here is the combofix log:
ComboFix 11-06-05.01 - Max 05/06/2011 14:15:59.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.2047.1072 [GMT 1:00]
Running from: c:\users\Max\Downloads\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\AutocompletePro
c:\program files (x86)\AutocompletePro\FireFoxExtension.exe
c:\program files (x86)\AutocompletePro\InstTracker.exe
c:\users\Max\AppData\Roaming\inst.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-05-05 to 2011-06-05 )))))))))))))))))))))))))))))))
.
.
2011-06-05 13:23 . 2011-06-05 13:23 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-05 13:11 . 2011-06-05 13:12 -------- d-----w- C:\32788R22FWJFW
2011-06-05 12:53 . 2011-06-05 12:53 -------- d-----w- C:\_OTL
2011-06-05 11:23 . 2011-06-05 11:24 -------- d-----w- c:\users\Max\AppData\Local\{D450A6E0-961B-4A0F-945E-4A6B299569F5}
2011-06-04 13:12 . 2011-06-04 13:12 -------- d-----w- c:\users\Max\AppData\Local\{6D746569-A748-4F23-8B0B-892D8D7FF89D}
2011-06-03 11:24 . 2011-06-03 11:25 -------- d-----w- c:\users\Max\AppData\Local\{95DD4672-0DF9-495E-A2D7-FF6ABD04C515}
2011-06-02 14:45 . 2011-06-02 14:45 -------- d-----w- c:\program files (x86)\Trend Micro
2011-06-02 09:38 . 2011-06-02 09:38 -------- d-----w- c:\programdata\!SASCORE
2011-06-02 08:46 . 2011-06-02 08:46 -------- d-----w- c:\users\Max\AppData\Local\{7A58BCE2-A10D-46BE-A0F1-C8476F39B981}
2011-06-01 15:57 . 2011-06-03 11:21 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-06-01 14:59 . 2011-06-01 14:59 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-06-01 14:19 . 2011-06-01 14:19 -------- d-----w- c:\users\Max\AppData\Roaming\Malwarebytes
2011-06-01 14:19 . 2011-06-01 14:19 -------- d-----w- c:\programdata\Malwarebytes
2011-06-01 14:19 . 2011-05-29 08:11 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-01 13:30 . 2011-06-01 13:30 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-06-01 13:29 . 2011-06-01 13:29 -------- d-----w- c:\program files (x86)\Java
2011-06-01 12:45 . 2011-06-01 12:45 -------- d-----w- c:\windows\Sun
2011-06-01 12:26 . 2011-06-01 12:26 81920 --sha-r- c:\windows\SysWow64\ACCTRESR.dll
2011-06-01 08:59 . 2011-06-01 09:00 -------- d-----w- c:\users\Max\AppData\Local\{00CB9DC7-5186-4D5F-9093-4A5327CFF1CB}
2011-05-30 08:42 . 2011-05-30 08:43 -------- d-----w- c:\users\Max\AppData\Local\{E663A506-66E6-49C8-A945-AF833F518461}
2011-05-29 09:28 . 2011-05-29 09:28 -------- d-----w- c:\users\Max\AppData\Local\{B3856120-960B-4718-AC67-66777BB79672}
2011-05-27 15:41 . 2011-05-27 15:41 -------- d-----w- c:\users\Max\AppData\Local\{C205A9CE-4CC0-4B14-BE0D-F6EF74FF0C96}
2011-05-26 15:42 . 2011-05-26 15:42 -------- d-----w- c:\users\Max\AppData\Local\{FB3357C9-53AD-491A-8E36-AFE1F18D06B6}
2011-05-25 15:57 . 2011-04-22 20:18 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-05-25 15:36 . 2011-05-25 15:36 -------- d-----w- c:\users\Max\AppData\Local\{7C1C3900-DFD7-4CE6-8839-3461F342F619}
2011-05-24 15:49 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe
2011-05-24 15:49 . 2011-04-09 05:56 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
2011-05-24 15:45 . 2011-05-24 15:45 -------- d-----w- c:\users\Max\AppData\Local\{4464AF72-D2CA-4F0E-98B8-8FCB497AA3D9}
2011-05-23 17:07 . 2011-05-23 17:07 -------- d-----w- c:\users\Max\AppData\Local\{63129AFB-1377-48F5-9FAE-48F45AF1E7F5}
2011-05-22 08:32 . 2011-05-22 08:32 -------- d-----w- c:\users\Max\AppData\Local\{F0F7401C-DFDF-46AD-90BE-C45456CB1928}
2011-05-20 16:23 . 2011-05-20 16:23 -------- d-----w- c:\users\Max\AppData\Local\{7B0BF98B-3285-4A7E-8AC3-A2D3010BACFA}
2011-05-19 15:41 . 2011-05-19 15:42 -------- d-----w- c:\users\Max\AppData\Local\{D79E6073-0FE4-455B-B633-493B60E95534}
2011-05-18 15:43 . 2011-05-18 15:44 -------- d-----w- c:\users\Max\AppData\Local\{D6C22B6D-6F4B-40A3-973B-24BD2B0E23C3}
2011-05-17 16:40 . 2011-05-17 16:40 -------- d-----w- c:\users\Max\AppData\Local\{59A1AD07-78F8-42E1-92CE-69D817F5606D}
2011-05-16 15:46 . 2011-05-16 15:46 -------- d-----w- c:\users\Max\AppData\Local\{8A02CF3E-9069-433A-A09A-05E0C70A5502}
2011-05-15 15:36 . 2011-05-15 15:36 -------- d-----w- c:\users\Max\AppData\Roaming\U3
2011-05-15 09:54 . 2011-05-15 09:54 -------- d-----w- c:\users\Max\AppData\Local\{2CA0A5BF-59E2-4E63-9BF9-0DA5A73EDE70}
2011-05-13 16:02 . 2011-05-13 16:02 -------- d-----w- c:\users\Max\AppData\Local\{7BCD617E-E5F5-45C0-ABCB-BB824739FE1C}
2011-05-12 15:54 . 2011-05-12 15:54 -------- d-----w- c:\users\Max\AppData\Local\{FD25DAB2-4D26-4EDD-832F-2525FEA244AD}
2011-05-11 16:02 . 2011-04-09 06:45 5509504 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-05-11 16:02 . 2011-04-09 06:13 3957632 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-05-11 16:02 . 2011-04-09 06:13 3901824 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-05-11 15:57 . 2011-05-11 15:58 -------- d-----w- c:\users\Max\AppData\Local\{3A8EC71D-20DF-4B13-BF16-49178D9D98B6}
2011-05-10 16:38 . 2011-05-10 16:39 -------- d-----w- c:\users\Max\AppData\Local\{AA63F145-075B-4271-A40D-C67C0E0F79BB}
2011-05-09 17:08 . 2011-05-09 17:08 -------- d-----w- c:\users\Max\AppData\Local\{B146BC96-8825-4DCA-B8E6-3478B6B50C4D}
2011-05-08 11:53 . 2011-05-08 11:53 -------- d-----w- c:\users\Max\AppData\Local\{9FE6EC70-5CE7-485B-B4FE-3E3DA7BFED27}
2011-05-08 11:27 . 2011-05-08 11:27 -------- d-----w- c:\program files (x86)\DVD Decrypter
2011-05-08 11:17 . 2011-05-08 11:19 -------- d-----w- c:\programdata\DVD Shrink
2011-05-08 11:14 . 2011-05-08 11:14 -------- d-----w- c:\users\Max\.dvdcss
2011-05-08 11:13 . 2011-05-08 11:13 -------- d-----w- c:\users\Max\AppData\Roaming\Digiarty
2011-05-08 11:13 . 2011-05-08 11:13 -------- d-----w- C:\OutputFolder
2011-05-08 11:13 . 2011-05-08 11:13 -------- d-----w- c:\program files (x86)\Digiarty
2011-05-08 10:53 . 2011-05-08 11:02 -------- d-----w- c:\users\Max\AppData\Roaming\HandBrake
2011-05-08 10:53 . 2011-05-08 10:53 -------- d-----w- c:\users\Max\AppData\Local\HandBrake
2011-05-08 10:53 . 2011-05-08 11:10 -------- d-----w- c:\program files (x86)\Handbrake
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-01 13:29 . 2010-05-23 08:46 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-04-28 15:48 . 2010-03-03 17:22 710976 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-04-24 13:15 . 2010-03-03 17:22 2594584 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2011-04-24 13:15 . 2010-05-20 15:46 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2011-04-24 13:15 . 2009-12-29 10:03 710976 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-04-14 13:01 . 2011-01-03 11:18 9984 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2011-04-14 13:01 . 2011-01-03 11:17 94992 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2011-04-14 13:01 . 2011-01-03 11:17 75160 ----a-w- c:\windows\system32\drivers\mfenlfk.sys
2011-04-14 13:01 . 2011-01-03 11:17 63056 ----a-w- c:\windows\system32\drivers\cfwids.sys
2011-04-14 13:01 . 2011-01-03 11:17 441840 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2011-04-14 13:01 . 2011-01-03 11:17 283744 ----a-w- c:\windows\system32\drivers\mfewfpk.sys
2011-04-14 13:01 . 2011-01-03 11:17 190520 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2011-04-14 13:01 . 2011-01-03 11:09 149032 ----a-w- c:\windows\system32\mfevtps.exe
2011-04-14 13:01 . 2010-10-13 22:28 530304 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2011-04-14 13:01 . 2010-10-13 22:28 121376 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2011-04-13 22:40 . 2011-04-13 22:40 4284416 ----a-w- c:\windows\SysWow64\GPhotos.scr
2011-04-02 15:48 . 2011-04-02 15:48 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-04-02 15:48 . 2011-04-02 15:48 1797632 ----a-w- c:\windows\SysWow64\jscript9.dll
2011-04-02 15:48 . 2011-04-02 15:48 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-04-02 15:48 . 2011-04-02 15:48 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
2011-04-02 15:48 . 2011-04-02 15:48 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-04-02 15:48 . 2011-04-02 15:48 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-04-02 15:48 . 2011-04-02 15:48 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-04-02 15:48 . 2011-04-02 15:48 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-04-02 15:48 . 2011-04-02 15:48 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-04-02 15:48 . 2011-04-02 15:48 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-04-02 15:48 . 2011-04-02 15:48 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-04-02 15:48 . 2011-04-02 15:48 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-04-02 15:48 . 2011-04-02 15:48 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-04-02 15:48 . 2011-04-02 15:48 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-04-02 15:48 . 2011-04-02 15:48 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-04-02 15:48 . 2011-04-02 15:48 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-04-02 15:48 . 2011-04-02 15:48 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-04-02 15:48 . 2011-04-02 15:48 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-04-02 15:48 . 2011-04-02 15:48 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-04-02 15:48 . 2011-04-02 15:48 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-04-02 15:48 . 2011-04-02 15:48 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-04-02 15:48 . 2011-04-02 15:48 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-04-02 15:48 . 2011-04-02 15:48 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-04-02 15:48 . 2011-04-02 15:48 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-04-02 15:48 . 2011-04-02 15:48 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-04-02 15:48 . 2011-04-02 15:48 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-04-02 15:48 . 2011-04-02 15:48 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-04-02 15:48 . 2011-04-02 15:48 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-04-02 15:48 . 2011-04-02 15:48 448512 ----a-w- c:\windows\system32\html.iec
2011-04-02 15:48 . 2011-04-02 15:48 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-04-02 15:48 . 2011-04-02 15:48 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-04-02 15:48 . 2011-04-02 15:48 2303488 ----a-w- c:\windows\system32\jscript9.dll
2011-04-02 15:48 . 2011-04-02 15:48 222208 ----a-w- c:\windows\system32\msls31.dll
2011-04-02 15:48 . 2011-04-02 15:48 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-04-02 15:48 . 2011-04-02 15:48 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-04-02 15:48 . 2011-04-02 15:48 160256 ----a-w- c:\windows\system32\wextract.exe
2011-04-02 15:48 . 2011-04-02 15:48 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-04-02 15:48 . 2011-04-02 15:48 1389056 ----a-w- c:\windows\system32\wininet.dll
2011-04-02 15:48 . 2011-04-02 15:48 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-04-02 15:48 . 2011-04-02 15:48 12288 ----a-w- c:\windows\system32\mshta.exe
2011-04-02 15:48 . 2011-04-02 15:48 114176 ----a-w- c:\windows\system32\admparse.dll
2011-04-02 15:48 . 2011-04-02 15:48 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-04-01 16:43 . 2009-12-29 10:03 2594584 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2011-04-01 16:43 . 2010-05-19 16:33 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2011-03-31 15:47 . 2011-03-31 15:47 2594584 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-7\markup.dll
2011-03-11 06:19 . 2011-04-15 08:12 1359872 ----a-w- c:\windows\system32\mfc42u.dll
2011-03-11 06:19 . 2011-04-15 08:12 1395712 ----a-w- c:\windows\system32\mfc42.dll
2011-03-11 05:40 . 2011-04-15 08:12 1164288 ----a-w- c:\windows\SysWow64\mfc42u.dll
2011-03-11 05:40 . 2011-04-15 08:12 1137664 ----a-w- c:\windows\SysWow64\mfc42.dll
2011-03-09 16:44 . 2010-06-24 10:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-03-08 06:14 . 2011-04-15 08:12 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-08 05:38 . 2011-04-15 08:12 740864 ----a-w- c:\windows\SysWow64\inetcomm.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{E601996F-E400-41CA-804B-CD6373A7EEE2}]
2010-05-06 16:06 777904 ----a-w- c:\program files (x86)\kikin\ie_kikin.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-12-28 39408]
"OfficeSyncProcess"="c:\program files (x86)\Microsoft Office\Office14\MSOSYNC.EXE" [2010-03-16 718208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe" [2009-07-24 240112]
"CPMonitor"="c:\program files (x86)\Roxio 2010\5.0\CPMonitor.exe" [2009-07-21 84464]
"Desktop Disc Tool"="c:\program files (x86)\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe" [2009-06-23 494064]
"LogitechVideoTray"="c:\program files (x86)\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-22 402432]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-04-05 1486392]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
.
c:\users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-3-29 227712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer6"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /k:C *
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-06-16 136176]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe [2009-07-24 219632]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-06-16 136176]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RoxMediaDB12;RoxMediaDB12;c:\program files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe [2009-07-24 1116656]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe
R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys
S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys
S1 MOBKFilter;MOBKFilter;c:\windows\system32\DRIVERS\MOBK.sys
S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-06 169408]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-04-14 245352]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe
S2 MOBKbackup;McAfee Online Backup;c:\program files (x86)\McAfee Online Backup\MOBKbackup.exe [2010-04-13 231224]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
S2 WTService;WTService;c:\windows\System32\atwtusb.exe
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys
S3 netr28ux;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28ux.sys
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-06-16 15:54]
.
2011-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-06-16 15:54]
.
2011-06-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3746345936-3213574714-259889910-1000Core.job
- c:\users\Max\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-14 12:36]
.
2011-06-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3746345936-3213574714-259889910-1000UA.job
- c:\users\Max\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-14 12:36]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK]
@="{3c3f3c1a-9153-7c05-f938-622e7003894d}"
[HKEY_CLASSES_ROOT\CLSID\{3c3f3c1a-9153-7c05-f938-622e7003894d}]
2010-04-13 20:11 3816248 ----a-w- c:\program files (x86)\McAfee Online Backup\MOBKshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK2]
@="{e6ea1d7d-144e-b977-98c4-84c53c1a69d0}"
[HKEY_CLASSES_ROOT\CLSID\{e6ea1d7d-144e-b977-98c4-84c53c1a69d0}]
2010-04-13 20:11 3816248 ----a-w- c:\program files (x86)\McAfee Online Backup\MOBKshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK3]
@="{b4caf489-1eec-c617-49ad-8d7088598c06}"
[HKEY_CLASSES_ROOT\CLSID\{b4caf489-1eec-c617-49ad-8d7088598c06}]
2010-04-13 20:11 3816248 ----a-w- c:\program files (x86)\McAfee Online Backup\MOBKshell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MacroKeyManager"="WTMKM.exe" [2009-08-11 5634792]
"VX3000"="c:\windows\vVX3000.exe" [2010-05-20 762736]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-07-29 497648]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.autocompletepro.com/?si=7981&bi=400
uDefault_Search_URL = hxxp://search.autocompletepro.com/?si=7981&bi=400
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Se&nd to OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: {{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} - c:\program files (x86)\kikin\ie_kikin.dll
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\586qrb0k.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2786678&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{30F9B915-B755-4826-820B-08FBA6BD249D} - c:\program files (x86)\ConduitEngine\ConduitEngine.dll
BHO-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files (x86)\uTorrentBar\tbuTor.dll
Toolbar-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files (x86)\uTorrentBar\tbuTor.dll
Toolbar-{30F9B915-B755-4826-820B-08FBA6BD249D} - c:\program files (x86)\ConduitEngine\ConduitEngine.dll
Wow6432Node-HKCU-Run-LogitechSoftwareUpdate - c:\program files (x86)\Logitech\Video\ManifestEngine.exe
Wow6432Node-HKCU-Run-EA Core - c:\program files (x86)\Electronic Arts\EADM\Core.exe
Wow6432Node-HKCU-Run-USBStickWatcher - e:\other\USB Stick Watcher\usbstickwatcher.exe
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKLM-Run-LogitechVideoRepair - c:\program files (x86)\Logitech\Video\ISStart.exe
HKLM-Run-MSSE - c:\program files\Microsoft Security Essentials\msseces.exe
HKLM-Run-ASUSWebStorage - c:\program files (x86)\ASUS\ASUS WebStorage\2.2.3.15\ASUSWSDashBoard.exe
HKLM-Run-(Default) - (no file)
AddRemove-AutoHotkey - c:\program files (x86)\AutoHotkey\uninst.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-3746345936-3213574714-259889910-1000\Software\SecuROM\License information*]
"datasecu"=hex:36,23,59,2d,86,1f,c3,bc,07,cf,51,23,5c,96,6c,f2,3d,67,82,90,46,
d4,7c,68,b9,3c,2c,af,e5,45,e0,a8,ea,b4,84,6b,67,5d,ba,11,9e,9b,67,b0,df,08,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-06-05 14:26:22
ComboFix-quarantined-files.txt 2011-06-05 13:26
.
Pre-Run: 386,239,217,664 bytes free
Post-Run: 387,727,495,168 bytes free
.
- - End Of File - - B7667C40616D2AB7AC9D04D1DB3BE768