ComboFix 11-12-19.01 - Samuli 19.12.2011 13:41:09.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.358.1033.18.8105.6264 [GMT 2:00]
Sijainti: c:\users\Samuli\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2011-11-19 to 2011-12-19 )))))))))))))))))
.
.
2011-12-19 11:44 . 2011-12-19 11:44 69000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{48AEC0D3-4555-4126-9118-28380CFDAB12}\offreg.dll
2011-12-19 11:43 . 2011-12-19 11:43 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-12-19 11:26 . 2011-12-19 11:36 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-12-19 11:26 . 2011-12-19 11:27 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2011-12-18 22:45 . 2011-12-18 22:45 917840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BCE47E93-41D4-4E60-9DD7-7EF3977D3B6E}\gapaengine.dll
2011-12-18 22:45 . 2011-11-21 01:40 8822856 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{48AEC0D3-4555-4126-9118-28380CFDAB12}\mpengine.dll
2011-12-18 22:44 . 2011-12-18 22:44 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2011-12-18 22:44 . 2011-12-18 22:44 -------- d-----w- c:\program files\Microsoft Security Client
2011-12-16 09:30 . 2011-11-21 11:40 8822856 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D78D2C31-84DD-4265-B13D-F8D0A73AE8B3}\mpengine.dll
2011-12-15 18:45 . 2011-10-15 06:31 723456 ----a-w- c:\windows\system32\EncDec.dll
2011-12-15 18:45 . 2011-10-15 05:38 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-12-15 18:45 . 2011-11-24 04:52 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-12-15 18:45 . 2011-11-05 05:32 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-15 18:45 . 2011-11-05 04:26 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-12-12 19:25 . 2011-12-12 19:25 -------- d-----w- c:\program files\TeamSpeak 3 Client
2011-12-07 20:19 . 2011-12-07 20:19 -------- d-----w- c:\programdata\Malwarebytes
2011-12-07 20:19 . 2011-12-07 20:19 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-12-07 20:19 . 2011-08-31 15:00 25416 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-07 15:57 . 2011-12-07 15:57 -------- d-----w- c:\program files (x86)\Common Files\InstallShield
2011-12-07 13:01 . 2011-12-07 13:01 -------- d-----w- c:\programdata\Origin
2011-12-07 13:01 . 2011-12-07 13:01 -------- d-----w- c:\programdata\Electronic Arts
2011-12-07 13:01 . 2011-12-07 13:01 -------- d-----w- c:\program files (x86)\Origin Games
2011-12-07 13:00 . 2011-12-07 13:01 -------- d-----w- c:\program files (x86)\Origin
2011-12-01 15:30 . 2011-12-01 15:30 -------- d-----w- c:\program files (x86)\Lavalys
2011-11-27 14:59 . 2011-11-27 14:59 -------- d-----w- c:\windows\system32\SPReview
2011-11-27 14:58 . 2011-11-27 14:58 -------- d-----w- c:\windows\system32\EventProviders
2011-11-23 21:28 . 2011-11-23 21:28 -------- d-----w- c:\program files (x86)\Common Files\Steam
2011-11-23 14:08 . 2011-11-23 14:08 -------- d-----w- c:\program files (x86)\Etron Technology
2011-11-23 14:07 . 2011-02-22 09:59 8192 ----a-w- c:\windows\system32\drivers\IntelMEFWVer.dll
2011-11-23 14:07 . 2011-11-23 14:07 -------- d-----w- c:\program files (x86)\Common Files\postureAgent
2011-11-23 14:07 . 2010-10-19 14:34 56344 ----a-w- c:\windows\system32\drivers\HECIx64.sys
2011-11-23 14:06 . 2011-04-21 18:17 74272 ----a-w- c:\windows\system32\RtNicProp64.dll
2011-11-23 14:06 . 2011-04-21 18:17 471144 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2011-11-23 14:06 . 2011-04-21 18:17 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2011-11-23 14:06 . 2011-11-23 14:06 -------- d-----w- c:\program files (x86)\Realtek
2011-11-23 14:05 . 2011-11-23 14:11 -------- d-----w- c:\program files (x86)\Intel
2011-11-23 14:05 . 2010-12-23 03:09 53248 ----a-r- c:\windows\SysWow64\CSVer.dll
2011-11-23 14:05 . 2011-11-23 14:05 -------- d-----w- C:\Intel
2011-11-21 18:58 . 2011-11-21 18:58 -------- d-----w- c:\program files\7-Zip
2011-11-20 21:50 . 2011-11-20 21:50 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2011-11-20 13:51 . 2010-11-20 13:27 229888 ----a-w- c:\windows\system32\XpsRasterService.dll
2011-11-20 13:50 . 2010-11-20 12:21 363008 ----a-w- c:\windows\SysWow64\wbemcomn.dll
2011-11-20 13:50 . 2010-11-20 12:21 189952 ----a-w- c:\program files (x86)\Windows Portable Devices\sqmapi.dll
2011-11-20 13:50 . 2010-11-20 12:19 606208 ----a-w- c:\windows\SysWow64\wbem\fastprox.dll
2011-11-20 13:50 . 2010-11-20 13:27 244736 ----a-w- c:\program files\Windows Portable Devices\sqmapi.dll
2011-11-20 13:50 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll
2011-11-20 13:50 . 2010-11-20 13:27 244736 ----a-w- c:\windows\system32\sqmapi.dll
2011-11-20 13:30 . 2011-11-21 21:32 -------- d-----w- c:\program files (x86)\Microsoft Works
2011-11-20 13:30 . 2011-11-20 13:30 -------- d-----w- c:\windows\PCHEALTH
2011-11-20 13:30 . 2011-11-20 13:30 -------- d-----w- c:\program files (x86)\Microsoft.NET
2011-11-20 13:28 . 2011-11-20 13:28 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2011-11-20 13:28 . 2011-12-15 20:14 -------- d-----w- c:\programdata\Microsoft Help
2011-11-20 13:27 . 2011-11-20 13:27 -------- d-----r- C:\MSOCache
2011-11-20 02:29 . 2011-11-19 16:39 -------- d-----w- c:\windows\Panther
2011-11-19 19:40 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2011-11-19 17:58 . 2008-07-12 06:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll
2011-11-19 17:58 . 2008-07-12 06:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2011-11-19 17:58 . 2008-07-12 06:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll
2011-11-19 17:54 . 2011-11-19 17:54 -------- d-----w- C:\Riot Games
2011-11-19 17:54 . 2011-12-07 15:59 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
2011-11-19 17:44 . 2010-12-17 11:40 715776 ----a-w- c:\windows\system32\kerberos.dll
2011-11-19 17:44 . 2010-12-17 07:07 542208 ----a-w- c:\windows\SysWow64\kerberos.dll
2011-11-19 17:38 . 2011-04-29 05:55 1110528 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2011-11-19 17:38 . 2011-04-29 04:57 759296 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2011-11-19 17:35 . 2011-02-19 12:03 46080 ----a-w- c:\windows\system32\atmlib.dll
2011-11-19 17:35 . 2011-02-19 09:00 367616 ----a-w- c:\windows\system32\atmfd.dll
2011-11-19 17:35 . 2011-02-19 06:30 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2011-11-19 17:35 . 2011-02-19 04:34 294912 ----a-w- c:\windows\SysWow64\atmfd.dll
2011-11-19 17:35 . 2010-09-30 10:41 100864 ----a-w- c:\windows\system32\fontsub.dll
2011-11-19 17:35 . 2010-09-30 06:47 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
2011-11-19 17:32 . 2011-02-05 17:10 642944 ----a-w- c:\windows\system32\winload.efi
2011-11-19 17:31 . 2011-05-24 11:42 404480 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-11-19 17:29 . 2011-11-19 17:29 -------- d-----w- c:\program files (x86)\uTorrent
2011-11-19 17:28 . 2011-06-23 05:43 5561216 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-11-19 17:28 . 2011-06-23 04:33 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-11-19 17:28 . 2011-06-23 04:33 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-11-19 17:28 . 2011-11-19 17:28 279616 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-11-19 17:28 . 2011-11-19 17:28 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2011-11-19 17:27 . 2011-11-19 17:27 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-11-19 17:25 . 2011-11-19 17:25 -------- d-----w- c:\programdata\SafeNet Sentinel
2011-11-19 17:24 . 2011-11-19 17:25 -------- d-----w- c:\program files (x86)\Common Files\TI Shared
2011-11-19 17:24 . 2011-11-19 17:24 142848 ----a-w- c:\windows\system32\drivers\tinspusb.sys
2011-11-19 17:24 . 2011-11-19 17:24 -------- d-----w- c:\programdata\TI-Nspire
2011-11-19 17:24 . 2011-11-19 17:24 89088 ----a-w- c:\windows\SysWow64\atl71.dll
2011-11-19 17:24 . 2011-11-19 17:24 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
2011-11-19 17:24 . 2011-11-19 17:24 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
2011-11-19 17:24 . 2011-11-19 17:24 1060864 ----a-w- c:\windows\SysWow64\MFC71.dll
2011-11-19 17:24 . 2011-11-19 17:24 1047552 ----a-w- c:\windows\SysWow64\MFC71u.dll
2011-11-19 17:24 . 2011-11-19 17:24 -------- d-----w- c:\program files (x86)\TI Education
2011-11-19 17:24 . 2011-12-18 15:04 -------- d-----w- c:\programdata\PMB Files
2011-11-19 17:24 . 2011-11-19 17:24 -------- d-----w- c:\program files (x86)\Pando Networks
2011-11-19 17:21 . 2010-10-19 20:51 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-11-19 17:18 . 2011-11-19 17:18 -------- d-----r- c:\program files (x86)\Skype
2011-11-19 17:18 . 2011-11-19 17:18 -------- d-----w- c:\programdata\Skype
2011-11-19 17:00 . 2011-12-18 22:44 -------- d-sh--w- c:\windows\Installer
2011-11-19 17:00 . 2011-12-19 11:44 -------- d-----w- c:\programdata\NVIDIA
2011-11-19 17:00 . 2011-11-19 20:08 -------- d-----w- c:\users\UpdatusUser
2011-11-19 17:00 . 2011-11-23 14:03 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2011-11-19 16:58 . 2011-11-19 16:58 -------- d-----w- C:\NVIDIA
2011-11-19 16:43 . 2011-11-19 18:14 -------- d-----w- c:\users\Samuli
2011-11-19 16:41 . 2011-11-19 16:41 -------- d-----w- C:\Recovery
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-27 15:04 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-11-27 15:04 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-10-15 08:53 . 2011-11-19 16:59 1640768 ----a-w- c:\windows\system32\nvvsvc.exe
2011-10-14 22:54 . 2011-10-14 22:54 321856 ----a-w- c:\windows\SysWow64\nvStreaming.exe
.
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]
"Steam"="i:\program files (x86)\Steam\Steam.exe" [2011-11-23 1242448]
"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
R2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-22 2656280]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 USBTINSP;TI-Nspire(TM) Handheld or TI Network Bridge Device Driver;c:\windows\system32\DRIVERS\tinspusb.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [x]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
'Ajoitetut tehtävät'-kansion sisältö
.
2011-12-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1189429063-4266591580-2574035882-1000Core.job
- c:\users\Samuli\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-19 17:04]
.
2011-12-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1189429063-4266591580-2574035882-1000UA.job
- c:\users\Samuli\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-19 17:04]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-12 168216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-12 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-12 416024]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Täydentävä tarkistus -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 62.241.198.246 62.241.198.245
.
- - - - POISTETUT JÄMÄRIVIT - - - -
.
Notify-igfxcui - (no file)
AddRemove-Sonic Generations_is1 - i:\program files (x86)\Sonic Generations\unins000.exe
.
.
.
--------------------- LUKITUT REKISTERIAVAIMET ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Muut prosessit ------------------------
.
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Valmistumisajankohta: 2011-12-19 13:47:17 - kone käynnistettiin uudelleen
ComboFix-quarantined-files.txt 2011-12-19 11:47
.
Ennen ajoa: 335 465 598 976 bytes free
Ajon jälkeen: 335 493 410 816 bytes free
.
- - End Of File - - 43C3B89F1BEC50EB02AFAF8C576D1D76
I did some research and found out that these two are false
2011-10-15 08:53 . 2011-11-19 16:59 1640768 ----a-w- c:\windows\system32\nvvsvc.exe
2011-10-14 22:54 . 2011-10-14 22:54 321856 ----a-w- c:\windows\SysWow64\nvStreaming.exe
I went on and deleted both of them, shut down the service and process + removed the files after. So what should I do next to ensure I am safe?? I am so annoyed by this. Thanks!

Help
This topic is locked

Back to top









