ComboFix 14-01-29.01 - user 01/30/2014 1:23.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.5327.3891 [GMT -4.5:30]
Running from: c:\users\user\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2013-12-28 to 2014-01-30 )))))))))))))))))))))))))))))))
.
.
2014-01-30 05:58 . 2014-01-30 05:58 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-01-30 03:55 . 2014-01-30 05:33 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2014-01-30 03:54 . 2014-01-30 04:40 119000 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-01-30 03:54 . 2014-01-30 03:54 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-01-29 15:28 . 2014-01-29 15:28 -------- d-----w- c:\programdata\Malwarebytes
2014-01-29 15:28 . 2014-01-29 15:28 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2014-01-29 15:28 . 2013-04-04 19:20 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-01-29 06:57 . 2013-12-03 23:58 10315576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D93B9976-F53B-4953-A6DC-217121CB273D}\mpengine.dll
2014-01-29 05:47 . 2014-01-29 05:47 -------- d-----w- c:\program files (x86)\BlueStacks
2014-01-29 05:47 . 2014-01-29 05:48 -------- d-----w- c:\programdata\BlueStacks
2014-01-28 15:05 . 2013-12-03 23:58 10315576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-01-26 02:02 . 2014-01-26 02:02 -------- d-----w- c:\program files (x86)\Common Files\Skype
2014-01-26 02:02 . 2014-01-26 02:02 -------- d-----r- c:\program files (x86)\Skype
2014-01-23 06:40 . 2014-01-23 06:39 46368 ----a-w- c:\windows\system32\drivers\avgtpx64.sys
2014-01-23 06:39 . 2014-01-23 06:40 -------- d-----w- c:\program files (x86)\Common Files\AVG Secure Search
2014-01-23 06:39 . 2014-01-24 11:12 -------- d-----w- c:\programdata\AVG SafeGuard toolbar
2014-01-23 06:39 . 2014-01-23 06:39 -------- d-----w- c:\program files (x86)\AVG SafeGuard toolbar
2014-01-23 06:39 . 2014-01-23 06:39 -------- d--h--w- c:\programdata\Common Files
2014-01-23 06:39 . 2014-01-23 06:39 -------- d-----w- c:\program files (x86)\HyperCam 2
2014-01-23 06:33 . 2014-01-11 15:30 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-01-23 06:33 . 2014-01-11 15:30 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C21DEF8C-42A1-44D0-A30D-90F231F95593}\gapaengine.dll
2014-01-22 20:50 . 2014-01-23 05:19 -------- d-----w- c:\program files (x86)\iWisoft Free Video Downloader
2014-01-22 20:47 . 2014-01-22 20:49 -------- d-----w- c:\program files (x86)\Mobogenie
2014-01-22 20:46 . 2009-09-30 01:27 758018 ----a-w- c:\windows\SysWow64\xvidcore.dll
2014-01-22 20:46 . 2008-12-05 02:16 180224 ----a-w- c:\windows\SysWow64\xvidvfw.dll
2014-01-22 20:46 . 2008-10-08 14:46 139264 ----a-w- c:\windows\SysWow64\xvid.ax
2014-01-22 20:46 . 2014-01-22 20:53 -------- d-----w- c:\program files (x86)\iWisoft Free Video Converter
2014-01-22 20:43 . 2014-01-29 19:55 -------- d-----w- c:\program files (x86)\MyPC Backup
2014-01-20 07:42 . 2014-01-26 02:02 -------- d-----w- c:\programdata\Skype
2014-01-19 01:20 . 2012-08-21 17:31 33240 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2014-01-19 01:20 . 2014-01-19 01:20 -------- d-----w- c:\program files\iPod
2014-01-19 01:20 . 2014-01-19 01:20 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-01-19 01:20 . 2014-01-19 01:20 -------- d-----w- c:\program files\iTunes
2014-01-19 01:20 . 2014-01-19 01:20 -------- d-----w- c:\program files (x86)\iTunes
2014-01-19 01:20 . 2014-01-19 01:20 -------- d-----w- c:\programdata\Apple Computer
2014-01-19 01:15 . 2014-01-19 01:15 -------- d-----w- c:\program files (x86)\Apple Software Update
2014-01-19 01:12 . 2014-01-19 01:12 -------- d-----w- c:\program files\Common Files\Apple
2014-01-19 01:12 . 2014-01-19 01:12 -------- d-----w- c:\program files\Bonjour
2014-01-19 01:12 . 2014-01-19 01:12 -------- d-----w- c:\program files (x86)\Bonjour
2014-01-19 01:12 . 2014-01-19 01:20 -------- d-----w- c:\program files (x86)\Common Files\Apple
2014-01-19 01:12 . 2014-01-19 01:14 -------- d-----w- c:\programdata\Apple
2014-01-19 00:49 . 2014-01-19 00:50 -------- d-----w- c:\program files\WinRAR
2014-01-18 16:21 . 2014-01-18 16:30 -------- d-----w- c:\program files (x86)\ManyCam
2014-01-18 14:56 . 2014-01-18 14:56 -------- d-----w- c:\program files\McAfee Security Scan
2014-01-18 14:21 . 2014-01-18 14:21 -------- d-----w- c:\programdata\McAfee Security Scan
2014-01-18 14:21 . 2014-01-18 14:21 -------- d-----w- c:\programdata\McAfee
2014-01-18 14:01 . 2014-01-18 14:01 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2014-01-18 13:33 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2014-01-18 13:33 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe
2014-01-18 13:33 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll
2014-01-18 13:33 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll
2014-01-18 13:33 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll
2014-01-18 13:33 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll
2014-01-18 13:33 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll
2014-01-18 13:33 . 2012-06-02 19:49 186752 ----a-w- c:\windows\system32\wuwebv.dll
2014-01-18 13:33 . 2012-06-02 19:45 36864 ----a-w- c:\windows\system32\wuapp.exe
2014-01-18 13:16 . 2014-01-27 14:54 -------- d-----w- c:\program files\Google
2014-01-18 13:16 . 2014-01-27 14:54 -------- d-----w- c:\program files (x86)\Google
2014-01-18 13:16 . 2014-01-18 14:21 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-01-18 13:16 . 2014-01-18 14:21 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-01-18 13:15 . 2014-01-18 13:15 -------- d-----w- c:\windows\SysWow64\Macromed
2014-01-18 13:15 . 2014-01-18 13:15 -------- d-----w- c:\windows\system32\Macromed
2014-01-12 05:26 . 2014-01-11 14:09 -------- d-----w- c:\windows\Panther
2014-01-11 15:30 . 2014-01-11 15:30 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2014-01-11 15:30 . 2014-01-11 15:30 -------- d-----w- c:\program files\Microsoft Security Client
2014-01-11 15:21 . 2014-01-11 15:21 -------- d-----w- c:\programdata\Ashampoo
2014-01-11 15:21 . 2014-01-11 15:21 -------- d-----w- c:\program files (x86)\Ashampoo
2014-01-11 15:13 . 2014-01-11 15:13 -------- d-----w- c:\program files (x86)\VideoLAN
2014-01-11 15:05 . 2014-01-11 15:05 -------- d-----w- c:\programdata\Microsoft Toolkit
2014-01-11 14:41 . 2014-01-11 14:41 -------- d-----w- c:\program files\Common Files\DESIGNER
2014-01-11 14:41 . 2014-01-11 14:41 -------- d-----w- c:\program files\Microsoft.NET
2014-01-11 14:41 . 2014-01-11 14:41 -------- d-----w- c:\program files (x86)\Microsoft SQL Server
2014-01-11 14:41 . 2014-01-11 14:41 -------- d-----w- c:\programdata\regid.1991-06.com.microsoft
2014-01-11 14:41 . 2014-01-11 14:41 -------- d-----w- c:\program files\Microsoft SQL Server
2014-01-11 14:41 . 2014-01-11 14:41 -------- d-----w- c:\windows\PCHEALTH
2014-01-11 14:39 . 2014-01-11 14:39 -------- d-----w- c:\program files\Microsoft Analysis Services
2014-01-11 14:39 . 2014-01-11 14:39 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2014-01-11 14:38 . 2014-01-11 14:41 -------- d-----w- c:\program files\Microsoft Office
2014-01-11 14:38 . 2014-01-11 14:45 -------- d-----w- c:\programdata\Microsoft Help
2014-01-11 14:38 . 2014-01-11 14:38 -------- d-----r- C:\MSOCache
2014-01-11 14:38 . 2014-01-11 14:38 -------- d-----w- c:\programdata\ATI
2014-01-11 14:27 . 2014-01-11 14:27 0 ----a-w- c:\windows\ativpsrm.bin
2014-01-11 14:27 . 2014-01-11 14:27 -------- d-----w- c:\windows\SysWow64\RTCOM
2014-01-11 14:27 . 2014-01-11 14:27 -------- d-----w- c:\program files\Realtek
2014-01-11 14:25 . 2012-12-26 17:26 805088 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2014-01-11 14:25 . 2012-12-26 17:26 74344 ----a-w- c:\windows\system32\RtNicProp64.dll
2014-01-11 14:25 . 2012-12-26 17:26 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2014-01-11 14:25 . 2014-01-11 14:26 -------- d-----w- c:\program files (x86)\Realtek
2014-01-11 14:25 . 2014-01-11 14:26 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
2014-01-11 14:23 . 2014-01-11 14:23 -------- d-----w- c:\program files\Common Files\ATI Technologies
2014-01-11 14:23 . 2014-01-11 14:23 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
2014-01-11 14:23 . 2014-01-11 14:23 -------- d-----w- c:\program files (x86)\AMD AVT
2014-01-11 14:23 . 2014-01-11 14:23 -------- d-----w- c:\program files\AMD
2014-01-11 14:23 . 2014-01-11 14:23 -------- d-----w- c:\program files (x86)\AMD
2014-01-11 14:23 . 2014-01-11 14:23 -------- d-----w- c:\programdata\AMD
2014-01-11 14:19 . 2014-01-11 14:41 -------- d-----w- c:\program files (x86)\Microsoft.NET
2014-01-11 14:18 . 2014-01-29 05:49 -------- d-sh--w- c:\windows\Installer
2014-01-11 14:17 . 2014-01-11 14:23 -------- d-----w- c:\program files\ATI Technologies
2014-01-11 14:17 . 2014-01-11 14:17 -------- d-----w- c:\program files\ATI
2014-01-11 14:16 . 2014-01-11 14:16 -------- d-----w- C:\MSI
2014-01-11 14:09 . 2014-01-26 10:54 -------- d-----w- c:\users\user
2014-01-11 14:09 . 2014-01-11 14:09 -------- d-----w- C:\Recovery
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-19 07:33 . 2010-11-21 03:27 270496 ------w- c:\windows\system32\MpSigStub.exe
2013-12-06 13:37 . 2013-12-06 13:37 35232 ----a-w- c:\windows\system32\drivers\mcaudrv_x64.sys
2013-11-27 01:54 . 2013-11-27 01:54 42016 ----a-w- c:\windows\system32\drivers\mcvidrv.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2014-01-23 06:39 3401752 ----a-w- c:\program files (x86)\AVG SafeGuard toolbar\17.3.1.91\AVG SafeGuard toolbar_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files (x86)\AVG SafeGuard toolbar\17.3.1.91\AVG SafeGuard toolbar_toolbar.dll" [2014-01-23 3401752]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2013-07-13 09:13 1724616 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2013-07-13 09:13 1724616 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2013-07-13 09:13 1724616 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ManyCam"="c:\program files (x86)\ManyCam\ManyCam.exe" [2013-12-09 5679200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-03-22 642656]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-14 59720]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-11-02 152392]
"mobilegeni daemon"="c:\program files (x86)\Mobogenie\DaemonProcess.exe" [2014-01-22 766656]
"vProt"="c:\program files (x86)\AVG SafeGuard toolbar\vprot.exe" [2014-01-23 2534936]
"BlueStacks Agent"="c:\program files (x86)\BlueStacks\HD-Agent.exe" [2014-01-20 811792]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.8.130\SSScheduler.exe [2013-9-6 324320]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys;c:\windows\SYSNATIVE\drivers\mbamchameleon.sys [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.8.130\McCHSvc.exe;c:\program files\McAfee Security Scan\3.8.130\McCHSvc.exe [x]
R3 MSICDSetup;MSICDSetup;d:\cdriver64.sys;d:\CDriver64.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 NTIOLib_1_0_C;NTIOLib_1_0_C;d:\ntiolib_x64.sys;d:\NTIOLib_X64.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys;c:\windows\SYSNATIVE\drivers\avgtpx64.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AODDriver4.2;AODDriver4.2;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
S2 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
S2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [x]
S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [x]
S2 vToolbarUpdater17.3.0;vToolbarUpdater17.3.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe [x]
S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys;c:\windows\SYSNATIVE\DRIVERS\amdhub30.sys [x]
S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys;c:\windows\SYSNATIVE\DRIVERS\amdxhc.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\DRIVERS\mcvidrv.sys;c:\windows\SYSNATIVE\DRIVERS\mcvidrv.sys [x]
S3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv_x64.sys;c:\windows\SYSNATIVE\drivers\mcaudrv_x64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-01-29 20:51 1211672 ----a-w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.102\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-01-30 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-18 14:21]
.
2014-01-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-01-18 13:16]
.
2014-01-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-01-18 13:16]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2013-07-13 09:07 2328776 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2013-07-13 09:07 2328776 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2013-07-13 09:07 2328776 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2013-02-22 7018568]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 1266912]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office15\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office15\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.3.0\ViProtocol.dll
FF - ProfilePath - c:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\z7e3dkl6.default\
FF - prefs.js: browser.startup.homepage - hxxp://mysearch.avg.com?cid={939490DD-10A4-4E97-949F-933725842409}&mid=4724f637ba0b47d282540574387de11f-06ce4fc639803a2e3563922518183d8e94088cb9&lang=us/finishurl=
http://toolbar.avg.com/p-install?la...pr=sa&d=&v=17.3.1.91&pid=safeguard&sg=&sap=hp
FF - prefs.js: keyword.URL -
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\BlueStacks]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_38_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_38_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_38_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_38_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2014-01-30 01:29:54
ComboFix-quarantined-files.txt 2014-01-30 05:59
.
Pre-Run: 427,579,109,376 bytes free
Post-Run: 427,749,060,608 bytes free
.
- - End Of File - - 8B4F2AAE0F3E9BDB909F07C29F17A545
A36C5E4F47E84449FF07ED3517B43A31