ComboFix 12-08-05.02 - User 08/05/2012 17:37:27.1.8 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8109.6937 [GMT -5:00]
Running from: c:\users\User\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\LP
c:\program files (x86)\LP\B63F\3469.tmp
c:\program files (x86)\LP\B63F\49EB.tmp
c:\program files (x86)\LP\B63F\4AC6.tmp
c:\program files (x86)\LP\B63F\9DF3.tmp
c:\program files (x86)\LP\B63F\AF13.tmp
c:\program files (x86)\LP\B63F\C541.tmp
c:\program files (x86)\LP\B63F\CB88.tmp
c:\program files (x86)\LP\B63F\D30A.tmp
c:\program files (x86)\LP\B63F\D815.tmp
c:\program files (x86)\LP\B63F\E233.tmp
c:\program files (x86)\LP\B63F\E52F.tmp
c:\program files (x86)\LP\B63F\E5CE.tmp
c:\program files (x86)\LP\B63F\EE34.tmp
c:\programdata\17672385l5n4
c:\windows\assembly\temp\@
c:\windows\assembly\temp\cfg.ini
.
.
((((((((((((((((((((((((( Files Created from 2012-07-05 to 2012-08-05 )))))))))))))))))))))))))))))))
.
.
2012-08-05 22:40 . 2012-08-05 22:40 -------- d-----w- c:\users\DefaultAppPool\AppData\Local\temp
2012-08-05 22:40 . 2012-08-05 22:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-05 22:40 . 2012-08-05 22:40 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2012-08-05 18:56 . 2012-08-05 18:56 -------- d-----w- C:\FRST
2012-08-05 02:50 . 2012-08-05 02:51 -------- d-----w- C:\HostsXpert
2012-08-05 00:29 . 2012-08-05 00:29 -------- d-----w- C:\_OTM
2012-07-31 02:06 . 2012-07-31 02:06 -------- d-----w- c:\program files (x86)\ERUNT
2012-07-31 01:36 . 2012-07-31 01:36 -------- d-----w- C:\_OTL
2012-07-26 05:48 . 2012-07-26 05:48 -------- d-----w- c:\program files (x86)\MSECache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-03 18:46 . 2012-02-18 05:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-30 06:04 . 2012-06-30 06:04 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-30 06:04 . 2012-06-30 06:04 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-06-02 22:19 . 2012-06-22 15:50 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-22 15:50 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-22 15:50 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-22 15:50 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-22 15:50 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-22 15:50 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-22 15:50 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 20:19 . 2012-06-22 15:50 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 20:15 . 2012-06-22 15:50 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-05-24 16:57 . 2012-02-28 01:28 0 --sha-w- c:\windows\system32\dds_trash_log.cmd
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideSCAHealth"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-04-05 158856]
R3 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-12-27 378472]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2010-11-11 155752]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-01 535656]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2413128680-2735381842-1444654988-1000Core.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-26 02:56]
.
2012-08-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2413128680-2735381842-1444654988-1000UA.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-26 02:56]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62 0.0.0.0
TCP: Interfaces\{E9BBE345-E75A-482D-B4C0-7AD3A469C10B}: NameServer = 8.8.8.8,8.8.4.4
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\3ch0u0t8.default\
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-84050329.sys
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-08-05 17:48:07 - machine was rebooted
ComboFix-quarantined-files.txt 2012-08-05 22:48
.
Pre-Run: 13,216,514,048 bytes free
Post-Run: 16,180,445,184 bytes free
.
- - End Of File - - FD9B566B896302EA696B8EF83202424E