ComboFix 14-11-15.01 - Matúško . 11. 2014 13:11:10.1.4 - x86
Microsoft Windows 7 Starter 6.1.7601.1.1250.421.1051.18.1012.284 [GMT 1:00]
Running from: c:\users\Mat˙Üko\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
SP: Microsoft Security Essentials *Disabled/Updated* {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\ntuser.pol
C:\torrent.exe
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\background.html
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\content.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\lsdb.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\manifest.json
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\TsCO.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ckgdjghkghdinihnnpoblibiaijnhkmc
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ckgdjghkghdinihnnpoblibiaijnhkmc\2.0\background.html
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ckgdjghkghdinihnnpoblibiaijnhkmc\2.0\content.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ckgdjghkghdinihnnpoblibiaijnhkmc\2.0\HOx.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ckgdjghkghdinihnnpoblibiaijnhkmc\2.0\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ckgdjghkghdinihnnpoblibiaijnhkmc\2.0\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfaocbpdfapkhdflaibhjhfcbgnboenn
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfaocbpdfapkhdflaibhjhfcbgnboenn\2.0\background.html
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfaocbpdfapkhdflaibhjhfcbgnboenn\2.0\content.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfaocbpdfapkhdflaibhjhfcbgnboenn\2.0\iP8wzNp9R.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfaocbpdfapkhdflaibhjhfcbgnboenn\2.0\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfaocbpdfapkhdflaibhjhfcbgnboenn\2.0\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\background.html
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\content.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\TsCO.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\pkfacdjmapfpbhlpokbkpolcdigdjgmg
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\pkfacdjmapfpbhlpokbkpolcdigdjgmg\2.0\background.html
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\pkfacdjmapfpbhlpokbkpolcdigdjgmg\2.0\content.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\pkfacdjmapfpbhlpokbkpolcdigdjgmg\2.0\cxiRzOLZV.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\pkfacdjmapfpbhlpokbkpolcdigdjgmg\2.0\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\pkfacdjmapfpbhlpokbkpolcdigdjgmg\2.0\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\background.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\content.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\TsCO.js
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\background.html
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\content.js
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\lsdb.js
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\manifest.json
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\TsCO.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ckgdjghkghdinihnnpoblibiaijnhkmc
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ckgdjghkghdinihnnpoblibiaijnhkmc\2.0\background.html
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ckgdjghkghdinihnnpoblibiaijnhkmc\2.0\content.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ckgdjghkghdinihnnpoblibiaijnhkmc\2.0\HOx.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ckgdjghkghdinihnnpoblibiaijnhkmc\2.0\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ckgdjghkghdinihnnpoblibiaijnhkmc\2.0\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfaocbpdfapkhdflaibhjhfcbgnboenn
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfaocbpdfapkhdflaibhjhfcbgnboenn\2.0\background.html
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfaocbpdfapkhdflaibhjhfcbgnboenn\2.0\content.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfaocbpdfapkhdflaibhjhfcbgnboenn\2.0\iP8wzNp9R.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfaocbpdfapkhdflaibhjhfcbgnboenn\2.0\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfaocbpdfapkhdflaibhjhfcbgnboenn\2.0\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\background.html
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\content.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\TsCO.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\pkfacdjmapfpbhlpokbkpolcdigdjgmg
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\pkfacdjmapfpbhlpokbkpolcdigdjgmg\2.0\background.html
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\pkfacdjmapfpbhlpokbkpolcdigdjgmg\2.0\content.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\pkfacdjmapfpbhlpokbkpolcdigdjgmg\2.0\cxiRzOLZV.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\pkfacdjmapfpbhlpokbkpolcdigdjgmg\2.0\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\pkfacdjmapfpbhlpokbkpolcdigdjgmg\2.0\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\background.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\content.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofojbjgaaddibdfpmmjeonahgbacejid\189\TsCO.js
c:\users\Matúško\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dddnogbnehhibmgaomapelniijieapon_0.localstorage
c:\users\Matúško\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_foidhhdbemgpefaimcnajpcknhjndpok_0.localstorage
c:\users\Matúško\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_chcjmggidmfcpmijonddkdanjdafgain_0.localstorage
c:\users\Matúško\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ofojbjgaaddibdfpmmjeonahgbacejid_0.localstorage-journal
c:\users\Matúško\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ofojbjgaaddibdfpmmjeonahgbacejid_0.localstorage
c:\users\Matúško\AppData\Local\Google\Chrome\User Data\Default\Preferences
.
.
((((((((((((((((((((((((( Files Created from 2014-10-16 to 2014-11-16 )))))))))))))))))))))))))))))))
.
.
2014-11-16 12:26 . 2014-11-16 12:26 -------- d-----w- c:\users\Matúško\AppData\Local\temp
2014-11-16 12:26 . 2014-11-16 12:26 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-11-16 11:45 . 2014-10-14 20:13 8901368 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0DAD82EF-3DEF-457E-A7B2-B37634F90A80}\mpengine.dll
2014-11-16 11:36 . 2014-11-16 11:36 -------- d-----w- C:\_OTL
2014-11-16 08:57 . 2014-11-16 08:57 512 ----a-w- C:\PhysicalMBR.bin
2014-11-14 07:10 . 2014-09-17 06:39 908840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{63D791C7-0C46-4C03-A973-D9CFBBE3A353}\gapaengine.dll
2014-11-14 06:32 . 2014-10-14 20:13 8901368 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-11-13 08:19 . 2014-11-15 12:13 -------- d-----w- C:\AdwCleaner
2014-11-13 07:44 . 2014-10-18 01:33 571904 ----a-w- c:\windows\system32\oleaut32.dll
2014-11-13 07:44 . 2014-08-12 01:36 701440 ----a-w- c:\windows\system32\IMJP10K.DLL
2014-11-13 07:44 . 2014-10-03 01:44 442880 ----a-w- c:\windows\system32\AUDIOKSE.dll
2014-11-13 07:44 . 2014-10-03 01:44 475136 ----a-w- c:\windows\system32\audiosrv.dll
2014-11-13 07:44 . 2014-10-03 01:44 275968 ----a-w- c:\windows\system32\EncDump.dll
2014-11-13 07:44 . 2014-10-03 01:44 374784 ----a-w- c:\windows\system32\AudioEng.dll
2014-11-13 07:44 . 2014-10-03 01:44 195584 ----a-w- c:\windows\system32\AudioSes.dll
2014-11-13 07:44 . 2014-08-21 06:26 1237504 ----a-w- c:\windows\system32\msxml3.dll
2014-11-13 07:44 . 2014-08-21 06:23 2048 ----a-w- c:\windows\system32\msxml3r.dll
2014-11-13 07:43 . 2014-10-10 00:45 2379264 ----a-w- c:\windows\system32\win32k.sys
2014-11-13 07:43 . 2014-09-19 09:23 248832 ----a-w- c:\windows\system32\schannel.dll
2014-11-13 07:43 . 2014-09-19 09:23 221184 ----a-w- c:\windows\system32\ncrypt.dll
2014-11-13 07:43 . 2014-09-19 09:23 550912 ----a-w- c:\windows\system32\kerberos.dll
2014-11-13 07:43 . 2014-09-19 09:23 172032 ----a-w- c:\windows\system32\wdigest.dll
2014-11-13 07:43 . 2014-09-19 09:23 65536 ----a-w- c:\windows\system32\TSpkg.dll
2014-11-13 07:43 . 2014-09-19 09:23 259584 ----a-w- c:\windows\system32\msv1_0.dll
2014-11-13 07:43 . 2014-09-19 09:23 17408 ----a-w- c:\windows\system32\credssp.dll
2014-11-13 07:42 . 2014-10-25 01:32 67584 ----a-w- c:\windows\system32\packager.dll
2014-11-13 07:42 . 2014-10-14 01:50 523776 ----a-w- c:\windows\system32\termsrv.dll
2014-11-13 07:42 . 2014-10-14 01:46 681984 ----a-w- c:\windows\system32\adtschema.dll
2014-11-13 07:42 . 2014-10-14 01:56 136632 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2014-11-13 07:42 . 2014-10-14 01:50 1059840 ----a-w- c:\windows\system32\lsasrv.dll
2014-11-13 07:42 . 2014-10-14 01:47 146432 ----a-w- c:\windows\system32\msaudite.dll
2014-11-08 17:17 . 2014-11-08 17:17 -------- d-----w- c:\program files\Common Files\Java
2014-11-08 17:17 . 2014-11-08 17:17 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2014-11-08 17:16 . 2014-11-08 17:16 -------- d-----w- c:\program files\Java
2014-11-06 19:21 . 2014-11-06 19:21 -------- d-----w- c:\users\Matúško\AppData\Local\Comodo
2014-11-06 19:21 . 2014-11-06 19:21 -------- d-----w- c:\users\Guest
2014-11-06 19:21 . 2014-11-06 19:21 -------- d-----w- c:\users\Administrator
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-11-13 19:19 . 2012-04-19 09:36 701104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-11-13 19:19 . 2012-04-19 09:36 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-10-30 11:24 . 2012-04-19 08:27 229000 ------w- c:\windows\system32\MpSigStub.exe
2014-10-10 01:44 . 2014-10-17 09:33 230912 ----a-w- c:\windows\system32\generaltel.dll
2014-10-10 01:44 . 2014-10-17 09:33 396288 ----a-w- c:\windows\system32\aepdu.dll
2014-10-10 01:39 . 2014-10-17 09:33 302592 ----a-w- c:\windows\system32\aeinv.dll
2014-09-25 01:40 . 2014-10-01 10:18 519680 ----a-w- c:\windows\system32\qdvd.dll
2014-09-18 01:32 . 2014-10-17 09:30 2363904 ----a-w- c:\windows\system32\msi.dll
2014-09-17 06:39 . 2012-06-12 14:54 908840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-09-09 21:47 . 2014-09-23 18:21 2048 ----a-w- c:\windows\system32\tzres.dll
2014-09-04 05:04 . 2014-10-17 09:33 372736 ----a-w- c:\windows\system32\rastls.dll
2014-09-02 07:03 . 2010-06-24 09:33 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-08-23 01:46 . 2014-08-28 07:13 305152 ----a-w- c:\windows\system32\gdi32.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-11-02 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-11-02 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-11-02 150552]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2011-03-18 2217256]
"IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-11-05 283160]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2011-06-30 1138780]
"AtherosBtStack"="c:\program files\Bluetooth Suite\BtvStack.exe" [2011-03-01 490656]
"AthBtTray"="c:\program files\Bluetooth Suite\AthBtTray.exe" [2011-03-01 302240]
"HPQuickWebProxy"="c:\program files\Hewlett-Packard\HP QuickWeb\hpqwutils.exe" [2011-04-08 78904]
"HPConnectionManager"="c:\program files\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe" [2011-02-15 94264]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-08-22 974432]
"HPOSD"="c:\program files\Hewlett-Packard\HP On Screen Display\HPOSD.exe" [2011-08-19 379960]
"HP Quick Launch"="c:\program files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2012-03-05 578944]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"NCPluginUpdater"="c:\program files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" [2014-11-11 21720]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2014-08-21 16:30 959176 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Quick Launch]
2012-03-05 12:38 578944 ----a-w- c:\program files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
.
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-11-06 102912]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2014-07-17 95920]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2014-08-22 288120]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-12-02 197224]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S1 aswKbd;aswKbd; [x]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\aestsrv.exe [2009-03-02 81920]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files\Bluetooth Suite\Ath_CoexAgent.exe [2011-03-01 138400]
S2 AtherosSvc;AtherosSvc;c:\program files\Bluetooth Suite\adminservice.exe [2011-03-01 72864]
S2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2013-11-04 92160]
S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 246840]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2013-05-13 270624]
S2 HPWMISVC;HPWMISVC;c:\program files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-03-05 35200]
S2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-05 13336]
S2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [2011-03-01 34976]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [2011-03-01 259232]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [2011-03-01 24736]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [2011-03-01 175776]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [2011-03-01 49312]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [2011-03-01 141088]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [2011-03-01 242336]
S3 BthMtpEnum;Bluetooth MTP Device Enumerator;c:\windows\system32\DRIVERS\BthMtpEnum.sys [2009-07-14 51200]
S3 hpCMSrv;HP Connection Manager 4.0 Service;c:\program files\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-02-15 1071160]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-11-30 327272]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 550760]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 195944]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 21864]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 19304]
S3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-10-28 17:57 1089352 ----a-w- c:\program files\Google\Chrome\Application\38.0.2125.111\Installer\chrmstp.exe
.
.
------- Supplementary Scan -------
.
uStart Page =
www.google.com
mStart Page =
www.google.com
TCP: DhcpNameServer = 192.168.2.1
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE} - c:\program files\InstallShield Installation Information\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}\setup.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_15_0_0_223_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_15_0_0_223_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2014-11-16 13:31:33
ComboFix-quarantined-files.txt 2014-11-16 12:31
.
Pre-Run: 210 972 246 016 bytes free
Post-Run: 210 630 324 224 bytes free
.
- - End Of File - - D3E15572DD79DE85C3D60A161137F6F3
A36C5E4F47E84449FF07ED3517B43A31