Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

combofix analysis report


  • This topic is locked This topic is locked
2 replies to this topic

#1 orhant

orhant

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:08:48 PM

Posted 17 January 2015 - 07:26 AM

this is combofix analysis report what is the results?
 
 
ComboFix 15-01-08.01 - home 17.01.2015  13:53:08.1.6 - x64
Microsoft Windows 7 Ultimate   6.1.7601.1.1254.90.1055.18.16349.13776 [GMT 2:00]
Running from: c:\users\home\Downloads\ComboFix.exe
AV: COMODO Antivirus *Disabled/Updated* {F0BC89B2-8937-0933-021B-B17D981F2A71}
FW: COMODO Firewall *Disabled* {C8870897-C358-086B-2944-184866CC6D0A}
SP: Comodo Defense+ *Disabled/Updated* {4BDD6856-AF0D-06BD-38AB-8A0FE39860CC}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Created a new restore point
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\1420827327.bdinstall.bin
.
.
(((((((((((((((((((((((((   Files Created from 2014-12-17 to 2015-01-17  )))))))))))))))))))))))))))))))
.
.
2015-01-17 12:00 . 2015-01-17 12:00 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2015-01-17 12:00 . 2015-01-17 12:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-01-16 18:07 . 2015-01-16 18:07 -------- d-----w- c:\users\home\AppData\Local\AskPartnerNetwork
2015-01-16 18:07 . 2015-01-16 18:07 -------- d-----w- c:\programdata\AskPartnerNetwork
2015-01-16 18:07 . 2015-01-16 18:07 -------- d-----w- c:\program files (x86)\AskPartnerNetwork
2015-01-16 18:07 . 2015-01-16 18:07 -------- d-----w- c:\programdata\APN
2015-01-16 18:06 . 2015-01-16 18:06 -------- d-----w- c:\windows\Sun
2015-01-16 18:05 . 2015-01-16 18:05 -------- d-----w- c:\program files (x86)\Common Files\Java
2015-01-16 18:05 . 2015-01-16 18:05 98216 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2015-01-16 18:05 . 2015-01-16 18:05 -------- d-----w- c:\programdata\Oracle
2015-01-16 18:05 . 2015-01-16 18:05 -------- d-----w- c:\program files (x86)\Java
2015-01-15 15:07 . 2015-01-15 15:07 -------- d-----w- c:\program files (x86)\Euro Truck Simulator 2 Multiplayer
2015-01-14 15:20 . 2015-01-14 15:20 -------- d-----w- c:\program files (x86)\Common Files\COMODO
2015-01-13 18:31 . 2015-01-13 18:31 -------- d-----w- C:\VTRoot
2015-01-13 18:28 . 2015-01-13 18:28 -------- d-----w- c:\programdata\Shared Space
2015-01-13 18:28 . 2015-01-13 18:28 -------- d-----w- c:\program files\COMODO
2015-01-13 18:27 . 2015-01-13 18:27 -------- d-----w- c:\users\home\AppData\Local\Comodo
2015-01-13 18:27 . 2015-01-13 18:27 57096 ----a-w- c:\windows\system32\certsentry.dll
2015-01-13 18:27 . 2015-01-13 18:27 48392 ----a-w- c:\windows\SysWow64\certsentry.dll
2015-01-13 18:27 . 2015-01-13 18:27 -------- d-----w- c:\program files (x86)\Comodo
2015-01-13 18:27 . 2015-01-13 18:27 -------- d-----w- c:\programdata\Comodo Downloader
2015-01-13 18:26 . 2015-01-13 18:29 -------- d-----w- c:\programdata\Comodo
2015-01-13 17:59 . 2014-12-15 02:13 11870360 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7B6AC9E7-738C-4FB0-9EF0-2443BB01A044}\mpengine.dll
2015-01-13 17:59 . 2015-01-08 07:55 298120 ------w- c:\windows\system32\MpSigStub.exe
2015-01-10 17:51 . 2015-01-10 17:51 -------- d-----w- c:\windows\system32\SPReview
2015-01-10 15:39 . 2015-01-10 15:39 -------- d-----w- c:\programdata\Malwarebytes
2015-01-10 12:28 . 2015-01-10 12:28 -------- d-----w- c:\users\home\AppData\Roaming\AVG2015
2015-01-10 12:28 . 2015-01-10 12:28 -------- d-----w- c:\users\home\AppData\Roaming\TuneUp Software
2015-01-10 12:28 . 2015-01-10 12:56 -------- d-----w- c:\programdata\AVG2015
2015-01-10 12:28 . 2015-01-10 12:45 -------- d-----w- C:\$AVG
2015-01-10 12:22 . 2015-01-10 12:56 -------- d-----w- c:\programdata\MFAData
2015-01-10 12:22 . 2015-01-10 12:34 -------- d-----w- c:\users\home\AppData\Local\Avg2015
2015-01-10 12:22 . 2015-01-10 12:22 -------- d--h--w- c:\programdata\Common Files
2015-01-10 12:22 . 2015-01-10 12:22 -------- d-----w- c:\users\home\AppData\Local\MFAData
2015-01-10 12:18 . 2015-01-10 12:18 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2015-01-09 16:52 . 2015-01-10 10:52 -------- d-----w- c:\program files\Bitdefender
2015-01-09 16:51 . 2015-01-09 18:16 -------- d-----w- c:\program files\Common Files\Bitdefender
2015-01-09 16:22 . 2015-01-09 16:22 -------- d-----w- c:\users\UpdatusUser\AppData\Local\Microsoft
2015-01-08 12:28 . 2015-01-08 17:08 -------- d-----w- c:\windows\system32\appmgmt
2015-01-07 19:44 . 2015-01-09 16:08 -------- d-----w- c:\users\home\AppData\Local\NVIDIA Corporation
2015-01-07 19:44 . 2010-05-26 09:41 470880 ----a-w- c:\windows\SysWow64\d3dx10_43.dll
2015-01-05 20:12 . 2015-01-05 20:12 -------- d-----w- c:\users\home\AppData\Local\Skype
2015-01-05 20:12 . 2015-01-09 16:21 -------- d-----w- c:\users\home\AppData\Roaming\Skype
2014-12-20 18:43 . 2015-01-17 09:32 -------- d-----w- c:\program files (x86)\Steam
2014-12-20 18:14 . 2014-12-20 18:14 -------- d-----w- c:\users\home\AppData\Local\Diagnostics
2014-12-19 21:30 . 2010-05-26 09:41 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll
2014-12-19 21:30 . 2010-05-26 09:41 2401112 ----a-w- c:\windows\system32\D3DX9_43.dll
2014-12-19 21:07 . 2015-01-16 15:09 -------- d-----w- C:\ets2
2014-12-19 16:20 . 2014-12-19 16:20 137728 ----a-w- c:\windows\SysWow64\drivers\ZTEusbnet.sys
2014-12-19 16:20 . 2014-12-19 16:20 123520 ----a-w- c:\windows\SysWow64\drivers\ZTEusbser6k.sys
2014-12-19 16:20 . 2014-12-19 16:20 123520 ----a-w- c:\windows\SysWow64\drivers\ZTEusbnmea.sys
2014-12-19 16:20 . 2014-12-19 16:20 123520 ----a-w- c:\windows\SysWow64\drivers\ZTEusbmdm6k.sys
2014-12-19 16:20 . 2014-12-19 16:20 11776 ----a-w- c:\windows\SysWow64\drivers\massfilter.sys
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-01-17 11:29 . 2014-10-24 11:37 30528 ----a-w- c:\windows\GVTDrv64.sys
2015-01-17 11:29 . 2014-10-24 11:37 25640 ----a-w- c:\windows\gdrv.sys
2015-01-16 17:58 . 2014-11-04 20:55 701616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2015-01-16 17:58 . 2014-10-24 15:05 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-01-15 16:48 . 2014-10-26 18:00 25640 ----a-w- c:\windows\etdrv.sys
2015-01-10 17:53 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2015-01-10 17:53 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2014-12-17 18:38 . 2014-12-17 18:38 74000 ----a-w- c:\windows\system32\bdsandboxuiskin32.dll
2014-12-08 22:20 . 2014-12-08 22:20 792648 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2014-12-08 22:20 . 2014-12-08 22:20 45880 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2014-12-08 22:20 . 2014-12-08 22:20 20184 ----a-w- c:\windows\system32\drivers\cmderd.sys
2014-12-08 22:20 . 2014-12-08 22:20 104608 ----a-w- c:\windows\system32\drivers\inspect.sys
2014-12-08 22:20 . 2014-12-08 22:20 437792 ----a-w- c:\windows\system32\guard64.dll
2014-12-08 22:20 . 2014-12-08 22:20 40736 ----a-w- c:\windows\system32\cmdcsr.dll
2014-12-08 22:20 . 2014-12-08 22:20 352272 ----a-w- c:\windows\SysWow64\guard32.dll
2014-12-08 22:20 . 2014-12-08 22:20 354520 ----a-w- c:\windows\system32\cmdvrt64.dll
2014-12-08 22:20 . 2014-12-08 22:20 45784 ----a-w- c:\windows\system32\cmdkbd64.dll
2014-12-08 22:20 . 2014-12-08 22:20 286424 ----a-w- c:\windows\SysWow64\cmdvrt32.dll
2014-12-08 22:20 . 2014-12-08 22:20 40664 ----a-w- c:\windows\SysWow64\cmdkbd32.dll
2014-12-02 14:37 . 2014-11-02 18:20 74000 ----a-w- c:\windows\SysWow64\bdsandboxuiskin32.dll
2014-12-02 14:37 . 2014-11-02 18:04 84336 ----a-w- c:\windows\system32\bdsandboxuiskin.dll
2014-12-02 11:37 . 2014-11-02 18:04 33360 ----a-w- c:\windows\system32\bdsandboxuh.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{D8278076-BC68-4484-9233-6E7F1628B56C}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\searchhook.dll" [2014-12-23 74648]
.
[HKEY_CLASSES_ROOT\clsid\{d8278076-bc68-4484-9233-6e7f1628b56c}]
[HKEY_CLASSES_ROOT\TypeLib\{7C4EE486-5EA5-4683-8C23-BF520933BB5E}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
2014-12-23 19:53 12184 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{4F524A2D-5350-4500-76A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport.dll" [2014-12-23 12184]
.
[HKEY_CLASSES_ROOT\clsid\{4f524a2d-5350-4500-76a7-7a786e7484d7}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"Octoshape Streaming Services"="c:\users\home\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2014-08-01 500016]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2014-11-21 7063832]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Dolby Home Theater v4"="c:\program files (x86)\Dolby Home Theater v4\pcee4.exe" [2012-08-31 508656]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2013-08-30 766208]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"MobileBroadband"="c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" [2013-07-17 76800]
"VmbNotifier"="c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbNotifier.exe" [2013-07-17 1862144]
"tvncontrol"="c:\program files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" [2015-01-14 2327248]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2015-01-16 507776]
"ApnTBMon"="c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2015-01-16 1949080]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"EasyTuneVI"="c:\program files (x86)\GIGABYTE\ET6\ETCall.exe" [2012-07-09 40960]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Start GeekBuddy.lnk - c:\program files\COMODO\GeekBuddy\launcher.exe "unit_manager.exe" [2014-9-25 48848]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R0 johci;JMicron 1394 Filter Driver;c:\windows\system32\DRIVERS\johci.sys;c:\windows\SYSNATIVE\DRIVERS\johci.sys [x]
R1 UsbCharger;UsbCharger;c:\windows\system32\DRIVERS\UsbCharger.sys;c:\windows\SYSNATIVE\DRIVERS\UsbCharger.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x]
R3 cmdvirth;COMODO Virtual Service Manager;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe [x]
R3 etdrv;etdrv;c:\windows\etdrv.sys;c:\windows\etdrv.sys [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys;c:\windows\GVTDrv64.sys [x]
R3 hptmv;hptmv;c:\windows\system32\DRIVERS\hptmv.sys;c:\windows\SYSNATIVE\DRIVERS\hptmv.sys [x]
R3 ICCS;Intel® Integrated Clock Controller Service - Intel® ICCS;c:\program files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 MegaSR1;MegaSR1;c:\windows\system32\DRIVERS\MegaSR1.sys;c:\windows\SYSNATIVE\DRIVERS\MegaSR1.sys [x]
R3 Pnp680;Pnp680;c:\windows\system32\DRIVERS\pnp680.sys;c:\windows\SYSNATIVE\DRIVERS\pnp680.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SI3112r;SI3112r;c:\windows\system32\DRIVERS\SI3112r.sys;c:\windows\SYSNATIVE\DRIVERS\SI3112r.sys [x]
R3 SI3114;SI3114;c:\windows\system32\DRIVERS\SI3114.sys;c:\windows\SYSNATIVE\DRIVERS\SI3114.sys [x]
R3 SI3124;SI3124;c:\windows\system32\DRIVERS\SI3124.sys;c:\windows\SYSNATIVE\DRIVERS\SI3124.sys [x]
R3 Si3124r5;Si3124r5;c:\windows\system32\DRIVERS\Si3124r5.sys;c:\windows\SYSNATIVE\DRIVERS\Si3124r5.sys [x]
R3 Si3531;Si3531;c:\windows\system32\DRIVERS\Si3531.sys;c:\windows\SYSNATIVE\DRIVERS\Si3531.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 viamrx64;viamrx64;c:\windows\system32\DRIVERS\viamrx64.sys;c:\windows\SYSNATIVE\DRIVERS\viamrx64.sys [x]
R3 ViBusX64;ViBusX64;c:\windows\system32\DRIVERS\ViBusX64.sys;c:\windows\SYSNATIVE\DRIVERS\ViBusX64.sys [x]
R3 ViPrtX64;ViPrtX64;c:\windows\system32\DRIVERS\ViPrtX64.sys;c:\windows\SYSNATIVE\DRIVERS\ViPrtX64.sys [x]
R3 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys;c:\windows\SYSNATIVE\DRIVERS\vmci.sys [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
S1 CFRMD;CFRMD;c:\windows\system32\DRIVERS\CFRMD.sys;c:\windows\SYSNATIVE\DRIVERS\CFRMD.sys [x]
S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys;c:\windows\SYSNATIVE\DRIVERS\cmderd.sys [x]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys;c:\windows\SYSNATIVE\DRIVERS\cmdguard.sys [x]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys;c:\windows\SYSNATIVE\DRIVERS\cmdhlp.sys [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AODDriver4.2;AODDriver4.2;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
S2 APNMCP;Ask Update Service;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [x]
S2 CLPSLauncher;COMODO LPS Launcher;c:\program files (x86)\Common Files\COMODO\launcher_service.exe;c:\program files (x86)\Common Files\COMODO\launcher_service.exe [x]
S2 DragonUpdater;COMODO Dragon Update Service;c:\program files (x86)\Comodo\Dragon\dragon_updater.exe;c:\program files (x86)\Comodo\Dragon\dragon_updater.exe [x]
S2 GeekBuddyRSP;GeekBuddyRSP Server;c:\program files (x86)\Common Files\COMODO\GeekBuddyRSP.exe;c:\program files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 VmbService;Vodafone Mobile Broadband Servisi;c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe;c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
S3 VUSB3HUB;VIA USB 3 Root Hub Service;c:\windows\system32\DRIVERS\ViaHub3.sys;c:\windows\SYSNATIVE\DRIVERS\ViaHub3.sys [x]
S3 xhcdrv;VIA USB eXtensible Host Controller Service;c:\windows\system32\DRIVERS\xhcdrv.sys;c:\windows\SYSNATIVE\DRIVERS\xhcdrv.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - CMDGUARD
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-01-16 19:24 1087816 ----a-w- c:\program files (x86)\Google\Chrome\Application\39.0.2171.99\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2015-01-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-04 17:58]
.
2015-01-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-10-24 11:21]
.
2015-01-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-10-24 11:21]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
2014-12-23 19:53 13720 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4F524A2D-5350-4500-76A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport_x64.dll" [2014-12-23 13720]
.
[HKEY_CLASSES_ROOT\CLSID\{4F524A2D-5350-4500-76A7-7A786E7484D7}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2013-12-13 13662936]
"RtHDVBg_Dolby"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2013-12-13 1368792]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-05-16 1012000]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cistray.exe" [2014-12-08 1297112]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.search.ask.com/?tpid=ORJ-SPE&o=APN11406&pf=V7&trgb=IE&p2=%5EBBE%5EOSJ000%5EYY%5ETR&gct=hp&apn_ptnrs=BBE&apn_dtid=%5EOSJ000%5EYY%5ETR&apn_dbr=ie&apn_uid=97A5BCF3-B9E9-48F5-991A-FDF416FB8AED&itbv=12.23.0.15&doi=2015-01-16&psv=&pt=tb
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Microsoft Excel'e &Ver - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.9.1 192.168.9.1
TCP: Interfaces\{3A14FDD3-7B56-4A0A-B6B6-74B98A1DF7D5}: NameServer = 156.154.70.25,156.154.71.25
TCP: Interfaces\{80130E56-7C63-42A5-8B5E-09625B1A62EE}: NameServer = 156.154.70.25,156.154.71.25
.
.
------- File Associations -------
.
inifile="%SystemRoot%\system32\NOTEPAD.EXE" %1
txtfile="%SystemRoot%\system32\NOTEPAD.EXE" %1
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-KSS - c:\program files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM-Run-InstallerLauncher - c:\program files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\setuplauncher.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\COMODO\CIS\Installer\Sym_Cam\CIS]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CmdAgent\Mode\Configurations]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,59,00,53,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CmdAgent\Mode\Data]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CmdAgent\Mode\Options]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\Software\COMODO\Cam]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\Software\COMODO\Firewall Pro]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,59,00,53,00,\
.
Completion time: 2015-01-17  14:03:53
ComboFix-quarantined-files.txt  2015-01-17 12:03
.
Pre-Run: 886.112.370.688 bayt boş
Post-Run: 885.615.071.232 bayt boş
.
- - End Of File - - 15FEDEEC5BF97BA1D86FF05272F3A507
A36C5E4F47E84449FF07ED3517B43A31


BC AdBot (Login to Remove)

 


#2 Machiavelli

Machiavelli

    Agent 007


  • Malware Response Instructor
  • 4,091 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:01:48 PM

Posted 17 January 2015 - 09:40 AM

Hey, :)

Please download FRST (by Farbar) from the link below and save it to your Desktop.

Download Mirror #1

If you are unsure whether you have 32-Bit or 64-Bit Windows, see here
  • Disable all anti-virus and anti-malware software to prevent them inhibiting FRST in any way. If you are unsure how to do this, see THIS.
  • Double-click FRST.exe/FRST64.exe (depending on which version you downloaded) to run it. (if you have Windows Vista / Windows 7 / Windows 8: Please do a Right click on the FRST icon and select Run as Administrator)
  • When the disclaimer appears, click Yes.
  • Click Scan to start FRST.
  • When FRST finishes scanning, two logs, FRST.txt and Addition.txt will open.
  • Copy (Ctrl+C) and Paste (Ctrl+V) the contents of both of these logs into your next post please.

~Machiavelli

If I don't reply within 24 hours please PM me!

  • Every topic with no replies within 5 days will be closed.
  • If you like my help here please give me feedback.

unite_blue.png
 
 


#3 Machiavelli

Machiavelli

    Agent 007


  • Malware Response Instructor
  • 4,091 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:01:48 PM

Posted 22 January 2015 - 10:17 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.

~Machiavelli

If I don't reply within 24 hours please PM me!

  • Every topic with no replies within 5 days will be closed.
  • If you like my help here please give me feedback.

unite_blue.png
 
 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users