Hi Broni,
I disabled Avast Free before running ComboFix.
Internet did NOT disconnect once ComboFix started, so after about 1-2 minutes, I manually disconnected.
Once ComboFix completed, I checked my Desktop and there was no .txt file, so I manually "Saved as" Dennis ComboFix Desktop May-24-2017
Here is the log ...
ComboFix 17-05-16.01 - Dennis 05/24/17 17:47:22.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.5815.4027 [GMT -7:00]
Running from: c:\users\Dennis\Desktop\ComboFix.exe
AV: Avast Antivirus *Disabled/Updated* {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
SP: Avast Antivirus *Disabled/Updated* {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Dennis\AppData\Roaming\Microsoft\Windows\Recent\Best Way to Back Up your Computer.url
c:\users\Dennis\AppData\Roaming\Microsoft\Windows\Recent\Best way to give Feedback to Win product team July15-2016.url
.
.
((((((((((((((((((((((((( Files Created from 2017-04-25 to 2017-05-25 )))))))))))))))))))))))))))))))
.
.
2017-05-25 01:03 . 2017-05-25 01:03 -------- d-----w- c:\users\test\AppData\Local\temp
2017-05-25 01:03 . 2017-05-25 01:03 -------- d-----w- c:\users\Public\AppData\Local\temp
2017-05-25 01:03 . 2017-05-25 01:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2017-05-24 19:56 . 2017-05-24 19:56 -------- d-----w- c:\programdata\SWCUTemp
2017-05-24 19:20 . 2017-05-24 19:49 -------- d-----w- C:\AdwCleaner
2017-05-24 02:55 . 2017-05-24 09:02 -------- d-----w- c:\programdata\RogueKiller
2017-05-24 02:55 . 2017-05-24 02:55 -------- d-----w- c:\program files\RogueKiller
2017-05-23 04:30 . 2017-05-23 05:05 -------- d-----w- C:\FRST
2017-05-20 02:43 . 2017-04-16 08:35 25741312 ----a-w- c:\windows\system32\mshtml.dll
2017-05-20 02:43 . 2017-04-16 07:10 15250944 ----a-w- c:\windows\system32\ieframe.dll
2017-05-20 02:41 . 2015-05-25 18:19 113664 ----a-w- c:\windows\system32\sechost.dll
2017-05-20 01:25 . 2015-07-23 00:02 879104 ----a-w- c:\windows\system32\tdh.dll
2017-05-20 01:25 . 2015-07-22 17:53 635392 ----a-w- c:\windows\SysWow64\tdh.dll
2017-05-20 01:01 . 2017-05-20 01:01 400456 ----a-w- c:\windows\system32\aswBoot.exe
2017-05-15 06:01 . 2017-05-15 06:01 -------- d-----w- c:\windows\SysWow64\Adobe
2017-05-09 11:36 . 2017-05-19 06:04 -------- d-----w- c:\windows\system32\DBBK
2017-05-09 04:24 . 2015-09-14 21:03 39672 ----a-w- c:\windows\system32\drivers\rvecschg.sys
2017-04-26 02:41 . 2017-04-26 02:41 -------- d-----w- c:\program files (x86)\Common Files\Java
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-05-25 00:32 . 2017-04-03 19:35 251832 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2017-05-24 07:55 . 2014-12-16 10:52 28272 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2017-05-20 02:56 . 2014-08-27 22:42 156335152 -c--a-w- c:\windows\system32\MRT.exe
2017-05-20 01:02 . 2016-07-30 13:31 158880 ----a-w- c:\windows\system32\drivers\aswstm.sys
2017-05-20 01:01 . 2016-07-30 13:31 75704 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2017-05-20 01:01 . 2016-07-30 13:31 569192 ----a-w- c:\windows\system32\drivers\aswSP.sys
2017-05-20 01:01 . 2016-07-30 13:31 38296 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2017-05-20 01:01 . 2016-07-30 13:31 339696 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2017-05-20 01:01 . 2016-07-30 13:31 128648 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2017-05-20 01:01 . 2016-07-30 13:31 101152 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2017-05-20 01:00 . 2016-07-30 13:31 32600 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2017-05-20 01:00 . 2016-07-30 13:31 1007160 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2017-05-20 01:00 . 2017-03-18 03:11 49016 ----a-w- c:\windows\system32\drivers\aswbuniva.sys
2017-05-20 01:00 . 2017-03-18 03:11 334576 ----a-w- c:\windows\system32\drivers\aswbloga.sys
2017-05-20 01:00 . 2017-03-18 03:11 190256 ----a-w- c:\windows\system32\drivers\aswbidsha.sys
2017-05-20 01:00 . 2017-03-18 03:11 311808 ----a-w- c:\windows\system32\drivers\aswbidsdrivera.sys
2017-05-09 23:37 . 2017-04-03 19:34 77440 ----a-w- c:\windows\system32\drivers\mbae64.sys
2017-04-28 00:32 . 2017-05-20 02:42 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2017-04-26 02:44 . 2016-11-23 04:16 110144 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2017-04-26 02:38 . 2017-01-23 06:14 97856 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2017-04-17 17:45 . 2014-09-30 01:19 802904 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2017-04-17 17:45 . 2014-09-30 01:19 144472 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2017-04-03 19:35 . 2017-04-03 19:35 186304 ----a-w- c:\windows\system32\drivers\MBAMChameleon.sys
2017-04-03 19:35 . 2017-04-03 19:35 111544 ----a-w- c:\windows\system32\drivers\farflt.sys
2017-04-03 19:35 . 2017-04-03 19:35 82720 ----a-w- c:\windows\system32\drivers\mwac.sys
2017-04-03 19:35 . 2017-04-03 19:35 43968 ----a-w- c:\windows\system32\drivers\mbam.sys
2017-03-27 03:33 . 2017-03-27 03:33 28344 ----a-w- c:\windows\SysWow64\aspnet_counters.dll
2017-03-27 03:33 . 2017-03-27 03:33 19104 ----a-w- c:\windows\SysWow64\msvcr110_clr0400.dll
2017-03-27 03:33 . 2017-03-27 03:33 19104 ----a-w- c:\windows\SysWow64\msvcr100_clr0400.dll
2017-03-27 03:33 . 2017-03-27 03:33 19104 ----a-w- c:\windows\SysWow64\msvcp110_clr0400.dll
2017-03-27 03:29 . 2017-03-27 03:29 30400 ----a-w- c:\windows\system32\aspnet_counters.dll
2017-03-27 03:29 . 2017-03-27 03:29 19112 ----a-w- c:\windows\system32\msvcr110_clr0400.dll
2017-03-27 03:29 . 2017-03-27 03:29 19112 ----a-w- c:\windows\system32\msvcr100_clr0400.dll
2017-03-27 03:29 . 2017-03-27 03:29 19112 ----a-w- c:\windows\system32\msvcp110_clr0400.dll
2017-03-22 15:32 . 2017-04-16 06:17 3165184 ----a-w- c:\windows\system32\wucltux.dll
2017-03-22 15:32 . 2017-04-16 06:16 98816 ----a-w- c:\windows\system32\wudriver.dll
2017-03-22 15:32 . 2017-04-16 06:16 192512 ----a-w- c:\windows\system32\wuwebv.dll
2017-03-22 15:30 . 2017-04-16 06:16 91136 ----a-w- c:\windows\system32\WinSetupUI.dll
2017-03-22 15:24 . 2017-04-16 06:16 174080 ----a-w- c:\windows\SysWow64\wuwebv.dll
2017-03-22 15:17 . 2017-04-16 06:17 2651136 ----a-w- c:\windows\system32\wuaueng.dll
2017-03-22 15:15 . 2017-04-16 06:17 709120 ----a-w- c:\windows\system32\wuapi.dll
2017-03-22 15:15 . 2017-04-16 06:16 37888 ----a-w- c:\windows\system32\wuapp.exe
2017-03-22 15:15 . 2017-04-16 06:16 140288 ----a-w- c:\windows\system32\wuauclt.exe
2017-03-22 15:15 . 2017-04-16 06:16 36864 ----a-w- c:\windows\system32\wups.dll
2017-03-22 15:15 . 2017-04-16 06:16 37888 ----a-w- c:\windows\system32\wups2.dll
2017-03-22 15:15 . 2017-04-16 06:16 12288 ----a-w- c:\windows\system32\wu.upgrade.ps.dll
2017-03-22 15:05 . 2017-04-16 06:17 573440 ----a-w- c:\windows\SysWow64\wuapi.dll
2017-03-22 15:05 . 2017-04-16 06:16 35328 ----a-w- c:\windows\SysWow64\wuapp.exe
2017-03-22 15:05 . 2017-04-16 06:16 30208 ----a-w- c:\windows\SysWow64\wups.dll
2017-03-22 15:05 . 2017-04-16 06:16 93696 ----a-w- c:\windows\SysWow64\wudriver.dll
2017-03-10 16:35 . 2017-04-16 06:17 382696 ----a-w- c:\windows\system32\atmfd.dll
2017-03-10 16:31 . 2017-04-16 06:16 41472 ----a-w- c:\windows\system32\lpk.dll
2017-03-10 16:31 . 2017-04-16 06:16 100864 ----a-w- c:\windows\system32\fontsub.dll
2017-03-10 16:31 . 2017-04-16 06:16 14336 ----a-w- c:\windows\system32\dciman32.dll
2017-03-10 16:31 . 2017-04-16 06:16 46080 ----a-w- c:\windows\system32\atmlib.dll
2017-03-10 16:27 . 2017-04-16 06:17 308456 ----a-w- c:\windows\SysWow64\atmfd.dll
2017-03-10 16:20 . 2017-04-16 06:16 25600 ----a-w- c:\windows\SysWow64\lpk.dll
2017-03-10 16:19 . 2017-04-16 06:16 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
2017-03-10 16:19 . 2017-04-16 06:16 10240 ----a-w- c:\windows\SysWow64\dciman32.dll
2017-03-10 15:53 . 2017-04-16 06:16 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2017-03-07 16:30 . 2017-04-16 06:16 85504 ----a-w- c:\windows\system32\asycfilt.dll
2017-03-07 16:17 . 2017-04-16 06:16 67584 ----a-w- c:\windows\SysWow64\asycfilt.dll
2017-03-07 14:05 . 2017-04-16 06:16 243200 ----a-w- c:\windows\system32\rdpudd.dll
2017-03-04 01:27 . 2017-04-16 06:17 1574912 ----a-w- c:\windows\system32\quartz.dll
2017-03-04 01:27 . 2017-04-16 06:16 93696 ----a-w- c:\windows\system32\mfmjpegdec.dll
2017-03-04 01:14 . 2017-04-16 06:17 1329664 ----a-w- c:\windows\SysWow64\quartz.dll
2017-03-04 01:14 . 2017-04-16 06:16 77312 ----a-w- c:\windows\SysWow64\mfmjpegdec.dll
2001-09-30 05:31 . 2016-03-01 01:05 314931 ----a-r- c:\program files (x86)\binkw32.dll
2001-09-30 05:31 . 2016-03-01 01:04 314931 ----a-r- c:\program files\binkw32.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2017-05-05 9772248]
"GUDelayStartup"="c:\program files (x86)\Glary Utilities 5\StartupManager.exe" [2017-05-19 43984]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-04-13 284696]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-08-10 975952]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2017-03-15 587288]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"panda"="reg.exe delete HKCU\Software\AppDataLow\Software\panda" [X]
"panda_XP"="reg.exe delete HKCU\Software\panda" [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableSecureUIAPath"= 1 (0x1)
"SoftwareSASGeneration"= 1 (0x1)
"MaxGPOScriptWait"= 600 (0x258)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk * \0PCloudBroom64.exe \systemroot\system32\BroomData.bit\0PCloudBroom64.exe \systemroot\system32\BroomData.bit\0PCloudBroom64.exe \systemroot\system32\BroomData.bit
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-disabled]
"EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe"
"BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
R1 JSWPSLWF;JumpStart Wireless Filter Driver;c:\windows\system32\DRIVERS\jswpslwfx.sys;c:\windows\SYSNATIVE\DRIVERS\jswpslwfx.sys [x]
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 aswbIDSAgent;aswbIDSAgent;c:\program files\AVAST Software\Avast\x64\aswidsagenta.exe;c:\program files\AVAST Software\Avast\x64\aswidsagenta.exe [x]
R3 aswHwid;aswHwid;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\DRIVERS\LEqdUsb.Sys;c:\windows\SYSNATIVE\DRIVERS\LEqdUsb.Sys [x]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\DRIVERS\LHidEqd.Sys;c:\windows\SYSNATIVE\DRIVERS\LHidEqd.Sys [x]
R3 panda_url_filteringd;panda_url_filteringd driver;c:\program files\Panda Security URL Filtering\panda_url_filteringd.sys;c:\program files\Panda Security URL Filtering\panda_url_filteringd.sys [x]
R3 PSKMAD;PSKMAD;c:\windows\system32\DRIVERS\PSKMAD.sys;c:\windows\SYSNATIVE\DRIVERS\PSKMAD.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe;c:\program files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 Unchecky;Unchecky;c:\program files (x86)\Unchecky\bin\unchecky_svc.exe;c:\program files (x86)\Unchecky\bin\unchecky_svc.exe [x]
R3 VSStandardCollectorService140;Visual Studio Standard Collector Service;c:\program files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe;c:\program files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [x]
S0 aswbidsh;aswbidsh;c:\windows\\SystemRoot\system32\drivers\aswbidsha.sys;c:\windows\\SystemRoot\system32\drivers\aswbidsha.sys [x]
S0 aswblog;aswblog;c:\windows\\SystemRoot\system32\drivers\aswbloga.sys;c:\windows\\SystemRoot\system32\drivers\aswbloga.sys [x]
S0 aswbuniv;aswbuniv;c:\windows\\SystemRoot\system32\drivers\aswbuniva.sys;c:\windows\\SystemRoot\system32\drivers\aswbuniva.sys [x]
S0 aswRvrt;aswRvrt;c:\windows\\SystemRoot\system32\drivers\aswRvrt.sys;c:\windows\\SystemRoot\system32\drivers\aswRvrt.sys [x]
S0 aswVmm;aswVmm;c:\windows\\SystemRoot\system32\drivers\aswVmm.sys;c:\windows\\SystemRoot\system32\drivers\aswVmm.sys [x]
S1 aswbidsdriver;aswbidsdriver;c:\windows\system32\drivers\aswbidsdrivera.sys;c:\windows\SYSNATIVE\drivers\aswbidsdrivera.sys [x]
S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys;c:\windows\SYSNATIVE\drivers\aswKbd.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 GUBootStartup;GUBootStartup;c:\windows\System32\drivers\GUBootStartup.sys;c:\windows\SYSNATIVE\drivers\GUBootStartup.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [x]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 IpOverUsbSvc;Windows Phone IP over USB Transport (IpOverUsbSvc);c:\program files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe;c:\program files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [x]
S2 MBAMService;Malwarebytes Service;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe [x]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [x]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x]
S2 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 RDPDISPM;RDPDISPM;c:\windows\system32\DRIVERS\rdpdispm.sys;c:\windows\SYSNATIVE\DRIVERS\rdpdispm.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MBAMSWISSARMY
*Deregistered* - mwlPSDFilter
*Deregistered* - mwlPSDNServ
*Deregistered* - mwlPSDVDisk
*Deregistered* - X5XSEx_Pr143
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00asw]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2017-05-20 01:01 1505952 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00asw]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2017-05-20 01:01 1505952 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-01-11 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-01-11 392984]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-01-11 417560]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-06-22 10920552]
"Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2016-10-14 1841496]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2011-01-05 860040]
"OOTag"="c:\program files (x86)\Acer\OOBEOffer\ootag.exe" [2010-02-23 13856]
"GwxControlPanelMonitor"="c:\program files (x86)\UltimateOutsider\GWX Control Panel\GWX_control_panel.exe" [2016-04-02 4596296]
"Malwarebytes TrayApp"="c:\program files\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe" [2017-05-10 3146704]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvLaunch.exe" [2017-05-20 213824]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://
www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 64.59.144.19 64.59.150.135
FF - ProfilePath - c:\users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\ktc8jgaw.default\
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-AppXSvc
SafeBoot-ClipSvc
SafeBoot-TweakingRemoveSafeBoot
SafeBoot-WSService
AddRemove-Panda Security URL Filtering - c:\program files\Panda Security URL Filtering\uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_25_0_0_148_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_25_0_0_148_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_25_0_0_148_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_25_0_0_148_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_25_0_0_148.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.25"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_25_0_0_148.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_25_0_0_148.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_25_0_0_148.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2017-05-24 18:07:58
ComboFix-quarantined-files.txt 2017-05-25 01:07
.
Pre-Run: 30,078,840,832 bytes free
Post-Run: 29,701,898,240 bytes free
.
- - End Of File - - 5243F885C77CD7B21B53FB01FE5ED39F