Malware problem computer workings slowly. There are processes that i didn't install. - Page 2
Page 2 of 2 FirstFirst 12
Results 16 to 24 of 24

Thread: Malware problem computer workings slowly. There are processes that i didn't install.

  1. #16
    Join Date
    Mar 2017
    Posts
    17
    I was able to run combofix.

    ComboFix 17-03-28.01 - Asce 03/28/2017 9:08.1.8 - x64
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6142.4577 [GMT 3:00]
    Running from: c:\users\Asce\Desktop\ComboFix.exe
    AV: Kaspersky Anti-Virus *Disabled/Updated* {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
    AV: Malwarebytes *Disabled/Updated* {23007AD3-69FE-687C-2629-D584AFFAF72B}
    SP: Kaspersky Anti-Virus *Disabled/Updated* {3D579475-6DDE-A186-1569-44B9F9DE8725}
    SP: Malwarebytes *Disabled/Updated* {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    C:\Install.exe
    c:\programdata\ntuser.pol
    c:\users\Asce\AppData\Local\assembly\tmp
    c:\users\Asce\AppData\Local\Temp\VPN_6677\B7091C83.dll
    c:\windows\msdownld.tmp
    c:\windows\TEMP\VPN_3742\B7091C83.dll
    .
    .
    ((((((((((((((((((((((((( Files Created from 2017-02-28 to 2017-03-28 )))))))))))))))))))))))))))))))
    .
    .
    2017-03-28 06:16 . 2017-03-28 06:16 -------- d-----w- c:\users\Default\AppData\Local\temp
    2017-03-25 07:55 . 2017-03-25 07:55 -------- d-----w- c:\windows\system32\wbem\Framework
    2017-03-25 07:53 . 2017-03-25 07:53 -------- d-----w- c:\program files (x86)\GPU Temp
    2017-03-25 06:47 . 2017-03-25 06:47 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{59896AD4-81AA-41F7-A119-D82B1CF4AEDD}\offreg.3400.dll
    2017-03-25 05:01 . 2016-04-14 05:38 56384 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
    2017-03-25 05:01 . 2016-04-14 05:38 113216 ----a-w- c:\windows\system32\nvaudcap64v.dll
    2017-03-25 05:01 . 2016-04-14 05:38 102976 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
    2017-03-25 04:41 . 2017-03-25 04:50 -------- d-----w- c:\windows\system32\MRT
    2017-03-25 04:37 . 2013-05-06 06:13 110176 ----a-w- c:\windows\system32\klfphc.dll
    2017-03-25 04:37 . 2017-03-25 04:37 -------- d-----w- c:\windows\ELAMBKUP
    2017-03-25 04:36 . 2017-03-28 04:42 -------- d-----w- c:\programdata\Kaspersky Lab
    2017-03-25 04:36 . 2017-03-25 04:38 -------- d-----w- c:\program files (x86)\Kaspersky Lab
    2017-03-25 04:36 . 2017-03-25 05:10 195296 ----a-w- c:\windows\system32\drivers\klflt.sys
    2017-03-25 04:36 . 2017-03-25 05:10 1035488 ----a-w- c:\windows\system32\drivers\klif.sys
    2017-03-25 04:35 . 2017-03-22 11:05 12774864 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{59896AD4-81AA-41F7-A119-D82B1CF4AEDD}\mpengine.dll
    2017-03-25 04:34 . 2017-03-25 04:35 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
    2017-03-25 03:54 . 2017-03-25 04:14 -------- d-----w- C:\AdwCleaner
    2017-03-25 02:03 . 2017-03-28 04:06 28272 ----a-w- c:\windows\system32\drivers\TrueSight.sys
    2017-03-25 02:02 . 2017-03-25 02:02 -------- d-----w- c:\programdata\RogueKiller
    2017-03-25 01:58 . 2017-03-25 01:58 -------- d-----w- c:\program files\RogueKiller
    2017-03-24 12:08 . 2017-03-28 03:04 -------- d-----w- C:\FRST
    2017-03-24 10:10 . 2017-03-27 13:41 111544 ----a-w- c:\windows\system32\drivers\farflt.sys
    2017-03-24 10:10 . 2017-03-28 05:34 82208 ----a-w- c:\windows\system32\drivers\mwac.sys
    2017-03-24 10:10 . 2017-03-28 02:25 43968 ----a-w- c:\windows\system32\drivers\mbam.sys
    2017-03-24 10:09 . 2017-03-25 06:17 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
    2017-03-24 10:09 . 2017-03-28 02:25 251840 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
    2017-03-24 10:09 . 2017-03-28 02:25 186304 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
    2017-03-24 10:09 . 2017-02-24 04:23 77408 ----a-w- c:\windows\system32\drivers\mbae64.sys
    2017-03-24 10:09 . 2017-03-24 10:10 -------- d-----w- c:\programdata\Malwarebytes
    2017-03-24 10:09 . 2017-03-24 10:09 -------- d-----w- c:\program files\Malwarebytes
    2017-03-24 09:43 . 2017-03-27 13:20 -------- d-----w- c:\users\Asce\AppData\Local\NVIDIA Corporation
    2017-03-24 09:37 . 2017-03-27 13:20 -------- d-----w- c:\users\Asce\AppData\Local\NVIDIA
    2017-03-24 09:35 . 2017-03-28 02:24 -------- d-----w- c:\programdata\NVIDIA
    2017-03-24 09:35 . 2016-01-23 01:12 110016 ----a-w- c:\windows\SysWow64\nvStreaming.exe
    2017-03-24 09:34 . 2016-01-23 01:04 6368312 ----a-w- c:\windows\system32\nvcpl.dll
    2017-03-24 09:34 . 2016-01-23 01:04 2992064 ----a-w- c:\windows\system32\nvsvc64.dll
    2017-03-24 09:34 . 2016-01-23 01:04 2563128 ----a-w- c:\windows\system32\nvsvcr.dll
    2017-03-24 09:34 . 2016-01-23 01:04 1263040 ----a-w- c:\windows\system32\nvvsvc.exe
    2017-03-24 09:34 . 2016-01-23 01:04 83512 ----a-w- c:\windows\system32\nv3dappshextr.dll
    2017-03-24 09:34 . 2016-01-23 01:04 71224 ----a-w- c:\windows\system32\nvshext.dll
    2017-03-24 09:34 . 2016-01-23 01:04 532024 ----a-w- c:\windows\system32\nv3dappshext.dll
    2017-03-24 09:34 . 2016-01-23 01:04 393784 ----a-w- c:\windows\system32\nvmctray.dll
    2017-03-24 09:34 . 2016-01-22 21:07 6125650 ----a-w- c:\windows\system32\nvcoproc.bin
    2017-03-24 09:34 . 2017-03-25 07:51 -------- d-----w- c:\programdata\NVIDIA Corporation
    2017-03-24 09:32 . 2016-02-12 18:52 98816 ----a-w- c:\windows\system32\wudriver.dll
    2017-03-24 09:31 . 2016-05-11 17:02 483840 ----a-w- c:\windows\system32\StructuredQuery.dll
    2017-03-24 09:30 . 2016-04-06 15:27 668160 ----a-w- c:\program files\Windows Journal\MSPVWCTL.DLL
    2017-03-24 09:25 . 2016-07-22 14:58 142336 ----a-w- c:\windows\system32\poqexec.exe
    2017-03-24 09:25 . 2016-07-22 14:51 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
    2017-03-24 09:10 . 2017-03-25 07:51 -------- d-----w- c:\program files\NVIDIA Corporation
    2017-03-24 09:10 . 2017-03-24 09:10 -------- d-----w- C:\NVIDIA
    2017-03-24 09:08 . 2017-03-24 09:08 20647512 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2017-03-28 02:24 . 2015-05-18 12:56 25640 ----a-w- c:\windows\gdrv.sys
    2017-03-25 07:49 . 2015-10-04 20:42 802904 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
    2017-03-25 07:49 . 2015-10-04 20:42 144472 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2017-03-25 05:10 . 2016-06-14 15:47 199392 ----a-w- c:\windows\system32\drivers\kneps.sys
    2017-03-25 05:10 . 2016-12-26 20:03 135904 ----a-w- c:\windows\system32\drivers\klwtp.sys
    2017-03-25 05:10 . 2016-12-26 20:03 313112 ----a-w- c:\windows\system32\drivers\klhk.sys
    2017-02-09 16:14 . 2017-03-24 09:32 44032 ----a-w- c:\windows\apppatch\acwow64.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2014-03-04 3696912]
    "Octoshape Streaming Services"="c:\users\Asce\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2011-03-24 107800]
    "f.lux"="c:\users\Asce\AppData\Local\FluxSoftware\Flux\flux.exe" [2013-10-23 1017224]
    "Voobly"="c:\program files (x86)\Voobly\voobly.exe" [2015-01-19 159744]
    "ISUSPM Startup"="c:\progra~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-17 221184]
    "SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2015-05-27 787592]
    "Steam"="c:\steam\steam.exe" [2017-03-24 3019552]
    "Spotify Web Helper"="c:\users\Asce\AppData\Roaming\Spotify\SpotifyWebHelper.exe" [2015-12-17 2346096]
    "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2015-12-17 50378880]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "StartCCC"="c:\program files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-11-20 767176]
    "JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-01-19 43632]
    "NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-11-20 106496]
    "ISUSScheduler"="c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]
    "EasyTuneVI"="c:\program files (x86)\GIGABYTE\ET6\ETcall.exe" [2007-07-26 20480]
    "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2015-11-12 5565448]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    SoftEther VPN Client Manager Startup.lnk - c:\program files\SoftEther VPN Client\vpncmgr_x64.exe /startup [2015-5-2 5379640]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]
    @="Service"
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
    "DisableMonitoring"=dword:00000001
    .
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
    R2 MBAMService;Malwarebytes Service;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe [x]
    R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
    R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x]
    R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
    R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
    R3 EasyAntiCheat;EasyAntiCheat;c:\windows\system32\EasyAntiCheat.exe;c:\windows\SYSNATIVE\EasyAntiCheat.exe [x]
    R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
    R3 klvssbrigde64;klvssbrigde64;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\x64\vssbridge64.exe;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\x64\vssbridge64.exe [x]
    R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
    R3 Origin Client Service;Origin Client Service;c:\program files (x86)\Origin\OriginClientService.exe;c:\program files (x86)\Origin\OriginClientService.exe [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
    R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
    R3 VASDeviceDrm;Virtual Audio Streaming with Drm (WDM);c:\windows\system32\drivers\vasdDev.sys;c:\windows\SYSNATIVE\drivers\vasdDev.sys [x]
    R3 vvftav303;vvftav303;c:\windows\system32\drivers\vvftav303.sys;c:\windows\SYSNATIVE\drivers\vvftav303.sys [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
    R3 ZSMC0303;A4 TECH PC Camera H;c:\windows\system32\Drivers\usbVM303.sys;c:\windows\SYSNATIVE\Drivers\usbVM303.sys [x]
    S0 cm_km;AO Kaspersky Lab Cryptographic Module x64 (56 bit);c:\windows\system32\DRIVERS\cm_km.sys;c:\windows\SYSNATIVE\DRIVERS\cm_km.sys [x]
    S0 klbackupdisk;Kaspersky Lab klbackupdisk;c:\windows\system32\DRIVERS\klbackupdisk.sys;c:\windows\SYSNATIVE\DRIVERS\klbackupdisk.sys [x]
    S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
    S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
    S1 klbackupflt;Kaspersky Lab klbackupflt;c:\windows\system32\DRIVERS\klbackupflt.sys;c:\windows\SYSNATIVE\DRIVERS\klbackupflt.sys [x]
    S1 klhk;Kaspersky Lab service driver;c:\windows\system32\DRIVERS\klhk.sys;c:\windows\SYSNATIVE\DRIVERS\klhk.sys [x]
    S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
    S1 klpd;Kaspersky Lab format recognizer driver;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x]
    S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x]
    S1 Klwtp;KLwtp - WFP callout traffic inspector;c:\windows\system32\DRIVERS\klwtp.sys;c:\windows\SYSNATIVE\DRIVERS\klwtp.sys [x]
    S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x]
    S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
    S2 AVP17.0.0;Kaspersky Anti-Virus Service 17.0.0;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\avp.exe;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\avp.exe [x]
    S2 DES2 Service;DES2 Service for Energy Saving.;c:\program files (x86)\Gigabyte\EnergySaver2\des2svr.exe;c:\program files (x86)\Gigabyte\EnergySaver2\des2svr.exe [x]
    S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
    S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
    S2 JMB36X;JMB36X;c:\windows\SysWOW64\XSrvSetup.exe;c:\windows\SysWOW64\XSrvSetup.exe [x]
    S2 kldisk;kldisk;c:\windows\system32\DRIVERS\kldisk.sys;c:\windows\SYSNATIVE\DRIVERS\kldisk.sys [x]
    S2 KSDE1.0.0;Kaspersky Secure Connection Service 1.0.0;c:\program files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe;c:\program files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [x]
    S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
    S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
    S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [x]
    S2 SEVPNCLIENT;SoftEther VPN Client;c:\program files\SoftEther VPN Client\vpnclient_x64.exe;c:\program files\SoftEther VPN Client\vpnclient_x64.exe [x]
    S2 Smart TimeLock;Smart TimeLock Service;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [x]
    S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
    S3 klflt;Kaspersky Lab Kernel DLL;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x]
    S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x]
    S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
    S3 kltap;Kaspersky Security Data Escort Adapter;c:\windows\system32\DRIVERS\kltap.sys;c:\windows\SYSNATIVE\DRIVERS\kltap.sys [x]
    S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
    S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x]
    S3 Neo_braz;VPN Client Device Driver - braz;c:\windows\system32\DRIVERS\Neo_0005.sys;c:\windows\SYSNATIVE\DRIVERS\Neo_0005.sys [x]
    S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
    S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
    S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
    S3 NvStreamNetworkSvc;NVIDIA Streamer Network Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [x]
    S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *Deregistered* - ESProtectionDriver
    *Deregistered* - TrueSight
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
    2017-03-24 09:44 1368920 ----a-w- c:\program files (x86)\Google\Chrome\Application\56.0.2924.87\Installer\chrmstp.exe
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2014-07-02 10464536]
    "SoftEther VPN Client UI Helper"="c:\program files\SoftEther VPN Client\vpnclient_x64.exe" [2015-05-02 5189176]
    "Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]
    "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2016-06-15 2398776]
    "Malwarebytes TrayApp"="c:\program files\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe" [2017-01-20 2780112]
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    mDefault_Search_URL = www.google.com
    mDefault_Page_URL = www.google.com
    mStart Page = www.google.com
    mLocal Page = c:\windows\SysWOW64\blank.htm
    mSearch Page = www.google.com
    Trusted Zone: clonewarsadventures.com
    Trusted Zone: freerealms.com
    Trusted Zone: soe.com
    Trusted Zone: sony.com
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Wow6432Node-HKCU-Run-GNE_SwapScreen - c:\users\Asce\Desktop\SwapScreen.exe
    HKLM-Run-VMSnap3 - c:\windows\VMSnap3.exe
    HKLM-Run-Domino - c:\windows\Domino.exe
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\S-1-5-21-1292172697-4276861399-4271014393-1000\Software\SecuROM\License information*]
    "datasecu"=hex:40,8a,3f,71,dc,11,75,d6,c1,58,e5,a4,f2,1b,b0,2c,0d,cf,4f,fa,52,
    37,36,0d,b2,15,fe,33,23,79,15,ec,28,ad,d0,11,96,aa,43,85,f0,82,29,6b,c0,a9,\
    "rkeysecu"=hex:14,69,eb,d1,0f,f6,0d,53,12,94,81,51,4d,80,1e,91
    .
    [HKEY_USERS\S-1-5-21-1292172697-4276861399-4271014393-1000_Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
    @Denied: (Full) (Everyone)
    @Allowed: (Read) (RestrictedCode)
    "scansk"=hex(0):2a,a9,57,30,47,d5,5b,d1,17,d1,dc,99,4a,6c,bd,6b,ce,4c,d5,86,d0,
    7b,bf,1e,43,43,dc,29,cd,66,5b,14,80,3a,7c,69,fa,75,1f,7a,00,00,00,00,00,00,\
    .
    [HKEY_USERS\S-1-5-21-1292172697-4276861399-4271014393-1000_Classes\Wow6432Node\CLSID\{c7f78aad-50fe-4595-bb90-f1b121d4b01f}]
    @Denied: (Full) (Everyone)
    @Allowed: (Read) (RestrictedCode)
    "Model"=dword:00000156
    "Therad"=dword:0000001e
    "MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
    38,95,44,d7,18,be,e1,28,c7,b4,b6,c7,57,5f,49,ba,40,58,2d,27,a9,be,b1,47,30,\
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    Completion time: 2017-03-28 09:19:03
    ComboFix-quarantined-files.txt 2017-03-28 06:19
    .
    Pre-Run: 259,750,535,168 bytes free
    Post-Run: 260,588,486,656 bytes free
    .
    - - End Of File - - CDC173FC097D24C12D3AA559A215F6DA
    A36C5E4F47E84449FF07ED3517B43A31

  2. #17
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,203
    Download attached fixlist.txt file and save it to the Desktop.
    NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Run FRST(FRST64) and press the Fix button just once and wait.
    The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
    Attached Files Attached Files

  3. #18
    Join Date
    Mar 2017
    Posts
    17
    Fix result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017
    Ran by Asce (28-03-2017 13:48:54) Run:1
    Running from C:\Users\Asce\Desktop
    Loaded Profiles: Asce (Available Profiles: Asce)
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\MountPoints2: {03f5a58e-0cdf-11e4-9364-fa05310c68ca} - F:\AutoRun.exe
    HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\MountPoints2: {10963882-1014-11e4-ba5d-c05a936a09ba} - F:\setup.exe
    GroupPolicy: Restriction <======= ATTENTION
    S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X]
    2015-11-05 01:14 - 2017-03-24 12:51 - 0007608 _____ () C:\Users\Asce\AppData\Local\Resmon.ResmonCfg
    2015-12-11 22:02 - 2015-12-11 22:02 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
    2015-10-23 20:47 - 2015-10-23 20:47 - 2892128 _____ (AVG Technologies) C:\Users\Asce\AppData\Local\Temp\avg-ae9d4a66-87be-4c57-9f03-a23b13fdc342.exe
    2016-01-05 21:18 - 2015-11-12 17:54 - 0091048 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Asce\AppData\Local\Temp\avguirn_0899728453.exe
    2017-03-25 05:02 - 2015-10-20 04:09 - 1730496 _____ (Microsoft Corporation) C:\Users\Asce\AppData\Local\Temp\dllnt_dump.dll
    2015-10-08 20:45 - 2015-10-08 20:49 - 0204800 _____ (Sony DADC Austria AG) C:\Users\Asce\AppData\Local\Temp\drm_dyndata_7400009.dll
    2015-11-10 22:16 - 2015-11-11 00:19 - 0035680 _____ () C:\Users\Asce\AppData\Local\Temp\i4jdel0.exe
    2015-07-18 16:30 - 2015-07-18 16:30 - 0011264 _____ ( ) C:\Users\Asce\AppData\Local\Temp\iuo4idyi.dll
    2015-10-24 22:18 - 2015-12-08 23:45 - 56061688 _____ (Rockstar Games) C:\Users\Asce\AppData\Local\Temp\Social%20Club%20v1.1.6.8%20Setup.exe
    2015-12-21 04:39 - 2015-12-21 04:39 - 56838704 _____ (Rockstar Games) C:\Users\Asce\AppData\Local\Temp\Social%20Club%20v1.1.6.9%20Setup.exe
    2017-03-24 12:48 - 2017-03-24 12:48 - 14456872 _____ (Microsoft Corporation) C:\Users\Asce\AppData\Local\Temp\vc_redist.x86.exe
    2015-08-03 02:58 - 2015-08-03 02:58 - 0118784 _____ () C:\Users\Asce\AppData\Local\Temp\xmlUpdater.exe
    2017-03-25 07:46 - 2017-03-25 07:46 - 0503808 _____ () C:\Users\Asce\AppData\Local\Temp\xuninst.exe
    2017-03-25 07:09 - 2015-02-08 18:49 - 0455600 _____ (Macrovision Corporation) C:\Users\Asce\AppData\Local\Temp\_isFB2F.exe

    *****************

    HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{03f5a58e-0cdf-11e4-9364-fa05310c68ca} => key not found.
    HKCR\CLSID\{03f5a58e-0cdf-11e4-9364-fa05310c68ca} => key not found.
    HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{10963882-1014-11e4-ba5d-c05a936a09ba} => key removed successfully
    HKCR\CLSID\{10963882-1014-11e4-ba5d-c05a936a09ba} => key not found.
    C:\Windows\system32\GroupPolicy\Machine => moved successfully
    C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
    C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
    HKLM\System\CurrentControlSet\Services\IntcAzAudAddService => key removed successfully
    IntcAzAudAddService => service removed successfully
    C:\Users\Asce\AppData\Local\Resmon.ResmonCfg => moved successfully
    C:\ProgramData\DP45977C.lfl => moved successfully
    "C:\Users\Asce\AppData\Local\Temp\avg-ae9d4a66-87be-4c57-9f03-a23b13fdc342.exe" => not found.
    "C:\Users\Asce\AppData\Local\Temp\avguirn_0899728453.exe" => not found.
    "C:\Users\Asce\AppData\Local\Temp\dllnt_dump.dll" => not found.
    "C:\Users\Asce\AppData\Local\Temp\drm_dyndata_7400009.dll" => not found.
    "C:\Users\Asce\AppData\Local\Temp\i4jdel0.exe" => not found.
    "C:\Users\Asce\AppData\Local\Temp\iuo4idyi.dll" => not found.
    "C:\Users\Asce\AppData\Local\Temp\Social%20Club%20v1.1.6.8%20Setup.exe" => not found.
    "C:\Users\Asce\AppData\Local\Temp\Social%20Club%20v1.1.6.9%20Setup.exe" => not found.
    "C:\Users\Asce\AppData\Local\Temp\vc_redist.x86.exe" => not found.
    "C:\Users\Asce\AppData\Local\Temp\xmlUpdater.exe" => not found.
    "C:\Users\Asce\AppData\Local\Temp\xuninst.exe" => not found.
    "C:\Users\Asce\AppData\Local\Temp\_isFB2F.exe" => not found.


    The system needed a reboot.

    ==== End of Fixlog 13:48:55 ====

  4. #19
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,203
    Last scans...

    Download Security Check from here or here and save it to your Desktop.

    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.



    NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
    NOTE 2. SecurityCheck may produce some false warning(s), so leave the results reading to me.
    NOTE 3. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message restart computer and Security Check should run


    Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    Make sure the following options are checked:

    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
    • Other Services



    Press "Scan".
    It will create a log (FSS.txt) in the same directory the tool is run.
    Please copy and paste the log to your reply.


    Download Temp File Cleaner (TFC)
    Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe

    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.




    Download Sophos Free Virus Removal Tool and save it to your desktop.

    • Double click the icon and select Run
    • Click Next
    • Select I accept the terms in this license agreement, then click Next twice
    • Click Install
    • Click Finish to launch the program
    • Once the virus database has been updated click Start Scanning
    • If any threats are found click Details, then View log file... (bottom left hand corner)
    • Copy and paste the results in your reply
    • Close the Notepad document, close the Threat Details screen, then click Start cleanup
    • Click Exit to close the program

  5. #20
    Join Date
    Mar 2017
    Posts
    17
    Farbar Service Scanner Version: 27-01-2016
    Ran by Asce (administrator) on 29-03-2017 at 16:01:28
    Running from "C:\Users\Asce\AppData\Local\Temp\scoped_dir1972_2862"
    Microsoft Windows 7 Home Premium Service Pack 1 (X64)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Localhost is accessible.
    LAN connected.
    Google IP is accessible.
    Google.com is accessible.
    Yahoo.com is accessible.


    Windows Firewall:
    =============

    Firewall Disabled Policy:
    ==================


    System Restore:
    ============

    System Restore Policy:
    ========================


    Action Center:
    ============

    wscsvc Service is not running. Checking service configuration:
    The start type of wscsvc service is OK.
    The ImagePath of wscsvc service is OK.
    The ServiceDll of wscsvc service is OK.


    Windows Update:
    ============

    Windows Autoupdate Disabled Policy:
    ============================


    Windows Defender:
    ==============

    Other Services:
    ==============


    File Check:
    ========
    C:\Windows\System32\nsisvc.dll => File is digitally signed
    C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
    C:\Windows\System32\dhcpcore.dll => File is digitally signed
    C:\Windows\System32\drivers\afd.sys => File is digitally signed
    C:\Windows\System32\drivers\tdx.sys => File is digitally signed
    C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
    C:\Windows\System32\dnsrslvr.dll => File is digitally signed
    C:\Windows\System32\dnsapi.dll => File is digitally signed
    C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
    C:\Windows\System32\mpssvc.dll => File is digitally signed
    C:\Windows\System32\bfe.dll => File is digitally signed
    C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
    C:\Windows\System32\SDRSVC.dll => File is digitally signed
    C:\Windows\System32\vssvc.exe => File is digitally signed
    C:\Windows\System32\wscsvc.dll => File is digitally signed
    C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
    C:\Windows\System32\wuaueng.dll => File is digitally signed
    C:\Windows\System32\qmgr.dll => File is digitally signed
    C:\Windows\System32\es.dll => File is digitally signed
    C:\Windows\System32\cryptsvc.dll => File is digitally signed
    C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
    C:\Windows\System32\ipnathlp.dll => File is digitally signed
    C:\Windows\System32\iphlpsvc.dll => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed


    **** End of log ****

  6. #21
    Join Date
    Mar 2017
    Posts
    17
    Results of screen317's Security Check version 1.014 --- 12/23/15
    Windows 7 Service Pack 1 x64 (UAC is enabled)
    Internet Explorer 11
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Security Center service is not running! This report may not be accurate!
    Windows Firewall Enabled!
    Kaspersky Anti-Virus
    Malwarebytes
    Antivirus up to date!
    `````````Anti-malware/Other Utilities Check:`````````
    Java 8 Update 40
    Java version 32-bit out of Date!
    Adobe Flash Player 25.0.0.127
    Adobe Reader XI
    Google Chrome (56.0.2924.87)
    Google Chrome (SetupMetrics...)
    ````````Process Check: objlist.exe by Laurent````````
    Malwarebytes Anti-Malware mbamservice.exe
    Kaspersky Lab Kaspersky Anti-Virus 17.0.0 avp.exe
    Kaspersky Lab Kaspersky Anti-Virus 17.0.0 avpui.exe
    Kaspersky Lab Kaspersky Anti-Virus 17.0.0 x64 wmi64.exe
    Malwarebytes Anti-Malware mbamtray.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 1%
    ````````````````````End of Log``````````````````````


    ComboFix 17-03-28.01 - Asce 03/28/2017 9:08.1.8 - x64
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6142.4577 [GMT 3:00]
    Running from: c:\users\Asce\Desktop\ComboFix.exe
    AV: Kaspersky Anti-Virus *Disabled/Updated* {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
    AV: Malwarebytes *Disabled/Updated* {23007AD3-69FE-687C-2629-D584AFFAF72B}
    SP: Kaspersky Anti-Virus *Disabled/Updated* {3D579475-6DDE-A186-1569-44B9F9DE8725}
    SP: Malwarebytes *Disabled/Updated* {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    C:\Install.exe
    c:\programdata\ntuser.pol
    c:\users\Asce\AppData\Local\assembly\tmp
    c:\users\Asce\AppData\Local\Temp\VPN_6677\B7091C83.dll
    c:\windows\msdownld.tmp
    c:\windows\TEMP\VPN_3742\B7091C83.dll
    .
    .
    ((((((((((((((((((((((((( Files Created from 2017-02-28 to 2017-03-28 )))))))))))))))))))))))))))))))
    .
    .
    2017-03-28 06:16 . 2017-03-28 06:16 -------- d-----w- c:\users\Default\AppData\Local\temp
    2017-03-25 07:55 . 2017-03-25 07:55 -------- d-----w- c:\windows\system32\wbem\Framework
    2017-03-25 07:53 . 2017-03-25 07:53 -------- d-----w- c:\program files (x86)\GPU Temp
    2017-03-25 06:47 . 2017-03-25 06:47 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{59896AD4-81AA-41F7-A119-D82B1CF4AEDD}\offreg.3400.dll
    2017-03-25 05:01 . 2016-04-14 05:38 56384 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
    2017-03-25 05:01 . 2016-04-14 05:38 113216 ----a-w- c:\windows\system32\nvaudcap64v.dll
    2017-03-25 05:01 . 2016-04-14 05:38 102976 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
    2017-03-25 04:41 . 2017-03-25 04:50 -------- d-----w- c:\windows\system32\MRT
    2017-03-25 04:37 . 2013-05-06 06:13 110176 ----a-w- c:\windows\system32\klfphc.dll
    2017-03-25 04:37 . 2017-03-25 04:37 -------- d-----w- c:\windows\ELAMBKUP
    2017-03-25 04:36 . 2017-03-28 04:42 -------- d-----w- c:\programdata\Kaspersky Lab
    2017-03-25 04:36 . 2017-03-25 04:38 -------- d-----w- c:\program files (x86)\Kaspersky Lab
    2017-03-25 04:36 . 2017-03-25 05:10 195296 ----a-w- c:\windows\system32\drivers\klflt.sys
    2017-03-25 04:36 . 2017-03-25 05:10 1035488 ----a-w- c:\windows\system32\drivers\klif.sys
    2017-03-25 04:35 . 2017-03-22 11:05 12774864 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{59896AD4-81AA-41F7-A119-D82B1CF4AEDD}\mpengine.dll
    2017-03-25 04:34 . 2017-03-25 04:35 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
    2017-03-25 03:54 . 2017-03-25 04:14 -------- d-----w- C:\AdwCleaner
    2017-03-25 02:03 . 2017-03-28 04:06 28272 ----a-w- c:\windows\system32\drivers\TrueSight.sys
    2017-03-25 02:02 . 2017-03-25 02:02 -------- d-----w- c:\programdata\RogueKiller
    2017-03-25 01:58 . 2017-03-25 01:58 -------- d-----w- c:\program files\RogueKiller
    2017-03-24 12:08 . 2017-03-28 03:04 -------- d-----w- C:\FRST
    2017-03-24 10:10 . 2017-03-27 13:41 111544 ----a-w- c:\windows\system32\drivers\farflt.sys
    2017-03-24 10:10 . 2017-03-28 05:34 82208 ----a-w- c:\windows\system32\drivers\mwac.sys
    2017-03-24 10:10 . 2017-03-28 02:25 43968 ----a-w- c:\windows\system32\drivers\mbam.sys
    2017-03-24 10:09 . 2017-03-25 06:17 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
    2017-03-24 10:09 . 2017-03-28 02:25 251840 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
    2017-03-24 10:09 . 2017-03-28 02:25 186304 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
    2017-03-24 10:09 . 2017-02-24 04:23 77408 ----a-w- c:\windows\system32\drivers\mbae64.sys
    2017-03-24 10:09 . 2017-03-24 10:10 -------- d-----w- c:\programdata\Malwarebytes
    2017-03-24 10:09 . 2017-03-24 10:09 -------- d-----w- c:\program files\Malwarebytes
    2017-03-24 09:43 . 2017-03-27 13:20 -------- d-----w- c:\users\Asce\AppData\Local\NVIDIA Corporation
    2017-03-24 09:37 . 2017-03-27 13:20 -------- d-----w- c:\users\Asce\AppData\Local\NVIDIA
    2017-03-24 09:35 . 2017-03-28 02:24 -------- d-----w- c:\programdata\NVIDIA
    2017-03-24 09:35 . 2016-01-23 01:12 110016 ----a-w- c:\windows\SysWow64\nvStreaming.exe
    2017-03-24 09:34 . 2016-01-23 01:04 6368312 ----a-w- c:\windows\system32\nvcpl.dll
    2017-03-24 09:34 . 2016-01-23 01:04 2992064 ----a-w- c:\windows\system32\nvsvc64.dll
    2017-03-24 09:34 . 2016-01-23 01:04 2563128 ----a-w- c:\windows\system32\nvsvcr.dll
    2017-03-24 09:34 . 2016-01-23 01:04 1263040 ----a-w- c:\windows\system32\nvvsvc.exe
    2017-03-24 09:34 . 2016-01-23 01:04 83512 ----a-w- c:\windows\system32\nv3dappshextr.dll
    2017-03-24 09:34 . 2016-01-23 01:04 71224 ----a-w- c:\windows\system32\nvshext.dll
    2017-03-24 09:34 . 2016-01-23 01:04 532024 ----a-w- c:\windows\system32\nv3dappshext.dll
    2017-03-24 09:34 . 2016-01-23 01:04 393784 ----a-w- c:\windows\system32\nvmctray.dll
    2017-03-24 09:34 . 2016-01-22 21:07 6125650 ----a-w- c:\windows\system32\nvcoproc.bin
    2017-03-24 09:34 . 2017-03-25 07:51 -------- d-----w- c:\programdata\NVIDIA Corporation
    2017-03-24 09:32 . 2016-02-12 18:52 98816 ----a-w- c:\windows\system32\wudriver.dll
    2017-03-24 09:31 . 2016-05-11 17:02 483840 ----a-w- c:\windows\system32\StructuredQuery.dll
    2017-03-24 09:30 . 2016-04-06 15:27 668160 ----a-w- c:\program files\Windows Journal\MSPVWCTL.DLL
    2017-03-24 09:25 . 2016-07-22 14:58 142336 ----a-w- c:\windows\system32\poqexec.exe
    2017-03-24 09:25 . 2016-07-22 14:51 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
    2017-03-24 09:10 . 2017-03-25 07:51 -------- d-----w- c:\program files\NVIDIA Corporation
    2017-03-24 09:10 . 2017-03-24 09:10 -------- d-----w- C:\NVIDIA
    2017-03-24 09:08 . 2017-03-24 09:08 20647512 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2017-03-28 02:24 . 2015-05-18 12:56 25640 ----a-w- c:\windows\gdrv.sys
    2017-03-25 07:49 . 2015-10-04 20:42 802904 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
    2017-03-25 07:49 . 2015-10-04 20:42 144472 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2017-03-25 05:10 . 2016-06-14 15:47 199392 ----a-w- c:\windows\system32\drivers\kneps.sys
    2017-03-25 05:10 . 2016-12-26 20:03 135904 ----a-w- c:\windows\system32\drivers\klwtp.sys
    2017-03-25 05:10 . 2016-12-26 20:03 313112 ----a-w- c:\windows\system32\drivers\klhk.sys
    2017-02-09 16:14 . 2017-03-24 09:32 44032 ----a-w- c:\windows\apppatch\acwow64.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2014-03-04 3696912]
    "Octoshape Streaming Services"="c:\users\Asce\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2011-03-24 107800]
    "f.lux"="c:\users\Asce\AppData\Local\FluxSoftware\Flux\flux.exe" [2013-10-23 1017224]
    "Voobly"="c:\program files (x86)\Voobly\voobly.exe" [2015-01-19 159744]
    "ISUSPM Startup"="c:\progra~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-17 221184]
    "SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2015-05-27 787592]
    "Steam"="c:\steam\steam.exe" [2017-03-24 3019552]
    "Spotify Web Helper"="c:\users\Asce\AppData\Roaming\Spotify\SpotifyWebHelper.exe" [2015-12-17 2346096]
    "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2015-12-17 50378880]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "StartCCC"="c:\program files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-11-20 767176]
    "JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-01-19 43632]
    "NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-11-20 106496]
    "ISUSScheduler"="c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]
    "EasyTuneVI"="c:\program files (x86)\GIGABYTE\ET6\ETcall.exe" [2007-07-26 20480]
    "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2015-11-12 5565448]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    SoftEther VPN Client Manager Startup.lnk - c:\program files\SoftEther VPN Client\vpncmgr_x64.exe /startup [2015-5-2 5379640]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]
    @="Service"
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
    "DisableMonitoring"=dword:00000001
    .
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
    R2 MBAMService;Malwarebytes Service;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe [x]
    R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
    R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x]
    R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
    R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
    R3 EasyAntiCheat;EasyAntiCheat;c:\windows\system32\EasyAntiCheat.exe;c:\windows\SYSNATIVE\EasyAntiCheat.exe [x]
    R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
    R3 klvssbrigde64;klvssbrigde64;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\x64\vssbridge64.exe;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\x64\vssbridge64.exe [x]
    R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
    R3 Origin Client Service;Origin Client Service;c:\program files (x86)\Origin\OriginClientService.exe;c:\program files (x86)\Origin\OriginClientService.exe [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
    R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
    R3 VASDeviceDrm;Virtual Audio Streaming with Drm (WDM);c:\windows\system32\drivers\vasdDev.sys;c:\windows\SYSNATIVE\drivers\vasdDev.sys [x]
    R3 vvftav303;vvftav303;c:\windows\system32\drivers\vvftav303.sys;c:\windows\SYSNATIVE\drivers\vvftav303.sys [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
    R3 ZSMC0303;A4 TECH PC Camera H;c:\windows\system32\Drivers\usbVM303.sys;c:\windows\SYSNATIVE\Drivers\usbVM303.sys [x]
    S0 cm_km;AO Kaspersky Lab Cryptographic Module x64 (56 bit);c:\windows\system32\DRIVERS\cm_km.sys;c:\windows\SYSNATIVE\DRIVERS\cm_km.sys [x]
    S0 klbackupdisk;Kaspersky Lab klbackupdisk;c:\windows\system32\DRIVERS\klbackupdisk.sys;c:\windows\SYSNATIVE\DRIVERS\klbackupdisk.sys [x]
    S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
    S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
    S1 klbackupflt;Kaspersky Lab klbackupflt;c:\windows\system32\DRIVERS\klbackupflt.sys;c:\windows\SYSNATIVE\DRIVERS\klbackupflt.sys [x]
    S1 klhk;Kaspersky Lab service driver;c:\windows\system32\DRIVERS\klhk.sys;c:\windows\SYSNATIVE\DRIVERS\klhk.sys [x]
    S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
    S1 klpd;Kaspersky Lab format recognizer driver;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x]
    S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x]
    S1 Klwtp;KLwtp - WFP callout traffic inspector;c:\windows\system32\DRIVERS\klwtp.sys;c:\windows\SYSNATIVE\DRIVERS\klwtp.sys [x]
    S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x]
    S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
    S2 AVP17.0.0;Kaspersky Anti-Virus Service 17.0.0;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\avp.exe;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\avp.exe [x]
    S2 DES2 Service;DES2 Service for Energy Saving.;c:\program files (x86)\Gigabyte\EnergySaver2\des2svr.exe;c:\program files (x86)\Gigabyte\EnergySaver2\des2svr.exe [x]
    S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
    S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
    S2 JMB36X;JMB36X;c:\windows\SysWOW64\XSrvSetup.exe;c:\windows\SysWOW64\XSrvSetup.exe [x]
    S2 kldisk;kldisk;c:\windows\system32\DRIVERS\kldisk.sys;c:\windows\SYSNATIVE\DRIVERS\kldisk.sys [x]
    S2 KSDE1.0.0;Kaspersky Secure Connection Service 1.0.0;c:\program files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe;c:\program files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [x]
    S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
    S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
    S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [x]
    S2 SEVPNCLIENT;SoftEther VPN Client;c:\program files\SoftEther VPN Client\vpnclient_x64.exe;c:\program files\SoftEther VPN Client\vpnclient_x64.exe [x]
    S2 Smart TimeLock;Smart TimeLock Service;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [x]
    S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
    S3 klflt;Kaspersky Lab Kernel DLL;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x]
    S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x]
    S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
    S3 kltap;Kaspersky Security Data Escort Adapter;c:\windows\system32\DRIVERS\kltap.sys;c:\windows\SYSNATIVE\DRIVERS\kltap.sys [x]
    S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
    S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x]
    S3 Neo_braz;VPN Client Device Driver - braz;c:\windows\system32\DRIVERS\Neo_0005.sys;c:\windows\SYSNATIVE\DRIVERS\Neo_0005.sys [x]
    S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
    S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
    S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
    S3 NvStreamNetworkSvc;NVIDIA Streamer Network Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [x]
    S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *Deregistered* - ESProtectionDriver
    *Deregistered* - TrueSight
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
    2017-03-24 09:44 1368920 ----a-w- c:\program files (x86)\Google\Chrome\Application\56.0.2924.87\Installer\chrmstp.exe
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2014-07-02 10464536]
    "SoftEther VPN Client UI Helper"="c:\program files\SoftEther VPN Client\vpnclient_x64.exe" [2015-05-02 5189176]
    "Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]
    "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2016-06-15 2398776]
    "Malwarebytes TrayApp"="c:\program files\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe" [2017-01-20 2780112]
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    mDefault_Search_URL = www.google.com
    mDefault_Page_URL = www.google.com
    mStart Page = www.google.com
    mLocal Page = c:\windows\SysWOW64\blank.htm
    mSearch Page = www.google.com
    Trusted Zone: clonewarsadventures.com
    Trusted Zone: freerealms.com
    Trusted Zone: soe.com
    Trusted Zone: sony.com
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Wow6432Node-HKCU-Run-GNE_SwapScreen - c:\users\Asce\Desktop\SwapScreen.exe
    HKLM-Run-VMSnap3 - c:\windows\VMSnap3.exe
    HKLM-Run-Domino - c:\windows\Domino.exe
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\S-1-5-21-1292172697-4276861399-4271014393-1000\Software\SecuROM\License information*]
    "datasecu"=hex:40,8a,3f,71,dc,11,75,d6,c1,58,e5,a4,f2,1b,b0,2c,0d,cf,4f,fa,52,
    37,36,0d,b2,15,fe,33,23,79,15,ec,28,ad,d0,11,96,aa,43,85,f0,82,29,6b,c0,a9,\
    "rkeysecu"=hex:14,69,eb,d1,0f,f6,0d,53,12,94,81,51,4d,80,1e,91
    .
    [HKEY_USERS\S-1-5-21-1292172697-4276861399-4271014393-1000_Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
    @Denied: (Full) (Everyone)
    @Allowed: (Read) (RestrictedCode)
    "scansk"=hex(0):2a,a9,57,30,47,d5,5b,d1,17,d1,dc,99,4a,6c,bd,6b,ce,4c,d5,86,d0,
    7b,bf,1e,43,43,dc,29,cd,66,5b,14,80,3a,7c,69,fa,75,1f,7a,00,00,00,00,00,00,\
    .
    [HKEY_USERS\S-1-5-21-1292172697-4276861399-4271014393-1000_Classes\Wow6432Node\CLSID\{c7f78aad-50fe-4595-bb90-f1b121d4b01f}]
    @Denied: (Full) (Everyone)
    @Allowed: (Read) (RestrictedCode)
    "Model"=dword:00000156
    "Therad"=dword:0000001e
    "MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
    38,95,44,d7,18,be,e1,28,c7,b4,b6,c7,57,5f,49,ba,40,58,2d,27,a9,be,b1,47,30,\
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    Completion time: 2017-03-28 09:19:03
    ComboFix-quarantined-files.txt 2017-03-28 06:19
    .
    Pre-Run: 259,750,535,168 bytes free
    Post-Run: 260,588,486,656 bytes free
    .
    - - End Of File - - CDC173FC097D24C12D3AA559A215F6DA
    A36C5E4F47E84449FF07ED3517B43A31

    Fix result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017
    Ran by Asce (28-03-2017 13:48:54) Run:1
    Running from C:\Users\Asce\Desktop
    Loaded Profiles: Asce (Available Profiles: Asce)
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\MountPoints2: {03f5a58e-0cdf-11e4-9364-fa05310c68ca} - F:\AutoRun.exe
    HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\MountPoints2: {10963882-1014-11e4-ba5d-c05a936a09ba} - F:\setup.exe
    GroupPolicy: Restriction <======= ATTENTION
    S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X]
    2015-11-05 01:14 - 2017-03-24 12:51 - 0007608 _____ () C:\Users\Asce\AppData\Local\Resmon.ResmonCfg
    2015-12-11 22:02 - 2015-12-11 22:02 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
    2015-10-23 20:47 - 2015-10-23 20:47 - 2892128 _____ (AVG Technologies) C:\Users\Asce\AppData\Local\Temp\avg-ae9d4a66-87be-4c57-9f03-a23b13fdc342.exe
    2016-01-05 21:18 - 2015-11-12 17:54 - 0091048 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Asce\AppData\Local\Temp\avguirn_0899728453.exe
    2017-03-25 05:02 - 2015-10-20 04:09 - 1730496 _____ (Microsoft Corporation) C:\Users\Asce\AppData\Local\Temp\dllnt_dump.dll
    2015-10-08 20:45 - 2015-10-08 20:49 - 0204800 _____ (Sony DADC Austria AG) C:\Users\Asce\AppData\Local\Temp\drm_dyndata_7400009.dll
    2015-11-10 22:16 - 2015-11-11 00:19 - 0035680 _____ () C:\Users\Asce\AppData\Local\Temp\i4jdel0.exe
    2015-07-18 16:30 - 2015-07-18 16:30 - 0011264 _____ ( ) C:\Users\Asce\AppData\Local\Temp\iuo4idyi.dll
    2015-10-24 22:18 - 2015-12-08 23:45 - 56061688 _____ (Rockstar Games) C:\Users\Asce\AppData\Local\Temp\Social%20Club%20v1.1.6.8%20Setup.exe
    2015-12-21 04:39 - 2015-12-21 04:39 - 56838704 _____ (Rockstar Games) C:\Users\Asce\AppData\Local\Temp\Social%20Club%20v1.1.6.9%20Setup.exe
    2017-03-24 12:48 - 2017-03-24 12:48 - 14456872 _____ (Microsoft Corporation) C:\Users\Asce\AppData\Local\Temp\vc_redist.x86.exe
    2015-08-03 02:58 - 2015-08-03 02:58 - 0118784 _____ () C:\Users\Asce\AppData\Local\Temp\xmlUpdater.exe
    2017-03-25 07:46 - 2017-03-25 07:46 - 0503808 _____ () C:\Users\Asce\AppData\Local\Temp\xuninst.exe
    2017-03-25 07:09 - 2015-02-08 18:49 - 0455600 _____ (Macrovision Corporation) C:\Users\Asce\AppData\Local\Temp\_isFB2F.exe

    *****************

    HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{03f5a58e-0cdf-11e4-9364-fa05310c68ca} => key not found.
    HKCR\CLSID\{03f5a58e-0cdf-11e4-9364-fa05310c68ca} => key not found.
    HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{10963882-1014-11e4-ba5d-c05a936a09ba} => key removed successfully
    HKCR\CLSID\{10963882-1014-11e4-ba5d-c05a936a09ba} => key not found.
    C:\Windows\system32\GroupPolicy\Machine => moved successfully
    C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
    C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
    HKLM\System\CurrentControlSet\Services\IntcAzAudAddService => key removed successfully
    IntcAzAudAddService => service removed successfully
    C:\Users\Asce\AppData\Local\Resmon.ResmonCfg => moved successfully
    C:\ProgramData\DP45977C.lfl => moved successfully
    "C:\Users\Asce\AppData\Local\Temp\avg-ae9d4a66-87be-4c57-9f03-a23b13fdc342.exe" => not found.
    "C:\Users\Asce\AppData\Local\Temp\avguirn_0899728453.exe" => not found.
    "C:\Users\Asce\AppData\Local\Temp\dllnt_dump.dll" => not found.
    "C:\Users\Asce\AppData\Local\Temp\drm_dyndata_7400009.dll" => not found.
    "C:\Users\Asce\AppData\Local\Temp\i4jdel0.exe" => not found.
    "C:\Users\Asce\AppData\Local\Temp\iuo4idyi.dll" => not found.
    "C:\Users\Asce\AppData\Local\Temp\Social%20Club%20v1.1.6.8%20Setup.exe" => not found.
    "C:\Users\Asce\AppData\Local\Temp\Social%20Club%20v1.1.6.9%20Setup.exe" => not found.
    "C:\Users\Asce\AppData\Local\Temp\vc_redist.x86.exe" => not found.
    "C:\Users\Asce\AppData\Local\Temp\xmlUpdater.exe" => not found.
    "C:\Users\Asce\AppData\Local\Temp\xuninst.exe" => not found.
    "C:\Users\Asce\AppData\Local\Temp\_isFB2F.exe" => not found.


    The system needed a reboot.

    ==== End of Fixlog 13:48:55 ====

  7. #22
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,203
    Not sure why you posted Combofix and fixlist log.
    I need Sophos log.

  8. #23
    Join Date
    Mar 2017
    Posts
    17
    sophos literally takes 10 hour to scan i can't scan it. Is it normal do i need to keep the machine wake up that much time ?

  9. #24
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,203
    If it displays progress keep it going.
    If it's stuck...

    Please run a free online scan with the ESET Online Scanner


    • Disable your antivirus program
    • Under "ESET Online Scanner" click on "Scan now" button.
    • It'll download small file "esetonlinescanner_enu.exe".
    • Double click on downloaded file.
    • Click on Accept button.
    • Checkmark "Disable detection of potentially unwanted applications".
    • Click Scan
    • Accept any security warnings from your browser.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.

Thread Information

Users Browsing this Thread

There are currently 2 users browsing this thread. (0 members and 2 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •