ComboFix 12-10-04.02 - Melissa 10/07/2012 14:36:29.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4095.1794 [GMT -4:00]
Running from: c:\users\Melissa\Downloads\ComboFix.exe
AV: ESET Smart Security 5.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET Personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 5.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\SET7086.tmp
c:\windows\SysWow64\SET9F8B.tmp
.
.
((((((((((((((((((((((((( Files Created from 2012-09-07 to 2012-10-07 )))))))))))))))))))))))))))))))
.
.
2012-10-07 18:47 . 2012-10-07 18:47 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2012-10-07 18:47 . 2012-10-07 18:47 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-10-07 18:47 . 2012-10-07 18:47 -------- d-----w- c:\users\Mcx1-TASTEYCAKES-HP\AppData\Local\temp
2012-10-07 18:47 . 2012-10-07 18:47 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-10-07 07:00 . 2012-10-07 07:01 -------- d-----w- C:\1153cc263f688a0653c5
2012-10-07 06:21 . 2012-10-07 06:23 -------- d-----w- C:\e7799947958651ca0a0f4baa56fc2c5d
2012-10-07 06:19 . 2012-10-07 06:19 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{44650D84-5D01-4E3A-939A-5D04455FDBD1}\offreg.dll
2012-10-07 06:09 . 2012-09-19 04:58 9308616 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{44650D84-5D01-4E3A-939A-5D04455FDBD1}\mpengine.dll
2012-10-07 03:45 . 2012-10-07 03:45 -------- d-----w- C:\temp
2012-10-07 03:44 . 2012-10-07 03:45 -------- d-----w- c:\windows\LastGood
2012-10-07 03:02 . 2012-10-07 03:02 -------- d-----w- c:\users\Melissa\AppData\Local\ESET
2012-10-07 02:59 . 2012-10-07 02:59 -------- d-----w- c:\program files\ESET
2012-10-06 16:38 . 2012-10-06 16:38 -------- d-----w- c:\program files (x86)\ESET
2012-10-06 12:39 . 2012-10-06 12:39 -------- d-----w- c:\users\Melissa\AppData\Local\Secunia PSI
2012-10-06 12:36 . 2012-10-06 12:36 -------- d-----w- c:\program files (x86)\Secunia
2012-10-05 01:00 . 2012-10-05 01:00 -------- d-----w- c:\users\Melissa\AppData\Local\red 5 studios
2012-10-05 00:19 . 2012-10-05 00:19 -------- d-----w- c:\program files (x86)\Xiph.Org
2012-10-05 00:19 . 2012-10-05 00:19 -------- d-----w- c:\program files (x86)\Red 5 Studios
2012-10-04 23:05 . 2012-10-05 17:20 -------- d-----w- c:\users\Melissa\AppData\Local\Windows Live
2012-10-04 16:31 . 2012-10-04 16:31 -------- d-----w- c:\program files (x86)\Microsoft Chart Controls
2012-10-04 16:24 . 2012-10-04 16:24 -------- d-----w- c:\users\Melissa\AppData\Local\Demo2
2012-10-04 16:24 . 2012-10-04 16:24 -------- d-----w- c:\users\Melissa\AppData\Local\GameMaker_Player
2012-10-04 15:21 . 2012-10-04 15:21 -------- d-----w- c:\users\Melissa\AppData\Local\gamemaker_studio
2012-10-04 15:21 . 2012-10-04 15:21 -------- d-----w- c:\programdata\gamemaker_studio
2012-10-04 06:41 . 2012-10-04 16:53 -------- d-----w- c:\programdata\Hi-Rez Studios
2012-10-04 06:40 . 2012-10-04 06:41 -------- d-----w- c:\program files (x86)\Hi-Rez Studios
2012-09-25 23:45 . 2012-08-21 21:01 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
2012-09-24 14:40 . 2012-09-24 14:40 -------- d-----w- c:\programdata\boost_interprocess
2012-09-21 16:49 . 2012-09-21 16:49 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2012-09-21 15:05 . 2012-09-21 15:05 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins
2012-09-21 14:56 . 2012-09-21 16:52 -------- d-----w- c:\programdata\EA Logs
2012-09-21 04:22 . 2012-09-21 04:22 -------- d--h--w- c:\program files (x86)\Common Files\EAInstaller
2012-09-21 01:21 . 2012-09-21 01:27 -------- d-----w- c:\program files (x86)\Origin Games
2012-09-21 01:21 . 2012-09-21 01:22 -------- d-----w- c:\users\Melissa\AppData\Roaming\Origin
2012-09-21 01:21 . 2012-09-21 14:56 -------- d-----w- c:\users\Melissa\AppData\Local\Origin
2012-09-21 01:19 . 2012-09-21 01:25 -------- d-----w- c:\programdata\Origin
2012-09-21 01:19 . 2012-09-21 01:21 -------- d-----w- c:\program files (x86)\Origin
2012-09-20 21:42 . 2012-09-20 21:42 -------- d-----w- c:\users\Melissa\AppData\Local\Desura
2012-09-20 21:41 . 2012-09-20 21:41 -------- d-----w- c:\program files (x86)\Common Files\Desura
2012-09-20 21:36 . 2012-09-20 21:36 -------- d-----w- c:\programdata\Desura
2012-09-20 21:36 . 2012-09-20 21:42 -------- d-----w- c:\program files (x86)\Desura
2012-09-20 01:51 . 2007-09-07 22:20 -------- d-----w- C:\hidden
2012-09-15 18:04 . 2012-08-21 17:01 33240 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-09-15 18:03 . 2012-09-15 18:03 -------- d-----w- c:\program files\iPod
2012-09-15 18:03 . 2012-09-15 18:04 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-09-15 18:03 . 2012-09-15 18:04 -------- d-----w- c:\program files\iTunes
2012-09-15 17:58 . 2012-09-15 17:58 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-09-15 17:58 . 2012-09-15 17:58 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-09-15 17:58 . 2012-09-15 17:58 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-09-15 17:58 . 2012-09-15 17:58 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-09-15 17:58 . 2012-09-15 17:58 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-09-15 17:58 . 2012-09-15 17:58 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-09-15 17:58 . 2012-09-15 17:58 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-09-12 12:45 . 2012-08-22 18:12 950128 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-09-12 12:45 . 2012-07-04 20:26 41472 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-12 12:45 . 2012-08-02 17:58 574464 ----a-w- c:\windows\system32\d3d10level9.dll
2012-09-12 12:45 . 2012-08-02 16:57 490496 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2012-09-12 12:45 . 2012-08-22 18:12 1913200 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-12 12:45 . 2012-08-22 18:12 376688 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-12 12:45 . 2012-08-22 18:12 288624 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-09 03:43 . 2012-09-30 04:09 -------- d-----w- c:\users\Melissa\AppData\Roaming\.minecraft
2012-09-09 03:41 . 2012-09-09 03:47 -------- d-----w- c:\program files (x86)\Minecraft
2012-09-09 03:22 . 2012-09-09 03:22 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-09-09 03:22 . 2012-09-09 03:22 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-09-09 03:14 . 2012-09-09 03:14 289768 ----a-w- c:\windows\system32\javaws.exe
2012-09-09 03:14 . 2012-09-09 03:14 108008 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2012-09-09 03:14 . 2012-09-09 03:14 189416 ----a-w- c:\windows\system32\javaw.exe
2012-09-09 03:14 . 2012-09-09 03:14 188904 ----a-w- c:\windows\system32\java.exe
2012-09-09 03:14 . 2012-09-09 03:14 -------- d-----w- c:\program files\Java
2012-09-09 01:07 . 2012-09-22 02:04 -------- d-----w- c:\program files\Nightly
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-25 23:52 . 2011-06-14 05:53 281520 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-09-25 23:52 . 2011-05-15 03:39 281520 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-09-25 23:52 . 2011-05-15 03:39 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-09-22 02:50 . 2011-05-15 03:39 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-09-21 08:06 . 2012-04-12 12:46 696240 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-09-21 08:06 . 2011-06-03 04:59 73136 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-09-13 06:17 . 2011-02-28 10:40 64462936 ----a-w- c:\windows\system32\MRT.exe
2012-09-09 03:22 . 2012-06-15 17:52 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-09-09 03:22 . 2011-02-28 10:02 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-09-09 03:14 . 2012-08-24 16:46 916456 ----a-w- c:\windows\system32\deployJava1.dll
2012-09-09 03:14 . 2012-08-24 16:46 1034216 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-07 21:04 . 2012-08-04 02:45 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-06 01:57 . 2012-09-06 01:57 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-09-06 01:57 . 2012-09-06 01:57 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-09-06 01:57 . 2012-09-06 01:57 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-09-06 01:57 . 2012-09-06 01:57 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-09-06 01:57 . 2012-09-06 01:57 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-09-06 01:57 . 2012-09-06 01:57 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-09-06 01:57 . 2012-09-06 01:57 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-09-06 01:57 . 2012-09-06 01:57 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-09-06 01:57 . 2012-09-06 01:57 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-09-06 01:57 . 2012-09-06 01:57 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-09-06 01:57 . 2012-09-06 01:57 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-09-06 01:57 . 2012-09-06 01:57 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-09-06 01:57 . 2012-09-06 01:57 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-09-06 01:57 . 2012-09-06 01:57 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-09-06 01:57 . 2012-09-06 01:57 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-09-06 01:57 . 2012-09-06 01:57 222208 ----a-w- c:\windows\system32\msls31.dll
2012-09-06 01:57 . 2012-09-06 01:57 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-09-06 01:57 . 2012-09-06 01:57 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-09-06 01:57 . 2012-09-06 01:57 65024 ----a-w- c:\windows\system32\pngfilt.dll
2012-09-06 01:57 . 2012-09-06 01:57 55296 ----a-w- c:\windows\system32\msfeedsbs.dll
2012-09-06 01:57 . 2012-09-06 01:57 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-09-06 01:57 . 2012-09-06 01:57 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-09-06 01:57 . 2012-09-06 01:57 267776 ----a-w- c:\windows\system32\ieaksie.dll
2012-09-06 01:57 . 2012-09-06 01:57 197120 ----a-w- c:\windows\system32\msrating.dll
2012-09-06 01:57 . 2012-09-06 01:57 163840 ----a-w- c:\windows\system32\ieakui.dll
2012-09-06 01:57 . 2012-09-06 01:57 160256 ----a-w- c:\windows\system32\ieakeng.dll
2012-09-06 01:57 . 2012-09-06 01:57 149504 ----a-w- c:\windows\system32\occache.dll
2012-09-06 01:57 . 2012-09-06 01:57 145920 ----a-w- c:\windows\system32\iepeers.dll
2012-09-06 01:57 . 2012-09-06 01:57 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-09-06 01:57 . 2012-09-06 01:57 12288 ----a-w- c:\windows\system32\mshta.exe
2012-09-06 01:57 . 2012-09-06 01:57 114176 ----a-w- c:\windows\system32\admparse.dll
2012-09-06 01:57 . 2012-09-06 01:57 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-09-06 01:57 . 2012-09-06 01:57 10752 ----a-w- c:\windows\system32\msfeedssync.exe
2012-09-06 01:57 . 2012-09-06 01:57 89088 ----a-w- c:\windows\system32\ie4uinit.exe
2012-09-06 01:57 . 2012-09-06 01:57 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-09-06 01:57 . 2012-09-06 01:57 82432 ----a-w- c:\windows\system32\icardie.dll
2012-09-06 01:57 . 2012-09-06 01:57 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-09-06 01:57 . 2012-09-06 01:57 534528 ----a-w- c:\windows\system32\ieapfltr.dll
2012-09-06 01:57 . 2012-09-06 01:57 452608 ----a-w- c:\windows\system32\dxtmsft.dll
2012-09-06 01:57 . 2012-09-06 01:57 448512 ----a-w- c:\windows\system32\html.iec
2012-09-06 01:57 . 2012-09-06 01:57 403248 ----a-w- c:\windows\system32\iedkcs32.dll
2012-09-06 01:57 . 2012-09-06 01:57 39936 ----a-w- c:\windows\system32\iernonce.dll
2012-09-06 01:57 . 2012-09-06 01:57 3695416 ----a-w- c:\windows\system32\ieapfltr.dat
2012-09-06 01:57 . 2012-09-06 01:57 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-09-06 01:57 . 2012-09-06 01:57 282112 ----a-w- c:\windows\system32\dxtrans.dll
2012-09-06 01:57 . 2012-09-06 01:57 249344 ----a-w- c:\windows\system32\webcheck.dll
2012-09-06 01:57 . 2012-09-06 01:57 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-09-06 01:57 . 2012-09-06 01:57 160256 ----a-w- c:\windows\system32\wextract.exe
2012-09-06 01:57 . 2012-09-06 01:57 103936 ----a-w- c:\windows\system32\inseng.dll
2012-08-30 19:14 . 2011-10-29 02:55 2422120 ----a-w- c:\windows\SysWow64\nvapi.dll
2012-08-30 19:14 . 2011-10-29 02:55 1760104 ----a-w- c:\windows\system32\nvdispco64.dll
2012-08-30 19:14 . 2010-07-10 13:38 2725224 ----a-w- c:\windows\system32\nvapi64.dll
2012-08-30 19:14 . 2010-07-10 13:38 12465512 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2012-08-30 19:14 . 2009-07-13 21:59 14879080 ----a-w- c:\windows\system32\nvwgf2umx.dll
2012-08-30 16:18 . 2010-07-10 00:27 891240 ----a-w- c:\windows\system32\nvvsvc.exe
2012-08-30 16:18 . 2010-07-10 00:27 63336 ----a-w- c:\windows\system32\nvshext.dll
2012-08-30 16:18 . 2010-07-10 00:27 118120 ----a-w- c:\windows\system32\nvmctray.dll
2012-08-30 16:18 . 2010-07-10 00:27 3266920 ----a-w- c:\windows\system32\nvsvc64.dll
2012-08-30 16:17 . 2010-07-10 00:27 6198120 ----a-w- c:\windows\system32\nvcpl.dll
2012-08-30 14:40 . 2012-08-30 14:40 429416 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2012-08-21 17:01 . 2011-02-28 10:16 125872 ----a-w- c:\windows\system32\GEARAspi64.dll
2012-08-21 17:01 . 2011-02-28 10:16 106928 ----a-w- c:\windows\SysWow64\GEARAspi.dll
2012-07-18 18:15 . 2012-08-14 20:06 3148800 ----a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files (x86)\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll" [2011-01-21 213816]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2011-08-29 3077528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"PDF Complete"="c:\program files (x86)\PDF Complete\pdfsty.exe" [2010-09-28 664600]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-28 59280]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-09-10 421776]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
GamersFirst LIVE!.lnk - c:\program files (x86)\GamersFirst\LIVE!\Live.exe [2011-8-15 2589808]
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2012-9-24 573536]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2012-1-24 16032]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
2;2 cvhsvc;Client Virtualization Handler [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-21 250288]
R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-05-11 6790656]
R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-05-11 221184]
R3 Desura Install Service;Desura Install Service;c:\program files (x86)\Common Files\Desura\desura_service.exe [2012-09-20 131912]
R3 DrvAgent64;DrvAgent64;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS [2011-12-19 21712]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-06 114144]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys [2010-07-22 1002848]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe [2012-07-19 738152]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-02-28 1255736]
R3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\Zune\WMZuneComm.exe [2010-11-11 306416]
R3 X6va005;X6va005;c:\users\Melissa\AppData\Local\Temp\005742C.tmp [x]
R4 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [2010-08-13 75904]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [2010-08-13 38016]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2012-03-14 62496]
S0 RapportKE64;RapportKE64;c:\windows\System32\Drivers\RapportKE64.sys [2011-11-08 63760]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2012-03-14 209768]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2012-03-14 148528]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [2012-03-14 38288]
S1 RapportCerberus_34302;RapportCerberus_34302;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\34302\RapportCerberus64_34302.sys [2011-12-15 397520]
S1 RapportEI64;RapportEI64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2011-11-08 55056]
S1 RapportPG64;RapportPG64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2011-11-08 61712]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-05-11 203264]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2012-03-07 913144]
S2 FlipShareServer;FlipShare Server;c:\program files (x86)\Flip Video\FlipShareServer\FlipShareServer.exe [2010-12-15 1085440]
S2 Giraffic;Veoh Giraffic Video Accelerator;c:\program files (x86)\Giraffic\Veoh_GirafficWatchdog.exe [2012-07-02 2232504]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-08-29 2369960]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-09 86072]
S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-08-06 291896]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-28 94264]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-07 399432]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-07 676936]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-08-30 1258856]
S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe [2010-09-28 1119768]
S2 RapportMgmtService;Rapport Management Service;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2011-11-08 931640]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2012-09-24 1328736]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2012-09-24 656480]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-08-30 382312]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-07 25928]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2011-12-16 17976]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-09-03 349800]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-12 08:06]
.
2012-09-09 c:\windows\Tasks\HPCeeScheduleForMelissa.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]
.
2012-09-25 c:\windows\Tasks\HPCeeScheduleForTASTEYCAKES-HP$.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2010-09-15 611896]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2012-03-07 4081008]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mDefault_Page_URL = hxxp://
www.yahoo.com
mStart Page = hxxp://
www.yahoo.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
FF - ProfilePath - c:\users\Melissa\AppData\Roaming\Mozilla\Firefox\Profiles\gid5nsgr.default\
FF - prefs.js: browser.startup.homepage - hxxp://
www.yahoo.com/
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
WebBrowser-{CD90BF73-20F6-44EF-993D-BB920303BD2E} - (no file)
WebBrowser-{687578B9-7132-4A7A-80E4-30EE31099E03} - (no file)
AddRemove-{6F44AF95-3CDE-4513-AD3F-6D45F17BF324} - c:\program files (x86)\InstallShield Installation Information\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va005]
"ImagePath"="\??\c:\users\Melissa\AppData\Local\Temp\005742C.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-631818756-1652327538-4216934692-1000\Software\SecuROM\License information*]
"datasecu"=hex:0f,23,db,04,f9,fc,2c,96,3f,ae,f6,63,a5,43,15,71,60,02,fc,3b,b8,
aa,c4,99,50,f2,ba,60,15,7f,1f,f3,1f,53,46,ca,5b,10,14,66,cb,f1,56,2c,b8,69,\
"rkeysecu"=hex:df,80,1b,41,9e,10,4b,52,c7,c1,f5,5e,c2,ad,db,f1
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-10-07 14:50:16
ComboFix-quarantined-files.txt 2012-10-07 18:50
ComboFix2.txt 2012-10-05 19:05
.
Pre-Run: 475,080,794,112 bytes free
Post-Run: 474,942,537,728 bytes free
.
- - End Of File - - 95AE8EA6845EF8C60E7A36D34DF0D6D2