Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 10-08-08.01 - Administrator 10.08.2010 13:33:30.2.1 - x86
- Microsoft Windows XP Professional 5.1.2600.3.1250.385.1033.18.1535.1128 [GMT 2:00]
- Running from: c:\documents and settings\Administrator\My Documents\ComboFix.exe
- Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
- AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
- * Resident AV is active
- WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
- FILE ::
- "C:\bog.exe"
- "C:\bog2.exe"
- "c:\windows\eReg.dat"
- "c:\windows\system32\unins000.dat"
- "c:\windows\system32\unins000.exe"
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- C:\bog.exe
- C:\bog2.exe
- c:\windows\eReg.dat
- c:\windows\system32\unins000.dat
- c:\windows\system32\unins000.exe
- .
- ((((((((((((((((((((((((( Files Created from 2010-07-10 to 2010-08-10 )))))))))))))))))))))))))))))))
- .
- 2010-08-08 20:28 . 2010-08-08 20:28 -------- d-----w- C:\_OTL
- 2010-08-08 01:06 . 2010-08-08 01:06 -------- d-----w- c:\documents and settings\Administrator\Application Data\Need for Speed World
- 2010-08-08 00:58 . 2010-08-08 00:58 10896656 ----a-w- c:\documents and settings\All Users\Application Data\Electronic Arts\Need For Speed World\Data\nfsw.exe
- 2010-08-08 00:58 . 2010-08-08 00:58 267536 ----a-w- c:\documents and settings\All Users\Application Data\Electronic Arts\Need For Speed World\Data\gameplay.dll
- 2010-08-08 00:58 . 2010-08-08 00:58 1790736 ----a-w- c:\documents and settings\All Users\Application Data\Electronic Arts\Need For Speed World\Data\gameplay.native.dll
- 2010-08-08 00:58 . 2010-08-08 00:58 4068624 ----a-w- c:\documents and settings\All Users\Application Data\Electronic Arts\Need For Speed World\Data\eawebkit.dll
- 2010-08-08 00:58 . 2010-08-08 00:58 462864 ----a-w- c:\documents and settings\All Users\Application Data\Electronic Arts\Need For Speed World\Data\d3dx10_37.dll
- 2010-08-08 00:58 . 2010-08-08 00:58 3786760 ----a-w- c:\documents and settings\All Users\Application Data\Electronic Arts\Need For Speed World\Data\d3dx9_37.dll
- 2010-08-08 00:40 . 2010-08-08 00:40 883670 ----a-w- c:\documents and settings\All Users\Application Data\Electronic Arts\Need For Speed World\Data\pb\pbcl.dll
- 2010-08-08 00:40 . 2010-08-08 00:40 57344 ----a-w- c:\documents and settings\All Users\Application Data\Electronic Arts\Need For Speed World\Data\pb\pbag.dll
- 2010-08-08 00:31 . 2010-08-08 00:31 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Electronic_Arts_Inc
- 2010-08-08 00:29 . 2010-08-08 00:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
- 2010-08-07 10:12 . 2010-08-07 10:12 452104 ----a-w- c:\documents and settings\Administrator\Application Data\Real\Update\setup3.12\setup.exe
- 2010-08-05 20:13 . 2010-08-05 20:13 503808 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-32736981-n\msvcp71.dll
- 2010-08-05 20:13 . 2010-08-05 20:13 499712 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-32736981-n\jmc.dll
- 2010-08-05 20:13 . 2010-08-05 20:13 348160 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-32736981-n\msvcr71.dll
- 2010-08-05 20:13 . 2010-08-05 20:13 61440 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-412fde9c-n\decora-sse.dll
- 2010-08-05 20:13 . 2010-08-05 20:13 12800 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-412fde9c-n\decora-d3d.dll
- 2010-08-01 21:15 . 2010-08-01 21:15 -------- d-----w- c:\program files\Common Files\Java
- 2010-07-27 17:09 . 2010-07-27 17:09 -------- d-----w- c:\documents and settings\All Users\Application Data\EasyMP3Downloader
- 2010-07-27 17:09 . 2010-07-27 17:09 -------- d-----w- c:\documents and settings\Administrator\Application Data\EasyMP3Downloader
- 2010-07-24 11:14 . 2010-07-24 11:14 460 ----a-w- c:\documents and settings\Administrator\304217.zip
- 2010-07-24 10:58 . 2010-07-24 10:58 191184 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
- 2010-07-24 10:35 . 2010-07-24 10:35 -------- dc----w- c:\documents and settings\All Users\Application Data\{2840BBCB-9BEC-47F6-BA0F-10D3C34BF151}
- 2010-07-24 10:24 . 2010-07-24 10:38 -------- d-----w- c:\documents and settings\Administrator\Application Data\uniblue
- 2010-07-24 10:08 . 2010-07-24 10:24 -------- d-----w- c:\documents and settings\Administrator\Application Data\IObit
- 2010-07-24 10:04 . 2010-07-24 10:04 117760 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
- 2010-07-24 10:03 . 2010-07-24 10:03 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
- 2010-07-24 10:03 . 2010-07-24 10:03 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
- 2010-07-24 09:21 . 2010-07-24 10:58 -------- d-----w- c:\program files\Common Files\PC Tools
- 2010-07-24 08:43 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
- 2010-07-24 08:43 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
- 2010-07-22 12:52 . 2010-07-22 12:52 -------- d-----w- c:\program files\SystemRequirementsLab
- 2010-07-22 09:28 . 2010-07-22 09:28 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\HandBrake
- 2010-07-22 09:28 . 2010-07-22 09:28 -------- d-----w- c:\documents and settings\Administrator\Application Data\HandBrake
- 2010-07-22 09:09 . 2010-07-22 09:09 -------- d-----w- c:\windows\system32\Samsung_USB_Drivers
- 2010-07-22 09:09 . 2010-07-22 09:09 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield
- 2010-07-21 10:25 . 2010-07-21 10:25 -------- d-----w- c:\documents and settings\Administrator\Application Data\VitySoft
- 2010-07-20 11:05 . 2010-07-20 11:08 -------- d-----w- c:\documents and settings\Administrator\Application Data\DMCache
- 2010-07-20 09:51 . 2010-07-20 09:51 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Ilivid Player
- 2010-07-17 12:37 . 2010-07-17 12:37 -------- d-----w- c:\documents and settings\Administrator\Application Data\Command and Conquer 3 Kanes Wrath
- 2010-07-17 12:21 . 2010-07-17 12:21 -------- d-----w- c:\program files\Folding@Home #01
- 2010-07-17 11:39 . 2010-07-17 11:39 -------- d-----w- c:\windows\system32\wbem\Repository
- 2010-07-16 16:13 . 2010-07-16 16:13 -------- d-----w- c:\windows\DVD Decrypter
- 2010-07-14 21:50 . 2008-03-09 05:25 236 ----a-w- c:\program files\Common Files\dx.reg
- 2010-07-14 21:50 . 2008-03-05 14:03 329224 ----a-w- c:\windows\system32\DXErr.exe
- 2010-07-14 21:50 . 2008-03-05 14:03 209416 ----a-w- c:\windows\system32\dxcpl.exe
- 2010-07-14 21:50 . 2006-11-02 10:46 167936 ----a-w- c:\windows\system32\dxgi.dll
- 2010-07-14 21:50 . 2008-04-12 16:13 1029126 ----a-w- c:\windows\system32\d3d10.dll
- 2010-07-14 21:50 . 2006-11-29 12:06 440080 ----a-w- c:\windows\system32\d3dx10.dll
- 2010-07-14 21:50 . 2006-11-02 10:47 1162656 ----a-w- c:\windows\system32\ntdllnew.dll
- 2010-07-13 19:27 . 2010-07-13 20:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\IconTweaker
- 2010-07-13 18:29 . 2010-07-13 18:29 -------- d-----w- c:\documents and settings\Administrator\Application Data\Styler
- 2010-07-13 13:54 . 2010-07-13 20:05 -------- d-----w- c:\documents and settings\All Users\Application Data\IconTweaker
- 2010-07-13 13:32 . 2010-07-13 13:32 -------- d-----w- c:\documents and settings\Administrator\Application Data\ViGlance
- 2010-07-11 19:32 . 2010-07-17 16:40 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory
- 2010-07-11 19:32 . 2010-07-11 19:32 136 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
- 2010-07-11 19:30 . 2010-07-11 19:30 -------- d-----w- c:\windows\system32\URTTEMP
- 2010-07-11 19:27 . 2010-07-17 16:29 -------- d-----w- c:\windows\San Andreas Mod Installer
- 2010-07-11 17:54 . 2010-07-11 17:54 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
- 2010-07-11 17:54 . 2010-07-11 17:54 -------- d-----w- c:\documents and settings\Administrator\Application Data\DAEMON Tools Pro
- 2010-07-11 14:33 . 2010-07-11 14:33 -------- d-----w- c:\documents and settings\All Users\Application Data\RegCure
- 2010-07-11 14:33 . 2010-07-11 14:34 -------- d-----w- c:\program files\RegCure
- 2010-07-11 12:28 . 2010-07-11 12:28 -------- d-----w- c:\windows\RegCure
- 2010-07-11 12:00 . 2010-07-11 12:00 -------- d-----w- c:\program files\Common Files\xing shared
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2010-08-08 00:31 . 2010-01-16 03:41 69616 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
- 2010-08-07 22:03 . 2010-01-17 11:01 -------- d-----w- c:\documents and settings\Administrator\Application Data\Skype
- 2010-08-04 18:35 . 2010-01-17 01:40 -------- d-----w- c:\documents and settings\Administrator\Application Data\BitTorrent
- 2010-08-04 11:50 . 2010-01-16 04:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
- 2010-08-01 20:44 . 2010-01-16 06:04 -------- d-----w- c:\program files\Java
- 2010-07-29 10:40 . 2010-01-23 15:07 -------- d-----w- c:\documents and settings\Administrator\Application Data\BSplayer Pro
- 2010-07-24 10:30 . 2010-01-17 01:40 -------- d-----w- c:\documents and settings\Administrator\Application Data\DNA
- 2010-07-24 10:02 . 2010-01-17 11:08 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
- 2010-07-24 10:01 . 2010-01-23 16:11 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
- 2010-07-24 08:44 . 2010-01-17 11:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
- 2010-07-22 09:55 . 2005-12-31 23:18 -------- d--h--w- c:\program files\InstallShield Installation Information
- 2010-07-22 09:09 . 2010-01-17 03:27 -------- d-----w- c:\program files\Common Files\InstallShield
- 2010-07-17 03:00 . 2010-04-20 12:25 423656 ----a-w- c:\windows\system32\deployJava1.dll
- 2010-07-15 23:06 . 2010-01-17 01:40 -------- d-----w- c:\program files\DNA
- 2010-07-15 19:07 . 2010-01-17 22:17 138184 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
- 2010-07-15 19:07 . 2010-01-17 22:16 183112 ----a-w- c:\windows\system32\PnkBstrB.exe
- 2010-07-13 19:07 . 2008-04-14 03:42 218624 ----a-w- c:\windows\system32\uxtheme.dll
- 2010-07-13 13:30 . 2008-04-14 03:42 218624 ----a-w- c:\windows\system32\uxtheme(2).dll
- 2010-07-13 12:44 . 2010-02-02 22:36 -------- d-----w- c:\program files\DivX
- 2010-07-13 12:44 . 2010-02-02 22:36 -------- d-----w- c:\program files\Common Files\DivX Shared
- 2010-07-11 17:59 . 2006-01-01 00:18 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
- 2010-07-11 17:59 . 2006-01-01 00:20 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
- 2010-07-11 12:00 . 2010-03-15 19:43 -------- d-----w- c:\program files\Common Files\Real
- 2010-07-11 12:00 . 2010-03-15 19:43 348160 ----a-w- c:\windows\system32\msvcr71.dll
- 2010-07-11 12:00 . 2003-03-18 20:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
- 2010-07-11 11:51 . 2010-03-15 19:43 -------- d-----w- c:\program files\Real
- 2010-07-10 18:51 . 2010-01-16 06:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
- 2010-07-10 18:05 . 2010-07-10 18:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\Auslogics
- 2010-07-10 12:15 . 2010-01-16 04:31 -------- d-----w- c:\documents and settings\Administrator\Application Data\Nero
- 2010-07-10 12:01 . 2010-07-10 12:01 -------- d-----w- c:\program files\Microsoft.NET
- 2010-07-10 11:35 . 2010-07-04 19:07 -------- d-----w- c:\program files\Eset
- 2010-07-10 10:49 . 2010-01-16 04:15 -------- d-----w- c:\program files\Common Files\Nero
- 2010-07-10 10:49 . 2010-01-16 04:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
- 2010-07-10 09:28 . 2010-02-17 10:04 -------- d-----w- c:\program files\Unlocker
- 2010-07-08 11:11 . 2010-01-16 06:08 -------- d-----w- c:\program files\Common Files\Adobe
- 2010-07-07 10:16 . 2010-07-07 08:59 -------- d-----w- c:\documents and settings\All Users\Application Data\regid.1986-12.com.adobe
- 2010-07-07 09:45 . 2010-07-07 09:45 -------- d-----w- c:\program files\Common Files\Adobe AIR
- 2010-07-05 16:04 . 2010-07-04 19:07 512096 ----a-w- c:\windows\system32\drivers\amon.sys
- 2010-07-05 16:04 . 2010-07-04 19:07 298104 ----a-w- c:\windows\system32\imon.dll
- 2010-07-05 16:04 . 2010-07-04 19:07 15424 ----a-w- c:\windows\system32\drivers\nod32drv.sys
- 2010-07-04 18:52 . 2010-07-04 18:52 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
- 2010-07-04 18:51 . 2010-01-16 03:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
- 2010-07-04 18:36 . 2010-01-23 23:27 -------- d-----w- c:\program files\Google
- 2010-06-26 14:03 . 2010-01-24 18:04 286720 ------w- c:\windows\Setup1.exe
- 2010-06-26 14:03 . 2010-01-24 18:04 73216 ----a-w- c:\windows\ST6UNST.EXE
- 2010-06-25 20:41 . 2010-06-25 13:52 -------- d-----w- c:\documents and settings\Administrator\Application Data\Microsoft Games
- 2010-06-25 20:41 . 2010-06-25 13:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Games
- 2010-06-25 16:10 . 2010-06-25 16:10 -------- d-----w- c:\documents and settings\Administrator\Application Data\fltk.org
- 2010-06-14 14:31 . 2010-01-16 03:23 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
- 2010-06-11 15:31 . 2010-06-11 15:31 -------- d-----w- c:\program files\Drag Racer 3
- 2010-06-02 02:55 . 2010-06-25 20:32 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
- 2010-06-02 02:55 . 2010-06-25 20:32 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
- 2010-06-02 02:55 . 2010-06-25 20:32 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
- 2010-05-27 20:40 . 2010-05-27 20:41 36864 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{89A43E80-AC6C-4DA8-9800-F4B30ED577C0}\PostBuild.exe
- 2010-05-27 20:33 . 2010-05-27 20:32 93783440 ----a-w- c:\documents and settings\All Users\Application Data\OLYMPUS\ib\CameraBackup\000JB3208233\SETUP.EXE
- 2010-05-27 20:13 . 2010-05-27 20:13 503808 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-7f087506-n\msvcp71.dll
- 2010-05-27 20:13 . 2010-05-27 20:13 499712 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-7f087506-n\jmc.dll
- 2010-05-27 20:13 . 2010-05-27 20:13 348160 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-7f087506-n\msvcr71.dll
- 2010-05-27 20:13 . 2010-05-27 20:13 61440 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-1d7cbea8-n\decora-sse.dll
- 2010-05-27 20:13 . 2010-05-27 20:13 12800 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-1d7cbea8-n\decora-d3d.dll
- 2010-05-26 09:41 . 2010-06-25 20:32 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
- 2010-05-26 09:41 . 2010-06-25 20:32 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
- 2010-05-26 09:41 . 2010-06-25 20:32 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
- 2010-05-26 09:41 . 2010-06-25 20:32 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
- 2010-05-26 09:41 . 2010-06-25 20:32 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
- .
- ((((((((((((((((((((((((((((( SnapShot@2010-08-08_21.01.25 )))))))))))))))))))))))))))))))))))))))))
- .
- + 2010-08-10 11:38 . 2010-08-10 11:38 16384 c:\windows\temp\Perflib_Perfdata_6d4.dat
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "Olympus ib"="c:\program files\Olympus\ib\olycamdetect.exe" [2010-02-04 93376]
- "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
- "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-24 7696384]
- "nwiz"="nwiz.exe" [2006-08-24 1617920]
- "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
- "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
- "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
- "SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
- "MDS_Menu"="c:\program files\Olympus\ib\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
- "nod32kui"="c:\program files\Eset\nod32kui.exe" [2010-07-05 949376]
- "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
- "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-07-11 185896]
- c:\documents and settings\All Users\Start Menu\Programs\Startup\
- 11bg Wireless LAN USB Utility.lnk - c:\program files\OEM\11bg Wireless LAN USB Utility\RtWLan.exe [2010-2-25 835584]
- [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
- 2009-09-03 12:21 548352 ----a-w- d:\program files\SUPERAntiSpyware\SASWINLO.dll
- [HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Real Desktop.lnk]
- backup=c:\windows\pss\Real Desktop.lnkStartup
- [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^11bg Wireless LAN USB Utility.lnk]
- path=c:\documents and settings\All Users\Start Menu\Programs\Startup\11bg Wireless LAN USB Utility.lnk
- backup=c:\windows\pss\11bg Wireless LAN USB Utility.lnkCommon Startup
- [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BitTorrent Ultra Accelerator.lnk]
- backup=c:\windows\pss\BitTorrent Ultra Accelerator.lnkCommon Startup
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 3]
- 2009-06-30 07:55 2329224 ----a-w- d:\program files\IObit\Advanced SystemCare 3\AWC.exe
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
- 2010-07-13 19:17 323392 ----a-w- c:\program files\DNA\btdna.exe
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
- 2006-10-31 00:03 284184 ----a-w- c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
- 2006-11-15 20:58 746520 ----a-w- c:\program files\Logitech\QuickCam10\QuickCam10.exe
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
- 2006-11-15 21:01 244512 ----a-w- c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
- 2009-07-26 15:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
- 2006-08-24 06:46 86016 ----a-w- c:\windows\system32\nvmctray.dll
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
- 2009-10-09 14:01 25626408 ----a-r- c:\program files\Skype\Phone\Skype.exe
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
- 2009-11-23 13:21 2001648 ----a-w- d:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
- 2010-07-11 12:00 185896 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpyEraser]
- 2007-08-16 07:03 1269000 ----a-w- d:\program files\Unibluee\SpyEraser\SpyEraser.exe
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
- 2010-07-04 19:51 17408 ----a-w- c:\program files\Unlocker\UnlockerAssistant.exe
- [HKEY_LOCAL_MACHINE\software\microsoft\security center]
- "AntiVirusOverride"=dword:00000001
- "FirewallOverride"=dword:00000001
- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
- "EnableFirewall"= 0 (0x0)
- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
- "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
- "%windir%\\system32\\sessmgr.exe"=
- "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
- "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
- "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
- "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
- "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
- "c:\\Program Files\\DNA\\btdna.exe"=
- "d:\\Program Files\\BitTorrent\\bittorrent.exe"=
- "d:\\Nova mapa\\Moja mapa\\Igre\\Tom Clancy H.A.W.X\\HAWX.exe"=
- "d:\\Nova mapa\\Moja mapa\\Igre\\Tom Clancy H.A.W.X\\HAWX_dx10.exe"=
- "d:\\Nova mapa\\Moja mapa\\Igre\\PES 2009\\pes2009.exe"=
- "d:\\Nova mapa\\Moja mapa\\Igre\\PES 2009\\hnl2009.exe"=
- "updater.exe"= c:\windows\updater.exe
- "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
- R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [16.1.2010 5:30 13696]
- R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [4.7.2010 21:07 15424]
- R1 SASDIFSV;SASDIFSV;d:\program files\SUPERAntiSpyware\sasdifsv.sys [23.11.2009 8:43 9968]
- R1 SASKUTIL;SASKUTIL;d:\program files\SUPERAntiSpyware\SASKUTIL.SYS [23.11.2009 8:43 74480]
- R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [1.1.2006 1:18 38144]
- R2 FAH-01;Folding Service #01;c:\program files\Folding@Home #01\Folding@Home #01\FAH-Console.exe [30.6.2008 20:38 253952]
- R2 FAH-02;Folding Service #02;c:\program files\Folding@Home #01\Folding@Home #02\FAH-Console.exe [30.6.2008 20:38 253952]
- R3 RTL8187B;Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [1.1.2006 1:18 275968]
- S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [24.1.2010 1:27 135664]
- S3 OlyCamComm;OLYMPUS USB Communication Device;c:\windows\system32\drivers\OlyCamComm.sys [27.5.2010 22:32 21648]
- S3 SASENUM;SASENUM;d:\program files\SUPERAntiSpyware\SASENUM.SYS [23.11.2009 8:43 7408]
- S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1.1.2006 2:18 691696]
- .
- Contents of the 'Scheduled Tasks' folder
- 2010-08-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-23 23:27]
- 2010-08-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-23 23:27]
- 2010-08-10 c:\windows\Tasks\RegCure Program Check.job
- - d:\program files\RegCure\RegCure.exe [2007-10-16 08:20]
- 2010-07-11 c:\windows\Tasks\RegCure.job
- - d:\program files\RegCure\RegCure.exe [2007-10-16 08:20]
- 2010-07-24 c:\windows\Tasks\Uniblue SpyEraser.job
- - d:\program files\Unibluee\SpyEraser\SpyEraser.exe [2010-07-24 07:03]
- 2010-08-10 c:\windows\Tasks\User_Feed_Synchronization-{45AACD1B-D57A-44EF-B942-D264B60DF36D}.job
- - c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
- .
- .
- ------- Supplementary Scan -------
- .
- IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
- LSP: c:\windows\system32\imon.dll
- FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\s18irdy2.default\
- FF - prefs.js: browser.startup.homepage - www.google.hr
- FF - plugin: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
- FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
- FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
- FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
- FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
- FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
- FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
- ---- FIREFOX POLICIES ----
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
- .
- - - - - ORPHANS REMOVED - - - -
- AddRemove-DirectX10 for Windows XP - Win2000, 2003,..._is1 - c:\windows\system32\unins000.exe
- **************************************************************************
- catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
- Rootkit scan 2010-08-10 13:39
- Windows 5.1.2600 Service Pack 3 NTFS
- scanning hidden processes ...
- scanning hidden autostart entries ...
- scanning hidden files ...
- scan completed successfully
- hidden files: 0
- **************************************************************************
- .
- --------------------- LOCKED REGISTRY KEYS ---------------------
- [HKEY_USERS\S-1-5-21-2052111302-1383384898-1177238915-500\Software\Microsoft\Internet Explorer\User Preferences]
- @Denied: (2) (Administrator)
- "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
- d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,7e,ac,90,07,85,64,ed,45,9a,be,db,\
- "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
- d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,7e,ac,90,07,85,64,ed,45,9a,be,db,\
- .
- --------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - - > 'winlogon.exe'(696)
- d:\program files\SUPERAntiSpyware\SASWINLO.dll
- c:\windows\system32\WININET.dll
- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
- - - - - - - - > 'explorer.exe'(8080)
- c:\windows\system32\WININET.dll
- c:\program files\Common Files\Logitech\LVMVFM\LVPrcInj.dll
- c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
- c:\windows\system32\ieframe.dll
- c:\windows\system32\msi.dll
- c:\windows\system32\webcheck.dll
- c:\windows\system32\WPDShServiceObj.dll
- c:\windows\system32\PortableDeviceTypes.dll
- c:\windows\system32\PortableDeviceApi.dll
- c:\program files\Internet Explorer\mui\041a\browselc.dll
- c:\program files\Microsoft Office\Office12\1050\GrooveIntlResource.dll
- c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
- c:\windows\system32\nvcpl.dll
- c:\windows\system32\nvapi.dll
- c:\windows\system32\nvshell.dll
- .
- ------------------------ Other Running Processes ------------------------
- .
- c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
- c:\program files\Java\jre6\bin\jqs.exe
- c:\program files\Eset\nod32krn.exe
- c:\windows\system32\nvsvc32.exe
- c:\windows\SOUNDMAN.EXE
- .
- **************************************************************************
- .
- Completion time: 2010-08-10 13:42:56 - machine was rebooted
- ComboFix-quarantined-files.txt 2010-08-10 11:42
- ComboFix2.txt 2010-08-08 21:05
- Pre-Run: 1.161.420.800 bytes free
- Post-Run: 1.149.427.712 bytes free
- - - End Of File - - CAB8635B820D3674284566D1EE58BC64
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement