Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 15-07-23.01 - Caleb 07/25/2015 0:43.1.8 - x64
- Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.16279.13213 [GMT -4:00]
- Running from: c:\users\Caleb\Downloads\ComboFix.exe
- AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
- SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
- SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- C:\install.exe
- c:\programdata\PCDr\6664\AddOnDownloaded\2c507aa3-5c72-4011-b9e1-3928beb6f336.dll
- c:\programdata\PCDr\6664\AddOnDownloaded\5d59ed02-c0da-4e0e-8811-16a3d0b6a87d.dll
- c:\programdata\PCDr\6664\AddOnDownloaded\964840d8-cf70-45c0-a3db-802e021f9658.dll
- c:\programdata\PCDr\6664\AddOnDownloaded\9b664440-a1fb-457f-a208-c519fea54f87.dll
- c:\programdata\PCDr\6664\AddOnDownloaded\9bf708b5-617d-4352-8ecd-ff95912dcb95.dll
- c:\programdata\PCDr\6664\AddOnDownloaded\bb97e28d-bdfb-4fa4-902d-264275c5cb1b.dll
- c:\windows\SysWow64\Packet.dll
- c:\windows\SysWow64\wpcap.dll
- .
- Infected copy of c:\windows\SysWow64\Version.dll was found and disinfected
- Restored copy from - c:\windows\winsxs\x86_microsoft-windows-version_31bf3856ad364e35_6.1.7600.16385_none_14d4a552b2395165\version.dll
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- -------\Service_NPF
- .
- .
- ((((((((((((((((((((((((( Files Created from 2015-06-25 to 2015-07-25 )))))))))))))))))))))))))))))))
- .
- .
- 2015-07-25 04:52 . 2015-07-25 04:52 8782 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS
- 2015-07-25 04:50 . 2015-07-25 04:50 -------- d-----w- c:\users\Default\AppData\Local\temp
- 2015-07-25 04:41 . 2015-07-25 04:41 -------- d-----w- C:\AdwCleaner
- 2015-07-24 17:56 . 2015-07-24 17:56 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{02442E57-5F7B-4704-AD31-F146068A695A}\offreg.2848.dll
- 2015-07-23 20:35 . 2015-07-23 20:35 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{02442E57-5F7B-4704-AD31-F146068A695A}\offreg.6676.dll
- 2015-07-22 17:49 . 2015-07-22 17:49 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{02442E57-5F7B-4704-AD31-F146068A695A}\offreg.6252.dll
- 2015-07-22 17:25 . 2015-07-22 17:25 -------- d-----w- c:\users\Caleb\AppData\Local\CEF
- 2015-07-21 20:39 . 2015-07-21 20:39 -------- d-----w- c:\users\Caleb\AppData\Roaming\Trove
- 2015-07-21 05:01 . 2015-07-21 05:01 -------- d-----w- c:\program files\CCleaner
- 2015-07-21 04:29 . 2015-07-21 04:29 -------- d-----w- c:\windows\SysWow64\NV
- 2015-07-21 04:29 . 2015-07-21 04:29 -------- d-----w- c:\windows\system32\NV
- 2015-07-21 04:24 . 2015-07-03 04:28 47976 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
- 2015-07-21 04:24 . 2015-07-03 04:28 65896 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
- 2015-07-20 17:14 . 2015-07-20 17:14 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{02442E57-5F7B-4704-AD31-F146068A695A}\offreg.7076.dll
- 2015-07-19 06:51 . 2015-06-25 18:09 814280 ----a-w- c:\program files\Internet Explorer\iexplore.exe
- 2015-07-19 06:48 . 2015-05-09 18:26 493504 ----a-w- c:\windows\system32\mcupdate_GenuineIntel.dll
- 2015-07-19 00:50 . 2015-07-19 06:46 -------- d-----w- c:\program files (x86)\Armadillo Run Demo
- 2015-07-18 16:44 . 2015-06-12 07:50 12221144 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{02442E57-5F7B-4704-AD31-F146068A695A}\mpengine.dll
- 2015-07-15 19:34 . 2015-07-15 19:34 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
- 2015-07-15 03:24 . 2015-07-15 03:24 18524336 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
- 2015-07-14 15:01 . 2015-07-14 15:01 -------- d-----w- c:\users\Caleb\AppData\Local\Targem
- 2015-07-13 23:49 . 2015-07-14 00:00 -------- d-----w- c:\programdata\Gyazo
- 2015-07-07 07:46 . 2015-07-07 07:46 189136 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\OFFICE15\LICLUA.EXE
- .
- .
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2015-07-25 04:19 . 2014-07-14 01:30 136408 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
- 2015-07-15 03:24 . 2013-06-11 04:45 778416 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
- 2015-07-15 03:24 . 2013-06-11 04:45 142512 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
- 2015-07-14 19:06 . 2013-11-04 01:56 1423120 ----a-w- c:\windows\SysWow64\nvspcap.dll
- 2015-07-14 19:06 . 2014-11-09 08:18 1316184 ----a-w- c:\windows\SysWow64\nvspbridge.dll
- 2015-07-14 19:05 . 2014-11-09 08:18 1756424 ----a-w- c:\windows\system32\nvspbridge64.dll
- 2015-07-14 19:05 . 2013-11-04 01:56 1710056 ----a-w- c:\windows\system32\nvspcap64.dll
- 2015-07-14 15:44 . 2013-08-27 19:09 33856 ---ha-w- c:\windows\system32\hamachi.sys
- 2015-07-03 12:43 . 2013-06-15 18:11 130333168 ----a-w- c:\windows\system32\MRT.exe
- 2015-07-03 04:28 . 2013-11-04 01:54 69992 ----a-w- c:\windows\system32\nvaudcap64v.dll
- 2015-06-23 17:30 . 2010-11-21 03:27 300704 ------w- c:\windows\system32\MpSigStub.exe
- 2015-06-17 09:10 . 2015-02-22 05:53 15866992 ----a-w- c:\windows\system32\nvd3dumx.dll
- 2015-06-17 09:10 . 2014-04-27 02:13 1567576 ----a-w- c:\windows\system32\nvhdagenco6420103.dll
- 2015-06-17 09:10 . 2013-08-27 12:53 938752 ----a-w- c:\windows\SysWow64\nvumdshim.dll
- 2015-06-17 09:10 . 2013-06-11 06:18 17724600 ----a-w- c:\windows\system32\nvwgf2umx.dll
- 2015-06-17 09:10 . 2013-06-11 06:18 1099992 ----a-w- c:\windows\system32\nvumdshimx.dll
- 2015-06-17 09:10 . 2013-06-11 06:18 176904 ----a-w- c:\windows\system32\nvinitx.dll
- 2015-06-17 09:10 . 2013-06-11 06:18 155280 ----a-w- c:\windows\SysWow64\nvinit.dll
- 2015-06-17 09:10 . 2013-06-11 06:18 12855416 ----a-w- c:\windows\SysWow64\nvd3dum.dll
- 2015-06-17 09:10 . 2013-06-11 06:17 3395648 ----a-w- c:\windows\system32\nvapi64.dll
- 2015-06-17 09:10 . 2013-06-11 06:17 2997544 ----a-w- c:\windows\SysWow64\nvapi.dll
- 2015-06-17 06:48 . 2013-06-11 06:37 937616 ----a-w- c:\windows\system32\nvvsvc.exe
- 2015-06-17 06:48 . 2013-06-11 06:37 74896 ----a-w- c:\windows\system32\nv3dappshextr.dll
- 2015-06-17 06:48 . 2013-06-11 06:37 62792 ----a-w- c:\windows\system32\nvshext.dll
- 2015-06-17 06:48 . 2013-06-11 06:37 385168 ----a-w- c:\windows\system32\nvmctray.dll
- 2015-06-17 06:48 . 2013-06-11 06:37 2558792 ----a-w- c:\windows\system32\nvsvcr.dll
- 2015-06-17 06:48 . 2013-06-11 06:37 1059472 ----a-w- c:\windows\system32\nv3dappshext.dll
- 2015-06-17 06:48 . 2013-06-11 06:37 6873232 ----a-w- c:\windows\system32\nvcpl.dll
- 2015-06-17 06:48 . 2013-06-11 06:37 3492168 ----a-w- c:\windows\system32\nvsvc64.dll
- 2015-06-09 10:51 . 2014-10-27 20:22 627920 ----a-w- c:\programdata\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe
- 2015-06-02 14:11 . 2013-06-11 06:37 4421614 ----a-w- c:\windows\system32\nvcoproc.bin
- 2015-05-25 18:01 . 2015-07-19 06:51 44032 ----a-w- c:\windows\apppatch\acwow64.dll
- 2015-05-01 13:17 . 2015-05-14 03:21 124112 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
- 2015-05-01 13:16 . 2015-05-14 03:21 102608 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
- .
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
- @="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
- [HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
- 2015-06-16 14:08 1730264 ----a-w- c:\program files\Microsoft Office 15\root\office15\grooveex.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
- @="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
- [HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
- 2015-06-16 14:08 1730264 ----a-w- c:\program files\Microsoft Office 15\root\office15\grooveex.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
- @="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
- [HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
- 2015-06-16 14:08 1730264 ----a-w- c:\program files\Microsoft Office 15\root\office15\grooveex.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
- @="{C5994560-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
- 2011-06-13 15:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
- @="{C5994561-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
- 2011-06-13 15:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
- @="{C5994562-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
- 2011-06-13 15:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
- @="{C5994563-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
- 2011-06-13 15:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
- @="{C5994564-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
- 2011-06-13 15:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
- @="{C5994565-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
- 2011-06-13 15:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
- @="{C5994566-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
- 2011-06-13 15:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
- @="{C5994567-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
- 2011-06-13 15:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
- @="{C5994568-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
- 2011-06-13 15:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
- .
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "Steam"="c:\program files (x86)\Steam\steam.exe" [2015-07-23 2895552]
- "WhatPulse"="c:\program files (x86)\WhatPulse2\whatpulse.exe" [2014-12-08 3563520]
- "Akamai NetSession Interface"="c:\users\Caleb\AppData\Local\Akamai\netsession_win.exe" [2014-10-30 4673432]
- "GoogleChromeAutoLaunch_36965A81DD909523F7BF6769949A7463"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2015-07-13 813896]
- "CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2015-06-01 8358680]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
- "RUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe" [2011-09-20 115048]
- "Alienware Survey"="c:\program files (x86)\Alienware Customer Surveys\AlienSurvey.exe" [2013-03-09 7390264]
- "EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2013-03-28 1058880]
- "amd_dc_opt"="c:\program files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
- "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-11-04 5223016]
- "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2015-07-14 5579624]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
- "ConsentPromptBehaviorAdmin"= 5 (0x5)
- "ConsentPromptBehaviorUser"= 3 (0x3)
- "EnableUIADesktopToggle"= 0 (0x0)
- "SoftwareSASGeneration"= 1 (0x1)
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
- "LoadAppInit_DLLs"=1 (0x1)
- "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll c:\windows\SysWOW64\nvinit.dll c:\windows\SysWOW64\nvinit.dll
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
- @=""
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
- "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
- "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
- "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
- "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
- .
- R2 AlienFusionService;Alienware Fusion Service;c:\program files\Alienware\Command Center\AlienFusionService.exe;c:\program files\Alienware\Command Center\AlienFusionService.exe [x]
- R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
- R2 DellDataVault;Dell Data Vault;c:\program files\Dell\DellDataVault\DellDataVault.exe ;c:\program files\Dell\DellDataVault\DellDataVault.exe [x]
- R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
- R3 DDDriver;DDDriver;c:\windows\system32\drivers\DDDriver64Dcsa.sys;c:\windows\SYSNATIVE\drivers\DDDriver64Dcsa.sys [x]
- R3 DellProf;DellProf;c:\windows\system32\drivers\DellProf.sys;c:\windows\SYSNATIVE\drivers\DellProf.sys [x]
- R3 EasyAntiCheat;EasyAntiCheat;c:\windows\system32\EasyAntiCheat.exe;c:\windows\SYSNATIVE\EasyAntiCheat.exe [x]
- R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
- R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
- R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
- R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
- R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
- R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
- R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
- R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
- R4 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
- R4 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\drivers\nvstusb.sys;c:\windows\SYSNATIVE\drivers\nvstusb.sys [x]
- S0 aswRvrt;avast! Revert; [x]
- S0 aswVmm;avast! VM Monitor; [x]
- S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
- S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
- S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [x]
- S2 AlienFXWindowsService;AlienFXWindowsService;c:\program files\Alienware\Command Center\AlienFXWindowsService.exe;c:\program files\Alienware\Command Center\AlienFXWindowsService.exe [x]
- S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
- S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
- S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
- S2 ClickToRunSvc;Microsoft Office ClickToRun Service;c:\program files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe;c:\program files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [x]
- S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
- S2 EpsonCustomerParticipation;EpsonCustomerParticipation;c:\program files\EPSON\EpsonCustomerParticipation\EPCP.exe;c:\program files\EPSON\EpsonCustomerParticipation\EPCP.exe [x]
- S2 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\EscSvc64.exe;c:\windows\SYSNATIVE\EscSvc64.exe [x]
- S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
- S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
- S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
- S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
- S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
- S2 MSI_ODD_Service;MSI_ODD_Service;c:\program files (x86)\msi\ODD Monitor\ODD_Monitor.exe;c:\program files (x86)\msi\ODD Monitor\ODD_Monitor.exe [x]
- S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
- S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [x]
- S2 Razer Game Scanner Service;Razer Game Scanner;c:\program files (x86)\Razer\Razer Services\GSS\GameScannerService.exe;c:\program files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [x]
- S2 RtkAudioService;Realtek Audio Service;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe [x]
- S2 rzpmgrk;rzpmgrk;c:\windows\system32\drivers\rzpmgrk.sys;c:\windows\SYSNATIVE\drivers\rzpmgrk.sys [x]
- S2 rzpnk;rzpnk;c:\windows\system32\drivers\rzpnk.sys;c:\windows\SYSNATIVE\drivers\rzpnk.sys [x]
- S2 SftService;SoftThinks Agent Service;c:\program files (x86)\AlienRespawn\sftservice.EXE;c:\program files (x86)\AlienRespawn\sftservice.EXE [x]
- S2 SupportAssistAgent;Dell SupportAssist Agent;c:\program files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe;c:\program files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [x]
- S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
- S2 VBoxAswDrv;VBoxAsw Support Driver;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [x]
- S2 ZAtheros Wlan Agent;ZAtheros Wlan Agent;c:\program files (x86)\Dell Wireless\Ath_WlanAgent.exe;c:\program files (x86)\Dell Wireless\Ath_WlanAgent.exe [x]
- S3 AvastVBoxSvc;AvastVBox COM Service;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [x]
- S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
- S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
- S3 NTIOLib_X64;NTIOLib_X64;c:\program files (x86)\msi\ODD Monitor\NTIOLib_X64.sys;c:\program files (x86)\msi\ODD Monitor\NTIOLib_X64.sys [x]
- S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
- S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
- S3 rusb3hub;Renesas Electronics USB 3.0 Hub Driver (Version 3.0);c:\windows\system32\DRIVERS\rusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\rusb3hub.sys [x]
- S3 rusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver (Version 3.0);c:\windows\system32\DRIVERS\rusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\rusb3xhc.sys [x]
- .
- .
- --- Other Services/Drivers In Memory ---
- .
- *NewlyCreated* - WS2IFSL
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
- 2015-07-14 15:38 991048 ----a-w- c:\program files (x86)\Google\Chrome\Application\43.0.2357.134\Installer\chrmstp.exe
- .
- Contents of the 'Scheduled Tasks' folder
- .
- 2015-07-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-11 03:24]
- .
- 2015-07-25 c:\windows\Tasks\EPSON XP-410 Series Invitation {08C5BE64-69A3-44A8-8043-188E2CE1418E}.job
- - c:\windows\system32\spool\DRIVERS\x64\3\E_ITSLAE.EXE [2013-10-16 05:20]
- .
- 2015-07-25 c:\windows\Tasks\EPSON XP-410 Series Update {08C5BE64-69A3-44A8-8043-188E2CE1418E}.job
- - c:\windows\system32\spool\DRIVERS\x64\3\E_ITSLAE.EXE [2013-10-16 05:20]
- .
- 2015-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-24 23:52]
- .
- 2015-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-24 23:52]
- .
- 2015-07-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3232754702-2565239759-2421808633-1001Core.job
- - c:\users\Caleb\AppData\Local\Google\Update\GoogleUpdate.exe [2013-09-04 23:47]
- .
- 2015-07-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3232754702-2565239759-2421808633-1001UA.job
- - c:\users\Caleb\AppData\Local\Google\Update\GoogleUpdate.exe [2013-09-04 23:47]
- .
- .
- --------- X64 Entries -----------
- .
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
- @="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
- [HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
- 2015-06-16 14:59 2335448 ----a-w- c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
- @="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
- [HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
- 2015-06-16 14:59 2335448 ----a-w- c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
- @="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
- [HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
- 2015-06-16 14:59 2335448 ----a-w- c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"]
- @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
- 2015-05-05 03:08 184856 ----a-w- c:\users\Caleb\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"]
- @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
- 2015-05-05 03:08 184856 ----a-w- c:\users\Caleb\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"]
- @="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
- 2015-05-05 03:08 184856 ----a-w- c:\users\Caleb\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"]
- @="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
- 2015-05-05 03:08 184856 ----a-w- c:\users\Caleb\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"]
- @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
- 2015-05-05 03:08 184856 ----a-w- c:\users\Caleb\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"]
- @="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
- 2015-05-05 03:08 184856 ----a-w- c:\users\Caleb\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"]
- @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
- 2015-05-05 03:08 184856 ----a-w- c:\users\Caleb\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"]
- @="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
- 2015-05-05 03:08 184856 ----a-w- c:\users\Caleb\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
- @="{472083B0-C522-11CF-8763-00608CC02F24}"
- [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
- 2014-10-25 17:26 860984 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
- @="{C5994560-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
- 2011-06-13 15:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
- @="{C5994561-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
- 2011-06-13 15:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
- @="{C5994562-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
- 2011-06-13 15:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
- @="{C5994563-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
- 2011-06-13 15:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
- @="{C5994564-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
- 2011-06-13 15:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
- @="{C5994565-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
- 2011-06-13 15:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
- @="{C5994566-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
- 2011-06-13 15:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
- @="{C5994567-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
- 2011-06-13 15:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
- @="{C5994568-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
- 2011-06-13 15:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2014-12-11 7666392]
- "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2014-12-11 1391472]
- "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-14 172144]
- "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-12-14 399984]
- "Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-14 441968]
- "ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2015-07-14 1710056]
- "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2015-07-14 2631824]
- "Launch Keyboard CI"="c:\program files\Alienware\Alienware TactX Keyboard CI\txkbci.exe" [2012-07-11 3439928]
- "Command Center Controllers"="c:\program files\Alienware\Command Center\AWCCStartupOrchestrator.exe" [2012-07-25 12656]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
- "AppInit_DLLs"=c:\windows\System32\nvinitx.dll
- .
- ------- Supplementary Scan -------
- .
- uLocal Page = c:\windows\system32\blank.htm
- uStart Page = hxxp://www.google.com/
- mLocal Page = c:\windows\SysWOW64\blank.htm
- uInternet Settings,ProxyOverride = *.local;<local>
- IE: E&xport to Microsoft Excel - c:\program files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
- IE: Se&nd to OneNote - c:\program files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
- Trusted Zone: clonewarsadventures.com
- Trusted Zone: dell.com
- Trusted Zone: freerealms.com
- Trusted Zone: sharepoint.com\wvk12
- Trusted Zone: sharepoint.com\wvk12-my
- Trusted Zone: soe.com
- Trusted Zone: sony.com
- Trusted Zone: vizzed.com\www
- TCP: Interfaces\{6FE99A6E-6012-4547-9371-BE7AAE4BDD2E}: NameServer = 8.8.8.8,8.8.4.4
- .
- - - - - ORPHANS REMOVED - - - -
- .
- Toolbar-Locked - (no file)
- HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
- Toolbar-Locked - (no file)
- AddRemove-GameStop App - c:\programdata\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\GameStopApp_setup.exe
- AddRemove-{2E55EEFD-2162-4A7D-9158-EDB0305603A6} - c:\programdata\{6AACA38B-2810-4B47-BDEC-D7A1F38B1531}\DDV.exe
- AddRemove-{EA450D5D-95EA-4FD0-B8B0-6D8E68FBE2C7} - c:\programdata\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\GameStopApp_setup.exe
- .
- .
- .
- --------------------- LOCKED REGISTRY KEYS ---------------------
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
- @Denied: (A 2) (Everyone)
- @="FlashBroker"
- "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_18_0_0_209_ActiveX.exe,-101"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
- "Enabled"=dword:00000001
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
- @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_18_0_0_209_ActiveX.exe"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
- @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
- @Denied: (A 2) (Everyone)
- @="IFlashBroker6"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
- @="{00020424-0000-0000-C000-000000000046}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
- @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
- "Version"="1.0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
- @Denied: (A 2) (Everyone)
- @="FlashBroker"
- "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_18_0_0_209_ActiveX.exe,-101"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
- "Enabled"=dword:00000001
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_18_0_0_209_ActiveX.exe"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
- @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
- @Denied: (A 2) (Everyone)
- @="Shockwave Flash Object"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_209.ocx"
- "ThreadingModel"="Apartment"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
- @="0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
- @="ShockwaveFlash.ShockwaveFlash.18"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_209.ocx, 1"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
- @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
- @="1.0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
- @="ShockwaveFlash.ShockwaveFlash"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
- @Denied: (A 2) (Everyone)
- @="Macromedia Flash Factory Object"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_209.ocx"
- "ThreadingModel"="Apartment"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
- @="FlashFactory.FlashFactory.1"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_209.ocx, 1"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
- @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
- @="1.0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
- @="FlashFactory.FlashFactory"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
- @Denied: (A 2) (Everyone)
- @="IFlashBroker6"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
- @="{00020424-0000-0000-C000-000000000046}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
- @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
- "Version"="1.0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
- @Denied: (A) (Everyone)
- "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
- @Denied: (A) (Everyone)
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
- "Key"="ActionsPane3"
- "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
- @Denied: (Full) (Everyone)
- .
- ------------------------ Other Running Processes ------------------------
- .
- c:\program files\AVAST Software\Avast\AvastSvc.exe
- c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
- c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
- c:\program files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler.exe
- c:\windows\SysWOW64\PnkBstrA.exe
- c:\program files (x86)\AlienRespawn\TOASTER.EXE
- c:\program files (x86)\AlienRespawn\COMPONENTS\SCHEDULER\STSERVICE.EXE
- c:\program files (x86)\AlienRespawn\Components\DSUpdate\DSUpd.exe
- c:\program files (x86)\TeamViewer\TeamViewer_Service.exe
- c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
- .
- **************************************************************************
- .
- Completion time: 2015-07-25 00:58:09 - machine was rebooted
- ComboFix-quarantined-files.txt 2015-07-25 04:58
- .
- Pre-Run: 699,681,320,960 bytes free
- Post-Run: 700,174,364,672 bytes free
- .
- - - End Of File - - CCB77F21552363892B17636C578A9C57
- 5C616939100B85E558DA92B899A0FC36
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement