ComboFix 15-04-01.01 - Elena 04/03/2015 14:09:44.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3558.1588 [GMT -7:00]
Running from: c:\users\Elena\Downloads\ComboFix.exe
AV: AVG AntiVirus Free Edition 2015 *Disabled/Updated* {4D41356F-32AD-7C42-C820-63775EE4F413}
SP: AVG AntiVirus Free Edition 2015 *Disabled/Updated* {F620D48B-1497-73CC-F290-58052563BEAE}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Elena\AppData\Local\assembly\tmp
c:\users\Elena\AppData\Local\assembly\tmp\088D5MX9\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\088D5MX9\PollEverywhere.ErrorHandler.DLL
c:\users\Elena\AppData\Local\assembly\tmp\1VD5JE7Q\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\1VD5JE7Q\SharpBrake.2010.DLL
c:\users\Elena\AppData\Local\assembly\tmp\21RBT1RN\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\21RBT1RN\SharpBrake.2010.DLL
c:\users\Elena\AppData\Local\assembly\tmp\77LC9RTW\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\77LC9RTW\AutoUpdater.NET.DLL
c:\users\Elena\AppData\Local\assembly\tmp\C3FJ68C2\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\C3FJ68C2\PollEverywhere.ErrorHandler.DLL
c:\users\Elena\AppData\Local\assembly\tmp\CS8895C7\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\CS8895C7\PEPPTAddin.DLL
c:\users\Elena\AppData\Local\assembly\tmp\GMZRLHTD\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\GMZRLHTD\AutoUpdater.NET.DLL
c:\users\Elena\AppData\Local\assembly\tmp\H5LO4OMU\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\H5LO4OMU\SharpBrake.2010.DLL
c:\users\Elena\AppData\Local\assembly\tmp\HU5LE360\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\HU5LE360\PollEverywhere.WCFContracts.DLL
c:\users\Elena\AppData\Local\assembly\tmp\JBAJ5KF5\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\JBAJ5KF5\PollEverywhere.WCFContracts.DLL
c:\users\Elena\AppData\Local\assembly\tmp\JNVI7ZGV\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\JNVI7ZGV\PEPPTAddin.DLL
c:\users\Elena\AppData\Local\assembly\tmp\JQHUX8C9\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\JQHUX8C9\SharpBrake.2010.DLL
c:\users\Elena\AppData\Local\assembly\tmp\NGEMVBTF\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\NGEMVBTF\AutoUpdater.NET.DLL
c:\users\Elena\AppData\Local\assembly\tmp\OY7ALXAE\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\OY7ALXAE\AutoUpdater.NET.DLL
c:\users\Elena\AppData\Local\assembly\tmp\PHQ7CGYD\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\PHQ7CGYD\PEPPTAddin.DLL
c:\users\Elena\AppData\Local\assembly\tmp\PMX2O5RG\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\PMX2O5RG\Microsoft.Office.Tools.Common.v4.0.Utilities.DLL
c:\users\Elena\AppData\Local\assembly\tmp\QWJSYXLA\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\QWJSYXLA\SharpBrake.2010.DLL
c:\users\Elena\AppData\Local\assembly\tmp\S22XVSSJ\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\S22XVSSJ\AutoUpdater.NET.DLL
c:\users\Elena\AppData\Local\assembly\tmp\SQ9OKAI4\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\SQ9OKAI4\PEPPTAddin.DLL
c:\users\Elena\AppData\Local\assembly\tmp\TZVY3U6A\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\TZVY3U6A\SharpBrake.2010.DLL
c:\users\Elena\AppData\Local\assembly\tmp\X5NH9FKS\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\X5NH9FKS\AutoUpdater.NET.DLL
c:\users\Elena\AppData\Local\assembly\tmp\ZAGJEMZC\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\ZAGJEMZC\PollEverywhere.WCFContracts.DLL
c:\users\Elena\AppData\Local\assembly\tmp\ZX4ONCPA\__AssemblyInfo__.ini
c:\users\Elena\AppData\Local\assembly\tmp\ZX4ONCPA\SharpBrake.2010.DLL
c:\users\Elena\AppData\Roaming\Microsoft Corporation\2007 Microsoft Office system
c:\windows\gt.exe
c:\windows\version.txt
.
.
((((((((((((((((((((((((( Files Created from 2015-03-03 to 2015-04-03 )))))))))))))))))))))))))))))))
.
.
2015-04-03 22:16 . 2015-04-03 22:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-04-02 06:31 . 2015-04-02 06:31 -------- d-----w- C:\RegBackup
2015-03-31 04:24 . 2015-03-31 04:29 -------- d-----w- C:\FRST
2015-03-30 16:47 . 2015-04-02 05:37 136408 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-03-30 16:47 . 2015-03-17 13:15 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2015-03-30 16:47 . 2015-03-17 13:15 107736 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-03-30 16:47 . 2015-03-17 13:15 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2015-03-30 16:47 . 2015-03-30 16:47 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2015-03-29 17:06 . 2015-03-29 17:06 -------- d-----w- c:\users\Elena\AppData\Roaming\AVG
2015-03-29 17:04 . 2015-03-29 17:04 -------- d-----w- c:\users\Elena\AppData\Local\Avg
2015-03-29 17:03 . 2015-03-29 17:07 -------- d-----w- c:\programdata\AVG
2015-03-25 18:21 . 2015-03-25 18:21 281056 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys
2015-03-25 03:06 . 2015-03-11 04:06 677888 ----a-w- c:\windows\system32\generaltel.dll
2015-03-25 03:06 . 2015-03-11 04:06 760832 ----a-w- c:\windows\system32\invagent.dll
2015-03-25 03:06 . 2015-03-11 04:06 943616 ----a-w- c:\windows\system32\appraiser.dll
2015-03-25 03:06 . 2015-03-11 04:05 30720 ----a-w- c:\windows\system32\acmigration.dll
2015-03-25 03:06 . 2015-03-11 04:02 1107456 ----a-w- c:\windows\system32\aeinv.dll
2015-03-25 03:06 . 2015-03-11 04:06 414720 ----a-w- c:\windows\system32\devinv.dll
2015-03-25 03:06 . 2015-03-11 04:05 227328 ----a-w- c:\windows\system32\aepdu.dll
2015-03-25 03:06 . 2015-03-11 04:05 192000 ----a-w- c:\windows\system32\aepic.dll
2015-03-11 12:38 . 2015-02-03 03:30 55808 ----a-w- c:\windows\system32\rrinstaller.exe
2015-03-11 12:37 . 2015-02-03 03:31 215552 ----a-w- c:\windows\system32\ubpm.dll
2015-03-11 12:36 . 2015-02-03 03:31 1424896 ----a-w- c:\windows\system32\WindowsCodecs.dll
2015-03-11 12:32 . 2015-02-04 03:16 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2015-03-11 12:32 . 2015-02-04 02:54 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2015-03-08 23:15 . 2015-01-09 03:14 91136 ----a-w- c:\windows\system32\wdi.dll
2015-03-08 23:15 . 2015-01-09 03:14 950272 ----a-w- c:\windows\system32\perftrack.dll
2015-03-08 23:15 . 2015-01-09 03:14 29696 ----a-w- c:\windows\system32\powertracker.dll
2015-03-08 23:15 . 2015-01-09 02:48 76800 ----a-w- c:\windows\SysWow64\wdi.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-04-02 05:21 . 2014-10-19 00:51 35064 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2015-03-29 16:14 . 2013-01-02 20:45 778928 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2015-03-29 16:14 . 2011-12-13 01:48 142512 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-03-12 10:07 . 2011-12-13 04:11 122905848 ----a-w- c:\windows\system32\MRT.exe
2015-02-26 00:37 . 2015-02-26 00:37 284128 ----a-w- c:\windows\system32\drivers\avgtdia.sys
2015-02-17 23:04 . 2015-02-17 23:04 1202848 ----a-w- c:\windows\SysWow64\FM20.DLL
2015-02-16 23:33 . 2015-02-16 23:33 856992 ----a-w- c:\windows\system32\tadefxapo264.dll
2015-02-16 23:33 . 2015-02-16 23:33 1959128 ----a-w- c:\windows\system32\RTSnMg64.cpl
2015-02-16 23:33 . 2015-02-16 23:33 2860760 ----a-w- c:\windows\system32\RtPgEx64.dll
2015-02-16 23:33 . 2015-02-16 23:33 4263128 ----a-w- c:\windows\system32\drivers\RTKVHD64.sys
2015-02-16 23:33 . 2015-02-16 23:33 3186544 ----a-w- c:\windows\system32\RtkApi64.dll
2015-02-16 23:33 . 2015-02-16 23:33 629464 ----a-w- c:\windows\system32\RtDataProc64.dll
2015-02-16 23:32 . 2015-02-16 23:32 1287384 ----a-w- c:\windows\system32\RTCOM64.dll
2015-02-16 23:32 . 2015-02-16 23:32 2827120 ----a-w- c:\windows\system32\RltkAPO64.dll
2015-02-16 23:32 . 2015-02-16 23:32 959704 ----a-w- c:\windows\system32\RCoInstII64.dll
2015-02-16 23:32 . 2015-02-16 23:32 1550528 ----a-w- c:\windows\system32\CX64APO.dll
2015-02-16 23:31 . 2015-02-16 23:31 560328 ----a-w- c:\windows\system32\AERTAC64.dll
2015-02-16 23:31 . 2015-02-16 23:31 83656 ----a-w- c:\windows\system32\drivers\amd_sata.sys
2015-02-16 23:31 . 2015-02-16 23:31 43720 ----a-w- c:\windows\system32\drivers\amd_xata.sys
2015-02-16 23:30 . 2015-02-16 23:30 942808 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2015-02-16 23:30 . 2015-02-16 23:30 73800 ----a-w- c:\windows\system32\RtNicProp64.dll
2015-02-16 23:30 . 2011-12-03 06:09 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2015-02-16 23:26 . 2015-02-16 23:26 94720 ----a-w- c:\windows\system32\drivers\AtihdW76.sys
2015-02-16 23:26 . 2015-02-16 23:26 110080 ----a-w- c:\windows\system32\DelayAPO.dll
2015-02-16 23:25 . 2015-02-16 23:25 332080 ----a-w- c:\windows\system32\RaCoInstx.dll
2015-02-16 23:25 . 2015-02-16 23:25 2472136 ----a-w- c:\windows\system32\drivers\netr28x.sys
2015-02-16 23:25 . 2015-02-16 23:25 331992 ----a-w- c:\windows\system32\drivers\RtsUVStor.sys
2015-02-16 23:25 . 2015-02-16 23:25 9890008 ----a-w- c:\windows\SysWow64\RsCRIcon.dll
2015-02-16 23:17 . 2015-02-16 23:17 62800 ----a-w- c:\windows\system\S6000Rmv.dll
2015-02-16 23:17 . 2015-02-16 23:17 427344 ----a-w- c:\windows\system\S6000Dex.dll
2015-02-16 23:17 . 2015-02-16 23:17 3396304 ----a-w- c:\windows\system32\drivers\S6000KNT.sys
2015-02-16 23:17 . 2015-02-16 23:17 246608 ----a-w- c:\windows\system32\S6000DIF.dll
2015-02-16 23:17 . 2015-02-16 23:17 140624 ----a-w- c:\windows\system\S6000Vex.dll
2015-02-16 23:17 . 2015-02-16 23:17 12112 ----a-w- c:\windows\system\S6000Remov.exe
2015-02-16 23:08 . 2015-02-16 23:08 26528 ----a-w- c:\windows\SysWow64\drivers\HWiNFO64A.SYS
2015-02-05 17:27 . 2015-02-05 17:27 133088 ----a-w- c:\windows\system32\drivers\avgmfx64.sys
2015-02-03 17:47 . 2015-02-03 17:47 341472 ----a-w- c:\windows\system32\drivers\avgloga.sys
2015-01-27 23:36 . 2015-02-17 00:00 1239720 ----a-w- c:\windows\system32\aitstatic.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-07-01 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-07-28 336384]
"YouCam Mirage"="c:\program files (x86)\Lenovo\YouCam\YCMMirage.exe" [2011-01-28 136488]
"YouCam Tray"="c:\program files (x86)\Lenovo\YouCam\YouCam.exe" [2011-01-28 228448]
"VeriFaceManager"="c:\program files (x86)\Lenovo\VeriFace\PManage.exe" [2011-12-03 329056]
"UpdateP2GShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2010-07-26 222504]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"ControlCenter4"="c:\program files (x86)\ControlCenter4\BrCcBoot.exe" [2012-09-07 143360]
"BrStsMon00"="c:\program files (x86)\Browny02\Brother\BrStMonW.exe" [2012-06-06 3076096]
"AVG_UI"="c:\program files (x86)\AVG\AVG2015\avgui.exe" [2015-03-25 3723728]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 8"="c:\program files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" [2014-12-10 2427680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R2 RaMediaServer;Ralink UPnP Media Server;c:\program files (x86)\Ralink\RT2860 Wireless LAN Card\ExtraFiles\RaMediaServer.exe;c:\program files (x86)\Ralink\RT2860 Wireless LAN Card\ExtraFiles\RaMediaServer.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 BrSerIb;Brother Serial Interface Driver(WDM);c:\windows\system32\DRIVERS\BrSerIb.sys;c:\windows\SYSNATIVE\DRIVERS\BrSerIb.sys [x]
R3 BrUsbSIb;Brother Serial USB Driver(WDM);c:\windows\system32\DRIVERS\BrUsbSIb.sys;c:\windows\SYSNATIVE\DRIVERS\BrUsbSIb.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys;c:\windows\SYSNATIVE\DRIVERS\wsvd.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsha.sys [x]
S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys;c:\windows\SYSNATIVE\DRIVERS\avgloga.sys [x]
S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x]
S0 fbfmon;fbfmon;c:\windows\system32\drivers\fbfmon.sys;c:\windows\SYSNATIVE\drivers\fbfmon.sys [x]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys;c:\windows\SYSNATIVE\DRIVERS\LhdX64.sys [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
S1 Avgdiska;AVG Disk Driver;c:\windows\system32\DRIVERS\avgdiska.sys;c:\windows\SYSNATIVE\DRIVERS\avgdiska.sys [x]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsdrivera.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgldx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys;c:\windows\SYSNATIVE\DRIVERS\avgtdia.sys [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys;c:\windows\SYSNATIVE\drivers\avgtpx64.sys [x]
S1 BPntDrv;BPntDrv;c:\windows\system32\drivers\BPntDrv.sys;c:\windows\SYSNATIVE\drivers\BPntDrv.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 AdvancedSystemCareService8;Advanced SystemCare Service 8;c:\program files (x86)\IObit\Advanced SystemCare 8\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2015\avgidsagent.exe;c:\program files (x86)\AVG\AVG2015\avgidsagent.exe [x]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2015\avgwdsvc.exe;c:\program files (x86)\AVG\AVG2015\avgwdsvc.exe [x]
S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [x]
S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [x]
S2 IMFservice;IMF Service;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [x]
S2 PasswordBox;PasswordBox;c:\program files (x86)\PasswordBox\pbbtnService.exe;c:\program files (x86)\PasswordBox\pbbtnService.exe [x]
S2 RtkAudioService;Realtek Audio Service;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe [x]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys;c:\windows\SYSNATIVE\DRIVERS\AcpiVpc.sys [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 BrYNSvc;BrYNSvc;c:\program files (x86)\Browny02\BrYNSvc.exe;c:\program files (x86)\Browny02\BrYNSvc.exe [x]
S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys;c:\windows\SYSNATIVE\DRIVERS\dc3d.sys [x]
S3 FileMonitor;FileMonitor;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x]
S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
S3 RegFilter;RegFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [x]
S3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 S6000KNT;S6000KNT_WebCam Driver;c:\windows\system32\Drivers\S6000KNT.sys;c:\windows\SYSNATIVE\Drivers\S6000KNT.sys [x]
S3 UrlFilter;UrlFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-03-21 11:32 1061704 ----a-w- c:\program files (x86)\Google\Chrome\Application\41.0.2272.101\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2015-04-03 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-02 16:14]
.
2015-04-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-03 07:14]
.
2015-04-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-03 07:14]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
2015-02-16 23:10 2471744 ----a-w- c:\program files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2011-12-03 06:25 1508192 ----a-w- c:\windows\System32\IcnOvrly.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2015-02-16 13774040]
"Lenovo EE Boot Optimizer"="c:\program files (x86)\Lenovo\Boot Optimizer\PopWnd.exe" [2011-12-03 206176]
"OnekeyStudio"="c:\program files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe" [2011-12-03 789920]
"Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2011-12-03 9769888]
"EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\Utility.exe" [2011-12-03 5908928]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]
"RtHDVBg_LENOVO_DOLBYDRAGON"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2015-02-16 1396592]
"RtHDVBg_LENOVO_MICPKEY"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2015-02-16 1396592]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 104.131.192.211 107.170.168.61 66.60.130.158
FF - ProfilePath - c:\users\Elena\AppData\Roaming\Mozilla\Firefox\Profiles\45ne04a1.default\
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
Wow6432Node-HKLM-Run-S6000Mnt - S6000Rmv.dll
Wow6432Node-HKU-Default-Run-Advanced SystemCare 7 - c:\program files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2015-04-03 15:59:41
ComboFix-quarantined-files.txt 2015-04-03 22:59
.
Pre-Run: 392,753,836,032 bytes free
Post-Run: 391,957,872,640 bytes free
.
- - End Of File - - 95FB66F59DA2C85B7C6939B9F643909A
A36C5E4F47E84449FF07ED3517B43A31