ComboFix 12-06-02.03 - j-cash 06/03/2012 0:58.2.2 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4094.2137 [GMT -4:00]
Running from: c:\users\j-cash\Desktop\ComboFix.exe
Command switches used :: c:\users\j-cash\Desktop\CFscript.txt
AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\SysWow64\drivers\tmcomm.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\j-cash\AppData\Roaming\uTorrent
c:\users\j-cash\AppData\Roaming\uTorrent\(2008) The Sound of Madness.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\3 Doors Down - Kryptonite(1).mp3.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Adobe Photoshop CS4 Extended + Activation.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Alice with dog 2.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Alkaline Trio - Agony and Irony [2008].torrent
c:\users\j-cash\AppData\Roaming\uTorrent\babysitter 23.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Black Eyed Peas - Imma be.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Black Eyed Peas - Imma Bee (DJ Smoob).mp3.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\BS1.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\
Chevelle-Singles-2009-18MB-@320-gR1m.torrentc:\users\j-cash\AppData\Roaming\uTorrent\Chevelle - Greatest Hits (2009) - [kn0wnunkn0wn].torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Clutch-Strange_Cousins_From_The_West-(RETAIL)-2009-h8me.rar.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\College Teens Bookbang - Samantha.wmv.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Deftones - Diamond Eyes [mp3-320-2010].torrent
c:\users\j-cash\AppData\Roaming\uTorrent\dht.dat
c:\users\j-cash\AppData\Roaming\uTorrent\dht.dat.old
c:\users\j-cash\AppData\Roaming\uTorrent\Disturbed - Indestructible 2008 (320k) Heavy Metal.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Drake-Thank.Me.Later-(Retail)-2010-[NoFS].torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Eminem - Relapse (2009) (320 Kbps).torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Explicit Voyeurs College Dorm.wmv.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Five Finger Death Punch - War Is The Answer.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Five_Finger_Death_Punch-The_Way_Of_The_Fist-(Retail)-2008-HHI.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Flight 187.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\framing hanley - lollipop.mp3.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Hollywood Undead-Never Going Down.zip.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Intuit TurboTax Home and Business 2011 @ Only By THE RAIN.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Killswitch Engage - Killswitch Engage (2009) - Metal [www.torrentazos.com].torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Lifehouse - Broken (Radio Remix).mp3.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\LiL Wayne- Lollipop Remastered Remix feat. T-pain, Gabriel, Antonio, DICE & Gorilla Zoe.mp3.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Lil Wayne - Tha Carter III [EAC Rip]-TNas11.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Lil_Wayne-Lollipop__Ft._Static_Major___DIRTY_-_www.dj-emi.blogspot.com_.mp3.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\MOV00125.MP4.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Mudvayne-The_New_Game-2008-MUDVAYNE.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Mudvayne - The new Game.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Nickleback - dark horse(split tracks+covers).torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Paranormal.Activity.Theatrical.Ending PBM.avi.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Pitbull - I Know You Want Me [2156].mp3.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\resume.dat
c:\users\j-cash\AppData\Roaming\uTorrent\resume.dat.old
c:\users\j-cash\AppData\Roaming\uTorrent\rss.dat
c:\users\j-cash\AppData\Roaming\uTorrent\rss.dat.old
c:\users\j-cash\AppData\Roaming\uTorrent\Seether.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\settings.dat
c:\users\j-cash\AppData\Roaming\uTorrent\settings.dat.old
c:\users\j-cash\AppData\Roaming\uTorrent\Sex Drive (unrated edition) [Elite078].torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Sick Puppies - Tri-Polar 2009 (320@kbps) - lllSCOOPlll.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Skillet - Awake [Album 2009] [320kpbs].torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Slipknot - All Hope Is Gone.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Soulja boy - crank that travis barker remix.mp3.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\T.I. - Paper Trail [EAC Rip]-TNas11.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\The Hangover [2009-MP3-VBR-320Kbps] - [AJ].torrent
c:\users\j-cash\AppData\Roaming\uTorrent\THE_HANGOVER_2.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\Trey Songz - Bottoms Up (feat. Nicki Minaj) [2010-Single][MJN].torrent
c:\users\j-cash\AppData\Roaming\uTorrent\TTax2010Dlx.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\V.I.C. & Soulja Boy ft. Black Lungz - Get Silly.mp3.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\VA - 100 Tracks From The Swinging 60's (2009) [5CD].1.torrent
c:\users\j-cash\AppData\Roaming\uTorrent\VA - 100 Tracks From The Swinging 60's (2009) [5CD].torrent
c:\windows\SysWow64\drivers\tmcomm.sys
.
.
((((((((((((((((((((((((( Files Created from 2012-05-03 to 2012-06-03 )))))))))))))))))))))))))))))))
.
.
2012-06-03 05:03 . 2012-06-03 05:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-05-29 00:27 . 2012-05-29 00:27 -------- d-----w- c:\program files (x86)\MALWAREBYTES ANTI-MALWARE
2012-05-28 16:26 . 2012-05-28 16:26 388096 ----a-r- c:\users\j-cash\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-05-28 16:26 . 2012-05-28 16:26 -------- d-----w- c:\program files (x86)\Trend Micro
2012-05-08 18:42 . 2012-04-03 08:22 4699520 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-08 18:42 . 2012-04-02 13:59 2766848 ----a-w- c:\windows\system32\win32k.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-04 19:56 . 2011-01-17 04:15 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-27 13:33 . 2011-05-16 14:45 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-03-08 22:50 . 2012-03-08 22:50 49016 ----a-w- c:\windows\SysWow64\sirenacm.dll
2012-03-08 22:37 . 2012-03-08 22:37 302448 ----a-w- c:\windows\WLXPGSS.SCR
.
.
(((((((((((((((((((((((((((((
SnapShot@2012-06-02_06.04.42 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 02:23 . 2012-06-03 05:08 53116 c:\windows\system32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 15:45 . 2012-06-03 05:08 72486 c:\windows\system32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-20 22:13 . 2012-06-03 05:08 12354 c:\windows\system32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1517543764-884281664-660548895-1000_UserData.bin
+ 2012-06-03 05:05 . 2012-06-03 05:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-06-02 06:02 . 2012-06-02 06:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-06-03 05:05 . 2012-06-03 05:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-06-02 06:02 . 2012-06-02 06:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 12:46 . 2012-06-02 06:08 604502 c:\windows\system32\perfh009.dat
- 2006-11-02 12:46 . 2012-05-29 16:50 604502 c:\windows\system32\perfh009.dat
+ 2006-11-02 12:46 . 2012-06-02 06:08 104202 c:\windows\system32\perfc009.dat
- 2006-11-02 12:46 . 2012-05-29 16:50 104202 c:\windows\system32\perfc009.dat
+ 2010-10-27 07:16 . 2012-06-03 05:04 348072 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2010-10-27 07:16 . 2012-06-02 06:01 348072 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2010-10-27 07:16 . 2012-06-03 05:04 6066971 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1517543764-884281664-660548895-1000-8192.dat
- 2010-10-27 07:16 . 2012-06-02 06:01 6066971 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1517543764-884281664-660548895-1000-8192.dat
+ 2011-05-16 14:38 . 2012-06-03 05:04 39764032 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1517543764-884281664-660548895-1000-4096.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1555968]
"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-14 61440]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-05-23 128296]
"Google Quick Search Box"="c:\program files (x86)\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-07-21 122368]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"AdobeCS4ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"AVG_TRAY"="c:\program files (x86)\AVG\AVG10\avgtray.exe" [2012-01-18 2339168]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"Nikon Message Center 2"="c:\program files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe" [2010-05-26 619008]
"ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG10\avgchsva.exe /sync\0c:\progra~2\AVG\AVG10\avgrsa.exe /sync /restart
.
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-03-05 88576]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-06-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-31 22:01]
.
2012-06-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-31 22:01]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-03-05 6963744]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [BU]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.yahoo.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
Trusted Zone: intuit.com\ttlc
TCP: DhcpNameServer = 10.0.0.1
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\JSXFile\shell\Edit]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\JSXFile\shell\Open]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Photoshop.Image.11\protocol\StdFileEditing\server]
@DACL=(02 0000)
@="c:\\Program Files\\Adobe\\Adobe Photoshop CS4 (64 Bit)\\Photoshop.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files (x86)\AVG\AVG10\avgwdsvc.exe
c:\program files (x86)\Common Files\Motive\McciCMService.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
c:\program files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
c:\program files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
.
**************************************************************************
.
Completion time: 2012-06-03 01:12:52 - machine was rebooted
ComboFix-quarantined-files.txt 2012-06-03 05:12
ComboFix2.txt 2012-06-02 06:09
.
Pre-Run: 203,048,206,336 bytes free
Post-Run: 202,809,835,520 bytes free
.
- - End Of File - - 8146B7DDB0A963223F06F3AE32831D64