Please find paste of dds.txt and attached file attach.txt. Thank you
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17801 BrowserJavaVersion: 11.31.2
Run by ghamrick at 14:10:08 on 2015-06-05
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.11967.9943 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
SP: Microsoft Security Essentials *Enabled/Updated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
C:\Windows\system32\svchost.exe -k apphost
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Windows\System32\TpShocks.exe
C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files (x86)\SunplusIT Integrated Camera\Monitor.exe
C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files\HP\HP Officejet Pro 8610\Bin\ScanToPCActivationApp.exe
C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
C:\Users\ghamrick\AppData\Local\Akamai\netsession_win.exe
C:\Users\ghamrick\AppData\Local\Akamai\netsession_win.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Windows\system32\rundll32.exe
C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
C:\Program Files (x86)\Popcorn Time\Updater.exe
C:\Windows\system32\svchost.exe -k iissvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\PROGRA~1\LENOVO\HOTKEY\tpnumlkd.exe
C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\rundll32.exe
C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE
C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE
C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.exe
C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\HP\HP Officejet Pro 8610\Bin\HPNetworkCommunicatorCom.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uProxyOverride = <local>
mWinlogon: Userinit = userinit.exe,
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
uRun: [HP Officejet Pro 8610 (NET)] "C:\Program Files\HP\HP Officejet Pro 8610\Bin\ScanToPCActivationApp.exe" -deviceID "CN45LBK1XT:NW" -scfn "HP Officejet Pro 8610 (NET)" -AutoStart 1
uRun: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
uRun: [Spybot-S&D Cleaning] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean
uRun: [Uploader] C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe
uRun: [Akamai NetSession Interface] "C:\Users\ghamrick\AppData\Local\Akamai\netsession_win.exe"
mRun: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
mRun: [PWMTRV] rundll32 "C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.DLL",PwrMgrBkGndMonitor
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [Lenovo Registration] C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe /boot
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [Dolby Home Theater v4] "C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart
mRun: [DelaypluginInstall] C:\ProgramData\Aimersoft\Video Converter Ultimate\DelayPluginI.exe
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Aimersoft Helper Compact.exe] C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
StartupFolder: C:\Users\ghamrick\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\ghamrick\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\ghamrick\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\EVERNO~1.LNK - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
StartupFolder: C:\Users\ghamrick\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENVP~1.LNK - C:\Program Files\OpenVPN\bin\openvpn-gui.exe
StartupFolder: C:\Users\ghamrick\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\PASSWO~1.LNK - D:\Password Safe\pwsafe.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
mPolicies-System: DisableCAD = dword:1
IE: Clip bookmark - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=0
IE: Clip image - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=4
IE: Clip selection - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=3
IE: Clip this page - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=1
IE: Clip URL - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MIF5BA~1\Office15\EXCEL.EXE/3000
IE: New note - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\NewNote.html
IE: Se&nd to OneNote - C:\PROGRA~1\MIF5BA~1\Office15\ONBttnIE.dll/105
IE: Send to Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm
IE: SmarThru4 Capture Selection - C:\Program Files (x86)\SmarThru 4\x64\WebCapture.dll2.htm
IE: SmarThru4 Save as HTML - C:\Program Files (x86)\SmarThru 4\x64\WebCapture.dll1.htm
IE: SmarThru4 Save Selected Text - C:\Program Files (x86)\SmarThru 4\x64\WebCapture.dll.htm
IE: SmarThru4 Web Capture - C:\Program Files (x86)\SmarThru 4\x64\WebCapture.dll
IE: {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 8.8.8.8
TCP: Interfaces\{0C9854BA-E9D7-4606-ABD7-782B8B923BB4} : DHCPNameServer = 8.8.8.8
TCP: Interfaces\{61C2F9C5-4B45-415F-9D38-3DB6EB229621} : NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
TCP: Interfaces\{796DFF5C-045D-4CCF-B4BC-B9F3CDDFAEA7}\84F4F4655425E45445 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{796DFF5C-045D-4CCF-B4BC-B9F3CDDFAEA7}\86F6F6675627E65647 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{796DFF5C-045D-4CCF-B4BC-B9F3CDDFAEA7}\E45445745414256353 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{CD5734AE-ED61-4179-A6EA-5466204EB18C} : DHCPNameServer = 208.67.222.222 192.168.1.1
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Handler: WSAMVCUchrome - {086BD280-4613-43B5 - <orphaned>
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
LSA: Notification Packages = scecli C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll ACGina
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
x64-Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
x64-Run: [RtHDVBg_Dolby] "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
x64-Run: [TpShocks] TpShocks.exe
x64-Run: [LENOVO.TPKNRRES] C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Run: [IgfxTray] "C:\Windows\System32\igfxtray.exe"
x64-Run: [HotKeysCmds] "C:\Windows\System32\hkcmd.exe"
x64-Run: [Persistence] "C:\Windows\System32\igfxpers.exe"
x64-Run: [AcWin7Hlpr] C:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
x64-Run: [Integrated Camera_Monitor] C:\Program Files (x86)\SunplusIT Integrated Camera\Monitor.exe
x64-Run: [BLEServicesCtrl] C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe
x64-Run: [Logitech Download Assistant] C:\Windows\System32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
x64-IE: {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
x64-IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\AddNote.html
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
x64-Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Handler: WSAMVCUchrome - {086BD280-4613-43B5 - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-Notify: psfus - C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
x64-SSODL: WebCheck - <orphaned>
Hosts: 127.0.0.1
Spyware Info | Spyware Info
Hosts: 192.168.1.1 router.asus.com
.
============= SERVICES / DRIVERS ===============
.
R0 DzHDD64;DzHDD64;C:\Windows\System32\drivers\DZHDD64.SYS [2013-10-17 29512]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2013-10-17 20024]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2015-3-4 280376]
R0 TPDIGIMN;TPDIGIMN;C:\Windows\System32\drivers\ApsHM64.sys [2014-1-29 29496]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2014-4-16 283064]
R1 RsFx0151;RsFx0151 Driver;C:\Windows\System32\drivers\RsFx0151.sys [2011-6-17 313696]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-12-10 732160]
R2 IntelHaxm;Intel Haxm;C:\Windows\System32\drivers\IntelHaxm.sys [2013-11-6 89072]
R2 LENOVO.CAMMUTE;Lenovo Camera Mute;C:\Program Files\Lenovo\Communications Utility\CamMute.exe [2013-10-17 59168]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;C:\Program Files\Lenovo\HOTKEY\micmute.exe [2015-4-17 111048]
R2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction;C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe [2013-10-17 72992]
R2 LENOVO.TVTVCAM;Lenovo Virtual Camera Controller;C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [2013-10-17 197408]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe [2013-10-24 115184]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2013-6-18 124568]
R2 PST Service;PST Service;C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [2013-11-15 65657]
R2 risdxc;risdxc;C:\Windows\System32\drivers\risdxc64.sys [2013-10-17 101888]
R2 smihlp2;SMI Helper Driver (smihlp2);C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [2011-5-30 13128]
R2 SSPORT;SSPORT;C:\Windows\System32\drivers\SSPORT.sys [2014-5-9 11576]
R3 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2012-6-18 1095616]
R3 Bluetooth Media Service;Bluetooth Media Service;C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [2012-6-18 1333184]
R3 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2012-6-18 1124288]
R3 btmaux;Intel Bluetooth Auxiliary Service;C:\Windows\System32\drivers\btmaux.sys [2012-5-21 111104]
R3 btmhsf;btmhsf;C:\Windows\System32\drivers\btmhsf.sys [2012-6-9 849408]
R3 ibtfltcoex;ibtfltcoex;C:\Windows\System32\drivers\iBtFltCoex.sys [2012-7-9 60928]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-10-24 169752]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2013-10-17 342528]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2013-10-17 358456]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2013-10-17 791608]
R3 iwdbus;IWD Bus Enumerator;C:\Windows\System32\drivers\iwdbus.sys [2013-7-26 25528]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2014-7-19 25816]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2015-4-30 366544]
R3 SmbDrvI;SmbDrvI;C:\Windows\System32\drivers\Smb_driver_Intel.sys [2014-5-16 31472]
R3 SPUVCbv;SPUVCb Driver Service;C:\Windows\System32\drivers\SPUVCBv_x64.sys [2015-5-5 688032]
R3 TVTI2C;Lenovo SM bus driver;C:\Windows\System32\drivers\tvti2c.sys [2012-2-7 40248]
R3 tvtvcamd;Camera Plus (VGA Resolution Maximum);C:\Windows\System32\drivers\tvtvcamd.sys [2013-10-17 27432]
R3 usb3Hub;UoIP Hub;C:\Windows\System32\drivers\usb3Hub.sys [2013-6-20 206744]
S2 Apple Mobile Device Service;Apple Mobile Device Service;C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-1-20 77128]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-4-12 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-4-11 124088]
S2 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-13 27136]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2013-10-17 169432]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-7-19 1080120]
S2 Motorola Device Manager;Motorola Device Manager Service;C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [2013-11-15 137528]
S3 c2wts;Claims to Windows Token Service;C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [2014-1-9 15768]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\System32\drivers\ssudbus.sys [2014-1-22 108800]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-20 71168]
S3 DozeSvc;Lenovo Doze Mode Service;C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [2013-10-17 319536]
S3 hitmanpro37;HitmanPro 3.7 Support Driver;C:\Windows\System32\drivers\hitmanpro37.sys [2015-6-4 43664]
S3 HTCAND64;HTC Device Driver;C:\Windows\System32\drivers\ANDROIDUSB.sys [2009-11-2 33736]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2015-5-13 114688]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\Windows\System32\drivers\intelaud.sys [2013-7-26 35256]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-10 803872]
S3 iumsvc;Intel(R) Update Manager;C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-2-28 174368]
S3 LSCWinService;LSCWinService;C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [2015-3-9 272440]
S3 MBAMWebAccessControl;MBAMWebAccessControl;C:\Windows\System32\drivers\mwac.sys [2014-7-19 63704]
S3 motandroidusb;Mot ADB Interface Driver;C:\Windows\System32\drivers\motoandroid.sys [2013-3-26 32768]
S3 MSSQL$CIMS_DEV;SQL Server (CIMS_DEV);C:\Program Files\Microsoft SQL Server\MSSQL10_50.CIMS_DEV\MSSQL\Binn\sqlservr.exe [2011-6-17 62111072]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2014-1-8 284912]
S3 Power Manager DBC Service;Power Manager Service;C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe [2013-10-17 1668896]
S3 PwmEWSvc;Cisco EnergyWise Enabler;C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.exe [2013-10-17 1664800]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2014-4-19 19456]
S3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;C:\Windows\System32\drivers\RTL8192cu.sys [2010-8-12 748648]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\Windows\System32\drivers\ssudmdm.sys [2014-1-22 206080]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2014-4-19 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2014-4-19 30208]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2014-7-28 54784]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files\Microsoft SQL Server\100\Shared\sqladhlp.exe [2010-4-3 59744]
.
=============== File Associations ===============
.
FileExt: .pif: CryptoPreventPIF="C:\Program Files (x86)\Foolish IT\CryptoPrevent\CryptoPreventFilterMod.CryptoPreventEXEC" *"%1" %*
FileExt: .scr: CryptoPreventSCR="C:\Program Files (x86)\Foolish IT\CryptoPrevent\CryptoPreventFilterMod.CryptoPreventEXEC" "%1" /S %*
FileExt: .txt: Applications\notepad++.exe="C:\Program Files (x86)\Notepad++\notepad++.exe" "%1" [UserChoice]
FileExt: .ini: Applications\notepad++.exe="C:\Program Files (x86)\Notepad++\notepad++.exe" "%1" [UserChoice]
FileExt: .js: VisualStudio.js.12.0 - HKCR\Unknown\Shell=C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,OpenAs_RunDLL %1 [UserChoice] [default=openas]
.
=============== Created Last 30 ================
.
2015-06-04 15:37:44 -------- dc----w- C:\FRST
2015-06-04 14:27:51 43664 -c--a-w- C:\Windows\System32\drivers\hitmanpro37.sys
2015-06-04 14:19:43 -------- dc----w- C:\ProgramData\HitmanPro
2015-06-04 12:55:17 -------- dc----w- C:\AdwCleaner
2015-06-04 12:29:21 12214312 -c--a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{71B21811-CDB6-4E7A-891E-1B8E1B1B0FC1}\mpengine.dll
2015-06-04 12:17:41 24 -c--a-w- C:\Users\ghamrick\AppData\Roaming\appdataFr25.bin
2015-06-03 12:13:20 1187344 -c--a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F2BEF488-1E72-409D-8069-5BB343B00906}\gapaengine.dll
2015-06-03 12:12:57 12214312 -c--a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2015-06-03 01:15:52 34072 -c--a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll
2015-06-03 01:15:52 229608 -c--a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2015-06-03 01:15:52 215040 -c--a-w- C:\Program Files (x86)\Mozilla Firefox\browser\plugins\npatgpc.dll
2015-06-01 22:49:24 -------- dc----w- C:\Users\ghamrick\AppData\Local\GWX
2015-05-22 20:16:10 -------- dc----w- C:\Users\ghamrick\.gnupg
2015-05-14 07:05:11 -------- dc----w- C:\Windows\PCHEALTH
2015-05-14 07:03:43 124112 ----a-w- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2015-05-14 07:03:43 102608 ----a-w- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 12:47:00 328704 ----a-w- C:\Windows\System32\services.exe
2015-05-13 12:45:57 72192 ----a-w- C:\Windows\System32\aelupsvc.dll
2015-05-13 12:45:57 6656 ----a-w- C:\Windows\System32\shimeng.dll
2015-05-13 12:45:57 5120 ----a-w- C:\Windows\SysWow64\shimeng.dll
2015-05-13 12:45:57 342016 ----a-w- C:\Windows\System32\apphelp.dll
2015-05-13 12:45:57 295936 ----a-w- C:\Windows\SysWow64\apphelp.dll
2015-05-13 12:45:57 23552 ----a-w- C:\Windows\System32\sdbinst.exe
2015-05-13 12:45:57 20992 ----a-w- C:\Windows\SysWow64\sdbinst.exe
2015-05-06 20:57:34 -------- dc----w- C:\Program Files (x86)\SunplusIT Integrated Camera
.
==================== Find3M ====================
.
2015-06-04 13:47:26 136408 -c--a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2015-06-04 12:20:38 778416 -c--a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2015-06-04 12:20:38 142512 -c--a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2015-05-14 07:35:55 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2015-05-14 07:35:52 142336 ----a-w- C:\Windows\System32\poqexec.exe
2015-05-14 07:19:17 460800 ----a-w- C:\Windows\System32\certcli.dll
2015-05-14 07:19:17 342016 ----a-w- C:\Windows\SysWow64\certcli.dll
2015-05-14 07:19:17 342016 ----a-w- C:\Windows\System32\schannel.dll
2015-05-14 07:19:17 248832 ----a-w- C:\Windows\SysWow64\schannel.dll
2015-05-14 07:17:09 3204608 ----a-w- C:\Windows\System32\win32k.sys
2015-05-14 07:17:09 1647104 ----a-w- C:\Windows\System32\DWrite.dll
2015-05-14 07:17:09 1250816 ----a-w- C:\Windows\SysWow64\DWrite.dll
2015-05-14 07:17:09 1179136 ----a-w- C:\Windows\System32\FntCache.dll
2015-05-14 07:16:47 275456 ----a-w- C:\Windows\System32\InkEd.dll
2015-05-14 07:16:47 24576 ----a-w- C:\Windows\System32\jnwmon.dll
2015-05-14 07:16:47 216064 ----a-w- C:\Windows\SysWow64\InkEd.dll
2015-05-14 07:09:15 2543104 ----a-w- C:\Windows\System32\wpdshext.dll
2015-05-14 07:09:15 2311168 ----a-w- C:\Windows\SysWow64\wpdshext.dll
2015-05-14 07:02:31 470528 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
2015-05-14 07:02:31 309248 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2015-05-14 07:02:31 2560 ----a-w- C:\Windows\apppatch\AcRes.dll
2015-05-14 07:02:31 2178560 ----a-w- C:\Windows\apppatch\AcGenral.dll
2015-05-14 07:02:31 103424 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2015-05-05 08:22:14 428064 -c--a-w- C:\Windows\System32\VCamPPage_x64.dll
2015-05-05 08:17:50 81440 -c--a-w- C:\Windows\System32\DextUVCB_x64.ax
2015-05-05 08:17:50 78368 -c--a-w- C:\Windows\SysWow64\DextUVCB.ax
2015-05-05 08:17:50 688032 -c--a-w- C:\Windows\System32\drivers\SPUVCBv_x64.sys
2015-05-05 08:17:50 357920 -c--a-w- C:\Windows\SysWow64\VCamPPage.dll
2015-04-15 07:08:57 404480 ----a-w- C:\Windows\System32\gdi32.dll
2015-04-15 07:08:57 311808 ----a-w- C:\Windows\SysWow64\gdi32.dll
2015-04-15 07:03:27 2048 ----a-w- C:\Windows\SysWow64\msxml3r.dll
2015-04-15 07:03:27 2048 ----a-w- C:\Windows\System32\msxml3r.dll
2015-04-15 07:03:27 1882624 ----a-w- C:\Windows\System32\msxml3.dll
2015-04-15 07:03:27 1237504 ----a-w- C:\Windows\SysWow64\msxml3.dll
2015-04-15 07:01:37 754688 ----a-w- C:\Windows\System32\drivers\http.sys
2015-04-15 07:00:34 79360 ----a-w- C:\Windows\System32\clfsw32.dll
2015-04-15 07:00:34 58880 ----a-w- C:\Windows\SysWow64\clfsw32.dll
2015-04-15 07:00:34 367552 ----a-w- C:\Windows\System32\clfs.sys
2015-04-14 13:37:56 63704 -c--a-w- C:\Windows\System32\drivers\mwac.sys
2015-04-14 13:37:46 107736 -c--a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2015-04-14 13:37:42 25816 -c--a-w- C:\Windows\System32\drivers\mbam.sys
2015-04-08 15:02:09 53248 -c--a-w- C:\Windows\SysWow64\zlib.dll
2015-03-16 21:36:56 922704 -c--a-w- C:\Windows\System32\drivers\VBoxDrv.sys
2015-03-16 21:35:46 204264 -c--a-w- C:\Windows\System32\VBoxNetFltNobj.dll
2015-03-16 21:35:46 156360 -c--a-w- C:\Windows\System32\drivers\VBoxNetFlt.sys
2015-03-16 21:35:46 141440 -c--a-w- C:\Windows\System32\drivers\VBoxNetAdp.sys
2015-03-16 21:35:46 128592 -c--a-w- C:\Windows\System32\drivers\VBoxUSBMon.sys
2015-03-12 07:15:15 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2015-03-12 07:15:15 46080 ----a-w- C:\Windows\System32\atmlib.dll
2015-03-12 07:15:15 41984 ----a-w- C:\Windows\System32\lpk.dll
2015-03-12 07:15:15 372224 ----a-w- C:\Windows\System32\atmfd.dll
2015-03-12 07:15:15 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2015-03-12 07:15:15 299008 ----a-w- C:\Windows\SysWow64\atmfd.dll
2015-03-12 07:15:15 25600 ----a-w- C:\Windows\SysWow64\lpk.dll
2015-03-12 07:15:15 14336 ----a-w- C:\Windows\System32\dciman32.dll
2015-03-12 07:15:15 10240 ----a-w- C:\Windows\SysWow64\dciman32.dll
2015-03-12 07:15:15 100864 ----a-w- C:\Windows\System32\fontsub.dll
2015-03-12 07:13:02 3179520 ----a-w- C:\Windows\System32\rdpcorets.dll
2015-03-12 07:13:02 243200 ----a-w- C:\Windows\System32\rdpudd.dll
2015-03-12 07:13:02 16384 ----a-w- C:\Windows\System32\RdpGroupPolicyExtension.dll
2015-03-12 07:12:09 215552 ----a-w- C:\Windows\System32\ubpm.dll
2015-03-12 07:12:09 171520 ----a-w- C:\Windows\SysWow64\ubpm.dll
2015-03-12 07:10:46 459336 ----a-w- C:\Windows\System32\drivers\cng.sys
2015-03-12 07:03:56 828928 ----a-w- C:\Windows\SysWow64\msctf.dll
2015-03-12 07:03:56 1067520 ----a-w- C:\Windows\System32\msctf.dll
2015-03-12 07:03:37 1424896 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2015-03-12 07:03:37 1230848 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2015-03-12 07:00:36 465920 ----a-w- C:\Windows\System32\WMPhoto.dll
2015-03-12 07:00:36 417792 ----a-w- C:\Windows\SysWow64\WMPhoto.dll
.
============= FINISH: 14:10:52.77 ===============