CODE
ComboFix 10-06-02.04 - NickHDoan 06/03/2010 9:17.1.2 - x86 NETWORK
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.1983.1632 [GMT -5:00]
Running from: c:\users\NickHDoan\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2010-05-03 to 2010-06-03 )))))))))))))))))))))))))))))))
.
2010-06-03 14:21 . 2010-06-03 14:21 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-06-03 13:05 . 2010-06-03 13:05 57560 ----a-w- c:\users\NickHDoan\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-03 07:34 . 2010-06-03 04:51 -------- d-----w- c:\windows\Panther
2010-06-03 05:24 . 2010-06-03 05:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-03 05:24 . 2009-07-24 15:49 114688 ----a-w- c:\windows\system32\RicohMediadriverVer.dll
2010-06-03 05:24 . 2009-06-25 21:58 48128 ----a-w- c:\windows\system32\drivers\rimmptsk.sys
2010-06-03 05:24 . 2009-06-25 21:25 38400 ----a-w- c:\windows\system32\drivers\rixdptsk.sys
2010-06-03 05:24 . 2009-06-25 21:10 44544 ----a-w- c:\windows\system32\drivers\rimsptsk.sys
2010-06-03 05:24 . 2007-07-25 17:48 172032 ----a-w- c:\windows\system32\rixdicon.dll
2010-06-03 05:24 . 2004-09-04 08:00 90112 ----a-w- c:\windows\system32\snymsico.dll
2010-06-03 05:20 . 2008-07-08 06:45 4984 ----a-w- c:\windows\system32\drivers\nvphy.bin
2010-06-03 05:20 . 2008-08-27 18:58 453152 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-06-03 05:20 . 2010-06-03 05:20 -------- d-----w- C:\NVIDIA
2010-06-03 05:12 . 2010-06-03 13:20 -------- d-----w- c:\users\NickHDoan\AppData\Local\ElevatedDiagnostics
2010-06-03 05:06 . 2010-06-03 14:13 -------- d-----w- c:\windows\system32\wbem\Performance
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
.
- - - - ORPHANS REMOVED - - - -
HKLM-RunOnce-<NO NAME> - (no file)
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-06-03 09:22:47
ComboFix-quarantined-files.txt 2010-06-03 14:22
Pre-Run: 150,675,288,064 bytes free
Post-Run: 150,599,467,008 bytes free
- - End Of File - - FDF29490B19744F40677B8AC17209152
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.1983.1632 [GMT -5:00]
Running from: c:\users\NickHDoan\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2010-05-03 to 2010-06-03 )))))))))))))))))))))))))))))))
.
2010-06-03 14:21 . 2010-06-03 14:21 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-06-03 13:05 . 2010-06-03 13:05 57560 ----a-w- c:\users\NickHDoan\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-03 07:34 . 2010-06-03 04:51 -------- d-----w- c:\windows\Panther
2010-06-03 05:24 . 2010-06-03 05:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-03 05:24 . 2009-07-24 15:49 114688 ----a-w- c:\windows\system32\RicohMediadriverVer.dll
2010-06-03 05:24 . 2009-06-25 21:58 48128 ----a-w- c:\windows\system32\drivers\rimmptsk.sys
2010-06-03 05:24 . 2009-06-25 21:25 38400 ----a-w- c:\windows\system32\drivers\rixdptsk.sys
2010-06-03 05:24 . 2009-06-25 21:10 44544 ----a-w- c:\windows\system32\drivers\rimsptsk.sys
2010-06-03 05:24 . 2007-07-25 17:48 172032 ----a-w- c:\windows\system32\rixdicon.dll
2010-06-03 05:24 . 2004-09-04 08:00 90112 ----a-w- c:\windows\system32\snymsico.dll
2010-06-03 05:20 . 2008-07-08 06:45 4984 ----a-w- c:\windows\system32\drivers\nvphy.bin
2010-06-03 05:20 . 2008-08-27 18:58 453152 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-06-03 05:20 . 2010-06-03 05:20 -------- d-----w- C:\NVIDIA
2010-06-03 05:12 . 2010-06-03 13:20 -------- d-----w- c:\users\NickHDoan\AppData\Local\ElevatedDiagnostics
2010-06-03 05:06 . 2010-06-03 14:13 -------- d-----w- c:\windows\system32\wbem\Performance
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
.
- - - - ORPHANS REMOVED - - - -
HKLM-RunOnce-<NO NAME> - (no file)
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-06-03 09:22:47
ComboFix-quarantined-files.txt 2010-06-03 14:22
Pre-Run: 150,675,288,064 bytes free
Post-Run: 150,599,467,008 bytes free
- - End Of File - - FDF29490B19744F40677B8AC17209152
I have no idea if I'm infected with a virus/malware/spyware/adware but I start up Windows 7 in normal mode and after like 1-2 minutes everything freezes. When I go to Safe Mode, everything is fine. I have a feeling it has to do with my 3 year old laptop.