ComboFix 12-06-07.03 - Fede 08/06/2012 0:01.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.34.3082.18.3950.2136 [GMT 2:00] Running from: c:\users\Fede\Desktop\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\prefs.js c:\program files (x86)\facemoods.com c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsApp.dll c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsEng.dll c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll c:\program files (x86)\facemoods.com\facemoods\1.4.17.11\uninstall.exe c:\program files (x86)\Object c:\program files (x86)\Object\chromeaddon\._included.js c:\program files (x86)\Object\chromeaddon\included.js c:\program files (x86)\Object\config.ini c:\program files (x86)\Object\facetheme_uninstall.exe c:\users\Fede\AppData\Local\Temp\_MEI33922\_cacheinvalidation.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\_ctypes.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\_elementtree.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\_hashlib.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\_socket.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\_ssl.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\pyexpat.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\pysqlite2._sqlite.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\python26.dll c:\users\Fede\AppData\Local\Temp\_MEI33922\pythoncom26.dll c:\users\Fede\AppData\Local\Temp\_MEI33922\PyWinTypes26.dll c:\users\Fede\AppData\Local\Temp\_MEI33922\select.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\win32api.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\win32com.shell.shell.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\win32crypt.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\win32event.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\win32file.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\win32inet.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\win32pdh.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\win32process.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\wx._controls_.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\wx._core_.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\wx._gdi_.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\wx._html2.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\wx._misc_.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\wx._windows_.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\wx._wizard.pyd c:\users\Fede\AppData\Local\Temp\_MEI33922\wxbase293u_net_vc.dll c:\users\Fede\AppData\Local\Temp\_MEI33922\wxbase293u_vc.dll c:\users\Fede\AppData\Local\Temp\_MEI33922\wxmsw293u_adv_vc.dll c:\users\Fede\AppData\Local\Temp\_MEI33922\wxmsw293u_core_vc.dll c:\users\Fede\AppData\Local\Temp\_MEI33922\wxmsw293u_html_vc.dll c:\users\Fede\AppData\Local\Temp\_MEI33922\wxmsw293u_webview_vc.dll c:\windows\assembly\GAC_32\Desktop.ini c:\windows\assembly\GAC_64\Desktop.ini c:\windows\system32\dds_trash_log.cmd . . ((((((((((((((((((((((((( Files Created from 2012-05-07 to 2012-06-07 ))))))))))))))))))))))))))))))) . . 2012-06-07 22:15 . 2012-06-07 22:15 -------- d-----w- c:\users\juan\AppData\Local\temp 2012-06-07 22:15 . 2012-06-07 22:15 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-06-07 21:41 . 2012-06-07 21:41 -------- d-----w- C:\_OTL 2012-06-07 19:09 . 2012-06-07 19:09 -------- d-----w- c:\program files (x86)\Greatis 2012-06-07 19:06 . 2012-06-07 19:06 39184 ----a-w- c:\windows\system32\Partizan.exe 2012-06-07 18:59 . 2012-06-07 19:08 -------- d-----w- c:\programdata\RegRun 2012-06-07 18:59 . 2012-06-07 19:11 2 --shatr- c:\windows\winstart.bat 2012-06-07 18:58 . 2012-06-07 19:14 -------- d-----w- c:\program files (x86)\UnHackMe 2012-06-07 17:31 . 2010-05-26 08:45 18816 ------w- c:\windows\SysWow64\SAVRKBootTasks.sys 2012-06-07 13:00 . 2012-06-07 13:00 -------- d-----w- c:\users\Fede\AppData\Roaming\GlarySoft 2012-06-07 11:58 . 2012-06-07 11:58 -------- d-----w- c:\program files (x86)\Sophos 2012-06-07 11:37 . 2012-06-07 11:59 -------- d-----w- c:\users\Fede\Pavark 2012-06-07 11:37 . 2012-06-07 11:37 -------- d-----w- C:\VritualRoot 2012-06-06 17:41 . 2012-06-06 17:42 -------- d-----w- c:\program files (x86)\Transport Giant Gold 2012-06-06 17:05 . 2012-06-06 17:05 -------- d-sh--w- c:\windows\SysWow64\%APPDATA% 2012-06-06 13:07 . 2012-06-06 13:07 -------- d-----w- c:\users\Fede\AppData\Local\SniperV2 2012-06-05 13:05 . 2012-06-05 13:05 -------- d-----w- c:\program files (x86)\Common Files\Java 2012-06-05 13:02 . 2012-04-04 16:47 772504 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2012-06-05 13:02 . 2012-04-04 16:47 687504 ----a-w- c:\windows\SysWow64\deployJava1.dll 2012-06-03 00:08 . 2012-06-03 00:08 -------- d-----w- c:\program files (x86)\Rockstar Games 2012-06-02 23:21 . 2012-06-02 23:21 -------- d-----w- c:\programdata\Rockstar Games 2012-05-31 19:52 . 2012-05-31 19:52 -------- d-----w- c:\program files (x86)\Common Files\Skype 2012-05-28 05:11 . 2012-05-28 05:12 -------- d-----w- C:\sintaxis 2012-05-27 15:10 . 2012-05-27 15:10 -------- d-----w- c:\program files (x86)\MSECache 2012-05-21 14:44 . 2012-05-21 14:44 -------- d-----w- c:\users\Fede\AppData\Roaming\Ubisoft 2012-05-20 15:05 . 2012-05-20 15:05 -------- d-sh--w- c:\windows\ftpcache 2012-05-20 15:02 . 2012-05-20 15:02 -------- d-----w- c:\programdata\Lionhead Studios 2012-05-20 14:57 . 2012-05-20 14:57 -------- d-----w- c:\users\Fede\AppData\Roaming\Lionhead Studios 2012-05-19 11:57 . 2012-05-19 11:57 -------- d-----w- c:\programdata\GFI Software 2012-05-19 11:24 . 2012-01-25 06:38 77312 ----a-w- c:\windows\system32\rdpwsx.dll 2012-05-19 11:24 . 2012-01-25 06:38 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll 2012-05-19 10:32 . 2012-05-19 10:32 -------- d-----w- c:\windows\system32\SPReview 2012-05-18 10:48 . 2012-05-18 10:49 -------- d-----w- c:\program files\CCleaner 2012-05-18 10:31 . 2012-05-18 10:31 -------- d-----w- c:\program files (x86)\Windows Startup Inspector 2012-05-18 10:24 . 2012-05-18 10:24 -------- d-----w- c:\programdata\Lavasoft 2012-05-18 10:24 . 2012-05-19 11:57 -------- d-----w- c:\program files (x86)\Ad-Aware Antivirus 2012-05-18 10:22 . 2012-05-19 11:56 -------- d-----w- c:\users\Fede\AppData\Roaming\Ad-Aware Antivirus 2012-05-17 09:04 . 2012-05-17 09:04 -------- d-----w- c:\users\Fede\AppData\Local\Comodo 2012-05-17 09:04 . 2012-05-17 17:51 -------- d-----w- c:\programdata\CPA_VA 2012-05-17 08:45 . 2012-05-17 08:49 -------- d-----w- c:\programdata\Comodo 2012-05-17 08:45 . 2012-05-17 08:45 -------- d-----w- c:\program files\COMODO 2012-05-17 08:45 . 2012-05-17 08:45 -------- d-----w- c:\program files (x86)\Comodo 2012-05-17 08:45 . 2012-05-17 08:45 1700352 ----a-w- c:\windows\SysWow64\gdiplus.dll 2012-05-17 08:40 . 2012-05-18 10:33 -------- d-----w- c:\users\Fede\AppData\Roaming\wsInspector 2012-05-17 08:38 . 2012-05-17 08:38 -------- d-----w- c:\program files (x86)\Startup Inspector for Windows 2012-05-17 08:36 . 2012-05-17 08:36 -------- d-----w- c:\windows\system32\EventProviders 2012-05-16 22:03 . 2010-11-05 01:57 48976 ----a-w- c:\windows\system32\netfxperf.dll 2012-05-16 22:03 . 2010-11-05 01:57 1942856 ----a-w- c:\windows\system32\dfshim.dll 2012-05-16 22:01 . 2010-11-20 13:27 297984 ----a-w- c:\windows\system32\ws2_32.dll 2012-05-16 22:00 . 2010-11-20 13:27 303104 ----a-w- c:\program files\DVD Maker\WMM2CLIP.dll 2012-05-16 21:59 . 2010-11-20 12:21 189952 ----a-w- c:\windows\SysWow64\sqmapi.dll 2012-05-16 21:59 . 2010-11-20 12:21 189952 ----a-w- c:\windows\SysWow64\wdscore.dll 2012-05-16 21:59 . 2010-11-20 12:17 209920 ----a-w- c:\windows\SysWow64\PkgMgr.exe 2012-05-16 21:59 . 2010-11-20 12:18 323072 ----a-w- c:\windows\SysWow64\drvstore.dll 2012-05-16 21:59 . 2010-11-20 12:18 257024 ----a-w- c:\windows\SysWow64\dpx.dll 2012-05-16 21:59 . 2010-11-20 12:21 363008 ----a-w- c:\windows\SysWow64\wbemcomn.dll 2012-05-16 21:59 . 2010-11-20 12:21 189952 ----a-w- c:\program files (x86)\Windows Portable Devices\sqmapi.dll 2012-05-16 21:59 . 2010-11-20 12:19 606208 ----a-w- c:\windows\SysWow64\wbem\fastprox.dll 2012-05-16 21:56 . 2010-11-20 13:27 524288 ----a-w- c:\windows\system32\wmicmiplugin.dll 2012-05-16 21:56 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll 2012-05-16 21:56 . 2010-11-20 13:27 1225216 ----a-w- c:\windows\system32\wbem\wbemcore.dll 2012-05-16 21:56 . 2010-11-20 13:27 244736 ----a-w- c:\program files\Windows Portable Devices\sqmapi.dll 2012-05-16 21:56 . 2010-11-20 13:27 244736 ----a-w- c:\windows\system32\sqmapi.dll 2012-05-16 21:56 . 2010-11-20 13:27 933376 ----a-w- c:\windows\system32\SmiEngine.dll 2012-05-16 21:56 . 2010-11-20 13:25 199168 ----a-w- c:\windows\system32\PkgMgr.exe 2012-05-16 21:55 . 2010-11-20 13:26 422912 ----a-w- c:\windows\system32\drvstore.dll 2012-05-16 21:55 . 2010-11-20 13:26 399872 ----a-w- c:\windows\system32\dpx.dll 2012-05-16 21:47 . 2012-05-16 21:47 -------- d-----w- c:\users\Fede\AppData\Roaming\QuickScan 2012-05-15 17:19 . 2012-05-15 17:19 -------- d-----we c:\windows\system64 2012-05-15 17:06 . 2012-05-15 22:45 -------- d-----w- C:\FRST 2012-05-15 16:40 . 2012-06-07 11:49 -------- d-----w- C:\TDSSKiller_Quarantine 2012-05-15 12:28 . 2012-05-15 12:28 -------- d-----w- c:\users\Fede\AppData\Roaming\Easeware 2012-05-15 12:27 . 2012-05-15 12:27 -------- d-----w- c:\program files\Easeware 2012-05-14 19:02 . 2012-05-18 11:02 -------- dc----w- c:\users\Fede\AppData\Local\MigWiz 2012-05-14 18:42 . 2012-05-14 22:07 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2012-05-14 18:42 . 2012-05-14 22:07 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2012-05-11 21:10 . 2012-05-11 21:10 -------- d-----w- c:\programdata\ATI 2012-05-11 08:59 . 2012-06-07 10:12 -------- d-----w- c:\programdata\AVG2012 2012-05-11 08:58 . 2012-05-11 12:29 -------- d-----w- c:\program files (x86)\AVG 2012-05-11 01:07 . 2012-03-30 11:35 1918320 ----a-w- c:\windows\system32\drivers\tcpip.sys 2012-05-11 01:07 . 2012-03-31 05:42 1732096 ----a-w- c:\program files\Windows Journal\NBDoc.DLL 2012-05-11 01:07 . 2012-03-31 05:40 1367552 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2012-05-11 01:07 . 2010-11-20 13:24 2164224 ----a-w- c:\program files\Windows Journal\Journal.exe 2012-05-11 01:07 . 2012-03-31 05:40 1393664 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll 2012-05-11 01:07 . 2012-03-31 04:29 936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll 2012-05-11 01:07 . 2012-03-31 05:40 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll 2012-05-11 01:07 . 2012-03-03 06:35 1544704 ----a-w- c:\windows\system32\DWrite.dll 2012-05-11 01:07 . 2012-03-03 05:31 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll 2012-05-11 01:06 . 2012-03-31 06:05 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe 2012-05-11 01:06 . 2012-03-31 03:10 3146240 ----a-w- c:\windows\system32\win32k.sys 2012-05-11 01:06 . 2012-03-31 04:39 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2012-05-11 01:06 . 2012-03-31 04:39 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2012-05-11 01:05 . 2012-03-17 07:58 75120 ----a-w- c:\windows\system32\drivers\partmgr.sys 2012-05-10 18:04 . 2012-05-17 18:12 -------- d-----w- C:\Update 2012-05-09 15:07 . 2012-05-10 13:44 -------- d-----w- c:\users\Fede\AppData\Roaming\Xidicone 2012-05-09 15:06 . 2012-05-09 15:06 -------- d-----w- c:\programdata\Xidicone 2012-05-09 11:00 . 2012-05-10 13:44 -------- d-----w- c:\program files\Microsoft Security Client . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-05-19 10:39 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll 2012-05-19 10:39 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll 2012-05-13 09:45 . 2012-05-05 17:20 419488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-05-13 09:45 . 2011-10-13 16:05 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-05-06 11:10 . 2012-05-06 11:10 110080 ----a-r- c:\users\Fede\AppData\Roaming\Microsoft\Installer\{5B210B8A-B66E-4702-B44D-0D6F388D29EB}\IconF7A21AF7.exe 2012-05-06 11:10 . 2012-05-06 11:10 110080 ----a-r- c:\users\Fede\AppData\Roaming\Microsoft\Installer\{5B210B8A-B66E-4702-B44D-0D6F388D29EB}\IconD7F16134.exe 2012-05-06 11:10 . 2012-05-06 11:10 110080 ----a-r- c:\users\Fede\AppData\Roaming\Microsoft\Installer\{5B210B8A-B66E-4702-B44D-0D6F388D29EB}\Icon1226A4C5.exe 2012-05-02 00:46 . 2012-05-02 00:46 4472832 ----a-w- c:\windows\SysWow64\GPhotos.scr 2012-04-13 08:46 . 2012-05-04 10:52 8917360 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FE7DB59B-F1C2-4301-9891-A5274288A180}\mpengine.dll 2012-03-23 16:20 . 2012-03-09 18:39 189248 ----a-w- c:\windows\SysWow64\PnkBstrB.exe 2012-03-23 16:20 . 2012-03-09 18:39 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe 2012-03-11 19:13 . 2012-03-11 19:13 577824 ----a-w- c:\windows\system32\drivers\cmdGuard.sys 2012-03-11 19:13 . 2012-03-11 19:13 43248 ----a-w- c:\windows\system32\drivers\cmdhlp.sys 2012-03-11 19:13 . 2012-03-11 19:13 22696 ----a-w- c:\windows\system32\drivers\cmderd.sys 2012-03-11 19:13 . 2012-03-11 19:13 41200 ----a-w- c:\windows\system32\cmdcsr.dll 2012-03-11 19:13 . 2012-03-11 19:13 301224 ----a-w- c:\windows\SysWow64\guard32.dll 2012-03-11 19:13 . 2012-03-11 19:13 389840 ----a-w- c:\windows\system32\guard64.dll 2012-03-11 12:32 . 2012-03-09 18:43 283416 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr 2012-03-11 00:09 . 2012-03-09 18:39 283416 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0 2012-02-24 17:04 . 2012-02-24 17:04 171008 ----a-w- c:\program files (x86)\binkw32.dll 2011-08-10 15:04 . 2011-08-10 15:04 1524557 ----a-w- c:\program files\wrar401es[1].exe . . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [-] 2009-07-14 . 50BEA589F7D7958BDD2528A8F69D05CC . 329216 . . [6.1.7600.16385] .. c:\windows\system64\services.exe [7] 2009-07-14 . 24ACB7E5BE595468E3B9AA488B9B4FCB . 328704 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe [-] 2009-07-14 . 50BEA589F7D7958BDD2528A8F69D05CC . 329216 . . [6.1.7600.16385] .. c:\windows\system32\services.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-05-20 39408] "Steam"="c:\users\Public\Documents\fede\Steam\steam.exe" [2012-02-15 1242448] "GoogleDriveSync"="c:\program files (x86)\Google\Drive\googledrivesync.exe" [2012-05-16 11921064] "DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2012-02-02 3035968] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-11-20 284696] "ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2009-08-26 320880] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-13 98304] "NortonOnlineBackupReminder"="c:\program files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-06-17 538472] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888] "AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240] "iTunesHelper"="C:\iTunesHelper.exe" [2012-01-16 421736] "WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2011-12-09 74752] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] "COMODO"="c:\program files\COMODO\COMODO GeekBuddy\CLPSLA.exe" [2011-11-23 213304] "CPA"="c:\program files\COMODO\COMODO GeekBuddy\VALA.exe" [2011-11-23 184120] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon] 2009-12-01 20:03 98304 ----a-w- c:\windows\System32\VESWinlogon.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\SysWOW64\guard32.dll . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-disabled] "PMBVolumeWatcher"=c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe "MarketingTools"=c:\program files (x86)\Sony\Marketing Tools\MarketingTools.exe . R1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Servicio Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-20 133104] R2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [2009-08-30 362992] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-05-03 158856] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-13 257696] R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x] R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x] R3 dump_wmimmc;dump_wmimmc;c:\program files (x86)\NCsoft\Lineage II\system\GameGuard\dump_wmimmc.sys [x] R3 gupdatem;Servicio de Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-20 133104] R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [x] R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\2F6A.tmp [x] R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x] R3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [2009-08-30 313840] R3 SOHCImp;VAIO Media plus Content Importer;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [2009-10-15 120104] R3 SOHDBSvr;VAIO Media plus Database Manager;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [2009-10-15 70952] R3 SOHDms;VAIO Media plus Digital Media Server;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe [2009-10-15 427304] R3 SOHDs;VAIO Media plus Device Searcher;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [2009-10-15 75048] R3 SOHPlMgr;VAIO Media plus Playlist Manager;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [2009-10-15 91432] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2009-09-16 480624] R3 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [2009-09-01 361840] R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [2009-09-08 110960] R3 WatAdminSvc;Servicio de tecnologías de activación de Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 MSSQLServerADHelper100;Servicio auxiliar de SQL Active Directory;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 59744] R4 RsFx0150;RsFx0150 Driver;c:\windows\system32\DRIVERS\RsFx0150.sys [x] R4 SQLAgent$SQLEXPRESS;Agente SQL Server (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2010-04-03 428384] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys [x] S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [x] S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 CLPSLS;COMODO livePCsupport Service;c:\program files\COMODO\COMODO GeekBuddy\CLPSLS.exe [2011-11-23 1267000] S2 dlbk_device;dlbk_device;c:\windows\system32\dlbkcoms.exe [2007-06-25 567024] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-11-20 13336] S2 MsDepSvc;Servicio Agente de implementación web;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe [2011-04-01 67400] S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2009-10-24 360224] S2 rimspci;rimspci;c:\windows\system32\drivers\rimssne64.sys [x] S2 risdsnpe;risdsnpe;c:\windows\system32\drivers\risdsne64.sys [x] S2 SampleCollector;VAIO Care Performance Service;c:\program files\Sony\VAIO Care\VCPerfService.exe [2011-01-29 259192] S2 uCamMonitor;CamMonitor;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2008-09-18 104960] S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-12-14 2320920] S2 VCFw;VAIO Content Folder Watcher;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2009-09-14 642416] S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys [x] S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\drivers\SFEP.sys [x] S3 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe [2009-11-30 571248] S3 VCService;VCService;c:\program files\Sony\VAIO Care\VCService.exe [2011-02-14 44736] S3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update 5\VUAgent.exe [2009-10-30 1165680] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x] . . --- Other Services/Drivers In Memory --- . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-06-07 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 09:45] . 2012-06-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-20 09:36] . 2012-06-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-20 09:36] . 2012-06-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-308961309-1451343532-2030891354-1001Core.job - c:\users\Fede\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-07 18:30] . 2012-06-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-308961309-1451343532-2030891354-1001UA.job - c:\users\Fede\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-07 18:30] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}] 2012-05-16 15:53 754712 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}] 2012-05-16 15:53 754712 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}] 2012-05-16 15:53 754712 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}] 2012-05-16 15:53 754712 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-16 9636896] "Apoint"="c:\program files (x86)\Apoint\Apoint.exe" [BU] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-05-20 171520] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-21 2327952] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608] "COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2012-03-11 9569096] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 "AppInit_DLLs"=c:\windows\System32\guard64.dll . ------- Supplementary Scan ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.es/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xportar a Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Enviar imagen al dispositivo &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Enviar página al dispositivo &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm IE: {{20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - LSP: mswsock.dll TCP: DhcpNameServer = 80.58.61.250 80.58.61.254 TCP: Interfaces\{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}: NameServer = 80.58.61.250,80.58.61.254 TCP: Interfaces\{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}\75C414E4F544430303: NameServer = 80.58.61.250,80.58.61.254 TCP: Interfaces\{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}\75C414E4F554242334: NameServer = 80.58.61.250,80.58.61.254 . - - - - ORPHANS REMOVED - - - - . Toolbar-10 - (no file) ShellExecuteHooks-{F552DDE6-2090-4bf4-B924-6141E87789A5} - c:\progra~2\Greatis\REGRUN~1\RRShell.dll SafeBoot-41019062.sys Toolbar-10 - (no file) . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MsDepSvc] "ImagePath"="\"c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe\" -runService:MsDepSvc" -- . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\SampleCollector] "ImagePath"="\"c:\program files\Sony\VAIO Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=5000\" \"/procinterval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor Information(*)\Processor Frequency:1\" \"/expandcounter=\Processor(*)\% Idle Time:1\" \"/expandcounter=\Processor(*)\% C1 Time:1\" \"/expandcounter=\Processor(*)\% C2 Time:1\" \"/expandcounter=\Processor(*)\% C3 Time:1\" \"/expandcounter=\Processor(*)\% Processor Time:1\" \"/directory=c:\programdata\Sony Corporation\VAIO Care\inteldata\"" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MEMSWEEP2] "ImagePath"="\??\c:\windows\system32\2F6A.tmp" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-308961309-1451343532-2030891354-1001\Software\SecuROM\License information*] @Allowed: (Read) (RestrictedCode) "datasecu"=hex:97,93,bf,e8,c1,16,86,15,0f,67,8c,58,1f,88,f8,b8,eb,fe,d4,4d,a0, 60,45,74,14,b3,c3,36,ab,d5,ee,d7,db,7a,cc,f6,86,cf,42,7b,6c,f0,99,57,43,c5,\ "rkeysecu"=hex:ea,c7,e6,93,db,c6,af,25,a3,35,4a,db,29,f1,6e,a5 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Other Running Processes ------------------------ . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe c:\windows\SysWOW64\PnkBstrA.exe c:\program files (x86)\SONY\VAIO Event Service\VESMgr.exe c:\windows\SysWOW64\DllHost.exe c:\program files (x86)\Google\Update\1.3.21.111\GoogleCrashHandler.exe c:\program files (x86)\SONY\VAIO Event Service\VESMgrSub.exe c:\program files\Sony\VAIO Care\listener.exe . ************************************************************************** . Completion time: 2012-06-08 00:33:18 - machine was rebooted ComboFix-quarantined-files.txt 2012-06-07 22:33 ComboFix2.txt 2012-05-15 16:37 . Pre-Run: 326.090.256.384 bytes libres Post-Run: 325.575.557.120 bytes libres . - - End Of File - - A0CDA93B7A32C417C287F83EECD3E382