Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 11-06-25.05 - Omega 6.06.2011. 18:18:31.2.4 - x64
- Microsoft Windows 7 Professional 6.1.7601.1.1250.385.1033.18.4091.2983 [GMT 2:00]
- Running from: c:\users\Omega\Desktop\ComboFix.exe
- Command switches used :: c:\users\Omega\Desktop\CFScript.txt
- AV: ESET Smart Security 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
- FW: ESET Personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
- SP: ESET Smart Security 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
- SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- .
- FILE ::
- "c:\windows\ativpsrm.bin"
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- c:\windows\ativpsrm.bin
- .
- .
- ((((((((((((((((((((((((( Files Created from 2011-05-26 to 2011-06-26 )))))))))))))))))))))))))))))))
- .
- .
- 2011-06-26 16:21 . 2011-06-26 16:21 -------- d-----w- c:\users\Default\AppData\Local\temp
- 2011-06-25 19:49 . 2011-06-25 19:49 -------- d-----w- C:\_OTS
- 2011-06-25 15:17 . 2011-06-25 15:43 -------- d-----w- c:\programdata\TuneUp Software
- 2011-06-25 15:13 . 2011-06-25 15:13 -------- d-sh--w- c:\programdata\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
- 2011-06-24 21:51 . 2011-06-24 21:51 -------- d-----w- c:\programdata\ATI
- 2011-06-24 21:49 . 2010-04-29 03:43 38528 ----a-w- c:\windows\system32\drivers\usbfilter.sys
- 2011-06-24 14:40 . 2011-02-24 06:15 476160 ----a-w- c:\windows\system32\XpsGdiConverter.dll
- 2011-06-24 14:40 . 2011-02-24 05:38 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
- 2011-06-24 14:40 . 2011-03-12 12:08 1465344 ----a-w- c:\windows\system32\XpsPrint.dll
- 2011-06-24 14:40 . 2011-03-12 11:23 870912 ----a-w- c:\windows\SysWow64\XpsPrint.dll
- 2011-06-24 14:40 . 2011-02-18 10:51 31232 ----a-w- c:\windows\system32\prevhost.exe
- 2011-06-24 14:40 . 2011-02-18 05:39 31232 ----a-w- c:\windows\SysWow64\prevhost.exe
- 2011-06-24 14:10 . 2011-06-26 14:58 -------- d-----w- c:\programdata\boost_interprocess
- 2011-06-24 13:49 . 2011-06-25 15:27 -------- d-----w- c:\program files (x86)\Microsoft.NET
- 2011-06-24 13:49 . 2011-06-24 13:49 -------- d-----w- c:\windows\PCHEALTH
- 2011-06-24 13:46 . 2011-06-24 13:46 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
- 2011-06-24 13:45 . 2011-06-24 13:45 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
- 2011-06-24 13:45 . 2011-06-24 15:18 -------- d-----w- c:\programdata\Microsoft Help
- 2011-06-24 13:45 . 2011-06-24 13:45 -------- d-----r- C:\MSOCache
- 2011-06-24 10:24 . 2011-06-24 10:24 -------- d-----w- c:\program files (x86)\HD Tune Pro
- 2011-06-24 10:21 . 2011-06-20 06:57 8873296 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CE41931E-0043-4899-A23C-7407CD64D743}\mpengine.dll
- 2011-06-24 10:18 . 2011-06-24 10:18 -------- d-----w- c:\program files\ESET
- 2011-06-24 10:14 . 2011-06-24 10:14 -------- d-----w- c:\programdata\OEM
- 2011-06-24 10:14 . 2011-06-24 10:14 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
- 2011-06-24 10:14 . 2011-06-24 10:14 -------- d-----w- c:\program files\Acer
- 2011-06-24 10:12 . 2011-06-24 10:12 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
- 2011-06-24 10:12 . 2011-06-24 10:12 -------- d-----w- c:\windows\SysWow64\Macromed
- 2011-06-24 10:08 . 2011-06-24 10:08 -------- d-----w- c:\program files (x86)\Launch Manager
- 2011-06-24 00:30 . 2011-06-24 21:49 -------- dc----w- c:\windows\system32\DRVSTORE
- 2011-06-24 00:28 . 2011-06-24 00:27 51200 ----a-w- c:\windows\system32\ATIODCLI.exe
- 2011-06-24 00:28 . 2011-06-24 00:27 332800 ----a-w- c:\windows\system32\ATIODE.exe
- 2011-06-24 00:28 . 2011-06-24 00:27 16440 ----a-w- c:\windows\system32\drivers\AtiPcie64.sys
- 2011-06-24 00:28 . 2011-06-24 00:27 118784 ----a-w- c:\windows\system32\atibtmon.exe
- 2011-06-24 00:28 . 2010-10-28 09:04 340480 ----a-w- c:\windows\system32\atiadlxx.dll
- 2011-06-24 00:17 . 2011-06-24 00:17 -------- d-----w- c:\program files (x86)\FinalWire
- 2011-06-23 23:57 . 2011-06-23 23:57 -------- d-----w- c:\windows\system32\appmgmt
- 2011-06-23 23:51 . 2011-06-23 23:51 -------- d-----w- c:\programdata\AMD
- 2011-06-23 23:51 . 2010-02-18 07:18 46136 ----a-w- c:\windows\system32\drivers\amdiox64.sys
- 2011-06-23 23:50 . 2011-06-23 23:50 -------- d-----w- C:\ATI
- 2011-06-23 23:49 . 2011-06-24 20:58 -------- d-----w- C:\AMD
- 2011-06-23 22:11 . 2011-06-23 12:20 -------- d-----w- c:\windows\Panther
- 2011-06-23 18:07 . 2011-02-25 06:19 2871808 ----a-w- c:\windows\explorer.exe
- 2011-06-23 18:07 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\SysWow64\explorer.exe
- 2011-06-23 18:07 . 2011-02-19 12:05 1139200 ----a-w- c:\windows\system32\FntCache.dll
- 2011-06-23 18:07 . 2011-02-19 12:04 1544192 ----a-w- c:\windows\system32\DWrite.dll
- 2011-06-23 18:07 . 2011-02-19 12:04 902656 ----a-w- c:\windows\system32\d2d1.dll
- 2011-06-23 18:07 . 2011-02-19 06:30 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll
- 2011-06-23 18:07 . 2011-02-19 06:30 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
- 2011-06-23 18:07 . 2011-04-22 22:15 27520 ----a-w- c:\windows\system32\drivers\Diskdump.sys
- 2011-06-23 18:07 . 2011-01-17 11:09 197120 ----a-w- c:\windows\system32\d3d10_1.dll
- 2011-06-23 18:07 . 2011-01-17 05:47 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
- 2011-06-23 17:54 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe
- 2011-06-23 17:54 . 2011-04-09 05:56 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
- 2011-06-23 14:02 . 2011-06-23 14:02 -------- d-----r- c:\program files (x86)\Skype
- 2011-06-23 14:02 . 2011-06-25 19:46 -------- d-sh--w- c:\windows\Installer
- 2011-06-23 14:02 . 2011-06-23 14:02 -------- d-----w- c:\programdata\Skype
- 2011-06-23 12:26 . 2010-05-11 10:11 2229608 ----a-w- c:\windows\system32\drivers\athrx.sys
- 2011-06-23 12:20 . 2011-06-23 12:22 -------- d-----w- c:\users\Omega
- 2011-06-23 12:20 . 2011-06-23 12:20 -------- d-----w- C:\Recovery
- .
- .
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2011-05-25 04:12 . 2011-05-25 04:12 676864 ----a-w- c:\windows\SysWow64\aticfx32.dll
- 2011-05-25 04:11 . 2011-05-25 04:11 795648 ----a-w- c:\windows\system32\aticfx64.dll
- 2011-05-25 04:05 . 2011-05-25 04:05 278528 ----a-w- c:\windows\SysWow64\Oemdspif.dll
- 2011-05-25 03:18 . 2011-05-25 03:18 1222656 ----a-w- c:\windows\system32\atiumd6v.dll
- 2011-05-25 03:18 . 2011-05-25 03:18 1923584 ----a-w- c:\windows\SysWow64\atiumdmv.dll
- 2011-05-24 22:04 . 2011-05-24 22:04 61952 ----a-w- c:\windows\system32\OVDecode64.dll
- 2011-05-24 22:04 . 2011-05-24 22:04 59904 ----a-w- c:\windows\SysWow64\OVDecode.dll
- 2011-05-24 21:44 . 2011-05-24 21:44 53760 ----a-w- c:\windows\system32\OpenCL.dll
- 2011-05-24 21:44 . 2011-05-24 21:44 51712 ----a-w- c:\windows\SysWow64\OpenCL.dll
- 2011-05-24 21:44 . 2011-05-24 21:44 16672768 ----a-w- c:\windows\system32\amdocl64.dll
- 2011-05-24 21:43 . 2011-05-24 21:43 12798976 ----a-w- c:\windows\SysWow64\amdocl.dll
- 2011-05-24 17:14 . 2010-11-21 03:27 270720 ------w- c:\windows\system32\MpSigStub.exe
- .
- .
- (((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- --- c:\windows\explorer.exe ---
- Company: Microsoft Corporation
- File Description: Windows Explorer
- File Version: 6.1.7600.16385 (win7_rtm.090713-1255)
- Product Name: Microsoft® Windows® Operating System
- Copyright: © Microsoft Corporation. All rights reserved.
- Original Filename: EXPLORER.EXE.MUI
- File size: 2871808
- Created time: 2011-06-23 18:07
- Modified time: 2011-02-25 06:19
- MD5: 332FEAB1435662FC6C672E25BEB37BE3
- SHA1: 5A49D7390EE87519B9D69D3E4AA66CA066CC8255
- .
- .
- ((((((((((((((((((((((((((((( SnapShot@2011-06-26_11.20.00 )))))))))))))))))))))))))))))))))))))))))
- .
- + 2010-11-21 03:09 . 2011-06-26 16:12 24008 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- + 2009-07-14 05:10 . 2011-06-26 16:12 32272 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- - 2009-07-14 05:30 . 2011-06-24 21:48 86016 c:\windows\system32\DriverStore\infpub.dat
- + 2009-07-14 05:30 . 2011-06-26 14:51 86016 c:\windows\system32\DriverStore\infpub.dat
- + 2011-06-23 12:15 . 2011-06-26 12:27 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- - 2011-06-23 12:15 . 2011-06-25 15:19 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- + 2011-06-26 12:27 . 2011-06-26 12:27 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- - 2009-07-14 04:54 . 2011-06-25 15:19 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- + 2009-07-14 04:54 . 2011-06-26 12:27 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- + 2011-06-25 14:45 . 2011-06-26 16:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- - 2011-06-25 14:45 . 2011-06-26 11:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- + 2011-06-25 14:45 . 2011-06-26 16:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- - 2011-06-25 14:45 . 2011-06-26 11:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- + 2011-06-25 10:46 . 2011-06-26 12:03 2186 c:\windows\system32\wdi\ERCQueuedResolutions.dat
- + 2011-06-23 12:23 . 2011-06-26 16:12 5478 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4215902464-4029754357-1815175175-1000_UserData.bin
- - 2011-06-26 11:14 . 2011-06-26 11:14 9560 c:\windows\system32\NetworkList\Icons\{5E45F88B-E8C0-44D7-A28E-29678169E051}_48.bin
- + 2011-06-26 11:14 . 2011-06-26 14:58 9560 c:\windows\system32\NetworkList\Icons\{5E45F88B-E8C0-44D7-A28E-29678169E051}_48.bin
- + 2011-06-26 11:14 . 2011-06-26 14:58 4280 c:\windows\system32\NetworkList\Icons\{5E45F88B-E8C0-44D7-A28E-29678169E051}_32.bin
- - 2011-06-26 11:14 . 2011-06-26 11:14 4280 c:\windows\system32\NetworkList\Icons\{5E45F88B-E8C0-44D7-A28E-29678169E051}_32.bin
- + 2011-06-26 11:14 . 2011-06-26 14:58 2456 c:\windows\system32\NetworkList\Icons\{5E45F88B-E8C0-44D7-A28E-29678169E051}_24.bin
- - 2011-06-26 11:14 . 2011-06-26 11:14 2456 c:\windows\system32\NetworkList\Icons\{5E45F88B-E8C0-44D7-A28E-29678169E051}_24.bin
- + 2011-06-26 16:22 . 2011-06-26 16:22 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- - 2011-06-26 11:19 . 2011-06-26 11:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- + 2011-06-26 16:22 . 2011-06-26 16:22 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- - 2011-06-26 11:19 . 2011-06-26 11:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- + 2011-06-24 14:10 . 2011-06-26 12:36 170304 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
- - 2009-07-14 02:36 . 2011-06-25 20:53 616008 c:\windows\system32\perfh009.dat
- + 2009-07-14 02:36 . 2011-06-26 16:17 616008 c:\windows\system32\perfh009.dat
- + 2009-07-14 02:36 . 2011-06-26 16:17 106388 c:\windows\system32\perfc009.dat
- - 2009-07-14 02:36 . 2011-06-25 20:53 106388 c:\windows\system32\perfc009.dat
- + 2009-07-14 05:30 . 2011-06-26 14:51 143360 c:\windows\system32\DriverStore\infstrng.dat
- - 2009-07-14 05:30 . 2011-06-24 21:48 143360 c:\windows\system32\DriverStore\infstrng.dat
- + 2009-07-14 00:21 . 2009-07-14 01:41 299520 c:\windows\system32\drivers\UMDF\WpdFs.dll
- + 2009-07-14 05:01 . 2011-06-26 16:21 334996 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- - 2009-07-14 05:01 . 2011-06-26 11:18 334996 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- + 2011-06-23 14:21 . 2011-06-26 12:40 9535548 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4215902464-4029754357-1815175175-1000-8192.dat
- - 2011-06-23 14:21 . 2011-06-26 11:18 9535548 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4215902464-4029754357-1815175175-1000-8192.dat
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- .
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-06-15 15141768]
- "googletalk"="c:\users\Omega\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
- "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-06-22 968272]
- "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-10-28 98304]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
- "ConsentPromptBehaviorAdmin"= 5 (0x5)
- "ConsentPromptBehaviorUser"= 3 (0x3)
- "EnableUIADesktopToggle"= 0 (0x0)
- .
- R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
- R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
- R3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
- R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]
- R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
- R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
- R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
- S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
- S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
- S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
- S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-06-22 321104]
- S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
- S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2011-01-12 810144]
- S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
- S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-06-11 868896]
- S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
- S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
- S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
- S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
- S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
- .
- .
- .
- --------- x86-64 -----------
- .
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-06-11 861216]
- "egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-01-12 2918656]
- .
- ------- Supplementary Scan -------
- .
- uLocal Page = c:\windows\system32\blank.htm
- mLocal Page = c:\windows\SysWOW64\blank.htm
- IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
- IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
- FF - ProfilePath - c:\users\Omega\AppData\Roaming\Mozilla\Firefox\Profiles\7g0t4v0c.default\
- .
- .
- --------------------- LOCKED REGISTRY KEYS ---------------------
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Swearware\backup\winsock2\Parameters]
- @DACL=(02 0000)
- @SACL=
- "NameSpace_Callout"=expand:"%SystemRoot%\\System32\\fwpuclnt.dll"
- "WinSock_Registry_Version"="2.0"
- "AutodialDLL"="rasadhlp.dll"
- "Current_NameSpace_Catalog"="NameSpace_Catalog5"
- "Current_Protocol_Catalog"="Protocol_Catalog9"
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
- @Denied: (Full) (Everyone)
- .
- ------------------------ Other Running Processes ------------------------
- .
- c:\program files (x86)\Launch Manager\LMworker.exe
- .
- **************************************************************************
- .
- Completion time: 2011-06-26 18:26:57 - machine was rebooted
- ComboFix-quarantined-files.txt 2011-06-26 16:26
- ComboFix2.txt 2011-06-26 11:25
- .
- Pre-Run: 180.921.303.040 bytes free
- Post-Run: 180.596.736.000 bytes free
- .
- - - End Of File - - AC2478C458892781D012B1655CE685D2
Advertisement
Add Comment
Please, Sign In to add comment