Goodmorning Will, Here's the log from the combofix scan:
ComboFix 13-01-28.02 - Troy 01/28/2013 19:23:53.1.4 - x64
Microsoft Windows 7 Enterprise 6.1.7601.1.1252.1.1033.18.7657.6211 [GMT -8:00]
Running from: c:\users\Troy\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\intellidownload\gunzip.exe
c:\program files (x86)\Shop to Win
c:\program files (x86)\Shop to Win\TestFeeds\DisableStatus.xml
c:\program files (x86)\Shop to Win\TestFeeds\DisableStatusDirection.xml
c:\program files (x86)\Shop to Win\TestFeeds\GenericPopup.xml
c:\program files (x86)\Shop to Win\TestFeeds\MainStatus.xml
c:\program files (x86)\Shop to Win\TestFeeds\ShoppingConfirmation.xml
c:\program files (x86)\Shop to Win\unins000.dat
c:\program files (x86)\smartdl
c:\program files (x86)\smartdl\dler.exe
c:\program files (x86)\smartdl\gunzip.exe
c:\program files (x86)\smartdl\header.bmp
c:\program files (x86)\smartdl\header2.bmp
c:\program files (x86)\smartdl\header3.bmp
c:\program files (x86)\smartdl\next.bmp
c:\program files (x86)\smartdl\skip.bmp
c:\program files (x86)\smartdl\status
c:\program files (x86)\smartdl\wget.exe
c:\users\Troy\Documents\ShopToWin
c:\windows\SysWow64\libs.exe
c:\windows\SysWow64\Packet.dll
c:\windows\SysWow64\pthreadVC.dll
c:\windows\SysWow64\windows
c:\windows\SysWow64\WinMonitor.exe
c:\windows\SysWow64\wpcap.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Service_npf
.
.
((((((((((((((((((((((((( Files Created from 2012-12-28 to 2013-01-29 )))))))))))))))))))))))))))))))
.
.
2013-01-28 18:02 . 2013-01-08 05:32 9161176 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{208960A1-2B11-4FA3-82ED-1C9893B29A83}\mpengine.dll
2013-01-28 17:51 . 2013-01-08 05:32 9161176 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-01-28 14:42 . 2013-01-28 14:42 -------- d-----w- c:\users\Troy\AppData\Roaming\Systweak
2013-01-28 14:42 . 2013-01-28 17:47 -------- d-----w- c:\program files (x86)\RegClean Pro
2013-01-28 14:11 . 2013-01-28 14:11 -------- d-----w- c:\users\Troy\AppData\Roaming\SpeedMaxPc
2013-01-28 09:15 . 2013-01-28 09:15 -------- d-----w- c:\users\Troy\AppData\Roaming\ParetoLogic
2013-01-28 09:15 . 2013-01-28 15:14 -------- d-----w- c:\programdata\ParetoLogic
2013-01-28 04:40 . 2013-01-28 04:46 -------- d-----w- c:\users\Troy\AppData\Roaming\FixCleaner
2013-01-28 04:40 . 2013-01-28 15:12 -------- d-----w- c:\program files (x86)\FixCleaner
2013-01-28 04:26 . 2013-01-28 04:26 -------- d-----w- c:\users\Troy\AppData\Roaming\SpeedyPC Software
2013-01-28 04:25 . 2013-01-28 15:15 -------- d-----w- c:\programdata\SpeedyPC Software
2013-01-26 06:20 . 2013-01-28 17:47 -------- d-----w- c:\program files (x86)\InfoAtoms
2013-01-25 18:53 . 2013-01-25 18:53 -------- d-----w- c:\users\Troy\AppData\Roaming\Foxit Software
2013-01-25 11:51 . 2013-01-25 19:32 -------- d-----w- c:\users\Troy\AppData\Roaming\Uniblue
2013-01-21 08:13 . 2013-01-21 08:13 -------- d-----w- c:\users\Troy\AppData\Local\cache
2013-01-21 08:09 . 2013-01-21 08:09 -------- d-----w- c:\programdata\VTech
2013-01-21 08:09 . 2013-01-21 08:09 -------- d-----w- c:\program files (x86)\VTech
2013-01-21 00:05 . 2013-01-21 00:08 -------- d-----w- c:\windows\$regcmp$
2013-01-20 08:51 . 2013-01-20 08:52 -------- d-----w- c:\program files\Microsoft Silverlight
2013-01-20 08:51 . 2013-01-20 08:52 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2013-01-18 12:52 . 2013-01-18 12:52 -------- d-----w- c:\users\Troy\AppData\Roaming\DriverCure
2013-01-18 12:52 . 2013-01-18 12:52 -------- d-----w- c:\users\Troy\AppData\Roaming\SparkTrust
2013-01-16 08:51 . 2013-01-28 17:47 -------- d-----w- c:\users\Troy\AppData\Roaming\Azureus
2013-01-16 06:53 . 2013-01-16 07:07 -------- d-----w- c:\users\Troy\AppData\Roaming\Apple Computer
2013-01-16 06:52 . 2013-01-28 11:10 -------- d-----w- c:\users\Troy\AppData\Local\Adobe
2013-01-16 06:39 . 2013-01-16 06:39 -------- d-----w- c:\users\Troy\AppData\Roaming\Ashampoo
2013-01-16 06:15 . 2013-01-16 06:15 -------- d-----w- c:\users\Troy\AppData\Roaming\CleanMyPC Software
2013-01-15 21:19 . 2013-01-15 21:19 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2013-01-15 21:19 . 2013-01-15 21:19 -------- d-----w- c:\program files\Microsoft Security Client
2013-01-15 21:06 . 2013-01-18 12:55 -------- d-----w- c:\programdata\SparkTrust
2013-01-15 20:35 . 2013-01-15 20:35 -------- d-----w- c:\program files (x86)\NoVirusThanks
2013-01-15 18:49 . 2013-01-15 18:49 -------- d-----w- c:\programdata\ErrorEND64
2013-01-15 03:54 . 2013-01-28 17:46 -------- d-----w- c:\users\Administrator
2013-01-15 02:40 . 2011-09-28 17:20 200704 ----a-w- c:\windows\SysWow64\vbalExpBar6.ocx
2013-01-15 02:40 . 2011-09-28 17:20 484352 ----a-w- c:\windows\SysWow64\lame_enc.dll
2013-01-15 02:40 . 2011-09-28 17:20 40960 ----a-w- c:\windows\SysWow64\SSubTmr6.dll
2013-01-15 02:40 . 2011-09-28 17:20 32768 ----a-w- c:\windows\SysWow64\CMDLGFR.DLL
2013-01-15 02:40 . 2011-09-28 17:20 15360 ----a-w- c:\windows\SysWow64\inetfr.DLL
2013-01-15 02:40 . 2011-09-28 17:20 141312 ----a-w- c:\windows\SysWow64\MSCMCFR.DLL
2013-01-15 02:40 . 2011-09-28 17:20 119568 ----a-w- c:\windows\SysWow64\VB6FR.DLL
2013-01-15 02:40 . 2011-09-28 17:20 115920 ----a-w- c:\windows\SysWow64\msinet.OCX
2013-01-15 02:40 . 2011-09-28 17:20 101888 ----a-w- c:\windows\SysWow64\VB6STKIT.DLL
2013-01-15 02:40 . 2013-01-15 02:40 -------- d-----w- c:\program files (x86)\Searchqu Toolbar
2013-01-15 02:39 . 2013-01-15 02:41 -------- d-----w- c:\program files (x86)\Free Easy CD DVD Burner
2013-01-14 23:56 . 2013-01-14 23:56 -------- d-----w- c:\program files (x86)\OI App Manager
2013-01-14 21:32 . 2013-01-28 17:47 -------- d-----w- c:\program files\Adobe
2013-01-14 21:25 . 2013-01-28 17:47 -------- d-----w- c:\program files\Common Files\Adobe
2013-01-14 05:35 . 2013-01-14 05:35 3591 ----a-w- c:\users\Troy\Msirepair.reg
2013-01-13 22:08 . 2013-01-13 22:21 -------- d-----w- c:\users\Troy\Doctor Web
2013-01-12 00:26 . 2013-01-28 15:15 -------- d-----w- c:\programdata\SpeedMaxPc
2013-01-12 00:14 . 2010-06-02 12:55 518488 ----a-w- c:\windows\system32\XAudio2_7.dll
2013-01-12 00:14 . 2010-06-02 12:55 77656 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2013-01-12 00:14 . 2010-06-02 12:55 74072 ----a-w- c:\windows\SysWow64\XAPOFX1_5.dll
2013-01-12 00:14 . 2010-06-02 12:55 527192 ----a-w- c:\windows\SysWow64\XAudio2_7.dll
2013-01-12 00:14 . 2010-05-26 19:41 2526056 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2013-01-12 00:14 . 2010-05-26 19:41 276832 ----a-w- c:\windows\system32\d3dx11_43.dll
2013-01-12 00:14 . 2010-05-26 19:41 248672 ----a-w- c:\windows\SysWow64\d3dx11_43.dll
2013-01-12 00:13 . 2009-09-05 01:29 453456 ----a-w- c:\windows\SysWow64\d3dx10_42.dll
2013-01-12 00:13 . 2009-09-05 01:29 523088 ----a-w- c:\windows\system32\d3dx10_42.dll
2013-01-12 00:12 . 2006-11-29 21:06 4398360 ----a-w- c:\windows\system32\d3dx9_32.dll
2013-01-12 00:12 . 2006-11-29 21:06 3426072 ----a-w- c:\windows\SysWow64\d3dx9_32.dll
2013-01-12 00:12 . 2013-01-12 00:12 -------- d-----w- c:\program files (x86)\Microsoft SkyDrive
2013-01-12 00:12 . 2013-01-12 00:12 -------- d-----r- c:\users\Troy\SkyDrive
2013-01-12 00:12 . 2013-01-12 00:12 -------- d-----w- c:\programdata\Microsoft SkyDrive
2013-01-12 00:11 . 2013-01-12 00:11 -------- d-----w- c:\users\Troy\AppData\Local\Windows Live
2013-01-12 00:10 . 2013-01-12 00:10 -------- d-----w- c:\program files (x86)\Common Files\Windows Live
2013-01-11 04:35 . 2002-01-05 23:48 974848 ----a-w- c:\windows\SysWow64\mfc70.dll
2013-01-11 04:35 . 2002-01-05 22:40 487424 ----a-w- c:\windows\SysWow64\msvcp70.dll
2013-01-11 04:35 . 2002-01-05 10:37 344064 ----a-w- c:\windows\SysWow64\msvcr70.dll
2013-01-11 02:57 . 2012-03-24 03:58 11137024 ----a-w- c:\windows\SysWow64\libmfxsw32.dll
2013-01-10 19:51 . 2013-01-11 04:54 -------- d-----w- c:\program files (x86)\AVS4YOU
2013-01-10 19:51 . 2013-01-11 02:58 -------- d-----w- c:\program files (x86)\Common Files\AVSMedia
2013-01-10 19:51 . 2013-01-10 19:52 -------- d-----w- c:\programdata\AVS4YOU
2013-01-10 19:51 . 2012-03-24 03:59 1700352 ----a-w- c:\windows\SysWow64\GdiPlus.dll
2013-01-10 19:51 . 2012-03-24 03:59 24576 ----a-w- c:\windows\SysWow64\msxml3a.dll
2013-01-09 11:40 . 2013-01-09 11:40 -------- d-----w- c:\program files (x86)\Common Files\xing shared
2013-01-09 11:40 . 2013-01-09 11:40 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
2013-01-09 10:04 . 2013-01-09 10:04 -------- d-----w- c:\programdata\WoW Worldwide Software LTD
2013-01-09 10:03 . 2013-01-09 10:03 -------- d-----w- c:\program files (x86)\VaudiX
2013-01-09 10:02 . 2013-01-13 22:34 -------- d-----w- c:\program files (x86)\MocaFlix
2013-01-09 10:00 . 2013-01-09 11:02 -------- d-----w- c:\programdata\Vaudix
2013-01-09 09:25 . 2013-01-09 09:27 -------- d-----w- c:\program files (x86)\vGrabber-software
2013-01-09 06:37 . 2012-11-09 05:45 750592 ----a-w- c:\windows\system32\win32spl.dll
2013-01-09 06:37 . 2012-11-09 04:43 492032 ----a-w- c:\windows\SysWow64\win32spl.dll
2013-01-09 06:14 . 2012-11-23 03:26 3149824 ----a-w- c:\windows\system32\win32k.sys
2013-01-09 05:48 . 2012-11-30 05:45 362496 ----a-w- c:\windows\system32\wow64win.dll
2013-01-09 05:40 . 2012-11-23 03:13 68608 ----a-w- c:\windows\system32\taskhost.exe
2013-01-08 22:53 . 2013-01-08 22:53 -------- d-----w- c:\users\Troy\AppData\Local\join.me
2013-01-04 20:07 . 2013-01-04 20:07 -------- d-----w- c:\users\Troy\AppData\Local\Programs
2013-01-04 09:42 . 2013-01-04 09:42 -------- d-----w- c:\programdata\Alien Skin
2013-01-04 09:42 . 2013-01-04 09:42 -------- d-----w- c:\users\Troy\AppData\Local\Alien Skin
2013-01-04 09:32 . 2013-01-04 09:32 -------- d-----w- c:\program files (x86)\Alien Skin
2013-01-03 00:13 . 2013-01-03 00:13 -------- d-----w- c:\users\Public\Roaming
2013-01-01 21:50 . 2013-01-01 21:50 -------- d-----w- c:\program files\PhotomatixPro4
2013-01-01 21:50 . 2013-01-01 21:50 -------- d-----w- c:\users\Troy\AppData\Roaming\HDRsoft
2013-01-01 20:16 . 2013-01-01 20:52 -------- d-----w- c:\users\Troy\AppData\Roaming\Imagenomic
2013-01-01 20:14 . 2013-01-01 20:50 -------- d-----w- c:\program files (x86)\Imagenomic
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-09 11:04 . 2012-06-05 10:53 67599240 ----a-w- c:\windows\system32\MRT.exe
2012-12-22 22:23 . 2012-05-20 23:40 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-12-22 22:23 . 2012-05-20 23:40 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-12-16 17:11 . 2012-12-21 11:01 46080 ----a-w- c:\windows\system32\atmlib.dll
2012-12-16 14:45 . 2012-12-21 11:01 367616 ----a-w- c:\windows\system32\atmfd.dll
2012-12-16 14:13 . 2012-12-21 11:01 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2012-12-16 14:13 . 2012-12-21 11:01 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2012-12-15 00:49 . 2012-05-06 02:49 24176 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-11-30 04:45 . 2013-01-09 05:48 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2012-11-21 05:09 . 2012-11-21 05:09 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
2012-11-14 07:06 . 2012-12-14 01:52 17811968 ----a-w- c:\windows\system32\mshtml.dll
2012-11-14 06:32 . 2012-12-14 01:52 10925568 ----a-w- c:\windows\system32\ieframe.dll
2012-11-14 06:11 . 2012-12-14 01:52 2312704 ----a-w- c:\windows\system32\jscript9.dll
2012-11-14 06:04 . 2012-12-14 01:52 1346048 ----a-w- c:\windows\system32\urlmon.dll
2012-11-14 06:04 . 2012-12-14 01:52 1392128 ----a-w- c:\windows\system32\wininet.dll
2012-11-14 06:02 . 2012-12-14 01:52 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
2012-11-14 06:02 . 2012-12-14 01:52 237056 ----a-w- c:\windows\system32\url.dll
2012-11-14 05:59 . 2012-12-14 01:52 85504 ----a-w- c:\windows\system32\jsproxy.dll
2012-11-14 05:58 . 2012-12-14 01:52 816640 ----a-w- c:\windows\system32\jscript.dll
2012-11-14 05:57 . 2012-12-14 01:52 599040 ----a-w- c:\windows\system32\vbscript.dll
2012-11-14 05:57 . 2012-12-14 01:52 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2012-11-14 05:55 . 2012-12-14 01:52 2144768 ----a-w- c:\windows\system32\iertutil.dll
2012-11-14 05:55 . 2012-12-14 01:52 729088 ----a-w- c:\windows\system32\msfeeds.dll
2012-11-14 05:53 . 2012-12-14 01:52 96768 ----a-w- c:\windows\system32\mshtmled.dll
2012-11-14 05:52 . 2012-12-14 01:52 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-11-14 05:46 . 2012-12-14 01:52 248320 ----a-w- c:\windows\system32\ieui.dll
2012-11-14 02:09 . 2012-12-14 01:52 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll
2012-11-14 01:58 . 2012-12-14 01:52 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2012-11-14 01:57 . 2012-12-14 01:52 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2012-11-14 01:49 . 2012-12-14 01:52 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2012-11-14 01:48 . 2012-12-14 01:52 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2012-11-14 01:44 . 2012-12-14 01:52 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2012-11-09 05:45 . 2012-12-13 02:03 2048 ----a-w- c:\windows\system32\tzres.dll
2012-11-09 04:42 . 2012-12-13 02:03 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-11-08 17:24 . 2012-12-21 19:50 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B7025589-5D1D-4358-A67B-2704BCA9FA66}\mpengine.dll
2012-11-02 05:59 . 2012-12-13 02:02 478208 ----a-w- c:\windows\system32\dpnet.dll
2012-11-02 05:11 . 2012-12-13 02:02 376832 ----a-w- c:\windows\SysWow64\dpnet.dll
2010-01-26 18:11 . 2012-08-13 10:28 444283 ----a-w- c:\program files\Common Files\WinPcapNmap.exe
.
Code:
<pre>
c:\windows\Setup\scripts\7z 4.65 x64 Silent .exe
</pre>
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files (x86)\Vuze_Remote\prxtbVuze.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{234D72B6-0A31-D400-BF59-AB9820A24223}]
2013-01-09 08:19 118784 ----a-w- c:\programdata\Vaudix\50ed2817d604b.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2011-05-09 08:49 176936 ----a-w- c:\program files (x86)\Vuze_Remote\prxtbVuze.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files (x86)\Vuze_Remote\prxtbVuze.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\Troy\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\Troy\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\Troy\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\Troy\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Registry Cleaner Scheduler"="c:\program files (x86)\CleanMyPC\Registry Cleaner\RCHelper.exe" [2012-05-12 1403640]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-05-03 17355912]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2012-01-18 911160]
"Akamai NetSession Interface"="c:\users\Troy\AppData\Local\Akamai\netsession_win.exe" [2012-05-26 4327744]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2013-01-09 295072]
"AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-10 1073312]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-12-15 512360]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-06-08 421776]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2011-05-06 3037296]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-31 59280]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2012-04-04 36760]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2012-04-04 815512]
"AgentMonitor"="c:\program files (x86)\VTech\DownloadManager\System\AgentMonitor.exe" [2012-11-08 377800]
.
c:\users\Troy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Troy\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-12-21 28538560]
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2011-9-2 245120]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Audible Download Manager.lnk - c:\program files (x86)\Audible\Bin\AudibleDownloadHelper.exe [2011-3-14 2125472]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableInstallerDetection"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~2\VaudiX\sprotector.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-06-05 1255736]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-15 24176]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-08-31 128456]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-09-13 368896]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-10 174440]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-21 20992]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [2011-03-29 694888]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-21 88960]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 34816]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-04-25 52736]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-09-28 239616]
R4 BroadCamService;BroadCam Video Streaming Server;c:\program files (x86)\NCH Software\BroadCam\broadcam.exe [2012-08-26 2584068]
R4 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-15 398184]
R4 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-15 682344]
R4 Realtek11nSU;Realtek11nSU;c:\program files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe [2010-04-16 36864]
R4 RLM-GenArts;RLM-GenArts;c:\program files (x86)\GenArts\rlm\rlm.exe [2010-04-02 1540096]
R4 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-07-06 3048136]
R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-05-03 158856]
R4 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe [2011-03-29 27760]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2011-11-03 56208]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-05-14 96896]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C60x64.sys [2011-03-23 76912]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2011-03-29 2157680]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2013-01-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-25 04:16]
.
2013-01-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-25 04:16]
.
2013-01-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3706292512-3240535162-4024994405-1000Core.job
- c:\users\Troy\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-31 17:39]
.
2013-01-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3706292512-3240535162-4024994405-1000UA.job
- c:\users\Troy\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-31 17:39]
.
2013-01-29 c:\windows\Tasks\SpeedMaxPc Registration3.job
- c:\windows\system32\rundll32.exe [2009-07-13 01:14]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\Troy\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\Troy\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\Troy\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\Troy\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-12-15 478984]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-13 1289704]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{F791A188-699D-4FD4-955A-EB59E89B1907}"= "c:\program files\Theme Resource Changer\ThemeResourceChanger.dll" [2010-10-07 103936]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://websearch.just-browse.info/
mStart Page = hxxp://websearch.just-browse.info/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local;<local>
IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Download with &Media Finder - c:\program files (x86)\Media Finder\hook.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\users\Troy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{404474E3-A6C9-4F5B-A628-74EF9063583B}: NameServer = 4.2.2.1,4.2.2.2
FF - ProfilePath - c:\users\Troy\AppData\Roaming\Mozilla\Firefox\Profiles\t1yvk9h7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://websearch.just-browse.info/?l=1&q=
FF - prefs.js: browser.search.selectedEngine - WebSearch
FF - prefs.js: browser.startup.homepage - hxxp://websearch.just-browse.info/
FF - prefs.js: keyword.URL - hxxp://websearch.just-browse.info/?l=1&q=
FF - ExtSQL: 2013-01-09 03:31;
50ed2817d5ed0@50ed2817d5f00.com; c:\users\Troy\AppData\Roaming\Mozilla\Firefox\Profiles\t1yvk9h7.default\extensions\50ed2817d5ed0@50ed2817d5f00.com
FF - ExtSQL: !HIDDEN! 2012-06-20 07:09; {EB132DB0-A4CA-11DF-9732-0E29E0D72085}; c:\program files (x86)\OApps\firefoxaddon
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)
URLSearchHooks-{90b49673-5506-483e-b92b-ca0265bd9ca8} - (no file)
WebBrowser-{687578B9-7132-4A7A-80E4-30EE31099E03} - (no file)
WebBrowser-{BA14329E-9550-4989-B3F2-9732E92D17CC} - (no file)
WebBrowser-{90B49673-5506-483E-B92B-CA0265BD9CA8} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:9e,f2,fa,f1,b9,f2,2b,ab,23,ce,0f,20,ba,52,9a,bd,5b,68,64,0b,17,
42,17,6c,9e,35,70,fb,00,d3,64,a9,a9,08,d9,b9,3c,80,48,0a,99,e3,b3,93,05,ce,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:9e,f2,fa,f1,b9,f2,2b,ab,23,ce,0f,20,ba,52,9a,bd,5b,68,64,0b,17,
42,17,6c,9e,35,70,fb,00,d3,64,a9,a9,08,d9,b9,3c,80,48,0a,99,e3,b3,93,05,ce,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*]
"value"="?\05\01\15\08\128?"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
.
**************************************************************************
.
Completion time: 2013-01-28 19:51:49 - machine was rebooted
ComboFix-quarantined-files.txt 2013-01-29 03:51
.
Pre-Run: 827,514,191,872 bytes free
Post-Run: 830,318,276,608 bytes free
.
- - End Of File - - 1713168893C961AD31F21B7BDEF25770
View attachment ComboFix.zip
Truth