Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 11-06-25.05 - Omega 6.06.2011. 13:14:54.1.4 - x64
- Microsoft Windows 7 Professional 6.1.7601.1.1250.385.1033.18.4091.2795 [GMT 2:00]
- Running from: c:\users\Omega\Desktop\ComboFix.exe
- AV: ESET Smart Security 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
- FW: ESET Personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
- SP: ESET Smart Security 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
- SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- .
- .
- ((((((((((((((((((((((((( Files Created from 2011-05-26 to 2011-06-26 )))))))))))))))))))))))))))))))
- .
- .
- 2011-06-26 11:18 . 2011-06-26 11:18 -------- d-----w- c:\users\Default\AppData\Local\temp
- 2011-06-26 11:13 . 2011-06-26 11:14 -------- d-----w- C:\32788R22FWJFW
- 2011-06-25 19:50 . 2011-06-25 19:50 0 ----a-w- c:\windows\ativpsrm.bin
- 2011-06-25 19:49 . 2011-06-25 19:49 -------- d-----w- C:\_OTS
- 2011-06-25 15:17 . 2011-06-25 15:43 -------- d-----w- c:\programdata\TuneUp Software
- 2011-06-25 15:13 . 2011-06-25 15:13 -------- d-sh--w- c:\programdata\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
- 2011-06-24 21:51 . 2011-06-24 21:51 -------- d-----w- c:\programdata\ATI
- 2011-06-24 21:49 . 2010-04-29 03:43 38528 ----a-w- c:\windows\system32\drivers\usbfilter.sys
- 2011-06-24 14:40 . 2011-02-24 06:15 476160 ----a-w- c:\windows\system32\XpsGdiConverter.dll
- 2011-06-24 14:40 . 2011-02-24 05:38 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
- 2011-06-24 14:40 . 2011-03-12 12:08 1465344 ----a-w- c:\windows\system32\XpsPrint.dll
- 2011-06-24 14:40 . 2011-03-12 11:23 870912 ----a-w- c:\windows\SysWow64\XpsPrint.dll
- 2011-06-24 14:40 . 2011-02-18 10:51 31232 ----a-w- c:\windows\system32\prevhost.exe
- 2011-06-24 14:40 . 2011-02-18 05:39 31232 ----a-w- c:\windows\SysWow64\prevhost.exe
- 2011-06-24 14:10 . 2011-06-25 10:26 -------- d-----w- c:\programdata\boost_interprocess
- 2011-06-24 13:49 . 2011-06-25 15:27 -------- d-----w- c:\program files (x86)\Microsoft.NET
- 2011-06-24 13:49 . 2011-06-24 13:49 -------- d-----w- c:\windows\PCHEALTH
- 2011-06-24 13:46 . 2011-06-24 13:46 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
- 2011-06-24 13:45 . 2011-06-24 13:45 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
- 2011-06-24 13:45 . 2011-06-24 15:18 -------- d-----w- c:\programdata\Microsoft Help
- 2011-06-24 13:45 . 2011-06-24 13:45 -------- d-----r- C:\MSOCache
- 2011-06-24 10:24 . 2011-06-24 10:24 -------- d-----w- c:\program files (x86)\HD Tune Pro
- 2011-06-24 10:21 . 2011-06-20 06:57 8873296 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CE41931E-0043-4899-A23C-7407CD64D743}\mpengine.dll
- 2011-06-24 10:18 . 2011-06-24 10:18 -------- d-----w- c:\program files\ESET
- 2011-06-24 10:14 . 2011-06-24 10:14 -------- d-----w- c:\programdata\OEM
- 2011-06-24 10:14 . 2011-06-24 10:14 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
- 2011-06-24 10:14 . 2011-06-24 10:14 -------- d-----w- c:\program files\Acer
- 2011-06-24 10:12 . 2011-06-24 10:12 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
- 2011-06-24 10:12 . 2011-06-24 10:12 -------- d-----w- c:\windows\SysWow64\Macromed
- 2011-06-24 10:08 . 2011-06-24 10:08 -------- d-----w- c:\program files (x86)\Launch Manager
- 2011-06-24 00:30 . 2011-06-24 21:49 -------- dc----w- c:\windows\system32\DRVSTORE
- 2011-06-24 00:28 . 2011-06-24 00:27 51200 ----a-w- c:\windows\system32\ATIODCLI.exe
- 2011-06-24 00:28 . 2011-06-24 00:27 332800 ----a-w- c:\windows\system32\ATIODE.exe
- 2011-06-24 00:28 . 2011-06-24 00:27 16440 ----a-w- c:\windows\system32\drivers\AtiPcie64.sys
- 2011-06-24 00:28 . 2011-06-24 00:27 118784 ----a-w- c:\windows\system32\atibtmon.exe
- 2011-06-24 00:28 . 2010-10-28 09:04 340480 ----a-w- c:\windows\system32\atiadlxx.dll
- 2011-06-24 00:17 . 2011-06-24 00:17 -------- d-----w- c:\program files (x86)\FinalWire
- 2011-06-23 23:57 . 2011-06-23 23:57 -------- d-----w- c:\windows\system32\appmgmt
- 2011-06-23 23:51 . 2011-06-23 23:51 -------- d-----w- c:\programdata\AMD
- 2011-06-23 23:51 . 2010-02-18 07:18 46136 ----a-w- c:\windows\system32\drivers\amdiox64.sys
- 2011-06-23 23:50 . 2011-06-23 23:50 -------- d-----w- C:\ATI
- 2011-06-23 23:49 . 2011-06-24 20:58 -------- d-----w- C:\AMD
- 2011-06-23 22:11 . 2011-06-23 12:20 -------- d-----w- c:\windows\Panther
- 2011-06-23 18:07 . 2011-02-25 06:19 2871808 ----a-w- c:\windows\explorer.exe
- 2011-06-23 18:07 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\SysWow64\explorer.exe
- 2011-06-23 18:07 . 2011-02-19 12:05 1139200 ----a-w- c:\windows\system32\FntCache.dll
- 2011-06-23 18:07 . 2011-02-19 12:04 1544192 ----a-w- c:\windows\system32\DWrite.dll
- 2011-06-23 18:07 . 2011-02-19 12:04 902656 ----a-w- c:\windows\system32\d2d1.dll
- 2011-06-23 18:07 . 2011-02-19 06:30 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll
- 2011-06-23 18:07 . 2011-02-19 06:30 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
- 2011-06-23 18:07 . 2011-04-22 22:15 27520 ----a-w- c:\windows\system32\drivers\Diskdump.sys
- 2011-06-23 18:07 . 2011-01-17 11:09 197120 ----a-w- c:\windows\system32\d3d10_1.dll
- 2011-06-23 18:07 . 2011-01-17 05:47 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
- 2011-06-23 17:54 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe
- 2011-06-23 17:54 . 2011-04-09 05:56 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
- 2011-06-23 14:02 . 2011-06-23 14:02 -------- d-----r- c:\program files (x86)\Skype
- 2011-06-23 14:02 . 2011-06-25 19:46 -------- d-sh--w- c:\windows\Installer
- 2011-06-23 14:02 . 2011-06-23 14:02 -------- d-----w- c:\programdata\Skype
- 2011-06-23 12:26 . 2010-05-11 10:11 2229608 ----a-w- c:\windows\system32\drivers\athrx.sys
- 2011-06-23 12:20 . 2011-06-23 12:22 -------- d-----w- c:\users\Omega
- 2011-06-23 12:20 . 2011-06-23 12:20 -------- d-----w- C:\Recovery
- .
- .
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2011-05-25 04:12 . 2011-05-25 04:12 676864 ----a-w- c:\windows\SysWow64\aticfx32.dll
- 2011-05-25 04:11 . 2011-05-25 04:11 795648 ----a-w- c:\windows\system32\aticfx64.dll
- 2011-05-25 04:05 . 2011-05-25 04:05 278528 ----a-w- c:\windows\SysWow64\Oemdspif.dll
- 2011-05-25 03:18 . 2011-05-25 03:18 1222656 ----a-w- c:\windows\system32\atiumd6v.dll
- 2011-05-25 03:18 . 2011-05-25 03:18 1923584 ----a-w- c:\windows\SysWow64\atiumdmv.dll
- 2011-05-24 22:04 . 2011-05-24 22:04 61952 ----a-w- c:\windows\system32\OVDecode64.dll
- 2011-05-24 22:04 . 2011-05-24 22:04 59904 ----a-w- c:\windows\SysWow64\OVDecode.dll
- 2011-05-24 21:44 . 2011-05-24 21:44 53760 ----a-w- c:\windows\system32\OpenCL.dll
- 2011-05-24 21:44 . 2011-05-24 21:44 51712 ----a-w- c:\windows\SysWow64\OpenCL.dll
- 2011-05-24 21:44 . 2011-05-24 21:44 16672768 ----a-w- c:\windows\system32\amdocl64.dll
- 2011-05-24 21:43 . 2011-05-24 21:43 12798976 ----a-w- c:\windows\SysWow64\amdocl.dll
- 2011-05-24 17:14 . 2010-11-21 03:27 270720 ------w- c:\windows\system32\MpSigStub.exe
- .
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- .
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-06-15 15141768]
- "googletalk"="c:\users\Omega\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
- "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-06-22 968272]
- "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-10-28 98304]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
- "ConsentPromptBehaviorAdmin"= 5 (0x5)
- "ConsentPromptBehaviorUser"= 3 (0x3)
- "EnableUIADesktopToggle"= 0 (0x0)
- .
- R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
- R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
- R3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
- R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]
- R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
- R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
- R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
- S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
- S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
- S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
- S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-06-22 321104]
- S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
- S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2011-01-12 810144]
- S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
- S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-06-11 868896]
- S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
- S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
- S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
- S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
- S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
- .
- .
- .
- --------- x86-64 -----------
- .
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-06-11 861216]
- "egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-01-12 2918656]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
- "LoadAppInit_DLLs"=0x0
- .
- ------- Supplementary Scan -------
- .
- uLocal Page = c:\windows\system32\blank.htm
- mLocal Page = c:\windows\SysWOW64\blank.htm
- IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
- IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
- TCP: DhcpNameServer = 192.168.2.1
- FF - ProfilePath - c:\users\Omega\AppData\Roaming\Mozilla\Firefox\Profiles\7g0t4v0c.default\
- .
- .
- --------------------- LOCKED REGISTRY KEYS ---------------------
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Swearware\backup\winsock2\Parameters]
- @DACL=(02 0000)
- @SACL=
- "NameSpace_Callout"=expand:"%SystemRoot%\\System32\\fwpuclnt.dll"
- "WinSock_Registry_Version"="2.0"
- "AutodialDLL"="rasadhlp.dll"
- "Current_NameSpace_Catalog"="NameSpace_Catalog5"
- "Current_Protocol_Catalog"="Protocol_Catalog9"
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
- @Denied: (Full) (Everyone)
- .
- ------------------------ Other Running Processes ------------------------
- .
- c:\program files (x86)\Launch Manager\LMworker.exe
- .
- **************************************************************************
- .
- Completion time: 2011-06-26 13:25:00 - machine was rebooted
- ComboFix-quarantined-files.txt 2011-06-26 11:25
- .
- Pre-Run: 181.274.132.480 bytes free
- Post-Run: 180.873.199.616 bytes free
- .
- - - End Of File - - 4260B6C0552A5EE5DF43BF03D83EC8C7
Advertisement
Add Comment
Please, Sign In to add comment