Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 12-06-27.01 - nick 27/06/2012 23:21:19.1.2 - x86
- Microsoft Windows XP Home Edition 5.1.2600.3.1253.30.1032.18.1022.503 [GMT 3:00]
- Running from: f:\τα έγγραφα μου\Ληφθέντα αρχεία\ComboFix.exe
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- c:\documents and settings\All Users\Application Data\TEMP
- c:\documents and settings\nick\Application Data\facemoods.com
- c:\documents and settings\nick\Application Data\PriceGong
- c:\documents and settings\nick\Application Data\PriceGong\Data\1.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\a.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\b.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\c.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\d.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\e.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\f.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\g.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\h.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\i.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\J.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\k.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\l.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\m.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\mru.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\n.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\o.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\p.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\q.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\r.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\s.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\t.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\u.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\v.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\w.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\x.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\y.xml
- c:\documents and settings\nick\Application Data\PriceGong\Data\z.xml
- c:\documents and settings\nick\Local Settings\Application Data\{1b63943d-e31c-cd2d-7a63-5dd2deb1a814}
- c:\documents and settings\nick\Local Settings\Application Data\{1b63943d-e31c-cd2d-7a63-5dd2deb1a814}\@
- c:\documents and settings\nick\Local Settings\Application Data\{1b63943d-e31c-cd2d-7a63-5dd2deb1a814}\n
- c:\documents and settings\nick\Local Settings\Application Data\{1b63943d-e31c-cd2d-7a63-5dd2deb1a814}\U\00000001.@
- c:\documents and settings\nick\Local Settings\Application Data\{1b63943d-e31c-cd2d-7a63-5dd2deb1a814}\U\80000000.@
- c:\documents and settings\nick\Local Settings\Application Data\{1b63943d-e31c-cd2d-7a63-5dd2deb1a814}\U\800000cb.@
- c:\documents and settings\nick\Local Settings\Application Data\assembly\tmp
- c:\windows\Installer\{1b63943d-e31c-cd2d-7a63-5dd2deb1a814}
- c:\windows\Installer\{1b63943d-e31c-cd2d-7a63-5dd2deb1a814}\@
- c:\windows\Installer\{1b63943d-e31c-cd2d-7a63-5dd2deb1a814}\n
- c:\windows\system32\SET18C.tmp
- c:\windows\system32\SET198.tmp
- f:\τα έγγραφα μου\vlc-2.0.1-win32.exe
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- -------\Legacy_NPF
- .
- .
- ((((((((((((((((((((((((( Files Created from 2012-05-27 to 2012-06-27 )))))))))))))))))))))))))))))))
- .
- .
- 2012-06-27 20:12 . 2012-06-27 20:12 -------- d-----w- c:\documents and settings\nick\Local Settings\Application Data\AskToolbar
- 2012-06-27 18:01 . 2012-06-27 18:01 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
- 2012-06-27 17:32 . 2012-06-27 20:12 -------- d-----w- C:\sh4ldr
- 2012-06-27 17:32 . 2012-06-27 17:32 -------- d-----w- c:\program files\Enigma Software Group
- 2012-06-27 17:32 . 2012-06-27 20:12 -------- d-----w- c:\windows\9E897D0FF80441A3966C7BB6EB5B6BE8.TMP
- 2012-06-27 17:31 . 2012-06-27 17:31 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
- 2012-06-27 17:26 . 2012-06-27 17:26 -------- d-----w- c:\documents and settings\nick\Application Data\DriverCure
- 2012-06-27 17:26 . 2012-06-27 17:26 -------- d-----w- c:\documents and settings\nick\Application Data\SpeedyPC Software
- 2012-06-27 17:26 . 2012-06-27 20:12 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedyPC Software
- 2012-06-27 17:08 . 2012-06-27 17:08 242240 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
- 2012-06-27 06:19 . 2012-06-27 17:09 -------- d-----w- c:\documents and settings\nick\Application Data\DAEMON Tools Lite
- 2012-06-27 06:19 . 2012-06-27 17:08 -------- d-----w- c:\program files\DAEMON Tools Lite
- 2012-06-27 06:18 . 2012-06-27 06:19 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
- 2012-06-19 14:23 . 2012-06-19 14:23 -------- d-----w- c:\documents and settings\nick\Application Data\Corel
- 2012-06-19 14:23 . 2012-06-19 14:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Protexis
- 2012-06-19 14:22 . 2012-06-19 14:22 -------- d-----w- c:\documents and settings\nick\Application Data\Ulead Systems
- 2012-06-19 14:22 . 2012-06-19 14:22 -------- d-----w- c:\documents and settings\nick\Local Settings\Application Data\Corel PaintShop Pro
- 2012-06-19 14:21 . 2012-06-24 13:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Corel
- 2012-06-19 14:21 . 2012-06-19 14:21 -------- d-----w- c:\program files\Common Files\Protexis
- 2012-06-19 14:17 . 2012-06-19 14:17 -------- d-----w- c:\program files\Corel
- 2012-06-19 14:17 . 2007-07-19 21:57 267112 ----a-w- c:\windows\system32\xactengine2_9.dll
- 2012-06-19 14:17 . 2007-06-20 17:46 266088 ----a-w- c:\windows\system32\xactengine2_8.dll
- 2012-06-19 14:17 . 2007-05-16 13:45 443752 ----a-w- c:\windows\system32\d3dx10_34.dll
- 2012-06-19 14:17 . 2007-05-16 13:45 1124720 ----a-w- c:\windows\system32\D3DCompiler_34.dll
- 2012-06-19 14:17 . 2007-04-04 15:53 81768 ----a-w- c:\windows\system32\xinput1_3.dll
- 2012-06-19 14:17 . 2007-04-04 15:55 261480 ----a-w- c:\windows\system32\xactengine2_7.dll
- 2012-06-19 14:17 . 2007-03-15 13:57 443752 ----a-w- c:\windows\system32\d3dx10_33.dll
- 2012-06-19 14:17 . 2007-03-12 13:42 1123696 ----a-w- c:\windows\system32\D3DCompiler_33.dll
- 2012-06-19 12:21 . 2012-06-19 12:21 -------- d-----w- c:\documents and settings\All Users\Application Data\regid.1986-12.com.adobe
- 2012-06-19 11:24 . 2012-06-19 11:24 -------- d-----w- c:\documents and settings\nick\Local Settings\Application Data\fontconfig
- 2012-06-19 11:24 . 2012-06-19 11:43 -------- d-----w- c:\documents and settings\nick\.gimp-2.8
- 2012-06-19 11:24 . 2012-06-19 11:24 -------- d-----w- c:\documents and settings\nick\Local Settings\Application Data\gegl-0.2
- 2012-06-13 11:59 . 2012-05-11 14:41 521728 -c----w- c:\windows\system32\dllcache\jsdbgui.dll
- 2012-06-11 14:22 . 2012-05-13 17:05 79872 ----a-w- c:\windows\system32\ff_vfw.dll
- 2012-06-11 14:22 . 2012-06-11 14:22 -------- d-----w- c:\program files\ffdshow
- 2012-06-11 14:19 . 2012-06-11 14:19 -------- d-----w- c:\program files\Haali
- 2012-06-11 13:45 . 2012-06-11 13:45 -------- d-----w- c:\documents and settings\nick\Application Data\RealNetworks
- 2012-06-02 13:14 . 2012-06-02 13:48 -------- d-----w- c:\documents and settings\nick\Application Data\Nero
- 2012-06-02 13:11 . 2012-06-02 13:12 -------- d-----w- c:\program files\Common Files\Nero
- 2012-06-02 13:11 . 2012-06-02 13:13 -------- d-----w- c:\program files\Nero
- 2012-06-02 13:11 . 2012-06-02 13:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
- 2012-06-02 13:05 . 2012-06-02 13:05 -------- d-----w- c:\program files\Ask.com
- 2012-06-02 13:05 . 2008-10-15 03:22 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll
- 2012-06-02 13:04 . 2007-05-16 13:45 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll
- 2012-06-01 18:35 . 2012-06-01 18:35 -------- d-----w- c:\program files\Common Files\xing shared
- 2012-05-30 17:33 . 2012-05-30 17:33 -------- d-----w- c:\documents and settings\nick\Application Data\Command & Conquer 3 Kane's Wrath
- 2012-05-30 17:32 . 2007-10-22 00:39 267272 ----a-w- c:\windows\system32\xactengine2_10.dll
- 2012-05-30 17:32 . 2007-10-22 00:37 17928 ----a-w- c:\windows\system32\X3DAudio1_2.dll
- 2012-05-30 17:32 . 2007-10-12 12:14 1374232 ----a-w- c:\windows\system32\D3DCompiler_36.dll
- 2012-05-30 17:32 . 2007-10-02 06:56 444776 ----a-w- c:\windows\system32\d3dx10_36.dll
- 2012-05-30 17:32 . 2007-10-12 12:14 3734536 ----a-w- c:\windows\system32\d3dx9_36.dll
- .
- .
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2012-06-23 11:35 . 2012-04-23 16:26 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
- 2012-06-23 11:35 . 2011-05-30 07:33 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
- 2012-06-02 12:19 . 2009-08-06 17:24 24088 ----a-w- c:\windows\system32\wucltui.dll.mui
- 2012-06-02 12:19 . 2009-08-06 17:24 16408 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
- 2012-06-02 12:19 . 2009-08-06 17:24 16408 ----a-w- c:\windows\system32\wuapi.dll.mui
- 2012-06-02 12:19 . 2010-12-22 05:29 329240 ----a-w- c:\windows\system32\wucltui.dll
- 2012-06-02 12:19 . 2010-12-22 05:29 210968 ----a-w- c:\windows\system32\wuweb.dll
- 2012-06-02 12:19 . 2010-12-22 05:29 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
- 2012-06-02 12:19 . 2010-12-22 05:29 53784 ----a-w- c:\windows\system32\wuauclt.exe
- 2012-06-02 12:19 . 2010-12-22 05:29 35864 ----a-w- c:\windows\system32\wups.dll
- 2012-06-02 12:19 . 2009-08-06 17:24 45080 ----a-w- c:\windows\system32\wups2.dll
- 2012-06-02 12:19 . 2006-03-02 12:00 97304 ----a-w- c:\windows\system32\cdm.dll
- 2012-06-02 12:19 . 2010-12-22 05:29 577048 ----a-w- c:\windows\system32\wuapi.dll
- 2012-06-02 12:19 . 2009-08-06 17:23 19480 ----a-w- c:\windows\system32\wuaueng.dll.mui
- 2012-06-02 12:19 . 2010-12-22 05:29 1933848 ----a-w- c:\windows\system32\wuaueng.dll
- 2012-06-02 12:19 . 2010-12-22 10:51 18672 ----a-w- c:\windows\system32\mucltui.dll.mui
- 2012-06-02 12:18 . 2010-12-22 10:51 275696 ----a-w- c:\windows\system32\mucltui.dll
- 2012-06-02 12:18 . 2010-12-22 10:51 214256 ----a-w- c:\windows\system32\muweb.dll
- 2012-06-01 18:34 . 2011-12-05 16:02 499712 ----a-w- c:\windows\system32\msvcp71.dll
- 2012-05-31 13:21 . 2006-03-02 12:00 604160 ----a-w- c:\windows\system32\crypt32.dll
- 2012-05-24 21:18 . 2012-05-24 21:18 4472832 ----a-w- c:\windows\system32\GPhotos.scr
- 2012-05-16 15:06 . 2006-03-02 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
- 2012-05-15 13:55 . 2006-03-02 12:00 1863424 ----a-w- c:\windows\system32\win32k.sys
- 2012-05-15 10:18 . 2011-12-31 19:33 65536 ----a-w- c:\windows\system32\OpenCL.dll
- 2012-05-15 10:18 . 2011-12-31 19:33 883008 ----a-w- c:\windows\system32\nvgenco32.dll
- 2012-05-15 10:18 . 2011-12-31 19:33 2530624 ----a-w- c:\windows\system32\nvcuvid.dll
- 2012-05-15 10:18 . 2011-12-31 19:33 1000768 ----a-w- c:\windows\system32\nvdispco32.dll
- 2012-05-15 10:18 . 2011-12-31 19:33 6012928 ----a-w- c:\windows\system32\nvcuda.dll
- 2012-05-15 10:18 . 2011-12-31 19:33 2445120 ----a-w- c:\windows\system32\nvcuvenc.dll
- 2012-05-15 10:18 . 2011-12-31 19:33 17543168 ----a-w- c:\windows\system32\nvcompiler.dll
- 2012-05-15 10:18 . 2006-02-15 11:07 18771968 ----a-w- c:\windows\system32\nvoglnt.dll
- 2012-05-15 10:18 . 2006-02-13 13:05 4373248 ----a-w- c:\windows\system32\nv4_disp.dll
- 2012-05-15 10:18 . 2006-02-13 13:05 2359808 ----a-w- c:\windows\system32\nvapi.dll
- 2012-05-15 10:18 . 2006-02-13 13:05 14014656 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
- 2012-05-15 09:43 . 2006-02-13 13:05 229376 ----a-w- c:\windows\system32\nvrszhc.dll
- 2012-05-15 09:43 . 2011-12-31 19:34 253952 ----a-w- c:\windows\system32\nvrsth.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 282624 ----a-w- c:\windows\system32\nvrsit.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 253952 ----a-w- c:\windows\system32\nvrssv.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 126976 ----a-w- c:\windows\system32\nvrszht.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 335872 ----a-w- c:\windows\system32\nvrsar.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 282624 ----a-w- c:\windows\system32\nvrsel.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 274432 ----a-w- c:\windows\system32\nvrsnl.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 274432 ----a-w- c:\windows\system32\nvrsesm.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 266240 ----a-w- c:\windows\system32\nvrsko.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 249856 ----a-w- c:\windows\system32\nvrseng.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 335872 ----a-w- c:\windows\system32\nvrshe.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 286720 ----a-w- c:\windows\system32\nvrsfr.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 274432 ----a-w- c:\windows\system32\nvrspt.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 258048 ----a-w- c:\windows\system32\nvrssl.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 253952 ----a-w- c:\windows\system32\nvrsno.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 249856 ----a-w- c:\windows\system32\nvrsfi.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 282624 ----a-w- c:\windows\system32\nvrses.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 270336 ----a-w- c:\windows\system32\nvrsru.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 258048 ----a-w- c:\windows\system32\nvrssk.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 262144 ----a-w- c:\windows\system32\nvrshu.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 258048 ----a-w- c:\windows\system32\nvrstr.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 253952 ----a-w- c:\windows\system32\nvrsda.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 274432 ----a-w- c:\windows\system32\nvrsja.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 258048 ----a-w- c:\windows\system32\nvrspl.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 278528 ----a-w- c:\windows\system32\nvrsde.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 270336 ----a-w- c:\windows\system32\nvrsptb.dll
- 2012-05-15 09:43 . 2006-02-13 13:05 249856 ----a-w- c:\windows\system32\nvrscs.dll
- 2012-05-15 09:40 . 2006-02-13 13:05 54272 ----a-w- c:\windows\system32\nvwddi.dll
- 2012-05-15 09:40 . 2006-02-13 13:05 15504192 ----a-w- c:\windows\system32\nvcpl.dll
- 2012-05-15 09:40 . 2006-02-13 13:05 143680 ----a-w- c:\windows\system32\nvcolor.exe
- 2012-05-15 09:40 . 2006-02-13 13:05 164160 ----a-w- c:\windows\system32\nvsvc32.exe
- 2012-05-15 09:40 . 2006-02-13 13:05 108352 ----a-w- c:\windows\system32\nvmctray.dll
- 2012-05-11 14:41 . 2006-03-02 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
- 2012-05-11 14:41 . 2006-03-02 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
- 2012-05-11 11:38 . 2006-03-02 12:00 385024 ----a-w- c:\windows\system32\html.iec
- 2012-05-05 03:14 . 2006-03-02 12:00 2155520 ----a-w- c:\windows\system32\ntoskrnl.exe
- 2012-05-05 03:14 . 2004-09-04 06:41 2033664 ----a-w- c:\windows\system32\ntkrnlpa.exe
- 2012-05-02 13:47 . 2010-12-22 05:27 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
- 2012-04-23 16:35 . 2010-12-29 16:38 73728 ----a-w- c:\windows\system32\javacpl.cpl
- 2012-04-23 16:35 . 2010-12-29 16:38 472808 ----a-w- c:\windows\system32\deployJava1.dll
- 2012-04-04 12:56 . 2011-10-25 09:55 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
- .
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- .
- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
- "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\prxtbuTo2.dll" [2011-05-09 176936]
- .
- [HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
- .
- [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
- 2011-05-09 09:49 176936 ----a-w- c:\program files\uTorrentBar\prxtbuTo2.dll
- .
- [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
- 2010-05-21 09:17 1233288 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
- "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\prxtbuTo2.dll" [2011-05-09 176936]
- "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-21 1233288]
- .
- [HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
- .
- [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
- [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
- [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
- [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
- .
- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
- "{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}"= "c:\program files\uTorrentBar\prxtbuTo2.dll" [2011-05-09 176936]
- "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-21 1233288]
- .
- [HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
- .
- [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
- [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
- [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
- [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
- .
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
- "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2012-04-17 3671872]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 61952]
- "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-01-21 91520]
- "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
- "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
- "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
- "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-05-15 15504192]
- "NvMediaCenter"="NvMCTray.dll" [2012-05-15 108352]
- "nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2012-05-15 1634112]
- "TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2012-06-01 296056]
- "WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-03-22 74752]
- "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
- "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
- "AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
- "UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408]
- .
- [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
- .
- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
- "%windir%\\system32\\sessmgr.exe"=
- .
- R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [27/6/2012 8:08 μμ 242240]
- R2 NAUpdate;@c:\program files\Nero\Update\NASvc.exe,-200;c:\program files\Nero\Update\NASvc.exe [4/5/2010 12:07 μμ 503080]
- R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [23/4/2012 2:23 μμ 1262400]
- R2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [19/6/2012 5:32 μμ 3048136]
- R3 SNCT511;See U Camera;c:\windows\system32\drivers\snct511.sys [19/6/2012 11:32 πμ 219264]
- S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/1/2011 1:09 πμ 136176]
- S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [14/6/2012 11:37 πμ 160944]
- S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [23/4/2012 7:26 μμ 250056]
- S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [24/12/2010 2:10 μμ 13192]
- S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [24/12/2010 2:10 μμ 8456]
- S3 gupdatem;Υπηρεσία Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/1/2011 1:09 πμ 136176]
- S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [21/1/2010 5:51 μμ 30963576]
- S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [11/5/2012 11:23 μμ 113120]
- S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [9/1/2010 8:37 μμ 4640000]
- S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19/2/2010 1:37 μμ 517096]
- S3 wxpSvc;webcamXP Service;c:\program files\wLite\wService.exe [3/5/2010 12:34 πμ 5027328]
- .
- Contents of the 'Scheduled Tasks' folder
- .
- 2012-06-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-23 11:35]
- .
- 2012-06-26 c:\windows\Tasks\debutShakeIcon.job
- - c:\program files\NCH Software\Debut\debut.exe [2012-06-19 10:50]
- .
- 2012-06-26 c:\windows\Tasks\ExpressBurnReminder.job
- - c:\program files\NCH Software\ExpressBurn\expressburn.exe [2012-06-19 10:51]
- .
- 2012-06-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- - c:\program files\Google\Update\GoogleUpdate.exe [2011-01-09 22:09]
- .
- 2012-06-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- - c:\program files\Google\Update\GoogleUpdate.exe [2011-01-09 22:09]
- .
- 2012-06-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-1592454029-725345543-1004Core.job
- - c:\documents and settings\nick\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-12-22 06:01]
- .
- 2012-06-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-1592454029-725345543-1004UA.job
- - c:\documents and settings\nick\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-12-22 06:01]
- .
- 2012-06-26 c:\windows\Tasks\prismShakeIcon.job
- - c:\program files\NCH Software\Prism\prism.exe [2012-06-19 10:50]
- .
- 2012-06-27 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-220523388-1592454029-725345543-1004.job
- - c:\program files\Real\RealUpgrade\realupgrade.exe [2012-04-30 15:21]
- .
- 2012-06-27 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-220523388-1592454029-725345543-1004.job
- - c:\program files\Real\RealUpgrade\realupgrade.exe [2012-04-30 15:21]
- .
- 2012-06-27 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- - c:\program files\Ask.com\UpdateTask.exe [2010-05-21 09:17]
- .
- 2012-06-27 c:\windows\Tasks\Screamer Radio.job
- - c:\docume~1\nick\6808~1\system\players\SCREAM~1\screamer.exe [2010-11-20 14:58]
- .
- 2012-06-22 c:\windows\Tasks\videopadShakeIcon.job
- - c:\program files\NCH Software\VideoPad\videopad.exe [2012-06-19 10:50]
- .
- .
- ------- Supplementary Scan -------
- .
- uStart Page = hxxp://greek.toggle.com/el/index.php?rvs=google/
- mStart Page = hxxp://greek.toggle.com/el/index.php?rvs=google
- uInternet Connection Wizard,ShellNext = iexplore
- IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
- IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office14\EXCEL.EXE/3000
- IE: Se&nd to OneNote - c:\progra~1\MI1933~1\Office14\ONBttnIE.dll/105
- TCP: DhcpNameServer = 192.168.1.1
- FF - ProfilePath - c:\documents and settings\nick\Application Data\Mozilla\Firefox\Profiles\ock63add.default\
- FF - prefs.js: browser.startup.homepage - www.google.gr
- .
- - - - - ORPHANS REMOVED - - - -
- .
- HKCU-Run-DAEMON Tools Pro Agent - c:\program files\DAEMON Tools Pro\DTAgent.exe
- HKLM-Run-GhostMouse - c:\program files\GhostMouse Free\GhostMouse.exe
- HKLM-Run-avgnt - c:\program files\Avira\AntiVir Desktop\avgnt.exe
- AddRemove-Opera 11.11.2109 - c:\program files\Opera\Opera.exe
- AddRemove-Streamripper - c:\program files\Streamripper\Uninstall.exe
- AddRemove-{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1 - c:\program files\Core Temp\unins000.exe
- .
- .
- .
- **************************************************************************
- .
- catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
- Rootkit scan 2012-06-27 23:31
- Windows 5.1.2600 Service Pack 3 NTFS
- .
- scanning hidden processes ...
- .
- scanning hidden autostart entries ...
- .
- scanning hidden files ...
- .
- scan completed successfully
- hidden files: 0
- .
- **************************************************************************
- .
- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wxpSvc]
- "ImagePath"="c:\program files\wLite\wService.exe /startedbyscm:5053B757-40E35B3B-webcamSRV"
- .
- --------------------- LOCKED REGISTRY KEYS ---------------------
- .
- [HKEY_USERS\S-1-5-21-220523388-1592454029-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\jpg Φ€|Φ[d
- H†s•]
- @Class="Shell"
- "a"="c:\\Documents and Settings\\nick\\Επιφάνεια εργασίας\\Φάκελος\\1111111111111.?g??????D"
- "MRUList"="cba"
- "b"="c:\\Documents and Settings\\nick\\Επιφάνεια εργασίας\\Φάκελος\\22222222222.?g??????D"
- "c"="c:\\Documents and Settings\\nick\\Επιφάνεια εργασίας\\Φάκελος\\ASPROMAYRI1.?g??????D"
- .
- [HKEY_USERS\S-1-5-21-220523388-1592454029-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. jpg Φ€|Φ[d
- H†s•]
- @Class="Shell"
- .
- [HKEY_USERS\S-1-5-21-220523388-1592454029-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. jpg Φ€|Φ[d
- H†s•\OpenWithList]
- @Class="Shell"
- "a"="Corel PaintShop Pro.exe"
- "MRUList"="a"
- .
- [HKEY_USERS\S-1-5-21-220523388-1592454029-725345543-1004\Software\SecuROM\License information*]
- "datasecu"=hex:74,82,93,d0,a7,bf,04,d4,cc,69,8c,d6,08,47,0f,19,5f,fe,14,cc,e8,
- 66,c0,f1,0f,fd,bb,0c,58,69,c3,a0,1b,bd,f4,34,82,b8,de,35,1a,f5,a1,08,3b,71,\
- "rkeysecu"=hex:49,1a,27,73,6a,63,8e,bb,5b,74,f0,10,22,0b,a7,bb
- .
- --------------------- DLLs Loaded Under Running Processes ---------------------
- .
- - - - - - - - > 'explorer.exe'(2000)
- c:\program files\Unlocker\UnlockerHook.dll
- c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
- c:\progra~1\MI1933~1\Office14\1033\GrooveIntlResource.dll
- c:\windows\system32\msi.dll
- c:\windows\system32\webcheck.dll
- c:\windows\system32\WPDShServiceObj.dll
- c:\windows\system32\PortableDeviceTypes.dll
- c:\windows\system32\PortableDeviceApi.dll
- .
- ------------------------ Other Running Processes ------------------------
- .
- c:\windows\ATKKBService.exe
- c:\program files\Java\jre6\bin\jqs.exe
- c:\program files\Google\Update\1.3.21.111\GoogleCrashHandler.exe
- c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
- c:\windows\system32\nvsvc32.exe
- c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
- c:\windows\system32\RunDLL32.exe
- c:\windows\system32\wbem\wmiapsrv.exe
- c:\windows\system32\wscntfy.exe
- .
- **************************************************************************
- .
- Completion time: 2012-06-27 23:32:51 - machine was rebooted
- ComboFix-quarantined-files.txt 2012-06-27 20:32
- .
- Pre-Run: 7 Κατάλογοι 52.699.578.368 διαθέσιμα byte
- Post-Run: 9 Κατάλογοι 53.017.104.384 διαθέσιμα byte
- .
- WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
- [boot loader]
- timeout=2
- default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
- [operating systems]
- c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
- UnsupportedDebug="do not select this" /debug
- multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- .
- - - End Of File - - 8112281666344426AB71DCC16D5E9397
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement