hey Gringo, here is my Combofix log:
ComboFix 12-04-27.01 - mark's 27/04/2012 13:51:49.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.4063.2676 [GMT 1:00]
Running from: c:\users\mark's\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R5DVJE0U\ComboFix.exe
AV: Norton Internet Security *Disabled/Outdated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
AV: Virgin Media Security Anti-Virus *Disabled/Outdated* {A61154FD-4365-E00F-9A33-13A09AD54B56}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
FW: Virgin Media Security Firewall *Disabled* {9E2AD5D8-090A-E157-B16C-BA9564060C2D}
SP: Norton Internet Security *Disabled/Outdated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Virgin Media Security Anti-Spyware *Disabled/Outdated* {1D70B519-655F-EF81-A083-28D2E15201EB}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\program files (x86)\3
c:\program files (x86)\3\3Connect\3ConnectHelp.chm
c:\program files (x86)\3\3Connect\AceDb.encrypt
c:\program files (x86)\3\3Connect\AutoUpdateSrv.exe
c:\program files (x86)\3\3Connect\BlacklistedProcesses.xml
c:\program files (x86)\3\3Connect\capicom.dll
c:\program files (x86)\3\3Connect\CiscoApiWrapper.dll
c:\program files (x86)\3\3Connect\Config.encrypt
c:\program files (x86)\3\3Connect\Config.xml
c:\program files (x86)\3\3Connect\Config_23420.encrypt
c:\program files (x86)\3\3Connect\Config_23420.xml
c:\program files (x86)\3\3Connect\Config_27205.encrypt
c:\program files (x86)\3\3Connect\Config_27205.xml
c:\program files (x86)\3\3Connect\Config_Default.encrypt
c:\program files (x86)\3\3Connect\Config_Default.xml
c:\program files (x86)\3\3Connect\ConfigAup.encrypt
c:\program files (x86)\3\3Connect\ConfigAup.xml
c:\program files (x86)\3\3Connect\DeviceInstaller.exe
c:\program files (x86)\3\3Connect\Dialog.cfg
c:\program files (x86)\3\3Connect\Flash.ocx
c:\program files (x86)\3\3Connect\HuaweiE220.dll
c:\program files (x86)\3\3Connect\ImportConfiguration.exe
c:\program files (x86)\3\3Connect\InstallHelpers.dll
c:\program files (x86)\3\3Connect\LanDevice.dll
c:\program files (x86)\3\3Connect\Logger.dll
c:\program files (x86)\3\3Connect\mfc80u.dll
c:\program files (x86)\3\3Connect\Microsoft.VC80.CRT.manifest
c:\program files (x86)\3\3Connect\Microsoft.VC80.MFC.manifest
c:\program files (x86)\3\3Connect\modemcust.cfg
c:\program files (x86)\3\3Connect\modeminfo.cfg
c:\program files (x86)\3\3Connect\Modems\Huawei Modems.exe
c:\program files (x86)\3\3Connect\msvcp80.dll
c:\program files (x86)\3\3Connect\msvcr80.dll
c:\program files (x86)\3\3Connect\NetworkCodes.cfg
c:\program files (x86)\3\3Connect\OperatorList.xml
c:\program files (x86)\3\3Connect\OptGlobetrotterGTMax72.dll
c:\program files (x86)\3\3Connect\Res.dll
c:\program files (x86)\3\3Connect\Skins\FlashSkin\gui.swf
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\account.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\arrow_dwn.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\arrow_up.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\background_history.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\background_main.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\background_rss.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\background_sidebox.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\btn_back.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\btn_connect.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\btn_default.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\btn_disconnect.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\btn_login.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\btn_rssclose.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\btn_rssopen.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\exit.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\globe.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\graph.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\minimize.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\nr_sms.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\rgn_history.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\rgn_main.swf
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\rgn_rss.swf
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\roaming.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\signal.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\sms.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\tab_1.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\images\tab_2.png
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\settings\constructor.xml
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\settings\offline.xml
c:\program files (x86)\3\3Connect\Skins\FlashSkin\resources\settings\strings.xml
c:\program files (x86)\3\3Connect\Sms.xml
c:\program files (x86)\3\3Connect\SmsApp2.dll
c:\program files (x86)\3\3Connect\SoftOpt.encrypt
c:\program files (x86)\3\3Connect\Strings.txt
c:\program files (x86)\3\3Connect\SysConfig.dat
c:\program files (x86)\3\3Connect\SystemInfo.txt
c:\program files (x86)\3\3Connect\Update\ConfigAup.encrypt
c:\program files (x86)\3\3Connect\Update\ConfigAup.xml
c:\program files (x86)\3\3Connect\Wilog.exe
c:\program files (x86)\3\3Connect\WWanDevice.dll
c:\program files (x86)\3\3Connect\ZTE620.dll
c:\programdata\LJOBGq6J.exe
c:\users\mark's\AppData\Local\assembly\tmp
c:\users\mark's\AppData\Local\promo.exe
c:\users\Public\videos\HP MediaSmart Demo.exe
c:\windows\system32\consrv.dll
c:\windows\System64
c:\windows\SysWow64\Ir5FDD2.tmp
c:\windows\SysWow64\urttemp
c:\windows\SysWow64\urttemp\regtlib.exe
c:\windows\Tasks\At1.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At15.job
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_AMService
.
.
((((((((((((((((((((((((( Files Created from 2012-03-27 to 2012-04-27 )))))))))))))))))))))))))))))))
.
.
2012-04-27 13:06 . 2012-04-27 13:06 -------- d-----w- c:\users\Mcx1-MARKS-PC\AppData\Local\temp
2012-04-27 13:06 . 2012-04-27 13:06 -------- d-----w- c:\users\MARKS\AppData\Local\temp
2012-04-27 13:06 . 2012-04-27 13:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-04-25 14:52 . 2012-04-26 18:42 -------- d-----w- c:\programdata\Comodo
2012-04-25 14:52 . 2012-04-25 14:52 -------- d-----w- c:\program files\COMODO
2012-04-25 14:52 . 2012-04-25 14:52 -------- d-----w- c:\users\mark's\AppData\Local\Comodo
2012-04-25 14:51 . 2012-04-25 14:51 -------- d-----w- c:\program files (x86)\Comodo
2012-04-25 14:10 . 2012-04-25 14:10 -------- d-----w- c:\programdata\AVAST Software
2012-04-25 14:10 . 2012-04-25 14:10 -------- d-----w- c:\program files\AVAST Software
2012-04-24 17:39 . 2012-04-24 17:39 -------- d-----w- c:\users\mark's\AppData\Roaming\Malwarebytes
2012-04-24 17:38 . 2012-04-24 17:38 -------- d-----w- c:\programdata\Malwarebytes
2012-04-24 17:38 . 2012-04-25 18:48 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-04-24 16:38 . 2012-04-24 16:38 50000 ----a-w- c:\windows\system32\drivers\seewqemb.sys
2012-04-24 16:37 . 2012-04-24 16:37 50000 ----a-w- c:\windows\system32\drivers\adjdueyx.sys
2012-04-24 16:27 . 2010-04-09 11:06 374664 ----a-w- c:\windows\system32\drivers\netio.sys
2012-04-24 12:47 . 2012-04-25 18:48 -------- d-----w- C:\eb9e8a28380d1f1c67258fc8
2012-04-24 11:34 . 2012-04-24 11:34 -------- d-----w- c:\users\mark's\AppData\Roaming\Tific
2012-04-24 11:34 . 2012-04-24 11:34 -------- d-----w- c:\users\mark's\AppData\Local\Symantec
2012-04-24 10:21 . 2012-04-27 12:43 0 --sha-w- c:\windows\system32\dds_trash_log.cmd
2012-04-24 10:11 . 2012-04-24 10:22 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-24 10:11 . 2012-04-24 10:22 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-04-24 10:11 . 2012-04-24 10:11 -------- d-----w- c:\windows\system32\Macromed
2012-04-24 09:26 . 2012-04-18 02:03 8917360 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{67BC5790-5369-478A-AF30-8AEDE805F3D4}\mpengine.dll
2012-04-18 11:49 . 2012-04-18 11:49 -------- d-----w- c:\programdata\CCP
2012-04-17 23:22 . 2012-04-19 17:36 283416 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-04-17 23:22 . 2012-04-17 23:22 -------- d-----w- c:\users\mark's\AppData\Local\PunkBuster
2012-04-17 23:18 . 2012-04-19 17:36 283416 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-04-17 23:18 . 2012-04-18 15:08 283416 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-04-17 23:18 . 2012-04-17 23:18 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-04-17 23:16 . 2012-04-17 23:16 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2012-04-17 23:16 . 2012-04-17 23:16 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-04-17 21:07 . 2012-04-17 21:07 -------- d-----w- c:\program files (x86)\CCP
2012-04-17 16:03 . 2012-04-17 16:03 -------- d-----w- c:\users\mark's\AppData\Local\GamersFirst LIVE!
2012-04-17 16:02 . 2012-04-17 22:20 -------- d-----w- c:\program files (x86)\GamersFirst
2012-04-17 15:49 . 2012-04-17 15:49 -------- d-----w- c:\users\mark's\AppData\Local\CCP
2012-04-17 14:06 . 2012-04-17 14:06 -------- d-----w- c:\users\mark's\AppData\Local\NCSoft
2012-04-17 14:03 . 2012-04-17 14:03 -------- d-----w- C:\AMD
2012-04-17 13:34 . 2012-04-27 13:06 -------- d-----w- c:\users\mark's\AppData\Local\assembly
2012-04-17 13:33 . 2012-04-17 13:34 -------- d-----w- c:\program files (x86)\NCSoft
2012-04-14 02:00 . 2012-03-06 06:43 5504880 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-14 02:00 . 2012-03-06 05:59 3958128 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-04-14 02:00 . 2012-03-06 05:59 3902320 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-04-13 15:12 . 2012-03-01 06:54 22896 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-13 15:12 . 2012-03-01 06:40 80896 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-13 15:12 . 2012-03-01 05:45 158720 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-04-13 15:12 . 2012-03-01 06:45 220672 ----a-w- c:\windows\system32\wintrust.dll
2012-04-13 15:12 . 2012-03-01 05:49 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-04-13 15:12 . 2012-03-01 06:35 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-13 15:12 . 2012-03-01 05:40 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-04-02 12:44 . 2012-04-02 12:44 -------- d-----w- C:\Mechanical Programs
2012-04-02 12:44 . 2012-04-02 12:44 -------- d-----w- c:\program files (x86)\Wolsink
2012-03-29 19:10 . 2012-03-29 19:10 -------- d-----w- c:\users\mark's\AppData\Local\Autodesk, Inc
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-03 03:04 . 2012-03-03 03:04 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-03-03 03:04 . 2012-03-03 03:04 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-03-03 03:04 . 2012-03-03 03:04 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-03-03 03:04 . 2012-03-03 03:04 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-03-03 03:04 . 2012-03-03 03:04 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-03-03 03:04 . 2012-03-03 03:04 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-03-03 03:04 . 2012-03-03 03:04 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-03-03 03:04 . 2012-03-03 03:04 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2012-03-03 03:04 . 2012-03-03 03:04 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-03-03 03:04 . 2012-03-03 03:04 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-03-03 03:04 . 2012-03-03 03:04 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-03-03 03:04 . 2012-03-03 03:04 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-03-03 03:04 . 2012-03-03 03:04 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-03-03 03:04 . 2012-03-03 03:04 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-03-03 03:04 . 2012-03-03 03:04 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2012-03-03 03:04 . 2012-03-03 03:04 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-03-03 03:04 . 2012-03-03 03:04 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-03-03 03:04 . 2012-03-03 03:04 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-03-03 03:04 . 2012-03-03 03:04 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-03-03 03:04 . 2012-03-03 03:04 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-03-03 03:04 . 2012-03-03 03:04 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-03-03 03:04 . 2012-03-03 03:04 603648 ----a-w- c:\windows\system32\vbscript.dll
2012-03-03 03:04 . 2012-03-03 03:04 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-03-03 03:04 . 2012-03-03 03:04 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-03-03 03:04 . 2012-03-03 03:04 448512 ----a-w- c:\windows\system32\html.iec
2012-03-03 03:04 . 2012-03-03 03:04 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-03-03 03:04 . 2012-03-03 03:04 222208 ----a-w- c:\windows\system32\msls31.dll
2012-03-03 03:04 . 2012-03-03 03:04 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2012-03-03 03:04 . 2012-03-03 03:04 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-03-03 03:04 . 2012-03-03 03:04 160256 ----a-w- c:\windows\system32\wextract.exe
2012-03-03 03:04 . 2012-03-03 03:04 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-03-03 03:04 . 2012-03-03 03:04 12288 ----a-w- c:\windows\system32\mshta.exe
2012-03-03 03:04 . 2012-03-03 03:04 114176 ----a-w- c:\windows\system32\admparse.dll
2012-03-03 03:04 . 2012-03-03 03:04 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-02-23 09:18 . 2010-04-15 19:50 279656 ----a-w- c:\windows\system32\MpSigStub.exe
2012-02-15 06:27 . 2012-03-14 09:07 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-02-15 05:44 . 2012-03-14 09:07 826368 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-02-15 04:47 . 2012-03-14 09:07 204800 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-02-15 04:46 . 2012-03-14 09:07 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-02-10 06:18 . 2012-03-14 09:08 1541120 ----a-w- c:\windows\system32\DWrite.dll
2012-02-10 06:17 . 2012-03-14 09:08 1837568 ----a-w- c:\windows\system32\d3d10warp.dll
2012-02-10 06:17 . 2012-03-14 09:08 902656 ----a-w- c:\windows\system32\d2d1.dll
2012-02-10 06:17 . 2012-03-14 09:08 320512 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-02-10 06:17 . 2012-03-14 09:08 197120 ----a-w- c:\windows\system32\d3d10_1.dll
2012-02-10 05:41 . 2012-03-14 09:08 1074176 ----a-w- c:\windows\SysWow64\DWrite.dll
2012-02-10 05:41 . 2012-03-14 09:08 218624 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2012-02-10 05:41 . 2012-03-14 09:08 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2012-02-10 05:41 . 2012-03-14 09:08 1170944 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2012-02-10 05:41 . 2012-03-14 09:08 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2012-02-07 10:02 . 2012-02-07 10:02 1070352 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2012-02-03 04:16 . 2012-03-14 09:08 3143168 ----a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files (x86)\Vuze_Remote\prxtbVuze.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2011-05-09 08:49 176936 ----a-w- c:\program files (x86)\Vuze_Remote\prxtbVuze.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files (x86)\Vuze_Remote\prxtbVuze.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPADVISOR"="c:\program files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-10-25 1668664]
"LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2010-03-19 2363392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-09-27 59240]
"ServiceManager.exe"="c:\program files (x86)\Virgin Media\Service Manager\ServiceManager.exe" [2011-03-25 4371768]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-02-28 1987976]
.
c:\users\mark's\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Trivial Pursuit_ Unhinged Registration.lnk - c:\users\mark's\AppData\Local\Temp\{F2657087-AF0A-493D-BB1E-3A93922AB727}\{4E61888C-3D42-4691-AD25-E9AF648EAB63}\ATR1.EXE [N/A]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-31 1079584]
GamersFirst LIVE!.lnk - c:\program files (x86)\GamersFirst\LIVE!\Live.exe [2011-8-15 2589808]
Update Agent.lnk - c:\program files (x86)\3\3Connect\AutoUpdateSrv.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"WallpaperStyle"= 2
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ServicepointService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R1 ikwtemjp;ikwtemjp;c:\windows\system32\drivers\ikwtemjp.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-26 116648]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-24 253088]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-02-25 227896]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-01-10 1431888]
R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-26 116648]
R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b87ff64c8b56b7db\AESTSr64.exe [2011-02-16 89600]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2011-02-02 18656]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2009-07-14 27136]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-02-28 2343816]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [x]
S2 ServicepointService;ServicepointService;c:\program files (x86)\Virgin Media\Service Manager\ServicepointService.exe [2011-03-25 689464]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-03-19 10:15 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-24 10:22]
.
2012-04-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-26 18:13]
.
2012-04-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-26 18:13]
.
2012-04-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2373302188-527143305-3203656255-1001Core.job
- c:\users\mark's\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-10 19:03]
.
2012-04-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2373302188-527143305-3203656255-1001UA.job
- c:\users\mark's\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-10 19:03]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2009-07-21 610872]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-04 186904]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-02-16 456192]
"combofix"="c:\combofix\CF24705.3XE" [2009-07-14 344576]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
symids
sdcplh
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uLocal Page = c:\windows\system32\blank.htm
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
Toolbar-!{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
Wow6432Node-HKCU-Run-NCsoft - (no file)
Wow6432Node-HKU-Default-Run-4Y3Y0C3A1F7XWVWEOUTJ - c:\recycle.bin\B6232F3A6A9.exe
Toolbar-10 - (no file)
Toolbar-!{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
WebBrowser-{BA14329E-9550-4989-B3F2-9732E92D17CC} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{BA14329E-9550-4989-B3F2-9732E92D17CC}"=hex:51,66,7a,6c,4c,1d,38,12,f0,31,07,
be,62,db,e7,0c,cc,e4,d4,72,ec,73,53,d8
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{597A9974-8CB0-4F41-B61F-ED065738A397}"=hex:51,66,7a,6c,4c,1d,38,12,1a,9a,69,
5d,82,c2,2f,0a,c9,09,ae,46,52,66,e7,83
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93,
aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3f,5a,3c,b3,cd,2f,00,4c,bd,7f,da,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3f,5a,3c,b3,cd,2f,00,4c,bd,7f,da,\
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\DbgagD\1*]
"value"="?\0a\02\19\119+T"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\CyberLink\Shared files\RichVideo.exe
c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
c:\program files (x86)\Hewlett-Packard\Media\Live TV\TVAgent.exe
c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
.
**************************************************************************
.
Completion time: 2012-04-27 14:21:16 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-27 13:21
.
Pre-Run: 32,946,638,848 bytes free
Post-Run: 34,350,436,352 bytes free
.
- - End Of File - - 8F0470909A94E690F9FE378E4DCD1755
I have not noticed a difference in how the computer is running as yet.
Has combofix removed the bad files?