_none_884c7e790e016412\mshtml.dll
[7] 2010-11-21 03:24:42 . 1C8B787BAA52DEAD1A6FEC1502D652F0 . 8988160 . . [8.00.7601.17514 (win7sp1_rtm.101119-1850)] .. C:\Windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.7601.17514_none_8c235f42afcafdda\mshtml.dll
[-] 2012-06-29 04:55:23 . 8415F4792D7BC07BE328DF56FE32045A . 17809920 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\system32\mshtml.dll
[7] 2012-08-02 14:14:24 . 228443FF3A1FB0B974D278F7C6403FAD . 1390080 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\amd64_microsoft-windows-I..tocolimplementation_31bf3856ad364e35_9.4.8112.16443_none_7673927b74853f21\wininet.dll
[7] 2012-08-02 14:14:24 . B70CDC073F70E6D082A62AB5880D6B07 . 1390080 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\amd64_microsoft-windows-I..tocolimplementation_31bf3856ad364e35_9.4.8112.20548_none_770230b88d9e5d9e\wininet.dll
[7] 2012-08-02 14:04:05 . 1BF2BCC7E3C26FD4C8EF0C9EFB0CC25D . 1389056 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\amd64_microsoft-windows-I..tocolimplementation_31bf3856ad364e35_9.4.8112.16421_none_768731bf7476d491\wininet.dll
[-] 2012-06-29 03:49:11 . 8EA68FD3780DDDD5072F8CB830B3CB3D . 1392128 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\amd64_microsoft-windows-I..tocolimplementation_31bf3856ad364e35_9.4.8112.16448_none_767893ed7480bdd4\wininet.dll
[-] 2012-06-29 01:51:43 . 8BA7EDA2656ED7FBC93BDD5CB02B8D4E . 1392128 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\amd64_microsoft-windows-I..tocolimplementation_31bf3856ad364e35_9.4.8112.20554_none_76f35fa48daa1433\wininet.dll
[7] 2012-06-02 12:05:28 . 5A45FA344F4AD99D903F4B20E43B89EC . 1392128 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\amd64_microsoft-windows-I..tocolimplementation_31bf3856ad364e35_9.4.8112.16447_none_767793a37481a47d\wininet.dll
[7] 2012-06-02 11:09:20 . 571E809181EBF0A04FEFAA9BC9961F5B . 1392128 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\amd64_microsoft-windows-I..tocolimplementation_31bf3856ad364e35_9.4.8112.20553_none_76f25f5a8daafadc\wininet.dll
[7] 2010-11-21 03:23:55 . F6C5302E1F4813D552F41A0AC82455E5 . 1188864 . . [8.00.7601.17514 (win7sp1_rtm.101119-1850)] .. C:\Windows\winsxs\amd64_microsoft-windows-I..tocolimplementation_31bf3856ad364e35_8.0.7601.17514_none_7ac940242f7494a4\wininet.dll
[-] 2012-06-29 03:49:11 . 8EA68FD3780DDDD5072F8CB830B3CB3D . 1392128 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\system32\wininet.dll
[7] 2012-08-02 14:14:24 . F82BF2CB075B49E9FAB5FF213C45C020 . 12281856 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16443_none_92225bec293c6a52\mshtml.dll
[7] 2012-08-02 14:14:24 . B9E083B14B1994F1255983F2DF31C7DF . 12281856 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20548_none_92b0fa29425588cf\mshtml.dll
[7] 2012-08-02 14:04:05 . 4DEF8126CABAA6CDC12103CD74C6A919 . 12268544 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16421_none_9235fb30292dffc2\mshtml.dll
[-] 2012-06-29 00:52:30 . 5E8E869E1342308752A37A2C90CCA79D . 12317184 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\SysWOW64\mshtml.dll
[-] 2012-06-29 00:52:30 . 5E8E869E1342308752A37A2C90CCA79D . 12317184 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16448_none_92275d5e2937e905\mshtml.dll
[-] 2012-06-28 23:11:03 . AEC51857AEC2F5CE4520366240AFC671 . 12317184 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20554_none_92a2291542613f64\mshtml.dll
[7] 2012-06-02 09:07:00 . 6820A9E91AFF7CB3A510360D8CCD9BDD . 12314624 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16447_none_92265d142938cfae\mshtml.dll
[7] 2012-06-02 08:48:46 . 1ABF770552EA9D4FE90F654468FAF4CE . 12314624 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20553_none_92a128cb4262260d\mshtml.dll
[7] 2010-11-21 03:25:08 . C50799F0D47DFB9774F721521B6C41D5 . 5977600 . . [8.00.7601.17514 (win7sp1_rtm.101119-1850)] .. C:\Windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.7601.17514_none_96780994e42bbfd5\mshtml.dll
[7] 2012-08-02 14:14:24 . 44465367256D1C72B58F5ABAA19E7016 . 1127424 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\x86_microsoft-windows-I..tocolimplementation_31bf3856ad364e35_9.4.8112.16443_none_1a54f6f7bc27cdeb\wininet.dll
[7] 2012-08-02 14:14:24 . 11A34DCA08EB2A586246F2D6C2A81D58 . 1127424 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\x86_microsoft-windows-I..tocolimplementation_31bf3856ad364e35_9.4.8112.20548_none_1ae39534d540ec68\wininet.dll
[7] 2012-08-02 14:04:05 . A1236375B74EA63C75657D564890C436 . 1126912 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\x86_microsoft-windows-I..tocolimplementation_31bf3856ad364e35_9.4.8112.16421_none_1a68963bbc19635b\wininet.dll
[-] 2012-06-29 00:09:01 . 75A97A2C060E72AB49E071E08C7DD2BA . 1129472 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\SysWOW64\wininet.dll
[-] 2012-06-29 00:09:01 . 75A97A2C060E72AB49E071E08C7DD2BA . 1129472 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\x86_microsoft-windows-I..tocolimplementation_31bf3856ad364e35_9.4.8112.16448_none_1a59f869bc234c9e\wininet.dll
[-] 2012-06-28 22:54:19 . 54C30A4066A28F9A017E095E283B2762 . 1129472 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\x86_microsoft-windows-I..tocolimplementation_31bf3856ad364e35_9.4.8112.20554_none_1ad4c420d54ca2fd\wininet.dll
[7] 2012-06-02 08:25:08 . 8E87270C4704CF2951E1E7820D6C8A2B . 1129472 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\x86_microsoft-windows-I..tocolimplementation_31bf3856ad364e35_9.4.8112.16447_none_1a58f81fbc243347\wininet.dll
[7] 2012-06-02 08:16:44 . E430161A632F9A8FE512DE0CA5685559 . 1129472 . . [9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)] .. C:\Windows\winsxs\x86_microsoft-windows-I..tocolimplementation_31bf3856ad364e35_9.4.8112.20553_none_1ad3c3d6d54d89a6\wininet.dll
[7] 2010-11-21 03:24:08 . 44214C94911C7CFB1D52CB64D5E8368D . 980992 . . [8.00.7601.17514 (win7sp1_rtm.101119-1850)] .. C:\Windows\winsxs\x86_microsoft-windows-I..tocolimplementation_31bf3856ad364e35_8.0.7601.17514_none_1eaaa4a07717236e\wininet.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2012-08-09 17:02:28 220608 ----a-w- C:\Users\Rickyfk\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2012-08-09 17:02:28 220608 ----a-w- C:\Users\Rickyfk\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2012-08-09 17:02:28 220608 ----a-w- C:\Users\Rickyfk\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19:10 94208 ----a-w- C:\Users\Rickyfk\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19:10 94208 ----a-w- C:\Users\Rickyfk\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19:10 94208 ----a-w- C:\Users\Rickyfk\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2010-11-21 03:24:51 1475584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"mcui_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2012-03-22 01:18:44 1675160]
"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 15:07:54 252296]
"RUSB3MON"="C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe" [2011-09-20 13:17:44 115048]
"Malwarebytes' Anti-Malware"="C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 17:46:44 462920]
C:\Users\Rickyfk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - C:\Users\Rickyfk\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-7-24 26909544]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\Windows\SysWOW64\nvinit.dll
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
R2 AlienFusionService;Alienware Fusion Service;C:\Program Files\Alienware\Command Center\AlienFusionService.exe [2012-06-18 20:43:48 14704]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 22:27:14 138576]
R2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-07-13 17:28:36 160944]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-08 19:04:13 250056]
R3 ALSysIO;ALSysIO;C:\Users\Rickyfk\AppData\Local\Temp\ALSysIO64.sys [x]
R3 cphs;Intel(R) Content Protection HECI Service;C:\Windows\SysWow64\IntelCpHeciSvc.exe [2012-03-22 21:34:18 276248]
R3 McAWFwk;McAfee Activation Service;c:\PROGRA~1\mcafee\msc\mcawfwk.exe [2011-03-08 22:00:50 224704]
R3 mferkdet;McAfee Inc. mferkdet;C:\Windows\system32\drivers\mferkdet.sys [2012-02-22 17:29:46 100912]
R3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-14 00:17:12 113120]
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;C:\Windows\system32\drivers\nvstusb.sys [2012-03-04 23:31:18 398656]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 01:34:24 4925184]
R3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 03:24:33 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 03:23:47 31232]
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.6;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2012-05-30 17:11:34 149544]
R3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe [2012-08-08 17:22:48 1255736]
R4 McOobeSv;McAfee OOBE Service;C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 23:28:20 249936]
S0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\system32\drivers\mfewfpk.sys [2012-02-22 17:29:46 289664]
S0 nvpciflt;nvpciflt;C:\Windows\system32\DRIVERS\nvpciflt.sys [2011-10-20 09:20:00 28992]
S1 mfenlfk;McAfee NDIS Light Filter;C:\Windows\system32\DRIVERS\mfenlfk.sys [2012-02-22 17:29:46 75936]
S1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 00:07:22 59904]
S2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 02:14:26 98208]
S2 AlienFXWindowsService;AlienFXWindowsService;C:\Program Files\Alienware\Command Center\AlienFXWindowsService.exe [2012-06-18 20:56:54 13168]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-06-27 16:29:24 2369960]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-02-03 03:29:52 628448]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-03-06 19:40:14 163608]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 17:46:44 655944]
S2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 23:28:20 249936]
S2 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 23:28:20 249936]
S2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-05-25 20:59:02 210616]
S2 mfevtp;McAfee Validation Trust Protection Service;C:\Windows\system32\mfevtps.exe [2012-05-25 21:13:54 162224]
S2 MSI_ODD_Service;MSI_ODD_Service;c:\Program Files (x86)\msi\ODD Monitor\ODD_Monitor.exe [2011-10-05 00:42:30 76800]
S2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-05-04 16:07:22 503080]
S2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-20 09:20:00 2253120]
S2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\AlienRespawn\sftservice.EXE [2012-02-16 17:49:44 1695040]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-20 08:26:00 381248]
S2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\system32\DRIVERS\TurboB.sys [2012-05-30 17:10:50 16168]
S2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-03-06 19:41:36 363800]
S3 cfwids;McAfee Inc. cfwids;C:\Windows\system32\drivers\cfwids.sys [2012-02-22 17:29:46 65264]
S3 DCamUSBVM;Lenovo Q350 USB PC Camera;C:\Windows\system32\Drivers\usbVM31b.sys [2005-09-19 17:57:36 142336]
S3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys [2011-12-06 11:23:08 331264]
S3 Lycosa;Lycosa Keyboard;C:\Windows\system32\drivers\Lycosa.sys [2008-01-17 20:51:44 18816]
S3 MBAMProtector;MBAMProtector;C:\Windows\system32\drivers\mbam.sys [2012-07-03 17:46:44 24904]
S3 MEIx64;Intel(R) Management Engine Interface ;C:\Windows\system32\DRIVERS\HECIx64.sys [2011-11-10 06:04:14 60184]
S3 mfefirek;McAfee Inc. mfefirek;C:\Windows\system32\drivers\mfefirek.sys [2012-02-22 17:29:46 487296]
S3 NTIOLib_X64;NTIOLib_X64;C:\Program Files (x86)\msi\ODD Monitor\NTIOLib_X64.sys [2010-01-18 18:36:44 14136]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys [2011-07-07 20:21:28 174184]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 23:34:52 539240]
S3 rusb3hub;Renesas Electronics USB 3.0 Hub Driver (Version 3.0);C:\Windows\system32\DRIVERS\rusb3hub.sys [2011-09-15 19:14:58 100352]
S3 rusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver (Version 3.0);C:\Windows\system32\DRIVERS\rusb3xhc.sys [2011-09-15 19:15:00 216064]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - WS2IFSL
*Deregistered* - mfeavfk01
Contents of the 'Scheduled Tasks' folder
2012-08-15 C:\Windows\Tasks\Adobe Flash Player Updater.job
- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-02 12:28:27 . 2012-08-08 19:04:13]
2012-08-11 C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
- C:\Program Files\AlienAutopsy\uaclauncher.exe [2012-05-22 07:09:58 . 2012-05-22 07:09:58]
2012-08-15 C:\Windows\Tasks\SystemToolsDailyTest.job
- C:\Program Files\AlienAutopsy\uaclauncher.exe [2012-05-22 07:09:58 . 2012-05-22 07:09:58]
--------- X64 Entries -----------
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2012-08-09 17:02:27 244672 ----a-w- C:\Users\Rickyfk\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64\SkyDriveShell64.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2012-08-09 17:02:27 244672 ----a-w- C:\Users\Rickyfk\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64\SkyDriveShell64.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2012-08-09 17:02:27 244672 ----a-w- C:\Users\Rickyfk\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64\SkyDriveShell64.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19:10 97792 ----a-w- C:\Users\Rickyfk\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19:10 97792 ----a-w- C:\Users\Rickyfk\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19:10 97792 ----a-w- C:\Users\Rickyfk\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19:10 97792 ----a-w- C:\Users\Rickyfk\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-11-03 05:07:06 6412904]
"RtHDVBg"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" [2011-10-20 07:46:24 1157224]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2012-03-22 21:34:10 170264]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2012-03-22 21:34:02 398616]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2012-03-22 21:34:06 439064]
"Command Center Controllers"="C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe" [2012-06-18 21:15:12 12656]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 01:39:57 168960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=C:\Windows\System32\nvinitx.dll
------- Supplementary Scan -------
uLocal Page = C:\Windows\system32\blank.htm
uStart Page =
www.alienwarearena.com/welcome-ca-e
mLocal Page = C:\Windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 24.226.1.93 24.226.10.193 24.226.10.194 24.226.1.94
FF - ProfilePath - C:\Users\Rickyfk\AppData\Roaming\Mozilla\Firefox\Profiles\ycru0hz5.default\
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=112542&tt=090812_ppc_3212_8
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://
www.google.com/search?babsrc=TB_ggl&q=
FF - user.js: extensions.BabylonToolbar.id - d0c8a7b2000000000000844bf5824044
FF - user.js: extensions.BabylonToolbar.instlDay - 15562
FF - user.js: extensions.BabylonToolbar.vrsn - 1.6.4.6
FF - user.js: extensions.BabylonToolbar.vrsni - 1.6.4.6
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.6.4.623:14:11
FF - user.js: extensions.BabylonToolbar.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar.tlbrId - base
FF - user.js: extensions.BabylonToolbar.instlRef - sst
FF - user.js: extensions.BabylonToolbar.dfltLng - en
FF - user.js: extensions.BabylonToolbar.excTlbr - false
FF - user.js: extensions.BabylonToolbar.admin - false
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
HKLM-Run-(Default) - (no file)
------------------------ Other Running Processes ------------------------
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\AlienRespawn\Components\DSUpdate\DSUpd.exe
C:\Program Files (x86)\AlienRespawn\TOASTER.EXE
C:\Program Files (x86)\AlienRespawn\COMPONENTS\SCHEDULER\STSERVICE.EXE
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
**************************************************************************
Completion time: 2012-08-15 19:46:19 - machine was rebooted
ComboFix-quarantined-files.txt 2012-08-15 23:46:19
Pre-Run: 832,415,150,080 bytes free
Post-Run: 833,612,673,024 bytes free
- - End Of File - - C7C7292F007A9ECCC83961FCC0CBD39A