ComboFix seemed to find and delete a few things. Log below. I tried to re-create the re-direct by searching in Google, and the usual behavior where Happili* was displayed at the first attempt, didn't happen this time. I did not get a redirect.
ComboFix 12-04-19.01 - JSR 04/19/2012 16:18:57.1.8 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8086.6170 [GMT -4:00]
Running from: c:\users\JSR\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: PC Tools Spyware Doctor *Disabled/Outdated* {94076BB2-F3DA-227F-9A1E-F060FF73600F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
c:\users\JSR\AppData\Local\Temp\{C353F26A-35F9-4077-B058-0375B027DF1E}\fpb.tmp
c:\users\JSR\AppData\Local\Temp\rathc.dll
c:\windows\SysWow64\dlumd10.dll
c:\windows\SysWow64\dlumd11.dll
c:\windows\SysWow64\dlumd9.dll
E:\install.exe
F:\Autorun.inf
.
.
((((((((((((((((((((((((( Files Created from 2012-03-19 to 2012-04-19 )))))))))))))))))))))))))))))))
.
.
2012-04-19 11:25 . 2010-11-12 09:00 302080 ----a-w- c:\windows\system32\CNCALAN.DLL
2012-04-12 16:03 . 2012-04-12 16:03 -------- d-----w- C:\Dell Management Packs
2012-04-12 15:56 . 2012-04-12 15:56 -------- d-----w- c:\programdata\Canon IJ Network Tool
2012-04-12 15:56 . 2010-09-13 18:44 106496 ----a-w- c:\windows\SysWow64\CNC880U.dll
2012-04-12 15:56 . 2010-09-06 21:03 315392 ----a-w- c:\windows\SysWow64\CNC880L.dll
2012-04-12 15:56 . 2008-08-25 22:02 15872 ----a-w- c:\windows\SysWow64\CNHMCA.dll
2012-04-12 15:56 . 2012-04-12 15:56 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
2012-04-12 15:56 . 2012-04-12 15:56 -------- d--h--w- c:\program files\CanonBJ
2012-04-12 15:12 . 2012-04-12 15:12 -------- d-----w- c:\users\JSR\AppData\Roaming\Registry Mechanic
2012-04-12 15:10 . 2012-03-21 16:23 512472 ----a-w- c:\windows\SysWow64\msxml.dll
2012-04-12 15:10 . 2012-03-21 16:23 40408 ----a-w- c:\windows\system32\CleanMFT64.exe
2012-04-12 15:10 . 2008-04-02 20:54 1101824 ----a-w- c:\windows\SysWow64\UniBox210.ocx
2012-04-12 15:10 . 2008-04-02 20:53 212992 ----a-w- c:\windows\SysWow64\UniBoxVB12.ocx
2012-04-12 15:10 . 2008-04-02 20:53 880640 ----a-w- c:\windows\SysWow64\UniBox10.ocx
2012-04-12 15:10 . 2012-04-12 15:10 -------- d-----w- c:\program files (x86)\PC Tools
2012-04-12 15:10 . 2012-04-12 15:10 -------- d-----w- c:\users\JSR\AppData\Roaming\Product_RM
2012-04-12 15:00 . 2012-04-12 15:00 -------- d-----w- c:\windows\system32\appmgmt
2012-04-12 10:03 . 2012-04-12 10:03 -------- d-----w- c:\windows\ja-JP
2012-04-12 10:03 . 2012-04-19 11:25 -------- d-----w- c:\windows\SysWow64\wbem\ja-JP
2012-04-12 10:03 . 2012-04-12 10:03 -------- d-----w- c:\windows\SysWow64\ja
2012-04-12 10:03 . 2012-04-12 10:03 -------- d-----w- c:\windows\SysWow64\drivers\UMDF\ja-JP
2012-04-12 10:03 . 2012-04-12 10:03 -------- d-----w- c:\windows\SysWow64\drivers\ja-JP
2012-04-12 10:03 . 2012-04-12 10:03 -------- d-----w- c:\windows\SysWow64\0411
2012-04-12 10:03 . 2012-04-12 10:03 -------- d-----w- c:\windows\system32\ja
2012-04-12 10:03 . 2012-04-12 10:03 -------- d-----w- c:\windows\system32\drivers\UMDF\ja-JP
2012-04-12 10:03 . 2012-04-12 10:03 -------- d-----w- c:\windows\system32\drivers\ja-JP
2012-04-12 10:03 . 2012-04-12 10:03 -------- d-----w- c:\windows\system32\0411
2012-04-12 10:02 . 2012-04-19 11:25 -------- d-----w- c:\windows\system32\wbem\ja-JP
2012-04-12 10:00 . 2010-11-20 09:27 287744 ----a-w- c:\windows\system32\lzhfldr2.dll
2012-04-12 10:00 . 2010-11-20 08:20 266240 ----a-w- c:\windows\SysWow64\lzhfldr2.dll
2012-04-12 10:00 . 2009-07-13 22:15 377856 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\mshwjpn.dll
2012-04-12 10:00 . 2009-07-13 22:07 11507712 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\mshwjpnr.dll
2012-04-12 10:00 . 2009-07-13 22:15 1179136 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\imjplm.dll
2012-04-12 10:00 . 2009-07-13 22:15 9728 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\dicjp.dll
2012-04-12 10:00 . 2009-07-13 23:12 3072 ----a-w- c:\windows\system32\Spool\prtprocs\x64\ja-JP\LXKPTPRC.DLL.mui
2012-04-12 10:00 . 2009-07-13 22:41 492032 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\mshwjpn.dll
2012-04-12 10:00 . 2009-07-13 22:41 1198080 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\imjplm.dll
2012-04-12 10:00 . 2009-07-13 22:40 11776 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\dicjp.dll
2012-04-12 10:00 . 2009-07-13 22:29 11507712 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\mshwjpnr.dll
2012-04-12 04:06 . 2012-04-12 04:06 -------- d-----w- c:\windows\SysWow64\drivers\da-DK
2012-04-12 04:05 . 2012-04-12 04:05 -------- d-----w- c:\windows\SysWow64\da
2012-04-12 04:05 . 2012-04-12 09:56 -------- d-----w- c:\windows\SysWow64\wbem\da-DK
2012-04-12 04:05 . 2012-04-12 04:05 -------- d-----w- c:\windows\da-DK
2012-04-12 04:05 . 2012-04-12 04:05 -------- d-----w- c:\windows\system32\drivers\da-DK
2012-04-12 04:05 . 2012-04-12 04:05 -------- d-----w- c:\windows\system32\drivers\UMDF\da-DK
2012-04-12 04:05 . 2012-04-12 04:05 -------- d-----w- c:\windows\system32\da
2012-04-12 04:05 . 2012-04-12 09:56 -------- d-----w- c:\windows\system32\wbem\da-DK
2012-04-12 04:04 . 2012-04-12 09:58 -------- d-----w- c:\windows\SysWow64\wbem\ro-RO
2012-04-12 04:04 . 2012-04-12 04:04 -------- d-----w- c:\windows\SysWow64\drivers\ro-RO
2012-04-12 04:04 . 2012-04-12 04:04 -------- d-----w- c:\windows\ro-RO
2012-04-12 04:04 . 2012-04-12 04:04 -------- d-----w- c:\windows\system32\drivers\ro-RO
2012-04-12 04:04 . 2012-04-12 09:58 -------- d-----w- c:\windows\system32\wbem\ro-RO
2012-04-12 04:04 . 2012-04-12 04:04 -------- d-----w- c:\windows\SysWow64\drivers\hr-HR
2012-04-12 04:04 . 2012-04-12 09:59 -------- d-----w- c:\windows\SysWow64\wbem\hr-HR
2012-04-12 04:04 . 2012-04-12 04:04 -------- d-----w- c:\windows\system32\drivers\hr-HR
2012-04-12 04:04 . 2012-04-12 04:04 -------- d-----w- c:\windows\hr-HR
2012-04-12 04:04 . 2012-04-12 09:59 -------- d-----w- c:\windows\system32\wbem\hr-HR
2012-04-12 04:03 . 2012-04-12 04:03 -------- d-----w- c:\windows\SysWow64\zh-CHT
2012-04-12 04:03 . 2012-04-12 04:03 -------- d-----w- c:\windows\SysWow64\drivers\zh-TW
2012-04-12 04:03 . 2012-04-12 09:56 -------- d-----w- c:\windows\SysWow64\wbem\zh-HK
2012-04-12 04:03 . 2012-04-12 04:03 -------- d-----w- c:\windows\SysWow64\wbem\zh-TW
2012-04-12 04:03 . 2012-04-12 04:03 -------- d-----w- c:\windows\zh-TW
2012-04-12 04:03 . 2012-04-12 04:03 -------- d-----w- c:\windows\system32\zh-CHT
2012-04-12 04:02 . 2012-04-12 04:02 -------- d-----w- c:\windows\system32\drivers\zh-TW
2012-04-12 04:02 . 2012-04-12 04:02 -------- d-----w- c:\windows\system32\drivers\zh-HK
2012-04-12 04:02 . 2012-04-12 04:02 -------- d-----w- c:\windows\system32\drivers\UMDF\zh-TW
2012-04-12 04:02 . 2012-04-12 04:02 -------- d-----w- c:\windows\system32\wbem\zh-TW
2012-04-12 04:02 . 2012-04-12 09:56 -------- d-----w- c:\windows\system32\wbem\zh-HK
2012-04-12 04:02 . 2012-04-12 04:02 -------- d-----w- c:\windows\pt-BR
2012-04-12 04:01 . 2012-04-12 09:58 -------- d-----w- c:\windows\SysWow64\wbem\pt-BR
2012-04-12 04:01 . 2012-04-12 04:01 -------- d-----w- c:\windows\SysWow64\drivers\pt-BR
2012-04-12 04:01 . 2012-04-12 04:01 -------- d-----w- c:\windows\system32\drivers\pt-BR
2012-04-12 04:01 . 2012-04-12 04:01 -------- d-----w- c:\windows\system32\drivers\UMDF\pt-BR
2012-04-12 04:01 . 2012-04-12 09:58 -------- d-----w- c:\windows\system32\wbem\pt-BR
2012-04-12 04:00 . 2012-04-12 04:00 -------- d-----w- c:\windows\pt-PT
2012-04-12 04:00 . 2012-04-12 04:00 -------- d-----w- c:\windows\SysWow64\drivers\pt-PT
2012-04-12 04:00 . 2012-04-12 09:58 -------- d-----w- c:\windows\SysWow64\wbem\pt-PT
2012-04-12 04:00 . 2012-04-12 04:00 -------- d-----w- c:\windows\SysWow64\pt
2012-04-12 04:00 . 2012-04-12 04:00 -------- d-----w- c:\windows\system32\drivers\pt-PT
2012-04-12 04:00 . 2012-04-12 04:00 -------- d-----w- c:\windows\system32\drivers\UMDF\pt-PT
2012-04-12 04:00 . 2012-04-12 09:58 -------- d-----w- c:\windows\system32\wbem\pt-PT
2012-04-12 04:00 . 2012-04-12 04:00 -------- d-----w- c:\windows\system32\pt
2012-04-12 03:59 . 2012-04-12 03:59 -------- d-----w- c:\windows\SysWow64\drivers\pl-PL
2012-04-12 03:59 . 2012-04-12 09:58 -------- d-----w- c:\windows\SysWow64\wbem\pl-PL
2012-04-12 03:59 . 2012-04-12 03:59 -------- d-----w- c:\windows\SysWow64\pl
2012-04-12 03:59 . 2012-04-12 03:59 -------- d-----w- c:\windows\pl-PL
2012-04-12 03:59 . 2012-04-12 03:59 -------- d-----w- c:\windows\system32\drivers\UMDF\pl-PL
2012-04-12 03:59 . 2012-04-12 03:59 -------- d-----w- c:\windows\system32\drivers\pl-PL
2012-04-12 03:59 . 2012-04-12 09:58 -------- d-----w- c:\windows\system32\wbem\pl-PL
2012-04-12 03:59 . 2012-04-12 03:59 -------- d-----w- c:\windows\system32\pl
2012-04-12 03:58 . 2012-04-12 03:58 -------- d-----w- c:\windows\tr-TR
2012-04-12 03:58 . 2012-04-12 03:58 -------- d-----w- c:\windows\SysWow64\tr
2012-04-12 03:58 . 2012-04-12 03:58 -------- d-----w- c:\windows\SysWow64\drivers\tr-TR
2012-04-12 03:58 . 2012-04-12 09:59 -------- d-----w- c:\windows\SysWow64\wbem\tr-TR
2012-04-12 03:58 . 2012-04-12 03:58 -------- d-----w- c:\windows\system32\drivers\tr-TR
2012-04-12 03:58 . 2012-04-12 03:58 -------- d-----w- c:\windows\system32\tr
2012-04-12 03:58 . 2012-04-12 03:58 -------- d-----w- c:\windows\system32\drivers\UMDF\tr-TR
2012-04-12 03:58 . 2012-04-12 09:59 -------- d-----w- c:\windows\system32\wbem\tr-TR
2012-04-12 03:58 . 2012-04-12 03:58 -------- d-----w- c:\windows\SysWow64\drivers\bg-BG
2012-04-12 03:57 . 2012-04-12 09:56 -------- d-----w- c:\windows\SysWow64\wbem\bg-BG
2012-04-12 03:57 . 2012-04-12 03:57 -------- d-----w- c:\windows\system32\drivers\bg-BG
2012-04-12 03:57 . 2012-04-12 03:57 -------- d-----w- c:\windows\bg-BG
2012-04-12 03:57 . 2012-04-12 09:56 -------- d-----w- c:\windows\system32\wbem\bg-BG
2012-04-12 03:57 . 2012-04-12 03:57 -------- d-----w- c:\windows\SysWow64\zh-CHS
2012-04-12 03:57 . 2012-04-12 03:57 -------- d-----w- c:\windows\SysWow64\drivers\zh-CN
2012-04-12 03:57 . 2012-04-12 09:56 -------- d-----w- c:\windows\SysWow64\wbem\zh-CN
2012-04-12 03:57 . 2012-04-12 03:57 -------- d-----w- c:\windows\system32\zh-CHS
2012-04-12 03:57 . 2012-04-12 03:57 -------- d-----w- c:\windows\system32\drivers\zh-CN
2012-04-12 03:57 . 2012-04-12 03:57 -------- d-----w- c:\windows\system32\drivers\UMDF\zh-CN
2012-04-12 03:57 . 2012-04-12 09:56 -------- d-----w- c:\windows\system32\wbem\zh-CN
2012-04-12 03:56 . 2012-04-12 03:56 -------- d-----w- c:\windows\zh-CN
2012-04-12 03:56 . 2012-04-12 03:56 -------- d-----w- c:\windows\SysWow64\drivers\sr-Latn-CS
2012-04-12 03:56 . 2012-04-12 09:59 -------- d-----w- c:\windows\SysWow64\wbem\sr-Latn-CS
2012-04-12 03:56 . 2012-04-12 03:56 -------- d-----w- c:\windows\sr-Latn-CS
2012-04-12 03:56 . 2012-04-12 09:59 -------- d-----w- c:\windows\system32\wbem\sr-Latn-CS
2012-04-12 03:56 . 2012-04-12 03:56 -------- d-----w- c:\windows\system32\drivers\sr-Latn-CS
2012-04-12 03:56 . 2012-04-12 09:59 -------- d-----w- c:\windows\SysWow64\wbem\et-EE
2012-04-12 03:56 . 2012-04-12 03:56 -------- d-----w- c:\windows\SysWow64\drivers\et-EE
2012-04-12 03:56 . 2012-04-12 03:56 -------- d-----w- c:\windows\system32\drivers\et-EE
2012-04-12 03:56 . 2012-04-12 09:59 -------- d-----w- c:\windows\system32\wbem\et-EE
2012-04-12 03:56 . 2012-04-12 03:56 -------- d-----w- c:\windows\et-EE
2012-04-12 03:55 . 2012-04-12 03:55 -------- d-----w- c:\windows\lt-LT
2012-04-12 03:55 . 2012-04-12 09:59 -------- d-----w- c:\windows\SysWow64\wbem\lt-LT
2012-04-12 03:55 . 2012-04-12 03:55 -------- d-----w- c:\windows\SysWow64\drivers\lt-LT
2012-04-12 03:55 . 2012-04-12 09:59 -------- d-----w- c:\windows\system32\wbem\lt-LT
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-17 14:34 . 2012-02-07 23:13 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-03-15 13:49 . 2012-03-15 13:49 17408 ----a-w- c:\windows\system32\drivers\DisplayLinkUsbPort_6.2.37054.0.sys
2012-02-24 13:00 . 2012-03-11 18:19 26856 ----a-w- c:\windows\system32\drivers\tclondrv.sys
2012-02-17 06:38 . 2012-03-15 13:45 1112064 ----a-w- c:\windows\system32\rdpcorets.dll
2012-02-17 06:38 . 2012-03-15 13:45 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-02-17 05:34 . 2012-03-15 13:45 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-02-17 04:58 . 2012-03-15 13:45 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-02-17 04:57 . 2012-03-15 13:45 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-02-15 15:01 . 2012-02-15 15:01 52736 ----a-w- c:\windows\system32\drivers\usbaapl64.sys
2012-02-15 15:01 . 2012-02-15 15:01 4547944 ----a-w- c:\windows\system32\usbaaplrc.dll
2012-02-14 16:09 . 2012-02-14 16:09 1070352 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2012-02-10 06:36 . 2012-03-15 13:45 1544192 ----a-w- c:\windows\system32\DWrite.dll
2012-02-10 05:38 . 2012-03-15 13:45 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll
2012-02-08 01:01 . 2012-02-08 01:01 86528 ----a-w- c:\windows\SysWow64\SearchFilterHost.exe
2012-02-08 01:01 . 2012-02-08 01:01 778752 ----a-w- c:\windows\system32\mssvp.dll
2012-02-08 01:01 . 2012-02-08 01:01 75264 ----a-w- c:\windows\system32\msscntrs.dll
2012-02-08 01:01 . 2012-02-08 01:01 666624 ----a-w- c:\windows\SysWow64\mssvp.dll
2012-02-08 01:01 . 2012-02-08 01:01 59392 ----a-w- c:\windows\SysWow64\msscntrs.dll
2012-02-08 01:01 . 2012-02-08 01:01 591872 ----a-w- c:\windows\system32\SearchIndexer.exe
2012-02-08 01:01 . 2012-02-08 01:01 491520 ----a-w- c:\windows\system32\mssph.dll
2012-02-08 01:01 . 2012-02-08 01:01 427520 ----a-w- c:\windows\SysWow64\SearchIndexer.exe
2012-02-08 01:01 . 2012-02-08 01:01 337408 ----a-w- c:\windows\SysWow64\mssph.dll
2012-02-08 01:01 . 2012-02-08 01:01 31232 ----a-w- c:\windows\SysWow64\prevhost.exe
2012-02-08 01:01 . 2012-02-08 01:01 31232 ----a-w- c:\windows\system32\prevhost.exe
2012-02-08 01:01 . 2012-02-08 01:01 288256 ----a-w- c:\windows\system32\mssphtb.dll
2012-02-08 01:01 . 2012-02-08 01:01 249856 ----a-w- c:\windows\system32\SearchProtocolHost.exe
2012-02-08 01:01 . 2012-02-08 01:01 2315776 ----a-w- c:\windows\system32\tquery.dll
2012-02-08 01:01 . 2012-02-08 01:01 2223616 ----a-w- c:\windows\system32\mssrch.dll
2012-02-08 01:01 . 2012-02-08 01:01 197120 ----a-w- c:\windows\SysWow64\mssphtb.dll
2012-02-08 01:01 . 2012-02-08 01:01 164352 ----a-w- c:\windows\SysWow64\SearchProtocolHost.exe
2012-02-08 01:01 . 2012-02-08 01:01 1549312 ----a-w- c:\windows\SysWow64\tquery.dll
2012-02-08 01:01 . 2012-02-08 01:01 1401344 ----a-w- c:\windows\SysWow64\mssrch.dll
2012-02-08 01:01 . 2012-02-08 01:01 113664 ----a-w- c:\windows\system32\SearchFilterHost.exe
2012-02-08 01:01 . 2012-02-08 01:01 861696 ----a-w- c:\windows\system32\oleaut32.dll
2012-02-08 01:01 . 2012-02-08 01:01 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2012-02-08 01:01 . 2012-02-08 01:01 613888 ----a-w- c:\windows\system32\psisdecd.dll
2012-02-08 01:01 . 2012-02-08 01:01 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2012-02-08 01:01 . 2012-02-08 01:01 476160 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2012-02-08 01:01 . 2012-02-08 01:01 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll
2012-02-08 01:01 . 2012-02-08 01:01 331776 ----a-w- c:\windows\system32\oleacc.dll
2012-02-08 01:01 . 2012-02-08 01:01 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2012-02-08 01:01 . 2012-02-08 01:01 233472 ----a-w- c:\windows\SysWow64\oleacc.dll
2012-02-08 01:01 . 2012-02-08 01:01 108032 ----a-w- c:\windows\system32\psisrndr.ax
2012-02-08 01:01 . 2012-02-08 01:01 86016 ----a-w- c:\windows\SysWow64\odbccu32.dll
2012-02-08 01:01 . 2012-02-08 01:01 81920 ----a-w- c:\windows\SysWow64\odbccr32.dll
2012-02-08 01:01 . 2012-02-08 01:01 319488 ----a-w- c:\windows\SysWow64\odbcjt32.dll
2012-02-08 01:01 . 2012-02-08 01:01 212992 ----a-w- c:\windows\system32\odbctrac.dll
2012-02-08 01:01 . 2012-02-08 01:01 163840 ----a-w- c:\windows\SysWow64\odbctrac.dll
2012-02-08 01:01 . 2012-02-08 01:01 163840 ----a-w- c:\windows\system32\odbccp32.dll
2012-02-08 01:01 . 2012-02-08 01:01 122880 ----a-w- c:\windows\SysWow64\odbccp32.dll
2012-02-08 01:01 . 2012-02-08 01:01 106496 ----a-w- c:\windows\system32\odbccu32.dll
2012-02-08 01:01 . 2012-02-08 01:01 106496 ----a-w- c:\windows\system32\odbccr32.dll
2012-02-08 01:01 . 2012-02-08 01:01 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2012-02-08 01:01 . 2012-02-08 01:01 6144 ---ha-w- c:\windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 5120 ---ha-w- c:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2012-02-08 01:01 . 2012-02-08 01:01 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2012-02-08 01:01 . 2012-02-08 01:01 421888 ----a-w- c:\windows\system32\KernelBase.dll
2012-02-08 01:01 . 2012-02-08 01:01 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 362496 ----a-w- c:\windows\system32\wow64win.dll
2012-02-08 01:01 . 2012-02-08 01:01 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3584 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3584 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 338432 ----a-w- c:\windows\system32\conhost.exe
2012-02-08 01:01 . 2012-02-08 01:01 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
2012-02-08 01:01 . 2012-02-08 01:01 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MobileDocuments"="c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"VolPanel"="c:\program files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe" [2009-05-05 241789]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2012-04-04 35736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2011-04-13 503942]
"RemoteControl9"="c:\program files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [2010-10-01 87336]
"PDVD9LanguageShortcut"="c:\program files (x86)\CyberLink\PowerDVD9\Language\Language.exe" [2010-09-18 50472]
"BDRegion"="c:\program files (x86)\Cyberlink\Shared Files\brs.exe" [2011-08-12 75048]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-11-22 1675160]
"NeroLauncher"="c:\program files (x86)\Nero\SyncUP\NeroLauncher.exe" [2011-07-07 75064]
"AccuWeatherWidget"="c:\program files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" [2011-05-30 885760]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-11 624248]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxWatchTray13.exe" [2010-07-16 307184]
"Desktop Disc Tool"="c:\program files (x86)\Roxio 2011\Roxio Burn\RoxioBurnLauncher.exe" [2010-06-30 477680]
"CPMonitor"="c:\program files (x86)\Roxio\CinePlayer\5.0\CPMonitor.exe" [2010-08-25 84464]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
"SSDMonitor"="c:\program files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe" [2012-03-21 103896]
"IJNetworkScannerSelectorEX"="c:\program files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe" [2010-09-09 452016]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys
R0 TFSysMon;TFSysMon;c:\windows\system32\drivers\TfSysMon.sys
R2 CLKMSVC10_9EC60124;CyberLink Product - 2012/02/07 17:50;c:\program files (x86)\Cyberlink\PowerDVD9\NavFilter\kmsvc.exe [2011-08-12 248304]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 DellDigitalDelivery;Dell Digital Delivery Service;c:\program files (x86)\Dell Digital Delivery\DeliveryService.exe [2011-10-26 162816]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxWatch13.exe [2010-07-16 354288]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-17 253088]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2011-10-18 1354064]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-02-07 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-02-07 79360]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys
R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys
R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [2011-03-08 224704]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-11-01 340240]
R3 netvsc;netvsc;c:\windows\system32\DRIVERS\netvsc60.sys
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\drivers\nvstusb.sys
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg64.sys
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys
R3 RoxMediaDB13;RoxMediaDB13;c:\program files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxMediaDB13.exe [2010-07-16 1099248]
R3 sdAuxService;PC Tools Auxiliary Service;c:\program files (x86)\PC Tools Security\pctsAuxs.exe [2012-02-24 402336]
R3 Sound Blaster X-Fi MB Licensing Service;Sound Blaster X-Fi MB Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe [2012-02-07 79360]
R3 Synth3dVsc;Microsoft Virtual 3D Video Transport Driver;c:\windows\system32\drivers\Synth3dVsc.sys
R3 SynthVid;SynthVid;c:\windows\system32\DRIVERS\VMBusVideoM.sys
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys
R3 tsusbhub;Remote Deskotop USB Hub;c:\windows\system32\drivers\tsusbhub.sys
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe
R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys
R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys
R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-28 249936]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 dlkmdldr;dlkmdldr;c:\windows\system32\drivers\dlkmdldr.sys
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys
S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys
S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA64.sys
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys
S0 Sahdad64;HDD Filter Driver;c:\windows\System32\Drivers\Sahdad64.sys
S0 Saibad64;Volume Filter Driver;c:\windows\System32\Drivers\Saibad64.sys
S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys
S0 tclondrv;tclondrv;c:\windows\system32\DRIVERS\tclondrv.sys
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys
S1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi64.sys
S1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD64.sys
S1 SaibVdAd64;Virtual Disk Driver;c:\windows\system32\Drivers\SaibVdAd64.sys
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys
S2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe [2009-06-03 457200]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-10-19 661504]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-10-18 936272]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2011-10-18 1001808]
S2 BOT4Service;BOT4Service;c:\program files (x86)\Roxio\BackOnTrack\App\BService.exe [2010-09-13 39408]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files (x86)\PC Tools Security\BDT\BDTUpdateService.exe [2012-02-17 550864]
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-10-21 135440]
S2 DisplayLinkService;DisplayLinkManager;c:\program files\DisplayLink Core Software\DisplayLinkManager.exe [2011-12-14 8448944]
S2 IntuitUpdateServiceV4;Intuit Update Service v4;c:\program files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [2011-08-25 13672]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-28 249936]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-28 249936]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-12-06 208536]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-11-04 687400]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-04-22 2009704]
S2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [2012-03-21 793048]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-09-22 1692480]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-04-22 378472]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys
S3 DisplayLinkUsbPort;DisplayLink USB Device;c:\windows\system32\DRIVERS\DisplayLinkUsbPort_6.2.37054.0.sys
S3 dlcdcecm;dlcdcecm;c:\windows\system32\DRIVERS\dlcdcecm.sys
S3 dlkmd;dlkmd;c:\windows\system32\drivers\dlkmd.sys
S3 dlusbaudio;dlusbaudio;c:\windows\system32\DRIVERS\dlusbaudio_x64.sys
S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys
S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys
S3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys
S3 PCTBD;PC Tools Browser Defender Driver;c:\windows\system32\Drivers\PCTBD64.sys
S3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - CLKMDRV10_9EC60124
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-19 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 14:34]
.
2012-03-27 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2011-03-22 17:20]
.
2012-04-19 c:\windows\Tasks\RMAutoUpdate.job
- c:\program files (x86)\PC Tools\PC Tools Registry Mechanic\SULauncher.exe [2012-04-12 16:23]
.
2012-04-18 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\pcdrcui.exe [2011-03-22 17:20]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTMasterOnOffMonitor"="CTMWatch.dll StartCTMasterOnOffWatch" [X]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-02-18 6611048]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-01-18 2188904]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2011-04-22 312936]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-05 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-05 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-05 416024]
"FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-12-17 686704]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-10-18 10357008]
"IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-11-01 1935120]
"QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2011-01-25 4479648]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"RunDLLEntry"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568]
"DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2011-05-30 2055816]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.cnn.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
Trusted Zone: intuit.com\ttlc
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62 192.168.1.1
FF - ProfilePath - c:\users\JSR\AppData\Roaming\Mozilla\Firefox\Profiles\my2zrenn.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.cnn.com/
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-TuneClone - c:\program files\TuneClone\TuneClone.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_233_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_233.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Juniper Networks\Common Files\dsNcService.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Dell DataSafe Local Backup\TOASTER.EXE
c:\program files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
.
**************************************************************************
.
Completion time: 2012-04-19 16:35:48 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-19 20:35
.
Pre-Run: 156,262,473,728 bytes free
Post-Run: 156,146,462,720 bytes free
.
- - End Of File - - 07CA8B538F0F902FC626A6903087803C