Re: Pomalý PC
Napsal: 28 pro 2013 20:59
ComboFix 13-12-26.01 - Logic PC . 12. 2013 20:45:21.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.421.1051.18.4079.2657 [GMT 1:00]
Running from: c:\users\Logic PC\Desktop\ComboFix.exe
Command switches used :: c:\users\Logic PC\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 7.0 *Enabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
SP: ESET NOD32 Antivirus 7.0 *Enabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\$AVG-SHREDDER-TMP-4027486f-393b-4311-a5b1-b2767e606368
c:\program files (x86)\VLC Player GPU+
c:\program files (x86)\VLC Player GPU+\deinstaller.exe
c:\program files (x86)\VLC Player GPU+\diablo130302.cl
c:\program files (x86)\VLC Player GPU+\diakgcn121016.cl
c:\program files (x86)\VLC Player GPU+\GPUMonitor.exe
c:\program files (x86)\VLC Player GPU+\Installer.exe
c:\program files (x86)\VLC Player GPU+\libcurl.dll
c:\program files (x86)\VLC Player GPU+\libeay32.dll
c:\program files (x86)\VLC Player GPU+\libidn-11.dll
c:\program files (x86)\VLC Player GPU+\libpdcurses.dll
c:\program files (x86)\VLC Player GPU+\lua5.1.dll
c:\program files (x86)\VLC Player GPU+\OpenCL.dll
c:\program files (x86)\VLC Player GPU+\path.inf
c:\program files (x86)\VLC Player GPU+\phatk121016.cl
c:\program files (x86)\VLC Player GPU+\poclbm130302.cl
c:\program files (x86)\VLC Player GPU+\pthreadGC2.dll
c:\program files (x86)\VLC Player GPU+\README
c:\program files (x86)\VLC Player GPU+\scrypt130302.cl
c:\program files (x86)\VLC Player GPU+\ssleay32.dll
c:\program files (x86)\VLC Player GPU+\uninstall.exe
c:\program files (x86)\VLC Player GPU+\Uninstall\IRIMG1.JPG
c:\program files (x86)\VLC Player GPU+\Uninstall\IRIMG2.JPG
c:\program files (x86)\VLC Player GPU+\Uninstall\uninstall.dat
c:\program files (x86)\VLC Player GPU+\Uninstall\uninstall.xml
c:\program files (x86)\VLC Player GPU+\zlib1.dll
c:\programdata\AVG2014
c:\programdata\AVG2014\$AVG\$VAULT\vault.db
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_Skype C2C Service
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Files Created from 2013-11-28 to 2013-12-28 )))))))))))))))))))))))))))))))
.
.
2013-12-27 12:03 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5903F4CC-1D23-47DE-96F8-BA7924C4396A}\mpengine.dll
2013-12-27 11:09 . 2013-12-27 11:09 -------- d-----w- c:\program files (x86)\Aerosoft
2013-12-27 10:35 . 2013-12-27 10:36 -------- d-----w- C:\AdwCleaner
2013-12-26 16:23 . 2013-12-26 16:23 -------- d-----w- c:\users\Logic PC\AppData\Roaming\Malwarebytes
2013-12-26 16:23 . 2013-12-26 16:23 -------- d-----w- c:\programdata\Malwarebytes
2013-12-25 20:57 . 2013-12-25 20:58 -------- d-----w- c:\program files\trend micro
2013-12-25 20:57 . 2013-12-25 20:57 -------- d-----w- C:\rsit
2013-12-25 18:02 . 2013-12-25 18:02 -------- d-----w- c:\users\Logic PC\AppData\Local\ESET
2013-12-25 16:38 . 2013-12-25 16:38 -------- d-----w- c:\program files\ESET
2013-12-25 15:41 . 2013-12-25 15:41 -------- d-----w- c:\users\Logic PC\AppData\Roaming\Image-Line
2013-12-25 15:41 . 2013-12-25 15:41 -------- d-----w- c:\program files\Image-Line
2013-12-25 15:40 . 2013-12-25 15:40 -------- d-----w- c:\users\Logic PC\AppData\Roaming\FlowStone
2013-12-25 15:40 . 2013-12-25 15:40 -------- d-----w- c:\program files (x86)\DSPRobotics
2013-12-25 15:38 . 2013-12-25 15:38 -------- d-----w- C:\flstudio
2013-12-24 21:49 . 2013-12-25 15:41 -------- d-----w- c:\program files (x86)\Image-Line
2013-12-23 10:27 . 2013-12-24 22:12 -------- d-----w- c:\programdata\saviinshop
2013-12-23 10:27 . 2013-12-23 10:27 -------- d-----w- c:\programdata\1b13b76c6d07173b
2013-12-23 10:27 . 2013-12-24 22:11 -------- d-----w- c:\programdata\downloaduitkeep
2013-12-22 23:40 . 2013-12-23 00:40 -------- d---a-w- C:\3590F75ABA9E485486C100C1A9D4FF06Z.Z...ZZ.ZZ..ZZZ
2013-12-20 18:18 . 2013-12-26 17:26 -------- d-----w- c:\program files (x86)\Seznam.cz
2013-12-20 18:18 . 2013-12-26 17:26 -------- d-----w- c:\users\Logic PC\AppData\Roaming\Seznam.cz
2013-12-20 18:18 . 2013-12-20 18:18 -------- d-----w- C:\totalcmd
2013-12-13 10:33 . 2013-12-13 10:33 -------- d-s---w- c:\windows\SysWow64\Microsoft
2013-12-13 10:18 . 2013-12-13 10:18 -------- d-----w- c:\users\Logic PC\AppData\Roaming\AVAST Software
2013-12-13 10:06 . 2013-10-31 06:46 131232 ----a-w- c:\windows\system32\drivers\aswFW.sys
2013-12-13 10:06 . 2013-12-13 10:10 447888 ----a-w- c:\windows\system32\drivers\aswNdisFlt.sys
2013-12-12 21:27 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2013-12-12 21:27 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
2013-12-12 21:27 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2013-12-12 21:27 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL
2013-12-12 21:27 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll
2013-12-12 18:54 . 2013-12-18 14:03 -------- d-----w- c:\program files (x86)\Valve
2013-12-12 18:47 . 2008-07-12 07:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll
2013-12-12 18:47 . 2008-07-12 07:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll
2013-12-12 18:47 . 2008-07-12 07:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2013-12-12 18:47 . 2013-12-12 18:47 -------- d-----w- C:\Riot Games
2013-12-12 17:37 . 2013-12-12 17:37 -------- d-----w- c:\users\Logic PC\AppData\Local\Daring_Development_Inc
2013-12-05 16:19 . 2013-12-05 16:19 -------- d-----w- c:\program files\CCleaner
2013-12-03 16:23 . 2013-12-03 16:23 -------- d-----w- c:\users\Logic PC\AppData\Local\Macromedia
2013-12-03 16:22 . 2013-12-03 16:22 -------- d-----w- c:\programdata\McAfee
2013-12-03 16:14 . 2013-12-03 16:21 -------- d-----w- c:\users\Logic PC\AppData\Local\Mozilla
2013-11-30 14:00 . 2013-12-24 22:10 -------- d-----w- c:\program files (x86)\Shopping Suggestion
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-14 23:20 . 2013-08-12 11:27 90708896 ----a-w- c:\windows\system32\MRT.exe
2013-12-13 10:10 . 2013-08-19 11:12 334648 ----a-w- c:\windows\system32\aswBoot.exe
2013-12-13 10:05 . 2013-08-19 15:17 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-12-13 10:05 . 2013-08-19 15:17 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-11-26 17:28 . 2013-11-26 17:28 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-11-26 17:28 . 2013-11-26 17:28 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-11-26 17:28 . 2013-11-26 17:28 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-11-26 17:28 . 2013-11-26 17:28 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-11-26 17:28 . 2013-11-26 17:28 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-11-26 17:28 . 2013-11-26 17:28 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2013-11-26 17:28 . 2013-11-26 17:28 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-11-26 17:28 . 2013-11-26 17:28 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2013-11-26 17:28 . 2013-11-26 17:28 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-11-26 17:28 . 2013-11-26 17:28 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2013-11-26 17:28 . 2013-11-26 17:28 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-11-26 17:28 . 2013-11-26 17:28 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-11-26 17:28 . 2013-11-26 17:28 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-11-26 17:28 . 2013-11-26 17:28 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-11-26 17:28 . 2013-11-26 17:28 337408 ----a-w- c:\windows\SysWow64\html.iec
2013-11-26 17:28 . 2013-11-26 17:28 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-11-26 17:28 . 2013-11-26 17:28 235008 ----a-w- c:\windows\system32\elshyph.dll
2013-11-26 17:28 . 2013-11-26 17:28 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2013-11-26 17:28 . 2013-11-26 17:28 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-11-26 17:28 . 2013-11-26 17:28 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2013-11-26 17:28 . 2013-11-26 17:28 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2013-11-26 17:28 . 2013-11-26 17:28 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-11-26 17:28 . 2013-11-26 17:28 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-11-26 17:28 . 2013-11-26 17:28 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-11-26 17:28 . 2013-11-26 17:28 942592 ----a-w- c:\windows\system32\jsIntl.dll
2013-11-26 17:28 . 2013-11-26 17:28 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-11-26 17:28 . 2013-11-26 17:28 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-11-26 17:28 . 2013-11-26 17:28 84992 ----a-w- c:\windows\system32\mshtmled.dll
2013-11-26 17:28 . 2013-11-26 17:28 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-11-26 17:28 . 2013-11-26 17:28 81408 ----a-w- c:\windows\system32\icardie.dll
2013-11-26 17:28 . 2013-11-26 17:28 774144 ----a-w- c:\windows\system32\jscript.dll
2013-11-26 17:28 . 2013-11-26 17:28 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-11-26 17:28 . 2013-11-26 17:28 626176 ----a-w- c:\windows\system32\msfeeds.dll
2013-11-26 17:28 . 2013-11-26 17:28 62464 ----a-w- c:\windows\system32\pngfilt.dll
2013-11-26 17:28 . 2013-11-26 17:28 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2013-11-26 17:28 . 2013-11-26 17:28 548352 ----a-w- c:\windows\system32\vbscript.dll
2013-11-26 17:28 . 2013-11-26 17:28 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-11-26 17:28 . 2013-11-26 17:28 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-11-26 17:28 . 2013-11-26 17:28 48128 ----a-w- c:\windows\system32\imgutil.dll
2013-11-26 17:28 . 2013-11-26 17:28 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2013-11-26 17:28 . 2013-11-26 17:28 413696 ----a-w- c:\windows\system32\html.iec
2013-11-26 17:28 . 2013-11-26 17:28 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-11-26 17:28 . 2013-11-26 17:28 30208 ----a-w- c:\windows\system32\licmgr10.dll
2013-11-26 17:28 . 2013-11-26 17:28 296960 ----a-w- c:\windows\system32\dxtrans.dll
2013-11-26 17:28 . 2013-11-26 17:28 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2013-11-26 17:28 . 2013-11-26 17:28 247808 ----a-w- c:\windows\system32\msls31.dll
2013-11-26 17:28 . 2013-11-26 17:28 243200 ----a-w- c:\windows\system32\webcheck.dll
2013-11-26 17:28 . 2013-11-26 17:28 235520 ----a-w- c:\windows\system32\url.dll
2013-11-26 17:28 . 2013-11-26 17:28 195584 ----a-w- c:\windows\system32\msrating.dll
2013-11-26 17:28 . 2013-11-26 17:28 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-11-26 17:28 . 2013-11-26 17:28 147968 ----a-w- c:\windows\system32\occache.dll
2013-11-26 17:28 . 2013-11-26 17:28 143872 ----a-w- c:\windows\system32\wextract.exe
2013-11-26 17:28 . 2013-11-26 17:28 13824 ----a-w- c:\windows\system32\mshta.exe
2013-11-26 17:28 . 2013-11-26 17:28 135680 ----a-w- c:\windows\system32\iepeers.dll
2013-11-26 17:28 . 2013-11-26 17:28 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2013-11-26 17:28 . 2013-11-26 17:28 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-11-26 17:28 . 2013-11-26 17:28 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-11-26 17:28 . 2013-11-26 17:28 105984 ----a-w- c:\windows\system32\iesysprep.dll
2013-11-26 17:28 . 2013-11-26 17:28 101376 ----a-w- c:\windows\system32\inseng.dll
2013-11-26 11:25 . 2010-11-21 03:27 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-10-31 16:19 . 2013-09-21 14:16 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-10-31 09:53 . 2013-09-21 13:46 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-10-14 17:00 . 2013-11-26 17:31 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
2013-10-12 02:30 . 2013-11-13 13:14 830464 ----a-w- c:\windows\system32\nshwfp.dll
2013-10-12 02:29 . 2013-11-13 13:14 859648 ----a-w- c:\windows\system32\IKEEXT.DLL
2013-10-12 02:29 . 2013-11-13 13:14 324096 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2013-10-12 02:03 . 2013-11-13 13:14 656896 ----a-w- c:\windows\SysWow64\nshwfp.dll
2013-10-12 02:01 . 2013-11-13 13:14 216576 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL
2013-10-05 20:25 . 2013-11-13 13:14 1474048 ----a-w- c:\windows\system32\crypt32.dll
2013-10-05 19:57 . 2013-11-13 13:14 1168384 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-10-04 02:28 . 2013-11-13 13:14 190464 ----a-w- c:\windows\system32\SmartcardCredentialProvider.dll
2013-10-04 02:25 . 2013-11-13 13:14 197120 ----a-w- c:\windows\system32\credui.dll
2013-10-04 02:24 . 2013-11-13 13:14 1930752 ----a-w- c:\windows\system32\authui.dll
2013-10-04 01:58 . 2013-11-13 13:14 152576 ----a-w- c:\windows\SysWow64\SmartcardCredentialProvider.dll
2013-10-04 01:56 . 2013-11-13 13:14 168960 ----a-w- c:\windows\SysWow64\credui.dll
2013-10-04 01:56 . 2013-11-13 13:14 1796096 ----a-w- c:\windows\SysWow64\authui.dll
2013-10-03 02:23 . 2013-11-13 13:14 404480 ----a-w- c:\windows\system32\gdi32.dll
2013-10-03 02:00 . 2013-11-13 13:14 311808 ----a-w- c:\windows\SysWow64\gdi32.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2011-06-24 5199984]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-09-28 642728]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys;c:\windows\SYSNATIVE\Drivers\ssadadb.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdm.sys [x]
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys;c:\windows\SYSNATIVE\DRIVERS\ssadserd.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [x]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfpr.sys [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe;c:\windows\SYSNATIVE\viakaraokesrv.exe [x]
S3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2013-09-12 5618456]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = https://www.google.sk/
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
DPF: {444785F1-DE89-4295-863A-D46C3A781394} - hxxp://webplayer.unity3d.com/download_webplayer-2.x/UnityWebPlayer.cab
FF - ProfilePath - c:\users\Logic PC\AppData\Roaming\Mozilla\Firefox\Profiles\ex0rp68p.default\
FF - ExtSQL: 2013-12-03 17:16; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Logic PC\AppData\Roaming\Mozilla\Firefox\Profiles\ex0rp68p.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{434D452D-5637-006A-76A7-7A786E7484D7} - (no file)
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
AddRemove-BetterSurf Plus V1 - c:\program files (x86)\BetterSurf\BetterSurfPlusV1\uninstall.exe
AddRemove-VLC Player GPU+11.041.44 - c:\program files (x86)\VLC Player GPU+\uninstall.exe
AddRemove-Webexp Enhanced - c:\program files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha57\uninstall.exe
AddRemove-{1C52B8B6-FFA2-12F6-0A5A-E8301F96A568} - c:\programdata\downloaduitkeep\sqTwSgf.exe
AddRemove-{62D82EC1-0D3A-DF54-8E3E-07E1337A5311} - c:\programdata\SaveNshare.\y93.exe
AddRemove-{70BD2558-27DA-8B02-02D0-D8704ECD2EDF} - c:\programdata\saviinshop\MFVU.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\windows\SysWOW64\DllHost.exe
.
**************************************************************************
.
Completion time: 2013-12-28 20:54:56 - machine was rebooted
ComboFix-quarantined-files.txt 2013-12-28 19:54
ComboFix2.txt 2013-12-28 18:08
.
Pre-Run: 99 589 259 264 bytes free
Post-Run: 99 277 627 392 bytes free
.
- - End Of File - - 63A74530952E64B1E578B7FA8BA443A3
A36C5E4F47E84449FF07ED3517B43A31
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.421.1051.18.4079.2657 [GMT 1:00]
Running from: c:\users\Logic PC\Desktop\ComboFix.exe
Command switches used :: c:\users\Logic PC\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 7.0 *Enabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
SP: ESET NOD32 Antivirus 7.0 *Enabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\$AVG-SHREDDER-TMP-4027486f-393b-4311-a5b1-b2767e606368
c:\program files (x86)\VLC Player GPU+
c:\program files (x86)\VLC Player GPU+\deinstaller.exe
c:\program files (x86)\VLC Player GPU+\diablo130302.cl
c:\program files (x86)\VLC Player GPU+\diakgcn121016.cl
c:\program files (x86)\VLC Player GPU+\GPUMonitor.exe
c:\program files (x86)\VLC Player GPU+\Installer.exe
c:\program files (x86)\VLC Player GPU+\libcurl.dll
c:\program files (x86)\VLC Player GPU+\libeay32.dll
c:\program files (x86)\VLC Player GPU+\libidn-11.dll
c:\program files (x86)\VLC Player GPU+\libpdcurses.dll
c:\program files (x86)\VLC Player GPU+\lua5.1.dll
c:\program files (x86)\VLC Player GPU+\OpenCL.dll
c:\program files (x86)\VLC Player GPU+\path.inf
c:\program files (x86)\VLC Player GPU+\phatk121016.cl
c:\program files (x86)\VLC Player GPU+\poclbm130302.cl
c:\program files (x86)\VLC Player GPU+\pthreadGC2.dll
c:\program files (x86)\VLC Player GPU+\README
c:\program files (x86)\VLC Player GPU+\scrypt130302.cl
c:\program files (x86)\VLC Player GPU+\ssleay32.dll
c:\program files (x86)\VLC Player GPU+\uninstall.exe
c:\program files (x86)\VLC Player GPU+\Uninstall\IRIMG1.JPG
c:\program files (x86)\VLC Player GPU+\Uninstall\IRIMG2.JPG
c:\program files (x86)\VLC Player GPU+\Uninstall\uninstall.dat
c:\program files (x86)\VLC Player GPU+\Uninstall\uninstall.xml
c:\program files (x86)\VLC Player GPU+\zlib1.dll
c:\programdata\AVG2014
c:\programdata\AVG2014\$AVG\$VAULT\vault.db
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_Skype C2C Service
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Files Created from 2013-11-28 to 2013-12-28 )))))))))))))))))))))))))))))))
.
.
2013-12-27 12:03 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5903F4CC-1D23-47DE-96F8-BA7924C4396A}\mpengine.dll
2013-12-27 11:09 . 2013-12-27 11:09 -------- d-----w- c:\program files (x86)\Aerosoft
2013-12-27 10:35 . 2013-12-27 10:36 -------- d-----w- C:\AdwCleaner
2013-12-26 16:23 . 2013-12-26 16:23 -------- d-----w- c:\users\Logic PC\AppData\Roaming\Malwarebytes
2013-12-26 16:23 . 2013-12-26 16:23 -------- d-----w- c:\programdata\Malwarebytes
2013-12-25 20:57 . 2013-12-25 20:58 -------- d-----w- c:\program files\trend micro
2013-12-25 20:57 . 2013-12-25 20:57 -------- d-----w- C:\rsit
2013-12-25 18:02 . 2013-12-25 18:02 -------- d-----w- c:\users\Logic PC\AppData\Local\ESET
2013-12-25 16:38 . 2013-12-25 16:38 -------- d-----w- c:\program files\ESET
2013-12-25 15:41 . 2013-12-25 15:41 -------- d-----w- c:\users\Logic PC\AppData\Roaming\Image-Line
2013-12-25 15:41 . 2013-12-25 15:41 -------- d-----w- c:\program files\Image-Line
2013-12-25 15:40 . 2013-12-25 15:40 -------- d-----w- c:\users\Logic PC\AppData\Roaming\FlowStone
2013-12-25 15:40 . 2013-12-25 15:40 -------- d-----w- c:\program files (x86)\DSPRobotics
2013-12-25 15:38 . 2013-12-25 15:38 -------- d-----w- C:\flstudio
2013-12-24 21:49 . 2013-12-25 15:41 -------- d-----w- c:\program files (x86)\Image-Line
2013-12-23 10:27 . 2013-12-24 22:12 -------- d-----w- c:\programdata\saviinshop
2013-12-23 10:27 . 2013-12-23 10:27 -------- d-----w- c:\programdata\1b13b76c6d07173b
2013-12-23 10:27 . 2013-12-24 22:11 -------- d-----w- c:\programdata\downloaduitkeep
2013-12-22 23:40 . 2013-12-23 00:40 -------- d---a-w- C:\3590F75ABA9E485486C100C1A9D4FF06Z.Z...ZZ.ZZ..ZZZ
2013-12-20 18:18 . 2013-12-26 17:26 -------- d-----w- c:\program files (x86)\Seznam.cz
2013-12-20 18:18 . 2013-12-26 17:26 -------- d-----w- c:\users\Logic PC\AppData\Roaming\Seznam.cz
2013-12-20 18:18 . 2013-12-20 18:18 -------- d-----w- C:\totalcmd
2013-12-13 10:33 . 2013-12-13 10:33 -------- d-s---w- c:\windows\SysWow64\Microsoft
2013-12-13 10:18 . 2013-12-13 10:18 -------- d-----w- c:\users\Logic PC\AppData\Roaming\AVAST Software
2013-12-13 10:06 . 2013-10-31 06:46 131232 ----a-w- c:\windows\system32\drivers\aswFW.sys
2013-12-13 10:06 . 2013-12-13 10:10 447888 ----a-w- c:\windows\system32\drivers\aswNdisFlt.sys
2013-12-12 21:27 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2013-12-12 21:27 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
2013-12-12 21:27 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2013-12-12 21:27 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL
2013-12-12 21:27 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll
2013-12-12 18:54 . 2013-12-18 14:03 -------- d-----w- c:\program files (x86)\Valve
2013-12-12 18:47 . 2008-07-12 07:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll
2013-12-12 18:47 . 2008-07-12 07:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll
2013-12-12 18:47 . 2008-07-12 07:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2013-12-12 18:47 . 2013-12-12 18:47 -------- d-----w- C:\Riot Games
2013-12-12 17:37 . 2013-12-12 17:37 -------- d-----w- c:\users\Logic PC\AppData\Local\Daring_Development_Inc
2013-12-05 16:19 . 2013-12-05 16:19 -------- d-----w- c:\program files\CCleaner
2013-12-03 16:23 . 2013-12-03 16:23 -------- d-----w- c:\users\Logic PC\AppData\Local\Macromedia
2013-12-03 16:22 . 2013-12-03 16:22 -------- d-----w- c:\programdata\McAfee
2013-12-03 16:14 . 2013-12-03 16:21 -------- d-----w- c:\users\Logic PC\AppData\Local\Mozilla
2013-11-30 14:00 . 2013-12-24 22:10 -------- d-----w- c:\program files (x86)\Shopping Suggestion
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-14 23:20 . 2013-08-12 11:27 90708896 ----a-w- c:\windows\system32\MRT.exe
2013-12-13 10:10 . 2013-08-19 11:12 334648 ----a-w- c:\windows\system32\aswBoot.exe
2013-12-13 10:05 . 2013-08-19 15:17 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-12-13 10:05 . 2013-08-19 15:17 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-11-26 17:28 . 2013-11-26 17:28 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-11-26 17:28 . 2013-11-26 17:28 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-11-26 17:28 . 2013-11-26 17:28 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-11-26 17:28 . 2013-11-26 17:28 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-11-26 17:28 . 2013-11-26 17:28 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-11-26 17:28 . 2013-11-26 17:28 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2013-11-26 17:28 . 2013-11-26 17:28 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-11-26 17:28 . 2013-11-26 17:28 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2013-11-26 17:28 . 2013-11-26 17:28 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-11-26 17:28 . 2013-11-26 17:28 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2013-11-26 17:28 . 2013-11-26 17:28 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-11-26 17:28 . 2013-11-26 17:28 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-11-26 17:28 . 2013-11-26 17:28 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-11-26 17:28 . 2013-11-26 17:28 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-11-26 17:28 . 2013-11-26 17:28 337408 ----a-w- c:\windows\SysWow64\html.iec
2013-11-26 17:28 . 2013-11-26 17:28 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-11-26 17:28 . 2013-11-26 17:28 235008 ----a-w- c:\windows\system32\elshyph.dll
2013-11-26 17:28 . 2013-11-26 17:28 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2013-11-26 17:28 . 2013-11-26 17:28 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-11-26 17:28 . 2013-11-26 17:28 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2013-11-26 17:28 . 2013-11-26 17:28 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2013-11-26 17:28 . 2013-11-26 17:28 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-11-26 17:28 . 2013-11-26 17:28 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-11-26 17:28 . 2013-11-26 17:28 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-11-26 17:28 . 2013-11-26 17:28 942592 ----a-w- c:\windows\system32\jsIntl.dll
2013-11-26 17:28 . 2013-11-26 17:28 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-11-26 17:28 . 2013-11-26 17:28 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-11-26 17:28 . 2013-11-26 17:28 84992 ----a-w- c:\windows\system32\mshtmled.dll
2013-11-26 17:28 . 2013-11-26 17:28 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-11-26 17:28 . 2013-11-26 17:28 81408 ----a-w- c:\windows\system32\icardie.dll
2013-11-26 17:28 . 2013-11-26 17:28 774144 ----a-w- c:\windows\system32\jscript.dll
2013-11-26 17:28 . 2013-11-26 17:28 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-11-26 17:28 . 2013-11-26 17:28 626176 ----a-w- c:\windows\system32\msfeeds.dll
2013-11-26 17:28 . 2013-11-26 17:28 62464 ----a-w- c:\windows\system32\pngfilt.dll
2013-11-26 17:28 . 2013-11-26 17:28 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2013-11-26 17:28 . 2013-11-26 17:28 548352 ----a-w- c:\windows\system32\vbscript.dll
2013-11-26 17:28 . 2013-11-26 17:28 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-11-26 17:28 . 2013-11-26 17:28 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-11-26 17:28 . 2013-11-26 17:28 48128 ----a-w- c:\windows\system32\imgutil.dll
2013-11-26 17:28 . 2013-11-26 17:28 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2013-11-26 17:28 . 2013-11-26 17:28 413696 ----a-w- c:\windows\system32\html.iec
2013-11-26 17:28 . 2013-11-26 17:28 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-11-26 17:28 . 2013-11-26 17:28 30208 ----a-w- c:\windows\system32\licmgr10.dll
2013-11-26 17:28 . 2013-11-26 17:28 296960 ----a-w- c:\windows\system32\dxtrans.dll
2013-11-26 17:28 . 2013-11-26 17:28 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2013-11-26 17:28 . 2013-11-26 17:28 247808 ----a-w- c:\windows\system32\msls31.dll
2013-11-26 17:28 . 2013-11-26 17:28 243200 ----a-w- c:\windows\system32\webcheck.dll
2013-11-26 17:28 . 2013-11-26 17:28 235520 ----a-w- c:\windows\system32\url.dll
2013-11-26 17:28 . 2013-11-26 17:28 195584 ----a-w- c:\windows\system32\msrating.dll
2013-11-26 17:28 . 2013-11-26 17:28 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-11-26 17:28 . 2013-11-26 17:28 147968 ----a-w- c:\windows\system32\occache.dll
2013-11-26 17:28 . 2013-11-26 17:28 143872 ----a-w- c:\windows\system32\wextract.exe
2013-11-26 17:28 . 2013-11-26 17:28 13824 ----a-w- c:\windows\system32\mshta.exe
2013-11-26 17:28 . 2013-11-26 17:28 135680 ----a-w- c:\windows\system32\iepeers.dll
2013-11-26 17:28 . 2013-11-26 17:28 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2013-11-26 17:28 . 2013-11-26 17:28 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-11-26 17:28 . 2013-11-26 17:28 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-11-26 17:28 . 2013-11-26 17:28 105984 ----a-w- c:\windows\system32\iesysprep.dll
2013-11-26 17:28 . 2013-11-26 17:28 101376 ----a-w- c:\windows\system32\inseng.dll
2013-11-26 11:25 . 2010-11-21 03:27 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-10-31 16:19 . 2013-09-21 14:16 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-10-31 09:53 . 2013-09-21 13:46 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-10-14 17:00 . 2013-11-26 17:31 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
2013-10-12 02:30 . 2013-11-13 13:14 830464 ----a-w- c:\windows\system32\nshwfp.dll
2013-10-12 02:29 . 2013-11-13 13:14 859648 ----a-w- c:\windows\system32\IKEEXT.DLL
2013-10-12 02:29 . 2013-11-13 13:14 324096 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2013-10-12 02:03 . 2013-11-13 13:14 656896 ----a-w- c:\windows\SysWow64\nshwfp.dll
2013-10-12 02:01 . 2013-11-13 13:14 216576 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL
2013-10-05 20:25 . 2013-11-13 13:14 1474048 ----a-w- c:\windows\system32\crypt32.dll
2013-10-05 19:57 . 2013-11-13 13:14 1168384 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-10-04 02:28 . 2013-11-13 13:14 190464 ----a-w- c:\windows\system32\SmartcardCredentialProvider.dll
2013-10-04 02:25 . 2013-11-13 13:14 197120 ----a-w- c:\windows\system32\credui.dll
2013-10-04 02:24 . 2013-11-13 13:14 1930752 ----a-w- c:\windows\system32\authui.dll
2013-10-04 01:58 . 2013-11-13 13:14 152576 ----a-w- c:\windows\SysWow64\SmartcardCredentialProvider.dll
2013-10-04 01:56 . 2013-11-13 13:14 168960 ----a-w- c:\windows\SysWow64\credui.dll
2013-10-04 01:56 . 2013-11-13 13:14 1796096 ----a-w- c:\windows\SysWow64\authui.dll
2013-10-03 02:23 . 2013-11-13 13:14 404480 ----a-w- c:\windows\system32\gdi32.dll
2013-10-03 02:00 . 2013-11-13 13:14 311808 ----a-w- c:\windows\SysWow64\gdi32.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2011-06-24 5199984]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-09-28 642728]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys;c:\windows\SYSNATIVE\Drivers\ssadadb.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdm.sys [x]
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys;c:\windows\SYSNATIVE\DRIVERS\ssadserd.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [x]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfpr.sys [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe;c:\windows\SYSNATIVE\viakaraokesrv.exe [x]
S3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2013-09-12 5618456]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = https://www.google.sk/
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
DPF: {444785F1-DE89-4295-863A-D46C3A781394} - hxxp://webplayer.unity3d.com/download_webplayer-2.x/UnityWebPlayer.cab
FF - ProfilePath - c:\users\Logic PC\AppData\Roaming\Mozilla\Firefox\Profiles\ex0rp68p.default\
FF - ExtSQL: 2013-12-03 17:16; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Logic PC\AppData\Roaming\Mozilla\Firefox\Profiles\ex0rp68p.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{434D452D-5637-006A-76A7-7A786E7484D7} - (no file)
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
AddRemove-BetterSurf Plus V1 - c:\program files (x86)\BetterSurf\BetterSurfPlusV1\uninstall.exe
AddRemove-VLC Player GPU+11.041.44 - c:\program files (x86)\VLC Player GPU+\uninstall.exe
AddRemove-Webexp Enhanced - c:\program files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha57\uninstall.exe
AddRemove-{1C52B8B6-FFA2-12F6-0A5A-E8301F96A568} - c:\programdata\downloaduitkeep\sqTwSgf.exe
AddRemove-{62D82EC1-0D3A-DF54-8E3E-07E1337A5311} - c:\programdata\SaveNshare.\y93.exe
AddRemove-{70BD2558-27DA-8B02-02D0-D8704ECD2EDF} - c:\programdata\saviinshop\MFVU.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\windows\SysWOW64\DllHost.exe
.
**************************************************************************
.
Completion time: 2013-12-28 20:54:56 - machine was rebooted
ComboFix-quarantined-files.txt 2013-12-28 19:54
ComboFix2.txt 2013-12-28 18:08
.
Pre-Run: 99 589 259 264 bytes free
Post-Run: 99 277 627 392 bytes free
.
- - End Of File - - 63A74530952E64B1E578B7FA8BA443A3
A36C5E4F47E84449FF07ED3517B43A31