Hello;
Here is the Combofix Log
ComboFix 13-05-12.01 - User 05/12/2013 8:45.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2812.1662 [GMT -4:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
AV: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\MyOwnSuperhero\bar\2.bin\v3BAr.dll
c:\program files\Webfetti\bar\2.bin\7dBAr.dll
.
.
((((((((((((((((((((((((( Files Created from 2013-04-12 to 2013-05-12 )))))))))))))))))))))))))))))))
.
.
2013-05-12 12:54 . 2013-05-12 12:54 βββ dββw- c:\users\Default\AppData\Local\temp
2013-05-11 13:28 . 2013-05-11 13:28 βββ dββw- c:\program files\FGIcon
2013-05-11 13:28 . 2013-05-11 13:28 βββ dββw- c:\programdata\Wincert
2013-05-11 13:28 . 2013-05-11 13:28 βββ dββw- c:\program files\Settings Alerter
2013-05-11 13:28 . 2013-05-11 13:28 βββ dββw- c:\programdata\Tarma Installer
2013-05-11 12:54 . 2013-05-11 15:03 βββ dββw- c:\users\User\AppData\Roaming\Strongvault
2013-05-11 12:52 . 2013-05-11 15:02 βββ dββw- c:\users\User\AppData\Local\SwvUpdater
2013-05-11 12:51 . 2013-05-11 15:03 βββ d-shβw- c:\windows\system32\AI_RecycleBin
2013-05-11 12:49 . 2013-05-11 15:03 βββ dββw- C:\AI_RecycleBin
2013-05-11 12:49 . 2013-05-11 12:49 βββ dββw- c:\program files\LyricsTube
2013-05-10 22:56 . 2013-05-10 22:56 βββ dββw- c:\program files\KeyBar_1.8
2013-05-10 22:54 . 2013-05-10 22:55 βββ dββw- c:\program files\OtShot
2013-05-10 22:05 . 2013-05-10 22:05 βββ dββw- c:\users\User\AppData\Roaming\Iminent
2013-05-10 22:05 . 2013-05-10 22:05 βββ dββw- c:\programdata\Iminent
2013-05-10 21:58 . 2013-05-10 21:58 βββ dββw- c:\program files\Conduit
2013-05-10 21:58 . 2013-05-11 22:14 βββ dββw- c:\users\User\AppData\Local\Conduit
2013-05-10 21:58 . 2013-05-11 12:51 βββ dββw- c:\users\User\AppData\Local\CRE
2013-05-10 21:40 . 2013-05-10 21:40 βββ dββw- c:\program files\LessTabs
2013-05-10 21:40 . 2013-05-10 21:40 βββ dββw- c:\program files\IMinent Toolbar
2013-05-10 21:39 . 2013-05-10 21:39 βββ dββw- c:\program files\Common Files\Umbrella
2013-05-10 21:39 . 2013-05-10 22:04 βββ dββw- c:\program files\Iminent
2013-05-10 17:02 . 2013-05-10 17:02 13024 β-a-w- c:\windows\system32\drivers\SWDUMon.sys
2013-05-10 17:02 . 2013-05-10 17:02 βββ dββw- c:\users\User\AppData\Local\SlimWare Utilities Inc
2013-05-10 12:04 . 2013-05-10 12:20 βββ dββw- C:\temp
2013-05-10 01:17 . 2013-05-10 01:17 βββ dββw- C:\_OTL
2013-05-09 19:53 . 2013-05-09 19:53 βββ dββw- c:\windows\ERUNT
2013-05-09 19:53 . 2013-05-09 22:41 βββ dββw- C:\JRT
2013-05-09 15:00 . 2013-05-09 22:27 690 β-a-w- c:\windows\DeleteOnReboot.bat
2013-05-09 12:50 . 2013-05-09 12:50 βββ dββw- c:\users\User\AppData\Roaming\Foresight Software
2013-05-09 12:50 . 2013-05-10 17:42 βββ dββw- c:\programdata\Foresight Software
2013-05-08 18:56 . 2013-05-08 19:47 βββ dββw- c:\programdata\Spybot - Search & Destroy
2013-05-08 18:55 . 2009-01-25 16:14 15224 β-a-w- c:\windows\system32\sdnclean.exe
2013-05-08 18:55 . 2013-05-08 18:56 βββ dββw- c:\program files\Spybot - Search & Destroy 2
2013-05-08 18:55 . 2013-05-08 18:55 βββ dββw- c:\users\User\AppData\Local\Programs
2013-05-01 12:29 . 2013-04-04 09:35 94112 β-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-04-30 01:33 . 2013-04-30 01:33 9728 βha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-04-24 12:04 . 2013-04-12 13:45 1211752 β-a-w- c:\windows\system32\drivers\ntfs.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-01 12:30 . 2012-07-04 12:34 861088 β-a-w- c:\windows\system32\npdeployJava1.dll
2013-04-01 12:30 . 2010-12-05 10:25 782240 β-a-w- c:\windows\system32\deployJava1.dll
2013-03-31 12:49 . 2012-12-26 11:40 499712 β-a-w- c:\windows\system32\msvcp71.dll
2013-03-31 12:49 . 2012-12-26 11:40 348160 β-a-w- c:\windows\system32\msvcr71.dll
2013-03-29 06:53 . 2013-03-29 06:53 208184 β-a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2013-03-21 07:08 . 2013-03-21 07:08 182072 β-a-w- c:\windows\system32\drivers\avgtdix.sys
2013-03-19 12:19 . 2012-08-30 18:43 33624 β-a-w- c:\windows\system32\drivers\avgtpx86.sys
2013-03-19 05:04 . 2013-04-10 15:05 3968856 β-a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-19 05:04 . 2013-04-10 15:05 3913560 β-a-w- c:\windows\system32\ntoskrnl.exe
2013-03-19 04:48 . 2013-04-10 15:05 38912 β-a-w- c:\windows\system32\csrsrv.dll
2013-03-19 02:49 . 2013-04-10 15:05 69632 β-a-w- c:\windows\system32\smss.exe
2013-03-13 14:35 . 2012-04-08 15:38 693976 β-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-13 14:35 . 2011-05-15 20:27 73432 β-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-01 14:32 . 2013-03-01 14:32 22328 β-a-w- c:\windows\system32\drivers\avgidsshimx.sys
2013-03-01 03:09 . 2013-04-10 15:05 2347008 β-a-w- c:\windows\system32\win32k.sys
2013-02-15 04:37 . 2013-04-10 15:05 3217408 β-a-w- c:\windows\system32\mstscax.dll
2013-02-15 04:34 . 2013-04-10 15:05 131584 β-a-w- c:\windows\system32\aaclient.dll
2013-02-15 03:25 . 2013-04-10 15:05 36864 β-a-w- c:\windows\system32\tsgqec.dll
2013-02-12 03:32 . 2013-03-26 12:27 15872 β-a-w- c:\windows\system32\drivers\usb8023.sys
2012-09-06 01:27 . 2013-04-12 20:50 266720 β-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9ed31f84-c8b3-4926-b950-dff74047ff79}"= "c:\program files\KeyBar_1.8\prxtbKeyB.dll" [2013-04-10 231712]
.
[HKEY_CLASSES_ROOT\clsid\{9ed31f84-c8b3-4926-b950-dff74047ff79}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{58124A0B-DC32-4180-9BFF-E0E21AE34026}]
2012-12-19 15:22 2609864 β-a-w- c:\program files\IMinent Toolbar\tbcore3.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{9ed31f84-c8b3-4926-b950-dff74047ff79}]
2013-04-10 10:19 231712 β-a-w- c:\program files\KeyBar_1.8\prxtbKeyB.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{977AE9CC-AF83-45E8-9E03-E2798216E2D5}"= "c:\program files\IMinent Toolbar\tbcore3.dll" [2012-12-19 2609864]
"{9ed31f84-c8b3-4926-b950-dff74047ff79}"= "c:\program files\KeyBar_1.8\prxtbKeyB.dll" [2013-04-10 231712]
.
[HKEY_CLASSES_ROOT\clsid\{977ae9cc-af83-45e8-9e03-e2798216e2d5}]
[HKEY_CLASSES_ROOT\TBSB01620.TBSB01620.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB01620.TBSB01620]
.
[HKEY_CLASSES_ROOT\clsid\{9ed31f84-c8b3-4926-b950-dff74047ff79}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{977AE9CC-AF83-45E8-9E03-E2798216E2D5}"= "c:\program files\IMinent Toolbar\tbcore3.dll" [2012-12-19 2609864]
"{9ED31F84-C8B3-4926-B950-DFF74047FF79}"= "c:\program files\KeyBar_1.8\prxtbKeyB.dll" [2013-04-10 231712]
.
[HKEY_CLASSES_ROOT\clsid\{977ae9cc-af83-45e8-9e03-e2798216e2d5}]
[HKEY_CLASSES_ROOT\TBSB01620.TBSB01620.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB01620.TBSB01620]
.
[HKEY_CLASSES_ROOT\clsid\{9ed31f84-c8b3-4926-b950-dff74047ff79}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ComcastSecureBackupShare]
@="{72bcb80d-7778-eb4a-ec51-22340ad33e07}"
[HKEY_CLASSES_ROOT\CLSID\{72bcb80d-7778-eb4a-ec51-22340ad33e07}]
2010-12-14 17:06 3424488 β-a-w- c:\program files\SecureBackupShare\ComcastSecureBackupShareshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ComcastSecureBackupShare2]
@="{b723586e-9ca0-5b27-341a-4990a8c342cf}"
[HKEY_CLASSES_ROOT\CLSID\{b723586e-9ca0-5b27-341a-4990a8c342cf}]
2010-12-14 17:06 3424488 β-a-w- c:\program files\SecureBackupShare\ComcastSecureBackupShareshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ComcastSecureBackupShare3]
@="{f614e4c4-b3fa-5249-b9ea-4fe7d38b8cd0}"
[HKEY_CLASSES_ROOT\CLSID\{f614e4c4-b3fa-5249-b9ea-4fe7d38b8cd0}]
2010-12-14 17:06 3424488 β-a-w- c:\program files\SecureBackupShare\ComcastSecureBackupShareshell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MyTOSHIBA"="c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe" [2009-08-06 264048]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-02 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-30 98304]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-29 7625248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-21 1545512]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2009-08-21 476512]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2009-07-28 460088]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2009-08-05 738616]
"TosWaitSrv"="c:\program files\TOSHIBA\TPHM\TosWaitSrv.exe" [2009-08-07 611672]
"Teco"="c:\program files\TOSHIBA\TECO\Teco.exe" [2009-08-11 1324384]
"TWebCamera"="c:\program files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2009-08-11 2446648]
"SmartFaceVWatcher"="c:\program files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [2009-07-29 163840]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-04 611672]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-05-26 1468296]
"Toshiba Online Backup"="c:\program files\Toshiba Online Backup\ToshibaOnlineBackup.exe" [2010-01-15 965976]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"AVG_UI"="c:\program files\AVG\AVG2013\avgui.exe" [2013-04-29 4408368]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-19 421888]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"TkBellExe"="c:\program files\real\realplayer\Update\realsched.exe" [2013-03-31 295512]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"SDTray"="c:\program files\Spybot - Search & Destroy 2\SDTray.exe" [2012-11-13 3825176]
"Iminent"="c:\program files\Iminent\Iminent.exe" [2013-04-30 1074736]
"IminentMessenger"="c:\program files\Iminent\Iminent.Messengers.exe" [2013-04-30 884784]
"OtShot"="c:\program files\OtShot\otshot.exe" [2012-10-18 4386816]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secure Backup and Share Status.lnk - c:\program files\SecureBackupShare\ComcastSecureBackupSharestat.exe [2010-12-14 3539688]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R3 cpuz134;cpuz134;c:\users\User\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [x]
R3 GamesAppService;GamesAppService;c:\program files\WildTangent Games\App\GamesAppService.exe [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 SWDUMon;SWDUMon;c:\windows\system32\DRIVERS\SWDUMon.sys [x]
R3 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 AVGIDSHX;AVGIDSHX;c:\windows\system32\DRIVERS\avgidshx.sys [x]
S0 Avglogx;AVG Logging Driver;c:\windows\system32\DRIVERS\avglogx.sys [x]
S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [x]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdriverx.sys [x]
S1 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\avgidsshimx.sys [x]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [x]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [x]
S1 ComcastSecureBackupShareFilter;ComcastSecureBackupShareFilter;c:\windows\system32\DRIVERS\ComcastSecureBackupShare.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2013\avgidsagent.exe [x]
S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2013\avgwdsvc.exe [x]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [x]
S2 ComcastSecureBackupSharebackup;Comcast Secure Backup & Share Backup Service;c:\program files\SecureBackupShare\ComcastSecureBackupSharebackup.exe [x]
S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [x]
S2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\RealNetworks\RealDownloader\rndlresolversvc.exe [x]
S2 SDScannerService;Spybot-S&D; 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [x]
S2 SDUpdateService;Spybot-S&D; 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [x]
S2 SDWSCService;Spybot-S&D; 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [x]
S2 SProtection;SProtection;c:\program files\Common Files\Umbrella\umbrella.exe [x]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [x]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
S2 XobniService;XobniService;c:\program files\Xobni\XobniService.exe [x]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [x]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [x]
S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc Mcx2Svc SensrSvc
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
FontCache
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{01250B8F-D947-4F8A-9408-FE8E3EE2EC92}]
2009-08-06 16:15 264048 β-a-w- c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-10 12:20 1642448 β-a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-05-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-08 14:35]
.
2013-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-14 16:47]
.
2013-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-14 16:47]
.
.
ββ- Supplementary Scan ββ-
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&CUI;=UN35564223172798513&UM;=2&ctid;=CT3289847
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 75.75.76.76 75.75.75.75
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&CUI;=UN35092422866735130&UM;=2&SearchSource;=3&q;={searchTerms}
FF - prefs.js: browser.search.selectedEngine - WhiteSmoke New Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT3289847&CUI;=UN35092422866735130&UM;=2&SearchSource;=13
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource;=2&CUI;=UN35092422866735130&UM;=2&q;=
FF - ExtSQL: 2013-03-31 08:50; {DAC3F861-B30D-40dd-9166-F4E75327FAC7}; c:\programdata\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF - ExtSQL: 2013-05-10 17:40; [removed]; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\[removed]
FF - ExtSQL: 2013-05-10 17:40; [removed]; c:\program files\Mozilla Firefox\extensions\[removed]
FF - ExtSQL: 2013-05-10 17:58; {6c3bc03f-d7b9-43ac-8931-c242e3cae971}; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\{6c3bc03f-d7b9-43ac-8931-c242e3cae971}
FF - ExtSQL: 2013-05-10 18:55; {9ed31f84-c8b3-4926-b950-dff74047ff79}; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\{9ed31f84-c8b3-4926-b950-dff74047ff79}
FF - ExtSQL: 2013-05-11 08:50; {739df940-c5ee-4bab-9d7e-270894ae687a}; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\{739df940-c5ee-4bab-9d7e-270894ae687a}
FF - ExtSQL: !HIDDEN! 2013-05-10 17:40; [removed]; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\[removed]
FF - ExtSQL: !HIDDEN! 2013-05-10 17:40; [removed]; c:\program files\Mozilla Firefox\extensions\[removed]
FF - user.js: extensions.autoDisableScopes - 0
FF - user.js: extensions.shownSelectionUI - true
FF - user.js: extentions.y2layers.installId - e803e1ea-1a21-4412-8f75-cb13afdc7f45
FF - user.js: extentions.y2layers.defaultEnableAppsList - DropDownDeals,buzzdock,YontooNewOffers
.
.
ββ- File Associations ββ-
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{84FF7BD6-B47F-46F8-9130-01B2696B36CB} - (no file)
BHO-{1C8501DD-5580-48AB-B25C-6D5DBE835A6A} - (no file)
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
Notify-SDWinLogon - SDWinLogon.dll
AddRemove-Coupon Printer for Windows5.0.0.0 - c:\program files\Coupons\uninstall.exe
AddRemove-IMBoosterARP - c:\program files\Iminent\inst\Bootstrapper\Bootstrapper.exe
AddRemove-Search Toolbar - c:\program files\Search Toolbar\SearchToolbarUninstall.exe
.
.
.
βββββββ LOCKED REGISTRY KEYS βββββββ
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}"=hex:51,66,7a,6c,4c,1d,38,12,28,b9,b1,
5e,21,d7,a9,08,e9,36,2a,eb,0a,ff,3e,f3
"{7B13EC3E-999A-4B70-B9CB-2617B8323822}"=hex:51,66,7a,6c,4c,1d,38,12,50,ef,00,
7f,a8,d7,1e,0e,c6,dd,65,57,bd,6c,7c,36
"{A8C7C2CA-6DFD-4E16-8458-592361564D38}"=hex:51,66,7a,6c,4c,1d,38,12,a4,c1,d4,
ac,cf,23,78,0b,fb,4e,1a,63,64,08,09,2c
"{9D425283-D487-4337-BAB6-AB8354A81457}"=hex:51,66,7a,6c,4c,1d,38,12,ed,51,51,
99,b5,9a,59,06,c5,a0,e8,c3,51,f6,50,43
"{95B7759C-8C7F-4BF1-B163-73684A933233}"=hex:51,66,7a,6c,4c,1d,38,12,f2,76,a4,
91,4d,c2,9f,0e,ce,75,30,28,4f,cd,76,27
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,
27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b
"{0095C290-A428-4BDD-B98C-E0A116F1C702}"=hex:51,66,7a,6c,4c,1d,38,12,fe,c1,86,
04,1a,ea,b3,0e,c6,9a,a3,e1,13,af,83,16
"{14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6}"=hex:51,66,7a,6c,4c,1d,38,12,91,e9,dd,
10,ef,d8,6f,04,d1,21,96,ac,d9,7d,87,e2
"{1631550F-191D-4826-B069-D9439253D926}"=hex:51,66,7a,6c,4c,1d,38,12,61,56,22,
12,2f,57,48,0d,cf,7f,9a,03,97,0d,9d,32
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{3049C3E9-B461-4BC5-8870-4C09146192CA}"=hex:51,66,7a,6c,4c,1d,38,12,87,c0,5a,
34,53,fa,ab,0e,f7,66,0f,49,11,3f,d6,de
"{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}"=hex:51,66,7a,6c,4c,1d,38,12,7c,f0,b1,
38,5c,21,3d,0e,d9,78,0d,25,e1,c9,8c,d4
"{435EAA86-D32B-484F-869C-53745FCB1642}"=hex:51,66,7a,6c,4c,1d,38,12,e8,a9,4d,
47,19,9d,21,0d,f9,8a,10,34,5a,95,52,56
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,
ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3
"{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}"=hex:51,66,7a,6c,4c,1d,38,12,92,9a,85,
b0,57,58,7a,01,de,dd,87,e2,a1,ff,7a,f8
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:c4,ad,76,d6,22,26,cd,01
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
βββββββ DLLs Loaded Under Running Processes βββββββ
.
- - - - - - - > 'lsass.exe'(800)
c:\windows\system32\ARstore.dll
.
Completion time: 2013-05-12 08:58:17
ComboFix-quarantined-files.txt 2013-05-12 12:58
.
Pre-Run: 249,772,179,456 bytes free
Post-Run: 249,468,657,664 bytes free
.
- - End Of File - - 3F7D02E29DA500FBDFCAEC1B90297314
Hello;
I couldn't get combofix log right after reboot, the machine did not reboot correctly,
I ran combofix again, there was no reboot so i was able to get the log so I will add it below.
The computer seems to be running better, but still have the reboot issue.
The script file in combo fix seemed to run ok the first time.
I will get the Bios properties on my next boot.
ComboFix 13-05-12.01 - User 05/12/2013 11:32:43.4.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2812.1548 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2013-04-12 to 2013-05-12 )))))))))))))))))))))))))))))))
.
.
2013-05-12 15:43 . 2013-05-12 15:43 βββ dββw- c:\users\Default\AppData\Local\temp
2013-05-12 15:13 . 2013-05-12 15:43 βββ dββw- c:\users\User\AppData\Local\temp
2013-05-11 13:28 . 2013-05-11 13:28 βββ dββw- c:\program files\FGIcon
2013-05-11 13:28 . 2013-05-11 13:28 βββ dββw- c:\programdata\Wincert
2013-05-11 13:28 . 2013-05-11 13:28 βββ dββw- c:\program files\Settings Alerter
2013-05-11 13:28 . 2013-05-11 13:28 βββ dββw- c:\programdata\Tarma Installer
2013-05-11 12:52 . 2013-05-11 15:02 βββ dββw- c:\users\User\AppData\Local\SwvUpdater
2013-05-11 12:51 . 2013-05-11 15:03 βββ d-shβw- c:\windows\system32\AI_RecycleBin
2013-05-11 12:49 . 2013-05-11 15:03 βββ dββw- C:\AI_RecycleBin
2013-05-11 12:49 . 2013-05-11 12:49 βββ dββw- c:\program files\LyricsTube
2013-05-10 21:58 . 2013-05-11 12:51 βββ dββw- c:\users\User\AppData\Local\CRE
2013-05-10 21:40 . 2013-05-10 21:40 βββ dββw- c:\program files\LessTabs
2013-05-10 21:39 . 2013-05-10 21:39 βββ dββw- c:\program files\Common Files\Umbrella
2013-05-10 17:02 . 2013-05-10 17:02 13024 β-a-w- c:\windows\system32\drivers\SWDUMon.sys
2013-05-10 17:02 . 2013-05-10 17:02 βββ dββw- c:\users\User\AppData\Local\SlimWare Utilities Inc
2013-05-10 12:04 . 2013-05-10 12:20 βββ dββw- C:\temp
2013-05-10 01:17 . 2013-05-10 01:17 βββ dββw- C:\_OTL
2013-05-09 19:53 . 2013-05-09 19:53 βββ dββw- c:\windows\ERUNT
2013-05-09 19:53 . 2013-05-09 22:41 βββ dββw- C:\JRT
2013-05-09 15:00 . 2013-05-09 22:27 690 β-a-w- c:\windows\DeleteOnReboot.bat
2013-05-09 12:50 . 2013-05-09 12:50 βββ dββw- c:\users\User\AppData\Roaming\Foresight Software
2013-05-09 12:50 . 2013-05-10 17:42 βββ dββw- c:\programdata\Foresight Software
2013-05-08 18:56 . 2013-05-08 19:47 βββ dββw- c:\programdata\Spybot - Search & Destroy
2013-05-08 18:55 . 2009-01-25 16:14 15224 β-a-w- c:\windows\system32\sdnclean.exe
2013-05-08 18:55 . 2013-05-08 18:56 βββ dββw- c:\program files\Spybot - Search & Destroy 2
2013-05-08 18:55 . 2013-05-08 18:55 βββ dββw- c:\users\User\AppData\Local\Programs
2013-05-01 12:29 . 2013-04-04 09:35 94112 β-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-04-30 01:33 . 2013-04-30 01:33 9728 βha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-04-24 12:04 . 2013-04-12 13:45 1211752 β-a-w- c:\windows\system32\drivers\ntfs.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-01 12:30 . 2012-07-04 12:34 861088 β-a-w- c:\windows\system32\npdeployJava1.dll
2013-04-01 12:30 . 2010-12-05 10:25 782240 β-a-w- c:\windows\system32\deployJava1.dll
2013-03-31 12:49 . 2012-12-26 11:40 499712 β-a-w- c:\windows\system32\msvcp71.dll
2013-03-31 12:49 . 2012-12-26 11:40 348160 β-a-w- c:\windows\system32\msvcr71.dll
2013-03-29 06:53 . 2013-03-29 06:53 208184 β-a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2013-03-21 07:08 . 2013-03-21 07:08 182072 β-a-w- c:\windows\system32\drivers\avgtdix.sys
2013-03-19 12:19 . 2012-08-30 18:43 33624 β-a-w- c:\windows\system32\drivers\avgtpx86.sys
2013-03-19 05:04 . 2013-04-10 15:05 3968856 β-a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-19 05:04 . 2013-04-10 15:05 3913560 β-a-w- c:\windows\system32\ntoskrnl.exe
2013-03-19 04:48 . 2013-04-10 15:05 38912 β-a-w- c:\windows\system32\csrsrv.dll
2013-03-19 02:49 . 2013-04-10 15:05 69632 β-a-w- c:\windows\system32\smss.exe
2013-03-13 14:35 . 2012-04-08 15:38 693976 β-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-13 14:35 . 2011-05-15 20:27 73432 β-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-01 14:32 . 2013-03-01 14:32 22328 β-a-w- c:\windows\system32\drivers\avgidsshimx.sys
2013-03-01 03:09 . 2013-04-10 15:05 2347008 β-a-w- c:\windows\system32\win32k.sys
2013-02-15 04:37 . 2013-04-10 15:05 3217408 β-a-w- c:\windows\system32\mstscax.dll
2013-02-15 04:34 . 2013-04-10 15:05 131584 β-a-w- c:\windows\system32\aaclient.dll
2013-02-15 03:25 . 2013-04-10 15:05 36864 β-a-w- c:\windows\system32\tsgqec.dll
2013-02-12 03:32 . 2013-03-26 12:27 15872 β-a-w- c:\windows\system32\drivers\usb8023.sys
2012-09-06 01:27 . 2013-04-12 20:50 266720 β-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ComcastSecureBackupShare]
@="{72bcb80d-7778-eb4a-ec51-22340ad33e07}"
[HKEY_CLASSES_ROOT\CLSID\{72bcb80d-7778-eb4a-ec51-22340ad33e07}]
2010-12-14 17:06 3424488 β-a-w- c:\program files\SecureBackupShare\ComcastSecureBackupShareshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ComcastSecureBackupShare2]
@="{b723586e-9ca0-5b27-341a-4990a8c342cf}"
[HKEY_CLASSES_ROOT\CLSID\{b723586e-9ca0-5b27-341a-4990a8c342cf}]
2010-12-14 17:06 3424488 β-a-w- c:\program files\SecureBackupShare\ComcastSecureBackupShareshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ComcastSecureBackupShare3]
@="{f614e4c4-b3fa-5249-b9ea-4fe7d38b8cd0}"
[HKEY_CLASSES_ROOT\CLSID\{f614e4c4-b3fa-5249-b9ea-4fe7d38b8cd0}]
2010-12-14 17:06 3424488 β-a-w- c:\program files\SecureBackupShare\ComcastSecureBackupShareshell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MyTOSHIBA"="c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe" [2009-08-06 264048]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-02 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-30 98304]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-29 7625248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-21 1545512]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2009-08-21 476512]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2009-07-28 460088]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2009-08-05 738616]
"TosWaitSrv"="c:\program files\TOSHIBA\TPHM\TosWaitSrv.exe" [2009-08-07 611672]
"Teco"="c:\program files\TOSHIBA\TECO\Teco.exe" [2009-08-11 1324384]
"TWebCamera"="c:\program files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2009-08-11 2446648]
"SmartFaceVWatcher"="c:\program files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [2009-07-29 163840]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-04 611672]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-05-26 1468296]
"Toshiba Online Backup"="c:\program files\Toshiba Online Backup\ToshibaOnlineBackup.exe" [2010-01-15 965976]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"AVG_UI"="c:\program files\AVG\AVG2013\avgui.exe" [2013-04-29 4408368]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-19 421888]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"TkBellExe"="c:\program files\real\realplayer\Update\realsched.exe" [2013-03-31 295512]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"SDTray"="c:\program files\Spybot - Search & Destroy 2\SDTray.exe" [2012-11-13 3825176]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secure Backup and Share Status.lnk - c:\program files\SecureBackupShare\ComcastSecureBackupSharestat.exe [2010-12-14 3539688]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R3 cpuz134;cpuz134;c:\users\User\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [x]
R3 GamesAppService;GamesAppService;c:\program files\WildTangent Games\App\GamesAppService.exe [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 SWDUMon;SWDUMon;c:\windows\system32\DRIVERS\SWDUMon.sys [x]
R3 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [x]
R3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 AVGIDSHX;AVGIDSHX;c:\windows\system32\DRIVERS\avgidshx.sys [x]
S0 Avglogx;AVG Logging Driver;c:\windows\system32\DRIVERS\avglogx.sys [x]
S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [x]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdriverx.sys [x]
S1 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\avgidsshimx.sys [x]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [x]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [x]
S1 ComcastSecureBackupShareFilter;ComcastSecureBackupShareFilter;c:\windows\system32\DRIVERS\ComcastSecureBackupShare.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2013\avgidsagent.exe [x]
S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2013\avgwdsvc.exe [x]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [x]
S2 ComcastSecureBackupSharebackup;Comcast Secure Backup & Share Backup Service;c:\program files\SecureBackupShare\ComcastSecureBackupSharebackup.exe [x]
S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [x]
S2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\RealNetworks\RealDownloader\rndlresolversvc.exe [x]
S2 SDScannerService;Spybot-S&D; 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [x]
S2 SDUpdateService;Spybot-S&D; 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [x]
S2 SDWSCService;Spybot-S&D; 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [x]
S2 SProtection;SProtection;c:\program files\Common Files\Umbrella\umbrella.exe [x]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [x]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
S2 XobniService;XobniService;c:\program files\Xobni\XobniService.exe [x]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [x]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc Mcx2Svc SensrSvc
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
FontCache
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{01250B8F-D947-4F8A-9408-FE8E3EE2EC92}]
2009-08-06 16:15 264048 β-a-w- c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-10 12:20 1642448 β-a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-05-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-08 14:35]
.
2013-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-14 16:47]
.
2013-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-14 16:47]
.
.
ββ- Supplementary Scan ββ-
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&CUI;=UN35564223172798513&UM;=2&ctid;=CT3289847
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 75.75.76.76 75.75.75.75
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&CUI;=UN35092422866735130&UM;=2&SearchSource;=3&q;={searchTerms}
FF - prefs.js: browser.search.selectedEngine - WhiteSmoke New Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT3289847&CUI;=UN35092422866735130&UM;=2&SearchSource;=13
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource;=2&CUI;=UN35092422866735130&UM;=2&q;=
FF - ExtSQL: 2013-03-31 08:50; {DAC3F861-B30D-40dd-9166-F4E75327FAC7}; c:\programdata\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF - ExtSQL: 2013-05-10 17:40; [removed]; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\[removed]
FF - ExtSQL: 2013-05-10 17:40; [removed]; c:\program files\Mozilla Firefox\extensions\[removed]
FF - ExtSQL: 2013-05-10 17:58; {6c3bc03f-d7b9-43ac-8931-c242e3cae971}; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\{6c3bc03f-d7b9-43ac-8931-c242e3cae971}
FF - ExtSQL: 2013-05-10 18:55; {9ed31f84-c8b3-4926-b950-dff74047ff79}; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\{9ed31f84-c8b3-4926-b950-dff74047ff79}
FF - ExtSQL: 2013-05-11 08:50; {739df940-c5ee-4bab-9d7e-270894ae687a}; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\{739df940-c5ee-4bab-9d7e-270894ae687a}
FF - ExtSQL: !HIDDEN! 2013-05-10 17:40; [removed]; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\[removed]
FF - ExtSQL: !HIDDEN! 2013-05-10 17:40; [removed]; c:\program files\Mozilla Firefox\extensions\[removed]
FF - user.js: extensions.autoDisableScopes - 0
FF - user.js: extensions.shownSelectionUI - true
FF - user.js: extentions.y2layers.installId - e803e1ea-1a21-4412-8f75-cb13afdc7f45
FF - user.js: extentions.y2layers.defaultEnableAppsList - DropDownDeals,buzzdock,YontooNewOffers
.
.
ββ- File Associations ββ-
.
.scr=AutoCADScriptFile
.
.
βββββββ LOCKED REGISTRY KEYS βββββββ
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}"=hex:51,66,7a,6c,4c,1d,38,12,28,b9,b1,
5e,21,d7,a9,08,e9,36,2a,eb,0a,ff,3e,f3
"{7B13EC3E-999A-4B70-B9CB-2617B8323822}"=hex:51,66,7a,6c,4c,1d,38,12,50,ef,00,
7f,a8,d7,1e,0e,c6,dd,65,57,bd,6c,7c,36
"{A8C7C2CA-6DFD-4E16-8458-592361564D38}"=hex:51,66,7a,6c,4c,1d,38,12,a4,c1,d4,
ac,cf,23,78,0b,fb,4e,1a,63,64,08,09,2c
"{9D425283-D487-4337-BAB6-AB8354A81457}"=hex:51,66,7a,6c,4c,1d,38,12,ed,51,51,
99,b5,9a,59,06,c5,a0,e8,c3,51,f6,50,43
"{95B7759C-8C7F-4BF1-B163-73684A933233}"=hex:51,66,7a,6c,4c,1d,38,12,f2,76,a4,
91,4d,c2,9f,0e,ce,75,30,28,4f,cd,76,27
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,
27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b
"{0095C290-A428-4BDD-B98C-E0A116F1C702}"=hex:51,66,7a,6c,4c,1d,38,12,fe,c1,86,
04,1a,ea,b3,0e,c6,9a,a3,e1,13,af,83,16
"{14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6}"=hex:51,66,7a,6c,4c,1d,38,12,91,e9,dd,
10,ef,d8,6f,04,d1,21,96,ac,d9,7d,87,e2
"{1631550F-191D-4826-B069-D9439253D926}"=hex:51,66,7a,6c,4c,1d,38,12,61,56,22,
12,2f,57,48,0d,cf,7f,9a,03,97,0d,9d,32
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{3049C3E9-B461-4BC5-8870-4C09146192CA}"=hex:51,66,7a,6c,4c,1d,38,12,87,c0,5a,
34,53,fa,ab,0e,f7,66,0f,49,11,3f,d6,de
"{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}"=hex:51,66,7a,6c,4c,1d,38,12,7c,f0,b1,
38,5c,21,3d,0e,d9,78,0d,25,e1,c9,8c,d4
"{435EAA86-D32B-484F-869C-53745FCB1642}"=hex:51,66,7a,6c,4c,1d,38,12,e8,a9,4d,
47,19,9d,21,0d,f9,8a,10,34,5a,95,52,56
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,
ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3
"{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}"=hex:51,66,7a,6c,4c,1d,38,12,92,9a,85,
b0,57,58,7a,01,de,dd,87,e2,a1,ff,7a,f8
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:c4,ad,76,d6,22,26,cd,01
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
βββββββ DLLs Loaded Under Running Processes βββββββ
.
- - - - - - - > 'lsass.exe'(796)
c:\windows\system32\ARstore.dll
.
- - - - - - - > 'Explorer.exe'(4508)
c:\program files\SecureBackupShare\ComcastSecureBackupShareshell.dll
c:\program files\SecureBackupShare\LIBEAY32.dll
.
Completion time: 2013-05-12 11:46:33
ComboFix-quarantined-files.txt 2013-05-12 15:46
ComboFix2.txt 2013-05-12 15:21
ComboFix3.txt 2013-05-12 13:43
ComboFix4.txt 2013-05-12 12:58
.
Pre-Run: 249,462,284,288 bytes free
Post-Run: 249,160,941,568 bytes free
.
- - End Of File - - 1303AFCF2BEBDCEDC60FFBB6595E595B