ComBo Fix Log
ComboFix 12-07-29.02 - Ryuu 30/07/2012 11:12:09.1.8 - x64 NETWORK
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.65.1033.18.8044.6918 [GMT 8:00]
Running from: c:\users\Ryuu\Desktop\ComboFix.exe
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\2
c:\program files (x86)\2\0\1.cmd
c:\program files\Web Assistant\ExTEnsion32.dll
c:\programdata\1323230167.bdinstall.bin
c:\programdata\1323233335.bdinstall.bin
c:\programdata\Amazon.ico
c:\programdata\MercadoLivre.ico
c:\users\Ryuu\AppData\Local\Minibar
c:\users\Ryuu\AppData\Local\Minibar\common.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome.manifest
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\content.xul
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\extension_info.json
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\icons\icon128.png
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\icons\icon19.png
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\icons\icon32.png
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\icons\icon48.png
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango-ui\button.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango-ui\popup.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango-ui\popup_window.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango-ui\popup_window.xul
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango-ui\theme\bubble\bottom-left.png
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango-ui\theme\bubble\bottom-middle.png
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango-ui\theme\bubble\bottom-right.png
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango-ui\theme\bubble\middle-left.png
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango-ui\theme\bubble\middle-right.png
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango-ui\theme\bubble\style.css
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango-ui\theme\bubble\tail-bottom.png
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango-ui\theme\bubble\tail-left.png
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango-ui\theme\bubble\tail-right.png
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango-ui\theme\bubble\tail-top.png
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango-ui\theme\bubble\top-left.png
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango-ui\theme\bubble\top-middle.png
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango-ui\theme\bubble\top-right.png
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango-ui\ui.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango\browser.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango\console.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango\event_listener.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango\initialize.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango\io.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango\jsonstorage.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango\kango.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango\lang.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango\messaging.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango\storage.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango\uninstall_observer.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango\userscript_engine.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\kango\xhr.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\main.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\minibar\actions.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\minibar\cachedxhr.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\minibar\config.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\minibar\config.json
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\minibar\homepage_helper.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\minibar\macros.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\minibar\minibar.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\minibar\search_helper.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\minibar\search_hook.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\chrome\content\minibar\tabpage_helper.js
c:\users\Ryuu\AppData\Local\Minibar\firefox\install.rdf
c:\users\Ryuu\AppData\Local\Minibar\firefox\plugins\npMinibarPlugin.dll
c:\users\Ryuu\AppData\Local\Minibar\firefox_installer.js
c:\users\Ryuu\AppData\Local\Minibar\ie_installer.js
c:\users\Ryuu\AppData\Local\Minibar\minibar.xpi
c:\users\Ryuu\AppData\Local\Minibar\Uninstall.exe
c:\users\Ryuu\AppData\Local\TempDIR
c:\users\Ryuu\hosts
c:\users\Ryuu\RelicCOH.exe
c:\users\Ryuu\SpecOpsTheLine.exe
c:\users\Ryuu\steam_api.dll
c:\users\Ryuu\Steamclient.dll
c:\windows\jestertb.dll
c:\windows\RazorDOX
c:\windows\RazorDOX\RazorDOX.dll
c:\windows\RazorDOX\RazorDOX.ini
c:\windows\SysWow64\DEBUG.log
c:\windows\SysWow64\Packet.dll
c:\windows\SysWow64\pthreadVC.dll
c:\windows\SysWow64\themeui.dll.tmp
c:\windows\SysWow64\uxtheme.dll.tmp
c:\windows\SysWow64\wpcap.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Service_npf
-------\Service_RelevantKnowledge
.
.
((((((((((((((((((((((((( Files Created from 2012-06-28 to 2012-07-30 )))))))))))))))))))))))))))))))
.
.
2012-07-30 03:21 . 2012-07-30 03:21 -------- d-----w- c:\users\Mike\AppData\Local\temp
2012-07-30 03:21 . 2012-07-30 03:21 -------- d-----w- c:\users\Guest\AppData\Local\temp
2012-07-30 03:21 . 2012-07-30 03:21 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-07-30 02:49 . 2012-07-30 02:49 328704 ----a-w- c:\windows\system32\services.exe.4D866F236C783CD8
2012-07-29 06:01 . 2012-07-03 05:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-29 04:36 . 2012-07-29 04:36 -------- d-----w- C:\FRST
2012-07-28 09:52 . 2012-07-28 09:52 -------- d-----w- c:\users\Ryuu\AppData\Roaming\Malwarebytes
2012-07-28 09:52 . 2012-07-28 09:52 -------- d-----w- c:\programdata\Malwarebytes
2012-07-28 09:52 . 2012-07-29 06:01 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-07-28 09:34 . 2012-07-29 04:07 -------- d-----w- C:\d51ee645f6d2af991e9c9d0cf0e4
2012-07-28 09:20 . 2012-07-29 04:07 -------- d-----w- C:\4e4dd3ab32a9b8fe7501dbe8dbd4f4
2012-07-28 08:46 . 2012-07-28 08:46 -------- d-----w- c:\users\Ryuu\AppData\Roaming\Systweak
2012-07-28 08:45 . 2012-07-29 04:07 -------- d-----w- c:\program files (x86)\Advanced System Optimizer 3
2012-07-28 07:53 . 2012-07-15 18:40 9133488 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C546CAE4-2870-4851-ABC7-F808A738AFDD}\mpengine.dll
2012-07-28 07:51 . 2012-07-28 07:51 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2012-07-28 07:51 . 2012-07-28 07:51 -------- d-----w- c:\program files\Microsoft Security Client
2012-07-27 05:10 . 2012-07-27 05:10 0 ----a-w- c:\windows\SysWow64\shoC467.tmp
2012-07-25 15:28 . 2012-07-25 15:28 0 ----a-w- c:\windows\SysWow64\shoCA95.tmp
2012-07-24 14:39 . 2012-07-24 14:39 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-24 14:39 . 2012-07-24 14:39 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-24 05:26 . 2012-07-24 05:26 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-07-24 05:26 . 2012-07-24 05:26 -------- d-----w- c:\program files (x86)\Oracle
2012-07-24 05:25 . 2012-07-05 14:06 772544 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-07-23 09:16 . 2012-07-23 09:16 -------- d-----w- c:\program files (x86)\Cheat Engine 6.2
2012-07-23 08:22 . 2012-07-23 08:22 -------- d-----w- c:\users\Ryuu\AppData\Roaming\FALCOM
2012-07-23 07:53 . 2012-07-23 07:53 -------- d-----w- c:\programdata\RELOADED
2012-07-23 07:50 . 2012-07-23 07:53 -------- d-----w- c:\program files (x86)\Ys Origin
2012-07-21 15:32 . 2012-07-21 15:32 -------- d-----w- c:\users\Mike\AppData\Local\Activision
2012-07-21 09:21 . 2012-07-21 09:21 -------- d-----w- c:\users\Ryuu\AppData\Local\Activision
2012-07-21 07:11 . 2012-07-21 07:11 -------- d-----w- c:\program files (x86)\Activision
2012-07-20 12:03 . 2012-07-20 12:03 -------- d-----w- c:\users\Mike\AppData\Local\Wondershare
2012-07-20 09:55 . 2012-07-20 09:55 -------- d-----w- c:\program files (x86)\OApps
2012-07-20 09:55 . 2012-07-20 09:55 -------- d-----w- c:\program files (x86)\TorrentSearch
2012-07-20 09:55 . 2012-07-29 04:22 -------- d-----w- c:\program files (x86)\smartdl
2012-07-20 09:43 . 2012-07-20 09:43 -------- d-----w- c:\program files (x86)\Alcohol Soft
2012-07-20 09:37 . 2012-07-20 09:37 834544 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-07-20 07:59 . 2009-07-13 19:25 -------- d-----w- c:\users\Ryuu\validators
2012-07-20 07:04 . 2012-07-20 07:04 -------- d-----w- c:\users\Default\AppData\Roaming\IObit
2012-07-19 11:37 . 2012-07-19 11:37 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%
2012-07-18 09:50 . 2012-07-18 09:50 -------- d-sh--w- c:\windows\ftpcache
2012-07-18 09:47 . 2012-07-18 09:47 -------- d-----w- c:\users\Ryuu\AppData\Roaming\Spec Ops The Line
2012-07-18 09:19 . 2012-07-18 09:19 -------- d-----w- c:\program files (x86)\R.G. Mechanics
2012-07-16 13:27 . 2012-07-16 13:27 0 ----a-w- c:\windows\SysWow64\sho29FA.tmp
2012-07-16 10:39 . 2012-07-16 10:39 -------- d-----w- c:\users\Ryuu\AppData\Roaming\Wondershare Video Converter Ultimate
2012-07-16 10:39 . 2012-07-16 10:39 -------- d-----w- c:\users\Ryuu\AppData\Local\Wondershare
2012-07-16 10:39 . 2012-07-16 10:39 -------- d-----w- c:\program files (x86)\Common Files\Wondershare
2012-07-16 01:03 . 2012-07-16 01:03 184891 ----a-w- C:\torrent.exe
2012-07-14 13:11 . 2012-07-14 16:47 -------- d-----w- c:\users\Mike\AppData\Roaming\NVIDIA
2012-07-14 05:27 . 2012-07-15 08:35 -------- d-----w- c:\program files (x86)\JoWooD Entertainment AG
2012-07-13 15:42 . 2012-07-13 15:42 -------- d--h--r- c:\users\Ryuu\AppData\Roaming\SecuROM
2012-07-13 11:16 . 2012-07-13 11:16 0 ----a-w- c:\windows\SysWow64\sho933A.tmp
2012-07-13 10:47 . 2012-06-12 03:08 3148800 ----a-w- c:\windows\system32\win32k.sys
2012-07-13 10:40 . 2012-06-02 12:49 17807360 ----a-w- c:\windows\system32\mshtml.dll
2012-07-13 10:40 . 2012-06-02 12:17 10924032 ----a-w- c:\windows\system32\ieframe.dll
2012-07-13 10:35 . 2012-07-13 11:18 -------- d-----w- c:\windows\SysWow64\NV
2012-07-13 10:35 . 2012-07-13 11:18 -------- d-----w- c:\windows\system32\NV
2012-07-12 14:25 . 2012-07-13 10:35 -------- d-----w- c:\programdata\NVIDIA
2012-07-12 14:25 . 2012-07-29 04:22 -------- d-----w- c:\users\UpdatusUser
2012-07-12 14:25 . 2012-05-15 09:29 889664 ----a-w- c:\windows\system32\nvvsvc.exe
2012-07-12 14:25 . 2012-05-15 09:29 858944 ----a-w- c:\windows\system32\nv3dappshext.dll
2012-07-12 14:25 . 2012-05-15 09:29 63296 ----a-w- c:\windows\system32\nvshext.dll
2012-07-12 14:25 . 2012-05-15 09:29 55616 ----a-w- c:\windows\system32\nv3dappshextr.dll
2012-07-12 14:25 . 2012-05-15 09:29 2561856 ----a-w- c:\windows\system32\nvsvcr.dll
2012-07-12 14:25 . 2012-05-15 09:29 118080 ----a-w- c:\windows\system32\nvmctray.dll
2012-07-12 14:25 . 2012-05-15 09:29 2621723 ----a-w- c:\windows\system32\nvcoproc.bin
2012-07-12 14:25 . 2012-05-15 09:29 3149632 ----a-w- c:\windows\system32\nvsvc64.dll
2012-07-12 14:25 . 2012-05-15 09:28 6151488 ----a-w- c:\windows\system32\nvcpl.dll
2012-07-12 14:24 . 2012-05-15 10:48 68928 ----a-w- c:\windows\system32\OpenCL.dll
2012-07-12 14:24 . 2012-05-15 10:48 61248 ----a-w- c:\windows\SysWow64\OpenCL.dll
2012-07-12 14:24 . 2012-07-12 14:24 -------- d-----w- c:\programdata\NVIDIA Corporation
2012-07-11 06:55 . 2012-06-06 06:06 2004480 ----a-w- c:\windows\system32\msxml6.dll
2012-07-11 06:55 . 2012-06-06 06:06 1881600 ----a-w- c:\windows\system32\msxml3.dll
2012-07-11 06:55 . 2012-06-06 05:05 1390080 ----a-w- c:\windows\SysWow64\msxml6.dll
2012-07-11 06:55 . 2012-06-06 05:05 1236992 ----a-w- c:\windows\SysWow64\msxml3.dll
2012-07-11 06:55 . 2010-06-26 03:55 2048 ----a-w- c:\windows\system32\msxml3r.dll
2012-07-11 06:55 . 2010-06-26 03:24 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
2012-07-11 06:55 . 2012-06-09 05:43 14172672 ----a-w- c:\windows\system32\shell32.dll
2012-07-07 13:34 . 2010-04-03 03:51 73568 ----a-w- c:\windows\SysWow64\perf-MSSQL$DRAGONICA-sqlctr10.51.2500.0.dll
2012-07-07 13:02 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-07-07 13:02 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-07-07 12:47 . 2012-07-07 12:47 -------- d-----w- c:\program files (x86)\THQ
2012-07-06 16:38 . 2012-07-06 16:38 -------- d-----w- c:\users\Mike\AppData\Local\Diagnostics
2012-07-04 09:12 . 2012-07-04 09:12 0 ----a-w- c:\windows\SysWow64\sho456C.tmp
2012-06-30 12:04 . 2012-06-30 12:04 0 ----a-w- c:\windows\SysWow64\sho7BBD.tmp
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-13 10:41 . 2011-12-05 17:54 59701280 ----a-w- c:\windows\system32\MRT.exe
2012-07-12 11:00 . 2012-04-19 12:00 9822920 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-07-08 06:09 . 2012-06-29 06:37 282696 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-07-08 06:09 . 2011-12-06 10:25 282696 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-07-05 14:06 . 2011-11-09 06:37 687544 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-07-03 11:30 . 2011-12-06 10:25 282696 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-06-29 05:54 . 2011-12-06 10:25 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-06-27 09:03 . 2012-06-27 09:03 0 ----a-w- c:\windows\SysWow64\shoC66B.tmp
2012-06-21 08:37 . 2012-06-21 08:37 3166792 ------w- c:\windows\SysWow64\pbsvc.exe
2012-06-21 08:29 . 2012-06-21 08:29 0 ----a-w- c:\windows\SysWow64\sho5254.tmp
2012-06-20 14:00 . 2012-06-20 14:00 0 ----a-w- c:\windows\SysWow64\sho6748.tmp
2012-06-20 02:11 . 2012-06-20 02:12 268720 ----a-w- c:\windows\system32\javaws.exe
2012-06-20 02:11 . 2012-06-20 02:12 189360 ----a-w- c:\windows\system32\javaw.exe
2012-06-20 02:11 . 2012-06-20 02:12 188840 ----a-w- c:\windows\system32\java.exe
2012-06-20 02:11 . 2012-06-20 02:12 839096 ----a-w- c:\windows\system32\deployJava1.dll
2012-06-20 02:11 . 2012-06-20 02:12 955840 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-06-16 03:25 . 2012-06-16 03:25 0 ----a-w- c:\windows\SysWow64\sho5BF6.tmp
2012-06-16 01:04 . 2012-06-16 01:04 0 ----a-w- c:\windows\SysWow64\sho40F7.tmp
2012-06-12 18:22 . 2012-06-12 18:22 0 ----a-w- c:\windows\SysWow64\sho4E24.tmp
2012-06-11 18:52 . 2012-06-11 18:52 0 ----a-w- c:\windows\SysWow64\sho21D3.tmp
2012-06-07 08:53 . 2012-06-07 08:53 0 ----a-w- c:\windows\SysWow64\shoB6C2.tmp
2012-06-05 19:24 . 2012-06-05 19:24 0 ----a-w- c:\windows\SysWow64\sho9A96.tmp
2012-06-02 22:19 . 2012-06-19 02:53 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-19 02:53 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-19 02:53 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-19 02:53 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-19 02:53 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-19 02:53 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-19 02:53 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 07:29 . 2012-06-02 07:29 0 ----a-w- c:\windows\SysWow64\shoA952.tmp
2012-06-02 07:19 . 2012-06-19 02:53 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 07:15 . 2012-06-19 02:53 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-05-31 04:25 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-05-30 18:16 . 2012-05-30 18:16 0 ----a-w- c:\windows\SysWow64\shoEDD8.tmp
2012-05-27 18:48 . 2012-05-27 18:48 0 ----a-w- c:\windows\SysWow64\shoE7B0.tmp
2012-05-26 12:54 . 2012-05-26 12:54 0 ----a-w- c:\windows\SysWow64\sho7087.tmp
2012-05-25 19:23 . 2012-05-25 19:23 0 ----a-w- c:\windows\SysWow64\shoA67C.tmp
2012-05-20 07:06 . 2012-05-20 07:06 0 ----a-w- c:\windows\SysWow64\sho3109.tmp
2012-05-20 06:15 . 2012-05-20 06:15 661600 ----a-w- c:\windows\SysWow64\xsherlock.xem
2012-05-11 06:46 . 2012-05-11 06:46 644400 ----a-w- c:\windows\SysWow64\mscomct2.ocx
2012-05-10 10:55 . 2012-05-10 10:55 0 ----a-w- c:\windows\SysWow64\shoF70B.tmp
2012-05-07 07:45 . 2012-05-07 07:45 0 ----a-w- c:\windows\SysWow64\shoA1CC.tmp
2012-05-05 07:03 . 2012-05-05 07:03 0 ----a-w- c:\windows\SysWow64\sho25DC.tmp
2012-05-04 11:06 . 2012-06-14 08:57 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 10:03 . 2012-06-14 08:57 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03 . 2012-06-14 08:57 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-05-04 07:04 . 2012-05-04 07:04 421888 ----a-w- c:\windows\SysWow64\RealMediaSplitter.ax
2012-05-04 07:04 . 2012-05-04 07:04 2174976 ----a-w- c:\program files (x86)\Common Files\atimpenc.dll
2012-05-01 05:40 . 2012-06-14 08:57 209920 ----a-w- c:\windows\system32\profsvc.dll
2010-01-26 03:11 . 2012-06-20 15:40 444283 ----a-w- c:\program files (x86)\Common Files\WinPcapNmap.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{adca5064-9e30-43fe-9856-58b07a3149fe}"= "c:\program files (x86)\FreeMake\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{adca5064-9e30-43fe-9856-58b07a3149fe}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{0931BD3F-547E-45C1-B133-D0E995645DBA}]
2012-07-13 17:44 92160 ----a-w- c:\program files (x86)\OApps\bho_project.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{adca5064-9e30-43fe-9856-58b07a3149fe}]
2011-05-09 08:49 176936 ----a-w- c:\program files (x86)\FreeMake\prxtbFree.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2012-04-24 06:24 1310000 ----a-w- c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{6B896ADB-4A82-46e2-858C-13134782CE34}"= "c:\program files (x86)\Xmlbar\FLV Downloader\IEBar\xbietb.dll" [2009-12-15 413696]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2012-04-24 1310000]
"{adca5064-9e30-43fe-9856-58b07a3149fe}"= "c:\program files (x86)\FreeMake\prxtbFree.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{6b896adb-4a82-46e2-858c-13134782ce34}]
[HKEY_CLASSES_ROOT\XBIEBar.XBIEBarObj.1]
[HKEY_CLASSES_ROOT\TypeLib\{D4FB30ED-7DDB-4e2c-A7F2-C7B905D5D771}]
[HKEY_CLASSES_ROOT\XBIEBar.XBIEBarObj]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{adca5064-9e30-43fe-9856-58b07a3149fe}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2012-05-18 880496]
"IDMan"="c:\program files (x86)\Internet Download Manager\IDMan.exe" [2011-08-01 3417496]
.
c:\users\Ryuu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Facebook Messenger.lnk - c:\users\Ryuu\AppData\Local\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe [2012-7-26 244656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2012-07-20 834544]
R1 wxutdbmc;wxutdbmc;c:\windows\system32\drivers\wxutdbmc.sys [x]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
R2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-05-12 249648]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
R2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [2011-07-06 145008]
R2 MSSQL$DRAGONICA;SQL Server (DRAGONICA);c:\program files (x86)\Microsoft SQL Server\MSSQL10_50.DRAGONICA\MSSQL\Binn\sqlservr.exe [2011-06-17 43040096]
R2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
R2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-11-29 16120]
R3 1394hub;1394 Enabled Hub;c:\windows\System32\svchost.exe [2009-07-14 27136]
R3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\DRIVERS\lgandbus64.sys [2010-12-07 19456]
R3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\DRIVERS\lganddiag64.sys [2010-12-07 27648]
R3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\DRIVERS\lgandgps64.sys [2010-12-07 27136]
R3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\DRIVERS\lgandmodem64.sys [2010-12-07 34304]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2011-05-12 36328]
R3 appliand;Applian Network Service;c:\windows\system32\DRIVERS\appliand.sys [2011-06-26 33888]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-06-07 191752]
R3 bScsiSDa;bScsiSDa;c:\windows\system32\DRIVERS\bScsiSDa.sys [2011-05-06 86056]
R3 BTWAMPFL;BTWAMPFL;c:\windows\system32\DRIVERS\btwampfl.sys [2011-01-10 349736]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2011-02-15 39464]
R3 cpuz135;cpuz135;c:\program files (x86)\CPUID\PC Wizard 2012\pcwiz_x64.sys [2012-02-07 23816]
R3 dump_wmimmc;dump_wmimmc; [x]
R3 EagleX64;EagleX64; [x]
R3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-20 98688]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]
R3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]
R3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]
R3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]
R3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
R3 SRS_AE_Service;SRS Audio Essentials;c:\windows\system32\drivers\SRS_AE_amd64.sys [2011-08-01 513824]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-05-12 157672]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-05-12 16872]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-05-12 177640]
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys [2011-05-12 146920]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-11-08 1255736]
R3 wolf;wolf; [x]
R3 X6va005;X6va005; [x]
R3 xsherlock;xsherlock;c:\windows\system32\xsherlock.xem [x]
R4 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-02 63928]
R4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-24 250056]
R4 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files (x86)\IObit\Advanced SystemCare 5\ASCService.exe [2011-11-10 490840]
R4 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2011-07-01 353360]
R4 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2011-05-10 872552]
R4 Giraffic;Veoh Giraffic Video Accelerator;c:\program files (x86)\Giraffic\Veoh_GirafficWatchdog.exe [2012-07-02 2232504]
R4 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe [2011-05-26 29696]
R4 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-04-30 13592]
R4 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2011-04-22 244624]
R4 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-18 113120]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 44896]
R4 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
R4 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [2011-04-24 256832]
R4 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
R4 SQLAgent$DRAGONICA;SQL Server Agent (DRAGONICA);c:\program files (x86)\Microsoft SQL Server\MSSQL10_50.DRAGONICA\MSSQL\Binn\SQLAGENT.EXE [2011-06-17 370016]
R4 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
R4 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-01 2656280]
R4 VideoAcceleratorService;VideoAcceleratorService;c:\progra~2\SPEEDB~1\VideoAcceleratorService.exe [2011-12-03 265928]
R4 Web Assistant Updater;Web Assistant Updater;c:\program files\Web Assistant\ExtensionUpdaterService.exe [2012-05-24 185856]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2012-05-15 28992]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-12-01 272448]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S3 appliandMP;appliandMP;c:\windows\system32\DRIVERS\appliand.sys [2011-06-26 33888]
S3 b57xdbd;Broadcom xD Picture Bus Driver Service;c:\windows\system32\drivers\b57xdbd.sys [2011-01-21 67624]
S3 b57xdmp;Broadcom xD Picture vstorp client drv;c:\windows\system32\drivers\b57xdmp.sys [2011-01-21 19496]
S3 bScsiMSa;bScsiMSa;c:\windows\system32\drivers\bScsiMSa.sys [2011-05-16 51240]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2011-04-05 142632]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2011-05-10 425000]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2011-02-10 82432]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2011-02-10 181760]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-29 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-24 14:39]
.
2012-07-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3545194168-222157450-2924182206-1001Core.job
- c:\users\Ryuu\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-01-23 10:46]
.
2012-07-28 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3545194168-222157450-2924182206-1001UA.job
- c:\users\Ryuu\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-01-23 10:46]
.
2012-07-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3545194168-222157450-2924182206-1005Core.job
- c:\users\Mike\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-12-23 12:52]
.
2012-07-28 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3545194168-222157450-2924182206-1005UA.job
- c:\users\Mike\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-12-23 12:52]
.
2012-07-29 c:\windows\Tasks\Final Media Player Update Checker.job
- c:\program files (x86)\FinalMediaPlayer\FMPCheckForUpdates.exe [2011-11-22 07:24]
.
2012-07-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3545194168-222157450-2924182206-1001Core.job
- c:\users\Ryuu\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-27 10:41]
.
2012-07-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3545194168-222157450-2924182206-1001UA.job
- c:\users\Ryuu\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-27 10:41]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}]
2012-05-24 07:23 201728 ----a-w- c:\program files\Web Assistant\Extension64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2011-05-30 16:50 22408 ----a-w- c:\program files (x86)\Internet Download Manager\IDMShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
"combofix"="c:\combofix\CF22011.3XE" [2010-11-21 345088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"combofix"="c:\combofix\CF22011.3XE" [2010-11-21 345088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.babylon.com/?affID=113480&tt=060612_8_&babsrc=HP_ss&mntrId=0a9026c700000000000002004c4f4f50
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://home.sweetim.com/?crg=3.1010000.10011&barid={BF131707-A10F-11E1-9CB4-B870F4AA8650}
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = proxy.trueinternet.co.th:8080
uInternet Settings,ProxyOverride = 127.0.0.1:9421;<local>
IE: &Clean Traces - c:\program files (x86)\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files (x86)\DAP\dapextie.htm
IE: &Xmlbar Search -
http://www.xmlbar.com/iebar/iemenu.php?lang=British English&ver=1.0
IE: Download &all with DAP - c:\program files (x86)\DAP\dapextie2.htm
IE: Download all links with IDM - c:\program files (x86)\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - c:\program files (x86)\Internet Download Manager\IEExt.htm
IE: Download with Xilisoft Online Video Downloader - c:\program files (x86)\Xilisoft\Online Video Downloader\upod_link.HTM
IE: Download with Xilisoft YouTube Video Converter - c:\program files (x86)\Xilisoft\YouTube Video Converter\upod_link.HTM
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105
IE: Search the Web - c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
IE: {{612F6E5C-B314-4bab-93D1-D266AAFBE700} - c:\program files (x86)\Xmlbar\FLV Downloader\FLVDownloader(xmlbar).exe
LSP: c:\program files (x86)\SpeedBit Video Accelerator\SBLSP.dll
TCP: DhcpNameServer = 192.168.1.254
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~2\DAP\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~2\DAP\dapie.dll
DPF: {2B6F3D45-8258-4A13-85B8-58C62DFDB4EA} - hxxps://secure1.playfps.com/play/ava/ax/WebLauncher.cab
FF - ProfilePath - c:\users\Ryuu\AppData\Roaming\Mozilla\Firefox\Profiles\8ztbwxdo.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - about:home
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extentions.y2layers.installId - 17eb04dd-eb6e-43d4-b51e-557eefece8b2
FF - user.js: extentions.y2layers.defaultEnableAppsList - bestvideodownloader,ezLooker,pagerage,buzzdock,toprelatedtopics,twittube
FF - user.js: extensions.autoDisableScopes - 14
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=112555&tt=220512_53all
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 0a9026c700000000000002004c4f4f50
FF - user.js: extensions.BabylonToolbar_i.hardId - 0a9026c700000000000002004c4f4f50
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15489
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1720:27
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
FF - user.js: extensions.incredibar_i.newTab - false
FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6PQAB82eZf&loc=IB_TB&I=26&search=
FF - user.js: extensions.incredibar_i.id - 0a9026c700000000000002004c4f4f50
FF - user.js: extensions.incredibar_i.instlDay - 15507
FF - user.js: extensions.incredibar_i.vrsn - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsni - 1.5.11.14
FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.11.148:34
FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
FF - user.js: extensions.incredibar_i.prdct - incredibar
FF - user.js: extensions.incredibar_i.aflt - orgnl
FF - user.js: extensions.incredibar_i.smplGrp - none
FF - user.js: extensions.incredibar_i.tlbrId - base
FF - user.js: extensions.incredibar_i.instlRef -
FF - user.js: extensions.incredibar_i.dfltLng -
FF - user.js: extensions.incredibar_i.excTlbr - false
FF - user.js: extensions.incredibar_i.ms_url_id -
FF - user.js: extensions.incredibar_i.upn2 - 6PQAB82eZf
FF - user.js: extensions.incredibar_i.upn2n - 92543067446074589
FF - user.js: extensions.incredibar_i.productid - 26
FF - user.js: extensions.incredibar_i.installerproductid - 26
FF - user.js: extensions.incredibar_i.did - 10643
FF - user.js: extensions.incredibar_i.ppd - 36
user_pref('extensions.autoDisableScopes', 0);user_pref('security.csp.enable', false);user_pref('security.OCSP.enabled', 0);
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{ADCA5064-9E30-43FE-9856-58B07A3149FE} - (no file)
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\Akamai]
"ServiceDll"="c:\program files (x86)\common files\akamai/netsession_win_4f7fccd.dll"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.5\bin\mysqld\" --defaults-file=\"c:\program files\MySQL\MySQL Server 5.5\my.ini\" MySQL"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\xsherlock]
"ImagePath"="c:\windows\system32\xsherlock.xem"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-3545194168-222157450-2924182206-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"?áÍ"=hex:1b,9b,39,f0,14,f1,ff,ff,fa,4f,cf,e4,60,03,0a,d7,ae,03,45,85,4b,fd,55,
e9,82,03,7a,92,e3,c3,a8,0e,ec,b0,a8,c2,22,d4,df,0d,41,45,94,3a,a2,31,c7,28,\
"·³²»"=hex:e2,06,90,c3,a9,ab,f7,ca,1c,f7,63,d7,3e,f2,89,5d
.
[HKEY_USERS\S-1-5-21-3545194168-222157450-2924182206-1001_Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):a9,69,f1,57,a1,be,2b,db,20,3c,1a,3b,ff,4e,f5,81,cd,ac,e7,b3,de,
99,7a,b4,dd,8d,bf,72,6e,01,ba,d0,91,65,bb,00,21,ba,bb,12,00,00,00,00,00,00,\
.
[HKEY_USERS\S-1-5-21-3545194168-222157450-2924182206-1001_Classes\Wow6432Node\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):80,39,9c,5c,b0,39,0d,c8,eb,5c,b0,92,7e,ad,fc,fa,31,b1,25,c7,c9,
8b,82,3a,b9,8e,62,13,c4,f8,d5,40,4e,5e,00,05,20,ef,eb,f8,00,00,00,00,00,00,\
.
[HKEY_USERS\S-1-5-21-3545194168-222157450-2924182206-1001_Classes\Wow6432Node\CLSID\{dfdd4cb2-21b3-4558-94e5-942b7730ddd3}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000153
"Therad"=dword:0000001d
.
[HKEY_USERS\S-1-5-21-3545194168-222157450-2924182206-1001_Classes\Wow6432Node\CLSID\{ee3e00c3-d68e-4e3c-bb70-97d257f91d6d}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000028
"Therad"=dword:00000015
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\DAEMON Tools Pro\DTShellHlp.exe
.
**************************************************************************
.
Completion time: 2012-07-30 11:31:26 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-30 03:31
.
Pre-Run: 62,927,572,992 bytes free
Post-Run: 62,688,063,488 bytes free
.
- - End Of File - - F36F00D7193B3BB5731689CCC6B0FA3A