ComboFix 13-08-07.01 - Leeanna 08/08/2013 16:17:22.4.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8140.4894 [GMT -10:00]
Running from: c:\users\Leeanna\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
FW: Kaspersky Internet Security *Disabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}
SP: Kaspersky Internet Security *Disabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Leeanna\AppData\Roaming\DefaultTab\DefaultTab
c:\users\Leeanna\GoToAssistDownloadHelper.exe
c:\users\Leeanna\videos\SteelSeries_USB_Soundcard_v120.exe
.
.
((((((((((((((((((((((((( Files Created from 2013-07-09 to 2013-08-09 )))))))))))))))))))))))))))))))
.
.
2013-08-09 02:22 . 2013-08-09 02:22 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-08-09 02:22 . 2013-08-09 02:22 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-09 00:30 . 2013-08-09 00:47 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2013-08-09 00:27 . 2013-08-09 00:27 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys.bak
2013-08-09 00:27 . 2013-08-09 00:27 41472 ----a-w- c:\windows\system32\drivers\RNDISMP.sys.bak
2013-08-09 00:27 . 2013-08-09 00:27 50768 ----a-w- c:\windows\system32\drivers\pcw.sys.bak
2013-08-09 00:26 . 2013-08-09 00:26 75120 ----a-w- c:\windows\system32\drivers\partmgr.sys.bak
2013-08-09 00:26 . 2013-08-09 00:26 44032 ----a-w- c:\windows\system32\drivers\npfs.sys.bak
2013-08-09 00:26 . 2013-08-09 00:26 60496 ----a-w- c:\windows\system32\drivers\mup.sys.bak
2013-08-09 00:26 . 2013-08-09 00:26 50768 ----a-w- c:\windows\system32\drivers\kbdclass.sys.bak
2013-08-09 00:26 . 2013-08-09 00:26 38912 ----a-w- c:\windows\system32\drivers\CompositeBus.sys.bak
2013-08-09 00:26 . 2013-08-09 00:26 45568 ----a-w- c:\windows\system32\drivers\circlass.sys.bak
2013-08-09 00:26 . 2013-08-09 00:26 61008 ----a-w- c:\windows\system32\drivers\AGP440.sys.bak
2013-08-08 05:45 . 2011-03-21 16:48 651264 ------w- c:\windows\system32\stapi64.dll
2013-08-08 05:45 . 2011-03-21 16:48 732672 ----a-w- c:\windows\system32\imapo32.dll
2013-08-08 05:45 . 2011-03-21 16:48 390656 ----a-w- c:\windows\system32\imthx64.dll
2013-08-08 05:45 . 2011-03-21 16:48 866304 ----a-w- c:\windows\system32\imapo64.dll
2013-08-08 05:45 . 2011-03-21 16:48 68608 ----a-w- c:\windows\system32\AESTAR64.dll
2013-08-08 05:45 . 2011-03-21 16:48 442368 ----a-w- c:\windows\system32\AESTEC64.dll
2013-08-08 05:45 . 2011-03-21 16:48 162304 ----a-w- c:\windows\system32\AESTAC64.dll
2013-08-08 05:45 . 2013-08-08 05:46 -------- d-----w- c:\program files\IDT
2013-08-08 05:45 . 2011-03-21 16:48 4637184 ----a-w- c:\windows\system32\stlang64.dll
2013-08-08 05:45 . 2011-03-21 16:48 228352 ----a-w- c:\windows\system32\MaxxAudioAPOShell64.dll
2013-08-08 05:45 . 2011-03-21 16:48 90624 ----a-w- c:\windows\system32\AESTCo64.dll
2013-08-08 05:45 . 2011-03-21 16:48 438784 ----a-w- c:\windows\system32\IDTNC64.cpl
2013-08-08 05:23 . 2013-08-08 02:25 143360 ------w- c:\windows\Vmix108.dll
2013-08-08 05:23 . 2013-08-08 02:25 8757248 ------w- c:\windows\SysWow64\CM108.dll
2013-08-08 05:23 . 2013-08-08 02:25 389120 ------w- c:\windows\system32\CM108.cpl
2013-08-08 05:23 . 2013-08-08 02:25 200704 ------w- c:\windows\SysWow64\cmpa108.dll
2013-08-08 03:53 . 2013-07-02 08:34 9460976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{15C1CB0E-2926-4300-9176-CE71B468A662}\mpengine.dll
2013-08-08 03:11 . 2013-08-08 02:25 820224 ------w- c:\windows\system32\Cmeau108.exe
2013-08-08 02:14 . 2013-08-08 02:25 359424 ------w- c:\windows\system32\CmiInstallResAll64.dll
2013-08-08 02:14 . 2013-08-08 02:25 524768 ----a-w- c:\windows\difxapi.dll
2013-08-06 17:51 . 2013-08-06 17:51 -------- d-----w- c:\users\Leeanna\AppData\Local\Windows Live Writer
2013-08-06 17:51 . 2013-08-06 17:51 -------- d-----w- c:\users\Leeanna\AppData\Roaming\Windows Live Writer
2013-08-05 19:09 . 2013-08-05 19:25 -------- d-----w- c:\users\Leeanna\AppData\Roaming\Apple Computer
2013-08-05 19:09 . 2013-08-05 19:09 -------- d-----w- c:\users\Leeanna\AppData\Local\Apple Computer
2013-08-05 19:08 . 2012-08-21 23:01 33240 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2013-08-05 19:07 . 2013-08-05 19:08 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-08-05 19:07 . 2013-08-05 19:08 -------- d-----w- c:\program files\iTunes
2013-08-05 19:07 . 2013-08-05 19:08 -------- d-----w- c:\program files (x86)\iTunes
2013-08-05 19:07 . 2013-08-05 19:07 -------- d-----w- c:\programdata\Apple Computer
2013-08-05 19:07 . 2013-08-05 19:07 -------- d-----w- c:\program files\iPod
2013-08-05 19:07 . 2013-08-05 19:07 -------- d-----w- c:\users\Leeanna\AppData\Local\Apple
2013-08-05 19:07 . 2013-08-05 19:07 -------- d-----w- c:\program files (x86)\Apple Software Update
2013-08-05 19:06 . 2013-08-05 19:06 -------- d-----w- c:\program files\Common Files\Apple
2013-08-05 19:06 . 2013-08-05 19:06 -------- d-----w- c:\program files (x86)\Bonjour
2013-08-05 19:06 . 2013-08-05 19:06 -------- d-----w- c:\program files\Bonjour
2013-08-05 19:06 . 2013-08-05 19:07 -------- d-----w- c:\program files (x86)\Common Files\Apple
2013-08-05 19:06 . 2013-08-05 19:07 -------- d-----w- c:\programdata\Apple
2013-08-05 03:20 . 2013-08-05 19:55 -------- d-----w- c:\users\Leeanna\AppData\Roaming\vlc
2013-08-05 03:20 . 2013-08-05 04:01 -------- d-----w- c:\program files\VideoLAN
2013-08-05 03:16 . 2013-08-05 03:34 -------- d-----w- c:\users\Leeanna\AppData\Local\Conduit
2013-08-05 03:14 . 2013-08-09 02:21 -------- d-----w- c:\users\Leeanna\AppData\Roaming\DefaultTab
2013-08-05 03:14 . 2013-08-05 03:16 -------- d-----w- c:\program files (x86)\Conduit
2013-08-05 03:14 . 2013-08-05 03:14 -------- d-----w- c:\users\Leeanna\AppData\Local\CRE
2013-08-05 01:08 . 2013-08-05 01:08 -------- d-----w- c:\windows\en
2013-08-05 01:04 . 2013-08-05 01:04 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2013-08-05 01:04 . 2013-08-05 01:04 -------- d-----w- c:\program files\Windows Live
2013-08-05 01:03 . 2013-08-05 01:04 -------- d-----w- c:\program files (x86)\Windows Live
2013-08-05 00:59 . 2013-08-06 17:50 -------- d-----w- c:\users\Leeanna\AppData\Local\Windows Live
2013-08-05 00:59 . 2013-08-05 00:59 -------- d-----w- c:\program files (x86)\Common Files\Windows Live
2013-07-30 23:02 . 2013-07-30 23:02 -------- d-----w- c:\users\Leeanna\AppData\Local\InfiniteCrisis
2013-07-30 22:43 . 2013-07-30 22:43 -------- d-----w- c:\users\Leeanna\AppData\Local\Turbine
2013-07-30 22:41 . 2013-07-30 22:41 -------- d-----w- c:\programdata\Turbine
2013-07-30 22:41 . 2013-08-01 01:54 -------- d-----w- c:\program files (x86)\InfiniteCrisis
2013-07-30 02:12 . 2013-07-30 02:12 -------- d-----w- c:\users\Public\Games
2013-07-27 02:30 . 2013-07-27 02:30 -------- d-----w- c:\program files (x86)\SplitMediaLabs
2013-07-25 06:41 . 2013-07-25 06:41 -------- d-----w- c:\program files (x86)\Common Files\Skype
2013-07-20 00:46 . 2013-07-20 00:46 -------- d-----w- c:\users\Leeanna\AppData\Local\CrashRpt
2013-07-20 00:46 . 2013-07-20 00:50 -------- d-----w- c:\users\Leeanna\AppData\Roaming\DawngateData
2013-07-20 00:46 . 2013-07-20 00:46 -------- d-----w- c:\program files (x86)\Electronic Arts
2013-07-15 01:22 . 2013-07-15 01:23 -------- d-----w- c:\users\Leeanna\AppData\Roaming\Origin
2013-07-15 01:22 . 2013-07-15 01:22 -------- d-----w- c:\program files (x86)\Origin Games
2013-07-15 01:22 . 2013-07-15 01:22 -------- d-----w- c:\users\Leeanna\AppData\Local\Origin
2013-07-15 01:21 . 2013-07-15 01:23 -------- d-----w- c:\programdata\Origin
2013-07-15 01:21 . 2013-07-15 01:21 -------- d-----w- c:\programdata\Electronic Arts
2013-07-15 01:21 . 2013-07-15 01:21 -------- d-----w- c:\program files (x86)\Origin
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-08 03:44 . 2011-08-09 00:45 78185248 ----a-w- c:\windows\system32\MRT.exe
2013-08-08 02:25 . 2013-01-17 03:54 315392 ----a-w- c:\windows\system\fltr108.dll
2013-08-08 02:25 . 2013-01-17 03:54 1310720 ----a-w- c:\windows\system32\drivers\CM10864.sys
2013-08-05 01:03 . 2012-07-18 00:37 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-07-09 20:05 . 2013-07-09 20:05 89600 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-07-09 20:05 . 2013-07-09 20:05 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-07-09 20:05 . 2013-07-09 20:05 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-07-09 20:05 . 2013-07-09 20:05 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-07-09 20:05 . 2013-07-09 20:05 61952 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-07-09 20:05 . 2013-07-09 20:05 61440 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-07-09 20:05 . 2013-07-09 20:05 523264 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-07-09 20:05 . 2013-07-09 20:05 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-07-09 20:05 . 2013-07-09 20:05 38400 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-07-09 20:05 . 2013-07-09 20:05 361984 ----a-w- c:\windows\SysWow64\html.iec
2013-07-09 20:05 . 2013-07-09 20:05 2877440 ----a-w- c:\windows\SysWow64\jscript9.dll
2013-07-09 20:05 . 2013-07-09 20:05 2706432 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-07-09 20:05 . 2013-07-09 20:05 2648576 ----a-w- c:\windows\system32\iertutil.dll
2013-07-09 20:05 . 2013-07-09 20:05 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-07-09 20:05 . 2013-07-09 20:05 226304 ----a-w- c:\windows\system32\elshyph.dll
2013-07-09 20:05 . 2013-07-09 20:05 197120 ----a-w- c:\windows\system32\msrating.dll
2013-07-09 20:05 . 2013-07-09 20:05 185344 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-07-09 20:05 . 2013-07-09 20:05 1767936 ----a-w- c:\windows\SysWow64\wininet.dll
2013-07-09 20:05 . 2013-07-09 20:05 158720 ----a-w- c:\windows\SysWow64\msls31.dll
2013-07-09 20:05 . 2013-07-09 20:05 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-07-09 20:05 . 2013-07-09 20:05 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-07-09 20:05 . 2013-07-09 20:05 138752 ----a-w- c:\windows\SysWow64\wextract.exe
2013-07-09 20:05 . 2013-07-09 20:05 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-07-09 20:05 . 2013-07-09 20:05 12800 ----a-w- c:\windows\SysWow64\mshta.exe
2013-07-09 20:05 . 2013-07-09 20:05 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-07-09 20:05 . 2013-07-09 20:05 109056 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-07-09 20:05 . 2013-07-09 20:05 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-07-09 20:05 . 2013-07-09 20:05 97280 ----a-w- c:\windows\system32\mshtmled.dll
2013-07-09 20:05 . 2013-07-09 20:05 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-07-09 20:05 . 2013-07-09 20:05 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-07-09 20:05 . 2013-07-09 20:05 855552 ----a-w- c:\windows\system32\jscript.dll
2013-07-09 20:05 . 2013-07-09 20:05 81408 ----a-w- c:\windows\system32\icardie.dll
2013-07-09 20:05 . 2013-07-09 20:05 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-07-09 20:05 . 2013-07-09 20:05 762368 ----a-w- c:\windows\system32\ieapfltr.dll
2013-07-09 20:05 . 2013-07-09 20:05 67072 ----a-w- c:\windows\system32\iesetup.dll
2013-07-09 20:05 . 2013-07-09 20:05 62976 ----a-w- c:\windows\system32\pngfilt.dll
2013-07-09 20:05 . 2013-07-09 20:05 603136 ----a-w- c:\windows\system32\msfeeds.dll
2013-07-09 20:05 . 2013-07-09 20:05 599552 ----a-w- c:\windows\system32\vbscript.dll
2013-07-09 20:05 . 2013-07-09 20:05 53248 ----a-w- c:\windows\system32\jsproxy.dll
2013-07-09 20:05 . 2013-07-09 20:05 526336 ----a-w- c:\windows\system32\ieui.dll
2013-07-09 20:05 . 2013-07-09 20:05 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-07-09 20:05 . 2013-07-09 20:05 51712 ----a-w- c:\windows\system32\ie4uinit.exe
2013-07-09 20:05 . 2013-07-09 20:05 51200 ----a-w- c:\windows\system32\imgutil.dll
2013-07-09 20:05 . 2013-07-09 20:05 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-07-09 20:05 . 2013-07-09 20:05 452096 ----a-w- c:\windows\system32\dxtmsft.dll
2013-07-09 20:05 . 2013-07-09 20:05 441856 ----a-w- c:\windows\system32\html.iec
2013-07-09 20:05 . 2013-07-09 20:05 39936 ----a-w- c:\windows\system32\iernonce.dll
2013-07-09 20:05 . 2013-07-09 20:05 3958784 ----a-w- c:\windows\system32\jscript9.dll
2013-07-09 20:05 . 2013-07-09 20:05 281600 ----a-w- c:\windows\system32\dxtrans.dll
2013-07-09 20:05 . 2013-07-09 20:05 27648 ----a-w- c:\windows\system32\licmgr10.dll
2013-07-09 20:05 . 2013-07-09 20:05 270848 ----a-w- c:\windows\system32\iedkcs32.dll
2013-07-09 20:05 . 2013-07-09 20:05 2706432 ----a-w- c:\windows\system32\mshtml.tlb
2013-07-09 20:05 . 2013-07-09 20:05 247296 ----a-w- c:\windows\system32\webcheck.dll
2013-07-09 20:05 . 2013-07-09 20:05 235008 ----a-w- c:\windows\system32\url.dll
2013-07-09 20:05 . 2013-07-09 20:05 2241024 ----a-w- c:\windows\system32\wininet.dll
2013-07-09 20:05 . 2013-07-09 20:05 216064 ----a-w- c:\windows\system32\msls31.dll
2013-07-09 20:05 . 2013-07-09 20:05 19238912 ----a-w- c:\windows\system32\mshtml.dll
2013-07-09 20:05 . 2013-07-09 20:05 173568 ----a-w- c:\windows\system32\ieUnatt.exe
2013-07-09 20:05 . 2013-07-09 20:05 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-07-09 20:05 . 2013-07-09 20:05 15404032 ----a-w- c:\windows\system32\ieframe.dll
2013-07-09 20:05 . 2013-07-09 20:05 1509376 ----a-w- c:\windows\system32\inetcpl.cpl
2013-07-09 20:05 . 2013-07-09 20:05 149504 ----a-w- c:\windows\system32\occache.dll
2013-07-09 20:05 . 2013-07-09 20:05 144896 ----a-w- c:\windows\system32\wextract.exe
2013-07-09 20:05 . 2013-07-09 20:05 1400416 ----a-w- c:\windows\system32\ieapfltr.dat
2013-07-09 20:05 . 2013-07-09 20:05 13824 ----a-w- c:\windows\system32\mshta.exe
2013-07-09 20:05 . 2013-07-09 20:05 136704 ----a-w- c:\windows\system32\iesysprep.dll
2013-07-09 20:05 . 2013-07-09 20:05 1365504 ----a-w- c:\windows\system32\urlmon.dll
2013-07-09 20:05 . 2013-07-09 20:05 136192 ----a-w- c:\windows\system32\iepeers.dll
2013-07-09 20:05 . 2013-07-09 20:05 135680 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-07-09 20:05 . 2013-07-09 20:05 12800 ----a-w- c:\windows\system32\msfeedssync.exe
2013-07-09 20:05 . 2013-07-09 20:05 102912 ----a-w- c:\windows\system32\inseng.dll
2013-07-09 20:04 . 2013-07-09 20:04 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-07-09 20:04 . 2013-07-09 20:04 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-07-09 20:04 . 2013-07-09 20:04 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2013-07-09 20:04 . 2013-07-09 20:04 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2013-07-09 20:04 . 2013-07-09 20:04 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-07-09 20:04 . 2013-07-09 20:04 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-07-09 20:04 . 2013-07-09 20:04 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-07-09 20:04 . 2013-07-09 20:04 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-07-09 20:04 . 2013-07-09 20:04 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2013-07-09 20:04 . 2013-07-09 20:04 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2013-07-09 20:04 . 2013-07-09 20:04 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-07-09 20:04 . 2013-07-09 20:04 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-07-09 20:04 . 2013-07-09 20:04 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-07-09 20:04 . 2013-07-09 20:04 3928064 ----a-w- c:\windows\system32\d2d1.dll
2013-07-09 20:04 . 2013-07-09 20:04 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2013-07-09 20:04 . 2013-07-09 20:04 363008 ----a-w- c:\windows\system32\dxgi.dll
2013-07-09 20:04 . 2013-07-09 20:04 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-07-09 20:04 . 2013-07-09 20:04 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-07-09 20:04 . 2013-07-09 20:04 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2013-07-09 20:04 . 2013-07-09 20:04 333312 ----a-w- c:\windows\system32\d3d10_1core.dll
2013-07-09 20:04 . 2013-07-09 20:04 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-07-09 20:04 . 2013-07-09 20:04 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-07-09 20:04 . 2013-07-09 20:04 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-07-09 20:04 . 2013-07-09 20:04 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-07-09 20:04 . 2013-07-09 20:04 296960 ----a-w- c:\windows\system32\d3d10core.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2011-08-30 3077528]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-21 19875432]
"ConduitFloatingPlugin_mfchmfgdaabgdjbcaophikcobddojjoe"="c:\program files (x86)\Conduit\CT3298573\plugins\TBVerifier.dll" [1623-04-06 287008]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-09-13 283160]
"AlienwareOn-ScreenDisplay"="c:\program files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe" [2011-09-03 1636208]
"Integrated Webcam Live! Central"="c:\program files (x86)\Integrated Webcam\Live! Central\WebcamInt.exe" [2010-08-19 487562]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-06-10 336384]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe" [2013-01-28 356376]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-22 59720]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-05-31 152392]
.
c:\users\Leeanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE /tsr [2013-1-8 246368]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventSystem]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ioloSystemService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 btwampfl;btwampfl;c:\windows\system32\drivers\btwampfl.sys;c:\windows\SYSNATIVE\drivers\btwampfl.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 NETwNx64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 64 Bit;c:\windows\system32\DRIVERS\NETwNx64.sys;c:\windows\SYSNATIVE\DRIVERS\NETwNx64.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBPNPA;USB PnP Sound Device Interface;c:\windows\system32\drivers\CM10864.sys;c:\windows\SYSNATIVE\drivers\CM10864.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
R4 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [x]
R4 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [x]
R4 SftService;SoftThinks Agent Service;c:\program files (x86)\AlienRespawn\sftservice.EXE;c:\program files (x86)\AlienRespawn\sftservice.EXE [x]
S0 EMSC;COMPAL Embedded System Control;c:\windows\system32\DRIVERS\EMSC.SYS;c:\windows\SYSNATIVE\DRIVERS\EMSC.SYS [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys;c:\windows\SYSNATIVE\DRIVERS\stdcfltn.sys [x]
S1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\ElRawDsk.sys;c:\windows\SYSNATIVE\drivers\ElRawDsk.sys [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x]
S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe;c:\program files\IDT\WDM\AESTSr64.exe [x]
S2 AlienFusionService;Alienware Fusion Service;c:\program files\Alienware\Command Center\AlienFusionService.exe;c:\program files\Alienware\Command Center\AlienFusionService.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 ioloSystemService;iolo System Service;c:\program files (x86)\iolo\Common\Lib\ioloServiceManager.exe;c:\program files (x86)\iolo\Common\Lib\ioloServiceManager.exe [x]
S2 PDFsFilter;PDFsFilter;c:\windows\system32\DRIVERS\PDFsFilter.sys;c:\windows\SYSNATIVE\DRIVERS\PDFsFilter.sys [x]
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys;c:\windows\SYSNATIVE\DRIVERS\Accelern.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys;c:\windows\SYSNATIVE\DRIVERS\CtClsFlt.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys;c:\windows\SYSNATIVE\DRIVERS\igdpmd64.sys [x]
S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-04 03:58 1173456 ----a-w- c:\program files (x86)\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-08-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-17 20:40]
.
2013-08-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-17 20:40]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"Command Center Controllers"="c:\program files\Alienware\Command Center\AWCCStartupOrchestrator.exe" [2010-11-10 13256]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-01-05 1933584]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-07-29 168216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-07-29 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-07-29 416024]
"Cm108Sound"="c:\windows\Syswow64\cm108.dll" [2013-08-08 8757248]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-03-21 525312]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.google.com
uInternet Settings,ProxyOverride = <local>;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: dell.com
TCP: DhcpNameServer = 24.25.227.55 209.18.47.61 24.25.227.53
.
.
------- File Associations -------
.
JSEFile=NOTEPAD.EXE %1
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
SafeBoot-AMP
SafeBoot-AMPSE
SafeBoot-vseamps
SafeBoot-vsedsps
SafeBoot-vseqrts
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-91864707-2432924159-1644299569-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-91864707-2432924159-1644299569-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_171_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_171_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-08-08 16:24:03
ComboFix-quarantined-files.txt 2013-08-09 02:24
.
Pre-Run: 490,785,763,328 bytes free
Post-Run: 490,338,775,040 bytes free
.
- - End Of File - - 8F3A2AECA8DCB599EA0773DF946AA293
D41D8CD98F00B204E9800998ECF8427E