ComboFix 18-08-08.01 - Salta Game 20/03/2019 22:04:06.1.2 - x86 Microsoft Windows 7 Home Basic 6.1.7601.1.1252.34.3082.18.1919.526 [GMT -3:00] Running from: c:\users\Salta Game\Desktop\ComboFix.exe * Resident AV is active . . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\juegos c:\juegos\1943 Portable By MaMeDiMiTriS.rar c:\juegos\1943.exe c:\juegos\ABurner2.exe c:\juegos\AfterBurner.exe c:\juegos\Altered Beast Portable By MaMeDiMiTriS.rar c:\juegos\Alteredbeast.exe c:\juegos\Bad Dudes Vs Dragon Ninja Portable By MaMeDiMiTriS.rar c:\juegos\BloodBros.exe c:\juegos\Cabal Portable By MaMeDiMiTriS.rar c:\juegos\Contra Portable By MaMeDiMiTriS.rar c:\juegos\Contra.exe c:\juegos\contra12.rar c:\juegos\DmC Devil May Cry Complete Edition MULTi9-PROPHET\637290-CMDCED.part1.rar c:\juegos\DmC Devil May Cry Complete Edition MULTi9-PROPHET\637290-CMDCED.part2.rar c:\juegos\DmC Devil May Cry Complete Edition MULTi9-PROPHET\637290-CMDCED.part3.rar c:\juegos\Double Dragon Gaiden Openbor Portable By MaMeDiMiTriS.rar c:\juegos\Double Dragon Reloaded Portable (Openbor) By MaMeDiMiTriS.rar c:\juegos\Double_Dragon.exe c:\juegos\DoubleDragonII.exe c:\juegos\Final Fight 2 Arcade Portable By MaMeDiMiTriS.rar c:\juegos\Final Fight Collections By MaMeDiMiTriS.rar c:\juegos\Final Fight Gold Portable Openbor By MaMeDiMiTriS.rar c:\juegos\Final Fight Portable By MaMeDiMiTriS.rar c:\juegos\Final Fight X Portable Openbor By MaMeDiMiTriS.rar c:\juegos\FinalFight.exe c:\juegos\Golden Axe 2.exe c:\juegos\Golden Axe Collections v2.0 By MaMeDiMiTriS.rar c:\juegos\Golden Axe TheDuel.exe c:\juegos\Grand Theft Auto San Andreas MULTi10-ElAmigos\147886-TAGSAN.rar c:\juegos\Grand Theft Auto San Andreas MULTi10-ElAmigos\Grand.Theft.Auto.San.Andreas.MULTi10-ElAmigos\elamigos.jpg c:\juegos\Grand Theft Auto San Andreas MULTi10-ElAmigos\Grand.Theft.Auto.San.Andreas.MULTi10-ElAmigos\Grand Theft Auto - San Andreas.iso c:\juegos\Grand Theft Auto San Andreas MULTi10-ElAmigos\Grand.Theft.Auto.San.Andreas.MULTi10-ElAmigos\Ova Games.url c:\juegos\Grand Theft Auto San Andreas MULTi10-ElAmigos\Grand.Theft.Auto.San.Andreas.MULTi10-ElAmigos\Readme.txt c:\juegos\Hammerin Harry Portable By MaMeDiMiTriS.rar c:\juegos\Hammerin Harry.exe c:\juegos\MarvelVSStreetFighters.exe c:\juegos\Operation Wolf.exe c:\juegos\operation.wolf.exe c:\juegos\Prisioners Of War Portable By MaMeDiMiTriS.rar c:\juegos\Psychic5 Portable By MaMeDiMiTriS.rar c:\juegos\Robocop 2 Portable By MaMeDiMiTriS.rar c:\juegos\Robocop 2.exe c:\juegos\Robocop Portable By MaMeDiMiTriS.rar c:\juegos\Robocop.exe c:\juegos\ShadowDancer.exe c:\juegos\Snow Bros 2.exe c:\juegos\Snow Bros Collections v2.0 By MaMeDiMiTriS.rar c:\juegos\snow_brothers.exe c:\juegos\SnowBros.exe c:\juegos\SnowBrothers3.exe c:\juegos\Street Fighter Collections v2.0 By MaMeDiMiTriS.rar c:\juegos\The NewZealand Story H_NEW VERSION.exe c:\juegos\The NewZealand Story H_OLD.exe c:\juegos\Toki Portable By MaMeDiMiTriS.rar c:\juegos\Toki.exe c:\juegos\Twin Cobra 2 Portable By MaMeDiMiTriS.rar c:\juegos\Western Collections v2.0 By MaMeDiMiTriS.rar c:\juegos\WonderBoy Portable By MaMeDiMiTriS.rar c:\juegos\Wonderboy.exe c:\juegos\Xaind Sleena.exe c:\users\Salta Game\AppData\Local\Microsoft\Windows\Temporary Internet Files\{D4C690BF-9D93-4120-84E2-66575647B2E3}.xps c:\users\Salta Game\AppData\Roaming\Microsoft\Windows\index001.dat . . ((((((((((((((((((((((((( Files Created from 2019-02-21 to 2019-03-21 ))))))))))))))))))))))))))))))) . . 2019-03-21 01:16 . 2019-03-21 01:16 -------- d-----w- c:\users\Salta Game\AppData\Local\temp 2019-03-21 01:16 . 2019-03-21 01:16 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2019-03-21 01:16 . 2019-03-21 01:16 -------- d-----w- c:\users\Default\AppData\Local\temp 2019-03-21 00:51 . 2019-03-21 00:51 -------- d-----w- c:\windows\ERUNT 2019-03-21 00:46 . 2019-03-21 00:46 64088 ----a-w- c:\windows\system32\drivers\mbam.sys 2019-03-21 00:45 . 2019-03-21 00:45 107168 ----a-w- c:\windows\system32\drivers\farflt.sys 2019-03-21 00:45 . 2019-03-21 00:45 85232 ----a-w- c:\windows\system32\drivers\mwac.sys 2019-03-20 22:32 . 2019-03-20 22:32 172280 ----a-w- c:\windows\system32\drivers\MbamChameleon.sys 2019-03-20 22:32 . 2019-03-20 22:39 240440 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2019-03-20 22:12 . 2019-03-20 22:12 -------- d-----w- c:\users\Salta Game\AppData\Local\VS Revo Group 2019-03-20 22:12 . 2019-03-20 22:12 -------- d-----w- c:\programdata\VS Revo Group 2019-03-20 22:11 . 2019-03-20 22:11 -------- d-----w- c:\program files\VS Revo Group 2019-03-20 22:07 . 2019-03-20 22:07 -------- d-----w- c:\users\Salta Game\AppData\Local\mbam 2019-03-20 22:03 . 2019-03-20 22:32 128552 ----a-w- c:\windows\system32\drivers\mbae.sys 2019-03-20 22:03 . 2019-03-20 22:03 -------- d-----w- c:\programdata\Malwarebytes 2019-03-20 22:03 . 2019-03-20 22:03 -------- d-----w- c:\program files\Malwarebytes 2019-03-20 21:55 . 2019-03-20 21:58 -------- d-----w- C:\FRST 2019-03-20 21:49 . 2019-03-20 22:16 -------- d-----w- c:\program files\Reimage 2019-03-20 21:16 . 2019-02-21 14:55 12009616 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0AF87ACC-C9B9-43B9-B22F-62AF85B1093E}\mpengine.dll 2019-03-20 00:38 . 2019-03-20 00:38 -------- d-----w- c:\users\Salta Game\AppData\Local\DESlock+ 2019-03-20 00:36 . 2019-03-20 00:47 -------- d-----w- C:\AdwCleaner 2019-03-20 00:19 . 2019-03-20 00:19 -------- d-----w- c:\users\Salta Game\AppData\Local\ESET 2019-03-20 00:01 . 2019-03-20 00:38 -------- d-----w- c:\program files\ESET 2019-03-19 23:24 . 2019-03-19 23:24 -------- d-----w- c:\programdata\{1C5CB847-36DB-4B88-A32B-0BC7A3CC5296} 2019-03-19 23:24 . 2019-03-20 00:41 -------- d-----w- c:\users\Salta Game\AppData\Local\App 2019-03-19 23:24 . 2019-03-20 20:51 -------- d-----w- c:\windows\system32\evtghkou 2019-03-19 23:23 . 2019-03-19 23:23 -------- d-----w- c:\programdata\{CC8296D9-1845-9B56-3D05-D5173DE28C46} 2019-03-19 23:23 . 2019-03-19 23:23 145168 ----a-w- c:\program files\Windows NT\symsrv.exe 2019-03-19 23:23 . 2019-03-19 23:23 1191936 ----a-w- c:\program files\Windows NT\symsrv.dll 2019-03-19 23:23 . 2019-03-19 23:39 -------- d-----w- c:\users\Salta Game\AppData\Roaming\my12jgyhep4 2019-03-19 23:22 . 2019-03-19 23:22 -------- d-----w- c:\program files\TigerTrade 2019-03-19 23:22 . 2019-03-20 00:40 -------- d-----w- c:\users\Salta Game\AppData\Local\Mail.Ru 2019-03-19 23:22 . 2019-03-19 23:22 -------- d-----w- c:\programdata\Mail.Ru 2019-03-19 23:21 . 2019-03-20 00:39 -------- d-----w- c:\program files\bsoi 2019-03-19 22:48 . 2019-03-19 22:48 253952 ------w- c:\windows\Setup1.exe 2019-03-19 22:48 . 2019-03-19 22:48 74240 ----a-w- c:\windows\ST6UNST.EXE 2019-03-19 22:13 . 2019-03-19 22:20 -------- d-----w- C:\Senior 2019-03-18 22:03 . 2019-02-21 14:55 12009616 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2019-03-12 22:11 . 2019-02-16 05:30 123904 ----a-w- c:\windows\system32\poqexec.exe 2019-03-12 22:10 . 2019-02-10 16:41 12574208 ----a-w- c:\windows\system32\wmploc.DLL 2019-03-01 00:46 . 2019-03-01 00:46 -------- d-----w- c:\programdata\boost_interprocess 2019-03-01 00:45 . 2019-03-20 00:41 -------- d-----w- c:\users\Salta Game\AppData\Local\GlobalMapper 2019-03-01 00:45 . 2019-03-01 00:45 -------- d-----w- c:\users\Salta Game\AppData\Local\SafeNet Sentinel 2019-03-01 00:45 . 2019-03-01 00:45 -------- d-----w- c:\programdata\SafeNet Sentinel 2019-03-01 00:43 . 2019-03-20 00:41 -------- d-----w- c:\users\Salta Game\AppData\Local\IIIQF 2019-02-27 06:59 . 2019-02-27 06:59 94856 ----a-w- c:\windows\system32\drivers\epfwwfp.sys 2019-02-27 06:59 . 2019-02-27 06:59 91720 ----a-w- c:\windows\system32\drivers\edevmon.sys 2019-02-27 06:59 . 2019-02-27 06:59 72480 ----a-w- c:\windows\system32\drivers\epfw.sys 2019-02-27 06:59 . 2019-02-27 06:59 53808 ----a-w- c:\windows\system32\drivers\EpfwLWF.sys 2019-02-27 06:59 . 2019-02-27 06:59 43952 ----a-w- c:\windows\system32\drivers\ekbdflt.sys 2019-02-27 06:59 . 2019-02-27 06:59 147288 ----a-w- c:\windows\system32\drivers\ehdrv.sys 2019-02-27 06:59 . 2019-02-27 06:59 125056 ----a-w- c:\windows\system32\drivers\eamonm.sys 2019-02-22 22:23 . 2019-03-20 22:19 -------- d-----w- c:\program files\Seagate 2019-02-22 22:18 . 2019-03-20 00:13 -------- d-----w- c:\users\Salta Game\AppData\Roaming\Hard Disk Sentinel 2019-02-22 22:17 . 2019-02-22 22:23 -------- d-----w- c:\program files\Hard Disk Sentinel . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2019-03-06 03:20 . 2019-03-12 22:34 5120 ----a-w- c:\windows\system32\drivers\es-ES\srv.sys.mui 2019-02-16 21:50 . 2017-11-04 21:10 97144 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2019-01-12 02:36 . 2019-02-12 21:45 352768 ----a-w- c:\windows\system32\msrd3x40.dll 2019-01-12 02:36 . 2019-02-12 21:45 1311744 ----a-w- c:\windows\system32\msjet40.dll 2019-01-04 15:56 . 2019-03-12 22:34 2560 ----a-w- c:\windows\apppatch\AcRes.dll 2019-01-01 16:01 . 2019-02-12 21:45 105192 ----a-w- c:\windows\system32\consent.exe 2019-01-01 15:58 . 2019-02-12 21:45 2368000 ----a-w- c:\windows\system32\msi.dll 2019-01-01 15:58 . 2019-02-12 21:45 337408 ----a-w- c:\windows\system32\msihnd.dll 2019-01-01 15:58 . 2019-02-12 21:45 25088 ----a-w- c:\windows\system32\msimsg.dll 2019-01-01 15:57 . 2019-02-12 21:45 1806848 ----a-w- c:\windows\system32\authui.dll 2019-01-01 15:57 . 2019-02-12 21:45 47104 ----a-w- c:\windows\system32\appinfo.dll 2019-01-01 15:39 . 2019-02-12 21:45 73216 ----a-w- c:\windows\system32\msiexec.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ESD Shell Icon Overlay Identifier] @="{AF106685-9C86-48AF-8524-8F485C459E17}" [HKEY_CLASSES_ROOT\CLSID\{AF106685-9C86-48AF-8524-8F485C459E17}] 2017-11-02 17:47 92864 ----a-w- c:\program files\ESET\ESET Secure Data\esdovrly.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\W32X86\3\E_TATIRQE.EXE" [2014-11-14 380400] "ultracopier"="c:\program files\Ultracopier\ultracopier.exe" [2016-01-01 1224192] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2017-09-14 16553448] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2016-11-14 1002984] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184] "EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2016-03-14 1092304] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2018-12-16 601424] "egui"="c:\program files\ESET\ESET Security\ecmds.exe" [2019-02-27 170128] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R1 MpKsld8c8093b;MpKsld8c8093b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D7E8DA2F-F263-4332-81A8-9B56B2511FD6}\MpKsld8c8093b.sys [x] R1 YjBiZDU1NjNiYTg4;YjBiZDU1NjNiYTg4;c:\windows\system32\drivers\YjBiZDU1NjNiYTg4 [x] R2 rcdll;rcdll service;c:\users\SALTAG~1\AppData\Local\Temp\rcdll.exe [x] R2 symsrv;symsrv service;c:\program files\windows nt\symsrv.exe [2019-03-19 145168] R3 GoogleChromeElevationService;Google Chrome Elevation Service;c:\program files\Google\Chrome\Application\72.0.3626.121\elevation_service.exe [2019-03-01 1043440] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2019-02-26 104960] R3 netr28u;RT2870 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr28u.sys [2013-01-24 1583136] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2016-08-25 105696] R3 NisSrv;Inspección de red de Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe [2016-11-14 280864] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2016-07-21 14848] R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys [2016-12-21 35632] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2016-07-21 24064] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2016-07-21 49152] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2016-07-21 26880] S0 DLMFENC;DLMFENC;c:\windows\system32\DRIVERS\DLMFENC.sys [2018-02-27 142408] S0 DLPCRYPT;DLPCRYPT;c:\windows\system32\DRIVERS\dlpcrypt.sys [2017-11-02 109824] S0 dlpvdisk;dlpvdisk;c:\windows\system32\DRIVERS\dlpvdisk.sys [2017-11-02 84984] S0 edevmon;edevmon;c:\windows\system32\DRIVERS\edevmon.sys [2019-02-27 91720] S0 MBAMSwissArmy;MBAMSwissArmy;c:\windows\System32\Drivers\mbamswissarmy.sys [2019-03-20 240440] S0 VDLPToken2;VDLPToken2;c:\windows\system32\DRIVERS\vdlptkn2.sys [2017-11-02 125432] S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2019-02-27 125056] S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2019-02-27 147288] S1 EpfwLWF;ESET Firewall;c:\windows\system32\DRIVERS\EpfwLWF.sys [2019-02-27 53808] S1 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2019-02-27 94856] S1 ESProtectionDriver;Malwarebytes Anti-Exploit;c:\windows\system32\drivers\mbae.sys [2019-03-20 128552] S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe [2009-07-14 20992] S2 dlpsrv;DESlock+ Service;c:\program files\ESET\ESET Secure Data\dlpsrv.exe [2017-11-02 486080] S2 ekbdflt;ekbdflt;c:\windows\system32\DRIVERS\ekbdflt.sys [2019-02-27 43952] S2 ekrn;ESET Service;c:\program files\ESET\ESET Security\ekrn.exe [2019-02-27 1887640] S2 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\EscSvc.exe [2017-03-10 223560] S2 MBAMChameleon;MBAMChameleon;c:\windows\System32\Drivers\MbamChameleon.sys [2019-03-20 172280] S2 MBAMService;Malwarebytes Service;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe [2019-02-01 5247944] S3 ekrnEpfw;ESET Firewall Helper;c:\program files\ESET\ESET Security\ekrn.exe [2019-02-27 1887640] S3 MBAMFarflt;MBAMFarflt;c:\windows\system32\DRIVERS\farflt.sys [2019-03-21 107168] S3 MBAMProtection;MBAMProtection;c:\windows\system32\DRIVERS\mbam.sys [2019-03-21 64088] S3 MBAMWebProtection;MBAMWebProtection;c:\windows\system32\DRIVERS\mwac.sys [2019-03-21 85232] . . --- Other Services/Drivers In Memory --- . *NewlyCreated* - ESPROTECTIONDRIVER *NewlyCreated* - MBAMFARFLT *NewlyCreated* - MBAMPROTECTION *NewlyCreated* - MBAMWEBPROTECTION . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr fdrespub AppIDSvc QWAVE wcncsvc SensrSvc utcsvc REG_MULTI_SZ DiagTrack . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2019-03-06 21:39 2237936 ----a-w- c:\program files\Google\Chrome\Application\72.0.3626.121\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2019-03-21 c:\windows\Tasks\EPSON L380 Series Update {BFD45B5F-F934-46C1-AF9E-A648E270D8F7}.job - c:\windows\system32\spool\DRIVERS\W32X86\3\E_TTSRQE.EXE [2017-02-01 16:30] . . ------- Supplementary Scan ------- . IE: &Enviar a OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105 IE: E&xportar a Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.100.1 FF - ProfilePath - c:\users\Salta Game\AppData\Roaming\Mozilla\Firefox\Profiles\6hq9oq2w.default\ . - - - - ORPHANS REMOVED - - - - . MSConfigStartUp-8886068 - c:\users\Salta Game\AppData\Roaming\my12jgyhep4\nufhqtdilk2.exe MSConfigStartUp-App - c:\users\Salta Game\AppData\Local\App\svchost.exe MSConfigStartUp-izxklosy - c:\users\Salta Game\vannqpfk.exe MSConfigStartUp-TK2CWDUWNXZAE02 - c:\program files\AUPPMFRHCS\UMKQUIT25.exe AddRemove-uTorrent - c:\users\Salta Game\AppData\Roaming\uTorrent\uTorrent.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\YjBiZDU1NjNiYTg4] "ImagePath"="\??\c:\windows\system32\drivers\YjBiZDU1NjNiYTg4" . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2019-03-20 22:19:30 ComboFix-quarantined-files.txt 2019-03-21 01:19 . Pre-Run: 21.407.055.872 bytes libres Post-Run: 22.125.842.432 bytes libres . - - End Of File - - 964F6C3CFFBE90F44436BE9463B32B80 A36C5E4F47E84449FF07ED3517B43A31