Reboot worked, guess that wasn't the virus/rootkit.
Will add requested logs here.
10:44:33.0273 0336 TDSS rootkit removing tool 2.7.22.0 Mar 21 2012 17:40:00
10:44:34.0802 0336 ============================================================
10:44:34.0802 0336 Current date / time: 2012/03/25 10:44:34.0802
10:44:34.0802 0336 SystemInfo:
10:44:34.0802 0336
10:44:34.0802 0336 OS Version: 6.1.7600 ServicePack: 0.0
10:44:34.0802 0336 Product type: Workstation
10:44:34.0802 0336 ComputerName: LEECHER
10:44:34.0802 0336 UserName: coxc
10:44:34.0802 0336 Windows directory: C:\windows
10:44:34.0802 0336 System windows directory: C:\windows
10:44:34.0802 0336 Processor architecture: Intel x86
10:44:34.0802 0336 Number of processors: 4
10:44:34.0802 0336 Page size: 0x1000
10:44:34.0802 0336 Boot type: Normal boot
10:44:34.0802 0336 ============================================================
10:44:36.0971 0336 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
10:44:36.0971 0336 \Device\Harddisk0\DR0:
10:44:36.0986 0336 MBR used
10:44:36.0986 0336 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xC800000
10:44:36.0986 0336 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0xE600800, BlocksNum 0xEBBD000
10:44:37.0095 0336 Initialize success
10:44:37.0095 0336 ============================================================
10:45:08.0576 3364 ============================================================
10:45:08.0576 3364 Scan started
10:45:08.0576 3364 Mode: Manual;
10:45:08.0576 3364 ============================================================
10:45:09.0278 3364 1394ohci - ok
10:45:09.0309 3364 ACPI - ok
10:45:09.0341 3364 AcpiPmi - ok
10:45:09.0450 3364 AdobeARMservice - ok
10:45:09.0465 3364 AdobeFlashPlayerUpdateSvc - ok
10:45:09.0481 3364 adp94xx - ok
10:45:09.0512 3364 adpahci - ok
10:45:09.0528 3364 adpu320 - ok
10:45:09.0543 3364 AeLookupSvc - ok
10:45:09.0575 3364 AFD - ok
10:45:09.0590 3364 agp440 - ok
10:45:09.0606 3364 aic78xx - ok
10:45:09.0637 3364 ALG - ok
10:45:09.0668 3364 aliide - ok
10:45:09.0684 3364 amdagp - ok
10:45:09.0715 3364 amdide - ok
10:45:09.0731 3364 AmdK8 - ok
10:45:09.0746 3364 AmdPPM - ok
10:45:09.0824 3364 amdsata - ok
10:45:09.0855 3364 amdsbs - ok
10:45:09.0871 3364 amdxata - ok
10:45:09.0902 3364 AppID - ok
10:45:09.0965 3364 AppIDSvc - ok
10:45:10.0058 3364 Appinfo - ok
10:45:10.0152 3364 arc - ok
10:45:10.0167 3364 arcsas - ok
10:45:10.0308 3364 AsUpIO - ok
10:45:10.0355 3364 AsusService - ok
10:45:10.0401 3364 AsyncMac - ok
10:45:10.0448 3364 atapi - ok
10:45:10.0464 3364 athr - ok
10:45:10.0511 3364 AudioEndpointBuilder - ok
10:45:10.0526 3364 Audiosrv - ok
10:45:10.0620 3364 AxInstSV - ok
10:45:10.0682 3364 b06bdrv - ok
10:45:10.0729 3364 b57nd60x - ok
10:45:10.0901 3364 BBSvc - ok
10:45:11.0010 3364 BBUpdate - ok
10:45:11.0072 3364 BCM43XX - ok
10:45:11.0088 3364 BDESVC - ok
10:45:11.0103 3364 bdfdll - ok
10:45:11.0119 3364 BDFsDrv - ok
10:45:11.0135 3364 BDRsDrv - ok
10:45:11.0166 3364 Beep - ok
10:45:11.0181 3364 BITS - ok
10:45:11.0197 3364 blbdrive - ok
10:45:11.0228 3364 bowser - ok
10:45:11.0228 3364 BrFiltLo - ok
10:45:11.0244 3364 BrFiltUp - ok
10:45:11.0259 3364 Browser - ok
10:45:11.0275 3364 Brserid - ok
10:45:11.0291 3364 BrSerWdm - ok
10:45:11.0291 3364 BrUsbMdm - ok
10:45:11.0306 3364 BrUsbSer - ok
10:45:11.0384 3364 BthEnum - ok
10:45:11.0384 3364 BTHMODEM - ok
10:45:11.0400 3364 BthPan - ok
10:45:11.0431 3364 BTHPORT - ok
10:45:11.0509 3364 bthserv - ok
10:45:11.0525 3364 BTHUSB - ok
10:45:11.0618 3364 btwampfl - ok
10:45:11.0634 3364 btwaudio - ok
10:45:11.0681 3364 btwavdt - ok
10:45:11.0805 3364 btwdins - ok
10:45:11.0821 3364 btwl2cap - ok
10:45:11.0868 3364 btwrchid - ok
10:45:11.0899 3364 cdfs - ok
10:45:11.0946 3364 cdrom - ok
10:45:12.0008 3364 CertPropSvc - ok
10:45:12.0024 3364 circlass - ok
10:45:12.0039 3364 CLFS - ok
10:45:12.0071 3364 clr_optimization_v2.0.50727_32 - ok
10:45:12.0133 3364 clr_optimization_v4.0.30319_32 - ok
10:45:12.0149 3364 CmBatt - ok
10:45:12.0164 3364 cmdide - ok
10:45:12.0180 3364 CNG - ok
10:45:12.0195 3364 Compbatt - ok
10:45:12.0227 3364 CompositeBus - ok
10:45:12.0289 3364 COMSysApp - ok
10:45:12.0320 3364 crcdisk - ok
10:45:12.0351 3364 CryptSvc - ok
10:45:12.0383 3364 cvhsvc - ok
10:45:12.0398 3364 DcomLaunch - ok
10:45:12.0414 3364 defragsvc - ok
10:45:12.0445 3364 DfsC - ok
10:45:12.0476 3364 Dhcp - ok
10:45:12.0492 3364 discache - ok
10:45:12.0554 3364 Disk - ok
10:45:12.0570 3364 Dnscache - ok
10:45:12.0585 3364 dot3svc - ok
10:45:12.0601 3364 DPS - ok
10:45:12.0663 3364 drmkaud - ok
10:45:12.0679 3364 DXGKrnl - ok
10:45:12.0695 3364 EapHost - ok
10:45:12.0710 3364 ebdrv - ok
10:45:12.0726 3364 EFS - ok
10:45:12.0741 3364 elxstor - ok
10:45:12.0757 3364 ErrDev - ok
10:45:12.0804 3364 ETD - ok
10:45:12.0835 3364 EventSystem - ok
10:45:12.0851 3364 exfat - ok
10:45:12.0866 3364 fastfat - ok
10:45:12.0882 3364 Fax - ok
10:45:12.0897 3364 fdc - ok
10:45:12.0913 3364 fdPHost - ok
10:45:12.0929 3364 FDResPub - ok
10:45:12.0944 3364 FileInfo - ok
10:45:12.0944 3364 Filetrace - ok
10:45:12.0991 3364 FileZilla Server - ok
10:45:13.0007 3364 flpydisk - ok
10:45:13.0038 3364 FltMgr - ok
10:45:13.0069 3364 FolderSize - ok
10:45:13.0085 3364 FontCache - ok
10:45:13.0085 3364 FontCache3.0.0.0 - ok
10:45:13.0100 3364 FsDepends - ok
10:45:13.0147 3364 fssfltr - ok
10:45:13.0147 3364 fsssvc - ok
10:45:13.0163 3364 Fs_Rec - ok
10:45:13.0209 3364 fvevol - ok
10:45:13.0225 3364 gagp30kx - ok
10:45:13.0241 3364 gpsvc - ok
10:45:13.0256 3364 hcw85cir - ok
10:45:13.0272 3364 HdAudAddService - ok
10:45:13.0287 3364 HDAudBus - ok
10:45:13.0303 3364 HidBatt - ok
10:45:13.0319 3364 HidBth - ok
10:45:13.0350 3364 HidIr - ok
10:45:13.0365 3364 hidserv - ok
10:45:13.0428 3364 HidUsb - ok
10:45:13.0443 3364 hkmsvc - ok
10:45:13.0459 3364 HomeGroupListener - ok
10:45:13.0475 3364 HomeGroupProvider - ok
10:45:13.0599 3364 HpSAMD - ok
10:45:13.0709 3364 HTTP - ok
10:45:13.0724 3364 hwpolicy - ok
10:45:13.0755 3364 i8042prt - ok
10:45:13.0787 3364 iaStor - ok
10:45:13.0802 3364 iaStorV - ok
10:45:13.0818 3364 idsvc - ok
10:45:13.0833 3364 igfx - ok
10:45:13.0865 3364 iirsp - ok
10:45:13.0880 3364 IKEEXT - ok
10:45:13.0943 3364 IntcAzAudAddService - ok
10:45:13.0943 3364 intelide - ok
10:45:13.0989 3364 intelppm - ok
10:45:14.0005 3364 IPBusEnum - ok
10:45:14.0021 3364 IpFilterDriver - ok
10:45:14.0036 3364 IPMIDRV - ok
10:45:14.0052 3364 IPNAT - ok
10:45:14.0099 3364 IRENUM - ok
10:45:14.0114 3364 isapnp - ok
10:45:14.0130 3364 iScsiPrt - ok
10:45:14.0223 3364 kbdclass - ok
10:45:14.0270 3364 kbdhid - ok
10:45:14.0286 3364 kbfiltr - ok
10:45:14.0301 3364 KeyIso - ok
10:45:14.0317 3364 KSecDD - ok
10:45:14.0333 3364 KSecPkg - ok
10:45:14.0348 3364 KtmRm - ok
10:45:14.0379 3364 L1C - ok
10:45:14.0457 3364 LanmanServer - ok
10:45:14.0489 3364 LanmanWorkstation - ok
10:45:14.0582 3364 lltdio - ok
10:45:14.0598 3364 lltdsvc - ok
10:45:14.0598 3364 lmhosts - ok
10:45:14.0645 3364 LSI_FC - ok
10:45:14.0691 3364 LSI_SAS - ok
10:45:14.0738 3364 LSI_SAS2 - ok
10:45:14.0769 3364 LSI_SCSI - ok
10:45:14.0785 3364 luafv - ok
10:45:14.0863 3364 MBAMProtector - ok
10:45:14.0879 3364 MBAMService - ok
10:45:14.0910 3364 MBAMSwissArmy - ok
10:45:14.0925 3364 mcdbus - ok
10:45:14.0957 3364 megasas - ok
10:45:14.0972 3364 MegaSR - ok
10:45:14.0988 3364 MMCSS - ok
10:45:15.0003 3364 Modem - ok
10:45:15.0113 3364 monitor - ok
10:45:15.0128 3364 mouclass - ok
10:45:15.0159 3364 mouhid - ok
10:45:15.0159 3364 mountmgr - ok
10:45:15.0300 3364 MozillaMaintenance - ok
10:45:15.0315 3364 mpio - ok
10:45:15.0331 3364 mpsdrv - ok
10:45:15.0347 3364 MRxDAV - ok
10:45:15.0362 3364 mrxsmb - ok
10:45:15.0378 3364 mrxsmb10 - ok
10:45:15.0393 3364 mrxsmb20 - ok
10:45:15.0409 3364 msahci - ok
10:45:15.0425 3364 msdsm - ok
10:45:15.0440 3364 MSDTC - ok
10:45:15.0456 3364 Msfs - ok
10:45:15.0471 3364 mshidkmdf - ok
10:45:15.0487 3364 msisadrv - ok
10:45:15.0518 3364 MSiSCSI - ok
10:45:15.0534 3364 msiserver - ok
10:45:15.0549 3364 MSKSSRV - ok
10:45:15.0565 3364 MSPCLOCK - ok
10:45:15.0581 3364 MSPQM - ok
10:45:15.0596 3364 MsRPC - ok
10:45:15.0612 3364 mssmbios - ok
10:45:15.0659 3364 MSTEE - ok
10:45:15.0674 3364 MTConfig - ok
10:45:15.0690 3364 Mup - ok
10:45:15.0690 3364 napagent - ok
10:45:15.0737 3364 NativeWifiP - ok
10:45:15.0768 3364 NDIS - ok
10:45:15.0861 3364 NdisCap - ok
10:45:15.0877 3364 NdisTapi - ok
10:45:15.0939 3364 Ndisuio - ok
10:45:15.0955 3364 NdisWan - ok
10:45:15.0971 3364 NDProxy - ok
10:45:16.0064 3364 Net Driver HPZ12 - ok
10:45:16.0127 3364 NetBIOS - ok
10:45:16.0142 3364 NetBT - ok
10:45:16.0158 3364 Netlogon - ok
10:45:16.0205 3364 Netman - ok
10:45:16.0220 3364 netprofm - ok
10:45:16.0236 3364 NetTcpPortSharing - ok
10:45:16.0267 3364 nfrd960 - ok
10:45:16.0314 3364 nhcDriverDevice - ok
10:45:16.0314 3364 NlaSvc - ok
10:45:16.0329 3364 Npfs - ok
10:45:16.0345 3364 nsi - ok
10:45:16.0361 3364 nsiproxy - ok
10:45:16.0376 3364 Ntfs - ok
10:45:16.0392 3364 Null - ok
10:45:16.0407 3364 nvraid - ok
10:45:16.0423 3364 nvstor - ok
10:45:16.0439 3364 nv_agp - ok
10:45:16.0439 3364 ohci1394 - ok
10:45:16.0454 3364 ose - ok
10:45:16.0470 3364 osppsvc - ok
10:45:16.0485 3364 p2pimsvc - ok
10:45:16.0532 3364 p2psvc - ok
10:45:16.0532 3364 Parport - ok
10:45:16.0548 3364 partmgr - ok
10:45:16.0563 3364 Parvdm - ok
10:45:16.0579 3364 PcaSvc - ok
10:45:16.0595 3364 pci - ok
10:45:16.0610 3364 pciide - ok
10:45:16.0626 3364 pcmcia - ok
10:45:16.0641 3364 pcw - ok
10:45:16.0657 3364 PEAUTH - ok
10:45:16.0704 3364 pla - ok
10:45:16.0704 3364 PlugPlay - ok
10:45:16.0797 3364 Pml Driver HPZ12 - ok
10:45:16.0813 3364 PNRPAutoReg - ok
10:45:16.0813 3364 PNRPsvc - ok
10:45:16.0844 3364 PolicyAgent - ok
10:45:16.0860 3364 Power - ok
10:45:16.0891 3364 PptpMiniport - ok
10:45:16.0907 3364 Processor - ok
10:45:16.0922 3364 ProfSvc - ok
10:45:16.0938 3364 ProtectedStorage - ok
10:45:16.0969 3364 Psched - ok
10:45:16.0985 3364 ql2300 - ok
10:45:17.0000 3364 ql40xx - ok
10:45:17.0016 3364 QWAVE - ok
10:45:17.0031 3364 QWAVEdrv - ok
10:45:17.0047 3364 RasAcd - ok
10:45:17.0078 3364 RasAgileVpn - ok
10:45:17.0094 3364 RasAuto - ok
10:45:17.0109 3364 Rasl2tp - ok
10:45:17.0141 3364 RasMan - ok
10:45:17.0172 3364 RasPppoe - ok
10:45:17.0187 3364 RasSstp - ok
10:45:17.0203 3364 rdbss - ok
10:45:17.0219 3364 rdpbus - ok
10:45:17.0234 3364 RDPCDD - ok
10:45:17.0281 3364 RDPENCDD - ok
10:45:17.0312 3364 RDPREFMP - ok
10:45:17.0312 3364 RDPWD - ok
10:45:17.0328 3364 rdyboost - ok
10:45:17.0343 3364 RemoteAccess - ok
10:45:17.0359 3364 RemoteRegistry - ok
10:45:17.0406 3364 RFCOMM - ok
10:45:17.0453 3364 RpcEptMapper - ok
10:45:17.0468 3364 RpcLocator - ok
10:45:17.0468 3364 RpcSs - ok
10:45:17.0515 3364 rspndr - ok
10:45:17.0531 3364 SamSs - ok
10:45:17.0562 3364 sbp2port - ok
10:45:17.0562 3364 SCardSvr - ok
10:45:17.0577 3364 scfilter - ok
10:45:17.0593 3364 Schedule - ok
10:45:17.0624 3364 SCPolicySvc - ok
10:45:17.0640 3364 SDRSVC - ok
10:45:17.0655 3364 secdrv - ok
10:45:17.0671 3364 seclogon - ok
10:45:17.0702 3364 SENS - ok
10:45:17.0718 3364 Serenum - ok
10:45:17.0749 3364 Serial - ok
10:45:17.0780 3364 sermouse - ok
10:45:17.0811 3364 SessionEnv - ok
10:45:17.0827 3364 sffdisk - ok
10:45:17.0843 3364 sffp_mmc - ok
10:45:17.0858 3364 sffp_sd - ok
10:45:17.0874 3364 sfloppy - ok
10:45:17.0889 3364 Sftfs - ok
10:45:17.0905 3364 sftlist - ok
10:45:17.0921 3364 Sftplay - ok
10:45:17.0936 3364 Sftredir - ok
10:45:17.0952 3364 Sftvol - ok
10:45:17.0952 3364 sftvsa - ok
10:45:17.0967 3364 SharedAccess - ok
10:45:17.0999 3364 ShellHWDetection - ok
10:45:18.0014 3364 sisagp - ok
10:45:18.0045 3364 SiSRaid2 - ok
10:45:18.0061 3364 SiSRaid4 - ok
10:45:18.0123 3364 Smb - ok
10:45:18.0155 3364 SNMPTRAP - ok
10:45:18.0170 3364 spldr - ok
10:45:18.0201 3364 Spooler - ok
10:45:18.0217 3364 sppsvc - ok
10:45:18.0233 3364 sppuinotify - ok
10:45:18.0248 3364 srv - ok
10:45:18.0248 3364 srv2 - ok
10:45:18.0264 3364 srvnet - ok
10:45:18.0279 3364 SSDPSRV - ok
10:45:18.0295 3364 SstpSvc - ok
10:45:18.0311 3364 stexstor - ok
10:45:18.0326 3364 StiSvc - ok
10:45:18.0342 3364 swenum - ok
10:45:18.0357 3364 swprv - ok
10:45:18.0373 3364 SysMain - ok
10:45:18.0389 3364 TabletInputService - ok
10:45:18.0404 3364 tap0901 - ok
10:45:18.0420 3364 TapiSrv - ok
10:45:18.0435 3364 TBS - ok
10:45:18.0467 3364 Tcpip - ok
10:45:18.0498 3364 TCPIP6 - ok
10:45:18.0513 3364 tcpipreg - ok
10:45:18.0545 3364 TDPIPE - ok
10:45:18.0560 3364 TDTCP - ok
10:45:18.0591 3364 tdx - ok
10:45:18.0607 3364 TermDD - ok
10:45:18.0623 3364 TermService - ok
10:45:18.0654 3364 Themes - ok
10:45:18.0669 3364 THREADORDER - ok
10:45:18.0685 3364 TrkWks - ok
10:45:18.0716 3364 truecrypt - ok
10:45:18.0732 3364 TrustedInstaller - ok
10:45:18.0763 3364 tssecsrv - ok
10:45:18.0779 3364 tunnel - ok
10:45:18.0794 3364 uagp35 - ok
10:45:18.0810 3364 udfs - ok
10:45:18.0841 3364 UI0Detect - ok
10:45:18.0950 3364 uliagpkx - ok
10:45:18.0966 3364 umbus - ok
10:45:18.0997 3364 UmPass - ok
10:45:19.0013 3364 upnphost - ok
10:45:19.0044 3364 usbaudio - ok
10:45:19.0059 3364 usbccgp - ok
10:45:19.0075 3364 usbcir - ok
10:45:19.0091 3364 usbehci - ok
10:45:19.0106 3364 usbhub - ok
10:45:19.0122 3364 usbohci - ok
10:45:19.0137 3364 usbprint - ok
10:45:19.0153 3364 USBSTOR - ok
10:45:19.0169 3364 usbuhci - ok
10:45:19.0231 3364 usbvideo - ok
10:45:19.0247 3364 UxSms - ok
10:45:19.0262 3364 VaultSvc - ok
10:45:19.0293 3364 vdrvroot - ok
10:45:19.0309 3364 vds - ok
10:45:19.0340 3364 vga - ok
10:45:19.0356 3364 VgaSave - ok
10:45:19.0371 3364 vhdmp - ok
10:45:19.0387 3364 viaagp - ok
10:45:19.0418 3364 ViaC7 - ok
10:45:19.0434 3364 viaide - ok
10:45:19.0512 3364 VideAceWindowsService - ok
10:45:19.0527 3364 volmgr - ok
10:45:19.0543 3364 volmgrx - ok
10:45:19.0559 3364 volsnap - ok
10:45:19.0574 3364 vsmraid - ok
10:45:19.0590 3364 VSS - ok
10:45:19.0605 3364 vwifibus - ok
10:45:19.0637 3364 vwififlt - ok
10:45:19.0652 3364 W32Time - ok
10:45:19.0668 3364 WacomPen - ok
10:45:19.0699 3364 WANARP - ok
10:45:19.0715 3364 Wanarpv6 - ok
10:45:19.0715 3364 wbengine - ok
10:45:19.0730 3364 WbioSrvc - ok
10:45:19.0746 3364 wcncsvc - ok
10:45:19.0761 3364 WcsPlugInService - ok
10:45:19.0777 3364 Wd - ok
10:45:19.0793 3364 Wdf01000 - ok
10:45:19.0808 3364 WdiServiceHost - ok
10:45:19.0824 3364 WdiSystemHost - ok
10:45:19.0839 3364 WebClient - ok
10:45:19.0855 3364 Wecsvc - ok
10:45:19.0871 3364 wercplsupport - ok
10:45:19.0917 3364 WerSvc - ok
10:45:19.0949 3364 WfpLwf - ok
10:45:19.0964 3364 WIMMount - ok
10:45:19.0980 3364 WinHttpAutoProxySvc - ok
10:45:19.0995 3364 Winmgmt - ok
10:45:20.0011 3364 WinRM - ok
10:45:20.0042 3364 Wlansvc - ok
10:45:20.0058 3364 wlcrasvc - ok
10:45:20.0073 3364 wlidsvc - ok
10:45:20.0089 3364 wmconnectcds - ok
10:45:20.0120 3364 WmiAcpi - ok
10:45:20.0136 3364 wmiApSrv - ok
10:45:20.0151 3364 WMPNetworkSvc - ok
10:45:20.0167 3364 WPCSvc - ok
10:45:20.0183 3364 WPDBusEnum - ok
10:45:20.0198 3364 ws2ifsl - ok
10:45:20.0214 3364 WSearch - ok
10:45:20.0307 3364 wsvd - ok
10:45:20.0323 3364 wuauserv - ok
10:45:20.0339 3364 WudfPf - ok
10:45:20.0354 3364 WUDFRd - ok
10:45:20.0385 3364 wudfsvc - ok
10:45:20.0401 3364 WwanSvc - ok
10:45:20.0495 3364 MBR (0x1B8) (fb2bd68d9599e4ff39931d2977fab819) \Device\Harddisk0\DR0
10:45:21.0680 3364 \Device\Harddisk0\DR0 - ok
10:45:21.0696 3364 Boot (0x1200) (7d6c9c9155d56d4c7dd8d18009a32406) \Device\Harddisk0\DR0\Partition0
10:45:21.0696 3364 \Device\Harddisk0\DR0\Partition0 - ok
10:45:21.0727 3364 Boot (0x1200) (7d307cf5c95a28519701a9311058963a) \Device\Harddisk0\DR0\Partition1
10:45:21.0758 3364 \Device\Harddisk0\DR0\Partition1 - ok
10:45:21.0758 3364 ============================================================
10:45:21.0758 3364 Scan finished
10:45:21.0758 3364 ============================================================
10:45:21.0789 3208 Detected object count: 0
10:45:21.0789 3208 Actual detected object count: 0
ComboFix 12-03-22.01 - coxc 03/25/2012 11:39:52.1.4 - x86
Microsoft Windows 7 Starter 6.1.7600.0.1252.1.1033.18.2038.1283 [GMT 11:00]
Running from: c:\users\coxc\Desktop\PCforumhelp.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\FullRemove.exe
c:\windows\$NtUninstallKB14816$
c:\windows\$NtUninstallKB14816$\382807857\@
c:\windows\$NtUninstallKB14816$\382807857\cfg.ini
c:\windows\$NtUninstallKB14816$\382807857\Desktop.ini
c:\windows\$NtUninstallKB14816$\382807857\L\xadqgnnk
c:\windows\$NtUninstallKB14816$\382807857\oemid
c:\windows\$NtUninstallKB14816$\382807857\U\00000001.@
c:\windows\$NtUninstallKB14816$\382807857\U\00000002.@
c:\windows\$NtUninstallKB14816$\382807857\U\00000004.@
c:\windows\$NtUninstallKB14816$\382807857\U\80000000.@
c:\windows\$NtUninstallKB14816$\382807857\U\80000004.@
c:\windows\$NtUninstallKB14816$\382807857\U\80000032.@
c:\windows\$NtUninstallKB14816$\382807857\version
c:\windows\$NtUninstallKB14816$\4159976919
c:\windows\system32\dds_trash_log.cmd
.
.
((((((((((((((((((((((((( Files Created from 2012-02-25 to 2012-03-25 )))))))))))))))))))))))))))))))
.
.
2012-03-25 00:53 . 2012-03-25 00:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-03-25 00:53 . 2012-03-25 00:53 -------- d-----w- c:\users\coxc\AppData\Local\temp
2012-03-24 23:16 . 2012-03-24 23:32 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\vlc
2012-03-24 23:04 . 2012-03-24 23:04 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Malwarebytes
2012-03-24 22:54 . 2012-03-24 22:54 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\Mozilla
2012-03-24 12:59 . 2012-03-24 01:36 84992 ----a-w- c:\windows\system32\268W38xW.com
2012-03-24 09:32 . 2012-03-24 09:32 -------- d--h--w- c:\windows\PIF
2012-03-24 01:07 . 2012-03-24 23:04 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-03-23 11:13 . 2012-03-14 02:15 6582328 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4BEEEEBD-DC9A-4B8D-9635-C6E7D7577799}\mpengine.dll
2012-03-23 02:14 . 2012-03-23 02:14 -------- d-----w- c:\users\coxc\AppData\Roaming\rockbox.org
2012-03-21 04:54 . 2012-03-21 04:54 592824 ----a-w- c:\program files\Mozilla Firefox\gkmedias.dll
2012-03-21 04:54 . 2012-03-21 04:54 44472 ----a-w- c:\program files\Mozilla Firefox\mozglue.dll
2012-03-15 22:36 . 2012-03-15 22:36 -------- d-----w- c:\users\coxc\AppData\Roaming\Stellarium
2012-03-15 21:56 . 2012-03-15 22:39 -------- d-----w- c:\program files\Stellarium
2012-03-15 21:05 . 2012-03-15 21:05 -------- d-----w- c:\program files\QTTabBar
2012-03-15 20:56 . 2012-03-15 20:56 -------- d-----w- c:\program files\qBittorrent
2012-03-14 16:00 . 2011-11-19 14:25 3957616 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-03-14 16:00 . 2011-11-19 14:25 3902320 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-14 08:25 . 2012-02-03 04:01 2341376 ----a-w- c:\windows\system32\win32k.sys
2012-03-14 08:25 . 2012-02-10 05:41 1074176 ----a-w- c:\windows\system32\DWrite.dll
2012-03-14 08:25 . 2012-02-10 05:41 218624 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-03-14 08:25 . 2012-02-10 05:41 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2012-03-14 08:25 . 2012-02-10 05:41 1170944 ----a-w- c:\windows\system32\d3d10warp.dll
2012-03-14 08:25 . 2012-02-10 05:41 739840 ----a-w- c:\windows\system32\d2d1.dll
2012-03-14 08:20 . 2012-02-15 05:44 826368 ----a-w- c:\windows\system32\rdpcore.dll
2012-03-14 08:20 . 2012-02-15 04:22 177152 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-14 08:20 . 2012-02-15 04:22 24064 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-03-14 08:20 . 2012-01-25 05:44 57856 ----a-w- c:\windows\system32\rdpwsx.dll
2012-03-14 08:20 . 2012-01-25 05:44 129536 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-03-14 08:20 . 2012-01-25 05:40 8192 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-03-08 11:06 . 2012-03-25 00:02 -------- d-----w- C:\Detective Conan
2012-03-08 10:17 . 2012-03-08 10:32 -------- d-----w- C:\Ano Hi Mita Hana no Namae o Bokutachi wa Mada Shiranai. [FroZen]
2012-03-07 12:35 . 2012-03-07 12:35 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-03-07 12:35 . 2012-03-07 12:35 -------- d-----w- c:\program files\Nightly
2012-03-04 04:37 . 2012-03-04 04:37 -------- d-----w- c:\users\coxc\AppData\Local\fontconfig
2012-03-04 04:24 . 2012-03-04 04:37 -------- d-----w- c:\users\coxc\AppData\Local\SMPlayer2
2012-02-28 00:06 . 2012-02-28 00:11 -------- d-----w- c:\programdata\ReaConverter
2012-02-28 00:06 . 2012-02-28 00:06 -------- d-----w- c:\users\coxc\AppData\Roaming\RCP 6
2012-02-28 00:06 . 2012-02-28 00:06 -------- d-----w- c:\program files\ReaConverter 6.7 Standard
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-22 22:18 . 2012-02-16 05:10 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-02-17 09:00 . 2012-02-17 09:00 71680 ----a-w- c:\windows\system32\drivers\nhcDriver.sys
2012-01-08 01:38 . 2012-01-08 01:30 21840 ----atw- c:\windows\system32\SIntfNT.dll
2012-01-08 01:38 . 2012-01-08 01:30 17212 ----atw- c:\windows\system32\SIntf32.dll
2012-01-08 01:38 . 2012-01-08 01:30 12067 ----atw- c:\windows\system32\SIntf16.dll
2012-01-07 06:46 . 2012-01-07 06:47 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-01-04 09:03 . 2012-02-14 20:54 442880 ----a-w- c:\windows\system32\ntshrui.dll
2012-01-03 05:44 . 2012-02-14 20:54 478208 ----a-w- c:\windows\system32\timedate.cpl
2012-03-21 04:54 . 2012-01-06 06:06 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"TrueCrypt"="c:\program files\truecrypt\TrueCrypt.exe" [2011-12-17 1517520]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-03-07 399224]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2010-04-13 548744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-09-05 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-05-10 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-05-10 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-05-10 150552]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-08-24 9722472]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
c:\users\coxc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2012-1-7 576000]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CapsHook]
2010-11-22 19:12 34728 ----a-w- c:\windows\System32\AsusSender.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eee Docking]
2010-06-10 21:12 414384 ----a-w- c:\program files\Asus\Eee Docking\Eee Docking.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
2011-11-05 01:17 980368 ----a-w- c:\progra~1\Eraser\Eraser.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotkeyMon]
2010-11-22 19:12 34728 ----a-w- c:\windows\System32\AsusSender.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotkeyService]
2010-11-22 19:12 34728 ----a-w- c:\windows\System32\AsusSender.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LiveUpdate]
2010-11-22 19:12 34728 ----a-w- c:\windows\System32\AsusSender.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Notebook Hardware Control]
2010-12-27 10:43 914432 ----a-w- c:\users\coxc\Documents\NotebookHardwareControl_2.4.3_32bit\Notebook Hardware Control 2.4.3\nhc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SuperHybridEngine]
2010-11-22 19:12 34728 ----a-w- c:\windows\System32\AsusSender.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
2010-07-04 19:51 17408 ----a-w- c:\program files\Unlocker\UnlockerAssistant.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2011-12-24 253600]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2012-03-24 40776]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [2012-03-06 112584]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [2009-07-22 81704]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 51040]
S1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2010-03-31 11520]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-09-04 64952]
S2 AsusService;Asus Launcher Service;c:\windows\System32\AsusService.exe [2009-08-19 219136]
S2 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176]
S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648]
S2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [2011-09-30 508776]
S2 VideAceWindowsService;VideAceWindowsService;c:\expressgateutil\VAWinService.exe [2011-01-12 91464]
S3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [2010-05-21 293928]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-05-21 33320]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-04-13 109960]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [2010-09-27 68208]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-10 20464]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-09-30 579944]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-09-30 194408]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-09-30 21864]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-09-30 19304]
S3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [2011-09-30 219496]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
wmconnectcds
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2011-12-19 21:55]
.
2012-03-24 c:\windows\Tasks\At1.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At10.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At11.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At12.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At13.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At14.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At15.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At16.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At17.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At18.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At19.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At2.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At20.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-25 c:\windows\Tasks\At21.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-25 c:\windows\Tasks\At22.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-25 c:\windows\Tasks\At23.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-25 c:\windows\Tasks\At24.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At25.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At26.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At27.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At28.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At29.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At3.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At30.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At31.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At32.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At33.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At34.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At35.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At36.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At37.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At38.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At39.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At4.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At40.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At41.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At42.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At43.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At44.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At45.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At46.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At47.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At48.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At5.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At6.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At7.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At8.job
- c:\windows\system32\268W38xW.com_ [2012-03-24 01:36]
.
2012-03-24 c:\windows\Tasks\At9.job
- c:\windows\system32\268W38xW.com [2012-03-24 01:36]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.ask.com/?l=dis&o=14200IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\coxc\AppData\Roaming\Mozilla\Firefox\Profiles\ko6rcm0p.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.com.au/.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
Toolbar-Locked - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-ASUSWebStorage - c:\program files\ASUS\ASUS WebStorage\3.0.58.109\AsusWSPanel.exe
MSConfigStartUp-Google Update - c:\users\coxc\AppData\Local\Google\Update\GoogleUpdate.exe
MSConfigStartUp-SSDMonitor - c:\program files\Common Files\PC Tools\sMonitor\SSDMonitor.exe
MSConfigStartUp-VizorHtmlDialog - c:\program files\Trend Micro\Titanium\VizorHtmlDialog.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(5420)
c:\program files\WIDCOMM\Bluetooth Software\btncopy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\WLANExt.exe
c:\windows\system32\conhost.exe
c:\program files\WIDCOMM\Bluetooth Software\btwdins.exe
c:\program files\FolderSize\FolderSizeSvc.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\conhost.exe
c:\windows\servicing\TrustedInstaller.exe
c:\program files\Elantech\ETDCtrlHelper.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Windows Live\Companion\companionuser.exe
c:\windows\system32\268W38~1.COM
c:\program files\Internet Explorer\iexplore.exe
c:\windows\system32\268W38~1.COM
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2012-03-25 12:07:30 - machine was rebooted
ComboFix-quarantined-files.txt 2012-03-25 01:07
.
Pre-Run: 1,007,824,896 bytes free
Post-Run: 1,367,334,912 bytes free
.
- - End Of File - - 9D0A89871E455C19518F71D337E3FA07