ComboFix 16-04-29.01 - r 05/07/2016 18:52:17.1.2 - x86
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.1979.995 [GMT -5:00]
Running from: c:\users\r\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DYXE7DZN\ComboFix.exe
AV: AVG AntiVirus Free Edition *Disabled/Updated* {4D41356F-32AD-7C42-C820-63775EE4F413}
SP: AVG AntiVirus Free Edition *Disabled/Updated* {F620D48B-1497-73CC-F290-58052563BEAE}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\PCDr\6793\AddOnDownloaded\0124e21d-018c-4ce0-92a3-b9e205a76bc0.dll
c:\programdata\PCDr\6793\AddOnDownloaded\06054fba-5619-4a86-a861-ffb0464bef5d.dll
c:\programdata\PCDr\6793\AddOnDownloaded\06fda46e-43c1-481a-9eb2-9799f42e7f99.dll
c:\programdata\PCDr\6793\AddOnDownloaded\0bc194f9-b102-4833-85bd-603e216a9274.dll
c:\programdata\PCDr\6793\AddOnDownloaded\0d461521-7dbf-4cec-a29e-936c88cdf8c9.dll
c:\programdata\PCDr\6793\AddOnDownloaded\100c3865-0c76-461b-b2fd-042d6d5fa7f6.dll
c:\programdata\PCDr\6793\AddOnDownloaded\14d73fac-0439-4f06-9763-0341fab0d44f.dll
c:\programdata\PCDr\6793\AddOnDownloaded\173c4dd2-e93c-4725-b006-db1d8f465192.dll
c:\programdata\PCDr\6793\AddOnDownloaded\1770287d-f115-443b-9fb7-268be5a136fc.dll
c:\programdata\PCDr\6793\AddOnDownloaded\1b0b3c38-2b97-4f8d-954b-06296209b73d.dll
c:\programdata\PCDr\6793\AddOnDownloaded\1d25df4e-fb49-4047-b057-5a757ec1e10a.dll
c:\programdata\PCDr\6793\AddOnDownloaded\1e0aaf9a-9947-4a7b-b1ae-8a89919438ed.dll
c:\programdata\PCDr\6793\AddOnDownloaded\1eec01b0-8ca5-44d8-a311-9e7f96e586dd.dll
c:\programdata\PCDr\6793\AddOnDownloaded\1f82ef5d-9e89-4c2f-839d-1dfc47d3af1b.dll
c:\programdata\PCDr\6793\AddOnDownloaded\263d6ac9-4f87-466c-947c-bd9af71d7035.dll
c:\programdata\PCDr\6793\AddOnDownloaded\2a6b5d0b-a2fc-4bdd-b3fe-6bbefb85b7e4.dll
c:\programdata\PCDr\6793\AddOnDownloaded\2eccd5d6-e118-4f76-97b6-ba56fb6c597a.dll
c:\programdata\PCDr\6793\AddOnDownloaded\2ed4ce9e-0dff-4595-a0aa-f3e3b671fddc.dll
c:\programdata\PCDr\6793\AddOnDownloaded\3087e0df-b321-44c3-b144-fb94c30c8383.dll
c:\programdata\PCDr\6793\AddOnDownloaded\32de12dc-d8c3-42aa-adc7-6c4c6b126d9e.dll
c:\programdata\PCDr\6793\AddOnDownloaded\3324fb70-b482-4ff5-9d0e-102981046ff0.dll
c:\programdata\PCDr\6793\AddOnDownloaded\3410f47b-5e8c-47c6-bf2c-234af4121d4c.dll
c:\programdata\PCDr\6793\AddOnDownloaded\35b44250-4f9f-4c83-a518-a7c76d04314b.dll
c:\programdata\PCDr\6793\AddOnDownloaded\378deb7f-049e-4a5e-83b2-5381dcd9e928.dll
c:\programdata\PCDr\6793\AddOnDownloaded\3972fea3-214c-4935-a7d1-96bf66115683.dll
c:\programdata\PCDr\6793\AddOnDownloaded\3b1c7acd-5e3e-4459-ab98-5109117e2341.dll
c:\programdata\PCDr\6793\AddOnDownloaded\41a30eb5-952e-4dbb-ae28-5f8aa6520aba.dll
c:\programdata\PCDr\6793\AddOnDownloaded\4546f2bc-b9d9-4667-abe7-b0bacc90279e.dll
c:\programdata\PCDr\6793\AddOnDownloaded\459715e4-d2b9-4b1d-9abd-b72ddc2c69b1.dll
c:\programdata\PCDr\6793\AddOnDownloaded\471d2ede-d247-4b88-8413-b4f925daed35.dll
c:\programdata\PCDr\6793\AddOnDownloaded\4804ced5-915b-48a3-a465-b8a5e02714bf.dll
c:\programdata\PCDr\6793\AddOnDownloaded\4818e109-9489-4cd8-9044-44defd8ec187.dll
c:\programdata\PCDr\6793\AddOnDownloaded\48b34bb5-ff90-4d9e-b894-efe9b9fb83df.dll
c:\programdata\PCDr\6793\AddOnDownloaded\49f89ca5-aa70-4aab-9314-4a62fc1f0e87.dll
c:\programdata\PCDr\6793\AddOnDownloaded\4cb05034-365d-4b59-a070-5750405458b0.dll
c:\programdata\PCDr\6793\AddOnDownloaded\50441041-9037-4c34-842c-4a8523e700da.dll
c:\programdata\PCDr\6793\AddOnDownloaded\51fdf16e-ecb9-4fa4-8469-76fc9a22293b.dll
c:\programdata\PCDr\6793\AddOnDownloaded\545e0921-6e62-4c80-bee9-427f48425c93.dll
c:\programdata\PCDr\6793\AddOnDownloaded\57d7325c-8462-4866-a9ca-3f9228775fed.dll
c:\programdata\PCDr\6793\AddOnDownloaded\5a2fca81-2a3a-4213-a397-872704c3f168.dll
c:\programdata\PCDr\6793\AddOnDownloaded\5bbfdaf0-4ed3-451e-8ae5-d6568a621a17.dll
c:\programdata\PCDr\6793\AddOnDownloaded\62d1f0b0-bc9a-4f6c-bad7-93b19a91276a.dll
c:\programdata\PCDr\6793\AddOnDownloaded\649574c7-1acb-458c-a846-1bc04bfcdb93.dll
c:\programdata\PCDr\6793\AddOnDownloaded\67c3d4fe-b638-467a-9fe2-c5813ade3330.dll
c:\programdata\PCDr\6793\AddOnDownloaded\6820b110-e483-4f1e-9b48-438f7916f078.dll
c:\programdata\PCDr\6793\AddOnDownloaded\6b56d7e1-5ac6-46da-8615-10fbe2919ac8.dll
c:\programdata\PCDr\6793\AddOnDownloaded\6b5978fa-48d7-4309-a523-7e157768c0d8.dll
c:\programdata\PCDr\6793\AddOnDownloaded\6bdfa889-cc66-47b8-8124-f44af6185c4a.dll
c:\programdata\PCDr\6793\AddOnDownloaded\6f4fb483-ce30-493a-8cb4-3e530ab1be5b.dll
c:\programdata\PCDr\6793\AddOnDownloaded\6f9e83ca-5216-40db-863d-61ffff2a1563.dll
c:\programdata\PCDr\6793\AddOnDownloaded\72db11e1-d2b2-4f9f-828a-5a68b9e7709f.dll
c:\programdata\PCDr\6793\AddOnDownloaded\739db3eb-d3cd-4c86-a6ea-01a49984fa3b.dll
c:\programdata\PCDr\6793\AddOnDownloaded\7aab56cb-b4f9-4339-82d7-9bebc9820fd4.dll
c:\programdata\PCDr\6793\AddOnDownloaded\7bd83798-7a02-4f50-83a2-b91cabcbd1f9.dll
c:\programdata\PCDr\6793\AddOnDownloaded\7c5b1d75-4145-4f69-b184-a8fb559fd417.dll
c:\programdata\PCDr\6793\AddOnDownloaded\7dbfef1a-6148-4748-a1b3-71627763a45a.dll
c:\programdata\PCDr\6793\AddOnDownloaded\7eb9d453-6936-472b-8a21-a9513eebbf65.dll
c:\programdata\PCDr\6793\AddOnDownloaded\7ee97e57-ddc8-4c67-a05d-8776b2353080.dll
c:\programdata\PCDr\6793\AddOnDownloaded\812fed95-c1fb-4695-be1a-fd6265302cf9.dll
c:\programdata\PCDr\6793\AddOnDownloaded\813755dc-2229-47a2-b85b-19d0aaa641c9.dll
c:\programdata\PCDr\6793\AddOnDownloaded\84044d39-7df5-40d8-9c83-1be344e0305e.dll
c:\programdata\PCDr\6793\AddOnDownloaded\872965c7-08b7-47fc-a74c-ff167590b71a.dll
c:\programdata\PCDr\6793\AddOnDownloaded\873c94c8-114d-4d39-a36a-14d636c6e7f3.dll
c:\programdata\PCDr\6793\AddOnDownloaded\8c64e2ef-3080-4951-8358-e991c1695e4a.dll
c:\programdata\PCDr\6793\AddOnDownloaded\934f6059-2d35-4bd9-a130-a17cb5563507.dll
c:\programdata\PCDr\6793\AddOnDownloaded\95863b84-2a1c-4539-bd21-ffbef3ea7fd9.dll
c:\programdata\PCDr\6793\AddOnDownloaded\9ad177b0-ddcd-4cf6-ac35-969dc98b22db.dll
c:\programdata\PCDr\6793\AddOnDownloaded\9afbb1e4-1951-4d6e-bd32-2e0e5254786f.dll
c:\programdata\PCDr\6793\AddOnDownloaded\9bd80958-c5f2-4f2f-aa6b-c45a01a4e97c.dll
c:\programdata\PCDr\6793\AddOnDownloaded\9cc8e4b9-2989-4941-94e1-8c5358218ffb.dll
c:\programdata\PCDr\6793\AddOnDownloaded\a360a789-e8b0-4637-9792-e0ff95e234e4.dll
c:\programdata\PCDr\6793\AddOnDownloaded\a9de0c84-9a7c-4638-9653-13aa8cf56e80.dll
c:\programdata\PCDr\6793\AddOnDownloaded\b2152f30-7380-4987-8fcf-e4c06952615d.dll
c:\programdata\PCDr\6793\AddOnDownloaded\b451e5c8-cdbf-46b4-8e59-e9a05ebf3533.dll
c:\programdata\PCDr\6793\AddOnDownloaded\b4cc2a4a-87f5-49cd-935c-18f1a80e65b7.dll
c:\programdata\PCDr\6793\AddOnDownloaded\ba005e12-3139-4327-9f7a-9f2ea6a6c841.dll
c:\programdata\PCDr\6793\AddOnDownloaded\bc6fc708-5b6b-4a72-b336-09b3089baa7a.dll
c:\programdata\PCDr\6793\AddOnDownloaded\bcd55a0b-5c73-4efb-87eb-fa42f0002bb9.dll
c:\programdata\PCDr\6793\AddOnDownloaded\bea3f575-677a-4c92-89ca-7be8480c11a9.dll
c:\programdata\PCDr\6793\AddOnDownloaded\c238c886-2790-4da6-895b-00c9110314ec.dll
c:\programdata\PCDr\6793\AddOnDownloaded\c27a8f9a-0718-4077-8610-9b1806d75bee.dll
c:\programdata\PCDr\6793\AddOnDownloaded\c4211805-b43b-471d-81af-4e0589f8607b.dll
c:\programdata\PCDr\6793\AddOnDownloaded\c502e200-e694-4725-9348-253ed2eac74c.dll
c:\programdata\PCDr\6793\AddOnDownloaded\c6528f35-d623-4e84-a9b2-58ecb22dabd4.dll
c:\programdata\PCDr\6793\AddOnDownloaded\c6bf01ba-05a7-4930-b8dd-7c5fd03e97ac.dll
c:\programdata\PCDr\6793\AddOnDownloaded\c746a3b1-ed0c-4bff-941c-d5e6f0583ce7.dll
c:\programdata\PCDr\6793\AddOnDownloaded\caac49ab-d9d8-4f29-a409-2a9a30ae62af.dll
c:\programdata\PCDr\6793\AddOnDownloaded\cdda52ec-6ccd-425a-8c72-b7bbdc8b3acd.dll
c:\programdata\PCDr\6793\AddOnDownloaded\d34c0cf7-889f-43dd-9283-b2b6f442aae3.dll
c:\programdata\PCDr\6793\AddOnDownloaded\d7306aee-c81a-43de-a6a8-e1baed06cbe9.dll
c:\programdata\PCDr\6793\AddOnDownloaded\dd1bac2a-784b-4124-895b-8444b4b4697b.dll
c:\programdata\PCDr\6793\AddOnDownloaded\ddb9fe5d-525c-4d5d-ac37-0bd10f2864f8.dll
c:\programdata\PCDr\6793\AddOnDownloaded\e45cd45a-4d7c-4802-881f-74582b847e5c.dll
c:\programdata\PCDr\6793\AddOnDownloaded\e5a71f43-c979-4b3d-a544-9ed1dc6dc4c8.dll
c:\programdata\PCDr\6793\AddOnDownloaded\edb10714-8498-4679-a667-4c4c359de017.dll
c:\programdata\PCDr\6793\AddOnDownloaded\ee4747a4-1d1b-42c1-8a8c-1de04bbb2379.dll
c:\programdata\PCDr\6793\AddOnDownloaded\ef78c3e8-1d94-4219-8070-7617e119bba4.dll
c:\programdata\PCDr\6793\AddOnDownloaded\f06c5597-1a85-4d1f-ac16-a6fdd2a6bedc.dll
c:\programdata\PCDr\6793\AddOnDownloaded\fbd50850-4122-4fe3-a72e-fcbe58a0f196.dll
c:\programdata\PCDr\6793\AddOnDownloaded\ff34f184-7b2d-4b07-9131-b1349888b6e5.dll
c:\windows\~GLH0005.TMP
c:\windows\~GLH0006.TMP
c:\windows\~GLH0007.TMP
c:\windows\~GLH0008.TMP
c:\windows\~GLH0009.TMP
c:\windows\~GLH000a.TMP
c:\windows\system32\~GLH0016.TMP
c:\windows\system32\~GLH0017.TMP
c:\windows\system32\~GLH0018.TMP
c:\windows\system32\~GLH001b.TMP
c:\windows\system32\~GLH001c.TMP
c:\windows\system32\~GLH001d.TMP
c:\windows\system32\~GLH001e.TMP
c:\windows\system32\~GLH001f.TMP
c:\windows\system32\~GLH0020.TMP
c:\windows\system32\~GLH0021.TMP
c:\windows\system32\~GLH0022.TMP
c:\windows\system32\~GLH0023.TMP
c:\windows\system32\~GLH0025.TMP
c:\windows\system32\~GLH0027.TMP
c:\windows\system32\~GLH0028.TMP
c:\windows\system32\~GLH002c.TMP
c:\windows\system32\~GLH002d.TMP
c:\windows\system32\~GLH0031.TMP
c:\windows\system32\drivers\~GLH001c.TMP
c:\windows\system32\drivers\~GLH001d.TMP
c:\windows\system32\drivers\~GLH001e.TMP
c:\windows\system32\drivers\~GLH001f.TMP
c:\windows\system32\drivers\~GLH0020.TMP
c:\windows\system32\drivers\~GLH0023.TMP
c:\windows\system32\drivers\~GLH0024.TMP
c:\windows\system32\drivers\~GLH0025.TMP
c:\windows\system32\drivers\~GLH0026.TMP
c:\windows\system32\drivers\~GLH0027.TMP
c:\windows\system32\drivers\~GLH0028.TMP
c:\windows\system32\drivers\~GLH0029.TMP
c:\windows\system32\drivers\~GLH002a.TMP
c:\windows\system32\drivers\~GLH002b.TMP
c:\windows\system32\drivers\~GLH002c.TMP
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Files Created from 2016-04-08 to 2016-05-08 )))))))))))))))))))))))))))))))
.
.
2016-05-08 00:00 . 2016-05-08 00:01 -------- d-----w- c:\users\r\AppData\Local\temp
2016-05-08 00:00 . 2016-05-08 00:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-05-02 17:04 . 2016-05-02 17:04 -------- dc-h--w- c:\programdata\{05EE3202-A879-4F9D-895C-AC535855E0A9}
2016-04-30 20:53 . 2010-02-23 17:00 256712 ----a-w- c:\windows\system32\PROUnstl.exe
2016-04-30 20:33 . 2016-04-30 21:05 -------- d-----w- c:\programdata\SupportAssistAgent
2016-04-30 20:24 . 2016-04-30 20:24 0 ----a-w- c:\windows\invcol.tmp
2016-04-25 20:10 . 2012-01-04 01:10 16512 ----a-w- c:\windows\system32\drivers\RD9700.sys
2016-04-23 02:41 . 2016-04-23 02:41 -------- d-----w- c:\program files\Common Files\Java
2016-04-20 19:17 . 2016-04-20 19:17 253184 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2016-04-20 02:09 . 2016-04-20 02:10 170200 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2016-04-20 02:08 . 2016-03-10 19:09 53120 ----a-w- c:\windows\system32\drivers\mwac.sys
2016-04-20 02:08 . 2016-03-10 19:08 126336 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2016-04-20 02:08 . 2016-03-10 19:08 24448 ----a-w- c:\windows\system32\drivers\mbam.sys
2016-04-19 23:59 . 2016-04-20 00:00 -------- d-----w- C:\AdwCleaner
2016-04-19 17:26 . 2016-04-19 17:26 -------- d-----w- c:\program files\Mozilla Maintenance Service
2016-04-18 14:10 . 2016-04-18 14:10 61696 ----a-w- c:\windows\system32\drivers\avgunivx.sys
2016-04-16 21:41 . 2016-04-16 21:41 -------- d-----w- c:\program files\Autodesk
2016-04-16 21:02 . 2016-04-16 21:02 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2016-04-15 22:37 . 2016-04-15 22:37 -------- d-----w- c:\programdata\PC-Doctor for Windows
2016-04-15 22:37 . 2016-04-15 22:37 -------- d-----w- c:\program files\Dell Support Center
2016-04-14 15:54 . 2016-04-14 15:54 46848 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2016-04-14 02:34 . 2016-03-04 16:52 1253376 ----a-w- c:\windows\system32\msxml3.dll
2016-04-14 02:33 . 2016-03-18 17:10 206336 ----a-w- c:\windows\system32\ncrypt.dll
2016-04-14 02:33 . 2016-03-18 17:10 72704 ----a-w- c:\windows\system32\secur32.dll
2016-04-14 02:33 . 2016-03-18 17:10 57344 ----a-w- c:\windows\system32\samlib.dll
2016-04-14 02:33 . 2016-03-18 17:10 486912 ----a-w- c:\windows\system32\samsrv.dll
2016-04-14 02:33 . 2016-03-18 17:09 1259520 ----a-w- c:\windows\system32\lsasrv.dll
2016-04-14 02:32 . 2016-03-18 15:32 2048 ----a-w- c:\windows\system32\tzres.dll
2016-04-14 02:25 . 2016-03-18 17:10 1316864 ----a-w- c:\windows\system32\ole32.dll
2016-04-14 02:25 . 2016-03-21 22:57 1208568 ----a-w- c:\windows\system32\ntdll.dll
2016-04-14 02:24 . 2016-03-17 17:45 105472 ----a-w- c:\windows\system32\mtxoci.dll
2016-04-14 02:24 . 2016-03-17 17:45 180224 ----a-w- c:\windows\system32\msorcl32.dll
2016-04-14 02:24 . 2016-03-17 17:45 290816 ----a-w- c:\program files\Common Files\System\Ole DB\msdaora.dll
2016-04-14 02:23 . 2016-03-29 20:30 2070016 ----a-w- c:\windows\system32\win32k.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-04-23 02:39 . 2015-08-31 17:28 95808 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2016-04-10 18:10 . 2014-05-23 14:37 797376 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2016-04-10 18:10 . 2014-05-23 14:37 142528 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2016-03-29 21:45 . 2016-03-29 21:45 191232 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2016-02-16 21:26 . 2016-02-16 21:26 134944 ----a-w- c:\windows\system32\drivers\avgdiskx.sys
2016-02-16 21:20 . 2016-02-16 21:20 287008 ----a-w- c:\windows\system32\drivers\avglogx.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2015-08-06 421888]
"SpybotPostWindows10UpgradeReInstall"="c:\program files\Common Files\AV\Spybot - Search and Destroy\Test.exe" [2015-07-29 1011200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Real\RealPlayer\Update\realsched.exe" [2014-05-28 295512]
"LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2012-09-13 204136]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-14 59720]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2013-05-08 41056]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2013-05-30 96056]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-12 137752]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-12 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-12 172568]
"VX3000"="c:\windows\vVX3000.exe" [2010-05-20 762736]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2010-05-20 119152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2015-08-06 421888]
"AvgUi"="c:\program files\AVG\Framework\Common\avguirnx.exe" [2016-04-14 186640]
"AVG_UI"="c:\program files\AVG\Av\avuirunnerx.exe" [2016-04-20 32528]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-03-05 1310720]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2016-04-01 596504]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-9-10 525664]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Ralink Wireless Utility.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
backup=c:\windows\pss\Ralink Wireless Utility.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2011-02-12 00:26 171032 ----a-w- c:\windows\System32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2011-02-12 00:26 137752 ----a-w- c:\windows\System32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2011-02-12 00:26 172568 ----a-w- c:\windows\System32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\picon]
2009-07-21 19:40 796696 ----a-w- c:\program files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-19 04:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
2009-04-11 04:28 2153472 ----a-w- c:\windows\System32\oobefldr.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
2008-04-11 22:23 38400 ----a-w- c:\windows\System32\SoundSchemes.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2016-04-12 01:30 1106072 ----a-w- c:\program files\Google\Chrome\Application\49.0.2623.112\Installer\chrmstp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B3688A53-AB2A-4b1d-8CEF-8F93D8C51C24}]
2008-08-28 15:50 30720 ----a-w- c:\windows\System32\soundschemes2.exe
.
Contents of the 'Scheduled Tasks' folder
.
2016-05-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-23 18:10]
.
2016-05-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-12-04 07:48]
.
2016-05-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-12-04 07:48]
.
.
------- Supplementary Scan -------
.
Trusted Zone: dell.com
TCP: DhcpNameServer = 192.168.0.1 205.171.3.25
FF - ProfilePath - c:\users\r\AppData\Roaming\Mozilla\Firefox\Profiles\hqczfzhm.default-1411339930239\
FF - prefs.js: browser.startup.homepage - hxxps://
www.wunderground.com/weather-radar/united-states/la/lake-charles/lch/?region=msy|aboutreferences
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-AVG_UI - c:\program files\AVG\AVG2014\avgui.exe
MSConfigStartUp-DellSystemDetect - c:\users\r\AppData\Local\Apps\2.0\9OKJOMET.AAJ\28PZQ8H1.GM2\dell..tion_0f612f649c4a10af_0005.0007_59de4fd2458fcaec\DellSystemDetect.exe
MSConfigStartUp-SDTray - c:\program files\Spybot - Search & Destroy 2\SDTray.exe
MSConfigStartUp-Spybot-S&D Cleaning - c:\program files\Spybot - Search & Destroy 2\SDCleaner.exe
AddRemove-58d94f3ce2c27db0 - c:\users\r\AppData\Local\Apps\2.0\9OKJOMET.AAJ\28PZQ8H1.GM2\dell..tion_6d0a76327dca4869_0007.0004_041659e87a6c2b4d\Uninstaller.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2016-05-07 19:00
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_21_0_0_213_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_21_0_0_213_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2016-05-07 19:06:49
ComboFix-quarantined-files.txt 2016-05-08 00:06
.
Pre-Run: 143,386,198,016 bytes free
Post-Run: 145,181,483,008 bytes free
.
- - End Of File - - 7420315D0E9BAB1936844A8453542A13
5C616939100B85E558DA92B899A0FC36