Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 13-04-06.01 - Dave 04/06/2013 8:23.2.2 - x86
- Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2771 [GMT -7:00]
- Running from: c:\documents and settings\Dave\Desktop\ComboFix.exe
- Command switches used :: c:\documents and settings\Dave\Desktop\CFScript.txt
- AV: Avira Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
- .
- FILE ::
- "c:\windows\system32\XDva021.sys"
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- -------\Legacy_XDVA021
- -------\Service_XDva021
- .
- .
- ((((((((((((((((((((((((( Files Created from 2013-03-06 to 2013-04-06 )))))))))))))))))))))))))))))))
- .
- .
- 2013-03-29 05:13 . 2013-03-29 05:12 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
- 2013-03-26 14:24 . 2013-03-26 14:24 -------- d-----w- c:\program files\ESET
- 2013-03-26 06:53 . 2013-03-26 06:53 -------- d-----w- c:\documents and settings\Dave\Application Data\Avira
- 2013-03-26 06:05 . 2013-03-26 06:05 -------- d-----w- c:\program files\RealNetworks
- 2013-03-26 06:05 . 2013-03-26 06:05 -------- d-----w- c:\documents and settings\All Users\Application Data\RealNetworks
- 2013-03-26 06:05 . 2013-03-26 06:05 -------- d-----w- c:\program files\Common Files\xing shared
- 2013-03-25 16:11 . 2013-03-29 04:18 84744 ----a-w- c:\windows\system32\drivers\avgntflt.sys
- 2013-03-25 16:11 . 2013-03-29 04:18 37352 ----a-w- c:\windows\system32\drivers\avkmgr.sys
- 2013-03-25 16:11 . 2013-03-29 04:18 135136 ----a-w- c:\windows\system32\drivers\avipbb.sys
- 2013-03-25 16:11 . 2013-03-25 16:11 -------- d-----w- c:\program files\Avira
- 2013-03-25 16:11 . 2013-03-25 16:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
- 2013-03-22 14:28 . 2013-02-12 00:32 12928 -c----w- c:\windows\system32\dllcache\usb8023x.sys
- 2013-03-22 14:28 . 2013-02-12 00:32 12928 -c----w- c:\windows\system32\dllcache\usb8023.sys
- 2013-03-14 16:13 . 2013-03-14 16:13 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
- 2013-03-13 15:14 . 2013-04-05 05:07 -------- d-----w- c:\program files\Mozilla Thunderbird
- .
- .
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2013-03-29 05:12 . 2007-05-17 07:25 143872 ----a-w- c:\windows\system32\javacpl.cpl
- 2013-03-29 05:12 . 2012-06-22 14:47 861088 ----a-w- c:\windows\system32\npdeployJava1.dll
- 2013-03-29 05:12 . 2010-05-06 04:12 782240 ----a-w- c:\windows\system32\deployJava1.dll
- 2013-03-26 06:05 . 2007-05-17 07:00 499712 ----a-w- c:\windows\system32\msvcp71.dll
- 2013-03-26 06:05 . 2007-05-17 07:00 348160 ----a-w- c:\windows\system32\msvcr71.dll
- 2013-03-13 15:48 . 2012-04-02 00:30 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
- 2013-03-13 15:48 . 2011-05-19 14:08 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
- 2013-02-12 00:32 . 2008-09-17 22:43 12928 ------w- c:\windows\system32\drivers\usb8023x.sys
- 2013-02-12 00:32 . 2004-08-04 12:00 12928 ----a-w- c:\windows\system32\drivers\usb8023.sys
- 2013-02-05 20:05 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
- 2013-02-05 20:05 . 2004-08-04 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
- 2013-02-05 20:05 . 2004-08-04 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
- 2013-02-05 05:53 . 2004-08-04 12:00 385024 ----a-w- c:\windows\system32\html.iec
- 2013-01-26 03:55 . 2004-08-04 12:00 552448 ------w- c:\windows\system32\oleaut32.dll
- 2013-01-07 01:19 . 2004-08-04 12:00 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
- 2013-01-07 00:37 . 2004-08-03 22:59 2027520 ----a-w- c:\windows\system32\ntkrnlpa.exe
- 2008-02-04 18:00 . 2013-03-13 15:41 44360 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
- 2008-02-04 18:00 . 2013-03-13 15:41 107936 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
- 2013-03-13 15:41 . 2013-03-13 15:41 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
- .
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- .
- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
- "{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn5\yt.dll" [2013-04-01 1500440]
- .
- [HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
- [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
- [HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
- [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
- .
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "Messenger (Yahoo!)"="c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe" [2010-02-17 5244216]
- "Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-10-05 868352]
- "AsusStartupHelp"="c:\program files\ASUS\AASP\1.00.16\AsRunHelp.exe" [2006-11-14 363008]
- "Launch Ai Booster"="c:\program files\ASUS\AI Booster\OverClk.exe" [2006-11-29 3714048]
- "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-09 57344]
- "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
- "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-09 47904]
- "EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2009-04-07 673616]
- "YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
- "Media Codec Update Service"="c:\program files\Essentials Codec Pack\WECPUpdate.exe" [2009-01-25 196608]
- "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-05-25 13895272]
- "NvMediaCenter"="NvMCTray.dll" [2011-05-25 111208]
- "nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2011-05-05 1632360]
- "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
- "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-12-12 152544]
- "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
- "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-03-29 345312]
- "TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2013-03-26 295512]
- "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
- .
- [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
- "RunNarrator"="Narrator.exe" [2008-04-14 53760]
- .
- c:\documents and settings\Dave\Start Menu\Programs\Startup\
- Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-9-9 113664]
- Epson all-in-one Registration.lnk - d:\common\EpsonReg\EpsonReg.exe [N/A]
- .
- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
- "%windir%\\system32\\sessmgr.exe"=
- "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
- "c:\\Program Files\\THQ\\Gas Powered Games\\Supreme Commander\\bin\\SupremeCommander.exe"=
- "c:\\Program Files\\THQ\\Gas Powered Games\\GPGNet\\GPG.Multiplayer.Client.exe"=
- "c:\\Program Files\\BitTorrent_DNA\\dna.exe"=
- "c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
- "c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
- "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
- "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
- "c:\\utils\\putty\\putty.exe"=
- "c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic.exe"=
- "c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_online.exe"=
- "c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_ds.exe"=
- "c:\\Program Files\\Epson Software\\Event Manager\\EEventManager.exe"=
- "c:\\Program Files\\EpsonNet\\EpsonNet Setup\\tool09\\ENEasyApp.exe"=
- "c:\\WINDOWS\\system32\\dpvsetup.exe"=
- "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
- "c:\\Program Files\\StarCraft II\\StarCraft II.exe"=
- "c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
- "c:\\Program Files\\StarCraft II\\Versions\\Base18574\\SC2.exe"=
- "c:\\Program Files\\StarCraft II\\Versions\\Base19132\\SC2.exe"=
- "c:\\Program Files\\Steam\\SteamApps\\common\\portal 2\\portal2.exe"=
- "c:\\Program Files\\StarCraft II\\Versions\\Base19679\\SC2.exe"=
- "c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
- "c:\\Program Files\\Steam\\SteamApps\\common\\FTL Faster Than Light\\FTLGame.exe"=
- "c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
- "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
- "c:\\Program Files\\iTunes\\iTunes.exe"=
- .
- R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [3/25/2013 9:11 AM 37352]
- R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [3/25/2013 9:11 AM 86752]
- R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\RealNetworks\RealDownloader\rndlresolversvc.exe [3/6/2013 2:21 AM 39056]
- S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [11/17/2007 8:46 AM 47360]
- .
- Contents of the 'Scheduled Tasks' folder
- .
- 2013-04-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 15:48]
- .
- 2013-01-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- - c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-02 01:57]
- .
- 2013-04-06 c:\windows\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-436374069-1364589140-839522115-1003.job
- - c:\program files\Real\RealUpgrade\realupgrade.exe [2013-03-06 18:36]
- .
- 2013-04-06 c:\windows\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-436374069-1364589140-839522115-1003.job
- - c:\program files\Real\RealUpgrade\realupgrade.exe [2013-03-06 18:36]
- .
- 2013-04-06 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-18.job
- - c:\program files\Real\RealUpgrade\realupgrade.exe [2013-03-06 18:36]
- .
- 2013-04-06 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-436374069-1364589140-839522115-1003.job
- - c:\program files\Real\RealUpgrade\realupgrade.exe [2013-03-06 18:36]
- .
- 2013-03-27 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-18.job
- - c:\program files\Real\RealUpgrade\realupgrade.exe [2013-03-06 18:36]
- .
- 2013-04-06 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-436374069-1364589140-839522115-1003.job
- - c:\program files\Real\RealUpgrade\realupgrade.exe [2013-03-06 18:36]
- .
- .
- ------- Supplementary Scan -------
- .
- uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
- uStart Page = hxxp://www.bing.com/?pc=Z045&form=ZGAPHP
- mStart Page = hxxp://www.yahoo.com/
- mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
- uInternet Settings,ProxyOverride = *.local
- uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
- LSP: %SYSTEMROOT%\system32\nvappfilter.dll
- TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
- FF - ProfilePath - c:\documents and settings\Dave\Application Data\Mozilla\Firefox\Profiles\4qnniv0d.default\
- FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
- FF - prefs.js: browser.search.selectedEngine - Yahoo
- FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
- FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z045&form=ZGAADF&q=
- FF - ExtSQL: 2013-03-25 23:05; {DAC3F861-B30D-40dd-9166-F4E75327FAC7}; c:\documents and settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
- FF - ExtSQL: !HIDDEN! 2009-09-03 00:07; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
- FF - user.js: yahoo.homepage.dontask - true
- .
- .
- **************************************************************************
- .
- catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
- Rootkit scan 2013-04-06 08:35
- Windows 5.1.2600 Service Pack 3 NTFS
- .
- scanning hidden processes ...
- .
- scanning hidden autostart entries ...
- .
- scanning hidden files ...
- .
- scan completed successfully
- hidden files: 0
- .
- **************************************************************************
- .
- --------------------- LOCKED REGISTRY KEYS ---------------------
- .
- [HKEY_USERS\S-1-5-21-436374069-1364589140-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
- "??"=hex:47,9d,bf,66,68,8f,3a,54,36,3f,c9,6d,64,c9,8f,43,e4,b6,3a,1e,04,e9,d9,
- a2,14,83,17,d3,fc,41,e5,a4,fa,f6,34,1f,20,23,3e,3e,c4,98,99,6a,33,ed,fe,20,\
- "??"=hex:a4,cc,29,03,52,bb,af,b9,97,f7,1a,59,54,2d,74,96
- .
- --------------------- DLLs Loaded Under Running Processes ---------------------
- .
- - - - - - - - > 'explorer.exe'(1344)
- c:\windows\system32\WININET.dll
- c:\windows\system32\ieframe.dll
- c:\windows\system32\webcheck.dll
- c:\windows\system32\WPDShServiceObj.dll
- c:\program files\WinSCP3\DragExt.dll
- c:\windows\system32\PortableDeviceTypes.dll
- c:\windows\system32\PortableDeviceApi.dll
- .
- ------------------------ Other Running Processes ------------------------
- .
- c:\program files\Common Files\EPSON\EBAPI\eEBSVC.exe
- c:\program files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
- c:\program files\Avira\AntiVir Desktop\avguard.exe
- c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
- c:\windows\system32\bgsvcgen.exe
- c:\program files\Bonjour\mDNSResponder.exe
- c:\program files\Java\jre7\bin\jqs.exe
- c:\program files\Common Files\LightScribe\LSSrvc.exe
- c:\windows\system32\nvsvc32.exe
- c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
- c:\windows\System32\StkASv2K.exe
- c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
- c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
- c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
- c:\program files\Avira\AntiVir Desktop\avshadow.exe
- c:\windows\system32\RunDLL32.exe
- c:\program files\iPod\bin\iPodService.exe
- c:\progra~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
- .
- **************************************************************************
- .
- Completion time: 2013-04-06 08:40:21 - machine was rebooted
- ComboFix-quarantined-files.txt 2013-04-06 15:40
- ComboFix2.txt 2013-04-02 03:16
- .
- Pre-Run: 254,465,994,752 bytes free
- Post-Run: 254,337,662,976 bytes free
- .
- - - End Of File - - 60588FE6C801D0595C90A1AC02F025F4
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement