Combo Fix
Combo Fix
4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.51.3082.18.2726.1610 [GMT -5:00]
Running from: c:\users\SERVER\Desktop\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619E
FD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B46268
9202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2013-08-04 to 2013-09-04 )))))))
))))))))))))))))))))))))
.
.
2013-09-04 04:04 . 2013-09-04 04:04
-------d-----wc:\users
\Default\AppData\Local\temp
2013-09-03 01:24 . 2013-09-03 01:24
-------d-----wc:\progr
am files\Common Files\DESIGNER
2013-09-03 01:23 . 2013-09-03 01:23
-------d-----wc:\progr
am files\Microsoft.NET
2013-09-03 01:23 . 2013-09-03 01:23
-------d-----wc:\progr
am files (x86)\Microsoft SQL Server
2013-09-03 01:22 . 2013-09-03 01:22
-------d-----wc:\progr
amdata\regid.1991-06.com.microsoft
2013-08-30 23:13 . 2013-08-30 23:13
-------d--h--wc:\windo
ws\PIF
2013-08-29 23:08 . 2013-08-29 23:08
-------d-----wc:\progr
am files\ReviverSoft
2013-08-29 22:49 . 2013-08-29 22:50
-------d-----wc:\progr
am files (x86)\USB Guardian
2013-08-27 22:18 . 2011-04-20 08:03
120320 ----a-wc:\windows\syste
m32\E_ILMHJB.DLL
2013-08-27 22:18 . 2011-03-15 08:03
83968 ----a-wc:\windows\syste
m32\E_ID4BHJB.DLL
2013-08-27 02:17 . 2013-08-27 02:17
-------d-----wC:\Adjus
tment Program
2013-08-26 21:56 . 2013-04-30 14:33
29704 ----a-wc:\windows\syste
m32\nitrolocalmon2.dll
2013-08-26 21:56 . 2013-04-30 14:33
17928 ----a-wc:\windows\syste
m32\nitrolocalui2.dll
2013-08-26 21:55 . 2013-08-26 21:55
-------d-----wc:\progr
am files\Common Files\Nitro
2013-08-26 21:55 . 2013-08-26 21:55
-------d-----wc:\progr
am files (x86)\Common Files\Nitro
2013-08-23 16:18 . 2013-08-23 16:18
-------d-----wc:\users
\SERVER\AppData\Roaming\PandoraRecovery
2013-08-18 00:07 . 2013-08-28 03:42
-------d-----wC:\Drive
rs
2013-08-17 04:48 . 2013-08-17 04:48
-------d-----wc:\progr
am files (x86)\SmartDCT4Calc v1.1.7
2013-08-17 04:46 . 2013-08-17 04:47
-------d-----wc:\progr
am files (x86)\usr
2013-08-17 01:38 . 2013-08-17 03:56
-------d-----wc:\progr
am files (x86)\WorldUnlock Codes Calculator
2013-08-17 00:37 . 2013-08-17 00:37
-------d-----wc:\users
\SERVER\AppData\Roaming\Apple Computer
2013-08-15 22:55 . 2013-08-15 22:56
-------d-----wc:\users
\SERVER\AppData\Local\Nokia
2013-08-15 22:55 . 2013-08-15 22:55
-------d-----wc:\users
\SERVER\AppData\Roaming\PC Suite
2013-08-15 22:55 . 2013-08-15 22:55
-------d-----wc:\progr
amdata\PC Suite
2013-08-15 22:55 . 2013-08-22 00:34
-------d-----wc:\progr
amdata\Nokia
2013-08-15 22:54 . 2012-10-17 19:53
26112 ----a-wc:\windows\syste
m32\drivers\pccsmcfdx64.sys
2013-08-15 22:54 . 2013-08-15 22:54
-------d-----wc:\progr
am files (x86)\PC Connectivity Solution
2013-08-15 22:54 . 2013-01-23 15:31
57856 ----a-wc:\windows\syste
m32\nmwcdclsX64.dll
2013-08-15 22:52 . 2013-08-15 22:55
-------d-----wc:\progr
am files (x86)\Nokia
2013-08-15 22:32 . 2013-08-15 22:32
-------d-----wc:\progr
am files\DIFX
2013-08-15 22:32 . 2013-08-15 22:54
-------dc----wc:\windo
ws\system32\DRVSTORE
2013-08-15 22:32 . 2012-02-12 02:25
28528 ----a-wc:\windows\rlt87
23a_chip_bt40_fw_asic_rom_patch.dll
2013-08-15 22:32 . 2013-08-15 22:32
-------d-----wc:\progr
am files (x86)\REALTEK
2013-08-15 22:32 . 2013-08-15 22:32
-------d-----wc:\users
\SERVER\AppData\Roaming\WinBatch
2013-08-15 21:55 . 2013-08-15 21:55
-------d-----wc:\progr
amdata\Mobile Master
2013-08-15 21:53 . 2013-08-15 21:53
-------d-----wc:\users
\SERVER\AppData\Roaming\Jumping Bytes
2013-08-15 21:00 . 2013-08-15 21:00
-------d-----wc:\users
\SERVER\AppData\Local\Wondershare
2013-08-15 21:00 . 2013-08-15 21:00
-------d-----wc:\progr
am files (x86)\Common Files\Wondershare
2013-08-15 21:00 . 2013-08-16 01:17
-------d-----wc:\progr
am files (x86)\Temp
2013-08-15 21:00 . 2013-08-15 21:00
-------d-----wc:\progr
am files (x86)\Wondershare
2013-08-15 16:26 . 2013-08-15 16:26
-------d-----wc:\users
\SERVER\AppData\Local\ApplicationHistory
2013-08-15 15:19 . 2013-08-15 15:19
-------d-----wc:\progr
am files (x86)\Your Uninstaller! 7
2013-08-15 15:19 . 2013-08-15 15:19
-------d-----wc:\users
\SERVER\AppData\Roaming\URSoft
2013-08-15 15:11 . 2013-08-15 15:11
-------d-----wc:\progr
am files (x86)\VS Revo Group
2013-08-14 00:52 . 2013-09-03 05:14
-------d-----wc:\users
\SERVER\AppData\Local\CrashDumps
2013-08-14 00:04 . 2013-08-14 00:04
-------d-----wc:\users
\SERVER\AppData\Roaming\Iminent
2013-08-14 00:04 . 2013-08-14 00:04
-------d-----wc:\progr
amdata\Iminent
2013-08-14 00:03 . 2013-08-14 00:03
-------d-----wc:\progr
am files (x86)\Common Files\Umbrella
2013-08-13 23:59 . 2013-08-13 23:59
-------d-----wc:\users
\SERVER\AppData\Roaming\Progeny
2013-08-13 23:53 . 2013-08-14 00:46
952
--sha-wc:\programdata\K
GyGaAvL.sys
2013-08-13 23:53 . 2004-12-07 12:11
258352 ----a-wc:\windows\SysWo
w64\unicows.dll
2013-08-13 23:53 . 2013-08-13 23:53
-------d-----wc:\progr
am files (x86)\Common Files\Progeny
2013-08-13 23:53 . 2013-08-31 04:36
-------d-----wc:\progr
am files\TLM Professional
2013-08-13 23:52 . 2013-08-13 23:52
-------d-----wc:\progr
am files (x86)\Common Files\InstallShield
2013-08-13 23:11 . 2013-08-14 01:13
-------d-----wc:\users
\SERVER\AppData\Roaming\CmapTools
2013-08-13 23:11 . 2013-08-14 14:47
-------d-----wc:\users
\SERVER\CmapToolsLogs
2013-08-13 23:09 . 2013-08-14 14:48
-------d-----wc:\progr
am files\IHMC CmapTools
2013-08-13 23:09 . 2013-08-13 23:09
-------d--h--wc:\progr
am files\Zero G Registry
2013-08-13 23:08 . 2013-08-13 23:08
-------d--h--wc:\users
\SERVER\InstallAnywhere
2013-08-13 14:53 . 2013-08-21 19:52
-------d-----wc:\users
\SERVER\AppData\Roaming\Skype
2013-08-13 14:53 . 2013-08-13 14:53
-------d-----wc:\progr
am files (x86)\Common Files\Skype
2013-08-13 14:53 . 2013-08-13 14:53
-------d-----rc:\progr
am files (x86)\Skype
2013-08-13 14:52 . 2013-08-13 14:53
-------d-----wc:\progr
amdata\Skype
2013-08-11 16:16 . 2013-08-11 16:19
-------d-----wc:\users
\SERVER\AppData\Roaming\Corel
2013-08-11 16:16 . 2013-08-11 16:16
-------d-----wc:\progr
amdata\Protexis64
2013-08-11 16:11 . 2013-08-11 16:11
-------d-----wc:\progr
am files (x86)\Microsoft SDKs
2013-08-11 16:10 . 2013-08-11 16:14
-------d-----wc:\progr
am files (x86)\Microsoft Visual Studio 9.0
2013-08-11 16:10 . 2013-08-11 16:10
-------d-----wc:\progr
am files (x86)\Common Files\Intel
2013-08-11 16:08 . 2013-08-11 16:08
-------d-----wc:\progr
am files\Common Files\Corel
2013-08-11 16:07 . 2013-08-11 16:07
-------d-----wc:\progr
am files\Common Files\Protexis
2013-08-11 16:07 . 2013-08-11 16:07
-------d-----wc:\progr
amdata\Corel
2013-08-11 16:02 . 2013-08-11 16:02
-------d-----wc:\progr
am files\Corel
2013-08-11 14:36 . 2013-08-14 14:26
-------d-----wc:\users
\SERVER\AppData\Roaming\Movdap
2013-08-08 21:38 . 2013-08-08 21:39
-------d-----wc:\users
\SERVER\AppData\Roaming\SmileysWeLove
2013-08-08 21:38 . 2009-09-12 16:21
1831424 ----a-wc:\windows\Netwo
rkCfg.exe
2013-08-08 21:38 . 2013-08-09 01:50
-------d-----wc:\progr
amdata\Anyplace Control 4
2013-08-08 11:59 . 2013-09-04 02:56
-------d-----wC:\servi
dor1.585b-Sin-Publi
2013-08-08 01:51 . 2013-09-03 08:47
-------d-----wc:\users
\SERVER\AppData\Roaming\Nitro PDF
2013-08-07 19:39 . 2013-08-26 22:33
-------d-----wc:\users
\SERVER\AppData\Roaming\Nitro
2013-08-07 19:39 . 2013-08-07 19:39
-------d-----wc:\users
\SERVER\AppData\Roaming\FileOpen
2013-08-07 19:39 . 2013-08-07 19:39
-------d-----wc:\progr
amdata\FileOpen
2013-08-07 19:37 . 2013-08-07 19:37
-------d-----wc:\progr
amdata\Nitro
2013-08-07 19:37 . 2013-08-07 19:37
-------d-----wc:\progr
am files (x86)\Nitro
2013-08-07 19:36 . 2013-08-26 21:54
-------d-----wc:\users
\SERVER\AppData\Roaming\Downloaded Installations
2013-08-07 19:24 . 2013-08-07 19:24
-------d-----wc:\users
\SERVER\AppData\Roaming\SolidDocuments
2013-08-07 19:23 . 2011-10-04 07:33
12800 ----a-wc:\windows\syste
m32\solidlocalui.dll
2013-08-07 19:23 . 2011-10-04 07:33
24576 ----a-wc:\windows\syste
m32\solidlocalmon.dll
2013-08-07 19:23 . 2013-08-07 19:23
-------d-----wc:\progr
am files (x86)\SolidDocuments
2013-08-07 19:22 . 2013-08-07 19:22
-------d-----wc:\progr
amdata\SolidDocuments
2013-08-07 02:07 . 2002-01-12 15:30
3567
----a-wc:\windows\SysWo
w64\drivers\PortTalk.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))
)))))))))))))))))))))))))))))))
.
2013-08-21 17:23 . 2013-07-31 06:21
71048 ----a-wc:\windows\SysWo
w64\FlashPlayerCPLApp.cpl
2013-08-21 17:23 . 2013-07-31 06:21
692104 ----a-wc:\windows\SysWo
w64\FlashPlayerApp.exe
2013-08-01 22:01 . 2013-08-01 19:30
82816 ----a-wc:\users\SERVER\
AppData\Roaming\pcouffin.sys
2013-08-01 04:19 . 2013-07-31 17:34
175736 ----a-wc:\windows\syste
m32\drivers\SYMEVENT64x86.SYS
2013-07-31 23:03 . 2013-07-31 23:03
52992 ----a-wc:\windows\syste
m32\drivers\KSafeDISK.sys
2013-07-31 23:03 . 2013-07-31 23:03
33024 ----a-wc:\windows\syste
m32\drivers\BTOWSFF.sys
2013-07-31 23:03 . 2013-07-31 23:03
59648 ----a-wc:\windows\syste
m32\drivers\BTOWSVF.sys
2013-07-31 06:22 . 2013-07-31 06:22
1199175 ----a-wc:\windows\unins
002.exe
2013-07-31 06:22 . 2013-07-31 06:22
1198049 ----a-wc:\windows\unins
001.exe
2013-07-31 06:20 . 2013-07-31 06:20
709719 ----a-wc:\windows\unins
000.exe
2013-07-31 06:12 . 2013-07-31 06:12
972712 ----a-wc:\windows\syste
m32\deployJava1.dll
2013-07-31 06:12 . 2013-07-31 06:12
312232 ----a-wc:\windows\syste
m32\javaws.exe
2013-07-31 06:12 . 2013-07-31 06:12
1093032 ----a-wc:\windows\syste
m32\npDeployJava1.dll
2013-07-31 06:12 . 2013-07-31 06:12
189352 ----a-wc:\windows\syste
m32\javaw.exe
2013-07-31 06:12 . 2013-07-31 06:12
188840 ----a-wc:\windows\syste
m32\java.exe
2013-07-31 06:12 . 2013-07-31 06:12
108968 ----a-wc:\windows\syste
m32\WindowsAccessBridge-64.dll
2013-07-31 06:11 . 2013-07-31 06:11
867240 ----a-wc:\windows\SysWo
w64\npDeployJava1.dll
2013-07-31 06:11 . 2013-07-31 06:11
789416 ----a-wc:\windows\SysWo
w64\deployJava1.dll
2013-07-31 06:11 . 2013-07-31 06:11
96168 ----a-wc:\windows\SysWo
w64\WindowsAccessBridge-32.dll
2013-06-26 23:20 . 2013-07-31 06:22
131072 ----a-wc:\windows\SysWo
w64\AiORuntimes.dll
2013-06-10 00:53 . 2013-06-10
w64\mfcm110u.dll
2013-06-10 00:53 . 2013-06-10
w64\mfcm110.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110fra.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110deu.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110esn.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110ita.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110rus.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110enu.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110jpn.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110kor.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110cht.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110chs.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110u.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110.dll
2013-06-10 00:53 . 2013-06-10
w64\atl110.dll
2013-06-09 20:59 . 2013-06-09
m32\mfcm110u.dll
2013-06-09 20:59 . 2013-06-09
m32\mfcm110.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110fra.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110deu.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110esn.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110ita.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110rus.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110enu.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110u.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110jpn.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110kor.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110cht.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110chs.dll
2013-06-09 20:59 . 2013-06-09
00:53
83024
----a-w-
c:\windows\SysWo
00:53
83016
----a-w-
c:\windows\SysWo
00:53
74832
----a-w-
c:\windows\SysWo
00:53
74832
----a-w-
c:\windows\SysWo
00:53
73808
----a-w-
c:\windows\SysWo
00:53
72784
----a-w-
c:\windows\SysWo
00:53
70736
----a-w-
c:\windows\SysWo
00:53
65104
----a-w-
c:\windows\SysWo
00:53
53840
----a-w-
c:\windows\SysWo
00:53
53328
----a-w-
c:\windows\SysWo
00:53
46160
----a-w-
c:\windows\SysWo
00:53
46160
----a-w-
c:\windows\SysWo
00:53
4456520 ----a-w-
c:\windows\SysWo
00:53
4421192 ----a-w-
c:\windows\SysWo
00:53
164424 ----a-w-
c:\windows\SysWo
20:59
90192
----a-w-
c:\windows\syste
20:59
90184
----a-w-
c:\windows\syste
20:59
74832
----a-w-
c:\windows\syste
20:59
74832
----a-w-
c:\windows\syste
20:59
73808
----a-w-
c:\windows\syste
20:59
72784
----a-w-
c:\windows\syste
20:59
70736
----a-w-
c:\windows\syste
20:59
65104
----a-w-
c:\windows\syste
20:59
5619784 ----a-w-
c:\windows\syste
20:59
5592648 ----a-w-
c:\windows\syste
20:59
53840
----a-w-
c:\windows\syste
20:59
53328
----a-w-
c:\windows\syste
20:59
46160
----a-w-
c:\windows\syste
20:59
46160
----a-w-
c:\windows\syste
20:59
192584 ----a-w-
c:\windows\syste
m32\atl110.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))
)))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EE932B49-D5C0
-4D19-A3DA-CE0849258DE6}]
2013-08-28 00:19
277560 ----a-wc:\program files (x86)\Common Fi
les\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explor
er\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2012-10-02 01:38
1720976 ----a-wc:\progra~2\MICROS~2\Office15\GR
OOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explor
er\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2012-10-02 01:38
1720976 ----a-wc:\progra~2\MICROS~2\Office15\GR
OOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explor
er\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2012-10-02 01:38
1720976 ----a-wc:\progra~2\MICROS~2\Office15\GR
OOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdateChecker"="c:\program files (x86)\Squeaky Chocolate" [X]
"ToolwizCareFree"="c:\program files (x86)\ToolwizCareFree\ToolwizCares.exe" [201
3-07-31 5191936]
"EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\x64\3\E_IATIHJB
.EXE" [2012-02-29 283232]
"USB Guardian"="c:\program files (x86)\USB Guardian\USB Guardian.exe" [2013-06-1
9 457216]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusch
ed.exe" [2013-03-12 253816]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManag
er.exe" [2010-08-30 979328]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [20
13-05-10 958576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\win
dows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c
:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft
.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:
\program files (x86)\Skype\Updater\Updater.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\driver
s\dmvsc.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\
Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engi
ne\OSE.EXE [x]
R3 PortTalk;PortTalk;c:\windows\system32\Drivers\PortTalk.sys;c:\windows\SYSNATI
VE\Drivers\PortTalk.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\dri
vers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RtkBtFilter;Realtek Bluetooth Filter Driver;c:\windows\system32\DRIVERS\RtkBt
filter.sys;c:\windows\SYSNATIVE\DRIVERS\RtkBtfilter.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\S
YSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\te
rminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATI
VE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD
.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATI
VE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\driver
s\rdvgkmd.sys [x]
S0 BTOWSVF;BTOWSVF;c:\windows\System32\Drivers\BTOWSVF.sys;c:\windows\SYSNATIVE\
Drivers\BTOWSVF.sys [x]
S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys;c:\windows\SYSNATIVE\
DRIVERS\iaStorA.sys [x]
S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys;c:\windows\SYSNATIVE\
DRIVERS\iaStorF.sys [x]
S0 iusb3hcs;Controlador del conmutador de la controladora de host Intel(R) USB 3
.0;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hc
s.sys [x]
S0 KSafeDISK;KSafeDISK;c:\windows\System32\Drivers\KSafeDISK.sys;c:\windows\SYSN
ATIVE\Drivers\KSafeDISK.sys [x]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1309010.00E\SYMD
S64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1309010.00E\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1
309010.00E\SYMEFA64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1309010.00E\SYMEFA64
.SYS [x]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7
}\NIS_19.1.0.28\Definitions\BASHDefs\20130715.001\BHDrvx64.sys;c:\programdata\No
rton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\2
0130715.001\BHDrvx64.sys [x]
S1 BTOWSFF;BTOWSFF;c:\windows\System32\Drivers\BTOWSFF.sys;c:\windows\SYSNATIVE\
Drivers\BTOWSFF.sys [x]
S1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drive
rs\NISx64\1309010.00E\ccSetx64.sys;c:\windows\SYSNATIVE\drivers\NISx64\1309010.0
0E\ccSetx64.sys [x]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7
}\NIS_19.1.0.28\Definitions\IPSDefs\20130903.001\IDSvia64.sys;c:\programdata\Nor
ton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\201
30903.001\IDSvia64.sys [x]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1309010.00E\I
ronx64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1309010.00E\Ironx64.SYS [x]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx
64\1309010.00E\SYMNETS.SYS;c:\windows\SYSNATIVE\Drivers\NISx64\1309010.00E\SYMNE
TS.SYS [x]
S2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);c:\program files\Common Files\EPSON\E
PW!3 SSRP\E_S50STB.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.E
XE [x]
S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\E
PW!3 SSRP\E_S50RPB.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.E
XE [x]
S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\
Engine\19.9.1.14\ccSvcHst.exe;c:\program files (x86)\Norton Internet Security\En
gine\19.9.1.14\ccSvcHst.exe [x]
S2 NitroDriverReadSpool8;NitroPDFDriverCreatorReadSpool8;c:\program files\Common
Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe;c:\program files\Common Files
\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [x]
S2 PSI_SVC_2_x64;Protexis Licensing V2 x64;c:\program files\Common Files\Protexi
s\License Service\PsiService_2.exe;c:\program files\Common Files\Protexis\Licens
e Service\PsiService_2.exe [x]
S2 SCPDFReadSpool;SolidConverterPDFReadSpool;c:\program files (x86)\SolidDocumen
ts\Solid Converter PDF\SCPDF\SolidConverterPDFServicex64.exe;c:\program files (x
86)\SolidDocuments\Solid Converter PDF\SCPDF\SolidConverterPDFServicex64.exe [x]
S2 SProtection;SProtection;c:\program files (x86)\Common Files\Umbrella\umbrella
.exe;c:\program files (x86)\Common Files\Umbrella\umbrella.exe [x]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\S
ymantec Shared\EENGINE\EraserUtilRebootDrv.sys;c:\program files (x86)\Common Fil
es\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x]
S3 IntcDAud;Sonido Intel(R) para pantallas;c:\windows\system32\DRIVERS\IntcDAud.
sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 iusb3hub;Controlador del concentrador Intel(R) USB 3.0;c:\windows\system32\DR
IVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Controlador de la controladora de host Intel(R) USB 3.0 eXtensible;c
:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sy
s [x]
S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controlle
r;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64
.sys [x]
S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\D
RIVERS\rtwlane.sys;c:\windows\SYSNATIVE\DRIVERS\rtwlane.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-09-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-31 17
:23]
.
.
--------- X64 Entries ----------.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258D
E6}]
2013-08-28 00:19
336952 ----a-wc:\program files (x86)\Common Fi
les\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2013-03-22 172016]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2013-03-22 399856]
"Persistence"="c:\windows\system32\igfxpers.exe" [2013-03-22 442352]
.
------- Supplementary Scan ------.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://start.iminent.com/?appId=1A40E0A8-A0C5-4D8D-B0FA-513C323397
9D
mDefault_Page_URL = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/
mStart Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/i
ndex.jsp?lg=es&pid=NIS&pvid=19.9.1.14
mSearch Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/
IE: E&xportar a Microsoft Excel - c:\progra~2\MICROS~2\Office15\EXCEL.EXE/3000
IE: Free YouTube Download - c:\program files (x86)\Common Files\DVDVideoSoft\plu
gins\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\program files (x86)\Common Files\DVDVideo
Soft\plugins\freeytmp3downloader.htm
IE: {{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258
DE6} - c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtn
s.dll
TCP: Interfaces\{5D718E17-9FF4-4DF8-904B-C63219A308DA}: NameServer = 200.48.225.
130,200.48.225.146
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x8
6)\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
FF - ProfilePath - c:\users\SERVER\AppData\Roaming\Mozilla\Firefox\Profiles\siec
c966.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.
aspx?ctid=CT1055551&CUI=UN41145102021057831&UM=1&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - StartWeb
FF - prefs.js: browser.startup.homepage - hxxp://start.iminent.com/?appId=1A40E0
A8-A0C5-4D8D-B0FA-513C3233979D
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT10
55551&SearchSource=2&CUI=UN41145102021057831&UM=1&q=
FF - ExtSQL: 2013-07-31 12:34; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; c:\progra
mdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\IPSFFPlgn
FF - ExtSQL: 2013-07-31 13:19; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; c:\progra
mdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn
FF - ExtSQL: 2013-07-31 14:25; {ACAA314B-EEBA-48e4-AD47-84E31C44796C}; c:\progra
m files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF - ExtSQL: 2013-08-29 17:50; {da30eff8-ccc6-4162-a20d-67402a26a215}; c:\users\
SERVER\AppData\Roaming\Mozilla\Firefox\Profiles\siecc966.default\extensions\{da3
0eff8-ccc6-4162-a20d-67402a26a215}
FF - user.js: extensions.delta.tlbrSrchUrl FF - user.js: extensions.delta.id - 96787de600000000000024ec992a7f8b
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15918
FF - user.js: extensions.delta.vrsn - 1.8.22.0
FF - user.js: extensions.delta.vrsni - 1.8.22.0
FF - user.js: extensions.delta.vrsnTs - 1.8.22.013:58
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - es
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.ffxUnstlRst - true
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta_i.babTrack - affID=119293&tsp=4961
FF - user.js: extensions.delta_i.babExt FF - user.js: extensions.delta_i.srcExt - ss
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C40800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C40800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C40800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B
0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B
0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B
0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actio
ns\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0
]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\Actio
nsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-09-03 23:06:28
ComboFix-quarantined-files.txt 2013-09-04 04:06
ComboFix2.txt 2013-08-31 02:42
ComboFix3.txt 2013-08-28 03:50
.
Pre-Run: 115,292,651,520 bytes libres
Post-Run: 115,239,292,928 bytes libres
.
- - End Of File - - 691A458865AD4F691091BB7C6980A784
A36C5E4F47E84449FF07ED3517B43A31