ComboFix 17-05-24.14 - Dwayne 2017/06/24 19:28:53.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.27.1033.18.8089.6064 [GMT 2:00]
Running from: c:\users\Dwayne\Desktop\ComboFix.exe
AV: Avast Antivirus *Disabled/Updated* {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Malwarebytes *Disabled/Updated* {23007AD3-69FE-687C-2629-D584AFFAF72B}
SP: Avast Antivirus *Disabled/Updated* {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
SP: Malwarebytes *Disabled/Updated* {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\28677E92A4.sys
c:\users\Dwayne\AppData\Roaming\Origin
c:\users\Dwayne\AppData\Roaming\Origin\Cloud Saves\blacklist
c:\users\Dwayne\AppData\Roaming\Origin\local.xml
c:\windows\msdownld.tmp
c:\windows\SysWow64\DEBUG.log
c:\windows\SysWow64\SET1C51.tmp
c:\windows\SysWow64\SET363C.tmp
c:\windows\SysWow64\SET42F4.tmp
c:\windows\SysWow64\SET4344.tmp
c:\windows\SysWow64\SET6638.tmp
c:\windows\SysWow64\SET6743.tmp
c:\windows\SysWow64\SET7A47.tmp
c:\windows\SysWow64\SET8616.tmp
c:\windows\SysWow64\SETBB3.tmp
c:\windows\SysWow64\SETBEF2.tmp
c:\windows\SysWow64\SETBF90.tmp
c:\windows\SysWow64\SETC360.tmp
c:\windows\SysWow64\SETC60.tmp
c:\windows\SysWow64\SETCFF5.tmp
c:\windows\SysWow64\SETDF79.tmp
c:\windows\SysWow64\SETDF8B.tmp
.
.
((((((((((((((((((((((((( Files Created from 2017-05-24 to 2017-06-24 )))))))))))))))))))))))))))))))
.
.
2073-12-03 08:13 . 2014-09-17 21:28 -------- d-----w- c:\windows\Panther
2073-12-02 23:08 . 2013-12-31 22:12 -------- d-----r- C:\MSOCache
2073-12-02 22:58 . 2073-12-02 22:58 -------- d-----w- C:\5ed878faeca74ae6af7708f79d0b85
2073-12-02 22:52 . 2073-12-02 22:52 -------- d-----w- c:\windows\system32\EventProviders
2073-12-02 22:50 . 2014-03-18 02:44 906968 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2073-12-02 22:50 . 2014-03-18 02:44 73800 ----a-w- c:\windows\system32\RtNicProp64.dll
2073-12-02 22:50 . 2014-03-18 02:44 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2073-12-02 22:49 . 2015-10-22 13:07 -------- d-----w- c:\program files (x86)\Realtek
2073-12-02 22:49 . 2016-08-24 11:24 -------- d--h--w- c:\program files (x86)\Temp
2073-12-02 22:49 . 2014-11-07 05:56 -------- d-----w- c:\program files (x86)\Common Files\InstallShield
2073-12-02 22:47 . 2014-03-31 05:28 450520 ----a-w- c:\windows\system32\drivers\IntcDAud.sys
2073-12-02 22:47 . 2073-12-02 22:47 -------- d-----w- c:\program files (x86)\Common Files\postureAgent
2073-12-02 22:47 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2073-12-02 22:47 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2073-12-02 22:47 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
2073-12-02 22:47 . 2013-09-16 10:17 99288 ----a-w- c:\windows\system32\drivers\TeeDriverx64.sys
2073-12-02 22:47 . 2013-09-16 10:17 1795952 ----a-w- c:\windows\system32\WdfCoInstaller01011.dll
2073-12-02 22:46 . 2017-01-05 21:32 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
2073-12-02 22:46 . 2014-09-17 21:47 -------- d-----w- c:\program files (x86)\Intel
2073-12-02 22:46 . 2013-08-21 13:16 53248 ----a-w- c:\windows\SysWow64\CSVer.dll
2073-12-02 22:46 . 2014-09-17 20:26 -------- d-----w- C:\Intel
2073-12-02 22:44 . 2014-09-02 23:25 -------- d-----w- c:\programdata\Norton
2073-12-02 22:43 . 2014-09-17 17:43 -------- d-----w- c:\program files (x86)\Microsoft.NET
2073-12-02 22:42 . 2014-09-17 21:15 -------- d-----w- c:\program files\Google
2073-12-02 22:41 . 2017-06-15 07:33 -------- d-sh--w- c:\windows\Installer
2073-12-02 22:41 . 2014-12-05 21:57 -------- d-----w- c:\program files (x86)\Google
2073-12-02 22:36 . 2073-12-02 22:36 -------- d-----w- C:\Recovery
2073-12-02 22:35 . 2016-06-02 05:50 -------- d-----w- c:\windows\SoftwareDistributionOLD
2017-06-24 17:36 . 2017-06-24 17:36 -------- d-----w- c:\users\Default\AppData\Local\temp
2017-06-24 07:37 . 2017-06-24 07:37 -------- d-----w- c:\program files\RogueKiller
2017-06-24 07:35 . 2017-06-24 07:35 -------- d-----w- c:\programdata\SWCUTemp
2017-06-21 21:51 . 2017-06-23 22:58 -------- d-----w- C:\FRST
2017-06-21 20:50 . 2017-06-24 13:03 188312 ----a-w- c:\windows\system32\drivers\MBAMChameleon.sys
2017-06-21 20:50 . 2017-06-24 17:16 113592 ----a-w- c:\windows\system32\drivers\farflt.sys
2017-06-21 20:50 . 2017-06-24 17:16 84256 ----a-w- c:\windows\system32\drivers\mwac.sys
2017-06-21 20:50 . 2017-06-24 17:16 44960 ----a-w- c:\windows\system32\drivers\mbam.sys
2017-06-21 20:50 . 2017-05-25 09:58 77376 ----a-w- c:\windows\system32\drivers\mbae64.sys
2017-06-21 20:50 . 2017-06-21 20:50 -------- d-----w- c:\program files\Malwarebytes
2017-06-20 18:33 . 2017-06-21 11:44 -------- d-----w- c:\users\Dwayne\AppData\Local\gtk-2.0
2017-06-20 18:33 . 2017-06-20 18:33 -------- d-----w- c:\users\Dwayne\.thumbnails
2017-06-20 18:27 . 2017-06-21 11:47 -------- d-----w- c:\users\Dwayne\.gimp-2.8
2017-06-20 18:27 . 2017-06-20 18:27 -------- d-----w- c:\users\Dwayne\AppData\Local\gegl-0.2
2017-06-17 19:00 . 2017-06-18 19:08 -------- d-----w- c:\users\Dwayne\AppData\Roaming\timodd
2017-06-15 07:35 . 2017-06-15 07:35 -------- d-----w- c:\programdata\RzSurroundVAD_1.1.62.0
2017-06-15 07:35 . 2016-09-17 00:12 44144 ----a-w- c:\windows\system32\drivers\rzpmgrk.sys
2017-06-14 11:40 . 2017-06-14 11:40 54728 ----a-w- c:\program files (x86)\Mozilla Firefox\pingsender.exe
2017-06-14 08:05 . 2017-05-21 04:24 60416 ----a-w- c:\windows\system32\msobjs.dll
2017-06-14 08:05 . 2017-05-21 04:24 146432 ----a-w- c:\windows\system32\msaudite.dll
2017-06-14 08:05 . 2017-05-21 04:24 690688 ----a-w- c:\windows\system32\adtschema.dll
2017-06-14 08:05 . 2017-05-21 04:06 60416 ----a-w- c:\windows\SysWow64\msobjs.dll
2017-06-14 08:05 . 2017-05-21 04:06 146432 ----a-w- c:\windows\SysWow64\msaudite.dll
2017-06-14 08:05 . 2017-05-21 04:06 690688 ----a-w- c:\windows\SysWow64\adtschema.dll
2017-06-14 08:05 . 2017-05-14 20:46 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2017-06-09 11:22 . 2017-06-09 11:22 144 ----a-w- c:\windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-06-05 13:59 . 2017-06-05 13:59 18412800 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\MSO.DLL
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-06-24 17:17 . 2014-09-17 19:46 25640 ----a-w- c:\windows\gdrv.sys
2017-06-24 17:17 . 2014-09-17 17:39 25640 ----a-w- c:\windows\etdrv.sys
2017-06-24 17:16 . 2016-01-31 16:13 252832 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2017-06-24 13:04 . 2014-09-19 19:42 28272 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2017-06-21 14:31 . 2016-07-17 17:35 803328 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2017-06-21 14:31 . 2016-07-17 17:35 144896 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2017-06-14 17:02 . 2014-09-17 18:38 133627792 -c--a-w- c:\windows\system32\MRT.exe
2017-05-13 05:19 . 2017-02-01 17:55 158880 ----a-w- c:\windows\system32\drivers\aswstm.sys
2017-05-12 18:03 . 2017-06-14 08:06 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2017-05-09 17:50 . 2017-02-01 17:55 339696 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2017-05-09 17:50 . 2017-05-09 17:50 400456 ----a-w- c:\windows\system32\aswBoot.exe
2017-05-09 17:50 . 2017-02-01 17:55 75704 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2017-05-09 17:50 . 2017-02-01 17:55 569192 ----a-w- c:\windows\system32\drivers\aswSP.sys
2017-05-09 17:50 . 2017-02-01 17:55 38296 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2017-05-09 17:50 . 2017-02-01 17:55 128648 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2017-05-09 17:50 . 2017-02-01 17:55 101152 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2017-05-09 17:49 . 2017-02-01 17:55 1007160 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2017-05-09 17:49 . 2013-12-31 22:04 49016 ----a-w- c:\windows\system32\drivers\aswbuniva.sys
2017-05-09 17:49 . 2013-12-31 22:04 334576 ----a-w- c:\windows\system32\drivers\aswbloga.sys
2017-05-09 17:49 . 2013-12-31 22:04 190256 ----a-w- c:\windows\system32\drivers\aswbidsha.sys
2017-05-09 17:49 . 2013-12-31 22:04 311808 ----a-w- c:\windows\system32\drivers\aswbidsdrivera.sys
2017-04-23 18:43 . 2016-01-31 16:27 97856 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2017-04-21 15:34 . 2017-05-09 18:30 1133568 ----a-w- c:\windows\system32\cdosys.dll
2017-04-21 15:15 . 2017-05-09 18:30 805376 ----a-w- c:\windows\SysWow64\cdosys.dll
2017-04-17 15:37 . 2017-05-09 18:30 512000 ----a-w- c:\windows\system32\rpcss.dll
2017-04-17 15:37 . 2017-05-09 18:30 2065408 ----a-w- c:\windows\system32\ole32.dll
2017-04-17 15:37 . 2017-05-09 18:30 876544 ----a-w- c:\windows\system32\oleaut32.dll
2017-04-17 15:37 . 2017-05-09 18:30 26112 ----a-w- c:\windows\system32\oleres.dll
2017-04-17 15:37 . 2017-05-09 18:30 8704 ----a-w- c:\windows\system32\comcat.dll
2017-04-17 15:12 . 2017-05-09 18:30 581632 ----a-w- c:\windows\SysWow64\oleaut32.dll
2017-04-17 15:12 . 2017-05-09 18:30 1417728 ----a-w- c:\windows\SysWow64\ole32.dll
2017-04-17 15:12 . 2017-05-09 18:30 26112 ----a-w- c:\windows\SysWow64\oleres.dll
2017-04-17 14:54 . 2017-05-09 18:30 7168 ----a-w- c:\windows\SysWow64\comcat.dll
2017-04-12 15:32 . 2017-05-09 18:30 229376 ----a-w- c:\windows\system32\wintrust.dll
2017-04-12 15:32 . 2017-05-09 18:30 1483776 ----a-w- c:\windows\system32\crypt32.dll
2017-04-12 15:32 . 2017-05-09 18:30 190976 ----a-w- c:\windows\system32\cryptsvc.dll
2017-04-12 15:32 . 2017-05-09 18:30 141824 ----a-w- c:\windows\system32\cryptnet.dll
2017-04-12 15:26 . 2017-05-09 18:30 179200 ----a-w- c:\windows\SysWow64\wintrust.dll
2017-04-12 15:25 . 2017-05-09 18:30 1176064 ----a-w- c:\windows\SysWow64\crypt32.dll
2017-04-12 15:25 . 2017-05-09 18:30 145920 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2017-04-12 15:25 . 2017-05-09 18:30 106496 ----a-w- c:\windows\SysWow64\cryptnet.dll
2017-04-07 15:34 . 2017-05-09 18:30 986856 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2017-04-07 15:34 . 2017-05-09 18:30 265448 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2017-04-07 15:30 . 2017-05-09 18:30 144384 ----a-w- c:\windows\system32\cdd.dll
2017-04-07 06:37 . 2017-04-07 06:37 15816 ----a-w- c:\windows\SysWow64\RzStats.IPC.dll
2017-04-05 14:55 . 2017-05-09 18:30 460800 ----a-w- c:\windows\system32\drivers\srv.sys
2017-04-05 14:55 . 2017-05-09 18:30 405504 ----a-w- c:\windows\system32\drivers\srv2.sys
2017-04-05 14:55 . 2017-05-09 18:30 168960 ----a-w- c:\windows\system32\drivers\srvnet.sys
2017-04-04 15:34 . 2017-05-09 18:30 1895656 ----a-w- c:\windows\system32\drivers\tcpip.sys
2017-04-04 15:34 . 2017-05-09 18:30 377576 ----a-w- c:\windows\system32\drivers\netio.sys
2017-04-04 15:34 . 2017-05-09 18:30 287976 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2017-04-04 14:53 . 2017-05-09 18:30 496128 ----a-w- c:\windows\system32\drivers\afd.sys
2017-04-01 19:48 . 2016-08-16 13:27 65536 ----a-w- c:\windows\system32\spu_storage.bin
2017-03-26 18:33 . 2017-03-26 18:33 28344 ----a-w- c:\windows\SysWow64\aspnet_counters.dll
2017-03-26 18:33 . 2017-03-26 18:33 19104 ----a-w- c:\windows\SysWow64\msvcr110_clr0400.dll
2017-03-26 18:33 . 2017-03-26 18:33 19104 ----a-w- c:\windows\SysWow64\msvcr100_clr0400.dll
2017-03-26 18:33 . 2017-03-26 18:33 19104 ----a-w- c:\windows\SysWow64\msvcp110_clr0400.dll
2017-03-26 18:29 . 2017-03-26 18:29 30400 ----a-w- c:\windows\system32\aspnet_counters.dll
2017-03-26 18:29 . 2017-03-26 18:29 19112 ----a-w- c:\windows\system32\msvcr110_clr0400.dll
2017-03-26 18:29 . 2017-03-26 18:29 19112 ----a-w- c:\windows\system32\msvcr100_clr0400.dll
2017-03-26 18:29 . 2017-03-26 18:29 19112 ----a-w- c:\windows\system32\msvcp110_clr0400.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2014-06-27 292848]
"Raptr"="c:\program files (x86)\Raptr\raptrstub.exe" [2015-10-01 56080]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"amd_dc_opt"="c:\program files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"Razer Synapse"="c:\program files (x86)\Razer\Synapse\RzSynapse.exe" [2017-04-13 596640]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2017-03-15 587288]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"SIV"="c:\program files (x86)\Gigabyte\SIV\RunOnceTc.exe" [2014-04-25 16192]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]
@="Service"
.
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;Malwarebytes Service;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 aswbIDSAgent;aswbIDSAgent;c:\program files\AVAST Software\Avast\x64\aswidsagenta.exe;c:\program files\AVAST Software\Avast\x64\aswidsagenta.exe [x]
R3 aswHwid;aswHwid;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
R3 BazisVirtualCDBus;WinCDEmu Virtual Bus Driver;c:\windows\system32\DRIVERS\BazisVirtualCDBus.sys;c:\windows\SYSNATIVE\DRIVERS\BazisVirtualCDBus.sys [x]
R3 cpuz137;cpuz137;c:\windows\TEMP\cpuz137\cpuz137_x64.sys;c:\windows\TEMP\cpuz137\cpuz137_x64.sys [x]
R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys;c:\windows\SYSNATIVE\DRIVERS\dc3d.sys [x]
R3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus;c:\windows\system32\DRIVERS\dtlitescsibus.sys;c:\windows\SYSNATIVE\DRIVERS\dtlitescsibus.sys [x]
R3 etocdrv;etocdrv;c:\windows\etocdrv.sys;c:\windows\etocdrv.sys [x]
R3 GPUZ;GPUZ;c:\windows\TEMP\GPUZ.sys;c:\windows\TEMP\GPUZ.sys [x]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
R3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x]
R3 jakstaVA;Digital Video Recorder;c:\windows\system32\DRIVERS\jaksta_va.sys;c:\windows\SYSNATIVE\DRIVERS\jaksta_va.sys [x]
R3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\DRIVERS\mcvidrv_x64.sys;c:\windows\SYSNATIVE\DRIVERS\mcvidrv_x64.sys [x]
R3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv_x64.sys;c:\windows\SYSNATIVE\drivers\mcaudrv_x64.sys [x]
R3 NTIOLib_1_0_4;NTIOLib_1_0_4;c:\program files (x86)\MSI\Live Update\NTIOLib_X64.sys;c:\program files (x86)\MSI\Live Update\NTIOLib_X64.sys [x]
R3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.20);c:\windows\system32\DRIVERS\RtTeam620.sys;c:\windows\SYSNATIVE\DRIVERS\RtTeam620.sys [x]
R3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.2);c:\windows\system32\DRIVERS\RtVlan620.sys;c:\windows\SYSNATIVE\DRIVERS\RtVlan620.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 aswbidsh;aswbidsh;c:\windows\\SystemRoot\system32\drivers\aswbidsha.sys;c:\windows\\SystemRoot\system32\drivers\aswbidsha.sys [x]
S0 aswblog;aswblog;c:\windows\\SystemRoot\system32\drivers\aswbloga.sys;c:\windows\\SystemRoot\system32\drivers\aswbloga.sys [x]
S0 aswbuniv;aswbuniv;c:\windows\\SystemRoot\system32\drivers\aswbuniva.sys;c:\windows\\SystemRoot\system32\drivers\aswbuniva.sys [x]
S0 aswRvrt;aswRvrt;c:\windows\\SystemRoot\system32\drivers\aswRvrt.sys;c:\windows\\SystemRoot\system32\drivers\aswRvrt.sys [x]
S0 aswVmm;aswVmm;c:\windows\\SystemRoot\system32\drivers\aswVmm.sys;c:\windows\\SystemRoot\system32\drivers\aswVmm.sys [x]
S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorA.sys [x]
S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorF.sys [x]
S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S1 aswbidsdriver;aswbidsdriver;c:\windows\system32\drivers\aswbidsdrivera.sys;c:\windows\SYSNATIVE\drivers\aswbidsdrivera.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 ndisrd;WinpkFilter LightWeight Filter;c:\windows\system32\DRIVERS\ndisrd.sys;c:\windows\SYSNATIVE\DRIVERS\ndisrd.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 FoxitReaderService;Foxit Reader Service;c:\program files (x86)\FOXIT SOFTWARE\FOXIT READER\FoxitConnectedPDFService.exe;c:\program files (x86)\FOXIT SOFTWARE\FOXIT READER\FoxitConnectedPDFService.exe [x]
S2 gadjservice;GIGABYTE Adjust;c:\program files (x86)\Gigabyte\AppCenter\AdjustService.exe;c:\program files (x86)\Gigabyte\AppCenter\AdjustService.exe [x]
S2 GUP7Serv;UP7 Click OC service;c:\program files (x86)\GIGABYTE\OCBtn\GUP7Serv.exe;c:\program files (x86)\GIGABYTE\OCBtn\GUP7Serv.exe [x]
S2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service;c:\windows\system32\igfxCUIService.exe;c:\windows\SYSNATIVE\igfxCUIService.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 PSI_SVC_2_x64;Corel License Validation Service V2 x64, Powered by arvato;c:\program files\Common Files\Protexis\License Service\PsiService_2.exe;c:\program files\Common Files\Protexis\License Service\PsiService_2.exe [x]
S2 Razer Game Scanner Service;Razer Game Scanner;c:\program files (x86)\Razer\Razer Services\GSS\GameScannerService.exe;c:\program files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [x]
S2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\DRIVERS\RtNdPt60.sys;c:\windows\SYSNATIVE\DRIVERS\RtNdPt60.sys [x]
S2 rzpmgrk;rzpmgrk;c:\windows\system32\drivers\rzpmgrk.sys;c:\windows\SYSNATIVE\drivers\rzpmgrk.sys [x]
S2 rzpnk;rzpnk;c:\windows\system32\drivers\rzpnk.sys;c:\windows\SYSNATIVE\drivers\rzpnk.sys [x]
S2 RzSurroundVADStreamingService;RzSurroundVADStreamingService;c:\programdata\Razer\Synapse\Devices\Razer Surround\Driver\RzSurroundVADStreamingService.exe;c:\programdata\Razer\Synapse\Devices\Razer Surround\Driver\RzSurroundVADStreamingService.exe [x]
S3 etdrv;etdrv;c:\windows\etdrv.sys;c:\windows\etdrv.sys [x]
S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 RZSURROUNDVADService;Razer Surround Audio Service;c:\windows\system32\drivers\RzSurroundVAD.sys;c:\windows\SYSNATIVE\drivers\RzSurroundVAD.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - ESProtectionDriver
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc
.
Contents of the 'Scheduled Tasks' folder
.
2017-06-24 c:\windows\Tasks\RtlLanOptimizerVistaStart.job
- c:\program files (x86)\Realtek\LanOptimizer\LanOptimizer.exe [2014-09-17 02:53]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveBlacklisted]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2017-03-21 06:15 775064 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveSynced]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2017-03-21 06:15 775064 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveSyncing]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2017-03-21 06:15 775064 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00asw]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2017-05-09 17:50 1505952 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00asw]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2017-05-09 17:50 1505952 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FAHConsole"="c:\program files\File Association Helper\FAHConsole.exe" [2014-01-28 729272]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2015-06-18 14021336]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvLaunch.exe" [2017-05-09 213824]
"Malwarebytes TrayApp"="c:\program files\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe" [2017-05-09 3146704]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://
www.google.co.za/
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 10.0.0.2
FF - ProfilePath - c:\users\Dwayne\AppData\Roaming\Mozilla\Firefox\Profiles\5geyetf6.default-1454257769290\
FF - prefs.js: browser.startup.homepage - hxxps://
www.google.co.za/
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
ShellIconOverlayIdentifiers-{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} - (no file)
AddRemove-SafeZone 1.48.2066.101 - c:\program files\AVAST Software\SZBrowser\Launcher.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1901267739-2306482670-2628607035-1001\Software\4kdownload.com\4K Video Downloader\FileWatcher\Ó3*]
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-1901267739-2306482670-2628607035-1001\Software\4kdownload.com\4K Video Downloader\FileWatcher\ýÿI*]
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2017-06-24 19:39:11
ComboFix-quarantined-files.txt 2017-06-24 17:39
.
Pre-Run: 403 416 453 120 bytes free
Post-Run: 402 755 559 424 bytes free
.
- - End Of File - - 2FD37C923321CCA07E6A2DA1C8D6E8D6
A36C5E4F47E84449FF07ED3517B43A31