Below is the Combofix log.
So far my computer is still running slowly. Pages often take several seconds to re-load. Videos on load, then stop often hanging for many minutes.
Thanks.
ComboFix 13-03-05.01 - new user 03/05/2013 10:09:23.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1222 [GMT -8:00]
Running from: c:\documents and settings\new user\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\_ctypes.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\_elementtree.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\_hashlib.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\_socket.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\_ssl.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\pyexpat.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\pysqlite2._sqlite.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\python26.dll
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\pythoncom26.dll
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\PyWinTypes26.dll
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\select.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\unicodedata.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\win32api.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\win32com.shell.shell.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\win32crypt.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\win32event.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\win32file.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\win32inet.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\win32pdh.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\win32process.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\win32profile.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\win32security.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\win32ts.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\windows._cacheinvalidation.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\wx._controls_.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\wx._core_.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\wx._gdi_.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\wx._html2.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\wx._misc_.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\wx._windows_.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\wx._wizard.pyd
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\wxbase293u_net_vc.dll
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\wxbase293u_vc.dll
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\wxmsw293u_adv_vc.dll
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\wxmsw293u_core_vc.dll
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\wxmsw293u_html_vc.dll
c:\docume~1\NEWUSE~1\LOCALS~1\Temp\_MEI29522\wxmsw293u_webview_vc.dll
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\_ctypes.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\_elementtree.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\_hashlib.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\_socket.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\_ssl.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\pyexpat.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\pysqlite2._sqlite.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\python26.dll
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\pythoncom26.dll
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\PyWinTypes26.dll
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\select.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\unicodedata.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\win32api.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\win32com.shell.shell.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\win32crypt.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\win32event.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\win32file.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\win32inet.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\win32pdh.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\win32process.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\win32profile.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\win32security.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\win32ts.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\windows._cacheinvalidation.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\wx._controls_.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\wx._core_.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\wx._gdi_.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\wx._html2.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\wx._misc_.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\wx._windows_.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\wx._wizard.pyd
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\wxbase293u_net_vc.dll
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\wxbase293u_vc.dll
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\wxmsw293u_adv_vc.dll
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\wxmsw293u_core_vc.dll
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\wxmsw293u_html_vc.dll
c:\documents and settings\new user\Local Settings\Temp\_MEI29522\wxmsw293u_webview_vc.dll
.
.
((((((((((((((((((((((((( Files Created from 2013-02-05 to 2013-03-05 )))))))))))))))))))))))))))))))
.
.
2013-03-05 14:00 . 2013-02-08 00:45 6954968 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0F3DC34E-4C11-4380-8528-14D326E2949C}\mpengine.dll
2013-03-05 09:12 . 2013-03-05 09:12 -------- d-----w- c:\documents and settings\new user\Local Settings\Application Data\Adobe_Systems_Incorporate
2013-03-04 01:04 . 2013-02-08 00:45 6954968 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-02-27 21:52 . 2012-12-15 00:49 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-02-27 21:52 . 2013-02-27 21:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-02-24 02:37 . 2013-02-24 02:37 405360 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-22 18:52 . 2013-02-22 18:52 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2013-02-22 18:52 . 2013-02-22 18:52 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2013-02-22 18:52 . 2013-02-22 18:52 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2013-02-22 18:52 . 2013-02-22 18:52 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2013-02-22 18:52 . 2013-02-22 18:52 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2013-02-22 18:52 . 2013-02-22 18:52 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2013-02-22 18:52 . 2013-02-22 18:52 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2013-02-22 18:51 . 2013-02-22 18:52 -------- d-----w- c:\program files\QuickTime
2013-02-22 18:48 . 2013-02-22 18:48 -------- d-----w- c:\program files\Apple Software Update
2013-02-22 14:52 . 2013-02-22 14:52 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-02-22 14:52 . 2013-02-22 14:52 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-02-18 22:16 . 2013-02-18 22:16 -------- d-----w- c:\documents and settings\new user\Application Data\Free-PDF-to-Word.com
2013-02-18 22:16 . 2013-02-18 22:26 -------- d-----w- c:\program files\Free PDF to Word Converter
2013-02-18 22:16 . 2013-02-18 22:28 -------- d-sh--w- c:\windows\system32\AI_RecycleBin
2013-02-18 22:15 . 2013-02-18 22:28 -------- d-----w- C:\AI_RecycleBin
2013-02-18 22:09 . 2013-02-18 22:09 -------- d-----w- c:\documents and settings\new user\Local Settings\Application Data\Updater21804
2013-02-16 03:58 . 2013-02-16 03:58 106088 ----a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
2013-02-11 05:59 . 2013-02-11 07:22 -------- d-----w- c:\documents and settings\All Users\AdobeTemp
2013-02-08 04:53 . 2013-02-08 04:53 16365936 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2013-02-08 00:37 . 2013-02-08 01:37 -------- d-----w- c:\documents and settings\new user\Application Data\Skype
2013-02-08 00:37 . 2013-02-08 00:37 -------- d-----w- c:\program files\Common Files\Skype
2013-02-08 00:37 . 2013-02-08 00:37 -------- d-----r- c:\program files\Skype
2013-02-08 00:37 . 2013-02-08 00:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2013-02-07 23:03 . 2013-02-07 23:03 -------- d-----w- c:\program files\TeamViewer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-22 14:52 . 2012-12-11 02:52 861088 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-02-22 14:52 . 2010-12-02 06:03 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-01-30 10:53 . 2012-12-06 01:38 232336 ------w- c:\windows\system32\MpSigStub.exe
2013-01-26 03:55 . 2006-02-28 12:00 552448 ----a-w- c:\windows\system32\oleaut32.dll
2013-01-20 23:59 . 2012-08-31 06:03 195296 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2013-01-07 01:19 . 2006-02-28 12:00 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-07 00:37 . 2004-08-03 22:59 2027520 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-04 01:20 . 2006-02-28 12:00 1867264 ----a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49 . 2006-02-28 12:00 148992 ----a-w- c:\windows\system32\mpg2splt.ax
2013-01-02 06:49 . 2006-02-28 12:00 1292288 ----a-w- c:\windows\system32\quartz.dll
2012-12-26 20:43 . 2006-02-28 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2012-12-26 20:43 . 2006-02-28 12:00 1830912 ------w- c:\windows\system32\inetcpl.cpl
2012-12-26 20:43 . 2006-02-28 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2012-12-26 20:43 . 2006-02-28 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2012-12-16 12:23 . 2006-02-28 12:00 290560 ----a-w- c:\windows\system32\atmfd.dll
2013-02-21 22:19 . 2013-02-21 22:18 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2012-12-18 03:50 556648 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2012-12-18 03:50 556648 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2012-12-18 03:50 556648 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2012-12-18 03:50 556648 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Jing"="c:\program files\TechSmith\Jing\Jing.exe" [2013-01-07 2909640]
"GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2012-12-18 16328976]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-08-01 1036288]
"Broadcom Wireless Manager"="c:\windows\system32\wltray.exe" [2007-06-14 1282048]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-13 141600]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 947152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-12-19 41208]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-12 59280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]
.
c:\documents and settings\new user\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Dynex Wireless Networking Utility.lnk - c:\program files\Dynex Enhanced G USB Network Adapter\DynexWCUI.exe [2009-1-27 1458176]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-9-11 972064]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\TeamViewer\\Version8\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version8\\TeamViewer_Service.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Documents and Settings\\new user\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
.
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [3/27/2009 2:54 PM 165160]
R2 IntuitUpdateServiceV4;Intuit Update Service v4;c:\program files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [2/6/2012 3:25 PM 13672]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2/27/2013 1:52 PM 398184]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2/27/2013 1:52 PM 682344]
R2 ReplicaSysMon;Seagate Replica System Monitor;c:\program files\Seagate Replica\bin\ReplicaSysMon.exe [2/21/2012 10:38 PM 416208]
R2 Seagate-Replica-Svc;Seagate Replica Service;c:\program files\Seagate Replica\bin\Seagate-Replica-Svc.exe [2/21/2012 10:38 PM 1947600]
R2 TeamViewer8;TeamViewer 8;c:\program files\TeamViewer\Version8\TeamViewer_Service.exe [2/7/2013 3:03 PM 3467768]
R2 thdudf;TOSHIBA UDF2.5 Reader File System Driver;c:\windows\system32\drivers\thdudf.sys [6/19/2012 11:33 PM 66944]
R2 UNS;Intel® Active Management Technology User Notification Service;c:\program files\Intel\AMT\UNS.exe [1/22/2009 8:20 PM 2521880]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2/27/2013 1:52 PM 21104]
R3 NdisWDM;Dynex Enhanced Wireless G USB Network Adapter Service;c:\windows\system32\drivers\NdisWDM.sys [1/27/2009 2:21 PM 198528]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [1/22/2009 8:28 PM 47360]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [1/8/2013 12:55 PM 161536]
.
Contents of the 'Scheduled Tasks' folder
.
2013-03-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-01-11 17:25]
.
2013-03-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-01-11 17:25]
.
2013-03-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1383384898-725345543-1003Core.job
- c:\documents and settings\new user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-16 17:20]
.
2013-03-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1383384898-725345543-1003UA.job
- c:\documents and settings\new user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-16 17:20]
.
2013-03-05 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2013-01-27 19:11]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.0.1 68.94.157.1
FF - ProfilePath - c:\documents and settings\new user\Application Data\Mozilla\Firefox\Profiles\bkfv6qww.default-1361669665718\
FF - ExtSQL: 2013-02-23 17:46; {73a6fe31-595d-460b-a920-fcc0f8843232}; c:\documents and settings\new user\Application Data\Mozilla\Firefox\Profiles\bkfv6qww.default-1361669665718\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-03-05 10:29
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Seagate-Replica-Svc]
"ImagePath"="c:\program files\Seagate Replica\bin\Seagate-Replica-Svc.exe /startedbyscm:FE2355B7-40E2EE35-RebitSvcModule"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1417001333-1383384898-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2A9F2178-EA4A-BD24-5CC8-73B0410FC935}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"oaibfkkmjogmcngfmgdoigbdngjdep"=hex:64,61,69,64,66,61,6d,69,00,90
"oamecmaoognmoigfcpfibafjagmeon"=hex:6a,61,69,64,69,61,67,6e,6e,6e,65,6d,6e,6c,
70,63,70,69,62,6a,00,fd
"nacfelhmipcfckeenmhilhmfanij"=hex:6a,61,69,64,69,61,67,6e,6e,6e,65,6d,6e,6c,
70,63,70,69,62,6a,00,fd
"eaefckhgpk"=hex:64,62,6b,68,68,70,67,6f,6d,6a,65,65,62,6e,70,64,64,68,6f,63,
67,6f,6f,6d,6b,6a,6e,63,64,62,70,6e,6e,67,65,61,66,6d,6a,6e,00,3d
"cahbhi"=hex:64,62,6e,65,6a,63,68,66,66,6a,6f,67,6d,63,6f,6f,62,69,6f,6e,6e,70,
6f,70,6d,6b,68,66,63,6c,62,6a,69,6d,6a,63,6e,6f,70,6b,00,3d
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(832)
c:\windows\System32\BCMLogon.dll
.
- - - - - - - > 'explorer.exe'(540)
c:\windows\system32\WININET.dll
c:\program files\Google\Drive\googledrivesync32.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\windows\System32\wltrysvc.exe
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Intel\AMT\atchksrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Google\Update\1.3.21.135\GoogleCrashHandler.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Intel\AMT\LMS.exe
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files\Seagate Replica\bin\Seagate-Replica-Autoplay.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Seagate Replica\bin\Seagate-Replica-Tray.exe
c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
.
**************************************************************************
.
Completion time: 2013-03-05 10:34:53 - machine was rebooted
ComboFix-quarantined-files.txt 2013-03-05 18:34
.
Pre-Run: 197,979,377,664 bytes free
Post-Run: 198,554,103,808 bytes free
.
- - End Of File - - 7E6E9C767CDF3DB3AFB7C837603EC87D