Combofix Log:
ComboFix 12-11-21.01 - Larry 11/22/2012 0:44.3.8 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.3189.2117 [GMT -5:00]
Running from: c:\users\Larry\Desktop\ComboFix.exe
Command switches used :: c:\users\Larry\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2012-10-22 to 2012-11-22 )))))))))))))))))))))))))))))))
.
.
2012-11-22 05:54 . 2012-11-22 05:54 -------- d-----w- c:\users\Mcx1-BABYCAKES\AppData\Local\temp
2012-11-22 05:54 . 2012-11-22 05:54 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-21 22:11 . 2012-11-08 18:00 6812136 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{02AA4A37-6AD1-4A31-B080-13BA72C4435A}\mpengine.dll
2012-11-21 04:14 . 2012-11-22 05:54 -------- d-----w- c:\users\Larry\AppData\Local\temp
2012-11-20 23:19 . 2012-11-20 23:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-11-20 23:19 . 2012-09-30 00:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-11-20 21:52 . 2012-11-08 18:00 6812136 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-11-16 08:03 . 2012-07-26 03:39 526952 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2012-11-16 08:03 . 2012-07-26 03:39 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2012-11-16 08:03 . 2012-07-26 02:46 9728 ----a-w- c:\windows\system32\Wdfres.dll
2012-11-16 08:02 . 2012-07-26 02:32 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2012-11-16 08:02 . 2012-07-26 02:33 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2012-11-16 08:02 . 2012-07-26 03:20 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2012-11-16 08:02 . 2012-07-26 03:20 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2012-11-16 08:02 . 2012-07-26 03:20 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2012-11-16 08:02 . 2012-07-26 03:21 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2012-11-16 08:02 . 2012-07-26 03:20 613888 ----a-w- c:\windows\system32\WUDFx.dll
2012-11-15 23:29 . 2012-11-15 23:29 -------- d-----w- c:\users\Larry\AppData\Roaming\MiKTeX
2012-11-15 23:26 . 2012-11-15 23:26 -------- d-----w- c:\users\Larry\AppData\Local\MiKTeX
2012-11-15 23:24 . 2012-11-15 23:24 -------- d-----w- c:\programdata\MiKTeX
2012-11-15 23:22 . 2012-11-15 23:23 -------- d-----w- c:\program files\MiKTeX 2.9
2012-11-15 14:10 . 2012-09-25 21:55 78336 ----a-w- c:\windows\system32\synceng.dll
2012-11-15 14:10 . 2012-10-18 17:57 2344960 ----a-w- c:\windows\system32\win32k.sys
2012-11-01 16:14 . 2012-08-21 17:01 26840 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-11-01 16:12 . 2012-11-01 16:12 -------- d-----w- c:\program files\iPod
2012-11-01 16:12 . 2012-11-01 16:13 -------- d-----w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-20 22:10 . 2012-10-17 20:25 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2012-11-16 21:13 . 2012-04-11 14:48 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-11-16 21:13 . 2011-11-30 04:02 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-17 20:25 . 2012-10-17 20:25 53248 ----a-r- c:\users\Larry\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2012-10-03 07:31 . 2012-10-20 07:34 740784 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{66442B3D-69D0-4C06-A6A9-6DFD403CAF5E}\gapaengine.dll
2012-10-03 07:31 . 2012-10-03 07:31 740784 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2012-09-25 03:39 . 2012-09-25 03:39 12872 ----a-w- c:\windows\system32\bootdelete.exe
2012-09-18 09:33 . 2012-09-18 09:33 55096 ----a-w- c:\windows\system32\LMouFiltCoInst.dll
2012-09-18 09:33 . 2012-09-18 09:33 43960 ----a-w- c:\windows\system32\drivers\LHidFilt.Sys
2012-09-18 09:33 . 2012-09-18 09:33 39608 ----a-w- c:\windows\system32\drivers\LMouFilt.Sys
2012-09-18 09:33 . 2012-09-18 09:33 1583928 ----a-w- c:\windows\system32\LkmdfCoInst.dll
2012-09-18 09:32 . 2012-09-18 09:32 43704 ----a-w- c:\windows\system32\drivers\LEqdUsb.sys
2012-09-18 09:32 . 2012-09-18 09:32 12216 ----a-w- c:\windows\system32\drivers\LHidEqd.sys
2012-09-14 18:30 . 2012-10-10 00:57 2048 ----a-w- c:\windows\system32\tzres.dll
2012-09-10 23:07 . 2012-09-10 23:07 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-10 23:07 . 2012-09-10 23:07 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-10 23:07 . 2012-09-10 23:07 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-31 17:21 . 2012-10-10 00:56 1210736 ----a-w- c:\windows\system32\drivers\ntfs.sys
2012-08-31 02:03 . 2012-08-31 02:03 193552 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-31 02:03 . 2012-03-21 00:44 99272 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2012-08-30 17:18 . 2012-10-10 00:56 3958128 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-08-30 17:18 . 2012-10-10 00:56 3902832 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-08-30 08:17 . 2012-09-21 11:12 6980552 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E762A38B-913E-47C6-AB32-0B573D0D7F9A}\mpengine.dll
2012-08-24 17:10 . 2012-10-10 00:57 172544 ----a-w- c:\windows\system32\wintrust.dll
2012-10-27 05:08 . 2012-10-27 05:07 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AF949550-9094-4807-95EC-D1C317803333}]
2012-10-06 08:16 366904 ----a-w- c:\program files\Logitech\SetPointP\SetPointSmooth.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"iCloudServices"="c:\program files\Common Files\Apple\Internet Services\iCloudServices.exe" [2012-08-29 59280]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-12-17 98304]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-09-24 1466368]
"fspuip"="c:\program files\FSP\fspuip.exe" [2009-08-31 3342336]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-09-24 7703072]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-28 59280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-01-21 91520]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"AllShareAgent"="c:\program files\Samsung\AllShare\AllShareAgent.exe" [2012-03-02 285072]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2012-10-06 1843512]
.
c:\users\Larry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech . Product Registration.lnk - c:\program files\Common Files\Logishrd\eReg\SetPoint\eReg.exe [2009-11-16 517384]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Hotkey.lnk - c:\program files\Hotkey\Hotkey.exe [2009-12-31 2413568]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.207\SSScheduler.exe [2011-6-17 272528]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2012-10-01 07:22 66360 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro36Crusader]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro36CrusaderBoot]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R0 johci;JMicron 1394 Filter Driver;c:\windows\system32\DRIVERS\johci.sys [x]
R2 SamsungAllShareV2.0;Samsung AllShare PC;c:\program files\Samsung\AllShare\AllShareDMS\AllShareDMS.exe [x]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.207\McCHSvc.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
R3 SimpleSlideShowServer;SimpleSlideShowServer;c:\program files\Samsung\AllShare\AllShareSlideShowService.exe [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [x]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 PowerBiosServer;PowerBiosServer;c:\program files\Hotkey\PowerBiosServer.exe [x]
S3 ALSysIO;ALSysIO;c:\users\Larry\AppData\Local\Temp\ALSysIO.sys [x]
S3 fspad_wlh32;Finger Sensing Pad Driver for Windows 2000/XP/Vista/Win7_wlh32;c:\windows\system32\DRIVERS\fspad_wlh32.sys [x]
S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\Drivers\LEqdUsb.Sys [x]
S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\Drivers\LHidEqd.Sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 NETw5s32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:\windows\system32\DRIVERS\NETw5s32.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - ALSYSIO
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-11 21:13]
.
2012-11-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-11-22 00:29]
.
2012-11-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-11-22 00:29]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://[bleep]inghomepage.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
FF - ProfilePath - c:\users\Larry\AppData\Roaming\Mozilla\Firefox\Profiles\xi4t5mq2.default-1353535127488\
FF - ExtSQL: 2012-10-17 16:23; {F003DA68-8256-4b37-A6C4-350FA04494DF}; c:\program files\Logitech\SetPointP\LogiSmoothFirefoxExt
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-191230454-82733176-2438189507-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:11,5f,55,34,cb,ee,36,c5,3b,b0,c2,7e,1f,be,32,21,b7,fd,a5,39,d6,
18,f8,e3,6e,e3,c5,c8,a7,ad,f5,94,63,73,59,60,d6,37,9c,bb,12,7f,a9,74,8b,e6,\
"rkeysecu"=hex:f0,74,40,85,a9,94,3c,ba,d1,06,6c,d7,b4,f3,26,6b
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-11-22 00:56:24
ComboFix-quarantined-files.txt 2012-11-22 05:56
ComboFix2.txt 2012-11-21 18:58
ComboFix3.txt 2012-11-21 04:14
.
Pre-Run: 12,727,504,896 bytes free
Post-Run: 12,676,763,648 bytes free
.
- - End Of File - - 2A18981E9205FFCDCC8BB997659C4BD3