ComboFix 15-03-23.01 - admin 03/24/2015 0:35.1.4 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3063.1771 [GMT 7:00]
Running from: c:\users\admin\Desktop\ComboFix.exe
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\CFLog
c:\programdata\1396080444.bdinstall.bin
c:\programdata\1401274575.bdinstall.bin
c:\programdata\1401275126.bdinstall.bin
c:\programdata\1401978631.bdinstall.bin
c:\programdata\1401978676.bdinstall.bin
c:\programdata\1402059130.bdinstall.bin
c:\programdata\1402395617.bdinstall.bin
c:\programdata\1402395649.bdinstall.bin
c:\programdata\1402395693.bdinstall.bin
c:\programdata\1402395702.bdinstall.bin
c:\programdata\1402395723.bdinstall.bin
c:\programdata\1402395878.bdinstall.bin
c:\programdata\1402396393.bdinstall.bin
c:\programdata\1402396404.bdinstall.bin
c:\programdata\1402396439.bdinstall.bin
c:\programdata\1402396449.bdinstall.bin
c:\programdata\1402396570.bdinstall.bin
c:\programdata\1402396598.bdinstall.bin
c:\users\admin\Documents\~WRL1634.tmp
c:\windows\system32\coMPstuii.dll
D:\setup.exe
.
.
((((((((((((((((((((((((( Files Created from 2015-02-23 to 2015-03-23 )))))))))))))))))))))))))))))))
.
.
2074-05-07 11:38 . 2006-11-21 13:48 203576 ------w- c:\program files\Microsoft Games\Age of Empires III\autopatcher2.exe
2015-03-22 06:15 . 2015-03-22 06:15 35064 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2015-03-22 06:15 . 2015-03-22 06:26 -------- d-----w- c:\programdata\RogueKiller
2015-03-22 02:13 . 2015-03-22 02:14 -------- d-----w- c:\program files\Mozilla Firefox 4.0 Beta 6
2015-03-21 03:29 . 2015-03-21 03:32 -------- d-----w- C:\FRST
2015-03-18 20:43 . 2015-03-18 20:43 -------- d-----w- c:\program files\doxygen
2015-03-14 14:58 . 2015-03-14 15:00 -------- d-----w- c:\users\admin\AppData\Local\Sublime Text 3
2015-03-14 14:58 . 2015-03-14 14:58 -------- d-----w- c:\users\admin\AppData\Roaming\Sublime Text 3
2015-03-14 14:58 . 2015-03-14 14:58 -------- d-----w- c:\program files\Sublime Text 3
2015-03-14 14:48 . 2015-03-14 14:48 -------- d-----w- c:\users\admin\AppData\Roaming\Sublime Text 2
2015-03-14 14:48 . 2015-03-14 14:48 -------- d-----w- c:\program files\Sublime Text 2
2015-03-12 14:17 . 2015-03-12 14:17 -------- d--h--w- c:\program files\InstallJammer Registry
2015-03-12 14:08 . 2015-03-12 14:08 -------- d-sh--w- c:\windows\ftpcache
2015-03-09 18:46 . 2015-03-09 18:46 -------- d-----w- c:\program files\iPod
2015-03-09 18:46 . 2015-03-09 18:47 -------- d-----w- c:\programdata\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-03-01 00:58 . 2015-03-14 14:04 -------- d-----w- c:\users\admin\.atom
2015-03-01 00:57 . 2015-03-01 00:58 -------- d-----w- c:\users\admin\AppData\Roaming\Atom
2015-03-01 00:55 . 2015-03-14 13:24 -------- d-----w- c:\users\admin\AppData\Local\atom
2015-03-01 00:55 . 2015-03-01 00:58 -------- d-----w- c:\users\admin\AppData\Local\SquirrelTemp
2015-03-01 00:50 . 2015-03-01 00:50 -------- d-----w- c:\users\admin\.ssh
2015-03-01 00:49 . 2015-03-14 13:16 -------- d-----w- c:\users\admin\AppData\Local\GitHub
2015-03-01 00:49 . 2015-03-14 13:16 -------- d-----w- c:\users\admin\AppData\Roaming\GitHub
2015-02-28 03:10 . 2015-02-28 03:10 -------- d-----w- c:\programdata\Avg_Update_0215av
2015-02-27 14:07 . 2015-02-27 14:24 -------- d-----w- c:\users\admin\AppData\Local\Temporary Projects
2015-02-24 13:41 . 2014-11-29 00:37 115752 ----a-w- c:\windows\system32\drivers\idmwfp.sys
2015-02-24 03:05 . 2015-02-24 03:05 -------- d-----w- c:\programdata\regid.1991-06.com.microsoft
2015-02-24 01:21 . 2015-03-23 13:09 -------- d-----w- c:\users\admin\AppData\Local\AVDworks
2015-02-24 01:20 . 2015-03-10 16:20 -------- d-----w- c:\users\admin\AppData\Local\Agcpworks
2015-02-24 01:19 . 2015-02-24 01:19 1610752 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityHelper.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-03-17 11:43 . 2015-03-17 11:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\39d8d2d8e613dacc3f3e425ce7f13d67\WMP x264 Codec Pack.exe
2015-03-17 11:43 . 2015-03-17 11:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\28e300da2ff2c2841cdb71373bc72170\WMP x264 Codec Pack.exe
2015-03-17 11:43 . 2015-03-17 11:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\03430d5d85fadc83f015a694d9376a73\WMP x264 Codec Pack.exe
2015-03-14 03:43 . 2015-03-14 03:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\fe4551ec6d342ef41164c1dac4a9cb26\Total Codec Pack.exe
2015-03-14 03:43 . 2015-03-14 03:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\fe3ffd2af530bec1f0fb6d9f96d576bc\Total Codec Pack.exe
2015-03-14 03:43 . 2015-03-14 03:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\e20885afd2d6105c7987c72cd3aa85d9\Total Codec Pack.exe
2015-03-14 03:43 . 2015-03-14 03:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\de30df4dcad9d0d2188cb12d1d428abe\Total Codec Pack.exe
2015-03-14 03:43 . 2015-03-14 03:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\c85704bb576f18c3ec859bfa111dd3f7\Total Codec Pack.exe
2015-03-14 03:43 . 2015-03-14 03:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\a4cf723e4a21f5bca7805a2875589f89\Total Codec Pack.exe
2015-03-14 03:43 . 2015-03-14 03:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\9b6f724b60339cac0dcd3b553fbd5d4e\Total Codec Pack.exe
2015-03-14 03:43 . 2015-03-14 03:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\9a3dfeeb8a7d0b60c3502a288a7f3ce1\Total Codec Pack.exe
2015-03-14 03:43 . 2015-03-14 03:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\8343da516817d696ea396879c9e9003e\Total Codec Pack.exe
2015-03-14 03:43 . 2015-03-14 03:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\5960162c555f7323e52e17e5deb00ad6\Total Codec Pack.exe
2015-03-14 03:43 . 2015-03-14 03:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\5522eb87020c0cdef925f213ca9b2b26\Total Codec Pack.exe
2015-03-14 03:43 . 2015-03-14 03:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\26e71696d2e063bc21c3c83f91fe37ff\Total Codec Pack.exe
2015-03-14 03:43 . 2015-03-14 03:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\1c32f158b04e9d9f484eb1e4ae6ef7b3\Total Codec Pack.exe
2015-03-14 03:43 . 2015-03-14 03:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\18fa99187d52939087cd6c542590b00e\Total Codec Pack.exe
2015-03-14 03:43 . 2015-03-14 03:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\188755cff03e222400eeb2a11aeaea68\Total Codec Pack.exe
2015-03-14 03:43 . 2015-03-14 03:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\12babf9b087f2101d7b723717155fcb4\Total Codec Pack.exe
2015-03-14 03:43 . 2015-03-14 03:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\0f3a756a6adbad0a43efdaf54a4dc25a\Total Codec Pack.exe
2015-03-14 03:43 . 2015-03-14 03:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\0588e9e089e5d2300b5b2b17bf829d5e\Total Codec Pack.exe
2015-03-14 03:43 . 2015-03-14 03:43 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\00254a729f3d99f72becd3b97beefb8b\Total Codec Pack.exe
2015-03-13 17:04 . 2015-03-13 17:04 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\fa659efe2dc1358a252e1b3d8b3b13a4\Total Codec Pack.exe
2015-03-13 17:04 . 2015-03-13 17:04 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\ed5e1c54fb35f1ebb0198b5e6a9f275f\Total Codec Pack.exe
2015-03-13 17:04 . 2015-03-13 17:04 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\b516bae3578381c74ab73567d03714eb\Total Codec Pack.exe
2015-03-13 17:04 . 2015-03-13 17:04 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\aaac5067c396d24196ba87d0a5c94327\Total Codec Pack.exe
2015-03-13 17:04 . 2015-03-13 17:04 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\98fee94735462aea38e625a49beb8c0b\Total Codec Pack.exe
2015-03-13 17:04 . 2015-03-13 17:04 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\808919ea019560401b516da14b0588b1\Total Codec Pack.exe
2015-03-13 17:04 . 2015-03-13 17:04 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\5a70ecff56af555da2ae47003196bc99\Total Codec Pack.exe
2015-03-13 17:04 . 2015-03-13 17:04 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\330162ce91f637fcd6c43fd5ae48b04c\Total Codec Pack.exe
2015-03-13 17:04 . 2015-03-13 17:04 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\326c7d91fa2d463213b380a79cd0521e\Total Codec Pack.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\fe5f0606391e1b3a67fcf91ded957196\TuneUp Utilities.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\fca2fbae34034ee7fe73f31e53507c09\Movavi Video Editor.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\fc2a76dc197f9defdd03b1965157d68d\Universal Simlock Remover.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\fb5dfc549b8b6affd7bc7d9cd9b341ad\InterMapper.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\f8d95bf5cd6352afeb8a8d1ef2c18ec6\Sapphire Plug-ins AE.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\f7220dc4e1be51be54157ae10731c24a\FlippingBook PDF Publisher.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\f6b9644b011ec3fd6f588f90e19c017f\MixMeister Fusion.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\f32d967baa57a2e0e2958779ff8faf12\Charles.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\eab61493d0df54d30c2ad9462e3bee27\91 PC Suite for Android.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\ea5e79d678e842fafac38766b44f4a54\AVS Audio Editor.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\e02c1cfd596c439a6d6c826bc1ff88df\ArcSoft TotalMedia.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\c2306a0b158b8ab018edbba1b9b9f775\3D Issue Professional.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\b08f84ce08997ab3cbd46af884ef9bc6\Sequencher.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\b07006a1eeadc2069604372e36047a9b\Nero Burning Rom.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\ad3fff69609316ac85dd648706b127f7\DeskScapes.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\ab0bb2fe40090c72f357b98d9fbe9030\ESET NOD32 Antivirus.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\a4eeebd9ad07f67f634a63fbaf5566d2\WinToFlash.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\9cc867e7a58c9d750717063a5fab65fa\Namo WebEditor (formerly SJ Namo WebEditor 2008 Suite).exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\926166af5b31f99c8f02e2fd157cde06\Aimersoft DVD Studio Pack.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\8ede4dc86b5a9ef59f9b287e68db777b\Zend Guard.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\8e8b06023caa27ef926fd02404d76a58\IDEAL Administration.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\8a085f1ccd0645951cba1b0f72453155\@RISK.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\8121bb898c1381151afeef5775156929\KMPlayer.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\7aeaf46c38b871dbaf6fd53de148f4bf\VIPRE Internet Security.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\7810c7c452d7a2cfa1342e3045938401\MixMeister Fusion + Video.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\775ac99fee31593774d9bcbc8cc87587\iZotope Ozone.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\72d328ce205f8949cc769727df068d49\NetSupport School.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\71c0ebd36f6b7dabd74f17133d823fd0\Retina Network Security Scanner.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\6f0afe7c9542b2a814cec8651e5c60a3\DVD-lab PRO.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\6dc570c32271499434defaa72ceeecb1\DameWare Remote Support.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\6b1ec46c9710696d097e233d48b07262\SRS HD Audio Lab (formerly SRS Audio Sandbox).exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\676237a88e9c56eea9d1fe06b1e69344\EZ Photo Calendar Creator.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\653adebd49bb6a1f2457e81a1297390d\Portrait Professional.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\58b394cfbc5a5c88d1f3d8cf25a8562e\Snagit.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\4fb47afa680b2e956192a3ddb27d8a61\UltraEdit.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\4c1faed2b681e3c4d925cd3726f74cfa\K7 TotalSecurity.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\4b1863f313043b754f7027a3e36d71c2\CopyTo.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\4a539c02f2b553240554eca7c61e29d2\ShadowProtect Desktop Edition.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\49a7f87925e6e6b9eaf24517160f17e1\ESET Smart Security.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\43ead8a56025f0a444a3c235aa64be13\CyberLink LabelPrint.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\4276e0c108cce6452e2b96cab30ce480\ESF Database Migration Toolkit Standard.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\3d876cec8c903c77fb0ea1cec85b8259\ZC Dream Photo Editor Pro.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\32c7c4617c2f124442f4d9e634ce0b39\SmartDraw.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\303f547e4d3583f6a66e3123cf1d7d93\Photo Slideshow Maker Professional.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\2a9777aa0a1ee159b01f6fee648f4f79\Adobe Director.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\23cab078d5bbf34d714c57f40ea3eb6f\Artisteer Standard Edition.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\22c5a059d6ed480fdc5acb52653650be\Kiwi Syslog Server.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\1ce4711eed04c93bdd7ed7a680ab291b\Sendblaster Free Edition.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\18474902db40b9986a3eb37c55dd8702\Recover My Files.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\12e248fb174f1aa1ed2153e725848165\VisualCron.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\0c378a9cfc79d75d5746a89300aaa7d5\Magic Burning Studio.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\0a7e99987399cff54359c212c5eea819\AVS Audio Converter.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\051b2101aeebbb2a2d4c743e24e6d2f2\Solid Converter PDF.exe
2015-03-13 15:33 . 2015-03-13 15:33 54525952 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\031f5a6f6ed4d08174464e3e0c217001\AKVIS Sketch.exe
2015-03-13 15:32 . 2015-03-13 15:32 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\f2a1cbf2a2362efa2ef657332b901ab0\WMP x264 Codec Pack.exe
2015-03-13 15:32 . 2015-03-13 15:32 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\efb98e99eedf98634aa58e0d9270816e\WMP x264 Codec Pack.exe
2015-03-13 15:32 . 2015-03-13 15:32 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\e8c87d099adeba5b52dabecb40f27bf7\WMP x264 Codec Pack.exe
2015-03-13 15:32 . 2015-03-13 15:32 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\e743528acf4010f84595a60e4968243c\WMP x264 Codec Pack.exe
2015-03-13 15:32 . 2015-03-13 15:32 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\e6d6952a666f977ad46199fbdf21591e\WMP x264 Codec Pack.exe
2015-03-13 15:32 . 2015-03-13 15:32 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\e4d76ce6842aed2585d46aa03bd6a658\WMP x264 Codec Pack.exe
2015-03-13 15:32 . 2015-03-13 15:32 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\e43a71bca640ee65e36575e8c5f2237a\WMP x264 Codec Pack.exe
2015-03-13 15:32 . 2015-03-13 15:32 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\e329aadffb093f88647031080a7c3190\WMP x264 Codec Pack.exe
2015-03-13 15:32 . 2015-03-13 15:32 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\de4eb97efe9edad41bcef39b148d4f28\WMP x264 Codec Pack.exe
2015-03-13 15:32 . 2015-03-13 15:32 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\dd3d5659bc23a8351edead3936c8d6e0\WMP x264 Codec Pack.exe
2015-03-13 15:32 . 2015-03-13 15:32 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\d9b87462ceef00ebb1f21187658eb5b1\WMP x264 Codec Pack.exe
2015-03-13 15:32 . 2015-03-13 15:32 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\d6f2b3b2ec680fa24764fa02972402d7\WMP x264 Codec Pack.exe
2015-03-13 15:32 . 2015-03-13 15:32 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\d45c3e99b3dee4341d58dfcb888ec81d\WMP x264 Codec Pack.exe
2015-03-13 15:32 . 2015-03-13 15:32 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\d447908840bf527518af74efb430f333\WMP x264 Codec Pack.exe
2015-03-13 15:32 . 2015-03-13 15:32 12582912 ----a-w- c:\programdata\Microsoft\Security\Client\SecurityCache\data\cddf3211e22940d2d011a4fa81001123\WMP x264 Codec Pack.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\admin\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\admin\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\admin\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\admin\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2015-02-19 07:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2015-02-19 07:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2015-02-19 07:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2015-02-19 07:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2015-02-19 07:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2015-02-19 07:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2014-04-21 08:02 23008 ----a-w- c:\program files\IDM\Internet Download Manager\IDMShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files\IDM\Internet Download Manager\IDMan.exe" [2015-02-28 3890768]
"iCloudServices"="c:\program files\Common Files\Apple\Internet Services\iCloudServices.exe" [2013-11-20 59720]
"ApplePhotoStreams"="c:\program files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2013-11-20 59720]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2010-12-22 2047088]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2015-02-12 60712]
"AVG_UI"="c:\program files\AVG\AVG2014\avgui.exe" [2014-12-16 5188112]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-01-21 91520]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2015-02-17 3978600]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2015-02-13 157480]
"combofix"="c:\combofix\CF16507.3XE" [2015-03-23 301568]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoAutorun"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Scripts\Logoff\0\0]
"Script"=c:\program files\Bitdefender\Bitdefender\support.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApplePhotoStreams]
2013-11-20 08:43 59720 ----a-w- c:\program files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlueStacks Agent]
2014-05-21 14:03 832272 ----a-w- c:\program files\BlueStacks\HD-Agent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2012-07-12 13:42 138096 ----atw- c:\users\admin\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GarenaPlus]
2015-01-20 12:20 9981528 ----a-w- c:\program files\Garena Plus\GarenaMessenger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iCloudServices]
2013-11-20 08:43 59720 ----a-w- c:\program files\Common Files\Apple\Internet Services\iCloudServices.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
2015-02-28 03:34 3890768 ----a-r- c:\program files\IDM\Internet Download Manager\IDMan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InFX]
2013-08-11 08:41 44032 ----a-w- c:\users\admin\AppData\Roaming\StratFX\nircmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2015-02-13 00:55 157480 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
2015-02-17 11:21 3978600 ----a-w- c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2014-10-02 07:23 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RIMBBLaunchAgent.exe]
2013-01-17 09:08 267792 ----a-w- c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-12-22 717296]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2014\avgidsagent.exe [2014-12-16 3247120]
R2 BstHdAndroidSvc;BlueStacks Android Service;c:\program files\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2015-02-17 1848680]
R3 Blackberry Device Manager;Blackberry Device Manager;c:\program files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [2013-01-18 577536]
R3 BprotectEx;Baidu ProtectEx;c:\windows\System32\drivers\BprotectEx.sys [x]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_2\bin\fbguard.exe [2011-02-01 81920]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files\Garena Plus\Room\safedrv.sys [x]
R3 GSService;GSService;c:\windows\system32\GSService.exe [2014-07-28 444640]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl.sys [2013-07-25 18944]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2014-01-15 5161056]
R3 OEM;USB Modem and USB Serial;c:\windows\system32\DRIVERS\hs60x5usbser.sys [2012-03-08 107000]
R3 Origin Client Service;Origin Client Service;d:\origin\OriginClientService.exe [2015-02-20 1910128]
R3 PCFApiUtil;PCFApiUtil;c:\program files\Baidu Security\PC Faster\4.0.0.0\PCFApiUtil.sys [x]
R3 STSService;STSService;c:\program files\SoundTaxi Media Suite\STSService.exe [2011-03-21 421376]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2013-04-12 104720]
R3 XDva392;XDva392; [x]
R4 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe [2010-12-14 27760]
S0 AVGIDSHX;AVGIDSHX;c:\windows\system32\DRIVERS\avgidshx.sys [2014-06-17 147736]
S0 Avglogx;AVG Logging Driver;c:\windows\system32\DRIVERS\avglogx.sys [2014-06-17 241944]
S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2014-06-17 27416]
S0 Bhbase;Baidu Hook Base;c:\windows\System32\drivers\Bhbase.sys [2014-03-11 47456]
S1 Avgdiskx;AVG Disk Driver;c:\windows\system32\DRIVERS\avgdiskx.sys [2014-06-30 121624]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdriverx.sys [2014-07-21 200984]
S1 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\avgidsshimx.sys [2014-06-17 21272]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2014-10-24 189720]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2014-10-20 197400]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2014-08-30 42784]
S1 HssDRV6;Hotspot Shield Routing Driver 6;c:\windows\system32\DRIVERS\hssdrv6.sys [2013-11-13 39624]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2013-04-12 188176]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2013-04-12 94480]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2013-04-30 217088]
S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2014\avgwdsvc.exe [2014-12-16 289328]
S2 BstHdDrv;BlueStacks Hypervisor;c:\program files\BlueStacks\HD-Hypervisor-x86.sys [2014-05-21 113424]
S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files\BlueStacks\HD-LogRotatorService.exe [2014-05-21 385808]
S2 BstHdUpdaterSvc;BlueStacks Updater Service;c:\program files\BlueStacks\HD-UpdaterService.exe [2014-05-21 774928]
S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [2014-11-29 115752]
S2 Innosvcd;Innosvcd;c:\windows\system32\innosvcd.exe [2013-04-04 193144]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn Hamachi\LMIGuardianSvc.exe [2015-02-16 411920]
S2 TeamViewer9;TeamViewer 9;d:\data\Games\Team Viewer 9\TeamViewer_Service.exe [2014-09-12 4799760]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-10-06 2655768]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2013-07-05 78848]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [2010-10-21 68208]
S3 MEI;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECI.sys [2010-09-21 41088]
S3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys [2013-11-13 37064]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2014-06-06 25088]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2013-04-12 115984]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2010-12-14 1153648]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-03-21 07:37 1061704 ----a-w- c:\program files\Google\Chrome\Application\41.0.2272.101\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2015-03-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-07 10:25]
.
2015-03-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1380481859-1212219880-2585911621-1000Core.job
- c:\users\admin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-31 13:42]
.
2015-03-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1380481859-1212219880-2585911621-1000UA.job
- c:\users\admin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-31 13:42]
.
2015-03-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore1ce820314248fdf.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-07-31 13:30]
.
2015-03-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-07-31 13:30]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.google.com
IE: Download all links with IDM - c:\program files\IDM\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - c:\program files\IDM\Internet Download Manager\IEExt.htm
TCP: DhcpNameServer = 91.194.254.105 8.8.8.8
TCP: Interfaces\{515E0BE1-5E90-47D0-88F7-E09BD12DBAFC}: NameServer = 8.8.8.8
TCP: Interfaces\{5897E3A2-9727-4A42-8EB5-9424E4FCA0E5}: NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{9D152133-7846-4DAC-B21E-A7253D1E1963}: NameServer = 208.67.222.222,208.67.220.220
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
FF - ProfilePath - c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\1h0mjti4.default\
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: !HIDDEN! 2014-06-08 15:12;
quick_start@gmail.com; c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\1h0mjti4.default\extensions\
quick_start@gmail.com
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
HKU-Default-Run-Bitdefender Wallet Agent - c:\program files\Bitdefender\Bitdefender\pmbxag.exe
HKU-Default-Run-Bitdefender Wallet - c:\program files\Bitdefender\Bitdefender\pwdmanui.exe
HKU-Default-Run-Bitdefender Wallet Application Agent - c:\program files\Bitdefender\Bitdefender\bdapppassmgr.exe
MSConfigStartUp-Malwarebytes Anti-Exploit - c:\program files\Malwarebytes Anti-Exploit\mbae.exe
MSConfigStartUp-Messenger (Yahoo!) - c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
AddRemove-AVG Web TuneUp - c:\program files\AVG Web TuneUp\UNINSTALL.exe
AddRemove-Exact Audio Copy PSP Edition - c:\program files\Exact Audio Copy PSP Edition\uninst.exe
AddRemove-TeXstudio_is1 - d:\data\Protext Latex\TeXstudio\Data\unins000.exe
AddRemove-Yahoo! Messenger - c:\progra~1\Yahoo!\MESSEN~1\UNWISE.EXE
AddRemove-{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f} - c:\programdata\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe
AddRemove-{ce085a78-074e-4823-8dc1-8a721b94b76d} - c:\programdata\Package Cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\vcredist_x86.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1380481859-1212219880-2585911621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2]
@Denied: (Full) (Everyone)
.
[HKEY_USERS\S-1-5-21-1380481859-1212219880-2585911621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f07c0317-e30a-11e0-b826-878dbc7a65f3}\shell]
@="AutoRun"
.
[HKEY_USERS\S-1-5-21-1380481859-1212219880-2585911621-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f07c031a-e30a-11e0-b826-878dbc7a65f3}\shell]
@="None"
.
[HKEY_USERS\S-1-5-21-1380481859-1212219880-2585911621-1000_Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):f5,4a,ed,ba,01,d4,4f,23,ff,28,c1,bc,e4,94,ce,02,b6,0a,5f,05,aa,
29,6a,e2,cf,af,14,dc,61,e7,36,4d,86,c3,11,37,cd,5a,e6,9f,00,00,00,00,00,00,\
.
[HKEY_USERS\S-1-5-21-1380481859-1212219880-2585911621-1000_Classes\CLSID\{602d3363-c9cb-468b-82cd-1aed85b52b18}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:000000ef
"Therad"=dword:00000026
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,75,07,18,dd,fb,11,42,94,27,b7,99,0d,2a,ba,05,1a,a2,02,c9,3e,9b,f9,\
.
[HKEY_USERS\S-1-5-21-1380481859-1212219880-2585911621-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):9b,15,e6,1a,80,90,e2,46,9c,13,f4,7f,5b,f6,29,32,e3,e4,a2,e4,a3,
f6,fb,84,6c,03,09,ad,32,34,6d,f7,76,56,7b,f6,88,69,23,09,00,00,00,00,00,00,\
.
[HKEY_USERS\S-1-5-21-1380481859-1212219880-2585911621-1000_Classes\CLSID\{b9afe023-29f5-4bb9-b8fb-9dc9cee56eb7}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000041
"Therad"=dword:0000001c
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\atieclxx.exe
c:\windows\system32\taskhost.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Garena Plus\ggdllhost.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\conhost.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\IDM\Internet Download Manager\IEMonitor.exe
c:\program files\Common Files\Apple\Internet Services\APSDaemon.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\sppsvc.exe
c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
.
**************************************************************************
.
Completion time: 2015-03-24 00:55:45 - machine was rebooted
ComboFix-quarantined-files.txt 2015-03-23 17:55
.
Pre-Run: 10,649,100,288 bytes free
Post-Run: 10,296,672,256 bytes free
.
- - End Of File - - 87945258C324A257CA9C5F77D4AB67C1
A36C5E4F47E84449FF07ED3517B43A31