Combofix.txt
part 1
ComboFix 12-01-23.02 - Ivett 01/25/2012 18:03:10.2.1 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.1790.1080 [GMT -5:00]
Running from: c:\users\Ivett\Desktop\ComboFix.exe
Command switches used :: c:\users\Ivett\Desktop\CFScript.txt
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Default\AppData\Local\AskToolbar
c:\users\Default\AppData\Local\AskToolbar\Downloaded Program Files\avira.inf
c:\users\Default\AppData\Local\AskToolbar\Downloaded Program Files\AviraTrans.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-12-25 to 2012-01-25 )))))))))))))))))))))))))))))))
.
.
2012-01-25 23:12 . 2012-01-25 23:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-25 00:04 . 2012-01-06 01:19 6557240 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{89945950-D0B9-4B2D-943D-4CC2F90B646F}\mpengine.dll
2012-01-24 00:27 . 2012-01-24 00:27 -------- d-----w- C:\_OTL
2012-01-23 04:06 . 2012-01-23 04:13 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2012-01-23 01:06 . 2012-01-23 01:07 -------- dc----w- c:\users\Ivett\AppData\Local\MigWiz
2012-01-22 03:22 . 2012-01-06 01:19 6557240 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-01-21 01:31 . 2012-01-21 01:31 703824 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6FD05E23-70B2-406C-B748-DE3943E2AB0F}\gapaengine.dll
2012-01-21 01:30 . 2012-01-21 01:30 -------- d-----w- c:\program files\Microsoft Security Client
2012-01-20 03:39 . 2012-01-20 03:46 -------- d-----w- c:\programdata\SUPERSetup
2012-01-20 03:13 . 2012-01-20 03:13 7450888 ----a-w- c:\program files\Common Files\Windows Live\.cache\6d7ccf7a1ccd72101\bingbarsetup.exe
2012-01-20 02:43 . 2012-01-20 03:23 -------- d-----w- c:\programdata\PC Unleashed Online
2012-01-19 03:07 . 2012-01-20 00:05 1660 ----a-w- c:\windows\system32\ASOROSet.bin
2012-01-08 02:39 . 2012-01-08 02:39 -------- d-----w- c:\programdata\!SASCORE
2012-01-06 23:48 . 2012-01-06 23:48 -------- d-----w- c:\program files\DIFX
2012-01-06 23:45 . 2012-01-06 23:45 -------- d-----w- c:\programdata\Leapfrog
2012-01-06 23:45 . 2012-01-06 23:47 -------- d-----w- c:\program files\LeapFrog
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-06 23:51 . 2011-05-15 19:03 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-18 16:29 . 2010-01-30 03:03 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-12-18 16:29 . 2009-11-18 01:49 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-11-24 04:25 . 2011-12-13 23:32 2342912 ----a-w- c:\windows\system32\win32k.sys
2011-11-05 04:26 . 2011-12-13 23:33 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-03 22:47 . 2011-12-13 23:38 1798144 ----a-w- c:\windows\system32\jscript9.dll
2011-11-03 22:40 . 2011-12-13 23:38 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-11-03 22:39 . 2011-12-13 23:38 1127424 ----a-w- c:\windows\system32\wininet.dll
2011-11-03 22:31 . 2011-12-13 23:38 2382848 ----a-w- c:\windows\system32\mshtml.tlb
.
.
(((((((((((((((((((((((((((((
SnapShot@2012-01-24_23.46.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:55 . 2012-01-25 23:16 56316 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-12-25 02:08 . 2012-01-25 23:16 16862 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2767901044-4139088532-1525254392-1002_UserData.bin
- 2010-12-25 01:02 . 2012-01-24 22:59 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-12-25 01:02 . 2012-01-25 22:44 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-25 01:02 . 2012-01-24 22:59 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-12-25 01:02 . 2012-01-25 22:44 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:41 . 2012-01-24 22:59 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:41 . 2012-01-25 22:44 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-29 02:18 . 2012-01-25 01:12 1772 c:\windows\System32\wdi\ERCQueuedResolutions.dat
- 2012-01-24 22:55 . 2012-01-24 22:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-25 22:40 . 2012-01-25 23:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-01-24 22:55 . 2012-01-24 22:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-01-25 22:40 . 2012-01-25 23:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-12-25 23:47 . 2012-01-24 23:50 280404 c:\windows\System32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2009-07-14 04:47 . 2012-01-25 01:12 307600 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 04:47 . 2012-01-24 02:11 307600 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2011-01-25 02:50 . 2012-01-24 02:11 498622 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2767901044-4139088532-1525254392-1002-8192.dat
+ 2011-01-25 02:50 . 2012-01-25 01:12 498622 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2767901044-4139088532-1525254392-1002-8192.dat
+ 2011-06-23 04:23 . 2012-01-25 01:12 627780 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2767901044-4139088532-1525254392-1002-12288.dat
+ 2012-01-08 02:37 . 2012-01-25 01:12 2384870 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2767901044-4139088532-1525254392-1002-4096.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4