ComboFix 13-11-03.02 - Collin 11/03/2013 15:47:27.1.4 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8108.5899 [GMT -8:00] Running from: c:\users\Collin\Downloads\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F} SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Collin\AppData\Roaming\inst.exe . . ((((((((((((((((((((((((( Files Created from 2013-10-03 to 2013-11-03 ))))))))))))))))))))))))))))))) . . 2013-11-03 23:51 . 2013-11-03 23:51 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-11-03 18:33 . 2013-10-14 07:12 10280728 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{712397E4-EBCA-443D-BA81-94C02045B5A5}\mpengine.dll 2013-11-03 00:09 . 2013-11-03 00:09 -------- d-----w- c:\program files (x86)\GanttProject-2.6 2013-11-02 07:18 . 2013-11-02 07:18 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help 2013-11-02 01:27 . 2013-10-14 07:12 10280728 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-11-01 20:26 . 2013-11-01 20:26 -------- d-----w- c:\program files (x86)\Audacity 2013-11-01 05:38 . 2013-11-01 05:38 -------- d-----w- c:\program files (x86)\NAMCO BANDAI Games 2013-11-01 05:37 . 2013-11-01 05:37 -------- d-----w- c:\windows\SysWow64\xlive 2013-11-01 05:37 . 2013-11-01 05:37 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE 2013-11-01 03:59 . 2013-11-02 01:53 -------- d-----w- c:\program files (x86)\Common Files\Symantec Shared 2013-11-01 00:56 . 2013-11-02 18:14 -------- d-----w- c:\programdata\Norton 2013-10-31 23:17 . 2013-11-02 06:56 214392 ----a-w- c:\windows\SysWow64\PnkBstrB.exe 2013-10-31 23:17 . 2013-11-02 06:50 214392 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0 2013-10-31 23:17 . 2013-10-31 23:17 76888 ----a-w- c:\windows\system32\PnkBstrA.exe 2013-10-30 19:53 . 2013-11-02 01:54 -------- d-----w- c:\program files (x86)\TrojanHunter 5.3 2013-10-30 18:53 . 2013-10-30 19:33 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2013-10-30 18:53 . 2013-10-30 18:53 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2013-10-30 03:03 . 2013-10-30 03:03 -------- d-----w- c:\programdata\Malwarebytes 2013-10-30 03:03 . 2013-10-30 03:03 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-10-30 03:03 . 2013-04-04 21:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-10-30 02:53 . 2013-10-30 02:53 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{10564C29-8A9E-4162-A7E5-C90C4F279CFF}\gapaengine.dll 2013-10-30 02:50 . 2013-10-30 02:50 -------- d-----w- c:\program files (x86)\Microsoft Security Client 2013-10-30 02:50 . 2013-10-30 02:50 -------- d-----w- c:\program files\Microsoft Security Client 2013-10-28 20:33 . 2013-10-18 01:36 1063200 ----a-w- c:\windows\system32\nvspcap64.dll 2013-10-28 20:33 . 2013-10-18 01:36 955168 ----a-w- c:\windows\SysWow64\nvspcap.dll 2013-10-28 20:32 . 2013-09-27 23:01 39200 ----a-w- c:\windows\system32\drivers\nvvad64v.sys 2013-10-28 20:32 . 2013-09-27 23:01 28960 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll 2013-10-28 01:50 . 2013-10-28 01:50 -------- d-----w- c:\program files (x86)\Link Logger 2013-10-23 10:02 . 2013-10-23 10:02 589600 ----a-w- c:\windows\SysWow64\nvStreaming.exe 2013-10-22 22:09 . 2013-10-16 00:48 1884448 ----a-w- c:\windows\system32\nvdispco6433158.dll 2013-10-22 22:09 . 2013-10-16 00:48 1511712 ----a-w- c:\windows\system32\nvdispgenco6433158.dll 2013-10-21 02:06 . 2013-10-21 02:06 -------- d-----w- c:\program files (x86)\Common Files\BattlEye 2013-10-21 02:00 . 2013-10-21 02:00 -------- d-----w- c:\programdata\Bohemia Interactive 2013-10-21 00:55 . 2013-10-21 00:55 -------- d-----w- c:\program files\OBS 2013-10-21 00:55 . 2013-10-21 00:55 -------- d-----w- c:\program files (x86)\OBS 2013-10-20 23:10 . 2013-10-20 23:10 -------- d-----w- c:\program files (x86)\FileZilla FTP Client 2013-10-20 22:02 . 2013-10-20 22:02 -------- d-----w- c:\program files (x86)\Notepad++ 2013-10-19 19:26 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll 2013-10-16 22:20 . 2013-10-16 22:20 -------- d-----w- c:\programdata\vsosdk 2013-10-16 21:53 . 2013-10-16 21:53 -------- d-----w- c:\program files (x86)\TeamViewer 2013-10-16 08:16 . 2013-10-16 08:16 -------- d-----w- c:\program files (x86)\Microsoft Synchronization Services 2013-10-16 08:16 . 2013-10-16 08:16 -------- d-----w- c:\windows\PCHEALTH 2013-10-16 08:16 . 2013-10-16 08:16 -------- d-----w- c:\program files (x86)\Microsoft Sync Framework 2013-10-16 08:16 . 2013-10-16 08:16 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition 2013-10-16 08:14 . 2013-10-16 08:14 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8 2013-10-16 08:14 . 2013-10-16 08:14 -------- d-----w- c:\program files\Microsoft Office 2013-10-16 08:14 . 2013-10-16 08:14 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services 2013-10-16 08:13 . 2013-11-03 08:30 -------- d-----w- c:\programdata\Microsoft Help 2013-10-16 08:12 . 2013-10-16 08:12 -------- d-----r- C:\MSOCache 2013-10-15 09:00 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui 2013-10-15 03:28 . 2013-10-15 03:28 973736 ----a-w- c:\windows\system32\deployJava1.dll 2013-10-15 03:28 . 2013-10-15 03:28 312744 ----a-w- c:\windows\system32\javaws.exe 2013-10-15 03:28 . 2013-10-15 03:28 1095080 ----a-w- c:\windows\system32\npDeployJava1.dll 2013-10-15 03:28 . 2013-10-15 03:28 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2013-10-15 03:28 . 2013-10-15 03:28 189352 ----a-w- c:\windows\system32\javaw.exe 2013-10-15 03:28 . 2013-10-15 03:28 189352 ----a-w- c:\windows\system32\java.exe 2013-10-15 03:28 . 2013-10-15 03:28 -------- d-----w- c:\program files\Java 2013-10-15 03:27 . 2013-10-15 03:27 -------- d-----w- c:\windows\system32\appmgmt 2013-10-15 03:26 . 2013-10-15 03:26 -------- d-----w- c:\programdata\Oracle 2013-10-15 03:25 . 2013-10-15 03:25 868264 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-10-15 03:25 . 2013-10-15 03:25 790440 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-10-15 03:20 . 2013-10-15 03:20 -------- d-----w- c:\programdata\McAfee 2013-10-15 00:38 . 2013-10-15 00:38 -------- d-----w- c:\programdata\LogiShrd 2013-10-15 00:37 . 2013-10-15 00:37 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys 2013-10-15 00:37 . 2013-10-15 00:38 -------- d-----w- c:\program files\Logitech Gaming Software 2013-10-14 17:27 . 2013-10-14 17:27 -------- d-----w- c:\windows\SysWow64\Wat 2013-10-14 17:27 . 2013-10-14 17:27 -------- d-----w- c:\windows\system32\Wat 2013-10-14 17:14 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe 2013-10-14 17:13 . 2013-07-19 01:58 2048 ----a-w- c:\windows\system32\tzres.dll 2013-10-14 17:12 . 2013-07-03 04:05 76800 ----a-w- c:\windows\system32\drivers\hidclass.sys 2013-10-14 17:11 . 2011-04-29 03:06 467456 ----a-w- c:\windows\system32\drivers\srv.sys 2013-10-14 17:10 . 2013-08-29 02:17 5549504 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-10-14 17:09 . 2012-06-16 05:16 609792 ----a-w- c:\windows\system32\vbscript.dll 2013-10-14 17:08 . 2011-12-16 08:46 634880 ----a-w- c:\windows\system32\msvcrt.dll 2013-10-14 17:00 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys 2013-10-14 17:00 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll 2013-10-14 17:00 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll 2013-10-14 17:00 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll 2013-10-14 17:00 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll 2013-10-14 16:56 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll 2013-10-14 16:56 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll 2013-10-14 01:48 . 2013-10-14 01:48 -------- d-----w- c:\program files\Microsoft Mouse and Keyboard Center 2013-10-14 01:24 . 2012-02-17 06:38 1031680 ----a-w- c:\windows\system32\rdpcore.dll 2013-10-14 01:24 . 2012-02-17 05:34 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll 2013-10-14 01:24 . 2012-02-17 04:57 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys 2013-10-14 01:20 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll 2013-10-14 01:20 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe 2013-10-14 01:20 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll 2013-10-14 01:20 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll 2013-10-14 01:20 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll 2013-10-14 01:20 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll 2013-10-14 01:20 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll 2013-10-14 01:20 . 2012-06-02 22:19 186752 ----a-w- c:\windows\system32\wuwebv.dll 2013-10-14 01:20 . 2012-06-02 22:15 36864 ----a-w- c:\windows\system32\wuapp.exe 2013-10-14 01:02 . 2013-10-30 05:25 -------- d--h--w- c:\program files (x86)\Common Files\EAInstaller 2013-10-14 01:02 . 2013-10-30 05:25 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins 2013-10-14 01:01 . 2013-10-14 01:01 -------- d-----w- c:\programdata\Package Cache 2013-10-14 01:01 . 2008-10-15 13:22 519000 ----a-w- c:\windows\system32\d3dx10_40.dll 2013-10-14 01:01 . 2008-10-15 13:22 452440 ----a-w- c:\windows\SysWow64\d3dx10_40.dll 2013-10-14 01:01 . 2008-10-15 13:22 2605920 ----a-w- c:\windows\system32\D3DCompiler_40.dll 2013-10-14 01:01 . 2008-10-15 13:22 2036576 ----a-w- c:\windows\SysWow64\D3DCompiler_40.dll 2013-10-14 01:01 . 2008-10-15 13:22 5631312 ----a-w- c:\windows\system32\D3DX9_40.dll 2013-10-14 01:01 . 2008-10-15 13:22 4379984 ----a-w- c:\windows\SysWow64\D3DX9_40.dll 2013-10-14 00:15 . 2013-10-16 21:43 -------- d-----w- c:\programdata\VSO 2013-10-14 00:15 . 2013-10-14 00:15 -------- d-----w- c:\program files (x86)\VSO 2013-10-13 22:51 . 2013-10-15 00:51 -------- d-----w- c:\program files (x86)\Warcraft III 2013-10-13 22:37 . 2013-10-13 22:51 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment 2013-10-13 22:11 . 2013-10-13 22:11 -------- d-----w- c:\program files (x86)\Common Files\Adobe 2013-10-13 22:05 . 2013-10-13 22:05 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys 2013-10-13 22:05 . 2013-10-13 22:05 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite 2013-10-13 22:04 . 2013-10-14 23:11 -------- d-----w- c:\programdata\DAEMON Tools Lite 2013-10-13 21:08 . 2006-02-03 15:43 3830992 ----a-w- c:\windows\system32\d3dx9_29.dll 2013-10-13 21:04 . 2013-10-13 21:04 -------- d-----w- c:\program files (x86)\RivaTuner Statistics Server 2013-10-13 21:03 . 2013-10-31 02:05 -------- d-----w- c:\program files (x86)\EVGA Precision X 2013-10-13 21:03 . 2013-10-13 21:03 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-10-13 21:03 . 2013-10-13 21:03 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-10-13 21:03 . 2013-10-13 21:03 -------- d-----w- c:\windows\SysWow64\Macromed 2013-10-13 21:03 . 2013-10-13 21:03 -------- d-----w- c:\windows\system32\Macromed 2013-10-13 21:02 . 2013-10-13 21:02 -------- d-----w- c:\program files\Core Temp 2013-10-13 20:57 . 2013-10-13 20:57 -------- d-----w- c:\program files (x86)\Katawa Shoujo 2013-10-13 20:57 . 2013-10-30 02:32 -------- d-----w- c:\program files (x86)\Origin Games 2013-10-13 20:47 . 2013-10-13 20:02 -------- d-----w- c:\windows\Panther 2013-10-13 20:37 . 2013-10-13 20:37 -------- d-----w- c:\program files (x86)\AGEIA Technologies 2013-10-13 20:35 . 2013-11-03 18:22 -------- d-----w- c:\programdata\NVIDIA 2013-10-13 20:35 . 2013-11-03 18:22 -------- d-----w- c:\users\UpdatusUser . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-08-29 01:48 . 2013-10-14 17:10 44032 ----a-w- c:\windows\apppatch\acwow64.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files (x86)\Steam\steam.exe" [2013-10-30 1820584] "EADM"="c:\program files (x86)\Origin\Origin.exe" [2013-10-15 3561816] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-08-01 3673696] "uTorrent"="c:\users\Collin\AppData\Roaming\uTorrent\uTorrent.exe" [2013-10-25 898904] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Corsair Headset Software"="c:\program files (x86)\Corsair\Corsair Headset Software\HeadsetControlPanel.exe" [2013-03-26 3160064] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-09-05 958576] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 ALSysIO;ALSysIO;c:\users\Collin\AppData\Local\Temp\ALSysIO64.sys;c:\users\Collin\AppData\Local\Temp\ALSysIO64.sys [x] R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] S0 asahci64;asahci64;c:\windows\system32\DRIVERS\asahci64.sys;c:\windows\SYSNATIVE\DRIVERS\asahci64.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x] S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys;c:\windows\SYSNATIVE\DRIVERS\asmthub3.sys [x] S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys;c:\windows\SYSNATIVE\DRIVERS\asmtxhci.sys [x] S3 CorsairAudioFilter;Corsair Audio Filtering Service;c:\windows\system32\DRIVERS\corsveng2kamd64.sys;c:\windows\SYSNATIVE\DRIVERS\corsveng2kamd64.sys [x] S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x] S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x] S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x] S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x] S3 RTCore64;RTCore64;c:\program files (x86)\EVGA Precision X\RTCore64.sys;c:\program files (x86)\EVGA Precision X\RTCore64.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2013-11-03 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-13 21:03] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-10-18 1028384] "Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2013-08-01 8290584] "ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2013-10-18 1063200] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-08-12 1356240] . ------- Supplementary Scan ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 TCP: Interfaces\{13E36A18-7EFE-4681-AF95-7A246853BC05}: NameServer = 8.8.8.8,8.8.4.4 FF - ProfilePath - c:\users\Collin\AppData\Roaming\Mozilla\Firefox\Profiles\ltsv2yd6.default\ FF - ExtSQL: 2013-10-13 13:38; jid1-xUfzOsOFlzSOXg@jetpack; c:\users\Collin\AppData\Roaming\Mozilla\Firefox\Profiles\ltsv2yd6.default\extensions\jid1-xUfzOsOFlzSOXg@jetpack.xpi FF - ExtSQL: 2013-10-13 13:38; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Collin\AppData\Roaming\Mozilla\Firefox\Profiles\ltsv2yd6.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF - ExtSQL: 2013-10-13 14:07; {2c93446d-612b-416d-9af0-b7355797b611}; c:\users\Collin\AppData\Roaming\Mozilla\Firefox\Profiles\ltsv2yd6.default\extensions\{2c93446d-612b-416d-9af0-b7355797b611}.xpi . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-11-03 15:53:25 ComboFix-quarantined-files.txt 2013-11-03 23:53 . Pre-Run: 134,579,367,936 bytes free Post-Run: 135,179,931,648 bytes free . - - End Of File - - 6997952E56EB556ACF73DEFB1A96EBC6 A36C5E4F47E84449FF07ED3517B43A31