Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 11-02-09.03 - Joe 02/09/2011 22:53:30.1.2 - x64
- Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.4095.1317 [GMT -6:00]
- Running from: c:\users\Joe\Downloads\ComboFix.exe
- AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
- SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
- SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- C:\install.exe
- c:\users\Joe\AppData\Roaming\inst.exe
- .
- ((((((((((((((((((((((((( Files Created from 2011-01-10 to 2011-02-10 )))))))))))))))))))))))))))))))
- .
- 2011-02-10 04:58 . 2011-02-10 04:58 -------- d-----w- c:\users\Default\AppData\Local\temp
- 2011-02-09 23:48 . 2011-01-13 08:20 7844688 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
- 2011-02-09 23:48 . 2011-01-13 08:20 7844688 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F0217F66-D8A3-473B-ABE7-A884A70E92BF}\mpengine.dll
- 2011-02-09 23:47 . 2011-02-09 23:47 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B5E24FA4-9EAE-41B5-998E-7D1AC36B5C78}\gapaengine.dll
- 2011-02-09 23:44 . 2011-02-09 23:44 -------- d-----w- c:\program files (x86)\Microsoft Security Client
- 2011-02-09 23:44 . 2011-02-09 23:44 -------- d-----w- c:\program files\Microsoft Security Client
- 2011-02-09 23:43 . 2010-04-09 11:06 374664 ----a-w- c:\windows\system32\drivers\netio.sys
- 2011-02-08 23:37 . 2010-12-18 06:11 714752 ----a-w- c:\windows\system32\kerberos.dll
- 2011-02-08 23:35 . 2011-01-13 10:20 7844688 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FFE9CC82-AD53-4889-883F-D9F886A45CDE}\mpengine.dll
- 2011-02-01 01:35 . 2011-02-01 01:35 -------- d-----w- c:\program files (x86)\Microsoft XNA
- 2011-01-21 04:17 . 2011-01-21 04:17 -------- d-----w- c:\program files (x86)\oZone3D
- 2011-01-12 00:22 . 2010-10-16 05:17 720896 ----a-w- c:\windows\system32\odbc32.dll
- 2011-01-12 00:22 . 2010-10-16 05:16 495616 ----a-w- c:\program files\Common Files\System\ado\msadox.dll
- 2011-01-12 00:22 . 2010-10-16 05:16 466944 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
- 2011-01-12 00:22 . 2010-10-16 05:16 1425408 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
- 2011-01-12 00:22 . 2010-10-16 05:16 258048 ----a-w- c:\program files\Common Files\System\msadc\msadco.dll
- 2011-01-12 00:22 . 2010-10-16 04:34 573440 ----a-w- c:\windows\SysWow64\odbc32.dll
- 2011-01-12 00:22 . 2010-10-16 04:33 372736 ----a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll
- 2011-01-12 00:22 . 2010-10-16 04:33 352256 ----a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll
- 2011-01-12 00:22 . 2010-10-16 04:33 987136 ----a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll
- 2011-01-12 00:22 . 2010-10-16 04:33 208896 ----a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2011-01-07 05:45 . 2011-01-07 05:37 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
- 2011-01-07 05:45 . 2011-01-07 05:37 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
- 2011-01-07 05:37 . 2011-01-07 05:37 75064 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
- 2011-01-07 05:37 . 2011-01-07 05:37 2434856 ----a-w- c:\windows\SysWow64\pbsvc_bc2.exe
- 2010-12-31 00:27 . 2010-12-23 01:21 466520 ----a-w- c:\windows\system32\wrap_oal.dll
- 2010-12-31 00:27 . 2010-12-23 01:21 445016 ----a-w- c:\windows\SysWow64\wrap_oal.dll
- 2010-12-31 00:27 . 2010-12-23 01:21 122968 ----a-w- c:\windows\system32\OpenAL32.dll
- 2010-12-31 00:27 . 2010-12-23 01:21 109144 ----a-w- c:\windows\SysWow64\OpenAL32.dll
- 2010-12-30 23:59 . 2010-12-30 23:59 428416 ----a-w- c:\windows\SysWow64\RzMwApi.dll
- 2010-12-30 21:50 . 2010-12-30 21:48 41984 ----a-w- c:\windows\system32\~WebUpdateHelper.exe
- 2010-12-16 15:23 . 2010-12-16 15:23 126464 ----a-w- c:\windows\system32\drivers\RzSynapse.sys
- 2010-11-26 04:20 . 2010-11-26 04:20 8120320 ----a-w- c:\windows\system32\drivers\atikmdag.sys
- 2010-11-26 03:19 . 2010-11-26 03:19 21610496 ----a-w- c:\windows\system32\atio6axx.dll
- 2010-11-26 03:02 . 2010-11-26 03:02 16702976 ----a-w- c:\windows\SysWow64\atioglxx.dll
- 2010-11-26 02:58 . 2010-11-26 02:58 143360 ----a-w- c:\windows\system32\atiapfxx.exe
- 2010-11-26 02:58 . 2010-11-26 02:58 550400 ----a-w- c:\windows\SysWow64\aticfx32.dll
- 2010-11-26 02:57 . 2010-11-26 02:57 648704 ----a-w- c:\windows\system32\aticfx64.dll
- 2010-11-26 02:54 . 2010-11-26 02:54 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
- 2010-11-26 02:54 . 2010-11-26 02:54 478720 ----a-w- c:\windows\system32\atieclxx.exe
- 2010-11-26 02:54 . 2010-11-26 02:54 203776 ----a-w- c:\windows\system32\atiesrxx.exe
- 2010-11-26 02:53 . 2010-11-26 02:53 120320 ----a-w- c:\windows\system32\atitmm64.dll
- 2010-11-26 02:52 . 2010-11-26 02:52 423424 ----a-w- c:\windows\system32\atipdl64.dll
- 2010-11-26 02:52 . 2010-11-26 02:52 356352 ----a-w- c:\windows\SysWow64\atipdlxx.dll
- 2010-11-26 02:52 . 2010-11-26 02:52 278528 ----a-w- c:\windows\SysWow64\Oemdspif.dll
- 2010-11-26 02:52 . 2010-11-26 02:52 16384 ----a-w- c:\windows\system32\atimuixx.dll
- 2010-11-26 02:52 . 2010-11-26 02:52 59392 ----a-w- c:\windows\system32\atiedu64.dll
- 2010-11-26 02:52 . 2010-11-26 02:52 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
- 2010-11-26 02:49 . 2010-11-26 02:49 4066816 ----a-w- c:\windows\SysWow64\atidxx32.dll
- 2010-11-26 02:40 . 2010-11-26 02:40 4794368 ----a-w- c:\windows\system32\atidxx64.dll
- 2010-11-26 02:30 . 2010-11-26 02:30 51200 ----a-w- c:\windows\system32\aticalrt64.dll
- 2010-11-26 02:30 . 2010-11-26 02:30 4122624 ----a-w- c:\windows\SysWow64\atiumdag.dll
- 2010-11-26 02:30 . 2010-11-26 02:30 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
- 2010-11-26 02:30 . 2010-11-26 02:30 44544 ----a-w- c:\windows\system32\aticalcl64.dll
- 2010-11-26 02:30 . 2010-11-26 02:30 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
- 2010-11-26 02:29 . 2010-11-26 02:29 6815232 ----a-w- c:\windows\system32\aticaldd64.dll
- 2010-11-26 02:29 . 2010-11-26 02:29 3217408 ----a-w- c:\windows\system32\atiumd6a.dll
- 2010-11-26 02:28 . 2010-11-26 02:28 5441024 ----a-w- c:\windows\SysWow64\aticaldd.dll
- 2010-11-26 02:24 . 2010-11-26 02:24 58880 ----a-w- c:\windows\system32\coinst.dll
- 2010-11-26 02:24 . 2010-11-26 02:24 5258240 ----a-w- c:\windows\system32\atiumd64.dll
- 2010-11-26 02:22 . 2010-11-26 02:22 3460096 ----a-w- c:\windows\SysWow64\atiumdva.dll
- 2010-11-26 02:17 . 2010-11-26 02:17 351232 ----a-w- c:\windows\system32\atiadlxx.dll
- 2010-11-26 02:17 . 2010-11-26 02:17 249856 ----a-w- c:\windows\SysWow64\atiadlxy.dll
- 2010-11-26 02:17 . 2010-11-26 02:17 14848 ----a-w- c:\windows\system32\atig6pxx.dll
- 2010-11-26 02:17 . 2010-11-26 02:17 12800 ----a-w- c:\windows\SysWow64\atiglpxx.dll
- 2010-11-26 02:17 . 2010-11-26 02:17 12800 ----a-w- c:\windows\system32\atiglpxx.dll
- 2010-11-26 02:17 . 2010-11-26 02:17 31744 ----a-w- c:\windows\system32\atig6txx.dll
- 2010-11-26 02:16 . 2010-11-26 02:16 27136 ----a-w- c:\windows\SysWow64\atigktxx.dll
- 2010-11-26 02:16 . 2010-11-26 02:16 289792 ----a-w- c:\windows\system32\drivers\atikmpag.sys
- 2010-11-26 02:16 . 2010-11-26 02:16 39936 ----a-w- c:\windows\system32\atiuxp64.dll
- 2010-11-26 02:15 . 2010-11-26 02:15 30720 ----a-w- c:\windows\SysWow64\atiuxpag.dll
- 2010-11-26 02:15 . 2010-11-26 02:15 37888 ----a-w- c:\windows\system32\atiu9p64.dll
- 2010-11-26 02:15 . 2010-11-26 02:15 28672 ----a-w- c:\windows\SysWow64\atiu9pag.dll
- 2010-11-26 02:15 . 2010-11-26 02:15 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
- 2010-11-26 02:09 . 2010-11-26 02:09 53760 ----a-w- c:\windows\system32\atimpc64.dll
- 2010-11-26 02:09 . 2010-11-26 02:09 53760 ----a-w- c:\windows\system32\amdpcom64.dll
- 2010-11-26 02:09 . 2010-11-26 02:09 52736 ----a-w- c:\windows\SysWow64\atimpc32.dll
- 2010-11-26 02:09 . 2010-11-26 02:09 52736 ----a-w- c:\windows\SysWow64\amdpcom32.dll
- 2010-11-18 03:38 . 2009-08-18 18:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
- 2010-11-18 03:38 . 2009-08-18 17:24 17816 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
- 2010-11-17 12:04 . 2010-11-17 12:04 115216 ----a-w- c:\windows\system32\drivers\AtihdW76.sys
- 2010-11-13 00:53 . 2010-09-19 06:51 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "Google Update"="c:\users\Joe\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-11-21 136176]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
- "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-03-19 421888]
- "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-07-21 141608]
- "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
- "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
- "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
- "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-11-26 98304]
- "Razer Naga Driver"="c:\program files (x86)\Razer\Naga Epic\NagaEpicSysTray.exe" [2010-12-30 957840]
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
- "ConsentPromptBehaviorAdmin"= 5 (0x5)
- "ConsentPromptBehaviorUser"= 3 (0x3)
- "EnableUIADesktopToggle"= 0 (0x0)
- [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
- Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
- @="Service"
- R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
- R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
- R3 atillk64;atillk64;c:\users\Joe\Desktop\winflash\atillk64.sys [x]
- R3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [2007-08-02 12672]
- R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2010-07-11 19952]
- R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2010-04-20 50688]
- R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-06 1255736]
- S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-11-26 203776]
- S2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x64.sys [2010-07-09 21480]
- S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-11-26 8120320]
- S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-11-26 289792]
- S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2010-11-17 115216]
- S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 40832]
- S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-25 72064]
- S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
- S3 RzSynapse;Razer Driver;c:\windows\system32\DRIVERS\RzSynapse.sys [2010-12-16 126464]
- .
- Contents of the 'Scheduled Tasks' folder
- 2011-01-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-560932278-2290011197-830165931-1001Core.job
- - c:\users\Joe\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-21 05:59]
- 2011-02-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-560932278-2290011197-830165931-1001UA.job
- - c:\users\Joe\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-21 05:59]
- .
- --------- x86-64 -----------
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 1436224]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
- "LoadAppInit_DLLs"=0x0
- .
- ------- Supplementary Scan -------
- .
- uLocal Page = c:\windows\system32\blank.htm
- mLocal Page = c:\windows\SysWOW64\blank.htm
- uInternet Settings,ProxyOverride = *.local
- TCP: {45078DEC-B30F-4C7F-A8ED-E35D66F90B48} = 208.180.83.133,208.180.42.68
- .
- - - - - ORPHANS REMOVED - - - -
- AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_bc2.exe
- .
- --------------------- LOCKED REGISTRY KEYS ---------------------
- [HKEY_USERS\S-1-5-21-560932278-2290011197-830165931-1001\Software\SecuROM\License information*]
- "datasecu"=hex:44,18,99,e5,f5,8d,48,d2,ee,e6,96,0d,8b,ae,a3,55,c9,6d,4b,a0,53,
- 7e,f2,81,8e,31,02,17,ed,c0,c0,ad,42,69,d5,76,cc,ea,95,3b,d3,74,65,99,2d,c5,\
- "rkeysecu"=hex:93,dd,bc,dc,75,2e,28,b7,c5,da,89,a6,04,35,74,37
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
- @Denied: (Full) (Everyone)
- .
- ------------------------ Other Running Processes ------------------------
- .
- c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
- c:\program files (x86)\Bonjour\mDNSResponder.exe
- c:\windows\SysWOW64\PnkBstrA.exe
- .
- **************************************************************************
- .
- Completion time: 2011-02-09 23:03:56 - machine was rebooted
- ComboFix-quarantined-files.txt 2011-02-10 05:03
- Pre-Run: 29,713,182,720 bytes free
- Post-Run: 29,639,577,600 bytes free
- - - End Of File - - F939FECB38C61649111CDBBDFA3E655E
Add Comment
Please, Sign In to add comment