Gaming Combofix Results

  • Thread starter Thread starter EpicJungle
  • Start date Start date
  • Views Views 1,148
  • Replies Replies 0

EpicJungle

stop browbeating me can't you see i'm sexy
Member
Joined
Aug 28, 2009
Messages
1,002
Solutions
2
Reaction score
4
Trophies
2
XP
397
Country
Canada
Okeeey... I just ran Combofix,
cause it seems that my computer seems to be experiencing weird problems..
So, I just want to show you the log,
for people to analyze it..
otherwise im just gonna join the forums mentioned on the tutorial..

ComboFix 10-07-21.01 - Eriz 07/21/2010 17:47:21.1.2 - x86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.3082.18.1013.162 [GMT -4:00]
Running from: c:\users\Eriz\Documents\ComboFix.exe
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\webserver
c:\program files\webserver\webserver.dat
c:\users\Eriz\AppData\Local10112010146100109.xxe
c:\users\Eriz\AppData\Local10112010146111103.xxe
c:\users\Eriz\AppData\Local10112010146114101.xxe
c:\users\Eriz\AppData\Local10112010146115119.xxe
c:\users\Eriz\AppData\Local1011201014650115.xxe
c:\users\Eriz\AppData\Local101120101465198.xxe
c:\users\Eriz\AppData\Local\rdr_1269777806.exe
c:\users\Eriz\AppData\Local\rdr_1269778107.exe
c:\users\Eriz\AppData\Local\rdr_1269778108.exe
c:\users\Eriz\AppData\Local\rdr_1269778109.exe

.
((((((((((((((((((((((((( Files Created from 2010-06-21 to 2010-07-21 )))))))))))))))))))))))))))))))
.

2010-07-21 22:01 . 2010-07-21 22:01 -------- d-----w- c:\users\Elijah\AppData\Local\temp
2010-07-21 22:01 . 2010-07-21 22:02 -------- d-----w- c:\users\Eriz\AppData\Local\temp
2010-07-21 22:01 . 2010-07-21 22:01 -------- d-----w- c:\users\Louie\AppData\Local\temp
2010-07-21 22:01 . 2010-07-21 22:01 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-07-21 22:01 . 2010-07-21 22:01 -------- d-----w- c:\users\Ester\AppData\Local\temp
2010-07-21 22:01 . 2010-07-21 22:01 -------- d-----w- c:\users\Erika\AppData\Local\temp
2010-07-14 07:56 . 2010-07-14 07:56 -------- d-----w- c:\program files\Common Files\Java
2010-07-14 07:55 . 2010-04-12 21:29 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-12 22:17 . 2010-07-12 22:17 -------- d-----w- c:\program files\Pure Networks
2010-07-11 14:16 . 2010-07-11 14:16 -------- d--h--w- c:\users\Eriz\Stuff
2010-07-10 13:29 . 2010-04-14 17:47 293376 ----a-w- c:\windows\system32\psisdecd.dll
2010-07-10 13:29 . 2010-04-14 17:46 428544 ----a-w- c:\windows\system32\EncDec.dll
2010-07-09 23:34 . 2010-07-09 23:34 -------- d-----w- c:\windows\tiinst
2010-07-09 23:09 . 2010-07-09 23:09 -------- d-----w- c:\users\Eriz\Card Reader TI Driver 2.0.0.6q
2010-07-09 23:08 . 2010-07-09 23:08 5146248 ----a-w- c:\users\Eriz\Card Reader TI Driver 2.0.0.6q.zip
2010-06-29 20:17 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
2010-06-24 14:27 . 2009-11-08 14:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-24 14:27 . 2009-11-08 14:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-24 14:27 . 2009-11-08 14:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-24 14:27 . 2009-11-08 14:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-24 14:27 . 2009-11-08 14:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-23 19:56 . 2010-04-16 16:05 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-06-23 19:56 . 2010-04-16 14:17 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-21 00:19 . 2006-11-02 16:00 671850 ----a-w- c:\windows\system32\perfh00A.dat
2010-07-21 00:19 . 2006-11-02 16:00 131296 ----a-w- c:\windows\system32\perfc00A.dat
2010-07-15 22:43 . 2008-10-30 23:54 1356 ----a-w- c:\users\Eriz\AppData\Local\d3d9caps.dat
2010-07-15 20:16 . 2008-11-17 22:25 -------- d-----w- c:\program files\Google
2010-07-15 11:34 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-07-14 07:55 . 2009-05-06 21:20 -------- d-----w- c:\program files\Java
2010-07-12 23:20 . 2008-08-31 02:43 75744 ----a-w- c:\users\Eriz\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-12 22:12 . 2010-02-28 21:01 8892928 ----a-w- c:\programdata\atscie.msi
2010-07-09 23:38 . 2009-06-02 17:30 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-28 20:57 . 2010-04-29 00:53 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-06-28 20:37 . 2010-04-29 00:55 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-06-28 20:37 . 2010-04-29 00:55 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-06-28 20:33 . 2010-04-29 00:55 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-06-28 20:32 . 2010-04-29 00:55 50256 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-06-28 20:32 . 2010-04-29 00:55 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-06-26 14:46 . 2008-09-20 14:48 -------- d-----w- c:\program files\Microsoft.NET
2010-06-15 18:57 . 2010-06-15 18:57 -------- d-----w- c:\program files\Common Files\Pure Networks Shared
2010-06-15 00:55 . 2010-06-08 14:37 -------- d-----w- c:\programdata\Yahoo! Companion
2010-06-13 00:54 . 2010-04-17 19:42 -------- d-----w- c:\users\Eriz\AppData\Roaming\gtk-2.0
2010-06-12 18:04 . 2010-02-28 20:56 -------- d-----w- c:\programdata\Pure Networks
2010-06-12 18:03 . 2010-02-28 21:55 -------- d-----w- c:\program files\Linksys
2010-06-12 17:45 . 2010-05-06 01:37 -------- d-----w- c:\program files\RocketDock
2010-06-10 19:54 . 2008-09-20 14:45 -------- d-----w- c:\programdata\Microsoft Help
2010-06-09 15:39 . 2010-02-05 01:05 -------- d-----w- c:\users\Eriz\AppData\Roaming\Apple Computer
2010-06-08 21:10 . 2010-06-08 21:08 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-06-08 21:10 . 2010-06-08 21:08 -------- d-----w- c:\program files\iTunes
2010-06-08 21:08 . 2010-06-08 21:08 -------- d-----w- c:\program files\iPod
2010-06-08 21:08 . 2008-12-07 22:37 -------- d-----w- c:\program files\Common Files\Apple
2010-06-08 21:05 . 2010-06-08 21:04 -------- d-----w- c:\program files\QuickTime
2010-06-08 20:55 . 2010-06-08 20:55 -------- d-----w- c:\program files\Bonjour
2010-06-08 14:37 . 2010-06-08 14:37 -------- d-----w- c:\programdata\Yahoo!
2010-06-08 14:37 . 2010-06-08 14:37 -------- d-----w- c:\program files\Yahoo!
2010-06-08 14:37 . 2010-06-08 14:37 -------- d-----w- c:\users\Eriz\AppData\Roaming\Yahoo!
2010-06-06 00:40 . 2008-09-30 01:28 8224 ----a-w- c:\users\Elijah\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-06 00:40 . 2010-06-06 00:40 -------- d-----w- c:\users\Elijah\AppData\Roaming\Rainmeter
2010-06-06 00:17 . 2009-10-04 19:17 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-03 20:48 . 2010-06-03 00:02 -------- d-----w- c:\users\Eriz\AppData\Roaming\Rainmeter
2010-06-03 02:41 . 2010-06-03 02:41 3600384 ----a-w- c:\windows\system32\GPhotos.scr
2010-06-02 23:10 . 2010-06-02 23:03 -------- d-----w- c:\program files\Rainmeter
2010-05-26 16:16 . 2010-06-09 19:51 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:25 . 2010-06-09 19:51 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-24 18:48 . 2010-05-24 18:48 -------- d-----w- c:\program files\7-Zip
2010-05-23 13:19 . 2010-05-23 13:19 -------- d-----w- c:\programdata\Trymedia
2010-05-21 18:14 . 2010-04-26 21:06 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-04 14:02 . 2009-11-27 19:00 75296 ----a-w- c:\users\Ester\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-04 05:59 . 2010-06-09 19:50 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 05:55 . 2010-06-09 19:50 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-05-04 05:55 . 2010-06-09 19:50 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-05-04 04:31 . 2010-06-09 19:50 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-05-03 23:21 . 2008-08-31 13:25 240128 ----a-w- c:\windows\system32\uxtheme.dll
2010-05-03 23:21 . 2008-08-31 13:24 615424 ----a-w- c:\windows\system32\themeui.dll
2010-05-01 13:53 . 2010-06-09 19:49 2036224 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 19:39 . 2010-04-05 23:16 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2010-04-05 23:16 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-26 20:56 . 2009-11-18 14:37 256 ----a-w- c:\windows\system32\pool.bin
2010-04-23 13:55 . 2010-05-25 21:09 2048 ----a-w- c:\windows\system32\tzres.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

------- Sigcheck -------

[-] 2010-05-03 . 5B8AB8E9F38BC52ECD183B099093C2BD . 247296 . . [6.0.6000.16386] . . c:\windows\System32\shsvcs.dll
[7] 2009-04-11 . C818C44C201898399BF999BB6B35D4E3 . 247296 . . [6.0.6000.16386] . . c:\windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6002.18005_none_cf1bd6361a0f622e\shsvcs.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-06-17 1295656]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"RogersServicepointAgent.exe"="c:\program files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe" [2009-02-27 3228912]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-03-06 236016]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2009-07-07 647216]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2009-07-08 472112]

c:\users\Erika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\users\Eriz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Desktop Manager.lnk - c:\program files\Research In Motion\BlackBerry\DesktopMgr.exe [2008-5-30 1508624]
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2009-11-1 119296]
VPN Client.lnk - c:\windows\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico [2008-9-21 6144]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exeautocheck autochk *

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1c9c6939f7be980;Google Update Service (gupdate1c9c6939f7be980);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-26 133104]
R3 Radialpoint Security Services;Rogers Online Protection;c:\program files\Rogers Online Protection\Rogers Online Protection\RpsSecurityAwareR.exe [2009-02-28 97520]
R3 SASENUM;SASENUM;c:\users\Eriz\AppData\Local\Temp\SAS_SelfExtract\SASENUM.SYS [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 aswSP;aswSP; [x]
S1 SASDIFSV;SASDIFSV;c:\users\Eriz\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV.SYS [x]
S1 SASKUTIL;SASKUTIL;c:\users\Eriz\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL.sys [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-06-28 50256]
S2 atashost;WebEx Service Host for Support Center;c:\windows\system32\atashost.exe [2009-03-06 20376]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
2008-04-11 21:23 38400 ----a-w- c:\windows\System32\SoundSchemes.exe
.
Contents of the 'Scheduled Tasks' folder

2010-07-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-26 17:22]
 

Site & Scene News

Popular threads in this forum