I ran virus scan, no viruses. Here is what combo fix came up with
ComboFix 15-11-27.01 - Home Base 11/29/2015 10:56:36.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.6103.3922 [GMT -6:00]
Running from: c:\users\Home Base\Downloads\ComboFix.exe
AV: AVG AntiVirus Free Edition *Disabled/Updated* {4D41356F-32AD-7C42-C820-63775EE4F413}
SP: AVG AntiVirus Free Edition *Disabled/Updated* {F620D48B-1497-73CC-F290-58052563BEAE}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Home Base\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmphsuvaj.dll
c:\users\HOMEBA~1\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmphsuvaj.dll
c:\users\Public\Documents\pre_fileassoc.tmp
.
.
((((((((((((((((((((((((( Files Created from 2015-10-28 to 2015-11-29 )))))))))))))))))))))))))))))))
.
.
2015-11-29 05:45 . 2015-11-29 05:45 -------- d-----w- c:\program files\Common Files\AV
2015-11-29 05:44 . 2015-11-29 05:44 -------- d-----w- C:\$AVG
2015-11-29 05:42 . 2015-11-29 16:48 -------- d-----w- c:\programdata\MFAData
2015-11-29 05:41 . 2015-11-29 05:44 -------- d-----w- c:\programdata\Avg
2015-11-29 05:41 . 2015-11-29 05:44 -------- d-----w- c:\program files (x86)\AVG
2015-11-29 05:41 . 2015-11-29 05:41 -------- d--h--w- c:\programdata\Common Files
2015-11-29 05:06 . 2015-11-29 05:06 -------- d-----w- c:\program files (x86)\SensorsViewPro42
2015-11-27 08:32 . 2015-10-29 09:28 11138400 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A8918810-943C-4AE1-BD59-8B23598788A2}\mpengine.dll
2015-11-24 21:07 . 2015-11-24 21:08 -------- d-----w- c:\programdata\WebEx
2015-11-22 02:58 . 2015-11-22 02:58 -------- d-----w- c:\program files (x86)\Common Files\Java
2015-11-22 01:04 . 2015-11-22 01:04 -------- d-----w- C:\Brother
2015-11-22 01:04 . 2015-11-22 01:04 -------- d-----w- c:\program files (x86)\Browny02
2015-11-22 01:04 . 2015-11-22 01:04 -------- d-----w- c:\programdata\ControlCenter4
2015-11-22 01:04 . 2015-11-22 01:04 -------- d-----w- c:\program files (x86)\ControlCenter4
2015-11-22 01:04 . 2009-12-08 22:19 290304 ------w- c:\windows\system32\BrfxDA5c.dll
2015-11-22 01:03 . 2012-09-10 22:31 245760 ------w- c:\windows\SysWow64\NSSearch.dll
2015-11-22 01:03 . 2012-07-09 23:19 5120 ------w- c:\windows\SysWow64\BrDctF2S.dll
2015-11-22 01:03 . 2010-03-16 01:45 73728 ------w- c:\windows\SysWow64\BrDctF2.dll
2015-11-22 01:03 . 2007-12-14 04:16 5120 ------w- c:\windows\SysWow64\BrDctF2L.dll
2015-11-22 01:03 . 2015-11-22 01:04 -------- d-----w- c:\program files (x86)\Brother
2015-11-22 01:03 . 2015-11-22 01:03 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
2015-11-17 16:27 . 2015-11-17 16:27 47785472 ----a-w- c:\windows\system32\amdocl64.dll
2015-11-17 16:27 . 2015-11-17 16:27 27535872 ----a-w- c:\windows\system32\amdocl12cl64.dll
2015-11-17 16:27 . 2015-11-17 16:27 50688 ----a-w- c:\windows\system32\amdmmcl6.dll
2015-11-17 16:27 . 2015-11-17 16:27 39712768 ----a-w- c:\windows\SysWow64\amdocl.dll
2015-11-17 16:27 . 2015-11-17 16:27 38400 ----a-w- c:\windows\SysWow64\amdmmcl.dll
2015-11-17 16:27 . 2015-11-17 16:27 22318592 ----a-w- c:\windows\SysWow64\amdocl12cl.dll
2015-11-17 16:27 . 2015-11-17 16:27 6345728 ----a-w- c:\windows\system32\amdmantle64.dll
2015-11-17 16:27 . 2015-11-17 16:27 5129728 ----a-w- c:\windows\SysWow64\amdmantle32.dll
2015-11-17 16:27 . 2015-11-17 16:27 228864 ----a-w- c:\windows\system32\amdgfxinfo64.dll
2015-11-17 16:27 . 2015-11-17 16:27 201216 ----a-w- c:\windows\SysWow64\amdgfxinfo32.dll
2015-11-17 16:16 . 2015-11-17 16:16 -------- d-----w- c:\programdata\MAGIX
2015-11-17 16:16 . 2015-11-17 16:16 -------- d-----w- c:\program files\Common Files\MAGIX Services
2015-11-17 16:16 . 2015-11-17 16:16 -------- d-----w- c:\program files (x86)\Common Files\MAGIX Services
2015-11-17 16:16 . 2015-11-17 16:16 -------- d-----w- c:\programdata\Xara
2015-11-17 16:16 . 2015-11-17 16:16 -------- d-----w- c:\program files (x86)\Xara
2015-11-17 16:16 . 2015-11-17 16:16 -------- d-----w- c:\program files (x86)\Common Files\Xara Services
2015-11-17 16:16 . 2015-11-17 16:16 -------- d-----w- c:\programdata\simplitec
2015-11-17 16:16 . 2015-11-17 16:16 -------- d-----w- c:\program files (x86)\simplitec
2015-11-17 16:16 . 2013-08-23 18:19 120200 ----a-w- c:\windows\SysWow64\DLLDEV32i.dll
2015-11-12 21:01 . 2015-11-22 02:58 110176 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2015-11-12 20:57 . 2015-11-22 02:58 -------- d-----w- c:\program files\Java
2015-11-09 02:19 . 2014-10-16 15:27 27424 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2015-11-08 01:43 . 2015-11-08 01:43 -------- d-----w- C:\found.001
2015-11-06 16:14 . 2015-11-06 16:14 -------- d-----w- c:\programdata\boost_interprocess
2015-11-06 15:30 . 2015-11-06 15:30 -------- d-----w- c:\program files\Send To Neat
2015-11-06 15:30 . 2014-05-20 19:01 148480 ----a-w- c:\windows\VPDAgent_x64.exe
2015-11-06 15:30 . 2014-05-20 19:01 54784 ----a-w- c:\windows\system32\sdtnpm.dll
2015-11-06 15:28 . 2015-11-06 15:28 -------- d-----w- c:\windows\twain_64
2015-11-06 15:28 . 2015-11-06 15:28 -------- d-----w- c:\program files (x86)\Common Files\Intuit
2015-11-06 15:28 . 2015-11-06 15:28 -------- d-----w- c:\programdata\The Neat Company
2015-11-06 15:28 . 2015-11-06 15:30 -------- d-----w- c:\program files (x86)\Neat
2015-11-06 15:28 . 2015-11-06 15:30 -------- d-----w- c:\program files\Common Files\The Neat Company
2015-11-06 15:23 . 2015-11-06 15:23 -------- d-----w- c:\program files\Microsoft Synchronization Services
2015-11-06 15:23 . 2015-11-06 15:23 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2015-11-06 15:21 . 2015-11-06 15:21 -------- d-----w- c:\program files (x86)\Microsoft Synchronization Services
2015-11-06 15:21 . 2015-11-06 15:21 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2015-11-06 15:12 . 2009-11-25 17:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2015-11-06 15:12 . 2009-11-25 17:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2015-11-06 15:12 . 2009-11-25 17:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
2015-11-06 15:12 . 2009-11-25 17:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2015-11-06 15:12 . 2009-11-25 17:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2015-11-06 15:12 . 2009-11-25 17:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2015-11-06 15:12 . 2009-11-25 17:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2015-11-06 15:12 . 2009-11-25 17:47 444752 ----a-w- c:\windows\system32\mscoree.dll
2015-11-06 15:12 . 2009-11-25 17:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2015-11-06 15:12 . 2009-11-25 17:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
2015-11-06 15:10 . 2015-11-06 15:10 -------- d-----w- c:\program files (x86)\Common Files\The Neat Company
2015-11-06 14:24 . 2015-11-06 14:24 -------- d-----w- c:\users\Public\Foxit Software
2015-11-06 14:24 . 2015-11-06 14:24 -------- d-----w- c:\program files (x86)\Foxit Software
2015-11-06 14:17 . 2015-11-06 14:17 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2015-11-06 12:43 . 2015-11-06 12:43 -------- d-----w- c:\program files\Common Files\ATI Technologies
2015-11-05 19:16 . 2015-11-22 03:27 -------- d-----w- c:\programdata\Oracle
2015-11-05 19:16 . 2015-11-22 02:59 -------- d-----w- c:\program files (x86)\Java
2015-11-05 14:13 . 2015-11-05 14:18 -------- d-----w- c:\windows\system32\MRT
2015-11-04 02:55 . 2015-11-04 02:55 -------- d-----w- c:\program files\Microsoft Silverlight
2015-11-04 02:55 . 2015-11-04 02:55 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2015-11-03 16:21 . 2015-11-03 16:21 -------- d-----w- c:\program files (x86)\MySQL
2015-11-03 14:49 . 2015-11-03 14:49 -------- d-----w- c:\program files (x86)\Eye-Fi
2015-11-03 09:15 . 2015-11-03 09:15 -------- d-----w- c:\windows\CheckSur
2015-11-03 09:04 . 2015-11-03 09:04 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2015-11-03 00:58 . 2015-11-05 09:02 -------- d-----w- c:\program files (x86)\Microsoft.NET
2015-11-03 00:58 . 2015-11-03 00:58 -------- d-----w- c:\windows\PCHEALTH
2015-11-03 00:55 . 2015-11-03 00:55 -------- d-----w- c:\program files\Microsoft Office
2015-11-03 00:52 . 2015-11-03 00:52 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2015-11-03 00:52 . 2015-11-16 15:45 -------- d-----w- c:\programdata\Microsoft Help
2015-11-03 00:52 . 2015-11-03 00:52 -------- d-----r- C:\MSOCache
2015-11-02 21:35 . 2015-11-02 21:35 -------- d-----w- c:\program files (x86)\Bonjour
2015-11-02 21:35 . 2015-11-02 21:35 -------- d-----w- c:\programdata\Apple
2015-11-02 21:35 . 2015-11-02 21:35 -------- d-----w- c:\program files\Bonjour
2015-11-02 21:34 . 2015-11-02 21:34 -------- d-----w- c:\program files (x86)\DYMO
2015-11-02 21:34 . 2015-11-02 21:34 -------- d-----w- c:\programdata\DYMO
2015-11-02 20:19 . 2015-11-05 09:19 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2015-11-02 09:39 . 2015-11-02 09:39 -------- d-----w- C:\found.000
2015-11-02 09:22 . 2015-11-02 09:22 -------- d-s---w- c:\windows\system32\CompatTel
2015-11-02 09:22 . 2015-11-02 09:22 -------- d-----w- c:\windows\system32\appraiser
2015-11-02 09:22 . 2015-11-02 09:22 -------- d-----w- c:\windows\Migration
2015-11-02 02:15 . 2015-11-09 22:14 -------- d-----w- c:\program files (x86)\Dropbox
2015-11-02 02:15 . 2015-11-02 02:15 -------- d-----w- c:\programdata\Dropbox
2015-10-31 19:33 . 2015-10-31 19:33 -------- d-----w- c:\windows\system32\DAX2
2015-10-31 19:31 . 2015-10-31 19:31 -------- d-----w- c:\program files\AMD
2015-10-31 19:30 . 2015-10-31 19:30 458960 ----a-w- c:\windows\system32\drivers\k57nd60a.sys
2015-10-31 19:30 . 2015-10-31 19:30 317440 ----a-w- c:\windows\system32\drivers\IntcDAud.sys
2015-10-31 19:30 . 2015-10-31 19:30 14848 ----a-w- c:\windows\system32\IntcDAuC.dll
2015-10-31 19:30 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2015-10-31 19:30 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2015-10-31 19:30 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2015-10-31 19:30 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
2015-10-31 19:30 . 2015-10-31 19:30 -------- d-----w- c:\program files\Synaptics
2015-10-31 19:30 . 2015-10-31 19:30 1795952 ----a-w- c:\windows\system32\WdfCoInstaller01011.dll
2015-10-31 19:30 . 2015-10-31 19:30 33448 ----a-w- c:\windows\system32\drivers\Smb_driver_Intel.sys
2015-10-31 19:23 . 2015-10-31 19:23 -------- d-----w- c:\windows\Workspace Logs
2015-10-31 19:23 . 2015-10-31 19:23 -------- d-----w- c:\program files (x86)\Workspace
2015-10-31 19:16 . 2015-10-31 19:13 -------- d-----w- c:\windows\Panther
2015-10-31 19:11 . 2015-10-31 19:11 26528 ----a-w- c:\windows\SysWow64\drivers\HWiNFO64A.SYS
2015-10-31 19:08 . 2015-10-31 19:08 -------- d-----w- C:\Windows.old
2015-10-31 19:07 . 2015-10-31 19:07 -------- d-----w- c:\programdata\{BAF091CA-86C4-4627-ADA1-897E2621C1B0}
2015-10-31 19:07 . 2015-11-29 06:09 -------- d-----w- c:\programdata\ProductData
2015-10-31 19:07 . 2015-10-31 19:07 -------- d-----w- c:\program files (x86)\Common Files\IObit
2015-10-31 19:06 . 2015-10-31 19:11 -------- d-----w- c:\programdata\IObit
2015-10-31 19:06 . 2015-10-31 19:11 -------- d-----w- c:\program files (x86)\IObit
2015-10-31 19:05 . 2015-11-29 05:45 -------- d-sh--w- c:\windows\Installer
2015-10-31 19:00 . 2015-11-03 14:11 -------- d-----w- c:\program files (x86)\Google
2015-10-31 18:59 . 2009-11-04 18:18 189440 ----a-w- c:\windows\system32\Spool\prtprocs\x64\dleedrpp.dll
2015-10-31 18:59 . 2015-10-31 18:59 -------- d-----w- c:\program files\Dell V715w
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-11-17 16:28 . 2011-01-27 03:28 7167416 ----a-w- c:\windows\SysWow64\atiumdag.dll
2015-11-17 16:28 . 2011-01-27 03:24 7898704 ----a-w- c:\windows\SysWow64\atiumdva.dll
2015-11-17 16:28 . 2011-01-27 03:12 166488 ----a-w- c:\windows\system32\atiuxp64.dll
2015-11-17 16:28 . 2011-01-27 03:12 136624 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2015-11-17 16:28 . 2011-01-27 03:12 123240 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2015-11-17 16:28 . 2011-01-27 04:00 1194928 ----a-w- c:\windows\SysWow64\aticfx32.dll
2015-11-17 16:28 . 2011-01-27 03:56 695808 ----a-w- c:\windows\system32\atieclxx.exe
2015-11-17 16:28 . 2011-01-27 03:55 296448 ----a-w- c:\windows\system32\atiesrxx.exe
2015-10-21 22:16 . 2015-10-21 22:16 284080 ----a-w- c:\windows\system32\drivers\avgldx64.sys
2015-10-21 22:15 . 2015-10-21 22:15 255408 ----a-w- c:\windows\system32\drivers\avgmfx64.sys
2015-10-19 14:03 . 2015-10-19 14:03 313776 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys
2015-10-13 10:24 . 2015-10-13 10:24 4587520 ----a-w- c:\windows\SysWow64\GPhotos.scr
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2015-11-04 23:46 198464 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt.28.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2015-11-04 23:46 198464 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt.28.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt3]
@="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
2015-11-04 23:46 198464 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt.28.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt4]
@="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
2015-11-04 23:46 198464 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt.28.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt5]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2015-11-04 23:46 198464 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt.28.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt6]
@="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
2015-11-04 23:46 198464 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt.28.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt7]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2015-11-04 23:46 198464 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt.28.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt8]
@="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
2015-11-04 23:46 198464 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt.28.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 8"="c:\program files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" [2015-04-08 2429728]
"wben"="c:\users\Home Base\AppData\Local\Workspace\wben.exe" [2014-10-20 1078896]
"Workspace Status"="c:\users\Home Base\AppData\Local\Workspace\workspacestatus.exe" [2015-10-31 694760]
"Eye-Fi"="c:\program files (x86)\Eye-Fi\Helper\EyeFiHelper.exe" [2011-12-22 3961464]
"DymoQuickPrint"="c:\program files (x86)\DYMO\DYMO Label Software\DymoQuickPrint.exe" [2014-03-20 1867056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Dropbox"="c:\program files (x86)\Dropbox\Client\Dropbox.exe" [2015-11-04 36713096]
"BrStsMon00"="c:\program files (x86)\Browny02\Brother\BrStMonW.exe" [2012-06-06 3076096]
"AvgUi"="c:\program files (x86)\AVG\Framework\Common\avguix.exe" [2015-11-12 1136552]
"AVG_UI"="c:\program files (x86)\AVG\Av\avgui.exe" [2015-10-30 3826600]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\Av\avgidsagent.exe;c:\program files (x86)\AVG\Av\avgidsagent.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
R3 Agent;VPDAgent;c:\windows\VPDAgent_x64.exe;c:\windows\VPDAgent_x64.exe [x]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
R3 AvgAMPS;AvgAMPS;c:\program files (x86)\AVG\Av\avgamps.exe;c:\program files (x86)\AVG\Av\avgamps.exe [x]
R3 dbupdate;Dropbox Update Service (dbupdate);c:\program files (x86)\Dropbox\Update\DropboxUpdate.exe;c:\program files (x86)\Dropbox\Update\DropboxUpdate.exe [x]
R3 dbupdatem;Dropbox Update Service (dbupdatem);c:\program files (x86)\Dropbox\Update\DropboxUpdate.exe;c:\program files (x86)\Dropbox\Update\DropboxUpdate.exe [x]
R3 File Backup;File Backup Service;c:\program files (x86)\Workspace\offSyncService.exe;c:\program files (x86)\Workspace\offSyncService.exe [x]
R3 Neat Startup Service;Neat Startup Service;c:\program files (x86)\Neat\exec\NeatStartupService.exe;c:\program files (x86)\Neat\exec\NeatStartupService.exe [x]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsha.sys [x]
S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys;c:\windows\SYSNATIVE\DRIVERS\avgloga.sys [x]
S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x]
S1 Avgdiska;AVG Disk Driver;c:\windows\system32\DRIVERS\avgdiska.sys;c:\windows\SYSNATIVE\DRIVERS\avgdiska.sys [x]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsdrivera.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgldx64.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S1 sensorsview;sensorsview;c:\program files (x86)\SensorsViewPro42\drv\sensorsview32_64.sys;c:\program files (x86)\SensorsViewPro42\drv\sensorsview32_64.sys [x]
S2 AdvancedSystemCareService8;Advanced SystemCare Service 8;c:\program files (x86)\IObit\Advanced SystemCare 8\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 avgsvc;AVG Service;c:\program files (x86)\AVG\Framework\Common\avgsvca.exe;c:\program files (x86)\AVG\Framework\Common\avgsvca.exe [x]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\Av\avgwdsvcx.exe;c:\program files (x86)\AVG\Av\avgwdsvcx.exe [x]
S2 dlee_device;dlee_device;c:\windows\system32\dleecoms.exe;c:\windows\SYSNATIVE\dleecoms.exe [x]
S2 DymoPnpService;DYMO PnP Service;c:\program files (x86)\DYMO\DYMO Label Software\DymoPnpService.exe;c:\program files (x86)\DYMO\DYMO Label Software\DymoPnpService.exe [x]
S2 SensorsVService;SensorsVService;c:\program files (x86)\SensorsViewPro42\svservice.exe;c:\program files (x86)\SensorsViewPro42\svservice.exe [x]
S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x]
S3 BrSerIb;Brother Serial Interface Driver(WDM);c:\windows\system32\DRIVERS\BrSerIb.sys;c:\windows\SYSNATIVE\DRIVERS\BrSerIb.sys [x]
S3 BrUsbSIb;Brother Serial USB Driver(WDM);c:\windows\system32\DRIVERS\BrUsbSIb.sys;c:\windows\SYSNATIVE\DRIVERS\BrUsbSIb.sys [x]
S3 BrYNSvc;BrYNSvc;c:\program files (x86)\Browny02\BrYNSvc.exe;c:\program files (x86)\Browny02\BrYNSvc.exe [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x]
S3 LVUVC64;Logitech HD Webcam C525(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
S3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-11-11 18:43 997704 ----a-w- c:\program files (x86)\Google\Chrome\Application\46.0.2490.86\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2015-11-29 c:\windows\Tasks\DropboxUpdateTaskMachineCore.job
- c:\program files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-11-02 02:15]
.
2015-11-29 c:\windows\Tasks\DropboxUpdateTaskMachineUA.job
- c:\program files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-11-02 02:15]
.
2015-11-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-10-31 19:00]
.
2015-11-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-10-31 19:00]
.
2015-11-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-529623786-2525329518-1012073515-1000Core.job
- c:\users\Home Base\AppData\Local\Google\Update\GoogleUpdate.exe [2015-11-02 20:50]
.
2015-11-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-529623786-2525329518-1012073515-1000UA.job
- c:\users\Home Base\AppData\Local\Google\Update\GoogleUpdate.exe [2015-11-02 20:50]
.
2015-11-29 c:\windows\Tasks\simplitec Power Suite.job
- c:\program files (x86)\simplitec\simpliclean\PowerSuite.exe [2015-11-17 20:16]
.
2015-11-29 c:\windows\Tasks\simplitec Service Provider.job
- c:\program files (x86)\simplitec\simpliclean\ServiceProvider.exe [2015-11-17 20:16]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
2015-10-31 19:07 2471744 ----a-w- c:\program files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2015-11-04 23:46 236352 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt64.28.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2015-11-04 23:46 236352 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt64.28.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt3]
@="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
2015-11-04 23:46 236352 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt64.28.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt4]
@="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
2015-11-04 23:46 236352 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt64.28.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt5]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2015-11-04 23:46 236352 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt64.28.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt6]
@="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
2015-11-04 23:46 236352 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt64.28.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt7]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2015-11-04 23:46 236352 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt64.28.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt8]
@="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
2015-11-04 23:46 236352 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt64.28.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\off0]
@="{8E33AEC3-C5F2-43C4-B048-9E3EB19B1DD5}"
[HKEY_CLASSES_ROOT\CLSID\{8E33AEC3-C5F2-43C4-B048-9E3EB19B1DD5}]
2015-10-31 19:23 1308432 ----a-w- c:\program files (x86)\Workspace\offsyncext64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\off1]
@="{8E33AEC4-C5F2-43C4-B048-9E3EB19B1DD5}"
[HKEY_CLASSES_ROOT\CLSID\{8E33AEC4-C5F2-43C4-B048-9E3EB19B1DD5}]
2015-10-31 19:23 1308432 ----a-w- c:\program files (x86)\Workspace\offsyncext64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2015-10-31 16407296]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
FF - ProfilePath - c:\users\Home Base\AppData\Roaming\Mozilla\Firefox\Profiles\9a6484x8.default\
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: content.notify.ontimer - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.switch.threshold - 750000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: nglayout.initialpaint.delay - 0
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-workspacedesktop - c:\users\Home Base\AppData\Local\Workspace\uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-529623786-2525329518-1012073515-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DB443615-24BF-60F8-DEF7-CB19EC210196}*]
"hadfihcbkkigakmi"=hex:6b,61,66,6c,62,70,70,61,63,65,66,6e,6a,61,70,61,6c,6e,
68,6a,62,67,00,77
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\IObit\Advanced SystemCare 8\Monitor.exe
c:\program files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
.
**************************************************************************
.
Completion time: 2015-11-29 11:12:10 - machine was rebooted
ComboFix-quarantined-files.txt 2015-11-29 17:12
.
Pre-Run: 892,374,908,928 bytes free
Post-Run: 892,329,713,664 bytes free
.
- - End Of File - - C53A526513ADE927D421614B9ED7DF93
A36C5E4F47E84449FF07ED3517B43A31