Command switches used :: c:\users\admin\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
FILE ::
"c:\windows\system32\drivers\wqjbnkgz.sys"
"c:\windows\System32\hale.exe"
"c:\windows\SysWow64\tasks.dll"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
c:\programdata\ntuser.pol
c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\Fonts\Vn.Fon
c:\windows\system32\drivers\wqjbnkgz.sys
c:\windows\System32\hale.exe
c:\windows\SysWow64\drivers\BkavAuto.sys
c:\windows\SysWow64\drivers\SysLib.sys
c:\windows\SysWow64\tasks.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_WQJBNKGZ
-------\Service_BkavAuto
-------\Service_SysLib
.
.
((((((((((((((((((((((((( Files Created from 2015-02-26 to 2015-03-26 )))))))))))))))))))))))))))))))
.
.
2015-03-26 07:59 . 2015-03-26 07:59 -------- d-----w- c:\users\MSSQL$HUY\AppData\Local\temp
2015-03-26 07:59 . 2015-03-26 07:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-03-23 14:16 . 2015-03-23 14:16 -------- d-s---w- c:\windows\SysWow64\Microsoft
2015-03-22 05:44 . 2015-03-22 06:25 -------- d-----w- c:\users\admin\AppData\Roaming\Dropbox
2015-03-22 05:24 . 2015-03-22 05:37 -------- d-----w- c:\windows\SysWow64\vbox
2015-03-22 05:24 . 2015-03-22 05:37 -------- d-----w- c:\windows\system32\vbox
2015-03-22 05:16 . 2015-03-23 14:42 -------- d-----w- c:\programdata\AVAST Software
2015-03-20 14:52 . 2015-03-23 14:21 -------- d-----w- c:\users\admin\AppData\Roaming\BitTorrent
2015-03-20 03:36 . 2015-03-20 03:38 -------- d-----w- C:\AdwCleaner
2015-03-20 02:54 . 2015-03-20 02:54 -------- d-----w- c:\programdata\Malwarebytes
2015-03-20 02:41 . 2015-03-20 02:41 35064 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2015-03-20 02:41 . 2015-03-20 02:57 -------- d-----w- c:\programdata\RogueKiller
2015-03-20 02:20 . 2015-03-20 02:20 0 ----a-w- c:\windows\SysWow64\link.sys
2015-03-20 02:11 . 2015-03-20 02:11 -------- d-----w- c:\users\admin\AppData\Roaming\Bkav2009
2015-03-20 02:08 . 2015-03-23 13:34 -------- d-----w- c:\users\Temp
2015-03-19 03:33 . 2015-03-19 03:35 -------- d-----w- C:\FRST
2015-03-16 10:01 . 2015-03-16 10:01 -------- d-----w- c:\program files (x86)\Realtek
2015-03-16 10:01 . 2010-05-07 02:42 245280 ----a-w- c:\windows\system32\drivers\RtsUStor.sys
2015-03-16 10:01 . 2015-03-16 10:01 -------- d-----w- C:\DRIVERS
2015-03-13 12:07 . 2014-11-14 14:15 23752 ----a-w- c:\windows\SysWow64\drivers\efimon.sys
2015-03-13 12:05 . 2015-03-13 12:05 -------- d-sh--w- c:\programdata\360Quarant
2015-03-12 11:00 . 2015-03-14 14:11 -------- d-----w- c:\programdata\PopCap Games
2015-03-12 10:56 . 2015-03-14 14:10 -------- d-----w- c:\program files (x86)\Opera
2015-03-12 10:56 . 2015-03-13 15:51 -------- d-----w- c:\program files (x86)\360
2015-03-12 02:42 . 2015-03-12 02:42 -------- d-----w- c:\users\admin\AppData\Roaming\JAM Software
2015-03-08 11:16 . 2015-03-08 11:16 -------- d-----w- c:\users\admin\AppData\Roaming\Tencent
2015-03-06 03:17 . 2015-03-06 03:17 -------- d-----w- c:\programdata\Microsoft Visual Studio
2015-03-06 02:41 . 2015-03-06 02:41 2562208 ----a-w- c:\programdata\Microsoft\VisualStudio\11.0\1033\ResourceCache.dll
2015-03-06 02:36 . 2015-03-06 02:36 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2015-03-06 02:34 . 2015-03-06 02:34 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2015-03-06 02:34 . 2015-03-06 02:34 -------- d-----w- c:\program files\Application Verifier
2015-03-06 02:34 . 2015-03-06 02:34 -------- d-----w- c:\program files (x86)\Application Verifier
2015-03-06 02:34 . 2015-03-06 02:34 -------- d-----w- c:\programdata\Windows App Certification Kit
2015-03-06 02:33 . 2015-03-06 02:33 -------- d-----w- c:\program files (x86)\Common Files\Microsoft
2015-03-06 02:32 . 2015-03-06 02:32 -------- d-----w- c:\programdata\PreEmptive Solutions
2015-03-06 02:30 . 2015-03-06 02:31 -------- d-----w- c:\program files (x86)\Microsoft ASP.NET
2015-03-06 02:30 . 2015-03-06 02:30 -------- d-----w- c:\program files (x86)\Microsoft Web Tools
2015-03-06 02:30 . 2015-03-06 02:30 -------- d-----w- c:\program files\Microsoft
2015-03-06 02:29 . 2015-03-06 02:29 -------- d-----w- c:\program files\IIS Express
2015-03-06 02:29 . 2015-03-06 02:29 -------- d-----w- c:\program files (x86)\IIS Express
2015-03-06 02:29 . 2015-03-06 02:29 -------- d-----w- c:\program files (x86)\NuGet
2015-03-06 02:28 . 2015-03-06 02:28 -------- d-----w- c:\program files (x86)\Microsoft WCF Data Services
2015-03-06 02:28 . 2015-03-06 02:28 -------- d-----w- c:\program files\IIS
2015-03-06 02:28 . 2015-03-06 02:28 -------- d-----w- c:\program files (x86)\IIS
2015-03-06 02:26 . 2015-03-06 02:26 -------- d-----w- c:\program files (x86)\Windows Kits
2015-03-06 02:20 . 2015-03-06 02:20 -------- d-----w- c:\program files (x86)\HTML Help Workshop
2015-03-06 02:20 . 2015-03-06 02:20 -------- d-----w- c:\program files (x86)\Microsoft Help Viewer
2015-03-06 02:12 . 2015-03-06 02:12 -------- d-----w- c:\windows\symbols
2015-03-06 02:12 . 2015-03-06 02:12 -------- d-----w- c:\program files\Microsoft Visual Studio 11.0
2015-03-06 02:08 . 2015-03-06 02:08 -------- d-----w- c:\programdata\regid.1991-06.com.microsoft
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-03-06 02:37 . 2014-10-08 02:26 84448 ----a-w- c:\programdata\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll
2015-02-15 15:40 . 2015-02-06 15:42 239104 ----a-w- c:\windows\mlwps.exe
2015-02-02 12:15 . 2009-08-18 05:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2015-02-02 12:13 . 2009-08-18 04:24 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-21 . 1151B1BAA6F350B1DB6598E0FEA7C457 . 390656 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[-] 2012-11-07 . 87A00ED70FEC36D0DD968E5058C29AA1 . 389632 . . [6.1.7601.17514] .. c:\windows\system32\winlogon.exe
.
[7] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[-] 2012-11-07 . D186BABDFAE7C0D93C9F6AE63957EE96 . 1008128 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UniKey"="c:\unikey 4.0 rc2 win64\UniKeyNT.exe" [2009-11-01 316928]
"Messenger (Yahoo!)"="c:\progra~2\Yahoo!\MESSEN~1\YahooMessenger.exe" [2012-05-24 6595928]
"GarenaPlus"="d:\games\LienMinhHuyenThoai\GameData\GarenaMessenger.exe" [2015-01-20 9981528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"YouCam Service"="d:\duy\UNG DUNG\YouCam 5 v5.0.0909 PreActivated_da fix watermark\YouCam\YouCamService.exe" [2011-09-09 247016]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-10-16 291648]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-03-04 343168]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"BkavHome"="c:\program files (x86)\BkavHome\BkavHome.exe" [2015-01-14 2435584]
.
c:\users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE /tsr [2010-3-29 227712]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Canon LBP3000 Status Window.lnk - c:\windows\System32\spool\drivers\x64\3\CNAB3LAD.EXE [2014-11-30 60384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R1 BAPIDRV;BAPIDRV;c:\windows\system32\DRIVERS\BAPIDRV64.sys;c:\windows\SYSNATIVE\DRIVERS\BAPIDRV64.sys [x]
R1 SysLib0;SysLib0;c:\windows\System32\Drivers\SysLib0.sys;c:\windows\SYSNATIVE\Drivers\SysLib0.sys [x]
R1 SysLib1;SysLib1;c:\windows\System32\Drivers\SysLib1.sys;c:\windows\SYSNATIVE\Drivers\SysLib1.sys [x]
R1 SysLib2;SysLib2;c:\windows\System32\Drivers\SysLib2.sys;c:\windows\SYSNATIVE\Drivers\SysLib2.sys [x]
R1 SysLib3;SysLib3;c:\windows\System32\Drivers\SysLib3.sys;c:\windows\SYSNATIVE\Drivers\SysLib3.sys [x]
R1 SysLib4;SysLib4;c:\windows\System32\Drivers\SysLib4.sys;c:\windows\SYSNATIVE\Drivers\SysLib4.sys [x]
R1 SysLib5;SysLib5;c:\windows\System32\Drivers\SysLib5.sys;c:\windows\SYSNATIVE\Drivers\SysLib5.sys [x]
R1 SysLib6;SysLib6;c:\windows\System32\Drivers\SysLib6.sys;c:\windows\SYSNATIVE\Drivers\SysLib6.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service; [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x]
R3 cxasbt;cxasbt;d:\duy\GAMES\AvatarStarVN\avital\cxbtf64.sys;d:\duy\GAMES\AvatarStarVN\avital\cxbtf64.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 GGSAFERDriver;GGSAFER Driver;d:\games\LienMinhHuyenThoai\GameData\Room\safedrv.sys;d:\games\LienMinhHuyenThoai\GameData\Room\safedrv.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 Ndisrd;WinpkFilter Service;c:\windows\system32\DRIVERS\ndisrd.sys;c:\windows\SYSNATIVE\DRIVERS\ndisrd.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x]
R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VBoxUSB;VirtualBox USB;c:\windows\system32\Drivers\VBoxUSB.sys;c:\windows\SYSNATIVE\Drivers\VBoxUSB.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
R4 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x]
R4 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x]
R4 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
R4 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
R4 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R4 RsFx0200;RsFx0200 Driver;c:\windows\system32\DRIVERS\RsFx0200.sys;c:\windows\SYSNATIVE\DRIVERS\RsFx0200.sys [x]
R4 SQLAgent$HUY;SQL Server Agent (HUY);e:\huy\SQL\Source\MSSQL11.HUY\MSSQL\Binn\SQLAGENT.EXE;e:\huy\SQL\Source\MSSQL11.HUY\MSSQL\Binn\SQLAGENT.EXE [x]
R4 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
R4 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
R4 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x]
S0 amdkmpfd;AMD PCI Root Bus Lower Filter;c:\windows\system32\DRIVERS\amdkmpfd.sys;c:\windows\SYSNATIVE\DRIVERS\amdkmpfd.sys [x]
S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S2 BkavHomeUpdateService;BkavHomeUpdateService;c:\program files (x86)\BkavHome\BkavHomeUpdateService.exe;c:\program files (x86)\BkavHome\BkavHomeUpdateService.exe [x]
S2 BkavService;BkavService;c:\windows\system32\BkavService.exe;c:\windows\SYSNATIVE\BkavService.exe [x]
S2 MSSQL$HUY;SQL Server (HUY);e:\huy\SQL\Source\MSSQL11.HUY\MSSQL\Binn\sqlservr.exe;e:\huy\SQL\Source\MSSQL11.HUY\MSSQL\Binn\sqlservr.exe [x]
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x]
S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys;c:\windows\SYSNATIVE\DRIVERS\igdpmd64.sys [x]
S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 NdisrdMP;NdisrdMP;c:\windows\system32\DRIVERS\ndisrd.sys;c:\windows\SYSNATIVE\DRIVERS\ndisrd.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-03-20 09:19 1061704 ----a-w- c:\program files (x86)\Google\Chrome\Application\41.0.2272.101\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2015-03-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-09 10:48]
.
2015-03-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-02-14 02:13]
.
2015-03-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-02-14 02:13]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2015-02-19 07:24 774472 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2015-02-19 07:24 774472 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2015-02-19 07:24 774472 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2015-02-19 07:24 774472 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2015-02-19 07:24 774472 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-03-19 439064]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-03-19 170264]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-03-19 398616]
.
------- Supplementary Scan -------
.
uStart Page = 00
mDefault_Search_URL = 00
mDefault_Page_URL = 00
mStart Page = 00
mSearch Page = 00
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{D0ED8A5C-3945-4A08-9E15-4394A60F2552}: NameServer = 208.67.222.222,208.67.220.220
TCP: Interfaces\{D0ED8A5C-3945-4A08-9E15-4394A60F2552}\155716E67602849656E6: NameServer = 208.67.222.222,208.67.220.220
TCP: Interfaces\{D0ED8A5C-3945-4A08-9E15-4394A60F2552}\175716E676869656E613: NameServer = 208.67.222.222,208.67.220.220
Handler: bksa - {AFBCA127-FD48-4FF5-B523-0E0DB4B8C295} - c:\program files (x86)\BkavHome\SiteAdvisor\BkavIESiteAdvisor.dll
.
- - - - ORPHANS REMOVED - - - -
.
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
AddRemove-Eusing Free Registry Cleaner - e:\huy\Ze\EUSING~1\UNWISE.EXE
AddRemove-Guitar Pro 5_is1 - d:\duy\UNG DUNG\Guitar Pro 5\unins000.exe
AddRemove-Mozilla Firefox 25.0 (x86 en-US) - c:\program files (x86)\Mozilla Firefox\uninstall\helper.exe
AddRemove-Teenage Mutant Ninja Turtles: Out of the Shadows_is1 - d:\games\Teenage_Mutant_Ninja_Turtles_Out_of_the_Shadows-FLT\TMNT-OotS\unins000.exe
AddRemove-The Witcher 2 - Assassins of Kings Enhanced Edition_is1 - d:\games\New folder\The Witcher 2 Enhanced Edition\unins000.exe
AddRemove-VirtuallTek Fighter Factory Classic_is1 - e:\huy\Mugen\FF\Fighter Factory Classic\unins000.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SysWOW64\BkavService.exe
d:\games\LienMinhHuyenThoai\GameData\ggdllhost.exe
.
**************************************************************************
.
Completion time: 2015-03-26 15:11:16 - machine was rebooted
ComboFix-quarantined-files.txt 2015-03-26 08:11
ComboFix2.txt 2015-03-23 13:34
.
Pre-Run: 12.348.334.080 bytes free
Post-Run: 13.574.279.168 bytes free
.
- - End Of File - - 0171D9D32E743BC4054E84FD4871FAB2
A36C5E4F47E84449FF07ED3517B43A31
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
FILE ::
"c:\windows\system32\drivers\wqjbnkgz.sys"
"c:\windows\System32\hale.exe"
"c:\windows\SysWow64\tasks.dll"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
c:\programdata\ntuser.pol
c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\Fonts\Vn.Fon
c:\windows\system32\drivers\wqjbnkgz.sys
c:\windows\System32\hale.exe
c:\windows\SysWow64\drivers\BkavAuto.sys
c:\windows\SysWow64\drivers\SysLib.sys
c:\windows\SysWow64\tasks.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_WQJBNKGZ
-------\Service_BkavAuto
-------\Service_SysLib
.
.
((((((((((((((((((((((((( Files Created from 2015-02-26 to 2015-03-26 )))))))))))))))))))))))))))))))
.
.
2015-03-26 07:59 . 2015-03-26 07:59 -------- d-----w- c:\users\MSSQL$HUY\AppData\Local\temp
2015-03-26 07:59 . 2015-03-26 07:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-03-23 14:16 . 2015-03-23 14:16 -------- d-s---w- c:\windows\SysWow64\Microsoft
2015-03-22 05:44 . 2015-03-22 06:25 -------- d-----w- c:\users\admin\AppData\Roaming\Dropbox
2015-03-22 05:24 . 2015-03-22 05:37 -------- d-----w- c:\windows\SysWow64\vbox
2015-03-22 05:24 . 2015-03-22 05:37 -------- d-----w- c:\windows\system32\vbox
2015-03-22 05:16 . 2015-03-23 14:42 -------- d-----w- c:\programdata\AVAST Software
2015-03-20 14:52 . 2015-03-23 14:21 -------- d-----w- c:\users\admin\AppData\Roaming\BitTorrent
2015-03-20 03:36 . 2015-03-20 03:38 -------- d-----w- C:\AdwCleaner
2015-03-20 02:54 . 2015-03-20 02:54 -------- d-----w- c:\programdata\Malwarebytes
2015-03-20 02:41 . 2015-03-20 02:41 35064 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2015-03-20 02:41 . 2015-03-20 02:57 -------- d-----w- c:\programdata\RogueKiller
2015-03-20 02:20 . 2015-03-20 02:20 0 ----a-w- c:\windows\SysWow64\link.sys
2015-03-20 02:11 . 2015-03-20 02:11 -------- d-----w- c:\users\admin\AppData\Roaming\Bkav2009
2015-03-20 02:08 . 2015-03-23 13:34 -------- d-----w- c:\users\Temp
2015-03-19 03:33 . 2015-03-19 03:35 -------- d-----w- C:\FRST
2015-03-16 10:01 . 2015-03-16 10:01 -------- d-----w- c:\program files (x86)\Realtek
2015-03-16 10:01 . 2010-05-07 02:42 245280 ----a-w- c:\windows\system32\drivers\RtsUStor.sys
2015-03-16 10:01 . 2015-03-16 10:01 -------- d-----w- C:\DRIVERS
2015-03-13 12:07 . 2014-11-14 14:15 23752 ----a-w- c:\windows\SysWow64\drivers\efimon.sys
2015-03-13 12:05 . 2015-03-13 12:05 -------- d-sh--w- c:\programdata\360Quarant
2015-03-12 11:00 . 2015-03-14 14:11 -------- d-----w- c:\programdata\PopCap Games
2015-03-12 10:56 . 2015-03-14 14:10 -------- d-----w- c:\program files (x86)\Opera
2015-03-12 10:56 . 2015-03-13 15:51 -------- d-----w- c:\program files (x86)\360
2015-03-12 02:42 . 2015-03-12 02:42 -------- d-----w- c:\users\admin\AppData\Roaming\JAM Software
2015-03-08 11:16 . 2015-03-08 11:16 -------- d-----w- c:\users\admin\AppData\Roaming\Tencent
2015-03-06 03:17 . 2015-03-06 03:17 -------- d-----w- c:\programdata\Microsoft Visual Studio
2015-03-06 02:41 . 2015-03-06 02:41 2562208 ----a-w- c:\programdata\Microsoft\VisualStudio\11.0\1033\ResourceCache.dll
2015-03-06 02:36 . 2015-03-06 02:36 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2015-03-06 02:34 . 2015-03-06 02:34 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2015-03-06 02:34 . 2015-03-06 02:34 -------- d-----w- c:\program files\Application Verifier
2015-03-06 02:34 . 2015-03-06 02:34 -------- d-----w- c:\program files (x86)\Application Verifier
2015-03-06 02:34 . 2015-03-06 02:34 -------- d-----w- c:\programdata\Windows App Certification Kit
2015-03-06 02:33 . 2015-03-06 02:33 -------- d-----w- c:\program files (x86)\Common Files\Microsoft
2015-03-06 02:32 . 2015-03-06 02:32 -------- d-----w- c:\programdata\PreEmptive Solutions
2015-03-06 02:30 . 2015-03-06 02:31 -------- d-----w- c:\program files (x86)\Microsoft ASP.NET
2015-03-06 02:30 . 2015-03-06 02:30 -------- d-----w- c:\program files (x86)\Microsoft Web Tools
2015-03-06 02:30 . 2015-03-06 02:30 -------- d-----w- c:\program files\Microsoft
2015-03-06 02:29 . 2015-03-06 02:29 -------- d-----w- c:\program files\IIS Express
2015-03-06 02:29 . 2015-03-06 02:29 -------- d-----w- c:\program files (x86)\IIS Express
2015-03-06 02:29 . 2015-03-06 02:29 -------- d-----w- c:\program files (x86)\NuGet
2015-03-06 02:28 . 2015-03-06 02:28 -------- d-----w- c:\program files (x86)\Microsoft WCF Data Services
2015-03-06 02:28 . 2015-03-06 02:28 -------- d-----w- c:\program files\IIS
2015-03-06 02:28 . 2015-03-06 02:28 -------- d-----w- c:\program files (x86)\IIS
2015-03-06 02:26 . 2015-03-06 02:26 -------- d-----w- c:\program files (x86)\Windows Kits
2015-03-06 02:20 . 2015-03-06 02:20 -------- d-----w- c:\program files (x86)\HTML Help Workshop
2015-03-06 02:20 . 2015-03-06 02:20 -------- d-----w- c:\program files (x86)\Microsoft Help Viewer
2015-03-06 02:12 . 2015-03-06 02:12 -------- d-----w- c:\windows\symbols
2015-03-06 02:12 . 2015-03-06 02:12 -------- d-----w- c:\program files\Microsoft Visual Studio 11.0
2015-03-06 02:08 . 2015-03-06 02:08 -------- d-----w- c:\programdata\regid.1991-06.com.microsoft
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-03-06 02:37 . 2014-10-08 02:26 84448 ----a-w- c:\programdata\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll
2015-02-15 15:40 . 2015-02-06 15:42 239104 ----a-w- c:\windows\mlwps.exe
2015-02-02 12:15 . 2009-08-18 05:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2015-02-02 12:13 . 2009-08-18 04:24 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-21 . 1151B1BAA6F350B1DB6598E0FEA7C457 . 390656 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[-] 2012-11-07 . 87A00ED70FEC36D0DD968E5058C29AA1 . 389632 . . [6.1.7601.17514] .. c:\windows\system32\winlogon.exe
.
[7] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[-] 2012-11-07 . D186BABDFAE7C0D93C9F6AE63957EE96 . 1008128 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UniKey"="c:\unikey 4.0 rc2 win64\UniKeyNT.exe" [2009-11-01 316928]
"Messenger (Yahoo!)"="c:\progra~2\Yahoo!\MESSEN~1\YahooMessenger.exe" [2012-05-24 6595928]
"GarenaPlus"="d:\games\LienMinhHuyenThoai\GameData\GarenaMessenger.exe" [2015-01-20 9981528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"YouCam Service"="d:\duy\UNG DUNG\YouCam 5 v5.0.0909 PreActivated_da fix watermark\YouCam\YouCamService.exe" [2011-09-09 247016]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-10-16 291648]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-03-04 343168]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"BkavHome"="c:\program files (x86)\BkavHome\BkavHome.exe" [2015-01-14 2435584]
.
c:\users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE /tsr [2010-3-29 227712]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Canon LBP3000 Status Window.lnk - c:\windows\System32\spool\drivers\x64\3\CNAB3LAD.EXE [2014-11-30 60384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R1 BAPIDRV;BAPIDRV;c:\windows\system32\DRIVERS\BAPIDRV64.sys;c:\windows\SYSNATIVE\DRIVERS\BAPIDRV64.sys [x]
R1 SysLib0;SysLib0;c:\windows\System32\Drivers\SysLib0.sys;c:\windows\SYSNATIVE\Drivers\SysLib0.sys [x]
R1 SysLib1;SysLib1;c:\windows\System32\Drivers\SysLib1.sys;c:\windows\SYSNATIVE\Drivers\SysLib1.sys [x]
R1 SysLib2;SysLib2;c:\windows\System32\Drivers\SysLib2.sys;c:\windows\SYSNATIVE\Drivers\SysLib2.sys [x]
R1 SysLib3;SysLib3;c:\windows\System32\Drivers\SysLib3.sys;c:\windows\SYSNATIVE\Drivers\SysLib3.sys [x]
R1 SysLib4;SysLib4;c:\windows\System32\Drivers\SysLib4.sys;c:\windows\SYSNATIVE\Drivers\SysLib4.sys [x]
R1 SysLib5;SysLib5;c:\windows\System32\Drivers\SysLib5.sys;c:\windows\SYSNATIVE\Drivers\SysLib5.sys [x]
R1 SysLib6;SysLib6;c:\windows\System32\Drivers\SysLib6.sys;c:\windows\SYSNATIVE\Drivers\SysLib6.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service; [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x]
R3 cxasbt;cxasbt;d:\duy\GAMES\AvatarStarVN\avital\cxbtf64.sys;d:\duy\GAMES\AvatarStarVN\avital\cxbtf64.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 GGSAFERDriver;GGSAFER Driver;d:\games\LienMinhHuyenThoai\GameData\Room\safedrv.sys;d:\games\LienMinhHuyenThoai\GameData\Room\safedrv.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 Ndisrd;WinpkFilter Service;c:\windows\system32\DRIVERS\ndisrd.sys;c:\windows\SYSNATIVE\DRIVERS\ndisrd.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x]
R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe;c:\program files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VBoxUSB;VirtualBox USB;c:\windows\system32\Drivers\VBoxUSB.sys;c:\windows\SYSNATIVE\Drivers\VBoxUSB.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
R4 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x]
R4 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x]
R4 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
R4 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
R4 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R4 RsFx0200;RsFx0200 Driver;c:\windows\system32\DRIVERS\RsFx0200.sys;c:\windows\SYSNATIVE\DRIVERS\RsFx0200.sys [x]
R4 SQLAgent$HUY;SQL Server Agent (HUY);e:\huy\SQL\Source\MSSQL11.HUY\MSSQL\Binn\SQLAGENT.EXE;e:\huy\SQL\Source\MSSQL11.HUY\MSSQL\Binn\SQLAGENT.EXE [x]
R4 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
R4 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
R4 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x]
S0 amdkmpfd;AMD PCI Root Bus Lower Filter;c:\windows\system32\DRIVERS\amdkmpfd.sys;c:\windows\SYSNATIVE\DRIVERS\amdkmpfd.sys [x]
S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S2 BkavHomeUpdateService;BkavHomeUpdateService;c:\program files (x86)\BkavHome\BkavHomeUpdateService.exe;c:\program files (x86)\BkavHome\BkavHomeUpdateService.exe [x]
S2 BkavService;BkavService;c:\windows\system32\BkavService.exe;c:\windows\SYSNATIVE\BkavService.exe [x]
S2 MSSQL$HUY;SQL Server (HUY);e:\huy\SQL\Source\MSSQL11.HUY\MSSQL\Binn\sqlservr.exe;e:\huy\SQL\Source\MSSQL11.HUY\MSSQL\Binn\sqlservr.exe [x]
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x]
S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys;c:\windows\SYSNATIVE\DRIVERS\igdpmd64.sys [x]
S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 NdisrdMP;NdisrdMP;c:\windows\system32\DRIVERS\ndisrd.sys;c:\windows\SYSNATIVE\DRIVERS\ndisrd.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-03-20 09:19 1061704 ----a-w- c:\program files (x86)\Google\Chrome\Application\41.0.2272.101\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2015-03-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-09 10:48]
.
2015-03-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-02-14 02:13]
.
2015-03-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-02-14 02:13]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2015-02-19 07:24 774472 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2015-02-19 07:24 774472 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2015-02-19 07:24 774472 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2015-02-19 07:24 774472 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2015-02-19 07:24 774472 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-03-19 439064]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-03-19 170264]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-03-19 398616]
.
------- Supplementary Scan -------
.
uStart Page = 00
mDefault_Search_URL = 00
mDefault_Page_URL = 00
mStart Page = 00
mSearch Page = 00
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{D0ED8A5C-3945-4A08-9E15-4394A60F2552}: NameServer = 208.67.222.222,208.67.220.220
TCP: Interfaces\{D0ED8A5C-3945-4A08-9E15-4394A60F2552}\155716E67602849656E6: NameServer = 208.67.222.222,208.67.220.220
TCP: Interfaces\{D0ED8A5C-3945-4A08-9E15-4394A60F2552}\175716E676869656E613: NameServer = 208.67.222.222,208.67.220.220
Handler: bksa - {AFBCA127-FD48-4FF5-B523-0E0DB4B8C295} - c:\program files (x86)\BkavHome\SiteAdvisor\BkavIESiteAdvisor.dll
.
- - - - ORPHANS REMOVED - - - -
.
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
AddRemove-Eusing Free Registry Cleaner - e:\huy\Ze\EUSING~1\UNWISE.EXE
AddRemove-Guitar Pro 5_is1 - d:\duy\UNG DUNG\Guitar Pro 5\unins000.exe
AddRemove-Mozilla Firefox 25.0 (x86 en-US) - c:\program files (x86)\Mozilla Firefox\uninstall\helper.exe
AddRemove-Teenage Mutant Ninja Turtles: Out of the Shadows_is1 - d:\games\Teenage_Mutant_Ninja_Turtles_Out_of_the_Shadows-FLT\TMNT-OotS\unins000.exe
AddRemove-The Witcher 2 - Assassins of Kings Enhanced Edition_is1 - d:\games\New folder\The Witcher 2 Enhanced Edition\unins000.exe
AddRemove-VirtuallTek Fighter Factory Classic_is1 - e:\huy\Mugen\FF\Fighter Factory Classic\unins000.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SysWOW64\BkavService.exe
d:\games\LienMinhHuyenThoai\GameData\ggdllhost.exe
.
**************************************************************************
.
Completion time: 2015-03-26 15:11:16 - machine was rebooted
ComboFix-quarantined-files.txt 2015-03-26 08:11
ComboFix2.txt 2015-03-23 13:34
.
Pre-Run: 12.348.334.080 bytes free
Post-Run: 13.574.279.168 bytes free
.
- - End Of File - - 0171D9D32E743BC4054E84FD4871FAB2
A36C5E4F47E84449FF07ED3517B43A31