ComboFix 16-07-16.01 - Administrator 07/18/2016 8:38.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.63.1033.18.1914.925 [GMT 8:00]
Running from: c:\users\Administrator\Downloads\ComboFix.exe
AV: Norton Security *Disabled/Updated* {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
FW: Norton Security *Enabled* {6BFC5632-188D-B806-D13E-C607121B42A0}
SP: Norton Security *Disabled/Updated* {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}
SP: Spybot - Search and Destroy *Disabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\DEBUG.log
c:\windows\wininit.ini
.
Infected copy of c:\windows\SysWow64\userinit.exe was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
.
.
((((((((((((((((((((((((( Files Created from 2016-06-18 to 2016-07-18 )))))))))))))))))))))))))))))))
.
.
2016-07-18 00:48 . 2016-07-18 00:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-07-17 01:55 . 2016-07-17 01:55 -------- d-----w- c:\program files\RogueKiller
2016-07-17 01:26 . 2016-07-17 01:30 -------- d-----w- C:\FRST
2016-07-16 16:01 . 2016-07-16 16:01 -------- d-----w- c:\users\Administrator\Nox_share
2016-07-16 16:01 . 2016-07-16 16:14 -------- d-----w- c:\users\Administrator\vmlogs
2016-07-16 15:55 . 2016-07-16 16:14 -------- d-----w- c:\users\Administrator\.BigNox
2016-07-16 15:54 . 2015-09-16 06:07 127432 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2016-07-16 15:54 . 2016-07-16 15:54 -------- d-----w- c:\program files\DIFX
2016-07-16 15:53 . 2015-09-16 03:29 253384 ----a-w- c:\windows\system32\drivers\XQHDrv.sys
2016-07-16 15:53 . 2016-07-16 16:29 -------- dc----w- c:\windows\system32\DRVSTORE
2016-07-16 15:48 . 2016-07-16 16:31 -------- d-----w- c:\users\Administrator\AppData\Roaming\Nox
2016-07-16 15:47 . 2016-07-16 16:30 -------- d-----w- c:\users\Administrator\AppData\Local\Nox
2016-07-16 12:18 . 2016-07-18 00:34 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2016-07-16 12:18 . 2016-07-18 00:51 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2
2016-07-16 10:22 . 2016-07-16 10:35 -------- d-----w- c:\users\Administrator\AppData\Roaming\Wireshark
2016-07-16 10:16 . 2016-07-16 10:16 -------- d-----w- c:\program files (x86)\WinPcap
2016-07-16 10:15 . 2016-07-16 10:15 -------- d-----w- c:\programdata\Package Cache
2016-07-16 10:14 . 2016-07-16 10:16 -------- d-----w- c:\program files\Wireshark
2016-07-16 04:00 . 2016-07-16 12:26 -------- d-----w- c:\program files\Common Files\AV
2016-07-16 03:46 . 2016-07-16 04:48 -------- d-----w- c:\users\Administrator\AppData\Local\NPE
2016-07-16 00:59 . 2016-07-16 00:59 -------- d-----w- c:\program files (x86)\Common Files\Symantec Shared
2016-07-16 00:54 . 2016-07-16 00:54 111344 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS
2016-07-16 00:54 . 2016-07-16 00:54 -------- d-----w- c:\program files\Common Files\Symantec Shared
2016-07-16 00:51 . 2016-07-16 22:57 -------- d-----w- c:\windows\system32\drivers\NSx64
2016-07-16 00:51 . 2016-07-16 00:51 -------- d-----w- c:\program files (x86)\Norton Security
2016-07-16 00:47 . 2016-07-16 00:47 -------- d-----w- c:\program files (x86)\NortonInstaller
2016-07-16 00:31 . 2016-07-16 04:06 -------- d-----w- c:\programdata\Norton
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-07-18 00:52 . 2015-07-12 15:13 192216 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2016-07-17 04:24 . 2015-02-19 18:39 28272 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2016-07-13 09:01 . 2015-02-12 18:45 796352 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2016-07-13 09:01 . 2015-02-12 18:45 142528 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2016-07-07 00:39 . 2010-11-21 03:27 485032 ------w- c:\windows\system32\MpSigStub.exe
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2013-01-10 . 332FEAB1435662FC6C672E25BEB37BE3 . 2871808 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[7] 2013-01-10 . 3B69712041F3D63605529BD66DC00C48 . 2871808 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[-] 2010-11-21 . 0FEF117801269BA26F1D63B2F1CDC6AA . 2389504 . . [6.1.7600.16385] .. c:\windows\explorer.exe
[7] 2010-11-21 . AC4C51EB24AA95B77F705AB159189E24 . 2872320 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"SpybotPostWindows10UpgradeReInstall"="c:\program files\Common Files\AV\Spybot - Search and Destroy\Test.exe" [2015-07-28 1011200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-01-22 91520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"TaskbarNoNotification"= 1 (0x1)
"HideSCAHealth"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R3 2310_00;2310_00;c:\windows\system32\drivers\2310_00.sys;c:\windows\SYSNATIVE\drivers\2310_00.sys [x]
R3 272x_1x;272x_1x;c:\windows\system32\drivers\272x_1x.sys;c:\windows\SYSNATIVE\drivers\272x_1x.sys [x]
R3 274x_3x;274x_3x;c:\windows\system32\drivers\274x_3x.sys;c:\windows\SYSNATIVE\drivers\274x_3x.sys [x]
R3 ahcix64s;ahcix64s;c:\windows\system32\drivers\ahcix64s.sys;c:\windows\SYSNATIVE\drivers\ahcix64s.sys [x]
R3 amd_sata;amd_sata;c:\windows\system32\drivers\amd_sata.sys;c:\windows\SYSNATIVE\drivers\amd_sata.sys [x]
R3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\drivers\amdhub30.sys;c:\windows\SYSNATIVE\drivers\amdhub30.sys [x]
R3 amdide64;amdide64;c:\windows\system32\drivers\amdide64.sys;c:\windows\SYSNATIVE\drivers\amdide64.sys [x]
R3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\drivers\amdxhc.sys;c:\windows\SYSNATIVE\drivers\amdxhc.sys [x]
R3 arcm_a64;arcm_a64;c:\windows\system32\drivers\arcm_a64.sys;c:\windows\SYSNATIVE\drivers\arcm_a64.sys [x]
R3 asahci64;asahci64;c:\windows\system32\drivers\asahci64.sys;c:\windows\SYSNATIVE\drivers\asahci64.sys [x]
R3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\drivers\asmthub3.sys;c:\windows\SYSNATIVE\drivers\asmthub3.sys [x]
R3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\drivers\asmtxhci.sys;c:\windows\SYSNATIVE\drivers\asmtxhci.sys [x]
R3 b06diag;Broadcom NetXtreme II Diag Driver;c:\windows\system32\drivers\bxdiaga.sys;c:\windows\SYSNATIVE\drivers\bxdiaga.sys [x]
R3 BFN7x64;Bigfoot Networks Killer Gaming Service;c:\windows\system32\drivers\Xeno7x64.sys;c:\windows\SYSNATIVE\drivers\Xeno7x64.sys [x]
R3 BFNVis64;Bigfoot Networks Killer Gaming Service;c:\windows\system32\drivers\XenoVa64.sys;c:\windows\SYSNATIVE\drivers\XenoVa64.sys [x]
R3 bxfcoe;bxfcoe;c:\windows\system32\drivers\bxfcoe.sys;c:\windows\SYSNATIVE\drivers\bxfcoe.sys [x]
R3 bxois;bxois;c:\windows\system32\drivers\bxois.sys;c:\windows\SYSNATIVE\drivers\bxois.sys [x]
R3 cbaf;UWB Cable Based Association Framework Driver;c:\windows\System32\Drivers\cbaf.sys;c:\windows\SYSNATIVE\Drivers\cbaf.sys [x]
R3 DC133;DC133;c:\windows\system32\drivers\DC133.sys;c:\windows\SYSNATIVE\drivers\DC133.sys [x]
R3 DC150;DC150;c:\windows\system32\drivers\DC150.sys;c:\windows\SYSNATIVE\drivers\DC150.sys [x]
R3 DC154;DC154;c:\windows\system32\drivers\DC154.sys;c:\windows\SYSNATIVE\drivers\DC154.sys [x]
R3 DC300e;DC300e;c:\windows\system32\drivers\DC300e.sys;c:\windows\SYSNATIVE\drivers\DC300e.sys [x]
R3 DC324e;DC324e;c:\windows\system32\drivers\DC324e.sys;c:\windows\SYSNATIVE\drivers\DC324e.sys [x]
R3 DC4300;DC4300;c:\windows\system32\drivers\DC4300.sys;c:\windows\SYSNATIVE\drivers\DC4300.sys [x]
R3 DC600e;DC600e;c:\windows\system32\drivers\DC600e.sys;c:\windows\SYSNATIVE\drivers\DC600e.sys [x]
R3 dfuuwb;Intel Wireless UWB Link 1480M Device Firmware Utility;c:\windows\System32\Drivers\DfuUWB.sys;c:\windows\SYSNATIVE\Drivers\DfuUWB.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\System32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
R3 EtronSTOR;Etron Enhance USB BOT/UASP Mass Storage Driver;c:\windows\System32\Drivers\EtronSTOR.sys;c:\windows\SYSNATIVE\Drivers\EtronSTOR.sys [x]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\System32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
R3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver;c:\windows\system32\drivers\FLxHCIc.sys;c:\windows\SYSNATIVE\drivers\FLxHCIc.sys [x]
R3 FLxHCIh;Fresco Logic xHCI (USB3) Hub Device Driver;c:\windows\system32\drivers\FLxHCIh.sys;c:\windows\SYSNATIVE\drivers\FLxHCIh.sys [x]
R3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\drivers\HECIx64.sys;c:\windows\SYSNATIVE\drivers\HECIx64.sys [x]
R3 hptiop;hptiop;c:\windows\system32\drivers\hptiop.sys;c:\windows\SYSNATIVE\drivers\hptiop.sys [x]
R3 hptmv;hptmv;c:\windows\system32\drivers\hptmv.sys;c:\windows\SYSNATIVE\drivers\hptmv.sys [x]
R3 hptmv6;hptmv6;c:\windows\system32\drivers\hptmv6.sys;c:\windows\SYSNATIVE\drivers\hptmv6.sys [x]
R3 HWA;Intel(R) Wireless USB Host Adapter;c:\windows\System32\Drivers\HWA.sys;c:\windows\SYSNATIVE\Drivers\HWA.sys [x]
R3 IAMTVE;Driver for Intel(R) Active Management Technology - KCS;c:\windows\system32\drivers\IAMTVE.sys;c:\windows\SYSNATIVE\drivers\IAMTVE.sys [x]
R3 IAMTXPE;Driver for Intel(R) Active Management Technology - KCS;c:\windows\system32\drivers\IAMTXPE.sys;c:\windows\SYSNATIVE\drivers\IAMTXPE.sys [x]
R3 iaStorA;iaStorA;c:\windows\system32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
R3 iaStorS;iaStorS;c:\windows\system32\drivers\iaStorS.sys;c:\windows\SYSNATIVE\drivers\iaStorS.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 IFCoEMP;IFCoEMP;c:\windows\system32\drivers\ifM60x64.sys;c:\windows\SYSNATIVE\drivers\ifM60x64.sys [x]
R3 IFCoEVB;IFCoEVB;c:\windows\system32\drivers\ifP60X64.sys;c:\windows\SYSNATIVE\drivers\ifP60X64.sys [x]
R3 ioatdma1;ioatdma1;c:\windows\System32\Drivers\qd162x64.sys;c:\windows\SYSNATIVE\Drivers\qd162x64.sys [x]
R3 ioatdma2;Intel(R) QuickData Technology device ver.2;c:\windows\System32\Drivers\qd262x64.sys;c:\windows\SYSNATIVE\Drivers\qd262x64.sys [x]
R3 ISCT;Intel(R) Smart Connect Technology Device Driver;c:\windows\system32\drivers\ISCTD64.sys;c:\windows\SYSNATIVE\drivers\ISCTD64.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 megasas2;megasas2;c:\windows\system32\drivers\megasas2.sys;c:\windows\SYSNATIVE\drivers\megasas2.sys [x]
R3 megasr1;megasr1;c:\windows\system32\drivers\MegaSR1.sys;c:\windows\SYSNATIVE\drivers\MegaSR1.sys [x]
R3 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys;c:\windows\SYSNATIVE\drivers\mv61xx.sys [x]
R3 mv91cons;mv91cons;c:\windows\system32\drivers\mv91cons.sys;c:\windows\SYSNATIVE\drivers\mv91cons.sys [x]
R3 mvs94xx;mvs94xx;c:\windows\system32\drivers\mvs94xx.sys;c:\windows\SYSNATIVE\drivers\mvs94xx.sys [x]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x]
R3 ocz10xx;ocz10xx;c:\windows\system32\drivers\ocz10xx.sys;c:\windows\SYSNATIVE\drivers\ocz10xx.sys [x]
R3 ocz12xx;ocz12xx;c:\windows\system32\drivers\ocz12xx.sys;c:\windows\SYSNATIVE\drivers\ocz12xx.sys [x]
R3 percsas2;percsas2;c:\windows\system32\drivers\percsas2.sys;c:\windows\SYSNATIVE\drivers\percsas2.sys [x]
R3 Pnp680;Pnp680;c:\windows\system32\drivers\pnp680.sys;c:\windows\SYSNATIVE\drivers\pnp680.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 rr172x;rr172x;c:\windows\system32\drivers\rr172x.sys;c:\windows\SYSNATIVE\drivers\rr172x.sys [x]
R3 rr174x;rr174x;c:\windows\system32\drivers\rr174x.sys;c:\windows\SYSNATIVE\drivers\rr174x.sys [x]
R3 rr2210;rr2210;c:\windows\system32\drivers\rr2210.sys;c:\windows\SYSNATIVE\drivers\rr2210.sys [x]
R3 rr232x;rr232x;c:\windows\system32\drivers\rr232x.sys;c:\windows\SYSNATIVE\drivers\rr232x.sys [x]
R3 rr2340;rr2340;c:\windows\system32\drivers\rr2340.sys;c:\windows\SYSNATIVE\drivers\rr2340.sys [x]
R3 rr2522;rr2522;c:\windows\system32\drivers\rr2522.sys;c:\windows\SYSNATIVE\drivers\rr2522.sys [x]
R3 rr276x;rr276x;c:\windows\system32\drivers\rr276x.sys;c:\windows\SYSNATIVE\drivers\rr276x.sys [x]
R3 rr278x;rr278x;c:\windows\system32\drivers\rr278x.sys;c:\windows\SYSNATIVE\drivers\rr278x.sys [x]
R3 rr62x;rr62x;c:\windows\system32\drivers\rr62x.sys;c:\windows\SYSNATIVE\drivers\rr62x.sys [x]
R3 rusb3hub;Renesas Electronics USB 3.0 Hub Driver (Version 3.0);c:\windows\system32\drivers\rusb3hub.sys;c:\windows\SYSNATIVE\drivers\rusb3hub.sys [x]
R3 rusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver (Version 3.0);c:\windows\system32\drivers\rusb3xhc.sys;c:\windows\SYSNATIVE\drivers\rusb3xhc.sys [x]
R3 SI3112r;SI3112r;c:\windows\system32\drivers\SI3112r.sys;c:\windows\SYSNATIVE\drivers\SI3112r.sys [x]
R3 SI3114;SI3114;c:\windows\system32\drivers\SI3114.sys;c:\windows\SYSNATIVE\drivers\SI3114.sys [x]
R3 SI3124;SI3124;c:\windows\system32\drivers\SI3124.sys;c:\windows\SYSNATIVE\drivers\SI3124.sys [x]
R3 Si3124r5;Si3124r5;c:\windows\system32\drivers\Si3124r5.sys;c:\windows\SYSNATIVE\drivers\Si3124r5.sys [x]
R3 Si3531;Si3531;c:\windows\system32\drivers\Si3531.sys;c:\windows\SYSNATIVE\drivers\Si3531.sys [x]
R3 silabenm;Silicon Labs CP210x USB to UART Bridge Serial Port Enumerator Driver;c:\windows\system32\drivers\silabenm.sys;c:\windows\SYSNATIVE\drivers\silabenm.sys [x]
R3 silabser;Silicon Labs CP210x USB to UART Bridge Driver;c:\windows\system32\drivers\silabser.sys;c:\windows\SYSNATIVE\drivers\silabser.sys [x]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 tihub3;TI USB3 Hub Service;c:\windows\system32\drivers\tihub3.sys;c:\windows\SYSNATIVE\drivers\tihub3.sys [x]
R3 tixhci;TI XHCI Service;c:\windows\system32\drivers\tixhci.sys;c:\windows\SYSNATIVE\drivers\tixhci.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 uwbusb;UWB Bus Control USB-Miniport Driver;c:\windows\System32\Drivers\usbuwbmini.sys;c:\windows\SYSNATIVE\Drivers\usbuwbmini.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 viamrx64;viamrx64;c:\windows\system32\drivers\viamrx64.sys;c:\windows\SYSNATIVE\drivers\viamrx64.sys [x]
R3 videX64;videX64;c:\windows\system32\drivers\videX64.sys;c:\windows\SYSNATIVE\drivers\videX64.sys [x]
R3 vmci;vmci;c:\windows\system32\drivers\vmci.sys;c:\windows\SYSNATIVE\drivers\vmci.sys [x]
R3 VUSB3HUB;VIA USB 3 Root Hub Service;c:\windows\system32\drivers\ViaHub3.sys;c:\windows\SYSNATIVE\drivers\ViaHub3.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 xhcdrv;VIA USB eXtensible Host Controller Service;c:\windows\system32\drivers\xhcdrv.sys;c:\windows\SYSNATIVE\drivers\xhcdrv.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\drivers\amd_xata.sys;c:\windows\SYSNATIVE\drivers\amd_xata.sys [x]
S0 DC3410;DC3410;c:\windows\system32\drivers\DC3410.sys;c:\windows\SYSNATIVE\drivers\DC3410.sys [x]
S0 iaStorF;iaStorF;c:\windows\system32\drivers\iaStorF.sys;c:\windows\SYSNATIVE\drivers\iaStorF.sys [x]
S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\drivers\iusb3hcs.sys;c:\windows\SYSNATIVE\drivers\iusb3hcs.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S0 SymEFASI;Symantec Extended File Attributes (SI);c:\windows\system32\drivers\NSx64\1606000.08E\SYMEFASI64.SYS;c:\windows\SYSNATIVE\drivers\NSx64\1606000.08E\SYMEFASI64.SYS [x]
S0 xfiltx64;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfiltx64.sys;c:\windows\SYSNATIVE\drivers\xfiltx64.sys [x]
S1 BHDrvx64;BHDrvx64;c:\program files (x86)\Norton Security\NortonData\22.5.4.24\Definitions\BASHDefs\20160711.001\BHDrvx64.sys;c:\program files (x86)\Norton Security\NortonData\22.5.4.24\Definitions\BASHDefs\20160711.001\BHDrvx64.sys [x]
S1 ccSet_NS;NS Settings Manager;c:\windows\system32\drivers\NSx64\1606000.08E\ccSetx64.sys;c:\windows\SYSNATIVE\drivers\NSx64\1606000.08E\ccSetx64.sys [x]
S1 IDSVia64;IDSVia64;c:\program files (x86)\Norton Security\NortonData\22.5.4.24\Definitions\IPSDefs\20160715.001\IDSvia64.sys;c:\program files (x86)\Norton Security\NortonData\22.5.4.24\Definitions\IPSDefs\20160715.001\IDSvia64.sys [x]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NSx64\1606000.08E\Ironx64.SYS;c:\windows\SYSNATIVE\drivers\NSx64\1606000.08E\Ironx64.SYS [x]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NSx64\1606000.08E\SYMNETS.SYS;c:\windows\SYSNATIVE\Drivers\NSx64\1606000.08E\SYMNETS.SYS [x]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxUSBMon.sys [x]
S1 XQHDrv;BigNox Service;c:\windows\system32\DRIVERS\XQHDrv.sys;c:\windows\SYSNATIVE\DRIVERS\XQHDrv.sys [x]
S2 AGSService;Adobe Genuine Software Integrity Service;c:\program files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe;c:\program files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [x]
S2 DashClientService;DashClientService;c:\program files (x86)\Realtek\RtkWin7(8)DashClientInstaller\RtkDashService64.exe;c:\program files (x86)\Realtek\RtkWin7(8)DashClientInstaller\RtkDashService64.exe [x]
S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys;c:\windows\SYSNATIVE\drivers\npf.sys [x]
S2 NS;Norton Security;c:\program files (x86)\Norton Security\Engine\22.6.0.142\NS.exe;c:\program files (x86)\Norton Security\Engine\22.6.0.142\NS.exe [x]
S2 RtDashPt;Realtek DASH Protocol Driver;c:\windows\system32\DRIVERS\RtDashPt.sys;c:\windows\SYSNATIVE\DRIVERS\RtDashPt.sys [x]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x]
S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x]
S3 rtkio;rtkio;c:\program files (x86)\Realtek\RtkWin7(8)DashClientInstaller\rtkio64.sys;c:\program files (x86)\Realtek\RtkWin7(8)DashClientInstaller\rtkio64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys;c:\windows\SYSNATIVE\drivers\usbfilter.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - RTKIO
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2016-06-17 22:51 1245848 ----a-w- c:\program files (x86)\Google\Chrome\Application\51.0.2704.103\Installer\chrmstp.exe
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{A6EADE66-0000-0000-484E-7E8A45000000}]
2016-06-30 11:55 322232 ----a-w- c:\program files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll
.
Contents of the 'Scheduled Tasks' folder
.
2016-07-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-12 09:01]
.
2016-07-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-02-21 02:53]
.
2016-07-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-02-21 02:53]
.
.
--------- X64 Entries -----------
.
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.254.254
FF - ProfilePath - c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\j809lgaq.default\
FF - prefs.js: browser.startup.homepage - hxxps://
www.google.com.ph/?gfe_rd=cr&ei=3jnZVMqMN-aK8QeuzIHoCA
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKCU-Run-BlueStacks Agent - c:\program files (x86)\BlueStacks\HD-Agent.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-File Audit_is1 - c:\program files (x86)\File Audit\unins000.exe
AddRemove-IDM Patch 6.25 build 03 - c:\program files (x86)\Internet Download Manager\Uninstall.exe
AddRemove-{8840E960-F3C1-11DC-4823-0BBCFDB50029} - c:\intellisoft\MMAE\Uninst_ae.exe
AddRemove-uTorrent - c:\users\Administrator\AppData\Roaming\uTorrent\uTorrent.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NS]
"ImagePath"="\"c:\program files (x86)\Norton Security\Engine\22.6.0.142\NS.exe\" /s \"NS\" /m \"c:\program files (x86)\Norton Security\Engine\22.6.0.142\diMaster.dll\" /prefetch:1"
"ImagePath"="\SystemRoot\System32\Drivers\NSx64\1606000.08E\SYMNETS.SYS"
"TrustedImagePaths"="c:\program files (x86)\Norton Security\Engine\22.6.0.142;c:\program files (x86)\Norton Security\Engine64\22.6.0.142"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (Administrator)
"Timestamp"=hex:dd,a6,fb,8c,3e,45,d0,01
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,60,c4,fd,e4,92,ca,9f,43,aa,c5,b0,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,60,c4,fd,e4,92,ca,9f,43,aa,c5,b0,\
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.3G2"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.3GP"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.3G2"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.3GP"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AAC\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ADTS"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADT\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ADTS"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADTS\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ADTS"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASF"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASX"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AU"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="VLC.avi"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.CDA"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2T\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.M2TS"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2TS\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.M2TS"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2V\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.m3u"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.M4A"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP4"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MOD\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MOV"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP3"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP3"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP4"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP4"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MTS\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.M2TS"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="AcroExch.Document.DC"
"Hash"="cGPTYUlwAyE="
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\Prezi.exe"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AU"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TS\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.TTS"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TTS\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.TTS"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WAV"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WAX"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASF"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMA"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMD"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMS"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMV"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASX"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmz\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMZ"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpl\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WPL"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WVX"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500_Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):a0,4b,1b,cc,59,aa,eb,a7,fb,76,d1,c8,4d,9e,11,e2,49,5e,b0,0d,aa,
0b,68,75,68,0b,cf,b4,82,43,c9,e3,34,6c,b5,8e,64,81,94,3a,00,00,00,00,00,00,\
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500_Classes\Wow6432Node\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):5d,a8,d2,bc,ff,c0,b4,d8,c7,ac,6a,46,2c,a8,eb,9a,61,7f,e1,1e,75,
d5,79,8b,b2,2f,2f,8f,47,a9,78,aa,eb,8c,51,1f,73,58,70,bf,00,00,00,00,00,00,\
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500_Classes\Wow6432Node\CLSID\{83ed2cc3-6dfd-40d6-b9fe-21cf68cc8557}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:0000009a
"Therad"=dword:0000000f
.
[HKEY_USERS\S-1-5-21-378024836-819946511-3807712176-500_Classes\Wow6432Node\CLSID\{e05c6977-3a1d-463a-bb44-3663a6fb00ba}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000046
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,5e,82,77,36,a1,de,e3,5e,54,29,86,0c,2f,8c,7e,87,15,19,98,a7,c2,04,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:e3,ec,c7,c6,5c,42,77,47,25,83,58,5d,3b,1f,0a,db,41,7e,f0,2b,12,
ca,c7,63,0a,cc,90,03,45,fa,b2,19,6c,cf,30,24,fb,13,f5,4d,b6,04,d2,12,95,f2,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:e3,ec,c7,c6,5c,42,77,47,25,83,58,5d,3b,1f,0a,db,41,7e,f0,2b,12,
ca,c7,63,0a,cc,90,03,45,fa,b2,19,6c,cf,30,24,fb,13,f5,4d,b6,04,d2,12,95,f2,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
.
**************************************************************************
.
Completion time: 2016-07-18 08:59:19 - machine was rebooted
ComboFix-quarantined-files.txt 2016-07-18 00:59
.
Pre-Run: 347,299,221,504 bytes free
Post-Run: 348,669,181,952 bytes free
.
- - End Of File - - F3C8E1CD74F7B9E70BAC88495F28ADCB
A36C5E4F47E84449FF07ED3517B43A31