Guest User

Untitled

a guest
Mar 19th, 2014
227
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 22.50 KB | None | 0 0
  1. ComboFix 14-03-19.01 - Chandler 03/19/2014 17:50:24.2.8 - x64
  2. Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6092.4314 [GMT -5:00]
  3. Running from: c:\users\Chandler\Downloads\ComboFix.exe
  4. Command switches used :: c:\users\Chandler\Desktop\CFScript.txt
  5. AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
  6. SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
  7. SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
  8. .
  9. .
  10. ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
  11. .
  12. .
  13. .
  14. --------------- FCopy ---------------
  15. .
  16. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe --> c:\windows\explorer.exe
  17. .
  18. ((((((((((((((((((((((((( Files Created from 2014-02-19 to 2014-03-19 )))))))))))))))))))))))))))))))
  19. .
  20. .
  21. 2014-03-19 23:00 . 2014-03-19 23:00 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
  22. 2014-03-19 23:00 . 2014-03-19 23:00 -------- d-----w- c:\users\UpdatusUser.Chandler-M14x\AppData\Local\temp
  23. 2014-03-19 23:00 . 2014-03-19 23:00 -------- d-----w- c:\users\Default\AppData\Local\temp
  24. 2014-03-19 03:59 . 2014-03-19 03:59 -------- d-----w- c:\windows\ERUNT
  25. 2014-03-19 03:51 . 2014-03-19 03:55 -------- d-----w- C:\AdwCleaner
  26. 2014-03-19 03:43 . 2014-03-19 03:43 -------- d-----w- c:\programdata\Dell
  27. 2014-03-19 03:41 . 2014-03-19 03:41 -------- d-----w- c:\program files (x86)\Alienware On-Screen Display
  28. 2014-03-19 03:22 . 2014-03-19 03:22 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CFFDE842-4083-4725-8DE3-C32DBC3A5FFB}\offreg.dll
  29. 2014-03-18 20:27 . 2014-03-07 04:43 10521840 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CFFDE842-4083-4725-8DE3-C32DBC3A5FFB}\mpengine.dll
  30. 2014-03-18 20:24 . 2014-03-18 20:24 -------- d-----w- c:\users\Chandler\AppData\Local\Skype
  31. 2014-03-18 20:24 . 2014-03-18 20:24 -------- d-----w- c:\program files (x86)\Common Files\Skype
  32. 2014-03-18 20:24 . 2014-03-18 20:24 -------- d-----r- c:\program files (x86)\Skype
  33. 2014-03-15 01:54 . 2014-03-15 01:54 -------- d-----w- c:\program files\Common Files\EPSON
  34. 2014-03-15 01:54 . 2007-04-09 21:06 10752 ----a-w- c:\windows\system32\E_GCINST.DLL
  35. 2014-03-15 01:54 . 2011-04-18 23:03 120320 ----a-w- c:\windows\system32\E_YLMIVE.DLL
  36. 2014-03-15 01:54 . 2011-03-13 23:03 83968 ----a-w- c:\windows\system32\E_YD4BIVE.DLL
  37. 2014-03-09 03:23 . 2014-03-09 03:36 -------- d-----w- c:\programdata\HitmanPro
  38. 2014-03-05 02:27 . 2014-03-05 02:27 -------- d-----w- c:\programdata\EPSON
  39. 2014-02-24 23:20 . 2014-02-24 23:20 -------- d-----w- c:\users\Chandler\AppData\Local\Blizzard
  40. 2014-02-23 19:39 . 2014-03-13 20:02 -------- d-----w- c:\program files (x86)\Hearthstone
  41. 2014-02-23 19:38 . 2014-02-23 19:38 -------- d-----w- c:\users\Chandler\AppData\Local\Blizzard Entertainment
  42. 2014-02-23 19:37 . 2014-03-18 22:26 -------- d-----w- c:\users\Chandler\AppData\Local\Battle.net
  43. 2014-02-23 19:37 . 2014-03-10 21:24 -------- d-----w- c:\users\Chandler\AppData\Roaming\Battle.net
  44. 2014-02-23 19:37 . 2014-03-10 22:31 -------- d-----w- c:\program files (x86)\Battle.net
  45. 2014-02-18 22:56 . 2014-02-18 22:56 -------- d-----w- c:\windows\SysWow64\NV
  46. 2014-02-18 22:56 . 2014-02-18 22:56 -------- d-----w- c:\windows\system32\NV
  47. .
  48. .
  49. .
  50. (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
  51. .
  52. 2014-02-09 22:03 . 2014-01-14 21:19 80184 ----a-w- c:\windows\system32\drivers\aswstm.sys
  53. 2014-02-09 22:03 . 2012-04-20 22:57 421704 ----a-w- c:\windows\system32\drivers\aswSP.sys
  54. 2014-02-09 22:03 . 2012-04-20 22:57 1038072 ----a-w- c:\windows\system32\drivers\aswSnx.sys
  55. 2014-02-09 22:03 . 2012-04-20 22:57 78648 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
  56. 2014-02-09 22:03 . 2012-04-20 22:57 334136 ----a-w- c:\windows\system32\aswBoot.exe
  57. 2014-02-09 22:03 . 2012-04-20 22:56 43152 ----a-w- c:\windows\avastSS.scr
  58. 2014-02-08 18:34 . 2014-01-14 22:12 61216 ----a-w- c:\windows\system32\OpenCL.dll
  59. 2014-02-08 18:34 . 2014-01-14 22:12 53024 ----a-w- c:\windows\SysWow64\OpenCL.dll
  60. 2014-02-08 18:34 . 2014-01-14 22:03 947296 ----a-w- c:\windows\system32\nvumdshimx.dll
  61. 2014-02-08 18:34 . 2014-01-14 22:03 832424 ----a-w- c:\windows\SysWow64\nvumdshim.dll
  62. 2014-02-08 18:34 . 2014-01-14 22:02 174296 ----a-w- c:\windows\system32\nvinitx.dll
  63. 2014-02-08 18:34 . 2014-01-14 22:02 148528 ----a-w- c:\windows\SysWow64\nvinit.dll
  64. 2014-02-08 18:34 . 2014-01-14 22:02 14669032 ----a-w- c:\windows\SysWow64\nvd3dum.dll
  65. 2014-02-08 18:34 . 2014-01-14 22:02 3090184 ----a-w- c:\windows\system32\nvapi64.dll
  66. 2014-02-08 18:34 . 2014-01-14 22:02 2713728 ----a-w- c:\windows\SysWow64\nvapi.dll
  67. 2014-02-08 17:42 . 2014-01-14 22:14 6712608 ----a-w- c:\windows\system32\nvcpl.dll
  68. 2014-02-08 17:42 . 2014-01-14 22:14 3498272 ----a-w- c:\windows\system32\nvsvc64.dll
  69. 2014-02-08 17:42 . 2014-01-14 22:14 923936 ----a-w- c:\windows\system32\nvvsvc.exe
  70. 2014-02-08 17:42 . 2014-01-14 22:14 67072 ----a-w- c:\windows\system32\nv3dappshextr.dll
  71. 2014-02-08 17:42 . 2014-01-14 22:14 63776 ----a-w- c:\windows\system32\nvshext.dll
  72. 2014-02-08 17:42 . 2014-01-14 22:14 386336 ----a-w- c:\windows\system32\nvmctray.dll
  73. 2014-02-08 17:42 . 2014-01-14 22:14 2559776 ----a-w- c:\windows\system32\nvsvcr.dll
  74. 2014-02-08 17:42 . 2014-01-14 22:14 1075488 ----a-w- c:\windows\system32\nv3dappshext.dll
  75. 2014-02-05 17:52 . 2014-01-14 22:14 3573739 ----a-w- c:\windows\system32\nvcoproc.bin
  76. 2014-02-05 17:16 . 2012-04-01 14:08 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
  77. 2014-02-05 17:16 . 2011-06-16 18:58 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
  78. 2014-01-14 21:19 . 2013-03-14 21:21 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
  79. 2014-01-14 21:19 . 2013-03-14 21:21 207904 ----a-w- c:\windows\system32\drivers\aswVmm.sys
  80. 2014-01-14 21:19 . 2012-04-20 22:57 92544 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
  81. 2014-01-06 22:20 . 2011-06-18 18:44 86054176 ----a-w- c:\windows\system32\MRT.exe
  82. .
  83. .
  84. ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
  85. .
  86. .
  87. *Note* empty entries & legit default entries are not shown
  88. REGEDIT4
  89. .
  90. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  91. "EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\x64\3\E_YATIIVE.EXE" [2012-02-28 283232]
  92. .
  93. [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
  94. "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-11-06 283160]
  95. "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-02-09 3767096]
  96. "AlienwareOn-ScreenDisplay"="c:\program files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe" [2011-01-10 1545584]
  97. .
  98. [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
  99. "ConsentPromptBehaviorAdmin"= 5 (0x5)
  100. "ConsentPromptBehaviorUser"= 3 (0x3)
  101. "EnableUIADesktopToggle"= 0 (0x0)
  102. .
  103. [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
  104. "LoadAppInit_DLLs"=1 (0x1)
  105. "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
  106. .
  107. [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
  108. BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
  109. .
  110. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
  111. @=""
  112. .
  113. R2 AlienFusionService;Alienware Fusion Service;c:\program files\Alienware\Command Center\AlienFusionService.exe;c:\program files\Alienware\Command Center\AlienFusionService.exe [x]
  114. R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
  115. R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
  116. R3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
  117. R3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;c:\windows\system32\drivers\BVRPMPR5a64.SYS;c:\windows\SYSNATIVE\drivers\BVRPMPR5a64.SYS [x]
  118. R3 dcdbas;System Management Driver;c:\windows\system32\DRIVERS\dcdbas64.sys;c:\windows\SYSNATIVE\DRIVERS\dcdbas64.sys [x]
  119. R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys;c:\windows\SYSNATIVE\Drivers\ANDROIDUSB.sys [x]
  120. R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
  121. R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
  122. R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
  123. R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
  124. R3 USBTINSP;TI-Nspire(TM) Handheld or TI Network Bridge Device Driver;c:\windows\system32\DRIVERS\tinspusb.sys;c:\windows\SYSNATIVE\DRIVERS\tinspusb.sys [x]
  125. R3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\DRIVERS\VX6000Xp.sys;c:\windows\SYSNATIVE\DRIVERS\VX6000Xp.sys [x]
  126. R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
  127. R3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys;c:\windows\SYSNATIVE\DRIVERS\WDKMD.sys [x]
  128. R3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys;c:\windows\SYSNATIVE\drivers\WsAudio_DeviceS(1).sys [x]
  129. R3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys;c:\windows\SYSNATIVE\drivers\WsAudio_DeviceS(2).sys [x]
  130. R3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys;c:\windows\SYSNATIVE\drivers\WsAudio_DeviceS(3).sys [x]
  131. R3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys;c:\windows\SYSNATIVE\drivers\WsAudio_DeviceS(4).sys [x]
  132. R3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys;c:\windows\SYSNATIVE\drivers\WsAudio_DeviceS(5).sys [x]
  133. R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys;c:\windows\SYSNATIVE\DRIVERS\WSDScan.sys [x]
  134. R3 X6va005;X6va005;c:\users\Chandler\AppData\Local\Temp\00574.tmp;c:\users\Chandler\AppData\Local\Temp\00574.tmp [x]
  135. R4 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [x]
  136. R4 SftService;SoftThinks Agent Service;c:\program files (x86)\AlienRespawn\sftservice.EXE;c:\program files (x86)\AlienRespawn\sftservice.EXE [x]
  137. S0 aswRvrt;avast! Revert; [x]
  138. S0 aswVmm;avast! VM Monitor; [x]
  139. S0 EMSC;COMPAL Embedded System Control;c:\windows\system32\DRIVERS\EMSC.SYS;c:\windows\SYSNATIVE\DRIVERS\EMSC.SYS [x]
  140. S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
  141. S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
  142. S1 aswKbd;aswKbd; [x]
  143. S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
  144. S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
  145. S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
  146. S1 nvkflt;nvkflt;c:\windows\system32\DRIVERS\nvkflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvkflt.sys [x]
  147. S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
  148. S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
  149. S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
  150. S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
  151. S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
  152. S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys;c:\windows\SYSNATIVE\DRIVERS\CtClsFlt.sys [x]
  153. S3 HtcVCom32;HTC Diagnostic Port;c:\windows\system32\DRIVERS\HtcVComV64.sys;c:\windows\SYSNATIVE\DRIVERS\HtcVComV64.sys [x]
  154. S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
  155. S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
  156. S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
  157. S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
  158. S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
  159. S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x]
  160. S3 SaiK0CCB;SaiK0CCB;c:\windows\system32\DRIVERS\SaiK0CCB.sys;c:\windows\SYSNATIVE\DRIVERS\SaiK0CCB.sys [x]
  161. S3 SaiU0CCB;SaiU0CCB;c:\windows\system32\DRIVERS\SaiU0CCB.sys;c:\windows\SYSNATIVE\DRIVERS\SaiU0CCB.sys [x]
  162. S3 VSTWinDriver6;VSTWinDriver6;c:\windows\system32\drivers\VSTwindrvr6.sys;c:\windows\SYSNATIVE\drivers\VSTwindrvr6.sys [x]
  163. .
  164. .
  165. Contents of the 'Scheduled Tasks' folder
  166. .
  167. 2014-02-06 c:\windows\Tasks\Adobe Flash Player Updater.job
  168. - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 17:16]
  169. .
  170. 2014-03-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3302613279-1342707372-354726626-1002Core.job
  171. - c:\users\Chandler\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-17 02:00]
  172. .
  173. 2014-03-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3302613279-1342707372-354726626-1002UA.job
  174. - c:\users\Chandler\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-17 02:00]
  175. .
  176. .
  177. --------- X64 Entries -----------
  178. .
  179. .
  180. [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
  181. @="{472083B0-C522-11CF-8763-00608CC02F24}"
  182. [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
  183. 2014-02-09 22:03 287280 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
  184. .
  185. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  186. "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-02-01 6602856]
  187. "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-12-17 1933584]
  188. "Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-11-08 1028384]
  189. "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2013-12-10 2279712]
  190. "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-02-01 2186856]
  191. "IgfxTray"="c:\windows\system32\igfxtray.exe" [2013-11-07 171992]
  192. "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2013-11-07 399832]
  193. "Persistence"="c:\windows\system32\igfxpers.exe" [2013-11-07 442328]
  194. "Command Center Controllers"="c:\program files\Alienware\Command Center\AWCCStartupOrchestrator.exe" [2012-06-15 12656]
  195. .
  196. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
  197. "AppInit_DLLs"=c:\windows\System32\nvinitx.dll
  198. .
  199. ------- Supplementary Scan -------
  200. .
  201. uLocal Page = c:\windows\system32\blank.htm
  202. uStart Page = hxxp://search.yahoo.com?type=714647&fr=spigot-yhp-ie
  203. mLocal Page = c:\windows\SysWOW64\blank.htm
  204. uInternet Settings,ProxyOverride = *.local
  205. IE: E&xport to Microsoft Excel - c:\program files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
  206. IE: Se&nd to OneNote - c:\program files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
  207. Trusted Zone: dell.com
  208. TCP: DhcpNameServer = 50.57.99.138 50.57.100.29 8.8.8.8
  209. TCP: Interfaces\{2E78D95F-DD24-48EC-9B34-B3113F66BD57}: NameServer = 0.0.0.0
  210. .
  211. - - - - ORPHANS REMOVED - - - -
  212. .
  213. Toolbar-Locked - (no file)
  214. .
  215. .
  216. .
  217. [HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va005]
  218. "ImagePath"="\??\c:\users\Chandler\AppData\Local\Temp\00574.tmp"
  219. .
  220. --------------------- LOCKED REGISTRY KEYS ---------------------
  221. .
  222. [HKEY_USERS\S-1-5-21-3302613279-1342707372-354726626-1002\Software\SecuROM\License information*]
  223. "datasecu"=hex:36,3c,e9,69,1e,b8,37,48,a1,6d,6b,60,b8,3b,15,d4,fe,be,89,8a,54,
  224. f0,8b,77,35,23,a9,58,85,eb,a2,23,b8,d9,10,12,2c,49,30,10,2d,02,4f,af,a1,3f,\
  225. "rkeysecu"=hex:7e,93,19,a6,53,3e,d9,68,4b,e3,86,ca,24,94,fa,10
  226. .
  227. [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
  228. @Denied: (A 2) (Everyone)
  229. @="FlashBroker"
  230. "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101"
  231. .
  232. [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
  233. "Enabled"=dword:00000001
  234. .
  235. [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
  236. @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe"
  237. .
  238. [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
  239. @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
  240. .
  241. [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
  242. @Denied: (A 2) (Everyone)
  243. @="IFlashBroker5"
  244. .
  245. [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
  246. @="{00020424-0000-0000-C000-000000000046}"
  247. .
  248. [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
  249. @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
  250. "Version"="1.0"
  251. .
  252. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
  253. @Denied: (A 2) (Everyone)
  254. @="FlashBroker"
  255. "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
  256. .
  257. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
  258. "Enabled"=dword:00000001
  259. .
  260. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
  261. @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
  262. .
  263. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
  264. @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
  265. .
  266. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
  267. @Denied: (A 2) (Everyone)
  268. @="Shockwave Flash Object"
  269. .
  270. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
  271. @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
  272. "ThreadingModel"="Apartment"
  273. .
  274. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
  275. @="0"
  276. .
  277. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
  278. @="ShockwaveFlash.ShockwaveFlash.11"
  279. .
  280. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
  281. @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
  282. .
  283. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
  284. @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
  285. .
  286. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
  287. @="1.0"
  288. .
  289. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
  290. @="ShockwaveFlash.ShockwaveFlash"
  291. .
  292. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
  293. @Denied: (A 2) (Everyone)
  294. @="Macromedia Flash Factory Object"
  295. .
  296. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
  297. @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
  298. "ThreadingModel"="Apartment"
  299. .
  300. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
  301. @="FlashFactory.FlashFactory.1"
  302. .
  303. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
  304. @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
  305. .
  306. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
  307. @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
  308. .
  309. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
  310. @="1.0"
  311. .
  312. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
  313. @="FlashFactory.FlashFactory"
  314. .
  315. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
  316. @Denied: (A 2) (Everyone)
  317. @="IFlashBroker5"
  318. .
  319. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
  320. @="{00020424-0000-0000-C000-000000000046}"
  321. .
  322. [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
  323. @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
  324. "Version"="1.0"
  325. .
  326. [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
  327. @Denied: (A) (Everyone)
  328. .
  329. [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
  330. @Denied: (A) (Everyone)
  331. .
  332. [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
  333. @Denied: (Full) (Everyone)
  334. .
  335. ------------------------ Other Running Processes ------------------------
  336. .
  337. c:\program files\AVAST Software\Avast\AvastSvc.exe
  338. c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
  339. c:\windows\SysWOW64\PnkBstrA.exe
  340. c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
  341. .
  342. **************************************************************************
  343. .
  344. Completion time: 2014-03-19 18:07:28 - machine was rebooted
  345. ComboFix-quarantined-files.txt 2014-03-19 23:07
  346. ComboFix2.txt 2014-03-19 20:32
  347. .
  348. Pre-Run: 314,748,919,808 bytes free
  349. Post-Run: 314,818,568,192 bytes free
  350. .
  351. - - End Of File - - B15D57C3BB38A22621EB52323F9C27C7
Advertisement
Add Comment
Please, Sign In to add comment