Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 10-11-14.04 - Uzair 15/11/2010 14:58:02.2.2 - x86
- Microsoft Windows 7 Ultimate 6.1.7600.0.1252.44.1033.18.2010.1123 [GMT 0:00]
- Running from: c:\users\Uzair\Desktop\ComboFix.exe
- Command switches used :: c:\users\Uzair\Desktop\CFScript.txt
- * Created a new restore point
- FILE ::
- "c:\windows\Brerea.exe"
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- c:\windows\Brerea.exe
- .
- ((((((((((((((((((((((((( Files Created from 2010-10-15 to 2010-11-15 )))))))))))))))))))))))))))))))
- .
- 2010-11-15 15:12 . 2010-11-15 15:12 -------- d-----w- c:\users\Default\AppData\Local\temp
- 2010-11-15 13:06 . 2010-11-15 14:25 -------- d-----w- c:\users\Uzair\AppData\Roaming\DivX
- 2010-11-13 23:34 . 2009-09-04 17:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
- 2010-11-13 23:34 . 2009-09-04 17:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
- 2010-11-13 22:18 . 2010-11-13 22:18 -------- d-----w- c:\program files\Veetle
- 2010-11-11 17:26 . 2010-11-11 17:26 -------- d-----w- c:\windows\Sun
- 2010-11-11 16:17 . 2010-11-11 16:17 105984 --sha-r- c:\windows\system32\msvbvm60O.dll
- 2010-11-10 15:38 . 2010-11-10 15:38 180224 ----a-w- c:\windows\system32\WinVd32.sys
- 2010-11-10 15:37 . 2010-11-10 15:37 7680 ----a-w- c:\windows\system32\WinFLsrv.exe
- 2010-11-10 15:37 . 2010-11-10 15:38 -------- d-----w- c:\program files\Folder Lock 6
- 2010-11-09 20:54 . 2010-10-07 23:21 6146896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1AAC5FFB-72A4-40F8-99C5-1551F7210ED5}\mpengine.dll
- 2010-11-08 07:05 . 2010-11-08 07:05 -------- d-----w- C:\found.001
- 2010-11-06 11:44 . 2010-11-06 11:44 -------- d-----w- c:\program files\iPod
- 2010-11-06 11:39 . 2010-11-06 11:39 -------- d-----w- c:\program files\Bonjour
- 2010-11-03 21:53 . 2010-11-13 21:35 -------- d-----w- c:\users\Uzair\Incomplete
- 2010-11-03 21:49 . 2010-11-13 22:06 -------- d-----w- c:\users\Uzair\AppData\Roaming\FrostWire
- 2010-11-03 21:47 . 2010-11-03 21:50 -------- d-----w- c:\program files\FrostWire
- 2010-10-27 09:41 . 2010-08-04 06:18 641536 ----a-w- c:\windows\system32\CPFilters.dll
- 2010-10-27 09:41 . 2010-08-04 06:17 417792 ----a-w- c:\windows\system32\msdri.dll
- 2010-10-27 09:41 . 2010-08-04 06:15 204288 ----a-w- c:\windows\system32\MSNP.ax
- 2010-10-27 09:41 . 2010-08-04 06:15 199680 ----a-w- c:\windows\system32\mpg2splt.ax
- 2010-10-27 09:41 . 2010-07-13 05:22 26504 ----a-w- c:\windows\system32\drivers\Diskdump.sys
- 2010-10-16 19:22 . 2010-06-29 04:57 4247040 ----a-w- c:\program files\Windows NT\Accessories\wordpad.exe
- 2010-10-16 19:22 . 2010-06-29 05:02 1413632 ----a-w- c:\windows\system32\ole32.dll
- 2010-10-16 19:22 . 2010-09-01 04:26 164864 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
- 2010-10-16 19:22 . 2010-09-01 04:23 12625408 ----a-w- c:\windows\system32\wmploc.DLL
- 2010-10-16 19:18 . 2010-05-05 06:46 363520 ----a-w- c:\windows\system32\StructuredQuery.dll
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2010-10-19 10:41 . 2010-06-27 11:34 222080 ------w- c:\windows\system32\MpSigStub.exe
- 2010-09-15 04:50 . 2010-07-06 11:51 472808 ----a-w- c:\windows\system32\deployJava1.dll
- 2010-09-08 11:17 . 2010-09-08 11:17 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
- 2010-09-08 11:17 . 2010-09-08 11:17 69632 ----a-w- c:\windows\system32\QuickTime.qts
- 2010-08-28 12:35 . 2010-08-28 12:35 112832 ----a-w- c:\programdata\Microsoft\VCExpress\10.0\1033\ResourceCache.dll
- 2010-08-21 05:32 . 2010-09-15 15:22 316928 ----a-w- c:\windows\system32\spoolsv.exe
- 2010-06-27 16:22 . 2010-06-28 11:19 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
- @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
- 2009-12-09 01:19 94208 ----a-w- c:\users\Uzair\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
- @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
- 2009-12-09 01:19 94208 ----a-w- c:\users\Uzair\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
- @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
- 2009-12-09 01:19 94208 ----a-w- c:\users\Uzair\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "Google Update"="c:\users\Uzair\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-06-27 136176]
- "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
- "Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-05-13 26192168]
- "ICQ"="c:\program files\ICQ7.2\ICQ.exe" [2010-10-27 133432]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2010-02-26 495708]
- "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-27 30192]
- "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
- "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
- "openvpn-gui"="c:\program files\UltraVPN\bin\openvpn-gui.exe" [2010-04-19 370948]
- "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
- "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
- "AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
- "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-21 1797008]
- "itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2009-06-01 1501064]
- "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
- "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-01 1164584]
- "Live! Central 2"="c:\program files\Creative\Creative Live! Cam\Live! Central 2\CTLVCentral2.exe" [2009-11-04 426140]
- "V0640Mon.exe"="c:\windows\V0640Mon.exe" [2009-09-22 28672]
- "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-07-28 136216]
- "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-07-28 171032]
- "Persistence"="c:\windows\system32\igfxpers.exe" [2010-07-28 170520]
- "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
- "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
- "V0640Pin.dll"="V0640Pin.dll" [2009-11-13 45056]
- "VX1000"="c:\windows\vVX1000.exe" [2010-05-20 762736]
- "LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2010-05-20 119152]
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
- "ConsentPromptBehaviorAdmin"= 5 (0x5)
- "ConsentPromptBehaviorUser"= 3 (0x3)
- "EnableUIADesktopToggle"= 0 (0x0)
- [hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
- "{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences\FencesMenu.dll" [2010-06-22 202088]
- [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
- "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
- R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
- R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-08-08 136176]
- R2 mi-raysat_3dsmax2011_32;mental ray 3.8 Satellite for Autodesk 3ds Max 2011 32-bit 32-bit;c:\program files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe [2010-03-10 86016]
- R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2009-08-21 143936]
- R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-06-27 30192]
- R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [x]
- R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
- R3 V0640Vid;Creative Live! Cam Socialize (VF0640) Driver;c:\windows\system32\DRIVERS\V0640Vid.sys [2009-12-03 273760]
- R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-28 1343400]
- R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
- R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]
- R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 366936]
- S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
- S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_028821c569ae5894\aestsrv.exe [2009-03-03 81920]
- S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 20992]
- S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2010-03-28 246520]
- S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 50704]
- S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2010-07-07 44432]
- S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
- S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-07-13 311296]
- [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
- Akamai REG_MULTI_SZ Akamai
- .
- Contents of the 'Scheduled Tasks' folder
- 2010-11-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- - c:\program files\Google\Update\GoogleUpdate.exe [2010-08-09 21:37]
- 2010-11-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- - c:\program files\Google\Update\GoogleUpdate.exe [2010-08-09 21:37]
- 2010-11-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2285835813-632877105-3558421781-1001Core.job
- - c:\users\Uzair\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-27 11:32]
- 2010-11-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2285835813-632877105-3558421781-1001UA.job
- - c:\users\Uzair\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-27 11:32]
- .
- .
- ------- Supplementary Scan -------
- .
- uInternet Settings,ProxyOverride = *.local
- IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
- IE: Free YouTube Download - c:\users\Uzair\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm
- IE: Free YouTube to Mp3 Converter - c:\users\Uzair\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
- DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.3.1.0.cab
- FF - ProfilePath - c:\users\Uzair\AppData\Roaming\Mozilla\Firefox\Profiles\vvf95d25.default\
- FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
- FF - component: c:\users\Uzair\AppData\Roaming\Mozilla\Firefox\Profiles\vvf95d25.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
- FF - component: c:\users\Uzair\AppData\Roaming\Mozilla\Firefox\Profiles\vvf95d25.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\FFExternalAlert.dll
- FF - component: c:\users\Uzair\AppData\Roaming\Mozilla\Firefox\Profiles\vvf95d25.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCore.dll
- ---- FIREFOX POLICIES ----
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
- .
- - - - - ORPHANS REMOVED - - - -
- WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
- .
- --------------------- LOCKED REGISTRY KEYS ---------------------
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
- @Denied: (Full) (Everyone)
- .
- Completion time: 2010-11-15 15:21:06
- ComboFix-quarantined-files.txt 2010-11-15 15:21
- ComboFix2.txt 2010-11-14 11:42
- Pre-Run: 28,254,040,064 bytes free
- Post-Run: 28,253,114,368 bytes free
- - - End Of File - - FB3DF6ACE19F8FC599AB48BDC4C13CCC
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement