ComboFix 10-06-27.04 - ROB 28/06/2010 10:31:51.1.2 - x86 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.2.1033.18.2047.1529 [GMT -3:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} . ((((((((((((((((((((((((( Files Created from 2010-05-28 to 2010-06-28 ))))))))))))))))))))))))))))))) . 2010-06-28 13:38 . 2010-06-28 13:38 -------- d-----w- c:\users\Default\AppData\Local\temp 2010-06-25 02:17 . 2009-11-25 15:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll 2010-06-25 02:17 . 2009-11-25 15:47 49472 ----a-w- c:\windows\system32\netfxperf.dll 2010-06-25 02:17 . 2009-11-25 15:47 297808 ----a-w- c:\windows\system32\mscoree.dll 2010-06-25 02:17 . 2009-11-25 15:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe 2010-06-25 02:17 . 2009-11-25 15:47 1130824 ----a-w- c:\windows\system32\dfshim.dll 2010-06-25 01:55 . 2010-05-21 05:18 977920 ----a-w- c:\windows\system32\wininet.dll 2010-06-25 01:54 . 2010-03-05 07:42 67584 ----a-w- c:\windows\system32\asycfilt.dll 2010-06-25 01:54 . 2010-05-01 14:49 2326528 ----a-w- c:\windows\system32\win32k.sys 2010-06-25 01:54 . 2010-05-27 07:24 34304 ----a-w- c:\windows\system32\atmlib.dll 2010-06-25 01:54 . 2010-05-27 03:49 293888 ----a-w- c:\windows\system32\atmfd.dll 2010-06-16 03:00 . 2010-06-16 03:00 -------- d-----w- c:\users\ROB\AppData\Roaming\NVIDIA 2010-06-16 02:58 . 2010-06-16 02:58 138056 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2010-06-16 02:58 . 2010-06-16 02:58 189248 ----a-w- c:\windows\system32\PnkBstrB.exe 2010-06-16 02:58 . 2010-06-16 02:58 75064 ----a-w- c:\windows\system32\PnkBstrA.exe 2010-06-16 02:58 . 2010-06-01 14:02 2419568 ----a-w- c:\windows\system32\pbsvc_apb.exe 2010-06-14 03:54 . 2010-06-14 03:55 -------- d-----w- c:\program files\NVIDIA Corporation 2010-06-14 03:54 . 2010-04-03 22:55 56424 ----a-w- c:\windows\system32\OpenCL.dll 2010-06-14 03:54 . 2010-04-03 22:55 4503144 ----a-w- c:\windows\system32\nvwgf2um.dll 2010-06-14 03:54 . 2010-04-03 22:55 11573800 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys 2010-06-14 03:54 . 2010-04-03 22:55 4029544 ----a-w- c:\windows\system32\nvcuda.dll 2010-06-14 03:54 . 2010-04-03 22:55 316008 ----a-w- c:\windows\system32\nvdecodemft.dll 2010-06-14 03:54 . 2010-04-03 22:55 2907752 ----a-w- c:\windows\system32\nvencodemft.dll 2010-06-14 03:54 . 2010-04-03 22:55 2646632 ----a-w- c:\windows\system32\nvcuvenc.dll 2010-06-14 03:54 . 2010-04-03 22:55 2009704 ----a-w- c:\windows\system32\nvcuvid.dll 2010-06-14 03:54 . 2010-04-03 22:55 15227496 ----a-w- c:\windows\system32\nvoglv32.dll 2010-06-14 03:54 . 2010-04-03 22:55 227944 ----a-w- c:\windows\system32\nvcod1914.dll 2010-06-14 03:54 . 2010-04-03 22:55 227944 ----a-w- c:\windows\system32\nvcod.dll 2010-06-14 03:54 . 2010-04-03 22:55 11647592 ----a-w- c:\windows\system32\nvcompiler.dll 2010-06-14 03:40 . 2010-06-14 03:40 -------- d-----w- c:\program files\SystemRequirementsLab 2010-06-14 03:32 . 2010-06-14 03:32 -------- d-----w- c:\program files\Realtime Worlds 2010-06-03 04:34 . 2010-06-07 22:34 -------- d-----w- c:\program files\StarCraft II Beta 2010-05-31 02:38 . 2010-05-31 03:48 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2010-05-31 02:38 . 2010-05-31 02:38 -------- d-----w- c:\program files\Spybot - Search & Destroy 2010-05-30 02:51 . 2010-05-30 02:51 -------- d-----w- c:\windows\system32\Wat 2010-05-30 02:40 . 2010-05-30 02:40 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help 2010-05-30 00:02 . 2009-10-31 05:45 2614272 ----a-w- c:\windows\explorer.exe 2010-05-30 00:02 . 2009-10-28 06:17 285696 ----a-w- c:\windows\system32\winlogon.exe 2010-05-30 00:02 . 2009-12-11 07:44 133720 ----a-w- c:\windows\system32\drivers\ksecpkg.sys 2010-05-30 00:02 . 2009-12-11 07:38 1037312 ----a-w- c:\windows\system32\lsasrv.dll 2010-05-30 00:01 . 2010-03-04 07:33 740864 ----a-w- c:\windows\system32\inetcomm.dll 2010-05-29 23:51 . 2010-02-27 12:07 3954568 ----a-w- c:\windows\system32\ntkrnlpa.exe 2010-05-29 23:51 . 2010-02-27 12:07 3899280 ----a-w- c:\windows\system32\ntoskrnl.exe 2010-05-29 23:50 . 2010-03-08 21:33 427520 ----a-w- c:\windows\system32\vbscript.dll 2010-05-29 23:50 . 2010-04-23 07:13 2048 ----a-w- c:\windows\system32\tzres.dll 2010-05-29 23:48 . 2010-02-27 07:32 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2010-05-29 23:48 . 2010-02-27 07:32 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys 2010-05-29 23:48 . 2010-02-27 07:32 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2010-05-29 23:26 . 2009-12-29 06:55 172032 ----a-w- c:\windows\system32\wintrust.dll 2010-05-29 23:25 . 2010-01-09 06:52 132608 ----a-w- c:\windows\system32\cabview.dll 2010-05-29 23:21 . 2010-05-29 23:21 -------- d-----w- c:\program files\Microsoft Security Essentials . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-06-28 13:10 . 2010-01-01 08:45 -------- d-----w- c:\programdata\NVIDIA 2010-06-28 00:44 . 2010-04-21 00:45 -------- d-----w- c:\program files\Full Tilt Poker 2010-06-25 02:17 . 2010-03-01 13:15 -------- d-----w- c:\programdata\Microsoft Help 2010-06-19 12:38 . 2010-01-12 03:54 -------- d-----w- c:\program files\Heroes of Newerth 2010-06-18 00:30 . 2010-03-23 15:05 -------- d-----w- c:\program files\D2Rob 2010-06-16 08:45 . 2010-06-16 08:45 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2010-06-16 02:58 . 2010-06-16 02:58 138056 ----a-w- c:\users\ROB\AppData\Roaming\PnkBstrK.sys 2010-06-16 02:58 . 2010-06-16 02:58 138056 ----a-w- c:\users\ROB\AppData\Roaming\PnkBstrK.sys 2010-06-14 03:55 . 2009-12-31 22:59 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2010-06-04 18:27 . 2010-06-04 18:27 45828 ----a-w- c:\programdata\Blizzard Entertainment\Battle.net\Cache\Download\Scan.dll 2010-06-04 18:27 . 2010-01-01 08:09 -------- d-----w- c:\programdata\Blizzard Entertainment 2010-06-03 20:19 . 2010-05-08 05:35 -------- d-----w- c:\program files\Warcraft III 2010-06-03 05:29 . 2009-12-31 22:28 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment 2010-05-30 02:53 . 2010-01-20 18:35 108824 ----a-w- c:\users\ROB\AppData\Local\GDIPFONTCACHEV1.DAT 2010-05-30 02:51 . 2009-07-14 02:37 -------- d-----w- c:\program files\Windows Mail 2010-05-30 02:42 . 2010-03-01 13:20 -------- d-----w- c:\program files\Microsoft Works 2010-05-21 20:52 . 2010-03-28 01:45 -------- d-----w- c:\program files\Diablo II 2010-05-21 17:14 . 2009-12-31 22:03 221568 ------w- c:\windows\system32\MpSigStub.exe 2010-05-09 04:06 . 2010-04-22 19:11 -------- d-----w- c:\programdata\NOS 2010-05-08 06:02 . 2010-05-08 05:38 77105 ----a-w- c:\windows\War3Unin.dat 2010-05-08 05:44 . 2010-05-08 05:38 2829 ----a-w- c:\windows\War3Unin.pif 2010-05-08 05:44 . 2010-05-08 05:38 139264 ----a-w- c:\windows\War3Unin.exe 2010-04-22 19:11 . 2010-04-22 19:11 86016 ----a-w- c:\programdata\NOS\Adobe_Downloads\arh.exe 2010-04-03 22:55 . 2009-12-31 22:58 600680 ----a-w- c:\windows\system32\nvudisp.exe 2010-04-03 22:55 . 2009-02-09 05:18 9386600 ----a-w- c:\windows\system32\nvd3dum.dll 2010-04-03 22:55 . 2009-02-09 05:18 1296488 ----a-w- c:\windows\system32\nvapi.dll 2010-04-03 21:27 . 2010-04-03 21:27 985704 ----a-w- c:\windows\system32\nvsvc.dll 2010-04-03 21:27 . 2010-04-03 21:27 66664 ----a-w- c:\windows\system32\nvshext.dll 2010-04-03 21:27 . 2010-04-03 21:27 13683816 ----a-w- c:\windows\system32\nvcpl.dll 2010-04-03 21:27 . 2010-04-03 21:27 129640 ----a-w- c:\windows\system32\nvvsvc.exe 2010-04-03 21:27 . 2010-04-03 21:27 110696 ----a-w- c:\windows\system32\nvmctray.dll 2010-04-02 19:54 . 2009-12-31 22:58 600680 ----a-w- c:\windows\system32\NVUNINST.EXE 2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat 2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2009-12-11 18:57 948672 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2009-12-22 04:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim] 2010-03-08 21:04 3972440 ----a-w- c:\program files\AIM\aim.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor] 2008-10-25 14:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSSE] 2010-02-21 08:03 1093208 ----a-w- c:\program files\Microsoft Security Essentials\msseces.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] 2010-04-03 21:27 13683816 ----a-w- c:\windows\System32\nvcpl.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] 2010-04-03 21:27 110696 ----a-w- c:\windows\System32\nvmctray.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl] 2010-02-03 10:40 394984 ----a-w- c:\program files\Sandboxie\SbieCtrl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] 2009-01-26 18:31 2144088 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2010-02-09 17:45 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2009-12-02 42368] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-30 1343400] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-04-03 240232] S3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992] S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\DRIVERS\VSTBS23.SYS [2009-07-13 266752] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.facebook.com/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 . . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2010-06-28 10:44:17 ComboFix-quarantined-files.txt 2010-06-28 13:44 Pre-Run: 129,207,775,232 bytes free Post-Run: 129,225,392,128 bytes free - - End Of File - - 200132F583BECAE1D93620CAAC1E6F18