Trojan v pc
Napsal: 02 dub 2014 10:02
Zdravím, pri používaní firefoxu (robí to aj na chrome), čo sa týka doslova každého kliknutia na inú stránku sa mi začala vyhadzovať od esetu tabulka s infiltráciou JS/Kryptik.I trojsky kôň obrázok : http://leteckaposta.cz/342317687 . Pár krát som robil prehliadku esetom, programom malwarebytes a pred tým ešte iobit malware fighterom no ten som vymazal nakolko som práve na tomto fóre prečítal že to nieje dobrý program a lepší je malwarebytes no nič mi nenašiel ani jeden program. Prikladám tu log z combofixu.
ComboFix 14-03-24.01 - admin . 04. 2014 10:37:57.3.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.421.1051.18.8138.6389 [GMT 2:00]
Running from: c:\users\admin\Downloads\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2014-03-02 to 2014-04-02 )))))))))))))))))))))))))))))))
.
.
2014-04-02 08:40 . 2014-04-02 08:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-04-01 21:37 . 2014-04-01 21:37 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-04-01 21:37 . 2014-04-01 21:37 -------- d-----w- c:\programdata\Malwarebytes
2014-04-01 21:37 . 2014-03-05 07:26 63192 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-04-01 21:37 . 2014-03-05 07:26 88280 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-04-01 21:37 . 2014-03-05 07:26 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-04-01 20:15 . 2014-04-01 20:32 -------- d-----w- c:\program files\Enigma Software Group
2014-04-01 20:11 . 2014-04-01 20:32 -------- d-----w- c:\windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-04-01 20:11 . 2014-04-01 20:11 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2014-03-28 22:23 . 2014-03-28 22:23 -------- d-----w- c:\users\admin\AppData\Local\Splashtop
2014-03-28 22:02 . 2014-03-28 22:02 -------- d-----w- c:\programdata\Splashtop
2014-03-28 22:02 . 2014-03-28 22:02 -------- d-----w- c:\program files (x86)\Splashtop
2014-03-26 15:18 . 2014-03-26 15:18 -------- d-----w- c:\windows\system32\logs
2014-03-26 14:51 . 2014-03-26 14:51 -------- d-----w- c:\users\admin\AppData\Roaming\.StarMade
2014-03-26 12:15 . 2013-11-15 01:52 7217152 ----a-w- c:\windows\SysWow64\CrypticError.exe
2014-03-26 10:47 . 2014-03-26 10:47 -------- d-----w- c:\users\admin\AppData\Roaming\SpaceEngineers
2014-03-25 18:15 . 2014-03-25 18:15 -------- d-----w- c:\program files (x86)\MSXML 4.0
2014-03-25 16:45 . 2014-03-25 16:45 -------- d-----w- c:\users\admin\AppData\Roaming\wargaming.net
2014-03-25 09:02 . 2014-03-25 09:02 -------- d-----w- c:\users\admin\AppData\Local\SWTOR
2014-03-25 08:36 . 2014-03-25 09:41 -------- d-----w- c:\programdata\BitRaider
2014-03-24 09:18 . 2014-03-17 09:16 10521840 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{81A9BED8-0E04-4DD2-982C-780B884372A7}\mpengine.dll
2014-03-24 09:17 . 2014-03-24 09:17 1653096 ----a-w- c:\windows\system32\drivers\ntfs.sys
2014-03-24 09:16 . 2014-03-24 09:16 44032 ----a-w- c:\windows\system32\tsgqec.dll
2014-03-24 09:16 . 2014-03-24 09:16 36864 ----a-w- c:\windows\SysWow64\tsgqec.dll
2014-03-24 09:16 . 2014-03-24 09:16 3138048 ----a-w- c:\windows\system32\mstscax.dll
2014-03-24 09:16 . 2014-03-24 09:16 2691072 ----a-w- c:\windows\SysWow64\mstscax.dll
2014-03-24 09:16 . 2014-03-24 09:16 158208 ----a-w- c:\windows\system32\aaclient.dll
2014-03-24 09:16 . 2014-03-24 09:16 131072 ----a-w- c:\windows\SysWow64\aaclient.dll
2014-03-24 09:15 . 2014-03-24 09:15 3150848 ----a-w- c:\windows\system32\win32k.sys
2014-03-24 09:14 . 2014-03-24 09:14 5497688 ----a-w- c:\windows\system32\ntoskrnl.exe
2014-03-24 09:14 . 2014-03-24 09:14 43520 ----a-w- c:\windows\system32\csrsrv.dll
2014-03-24 09:14 . 2014-03-24 09:14 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll
2014-03-24 09:14 . 2014-03-24 09:14 3958120 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2014-03-24 09:14 . 2014-03-24 09:14 3902312 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2014-03-24 09:14 . 2014-03-24 09:14 112640 ----a-w- c:\windows\system32\smss.exe
2014-03-24 09:13 . 2014-03-24 09:13 223752 ----a-w- c:\windows\system32\drivers\fvevol.sys
2014-03-24 09:11 . 2014-03-24 09:11 19968 ----a-w- c:\windows\system32\drivers\usb8023.sys
2014-03-24 09:08 . 2014-03-24 09:08 287576 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2014-03-24 09:08 . 2014-03-24 09:08 1893224 ----a-w- c:\windows\system32\drivers\tcpip.sys
2014-03-24 09:03 . 2014-03-24 09:03 801280 ----a-w- c:\windows\system32\usp10.dll
2014-03-24 09:03 . 2014-03-24 09:03 627712 ----a-w- c:\windows\SysWow64\usp10.dll
2014-03-24 09:01 . 2014-03-24 09:01 751104 ----a-w- c:\windows\system32\win32spl.dll
2014-03-24 09:01 . 2014-03-24 09:01 492032 ----a-w- c:\windows\SysWow64\win32spl.dll
2014-03-24 08:58 . 2014-03-24 08:58 307200 ----a-w- c:\windows\system32\ncrypt.dll
2014-03-24 08:58 . 2014-03-24 08:58 219136 ----a-w- c:\windows\SysWow64\ncrypt.dll
2014-03-24 08:54 . 2014-03-24 08:54 2001408 ----a-w- c:\windows\system32\msxml6.dll
2014-03-24 08:54 . 2014-03-24 08:54 1880064 ----a-w- c:\windows\system32\msxml3.dll
2014-03-24 08:54 . 2014-03-24 08:54 1388544 ----a-w- c:\windows\SysWow64\msxml6.dll
2014-03-24 08:54 . 2014-03-24 08:54 1236992 ----a-w- c:\windows\SysWow64\msxml3.dll
2014-03-24 08:53 . 2014-03-24 08:53 46080 ----a-w- c:\windows\system32\atmlib.dll
2014-03-24 08:53 . 2014-03-24 08:53 367616 ----a-w- c:\windows\system32\atmfd.dll
2014-03-24 08:53 . 2014-03-24 08:53 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2014-03-24 08:53 . 2014-03-24 08:53 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2014-03-24 08:52 . 2014-03-24 08:52 2048 ----a-w- c:\windows\system32\tzres.dll
2014-03-24 08:52 . 2014-03-24 08:52 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2014-03-24 08:50 . 2014-03-24 08:50 478208 ----a-w- c:\windows\system32\dpnet.dll
2014-03-24 08:50 . 2014-03-24 08:50 376832 ----a-w- c:\windows\SysWow64\dpnet.dll
2014-03-24 08:49 . 2014-03-24 08:49 295792 ----a-w- c:\windows\system32\drivers\volsnap.sys
2014-03-24 08:48 . 2014-03-24 08:48 850944 ----a-w- c:\windows\system32\jscript.dll
2014-03-24 08:48 . 2014-03-24 08:48 609792 ----a-w- c:\windows\system32\vbscript.dll
2014-03-24 08:48 . 2014-03-24 08:48 428032 ----a-w- c:\windows\SysWow64\vbscript.dll
2014-03-24 08:48 . 2014-03-24 08:48 95744 ----a-w- c:\windows\system32\synceng.dll
2014-03-24 08:48 . 2014-03-24 08:48 78336 ----a-w- c:\windows\SysWow64\synceng.dll
2014-03-24 08:47 . 2014-03-24 08:47 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2014-03-24 08:47 . 2014-03-24 08:47 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2014-03-24 08:47 . 2014-03-24 08:47 744448 ----a-w- c:\windows\system32\WUDFx.dll
2014-03-24 08:47 . 2014-03-24 08:47 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2014-03-24 08:47 . 2014-03-24 08:47 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2014-03-24 08:47 . 2014-03-24 08:47 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2014-03-24 08:47 . 2014-03-24 08:47 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2014-03-24 08:42 . 2014-03-24 08:42 714752 ----a-w- c:\windows\system32\kerberos.dll
2014-03-24 08:42 . 2014-03-24 08:42 541184 ----a-w- c:\windows\SysWow64\kerberos.dll
2014-03-24 08:41 . 2014-03-24 08:41 182272 ----a-w- c:\windows\system32\cryptsvc.dll
2014-03-24 08:41 . 2014-03-24 08:41 1462784 ----a-w- c:\windows\system32\crypt32.dll
2014-03-24 08:41 . 2014-03-24 08:41 140288 ----a-w- c:\windows\system32\cryptnet.dll
2014-03-24 08:41 . 2014-03-24 08:41 139264 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2014-03-24 08:41 . 2014-03-24 08:41 1157632 ----a-w- c:\windows\SysWow64\crypt32.dll
2014-03-24 08:41 . 2014-03-24 08:41 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2014-03-24 08:41 . 2014-03-24 08:41 503808 ----a-w- c:\windows\system32\srcore.dll
2014-03-24 08:41 . 2014-03-24 08:41 43008 ----a-w- c:\windows\SysWow64\srclient.dll
2014-03-24 08:39 . 2014-03-24 08:39 73216 ----a-w- c:\windows\system32\netapi32.dll
2014-03-24 08:39 . 2014-03-24 08:39 58880 ----a-w- c:\windows\system32\browcli.dll
2014-03-24 08:39 . 2014-03-24 08:39 41472 ----a-w- c:\windows\SysWow64\browcli.dll
2014-03-24 08:39 . 2014-03-24 08:39 136704 ----a-w- c:\windows\system32\browser.dll
2014-03-24 08:39 . 2014-03-24 08:39 220160 ----a-w- c:\windows\system32\wintrust.dll
2014-03-24 08:39 . 2014-03-24 08:39 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2014-03-24 08:38 . 2014-03-24 08:38 574464 ----a-w- c:\windows\system32\d3d10level9.dll
2014-03-24 08:38 . 2014-03-24 08:38 490496 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2014-03-24 08:38 . 2014-03-24 08:38 956416 ----a-w- c:\windows\system32\localspl.dll
2014-03-24 08:37 . 2014-03-24 08:37 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2014-03-24 08:37 . 2014-03-24 08:37 95088 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2014-03-24 08:37 . 2014-03-24 08:37 459216 ----a-w- c:\windows\system32\drivers\cng.sys
2014-03-24 08:37 . 2014-03-24 08:37 340992 ----a-w- c:\windows\system32\schannel.dll
2014-03-24 08:37 . 2014-03-24 08:37 225280 ----a-w- c:\windows\SysWow64\schannel.dll
2014-03-24 08:37 . 2014-03-24 08:37 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2014-03-24 08:37 . 2014-03-24 08:37 152432 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2014-03-24 08:37 . 2014-03-24 08:37 14165504 ----a-w- c:\windows\system32\shell32.dll
2014-03-24 08:36 . 2014-03-24 08:36 987136 ----a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll
2014-03-24 08:36 . 2014-03-24 08:36 1425408 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
2014-03-24 08:35 . 2014-03-24 08:35 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe
2014-03-24 08:35 . 2014-03-24 08:35 76288 ----a-w- c:\windows\system32\rdpwsx.dll
2014-03-24 08:35 . 2014-03-24 08:35 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll
2014-03-24 08:35 . 2014-03-24 08:35 204800 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2014-03-24 08:35 . 2014-03-24 08:35 208896 ----a-w- c:\windows\system32\profsvc.dll
2014-03-24 08:34 . 2014-03-24 08:34 3213824 ----a-w- c:\windows\system32\msi.dll
2014-03-24 08:34 . 2014-03-24 08:34 2342400 ----a-w- c:\windows\SysWow64\msi.dll
2014-03-24 08:33 . 2014-03-24 08:33 75632 ----a-w- c:\windows\system32\drivers\partmgr.sys
2014-03-24 08:33 . 2014-03-24 08:33 294912 ----a-w- c:\windows\system32\browserchoice.exe
2014-03-24 08:29 . 2014-03-24 08:29 902656 ----a-w- c:\windows\system32\d2d1.dll
2014-03-24 08:29 . 2014-03-24 08:29 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2014-03-24 08:29 . 2014-03-24 08:29 320512 ----a-w- c:\windows\system32\d3d10_1core.dll
2014-03-24 08:29 . 2014-03-24 08:29 218624 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2014-03-24 08:29 . 2014-03-24 08:29 197120 ----a-w- c:\windows\system32\d3d10_1.dll
2014-03-24 08:29 . 2014-03-24 08:29 1837568 ----a-w- c:\windows\system32\d3d10warp.dll
2014-03-24 08:29 . 2014-03-24 08:29 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2014-03-24 08:29 . 2014-03-24 08:29 1541120 ----a-w- c:\windows\system32\DWrite.dll
2014-03-24 08:29 . 2014-03-24 08:29 1170944 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2014-03-24 08:29 . 2014-03-24 08:29 1074176 ----a-w- c:\windows\SysWow64\DWrite.dll
2014-03-24 08:28 . 2014-03-24 08:28 80896 ----a-w- c:\windows\system32\imagehlp.dll
2014-03-24 08:28 . 2014-03-24 08:28 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2014-03-24 08:28 . 2014-03-24 08:28 5120 ----a-w- c:\windows\system32\wmi.dll
2014-03-24 08:28 . 2014-03-24 08:28 22896 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2014-03-24 08:28 . 2014-03-24 08:28 158720 ----a-w- c:\windows\SysWow64\imagehlp.dll
2014-03-24 08:16 . 2014-03-24 08:16 826368 ----a-w- c:\windows\SysWow64\rdpcore.dll
2014-03-24 08:16 . 2014-03-24 08:16 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-24 09:07 . 2014-03-24 09:07 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2014-03-24 08:49 . 2014-03-24 08:49 559104 ----a-w- c:\windows\apppatch\AcLayers.dll
2014-03-24 08:49 . 2014-03-24 08:49 347648 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2014-03-24 08:49 . 2014-03-24 08:49 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2014-03-24 08:37 . 2014-03-24 08:37 340992 ----a-w- c:\windows\system32\schannel.dll
2014-03-24 08:37 . 2014-03-24 08:37 225280 ----a-w- c:\windows\SysWow64\schannel.dll
2014-03-24 07:50 . 2014-03-24 07:50 285696 ----a-w- c:\windows\system32\schtasks.exe
2014-03-24 07:50 . 2014-03-24 07:50 179712 ----a-w- c:\windows\SysWow64\schtasks.exe
2014-03-24 07:50 . 2014-03-24 07:50 1114624 ----a-w- c:\windows\system32\schedsvc.dll
2014-03-24 00:06 . 2013-11-22 22:12 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2014-03-19 09:35 . 2013-12-19 17:23 214392 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-03-19 09:21 . 2013-12-19 17:23 214392 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-03-18 18:34 . 2013-12-19 18:16 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-03-12 12:56 . 2013-11-22 22:29 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-03-12 12:56 . 2013-11-22 22:29 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-03-04 14:35 . 2014-02-20 06:41 15783992 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2014-03-04 14:35 . 2013-11-22 22:36 62408 ----a-w- c:\windows\system32\OpenCL.dll
2014-03-04 14:35 . 2013-11-22 22:36 54216 ----a-w- c:\windows\SysWow64\OpenCL.dll
2014-03-04 14:35 . 2013-11-22 22:34 947808 ----a-w- c:\windows\system32\nvumdshimx.dll
2014-03-04 14:35 . 2013-11-22 22:34 3093280 ----a-w- c:\windows\system32\nvapi64.dll
2014-03-04 14:35 . 2013-11-22 22:34 2715264 ----a-w- c:\windows\SysWow64\nvapi.dll
2014-03-04 14:35 . 2013-11-22 22:34 14709720 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2014-03-04 13:06 . 2013-11-22 22:36 6714312 ----a-w- c:\windows\system32\nvcpl.dll
2014-03-04 13:06 . 2013-11-22 22:36 3497816 ----a-w- c:\windows\system32\nvsvc64.dll
2014-03-04 13:05 . 2014-01-08 23:29 2558808 ----a-w- c:\windows\system32\nvsvcr.dll
2014-03-04 13:05 . 2013-11-22 22:36 922968 ----a-w- c:\windows\system32\nvvsvc.exe
2014-03-04 13:05 . 2013-11-22 22:36 64968 ----a-w- c:\windows\system32\nvshext.dll
2014-03-04 13:05 . 2013-11-22 22:36 386336 ----a-w- c:\windows\system32\nvmctray.dll
2014-03-04 13:05 . 2013-11-22 22:36 3649185 ----a-w- c:\windows\system32\nvcoproc.bin
2014-02-08 18:34 . 2014-02-20 06:41 1885472 ----a-w- c:\windows\system32\nvdispco6433489.dll
2014-02-08 18:34 . 2014-02-20 06:41 1515296 ----a-w- c:\windows\system32\nvdispgenco6433489.dll
2014-02-05 09:31 . 2013-12-03 12:07 1048152 ----a-w- c:\windows\SysWow64\nvspcap.dll
2014-02-05 09:30 . 2013-12-03 12:07 1179576 ----a-w- c:\windows\system32\nvspcap64.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[-] 2013-11-22 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7600.16385] .. c:\windows\system32\user32.dll
.
[-] 2013-11-22 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7600.16385] .. c:\windows\SysWOW64\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files (x86)\BS_Player_ControlBar\prxtbBS_P.dll" [2013-11-06 226592]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2013-11-06 16:53 226592 ----a-w- c:\program files (x86)\BS_Player_ControlBar\prxtbBS_P.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files (x86)\BS_Player_ControlBar\prxtbBS_P.dll" [2013-11-06 226592]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2013-11-22 39408]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
"uTorrent"="c:\users\admin\AppData\Roaming\uTorrent\uTorrent.exe" [2014-01-26 905296]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2014-02-20 6161176]
"Advanced SystemCare 7"="d:\program files\Advanced SystemCare 7\ASCTray.exe" [2014-02-11 2288928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2012-02-29 56088]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-05-22 291648]
"Adobe Updater"="c:\programdata\adobe\color.vbs" [2013-12-11 101]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2014-02-26 3814736]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Cloud Panel.lnk - c:\users\admin\AppData\Roaming\CloudPanel\CloudPanelLauncher.exe [2014-3-22 828416]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 ArcService;Arc Service;d:\program files\Perfect World Entertainment\Arc\ArcService.exe;d:\program files\Perfect World Entertainment\Arc\ArcService.exe [x]
R3 BRDriver64;BRDriver64;c:\programdata\BitRaider\BRDriver64.sys;c:\programdata\BitRaider\BRDriver64.sys [x]
R3 BRSptSvc;BitRaider Mini-Support Service;c:\programdata\BitRaider\BRSptSvc.exe;c:\programdata\BitRaider\BRSptSvc.exe [x]
R3 cpuz136;cpuz136;c:\windows\TEMP\cpuz136\cpuz136_x64.sys;c:\windows\TEMP\cpuz136\cpuz136_x64.sys [x]
R3 FairplayKD;FairplayKD;c:\programdata\MTA San Andreas All\Common\temp\FairplayKD.sys;c:\programdata\MTA San Andreas All\Common\temp\FairplayKD.sys [x]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [x]
R3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x]
R3 OSFMount;OSFMount;d:\program files\Counter-Strike Global Offensive\image\x64\OSFMount.sys;d:\program files\Counter-Strike Global Offensive\image\x64\OSFMount.sys [x]
R3 WatAdminSvc;WatAdminSvc;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 X6va016;X6va016;c:\windows\SysWOW64\Drivers\X6va016;c:\windows\SysWOW64\Drivers\X6va016 [x]
S0 iusb3hcs;Ovládač prepínača hostiteľského radiča Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S2 AdvancedSystemCareService7;Advanced SystemCare Service 7;d:\program files\Advanced SystemCare 7\ASCService.exe;d:\program files\Advanced SystemCare 7\ASCService.exe [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [x]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfpr.sys [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 SplashtopRemoteService;Splashtop® Remote Service;c:\program files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe;c:\program files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe [x]
S2 SSUService;Splashtop Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe;c:\program files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 iusb3hub;Ovládač rozbočovača Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Ovládač hostiteľského radiča Intel(R) USB 3.0 eXtensible;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTCore64;RTCore64;c:\program files (x86)\EVGA Precision X\RTCore64.sys;c:\program files (x86)\EVGA Precision X\RTCore64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MBAMSWISSARMY
*NewlyCreated* - RTCORE64
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-03-15 15:54 1150280 ----a-w- c:\program files (x86)\Google\Chrome\Application\33.0.1750.154\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-04-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-22 12:56]
.
2014-04-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-11-22 22:32]
.
2014-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-11-22 22:32]
.
2014-04-02 c:\windows\Tasks\SlimDrivers Startup.job
- c:\program files (x86)\SlimDrivers\SlimDrivers.exe [2013-09-24 11:49]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
2014-03-23 23:56 2471744 ----a-w- d:\program files\IObit Uninstaller\UninstallExplorer64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-11-04 2919168]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2000-01-01 7204568]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-02-05 2234144]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-02-05 1179576]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va016]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va016"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-525872782-3713464005-3976650588-1000\Software\SecuROM\License information*]
"datasecu"=hex:b2,c3,4e,12,d4,aa,dd,40,f4,ec,34,b2,5f,30,a0,a3,48,ed,4b,70,96,
89,2e,b0,37,3f,50,65,bf,da,80,13,8a,18,47,ea,5e,cb,71,02,9c,45,b2,1f,e7,e2,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.12"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\ESET\ESET Security\CurrentVersion\Info]
@Denied: (2) (LocalSystem)
"AppDataDir"="c:\\ProgramData\\ESET\\ESET NOD32 Antivirus\\"
"DataDir"="ESET\\ESET NOD32 Antivirus\\"
"EditionName"=" "
"InstallDir"="c:\\Program Files\\ESET\\ESET NOD32 Antivirus\\"
"LanguageId"=dword:0000041b
"PackageTag"=dword:6090e758
"ProductBase"=dword:00000000
"ProductCode"="{1B2BD098-29D4-4752-81A2-CBFB8758ABC1}"
"ProductName"="ESET NOD32 Antivirus"
"ProductType"="eav"
"ProductVersion"="4.2.67.10"
"UniqueId"="000656D6528FD94F"
"ScannerBuild"=dword:00001fb8
"ScannerVersionId"=dword:000015d8
"ScannerVersion"="Locked/open ESET for status."
"ei2"=hex(b):bc,23,bf,9b,92,1e,4d,2a
"ei1"=hex(b):ac,22,0b,73,5d,8d,00,00
"ei3"=hex(b):7c,d9,8f,52,00,00,00,00
"ei4"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2014-04-02 10:41:29
ComboFix-quarantined-files.txt 2014-04-02 08:41
ComboFix2.txt 2014-04-01 21:28
ComboFix3.txt 2014-04-01 19:55
.
Pre-Run: 35 884 490 752 bytes free
Post-Run: 35 583 119 360 bytes free
.
- - End Of File - - D69DE6CD36CC7B50E8A64FF034AEA335
ComboFix 14-03-24.01 - admin . 04. 2014 10:37:57.3.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.421.1051.18.8138.6389 [GMT 2:00]
Running from: c:\users\admin\Downloads\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2014-03-02 to 2014-04-02 )))))))))))))))))))))))))))))))
.
.
2014-04-02 08:40 . 2014-04-02 08:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-04-01 21:37 . 2014-04-01 21:37 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-04-01 21:37 . 2014-04-01 21:37 -------- d-----w- c:\programdata\Malwarebytes
2014-04-01 21:37 . 2014-03-05 07:26 63192 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-04-01 21:37 . 2014-03-05 07:26 88280 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-04-01 21:37 . 2014-03-05 07:26 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-04-01 20:15 . 2014-04-01 20:32 -------- d-----w- c:\program files\Enigma Software Group
2014-04-01 20:11 . 2014-04-01 20:32 -------- d-----w- c:\windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-04-01 20:11 . 2014-04-01 20:11 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2014-03-28 22:23 . 2014-03-28 22:23 -------- d-----w- c:\users\admin\AppData\Local\Splashtop
2014-03-28 22:02 . 2014-03-28 22:02 -------- d-----w- c:\programdata\Splashtop
2014-03-28 22:02 . 2014-03-28 22:02 -------- d-----w- c:\program files (x86)\Splashtop
2014-03-26 15:18 . 2014-03-26 15:18 -------- d-----w- c:\windows\system32\logs
2014-03-26 14:51 . 2014-03-26 14:51 -------- d-----w- c:\users\admin\AppData\Roaming\.StarMade
2014-03-26 12:15 . 2013-11-15 01:52 7217152 ----a-w- c:\windows\SysWow64\CrypticError.exe
2014-03-26 10:47 . 2014-03-26 10:47 -------- d-----w- c:\users\admin\AppData\Roaming\SpaceEngineers
2014-03-25 18:15 . 2014-03-25 18:15 -------- d-----w- c:\program files (x86)\MSXML 4.0
2014-03-25 16:45 . 2014-03-25 16:45 -------- d-----w- c:\users\admin\AppData\Roaming\wargaming.net
2014-03-25 09:02 . 2014-03-25 09:02 -------- d-----w- c:\users\admin\AppData\Local\SWTOR
2014-03-25 08:36 . 2014-03-25 09:41 -------- d-----w- c:\programdata\BitRaider
2014-03-24 09:18 . 2014-03-17 09:16 10521840 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{81A9BED8-0E04-4DD2-982C-780B884372A7}\mpengine.dll
2014-03-24 09:17 . 2014-03-24 09:17 1653096 ----a-w- c:\windows\system32\drivers\ntfs.sys
2014-03-24 09:16 . 2014-03-24 09:16 44032 ----a-w- c:\windows\system32\tsgqec.dll
2014-03-24 09:16 . 2014-03-24 09:16 36864 ----a-w- c:\windows\SysWow64\tsgqec.dll
2014-03-24 09:16 . 2014-03-24 09:16 3138048 ----a-w- c:\windows\system32\mstscax.dll
2014-03-24 09:16 . 2014-03-24 09:16 2691072 ----a-w- c:\windows\SysWow64\mstscax.dll
2014-03-24 09:16 . 2014-03-24 09:16 158208 ----a-w- c:\windows\system32\aaclient.dll
2014-03-24 09:16 . 2014-03-24 09:16 131072 ----a-w- c:\windows\SysWow64\aaclient.dll
2014-03-24 09:15 . 2014-03-24 09:15 3150848 ----a-w- c:\windows\system32\win32k.sys
2014-03-24 09:14 . 2014-03-24 09:14 5497688 ----a-w- c:\windows\system32\ntoskrnl.exe
2014-03-24 09:14 . 2014-03-24 09:14 43520 ----a-w- c:\windows\system32\csrsrv.dll
2014-03-24 09:14 . 2014-03-24 09:14 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll
2014-03-24 09:14 . 2014-03-24 09:14 3958120 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2014-03-24 09:14 . 2014-03-24 09:14 3902312 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2014-03-24 09:14 . 2014-03-24 09:14 112640 ----a-w- c:\windows\system32\smss.exe
2014-03-24 09:13 . 2014-03-24 09:13 223752 ----a-w- c:\windows\system32\drivers\fvevol.sys
2014-03-24 09:11 . 2014-03-24 09:11 19968 ----a-w- c:\windows\system32\drivers\usb8023.sys
2014-03-24 09:08 . 2014-03-24 09:08 287576 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2014-03-24 09:08 . 2014-03-24 09:08 1893224 ----a-w- c:\windows\system32\drivers\tcpip.sys
2014-03-24 09:03 . 2014-03-24 09:03 801280 ----a-w- c:\windows\system32\usp10.dll
2014-03-24 09:03 . 2014-03-24 09:03 627712 ----a-w- c:\windows\SysWow64\usp10.dll
2014-03-24 09:01 . 2014-03-24 09:01 751104 ----a-w- c:\windows\system32\win32spl.dll
2014-03-24 09:01 . 2014-03-24 09:01 492032 ----a-w- c:\windows\SysWow64\win32spl.dll
2014-03-24 08:58 . 2014-03-24 08:58 307200 ----a-w- c:\windows\system32\ncrypt.dll
2014-03-24 08:58 . 2014-03-24 08:58 219136 ----a-w- c:\windows\SysWow64\ncrypt.dll
2014-03-24 08:54 . 2014-03-24 08:54 2001408 ----a-w- c:\windows\system32\msxml6.dll
2014-03-24 08:54 . 2014-03-24 08:54 1880064 ----a-w- c:\windows\system32\msxml3.dll
2014-03-24 08:54 . 2014-03-24 08:54 1388544 ----a-w- c:\windows\SysWow64\msxml6.dll
2014-03-24 08:54 . 2014-03-24 08:54 1236992 ----a-w- c:\windows\SysWow64\msxml3.dll
2014-03-24 08:53 . 2014-03-24 08:53 46080 ----a-w- c:\windows\system32\atmlib.dll
2014-03-24 08:53 . 2014-03-24 08:53 367616 ----a-w- c:\windows\system32\atmfd.dll
2014-03-24 08:53 . 2014-03-24 08:53 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2014-03-24 08:53 . 2014-03-24 08:53 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2014-03-24 08:52 . 2014-03-24 08:52 2048 ----a-w- c:\windows\system32\tzres.dll
2014-03-24 08:52 . 2014-03-24 08:52 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2014-03-24 08:50 . 2014-03-24 08:50 478208 ----a-w- c:\windows\system32\dpnet.dll
2014-03-24 08:50 . 2014-03-24 08:50 376832 ----a-w- c:\windows\SysWow64\dpnet.dll
2014-03-24 08:49 . 2014-03-24 08:49 295792 ----a-w- c:\windows\system32\drivers\volsnap.sys
2014-03-24 08:48 . 2014-03-24 08:48 850944 ----a-w- c:\windows\system32\jscript.dll
2014-03-24 08:48 . 2014-03-24 08:48 609792 ----a-w- c:\windows\system32\vbscript.dll
2014-03-24 08:48 . 2014-03-24 08:48 428032 ----a-w- c:\windows\SysWow64\vbscript.dll
2014-03-24 08:48 . 2014-03-24 08:48 95744 ----a-w- c:\windows\system32\synceng.dll
2014-03-24 08:48 . 2014-03-24 08:48 78336 ----a-w- c:\windows\SysWow64\synceng.dll
2014-03-24 08:47 . 2014-03-24 08:47 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2014-03-24 08:47 . 2014-03-24 08:47 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2014-03-24 08:47 . 2014-03-24 08:47 744448 ----a-w- c:\windows\system32\WUDFx.dll
2014-03-24 08:47 . 2014-03-24 08:47 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2014-03-24 08:47 . 2014-03-24 08:47 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2014-03-24 08:47 . 2014-03-24 08:47 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2014-03-24 08:47 . 2014-03-24 08:47 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2014-03-24 08:42 . 2014-03-24 08:42 714752 ----a-w- c:\windows\system32\kerberos.dll
2014-03-24 08:42 . 2014-03-24 08:42 541184 ----a-w- c:\windows\SysWow64\kerberos.dll
2014-03-24 08:41 . 2014-03-24 08:41 182272 ----a-w- c:\windows\system32\cryptsvc.dll
2014-03-24 08:41 . 2014-03-24 08:41 1462784 ----a-w- c:\windows\system32\crypt32.dll
2014-03-24 08:41 . 2014-03-24 08:41 140288 ----a-w- c:\windows\system32\cryptnet.dll
2014-03-24 08:41 . 2014-03-24 08:41 139264 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2014-03-24 08:41 . 2014-03-24 08:41 1157632 ----a-w- c:\windows\SysWow64\crypt32.dll
2014-03-24 08:41 . 2014-03-24 08:41 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2014-03-24 08:41 . 2014-03-24 08:41 503808 ----a-w- c:\windows\system32\srcore.dll
2014-03-24 08:41 . 2014-03-24 08:41 43008 ----a-w- c:\windows\SysWow64\srclient.dll
2014-03-24 08:39 . 2014-03-24 08:39 73216 ----a-w- c:\windows\system32\netapi32.dll
2014-03-24 08:39 . 2014-03-24 08:39 58880 ----a-w- c:\windows\system32\browcli.dll
2014-03-24 08:39 . 2014-03-24 08:39 41472 ----a-w- c:\windows\SysWow64\browcli.dll
2014-03-24 08:39 . 2014-03-24 08:39 136704 ----a-w- c:\windows\system32\browser.dll
2014-03-24 08:39 . 2014-03-24 08:39 220160 ----a-w- c:\windows\system32\wintrust.dll
2014-03-24 08:39 . 2014-03-24 08:39 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2014-03-24 08:38 . 2014-03-24 08:38 574464 ----a-w- c:\windows\system32\d3d10level9.dll
2014-03-24 08:38 . 2014-03-24 08:38 490496 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2014-03-24 08:38 . 2014-03-24 08:38 956416 ----a-w- c:\windows\system32\localspl.dll
2014-03-24 08:37 . 2014-03-24 08:37 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2014-03-24 08:37 . 2014-03-24 08:37 95088 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2014-03-24 08:37 . 2014-03-24 08:37 459216 ----a-w- c:\windows\system32\drivers\cng.sys
2014-03-24 08:37 . 2014-03-24 08:37 340992 ----a-w- c:\windows\system32\schannel.dll
2014-03-24 08:37 . 2014-03-24 08:37 225280 ----a-w- c:\windows\SysWow64\schannel.dll
2014-03-24 08:37 . 2014-03-24 08:37 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2014-03-24 08:37 . 2014-03-24 08:37 152432 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2014-03-24 08:37 . 2014-03-24 08:37 14165504 ----a-w- c:\windows\system32\shell32.dll
2014-03-24 08:36 . 2014-03-24 08:36 987136 ----a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll
2014-03-24 08:36 . 2014-03-24 08:36 1425408 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
2014-03-24 08:35 . 2014-03-24 08:35 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe
2014-03-24 08:35 . 2014-03-24 08:35 76288 ----a-w- c:\windows\system32\rdpwsx.dll
2014-03-24 08:35 . 2014-03-24 08:35 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll
2014-03-24 08:35 . 2014-03-24 08:35 204800 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2014-03-24 08:35 . 2014-03-24 08:35 208896 ----a-w- c:\windows\system32\profsvc.dll
2014-03-24 08:34 . 2014-03-24 08:34 3213824 ----a-w- c:\windows\system32\msi.dll
2014-03-24 08:34 . 2014-03-24 08:34 2342400 ----a-w- c:\windows\SysWow64\msi.dll
2014-03-24 08:33 . 2014-03-24 08:33 75632 ----a-w- c:\windows\system32\drivers\partmgr.sys
2014-03-24 08:33 . 2014-03-24 08:33 294912 ----a-w- c:\windows\system32\browserchoice.exe
2014-03-24 08:29 . 2014-03-24 08:29 902656 ----a-w- c:\windows\system32\d2d1.dll
2014-03-24 08:29 . 2014-03-24 08:29 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2014-03-24 08:29 . 2014-03-24 08:29 320512 ----a-w- c:\windows\system32\d3d10_1core.dll
2014-03-24 08:29 . 2014-03-24 08:29 218624 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2014-03-24 08:29 . 2014-03-24 08:29 197120 ----a-w- c:\windows\system32\d3d10_1.dll
2014-03-24 08:29 . 2014-03-24 08:29 1837568 ----a-w- c:\windows\system32\d3d10warp.dll
2014-03-24 08:29 . 2014-03-24 08:29 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2014-03-24 08:29 . 2014-03-24 08:29 1541120 ----a-w- c:\windows\system32\DWrite.dll
2014-03-24 08:29 . 2014-03-24 08:29 1170944 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2014-03-24 08:29 . 2014-03-24 08:29 1074176 ----a-w- c:\windows\SysWow64\DWrite.dll
2014-03-24 08:28 . 2014-03-24 08:28 80896 ----a-w- c:\windows\system32\imagehlp.dll
2014-03-24 08:28 . 2014-03-24 08:28 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2014-03-24 08:28 . 2014-03-24 08:28 5120 ----a-w- c:\windows\system32\wmi.dll
2014-03-24 08:28 . 2014-03-24 08:28 22896 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2014-03-24 08:28 . 2014-03-24 08:28 158720 ----a-w- c:\windows\SysWow64\imagehlp.dll
2014-03-24 08:16 . 2014-03-24 08:16 826368 ----a-w- c:\windows\SysWow64\rdpcore.dll
2014-03-24 08:16 . 2014-03-24 08:16 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-24 09:07 . 2014-03-24 09:07 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2014-03-24 08:49 . 2014-03-24 08:49 559104 ----a-w- c:\windows\apppatch\AcLayers.dll
2014-03-24 08:49 . 2014-03-24 08:49 347648 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2014-03-24 08:49 . 2014-03-24 08:49 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2014-03-24 08:37 . 2014-03-24 08:37 340992 ----a-w- c:\windows\system32\schannel.dll
2014-03-24 08:37 . 2014-03-24 08:37 225280 ----a-w- c:\windows\SysWow64\schannel.dll
2014-03-24 07:50 . 2014-03-24 07:50 285696 ----a-w- c:\windows\system32\schtasks.exe
2014-03-24 07:50 . 2014-03-24 07:50 179712 ----a-w- c:\windows\SysWow64\schtasks.exe
2014-03-24 07:50 . 2014-03-24 07:50 1114624 ----a-w- c:\windows\system32\schedsvc.dll
2014-03-24 00:06 . 2013-11-22 22:12 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2014-03-19 09:35 . 2013-12-19 17:23 214392 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-03-19 09:21 . 2013-12-19 17:23 214392 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-03-18 18:34 . 2013-12-19 18:16 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-03-12 12:56 . 2013-11-22 22:29 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-03-12 12:56 . 2013-11-22 22:29 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-03-04 14:35 . 2014-02-20 06:41 15783992 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2014-03-04 14:35 . 2013-11-22 22:36 62408 ----a-w- c:\windows\system32\OpenCL.dll
2014-03-04 14:35 . 2013-11-22 22:36 54216 ----a-w- c:\windows\SysWow64\OpenCL.dll
2014-03-04 14:35 . 2013-11-22 22:34 947808 ----a-w- c:\windows\system32\nvumdshimx.dll
2014-03-04 14:35 . 2013-11-22 22:34 3093280 ----a-w- c:\windows\system32\nvapi64.dll
2014-03-04 14:35 . 2013-11-22 22:34 2715264 ----a-w- c:\windows\SysWow64\nvapi.dll
2014-03-04 14:35 . 2013-11-22 22:34 14709720 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2014-03-04 13:06 . 2013-11-22 22:36 6714312 ----a-w- c:\windows\system32\nvcpl.dll
2014-03-04 13:06 . 2013-11-22 22:36 3497816 ----a-w- c:\windows\system32\nvsvc64.dll
2014-03-04 13:05 . 2014-01-08 23:29 2558808 ----a-w- c:\windows\system32\nvsvcr.dll
2014-03-04 13:05 . 2013-11-22 22:36 922968 ----a-w- c:\windows\system32\nvvsvc.exe
2014-03-04 13:05 . 2013-11-22 22:36 64968 ----a-w- c:\windows\system32\nvshext.dll
2014-03-04 13:05 . 2013-11-22 22:36 386336 ----a-w- c:\windows\system32\nvmctray.dll
2014-03-04 13:05 . 2013-11-22 22:36 3649185 ----a-w- c:\windows\system32\nvcoproc.bin
2014-02-08 18:34 . 2014-02-20 06:41 1885472 ----a-w- c:\windows\system32\nvdispco6433489.dll
2014-02-08 18:34 . 2014-02-20 06:41 1515296 ----a-w- c:\windows\system32\nvdispgenco6433489.dll
2014-02-05 09:31 . 2013-12-03 12:07 1048152 ----a-w- c:\windows\SysWow64\nvspcap.dll
2014-02-05 09:30 . 2013-12-03 12:07 1179576 ----a-w- c:\windows\system32\nvspcap64.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[-] 2013-11-22 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7600.16385] .. c:\windows\system32\user32.dll
.
[-] 2013-11-22 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7600.16385] .. c:\windows\SysWOW64\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files (x86)\BS_Player_ControlBar\prxtbBS_P.dll" [2013-11-06 226592]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2013-11-06 16:53 226592 ----a-w- c:\program files (x86)\BS_Player_ControlBar\prxtbBS_P.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files (x86)\BS_Player_ControlBar\prxtbBS_P.dll" [2013-11-06 226592]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2013-11-22 39408]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
"uTorrent"="c:\users\admin\AppData\Roaming\uTorrent\uTorrent.exe" [2014-01-26 905296]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2014-02-20 6161176]
"Advanced SystemCare 7"="d:\program files\Advanced SystemCare 7\ASCTray.exe" [2014-02-11 2288928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2012-02-29 56088]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-05-22 291648]
"Adobe Updater"="c:\programdata\adobe\color.vbs" [2013-12-11 101]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2014-02-26 3814736]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Cloud Panel.lnk - c:\users\admin\AppData\Roaming\CloudPanel\CloudPanelLauncher.exe [2014-3-22 828416]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 ArcService;Arc Service;d:\program files\Perfect World Entertainment\Arc\ArcService.exe;d:\program files\Perfect World Entertainment\Arc\ArcService.exe [x]
R3 BRDriver64;BRDriver64;c:\programdata\BitRaider\BRDriver64.sys;c:\programdata\BitRaider\BRDriver64.sys [x]
R3 BRSptSvc;BitRaider Mini-Support Service;c:\programdata\BitRaider\BRSptSvc.exe;c:\programdata\BitRaider\BRSptSvc.exe [x]
R3 cpuz136;cpuz136;c:\windows\TEMP\cpuz136\cpuz136_x64.sys;c:\windows\TEMP\cpuz136\cpuz136_x64.sys [x]
R3 FairplayKD;FairplayKD;c:\programdata\MTA San Andreas All\Common\temp\FairplayKD.sys;c:\programdata\MTA San Andreas All\Common\temp\FairplayKD.sys [x]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [x]
R3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x]
R3 OSFMount;OSFMount;d:\program files\Counter-Strike Global Offensive\image\x64\OSFMount.sys;d:\program files\Counter-Strike Global Offensive\image\x64\OSFMount.sys [x]
R3 WatAdminSvc;WatAdminSvc;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 X6va016;X6va016;c:\windows\SysWOW64\Drivers\X6va016;c:\windows\SysWOW64\Drivers\X6va016 [x]
S0 iusb3hcs;Ovládač prepínača hostiteľského radiča Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S2 AdvancedSystemCareService7;Advanced SystemCare Service 7;d:\program files\Advanced SystemCare 7\ASCService.exe;d:\program files\Advanced SystemCare 7\ASCService.exe [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [x]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfpr.sys [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 SplashtopRemoteService;Splashtop® Remote Service;c:\program files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe;c:\program files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe [x]
S2 SSUService;Splashtop Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe;c:\program files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 iusb3hub;Ovládač rozbočovača Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Ovládač hostiteľského radiča Intel(R) USB 3.0 eXtensible;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTCore64;RTCore64;c:\program files (x86)\EVGA Precision X\RTCore64.sys;c:\program files (x86)\EVGA Precision X\RTCore64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MBAMSWISSARMY
*NewlyCreated* - RTCORE64
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-03-15 15:54 1150280 ----a-w- c:\program files (x86)\Google\Chrome\Application\33.0.1750.154\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-04-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-22 12:56]
.
2014-04-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-11-22 22:32]
.
2014-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-11-22 22:32]
.
2014-04-02 c:\windows\Tasks\SlimDrivers Startup.job
- c:\program files (x86)\SlimDrivers\SlimDrivers.exe [2013-09-24 11:49]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
2014-03-23 23:56 2471744 ----a-w- d:\program files\IObit Uninstaller\UninstallExplorer64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-11-04 2919168]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2000-01-01 7204568]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-02-05 2234144]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-02-05 1179576]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va016]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va016"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-525872782-3713464005-3976650588-1000\Software\SecuROM\License information*]
"datasecu"=hex:b2,c3,4e,12,d4,aa,dd,40,f4,ec,34,b2,5f,30,a0,a3,48,ed,4b,70,96,
89,2e,b0,37,3f,50,65,bf,da,80,13,8a,18,47,ea,5e,cb,71,02,9c,45,b2,1f,e7,e2,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.12"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\ESET\ESET Security\CurrentVersion\Info]
@Denied: (2) (LocalSystem)
"AppDataDir"="c:\\ProgramData\\ESET\\ESET NOD32 Antivirus\\"
"DataDir"="ESET\\ESET NOD32 Antivirus\\"
"EditionName"=" "
"InstallDir"="c:\\Program Files\\ESET\\ESET NOD32 Antivirus\\"
"LanguageId"=dword:0000041b
"PackageTag"=dword:6090e758
"ProductBase"=dword:00000000
"ProductCode"="{1B2BD098-29D4-4752-81A2-CBFB8758ABC1}"
"ProductName"="ESET NOD32 Antivirus"
"ProductType"="eav"
"ProductVersion"="4.2.67.10"
"UniqueId"="000656D6528FD94F"
"ScannerBuild"=dword:00001fb8
"ScannerVersionId"=dword:000015d8
"ScannerVersion"="Locked/open ESET for status."
"ei2"=hex(b):bc,23,bf,9b,92,1e,4d,2a
"ei1"=hex(b):ac,22,0b,73,5d,8d,00,00
"ei3"=hex(b):7c,d9,8f,52,00,00,00,00
"ei4"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2014-04-02 10:41:29
ComboFix-quarantined-files.txt 2014-04-02 08:41
ComboFix2.txt 2014-04-01 21:28
ComboFix3.txt 2014-04-01 19:55
.
Pre-Run: 35 884 490 752 bytes free
Post-Run: 35 583 119 360 bytes free
.
- - End Of File - - D69DE6CD36CC7B50E8A64FF034AEA335