March 28th, 2017, 08:46 AM
#16
I was able to run combofix.
ComboFix 17-03-28.01 - Asce 03/28/2017 9:08.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6142.4577 [GMT 3:00]
Running from: c:\users\Asce\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *Disabled/Updated* {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
AV: Malwarebytes *Disabled/Updated* {23007AD3-69FE-687C-2629-D584AFFAF72B}
SP: Kaspersky Anti-Virus *Disabled/Updated* {3D579475-6DDE-A186-1569-44B9F9DE8725}
SP: Malwarebytes *Disabled/Updated* {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\programdata\ntuser.pol
c:\users\Asce\AppData\Local\assembly\tmp
c:\users\Asce\AppData\Local\Temp\VPN_6677\B7091C83.dll
c:\windows\msdownld.tmp
c:\windows\TEMP\VPN_3742\B7091C83.dll
.
.
((((((((((((((((((((((((( Files Created from 2017-02-28 to 2017-03-28 )))))))))))))))))))))))))))))))
.
.
2017-03-28 06:16 . 2017-03-28 06:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2017-03-25 07:55 . 2017-03-25 07:55 -------- d-----w- c:\windows\system32\wbem\Framework
2017-03-25 07:53 . 2017-03-25 07:53 -------- d-----w- c:\program files (x86)\GPU Temp
2017-03-25 06:47 . 2017-03-25 06:47 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{59896AD4-81AA-41F7-A119-D82B1CF4AEDD}\offreg.3400.dll
2017-03-25 05:01 . 2016-04-14 05:38 56384 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2017-03-25 05:01 . 2016-04-14 05:38 113216 ----a-w- c:\windows\system32\nvaudcap64v.dll
2017-03-25 05:01 . 2016-04-14 05:38 102976 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2017-03-25 04:41 . 2017-03-25 04:50 -------- d-----w- c:\windows\system32\MRT
2017-03-25 04:37 . 2013-05-06 06:13 110176 ----a-w- c:\windows\system32\klfphc.dll
2017-03-25 04:37 . 2017-03-25 04:37 -------- d-----w- c:\windows\ELAMBKUP
2017-03-25 04:36 . 2017-03-28 04:42 -------- d-----w- c:\programdata\Kaspersky Lab
2017-03-25 04:36 . 2017-03-25 04:38 -------- d-----w- c:\program files (x86)\Kaspersky Lab
2017-03-25 04:36 . 2017-03-25 05:10 195296 ----a-w- c:\windows\system32\drivers\klflt.sys
2017-03-25 04:36 . 2017-03-25 05:10 1035488 ----a-w- c:\windows\system32\drivers\klif.sys
2017-03-25 04:35 . 2017-03-22 11:05 12774864 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{59896AD4-81AA-41F7-A119-D82B1CF4AEDD}\mpengine.dll
2017-03-25 04:34 . 2017-03-25 04:35 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2017-03-25 03:54 . 2017-03-25 04:14 -------- d-----w- C:\AdwCleaner
2017-03-25 02:03 . 2017-03-28 04:06 28272 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2017-03-25 02:02 . 2017-03-25 02:02 -------- d-----w- c:\programdata\RogueKiller
2017-03-25 01:58 . 2017-03-25 01:58 -------- d-----w- c:\program files\RogueKiller
2017-03-24 12:08 . 2017-03-28 03:04 -------- d-----w- C:\FRST
2017-03-24 10:10 . 2017-03-27 13:41 111544 ----a-w- c:\windows\system32\drivers\farflt.sys
2017-03-24 10:10 . 2017-03-28 05:34 82208 ----a-w- c:\windows\system32\drivers\mwac.sys
2017-03-24 10:10 . 2017-03-28 02:25 43968 ----a-w- c:\windows\system32\drivers\mbam.sys
2017-03-24 10:09 . 2017-03-25 06:17 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2017-03-24 10:09 . 2017-03-28 02:25 251840 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2017-03-24 10:09 . 2017-03-28 02:25 186304 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2017-03-24 10:09 . 2017-02-24 04:23 77408 ----a-w- c:\windows\system32\drivers\mbae64.sys
2017-03-24 10:09 . 2017-03-24 10:10 -------- d-----w- c:\programdata\Malwarebytes
2017-03-24 10:09 . 2017-03-24 10:09 -------- d-----w- c:\program files\Malwarebytes
2017-03-24 09:43 . 2017-03-27 13:20 -------- d-----w- c:\users\Asce\AppData\Local\NVIDIA Corporation
2017-03-24 09:37 . 2017-03-27 13:20 -------- d-----w- c:\users\Asce\AppData\Local\NVIDIA
2017-03-24 09:35 . 2017-03-28 02:24 -------- d-----w- c:\programdata\NVIDIA
2017-03-24 09:35 . 2016-01-23 01:12 110016 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2017-03-24 09:34 . 2016-01-23 01:04 6368312 ----a-w- c:\windows\system32\nvcpl.dll
2017-03-24 09:34 . 2016-01-23 01:04 2992064 ----a-w- c:\windows\system32\nvsvc64.dll
2017-03-24 09:34 . 2016-01-23 01:04 2563128 ----a-w- c:\windows\system32\nvsvcr.dll
2017-03-24 09:34 . 2016-01-23 01:04 1263040 ----a-w- c:\windows\system32\nvvsvc.exe
2017-03-24 09:34 . 2016-01-23 01:04 83512 ----a-w- c:\windows\system32\nv3dappshextr.dll
2017-03-24 09:34 . 2016-01-23 01:04 71224 ----a-w- c:\windows\system32\nvshext.dll
2017-03-24 09:34 . 2016-01-23 01:04 532024 ----a-w- c:\windows\system32\nv3dappshext.dll
2017-03-24 09:34 . 2016-01-23 01:04 393784 ----a-w- c:\windows\system32\nvmctray.dll
2017-03-24 09:34 . 2016-01-22 21:07 6125650 ----a-w- c:\windows\system32\nvcoproc.bin
2017-03-24 09:34 . 2017-03-25 07:51 -------- d-----w- c:\programdata\NVIDIA Corporation
2017-03-24 09:32 . 2016-02-12 18:52 98816 ----a-w- c:\windows\system32\wudriver.dll
2017-03-24 09:31 . 2016-05-11 17:02 483840 ----a-w- c:\windows\system32\StructuredQuery.dll
2017-03-24 09:30 . 2016-04-06 15:27 668160 ----a-w- c:\program files\Windows Journal\MSPVWCTL.DLL
2017-03-24 09:25 . 2016-07-22 14:58 142336 ----a-w- c:\windows\system32\poqexec.exe
2017-03-24 09:25 . 2016-07-22 14:51 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
2017-03-24 09:10 . 2017-03-25 07:51 -------- d-----w- c:\program files\NVIDIA Corporation
2017-03-24 09:10 . 2017-03-24 09:10 -------- d-----w- C:\NVIDIA
2017-03-24 09:08 . 2017-03-24 09:08 20647512 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-03-28 02:24 . 2015-05-18 12:56 25640 ----a-w- c:\windows\gdrv.sys
2017-03-25 07:49 . 2015-10-04 20:42 802904 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2017-03-25 07:49 . 2015-10-04 20:42 144472 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2017-03-25 05:10 . 2016-06-14 15:47 199392 ----a-w- c:\windows\system32\drivers\kneps.sys
2017-03-25 05:10 . 2016-12-26 20:03 135904 ----a-w- c:\windows\system32\drivers\klwtp.sys
2017-03-25 05:10 . 2016-12-26 20:03 313112 ----a-w- c:\windows\system32\drivers\klhk.sys
2017-02-09 16:14 . 2017-03-24 09:32 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2014-03-04 3696912]
"Octoshape Streaming Services"="c:\users\Asce\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2011-03-24 107800]
"f.lux"="c:\users\Asce\AppData\Local\FluxSoftware\Flux\flux.exe" [2013-10-23 1017224]
"Voobly"="c:\program files (x86)\Voobly\voobly.exe" [2015-01-19 159744]
"ISUSPM Startup"="c:\progra~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-17 221184]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2015-05-27 787592]
"Steam"="c:\steam\steam.exe" [2017-03-24 3019552]
"Spotify Web Helper"="c:\users\Asce\AppData\Roaming\Spotify\SpotifyWebHelper.exe" [2015-12-17 2346096]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2015-12-17 50378880]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-11-20 767176]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-01-19 43632]
"NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-11-20 106496]
"ISUSScheduler"="c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]
"EasyTuneVI"="c:\program files (x86)\GIGABYTE\ET6\ETcall.exe" [2007-07-26 20480]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2015-11-12 5565448]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
SoftEther VPN Client Manager Startup.lnk - c:\program files\SoftEther VPN Client\vpncmgr_x64.exe /startup [2015-5-2 5379640]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;Malwarebytes Service;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
R3 EasyAntiCheat;EasyAntiCheat;c:\windows\system32\EasyAntiCheat.exe;c:\windows\SYSNATIVE\EasyAntiCheat.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 klvssbrigde64;klvssbrigde64;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\x64\vssbridge64.exe;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\x64\vssbridge64.exe [x]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
R3 Origin Client Service;Origin Client Service;c:\program files (x86)\Origin\OriginClientService.exe;c:\program files (x86)\Origin\OriginClientService.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 VASDeviceDrm;Virtual Audio Streaming with Drm (WDM);c:\windows\system32\drivers\vasdDev.sys;c:\windows\SYSNATIVE\drivers\vasdDev.sys [x]
R3 vvftav303;vvftav303;c:\windows\system32\drivers\vvftav303.sys;c:\windows\SYSNATIVE\drivers\vvftav303.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 ZSMC0303;A4 TECH PC Camera H;c:\windows\system32\Drivers\usbVM303.sys;c:\windows\SYSNATIVE\Drivers\usbVM303.sys [x]
S0 cm_km;AO Kaspersky Lab Cryptographic Module x64 (56 bit);c:\windows\system32\DRIVERS\cm_km.sys;c:\windows\SYSNATIVE\DRIVERS\cm_km.sys [x]
S0 klbackupdisk;Kaspersky Lab klbackupdisk;c:\windows\system32\DRIVERS\klbackupdisk.sys;c:\windows\SYSNATIVE\DRIVERS\klbackupdisk.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 klbackupflt;Kaspersky Lab klbackupflt;c:\windows\system32\DRIVERS\klbackupflt.sys;c:\windows\SYSNATIVE\DRIVERS\klbackupflt.sys [x]
S1 klhk;Kaspersky Lab service driver;c:\windows\system32\DRIVERS\klhk.sys;c:\windows\SYSNATIVE\DRIVERS\klhk.sys [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
S1 klpd;Kaspersky Lab format recognizer driver;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x]
S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x]
S1 Klwtp;KLwtp - WFP callout traffic inspector;c:\windows\system32\DRIVERS\klwtp.sys;c:\windows\SYSNATIVE\DRIVERS\klwtp.sys [x]
S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AVP17.0.0;Kaspersky Anti-Virus Service 17.0.0;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\avp.exe;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\avp.exe [x]
S2 DES2 Service;DES2 Service for Energy Saving.;c:\program files (x86)\Gigabyte\EnergySaver2\des2svr.exe;c:\program files (x86)\Gigabyte\EnergySaver2\des2svr.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 JMB36X;JMB36X;c:\windows\SysWOW64\XSrvSetup.exe;c:\windows\SysWOW64\XSrvSetup.exe [x]
S2 kldisk;kldisk;c:\windows\system32\DRIVERS\kldisk.sys;c:\windows\SYSNATIVE\DRIVERS\kldisk.sys [x]
S2 KSDE1.0.0;Kaspersky Secure Connection Service 1.0.0;c:\program files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe;c:\program files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [x]
S2 SEVPNCLIENT;SoftEther VPN Client;c:\program files\SoftEther VPN Client\vpnclient_x64.exe;c:\program files\SoftEther VPN Client\vpnclient_x64.exe [x]
S2 Smart TimeLock;Smart TimeLock Service;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 klflt;Kaspersky Lab Kernel DLL;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x]
S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
S3 kltap;Kaspersky Security Data Escort Adapter;c:\windows\system32\DRIVERS\kltap.sys;c:\windows\SYSNATIVE\DRIVERS\kltap.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x]
S3 Neo_braz;VPN Client Device Driver - braz;c:\windows\system32\DRIVERS\Neo_0005.sys;c:\windows\SYSNATIVE\DRIVERS\Neo_0005.sys [x]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 NvStreamNetworkSvc;NVIDIA Streamer Network Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - ESProtectionDriver
*Deregistered* - TrueSight
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2017-03-24 09:44 1368920 ----a-w- c:\program files (x86)\Google\Chrome\Application\56.0.2924.87\Installer\chrmstp.exe
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2014-07-02 10464536]
"SoftEther VPN Client UI Helper"="c:\program files\SoftEther VPN Client\vpnclient_x64.exe" [2015-05-02 5189176]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2016-06-15 2398776]
"Malwarebytes TrayApp"="c:\program files\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe" [2017-01-20 2780112]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mDefault_Search_URL = www.google.com
mDefault_Page_URL = www.google.com
mStart Page = www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = www.google.com
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-GNE_SwapScreen - c:\users\Asce\Desktop\SwapScreen.exe
HKLM-Run-VMSnap3 - c:\windows\VMSnap3.exe
HKLM-Run-Domino - c:\windows\Domino.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1292172697-4276861399-4271014393-1000\Software\SecuROM\License information*]
"datasecu"=hex:40,8a,3f,71,dc,11,75,d6,c1,58,e5,a4,f2,1b,b0,2c,0d,cf,4f,fa,52,
37,36,0d,b2,15,fe,33,23,79,15,ec,28,ad,d0,11,96,aa,43,85,f0,82,29,6b,c0,a9,\
"rkeysecu"=hex:14,69,eb,d1,0f,f6,0d,53,12,94,81,51,4d,80,1e,91
.
[HKEY_USERS\S-1-5-21-1292172697-4276861399-4271014393-1000_Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):2a,a9,57,30,47,d5,5b,d1,17,d1,dc,99,4a,6c,bd,6b,ce,4c,d5,86,d0,
7b,bf,1e,43,43,dc,29,cd,66,5b,14,80,3a,7c,69,fa,75,1f,7a,00,00,00,00,00,00,\
.
[HKEY_USERS\S-1-5-21-1292172697-4276861399-4271014393-1000_Classes\Wow6432Node\CLSID\{c7f78aad-50fe-4595-bb90-f1b121d4b01f}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000156
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,d7,18,be,e1,28,c7,b4,b6,c7,57,5f,49,ba,40,58,2d,27,a9,be,b1,47,30,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2017-03-28 09:19:03
ComboFix-quarantined-files.txt 2017-03-28 06:19
.
Pre-Run: 259,750,535,168 bytes free
Post-Run: 260,588,486,656 bytes free
.
- - End Of File - - CDC173FC097D24C12D3AA559A215F6DA
A36C5E4F47E84449FF07ED3517B43A31
March 28th, 2017, 12:33 PM
#17
Download attached fixlist.txt file and save it to the Desktop.
NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Run FRST(FRST64) and press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt ). Please post it to your reply.
Attached Files
March 28th, 2017, 01:25 PM
#18
Fix result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017
Ran by Asce (28-03-2017 13:48:54) Run:1
Running from C:\Users\Asce\Desktop
Loaded Profiles: Asce (Available Profiles: Asce)
Boot Mode: Normal
==============================================
fixlist content:
*****************
HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\MountPoints2: {03f5a58e-0cdf-11e4-9364-fa05310c68ca} - F:\AutoRun.exe
HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\MountPoints2: {10963882-1014-11e4-ba5d-c05a936a09ba} - F:\setup.exe
GroupPolicy: Restriction <======= ATTENTION
S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X]
2015-11-05 01:14 - 2017-03-24 12:51 - 0007608 _____ () C:\Users\Asce\AppData\Local\Resmon.ResmonCfg
2015-12-11 22:02 - 2015-12-11 22:02 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-10-23 20:47 - 2015-10-23 20:47 - 2892128 _____ (AVG Technologies) C:\Users\Asce\AppData\Local\Temp\avg-ae9d4a66-87be-4c57-9f03-a23b13fdc342.exe
2016-01-05 21:18 - 2015-11-12 17:54 - 0091048 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Asce\AppData\Local\Temp\avguirn_0899728453.exe
2017-03-25 05:02 - 2015-10-20 04:09 - 1730496 _____ (Microsoft Corporation) C:\Users\Asce\AppData\Local\Temp\dllnt_dump.dll
2015-10-08 20:45 - 2015-10-08 20:49 - 0204800 _____ (Sony DADC Austria AG) C:\Users\Asce\AppData\Local\Temp\drm_dyndata_7400009.dll
2015-11-10 22:16 - 2015-11-11 00:19 - 0035680 _____ () C:\Users\Asce\AppData\Local\Temp\i4jdel0.exe
2015-07-18 16:30 - 2015-07-18 16:30 - 0011264 _____ ( ) C:\Users\Asce\AppData\Local\Temp\iuo4idyi.dll
2015-10-24 22:18 - 2015-12-08 23:45 - 56061688 _____ (Rockstar Games) C:\Users\Asce\AppData\Local\Temp\Social%20Club%20v1.1.6.8%20Setup.exe
2015-12-21 04:39 - 2015-12-21 04:39 - 56838704 _____ (Rockstar Games) C:\Users\Asce\AppData\Local\Temp\Social%20Club%20v1.1.6.9%20Setup.exe
2017-03-24 12:48 - 2017-03-24 12:48 - 14456872 _____ (Microsoft Corporation) C:\Users\Asce\AppData\Local\Temp\vc_redist.x86.exe
2015-08-03 02:58 - 2015-08-03 02:58 - 0118784 _____ () C:\Users\Asce\AppData\Local\Temp\xmlUpdater.exe
2017-03-25 07:46 - 2017-03-25 07:46 - 0503808 _____ () C:\Users\Asce\AppData\Local\Temp\xuninst.exe
2017-03-25 07:09 - 2015-02-08 18:49 - 0455600 _____ (Macrovision Corporation) C:\Users\Asce\AppData\Local\Temp\_isFB2F.exe
*****************
HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{03f5a58e-0cdf-11e4-9364-fa05310c68ca} => key not found.
HKCR\CLSID\{03f5a58e-0cdf-11e4-9364-fa05310c68ca} => key not found.
HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{10963882-1014-11e4-ba5d-c05a936a09ba} => key removed successfully
HKCR\CLSID\{10963882-1014-11e4-ba5d-c05a936a09ba} => key not found.
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
HKLM\System\CurrentControlSet\Services\IntcAzAudAddService => key removed successfully
IntcAzAudAddService => service removed successfully
C:\Users\Asce\AppData\Local\Resmon.ResmonCfg => moved successfully
C:\ProgramData\DP45977C.lfl => moved successfully
"C:\Users\Asce\AppData\Local\Temp\avg-ae9d4a66-87be-4c57-9f03-a23b13fdc342.exe" => not found.
"C:\Users\Asce\AppData\Local\Temp\avguirn_0899728453.exe" => not found.
"C:\Users\Asce\AppData\Local\Temp\dllnt_dump.dll" => not found.
"C:\Users\Asce\AppData\Local\Temp\drm_dyndata_7400009.dll" => not found.
"C:\Users\Asce\AppData\Local\Temp\i4jdel0.exe" => not found.
"C:\Users\Asce\AppData\Local\Temp\iuo4idyi.dll" => not found.
"C:\Users\Asce\AppData\Local\Temp\Social%20Club%20v1.1.6.8%20Setup.exe" => not found.
"C:\Users\Asce\AppData\Local\Temp\Social%20Club%20v1.1.6.9%20Setup.exe" => not found.
"C:\Users\Asce\AppData\Local\Temp\vc_redist.x86.exe" => not found.
"C:\Users\Asce\AppData\Local\Temp\xmlUpdater.exe" => not found.
"C:\Users\Asce\AppData\Local\Temp\xuninst.exe" => not found.
"C:\Users\Asce\AppData\Local\Temp\_isFB2F.exe" => not found.
The system needed a reboot.
==== End of Fixlog 13:48:55 ====
March 28th, 2017, 08:21 PM
#19
Last scans...
Download Security Check from here or here and save it to your Desktop .
Double-click SecurityCheck.exe Follow the onscreen instructions inside of the black box. A Notepad document should open automatically called checkup.txt ; please post the contents of that document.
NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
NOTE 2. SecurityCheck may produce some false warning(s), so leave the results reading to me.
NOTE 3. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message restart computer and Security Check should run
Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
Make sure the following options are checked:
Internet Services Windows Firewall System Restore Security Center Windows Update Windows Defender Other Services
Press "Scan ".
It will create a log (FSS.txt) in the same directory the tool is run.
Please copy and paste the log to your reply.
Download Temp File Cleaner (TFC)
Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
Double click on TFC.exe to run the program. Click on Start button to begin cleaning process. TFC will close all running programs, and it may ask you to restart computer.
Download Sophos Free Virus Removal Tool and save it to your desktop.
Double click the icon and select Run Click Next Select I accept the terms in this license agreement , then click Next twice Click Install Click Finish to launch the program Once the virus database has been updated click Start Scanning If any threats are found click Details , then View log file... (bottom left hand corner) Copy and paste the results in your reply Close the Notepad document, close the Threat Details screen, then click Start cleanup Click Exit to close the program
March 29th, 2017, 03:41 PM
#20
Farbar Service Scanner Version: 27-01-2016
Ran by Asce (administrator) on 29-03-2017 at 16:01:28
Running from "C:\Users\Asce\AppData\Local\Temp\scoped_dir1972_2862"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Policy:
========================
Action Center:
============
wscsvc Service is not running. Checking service configuration:
The start type of wscsvc service is OK.
The ImagePath of wscsvc service is OK.
The ServiceDll of wscsvc service is OK.
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Windows Defender:
==============
Other Services:
==============
File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
**** End of log ****
March 29th, 2017, 03:43 PM
#21
Results of screen317's Security Check version 1.014 --- 12/23/15
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Windows Security Center service is not running! This report may not be accurate!
Windows Firewall Enabled!
Kaspersky Anti-Virus
Malwarebytes
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Java 8 Update 40
Java version 32-bit out of Date!
Adobe Flash Player 25.0.0.127
Adobe Reader XI
Google Chrome (56.0.2924.87)
Google Chrome (SetupMetrics...)
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Kaspersky Lab Kaspersky Anti-Virus 17.0.0 avp.exe
Kaspersky Lab Kaspersky Anti-Virus 17.0.0 avpui.exe
Kaspersky Lab Kaspersky Anti-Virus 17.0.0 x64 wmi64.exe
Malwarebytes Anti-Malware mbamtray.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 1%
````````````````````End of Log``````````````````````
ComboFix 17-03-28.01 - Asce 03/28/2017 9:08.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6142.4577 [GMT 3:00]
Running from: c:\users\Asce\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *Disabled/Updated* {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
AV: Malwarebytes *Disabled/Updated* {23007AD3-69FE-687C-2629-D584AFFAF72B}
SP: Kaspersky Anti-Virus *Disabled/Updated* {3D579475-6DDE-A186-1569-44B9F9DE8725}
SP: Malwarebytes *Disabled/Updated* {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\programdata\ntuser.pol
c:\users\Asce\AppData\Local\assembly\tmp
c:\users\Asce\AppData\Local\Temp\VPN_6677\B7091C83.dll
c:\windows\msdownld.tmp
c:\windows\TEMP\VPN_3742\B7091C83.dll
.
.
((((((((((((((((((((((((( Files Created from 2017-02-28 to 2017-03-28 )))))))))))))))))))))))))))))))
.
.
2017-03-28 06:16 . 2017-03-28 06:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2017-03-25 07:55 . 2017-03-25 07:55 -------- d-----w- c:\windows\system32\wbem\Framework
2017-03-25 07:53 . 2017-03-25 07:53 -------- d-----w- c:\program files (x86)\GPU Temp
2017-03-25 06:47 . 2017-03-25 06:47 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{59896AD4-81AA-41F7-A119-D82B1CF4AEDD}\offreg.3400.dll
2017-03-25 05:01 . 2016-04-14 05:38 56384 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2017-03-25 05:01 . 2016-04-14 05:38 113216 ----a-w- c:\windows\system32\nvaudcap64v.dll
2017-03-25 05:01 . 2016-04-14 05:38 102976 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2017-03-25 04:41 . 2017-03-25 04:50 -------- d-----w- c:\windows\system32\MRT
2017-03-25 04:37 . 2013-05-06 06:13 110176 ----a-w- c:\windows\system32\klfphc.dll
2017-03-25 04:37 . 2017-03-25 04:37 -------- d-----w- c:\windows\ELAMBKUP
2017-03-25 04:36 . 2017-03-28 04:42 -------- d-----w- c:\programdata\Kaspersky Lab
2017-03-25 04:36 . 2017-03-25 04:38 -------- d-----w- c:\program files (x86)\Kaspersky Lab
2017-03-25 04:36 . 2017-03-25 05:10 195296 ----a-w- c:\windows\system32\drivers\klflt.sys
2017-03-25 04:36 . 2017-03-25 05:10 1035488 ----a-w- c:\windows\system32\drivers\klif.sys
2017-03-25 04:35 . 2017-03-22 11:05 12774864 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{59896AD4-81AA-41F7-A119-D82B1CF4AEDD}\mpengine.dll
2017-03-25 04:34 . 2017-03-25 04:35 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2017-03-25 03:54 . 2017-03-25 04:14 -------- d-----w- C:\AdwCleaner
2017-03-25 02:03 . 2017-03-28 04:06 28272 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2017-03-25 02:02 . 2017-03-25 02:02 -------- d-----w- c:\programdata\RogueKiller
2017-03-25 01:58 . 2017-03-25 01:58 -------- d-----w- c:\program files\RogueKiller
2017-03-24 12:08 . 2017-03-28 03:04 -------- d-----w- C:\FRST
2017-03-24 10:10 . 2017-03-27 13:41 111544 ----a-w- c:\windows\system32\drivers\farflt.sys
2017-03-24 10:10 . 2017-03-28 05:34 82208 ----a-w- c:\windows\system32\drivers\mwac.sys
2017-03-24 10:10 . 2017-03-28 02:25 43968 ----a-w- c:\windows\system32\drivers\mbam.sys
2017-03-24 10:09 . 2017-03-25 06:17 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2017-03-24 10:09 . 2017-03-28 02:25 251840 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2017-03-24 10:09 . 2017-03-28 02:25 186304 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2017-03-24 10:09 . 2017-02-24 04:23 77408 ----a-w- c:\windows\system32\drivers\mbae64.sys
2017-03-24 10:09 . 2017-03-24 10:10 -------- d-----w- c:\programdata\Malwarebytes
2017-03-24 10:09 . 2017-03-24 10:09 -------- d-----w- c:\program files\Malwarebytes
2017-03-24 09:43 . 2017-03-27 13:20 -------- d-----w- c:\users\Asce\AppData\Local\NVIDIA Corporation
2017-03-24 09:37 . 2017-03-27 13:20 -------- d-----w- c:\users\Asce\AppData\Local\NVIDIA
2017-03-24 09:35 . 2017-03-28 02:24 -------- d-----w- c:\programdata\NVIDIA
2017-03-24 09:35 . 2016-01-23 01:12 110016 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2017-03-24 09:34 . 2016-01-23 01:04 6368312 ----a-w- c:\windows\system32\nvcpl.dll
2017-03-24 09:34 . 2016-01-23 01:04 2992064 ----a-w- c:\windows\system32\nvsvc64.dll
2017-03-24 09:34 . 2016-01-23 01:04 2563128 ----a-w- c:\windows\system32\nvsvcr.dll
2017-03-24 09:34 . 2016-01-23 01:04 1263040 ----a-w- c:\windows\system32\nvvsvc.exe
2017-03-24 09:34 . 2016-01-23 01:04 83512 ----a-w- c:\windows\system32\nv3dappshextr.dll
2017-03-24 09:34 . 2016-01-23 01:04 71224 ----a-w- c:\windows\system32\nvshext.dll
2017-03-24 09:34 . 2016-01-23 01:04 532024 ----a-w- c:\windows\system32\nv3dappshext.dll
2017-03-24 09:34 . 2016-01-23 01:04 393784 ----a-w- c:\windows\system32\nvmctray.dll
2017-03-24 09:34 . 2016-01-22 21:07 6125650 ----a-w- c:\windows\system32\nvcoproc.bin
2017-03-24 09:34 . 2017-03-25 07:51 -------- d-----w- c:\programdata\NVIDIA Corporation
2017-03-24 09:32 . 2016-02-12 18:52 98816 ----a-w- c:\windows\system32\wudriver.dll
2017-03-24 09:31 . 2016-05-11 17:02 483840 ----a-w- c:\windows\system32\StructuredQuery.dll
2017-03-24 09:30 . 2016-04-06 15:27 668160 ----a-w- c:\program files\Windows Journal\MSPVWCTL.DLL
2017-03-24 09:25 . 2016-07-22 14:58 142336 ----a-w- c:\windows\system32\poqexec.exe
2017-03-24 09:25 . 2016-07-22 14:51 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
2017-03-24 09:10 . 2017-03-25 07:51 -------- d-----w- c:\program files\NVIDIA Corporation
2017-03-24 09:10 . 2017-03-24 09:10 -------- d-----w- C:\NVIDIA
2017-03-24 09:08 . 2017-03-24 09:08 20647512 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-03-28 02:24 . 2015-05-18 12:56 25640 ----a-w- c:\windows\gdrv.sys
2017-03-25 07:49 . 2015-10-04 20:42 802904 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2017-03-25 07:49 . 2015-10-04 20:42 144472 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2017-03-25 05:10 . 2016-06-14 15:47 199392 ----a-w- c:\windows\system32\drivers\kneps.sys
2017-03-25 05:10 . 2016-12-26 20:03 135904 ----a-w- c:\windows\system32\drivers\klwtp.sys
2017-03-25 05:10 . 2016-12-26 20:03 313112 ----a-w- c:\windows\system32\drivers\klhk.sys
2017-02-09 16:14 . 2017-03-24 09:32 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2014-03-04 3696912]
"Octoshape Streaming Services"="c:\users\Asce\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2011-03-24 107800]
"f.lux"="c:\users\Asce\AppData\Local\FluxSoftware\Flux\flux.exe" [2013-10-23 1017224]
"Voobly"="c:\program files (x86)\Voobly\voobly.exe" [2015-01-19 159744]
"ISUSPM Startup"="c:\progra~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-17 221184]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2015-05-27 787592]
"Steam"="c:\steam\steam.exe" [2017-03-24 3019552]
"Spotify Web Helper"="c:\users\Asce\AppData\Roaming\Spotify\SpotifyWebHelper.exe" [2015-12-17 2346096]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2015-12-17 50378880]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-11-20 767176]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-01-19 43632]
"NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-11-20 106496]
"ISUSScheduler"="c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]
"EasyTuneVI"="c:\program files (x86)\GIGABYTE\ET6\ETcall.exe" [2007-07-26 20480]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2015-11-12 5565448]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
SoftEther VPN Client Manager Startup.lnk - c:\program files\SoftEther VPN Client\vpncmgr_x64.exe /startup [2015-5-2 5379640]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;Malwarebytes Service;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
R3 EasyAntiCheat;EasyAntiCheat;c:\windows\system32\EasyAntiCheat.exe;c:\windows\SYSNATIVE\EasyAntiCheat.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 klvssbrigde64;klvssbrigde64;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\x64\vssbridge64.exe;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\x64\vssbridge64.exe [x]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
R3 Origin Client Service;Origin Client Service;c:\program files (x86)\Origin\OriginClientService.exe;c:\program files (x86)\Origin\OriginClientService.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 VASDeviceDrm;Virtual Audio Streaming with Drm (WDM);c:\windows\system32\drivers\vasdDev.sys;c:\windows\SYSNATIVE\drivers\vasdDev.sys [x]
R3 vvftav303;vvftav303;c:\windows\system32\drivers\vvftav303.sys;c:\windows\SYSNATIVE\drivers\vvftav303.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 ZSMC0303;A4 TECH PC Camera H;c:\windows\system32\Drivers\usbVM303.sys;c:\windows\SYSNATIVE\Drivers\usbVM303.sys [x]
S0 cm_km;AO Kaspersky Lab Cryptographic Module x64 (56 bit);c:\windows\system32\DRIVERS\cm_km.sys;c:\windows\SYSNATIVE\DRIVERS\cm_km.sys [x]
S0 klbackupdisk;Kaspersky Lab klbackupdisk;c:\windows\system32\DRIVERS\klbackupdisk.sys;c:\windows\SYSNATIVE\DRIVERS\klbackupdisk.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 klbackupflt;Kaspersky Lab klbackupflt;c:\windows\system32\DRIVERS\klbackupflt.sys;c:\windows\SYSNATIVE\DRIVERS\klbackupflt.sys [x]
S1 klhk;Kaspersky Lab service driver;c:\windows\system32\DRIVERS\klhk.sys;c:\windows\SYSNATIVE\DRIVERS\klhk.sys [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
S1 klpd;Kaspersky Lab format recognizer driver;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x]
S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x]
S1 Klwtp;KLwtp - WFP callout traffic inspector;c:\windows\system32\DRIVERS\klwtp.sys;c:\windows\SYSNATIVE\DRIVERS\klwtp.sys [x]
S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AVP17.0.0;Kaspersky Anti-Virus Service 17.0.0;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\avp.exe;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\avp.exe [x]
S2 DES2 Service;DES2 Service for Energy Saving.;c:\program files (x86)\Gigabyte\EnergySaver2\des2svr.exe;c:\program files (x86)\Gigabyte\EnergySaver2\des2svr.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 JMB36X;JMB36X;c:\windows\SysWOW64\XSrvSetup.exe;c:\windows\SysWOW64\XSrvSetup.exe [x]
S2 kldisk;kldisk;c:\windows\system32\DRIVERS\kldisk.sys;c:\windows\SYSNATIVE\DRIVERS\kldisk.sys [x]
S2 KSDE1.0.0;Kaspersky Secure Connection Service 1.0.0;c:\program files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe;c:\program files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [x]
S2 SEVPNCLIENT;SoftEther VPN Client;c:\program files\SoftEther VPN Client\vpnclient_x64.exe;c:\program files\SoftEther VPN Client\vpnclient_x64.exe [x]
S2 Smart TimeLock;Smart TimeLock Service;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 klflt;Kaspersky Lab Kernel DLL;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x]
S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
S3 kltap;Kaspersky Security Data Escort Adapter;c:\windows\system32\DRIVERS\kltap.sys;c:\windows\SYSNATIVE\DRIVERS\kltap.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x]
S3 Neo_braz;VPN Client Device Driver - braz;c:\windows\system32\DRIVERS\Neo_0005.sys;c:\windows\SYSNATIVE\DRIVERS\Neo_0005.sys [x]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 NvStreamNetworkSvc;NVIDIA Streamer Network Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - ESProtectionDriver
*Deregistered* - TrueSight
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2017-03-24 09:44 1368920 ----a-w- c:\program files (x86)\Google\Chrome\Application\56.0.2924.87\Installer\chrmstp.exe
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2014-07-02 10464536]
"SoftEther VPN Client UI Helper"="c:\program files\SoftEther VPN Client\vpnclient_x64.exe" [2015-05-02 5189176]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2016-06-15 2398776]
"Malwarebytes TrayApp"="c:\program files\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe" [2017-01-20 2780112]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mDefault_Search_URL = www.google.com
mDefault_Page_URL = www.google.com
mStart Page = www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = www.google.com
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-GNE_SwapScreen - c:\users\Asce\Desktop\SwapScreen.exe
HKLM-Run-VMSnap3 - c:\windows\VMSnap3.exe
HKLM-Run-Domino - c:\windows\Domino.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1292172697-4276861399-4271014393-1000\Software\SecuROM\License information*]
"datasecu"=hex:40,8a,3f,71,dc,11,75,d6,c1,58,e5,a4,f2,1b,b0,2c,0d,cf,4f,fa,52,
37,36,0d,b2,15,fe,33,23,79,15,ec,28,ad,d0,11,96,aa,43,85,f0,82,29,6b,c0,a9,\
"rkeysecu"=hex:14,69,eb,d1,0f,f6,0d,53,12,94,81,51,4d,80,1e,91
.
[HKEY_USERS\S-1-5-21-1292172697-4276861399-4271014393-1000_Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):2a,a9,57,30,47,d5,5b,d1,17,d1,dc,99,4a,6c,bd,6b,ce,4c,d5,86,d0,
7b,bf,1e,43,43,dc,29,cd,66,5b,14,80,3a,7c,69,fa,75,1f,7a,00,00,00,00,00,00,\
.
[HKEY_USERS\S-1-5-21-1292172697-4276861399-4271014393-1000_Classes\Wow6432Node\CLSID\{c7f78aad-50fe-4595-bb90-f1b121d4b01f}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000156
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,d7,18,be,e1,28,c7,b4,b6,c7,57,5f,49,ba,40,58,2d,27,a9,be,b1,47,30,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2017-03-28 09:19:03
ComboFix-quarantined-files.txt 2017-03-28 06:19
.
Pre-Run: 259,750,535,168 bytes free
Post-Run: 260,588,486,656 bytes free
.
- - End Of File - - CDC173FC097D24C12D3AA559A215F6DA
A36C5E4F47E84449FF07ED3517B43A31
Fix result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017
Ran by Asce (28-03-2017 13:48:54) Run:1
Running from C:\Users\Asce\Desktop
Loaded Profiles: Asce (Available Profiles: Asce)
Boot Mode: Normal
==============================================
fixlist content:
*****************
HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\MountPoints2: {03f5a58e-0cdf-11e4-9364-fa05310c68ca} - F:\AutoRun.exe
HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\...\MountPoints2: {10963882-1014-11e4-ba5d-c05a936a09ba} - F:\setup.exe
GroupPolicy: Restriction <======= ATTENTION
S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X]
2015-11-05 01:14 - 2017-03-24 12:51 - 0007608 _____ () C:\Users\Asce\AppData\Local\Resmon.ResmonCfg
2015-12-11 22:02 - 2015-12-11 22:02 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-10-23 20:47 - 2015-10-23 20:47 - 2892128 _____ (AVG Technologies) C:\Users\Asce\AppData\Local\Temp\avg-ae9d4a66-87be-4c57-9f03-a23b13fdc342.exe
2016-01-05 21:18 - 2015-11-12 17:54 - 0091048 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Asce\AppData\Local\Temp\avguirn_0899728453.exe
2017-03-25 05:02 - 2015-10-20 04:09 - 1730496 _____ (Microsoft Corporation) C:\Users\Asce\AppData\Local\Temp\dllnt_dump.dll
2015-10-08 20:45 - 2015-10-08 20:49 - 0204800 _____ (Sony DADC Austria AG) C:\Users\Asce\AppData\Local\Temp\drm_dyndata_7400009.dll
2015-11-10 22:16 - 2015-11-11 00:19 - 0035680 _____ () C:\Users\Asce\AppData\Local\Temp\i4jdel0.exe
2015-07-18 16:30 - 2015-07-18 16:30 - 0011264 _____ ( ) C:\Users\Asce\AppData\Local\Temp\iuo4idyi.dll
2015-10-24 22:18 - 2015-12-08 23:45 - 56061688 _____ (Rockstar Games) C:\Users\Asce\AppData\Local\Temp\Social%20Club%20v1.1.6.8%20Setup.exe
2015-12-21 04:39 - 2015-12-21 04:39 - 56838704 _____ (Rockstar Games) C:\Users\Asce\AppData\Local\Temp\Social%20Club%20v1.1.6.9%20Setup.exe
2017-03-24 12:48 - 2017-03-24 12:48 - 14456872 _____ (Microsoft Corporation) C:\Users\Asce\AppData\Local\Temp\vc_redist.x86.exe
2015-08-03 02:58 - 2015-08-03 02:58 - 0118784 _____ () C:\Users\Asce\AppData\Local\Temp\xmlUpdater.exe
2017-03-25 07:46 - 2017-03-25 07:46 - 0503808 _____ () C:\Users\Asce\AppData\Local\Temp\xuninst.exe
2017-03-25 07:09 - 2015-02-08 18:49 - 0455600 _____ (Macrovision Corporation) C:\Users\Asce\AppData\Local\Temp\_isFB2F.exe
*****************
HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{03f5a58e-0cdf-11e4-9364-fa05310c68ca} => key not found.
HKCR\CLSID\{03f5a58e-0cdf-11e4-9364-fa05310c68ca} => key not found.
HKU\S-1-5-21-1292172697-4276861399-4271014393-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{10963882-1014-11e4-ba5d-c05a936a09ba} => key removed successfully
HKCR\CLSID\{10963882-1014-11e4-ba5d-c05a936a09ba} => key not found.
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
HKLM\System\CurrentControlSet\Services\IntcAzAudAddService => key removed successfully
IntcAzAudAddService => service removed successfully
C:\Users\Asce\AppData\Local\Resmon.ResmonCfg => moved successfully
C:\ProgramData\DP45977C.lfl => moved successfully
"C:\Users\Asce\AppData\Local\Temp\avg-ae9d4a66-87be-4c57-9f03-a23b13fdc342.exe" => not found.
"C:\Users\Asce\AppData\Local\Temp\avguirn_0899728453.exe" => not found.
"C:\Users\Asce\AppData\Local\Temp\dllnt_dump.dll" => not found.
"C:\Users\Asce\AppData\Local\Temp\drm_dyndata_7400009.dll" => not found.
"C:\Users\Asce\AppData\Local\Temp\i4jdel0.exe" => not found.
"C:\Users\Asce\AppData\Local\Temp\iuo4idyi.dll" => not found.
"C:\Users\Asce\AppData\Local\Temp\Social%20Club%20v1.1.6.8%20Setup.exe" => not found.
"C:\Users\Asce\AppData\Local\Temp\Social%20Club%20v1.1.6.9%20Setup.exe" => not found.
"C:\Users\Asce\AppData\Local\Temp\vc_redist.x86.exe" => not found.
"C:\Users\Asce\AppData\Local\Temp\xmlUpdater.exe" => not found.
"C:\Users\Asce\AppData\Local\Temp\xuninst.exe" => not found.
"C:\Users\Asce\AppData\Local\Temp\_isFB2F.exe" => not found.
The system needed a reboot.
==== End of Fixlog 13:48:55 ====
March 29th, 2017, 08:29 PM
#22
Not sure why you posted Combofix and fixlist log.
I need Sophos log.
March 30th, 2017, 12:43 PM
#23
sophos literally takes 10 hour to scan i can't scan it. Is it normal do i need to keep the machine wake up that much time ?
March 30th, 2017, 08:44 PM
#24
If it displays progress keep it going.
If it's stuck...
Please run a free online scan with the ESET Online Scanner
Disable your antivirus program Under "ESET Online Scanner" click on "Scan now" button. It'll download small file "esetonlinescanner_enu.exe". Double click on downloaded file. Click on Accept button. Checkmark "Disable detection of potentially unwanted applications". Click Scan Accept any security warnings from your browser. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. When the scan completes, click List of found threats Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
Forum Rules