ComboFix 16-04-29.01 - Alexa 05/07/2016 16:47:45.2.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6051.4461 [GMT -4:00]
Running from: c:\users\Alexa\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {768124D7-F5F7-6D2F-DDC2-94DFA4017C95}
SP: Microsoft Security Essentials *Disabled/Updated* {CDE0C533-D3CD-62A1-E772-AFADDF863628}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\windows\msdownld.tmp
.
.
((((((((((((((((((((((((( Files Created from 2016-04-07 to 2016-05-07 )))))))))))))))))))))))))))))))
.
.
2016-05-07 20:57 . 2016-05-07 20:57 -------- d-----w- c:\users\Public\AppData\Local\temp
2016-05-07 20:57 . 2016-05-07 20:57 -------- d-----w- c:\users\Guest\AppData\Local\temp
2016-05-07 20:57 . 2016-05-07 20:57 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-05-07 20:57 . 2016-05-07 20:57 -------- d-----w- c:\users\Dad\AppData\Local\temp
2016-05-07 20:43 . 2016-05-07 20:43 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BA88E6B5-DEB9-40F7-BBA5-14649511EE7A}\offreg.992.dll
2016-05-07 17:53 . 2016-04-20 01:13 11695896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BA88E6B5-DEB9-40F7-BBA5-14649511EE7A}\mpengine.dll
2016-05-06 18:16 . 2016-05-07 04:26 -------- d-----w- C:\FRST
2016-05-06 15:52 . 2016-04-20 01:13 11695896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2016-05-05 03:31 . 2016-05-05 03:31 -------- d-----w- c:\users\Alexa\AppData\Local\Electronic Arts
2016-05-05 01:21 . 2015-07-05 16:04 1190000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5EF5E8B0-D4D2-45BA-86B6-9EAFFCD86CB9}\gapaengine.dll
2016-05-05 01:10 . 2016-03-21 20:01 56384 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2016-05-05 01:10 . 2016-03-21 20:01 100416 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2016-04-16 22:00 . 2016-03-29 17:53 3216896 ----a-w- c:\windows\system32\win32k.sys
2016-04-11 01:51 . 2016-04-11 01:51 -------- d-----w- c:\program files\Microsoft Xbox 360 Accessories
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-05-07 20:41 . 2014-07-21 04:59 192216 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2016-05-07 16:39 . 2015-06-12 07:39 24688 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2016-04-22 07:57 . 2012-09-28 20:15 453288 ------w- c:\windows\system32\MpSigStub.exe
2016-04-17 06:38 . 2012-09-28 20:51 135176864 ----a-w- c:\windows\system32\MRT.exe
2016-04-08 02:19 . 2012-10-20 03:05 797376 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2016-04-08 02:19 . 2012-10-20 03:05 142528 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2016-03-22 04:12 . 2016-03-29 22:06 8659472 ----a-w- c:\windows\SysWow64\nvptxJitCompiler.dll
2016-03-22 04:12 . 2016-03-29 22:06 39992 ----a-w- c:\windows\system32\drivers\nvpciflt.sys
2016-03-22 04:12 . 2016-03-29 22:06 31555008 ----a-w- c:\windows\system32\nvoglv64.dll
2016-03-22 04:12 . 2016-03-29 22:06 21355248 ----a-w- c:\windows\system32\nvopencl.dll
2016-03-22 04:12 . 2016-03-29 22:06 19004040 ----a-w- c:\windows\system32\nvwgf2umx.dll
2016-03-22 04:12 . 2016-03-29 22:06 17748712 ----a-w- c:\windows\SysWow64\nvopencl.dll
2016-03-22 04:12 . 2016-03-29 22:06 16446032 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2016-03-22 04:12 . 2016-03-29 22:06 10550736 ----a-w- c:\windows\system32\nvptxJitCompiler.dll
2016-03-22 04:12 . 2016-03-29 22:06 889400 ----a-w- c:\windows\system32\NvIFR64.dll
2016-03-22 04:12 . 2016-03-29 22:06 753208 ----a-w- c:\windows\SysWow64\NvFBC.dll
2016-03-22 04:12 . 2016-03-29 22:06 695864 ----a-w- c:\windows\SysWow64\NvIFR.dll
2016-03-22 04:12 . 2016-03-29 22:06 678520 ----a-w- c:\windows\system32\nvfatbinaryLoader.dll
2016-03-22 04:12 . 2016-03-29 22:06 571912 ----a-w- c:\windows\SysWow64\nvfatbinaryLoader.dll
2016-03-22 04:12 . 2016-03-29 22:06 42923576 ----a-w- c:\windows\system32\nvcompiler.dll
2016-03-22 04:12 . 2016-03-29 22:06 37567424 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2016-03-22 04:12 . 2016-03-29 22:06 3235896 ----a-w- c:\windows\system32\nvcuvid.dll
2016-03-22 04:12 . 2016-03-29 22:06 2809280 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2016-03-22 04:12 . 2016-03-29 22:06 25321408 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2016-03-22 04:12 . 2016-03-29 22:06 20897416 ----a-w- c:\windows\system32\nvcuda.dll
2016-03-22 04:12 . 2016-03-29 22:06 1924152 ----a-w- c:\windows\system32\nvdispco6436472.dll
2016-03-22 04:12 . 2016-03-29 22:06 17342392 ----a-w- c:\windows\SysWow64\nvcuda.dll
2016-03-22 04:12 . 2016-03-29 22:06 17248408 ----a-w- c:\windows\system32\nvd3dumx.dll
2016-03-22 04:12 . 2016-03-29 22:06 1573432 ----a-w- c:\windows\system32\nvdispgenco6436472.dll
2016-03-22 04:12 . 2016-03-29 22:06 151368 ----a-w- c:\windows\system32\nvoglshim64.dll
2016-03-22 04:12 . 2016-03-29 22:06 129208 ----a-w- c:\windows\SysWow64\nvoglshim32.dll
2016-03-22 04:12 . 2016-03-29 22:06 12567608 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2016-03-22 04:12 . 2016-03-07 21:22 473592 ----a-w- c:\windows\system32\nvumdshimx.dll
2016-03-22 04:12 . 2016-03-07 21:22 175368 ----a-w- c:\windows\system32\nvinitx.dll
2016-03-22 04:12 . 2016-02-18 03:13 959544 ----a-w- c:\windows\system32\NvFBC64.dll
2016-03-22 04:12 . 2015-06-01 21:25 3286992 ----a-w- c:\windows\SysWow64\nvapi.dll
2016-03-22 04:12 . 2014-02-19 04:22 14128840 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2016-03-22 04:12 . 2014-01-22 23:24 391632 ----a-w- c:\windows\SysWow64\nvumdshim.dll
2016-03-22 04:12 . 2014-01-22 23:24 153392 ----a-w- c:\windows\SysWow64\nvinit.dll
2016-03-22 04:12 . 2012-10-26 00:02 3714472 ----a-w- c:\windows\system32\nvapi64.dll
2016-03-22 02:25 . 2012-11-02 17:35 2993088 ----a-w- c:\windows\system32\nvsvc64.dll
2016-03-22 02:25 . 2012-11-02 17:35 6369728 ----a-w- c:\windows\system32\nvcpl.dll
2016-03-22 02:25 . 2012-11-02 17:35 2561472 ----a-w- c:\windows\system32\nvsvcr.dll
2016-03-22 02:25 . 2012-11-02 17:35 1264064 ----a-w- c:\windows\system32\nvvsvc.exe
2016-03-22 02:25 . 2012-11-02 17:35 81856 ----a-w- c:\windows\system32\nv3dappshextr.dll
2016-03-22 02:25 . 2012-11-02 17:35 69568 ----a-w- c:\windows\system32\nvshext.dll
2016-03-22 02:25 . 2012-11-02 17:35 532536 ----a-w- c:\windows\system32\nv3dappshext.dll
2016-03-22 02:25 . 2012-11-02 17:35 393784 ----a-w- c:\windows\system32\nvmctray.dll
2016-03-21 20:01 . 2016-01-27 23:32 109632 ----a-w- c:\windows\system32\nvaudcap64v.dll
2016-03-18 18:10 . 2012-11-02 17:35 6253721 ----a-w- c:\windows\system32\nvcoproc.bin
2016-03-17 22:24 . 2016-04-16 22:01 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2016-03-16 21:30 . 2016-03-16 21:30 128792 ----a-w- c:\windows\SysWow64\vulkan-1-1-0-5-1.dll
2016-03-16 21:30 . 2016-03-11 04:08 128792 ----a-w- c:\windows\SysWow64\vulkan-1.dll
2016-03-16 21:29 . 2016-03-16 21:29 41752 ----a-w- c:\windows\SysWow64\vulkaninfo-1-1-0-5-1.exe
2016-03-16 21:29 . 2016-03-11 04:08 41752 ----a-w- c:\windows\SysWow64\vulkaninfo.exe
2016-03-16 21:29 . 2016-03-16 21:29 127768 ----a-w- c:\windows\system32\vulkan-1-1-0-5-1.dll
2016-03-16 21:29 . 2016-03-11 04:08 127768 ----a-w- c:\windows\system32\vulkan-1.dll
2016-03-16 21:28 . 2016-03-16 21:28 45848 ----a-w- c:\windows\system32\vulkaninfo-1-1-0-5-1.exe
2016-03-16 21:28 . 2016-03-11 04:08 45848 ----a-w- c:\windows\system32\vulkaninfo.exe
2016-03-10 18:09 . 2014-07-21 04:59 64896 ----a-w- c:\windows\system32\drivers\mwac.sys
2016-03-10 18:08 . 2014-07-21 04:59 140672 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2016-03-10 18:08 . 2012-09-29 00:05 27008 ----a-w- c:\windows\system32\drivers\mbam.sys
2016-03-08 10:07 . 2016-03-11 04:06 1924152 ----a-w- c:\windows\system32\nvdispco6436451.dll
2016-03-08 10:07 . 2016-03-11 04:06 1571776 ----a-w- c:\windows\system32\nvdispgenco6436451.dll
2016-03-03 12:20 . 2016-03-07 21:22 1922496 ----a-w- c:\windows\system32\nvdispco6436447.dll
2016-03-03 12:20 . 2016-03-07 21:22 1573432 ----a-w- c:\windows\system32\nvdispgenco6436447.dll
2016-02-23 23:58 . 2016-03-02 03:25 1571776 ----a-w- c:\windows\system32\nvdispgenco6436200.dll
2016-02-23 23:58 . 2016-03-02 03:25 1922496 ----a-w- c:\windows\system32\nvdispco6436200.dll
2016-02-17 06:40 . 2014-06-02 19:31 1316184 ----a-w- c:\windows\SysWow64\nvspbridge.dll
2016-02-17 06:40 . 2014-01-22 23:28 1571624 ----a-w- c:\windows\SysWow64\nvspcap.dll
2016-02-17 06:40 . 2015-11-24 01:07 112216 ----a-w- c:\windows\system32\NvRtmpStreamer64.dll
2016-02-17 06:40 . 2014-06-02 19:31 1756424 ----a-w- c:\windows\system32\nvspbridge64.dll
2016-02-17 06:40 . 2014-01-22 23:28 1903344 ----a-w- c:\windows\system32\nvspcap64.dll
2016-02-14 01:47 . 2016-02-14 01:47 125720 ----a-w- c:\windows\SysWow64\vulkan-1-1-0-3-0.dll
2016-02-14 01:46 . 2016-02-14 01:46 126232 ----a-w- c:\windows\system32\vulkan-1-1-0-3-0.dll
2016-02-14 01:45 . 2016-02-14 01:45 42264 ----a-w- c:\windows\SysWow64\vulkaninfo-1-1-0-3-0.exe
2016-02-14 01:45 . 2016-02-14 01:45 45848 ----a-w- c:\windows\system32\vulkaninfo-1-1-0-3-0.exe
2016-02-12 18:52 . 2016-03-09 03:50 98816 ----a-w- c:\windows\system32\wudriver.dll
2016-02-12 18:52 . 2016-03-09 03:50 3169792 ----a-w- c:\windows\system32\wucltux.dll
2016-02-12 18:52 . 2016-03-09 03:50 192512 ----a-w- c:\windows\system32\wuwebv.dll
2016-02-12 18:44 . 2016-03-09 03:50 91136 ----a-w- c:\windows\system32\WinSetupUI.dll
2016-02-12 18:39 . 2016-03-09 03:50 174080 ----a-w- c:\windows\SysWow64\wuwebv.dll
2016-02-12 18:22 . 2016-03-09 03:50 2610688 ----a-w- c:\windows\system32\wuaueng.dll
2016-02-12 18:19 . 2016-03-09 03:50 709120 ----a-w- c:\windows\system32\wuapi.dll
2016-02-12 18:18 . 2016-03-09 03:50 37888 ----a-w- c:\windows\system32\wuapp.exe
2016-02-12 18:18 . 2016-03-09 03:50 140288 ----a-w- c:\windows\system32\wuauclt.exe
2016-02-12 18:18 . 2016-03-09 03:50 36864 ----a-w- c:\windows\system32\wups.dll
2016-02-12 18:18 . 2016-03-09 03:50 37888 ----a-w- c:\windows\system32\wups2.dll
2016-02-12 18:18 . 2016-03-09 03:50 12288 ----a-w- c:\windows\system32\wu.upgrade.ps.dll
2016-02-12 18:06 . 2016-03-09 03:50 573440 ----a-w- c:\windows\SysWow64\wuapi.dll
2016-02-12 18:05 . 2016-03-09 03:50 93696 ----a-w- c:\windows\SysWow64\wudriver.dll
2016-02-12 18:05 . 2016-03-09 03:50 30208 ----a-w- c:\windows\SysWow64\wups.dll
2016-02-12 18:05 . 2016-03-09 03:50 35328 ----a-w- c:\windows\SysWow64\wuapp.exe
2016-02-09 09:57 . 2016-03-09 03:49 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2016-02-09 09:57 . 2016-03-09 03:49 14634496 ----a-w- c:\windows\system32\wmp.dll
2016-02-09 09:56 . 2016-03-09 03:49 5120 ----a-w- c:\windows\system32\msdxm.ocx
2016-02-09 09:56 . 2016-03-09 03:49 5120 ----a-w- c:\windows\system32\dxmasf.dll
2016-02-09 09:55 . 2016-03-09 03:49 30720 ----a-w- c:\windows\system32\seclogon.dll
2016-02-09 09:54 . 2016-03-09 03:49 9728 ----a-w- c:\windows\system32\spwmp.dll
2016-02-09 09:51 . 2016-03-09 03:49 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2016-04-30 3077712]
"Spotify Web Helper"="c:\users\Alexa\AppData\Roaming\Spotify\SpotifyWebHelper.exe" [2016-04-23 1525360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys;c:\windows\SYSNATIVE\DRIVERS\dc3d.sys [x]
R3 EasyAntiCheat;EasyAntiCheat;c:\windows\system32\EasyAntiCheat.exe;c:\windows\SYSNATIVE\EasyAntiCheat.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
R3 LVUVC64;Logitech HD Webcam C310(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x]
R3 Origin Client Service;Origin Client Service;c:\program files (x86)\Origin\OriginClientService.exe;c:\program files (x86)\Origin\OriginClientService.exe [x]
R3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys;c:\windows\SYSNATIVE\DRIVERS\WSDScan.sys [x]
R3 X6va017;X6va017;c:\windows\SysWOW64\Drivers\X6va017;c:\windows\SysWOW64\Drivers\X6va017 [x]
R3 X6va028;X6va028;c:\windows\SysWOW64\Drivers\X6va028;c:\windows\SysWOW64\Drivers\X6va028 [x]
R3 X6va029;X6va029;c:\windows\SysWOW64\Drivers\X6va029;c:\windows\SysWOW64\Drivers\X6va029 [x]
R3 X6va031;X6va031;c:\windows\SysWOW64\Drivers\X6va031;c:\windows\SysWOW64\Drivers\X6va031 [x]
R3 X6va035;X6va035;c:\windows\SysWOW64\Drivers\X6va035;c:\windows\SysWOW64\Drivers\X6va035 [x]
R4 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys;c:\windows\SYSNATIVE\DRIVERS\thpdrv.sys [x]
S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS;c:\windows\SYSNATIVE\DRIVERS\Thpevm.SYS [x]
S1 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys;c:\windows\SYSNATIVE\drivers\mbamchameleon.sys [x]
S2 AESMFilters;Andrea Samson Filters Service64;c:\windows\system32\AESMSr64.exe;c:\windows\SYSNATIVE\AESMSr64.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 Ds3Service;SCP DS3 Service;c:\program files\Scarlet.Crush Productions\bin\ScpService.exe;c:\program files\Scarlet.Crush Productions\bin\ScpService.exe [x]
S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
S2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service;c:\program files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe;c:\program files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [x]
S2 RtkAudioService;Realtek Audio Service;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe [x]
S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x]
S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 NvStreamNetworkSvc;NVIDIA Streamer Network Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 ScpVBus;Scp Virtual Bus Driver;c:\windows\system32\DRIVERS\ScpVBus.sys;c:\windows\SYSNATIVE\DRIVERS\ScpVBus.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{A6EADE66-0000-0000-484E-7E8A45000000}]
2015-12-18 15:42 286904 ----a-w- c:\program files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll
.
Contents of the 'Scheduled Tasks' folder
.
2016-05-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-20 02:19]
.
2016-05-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1051028164-3291638393-1546100382-1000Core.job
- c:\users\Alexa\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-28 04:09]
.
2016-05-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1051028164-3291638393-1546100382-1000UA.job
- c:\users\Alexa\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-28 04:09]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ThpSrv"="c:\windows\system32\thpsrv" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-05 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-05 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-05 418840]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2016-01-30 1340192]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2016-03-30 2396096]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2016-02-17 1903344]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2014-05-09 13672152]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://
www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Alexa\AppData\Roaming\Mozilla\Firefox\Profiles\9seab2en.default\
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-GoogleDriveSync - c:\program files (x86)\Google\Drive\googledrivesync.exe
ShellIconOverlayIdentifiers-{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va017]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va017"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va028]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va028"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va029]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va029"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va031]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va031"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va035]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va035"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1051028164-3291638393-1546100382-1000\Software\SecuROM\License information*]
"datasecu"=hex:26,9e,fc,f1,05,e5,3d,9f,9e,14,d8,a3,d2,aa,65,fb,00,da,8e,d6,72,
ab,dd,15,f3,4c,85,5b,54,15,8b,ab,cf,2a,2a,31,5a,7c,4b,3b,1a,77,d7,86,ff,bb,\
"rkeysecu"=hex:59,7e,f3,17,8f,30,20,05,a6,84,98,7e,d6,62,f5,c6
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_21_0_0_213_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_21_0_0_213_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_21_0_0_213_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_21_0_0_213_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_21_0_0_213.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.21"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_21_0_0_213.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_21_0_0_213.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_21_0_0_213.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2016-05-07 17:00:18
ComboFix-quarantined-files.txt 2016-05-07 21:00
ComboFix2.txt 2015-06-07 18:49
.
Pre-Run: 451,266,625,536 bytes free
Post-Run: 451,595,108,352 bytes free
.
- - End Of File - - E93348B0166F4183F5DD81D56BE166E9
A36C5E4F47E84449FF07ED3517B43A31