ComboFix 10-09-11.02 - Nessaboo 09/11/2010 12:45:44.5.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.2046.1431 [GMT -7:00]
Running from: c:\users\Nessaboo\Desktop\ComboFix.exe
Command switches used :: c:\users\Nessaboo\Desktop\CFScript.txt
.
((((((((((((((((((((((((( Files Created from 2010-08-11 to 2010-09-11 )))))))))))))))))))))))))))))))
.
2010-09-11 19:53 . 2010-09-11 19:53 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-09-11 19:53 . 2010-09-11 19:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-10 21:56 . 2010-09-10 21:56 -------- d-----w- c:\users\Nessaboo\AppData\Local\Apple
2010-09-10 21:55 . 2010-09-10 21:55 -------- d-----w- c:\users\Nessaboo\AppData\Local\Apple Computer
2010-09-09 06:16 . 2010-09-09 06:16 -------- d-----w- c:\program files\Common Files\Java
2010-09-09 06:15 . 2010-09-09 06:15 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-09 06:15 . 2010-09-09 06:15 -------- d-----w- c:\program files\Java
2010-09-04 20:07 . 2010-09-04 20:07 -------- d-----w- c:\users\Nessaboo\AppData\Local\WinZip
2010-09-04 20:07 . 2010-09-04 20:07 -------- d-----w- c:\programdata\WinZip
2010-09-04 19:46 . 2010-09-04 19:46 -------- d-----w- c:\program files\ERUNT
2010-09-02 04:45 . 2010-09-02 04:45 -------- d-----w- c:\program files\Trend Micro
2010-09-02 04:30 . 2010-09-02 04:30 -------- d-----w- c:\users\Nessaboo\AppData\Roaming\Malwarebytes
2010-09-02 04:30 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-02 04:30 . 2010-09-02 04:30 -------- d-----w- c:\programdata\Malwarebytes
2010-09-02 04:30 . 2010-09-02 04:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-02 04:30 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-30 06:39 . 2010-09-07 14:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-08-30 06:39 . 2010-09-07 14:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-08-30 06:39 . 2010-09-07 14:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-08-30 06:39 . 2010-09-07 14:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-08-30 06:39 . 2010-09-07 14:47 50768 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-08-30 06:39 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr
2010-08-30 06:39 . 2010-09-07 15:11 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-08-30 06:39 . 2010-08-30 06:39 -------- d-----w- c:\programdata\Alwil Software
2010-08-30 06:39 . 2010-08-30 06:39 -------- d-----w- c:\program files\Alwil Software
2010-08-30 05:13 . 2010-08-30 06:28 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-08-30 05:13 . 2010-08-30 05:13 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-08-30 03:54 . 2010-08-30 03:54 -------- d-----w- c:\windows\Sun
2010-08-30 03:50 . 2010-08-30 03:50 79360 --sha-r- c:\windows\system32\msimsgn.dll
2010-08-25 14:40 . 2010-04-07 07:10 571904 ----a-w- c:\windows\system32\oleaut32.dll
2010-08-22 17:35 . 2010-08-22 17:36 -------- d-----w- c:\users\Nessaboo\AppData\Local\Google
2010-08-22 16:41 . 2010-08-22 16:41 -------- d-----w- c:\users\Nessaboo\AppData\Local\IsolatedStorage
2010-08-22 16:41 . 2010-08-22 16:41 -------- d-----w- c:\program files\Microsoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-11 19:56 . 2010-05-17 03:45 -------- d-----w- c:\program files\Steam
2010-09-02 16:31 . 2010-05-17 03:45 -------- d-----w- c:\program files\Common Files\Steam
2010-08-12 10:03 . 2010-08-05 03:14 -------- d-----w- c:\programdata\Microsoft Help
2010-08-09 03:07 . 2010-07-26 01:16 -------- d-----w- c:\users\Nessaboo\AppData\Roaming\ImgBurn
2010-08-08 03:54 . 2010-08-08 03:54 -------- d-----w- c:\users\Nessaboo\AppData\Roaming\Red Kawa
2010-08-07 01:13 . 2010-08-07 01:11 -------- d-----w- c:\users\Nessaboo\AppData\Roaming\Juniper Networks
2010-08-07 01:12 . 2010-08-07 01:11 -------- d-----w- c:\program files\Juniper Networks
2010-08-07 01:11 . 2010-08-07 01:11 162656 ----a-w- c:\users\Nessaboo\AppData\Roaming\Juniper Networks\Setup Client\x86_Microsoft.VC80.CRTP_8.0.50727.762.exe
2010-08-07 01:11 . 2010-08-07 01:11 292704 ----a-w- c:\users\Nessaboo\AppData\Roaming\Juniper Networks\Setup Client\x86_Microsoft.VC80.CRTR_8.0.50727.762.exe
2010-08-05 03:28 . 2010-05-18 02:05 108824 ----a-w- c:\users\Nessaboo\AppData\Local\GDIPFONTCACHEV1.DAT
2010-08-05 03:18 . 2009-07-14 04:52 -------- d-----w- c:\program files\MSBuild
2010-08-05 03:18 . 2010-08-05 03:18 -------- d-----w- c:\program files\Microsoft Synchronization Services
2010-08-05 03:17 . 2010-08-05 03:17 -------- d-----w- c:\program files\Microsoft Sync Framework
2010-08-05 03:17 . 2010-08-05 03:17 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-08-05 03:17 . 2010-06-26 10:38 -------- d-----w- c:\program files\Microsoft.NET
2010-08-05 03:16 . 2010-08-05 03:16 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-08-05 03:15 . 2010-08-05 03:15 -------- d-----w- c:\program files\Microsoft Analysis Services
2010-07-29 06:30 . 2010-08-12 04:24 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-12 04:24 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-26 01:15 . 2010-07-26 01:15 -------- d-----w- c:\program files\ImgBurn
2010-07-26 01:07 . 2010-07-26 01:07 -------- d-----w- c:\programdata\NCH Swift Sound
2010-07-26 01:06 . 2010-07-26 01:06 -------- d-----w- c:\program files\NCH Swift Sound
2010-07-14 10:18 . 2010-05-17 05:20 -------- d-----w- c:\programdata\NOS
2010-06-30 06:25 . 2010-08-12 04:24 978432 ----a-w- c:\windows\system32\wininet.dll
2010-06-28 03:59 . 2010-06-28 03:59 50354 ----a-w- c:\users\Nessaboo\AppData\Roaming\Facebook\uninstall.exe
2010-06-22 02:47 . 2010-08-12 04:24 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-22 02:47 . 2010-08-12 04:24 307200 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-06-22 02:47 . 2010-08-12 04:24 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-06-19 06:33 . 2010-08-12 04:24 3955080 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-06-19 06:33 . 2010-08-12 04:24 3899784 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-06-19 06:23 . 2010-08-12 04:24 37376 ----a-w- c:\windows\system32\rtutils.dll
2010-06-19 04:07 . 2010-08-12 04:24 2326016 ----a-w- c:\windows\system32\win32k.sys
2010-06-16 05:48 . 2010-08-12 04:24 224256 ----a-w- c:\windows\system32\schannel.dll
2010-06-14 06:12 . 2010-08-12 04:24 1286016 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2010-08-23 1242448]
"AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2008-12-12 2292672]
"igndlm.exe"="c:\program files\Download Manager\DLM.exe" [2009-10-27 1103216]
"Google Update"="c:\users\Nessaboo\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-08-22 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2007-07-23 77824]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
c:\users\Nessaboo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4640000]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-18 1343400]
S1 aswSP;aswSP; [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-09-07 50768]
.
Contents of the 'Scheduled Tasks' folder
2010-09-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-32453113-1086635514-2273911061-1001Core.job
- c:\users\Nessaboo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-22 17:35]
2010-09-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-32453113-1086635514-2273911061-1001UA.job
- c:\users\Nessaboo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-22 17:35]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://images3.pnimedia.com/ProductAssets/costcous/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
DPF: {DB28CF23-0083-40B5-BF63-69925D672385} - hxxp://www.nero.com/doc/NeroVersionChecker.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://vpn1.hologic.com/dana-cached/sc/JuniperSetupClient.cab
FF - ProfilePath - c:\users\Nessaboo\AppData\Roaming\Mozilla\Firefox\Profiles\m01ih5tb.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - plugin: c:\progra~1\MICROS~3\Office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\MICROS~3\Office14\NPSPWRAP.DLL
FF - plugin: c:\program files\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\users\Nessaboo\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\Nessaboo\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-32453113-1086635514-2273911061-1001\Software\SecuROM\License information*]
"datasecu"=hex:3a,f5,44,df,3b,90,87,a4,f3,b6,65,79,06,09,b6,95,4b,c9,c9,cf,ca,
03,86,0b,20,29,a2,b5,6e,c2,59,e1,77,2b,80,11,49,0d,3b,fb,6c,20,7f,45,02,90,\
"rkeysecu"=hex:00,28,36,25,fe,b4,40,44,31,af,d3,3c,7a,86,7f,ec
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\atieclxx.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Juniper Networks\Common Files\dsNcService.exe
c:\programdata\EPSON\EPW!3 SSRP\E_S40RP7.EXE
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\conhost.exe
c:\windows\system32\WUDFHost.exe
c:\users\Nessaboo\AppData\Local\Google\Update\1.2.183.29\GoogleCrashHandler.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\sppsvc.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2010-09-11 13:01:34 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-11 20:01
ComboFix2.txt 2010-09-11 03:42
ComboFix3.txt 2010-09-09 06:01
ComboFix4.txt 2010-09-08 03:56
ComboFix5.txt 2010-09-11 19:44
Pre-Run: 19,401,986,048 bytes free
Post-Run: 19,265,761,280 bytes free
- - End Of File - - CD0142F54399BBAD71D24D805004D57D