Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 11-08-28.01 - Mateo 8.08.2011. 20:42:03.1.4 - x64
- Microsoft Windows 7 Ultimate 6.1.7601.1.1250.385.1033.18.4095.2519 [GMT 2:00]
- Running from: c:\users\Mateo\Desktop\ComboFix.exe
- AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
- SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
- SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- c:\programdata\TorrentEasy\fdmbtsupp.dll
- c:\users\Mateo\AppData\Roaming\Minecraft.exe
- c:\windows\SysWow64\jgaw400.dll
- c:\windows\SysWow64\Temp
- c:\windows\SysWow64\Temp\KSKD87SFDS
- .
- .
- ((((((((((((((((((((((((( Files Created from 2011-07-28 to 2011-08-28 )))))))))))))))))))))))))))))))
- .
- .
- 2011-08-28 18:47 . 2011-08-28 18:47 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
- 2011-08-28 18:47 . 2011-08-28 18:47 -------- d-----w- c:\users\Guest\AppData\Local\temp
- 2011-08-28 18:47 . 2011-08-28 18:47 -------- d-----w- c:\users\Default\AppData\Local\temp
- 2011-08-28 15:59 . 2011-08-28 15:59 2048 ----a-w- c:\windows\SysWow64\tzres.dll
- 2011-08-28 15:59 . 2011-08-28 15:59 2048 ----a-w- c:\windows\system32\tzres.dll
- 2011-08-28 00:16 . 2011-08-12 04:10 8862544 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{05B6E846-747B-4A77-AED3-58845FEE5307}\mpengine.dll
- 2011-08-26 12:47 . 2011-08-26 15:04 -------- d-----w- c:\users\Mateo\AppData\Local\Ahead
- 2011-08-26 12:44 . 2011-08-28 16:09 -------- d-----w- c:\program files (x86)\Common Files\Ahead
- 2011-08-22 13:36 . 2011-08-22 13:42 -------- d-----w- c:\program files (x86)\Minecraft Beta
- 2011-08-21 20:30 . 2011-08-21 20:30 -------- d-----w- c:\program files (x86)\LIMBO
- 2011-08-21 07:21 . 2011-08-22 21:26 2656 ----a-w- c:\windows\SysWow64\io02.sys
- 2011-08-11 11:27 . 2011-08-13 00:09 -------- d-----w- c:\users\Mateo\AppData\Roaming\.minecraft
- 2011-08-11 11:27 . 2011-08-11 11:27 -------- d-----w- c:\users\Mateo\AppData\Roaming\Minecraft
- 2011-08-11 06:19 . 2011-08-11 06:19 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
- 2011-08-10 14:45 . 2011-08-10 14:45 -------- d-----w- c:\program files (x86)\MSI Kombustor
- 2011-08-10 14:29 . 2011-08-10 14:29 -------- d-----w- c:\users\Mateo\AppData\Local\Micro-Star_Int'l_Co.,_Ltd
- 2011-08-10 14:07 . 2011-08-17 08:59 134104 ----a-w- c:\program files (x86)\Mozilla Firefox\components\browsercomps.dll
- 2011-08-10 14:07 . 2011-08-17 08:59 89048 ----a-w- c:\program files (x86)\Mozilla Firefox\libEGL.dll
- 2011-08-10 14:07 . 2011-08-17 08:59 785368 ----a-w- c:\program files (x86)\Mozilla Firefox\mozsqlite3.dll
- 2011-08-10 14:07 . 2011-08-17 08:59 478168 ----a-w- c:\program files (x86)\Mozilla Firefox\libGLESv2.dll
- 2011-08-10 14:07 . 2011-08-17 08:59 1846232 ----a-w- c:\program files (x86)\Mozilla Firefox\mozjs.dll
- 2011-08-10 14:07 . 2011-08-17 08:59 15832 ----a-w- c:\program files (x86)\Mozilla Firefox\mozalloc.dll
- 2011-08-10 14:07 . 2010-01-01 08:00 2106216 ----a-w- c:\program files (x86)\Mozilla Firefox\D3DCompiler_43.dll
- 2011-08-10 14:07 . 2010-01-01 08:00 1998168 ----a-w- c:\program files (x86)\Mozilla Firefox\d3dx9_43.dll
- 2011-08-10 13:54 . 2011-06-24 05:25 338432 ----a-w- c:\windows\system32\conhost.exe
- 2011-08-10 12:04 . 1999-06-25 08:55 149504 ----a-w- c:\windows\UNWISE.EXE
- 2011-08-10 10:14 . 2011-08-10 15:44 -------- d-----r- c:\users\Mateo\Virtual Machines
- 2011-08-10 10:07 . 2009-07-22 22:24 2048 ----a-w- c:\windows\system32\drivers\en-US\vpcusb.sys.mui
- 2011-08-10 10:01 . 2005-05-10 23:01 20480 ----a-w- c:\windows\system32\Jb4Instx.crl
- 2011-08-10 09:47 . 2011-08-10 09:47 -------- d-----w- C:\CtJbFW
- 2011-08-10 09:37 . 2011-08-10 10:01 -------- d-----w- c:\program files\Creative
- 2011-08-10 09:20 . 2000-05-22 08:58 647872 ------w- c:\windows\SysWow64\Mscomct2.ocx
- 2011-08-10 09:20 . 1999-10-11 01:00 41984 ------w- c:\windows\Ctregrun.exe
- 2011-08-10 09:19 . 2011-08-10 09:19 -------- d-----w- c:\program files (x86)\Common Files\SWF Studio
- 2011-08-10 09:17 . 2011-08-10 12:04 -------- d-----w- c:\program files (x86)\Creative
- 2011-08-10 09:16 . 2003-11-10 16:12 192512 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
- 2011-08-10 09:16 . 2003-11-10 16:14 729088 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
- 2011-08-10 09:16 . 2003-11-10 16:13 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
- 2011-08-10 09:16 . 2003-11-10 16:12 266240 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
- 2011-08-10 09:16 . 2003-11-10 16:11 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
- 2011-08-10 09:16 . 2011-08-10 09:16 311428 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
- 2011-08-10 09:16 . 2011-08-10 09:16 188548 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
- 2011-08-09 17:55 . 2011-08-10 13:52 -------- d-----w- c:\users\Mateo\AppData\Roaming\go
- 2011-08-09 17:55 . 2011-08-10 13:52 -------- d-----w- c:\programdata\Easybits GO
- 2011-08-09 15:40 . 2011-08-09 15:40 -------- d-----w- c:\users\Mateo\AppData\Roaming\DVRemote
- 2011-08-09 14:39 . 2011-08-09 14:39 -------- d-----w- c:\users\Mateo\AppData\Roaming\Malwarebytes
- 2011-08-09 14:38 . 2011-08-09 14:38 -------- d-----w- c:\programdata\Malwarebytes
- 2011-08-09 14:38 . 2011-07-06 17:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
- 2011-08-09 10:51 . 2011-08-09 11:26 -------- d-----w- c:\users\Mateo\AppData\Local\WMTools Downloaded Files
- 2011-08-09 10:26 . 2011-08-09 10:26 -------- d-----w- c:\program files (x86)\Movie Maker 2.6
- 2011-08-07 18:32 . 2011-08-07 18:32 -------- d-----w- c:\programdata\YouTube Downloader
- 2011-08-07 18:32 . 2011-08-07 18:32 -------- d-----w- c:\program files (x86)\YouTube Downloader
- 2011-08-07 18:08 . 2011-08-07 18:08 -------- d-----w- C:\Download
- 2011-08-07 18:08 . 2011-08-07 18:08 -------- d-----w- C:\tmpDownload
- 2011-08-07 18:08 . 2011-08-07 18:13 -------- d-----w- C:\YoutubeMusicDownloader
- 2011-08-06 17:22 . 2011-08-06 17:22 -------- d-----w- c:\programdata\Futuremark
- 2011-08-05 14:22 . 2011-08-05 14:50 -------- d-----w- c:\program files (x86)\DVDInfoPro
- 2011-08-04 09:50 . 2011-08-04 09:50 53248 ----a-r- c:\users\Mateo\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
- 2011-08-04 09:50 . 2011-08-04 09:50 -------- d-----w- c:\program files (x86)\Common Files\LogiShrd
- 2011-08-04 09:50 . 2011-08-04 09:50 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
- 2011-08-04 09:49 . 2011-08-04 09:51 -------- d-----w- c:\programdata\Logishrd
- 2011-08-04 09:49 . 2011-08-04 09:50 -------- d-----w- c:\users\Mateo\AppData\Roaming\Logitech
- 2011-08-04 09:49 . 2011-08-04 09:49 -------- d-----w- c:\users\Mateo\AppData\Roaming\Logishrd
- 2011-08-04 09:44 . 2011-08-04 09:44 -------- d-----w- c:\program files (x86)\Driver-Soft
- 2011-08-02 07:02 . 2011-08-02 07:02 -------- d-----w- c:\users\Mateo\.mobione
- 2011-07-31 12:07 . 2011-07-31 12:07 -------- d-----w- c:\program files (x86)\Common Files\Bcgsoft
- 2011-07-31 12:05 . 2011-07-31 12:05 -------- d-----w- c:\program files (x86)\The Game Creators
- 2011-07-31 11:21 . 2011-07-31 13:46 -------- d-----w- c:\users\Mateo\AppData\Roaming\WindSolutions
- 2011-07-31 11:21 . 2011-07-31 11:22 -------- d-----w- c:\programdata\WindSolutions
- 2011-07-31 10:08 . 2011-07-31 10:14 -------- d-----w- c:\windows\occache
- .
- .
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2011-08-25 12:10 . 2011-06-25 17:26 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
- 2011-08-25 12:10 . 2011-04-05 14:44 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
- 2011-08-24 08:56 . 2011-04-08 15:20 214520 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
- 2011-08-22 19:44 . 2011-04-05 14:44 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
- 2011-08-13 12:09 . 2011-05-15 07:18 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
- 2011-07-17 09:24 . 2011-07-17 09:24 43680 ----a-w- c:\windows\system32\drivers\lirsgt.sys
- 2011-07-17 09:24 . 2011-07-17 09:24 314016 ----a-w- c:\windows\system32\drivers\atksgt.sys
- 2011-07-16 11:56 . 2011-07-16 11:56 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
- 2011-07-16 04:26 . 2011-08-10 13:54 44032 ----a-w- c:\windows\apppatch\acwow64.dll
- 2011-06-30 11:30 . 2011-06-30 11:30 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
- 2011-06-30 11:30 . 2011-04-02 21:35 122904 ----a-w- c:\windows\system32\OpenAL32.dll
- 2011-06-20 11:28 . 2011-06-20 11:28 4096 ----a-w- c:\windows\SysWow64\drivers\nocashio.sys
- 2011-06-11 03:07 . 2011-07-13 09:01 3137536 ----a-w- c:\windows\system32\win32k.sys
- 2011-06-10 23:58 . 2011-06-10 23:58 81744 ----a-w- c:\windows\SysWow64\mfcm100u.dll
- 2011-06-10 23:58 . 2011-06-10 23:58 81744 ----a-w- c:\windows\SysWow64\mfcm100.dll
- 2011-06-10 23:58 . 2011-06-10 23:58 773968 ----a-w- c:\windows\SysWow64\msvcr100.dll
- 2011-06-10 23:58 . 2011-06-10 23:58 64336 ----a-w- c:\windows\SysWow64\mfc100fra.dll
- 2011-06-10 23:58 . 2011-06-10 23:58 64336 ----a-w- c:\windows\SysWow64\mfc100deu.dll
- 2011-06-10 23:58 . 2011-06-10 23:58 63824 ----a-w- c:\windows\SysWow64\mfc100esn.dll
- 2011-06-10 23:58 . 2011-06-10 23:58 62288 ----a-w- c:\windows\SysWow64\mfc100ita.dll
- 2011-06-10 23:58 . 2011-06-10 23:58 60752 ----a-w- c:\windows\SysWow64\mfc100rus.dll
- 2011-06-10 23:58 . 2011-06-10 23:58 55120 ----a-w- c:\windows\SysWow64\mfc100enu.dll
- 2011-06-10 23:58 . 2011-06-10 23:58 51024 ----a-w- c:\windows\SysWow64\vcomp100.dll
- 2011-06-10 23:58 . 2011-06-10 23:58 4422992 ----a-w- c:\windows\SysWow64\mfc100u.dll
- 2011-06-10 23:58 . 2011-06-10 23:58 4397384 ----a-w- c:\windows\SysWow64\mfc100.dll
- 2011-06-10 23:58 . 2011-06-10 23:58 43856 ----a-w- c:\windows\SysWow64\mfc100jpn.dll
- 2011-06-10 23:58 . 2011-06-10 23:58 43344 ----a-w- c:\windows\SysWow64\mfc100kor.dll
- 2011-06-10 23:58 . 2011-06-10 23:58 421200 ----a-w- c:\windows\SysWow64\msvcp100.dll
- 2011-06-10 23:58 . 2011-06-10 23:58 36176 ----a-w- c:\windows\SysWow64\mfc100cht.dll
- 2011-06-10 23:58 . 2011-06-10 23:58 36176 ----a-w- c:\windows\SysWow64\mfc100chs.dll
- 2011-06-10 23:58 . 2011-06-10 23:58 138056 ----a-w- c:\windows\SysWow64\atl100.dll
- 2011-06-10 23:15 . 2011-06-10 23:15 93008 ----a-w- c:\windows\SysWow64\TBM3A63.tmp
- 2011-06-10 23:15 . 2011-06-10 23:15 93008 ----a-w- c:\windows\SysWow64\TBM3A42.tmp
- 2011-06-10 23:15 . 2011-06-10 23:15 829264 ----a-w- c:\windows\SysWow64\TBM3B20.tmp
- 2011-06-10 23:15 . 2011-06-10 23:15 64336 ----a-w- c:\windows\SysWow64\TBM3943.tmp
- 2011-06-10 23:15 . 2011-06-10 23:15 64336 ----a-w- c:\windows\SysWow64\TBM38F2.tmp
- 2011-06-10 23:15 . 2011-06-10 23:15 63824 ----a-w- c:\windows\SysWow64\TBM3932.tmp
- 2011-06-10 23:15 . 2011-06-10 23:15 62288 ----a-w- c:\windows\SysWow64\TBM3963.tmp
- 2011-06-10 23:15 . 2011-06-10 23:15 608080 ----a-w- c:\windows\SysWow64\TBM3A73.tmp
- 2011-06-10 23:15 . 2011-06-10 23:15 60752 ----a-w- c:\windows\SysWow64\TBM39B4.tmp
- 2011-06-10 23:15 . 2011-06-10 23:15 57168 ----a-w- c:\windows\SysWow64\TBM3B7F.tmp
- 2011-06-10 23:15 . 2011-06-10 23:15 5601616 ----a-w- c:\windows\SysWow64\TBM39F3.tmp
- 2011-06-10 23:15 . 2011-06-10 23:15 5574984 ----a-w- c:\windows\SysWow64\TBM3872.tmp
- 2011-06-10 23:15 . 2011-06-10 23:15 55120 ----a-w- c:\windows\SysWow64\TBM3922.tmp
- 2011-06-10 23:15 . 2011-06-10 23:15 43856 ----a-w- c:\windows\SysWow64\TBM3974.tmp
- 2011-06-10 23:15 . 2011-06-10 23:15 43344 ----a-w- c:\windows\SysWow64\TBM3994.tmp
- 2011-06-10 23:15 . 2011-06-10 23:15 36176 ----a-w- c:\windows\SysWow64\TBM38E1.tmp
- 2011-06-10 23:15 . 2011-06-10 23:15 36176 ----a-w- c:\windows\SysWow64\TBM38D1.tmp
- 2011-06-10 23:15 . 2011-06-10 23:15 158536 ----a-w- c:\windows\SysWow64\TBM3833.tmp
- 2011-06-01 14:43 . 2011-06-01 14:43 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
- .
- .
- ------- Sigcheck -------
- Note: Unsigned files aren't necessarily malware.
- .
- [7] 2010-11-20 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
- [7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
- [-] 2011-04-02 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
- .
- [-] 2011-04-02 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
- [7] 2010-11-20 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
- [7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- .
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
- "Advanced SystemCare 4"="c:\program files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe" [2011-04-22 402832]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
- "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
- "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-02-23 3451496]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
- "ConsentPromptBehaviorAdmin"= 0 (0x0)
- "ConsentPromptBehaviorUser"= 3 (0x3)
- "EnableLUA"= 0 (0x0)
- "EnableUIADesktopToggle"= 0 (0x0)
- "PromptOnSecureDesktop"= 0 (0x0)
- "EnableLinkedConnections"= 1 (0x1)
- .
- [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
- Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
- .
- R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
- R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
- R2 Firefox Service;Firefox Service;c:\users\Mateo\AppData\Roaming\Mozilla\Firefox\Profiles\77cuhd3z.default\extensions\startup.service@mozilla.com\svc.exe [x]
- R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-05 136176]
- R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
- R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
- R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
- R3 dfmirage;dfmirage;c:\windows\system32\DRIVERS\dfmirage.sys [x]
- R3 ENTECH64;ENTECH64;c:\windows\system32\DRIVERS\ENTECH64.sys [2007-08-20 12744]
- R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2011-03-01 130976]
- R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [x]
- R3 gupdatem;Usluga Google ažuriranje (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-05 136176]
- R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [x]
- R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [x]
- R3 Jukebox3_x64;Jukebox3_x64;c:\windows\system32\DRIVERS\ctpdusbx.sys [x]
- R3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;c:\program files (x86)\MSI\Live Update 5\msibios64_100507.sys [x]
- R3 NTIOLib_1_0_4;NTIOLib_1_0_4;c:\program files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [x]
- R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
- R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys [x]
- R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
- R3 TipCtrl;TipCtrl;c:\program files (x86)\uTIPu\TipCtrl.exe [x]
- R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
- R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
- R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
- R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
- R3 vpcuxd;USB Virtualization Stub Service;c:\windows\system32\DRIVERS\vpcuxd.sys [x]
- R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
- R4 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
- R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
- R4 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-03-25 490280]
- R4 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [x]
- R4 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
- R4 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-06-01 2337144]
- R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
- S1 aswSnx;aswSnx; [x]
- S1 aswSP;aswSP; [x]
- S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
- S2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files (x86)\IObit\Advanced SystemCare 4\ASCService.exe [2011-04-22 352656]
- S2 aswFsBlk;aswFsBlk; [x]
- S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
- S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x]
- S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-08-04 2329480]
- S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2011-03-31 80896]
- S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
- S3 RTCore64;RTCore64;c:\program files (x86)\MSI Afterburner\RTCore64.sys [2010-05-27 14648]
- S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
- .
- .
- Contents of the 'Scheduled Tasks' folder
- .
- 2011-08-28 c:\windows\Tasks\GlaryInitialize.job
- - c:\program files (x86)\Glary Utilities\initialize.exe [2011-04-02 09:28]
- .
- 2011-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-05 08:53]
- .
- 2011-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-05 08:53]
- .
- .
- --------- x86-64 -----------
- .
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
- @="{472083B0-C522-11CF-8763-00608CC02F24}"
- [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
- 2011-02-23 14:04 134384 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
- "LoadAppInit_DLLs"=0x0
- .
- ------- Supplementary Scan -------
- .
- uLocal Page = c:\windows\system32\blank.htm
- uStart Page = hxxp://www.google.hr/
- uInternet Settings,ProxyOverride = *.local
- IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
- IE: Save video on Savevid.com - c:\program files (x86)\Savevid\redirect.htm
- TCP: Interfaces\{5F461A11-4018-45FC-8570-DD2DFA551E15}: NameServer = 208.67.222.222,208.67.220.220
- DPF: {173D9E48-B527-4AA0-A929-30B446002AA8} - hxxp://213.147.118.29:6055/DVRemoteAx.cab
- FF - ProfilePath - c:\users\Mateo\AppData\Roaming\Mozilla\Firefox\Profiles\lzvjtc6w.default\
- FF - prefs.js: browser.startup.homepage - hxxp://www.google.hr/
- FF - user.js: browser.cache.memory.capacity - 65536
- FF - user.js: browser.chrome.favicons - false
- FF - user.js: browser.display.show_image_placeholders - true
- FF - user.js: browser.turbo.enabled - true
- FF - user.js: browser.urlbar.autocomplete.enabled - true
- FF - user.js: browser.urlbar.autofill - true
- FF - user.js: browser.xul.error_pages.enabled - true
- FF - user.js: content.interrupt.parsing - true
- FF - user.js: content.max.tokenizing.time - 3000000
- FF - user.js: content.maxtextrun - 8191
- FF - user.js: content.notify.backoffcount - 5
- FF - user.js: content.notify.interval - 750000
- FF - user.js: content.notify.ontimer - true
- FF - user.js: content.switch.threshold - 750000
- FF - user.js: network.http.max-connections - 32
- FF - user.js: network.http.max-connections-per-server - 8
- FF - user.js: network.http.max-persistent-connections-per-proxy - 8
- FF - user.js: network.http.max-persistent-connections-per-server - 4
- FF - user.js: network.http.pipelining - true
- FF - user.js: network.http.pipelining.maxrequests - 8
- FF - user.js: network.http.proxy.pipelining - true
- FF - user.js: network.http.request.max-start-delay - 0
- FF - user.js: nglayout.initialpaint.delay - 0
- FF - user.js: plugin.expose_full_path - true
- FF - user.js: ui.submenuDelay - 0
- .
- - - - - ORPHANS REMOVED - - - -
- .
- AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
- AddRemove-Theme Park World - f:\igre\simtheme park\Uninst.isu
- .
- .
- .
- --------------------- LOCKED REGISTRY KEYS ---------------------
- .
- [HKEY_USERS\S-1-5-21-3263693909-2342236705-2179083420-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
- "??"=hex:95,cc,bb,0a,1d,89,07,be,1e,3e,29,f5,66,bc,52,93,4d,ba,ec,ec,5b,10,1a,
- 28,eb,07,d1,7f,62,44,77,66,a8,b4,04,91,c5,09,08,28,bd,b8,c9,1d,68,b8,68,e6,\
- "??"=hex:ee,05,af,95,26,d8,05,61,94,55,77,8f,bf,f8,62,97
- .
- [HKEY_USERS\S-1-5-21-3263693909-2342236705-2179083420-1001\Software\SecuROM\License information*]
- "datasecu"=hex:c2,f8,e0,8b,2f,6c,3c,0f,37,bf,99,3e,ac,e5,44,73,db,95,79,7e,2a,
- 0c,58,fe,30,71,83,0b,b3,ec,4b,c8,ec,03,19,67,c7,b3,d4,ff,77,9c,bb,68,78,20,\
- "rkeysecu"=hex:5b,d3,d4,03,8f,90,cc,ce,5a,ed,c2,05,a5,77,1d,47
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
- @Denied: (A 2) (Everyone)
- @="FlashBroker"
- "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe,-101"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
- "Enabled"=dword:00000001
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
- @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
- @Denied: (A 2) (Everyone)
- @="Shockwave Flash Object"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx"
- "ThreadingModel"="Apartment"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
- @="0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
- @="ShockwaveFlash.ShockwaveFlash.10"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
- @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
- @="1.0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
- @="ShockwaveFlash.ShockwaveFlash"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
- @Denied: (A 2) (Everyone)
- @="Macromedia Flash Factory Object"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx"
- "ThreadingModel"="Apartment"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
- @="FlashFactory.FlashFactory.1"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
- @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
- @="1.0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
- @="FlashFactory.FlashFactory"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
- @Denied: (A 2) (Everyone)
- @="IFlashBroker4"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
- @="{00020424-0000-0000-C000-000000000046}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
- @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
- "Version"="1.0"
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
- @Denied: (A) (Users)
- @Denied: (A) (Everyone)
- @Allowed: (B 1 2 3 4 5) (S-1-5-20)
- "BlindDial"=dword:00000000
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
- @Denied: (A) (Users)
- @Denied: (A) (Everyone)
- @Allowed: (B 1 2 3 4 5) (S-1-5-20)
- "BlindDial"=dword:00000000
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
- @Denied: (Full) (Everyone)
- .
- ------------------------ Other Running Processes ------------------------
- .
- c:\program files\AVAST Software\Avast\AvastSvc.exe
- c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
- c:\windows\SysWOW64\PnkBstrA.exe
- c:\program files (x86)\MSI Afterburner\MSIAfterburner.exe
- c:\program files (x86)\IObit\Advanced SystemCare 4\PMonitor.exe
- c:\program files (x86)\Google\Update\1.3.21.65\GoogleCrashHandler.exe
- .
- **************************************************************************
- .
- Completion time: 2011-08-28 20:53:44 - machine was rebooted
- ComboFix-quarantined-files.txt 2011-08-28 18:53
- .
- Pre-Run: 13.578.944.512 bytes free
- Post-Run: 13.241.544.704 bytes free
- .
- - - End Of File - - 1D40B250D1822DB68C84B7B7F8DAC626
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement