Alright, had some trouble with combofix in the start (McAfee was acting up) but here is my logs from MBRcheck and Combofix
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: (build 7600), 64-bit
Base Board Manufacturer: DELL Inc.
BIOS Manufacturer: DELL INC.
System Manufacturer: DELL Inc.
System Product Name: Studio XPS 435T/9000
Logical Drives Mask: 0x0000803c
Kernel Drivers (total 196):
0x03857000 \SystemRoot\system32\ntoskrnl.exe
0x0380E000 \SystemRoot\system32\hal.dll
0x00BBF000 \SystemRoot\system32\kdcom.dll
0x00CC6000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x00D0A000 \SystemRoot\system32\PSHED.dll
0x00D1E000 \SystemRoot\system32\CLFS.SYS
0x00C00000 \SystemRoot\system32\CI.dll
0x00E60000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00F04000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x01054000 \SystemRoot\System32\Drivers\spjz.sys
0x0117A000 \SystemRoot\System32\Drivers\WMILIB.SYS
0x01183000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
0x00F13000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x011B2000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x011BC000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x011C9000 \SystemRoot\system32\DRIVERS\pci.sys
0x01000000 \SystemRoot\System32\drivers\partmgr.sys
0x01015000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x00F6A000 \SystemRoot\System32\drivers\volmgrx.sys
0x0102A000 \SystemRoot\System32\drivers\mountmgr.sys
0x012E3000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x01200000 \SystemRoot\system32\DRIVERS\jraid.sys
0x0121D000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x01228000 \SystemRoot\system32\drivers\fltmgr.sys
0x01274000 \SystemRoot\system32\drivers\fileinfo.sys
0x00D7C000 \SystemRoot\system32\drivers\mfehidk.sys
0x01288000 \SystemRoot\System32\Drivers\PxHlpa64.sys
0x0142A000 \SystemRoot\System32\Drivers\Ntfs.sys
0x00E00000 \SystemRoot\System32\Drivers\msrpc.sys
0x015CD000 \SystemRoot\System32\Drivers\ksecdd.sys
0x01693000 \SystemRoot\System32\Drivers\cng.sys
0x01706000 \SystemRoot\System32\drivers\pcw.sys
0x01717000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x018F8000 \SystemRoot\system32\drivers\ndis.sys
0x01800000 \SystemRoot\system32\drivers\NETIO.SYS
0x01860000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x0188B000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x018D7000 \SystemRoot\System32\Drivers\spldr.sys
0x01721000 \SystemRoot\System32\drivers\rdyboost.sys
0x018DF000 \SystemRoot\System32\Drivers\mup.sys
0x019EA000 \SystemRoot\System32\drivers\hwpolicy.sys
0x0175B000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x01795000 \SystemRoot\system32\DRIVERS\disk.sys
0x017AB000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x02D4B000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x02D75000 \SystemRoot\System32\Drivers\Null.SYS
0x02D7E000 \SystemRoot\System32\Drivers\Beep.SYS
0x02D85000 \SystemRoot\System32\drivers\vga.sys
0x02D93000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x02DB8000 \SystemRoot\System32\drivers\watchdog.sys
0x02DC8000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x02DD1000 \SystemRoot\system32\drivers\rdpencdd.sys
0x02DDA000 \SystemRoot\system32\drivers\rdprefmp.sys
0x02DE3000 \SystemRoot\System32\Drivers\Msfs.SYS
0x02DEE000 \SystemRoot\System32\Drivers\Npfs.SYS
0x04001000 \SystemRoot\System32\drivers\tcpip.sys
0x01600000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x0164A000 \SystemRoot\system32\drivers\mfewfpk.sys
0x02C00000 \SystemRoot\system32\drivers\TDI.SYS
0x01400000 \SystemRoot\system32\DRIVERS\tdx.sys
0x01294000 \SystemRoot\System32\DRIVERS\netbt.sys
0x042D7000 \SystemRoot\system32\drivers\afd.sys
0x04361000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x0436A000 \SystemRoot\system32\DRIVERS\pacer.sys
0x04390000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x043A6000 \SystemRoot\system32\DRIVERS\mfenlfk.sys
0x043B7000 \SystemRoot\system32\DRIVERS\netbios.sys
0x043C6000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x043E1000 \SystemRoot\system32\DRIVERS\termdd.sys
0x04200000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x04251000 \SystemRoot\system32\drivers\nsiproxy.sys
0x0425D000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x04268000 \SystemRoot\System32\drivers\discache.sys
0x04277000 \SystemRoot\System32\Drivers\dfsc.sys
0x04295000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x042A6000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x017E9000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x0FE69000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x10AC4000 \SystemRoot\System32\Drivers\nvBridge.kmd
0x10AC6000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x10BBA000 \SystemRoot\System32\drivers\dxgmms1.sys
0x0FE00000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x0FE24000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x0482C000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x04882000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x048CC000 \SystemRoot\system32\DRIVERS\1394ohci.sys
0x0490A000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x04917000 \SystemRoot\System32\Drivers\asyqy7z9.SYS
0x0495C000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x04965000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x0497D000 \SystemRoot\system32\drivers\ksthunk.sys
0x04983000 \SystemRoot\system32\drivers\ks.sys
0x049C6000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x049DC000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x04800000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x0FE31000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x0480C000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x00FC6000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x04CBE000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x04CD8000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x04CE7000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x04CF6000 \SystemRoot\system32\DRIVERS\swenum.sys
0x04CF8000 \SystemRoot\system32\DRIVERS\circlass.sys
0x04D0A000 \SystemRoot\system32\DRIVERS\umbus.sys
0x04D1C000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x04D76000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x04D8B000 \SystemRoot\system32\drivers\nvhda64v.sys
0x04DB4000 \SystemRoot\system32\drivers\portcls.sys
0x04C00000 \SystemRoot\system32\drivers\drmk.sys
0x05E0C000 \SystemRoot\system32\drivers\RTKVHD64.sys
0x04C22000 \SystemRoot\system32\drivers\mfeavfk.sys
0x04C4F000 \SystemRoot\system32\drivers\mfefirek.sys
0x00030000 \SystemRoot\System32\win32k.sys
0x05E00000 \SystemRoot\System32\drivers\Dxapi.sys
0x04DF1000 \SystemRoot\System32\Drivers\crashdmp.sys
0x02C0D000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x02D29000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x02D3C000 \SystemRoot\system32\DRIVERS\monitor.sys
0x005C0000 \SystemRoot\System32\TSDDD.dll
0x0283B000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x02858000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x0285A000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x02868000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x02881000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x00640000 \SystemRoot\System32\cdd.dll
0x0288A000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x02897000 \SystemRoot\System32\Drivers\RtsUStor.sys
0x028D1000 \SystemRoot\system32\DRIVERS\usbcir.sys
0x028F0000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x028FE000 \SystemRoot\system32\DRIVERS\hidir.sys
0x0290F000 \SystemRoot\system32\drivers\luafv.sys
0x02932000 \SystemRoot\system32\drivers\WudfPf.sys
0x02953000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x02968000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x029BB000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x029CE000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x0665D000 \SystemRoot\system32\drivers\HTTP.sys
0x06725000 \SystemRoot\system32\DRIVERS\bowser.sys
0x06743000 \SystemRoot\System32\drivers\mpsdrv.sys
0x0675B000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x06788000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x067D6000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x06C9B000 \SystemRoot\system32\drivers\peauth.sys
0x06D41000 \SystemRoot\System32\Drivers\secdrv.SYS
0x06D4C000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x06D79000 \SystemRoot\System32\drivers\tcpipreg.sys
0x06D8B000 \SystemRoot\system32\drivers\tdtcp.sys
0x06D96000 \SystemRoot\System32\DRIVERS\tssecsrv.sys
0x06DA5000 \SystemRoot\System32\Drivers\RDPWD.SYS
0x06C00000 \SystemRoot\System32\DRIVERS\srv2.sys
0x076BB000 \SystemRoot\System32\DRIVERS\srv.sys
0x07751000 \SystemRoot\system32\drivers\cfwids.sys
0x0777B000 \SystemRoot\System32\Drivers\fastfat.SYS
0x0768D000 \SystemRoot\system32\drivers\mfeapfk.sys
0x077B1000 \SystemRoot\system32\DRIVERS\Rt64win7.sys
0x077EA000 \SystemRoot\system32\DRIVERS\serscan.sys
0x77020000 \Windows\System32\ntdll.dll
0x475D0000 \Windows\System32\smss.exe
0xFF340000 \Windows\System32\apisetschema.dll
0xFFEB0000 \Windows\System32\autochk.exe
0xFF2B0000 \Windows\System32\shlwapi.dll
0xFF290000 \Windows\System32\sechost.dll
0xFF1C0000 \Windows\System32\usp10.dll
0xFF040000 \Windows\System32\urlmon.dll
0x771F0000 \Windows\System32\normaliz.dll
0xFF030000 \Windows\System32\nsi.dll
0x76F00000 \Windows\System32\kernel32.dll
0x771E0000 \Windows\System32\psapi.dll
0xFEF90000 \Windows\System32\comdlg32.dll
0xFEF70000 \Windows\System32\imagehlp.dll
0xFEF60000 \Windows\System32\lpk.dll
0xFEE30000 \Windows\System32\wininet.dll
0xFED50000 \Windows\System32\oleaut32.dll
0xFEC40000 \Windows\System32\msctf.dll
0xFDEB0000 \Windows\System32\shell32.dll
0xFDE60000 \Windows\System32\Wldap32.dll
0xFDDC0000 \Windows\System32\clbcatq.dll
0xFDC90000 \Windows\System32\rpcrt4.dll
0xFDC20000 \Windows\System32\gdi32.dll
0xFDA40000 \Windows\System32\setupapi.dll
0xFD7E0000 \Windows\System32\iertutil.dll
0xFD700000 \Windows\System32\advapi32.dll
0x76E00000 \Windows\System32\user32.dll
0xFD4F0000 \Windows\System32\ole32.dll
0xFD470000 \Windows\System32\difxapi.dll
0xFD3D0000 \Windows\System32\msvcrt.dll
0xFD3A0000 \Windows\System32\imm32.dll
0xFD350000 \Windows\System32\ws2_32.dll
0xFD2E0000 \Windows\System32\KernelBase.dll
0xFD2A0000 \Windows\System32\wintrust.dll
0xFD280000 \Windows\System32\devobj.dll
0xFD240000 \Windows\System32\cfgmgr32.dll
0xFD0D0000 \Windows\System32\crypt32.dll
0xFD030000 \Windows\System32\comctl32.dll
0xFD020000 \Windows\System32\msasn1.dll
0x74FC0000 \Windows\SysWOW64\normaliz.dll
Processes (total 78):
0 System Idle Process
4 System
384 C:\Windows\System32\smss.exe
656 csrss.exe
732 C:\Windows\System32\wininit.exe
752 csrss.exe
788 C:\Windows\System32\services.exe
812 C:\Windows\System32\lsass.exe
820 C:\Windows\System32\lsm.exe
904 C:\Windows\System32\winlogon.exe
1004 C:\Windows\System32\svchost.exe
364 C:\Windows\System32\nvvsvc.exe
436 C:\Windows\System32\svchost.exe
880 C:\Windows\System32\svchost.exe
960 C:\Windows\System32\svchost.exe
1052 C:\Windows\System32\svchost.exe
1160 C:\Windows\System32\audiodg.exe
1212 C:\Windows\System32\svchost.exe
1268 C:\Program Files\Dell\DellDock\DockLogin.exe
1348 C:\Windows\System32\svchost.exe
1516 C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
1528 C:\Windows\System32\nvvsvc.exe
1656 C:\Windows\System32\spoolsv.exe
1684 C:\Windows\System32\svchost.exe
1840 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1888 C:\Program Files (x86)\Bonjour\mDNSResponder.exe
1936 C:\Windows\SysWOW64\svchost.exe
1960 C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
2028 C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe
1364 C:\Windows\System32\svchost.exe
1820 C:\Windows\System32\svchost.exe
1916 C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
2064 C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
2092 C:\Windows\System32\svchost.exe
2132 C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
2168 C:\Windows\System32\svchost.exe
2208 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
2432 C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
2472 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
2520 C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
2676 C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
2728 C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
2756 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
3092 C:\Windows\System32\svchost.exe
3220 C:\Windows\System32\svchost.exe
3304 C:\Windows\System32\taskhost.exe
3740 C:\Windows\System32\dwm.exe
3772 C:\Windows\explorer.exe
3892 C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe
4496 C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
4532 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
4704 C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
4880 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
4916 C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
5048 C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
5072 C:\Program Files\McAfee.com\Agent\mcagent.exe
5088 C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
5100 C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
5112 C:\Program Files (x86)\Winamp\winampa.exe
3716 C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
4256 C:\Windows\System32\SearchIndexer.exe
5256 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
5320 C:\Program Files\Windows Media Player\wmpnetwk.exe
5352 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
5516 C:\Windows\System32\svchost.exe
5684 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
5920 C:\Program Files (x86)\Winamp\winamp.exe
6108 dllhost.exe
4720 C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
308 C:\Program Files\Common Files\McAfee\Core\mchost.exe
4724 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
1548 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
3268 C:\Windows\System32\SearchProtocolHost.exe
6228 C:\Windows\System32\SearchFilterHost.exe
7068 dllhost.exe
4876 dllhost.exe
3908 C:\Users\Jeezys\Downloads\MBRCheck.exe
6788 C:\Windows\System32\conhost.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000002`4a600000 (NTFS)
\\.\F: --> \\.\PhysicalDrive0 at offset 0x00000000`02800000 (NTFS)
\\.\P: --> \\.\PhysicalDrive0 at offset 0x0000008b`bef00000 (NTFS)
PhysicalDrive0 Model Number: ST3750528AS, Rev: CC45
Size Device Name MBR Status
--------------------------------------------
698 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
Done!
ComboFix 11-01-31.02 - Jeezys 02/04/2011 22:28:23.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.8183.6424 [GMT -6:00]
Running from: c:\users\Jeezys\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\install.exe
F:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2011-01-05 to 2011-02-05 )))))))))))))))))))))))))))))))
.
2011-02-05 04:32 . 2011-02-05 04:32 -------- d-----w- c:\users\Mcx1-JEEZYS-PC\AppData\Local\temp
2011-02-05 04:27 . 2011-02-05 04:27 -------- d-----w- C:\32788R22FWJFW
2011-02-05 03:12 . 2011-02-05 03:12 -------- d-----w- c:\users\Jeezys\AppData\Roaming\Malwarebytes
2011-02-05 03:12 . 2010-12-21 00:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-02-05 03:12 . 2011-02-05 03:12 -------- d-----w- c:\progra~3\Malwarebytes
2011-02-05 03:12 . 2010-12-21 00:08 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-05 03:12 . 2011-02-05 03:12 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-02-04 01:05 . 2011-02-04 01:17 -------- d-----w- C:\Boot
2011-01-30 00:48 . 2011-01-30 00:48 -------- d-----w- c:\users\Jeezys\AppData\Roaming\Centrify
2011-01-25 04:28 . 2011-01-25 04:28 -------- d-----w- c:\program files\HP
2011-01-15 03:16 . 2011-01-15 03:16 -------- d-----w- c:\program files (x86)\Motorola
2011-01-13 04:28 . 2010-10-16 05:17 720896 ----a-w- c:\windows\system32\odbc32.dll
2011-01-13 04:28 . 2010-10-16 05:16 495616 ----a-w- c:\program files\Common Files\System\ado\msadox.dll
2011-01-13 04:28 . 2010-10-16 05:16 466944 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
2011-01-13 04:28 . 2010-10-16 05:16 1425408 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
2011-01-13 04:28 . 2010-10-16 05:16 258048 ----a-w- c:\program files\Common Files\System\msadc\msadco.dll
2011-01-13 04:28 . 2010-10-16 04:34 573440 ----a-w- c:\windows\SysWow64\odbc32.dll
2011-01-13 04:28 . 2010-10-16 04:33 372736 ----a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll
2011-01-13 04:28 . 2010-10-16 04:33 352256 ----a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll
2011-01-13 04:28 . 2010-10-16 04:33 987136 ----a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll
2011-01-13 04:28 . 2010-10-16 04:33 208896 ----a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll
2011-01-08 02:49 . 2011-01-08 02:49 795752 ----a-w- c:\windows\system32\easyUpdatusAPIU64.dll
2011-01-08 02:49 . 2011-01-08 02:49 6143080 ----a-w- c:\windows\system32\nvcpl.dll
2011-01-08 02:49 . 2011-01-08 02:49 3156072 ----a-w- c:\windows\system32\nvsvc64.dll
2011-01-08 02:48 . 2011-01-08 02:48 117864 ----a-w- c:\windows\system32\nvmctray.dll
2011-01-08 02:48 . 2011-01-08 02:48 1005160 ----a-w- c:\windows\system32\nvvsvc.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-08 03:27 . 2010-07-10 10:38 5653096 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2011-01-08 03:27 . 2010-07-10 10:38 10078312 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2011-01-08 03:27 . 2010-04-11 21:39 7729256 ----a-w- c:\windows\system32\nvwgf2umx.dll
2011-01-08 03:27 . 2010-04-11 21:39 2200680 ----a-w- c:\windows\system32\nvapi64.dll
2011-01-08 03:27 . 2010-04-11 21:39 12859496 ----a-w- c:\windows\system32\nvd3dumx.dll
2011-01-02 19:13 . 2011-01-02 19:13 737072 ----a-w- c:\progra~3\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-3\Microsoft.MediaCenter.Sports.UI.dll
2011-01-02 19:13 . 2011-01-02 19:13 4277016 ----a-w- c:\progra~3\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-3\markup.dll
2011-01-02 19:13 . 2010-11-26 10:11 42776 ----a-w- c:\progra~3\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2011-01-02 18:13 . 2010-08-27 20:21 42776 ----a-w- c:\progra~3\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2011-01-02 18:12 . 2010-11-26 10:10 539968 ----a-w- c:\progra~3\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2010-12-10 17:22 . 2010-08-27 20:21 539968 ----a-w- c:\progra~3\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-11-30 00:50 . 2010-11-30 00:50 327680 ----a-w- c:\users\Jeezys\AppData\Roaming\Adobe.exe
2010-11-29 23:38 . 2010-11-29 23:38 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2010-11-29 23:38 . 2010-11-29 23:38 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
2010-11-26 10:11 . 2010-11-26 10:11 737072 ----a-w- c:\progra~3\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll
2010-11-26 10:11 . 2010-11-26 10:11 4277016 ----a-w- c:\progra~3\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2010-11-13 00:53 . 2010-08-04 07:00 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2010-11-11 23:10 . 2010-06-30 00:03 29288 ----a-w- c:\windows\system32\nvhdap64.dll
2010-11-11 23:10 . 2010-06-30 00:03 155752 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-09-23 4240760]
"Adobe.exe"="c:\users\Jeezys\AppData\Roaming\Adobe.exe" [2010-11-30 327680]
"HLBackupScheduler"="c:\program files\Verizon V CAST Media Manager\V CAST Backup Scheduler.exe" [2010-12-08 5247624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"PDVDDXSrv"="c:\program files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-09-30 1484856]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"dellsupportcenter"="c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2010-07-12 74752]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
c:\users\Anyone\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-9-21 1316192]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-9-21 1316192]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SessionLauncher;SessionLauncher; [x]
R3 AE1000;Linksys AE1000 Driver;c:\windows\system32\DRIVERS\ae1000w7.sys [2010-02-12 1101600]
R3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\DRIVERS\motfilt.sys [2009-01-29 6144]
R3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;c:\windows\system32\drivers\BVRPMPR5a64.SYS [2009-05-04 35840]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-10-14 94864]
R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys [2010-06-18 20992]
R3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys [2009-01-29 9216]
R3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\DRIVERS\Motousbnet.sys [2010-04-01 26624]
R3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\DRIVERS\motusbdevice.sys [2010-01-26 10240]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-26 1124848]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [2010-06-21 693864]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2010-09-28 51712]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-04-15 1255736]
R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-10 834544]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2010-10-14 75032]
S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2010-10-14 283360]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-10-14 245352]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-10-14 149032]
S2 MotoHelper;MotoHelper Service;c:\program files (x86)\Motorola\MotoHelper\MotoHelperService.exe [2010-09-07 202048]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2010-03-04 658656]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-08 378984]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-10-14 62800]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-10-14 441328]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2010-11-11 155752]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-06-05 216064]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-05-23 215040]
--- Other Services/Drivers In Memory ---
*Deregistered* - mfeavfk01
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-10-03 8158240]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Jeezys\AppData\Roaming\Mozilla\Firefox\Profiles\08x31bot.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Arabic spell-checking dictionary:
ar@dictionaries.addons.mozilla.org - %profile%\extensions\ar@dictionaries.addons.mozilla.org
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
AddRemove-BattlEye - c:\program files (x86)\Bohemia Interactive\ArmABattlEye\UnInstallBE.exe
AddRemove-BattlEye for OA - c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowheadExpansion\BattlEye\UnInstallBE.exe
AddRemove-Octoshape add-in for Adobe Flash Player - c:\users\Jeezys\AppData\Roaming\Macromedia\Flash Player\
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1046951974-1599380402-3457755934-1000\Software\SecuROM\License information*]
"datasecu"=hex:97,0d,b4,d2,6d,65,dd,b4,a2,3f,b5,33,d4,b2,04,bc,02,0e,be,2f,a6,
0c,a3,88,d8,8a,10,6d,21,54,48,3e,9a,05,2f,ce,2b,31,d2,e9,e3,d5,06,2b,c3,d6,\
"rkeysecu"=hex:fc,c0,7e,17,05,7d,fc,b5,1a,af,54,29,89,3b,60,32
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-02-04 22:33:56
ComboFix-quarantined-files.txt 2011-02-05 04:33
Pre-Run: 409,748,377,600 bytes free
Post-Run: 409,713,152,000 bytes free
- - End Of File - - 59D00F6D0DEE0106F98C014786F0B2E4