Thomas
Full Member
  

Gender: 
Posts: 233
|
 |
Re: please check my log
« Reply #1 on: Jun 28th, 2010, 8:13am » |
Quote Modify
|
ComboFix 10-06-25.02 - april 06/26/2010 2:04.1.2 - x86 Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.3034.1901 [GMT -5:00] Running from: c:\users\april\Desktop\ComboFix.exe SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\programdata\80308f4 c:\programdata\80308f4\210813.reg c:\programdata\80308f4\mcp.ico c:\programdata\80308f4\SM8030_314.exe c:\programdata\80308f4\SMAV.ico c:\programdata\80308f4\SMAVSys\vd952342.bd c:\users\april\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Security Master AV.lnk c:\users\april\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.drv c:\users\april\AppData\Roaming\Microsoft\Windows\Recent\cb.exe c:\users\april\AppData\Roaming\Microsoft\Windows\Recent\DBOLE.sys c:\users\april\AppData\Roaming\Microsoft\Windows\Recent\dudl.sys c:\users\april\AppData\Roaming\Microsoft\Windows\Recent\energy.dll c:\users\april\AppData\Roaming\Microsoft\Windows\Recent\exec.exe c:\users\april\AppData\Roaming\Microsoft\Windows\Recent\FS.exe c:\users\april\AppData\Roaming\Microsoft\Windows\Recent\FW.exe c:\users\april\AppData\Roaming\Microsoft\Windows\Recent\hymt.sys c:\users\april\AppData\Roaming\Microsoft\Windows\Recent\kernel32.dll c:\users\april\AppData\Roaming\Microsoft\Windows\Recent\pal.dll c:\users\april\AppData\Roaming\Microsoft\Windows\Recent\PE.drv c:\users\april\AppData\Roaming\Microsoft\Windows\Recent\PE.sys c:\users\april\AppData\Roaming\Microsoft\Windows\Recent\runddlkey.dll c:\users\april\AppData\Roaming\Microsoft\Windows\Recent\runddlkey.drv c:\users\april\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.drv c:\users\april\AppData\Roaming\Microsoft\Windows\Recent\SM.drv c:\users\april\AppData\Roaming\Microsoft\Windows\Start Menu\Security Master AV.lnk c:\users\april\AppData\Roaming\Security Master AV c:\users\april\AppData\Roaming\Security Master AV\Instructions.ini c:\users\april\Desktop\Security Master AV.lnk c:\windows\system32\st326162.dll . ((((((((((((((((((((((((( Files Created from 2010-05-26 to 2010-06-26 ))))))))))))))))))))))))))))))) . 2010-06-26 03:24 . 2010-06-26 03:24--------d-sh--w-c:\programdata\SMDCXPSFBTAV 2010-06-24 08:00 . 2009-11-08 15:5599176----a-w-c:\windows\system32\PresentationHostProxy.dll 2010-06-24 08:00 . 2009-11-08 15:5549472----a-w-c:\windows\system32\netfxperf.dll 2010-06-24 08:00 . 2009-11-08 15:55297808----a-w-c:\windows\system32\mscoree.dll 2010-06-24 08:00 . 2009-11-08 15:55295264----a-w-c:\windows\system32\PresentationHost.exe 2010-06-24 08:00 . 2009-11-08 15:551130824----a-w-c:\windows\system32\dfshim.dll 2010-06-23 13:20 . 2010-04-16 16:4328672----a-w-c:\windows\system32\Apphlpdm.dll 2010-06-23 13:20 . 2010-04-16 14:394240384----a-w-c:\windows\system32\GameUXLegacyGDFs.dll 2010-06-21 16:58 . 2010-06-24 14:43--------d-----w-c:\programdata\boost_interprocess 2010-06-21 16:57 . 2010-06-21 16:59--------d-----w-c:\users\april\AppData\Roaming\TigerPlayer 2010-06-21 16:57 . 2010-06-21 16:57--------d-----w-c:\programdata\Apple Computer 2010-06-21 16:56 . 2010-06-21 16:57--------d-----w-c:\program files\MpcStar 2010-06-21 16:55 . 2010-06-21 16:55--------d-----w-c:\program files\AC3Filter 2010-06-21 16:54 . 2010-06-21 16:5457344----a-w-c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll 2010-06-20 23:16 . 2010-06-20 23:16--------d-----w-c:\program files\uTorrent 2010-06-20 23:15 . 2010-06-24 00:59--------d-----w-c:\users\april\AppData\Roaming\uTorrent 2010-06-16 18:22 . 2010-06-16 18:22--------d-----w-c:\programdata\WindowsSearch 2010-06-15 01:32 . 2010-06-15 01:32--------d-----w-c:\program files\ZooskMessenger 2010-06-10 01:55 . 2010-04-05 17:0167072----a-w-c:\windows\system32\asycfilt.dll 2010-06-10 01:55 . 2010-05-26 17:0634304----a-w-c:\windows\system32\atmlib.dll 2010-06-10 01:55 . 2010-05-26 14:47289792----a-w-c:\windows\system32\atmfd.dll 2010-06-09 08:16 . 2010-06-09 08:16--------d-----w-c:\program files\YTK Enhanced 2010-06-06 13:29 . 2010-06-09 06:01--------d-----w-c:\program files\Veoh Networks 2010-06-04 02:46 . 2010-06-04 02:48--------d-----w-c:\program files\CCleaner 2010-06-03 17:14 . 2010-06-03 17:14--------d-----w-c:\program files\Mind Quiz 2010-06-02 01:34 . 2010-06-04 02:09--------d-----w-c:\program files\Microsoft Silverlight 2010-06-01 19:13 . 2010-06-09 07:00--------d-----w-c:\users\april\AppData\Roaming\YTK Enhanced 2010-05-30 14:10 . 2010-05-30 14:10--------d-----w-c:\users\april\AppData\Roaming\com.zoosk.Desktop.09 6E6A67431258A508A2446A847B240591D2C99B.1 2010-05-30 14:10 . 2010-05-30 14:0838784----a-w-c:\users\april\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe 2010-05-30 14:10 . 2010-05-30 14:10--------d-----w-c:\program files\Common Files\Adobe AIR . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-06-12 10:24 . 2010-05-21 14:07--------d-----w-c:\program files\SUPERAntiSpyware 2010-06-10 10:23 . 2006-11-02 11:18--------d-----w-c:\program files\Windows Mail 2010-06-08 15:23 . 2010-05-23 02:11--------d-----w-c:\program files\Digital Asphyxia 2010-06-04 22:10 . 2010-05-21 17:1663488----a-w-c:\users\april\AppData\Roaming\SUPERAntiSpyware.com\SU PERAntiSpyware\SDDLLS\SD10006.dll 2010-06-04 22:10 . 2010-05-21 17:16117760----a-w-c:\users\april\AppData\Roaming\SUPERAntiSpyware.com\S UPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2010-05-24 18:33 . 2010-05-24 18:33--------d-----w-c:\program files\Windows Portable Devices 2010-05-24 18:33 . 2006-11-02 10:25665600----a-w-c:\windows\inf\drvindex.dat 2010-05-24 18:33 . 2010-05-24 18:330---ha-w-c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf 2010-05-23 23:33 . 2006-11-02 12:35--------d-----w-c:\program files\Windows Sidebar 2010-05-23 23:33 . 2006-11-02 12:35--------d-----w-c:\program files\Windows Photo Gallery 2010-05-23 23:33 . 2006-11-02 12:35--------d-----w-c:\program files\Windows Collaboration 2010-05-23 23:33 . 2006-11-02 12:35--------d-----w-c:\program files\Windows Calendar 2010-05-23 23:33 . 2006-11-02 12:35--------d-----w-c:\program files\Windows Defender 2010-05-23 02:12 . 2010-05-23 02:12--------d-----w-c:\users\april\AppData\Roaming\Digital Asphyxia 2010-05-23 02:12 . 2010-05-23 02:12--------d-----w-c:\programdata\Digital Asphyxia 2010-05-23 02:11 . 2010-05-23 02:11--------d-----w-c:\programdata\Tarma Installer 2010-05-23 02:11 . 2010-05-23 02:1182432--s---r-c:\programdata\Tarma Installer\{D6B25B8D-0566-42B1-A23D-7576138435D6}\Setup.exe 2010-05-23 01:44 . 2010-05-23 01:44--------d-----w-c:\programdata\Yahoo! 2010-05-23 01:44 . 2010-05-23 01:44--------d-----w-c:\program files\Yahoo! 2010-05-22 00:23 . 2010-05-22 00:22--------d-----w-c:\program files\Common Files\Adobe 2010-05-21 19:14 . 2010-01-06 12:17221568------w-c:\windows\system32\MpSigStub.exe 2010-05-21 17:16 . 2010-05-21 17:1652224----a-w-c:\users\april\AppData\Roaming\SUPERAntiSpyware.com\SU PERAntiSpyware\SDDLLS\SD10005.dll 2010-05-21 14:07 . 2010-05-21 14:07--------d-----w-c:\programdata\SUPERAntiSpyware.com 2010-05-21 14:07 . 2010-05-21 14:07--------d-----w-c:\users\april\AppData\Roaming\SUPERAntiSpyware.com 2010-05-21 14:07 . 2010-05-21 14:07--------d-----w-c:\program files\Common Files\Wise Installation Wizard 2010-05-16 16:24 . 2010-05-16 16:24--------d-----w-c:\programdata\EmailNotifier 2010-05-16 16:23 . 2010-05-16 16:2318944----a-r-c:\users\april\AppData\Roaming\Microsoft\Installer\{8F 018A9E-56DE-4A79-A5EF-25F413F1D538}\IconBB6A16301.exe 2010-05-13 04:38 . 2010-05-13 04:37--------d-----w-c:\users\april\AppData\Roaming\MySpace 2010-05-13 04:37 . 2010-05-13 04:37--------d-----w-c:\programdata\Roaming 2010-05-13 04:36 . 2010-05-13 04:337631232----a-w-c:\users\april\AppData\Roaming\MySpace\IM\Install\MS IMClientSetup.1.0.823.0-static-A.exe 2010-05-09 22:09 . 2010-05-09 22:07--------d-----w-c:\users\april\AppData\Roaming\Yahoo! 2010-05-09 22:07 . 2010-05-09 22:07262144----a-w-c:\programdata\ntuser.dat 2010-05-04 05:59 . 2010-06-10 01:59916480----a-w-c:\windows\system32\wininet.dll 2010-05-04 05:55 . 2010-06-10 01:5971680----a-w-c:\windows\system32\iesetup.dll 2010-05-04 05:55 . 2010-06-10 01:59109056----a-w-c:\windows\system32\iesysprep.dll 2010-05-04 04:31 . 2010-06-10 01:59133632----a-w-c:\windows\system32\ieUnatt.exe 2010-05-01 14:13 . 2010-06-10 01:592037248----a-w-c:\windows\system32\win32k.sys 2010-04-23 14:13 . 2010-05-26 02:262048----a-w-c:\windows\system32\tzres.dll 2010-04-20 20:45 . 2010-05-23 01:44607472----a-w-c:\programdata\Yahoo!\YUpdater\yupdater.exe 2010-04-16 16:43 . 2010-06-23 13:20173056----a-w-c:\windows\AppPatch\AcXtrnal.dll 2010-04-16 16:43 . 2010-06-23 13:20458752----a-w-c:\windows\AppPatch\AcSpecfc.dll 2010-04-16 16:43 . 2010-06-23 13:20542720----a-w-c:\windows\AppPatch\AcLayers.dll 2010-04-16 16:43 . 2010-06-23 13:202159616----a-w-c:\windows\AppPatch\AcGenral.dll 2010-04-12 21:29 . 2010-04-26 12:57411368----a-w-c:\windows\system32\deployJava1.dll 2010-01-05 04:05 . 2009-04-11 19:018192--sha-w-c:\windows\Users\Default\NTUSER.DAT . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-06-12 2403568] "VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2010-04-28 2633976] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2009-04-01 217088] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-04-01 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-04-01 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-04-01 150552] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040] "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-12-22 3810304] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-05-07 178712] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-04-01 483428] "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 2 (0x2) "EnableUIADesktopToggle"= 0 (0x0) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 19:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer"=wdmaud.drv [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "VistaSp2"=hex(b):ef,a7,1f,07,d1,fa,ca,01 R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x] R2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32coinst,serviceStartProc [x] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-28 67656] S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef805 6\aestsrv.exe [2009-04-01 81920] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetworkREG_MULTI_SZ PLA DPS BFE mpssvc LocalServiceAndNoImpersonationREG_MULTI_SZ FontCache . Contents of the 'Scheduled Tasks' folder 2010-06-26 c:\windows\Tasks\User_Feed_Synchronization-{62D09183-134D-4599-AA15-5ED0 E9810CAB}.job - c:\windows\system32\msfeedssync.exe [2010-06-10 04:30] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.yahoo.com/?ilc=1 IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsid ewiki.html DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab . - - - - ORPHANS REMOVED - - - - BHO-{CC3C8D60-29D6-4880-B9D8-443C4CBA2BEC} - (no file) HKCU-Run-Security Master AV - c:\programdata\80308f4\SM8030_314.exe ************************************************************************ ** scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: ************************************************************************ ** . Completion time: 2010-06-26 02:09:48 ComboFix-quarantined-files.txt 2010-06-26 07:09 Pre-Run: 165,977,063,424 bytes free Post-Run: 165,972,713,472 bytes free - - End Of File - - 1E72C8B7A8BD95C95D07BA05B27D5B4C
|