Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 11-07-02.03 - Dixon 07/03/2011 13:17:22.1.8 - x64
- Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.6135.4350 [GMT -7:00]
- Running from: c:\users\Dixon\Desktop\ComboFix.exe
- AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
- SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
- SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- C:\Install.exe
- c:\users\Dixon\videos\F.E.A.R. 3.exe
- d:\program files (x86)\Steam\Steam.exe
- .
- .
- ((((((((((((((((((((((((( Files Created from 2011-06-03 to 2011-07-03 )))))))))))))))))))))))))))))))
- .
- .
- 2011-07-03 20:13 . 2011-07-03 20:15 -------- d-----w- C:\32788R22FWJFW
- 2011-07-03 20:09 . 2011-07-03 20:09 -------- d-----w- C:\_OTL
- 2011-07-02 21:47 . 2011-06-07 17:10 8873296 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
- 2011-07-02 21:47 . 2011-06-07 17:10 8873296 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F9815B8C-B586-458A-8D82-6FF0D97390B3}\mpengine.dll
- 2011-07-01 19:01 . 2011-07-01 19:01 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{92830C51-F022-41C5-85DC-8327E2F106A8}\gapaengine.dll
- 2011-07-01 19:00 . 2011-05-29 16:11 39984 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
- 2011-07-01 19:00 . 2011-07-01 19:00 -------- d-----w- c:\program files (x86)\Microsoft Security Client
- 2011-07-01 19:00 . 2011-07-01 19:00 -------- d-----w- c:\program files\Microsoft Security Client
- 2011-07-01 17:31 . 2011-06-07 17:10 8873296 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CE089114-261A-4E5C-A3A5-D66BF21CB067}\mpengine.dll
- 2011-06-26 22:23 . 2011-06-26 22:23 -------- d-----w- c:\program files (x86)\Cheat Engine 6.1
- 2011-06-25 22:52 . 2011-06-25 23:54 -------- d-----w- c:\program files (x86)\Duke Nukem Forever
- 2011-06-23 21:52 . 2011-06-23 21:52 -------- d-----w- c:\users\Dixon\AppData\Roaming\Day 1 Studios
- 2011-06-23 21:41 . 2011-06-23 21:41 -------- d-----w- c:\program files (x86)\WB Games
- 2011-06-19 07:03 . 2011-06-19 07:03 -------- d-----w- c:\programdata\Trend Micro
- 2011-06-19 06:45 . 2011-06-19 06:45 -------- d-----w- c:\program files (x86)\Trend Micro
- 2011-06-19 04:42 . 2011-07-01 19:00 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
- 2011-06-19 02:14 . 2011-06-23 06:24 -------- d-----w- c:\users\Dixon\AppData\Roaming\ApexDC++
- 2011-06-19 02:14 . 2011-06-23 06:24 -------- d-----w- c:\users\Dixon\AppData\Local\ApexDC++
- 2011-06-18 22:28 . 2011-06-22 06:33 -------- d-----w- c:\program files (x86)\Hotspot Shield
- 2011-06-18 20:19 . 2011-06-19 09:00 -------- d-----w- c:\program files (x86)\proXPN
- 2011-06-18 06:39 . 2011-06-18 06:39 -------- d-----w- c:\program files (x86)\Conduit
- 2011-06-18 06:39 . 2011-06-18 06:39 -------- d-----w- c:\program files (x86)\uTorrentBar
- 2011-06-18 06:39 . 2011-06-18 06:39 -------- d-----w- C:\extensions
- 2011-06-17 21:08 . 2011-06-17 21:08 -------- d-----w- c:\program files\iTunes
- 2011-06-17 21:08 . 2011-06-17 21:08 -------- d-----w- c:\program files (x86)\iTunes
- 2011-06-17 21:08 . 2011-06-17 21:08 -------- d-----w- c:\program files\iPod
- 2011-06-17 21:07 . 2011-06-17 21:07 -------- d-----w- c:\program files\Bonjour
- 2011-06-17 21:07 . 2011-06-17 21:07 -------- d-----w- c:\program files (x86)\Bonjour
- 2011-06-17 20:32 . 2011-06-17 20:32 -------- d-----w- c:\program files (x86)\Common Files\Adobe
- 2011-06-17 07:52 . 2011-06-17 07:52 -------- d-----w- c:\users\Dixon\AppData\Roaming\Malwarebytes
- 2011-06-17 07:51 . 2011-06-17 07:51 -------- d-----w- c:\programdata\Malwarebytes
- 2011-06-17 07:51 . 2011-05-29 16:11 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
- 2011-06-17 03:07 . 2011-06-17 03:07 -------- d-----w- c:\program files (x86)\WinPcap
- 2011-06-16 23:50 . 2011-06-16 23:50 -------- d-----w- c:\program files (x86)\WinSCP
- 2011-06-14 04:24 . 2011-06-14 04:24 -------- d-----w- c:\users\Dixon\AppData\Local\{775A4998-DDB3-4B98-B339-10DB03DB3DD9}
- 2011-06-14 04:23 . 2011-06-14 04:23 469256 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\c05eacf21cc2a4a03\InstallManager_WLE_WLE.exe
- 2011-06-14 02:42 . 2011-07-01 20:48 -------- d-sh--w- c:\windows\SysWow64\YIKYOR
- 2011-06-14 01:54 . 2011-07-01 20:48 -------- d-----w- c:\windows\SysWow64\FDGETO
- 2011-06-13 14:31 . 2011-07-01 20:48 -------- d-sh--w- c:\windows\SysWow64\KFVGMK
- 2011-06-13 14:28 . 2011-07-01 20:48 -------- d-sh--w- c:\windows\SysWow64\TJMFUT
- 2011-06-13 07:38 . 2011-07-01 20:48 -------- d-sh--w- c:\windows\SysWow64\PANMAU
- 2011-06-13 07:27 . 2011-07-01 20:48 -------- d-sh--w- c:\windows\SysWow64\NFWOAW
- 2011-06-13 06:48 . 2011-07-01 20:48 -------- d-sh--w- c:\windows\SysWow64\EIQAJB
- 2011-06-08 03:23 . 2011-06-14 23:54 -------- d-----w- c:\programdata\Skype Extras
- 2011-06-08 03:23 . 2011-06-08 03:23 -------- d-----w- c:\program files (x86)\Common Files\Skype
- 2011-06-06 19:55 . 2011-06-06 19:55 183696 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
- 2011-06-05 00:30 . 2011-06-05 00:30 -------- d-----w- c:\users\Dixon\AppData\Local\{C2D6102E-EF45-4DC3-8922-2B5BEDCE7EC3}
- .
- .
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2011-06-25 22:52 . 2011-05-17 22:46 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
- 2011-06-17 08:18 . 2011-03-10 00:56 188128 ----a-w- c:\programdata\Microsoft\VCSExpress\10.0\1033\ResourceCache.dll
- 2011-06-17 08:17 . 2011-01-25 01:06 112832 ----a-w- c:\programdata\Microsoft\VCExpress\10.0\1033\ResourceCache.dll
- 2011-06-17 03:23 . 2009-07-13 23:57 23212544 ----a-w- c:\windows\system32\imageres.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
- 2011-06-02 23:28 . 2011-06-02 23:28 161792 ----a-w- c:\windows\SysWow64\msls31.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
- 2011-06-02 23:28 . 2011-06-02 23:28 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
- 2011-06-02 23:28 . 2011-06-02 23:28 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 367104 ----a-w- c:\windows\SysWow64\html.iec
- 2011-06-02 23:28 . 2011-06-02 23:28 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 152064 ----a-w- c:\windows\SysWow64\wextract.exe
- 2011-06-02 23:28 . 2011-06-02 23:28 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
- 2011-06-02 23:28 . 2011-06-02 23:28 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
- 2011-06-02 23:28 . 2011-06-02 23:28 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
- 2011-06-02 23:28 . 2011-06-02 23:28 11776 ----a-w- c:\windows\SysWow64\mshta.exe
- 2011-06-02 23:28 . 2011-06-02 23:28 101888 ----a-w- c:\windows\SysWow64\admparse.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
- 2011-06-02 23:28 . 2011-06-02 23:28 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
- 2011-06-02 23:28 . 2011-06-02 23:28 76800 ----a-w- c:\windows\system32\tdc.ocx
- 2011-06-02 23:28 . 2011-06-02 23:28 49664 ----a-w- c:\windows\system32\imgutil.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 48640 ----a-w- c:\windows\system32\mshtmler.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 222208 ----a-w- c:\windows\system32\msls31.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 173056 ----a-w- c:\windows\system32\ieUnatt.exe
- 2011-06-02 23:28 . 2011-06-02 23:28 1389056 ----a-w- c:\windows\system32\wininet.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 12288 ----a-w- c:\windows\system32\mshta.exe
- 2011-06-02 23:28 . 2011-06-02 23:28 114176 ----a-w- c:\windows\system32\admparse.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 111616 ----a-w- c:\windows\system32\iesysprep.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 448512 ----a-w- c:\windows\system32\html.iec
- 2011-06-02 23:28 . 2011-06-02 23:28 85504 ----a-w- c:\windows\system32\iesetup.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 603648 ----a-w- c:\windows\system32\vbscript.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 30720 ----a-w- c:\windows\system32\licmgr10.dll
- 2011-06-02 23:28 . 2011-06-02 23:28 165888 ----a-w- c:\windows\system32\iexpress.exe
- 2011-06-02 23:28 . 2011-06-02 23:28 160256 ----a-w- c:\windows\system32\wextract.exe
- 2011-06-02 23:28 . 2011-06-02 23:28 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
- 2011-05-25 02:14 . 2011-01-22 04:10 270720 ------w- c:\windows\system32\MpSigStub.exe
- 2011-05-24 23:40 . 2011-05-24 23:40 56832 ----a-w- c:\windows\system32\drivers\HssDrv.sys
- 2011-05-10 15:06 . 2011-05-10 15:06 51712 ----a-w- c:\windows\system32\drivers\usbaapl64.sys
- 2011-05-10 15:06 . 2011-05-10 15:06 4517664 ----a-w- c:\windows\system32\usbaaplrc.dll
- 2011-04-27 22:25 . 2011-04-27 22:25 84864 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
- 2011-04-22 22:15 . 2011-05-25 00:35 27520 ----a-w- c:\windows\system32\drivers\Diskdump.sys
- 2011-04-18 20:18 . 2011-04-18 20:18 40832 ----a-w- c:\windows\system32\drivers\MpNWMon.sys
- 2011-04-18 20:18 . 2011-04-18 20:18 189440 ----a-w- c:\windows\system32\drivers\MpFilter.sys
- 2011-04-10 01:55 . 2011-04-10 01:55 15453336 ----a-w- c:\windows\SysWow64\xlive.dll
- 2011-04-10 01:55 . 2011-04-10 01:55 13642904 ----a-w- c:\windows\SysWow64\xlivefnt.dll
- 2011-04-09 07:02 . 2011-05-11 04:39 5562240 ----a-w- c:\windows\system32\ntoskrnl.exe
- 2011-04-09 06:58 . 2011-05-12 01:15 142336 ----a-w- c:\windows\system32\poqexec.exe
- 2011-04-09 06:02 . 2011-05-11 04:39 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
- 2011-04-09 06:02 . 2011-05-11 04:39 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
- 2011-04-09 05:56 . 2011-05-12 01:15 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
- 2011-04-06 23:26 . 2011-04-06 23:26 96544 ----a-w- c:\windows\system32\dnssd.dll
- 2011-04-06 23:26 . 2011-04-06 23:26 69408 ----a-w- c:\windows\system32\jdns_sd.dll
- 2011-04-06 23:26 . 2011-04-06 23:26 237856 ----a-w- c:\windows\system32\dnssdX.dll
- 2011-04-06 23:26 . 2011-04-06 23:26 119584 ----a-w- c:\windows\system32\dns-sd.exe
- 2011-04-06 23:20 . 2011-04-06 23:20 91424 ----a-w- c:\windows\SysWow64\dnssd.dll
- 2011-04-06 23:20 . 2011-04-06 23:20 75040 ----a-w- c:\windows\SysWow64\jdns_sd.dll
- 2011-04-06 23:20 . 2011-04-06 23:20 197920 ----a-w- c:\windows\SysWow64\dnssdX.dll
- 2011-04-06 23:20 . 2011-04-06 23:20 107808 ----a-w- c:\windows\SysWow64\dns-sd.exe
- .
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- .
- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
- "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
- .
- [HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
- .
- [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
- 2010-12-09 20:51 3911776 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
- .
- [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
- 2010-12-09 20:51 3911776 ----a-w- c:\program files (x86)\uTorrentBar\tbuTor.dll
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
- "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
- "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776]
- .
- [HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
- .
- [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
- .
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760]
- "SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2010-10-17 590056]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
- "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-11-26 336384]
- "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-01-22 91520]
- "Razer Mamba Driver"="c:\program files (x86)\Razer\Mamba\RazerTray.exe" [2009-12-15 3278728]
- "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288]
- "THX Audio Control Panel"="c:\program files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" [2009-09-04 959488]
- "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
- "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-09 54840]
- "hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-23 150528]
- "PWRISOVM.EXE"="c:\program files (x86)\PowerISO\PWRISOVM.EXE" [2010-04-12 180224]
- "JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-01-19 43632]
- "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-30 421888]
- "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
- "Lycosa"="c:\program files (x86)\Razer\Lycosa\razerhid.exe" [2011-03-01 233984]
- "Logitech G930"="c:\program files (x86)\Logitech\G930\G930.exe" [2011-03-23 1516888]
- "Razer Blackwidow Driver"="c:\program files (x86)\Razer\BlackWidow Ultimate\BlackWidowUltimateTray.exe" [2011-03-08 883616]
- "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
- "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-06-08 421160]
- "Trend Micro RUBotted V2.0 Beta"="c:\program files (x86)\Trend Micro\RUBotted\RUBottedGUI.exe" [2010-12-17 1103184]
- .
- c:\users\Dixon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
- Windows Live Messenger.lnk - c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe [2010-11-10 4240760]
- .
- c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
- HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
- "ConsentPromptBehaviorAdmin"= 5 (0x5)
- "ConsentPromptBehaviorUser"= 3 (0x3)
- "EnableUIADesktopToggle"= 0 (0x0)
- .
- [hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
- "{F791A188-699D-4FD4-955A-EB59E89B1907}"= "c:\program files (x86)\The Skins Factory\Hyperdesk\Common\AveStartButtonChangerInProc.dll" [2010-01-28 104448]
- .
- [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
- Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
- @="Service"
- .
- R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
- R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
- R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-01-22 79360]
- R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-01-22 79360]
- R3 CV2K1;CommView Network Monitor;c:\windows\system32\DRIVERS\cv2k1.sys [x]
- R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
- R3 LADF_BakerCOnly;BakerC Filter Driver;c:\windows\system32\DRIVERS\ladfBakerCamd64.sys [x]
- R3 LADF_BakerROnly;BakerR Filter Driver;c:\windows\system32\DRIVERS\ladfBakerRamd64.sys [x]
- R3 LADF_DHP2;G35 DHP2 Filter Driver;c:\windows\system32\DRIVERS\ladfDHP2amd64.sys [x]
- R3 LADF_SBVM;G35 SBVM Filter Driver;c:\windows\system32\DRIVERS\ladfSBVMamd64.sys [x]
- R3 Lycosa;Lycosa Keyboard;c:\windows\system32\drivers\Lycosa.sys [x]
- R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-01-22 30963576]
- R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
- R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
- R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
- R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
- R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
- R3 TsVlb;TsVlb;c:\windows\system32\DRIVERS\tsvlb.sys [x]
- R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
- R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
- R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]
- R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [x]
- R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
- R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
- S0 mv91xx;mv91xx;c:\windows\system32\DRIVERS\mv91xx.sys [x]
- S1 TsVp;TsVp;c:\windows\system32\DRIVERS\tsvp.sys [x]
- S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
- S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
- S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x]
- S2 hshld;Hotspot Shield Service;c:\program files (x86)\Hotspot Shield\bin\openvpnas.exe [2011-06-02 298824]
- S2 HssWd;Hotspot Shield Monitoring Service;c:\program files (x86)\Hotspot Shield\bin\hsswd.exe [2011-05-25 329544]
- S2 HyperDeskCustomThemeEnabler;HyperDesk's Custom Theme Enabler;c:\windows\Installer\MSI8642.tmp [2011-04-17 102400]
- S2 RUBotSrv;Trend Micro RUBotted Service;c:\program files (x86)\Trend Micro\RUBotted\RUBotSrv.exe [2010-12-17 439632]
- S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-04-15 2280312]
- S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
- S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
- S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
- S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys [x]
- S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
- S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
- S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-28 288272]
- S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x]
- S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
- S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
- S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
- S3 RzSynapse;Razer Driver;c:\windows\system32\DRIVERS\RzSynapse.sys [x]
- S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [x]
- S3 TSCOMM;CommStudio Virtual Adapter by TamoSoft;c:\windows\system32\DRIVERS\tscomm.sys [x]
- S3 VKbms;Virtual HID Minidriver;c:\windows\system32\DRIVERS\VKbms.sys [x]
- .
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
- hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
- .
- Contents of the 'Scheduled Tasks' folder
- .
- 2011-07-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-745986013-3072718195-1801061463-1000Core.job
- - c:\users\Dixon\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-22 04:12]
- .
- 2011-07-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-745986013-3072718195-1801061463-1000UA.job
- - c:\users\Dixon\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-22 04:12]
- .
- .
- --------- x86-64 -----------
- .
- .
- [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
- 2011-05-24 23:41 287048 ----a-w- c:\program files (x86)\Hotspot Shield\HssIE\HssIE_64.dll
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-06-08 10867816]
- "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
- .
- [hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
- "{F791A188-699D-4FD4-955A-EB59E89B1907}"= "c:\program files (x86)\The Skins Factory\Hyperdesk\Common\AveStartButtonChangerInProc.dll" [2010-01-28 104448]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
- "LoadAppInit_DLLs"=0x0
- .
- ------- Supplementary Scan -------
- .
- uLocal Page = c:\windows\system32\blank.htm
- uStart Page = hxxp://search.hotspotshield.com/g/?c=h
- mLocal Page = c:\windows\SysWOW64\blank.htm
- uInternet Settings,ProxyOverride = *.local
- IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
- IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
- TCP: DhcpNameServer = 192.168.1.1
- CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\shell32.dll
- .
- - - - - ORPHANS REMOVED - - - -
- .
- Wow6432Node-HKCU-Run-Steam - d:\program files (x86)\Steam\steam.exe
- AddRemove-Bulletstorm_is1 - d:\games\TPTB\Bulletstorm\unins000.exe
- AddRemove-Steam App 10180 - d:\program files (x86)\Steam\steam.exe
- AddRemove-Steam App 10190 - d:\program files (x86)\Steam\steam.exe
- AddRemove-Steam App 1250 - d:\program files (x86)\Steam\steam.exe
- AddRemove-Steam App 17520 - d:\program files (x86)\Steam\steam.exe
- AddRemove-Steam App 220 - d:\program files (x86)\Steam\steam.exe
- AddRemove-Steam App 22350 - d:\program files (x86)\Steam\steam.exe
- AddRemove-Steam App 240 - d:\program files (x86)\Steam\steam.exe
- AddRemove-Steam App 33220 - d:\program files (x86)\Steam\steam.exe
- AddRemove-Steam App 380 - d:\program files (x86)\Steam\steam.exe
- AddRemove-Steam App 4000 - d:\program files (x86)\Steam\steam.exe
- AddRemove-Steam App 420 - d:\program files (x86)\Steam\steam.exe
- AddRemove-Steam App 42700 - d:\program files (x86)\Steam\steam.exe
- AddRemove-Steam App 42710 - d:\program files (x86)\Steam\steam.exe
- AddRemove-Steam App 550 - d:\program files (x86)\Steam\steam.exe
- AddRemove-Steam App 8850 - d:\program files (x86)\Steam\steam.exe
- AddRemove-Steam App 99850 - d:\program files (x86)\Steam\steam.exe
- AddRemove-Steam App 99900 - d:\program files (x86)\Steam\steam.exe
- .
- .
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HyperDeskCustomThemeEnabler]
- "ImagePath"="\"c:\windows\Installer\MSI8642.tmp\" -service"
- .
- --------------------- LOCKED REGISTRY KEYS ---------------------
- .
- [HKEY_USERS\S-1-5-21-745986013-3072718195-1801061463-1000\Software\SecuROM\License information*]
- "datasecu"=hex:8c,81,68,5b,9b,0c,5e,3e,f8,c1,75,78,a2,40,89,36,bb,fb,6c,62,e5,
- c7,2b,cf,34,47,4b,20,93,13,bf,5b,0e,57,6a,db,2a,6c,90,19,e4,0f,70,d5,11,7b,\
- "rkeysecu"=hex:42,c8,05,12,11,53,bc,26,69,c9,24,d3,f3,bd,d0,70
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
- @Denied: (A 2) (Everyone)
- @="FlashBroker"
- "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10r_ActiveX.exe,-101"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
- "Enabled"=dword:00000001
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10r_ActiveX.exe"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
- @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
- @Denied: (A 2) (Everyone)
- @="Shockwave Flash Object"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10r.ocx"
- "ThreadingModel"="Apartment"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
- @="0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
- @="ShockwaveFlash.ShockwaveFlash.10"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10r.ocx, 1"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
- @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
- @="1.0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
- @="ShockwaveFlash.ShockwaveFlash"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
- @Denied: (A 2) (Everyone)
- @="Macromedia Flash Factory Object"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10r.ocx"
- "ThreadingModel"="Apartment"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
- @="FlashFactory.FlashFactory.1"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10r.ocx, 1"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
- @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
- @="1.0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
- @="FlashFactory.FlashFactory"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
- @Denied: (A 2) (Everyone)
- @="IFlashBroker4"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
- @="{00020424-0000-0000-C000-000000000046}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
- @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
- "Version"="1.0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
- @Denied: (A) (Everyone)
- "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
- @Denied: (A) (Everyone)
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
- "Key"="ActionsPane3"
- "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
- @Denied: (Full) (Everyone)
- .
- ------------------------ Other Running Processes ------------------------
- .
- c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
- c:\program files (x86)\Bonjour\mDNSResponder.exe
- c:\program files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
- .
- **************************************************************************
- .
- Completion time: 2011-07-03 13:27:30 - machine was rebooted
- ComboFix-quarantined-files.txt 2011-07-03 20:27
- .
- Pre-Run: 463,381,774,336 bytes free
- Post-Run: 463,479,713,792 bytes free
- .
- - - End Of File - - 6A8AD399AD39BCBE78EDA64882CC5BCC
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement