2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.34.3082.18.1014.372 [GMT -5:0
0]
Running from: c:\users\Burbano\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Outdated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Disabled/Outdated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
[i] ADS - system32: deleted 12 bytes in 1 streams. [/i]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))
)))))))))))))))))))))))))))))
.
.
c:\windows\system32\oobe\audit.exe
c:\windows\system32\oobe\msoobe.exe
c:\windows\system32\oobe\oobeldr.exe
c:\windows\system32\oobe\Setup.exe
c:\windows\system32\oobe\setupsqm.exe
c:\windows\system32\oobe\windeploy.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-02-02 to 2012-03-02 )))))))
))))))))))))))))))))))))
.
.
2012-03-02 22:56 . 2012-03-02 22:56
-------d-----wc:\users
\Public\AppData\Local\temp
2012-03-02 22:56 . 2012-03-02 22:56
-------d-----wc:\users
\Default\AppData\Local\temp
2012-03-02 21:33 . 2010-05-06 20:41
307280 ----a-wc:\windows\syste
m32\drivers\aswSnx.sys
2012-03-02 21:32 . 2012-03-02 21:32
-------d-----wc:\progr
amdata\Alwil Software
2012-03-02 20:56 . 2010-05-06 20:34
23376 ----a-wc:\windows\syste
m32\drivers\aswRdr.sys
2012-03-02 20:56 . 2010-05-06 20:39
46672 ----a-wc:\windows\syste
m32\drivers\aswTdi.sys
2012-03-02 20:56 . 2010-05-06 20:59
38848 ----a-wc:\windows\syste
m32\avastSS.scr
2012-03-02 20:56 . 2010-05-06 20:39
164048 ----a-wc:\windows\syste
m32\drivers\aswSP.sys
2012-03-02 20:56 . 2010-05-06 20:33
19024 ----a-wc:\windows\syste
m32\drivers\aswFsBlk.sys
2012-03-02 20:55 . 2010-05-06 20:59
165032 ----a-wc:\windows\syste
m32\aswBoot.exe
2012-03-02 20:55 . 2010-05-06 20:34
51792 ----a-wc:\windows\syste
m32\drivers\aswMonFlt.sys
2012-03-02 20:55 . 2004-01-09 09:13
380928 ----a-wc:\windows\syste
m32\actskin4.ocx
2012-03-02 20:55 . 2012-03-02 21:35
-------d-----wc:\progr
am files\Alwil Software
2012-02-12 19:05 . 2012-02-12 19:06
-------dc-h--wc:\progr
amdata\{B49A644A-1076-4A3D-B124-DAA7862F2318}
2012-02-12 19:05 . 2012-02-12 19:05
-------d-----wc:\progr
am files\iLivid
2012-02-12 19:03 . 2012-02-12 19:03
-------d-----wc:\users
\Burbano\AppData\Local\PackageAware
2012-02-12 18:51 . 2012-02-12 18:51
-------d-----wc:\users
\Burbano\AppData\Roaming\Globe7
2012-02-12 18:50 . 2012-02-12 18:54
-------d-----wc:\progr
am files\Globe7
2012-02-12 03:00 . 2012-02-12 03:00
-------d-----wc:\users
\Burbano\AppData\Roaming\JCreator
2012-02-12 03:00 . 2012-02-12 03:00
-------d-----wc:\progr
amdata\JCreator
2012-02-12 02:58 . 2012-02-12 02:58
-------d-----wc:\progr
am files\Xinox Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))
)))))))))))))))))))))))))))))))
.
2012-01-31 12:44 . 2011-09-17 17:04
237072 ------wc:\windows\syste
m32\MpSigStub.exe
2011-12-05 14:42 . 2011-09-17 21:28
134104 ----a-wc:\program files
\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))
)))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellicon
overlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2011-05-30 16:50
21864 ----a-wc:\program files\Internet Downlo
ad Manager\IDMShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellicon
overlayidentifiers\snxPluginsShell]
@="{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}"
[HKEY_CLASSES_ROOT\CLSID\{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}]
2010-05-06 21:02
151648 ----a-wc:\program files\Alwil Software\
Avast5\snxPlugins.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"NokiaSuite.exe"="c:\program files\Nokia\Nokia Suite\NokiaSuite.exe" [2012-01-10
1083264]
"HW_OPENEYE_OUC_Mobile Partner"="c:\program files\Mobile Partner\UpdateDog\ouc.e
xe" [2009-07-27 110592]
"PSwitch"="c:\program files\Proxy Switcher Standard\ProxySwitcher.exe" [2012-0104 5299768]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 9
1520]
"USB Antivirus"="c:\program files\USB Disk Security\RunUSBGuard.exe" [2010-06-04
91040]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-09-03 1557800]
yware.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS --------------------.
[HKEY_USERS\S-1-5-21-1352276995-808599099-2034238897-1000_Classes\CLSID\{27243c5
b-0f74-458a-9e5f-01b4ff328e03}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:0000014a
"Therad"=dword:00000010
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
[HKEY_USERS\S-1-5-21-1352276995-808599099-2034238897-1000_Classes\CLSID\{7B8E916
4-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):9f,28,ef,6c,48,90,c2,65,c2,93,4a,ee,c6,33,da,31,ef,40,fd,81,06,
00,63,27,38,20,13,fb,67,0e,4c,93,20,a8,4b,be,2a,4b,dc,14,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-03-02 18:04:56
ComboFix-quarantined-files.txt 2012-03-02 23:04
ComboFix2.txt 2011-10-28 14:44
ComboFix3.txt 2011-09-03 21:28
ComboFix4.txt 2011-09-03 21:11
ComboFix5.txt 2012-03-02 22:22
.
Pre-Run: 9.885.032.448 bytes libres
Post-Run: 10.380.439.552 bytes libres
.
- - End Of File - - CA29C0A46DA805759FE74E77255D4999