OK - here it is: it amazes me that you can make anything out of it!
ComboFix 12-07-13.01 - Rita 07/12/2012 21:16:24.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3070.1777 [GMT -7:00]
Running from: c:\users\Rita\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\bProtector
c:\programdata\bProtector\bProtect.exe
c:\programdata\bProtector\bProtect.settings
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.comc:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\chrome.manifest
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\chrome\content\background.html
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\chrome\content\browser.xul
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\chrome\content\crossrider.js
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\chrome\content\crossriderapi.js
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\chrome\content\dialog.js
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\chrome\content\lib\faye-browser-min.js
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\chrome\content\manage-apps-style.css
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\chrome\content\manage-apps.html
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\chrome\content\messaging.js
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\chrome\content\options.js
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\chrome\content\options.xul
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\chrome\content\push.html
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\chrome\content\search_dialog.xul
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\chrome\content\update.html
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\defaults\preferences\prefs.js
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\install.rdf
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\locale\en-US\translations.dtd
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\skin\button1.png
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\skin\button2.png
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\skin\button3.png
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\skin\button4.png
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\skin\button5.png
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\skin\crossrider_statusbar.png
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\skin\icon128.png
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\skin\icon16.png
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\skin\icon24.png
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\skin\icon48.png
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\skin\panelarrow-up.png
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\skin\popup.css
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\skin\popup.html
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\skin\popup_binding.xml
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\skin\skin.css
c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\extensions\
crossriderapp5060@crossrider.com\skin\update.css
c:\users\Rita\g2ax_customer_downloadhelper_win32_x86.exe
c:\users\Rita\GoToAssistDownloadHelper.exe
c:\windows\security\Database\tmp.edb
c:\windows\UA000079.DLL
.
.
((((((((((((((((((((((((( Files Created from 2012-06-13 to 2012-07-13 )))))))))))))))))))))))))))))))
.
.
2012-07-13 04:27 . 2012-07-13 04:27 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2012-07-13 04:27 . 2012-07-13 04:27 -------- d-----w- c:\users\IUSR_NMPR\AppData\Local\temp
2012-07-12 13:35 . 2012-05-31 03:41 6762896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{04A5239F-C72B-45BA-83B9-F1CA5E9398AD}\mpengine.dll
2012-07-11 15:34 . 2012-06-12 02:40 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-07-08 01:33 . 2012-07-08 01:33 -------- d-----w- c:\users\Rita\.jsapi
2012-07-08 01:32 . 2012-07-08 01:32 -------- d-----w- c:\users\Rita\Sabre Red Workspace
2012-07-08 01:28 . 2012-07-08 01:32 -------- d-----w- c:\users\Rita\AppData\Local\Sabre Red Workspace
2012-07-08 00:45 . 2012-07-08 00:45 -------- d-----w- c:\windows\Pronto
2012-07-08 00:34 . 2012-07-08 00:34 -------- d-----w- C:\SABRE
2012-06-29 04:28 . 2012-06-29 04:28 -------- dc-h--w- c:\users\Rita\AppData\Local\{E8D024FE-9C03-4ECF-B3CA-FB58783D91C2}
2012-06-29 04:14 . 2012-06-29 04:14 -------- d-----w- c:\users\Rita\AppData\Roaming\DirectLife
2012-06-29 04:13 . 2012-06-29 04:13 -------- d-----w- c:\users\Rita\AppData\Local\PackageAware
2012-06-26 15:30 . 2012-06-26 15:30 -------- d-----w- c:\users\Rita\AppData\Local\Macromedia
2012-06-26 02:39 . 2012-06-26 02:40 -------- d-----w- c:\programdata\SUPERSetup
2012-06-26 02:38 . 2012-06-26 02:38 -------- d-----w- c:\program files\SUPERAntiSpyware
2012-06-19 14:42 . 2012-06-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-19 14:42 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-19 14:42 . 2012-06-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-19 14:42 . 2012-06-02 22:12 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-19 14:41 . 2012-06-02 22:19 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-19 14:41 . 2012-06-02 22:19 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-19 14:41 . 2012-06-02 22:12 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-19 14:41 . 2012-06-02 22:19 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-19 14:41 . 2012-06-02 22:12 33792 ----a-w- c:\windows\system32\wuapp.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-11 22:04 . 2012-04-15 15:45 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-11 22:04 . 2011-05-18 14:20 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-01 04:44 . 2012-06-12 23:39 164352 ----a-w- c:\windows\system32\profsvc.dll
2012-04-28 03:17 . 2012-06-12 23:39 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-26 04:45 . 2012-06-12 23:39 58880 ----a-w- c:\windows\system32\rdpwsx.dll
2012-04-26 04:45 . 2012-06-12 23:39 129536 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-04-26 04:41 . 2012-06-12 23:39 8192 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-04-24 04:36 . 2012-06-12 23:39 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2012-04-24 04:36 . 2012-06-12 23:39 1158656 ----a-w- c:\windows\system32\crypt32.dll
2012-04-24 04:36 . 2012-06-12 23:39 103936 ----a-w- c:\windows\system32\cryptnet.dll
2011-11-21 04:04 . 2011-12-10 03:10 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-04 1514152]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn3\YTNavAssist.dll" [2011-03-16 214840]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2012-01-04 00:31 1514152 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-04 1514152]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2006-11-12 446976]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2010-11-20 144384]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2007-03-28 224248]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-06-11 3905408]
"ALconnect"="c:\users\Rita\AppData\Roaming\DirectLife\ALconnect\ALconnect.exe" [2012-06-18 741504]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424]
"basicsmssmenu"="c:\program files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe" [2007-10-10 169328]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-11 30192]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-27 30040]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-30 421888]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-06-08 421160]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"Google Updater"="c:\program files\Google\Google Updater\GoogleUpdater.exe" [2011-09-30 161336]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-01-04 1391272]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
DING!.lnk - c:\program files\Southwest Airlines\Ding\Ding.exe [2006-6-22 462848]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Audible Download Manager.lnk - c:\program files\Audible\Bin\AudibleDownloadHelper.exe [2010-10-19 1795488]
Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
HP Button Manager.lnk - c:\program files\HP\Button Manager\BM.exe [2010-1-21 323584]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2008-10-30 282624]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
NETGEAR WG111v2 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v2\WG111v2.exe [2009-8-5 1261568]
ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2007-10-3 54512]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Digital Line Detect.lnk]
backup=c:\windows\pss\Digital Line Detect.lnk.CommonStartup
backupExtension=.CommonStartup
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk
.
[HKLM\~\startupfolder\C:^Users^Rita^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=c:\windows\pss\LimeWire On Startup.lnk.Startup
backupExtension=.Startup
path=c:\users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk
.
[HKLM\~\startupfolder\C:^Users^Rita^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MEMonitor.lnk]
backup=c:\windows\pss\MEMonitor.lnk.Startup
backupExtension=.Startup
path=c:\users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEMonitor.lnk
.
[HKLM\~\startupfolder\C:^Users^Rita^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
path=c:\users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2006-10-17 01:40 1197648 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCUTRAYICON]
2006-11-18 13:01 182744 ----a-w- c:\program files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter]
2009-05-21 17:55 206064 ----a-w- c:\program files\Dell Support Center\bin\sprtcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2010-11-20 12:17 144384 ----a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2006-09-29 18:39 151552 ----a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2006-10-03 17:35 221184 ----a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2006-10-03 17:37 81920 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NMSSupport]
2006-09-26 16:56 423424 ----a-w- c:\program files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2010-11-20 12:17 1174016 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
2010-11-20 12:20 859648 ----a-w- c:\windows\System32\OobeFldr.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2009-07-14 01:14 65024 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
2007-03-28 22:10 224248 ----a-w- c:\program files\Yahoo!\Search Protection\SearchProtection.exe
.
R2 gupdate1ca1b5d2d110ea5;Google Update Service (gupdate1ca1b5d2d110ea5);c:\program files\Google\Update\GoogleUpdate.exe
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
R3 f5ipfw;F5 Networks StoneWall Filter;c:\windows\system32\drivers\urfltwlh.sys
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe
S0 SCMNdisP;General NDIS Protocol Driver;c:\windows\system32\DRIVERS\scmndisp.sys
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
S2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
S2 F5 Networks Component Installer;F5 Networks Component Installer;c:\windows\system32\F5InstallerService.exe
S2 IBUpdaterService;Updater Service;c:\programdata\IBUpdaterService\ibsvc.exe
S2 nmsgopro;GoProto Protocol Driver for NMS;c:\windows\system32\DRIVERS\nmsgopro.sys
S2 nmsunidr;UniDriver for NMS;c:\windows\system32\DRIVERS\nmsunidr.sys
S2 SCM_Service;SCM_Service;c:\windows\System32\WinService.exe
S2 uCamMonitor;CamMonitor;c:\program files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys
S3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys
S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe
S3 RTL8187;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\DRIVERS\wg111v2.sys
S3 urvpndrv;F5 Networks VPN Adapter;c:\windows\system32\DRIVERS\covpnwlh.sys
S3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS
S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\DRIVERS\VSTBS23.SYS
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - avgntflt
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-07-14 01:14 126464 ----a-w- c:\windows\System32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-15 22:04]
.
2012-07-08 c:\windows\Tasks\DriverCure.job
- c:\program files\ParetoLogic\DriverCure\DriverCure.exe [2010-06-28 20:57]
.
2012-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-12 14:57]
.
2012-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-12 14:57]
.
2012-07-13 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2009-01-13 14:59]
.
2012-07-13 c:\windows\Tasks\ParetoLogic Registration3.job
- c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2010-04-06 21:30]
.
2012-06-30 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2009-01-13 14:59]
.
2012-07-13 c:\windows\Tasks\User_Feed_Synchronization-{17ED33CB-05F1-4DA1-9A19-750230D986D6}.job
- c:\windows\system32\msfeedssync.exe [2011-05-13 18:03]
.
.
------- Supplementary Scan -------
.
uDefault_Search_URL = hxxp://www.google.com/ie
uStart Page = hxxp://yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {{A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - c:\program files\SpecialSavings\SpecialSavingsSinged.dll
Trusted Zone: intuit.com\ttlc
Trusted Zone: weightwatchers.com
TCP: DhcpNameServer = 192.168.1.1
DPF: {195538FD-1C39-44B1-A7C3-5D7137A8A8F1} - file://C:/Program Files/F5 VPN/F5_TMP/f5opswati.cab
DPF: {2D36AF92-04D3-11D8-B719-0000865F231B} - hxxps://my.sabre.com/jars/TMinReqX.dll
DPF: {30CF9713-6614-4556-B5F5-66F8C7F9DEF1} - file://C:/Program Files/F5 VPN/F5_TMP/f5opswati.cab
DPF: {49EC7987-E331-44E3-B170-748B58A268B9} - file://C:/Program Files/F5 VPN/F5_TMP/f5opswati.cab
DPF: {8C2D1BF0-5364-403C-9968-E6E348C6B4FB} - hxxp://www.iradiopop.com/IRD/pages/VBIRDPlayer.CAB
DPF: {8F6AFB67-F834-4227-94A7-A51377E0678E} - file://C:/Program Files/F5 VPN/F5_TMP/f5GroupPolicyAgent.cab
DPF: {EBDC91CB-F23F-477D-B152-3F7243760D04} - file://C:/Program Files/F5 VPN/F5_TMP/f5opswati.cab
FF - ProfilePath - c:\users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\6skr432c.default\
FF - prefs.js: browser.search.selectedengine - search the web (babylon)
FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?af=114024&babsrc=hp_ss&mntrid=1a4c7ba500000000000000223f5c840e
FF - prefs.js: keyword.url - hxxp://search.babylon.com/?af=114024&babsrc=adbartrp&mntrid=1a4c7ba500000000000000223f5c840e&q=
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
.
------- File Associations -------
.
.reg=Regedit.Document
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - (no file)
Notify-GoToAssist - c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
MSConfigStartUp-Corel Photo Downloader - c:\program files\Corel\Corel Snapfire Plus\PhotoDownloader.exe
MSConfigStartUp-NvCplDaemon - c:\windows\system32\NvCpl.dll
MSConfigStartUp-NvMediaCenter - c:\windows\system32\NvMcTray.dll
MSConfigStartUp-NvSvc - c:\windows\system32\nvsvc.dll
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
AddRemove-Random House Webster's Unabridged Dictionary - c:\program files\Random House
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(3500)
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Seagate\Basics\Service\SyncServicesBasics.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2012-07-12 21:36:19 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-13 04:36
.
Pre-Run: 94,117,797,888 bytes free
Post-Run: 94,078,337,024 bytes free
.
- - End Of File - - BE052AFE48EEDB1636C22C4F7C962F22