Computer is running much better. Thanks so much, Gringo. No problems in running Combofix. This may be my last post for the night. Need to get some sleep
Report from Combofix:
ComboFix 12-04-07.02 - Technicyst Fix 04/08/2012 0:09.2.8 - x64
Running from: c:\users\Technicyst Fix\Downloads\ComboFix.exe
Command switches used :: c:\users\Technicyst Fix\Desktop\CFScript.txt
* Resident AV is active
.
.
.
((((((((((((((((((((((((( Files Created from 2012-03-08 to 2012-04-08 )))))))))))))))))))))))))))))))
.
.
2012-04-08 05:25 . 2012-04-08 05:25 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-04-08 03:38 . 2012-04-08 03:38 -------- d-----w- C:\TDSSKiller_Quarantine
2012-04-07 23:36 . 2012-04-07 23:37 -------- d-----w- C:\FRST
2012-04-07 17:14 . 2012-04-07 17:12 105552 ----a-w- c:\windows\system32\drivers\tmtdi.sys
2012-04-07 17:14 . 2012-04-07 17:12 90704 ----a-w- c:\windows\system32\drivers\tmactmon.sys
2012-04-07 17:14 . 2012-04-07 17:12 67664 ----a-w- c:\windows\system32\drivers\tmevtmgr.sys
2012-04-07 17:14 . 2012-04-07 17:12 144464 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2012-04-05 23:46 . 2012-04-07 17:13 -------- d-----w- c:\program files\Trend Micro
2012-04-05 23:45 . 2012-04-07 17:14 -------- d-----w- c:\programdata\Trend Micro
2012-04-05 23:31 . 2012-04-06 03:23 -------- d-----w- c:\program files (x86)\Trend Micro
2012-04-05 00:09 . 2012-04-07 15:58 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-04-04 16:31 . 2012-04-04 16:32 -------- d-----w- c:\windows\system32\EventProviders
2012-04-04 16:31 . 2012-04-07 15:58 -------- d-----w- C:\317d460ecafc1cdb9243
2012-03-31 14:13 . 2012-03-31 14:13 -------- d-----w- c:\programdata\PreSonus
2012-03-31 14:13 . 2012-03-31 14:13 -------- d-----w- c:\users\Technicyst Fix\AppData\Roaming\PreSonus
2012-03-31 14:13 . 2011-07-07 16:42 34152 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-03-31 14:12 . 2012-04-07 15:58 -------- d-----w- c:\program files\PreSonus
2012-03-29 21:18 . 2012-04-07 15:58 -------- d-----w- c:\users\Technicyst Fix\AppData\Roaming\McAfee
2012-03-28 19:42 . 2012-03-28 19:42 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-03-28 19:42 . 2012-03-28 19:42 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-03-28 19:41 . 2012-03-28 19:41 -------- d-----w- c:\windows\system32\Macromed
2012-03-19 23:00 . 2012-03-19 23:00 -------- d-----w- c:\users\Technicyst Fix\AppData\Local\blekkotb
2012-03-17 04:05 . 2012-03-17 04:05 -------- d-----w- c:\users\Technicyst Fix\AppData\Roaming\Renoise Plugin Server
2012-03-17 00:32 . 2012-03-17 00:32 -------- d-----w- c:\program files\Renoise 2.8.0
2012-03-15 08:01 . 2011-11-19 18:30 5504880 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-15 08:01 . 2011-11-19 14:25 3957616 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-03-15 08:01 . 2011-11-19 14:25 3902320 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-03-13 16:44 . 2012-03-13 16:44 -------- d-----w- c:\users\Technicyst Fix\AppData\Roaming\Cocoon Software
2012-03-13 16:44 . 2012-03-13 16:46 -------- d-----w- c:\program files\QuickMediaConverter
2012-03-13 16:43 . 2012-03-13 16:43 -------- d-----w- c:\users\Technicyst Fix\AppData\Local\WDSetup
2012-03-11 16:12 . 2012-03-11 16:12 -------- d-----w- c:\program files (x86)\ApecSoft
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-02 09:06 . 2012-03-02 09:06 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-03-02 09:06 . 2012-03-02 09:06 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-03-02 09:06 . 2012-03-02 09:06 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-03-02 09:06 . 2012-03-02 09:06 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-03-02 09:06 . 2012-03-02 09:06 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-03-02 09:06 . 2012-03-02 09:06 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-03-02 09:06 . 2012-03-02 09:06 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-03-02 09:06 . 2012-03-02 09:06 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-03-02 09:06 . 2012-03-02 09:06 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-03-02 09:06 . 2012-03-02 09:06 603648 ----a-w- c:\windows\system32\vbscript.dll
2012-03-02 09:06 . 2012-03-02 09:06 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-03-02 09:06 . 2012-03-02 09:06 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-03-02 09:06 . 2012-03-02 09:06 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-03-02 09:06 . 2012-03-02 09:06 448512 ----a-w- c:\windows\system32\html.iec
2012-03-02 09:06 . 2012-03-02 09:06 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2012-03-02 09:06 . 2012-03-02 09:06 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-03-02 09:06 . 2012-03-02 09:06 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-03-02 09:06 . 2012-03-02 09:06 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-03-02 09:06 . 2012-03-02 09:06 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2012-03-02 09:06 . 2012-03-02 09:06 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-03-02 09:06 . 2012-03-02 09:06 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-03-02 09:06 . 2012-03-02 09:06 2308096 ----a-w- c:\windows\system32\jscript9.dll
2012-03-02 09:06 . 2012-03-02 09:06 222208 ----a-w- c:\windows\system32\msls31.dll
2012-03-02 09:06 . 2012-03-02 09:06 1798656 ----a-w- c:\windows\SysWow64\jscript9.dll
2012-03-02 09:06 . 2012-03-02 09:06 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2012-03-02 09:06 . 2012-03-02 09:06 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-03-02 09:06 . 2012-03-02 09:06 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-03-02 09:06 . 2012-03-02 09:06 160256 ----a-w- c:\windows\system32\wextract.exe
2012-03-02 09:06 . 2012-03-02 09:06 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-03-02 09:06 . 2012-03-02 09:06 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-03-02 09:06 . 2012-03-02 09:06 1493504 ----a-w- c:\windows\system32\inetcpl.cpl
2012-03-02 09:06 . 2012-03-02 09:06 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2012-03-02 09:06 . 2012-03-02 09:06 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2012-03-02 09:06 . 2012-03-02 09:06 1390080 ----a-w- c:\windows\system32\wininet.dll
2012-03-02 09:06 . 2012-03-02 09:06 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-03-02 09:06 . 2012-03-02 09:06 12288 ----a-w- c:\windows\system32\mshta.exe
2012-03-02 09:06 . 2012-03-02 09:06 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-03-02 09:06 . 2012-03-02 09:06 114176 ----a-w- c:\windows\system32\admparse.dll
2012-03-02 09:06 . 2012-03-02 09:06 1127424 ----a-w- c:\windows\SysWow64\wininet.dll
2012-03-02 09:06 . 2012-03-02 09:06 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-03-02 09:06 . 2012-03-02 09:06 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-03-02 09:06 . 2012-03-02 09:06 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-01-22 19:17 . 2012-01-22 19:17 485576 ----a-w- c:\users\Technicyst Fix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Catalina Marketing Corp\UninstallCouponActivator.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2012-04-07_16.24.12 )))))))))))))))))))))))))))))))))))))))))
.
- 2012-04-07 16:22 . 2012-04-07 16:22 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-04-08 05:27 . 2012-04-08 05:27 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-04-07 16:22 . 2012-04-07 16:22 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-04-08 05:27 . 2012-04-08 05:27 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 05:01 . 2012-04-08 05:26 427032 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2012-04-07 16:21 427032 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2010-04-30 04:33 . 2012-04-08 05:26 2630828 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-328288376-2029984636-2289590902-1001-8192.dat
- 2010-04-30 04:33 . 2012-04-07 16:21 2630828 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-328288376-2029984636-2289590902-1001-8192.dat
+ 2012-04-07 17:12 . 2012-04-07 17:12 1282560 c:\windows\Installer\2ebf60.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"Steam"="c:\program files (x86)\steam\steam.exe" [2011-08-03 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Dell DataSafe Online"="c:\program files (x86)\Dell DataSafe Online\DataSafeOnline.exe" [2009-11-13 1807600]
"PDVDDXSrv"="c:\program files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520]
"DellSupportCenter"="c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-27 30040]
"Dell PanelMgr"="c:\windows\Dell\PanelMgr\SSMMgr.exe" [2009-05-09 541936]
"2335dn Scan2PC"="c:\windows\twain_32\Dell\Dell2335\Scan2Pc.exe" [2008-09-26 495616]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"AsioThk32Reg"="CTASIO.DLL" [2010-02-23 51712]
"CTHelper"="CTHELPER.EXE" [2010-02-24 23040]
"CTxfiHlp"="CTXFIHLP.EXE" [2010-02-24 23552]
"SAOB Monitor"="c:\program files (x86)\Acronis\TrueImageHome\OnlineBackupStandalone\TrueImageMonitor.exe" [2010-11-16 2536448]
"TrueImageMonitor.exe"="c:\program files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" [2011-02-02 5546376]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-01-16 421736]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-04 37296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"="c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [2011-10-08 559616]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 0242461333814782mcinstcleanup;McAfee Application Installer Cleanup (0242461333814782);c:\users\TECHNI~1\AppData\Local\Temp\024246~1.EXE [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [x]
R2 MOBCleanup;MOBCleanup;c:\users\Technicyst Fix\AppData\Local\Temp\MOBCleanup.exe [x]
R2 SessionLauncher;SessionLauncher;c:\users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-28 253600]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-03-01 183560]
R3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;c:\windows\system32\drivers\BVRPMPR5a64.SYS [x]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x]
R3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.SYS [x]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2010-04-15 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-04-15 79360]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [x]
R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [x]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\System32\drivers\CTAUDFX.SYS [x]
R3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.SYS [x]
R3 CTEAPSFX.SYS;CTEAPSFX.SYS;c:\windows\System32\drivers\CTEAPSFX.SYS [x]
R3 CTEAPSFX;CTEAPSFX;c:\windows\system32\drivers\CTEAPSFX.SYS [x]
R3 CTEDSPFX;CTEDSPFX;c:\windows\system32\drivers\CTEDSPFX.SYS [x]
R3 CTEDSPIO;CTEDSPIO;c:\windows\system32\drivers\CTEDSPIO.SYS [x]
R3 CTEDSPSY;CTEDSPSY;c:\windows\system32\drivers\CTEDSPSY.SYS [x]
R3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\System32\drivers\CTERFXFX.SYS [x]
R3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.SYS [x]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [x]
R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [x]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [x]
R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [x]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\System32\drivers\CTSBLFX.SYS [x]
R3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.SYS [x]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x]
R3 NvnUsbAudio;Novation USB Audio Driver;c:\windows\system32\DRIVERS\nvnusbaudio.sys [x]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-26 1124848]
R3 SynasUSB;SynasUSB;c:\windows\system32\drivers\SynUSB64.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [x]
R3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\Zune\WMZuneComm.exe [2010-09-24 306416]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);c:\windows\system32\DRIVERS\tdrpm273.sys [x]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x]
S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 afcdpsrv;Acronis Nonstop Backup Service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2011-05-24 3246040]
S2 Amsp;Trend Micro Solution Platform;c:\program files\Trend Micro\AMSP\coreServiceShell.exe coreFrameworkHost.exe [x]
S2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe [2011-07-06 2304912]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-12-06 208536]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [x]
S2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2009-07-17 4948992]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2010-08-20 689472]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [x]
S2 tmevtmgr;tmevtmgr;c:\windows\system32\DRIVERS\tmevtmgr.sys [x]
S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [x]
S3 automap;Automap MIDI Driver Service;c:\windows\system32\DRIVERS\automap.sys [x]
S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\System32\drivers\COMMONFX.SYS [x]
S3 CTEDSPFX.SYS;CTEDSPFX.SYS;c:\windows\System32\drivers\CTEDSPFX.SYS [x]
S3 CTEDSPIO.SYS;CTEDSPIO.SYS;c:\windows\System32\drivers\CTEDSPIO.SYS [x]
S3 CTEDSPSY.SYS;CTEDSPSY.SYS;c:\windows\System32\drivers\CTEDSPSY.SYS [x]
S3 L6GX;Service - Line 6 GX;c:\windows\system32\Drivers\L6GX64.sys [x]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 synusb64;eLicenser;c:\windows\system32\DRIVERS\synusb64.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-08 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-28 19:42]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-10-03 8158240]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2010-09-24 163568]
"Acronis Scheduler2 Service"="c:\program files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" [2011-02-02 390720]
"Trend Micro Titanium"="c:\program files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe" [2011-10-08 1111568]
"Trend Micro Client Framework"="c:\program files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe" [2011-02-10 197152]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
imagedrv
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000
Trusted Zone: internet
Trusted Zone: line6.net
Trusted Zone: mcafee.com
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
FF - ProfilePath - c:\users\Technicyst Fix\AppData\Roaming\Mozilla\Firefox\Profiles\ezd5qmvd.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe
c:\program files (x86)\Sony\Content Manager Assistant\CMA.exe
c:\program files (x86)\Common Files\Panasonic\HD Writer AutoStart\HDWriterAutoStart.exe
c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
c:\windows\SysWOW64\CTHELPER.EXE
c:\program files (x86)\Sony\Content Manager Assistant\CMAWatcher.exe
c:\program files (x86)\Creative Professional\Digital Audio System\E-MU PatchMix DSP\EmuPMixDSP.exe
c:\program files (x86)\Dell Support Center\bin\sprtsvc.exe
c:\program files (x86)\Mozilla Firefox\firefox.exe
.
**************************************************************************
.
Completion time: 2012-04-08 00:37:35 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-08 05:37
ComboFix2.txt 2012-04-07 16:32
.
Pre-Run: 197,404,557,312 bytes free
Post-Run: 197,250,129,920 bytes free
.
- - End Of File - - B73A2B5E4C180AFB7BBF3C47953761FA