ComboFix 17-09-14.01 - Administrator 09/27/2017 2:41.1.2 - x86
Running from: c:\documents and settings\Administrator.JWH\Desktop\ComboFix.exe
* Created a new restore point
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Ahmbed.gz
c:\documents and settings\Administrator.JACK-9B5A923336\WINDOWS
c:\documents and settings\Administrator.JWH\System
c:\documents and settings\Administrator.JWH\System\win_qs8.jqx
c:\documents and settings\All Users.WINDOWS.1\Application Data\1414704854.bdinstall.bin
c:\documents and settings\All Users.WINDOWS.1\Application Data\1414705052.2752.bin
c:\documents and settings\All Users.WINDOWS.1\Application Data\1414705052.3120.bin
c:\documents and settings\All Users.WINDOWS.1\Application Data\1414705052.3348.bin
c:\documents and settings\All Users.WINDOWS.1\Application Data\1414705523.bdinstall.bin
c:\documents and settings\All Users.WINDOWS.1\Application Data\1472400068.bdinstall.bin
c:\documents and settings\All Users.WINDOWS.1\Application Data\1472400077.bdinstall.bin
c:\documents and settings\All Users.WINDOWS.1\Application Data\1472400471.bdinstall.bin
c:\documents and settings\All Users.WINDOWS.1\Application Data\1474407212.bdinstall.bin
c:\documents and settings\All Users.WINDOWS.1\Application Data\F3627895AB.sys
c:\documents and settings\All Users.WINDOWS.1\Application Data\TEMP
c:\documents and settings\All Users.WINDOWS.1\Application Data\TEMP\RAIDTest
c:\documents and settings\Jack Holland.JACK\g2mdlhlpx.exe
c:\documents and settings\Jack Holland.JACK\gzip.exe
c:\documents and settings\Jack Holland.JACK\WINDOWS
c:\program files\Common Files\uninstall information
c:\program files\Conference
c:\program files\Conference\Conference.db
c:\program files\Conference\Conference.dll
c:\program files\Conference\Conference.exe
c:\program files\Conference\Conference.hst
c:\program files\Conference\Conference.ini
c:\program files\Conference\Languages\de.xml
c:\program files\Conference\Languages\en.xml
c:\program files\Conference\Languages\es.xml
c:\program files\Conference\Languages\fr.xml
c:\program files\Conference\Languages\pt.xml
c:\program files\Conference\Languages\ru.xml
c:\program files\GOOGLE~1.exe
c:\program files\Power Search Tool
c:\program files\Power Search Tool\alert_plugin.dll
c:\program files\Power Search Tool\basis.xml
c:\program files\Power Search Tool\ebay.bmp
c:\program files\Power Search Tool\icons.bmp
c:\program files\Power Search Tool\logo-4.bmp
c:\program files\Power Search Tool\mbback.bmp
c:\program files\Power Search Tool\mbbigopen.bmp
c:\program files\Power Search Tool\mbclose.bmp
c:\program files\Power Search Tool\mbfwd.bmp
c:\program files\Power Search Tool\mbsep.bmp
c:\program files\Power Search Tool\nav1c.bmp
c:\program files\Power Search Tool\options.html
c:\program files\Power Search Tool\PowerSearchTool4_0.crc
c:\program files\Power Search Tool\version.txt
c:\program files\readme.txt
c:\program files\WinPCap
c:\program files\WinPCap\rpcapd.exe
c:\program files\WinPCap\Uninstall.exe
C:\Thumbs.db
C:\WgaLogon.dll
C:\WgaTray.exe
c:\windows.1\wc98pp.dll
D:\install.exe
D:\SETUP.EXE
G:\install.exe
.
.
((((((((((((((((((((((((( Files Created from 2017-08-27 to 2017-09-27 )))))))))))))))))))))))))))))))
.
.
2017-09-26 12:13 . 2017-02-19 19:15 220192 ----a-w- c:\windows.1\system32\drivers\keyscrambler.sys
2017-09-26 12:12 . 2017-09-26 12:13 -------- d-----w- c:\program files\KeyScrambler
2017-09-25 13:26 . 2017-09-25 13:28 -------- d-----w- C:\AdwCleaner
2017-09-25 12:21 . 2017-08-24 18:27 59904 ----a-w- c:\windows.1\system32\drivers\mbae.sys
2017-09-25 12:20 . 2017-09-25 12:20 -------- d-----w- c:\program files\Malwarebytes
2017-09-25 12:10 . 2017-09-25 12:10 -------- d-----w- c:\documents and settings\All Users.WINDOWS.1\Application Data\MB2Migration
2017-09-25 09:13 . 2017-09-25 09:13 24688 ----a-w- c:\windows.1\system32\drivers\TrueSight.sys
2017-09-25 09:13 . 2017-09-25 12:10 -------- d-----w- c:\documents and settings\All Users.WINDOWS.1\Application Data\RogueKiller
2017-09-25 09:12 . 2017-09-25 09:13 -------- d-----w- c:\program files\RogueKiller
2017-09-25 09:12 . 2017-09-25 09:12 -------- d-----w- C:\Documents
2017-09-22 15:47 . 2017-09-24 06:34 -------- d-----w- C:\FRST
2017-09-22 14:35 . 2017-09-22 14:35 -------- d-----w- c:\documents and settings\Administrator.JWH\Local Settings\Application Data\ESET
2017-09-21 03:51 . 2017-09-21 03:51 -------- d-----w- c:\documents and settings\Administrator.JWH\Application Data\EurekaLog
2017-09-21 02:33 . 1998-06-24 07:00 198456 ----a-w- c:\windows.1\system32\Mci32.ocx
2017-09-21 02:33 . 1998-05-22 07:00 137736 ----a-w- c:\windows.1\system32\COMDLG32.OCX
2017-09-21 00:38 . 2017-09-21 00:38 -------- d-----w- c:\documents and settings\All Users.WINDOWS.1\Application Data\{74E9F814-C737-42CC-B721-DBBC4059367A}
2017-09-13 08:33 . 2017-09-13 09:33 5680640 ----a-w- c:\windows.1\system32\FlashPlayerInstaller.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-09-13 09:33 . 2014-05-06 21:16 803328 ----a-w- c:\windows.1\system32\FlashPlayerApp.exe
2017-09-13 09:33 . 2014-05-06 21:16 144896 ----a-w- c:\windows.1\system32\FlashPlayerCPLApp.cpl
2017-08-04 01:44 . 2014-05-26 23:45 1004 --sha-w- c:\documents and settings\All Users.WINDOWS.1\Application Data\KGyGaAvL.sys
2015-10-29 22:56 . 2015-10-29 22:56 448512 ----a-w- c:\program files\TFC.exe
2010-09-06 04:52 . 2010-11-08 12:15 2669056 ----a-w- c:\program files\VirtualDub.exe
2010-09-06 04:52 . 2010-11-08 12:15 69632 ----a-w- c:\program files\auxsetup.exe
2010-09-06 04:52 . 2010-11-08 12:15 8704 ----a-w- c:\program files\vdub.exe
2010-09-06 04:52 . 2010-11-08 12:15 73728 ----a-w- c:\program files\vdremote.dll
2010-09-06 04:52 . 2010-11-08 12:15 69632 ----a-w- c:\program files\vdicmdrv.dll
2010-09-06 04:51 . 2010-11-08 12:15 65536 ----a-w- c:\program files\vdsvrlnk.dll
2006-10-09 11:38 . 2006-10-09 11:36 11289224 ----a-w- c:\program files\widgetsus.exe
2005-07-15 18:22 . 2010-11-08 12:42 2728537 ----a-w- c:\program files\wax20e.exe
2004-11-09 00:12 . 2004-12-14 01:01 77893 -c--a-w- c:\program files\QCUtils.dll
2004-11-09 00:12 . 2004-12-14 01:01 499777 -c--a-w- c:\program files\QCSSL.dll
2004-11-09 00:12 . 2004-12-14 01:01 65607 -c--a-w- c:\program files\QCSocket.dll
2004-11-09 00:12 . 2004-12-14 01:01 110658 -c--a-w- c:\program files\Imap.dll
2004-11-09 00:12 . 2004-12-14 01:01 24647 -c--a-w- c:\program files\EuMemMgr.dll
2004-11-09 00:12 . 2004-12-14 01:01 2035781 -c--a-w- c:\program files\Eudora32.dll
2004-11-09 00:12 . 2004-12-14 01:01 2728003 -c--a-w- c:\program files\Eudora.exe
2004-10-26 00:08 . 2004-12-14 01:01 307276 -c--a-w- c:\program files\Paige32.dll
2004-09-20 18:10 . 2004-12-14 01:01 180299 -c--a-w- c:\program files\OLImport.eif
2004-09-20 18:10 . 2004-12-14 01:01 168011 -c--a-w- c:\program files\NSImport.eif
2004-09-20 18:10 . 2004-12-14 01:01 155723 -c--a-w- c:\program files\OEImport.eif
2004-08-27 18:10 . 2004-12-14 01:01 180298 -c--a-w- c:\program files\swEudora.exe
2004-08-27 18:10 . 2004-12-14 01:01 112128 -c--a-w- c:\program files\SPELL32.DLL
2004-08-27 18:10 . 2004-12-14 01:01 61497 -c--a-w- c:\program files\Ph.dll
2004-08-27 18:10 . 2004-12-14 01:01 65597 -c--a-w- c:\program files\Ldap.dll
2004-08-27 18:10 . 2004-12-14 01:01 32831 -c--a-w- c:\program files\ISock.dll
2004-08-27 18:10 . 2004-12-14 01:01 138752 -c--a-w- c:\program files\LDAP32.DLL
2004-08-27 18:10 . 2004-12-14 01:01 36933 -c--a-w- c:\program files\EudoraBk.dll
2004-08-27 18:10 . 2004-12-14 01:01 49213 -c--a-w- c:\program files\EuGraph.ocx
2004-08-27 18:10 . 2004-12-14 01:01 147537 -c--a-w- c:\program files\EuMAPI32.dll
2004-08-27 18:10 . 2004-12-14 01:01 82944 -c--a-w- c:\program files\EUMAPI.DLL
2004-08-27 18:10 . 2004-12-14 01:01 49219 -c--a-w- c:\program files\DirServ.dll
2003-09-04 21:15 . 2008-02-06 10:25 1724416 ----a-w- c:\program files\Antanta.exe
1999-06-25 17:55 . 2006-02-06 13:15 149504 ----a-w- c:\program files\UNWISE.EXE
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveBlacklisted]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2017-08-31 20:21 576408 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveSynced]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2017-08-31 20:21 576408 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveSyncing]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2017-08-31 20:21 576408 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"f.lux"="c:\documents and settings\Administrator.JWH\Local Settings\Application Data\FluxSoftware\Flux\flux.exe" [2017-09-10 1663480]
"Windscribe"="c:\program files\Windscribe\Windscribe.exe" [2017-05-09 10601064]
"Advanced SystemCare 10"="c:\program files\IObit\Advanced SystemCare\ASCTray.exe" [2017-05-17 3924256]
"World of Tanks (1)"="g:\games\World_of_Tanks\WargamingGameUpdater.exe" [2017-02-28 3135752]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\windows.1\system32\NvMcTray.dll" [2010-10-16 110696]
"NvCplDaemon"="c:\windows.1\system32\NvCpl.dll" [2010-10-16 13851752]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2015-08-04 597552]
"EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2009-12-18 976832]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-03-16 868352]
"RTHDCPL"="RTHDCPL.EXE" [2010-02-26 18791456]
"SkyTel"="SkyTel.EXE" [2010-02-26 1833504]
"KeyScrambler"="c:\program files\KeyScrambler\keyscrambler.exe" [2017-04-23 515600]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSimpleNetIDList"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SmartDefragBootTime.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator.JWH^Start Menu^Programs^Startup^EvernoteClipper.lnk]
backup=c:\windows.1\pss\EvernoteClipper.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 8
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KeyScrambler
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Act! Preloader]
2008-08-01 04:05 393216 ----a-w- c:\program files\ACT\ACT for Windows\ActSage.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Act.Outlook.Service]
2008-08-01 04:04 28672 ----a-w- c:\program files\ACT\ACT for Windows\Act.Outlook.Service.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2014-12-19 16:48 1022152 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 14:58 611712 ----a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AmazonGSDownloaderTray]
2009-10-23 20:31 326144 ----a-w- c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2013-04-22 04:43 59720 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 12:42 15360 ----a-w- c:\windows.1\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Epic Privacy Browser Installer]
2016-08-08 11:58 509096 ----atw- c:\documents and settings\Administrator.JWH\Local Settings\Application Data\Epic Privacy Browser\Installer\EpicUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FAHConsole]
2014-01-28 18:16 616632 ----a-w- c:\program files\File Association Helper\FAHConsole.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2007-01-13 16:47 163840 ----a-w- c:\windows.1\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2007-01-13 16:47 131072 ----a-w- c:\windows.1\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 12:42 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2007-01-13 16:46 135168 ----a-w- c:\windows.1\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Philips Device Listener]
2012-03-19 10:23 380416 ----a-w- c:\program files\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2010-02-26 01:01 84512 ----a-w- c:\windows.1\SOUNDMAN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
2007-04-04 03:55 839680 ----a-w- c:\program files\Analog Devices\SoundMAX\SMax4.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2007-03-16 15:06 868352 ----a-w- c:\program files\Analog Devices\Core\smax4pnp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2015-08-04 19:47 597552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\ACT\\ACT for Windows\\ActSage.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Epson Software\\Event Manager\\EEventManager.exe"=
"c:\\Documents and Settings\\Administrator.JWH\\Local Settings\\Application Data\\Epic Privacy Browser\\Application\\epic.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\Program Files\\Java\\jre1.8.0_60\\bin\\javaw.exe"=
"c:\\WINDOWS.1\\system32\\fxsclnt.exe"=
"c:\\WINDOWS.1\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Participatory Culture Foundation\\Miro\\Miro_Downloader.exe"=
"c:\\WINDOWS.1\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Daum\\PotPlayer\\PotPlayerMini.exe"=
"c:\\WINDOWS.1\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Documents and Settings\\Administrator.JWH\\Application Data\\Spotify\\Spotify.exe"=
"c:\\Program Files\\HTC\\HTC Sync Manager\\HTCSyncManager.exe"=
"c:\\Program Files\\IObit\\IObit Malware Fighter\\Surfing Protection\\FFNativeMessage.exe"=
"g:\\Games\\World_of_Tanks\\WoTLauncher.exe"=
"g:\\Games\\World_of_Tanks\\WorldOfTanks.exe"=
"c:\\Program Files\\IObit\\Advanced SystemCare\\Surfing Protection\\FFNativeMessage.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*

isabled:Windows Remote Management
"5353:TCP"= 5353:TCP:*

isabled:Adobe CSI CS4
"20010:UDP"= 20010:UDP:*

isabled:War Thunder
"3478:UDP"= 3478:UDP:*

isabled:War Thunder
"7850:TCP"= 7850:TCP:*

isabled:War Thunder
"7852:TCP"= 7852:TCP:*

isabled:War Thunder
"7853:TCP"= 7853:TCP:*

isabled:War Thunder
"27022:TCP"= 27022:TCP:*

isabled:War Thunder
"6881:TCP"= 6881:TCP:*

isabled:War Thunder
"33333:TCP"= 33333:TCP:*

isabled:War Thunder
"20443:TCP"= 20443:TCP:*

isabled:War Thunder
"8090:TCP"= 8090:TCP:*

isabled:War Thunder
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 0 (0x0)
.
R2 IObitUnSvr;IObit Uninstaller Service;c:\program files\IObit\IObit Uninstaller\IUService.exe [2016-10-28 360736]
R2 MBAMService;Malwarebytes Service;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe [2017-08-07 4430792]
R3 ACT! Scheduler;ACT! Scheduler;c:\program files\ACT\Act for Windows\Act.Scheduler.exe [2008-08-01 81920]
R3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows.1\system32\DRIVERS\ADM8511.SYS [2001-08-17 20160]
R3 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [2009-10-23 401920]
R3 Ambfilt;Ambfilt;c:\windows.1\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
R3 cpuz138;cpuz138; [x]
R3 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service;c:\program files\Hp\Common\HPSupportSolutionsFrameworkService.exe [2014-12-11 89864]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows.1\system32\DRIVERS\htcnprot.sys [2013-10-17 21248]
R3 IntuitUpdateServiceV4;Intuit Update Service v4;c:\program files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [2015-04-27 14624]
R3 MSICDSetup;MSICDSetup;E:\CDriver.sys [x]
R3 qcserxp;HTC Diagnostic Port;c:\windows.1\system32\DRIVERS\qcserxp.sys [2009-01-24 103424]
R3 QFXUpdateService;QFX Software Update Service;c:\program files\KeyScrambler\QFXUpdateService.exe [2017-04-23 75792]
R3 RegFilter;RegFilter;c:\program files\IObit\IObit Malware Fighter\drivers\wxp_x86\regfilter.sys [2017-01-07 31680]
R3 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2014-12-11 315496]
R3 WinRing0_1_2_0;WinRing0_1_2_0; [x]
R4 IMFFilter;IMFFilter;c:\program files\IObit\IObit Malware Fighter\Drivers\wxp_x86\IMFFilter.sys [2017-01-07 247872]
S0 avc3;avc3;c:\windows.1\system32\DRIVERS\avc3.sys [2013-04-17 633344]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows.1\System32\Drivers\SmartDefragDriver.sys [2016-03-22 15824]
S1 ElRawDisk;ElRawDisk;c:\windows.1\system32\drivers\rsdrv.sys [2009-02-12 22312]
S1 gzflt;gzflt;c:\windows.1\system32\DRIVERS\gzflt.sys [2016-09-25 164952]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows.1\system32\drivers\HWiNFO32.SYS [2015-01-09 23840]
S1 IMFCameraProtect;IMFCameraProtect;c:\windows.1\system32\drivers\IMFCameraProtect.sys [2017-03-17 25120]
S2 AdvancedSystemCareService10;Advanced SystemCare Service 10;c:\program files\IObit\Advanced SystemCare\ASCService.exe [2017-03-21 462624]
S2 gzserv;Bitdefender Antivirus Free Edition;c:\program files\Bitdefender\Antivirus Free Edition\gzserv.exe [2016-03-02 67592]
S2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [2017-07-19 1768736]
S2 MSSQL$ACT7;SQL Server (ACT7);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-11 29293408]
S2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [2013-10-17 166912]
S2 WindscribeService;WindscribeService;c:\program files\Windscribe\WindscribeService.exe [2017-05-09 71272]
S3 avchv;avchv Function Driver;c:\windows.1\system32\DRIVERS\avchv.sys [2012-11-02 242504]
S3 avckf;avckf;c:\windows.1\system32\DRIVERS\avckf.sys [2013-04-17 486536]
S3 IMFDownProtect;IMFDownProtect;c:\program files\IObit\IObit Malware Fighter\drivers\win7_x86\IMFDownProtect.sys [2017-03-08 20336]
S3 IMFForceDelete;IMFForceDelete;c:\program files\IObit\IObit Malware Fighter\drivers\win7_x86\IMFForceDelete.sys [2017-06-30 14168]
S3 KeyScrambler;KeyScrambler;c:\windows.1\system32\drivers\keyscrambler.sys [2017-02-19 220192]
S3 tapwindscribe0901;Windscribe VPN;c:\windows.1\system32\DRIVERS\tapwindscribe0901.sys [2017-04-21 30936]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2016-07-07 01:48 1106072 ----a-w- c:\program files\Google\Chrome\Application\49.0.2623.112\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2017-09-13 c:\windows.1\Tasks\Adobe Flash Player PPAPI Notifier.job
- c:\windows.1\system32\Macromed\Flash\FlashUtil32_27_0_0_130_pepper.exe [2017-09-13 09:33]
.
2017-09-21 c:\windows.1\Tasks\Adobe Flash Player Updater.job
- c:\windows.1\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-06 09:33]
.
2017-09-21 c:\windows.1\Tasks\DivXUpdate.job
- c:\program files\Common Files\DivX Shared\DivX Update\DivXUpdate.exe [2017-02-03 05:30]
.
2017-09-21 c:\windows.1\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 09:46]
.
2017-09-21 c:\windows.1\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 09:46]
.
2017-03-08 c:\windows.1\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
- c:\windows.1\system32\xp_eos.exe [2014-05-04 01:59]
.
2017-09-20 c:\windows.1\Tasks\Opera scheduled Autoupdate 1382443258.job
- c:\program files\Opera\launcher.exe [2013-10-22 12:29]
.
2017-09-21 c:\windows.1\Tasks\SmartDefrag_AutoAnalyze.job
- c:\program files\IObit\Smart Defrag\AutoDefrag.exe [2016-05-24 22:15]
.
2017-09-20 c:\windows.1\Tasks\SmartDefrag_Update.job
- c:\program files\IObit\Smart Defrag\AutoUpdate.exe [2017-09-14 16:59]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = about:blank
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Clip Image - c:\program files\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=4
IE: Clip selection - c:\program files\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=3
IE: Clip this page - c:\program files\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=1
IE: Clip URL - c:\program files\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: New Note - c:\program files\Evernote\Evernote\\EvernoteIERes\NewNote.html
TCP: DhcpNameServer = 192.168.1.254
.
.
------- File Associations -------
.
inifile="%SystemRoot%\system32\NOTEPAD.EXE" %1
txtfile="%SystemRoot%\system32\NOTEPAD.EXE" %1
.
- - - - ORPHANS REMOVED - - - -
.
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
HKCU-Run-World of Tanks - f:\games\World_of_Tanks\WargamingGameUpdater.exe
SafeBoot-Wdf01000.sys
AddRemove-MediaMonkey_is1 - f:\program files\MediaMonkey\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2017-09-27 03:08
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-583907252-115176313-1801674531-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b6,a5,9a,a3,0b,9f,08,4b,bf,22,11,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b6,a5,9a,a3,0b,9f,08,4b,bf,22,11,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS.1\\system32\\Macromed\\Flash\\FlashUtil32_27_0_0_130_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\WINDOWS.1\\system32\\Macromed\\Flash\\FlashUtil32_27_0_0_130_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2017-09-27 03:14:13
ComboFix-quarantined-files.txt 2017-09-27 10:14
.
Pre-Run: 14,868,897,792 bytes free
Post-Run: 14,804,348,928 bytes free
.
- - End Of File - - D568CF2DAAB9509382398E29F55B4173
8F558EB6672622401DA993E1E865C861