Hi Doris, I can't recall if I had sent this to you yet. Here is the Combofix log:
ComboFix 13-03-01.01 - Dave 03/01/2013 18:39:05.6.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3062.1590 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Dave\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Dave\AppData\Local\assembly\tmp
c:\users\Dave\AppData\Local\Temp\_MEI51442\_ctypes.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\_elementtree.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\_hashlib.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\_socket.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\_ssl.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\pyexpat.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\pysqlite2._sqlite.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\python26.dll
c:\users\Dave\AppData\Local\Temp\_MEI51442\pythoncom26.dll
c:\users\Dave\AppData\Local\Temp\_MEI51442\PyWinTypes26.dll
c:\users\Dave\AppData\Local\Temp\_MEI51442\select.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\unicodedata.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32api.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32com.shell.shell.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32crypt.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32event.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32file.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32inet.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32pdh.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32process.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32profile.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32security.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\win32ts.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\windows._cacheinvalidation.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\wx._controls_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\wx._core_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\wx._gdi_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\wx._html2.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\wx._misc_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\wx._windows_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\wx._wizard.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51442\wxbase293u_net_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51442\wxbase293u_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51442\wxmsw293u_adv_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51442\wxmsw293u_core_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51442\wxmsw293u_html_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51442\wxmsw293u_webview_vc.dll
.
.
((((((((((((((((((((((((( Files Created from 2013-02-02 to 2013-03-02 )))))))))))))))))))))))))))))))
.
.
2013-03-02 02:55 . 2013-03-02 02:55 ——– d—–w- c:\users\Public\AppData\Local\temp
2013-03-02 02:55 . 2013-03-02 02:55 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-03-02 02:55 . 2013-03-02 02:55 ——– d—–w- c:\users\Administrator\AppData\Local\temp
2013-03-01 03:48 . 2013-02-08 00:45 6954968 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{AD4A05E8-BF32-4014-9E14-52E7ABF56F14}\mpengine.dll
2013-02-28 22:28 . 2013-02-08 00:45 6954968 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-02-27 22:34 . 2013-02-27 22:34 ——– d—–w- C:\FRST
2013-02-27 21:48 . 2013-02-27 21:48 ——– d—–w- c:\users\Dave\AppData\Local\Proxure
2013-02-27 21:46 . 2013-02-27 21:46 ——– d—–w- c:\programdata\ClubSanDisk
2013-02-19 11:07 . 2013-01-08 22:01 768000 —-a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-19 04:22 . 2013-01-05 05:00 3967848 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-02-19 04:22 . 2013-01-05 05:00 3913064 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-02-19 04:22 . 2013-01-03 05:05 1293672 —-a-w- c:\windows\system32\drivers\tcpip.sys
2013-02-19 04:22 . 2013-01-03 05:04 187752 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2013-02-15 22:04 . 2013-02-15 22:04 208448 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2013-02-15 22:04 . 2013-02-15 22:04 208448 —-a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
2013-02-12 06:49 . 2013-02-12 06:49 ——– d—–w- c:\program files\ESET
2013-02-12 05:50 . 2013-02-12 05:50 ——– d—–w- c:\windows\ERUNT
2013-02-12 05:50 . 2013-02-12 05:52 ——– d—–w- C:\JRT
2013-02-08 07:51 . 2013-02-08 07:51 ——– d—–w- c:\users\Dave\AppData\Local\LogMeIn
2013-02-08 07:51 . 2013-01-26 00:37 53096 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2013-02-08 07:51 . 2013-01-26 00:37 31592 —-a-w- c:\windows\system32\LMIport.dll
2013-02-08 07:51 . 2013-01-26 00:37 84352 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2013-02-08 07:51 . 2012-11-29 19:56 47640 —-a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2013-02-08 07:51 . 2013-01-26 00:37 92520 —-a-w- c:\windows\system32\LMIinit.dll
2013-02-08 07:51 . 2013-03-01 14:55 ——– d—–w- c:\programdata\LogMeIn
2013-02-08 07:50 . 2013-02-08 07:55 ——– d—–w- c:\program files\LogMeIn
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-28 19:16 . 2012-03-31 19:00 691568 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-28 19:16 . 2011-06-23 17:40 71024 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-28 18:55 . 2013-02-28 18:56 94112 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-02-28 18:55 . 2012-06-01 19:57 861088 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-02-28 18:55 . 2010-05-10 16:51 782240 —-a-w- c:\windows\system32\deployJava1.dll
2013-01-30 10:53 . 2010-01-25 02:56 232336 ——w- c:\windows\system32\MpSigStub.exe
2013-01-20 23:59 . 2013-01-20 23:59 195296 —-a-w- c:\windows\system32\drivers\MpFilter.sys
2013-01-20 23:59 . 2012-03-21 03:44 100328 —-a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2013-01-13 19:53 . 2013-02-28 11:01 207872 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2013-01-13 19:53 . 2013-02-28 11:01 187392 —-a-w- c:\windows\system32\UIAnimation.dll
2013-01-13 19:43 . 2013-02-28 11:01 1230336 —-a-w- c:\windows\system32\WindowsCodecs.dll
2013-01-13 19:02 . 2013-02-28 11:01 417792 —-a-w- c:\windows\system32\WMPhoto.dll
2013-01-13 18:34 . 2013-02-28 11:01 364544 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2013-01-13 17:26 . 2013-02-28 11:01 1158144 —-a-w- c:\windows\system32\XpsPrint.dll
2013-01-08 22:03 . 2013-02-19 11:08 1129472 —-a-w- c:\windows\system32\wininet.dll
2013-01-08 21:58 . 2013-02-19 11:08 420864 —-a-w- c:\windows\system32\vbscript.dll
2013-01-04 04:50 . 2013-02-19 04:22 169984 —-a-w- c:\windows\system32\winsrv.dll
2013-01-04 03:00 . 2013-02-19 04:22 2347008 —-a-w- c:\windows\system32\win32k.sys
2012-12-16 14:13 . 2012-12-24 06:08 295424 —-a-w- c:\windows\system32\atmfd.dll
2012-12-16 14:13 . 2012-12-24 06:08 34304 —-a-w- c:\windows\system32\atmlib.dll
2012-12-15 00:49 . 2010-02-08 18:25 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-12-07 12:26 . 2013-01-09 10:53 308736 —-a-w- c:\windows\system32\Wpc.dll
2012-12-07 12:20 . 2013-01-09 10:53 2576384 —-a-w- c:\windows\system32\gameux.dll
2012-12-07 10:46 . 2013-01-09 10:53 43520 —-a-w- c:\windows\system32\csrr.rs
2012-12-07 10:46 . 2013-01-09 10:53 30720 —-a-w- c:\windows\system32\usk.rs
2012-12-07 10:46 . 2013-01-09 10:53 45568 —-a-w- c:\windows\system32\oflc-nz.rs
2012-12-07 10:46 . 2013-01-09 10:53 44544 —-a-w- c:\windows\system32\pegibbfc.rs
2012-12-07 10:46 . 2013-01-09 10:53 20480 —-a-w- c:\windows\system32\pegi-pt.rs
2012-12-07 10:46 . 2013-01-09 10:53 23552 —-a-w- c:\windows\system32\oflc.rs
2012-12-07 10:46 . 2013-01-09 10:53 20480 —-a-w- c:\windows\system32\pegi-fi.rs
2012-12-07 10:46 . 2013-01-09 10:53 46592 —-a-w- c:\windows\system32\fpb.rs
2012-12-07 10:46 . 2013-01-09 10:53 20480 —-a-w- c:\windows\system32\pegi.rs
2012-12-07 10:46 . 2013-01-09 10:53 21504 —-a-w- c:\windows\system32\grb.rs
2012-12-07 10:46 . 2013-01-09 10:53 40960 —-a-w- c:\windows\system32\cob-au.rs
2012-12-07 10:46 . 2013-01-09 10:53 15360 —-a-w- c:\windows\system32\djctq.rs
2012-12-07 10:46 . 2013-01-09 10:53 51712 —-a-w- c:\windows\system32\esrb.rs
2012-12-07 10:46 . 2013-01-09 10:53 55296 —-a-w- c:\windows\system32\cero.rs
2013-02-25 20:22 . 2013-01-10 19:10 263064 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2008-10-24 206112]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2012-01-21 719672]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2008-10-24 206112]
"cdloader"="c:\users\Dave\AppData\Roaming\mjusbsp\cdloader2.exe" [2010-12-03 50592]
"googletalk"="c:\users\Dave\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-01-25 39408]
"Spotify Web Helper"="c:\users\Dave\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-11-15 1199576]
"GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2012-12-18 16328976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2008-10-24 79136]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"HP LaserJet M1522 MFP Series Fax"="c:\program files\HP\hp LaserJet M1522\hppfaxprintersrv.exe" [2009-09-23 2453504]
"HPUsageTracking"="c:\program files\HP\HP UT\bin\hppusg.exe" [2007-08-31 36864]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2012-12-15 824232]
"LockStatusTray"="c:\windows\LockStatusTray.exe" [2008-02-19 192512]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 648072]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-23 150528]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-24 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-24 150552]
"OEM13Mon.exe"="c:\windows\OEM13Mon.exe" [2008-01-08 36864]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-10-06 59240]
"DNS7reminder"="c:\program files\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" [2007-04-16 259624]
"Cobian Backup 10 Interface"="c:\program files\Cobian Backup 10\cbInterface.exe" [2010-09-24 3154432]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2009-08-31 996616]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"ToolboxFX"="c:\program files\HP\ToolboxFX\bin\HPTLBXFX.exe" [2010-10-25 58936]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2011-08-10 1313640]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 1821576]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 947152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-12-12 152544]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2012-11-29 63048]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-18 946352]
.
c:\users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files\microsoft office\Office14\ONENOTEM.EXE [2011-9-2 227712]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-23 270336]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-4-20 813584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 19:28 72208 —-a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux5"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [x]
R3 HPFXBULKLEDM;HPFXBULKLEDM;c:\windows\system32\drivers\hppcbulkio.sys [x]
R3 HPFXFAX;HPFXFAX;c:\windows\system32\drivers\hpfxfax.sys [x]
R3 libusb0;Jawbone LibUsb-Win32 - Kernel Driver 09/22/2011,1.2.5.0;c:\windows\system32\DRIVERS\libusb0.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 SIUSBXP;SIUSBXP;c:\windows\system32\drivers\SiUSBXp.sys [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 Zoho Assist;Zoho Assist;c:\users\Dave\Documents\ZohoMeeting\ZohoMeeting.exe [x]
S0 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2media.sys [x]
S2 BthFilterHelper;Bluetooth Feature Support;c:\program files\CSR\Vista Profile Pack\BthFilterHelper.exe [x]
S2 cbVSCService;Cobian Backup 10 Volume Shadow Copy service;c:\program files\Cobian Backup 10\cbVSCService.exe [x]
S2 CobianBackup10;Cobian Backup 10;c:\program files\Cobian Backup 10\cbService.exe [x]
S2 CrossLoopService;CrossLoop Service;c:\users\Dave\AppData\Local\CrossLoop\CrossLoopService.exe [x]
S2 DragonSvc;Dragon Service;c:\program files\Common Files\Nuance\dgnsvc.exe [x]
S2 HP LaserJet Service;HP LaserJet Service;c:\program files\HP\HPLaserJetService\HPLaserJetService.exe [x]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [x]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [x]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [x]
S3 OEM13Vfx;Creative Camera OEM013 Video VFX Driver;c:\windows\system32\DRIVERS\OEM13Vfx.sys [x]
S3 OEM13Vid;Creative Camera OEM013 Driver;c:\windows\system32\DRIVERS\OEM13Vid.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc Mcx2Svc SensrSvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
HPService REG_MULTI_SZ HPSLPSVC
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
FontCache
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-03-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]
.
2013-03-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 19:16]
.
2013-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 05:19]
.
2013-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 05:19]
.
2013-03-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2557060353-3338967487-1032703843-1000Core.job
- c:\users\Dave\AppData\Local\Google\Update\GoogleUpdate.exe [2010-01-25 06:29]
.
2013-03-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2557060353-3338967487-1032703843-1000UA.job
- c:\users\Dave\AppData\Local\Google\Update\GoogleUpdate.exe [2010-01-25 06:29]
.
.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://www.google.com/ie
uStart Page =
https://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
FF - ProfilePath - c:\users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\qln39cgr.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - ExtSQL: !HIDDEN! 2010-08-15 23:37; [removed]; c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.download\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariDownload"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML".
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.safariextz\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariExtension"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webarchive\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xml\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'Explorer.exe'(5432)
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\System32\WUDFHost.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Microsoft IntelliPoint\dpupdchk.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Microsoft Office\Office14\OUTLOOK.EXE
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2013-03-01 19:10:01 - machine was rebooted
ComboFix-quarantined-files.txt 2013-03-02 03:09
ComboFix2.txt 2013-02-28 18:21
ComboFix3.txt 2013-02-26 19:57
ComboFix4.txt 2012-10-26 04:12
.
Pre-Run: 97,701,236,736 bytes free
Post-Run: 98,030,432,256 bytes free
.
- - End Of File - - 861DE45276396E3BA824DF20A2F6FCA6
And yes, I am using a router.