Report from ComboFixComboFix 12-07-07.04 - pc 8.07.2012. 4:41.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.387.1033.18.1917.1016 [GMT 2:00]
Running from: c:\users\pc\Desktop\ComboFix.exe
Command switches used :: c:\users\pc\Desktop\CFScript.txt
AV: ESET Smart Security 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET Personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Common Files\Spigot
c:\program files\Common Files\Spigot\GC\coupons_1.0.crx
c:\program files\Common Files\Spigot\Search Settings\baidu_ff.xml
c:\program files\Common Files\Spigot\Search Settings\baidu_ie.xml
c:\program files\Common Files\Spigot\Search Settings\config.ini
c:\program files\Common Files\Spigot\Search Settings\Lang\res1031.ini
c:\program files\Common Files\Spigot\Search Settings\Lang\res1033.ini
c:\program files\Common Files\Spigot\Search Settings\Lang\res1034.ini
c:\program files\Common Files\Spigot\Search Settings\Lang\res1036.ini
c:\program files\Common Files\Spigot\Search Settings\Lang\res1040.ini
c:\program files\Common Files\Spigot\Search Settings\wth.dll
c:\program files\Common Files\Spigot\Search Settings\yahoo_ff.xml
c:\program files\Common Files\Spigot\Search Settings\yahoo_ie.xml
c:\program files\Common Files\Spigot\Search Settings\yandex_ff.xml
c:\program files\Common Files\Spigot\Search Settings\yandex_ie.xml
c:\program files\Common Files\Spigot\wtxpcom\chrome.manifest
c:\program files\Common Files\Spigot\wtxpcom\components\chrome.manifest
c:\program files\Common Files\Spigot\wtxpcom\components\IFBHOHelperWidgiToolbar.xpt
c:\program files\Common Files\Spigot\wtxpcom\components\IFBHOWidgiToolbar.xpt
c:\program files\Common Files\Spigot\wtxpcom\components\install.rdf
c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll
c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.10
c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.11
c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.12
c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.13
c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.14
c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.5
c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.6
c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.7
c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.8
c:\program files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.9
c:\program files\Common Files\Spigot\wtxpcom\install.rdf
c:\program files\YouTube Downloader Toolbar
c:\program files\YouTube Downloader Toolbar\FF\chrome.manifest
c:\program files\YouTube Downloader Toolbar\FF\chrome\chrome.jar
c:\program files\YouTube Downloader Toolbar\FF\install.rdf
c:\program files\YouTube Downloader Toolbar\IE\5.8\config.ini
c:\program files\YouTube Downloader Toolbar\Res\amazon.gif
c:\program files\YouTube Downloader Toolbar\Res\dailymotion.gif
c:\program files\YouTube Downloader Toolbar\Res\dropinsavings.gif
c:\program files\YouTube Downloader Toolbar\Res\dropinsavingsabt.gif
c:\program files\YouTube Downloader Toolbar\Res\ebay.gif
c:\program files\YouTube Downloader Toolbar\Res\facebook.gif
c:\program files\YouTube Downloader Toolbar\Res\googleplus.gif
c:\program files\YouTube Downloader Toolbar\Res\hulu.gif
c:\program files\YouTube Downloader Toolbar\Res\icon_settings.gif
c:\program files\YouTube Downloader Toolbar\Res\Lang\res1031.ini
c:\program files\YouTube Downloader Toolbar\Res\Lang\res1033.ini
c:\program files\YouTube Downloader Toolbar\Res\Lang\res1034.ini
c:\program files\YouTube Downloader Toolbar\Res\Lang\res1036.ini
c:\program files\YouTube Downloader Toolbar\Res\Lang\res1040.ini
c:\program files\YouTube Downloader Toolbar\Res\metacafe.gif
c:\program files\YouTube Downloader Toolbar\Res\radio-close.gif
c:\program files\YouTube Downloader Toolbar\Res\radio-minimize.gif
c:\program files\YouTube Downloader Toolbar\Res\radiobeta.gif
c:\program files\YouTube Downloader Toolbar\Res\search-button-hover.gif
c:\program files\YouTube Downloader Toolbar\Res\search-button.gif
c:\program files\YouTube Downloader Toolbar\Res\search-chevron-hover.gif
c:\program files\YouTube Downloader Toolbar\Res\search-chevron.gif
c:\program files\YouTube Downloader Toolbar\Res\search_amazon.gif
c:\program files\YouTube Downloader Toolbar\Res\search_baidu.gif
c:\program files\YouTube Downloader Toolbar\Res\search_ebay.gif
c:\program files\YouTube Downloader Toolbar\Res\search_yahoo.gif
c:\program files\YouTube Downloader Toolbar\Res\search_yandex.gif
c:\program files\YouTube Downloader Toolbar\Res\search_youtube.gif
c:\program files\YouTube Downloader Toolbar\Res\twitter.gif
c:\program files\YouTube Downloader Toolbar\Res\veoh.gif
c:\program files\YouTube Downloader Toolbar\Res\widgets.xml
c:\program files\YouTube Downloader Toolbar\Res\youtube.gif
c:\program files\YouTube Downloader Toolbar\Res\ytd.gif
c:\program files\YouTube Downloader Toolbar\Res\ytd_logo.gif
c:\program files\YouTube Downloader Toolbar\Res\ytd_logo_hover.gif
c:\program files\YouTube Downloader Toolbar\WidgiHelper.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-06-08 to 2012-07-08 )))))))))))))))))))))))))))))))
.
.
2012-07-08 02:46 . 2012-07-08 02:46 -------- d-----w- c:\users\dzovko\AppData\Local\temp
2012-07-08 02:46 . 2012-07-08 02:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-07-08 02:46 . 2012-07-08 02:46 -------- d-----w- c:\users\ctn\AppData\Local\temp
2012-07-08 02:46 . 2012-07-08 02:46 -------- d-----w- c:\users\bigbrother\AppData\Local\temp
2012-07-06 18:39 . 2012-07-08 02:46 -------- d-----w- c:\users\pc\AppData\Local\temp
2012-07-05 08:58 . 2012-07-05 08:58 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-06-29 08:50 . 2012-06-29 08:50 -------- d-----w- c:\users\pc\AppData\Roaming\Malwarebytes
2012-06-29 08:50 . 2012-06-29 08:50 -------- d-----w- c:\programdata\Malwarebytes
2012-06-28 15:26 . 2012-06-28 15:26 -------- d-----w- c:\program files\Common Files\Corel
2012-06-28 15:25 . 2012-06-28 15:25 -------- d-----w- c:\program files\Common Files\Protexis
2012-06-28 15:18 . 2012-06-28 15:18 -------- d-----w- c:\program files\Corel
2012-06-28 02:25 . 2012-06-28 02:25 -------- d-sh--w- c:\windows\system32\%APPDATA%
2012-06-27 02:12 . 2004-06-17 10:01 2260992 ----a-w- c:\program files\WWIISniper.exe
2012-06-27 02:12 . 2004-08-12 11:58 1814528 ----a-w- c:\program files\Lithtech.exe
2012-06-27 02:11 . 2012-06-27 02:11 -------- d-----w- c:\program files\Profiles
2012-06-27 02:11 . 2003-08-08 13:31 405504 ----a-w- c:\program files\Server.dll
2012-06-27 02:11 . 2001-09-28 15:00 164864 ----a-w- c:\program files\UNWISE.EXE
2012-06-26 00:10 . 2012-06-28 02:21 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-26 00:10 . 2012-06-28 02:21 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-25 09:08 . 2012-06-25 09:08 -------- d-----w- c:\program files\Smart Projects
2012-06-23 09:08 . 2012-07-06 23:57 -------- d-----w- c:\program files\JDownloader
2012-06-22 09:50 . 2012-06-22 09:50 -------- d-----w- c:\users\pc\AppData\Roaming\WinAVI
2012-06-22 09:50 . 2012-06-22 09:50 -------- d-----w- c:\users\pc\AppData\Local\WinAVI
2012-06-22 09:34 . 2012-06-22 09:34 -------- d-----w- c:\users\pc\AppData\Roaming\AVS4YOU
2012-06-22 09:34 . 2012-06-22 09:34 -------- d-----w- c:\programdata\AVS4YOU
2012-06-22 09:33 . 2012-06-22 10:05 -------- d-----w- c:\program files\Common Files\AVSMedia
2012-06-22 09:33 . 2011-06-23 18:24 1700352 ----a-w- c:\windows\system32\GdiPlus.dll
2012-06-22 09:33 . 2011-06-23 18:24 24576 ----a-w- c:\windows\system32\msxml3a.dll
2012-06-22 09:33 . 2012-06-22 10:05 -------- d-----w- c:\program files\AVS4YOU
2012-06-22 09:29 . 2012-06-22 09:29 -------- d-----w- c:\program files\uTorrent
2012-06-22 09:28 . 2012-07-05 07:55 -------- d-----w- c:\users\pc\AppData\Roaming\uTorrent
2012-06-17 23:40 . 2012-06-27 03:17 -------- d-----w- c:\programdata\Big Fish Games
2012-06-17 18:52 . 2012-06-17 18:52 -------- d-----w- c:\users\pc\AppData\Local\Macromedia
2012-06-17 18:30 . 2012-06-17 18:35 -------- d-----w- c:\users\pc\AppData\Roaming\DMCache
2012-06-15 23:16 . 2012-06-15 23:20 -------- d-----w- c:\programdata\Protexis
2012-06-15 23:16 . 2012-06-15 23:16 -------- d-----w- c:\users\pc\AppData\Roaming\Corel
2012-06-15 23:10 . 2012-06-15 23:10 -------- d-----w- c:\program files\Microsoft SDKs
2012-06-15 23:10 . 2012-06-15 23:11 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0
2012-06-15 23:09 . 2012-06-28 15:25 -------- d-----w- c:\programdata\Corel
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-17 21:03 . 2012-05-11 14:15 85472 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-08-09 3076144]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"Smart File Advisor"="c:\program files\Smart File Advisor\sfa.exe" [2011-04-04 280824]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
.
c:\users\ctn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2011-3-1 576000]
.
c:\users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Media Player.lnk - c:\program files\Adobe Media Player\Adobe Media Player.exe [N/A]
iVMS-4000(v2.0).lnk - c:\program files\iVMS-4000(v2.0)\NetAppSoft.exe [2011-4-5 8327168]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 gupdate;Usluga Google ažuriranje (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R2 Web Assistant Updater;Web Assistant Updater;c:\program files\Web Assistant\ExtensionUpdaterService.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\7.1.362.0\SeaPort.exe [x]
R3 gupdatem;Usluga Google ažuriranje (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [x]
S2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [x]
S2 Autodesk Content Service;Autodesk Content Service;c:\program files\Autodesk\Content Service\Connect.Service.ContentService.exe [x]
S2 BBSvc;BingBar Service;c:\program files\Microsoft\BingBar\7.1.362.0\BBSvc.exe [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [x]
S2 TeamViewer7;TeamViewer 7;c:\program files\TeamViewer\Version7\TeamViewer_Service.exe [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-08 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-26 02:21]
.
2012-07-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-04-16 12:49]
.
2012-07-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-04-16 12:49]
.
.
------- Supplementary Scan -------
.
uStart Page =
https://accounts.google.com/ServiceLogin?service=mail&passive=true&rm=false&continue=hxxp://mail.google.com/mail/&scc=1<mpl=default<mplcache=2mStart Page = hxxp://startsear.ch/?aff=1&cf=f9388a60-3486-11e1-bc77-4487fcf8aa7e
IE: Download with &Media Finder - c:\program files\Media Finder\hook.html
TCP: Interfaces\{062F7739-7E59-41FA-A804-0DC890724D6C}: NameServer = 212.39.98.161,212.39.98.162
DPF: {CAFCF48D-8E34-4490-8154-026191D73924} - hxxp://192.168.120.81/codebase/NetVideoActiveX_V23.cab
FF - ProfilePath - c:\users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\502dw7pr.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p=
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-07-08 04:48:14
ComboFix-quarantined-files.txt 2012-07-08 02:48
ComboFix2.txt 2012-07-06 18:46
.
Pre-Run: 357.758.357.504 bytes free
Post-Run: 397.429.792.768 bytes free
.
- - End Of File - - E0F0B6D39BD065A9C83DA7B6EA078386
With no problems.
Alert from first post didn't appeared since my first ComboFix start, your second post. Everything seems to be fine at the moment.