Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 16-07-10.01 - Tim's 07/14/2016 19:58:39.1.8 - x64
- Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8136.3741 [GMT -5:00]
- Running from: T:\ComboFix.exe
- AV: Kaspersky Total Security *Enabled/Updated* {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
- FW: Kaspersky Total Security *Enabled* {BE0DF4B4-018B-AF50-0486-D6FE7C8A8AE3}
- SP: Kaspersky Total Security *Enabled/Updated* {3D579475-6DDE-A186-1569-44B9F9DE8725}
- SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- B:\Autorun.inf
- C:\Autorun.inf
- c:\programdata\ntuser.pol
- c:\users\Tim's\Media
- c:\users\Tim's\Media\Movies\Kiki's Delivery Service (2014)\Kiki's Delivery Service (2014).mkv
- c:\users\Tim's\Media\Movies\Princess Mononoke (1997)\Princess Mononoke (1997).mkv
- D:\Autorun.inf
- F:\Autorun.inf
- G:\Autorun.inf
- N:\Autorun.inf
- O:\Autorun.inf
- P:\Autorun.inf
- Q:\Autorun.inf
- R:\Autorun.inf
- S:\Autorun.inf
- T:\Autorun.inf
- T:\Update.exe
- U:\Autorun.inf
- V:\Autorun.inf
- W:\Autorun.inf
- .
- Infected copy of c:\windows\SysWow64\kernel32.dll was found and disinfected
- Restored copy from - c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.23418_none_fcc60199ba661304\kernel32.dll
- .
- .
- ((((((((((((((((((((((((( Files Created from 2016-06-15 to 2016-07-15 )))))))))))))))))))))))))))))))
- .
- .
- 2016-07-15 01:31 . 2016-07-15 01:31 -------- d-----w- c:\users\Default\AppData\Local\temp
- 2016-07-13 11:01 . 2016-07-13 11:01 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{46A68604-A5B2-4CC2-9BD7-A7D880869CBF}\offreg.3660.dll
- 2016-07-13 09:01 . 2016-06-26 00:27 756736 ----a-w- c:\windows\system32\win32spl.dll
- 2016-07-12 12:11 . 2016-06-21 22:04 12007136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{46A68604-A5B2-4CC2-9BD7-A7D880869CBF}\mpengine.dll
- 2016-07-09 02:10 . 2016-07-09 02:10 -------- d-----w- c:\users\Tim's\.filebot
- 2016-07-08 04:59 . 2016-07-08 12:40 -------- d-----w- c:\users\Tim's\AppData\Local\GitHub
- 2016-07-08 04:59 . 2016-07-08 12:40 -------- d-----w- c:\users\Tim's\AppData\Roaming\GitHub
- 2016-07-08 04:56 . 2016-07-08 11:03 -------- d-----w- c:\users\Tim's\AppData\Local\Deployment
- 2016-07-08 03:18 . 2016-07-08 03:25 -------- d-----w- c:\users\Tim's\AppData\Local\PlexMediaPlayer
- 2016-07-08 03:18 . 2016-07-08 03:18 -------- d-----w- c:\users\Tim's\AppData\Local\cache
- 2016-07-08 03:14 . 2016-07-08 03:14 -------- d-----w- c:\program files\Plex
- 2016-07-08 02:39 . 2016-07-15 01:30 -------- d-----w- C:\PlexPy
- 2016-07-08 02:36 . 2016-07-08 02:36 -------- d-----w- c:\programdata\Git
- 2016-07-08 02:35 . 2016-07-08 02:36 -------- d-----w- c:\program files\Git
- 2016-07-08 02:33 . 2016-07-08 02:34 -------- d-----w- C:\Python27
- 2016-07-08 01:52 . 2016-07-09 06:22 -------- d-----w- c:\program files\FileBot
- 2016-07-08 00:49 . 2016-07-08 00:54 -------- d-----w- c:\users\Tim's\AppData\Roaming\Notepad++
- 2016-07-08 00:49 . 2016-07-08 00:49 -------- d-----w- c:\program files (x86)\Notepad++
- 2016-07-02 00:37 . 2016-07-02 00:37 -------- d-----w- c:\program files (x86)\iolo
- 2016-07-02 00:37 . 2016-07-02 01:16 -------- d-----w- c:\programdata\iolo
- 2016-07-01 10:59 . 2016-07-01 10:59 -------- d-----w- c:\program files (x86)\Video to Video
- 2016-07-01 10:49 . 2016-07-01 10:49 -------- d-----w- c:\users\Tim's\AppData\Roaming\EaseFab
- 2016-07-01 10:48 . 2016-07-01 10:48 -------- d-----w- c:\program files (x86)\EaseFab
- 2016-06-30 19:51 . 2016-06-30 19:51 -------- d-----w- c:\program files\CCleaner
- 2016-06-30 11:55 . 2016-06-30 11:55 226488 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
- 2016-06-29 05:26 . 2016-06-29 05:25 110144 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
- 2016-06-29 05:25 . 2016-06-29 05:25 -------- d-----w- c:\windows\system32\config\systemprofile\.oracle_jre_usage
- 2016-06-29 05:24 . 2016-06-29 05:24 -------- d-----w- c:\program files\Java
- 2016-06-29 05:16 . 2016-06-29 05:16 -------- d-----w- c:\program files (x86)\Common Files\Java
- 2016-06-29 05:15 . 2016-06-29 05:15 97344 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
- 2016-06-28 23:47 . 2016-06-28 23:48 -------- d-----w- c:\program files (x86)\QuickTime
- 2016-06-28 19:16 . 2016-06-29 09:12 -------- d-----r- c:\users\Tim's\Dropbox
- 2016-06-28 16:37 . 2016-06-28 16:37 -------- d-----w- c:\users\Tim's\AppData\Roaming\Dropbox
- 2016-06-28 16:36 . 2016-06-30 07:40 -------- d-----w- c:\users\Tim's\AppData\Local\Dropbox
- 2016-06-28 09:11 . 2016-06-28 09:11 -------- d-----w- c:\programdata\Wondershare
- 2016-06-28 09:10 . 2016-06-28 09:10 -------- d-----w- c:\users\Tim's\AppData\Local\Wondershare
- 2016-06-27 20:25 . 2016-06-27 20:25 3395072 ----a-w- c:\windows\system32\python27.dll
- 2016-06-27 12:08 . 2016-06-28 23:44 -------- d-----w- C:\Media
- 2016-06-26 17:23 . 2016-06-26 17:23 -------- d-----w- c:\users\Tim's\AppData\Roaming\java
- 2016-06-26 17:23 . 2016-07-09 06:22 -------- d-----w- c:\users\Tim's\AppData\Roaming\FileBot
- 2016-06-26 17:19 . 2016-06-29 05:21 -------- d-----w- c:\windows\SysWow64\config\systemprofile\.oracle_jre_usage
- 2016-06-26 12:58 . 2016-06-26 12:58 -------- d-----w- c:\users\Tim's\AppData\Local\Mega Limited
- 2016-06-25 09:57 . 2016-06-27 18:38 -------- d-----w- C:\SUPERDelete
- 2016-06-25 02:58 . 2016-06-25 03:00 -------- d-----w- c:\users\Tim's\AppData\Local\Setup251271044
- 2016-06-25 02:58 . 2016-06-25 03:58 -------- d-----w- c:\users\Tim's\AppData\Local\{A7A89113-82FA-FC65-E9CC-DBB7351E2689}
- 2016-06-25 02:58 . 2016-06-25 02:58 -------- d-----w- c:\programdata\{CEB70BD4-44F5-8112-C233-1F505871949E}
- 2016-06-25 02:57 . 2016-06-25 11:52 -------- d-----w- c:\users\Tim's\AppData\Roaming\CDisplayEx
- 2016-06-25 02:57 . 2016-06-25 02:58 -------- d-----w- c:\users\Tim's\AppData\Local\defo
- 2016-06-25 02:57 . 2016-06-25 02:57 -------- d-----w- c:\program files\CDisplayEx
- 2016-06-15 03:57 . 2016-05-12 17:15 2048 ----a-w- c:\windows\system32\tzres.dll
- 2016-06-15 03:57 . 2016-05-12 15:18 2048 ----a-w- c:\windows\SysWow64\tzres.dll
- 2016-06-15 03:55 . 2016-05-13 22:15 382184 ----a-w- c:\windows\system32\atmfd.dll
- 2016-06-15 03:54 . 2016-04-14 16:46 114408 ----a-w- c:\windows\system32\consent.exe
- 2016-06-15 03:54 . 2016-04-14 16:42 504320 ----a-w- c:\windows\system32\msihnd.dll
- 2016-06-15 03:54 . 2016-04-14 16:42 3243520 ----a-w- c:\windows\system32\msi.dll
- 2016-06-15 03:54 . 2016-04-14 16:42 25088 ----a-w- c:\windows\system32\msimsg.dll
- 2016-06-15 03:54 . 2016-04-14 16:42 70144 ----a-w- c:\windows\system32\appinfo.dll
- 2016-06-15 03:54 . 2016-04-14 16:42 1941504 ----a-w- c:\windows\system32\authui.dll
- 2016-06-15 03:54 . 2016-04-14 15:33 337408 ----a-w- c:\windows\SysWow64\msihnd.dll
- 2016-06-15 03:54 . 2016-04-14 15:33 25088 ----a-w- c:\windows\SysWow64\msimsg.dll
- 2016-06-15 03:54 . 2016-04-14 15:33 2365440 ----a-w- c:\windows\SysWow64\msi.dll
- 2016-06-15 03:54 . 2016-04-14 15:33 1806848 ----a-w- c:\windows\SysWow64\authui.dll
- 2016-06-15 03:54 . 2016-04-14 15:19 128000 ----a-w- c:\windows\system32\msiexec.exe
- 2016-06-15 03:54 . 2016-04-14 15:11 73216 ----a-w- c:\windows\SysWow64\msiexec.exe
- .
- .
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2016-07-15 01:34 . 2015-08-12 07:22 192216 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
- 2016-07-12 23:43 . 2016-01-07 06:32 796352 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
- 2016-07-12 23:43 . 2016-01-07 06:32 142528 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
- 2016-07-10 15:31 . 2012-07-17 20:37 24800 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
- 2016-06-21 17:13 . 2015-08-11 20:32 485032 ------w- c:\windows\system32\MpSigStub.exe
- 2016-06-14 15:21 . 2016-07-13 09:01 2560 ----a-w- c:\windows\apppatch\AcRes.dll
- 2016-06-06 08:27 . 2016-06-06 08:27 15816 ----a-w- c:\windows\SysWow64\RzStats.IPC.dll
- 2016-05-24 08:31 . 2015-10-25 17:20 943536 ----a-w- c:\windows\system32\drivers\klif.sys
- 2016-05-24 08:31 . 2015-06-12 00:32 49240 ----a-w- c:\windows\system32\drivers\klim6.sys
- 2016-05-24 08:31 . 2015-07-04 07:18 237480 ----a-w- c:\windows\system32\drivers\klhk.sys
- .
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{F710F7E5-A520-471D-989C-F653AC328FB2}]
- 2015-12-12 00:55 1093960 ----a-w- c:\program files (x86)\Kaspersky Lab\Kaspersky Password Manager 8.0.4\ie_engine.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
- @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
- [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
- 2015-11-07 06:48 223432 ----a-w- c:\users\Tim's\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
- @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
- [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
- 2015-11-07 06:48 223432 ----a-w- c:\users\Tim's\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
- @="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
- [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
- 2015-11-07 06:48 223432 ----a-w- c:\users\Tim's\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll
- .
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2016-06-29 26424960]
- "kpm.exe"="c:\program files (x86)\Kaspersky Lab\Kaspersky Password Manager 8.0.4\kpm.exe" [2015-12-12 8087880]
- "uTorrent"="c:\users\Tim's\AppData\Roaming\uTorrent\uTorrent.exe" [2016-05-14 2133504]
- "Plex Media Server"="c:\program files (x86)\Plex\Plex Media Server\Plex Media Server.exe" [2016-06-24 12286280]
- "CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2016-06-10 8810200]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
- "Razer Synapse"="c:\program files (x86)\Razer\Synapse\RzSynapse.exe" [2016-06-16 596640]
- "Fast Boot"="c:\program files (x86)\MSI\Fast Boot\StartFastBoot.exe" [2015-04-22 759120]
- "Super Charger"="c:\program files (x86)\MSI\Super Charger\Super Charger.exe" [2015-09-09 1027024]
- "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2016-05-20 595992]
- .
- [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
- "iCloud"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloud.exe" [2015-10-21 60688]
- .
- c:\users\Tim's\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
- PlexPy.lnk - c:\plexpy\PlexPy.py [2016-7-7 8654]
- .
- c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
- Killer Network Manager.lnk - c:\program files\Killer Networking\Network Manager\NetworkManager.exe -minimize [2015-7-7 338432]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
- "ConsentPromptBehaviorAdmin"= 0 (0x0)
- "ConsentPromptBehaviorUser"= 3 (0x3)
- "EnableLUA"= 0 (0x0)
- "EnableUIADesktopToggle"= 0 (0x0)
- "PromptOnSecureDesktop"= 0 (0x0)
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
- @=""
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
- "DisableMonitoring"=dword:00000001
- .
- R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
- R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
- R3 CorsairAudioFilter;Corsair Audio Filtering Service;c:\windows\system32\DRIVERS\corsveng2kamd64.sys;c:\windows\SYSNATIVE\DRIVERS\corsveng2kamd64.sys [x]
- R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service;c:\program files\DAEMON Tools Lite\DiscSoftBusService.exe;c:\program files\DAEMON Tools Lite\DiscSoftBusService.exe [x]
- R3 DrvAgent64;DrvAgent64;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS [x]
- R3 gwfilt64;Service 2 for Creative X-Fi Audio (WDM);c:\windows\system32\drivers\gwfilt64.sys;c:\windows\SYSNATIVE\drivers\gwfilt64.sys [x]
- R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
- R3 INETMON;INETMON;c:\windows\System32\Drivers\INETMON.sys;c:\windows\SYSNATIVE\Drivers\INETMON.sys [x]
- R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x]
- R3 NTIOLib_MSI_RAID;NTIOLib_MSI_RAID;c:\msi\Smart Utilities\NTIOLib_X64.sys;c:\msi\Smart Utilities\NTIOLib_X64.sys [x]
- R3 NTIOLib_MSIDDR_CC;NTIOLib_MSIDDR_CC;c:\program files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys;c:\program files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys [x]
- R3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
- R3 PcaSp60;Rawether NDIS 6.X SPR Protocol Driver;c:\windows\system32\DRIVERS\PcaSp60.sys;c:\windows\SYSNATIVE\DRIVERS\PcaSp60.sys [x]
- R3 RTCore64;RTCore64;c:\program files (x86)\MSI Afterburner\RTCore64.sys;c:\program files (x86)\MSI Afterburner\RTCore64.sys [x]
- R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
- R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
- R4 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [x]
- R4 Apple Mobile Device Service;Apple Mobile Device Service;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [x]
- R4 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\EscSvc64.exe;c:\windows\SYSNATIVE\EscSvc64.exe [x]
- R4 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
- R4 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
- R4 ISCTAgent;Intel(R) Smart Connect Technology Agent;c:\program files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe ;c:\program files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [x]
- R4 MSI_FastBoot;MSI_FastBoot;c:\program files (x86)\MSI\Fast Boot\FastBootService.exe;c:\program files (x86)\MSI\Fast Boot\FastBootService.exe [x]
- R4 MSI_LiveUpdate_Service;MSI Live Update Service;c:\program files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe;c:\program files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [x]
- R4 MSI_SuperCharger;MSI_SuperCharger;c:\program files (x86)\MSI\Super Charger\ChargeService.exe;c:\program files (x86)\MSI\Super Charger\ChargeService.exe [x]
- R4 MSIBIOSData_CC;MSIBIOSData_CC;c:\program files (x86)\MSI\Command Center\BIOSData\MSIBIOSDataService.exe;c:\program files (x86)\MSI\Command Center\BIOSData\MSIBIOSDataService.exe [x]
- R4 MSIClock_CC;MSIClock_CC;c:\program files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe;c:\program files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe [x]
- R4 MSICOMM_CC;MSICOMM_CC;c:\program files (x86)\MSI\Command Center\MSICommService.exe;c:\program files (x86)\MSI\Command Center\MSICommService.exe [x]
- R4 MSICPU_CC;MSICPU_CC;c:\program files (x86)\MSI\Command Center\CPU\MSICPUService.exe;c:\program files (x86)\MSI\Command Center\CPU\MSICPUService.exe [x]
- R4 MSICTL_CC;MSI Command Center control Service;c:\program files (x86)\MSI\Command Center\MSIControlService.exe;c:\program files (x86)\MSI\Command Center\MSIControlService.exe [x]
- R4 MSIDDR_CC;MSI Command Center DDR Service;c:\program files (x86)\MSI\Command Center\DDR\MSIDDRService.exe;c:\program files (x86)\MSI\Command Center\DDR\MSIDDRService.exe [x]
- R4 MSISMB_CC;MSISMB_CC;c:\program files (x86)\MSI\Command Center\SMBus\MSISMBService.exe;c:\program files (x86)\MSI\Command Center\SMBus\MSISMBService.exe [x]
- R4 MSISuperIO_CC;MSISuperIO_CC;c:\program files (x86)\MSI\Command Center\SuperIO\MSISuperIOService.exe;c:\program files (x86)\MSI\Command Center\SuperIO\MSISuperIOService.exe [x]
- R4 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
- R4 NvStreamNetworkSvc;NVIDIA Streamer Network Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [x]
- R4 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [x]
- R4 Origin Client Service;Origin Client Service;g:\origin\OriginClientService.exe;g:\origin\OriginClientService.exe [x]
- R4 Razer Game Scanner Service;Razer Game Scanner;c:\program files (x86)\Razer\Razer Services\GSS\GameScannerService.exe;c:\program files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [x]
- R4 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
- R4 SuperRAIDSvc;SuperRAIDSvc;c:\msi\Smart Utilities\SuperRAIDSvc.exe;c:\msi\Smart Utilities\SuperRAIDSvc.exe [x]
- R4 vssbrigde64;vssbrigde64;c:\program files (x86)\Kaspersky Lab\Kaspersky Total Security 16.0.0\x64\vssbridge64.exe;c:\program files (x86)\Kaspersky Lab\Kaspersky Total Security 16.0.0\x64\vssbridge64.exe [x]
- R4 XTU3SERVICE;Intel(R) Extreme Tuning Utility Service;c:\program files (x86)\Intel\Extreme Tuning Utility\XtuService.exe;c:\program files (x86)\Intel\Extreme Tuning Utility\XtuService.exe [x]
- S0 cm_km;Kaspersky Lab ZAO Cryptographic Module x64 (Weak);c:\windows\system32\DRIVERS\cm_km.sys;c:\windows\SYSNATIVE\DRIVERS\cm_km.sys [x]
- S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
- S0 klbackupdisk;Kaspersky Lab klbackupdisk;c:\windows\system32\DRIVERS\klbackupdisk.sys;c:\windows\SYSNATIVE\DRIVERS\klbackupdisk.sys [x]
- S1 BfLwf;Killer Bandwidth Control;c:\windows\system32\DRIVERS\bflwfx64.sys;c:\windows\SYSNATIVE\DRIVERS\bflwfx64.sys [x]
- S1 klbackupflt;Kaspersky Lab klbackupflt;c:\windows\system32\DRIVERS\klbackupflt.sys;c:\windows\SYSNATIVE\DRIVERS\klbackupflt.sys [x]
- S1 klhk;Kaspersky Lab service driver;c:\windows\system32\DRIVERS\klhk.sys;c:\windows\SYSNATIVE\DRIVERS\klhk.sys [x]
- S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
- S1 klpd;Kaspersky Lab format recognizer driver;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x]
- S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x]
- S1 Klwtp;Klwtp;c:\windows\system32\DRIVERS\klwtp.sys;c:\windows\SYSNATIVE\DRIVERS\klwtp.sys [x]
- S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x]
- S1 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys;c:\windows\SYSNATIVE\drivers\mbamchameleon.sys [x]
- S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [x]
- S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [x]
- S2 AVP16.0.0;Kaspersky Anti-Virus Service 16.0.0;c:\program files (x86)\Kaspersky Lab\Kaspersky Total Security 16.0.0\avp.exe;c:\program files (x86)\Kaspersky Lab\Kaspersky Total Security 16.0.0\avp.exe [x]
- S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
- S2 GamingApp_Service;GamingApp_Service;c:\program files (x86)\MSI\MSI Gaming APP\GamingApp_Service.exe;c:\program files (x86)\MSI\MSI Gaming APP\GamingApp_Service.exe [x]
- S2 iocbios2;iocbios2;c:\program files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys;c:\program files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [x]
- S2 Killer Service V2;Killer Service V2;c:\program files\Killer Networking\Network Manager\KillerService.exe;c:\program files\Killer Networking\Network Manager\KillerService.exe [x]
- S2 kldisk;kldisk;c:\windows\system32\DRIVERS\kldisk.sys;c:\windows\SYSNATIVE\DRIVERS\kldisk.sys [x]
- S2 LGCoreTemp;Logitech CPU Core Tempurature;c:\program files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys;c:\program files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [x]
- S2 LogiRegistryService;Logitech Gaming Registry Service;c:\program files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe;c:\program files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [x]
- S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x]
- S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
- S2 rzpmgrk;rzpmgrk;c:\windows\system32\drivers\rzpmgrk.sys;c:\windows\SYSNATIVE\drivers\rzpmgrk.sys [x]
- S2 rzpnk;rzpnk;c:\windows\system32\drivers\rzpnk.sys;c:\windows\SYSNATIVE\drivers\rzpnk.sys [x]
- S3 AcpiCtlDrv;AcpiCtlDrv;c:\windows\system32\DRIVERS\AcpiCtlDrv.sys;c:\windows\SYSNATIVE\DRIVERS\AcpiCtlDrv.sys [x]
- S3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus;c:\windows\system32\DRIVERS\dtlitescsibus.sys;c:\windows\SYSNATIVE\DRIVERS\dtlitescsibus.sys [x]
- S3 dtliteusbbus;DAEMON Tools Lite Virtual USB Bus;c:\windows\system32\DRIVERS\dtliteusbbus.sys;c:\windows\SYSNATIVE\DRIVERS\dtliteusbbus.sys [x]
- S3 ICCWDT;Intel(R) Watchdog Timer Driver (Intel(R) WDT);c:\windows\system32\DRIVERS\ICCWDT.sys;c:\windows\SYSNATIVE\DRIVERS\ICCWDT.sys [x]
- S3 ikbevent;Intel Upper keyboard Class Filter Driver;c:\windows\system32\DRIVERS\ikbevent.sys;c:\windows\SYSNATIVE\DRIVERS\ikbevent.sys [x]
- S3 imsevent;Intel Upper Mouse Class Filter Driver;c:\windows\system32\DRIVERS\imsevent.sys;c:\windows\SYSNATIVE\DRIVERS\imsevent.sys [x]
- S3 ISCT;Intel(R) Smart Connect Technology Device Driver;c:\windows\system32\DRIVERS\ISCTD.sys;c:\windows\SYSNATIVE\DRIVERS\ISCTD.sys [x]
- S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
- S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
- S3 Ke2200;NDIS Miniport Driver for Killer e2201/e2202 PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\e22w7x64.sys;c:\windows\SYSNATIVE\DRIVERS\e22w7x64.sys [x]
- S3 klflt;Kaspersky Lab Kernel DLL;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x]
- S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x]
- S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
- S3 LGBusEnum;Logitech Gaming Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
- S3 LGJoyXlCore;Logitech Translation Layer Driver (LGS);c:\windows\system32\drivers\LGJoyXlCore.sys;c:\windows\SYSNATIVE\drivers\LGJoyXlCore.sys [x]
- S3 lgLowAudio;Logitech USB Filter Driver (LGS);c:\windows\system32\drivers\lgLowAudio.sys;c:\windows\SYSNATIVE\drivers\lgLowAudio.sys [x]
- S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
- S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
- S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
- S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
- S3 MBfilt;Service for Creative X-Fi Audio (WDM);c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x]
- S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
- S3 rzendpt;rzendpt;c:\windows\system32\DRIVERS\rzendpt.sys;c:\windows\SYSNATIVE\DRIVERS\rzendpt.sys [x]
- S3 rzmpos;rzmpos;c:\windows\system32\DRIVERS\rzmpos.sys;c:\windows\SYSNATIVE\DRIVERS\rzmpos.sys [x]
- S3 rzudd;Razer Keyboard Driver;c:\windows\system32\DRIVERS\rzudd.sys;c:\windows\SYSNATIVE\DRIVERS\rzudd.sys [x]
- S3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys;c:\windows\SYSNATIVE\DRIVERS\WSDScan.sys [x]
- .
- .
- --- Other Services/Drivers In Memory ---
- .
- *NewlyCreated* - MBAMSWISSARMY
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
- LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
- 2016-06-18 00:20 1245848 ----a-w- c:\program files (x86)\Google\Chrome\Application\51.0.2704.103\Installer\chrmstp.exe
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{A6EADE66-0000-0000-484E-7E8A45000000}]
- 2016-06-30 11:55 322232 ----a-w- c:\program files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll
- .
- Contents of the 'Scheduled Tasks' folder
- .
- 2016-07-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-07 23:43]
- .
- 2016-07-15 c:\windows\Tasks\EPSON WF-3620 Series Invitation {6B2D738F-562E-45EF-823C-90F4A0637E41}.job
- - c:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE [2015-08-30 00:20]
- .
- 2016-07-15 c:\windows\Tasks\EPSON WF-3620 Series Invitation {BB5532A9-CC62-4241-AB3E-042512DF47E8}.job
- - c:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE [2015-08-30 00:20]
- .
- 2016-07-15 c:\windows\Tasks\EPSON WF-3620 Series Update {6B2D738F-562E-45EF-823C-90F4A0637E41}.job
- - c:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE [2015-08-30 00:20]
- .
- 2016-07-15 c:\windows\Tasks\EPSON WF-3620 Series Update {BB5532A9-CC62-4241-AB3E-042512DF47E8}.job
- - c:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE [2015-08-30 00:20]
- .
- 2016-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-08-11 20:28]
- .
- 2016-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-08-11 20:28]
- .
- 2016-07-15 c:\windows\Tasks\Yahoo! Powered desil.job
- - c:\windows\system32\wscript.exe [2015-08-15 01:15]
- .
- .
- --------- X64 Entries -----------
- .
- .
- [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F710F7E5-A520-471D-989C-F653AC328FB2}]
- 2015-12-12 00:56 1335112 ----a-w- c:\program files (x86)\Kaspersky Lab\Kaspersky Password Manager 8.0.4\x64\ie_engine.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
- @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
- [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
- 2015-11-07 06:48 262344 ----a-w- c:\users\Tim's\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
- @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
- [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
- 2015-11-07 06:48 262344 ----a-w- c:\users\Tim's\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
- @="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
- [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
- 2015-11-07 06:48 262344 ----a-w- c:\users\Tim's\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2016-01-06 15053944]
- "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2016-03-30 2396096]
- "ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2016-03-30 1767248]
- "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2013-03-29 7174728]
- .
- ------- Supplementary Scan -------
- .
- uLocal Page = c:\windows\system32\blank.htm
- uStart Page = www.google.com
- mLocal Page = c:\windows\SysWOW64\blank.htm
- uInternet Settings,ProxyOverride = *.local
- IE: {{40AE684B-A1EA-4FF4-8E05-5BCADC4D4DB2} - {270F8CD9-C976-42FD-8F73-608C4A532638} - c:\program files (x86)\Kaspersky Lab\Kaspersky Password Manager 8.0.4\ie_toolbar_button.dll
- Trusted Zone: localhost
- Trusted Zone: webcompanion.com
- TCP: Interfaces\{88C5E2B5-8C40-4EA0-B030-CC6363B9D7EF}: NameServer = 192.168.2.1
- FF - ProfilePath - c:\users\Tim's\AppData\Roaming\Mozilla\Firefox\Profiles\419yi6ux.default-1467848165436\
- .
- - - - - ORPHANS REMOVED - - - -
- .
- ShellIconOverlayIdentifiers-{056D528D-CE28-4194-9BA3-BA2E9197FF8C} - (no file)
- ShellIconOverlayIdentifiers-{05B38830-F4E9-4329-978B-1DD28605D202} - (no file)
- ShellIconOverlayIdentifiers-{0596C850-7BDD-4C9D-AFDF-873BE6890637} - (no file)
- Wow6432Node-HKLM-Run-<NO NAME> - (no file)
- Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
- ShellIconOverlayIdentifiers-{056D528D-CE28-4194-9BA3-BA2E9197FF8C} - (no file)
- ShellIconOverlayIdentifiers-{05B38830-F4E9-4329-978B-1DD28605D202} - (no file)
- ShellIconOverlayIdentifiers-{0596C850-7BDD-4C9D-AFDF-873BE6890637} - (no file)
- .
- .
- .
- [HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
- "ImagePath"="c:\windows\system32\GameMon.des -service"
- .
- --------------------- LOCKED REGISTRY KEYS ---------------------
- .
- [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="WindowsLiveMail.Email.1"
- .
- [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
- @Denied: (2) (LocalSystem)
- "Progid"="WindowsLiveMail.VCard.1"
- .
- [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
- @Denied: (Full) (Everyone)
- .
- ------------------------ Other Running Processes ------------------------
- .
- c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
- q:\bandicam\bdcam.exe
- c:\program files (x86)\Malwarebytes Anti-Malware\mbam.exe
- c:\users\Tim's\AppData\Roaming\uTorrent\updates\3.4.7_42330\utorrentie.exe
- c:\users\Tim's\AppData\Roaming\uTorrent\updates\3.4.7_42330\utorrentie.exe
- c:\program files (x86)\MSI\Fast Boot\FastBoot.exe
- c:\program files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
- c:\program files (x86)\Plex\Plex Media Server\Plex Dlna Server.exe
- c:\program files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe
- c:\users\Tim's\AppData\Local\razer\InGameEngine\cache\RzSynapse\RzCefRenderProcess.exe
- c:\program files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
- .
- **************************************************************************
- .
- Completion time: 2016-07-14 20:43:56 - machine was rebooted
- ComboFix-quarantined-files.txt 2016-07-15 01:43
- .
- Pre-Run: 709,635,514,368 bytes free
- Post-Run: 709,848,686,592 bytes free
- .
- - - End Of File - - B7F923846B2C7AEF58DD73BB63013C40
- A36C5E4F47E84449FF07ED3517B43A31
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement