Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 17-08-04.01 - -bora 08/14/2017 22:49:49.1.2 - x86 NETWORK
- Microsoft Windows 7 Professional 6.1.7601.1.1255.972.1037.18.1782.1228 [GMT 3:00]
- Running from: c:\users\-bora\Downloads\ComboFix.exe
- SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- * Created a new restore point
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- c:\users\-bora\AppData\Roaming\Zer53CA.tmp
- c:\users\-bora\AppData\Roaming\Zer6ED9.tmp
- .
- .
- ((((((((((((((((((((((((( Files Created from 2017-07-14 to 2017-08-14 )))))))))))))))))))))))))))))))
- .
- .
- 2017-08-14 13:33 . 2017-05-23 06:22 30128 ----a-w- c:\windows\system32\sdnclean.exe
- 2017-08-14 13:33 . 2017-08-14 18:26 -------- d-----w- c:\programdata\Spybot - Search & Destroy
- 2017-08-14 13:33 . 2017-08-14 13:35 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
- 2017-08-14 12:29 . 2017-08-14 12:29 -------- d-----w- c:\programdata\ProductData
- 2017-08-14 04:45 . 2017-08-14 04:45 -------- d-----w- c:\users\-bora\AppData\Local\ElevatedDiagnostics
- 2017-08-13 22:01 . 2017-08-13 22:01 -------- d-----w- c:\users\-bora\AppData\Roaming\SUPERAntiSpyware.com
- 2017-08-13 21:59 . 2017-08-13 23:05 -------- d-----w- c:\program files\SUPERAntiSpyware
- 2017-08-13 21:59 . 2017-08-13 21:59 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
- 2017-08-13 16:33 . 2017-08-13 16:33 -------- d-----w- c:\program files\Common Files\Skype
- 2017-08-13 16:33 . 2017-08-13 16:33 -------- d-----r- c:\program files\Skype
- 2017-08-13 16:25 . 2017-08-13 16:25 -------- d-----w- C:\$AV_ASW
- 2017-08-13 16:22 . 2017-08-13 16:22 -------- d-----w- c:\users\-bora\AppData\Local\CEF
- 2017-08-13 16:21 . 2017-08-13 16:21 921280 ----a-w- c:\windows\ucrtbase.dll
- 2017-08-13 16:18 . 2017-08-13 17:26 -------- d-----w- c:\programdata\AVAST Software
- 2017-08-13 16:10 . 2017-08-13 16:10 -------- d-----w- c:\programdata\CheckPoint
- 2017-08-13 15:58 . 2017-08-13 17:26 -------- d-----w- c:\users\-bora\AppData\Local\FSDART
- 2017-08-13 15:58 . 2017-08-13 15:58 -------- d-----w- c:\programdata\F-Secure
- 2017-08-09 11:53 . 2017-08-09 11:57 -------- d-----w- c:\users\-bora\AppData\Roaming\audacity
- 2017-08-09 11:53 . 2017-08-09 11:53 -------- d-----w- c:\users\-bora\AppData\Local\Audacity
- 2017-08-05 12:36 . 2017-08-05 12:36 -------- d-----w- c:\users\-bora\AppData\Roaming\MiKTeX
- 2017-08-05 11:53 . 2017-08-05 11:53 -------- d-----w- c:\programdata\MiKTeX
- 2017-08-05 11:53 . 2017-08-05 11:53 -------- d-----w- c:\users\-bora\AppData\Local\MiKTeX
- 2017-08-05 11:51 . 2017-08-05 11:52 -------- d-----w- c:\program files\MiKTeX 2.9
- 2017-08-05 11:49 . 2017-08-05 22:28 -------- d-----w- c:\users\-bora\AppData\Roaming\TeXstudio
- 2017-08-05 11:49 . 2017-08-05 11:49 -------- d-----w- c:\program files\TeXstudio
- 2017-08-02 18:33 . 2017-08-02 18:33 -------- d-----w- c:\users\-bora\AppData\Roaming\Corona Labs
- 2017-08-02 18:33 . 2017-08-02 18:33 -------- d-----w- c:\users\-bora\AppData\Local\Corona Labs
- 2017-08-02 18:29 . 2017-08-02 18:29 -------- d-----w- c:\program files\Corona Labs
- 2017-08-02 12:23 . 2017-08-02 12:23 -------- d-----w- c:\windows\system32\sda
- 2017-08-02 12:22 . 2017-08-02 12:22 9890816 ----a-w- c:\windows\system32\RsCRIcon.dll
- 2017-08-02 12:22 . 2017-08-02 12:22 74752 ----a-w- c:\windows\system32\RtCRX.dll
- 2017-08-02 12:22 . 2017-08-02 12:22 3570176 ----a-w- c:\windows\RtCRU32.exe
- 2017-08-02 12:22 . 2017-08-02 12:22 308192 ----a-w- c:\windows\system32\drivers\RtsUer.sys
- 2017-08-02 12:17 . 2017-08-02 12:17 110280 ----a-w- c:\windows\system32\drivers\L1C62x86.sys
- 2017-08-02 12:00 . 2017-08-02 12:00 132480 ----a-w- c:\windows\system32\drivers\Impcd.sys
- 2017-08-02 11:00 . 2017-08-12 12:30 -------- d-----w- c:\program files\Uni-Android Tool
- 2017-07-31 13:21 . 2017-05-26 03:47 90096 ----a-w- c:\windows\system32\cpwmon2k_v32.dll
- 2017-07-31 13:19 . 2017-07-31 13:19 -------- d-----w- c:\program files\tamasoftware
- 2017-07-27 15:36 . 2017-07-27 15:36 -------- d-----w- c:\programdata\Steam
- 2017-07-27 14:46 . 2017-07-27 14:46 -------- d-----w- c:\program files\Klei Entertainment
- 2017-07-21 11:21 . 2017-07-17 21:00 10848512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{91358E61-768A-44F9-AB6A-8A5129C48D40}\mpengine.dll
- 2017-07-17 22:11 . 2017-07-17 22:11 451264 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE
- 2017-07-17 22:11 . 2017-07-17 22:11 28352 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE16\Office Setup Controller\pkeyconfig.companion.dll
- 2017-07-17 22:00 . 2017-07-17 22:00 213704 ----a-w- c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
- .
- .
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2017-08-14 18:39 . 2017-06-27 17:54 221600 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
- 2017-08-02 12:16 . 2012-01-10 19:15 57856 ----a-w- c:\windows\system32\igfxsrvc.dll
- 2017-08-02 12:16 . 2012-01-10 19:14 9030656 ----a-w- c:\windows\system32\igfxress.dll
- 2017-08-02 12:16 . 2012-01-10 20:18 6324224 ----a-w- c:\windows\system32\igdumd32.dll
- 2017-08-02 12:16 . 2012-01-10 20:12 581120 ----a-w- c:\windows\system32\igdumdx32.dll
- 2017-08-02 12:16 . 2012-01-10 19:55 7988224 ----a-w- c:\windows\system32\igd10umd32.dll
- 2017-08-02 12:16 . 2012-01-10 19:15 306688 ----a-w- c:\windows\system32\igfxpph.dll
- 2017-08-02 12:16 . 2012-01-10 19:14 96256 ----a-w- c:\windows\system32\hccutils.dll
- 2017-07-18 10:41 . 2017-01-30 10:34 3316928 ----a-w- c:\programdata\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe
- 2017-07-12 08:49 . 2017-06-27 17:54 65824 ----a-w- c:\windows\system32\drivers\mwac.sys
- 2017-07-11 11:03 . 2017-06-27 17:54 85400 ----a-w- c:\windows\system32\drivers\farflt.sys
- 2017-07-11 11:03 . 2017-06-27 17:54 40352 ----a-w- c:\windows\system32\drivers\mbam.sys
- 2017-07-05 17:34 . 2017-07-05 17:34 43119 --sh--w- c:\users\-bora\windowsdata.vbs
- 2017-07-01 15:38 . 2017-06-27 17:55 162240 ----a-w- c:\windows\system32\drivers\MBAMChameleon.sys
- 2017-07-01 11:33 . 2017-06-27 17:53 59936 ----a-w- c:\windows\system32\drivers\mbae.sys
- 2017-06-26 19:19 . 2017-06-26 19:19 43119 --sh--w- c:\users\-bora\tmp72B.tmp.vbs
- 2017-06-15 20:18 . 2017-07-12 09:02 514048 ----a-w- c:\windows\system32\drivers\http.sys
- 2017-06-12 22:29 . 2017-07-12 09:02 444928 ----a-w- c:\windows\system32\wvc.dll
- 2017-06-12 22:29 . 2017-07-12 09:02 1227264 ----a-w- c:\windows\system32\wdc.dll
- 2017-06-12 22:29 . 2017-07-12 09:02 390144 ----a-w- c:\windows\system32\sysmon.ocx
- 2017-06-12 22:28 . 2017-07-12 09:02 47104 ----a-w- c:\windows\system32\pdhui.dll
- 2017-06-12 22:06 . 2017-07-12 09:02 157184 ----a-w- c:\windows\system32\perfmon.exe
- 2017-06-12 22:06 . 2017-07-12 09:02 303616 ----a-w- c:\windows\system32\msinfo32.exe
- 2017-06-12 22:06 . 2017-07-12 09:02 103424 ----a-w- c:\windows\system32\resmon.exe
- 2017-06-10 15:39 . 2017-07-12 09:02 271360 ----a-w- c:\windows\system32\Wldap32.dll
- 2017-06-09 15:17 . 2017-07-12 09:02 1213672 ----a-w- c:\windows\system32\drivers\ntfs.sys
- 2017-06-06 15:12 . 2017-07-12 09:02 1499648 ----a-w- c:\windows\system32\ExplorerFrame.dll
- 2017-06-02 07:57 . 2017-06-26 18:22 497152 ----a-w- c:\windows\HelpPane.exe
- 2017-05-30 04:39 . 2017-07-12 09:02 1309928 ----a-w- c:\windows\system32\drivers\tcpip.sys
- 2017-05-30 04:39 . 2017-07-12 09:02 240872 ----a-w- c:\windows\system32\drivers\netio.sys
- 2017-05-30 04:39 . 2017-07-12 09:02 187624 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
- 2017-05-21 04:06 . 2017-07-12 09:02 2048 ----a-w- c:\windows\system32\tzres.dll
- .
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive1]
- @="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
- [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
- 2017-01-30 10:42 329376 ----a-w- c:\users\-bora\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive2]
- @="{5AB7172C-9C11-405C-8DD5-AF20F3606282}"
- [HKEY_CLASSES_ROOT\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}]
- 2017-01-30 10:42 329376 ----a-w- c:\users\-bora\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive3]
- @="{A78ED123-AB77-406B-9962-2A5D9D2F7F30}"
- [HKEY_CLASSES_ROOT\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}]
- 2017-01-30 10:42 329376 ----a-w- c:\users\-bora\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive4]
- @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
- [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
- 2017-01-30 10:42 329376 ----a-w- c:\users\-bora\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive5]
- @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
- [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
- 2017-01-30 10:42 329376 ----a-w- c:\users\-bora\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
- @="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
- [HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
- 2017-07-18 10:41 2106048 ----a-w- c:\program files\Microsoft Office\root\Office16\GROOVEEX.DLL
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
- @="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
- [HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
- 2017-07-18 10:41 2106048 ----a-w- c:\program files\Microsoft Office\root\Office16\GROOVEEX.DLL
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
- @="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
- [HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
- 2017-07-18 10:41 2106048 ----a-w- c:\program files\Microsoft Office\root\Office16\GROOVEEX.DLL
- .
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "WINDOW~1"="wscript.exe" [2013-10-12 141824]
- "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2017-06-12 6843808]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2016-09-22 587288]
- "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2016-12-02 15009280]
- "LangOver"="c:\program files\LangOver\LangOver.exe" [2017-02-08 2613248]
- "Malwarebytes TrayApp"="c:\program files\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe" [2017-05-09 3146704]
- "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
- "IgfxTray"="c:\windows\system32\igfxtray.exe" [2017-08-02 143856]
- "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2017-08-02 178672]
- "Persistence"="c:\windows\system32\igfxpers.exe" [2017-08-02 179184]
- "SDTray"="c:\program files\Spybot - Search & Destroy 2\SDTray.exe" [2017-05-23 4174464]
- .
- c:\users\-bora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
- WINDOW~1.VBS [2017-7-5 43119]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
- "ConsentPromptBehaviorAdmin"= 5 (0x5)
- "ConsentPromptBehaviorUser"= 3 (0x3)
- "EnableUIADesktopToggle"= 0 (0x0)
- .
- [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
- BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
- @=""
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioEndpointBuilder]
- @="Service"
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Audiosrv]
- @="Service"
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudAddService]
- @="Service"
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HDAudBus]
- @="Service"
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]
- @="Service"
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MMCSS]
- @="Service"
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96C-E325-11CE-BFC1-08002BE10318}]
- @="[6cFgE][?????, ????? ??? ???? ¢?????????? !!! !!! !]"
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{640167b4-59b0-47a6-b335-a6b3c0695aea}]
- @="Portable Media Devices"
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
- 2017-07-28 14:52 27815896 ----a-r- c:\program files\Skype\Phone\Skype.exe
- .
- R1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO32.SYS [2017-01-06 23840]
- R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880]
- R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664]
- R2 ClickToRunSvc;שירות 'לחץ והפעל' של Microsoft Office;c:\program files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2017-07-17 2835648]
- R2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
- R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [2017-05-23 1776864]
- R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2017-05-23 2131760]
- R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2017-05-23 233936]
- R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2017-06-01 317400]
- R2 wampstackApache;wampstackApache;c:\bitnami\WAMPST~1.30-\apache2\bin\httpd.exe [2016-07-07 23040]
- R2 wampstackMySQL;wampstackMySQL;c:\bitnami\wampstack-5.6.30-0\mysql\bin\mysqld.exe [2016-11-28 11088384]
- R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
- R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2017-07-14 104960]
- R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2017-08-02 132480]
- R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
- R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
- R3 VSStandardCollectorService140;Visual Studio Standard Collector Service;c:\program files\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [2016-09-06 86760]
- R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
- R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]
- R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 366936]
- S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2016-12-21 239168]
- S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2017-01-30 143776]
- S2 MBAMService;Malwarebytes Service;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe [2017-05-09 3398608]
- S3 ETDSMBus;ETDSMBus;c:\windows\system32\DRIVERS\ETDSMBus.sys [2017-08-02 28744]
- S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [2017-08-02 110280]
- S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [2017-08-14 221600]
- S3 RTSUER;Realtek USB Card Reader - UER;c:\windows\system32\Drivers\RtsUer.sys [2017-08-02 308192]
- .
- .
- --- Other Services/Drivers In Memory ---
- .
- *NewlyCreated* - MBAMSWISSARMY
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
- LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr fdrespub AppIDSvc QWAVE wcncsvc Mcx2Svc SensrSvc
- utcsvc REG_MULTI_SZ DiagTrack
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
- 2017-08-08 08:36 1429848 ----a-w- c:\program files\Google\Chrome\Application\60.0.3112.90\Installer\chrmstp.exe
- .
- Contents of the 'Scheduled Tasks' folder
- .
- 2017-08-14 c:\windows\Tasks\Check for updates (Spybot - Search & Destroy).job
- - c:\program files\Spybot - Search & Destroy 2\SDUpdate.exe [2017-08-14 06:26]
- .
- 2017-08-14 c:\windows\Tasks\Driver Booster Scheduler.job
- - c:\program files\IObit\Driver Booster\4.1.0\Scheduler.exe [2017-01-06 08:18]
- .
- 2017-08-14 c:\windows\Tasks\Driver Booster SkipUAC (-bora).job
- - c:\program files\IObit\Driver Booster\4.1.0\DriverBooster.exe [2017-01-06 13:18]
- .
- 2017-08-14 c:\windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job
- - c:\program files\Spybot - Search & Destroy 2\SDImmunize.exe [2017-08-14 06:21]
- .
- 2017-08-14 c:\windows\Tasks\Scan the system (Spybot - Search & Destroy).job
- - c:\program files\Spybot - Search & Destroy 2\SDScan.exe [2017-08-14 06:24]
- .
- .
- ------- Supplementary Scan -------
- .
- IE: E&xport to Microsoft Excel - c:\program files\Microsoft Office\Root\Office16\EXCEL.EXE/3000
- IE: Se&nd to OneNote - c:\program files\Microsoft Office\Root\Office16\ONBttnIE.dll/105
- TCP: DhcpNameServer = 10.100.102.1
- Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - c:\program files\Microsoft Office\root\Office16\MSOSB.DLL
- Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - c:\program files\Microsoft Office\root\Office16\MSOSB.DLL
- Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - c:\program files\Microsoft Office\root\Office16\MSOSB.DLL
- Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - c:\program files\Microsoft Office\root\Office16\MSOSB.DLL
- FF - ProfilePath - c:\users\-bora\AppData\Roaming\Mozilla\Firefox\Profiles\m2mhjriz.default\
- .
- - - - - ORPHANS REMOVED - - - -
- .
- Notify-SDWinLogon - SDWinLogon.dll
- SafeBoot-drmkaud
- SafeBoot-MBAMSwissArmy
- AddRemove-Torch - c:\users\-bora\AppData\Local\Torch\uninstall.exe
- .
- .
- .
- --------------------- LOCKED REGISTRY KEYS ---------------------
- .
- [HKEY_USERS\S-1-5-21-124123957-3465755313-2965481238-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
- "??"=hex:5e,09,99,8f,d0,d3,65,2f,3a,12,8b,33,e1,e4,61,38,c0,6f,91,52,36,ce,36,
- 5a,9c,6b,11,d1,9a,ba,82,4b,0f,e6,ca,d1,cc,5b,89,90,89,d1,3d,ef,cc,bd,7c,36,\
- "??"=hex:5f,90,6f,2a,e0,37,3c,c2,5e,35,19,df,2b,a4,8f,77
- .
- [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
- @Denied: (Full) (Everyone)
- .
- Completion time: 2017-08-14 23:01:53
- ComboFix-quarantined-files.txt 2017-08-14 20:01
- .
- Pre-Run: 32,090,980,352 bytes free
- Post-Run: 31,730,438,144 bytes free
- .
- - - End Of File - - 6BCB140CCF76DF0B0CCD7CE9894D6785
- A36C5E4F47E84449FF07ED3517B43A31
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement