Re: Malware jmenem playnow.chaseswing.eu + jeden Vir v PC
Napsal: 29 dub 2014 02:54
TADY
ComboFix 14-04-26.01 - user 04/28/2014 18:28:14.3.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.16330.14268 [GMT -7:00]
Running from: c:\users\user\Downloads\ComboFix.exe
Command switches used :: c:\users\user\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\program files\003\vxlsnyaiet64.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Spybot - Search & Destroy 2
c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe.log
c:\programdata\McAfee
c:\programdata\McAfee\MCLOGS\Common\McCHSvc\McCHSvc000.log
c:\programdata\McAfee\MCLOGS\Common\McUICnt\McUICnt000.log
c:\programdata\McAfee\MCLOGS\McLightInstaller\McUICnt\McUICnt000.log
c:\programdata\McAfee\MCLOGS\McUICnt\mcuicnt\mcuicnt000.log
c:\programdata\McAfee\MCLOGS\PartnerCustom\McCHSvc\McCHSvc000.log
c:\programdata\McAfee\MCLOGS\PartnerCustom\mcuicnt\mcuicnt000.log
c:\programdata\McAfee\MCLOGS\PartnerCustom\SecurityScan_Inner\SecurityScan_Inner000.log
c:\programdata\McAfee\MCLOGS\PartnerCustom\SecurityScan_Release\SecurityScan_Release000.log
c:\programdata\McAfee\MCLOGS\PartnerCustom\SSScheduler\SSScheduler000.log
c:\programdata\McAfee\MCLOGS\SecurityScanner\mcuicnt\mcuicnt000.log
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ESGIGUARD
-------\Service_c2cautoupdatesvc
-------\Service_c2cpnrsvc
-------\Service_esgiguard
-------\Service_SkypeUpdate
-------\Service_vxlsnyaiet64
.
.
((((((((((((((((((((((((( Files Created from 2014-03-28 to 2014-04-29 )))))))))))))))))))))))))))))))
.
.
2014-04-29 01:38 . 2014-04-29 01:38 -------- d-----w- c:\users\Public\AppData\Local\temp
2014-04-29 01:38 . 2014-04-29 01:38 -------- d-----w- c:\users\hedev\AppData\Local\temp
2014-04-29 01:38 . 2014-04-29 01:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-04-28 18:54 . 2014-04-28 18:54 -------- d-----w- C:\AdwCleaner
2014-04-27 16:34 . 2014-04-27 16:34 -------- d-----w- c:\users\user\AppData\Roaming\Malwarebytes
2014-04-27 16:33 . 2014-04-27 16:33 -------- d-----w- c:\programdata\Malwarebytes
2014-04-27 07:54 . 2010-08-30 15:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-04-27 04:38 . 2014-04-27 04:38 -------- d-----w- C:\rsit
2014-04-27 04:38 . 2014-04-27 04:38 -------- d-----w- c:\program files\trend micro
2014-04-27 03:04 . 2014-04-27 03:04 -------- d-----w- c:\program files\Enigma Software Group
2014-04-27 03:03 . 2014-04-27 05:53 -------- d-----w- c:\windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-04-27 03:03 . 2014-04-27 03:03 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2014-04-27 01:04 . 2014-04-27 01:04 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-04-27 01:04 . 2014-04-27 01:04 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-04-26 20:22 . 2014-04-26 20:22 -------- d-----w- c:\users\user\AppData\Local\com
2014-04-26 20:21 . 2014-04-26 20:21 -------- d-sh--w- c:\users\user\AppData\Local\EmieUserList
2014-04-26 20:21 . 2014-04-26 20:21 -------- d-sh--w- c:\users\user\AppData\Local\EmieSiteList
2014-04-26 00:32 . 2014-04-17 12:31 10651704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{689D5FE9-A67E-454D-9FA8-D30BDEC3CF6C}\mpengine.dll
2014-04-19 02:21 . 2014-04-19 02:21 -------- d-----w- c:\program files (x86)\Sunflowers
2014-04-19 01:54 . 2014-04-19 02:18 -------- d-----w- c:\users\user\AppData\Roaming\SpieleEntwicklungsKombinat
2014-04-19 01:53 . 2014-04-19 01:54 -------- d-----w- c:\programdata\SpieleEntwicklungsKombinat
2014-04-19 01:53 . 2014-04-19 02:25 211456 ----a-w- c:\windows\system32\drivers\atksgt.sys
2014-04-19 01:53 . 2014-04-19 02:25 35328 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2014-04-11 22:00 . 2014-04-11 22:02 -------- d-----w- c:\users\user\AppData\Local\Forgotten_Hope
2014-04-08 22:42 . 2014-03-21 19:43 40392 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2014-04-08 22:42 . 2014-03-21 19:43 33568 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2014-04-08 00:06 . 2014-04-08 00:06 -------- d-----w- c:\users\user\AppData\Local\Project Reality
2014-04-07 23:16 . 2014-04-07 23:16 -------- d-----w- c:\users\user\AppData\Roaming\PowerISO
2014-04-07 23:15 . 2014-03-11 07:00 129944 ----a-w- c:\windows\system32\drivers\scdemu.sys
2014-04-07 23:14 . 2014-04-07 23:15 -------- d-----w- c:\program files\PowerISO
2014-04-07 22:43 . 2014-04-07 22:54 -------- d-----w- c:\users\user\AppData\Roaming\NCH Software
2014-04-07 22:42 . 2014-04-07 22:54 -------- d-----w- c:\program files (x86)\NCH Software
2014-04-07 22:42 . 2014-04-07 22:46 -------- d-----w- c:\programdata\NCH Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-04-24 02:24 . 2012-11-30 02:06 280792 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-04-24 02:24 . 2012-11-30 02:02 280792 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-04-24 02:23 . 2012-11-30 02:02 281032 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-04-10 07:36 . 2012-11-16 08:14 90655440 ----a-w- c:\windows\system32\MRT.exe
2014-04-09 22:26 . 2014-02-06 06:46 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2014-04-06 22:14 . 2012-11-30 02:02 75064 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2014-04-02 13:27 . 2014-03-21 18:26 1081112 ----a-w- c:\windows\SysWow64\nvspcap.dll
2014-04-02 13:27 . 2014-03-21 18:26 1225920 ----a-w- c:\windows\system32\nvspcap64.dll
2014-03-31 16:35 . 2010-11-21 03:27 270496 ------w- c:\windows\system32\MpSigStub.exe
2014-03-21 19:43 . 2014-03-21 18:24 37320 ----a-w- c:\windows\system32\nvaudcap64v.dll
2014-03-21 18:46 . 2014-03-21 18:46 152848 ----a-w- c:\windows\SysWow64\comdlg32.ocx
2014-03-21 18:46 . 2014-03-21 18:46 1081616 ----a-w- c:\windows\SysWow64\mscomctl.ocx
2014-03-04 14:35 . 2014-03-21 18:24 9728064 ----a-w- c:\windows\SysWow64\nvcuda.dll
2014-03-04 14:35 . 2014-03-21 18:24 9690424 ----a-w- c:\windows\SysWow64\nvopencl.dll
2014-03-04 14:35 . 2014-03-21 18:24 892704 ----a-w- c:\windows\system32\NvIFR64.dll
2014-03-04 14:35 . 2014-03-21 18:24 877856 ----a-w- c:\windows\system32\NvFBC64.dll
2014-03-04 14:35 . 2014-03-21 18:24 863064 ----a-w- c:\windows\SysWow64\NvIFR.dll
2014-03-04 14:35 . 2014-03-21 18:24 846168 ----a-w- c:\windows\SysWow64\NvFBC.dll
2014-03-04 14:35 . 2014-03-21 18:24 832936 ----a-w- c:\windows\SysWow64\nvumdshim.dll
2014-03-04 14:35 . 2014-03-21 18:24 484296 ----a-w- c:\windows\system32\nvEncodeAPI64.dll
2014-03-04 14:35 . 2014-03-21 18:24 409544 ----a-w- c:\windows\SysWow64\nvEncodeAPI.dll
2014-03-04 14:35 . 2014-03-21 18:24 377688 ----a-w- c:\windows\system32\NvIFROpenGL.dll
2014-03-04 14:35 . 2014-03-21 18:24 353504 ----a-w- c:\windows\system32\nvoglshim64.dll
2014-03-04 14:35 . 2014-03-21 18:24 333600 ----a-w- c:\windows\SysWow64\NvIFROpenGL.dll
2014-03-04 14:35 . 2014-03-21 18:24 31474976 ----a-w- c:\windows\system32\nvoglv64.dll
2014-03-04 14:35 . 2014-03-21 18:24 3143456 ----a-w- c:\windows\system32\nvcuvid.dll
2014-03-04 14:35 . 2014-03-21 18:24 305600 ----a-w- c:\windows\SysWow64\nvoglshim32.dll
2014-03-04 14:35 . 2014-03-21 18:24 2958792 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2014-03-04 14:35 . 2014-03-21 18:24 2783008 ----a-w- c:\windows\system32\nvcuvenc.dll
2014-03-04 14:35 . 2014-03-21 18:24 2715264 ----a-w- c:\windows\SysWow64\nvapi.dll
2014-03-04 14:35 . 2014-03-21 18:24 25255256 ----a-w- c:\windows\system32\nvcompiler.dll
2014-03-04 14:35 . 2014-03-21 18:24 2411976 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2014-03-04 14:35 . 2014-03-21 18:24 23716640 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2014-03-04 14:35 . 2014-03-21 18:24 1885472 ----a-w- c:\windows\system32\nvdispco6433523.dll
2014-03-04 14:35 . 2014-03-21 18:24 17755424 ----a-w- c:\windows\system32\nvd3dumx.dll
2014-03-04 14:35 . 2014-03-21 18:24 17561544 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2014-03-04 14:35 . 2014-03-21 18:24 174296 ----a-w- c:\windows\system32\nvinitx.dll
2014-03-04 14:35 . 2014-03-21 18:24 15783992 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2014-03-04 14:35 . 2014-03-21 18:24 1516488 ----a-w- c:\windows\system32\nvdispgenco6433523.dll
2014-03-04 14:35 . 2014-03-21 18:24 148016 ----a-w- c:\windows\SysWow64\nvinit.dll
2014-03-04 14:35 . 2014-03-21 18:24 14709720 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2014-03-04 14:35 . 2014-03-21 18:24 12708128 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2014-03-04 14:35 . 2014-03-21 18:24 11636176 ----a-w- c:\windows\system32\nvcuda.dll
2014-03-04 14:35 . 2014-03-21 18:24 11589272 ----a-w- c:\windows\system32\nvopencl.dll
2014-03-04 14:35 . 2013-09-28 01:02 18302384 ----a-w- c:\windows\system32\nvwgf2umx.dll
2014-03-04 14:35 . 2013-09-28 01:02 947808 ----a-w- c:\windows\system32\nvumdshimx.dll
2014-03-04 14:35 . 2013-09-28 01:02 3093280 ----a-w- c:\windows\system32\nvapi64.dll
2014-03-04 13:06 . 2012-11-16 06:53 6714312 ----a-w- c:\windows\system32\nvcpl.dll
2014-03-04 13:06 . 2012-11-16 06:53 3497816 ----a-w- c:\windows\system32\nvsvc64.dll
2014-03-04 13:05 . 2012-11-16 06:53 922968 ----a-w- c:\windows\system32\nvvsvc.exe
2014-03-04 13:05 . 2012-11-16 06:53 64968 ----a-w- c:\windows\system32\nvshext.dll
2014-03-04 13:05 . 2012-11-16 06:53 386336 ----a-w- c:\windows\system32\nvmctray.dll
2014-03-04 13:05 . 2012-11-16 06:53 3649185 ----a-w- c:\windows\system32\nvcoproc.bin
2014-03-04 11:32 . 2014-03-21 18:25 599840 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2014-03-04 09:17 . 2014-04-09 21:20 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2014-02-10 18:06 . 2014-03-18 19:43 80184 ----a-w- c:\windows\system32\drivers\aswStm.sys
2014-02-10 18:06 . 2014-03-18 19:43 78648 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-02-10 18:06 . 2014-03-18 19:43 421704 ----a-w- c:\windows\system32\drivers\aswSP.sys
2014-02-10 18:06 . 2014-03-18 19:43 334136 ----a-w- c:\windows\system32\aswBoot.exe
2014-02-10 18:06 . 2014-03-18 19:43 1038072 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-02-10 18:06 . 2013-01-20 08:13 43152 ----a-w- c:\windows\avastSS.scr
2014-02-07 01:23 . 2014-03-13 00:13 3156480 ----a-w- c:\windows\system32\win32k.sys
2014-02-04 02:32 . 2014-03-13 00:09 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-02-04 02:32 . 2014-03-13 00:09 624128 ----a-w- c:\windows\system32\qedit.dll
2014-02-04 02:04 . 2014-03-13 00:09 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2014-02-04 02:04 . 2014-03-13 00:09 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2014-01-29 02:32 . 2014-03-13 00:13 484864 ----a-w- c:\windows\system32\wer.dll
2014-01-29 02:06 . 2014-03-13 00:13 381440 ----a-w- c:\windows\SysWow64\wer.dll
2013-08-04 05:48 . 2013-08-04 02:56 704282 ----a-w- c:\program files (x86)\unins000.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-28 59280]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-04-02 3774312]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2014-03-11 377368]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R3 aswTap;avast! SecureLine TAP Adapter v3;c:\windows\system32\DRIVERS\aswTap.sys;c:\windows\SYSNATIVE\DRIVERS\aswTap.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys;c:\windows\SYSNATIVE\DRIVERS\asmthub3.sys [x]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys;c:\windows\SYSNATIVE\DRIVERS\asmtxhci.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-04-26 00:50 1078088 ----a-w- c:\program files (x86)\Google\Chrome\Application\34.0.1847.131\Installer\chrmstp.exe
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-02-10 18:06 287280 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-01-30 23:05 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-01-30 23:05 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-01-30 23:05 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-01-30 23:05 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-01-30 23:05 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-01-30 23:05 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-19 11613288]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-04-02 2201032]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-04-02 1225920]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <-loopback>
uSearchAssistant = hxxp://www.google.com
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 64.59.144.93 64.59.150.139
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
AddRemove-PunkBusterSvc - c:\windows\system32\Pbsvc.exe
AddRemove-{9F7FC1EC-5C07-44A4-8338-22AF90644273}_is1 - c:\gsm fields of honor 6.2\unins000.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2080601920-2927812346-669093319-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:e5,f9,3a,98,d5,64,08,3f,75,2a,c2,77,0e,28,39,53,75,77,91,64,a2,99,c6,
f6,16,e7,77,90,21,0e,2a,89,14,db,8c,c4,fc,53,6c,c6,62,ae,e1,e9,0d,cf,e9,44,\
"??"=hex:8f,18,51,da,93,9e,4a,8c,e1,c2,f4,93,04,f3,cc,01
.
[HKEY_USERS\S-1-5-21-2080601920-2927812346-669093319-1000\Software\SecuROM\License information*]
"datasecu"=hex:a7,77,19,e1,e9,c5,a5,9d,17,cb,e7,d5,0a,1c,2e,78,6c,23,84,17,0f,
d5,59,37,11,a4,5e,bc,97,27,b8,87,aa,fc,b2,79,ee,37,11,11,a8,7a,50,2b,d4,c0,\
"rkeysecu"=hex:56,e8,dd,f2,09,33,14,41,7c,f6,bb,c3,d3,93,36,97
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\windows\system32\PnkBstrA.exe
.
**************************************************************************
.
Completion time: 2014-04-28 18:50:47 - machine was rebooted
ComboFix-quarantined-files.txt 2014-04-29 01:50
ComboFix2.txt 2014-04-28 18:10
.
Pre-Run: 1,613,346,680,832 bytes free
Post-Run: 1,613,098,885,120 bytes free
.
- - End Of File - - 0AA8746F5491CC77A2C40C861FAEBC95
A36C5E4F47E84449FF07ED3517B43A31

ComboFix 14-04-26.01 - user 04/28/2014 18:28:14.3.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.16330.14268 [GMT -7:00]
Running from: c:\users\user\Downloads\ComboFix.exe
Command switches used :: c:\users\user\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\program files\003\vxlsnyaiet64.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Spybot - Search & Destroy 2
c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe.log
c:\programdata\McAfee
c:\programdata\McAfee\MCLOGS\Common\McCHSvc\McCHSvc000.log
c:\programdata\McAfee\MCLOGS\Common\McUICnt\McUICnt000.log
c:\programdata\McAfee\MCLOGS\McLightInstaller\McUICnt\McUICnt000.log
c:\programdata\McAfee\MCLOGS\McUICnt\mcuicnt\mcuicnt000.log
c:\programdata\McAfee\MCLOGS\PartnerCustom\McCHSvc\McCHSvc000.log
c:\programdata\McAfee\MCLOGS\PartnerCustom\mcuicnt\mcuicnt000.log
c:\programdata\McAfee\MCLOGS\PartnerCustom\SecurityScan_Inner\SecurityScan_Inner000.log
c:\programdata\McAfee\MCLOGS\PartnerCustom\SecurityScan_Release\SecurityScan_Release000.log
c:\programdata\McAfee\MCLOGS\PartnerCustom\SSScheduler\SSScheduler000.log
c:\programdata\McAfee\MCLOGS\SecurityScanner\mcuicnt\mcuicnt000.log
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ESGIGUARD
-------\Service_c2cautoupdatesvc
-------\Service_c2cpnrsvc
-------\Service_esgiguard
-------\Service_SkypeUpdate
-------\Service_vxlsnyaiet64
.
.
((((((((((((((((((((((((( Files Created from 2014-03-28 to 2014-04-29 )))))))))))))))))))))))))))))))
.
.
2014-04-29 01:38 . 2014-04-29 01:38 -------- d-----w- c:\users\Public\AppData\Local\temp
2014-04-29 01:38 . 2014-04-29 01:38 -------- d-----w- c:\users\hedev\AppData\Local\temp
2014-04-29 01:38 . 2014-04-29 01:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-04-28 18:54 . 2014-04-28 18:54 -------- d-----w- C:\AdwCleaner
2014-04-27 16:34 . 2014-04-27 16:34 -------- d-----w- c:\users\user\AppData\Roaming\Malwarebytes
2014-04-27 16:33 . 2014-04-27 16:33 -------- d-----w- c:\programdata\Malwarebytes
2014-04-27 07:54 . 2010-08-30 15:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-04-27 04:38 . 2014-04-27 04:38 -------- d-----w- C:\rsit
2014-04-27 04:38 . 2014-04-27 04:38 -------- d-----w- c:\program files\trend micro
2014-04-27 03:04 . 2014-04-27 03:04 -------- d-----w- c:\program files\Enigma Software Group
2014-04-27 03:03 . 2014-04-27 05:53 -------- d-----w- c:\windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-04-27 03:03 . 2014-04-27 03:03 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2014-04-27 01:04 . 2014-04-27 01:04 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-04-27 01:04 . 2014-04-27 01:04 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-04-26 20:22 . 2014-04-26 20:22 -------- d-----w- c:\users\user\AppData\Local\com
2014-04-26 20:21 . 2014-04-26 20:21 -------- d-sh--w- c:\users\user\AppData\Local\EmieUserList
2014-04-26 20:21 . 2014-04-26 20:21 -------- d-sh--w- c:\users\user\AppData\Local\EmieSiteList
2014-04-26 00:32 . 2014-04-17 12:31 10651704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{689D5FE9-A67E-454D-9FA8-D30BDEC3CF6C}\mpengine.dll
2014-04-19 02:21 . 2014-04-19 02:21 -------- d-----w- c:\program files (x86)\Sunflowers
2014-04-19 01:54 . 2014-04-19 02:18 -------- d-----w- c:\users\user\AppData\Roaming\SpieleEntwicklungsKombinat
2014-04-19 01:53 . 2014-04-19 01:54 -------- d-----w- c:\programdata\SpieleEntwicklungsKombinat
2014-04-19 01:53 . 2014-04-19 02:25 211456 ----a-w- c:\windows\system32\drivers\atksgt.sys
2014-04-19 01:53 . 2014-04-19 02:25 35328 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2014-04-11 22:00 . 2014-04-11 22:02 -------- d-----w- c:\users\user\AppData\Local\Forgotten_Hope
2014-04-08 22:42 . 2014-03-21 19:43 40392 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2014-04-08 22:42 . 2014-03-21 19:43 33568 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2014-04-08 00:06 . 2014-04-08 00:06 -------- d-----w- c:\users\user\AppData\Local\Project Reality
2014-04-07 23:16 . 2014-04-07 23:16 -------- d-----w- c:\users\user\AppData\Roaming\PowerISO
2014-04-07 23:15 . 2014-03-11 07:00 129944 ----a-w- c:\windows\system32\drivers\scdemu.sys
2014-04-07 23:14 . 2014-04-07 23:15 -------- d-----w- c:\program files\PowerISO
2014-04-07 22:43 . 2014-04-07 22:54 -------- d-----w- c:\users\user\AppData\Roaming\NCH Software
2014-04-07 22:42 . 2014-04-07 22:54 -------- d-----w- c:\program files (x86)\NCH Software
2014-04-07 22:42 . 2014-04-07 22:46 -------- d-----w- c:\programdata\NCH Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-04-24 02:24 . 2012-11-30 02:06 280792 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-04-24 02:24 . 2012-11-30 02:02 280792 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-04-24 02:23 . 2012-11-30 02:02 281032 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-04-10 07:36 . 2012-11-16 08:14 90655440 ----a-w- c:\windows\system32\MRT.exe
2014-04-09 22:26 . 2014-02-06 06:46 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2014-04-06 22:14 . 2012-11-30 02:02 75064 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2014-04-02 13:27 . 2014-03-21 18:26 1081112 ----a-w- c:\windows\SysWow64\nvspcap.dll
2014-04-02 13:27 . 2014-03-21 18:26 1225920 ----a-w- c:\windows\system32\nvspcap64.dll
2014-03-31 16:35 . 2010-11-21 03:27 270496 ------w- c:\windows\system32\MpSigStub.exe
2014-03-21 19:43 . 2014-03-21 18:24 37320 ----a-w- c:\windows\system32\nvaudcap64v.dll
2014-03-21 18:46 . 2014-03-21 18:46 152848 ----a-w- c:\windows\SysWow64\comdlg32.ocx
2014-03-21 18:46 . 2014-03-21 18:46 1081616 ----a-w- c:\windows\SysWow64\mscomctl.ocx
2014-03-04 14:35 . 2014-03-21 18:24 9728064 ----a-w- c:\windows\SysWow64\nvcuda.dll
2014-03-04 14:35 . 2014-03-21 18:24 9690424 ----a-w- c:\windows\SysWow64\nvopencl.dll
2014-03-04 14:35 . 2014-03-21 18:24 892704 ----a-w- c:\windows\system32\NvIFR64.dll
2014-03-04 14:35 . 2014-03-21 18:24 877856 ----a-w- c:\windows\system32\NvFBC64.dll
2014-03-04 14:35 . 2014-03-21 18:24 863064 ----a-w- c:\windows\SysWow64\NvIFR.dll
2014-03-04 14:35 . 2014-03-21 18:24 846168 ----a-w- c:\windows\SysWow64\NvFBC.dll
2014-03-04 14:35 . 2014-03-21 18:24 832936 ----a-w- c:\windows\SysWow64\nvumdshim.dll
2014-03-04 14:35 . 2014-03-21 18:24 484296 ----a-w- c:\windows\system32\nvEncodeAPI64.dll
2014-03-04 14:35 . 2014-03-21 18:24 409544 ----a-w- c:\windows\SysWow64\nvEncodeAPI.dll
2014-03-04 14:35 . 2014-03-21 18:24 377688 ----a-w- c:\windows\system32\NvIFROpenGL.dll
2014-03-04 14:35 . 2014-03-21 18:24 353504 ----a-w- c:\windows\system32\nvoglshim64.dll
2014-03-04 14:35 . 2014-03-21 18:24 333600 ----a-w- c:\windows\SysWow64\NvIFROpenGL.dll
2014-03-04 14:35 . 2014-03-21 18:24 31474976 ----a-w- c:\windows\system32\nvoglv64.dll
2014-03-04 14:35 . 2014-03-21 18:24 3143456 ----a-w- c:\windows\system32\nvcuvid.dll
2014-03-04 14:35 . 2014-03-21 18:24 305600 ----a-w- c:\windows\SysWow64\nvoglshim32.dll
2014-03-04 14:35 . 2014-03-21 18:24 2958792 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2014-03-04 14:35 . 2014-03-21 18:24 2783008 ----a-w- c:\windows\system32\nvcuvenc.dll
2014-03-04 14:35 . 2014-03-21 18:24 2715264 ----a-w- c:\windows\SysWow64\nvapi.dll
2014-03-04 14:35 . 2014-03-21 18:24 25255256 ----a-w- c:\windows\system32\nvcompiler.dll
2014-03-04 14:35 . 2014-03-21 18:24 2411976 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2014-03-04 14:35 . 2014-03-21 18:24 23716640 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2014-03-04 14:35 . 2014-03-21 18:24 1885472 ----a-w- c:\windows\system32\nvdispco6433523.dll
2014-03-04 14:35 . 2014-03-21 18:24 17755424 ----a-w- c:\windows\system32\nvd3dumx.dll
2014-03-04 14:35 . 2014-03-21 18:24 17561544 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2014-03-04 14:35 . 2014-03-21 18:24 174296 ----a-w- c:\windows\system32\nvinitx.dll
2014-03-04 14:35 . 2014-03-21 18:24 15783992 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2014-03-04 14:35 . 2014-03-21 18:24 1516488 ----a-w- c:\windows\system32\nvdispgenco6433523.dll
2014-03-04 14:35 . 2014-03-21 18:24 148016 ----a-w- c:\windows\SysWow64\nvinit.dll
2014-03-04 14:35 . 2014-03-21 18:24 14709720 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2014-03-04 14:35 . 2014-03-21 18:24 12708128 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2014-03-04 14:35 . 2014-03-21 18:24 11636176 ----a-w- c:\windows\system32\nvcuda.dll
2014-03-04 14:35 . 2014-03-21 18:24 11589272 ----a-w- c:\windows\system32\nvopencl.dll
2014-03-04 14:35 . 2013-09-28 01:02 18302384 ----a-w- c:\windows\system32\nvwgf2umx.dll
2014-03-04 14:35 . 2013-09-28 01:02 947808 ----a-w- c:\windows\system32\nvumdshimx.dll
2014-03-04 14:35 . 2013-09-28 01:02 3093280 ----a-w- c:\windows\system32\nvapi64.dll
2014-03-04 13:06 . 2012-11-16 06:53 6714312 ----a-w- c:\windows\system32\nvcpl.dll
2014-03-04 13:06 . 2012-11-16 06:53 3497816 ----a-w- c:\windows\system32\nvsvc64.dll
2014-03-04 13:05 . 2012-11-16 06:53 922968 ----a-w- c:\windows\system32\nvvsvc.exe
2014-03-04 13:05 . 2012-11-16 06:53 64968 ----a-w- c:\windows\system32\nvshext.dll
2014-03-04 13:05 . 2012-11-16 06:53 386336 ----a-w- c:\windows\system32\nvmctray.dll
2014-03-04 13:05 . 2012-11-16 06:53 3649185 ----a-w- c:\windows\system32\nvcoproc.bin
2014-03-04 11:32 . 2014-03-21 18:25 599840 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2014-03-04 09:17 . 2014-04-09 21:20 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2014-02-10 18:06 . 2014-03-18 19:43 80184 ----a-w- c:\windows\system32\drivers\aswStm.sys
2014-02-10 18:06 . 2014-03-18 19:43 78648 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-02-10 18:06 . 2014-03-18 19:43 421704 ----a-w- c:\windows\system32\drivers\aswSP.sys
2014-02-10 18:06 . 2014-03-18 19:43 334136 ----a-w- c:\windows\system32\aswBoot.exe
2014-02-10 18:06 . 2014-03-18 19:43 1038072 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-02-10 18:06 . 2013-01-20 08:13 43152 ----a-w- c:\windows\avastSS.scr
2014-02-07 01:23 . 2014-03-13 00:13 3156480 ----a-w- c:\windows\system32\win32k.sys
2014-02-04 02:32 . 2014-03-13 00:09 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-02-04 02:32 . 2014-03-13 00:09 624128 ----a-w- c:\windows\system32\qedit.dll
2014-02-04 02:04 . 2014-03-13 00:09 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2014-02-04 02:04 . 2014-03-13 00:09 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2014-01-29 02:32 . 2014-03-13 00:13 484864 ----a-w- c:\windows\system32\wer.dll
2014-01-29 02:06 . 2014-03-13 00:13 381440 ----a-w- c:\windows\SysWow64\wer.dll
2013-08-04 05:48 . 2013-08-04 02:56 704282 ----a-w- c:\program files (x86)\unins000.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-28 59280]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-04-02 3774312]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2014-03-11 377368]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R3 aswTap;avast! SecureLine TAP Adapter v3;c:\windows\system32\DRIVERS\aswTap.sys;c:\windows\SYSNATIVE\DRIVERS\aswTap.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys;c:\windows\SYSNATIVE\DRIVERS\asmthub3.sys [x]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys;c:\windows\SYSNATIVE\DRIVERS\asmtxhci.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-04-26 00:50 1078088 ----a-w- c:\program files (x86)\Google\Chrome\Application\34.0.1847.131\Installer\chrmstp.exe
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-02-10 18:06 287280 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-01-30 23:05 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-01-30 23:05 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-01-30 23:05 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-01-30 23:05 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-01-30 23:05 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-01-30 23:05 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-19 11613288]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-04-02 2201032]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-04-02 1225920]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <-loopback>
uSearchAssistant = hxxp://www.google.com
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 64.59.144.93 64.59.150.139
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
AddRemove-PunkBusterSvc - c:\windows\system32\Pbsvc.exe
AddRemove-{9F7FC1EC-5C07-44A4-8338-22AF90644273}_is1 - c:\gsm fields of honor 6.2\unins000.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2080601920-2927812346-669093319-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:e5,f9,3a,98,d5,64,08,3f,75,2a,c2,77,0e,28,39,53,75,77,91,64,a2,99,c6,
f6,16,e7,77,90,21,0e,2a,89,14,db,8c,c4,fc,53,6c,c6,62,ae,e1,e9,0d,cf,e9,44,\
"??"=hex:8f,18,51,da,93,9e,4a,8c,e1,c2,f4,93,04,f3,cc,01
.
[HKEY_USERS\S-1-5-21-2080601920-2927812346-669093319-1000\Software\SecuROM\License information*]
"datasecu"=hex:a7,77,19,e1,e9,c5,a5,9d,17,cb,e7,d5,0a,1c,2e,78,6c,23,84,17,0f,
d5,59,37,11,a4,5e,bc,97,27,b8,87,aa,fc,b2,79,ee,37,11,11,a8,7a,50,2b,d4,c0,\
"rkeysecu"=hex:56,e8,dd,f2,09,33,14,41,7c,f6,bb,c3,d3,93,36,97
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\windows\system32\PnkBstrA.exe
.
**************************************************************************
.
Completion time: 2014-04-28 18:50:47 - machine was rebooted
ComboFix-quarantined-files.txt 2014-04-29 01:50
ComboFix2.txt 2014-04-28 18:10
.
Pre-Run: 1,613,346,680,832 bytes free
Post-Run: 1,613,098,885,120 bytes free
.
- - End Of File - - 0AA8746F5491CC77A2C40C861FAEBC95
A36C5E4F47E84449FF07ED3517B43A31