Hi, here is the Combofix data. And the computer is still showing these wierd ads; when you look at a webpage certain words are highlighted and you click on them and it takes you to some cheesy ad. And in LinkedIn, there is a panel on the side with some R rated ads that I know LinkedIn doesn't put up there. Pretty weird!
ComboFix 13-02-26.01 - Dave 02/26/2013 11:37:06.4.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3062.1404 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Dave\AppData\Local\assembly\tmp
c:\users\Dave\AppData\Local\Temp\_MEI51282\_ctypes.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\_elementtree.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\_hashlib.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\_socket.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\_ssl.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\pyexpat.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\pysqlite2._sqlite.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\python26.dll
c:\users\Dave\AppData\Local\Temp\_MEI51282\pythoncom26.dll
c:\users\Dave\AppData\Local\Temp\_MEI51282\PyWinTypes26.dll
c:\users\Dave\AppData\Local\Temp\_MEI51282\select.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\unicodedata.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32api.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32com.shell.shell.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32crypt.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32event.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32file.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32inet.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32pdh.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32process.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32profile.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32security.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32ts.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\windows._cacheinvalidation.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\wx._controls_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\wx._core_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\wx._gdi_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\wx._html2.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\wx._misc_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\wx._windows_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\wx._wizard.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\wxbase293u_net_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51282\wxbase293u_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51282\wxmsw293u_adv_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51282\wxmsw293u_core_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51282\wxmsw293u_html_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51282\wxmsw293u_webview_vc.dll
c:\users\Dave\g2mdlhlpx.exe
.
.
((((((((((((((((((((((((( Files Created from 2013-01-26 to 2013-02-26 )))))))))))))))))))))))))))))))
.
.
2013-02-26 19:52 . 2013-02-26 19:52 ——– d—–w- c:\users\Public\AppData\Local\temp
2013-02-26 19:52 . 2013-02-26 19:52 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-02-26 19:52 . 2013-02-26 19:52 ——– d—–w- c:\users\Administrator\AppData\Local\temp
2013-02-26 19:29 . 2013-02-26 19:29 29904 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3A5AEA98-B0EF-4EBC-AC93-68EC78833FFA}\MpKsl35130a3e.sys
2013-02-25 18:41 . 2013-02-25 18:41 60872 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3A5AEA98-B0EF-4EBC-AC93-68EC78833FFA}\offreg.dll
2013-02-25 18:41 . 2013-02-25 18:41 29904 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3A5AEA98-B0EF-4EBC-AC93-68EC78833FFA}\MpKsl7fc33600.sys
2013-02-25 18:11 . 2013-02-08 00:45 6954968 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3A5AEA98-B0EF-4EBC-AC93-68EC78833FFA}\mpengine.dll
2013-02-23 20:36 . 2013-02-08 00:45 6954968 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-02-19 11:07 . 2013-01-08 22:01 768000 —-a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-19 04:22 . 2013-01-04 03:00 2347008 —-a-w- c:\windows\system32\win32k.sys
2013-02-19 04:22 . 2013-01-05 05:00 3967848 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-02-19 04:22 . 2013-01-05 05:00 3913064 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-02-19 04:22 . 2013-01-03 05:05 1293672 —-a-w- c:\windows\system32\drivers\tcpip.sys
2013-02-19 04:22 . 2013-01-03 05:04 187752 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2013-02-19 04:22 . 2013-01-04 04:50 169984 —-a-w- c:\windows\system32\winsrv.dll
2013-02-15 22:31 . 2013-02-15 22:31 186432 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2013-02-15 22:31 . 2013-02-15 22:31 186432 —-a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
2013-02-12 06:49 . 2013-02-12 06:49 ——– d—–w- c:\program files\ESET
2013-02-12 05:50 . 2013-02-12 05:50 ——– d—–w- c:\windows\ERUNT
2013-02-12 05:50 . 2013-02-12 05:52 ——– d—–w- C:\JRT
2013-02-08 07:51 . 2013-02-08 07:51 ——– d—–w- c:\users\Dave\AppData\Local\LogMeIn
2013-02-08 07:51 . 2013-01-26 00:37 53096 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2013-02-08 07:51 . 2013-01-26 00:37 31592 —-a-w- c:\windows\system32\LMIport.dll
2013-02-08 07:51 . 2013-01-26 00:37 84352 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2013-02-08 07:51 . 2012-11-29 19:56 47640 —-a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2013-02-08 07:51 . 2013-01-26 00:37 92520 —-a-w- c:\windows\system32\LMIinit.dll
2013-02-08 07:51 . 2013-02-26 12:58 ——– d—–w- c:\programdata\LogMeIn
2013-02-08 07:50 . 2013-02-08 07:55 ——– d—–w- c:\program files\LogMeIn
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-07 22:25 . 2012-03-31 19:00 697712 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-07 22:25 . 2011-06-23 17:40 74096 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-30 10:53 . 2010-01-25 02:56 232336 ——w- c:\windows\system32\MpSigStub.exe
2012-12-16 14:13 . 2012-12-24 06:08 295424 —-a-w- c:\windows\system32\atmfd.dll
2012-12-16 14:13 . 2012-12-24 06:08 34304 —-a-w- c:\windows\system32\atmlib.dll
2012-12-15 00:49 . 2010-02-08 18:25 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-12-07 12:26 . 2013-01-09 10:53 308736 —-a-w- c:\windows\system32\Wpc.dll
2012-12-07 12:20 . 2013-01-09 10:53 2576384 —-a-w- c:\windows\system32\gameux.dll
2012-12-07 10:46 . 2013-01-09 10:53 43520 —-a-w- c:\windows\system32\csrr.rs
2012-12-07 10:46 . 2013-01-09 10:53 30720 —-a-w- c:\windows\system32\usk.rs
2012-12-07 10:46 . 2013-01-09 10:53 45568 —-a-w- c:\windows\system32\oflc-nz.rs
2012-12-07 10:46 . 2013-01-09 10:53 44544 —-a-w- c:\windows\system32\pegibbfc.rs
2012-12-07 10:46 . 2013-01-09 10:53 20480 —-a-w- c:\windows\system32\pegi-pt.rs
2012-12-07 10:46 . 2013-01-09 10:53 23552 —-a-w- c:\windows\system32\oflc.rs
2012-12-07 10:46 . 2013-01-09 10:53 20480 —-a-w- c:\windows\system32\pegi-fi.rs
2012-12-07 10:46 . 2013-01-09 10:53 46592 —-a-w- c:\windows\system32\fpb.rs
2012-12-07 10:46 . 2013-01-09 10:53 20480 —-a-w- c:\windows\system32\pegi.rs
2012-12-07 10:46 . 2013-01-09 10:53 21504 —-a-w- c:\windows\system32\grb.rs
2012-12-07 10:46 . 2013-01-09 10:53 40960 —-a-w- c:\windows\system32\cob-au.rs
2012-12-07 10:46 . 2013-01-09 10:53 15360 —-a-w- c:\windows\system32\djctq.rs
2012-12-07 10:46 . 2013-01-09 10:53 51712 —-a-w- c:\windows\system32\esrb.rs
2012-12-07 10:46 . 2013-01-09 10:53 55296 —-a-w- c:\windows\system32\cero.rs
2012-11-30 04:47 . 2013-01-09 10:54 293376 —-a-w- c:\windows\system32\KernelBase.dll
2012-11-30 04:45 . 2013-01-09 10:53 4096 —ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 4608 —ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 4096 —ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 4096 —ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 4096 —ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3584 —ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3584 —ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3584 —ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3584 —ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3584 —ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3584 —ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 4096 —ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 5120 —ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2012-11-30 02:55 . 2013-01-09 10:53 271360 —-a-w- c:\windows\system32\conhost.exe
2012-11-30 02:38 . 2013-01-09 10:53 6144 —ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-11-30 02:38 . 2013-01-09 10:53 4608 —ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-11-30 02:38 . 2013-01-09 10:53 3584 —ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-11-30 02:38 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-11-29 19:56 . 2012-11-29 19:56 25248 —-a-w- c:\windows\system32\lmimirr.dll
2012-11-29 19:56 . 2012-11-29 19:56 11552 —-a-w- c:\windows\system32\lmimirr2.dll
2012-11-29 19:56 . 2012-11-29 19:56 10144 —-a-w- c:\windows\system32\drivers\lmimirr.sys
2012-11-29 02:34 . 2012-11-29 02:35 740840 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{976634D8-D591-4345-A817-7182E360E333}\gapaengine.dll
2013-02-25 20:22 . 2013-01-10 19:10 263064 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2008-10-24 206112]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2012-01-21 719672]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2008-10-24 206112]
"cdloader"="c:\users\Dave\AppData\Roaming\mjusbsp\cdloader2.exe" [2010-12-03 50592]
"googletalk"="c:\users\Dave\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-01-25 39408]
"Spotify Web Helper"="c:\users\Dave\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-11-15 1199576]
"GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2012-12-18 16328976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2008-10-24 79136]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"HP LaserJet M1522 MFP Series Fax"="c:\program files\HP\hp LaserJet M1522\hppfaxprintersrv.exe" [2009-09-23 2453504]
"HPUsageTracking"="c:\program files\HP\HP UT\bin\hppusg.exe" [2007-08-31 36864]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2012-12-15 824232]
"LockStatusTray"="c:\windows\LockStatusTray.exe" [2008-02-19 192512]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 648072]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-23 150528]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-24 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-24 150552]
"OEM13Mon.exe"="c:\windows\OEM13Mon.exe" [2008-01-08 36864]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-10-06 59240]
"DNS7reminder"="c:\program files\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" [2007-04-16 259624]
"Cobian Backup 10 Interface"="c:\program files\Cobian Backup 10\cbInterface.exe" [2010-09-24 3154432]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2009-08-31 996616]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"ToolboxFX"="c:\program files\HP\ToolboxFX\bin\HPTLBXFX.exe" [2010-10-25 58936]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2011-08-10 1313640]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 1821576]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-13 947176]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-12-12 152544]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2012-11-29 63048]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-23 270336]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-4-20 813584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 19:28 72208 —-a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux5"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 CrossLoopService;CrossLoop Service;c:\users\Dave\AppData\Local\CrossLoop\CrossLoopService.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [x]
R3 HPFXBULKLEDM;HPFXBULKLEDM;c:\windows\system32\drivers\hppcbulkio.sys [x]
R3 HPFXFAX;HPFXFAX;c:\windows\system32\drivers\hpfxfax.sys [x]
R3 libusb0;Jawbone LibUsb-Win32 - Kernel Driver 09/22/2011,1.2.5.0;c:\windows\system32\DRIVERS\libusb0.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 SIUSBXP;SIUSBXP;c:\windows\system32\drivers\SiUSBXp.sys [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 Zoho Assist;Zoho Assist;c:\users\Dave\Documents\ZohoMeeting\ZohoMeeting.exe [x]
S0 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2media.sys [x]
S1 MpKsl35130a3e;MpKsl35130a3e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3A5AEA98-B0EF-4EBC-AC93-68EC78833FFA}\MpKsl35130a3e.sys [x]
S1 MpKsl7fc33600;MpKsl7fc33600;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3A5AEA98-B0EF-4EBC-AC93-68EC78833FFA}\MpKsl7fc33600.sys [x]
S2 BthFilterHelper;Bluetooth Feature Support;c:\program files\CSR\Vista Profile Pack\BthFilterHelper.exe [x]
S2 cbVSCService;Cobian Backup 10 Volume Shadow Copy service;c:\program files\Cobian Backup 10\cbVSCService.exe [x]
S2 CobianBackup10;Cobian Backup 10;c:\program files\Cobian Backup 10\cbService.exe [x]
S2 DragonSvc;Dragon Service;c:\program files\Common Files\Nuance\dgnsvc.exe [x]
S2 HP LaserJet Service;HP LaserJet Service;c:\program files\HP\HPLaserJetService\HPLaserJetService.exe [x]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [x]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [x]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [x]
S3 OEM13Vfx;Creative Camera OEM013 Video VFX Driver;c:\windows\system32\DRIVERS\OEM13Vfx.sys [x]
S3 OEM13Vid;Creative Camera OEM013 Driver;c:\windows\system32\DRIVERS\OEM13Vid.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL35130A3E
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
HPService REG_MULTI_SZ HPSLPSVC
.
Contents of the 'Scheduled Tasks' folder
.
2013-02-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]
.
2013-02-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 22:25]
.
2013-02-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 05:19]
.
2013-02-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 05:19]
.
2013-02-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2557060353-3338967487-1032703843-1000Core.job
- c:\users\Dave\AppData\Local\Google\Update\GoogleUpdate.exe [2010-01-25 06:29]
.
2013-02-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2557060353-3338967487-1032703843-1000UA.job
- c:\users\Dave\AppData\Local\Google\Update\GoogleUpdate.exe [2010-01-25 06:29]
.
.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://www.google.com/ie
uStart Page =
https://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //FWEvent.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\qln39cgr.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - ExtSQL: !HIDDEN! 2010-08-15 23:37; [removed]; c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-MobileDocuments - c:\program files\Common Files\Apple\Internet Services\ubd.exe
AddRemove-{16726771-C380-4280-BAF9-1223B3838786} - c:\programdata\SaveAs\uninstall.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.download\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariDownload"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.safariextz\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariExtension"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webarchive\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xml\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-02-26 11:57:11
ComboFix-quarantined-files.txt 2013-02-26 19:57
ComboFix2.txt 2012-10-26 04:12
.
Pre-Run: 97,461,280,768 bytes free
Post-Run: 97,831,178,240 bytes free
.
- - End Of File - - EE994F9D5BCD4F7363189AB776C954FF